Exploit Security News

Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.

Once a vulnerability is disclosed, the risk changes sharply the moment working exploit code goes public: a theoretical bug turns into something any attacker can weaponize. Proof-of-concept releases, exploitation write-ups and additions to exploit frameworks show up here as they appear. A published exploit is usually the signal that patching moves from "should" to "urgent".

Recent Exploit items

CVE-2026-102279 Laravel is a web application framework. Prior to 12.69.0 and 13.30.0, Laravel exception debug pages with APP_DEBUG=true pass attacker-controlled input to a Tippy.js tooltip configured…
@cveNotify · Sep 28, 2026
CVE-2026-100653 vLLM is an inference and serving engine for large language models. In versions from 0.22.1 through 0.28.0, the operator-supplied model revision pin (--revision / --code-revision) is no…
@cveNotify · Sep 28, 2026
CVE-2026-100650 vLLM through 0.29.0 fetches and fully materializes remote or inline media before enforcing its documented media controls (the VLLM_MAX_AUDIO_CLIP_FILESIZE_MB compressed-audio size cap,…
@cveNotify · Sep 28, 2026
CVE-2026-100503 Ghidra versions through 12.1.4 contain a heap use-after-free vulnerability in the decompiler's Funcdata::opInsertAfter function caused by stale INDIRECT effect-op references. Attackers…
@cveNotify · Sep 28, 2026
Citrix Patches Critical Zero Days Under Active Exploitation 📔 Citrix has confirmed exploitation of two critical zeroday RCE bugs. 📖 Read more. 🔗 Via " Infosecurity Magazine " ---------- 👁️ Seen on
@cibsecurity · Sep 28, 2026
Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats 🖋️ A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registe…
@cibsecurity · Sep 28, 2026
Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks 🖋️ Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may ha…
@cibsecurity · Sep 28, 2026
CVE-2026-87741 The ConvertPlus plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 3.6.3 via the style parameter of the cp_display_preview_mod…
@cveNotify · Sep 28, 2026
CVE-2026-86950 An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a mal…
@cveNotify · Sep 28, 2026
CVE-2026-101143 A vulnerability was found in Eleveo Quality Management 9.7.0. Affected by this issue is some unknown functionality of the file /qm/cz.zoom.scorecard.webui.Scorecard/cz.zoom.scorecard.w…
@cveNotify · Sep 28, 2026
CVE-2026-101142 A vulnerability has been found in Eleveo Quality Management 9.7.0. Affected by this vulnerability is an unknown functionality of the file Scorecard.jsp of the component Questionnaire A…
@cveNotify · Sep 28, 2026
CVE-2026-101141 A flaw has been found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/audio.jsp of the component Play Audio Page. Executing a manipulation…
@cveNotify · Sep 28, 2026
CVE-2026-97023 A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deletion of attacker-chosen files outside…
@cveNotify · Sep 28, 2026
CVE-2026-102010 A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal…
@cveNotify · Sep 28, 2026
CVE-2026-101139 A vulnerability was detected in Webkul Bagisto up to 2.4.6. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status Up…
@cveNotify · Sep 28, 2026
CVE-2026-97023 A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deletion of attacker-chosen files outside…
@cveNotify · Sep 28, 2026
CVE-2026-102010 A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal…
@cveNotify · Sep 28, 2026
CVE-2026-101139 A vulnerability was detected in Webkul Bagisto up to 2.4.6. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status Up…
@cveNotify · Sep 28, 2026
CVE-2026-101132 A security flaw has been discovered in DeepSeek deepseek-harness up to 0.1.7-rc.2. The affected element is the function loadProfile of the file packages/boot/app-boot/src/profile.ts of…
@cveNotify · Sep 28, 2026
CVE-2026-101131 A vulnerability was identified in deepseek-ai deepseek-harness up to 0.1.5-rc.3. Impacted is an unknown function of the file packages/e2b/e2b/src/index.ts of the component dsh. The man…
@cveNotify · Sep 28, 2026
CVE-2026-101111 Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Library (Free) < 6.4.6 - The public book-detail page template, site/views/view_book/tmpl/default.php, echoes th…
@cveNotify · Sep 28, 2026
CVE-2026-101110 Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 - site/booklibrary.php’s books() function reads the field and direction request parameter…
@cveNotify · Sep 28, 2026
CVE-2026-101109 Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle Manager (Free) < 6.5.8 - The public vehicle-detail page (task=view) echoes the title request parameter direc…
@cveNotify · Sep 28, 2026
CVE-2026-101108 Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 - site/vehiclemanager.php reads the order_field and order_direction sort parameters at…
@cveNotify · Sep 28, 2026
CVE-2026-101105 A vulnerability was determined in code-projects Matrimonial System 1.0. The affected element is the function processprofile_form of the file /create_profile of the component Profile Cr…
@cveNotify · Sep 28, 2026
CVE-2026-100753 Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (Free) < 6.7.9 - The public property-detail page’s “leave a review” form repopulates its title f…
@cveNotify · Sep 28, 2026
CVE-2026-100752 Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of three separate frontend…
@cveNotify · Sep 28, 2026
CVE-2026-55160 Stringer is a self-hosted, anti-social RSS reader. Prior to commit 75cb095, an unrestricted Server-Side Request Forgery (SSRF) vulnerability allows any authenticated user to force the S…
@cveNotify · Sep 28, 2026
Apple patched a new CoreGraphics flaw that may have been exploited in targeted iOS attacks. CVE-2026-86950 can trigger arbitrary code execution when a maliciously crafted file is processed. Fixes are…
@thehackernews · Sep 28, 2026
CVE-2026-94084 Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform. 🎖
@cveNotify · Sep 28, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds: new IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches: what was exposed, which organizations were affected, and how the incident came to light.
Patch
Vendor patches, security updates and fix releases for previously disclosed vulnerabilities.