Google Patches Fifth Chrome Zero-Day in 2026
Google’s Chrome 149 update patches 74 vulnerabilities, including the fifth zero‑day exploited in 2026 (CVE‑2026‑11645). The researcher earned $55,000 for the disclosure.
Google’s Chrome 149 update patches 74 vulnerabilities, including the fifth zero‑day exploited in 2026 (CVE‑2026‑11645). The researcher earned $55,000 for the disclosure.
CVE-2026-42897, an unpatched XSS flaw in Outlook Web Access, is actively exploited. Microsoft confirms attacks, but no fix is available as of May 19, 2026. Organizations face urgent risks.
A maximum severity Cisco SD-WAN vulnerability with a CVSS score of 10.0 is actively exploited in the wild. This is the second such exploit this year. Details on impact, access methods, and response timelines are now public.
A zero-day in Palo Alto firewalls is actively exploited in a campaign with clear signs of Chinese state involvement. Full technical and strategic breakdown.
CISA mandates federal agencies patch a critical Ivanti EPMM zero-day by May 12, 2026. Attackers already exploited it. Here’s what you need to know.
Progress Software patched a critical authentication bypass in MOVEit Automation on May 04, 2026. Attackers could exploit it without credentials. Details here.
CVE-2026-41940, a critical authentication bypass in cPanel and WHM, has been exploited in the wild since late February. PoC now public. Fixes rolling. Stay alert.
Firestarter malware persists on Cisco firewalls despite updates, say U.S. and U.K. agencies. Devices running ASA or FTD remain at risk. Full analysis.
A ‘Firestarter’ backdoor exploited a Cisco firewall at a US federal agency, maintaining access even after patching. Full technical breakdown and implications. April 27, 2026.