Skip to content
HiveSecurity
  • Home
  • Blog
  • Tags
  • Vulnerabilities
    • Tools
    • Cheat Sheet
    • Security Guides
  • Contact
  • About
Esc
Type to search...
  • Home
  • Blog
  • Tags
  • Vulnerabilities
  • Resources
  • Tools
  • Cheat Sheet
  • Security Guides
  • Contact
  • About
← All tags Tag

Vulnerability Management

25 articles

Week 37 Security Priorities: Revoke Trust Before You Chase Malware

Berlin's published data, exploited SonicWall gateways, a Chrome zero-day, AI-accelerated intrusion, payment-system abuse, and PostGREShell all point to the same task: identify and revoke inherited trust.

13 September 2026
Weekly Roundup Threat Intelligence Vulnerability Management

JFrog Artifactory CVEs: Your Artifact Repository Is a Build Boundary

CISA KEV activity and a fresh critical Artifactory authentication bypass show why package repositories need incident-grade monitoring, not just routine patching.

4 September 2026
Supply Chain DevSecOps Vulnerability Management

ownCloud CVE-2023-49105: The File Server Bug That Waited Three Years

CISA added an old ownCloud WebDAV authentication bypass to KEV after reported exploitation against Philippine research and defense-linked targets. The lesson is not novelty. It is exposed file infrastructure.

3 September 2026
Vulnerability Management Threat Intelligence Blue Team

Zimbra CVE-2026-73570: Patch the Mail Server, Then Prove It Wasn't Already Owned

Attackers are exploiting a Zimbra SNMP command injection flaw after a fixed version was already available. The real work is not only patching, but compromise triage.

25 August 2026
Email Security Vulnerability Management Incident Response

KerberLoss and ResetNightmare: Kerberos Can Fail Without Stealing a Ticket

Two Active Directory logic flaws presented at Black Hat show how SPN handling and password reset behavior can enable downgrade, disruption, and domain takeover.

23 August 2026
Active Directory Kerberos Identity Security

The File That Blinds the Scanner: ClamAV's Parser Bugs Are a Security-Control Problem

Seven ClamAV parser vulnerabilities can crash scanning processes, and Cisco products inherit the exposure. Defenders need to verify scanner health, not only malware verdicts.

22 August 2026
Vulnerability Management Endpoint Security Detection Engineering

CVE-2026-20349: Attackers Are Crashing the VPN Before Users Can Log In

Cisco says attackers are exploiting a remote denial-of-service flaw in ASA and FTD VPN services. Here is how to prioritize, detect, and contain it.

21 August 2026
Cisco Security VPN Security Vulnerability Management

CVE-2026-65400: When macOS Screen Sharing Becomes Remote Root

Attackers are exploiting a macOS Screen Sharing authentication flaw against exposed Macs. Patch, remove VNC exposure, and investigate before treating it as a routine update.

20 August 2026
macOS Security Vulnerability Management Incident Response

Why Managed File Transfer Tools Keep Becoming Mass-Breach Machines

MOVEit, GoAnywhere, Cleo, Accellion — the same extortion playbook keeps working on enterprise file-transfer software. Here's the structural reason why, and what to do about it.

19 August 2026
Blue Team Data Breach Supply Chain

vCenter CVE-2026-59309 and 59310: Patch the Control Plane

Two critical vCenter flaws threaten authentication and code execution. Use this practical plan to patch, isolate, detect, and recover safely.

14 August 2026
VMware Virtualization Security Vulnerability Management

Tomcat CVE-2026-34486: The Broken Encryption Fix

An incomplete Tomcat fix allowed EncryptInterceptor bypass and is now exploited. Learn which exact versions are exposed and how to contain clusters.

13 August 2026
Apache Tomcat Vulnerability Management Java Security

Langflow CVE-2026-9198: Auto-Login Was a Server Shell

Default Langflow deployments exposed a two-step path from no account to remote code execution. Learn how to patch, isolate, hunt, and rotate secrets.

11 August 2026
AI Security Vulnerability Management Application Security

LoadMaster CVE-2026-8037: The Load Balancer Became the Way In

An unauthenticated command-injection flaw turned a perimeter appliance into an entry point. Here is how to patch, contain, hunt, and recover.

10 August 2026
Vulnerability Management Network Security Incident Response

Week 32 Security Roundup: The Management Plane Is the Target

TeamCity, N-central, and Cisco FMC put the same lesson in three different packages: attackers want the systems that already control everything else.

8 August 2026
Weekly Roundup Threat Intelligence Vulnerability Management

NGINX's Configuration-Dependent Vulnerabilities: Why Version Scanning Is Not Enough

NGINX 1.30.4 and 1.31.3 fixed three new memory-safety flaws, but exposure depends on map, slice, SSI, proxy, and buffering configuration. Here is how to audit the real path.

6 August 2026
Web Security Vulnerability Management Linux Security

Your UniFi Console Is a Server: What Security Bulletin 066 Actually Requires

Ubiquiti disclosed 25 vulnerabilities across UniFi applications and devices. The critical issue is not the headline CVSS score, but which management services an attacker can reach.

5 August 2026
Network Security IoT Security Vulnerability Management

CVE-2026-48282: A Perfect 10 in Adobe ColdFusion, Exploited Within Two Hours

A CVSS 10.0 path traversal in Adobe ColdFusion's Remote Development Services lets unauthenticated attackers write a webshell straight into the web root. Attackers were probing it before most admins finished reading the advisory.

31 July 2026
Vulnerability Management CVE Web Application Security

Exploited Before the PoC Existed: CVE-2026-46817 in Oracle Payments

A critical, unauthenticated flaw in Oracle E-Business Suite's Payments module was hit in the wild on June 27, 2026 — six weeks after the patch, with no public exploit code anywhere. Here's what's confirmed, what's still speculation, and how to check if you're exposed.

21 July 2026
ERP Security Vulnerability Management Blue Team

N-days Are Becoming N-hours

Anthropic's June 2026 N-day research shows how frontier models can turn public patches into working exploits in hours. Here's what defenders should change now.

9 June 2026
AI Security Vulnerability Management Blue Team

Verizon DBIR 2026: The Remediation Paradox

Verizon's 2026 DBIR confirms vulnerability exploitation as the #1 breach vector for the first time in 19 years — while remediation rates dropped and patch times increased. Here's what the data actually says.

22 May 2026
Blue Team Vulnerability Management Threat Intelligence

500 Microsoft CVEs Later — We're Still Measuring Security Wrong

Microsoft patched 500+ vulnerabilities in five months. Linux ecosystems patched even more. So which is more secure? That's the wrong question — here's the metric that actually matters.

13 May 2026
Vulnerability Management Blue Team Threat Intelligence

Non-Human Identities: The Attack Surface Your Security Team Isn't Managing

Service accounts, API keys, OAuth tokens and machine credentials now outnumber human identities 144 to 1. Most organizations have zero visibility into them. Attackers do.

7 May 2026
Cybersecurity Identity Security Blue Team

Why Enterprise VPN and Gateway Products Are Perpetually Broken

Ivanti, Fortinet, Palo Alto — the names change but the pattern doesn't. Here's the structural reason why enterprise edge devices are permanently on fire and what you can do about it.

7 May 2026
Cybersecurity Red Team Blue Team

From CVE to RCE in Hours: The Collapse of the Exploitation Window

The average time from vulnerability disclosure to active exploitation has collapsed from 756 days in 2018 to mere hours in 2025. Here's what that means for defenders.

14 April 2026
Vulnerability Management Blue Team Threat Intelligence

Vulnerability Exploitation Overtook Phishing — What That Means for Defenders

For the first time, vulnerability exploitation is the #1 initial access vector — not phishing. Here's what the data says and how defenders must adapt.

14 April 2026
Blue Team Vulnerability Management Detection
HiveSecurity

Offensive thinking. Defensive expertise.

Content
  • Home
  • Blog
  • Tags
  • Vulnerabilities
Resources
  • Tools
  • Cheat Sheet
  • Security Guides
Company
  • Contact
  • About
  • RSS
  • Privacy
  • Security Policy

© 2026 Hive Security. All rights reserved.

Built with zero trust & least privilege