Explore our latest research, insights, and guidance on emerging security threats and best practices
We regularly publish our security findings, guidance, and analysis to help organizations stay ahead of emerging threats.
CVE-2026-87902 saw attempts the afternoon 7.1.2 shipped. Patchstack says probes now write PHP files. Previdian counted 68 honeypot tries. Last week's 7.1.1 is still open.
Mathew Potter
Security Analyst
CVE-2026-48842 is pre-auth SQL injection in virtuser_query. Cyber Centre updated AV26-503. Fixed in 1.6.16 and 1.7.1. If you cannot update, turn the plugin off.
Mathew Potter
Security Analyst
CVE-2026-63077 is unauthenticated commands on TeamCity On-Premises. Patched July 25 in 2025.11.7 and 2026.1.3. Federal clock was August 8. Cloud is fine. Internet-facing and old is not.
Mathew Potter
Security Analyst
third-party.com is not a reserved placeholder. Someone registered it and has been serving a Windows ClickFix since June. 1,700 GitHub hits. Use example.com. Flash the GS1900 today.
Mathew Potter
Security Analyst
CVE-2026-87899 is CalDAV and CardDAV to root. Any hosting account. Shared boxes are the blast. Fixed in 11.134.0.57, 11.136.0.41, 11.138.0.8. WP Toolkit 6.11.3 is a separate package.
Mathew Potter
Security Analyst
CVE-2026-94127 is unauthenticated code execution on APM authorization servers. CISA listed it. Due Friday. Closing the management port does not help. Engineering hotfix or F5's iRule.
Mathew Potter
Security Analyst
Subscribe to our research newsletter to receive the latest security insights directly in your inbox.
We respect your privacy. Unsubscribe at any time.