CVEs
Current vulnerabilities that matter: who is affected and what to do now.
- CWE-20A03:2021Citrix NetScaler ADC and Gateway (CVE-2026-88771)CVE-2026-88771 explained: how attackers turned a NetScaler log line into a root shell without logging in, and why patching alone does not clear you.
- CWE-22A01:2021GitLab CE/EE (CVE-2026-85706)CVE-2026-85706 explained: a path traversal in the GitLab commits API that leaked server files without a login, probed the day after the patch.
- CWE-305A07:2021PaperCut NG/MF (CVE-2026-81578)CVE-2026-81578 explained: how an authentication bypass in PaperCut NG/MF, chained with a second flaw, let attackers take over print servers worldwide.
- CWE-89A03:2021WordPress core (CVE-2026-60137)CVE-2026-60137 explained: a medium-rated SQL injection in WordPress core that, chained with CVE-2026-63030 as wp2shell, hands attackers an admin account.
- CWE-502A08:2021PTC Windchill and FlexPLM (CVE-2026-12569)CVE-2026-12569 explained: how a deserialization flaw in PTC Windchill and FlexPLM was used, most likely by Cl0p, to steal engineering data.
- CWE-94A03:2021Ivanti Endpoint Manager Mobile (CVE-2026-1281)CVE-2026-1281 explained: how a code injection in Ivanti EPMM let attackers take over mobile device management servers, and why patching was not enough.
- CWE-77A03:2021PAN-OS GlobalProtect (CVE-2024-3400)CVE-2024-3400 explained: how a command injection in the GlobalProtect gateway or portal of PAN-OS handed attackers root on the firewall itself.
- CWE-89A03:2021MOVEit Transfer (CVE-2023-34362)CVE-2023-34362 explained: how a SQL injection in MOVEit Transfer gave the Cl0p extortion group access to the data of thousands of organisations.
- CWE-420A05:2021Cisco IOS XE Web UI (CVE-2023-20198)CVE-2023-20198 explained: how an internet-exposed management interface in Cisco IOS XE let attackers create a full administrator account.
- CWE-119A07:2021Citrix Bleed (CVE-2023-4966)Citrix Bleed explained: how attackers read session tokens out of NetScaler memory, bypassed MFA with them, and why patching alone was not enough.
- CWE-917A03:2021Log4Shell (CVE-2021-44228)Log4Shell explained: how one line of text in a log file ran code on your server, who exploited it, and what you should still be checking today.
- CWE-22A01:2021FortiOS SSL VPN (CVE-2018-13379)CVE-2018-13379 explained: how a path traversal in FortiOS SSL VPN exposed plaintext passwords, and why it was still being exploited years later.