Skip to content
HiveSecurity
  • Home
  • Blog
  • Tags
  • Vulnerabilities
    • Tools
    • Cheat Sheet
    • Security Guides
  • Contact
  • About
Esc
Type to search...
  • Home
  • Blog
  • Tags
  • Vulnerabilities
  • Resources
  • Tools
  • Cheat Sheet
  • Security Guides
  • Contact
  • About
← All tags Tag

Vulnerability

19 articles

LiteLLM CVE-2026-59822: Your AI Gateway Is a Cloud Control Plane

An exploited LiteLLM MCP authentication bypass, unsafe defaults, code-executing guardrails, and unrestricted pass-through routes show why AI gateways must be isolated and operated as Tier-1 infrastructure.

15 September 2026
AI Security Cloud Security MCP

GitLab CVE-2026-85706: Patch the File Read, Then Rotate What It Exposed

CISA lists GitLab CVE-2026-85706 as exploited. Self-managed administrators must upgrade to 19.3.2, 19.2.6, or 19.1.8 or later, hunt the repository commits API, and treat readable secrets as potentially compromised.

14 September 2026
Vulnerability GitLab DevSecOps

Nightmare Eclipse in September 2026: Five New PoCs Test Windows' Trust Boundaries

Nightmare Eclipse's latest Windows PoCs target Defender, CrowdStrike, Kaspersky, Avast, and NVIDIA. What is confirmed, what is not, and how to respond.

13 September 2026
Windows Vulnerability Endpoint Security

PostGREShell CVE-2026-6471: When Replication Privilege Becomes Server Code Execution

CVE-2026-6471 lets a PostgreSQL role with REPLICATION privilege load an arbitrary logical-decoding plugin. The official severity is high, the prerequisites matter, and supported releases are fixed.

12 September 2026
Vulnerability Database Security Linux Security

Chrome CVE-2026-85046: Updating Is Easy. Proving Every Browser Updated Is Not

Google says an exploit for CVE-2026-85046 exists in the wild. Defenders need to deploy Chrome 152.0.7977.82 or .83 and verify the running version across managed and unmanaged endpoints.

9 September 2026
Vulnerability Browser Security Zero-Day

SonicWall SMA1000 Zero-Day Chain: Patch It, Then Assume It Was Breached

CVE-2026-83548 and CVE-2026-83549 are being exploited against SonicWall SMA1000 appliances. Patching closes the flaws, but exposed gateways still need compromise assessment and credential recovery.

8 September 2026
Vulnerability Network Security Zero-Day

PaperCut CVE-2026-81578 and 82078: The Print Server Became an RCE Pivot

PaperCut NG/MF has an actively exploited authentication-bypass and unsafe class-loading chain. Patch Release 2 matters, but exposed servers also need immediate compromise triage.

1 September 2026
Vulnerability Threat Intelligence Blue Team

CVE-2026-48558: A Perfect 10 in SimpleHelp Opens the Door for Djinn Stealer

An unsigned OIDC token is all it takes to become a fully authenticated technician on a SimpleHelp RMM server. Attackers are already using that shortcut to push a cross-platform infostealer built for the AI era.

19 July 2026
Vulnerability Threat Intelligence RMM

CVE-2026-58644: The SharePoint Patch That Arrived With an Incident-Response Deadline

CISA says attackers are exploiting a critical SharePoint deserialization flaw. Patching closes the bug, but exposed servers also need a focused compromise assessment.

17 July 2026
Cybersecurity Microsoft SharePoint Vulnerability

Forgotten Shims: How 11 Old Microsoft-Signed Files Break Secure Boot

ESET Research found 11 old UEFI shim bootloaders, all validly signed by Microsoft, that bypass Secure Boot on any system trusting Microsoft's third-party CA. CVE-2026-8863 and CVE-2026-10797 — no exploit chain required.

15 July 2026
Firmware Security Vulnerability CVE

IPV6_FRAG_ESCAPE: The Linux Container Escape Your CVE Scanner May Miss

IPV6_FRAG_ESCAPE is a Linux kernel 6.12 privilege escalation with public PoC code, no CVE at disclosure time, and a practical path from container user to host root.

3 July 2026
Linux Vulnerability Kernel

pedit COW & DirtyClone: Two New Linux Root Exploits That Bypass On-Disk Integrity Checks

CVE-2026-46331 and CVE-2026-43503 both corrupt the Linux page cache via network subsystems to grant root — bypassing file integrity tools like AIDE and Tripwire without touching files on disk.

27 June 2026
Linux Vulnerability Privilege Escalation

ShinyHunters Were Inside Two Weeks Before Oracle Noticed

A critical, unauthenticated RCE in Oracle PeopleSoft let ShinyHunters compromise universities and other organizations for weeks before Oracle's advisory caught up. Google notified 100+ potentially exposed organizations. The technical breakdown, IOCs, and what to hunt for.

17 June 2026
Threat Intelligence Vulnerability Zero-Day

GreatXML: When a Setup File Unlocks BitLocker

GreatXML is a public BitLocker-bypass PoC claim involving WinRE, Defender Offline Scan state, and unattend.xml. The defensive lesson is bigger than one repository: recovery environments are security boundaries.

11 June 2026
Windows Vulnerability BitLocker

RoguePlanet: Nightmare Eclipse's New Windows Defender LPE PoC After the June 2026 Patch

RoguePlanet is the latest public Nightmare Eclipse proof-of-concept targeting Microsoft Defender. The code points to a race condition that turns Defender cleanup behavior into SYSTEM execution.

10 June 2026
Windows Vulnerability Zero-Day

SSH-keysign-pwn: The Nine-Year Linux Kernel Flaw

CVE-2026-46333 (ssh-keysign-pwn) is a nine-year-old Linux kernel race condition that lets an unprivileged local user steal SSH host keys and dump /etc/shadow. Root command execution is also possible on specific configurations.

21 May 2026
Linux Vulnerability Kernel

YellowKey: The BitLocker Bypass Hidden in Windows Recovery

A researcher discovered a zero-day that bypasses BitLocker encryption on Windows 11 using a USB stick and the recovery environment — and suspects the component may be intentional. CVE-2026-45585, CVSS 6.8. Microsoft released an official mitigation on May 21, 2026.

Updated 21 May 2026
Windows Vulnerability Encryption

CVE-2026-42897: Exchange Server Zero-Day Executes JavaScript Through Your Inbox

Microsoft's on-prem Exchange Server has an actively exploited XSS zero-day (CVSS 8.1). A single crafted email in OWA triggers arbitrary JavaScript — here's how it works and how to stop it.

16 May 2026
Cybersecurity Web Security Blue Team

Dirty Frag & Copy Fail: Two New Linux Kernel Vulnerabilities Grant Root Privileges

Two new Linux kernel vulnerabilities — Dirty Frag (CVE-2026-43284/43500) and Copy Fail (CVE-2026-31431) — enable local privilege escalation to root on nearly all major distros. What users and admins need to know.

9 May 2026
Linux Vulnerability Privilege Escalation
HiveSecurity

Offensive thinking. Defensive expertise.

Content
  • Home
  • Blog
  • Tags
  • Vulnerabilities
Resources
  • Tools
  • Cheat Sheet
  • Security Guides
Company
  • Contact
  • About
  • RSS
  • Privacy
  • Security Policy

© 2026 Hive Security. All rights reserved.

Built with zero trust & least privilege