A vulnerability impacting Langflow is being exploited in the wild. Tracked as CVE-2026-0768, the vulnerability has a critical severity rating with a CVSS score of 9.8. Successful exploitation of the vulnerability may allow a remote attacker to execute arbitrary code on affected installations of Langflow. Peter Girnus, William Gamazo Sanchez, and Alfredo Oliveira of Trend Research have discovered and reported the vulnerability to Langflow.
Tag: Exploited in the Wild
Mozilla Firefox Zero-day Vulnerabilities Exploited in Attacks (CVE-2026-15718 & CVE-2026-15719)
Mozilla released a security update to address two vulnerabilities impacting the Firefox browser, tracked as CVE-2026-15718 & CVE-2026-15719. Mozilla mentioned in the advisory that they are aware that exploit code for this is public; however, they are unaware of any attacks in the wild abusing this flaw. CVE-2026-15718 This is an invalid pointer vulnerability exists … Continue reading “Mozilla Firefox Zero-day Vulnerabilities Exploited in Attacks (CVE-2026-15718 & CVE-2026-15719)”
Google Zero-day Vulnerability Exploited in the Wild (CVE-2026-11645)
Google released security updates to address a large number of vulnerabilities impacting the Chrome browser. Tracked as CVE-2026-11645, this is an out-of-bounds memory access vulnerability in the V8 JavaScript engine. CISA acknowledged the active exploitation of the vulnerability by adding it to its Known Exploited Vulnerabilities Catalog. CISA urges users to patch the vulnerability before June 23, 2026.
Adobe Acrobat and Reader Arbitrary Code Execution Vulnerability Exploited in the Wild (CVE-2026-34621)
Adobe released a security update to address an actively exploited vulnerability impacting Adobe Acrobat and Reader. Tracked as CVE-2026-34621, the vulnerability may allow an attacker to run malicious code on affected installations. Haifei Li from EXPMON discovered and reported the vulnerability to Adobe. CISA acknowledged the active exploitation of the vulnerability by adding it to its Known Exploited Vulnerabilities Catalog. CISA urges users to patch the vulnerability before April 27, … Continue reading “Adobe Acrobat and Reader Arbitrary Code Execution Vulnerability Exploited in the Wild (CVE-2026-34621)”
Fortinet FortiClientEMS Vulnerability Exploited in the Wild (CVE-2026-35616)
Fortinet released a security advisory to address an actively exploited vulnerability impacting FortiClientEMS. Tracked as CVE-2026-35616, the vulnerability has a critical severity rating with a CVSS score of 9.1. Successful exploitation may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
Google Patches Two Chrome Vulnerabilities Exploited in the Wild (CVE-2026-3909 & CVE-2026-3910)
Google released fixes to address two zero-day vulnerabilities impacting its Chrome browser. Tracked as CVE-2026-3909 & CVE-2026-3910, both vulnerabilities have been assigned a high severity rating with a CVSS score of 8.8. Both vulnerabilities were discovered and reported by Google itself on March 10, 2026. CISA also acknowledged the active exploitation of the vulnerabilities and added them to its Known Exploited Vulnerabilities Catalog. CISA urged users to patch the vulnerabilities before March … Continue reading “Google Patches Two Chrome Vulnerabilities Exploited in the Wild (CVE-2026-3909 & CVE-2026-3910)”
Google Patches its First Zero-day Vulnerability of the Year (CVE-2026-2441)
Google released a security advisory to address a high-severity zero-day vulnerability in Chrome. Tracked as CVE-2026-2441, the vulnerability is being exploited in the wild. The vulnerability is a use-after-free flaw in the CSS browser’s CSS handling. An independent researcher, Shaheen Fazim, discovered and reported the vulnerability to Google on February 11, 2026.
Apple iOS Zero-day Vulnerability Exploited in Attacks (CVE-2026-20700)
Apple released a security advisory to address its first zero-day vulnerability of the year. Tracked as CVE-2026-20700, successful exploitation of the vulnerability could lead to arbitrary code execution. Google Threat Analysis Group discovered and reported the vulnerability to Apple. The vulnerability exists in dyld, the Dynamic Link Editor used by Apple operating systems, including iOS, iPadOS, macOS, tvOS, watchOS, and visionOS. An attacker with memory write permission may exploit … Continue reading “Apple iOS Zero-day Vulnerability Exploited in Attacks (CVE-2026-20700)”
Fortinet FortiWeb Zero-day Vulnerability Exploited in the Wild (CVE-2025-64446)
Threat actors are exploiting a zero-day vulnerability, CVE-2025-64446, that has been discovered in Fortinet’s FortiWeb web application firewall product. Successful exploitation of this new vulnerability allows an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests. FortiGuard mentioned in the advisory that they are aware of the active exploitation … Continue reading “Fortinet FortiWeb Zero-day Vulnerability Exploited in the Wild (CVE-2025-64446)”
Malicious MCP Server on npm postmark-mcp Exploited in Attack
Security researchers discovered a significant vulnerability in the Model Context Protocol (MCP) server that was exploited in the wild. The reports described this as the first-ever instance of an MCP server being exploited in the wild, which can lead to software supply chain risks. The flaw exists in the npm package postmark-mcp, an MCP server … Continue reading “Malicious MCP Server on npm postmark-mcp Exploited in Attack”