Section
Cybersecurity
Deep coverage of cybersecurity — benchmarks, launches and the long-form analysis we wish we had.
Showing 9 of 14

wp2shell (CVE-2026-63030): A WordPress Core Pre-Auth RCE, and What to Do Now
wp2shell (CVE-2026-63030 + CVE-2026-60137) is a pre-authentication RCE in WordPress Core, already exploited in the wild. Here's who is affected, how the exploit chain works, how to patch, and how to check whether your server was already compromised.

New Langflow RCE (CVE-2026-10134) Is a Perfect 10 — Patch Now and Rotate Your Keys
CVE-2026-10134 is a CVSS 10.0 unauthenticated RCE in Langflow (versions 1.0.0 through 1.9.3) that lets attackers read every secret on the server. Here is the flaw, the pattern behind Langflow's 2026 RCEs, and how to patch.

SharePoint Zero-Day CVE-2026-58644: Patch Now and Rotate Your Machine Keys
SharePoint CVE-2026-58644 is a CVSS 9.8 remote-code-execution zero-day already exploited in the wild. CISA gave federal agencies until July 19, 2026 to patch on-prem SharePoint Server — and rotating your IIS machine keys matters as much as the patch.

Adobe ColdFusion CVE-2026-48282: A Max-Severity (CVSS 10) Bug Already Under Attack — Patch Now
CVE-2026-48282 is a CVSS 10.0 path-traversal flaw in Adobe ColdFusion that lets an unauthenticated attacker run code over the network. Adobe patched it June 30, 2026; it's already exploited and on CISA's KEV list. Here's what it is and how to respond.

Januscape (CVE-2026-53359): a 16-Year-Old KVM Flaw Lets VMs Escape the Host
Januscape (CVE-2026-53359) is a 16-year-old use-after-free in Linux KVM's shadow MMU that lets a guest VM escape to the host on Intel and AMD. Here's how the flaw works, who's exposed, and the patched kernel versions to deploy now.

RoguePlanet (CVE-2026-50656): Windows Defender Zero-Day Patched 29 Days After Public Exploit
RoguePlanet (CVE-2026-50656) is a Windows Defender zero-day that hands any local user SYSTEM control. Microsoft shipped the fix on July 9, 2026, nearly a month after working exploit code went public. Here is what it is, who is affected, and how to check your engine is patched.

BlueHammer (CVE-2026-33825): The Microsoft Defender Flaw Now Used in Ransomware
CISA has flagged BlueHammer (CVE-2026-33825), a Microsoft Defender privilege-escalation vulnerability, as exploited in ransomware attacks. Here's what the flaw does, whether you're patched, and why patching alone doesn't fully close it.

Argo CD's Unpatched RCE Flaw Lets Attackers Take Over Kubernetes Clusters (2026)
A newly disclosed Argo CD repo-server vulnerability gives unauthenticated attackers remote code execution and a path to full Kubernetes cluster takeover. There's no patch and no CVE — here's how the attack works and how to lock it down today.

Bad Epoll (CVE-2026-46242): the Linux Kernel Root Flaw and What It Means for Your Servers
Bad Epoll (CVE-2026-46242) is a Linux kernel privilege-escalation flaw that gives any local user root on kernel 6.4 and newer. Here is who is affected, how to check your version, and how to patch your servers.