// VULNERABILITIES

// ВРАЗЛИВОСТІ

6 articles
All Zero-Day Ransomware Phishing Supply Chain AI Security Data Breaches Malware Vulnerabilities Attacks Security
SolarWinds Patches Four Critical Serv-U Vulnerabilities

SolarWinds released patches for four critical vulnerabilities in their Serv-U product that could be exploited for remote code execution. This is a legitimate vulnerability disclosure involving specific CVEs/security defects in a widely-used file transfer software.

Ex-US Defense Contractor Executive Jailed for Selling Exploits to Russia

Peter Williams, an ex-US Defense Contractor executive, was sentenced to 87 months in prison for selling cyber exploits to a Russian broker. This represents an actual security incident involving the unauthorized transfer of exploits to a foreign adversary.

CISA: Recently patched RoundCube flaws now exploited in attacks

CISA has identified two Roundcube Webmail vulnerabilities that are being actively exploited in real attacks against organizations. U.S. federal agencies have been mandated to patch these vulnerabilities within three weeks, indicating confirmed active exploitation in the wild.

Recent RoundCube Webmail Vulnerability Exploited in Attacks

A vulnerability in RoundCube Webmail that was patched in December 2025 is being actively exploited in attacks. The flaw allows XSS (cross-site scripting) attacks through animate tags in SVG documents, representing a real security incident affecting webmail users.

Critical Grandstream Phone Vulnerability Exposes Calls to Interception

A critical vulnerability (CVE-2026-2329) was discovered in Grandstream phones that allows unauthenticated remote code execution with root privileges and can expose calls to interception. This is a legitimate vulnerability disclosure affecting a specific product with real security implications for affected organizations.

CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog

CISA added two actively exploited Roundcube webmail vulnerabilities (CVE-2025-49113 and another) to its Known Exploited Vulnerabilities catalog, indicating real-world attacks are occurring against this widely-used email software. The critical deserialization flaw (CVSS 9.9) enables remote code execution and is being actively weaponized in the wild.