Microsoft Exchange Server Remote Code Execution Vulnerability
View impact & remediation →Today's high-risk
vulnerability watch.
CVSS 8.0+ vulnerabilities prioritized with CISA KEV and Red Hat context, plus practical remediation guidance for infrastructure and platform teams.
Critical & high vulnerabilities
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
View impact & remediation →VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
View impact & remediation →Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
View impact & remediation →IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
View impact & remediation →An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Andro…
View impact & remediation →A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrar…
View impact & remediation →Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-ba…
View impact & remediation →A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
View impact & remediation →MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py …
View impact & remediation →Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
View impact & remediation →A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processin…
View impact & remediation →Microsoft Exchange Server Remote Code Execution Vulnerability
View impact & remediation →Active Directory Domain Services Elevation of Privilege Vulnerability
View impact & remediation →Internet Explorer Remote Code Execution Vulnerability
View impact & remediation →Internet Explorer Memory Corruption Vulnerability
View impact & remediation →Microsoft Exchange Server Remote Code Execution Vulnerability
View impact & remediation →Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thund…
View impact & remediation →From vulnerability finding to verified closure.
GraceITS supports remediation at scale across RHEL 7/8/9/10, Windows, Java, Oracle and application platforms using Qualys, Tanium and Ansible-driven automation.