CVE News
Latest CVE news and analysis — 30 articles tagged CVE on The Robotics Media.
- Cisco Ships Emergency Patch For CVSS-10 ISE Zero-Day Under Attack — — Cisco is warning customers to install emergency patches for CVE-2026-76460, a CVSS 10.0 authentication bypass in ISE that is already being exploited t...
- Unitree G1 EDU Root RCE Chain Reaches Robots Over Bluetooth — — Researcher Olivier Laflamme disclosed two independent root-RCE paths in Unitree's G1 EDU humanoid, including a Bluetooth Low Energy chain that reaches...
- AISLE Finds Six New cURL CVEs After Anthropic Mythos And OpenAI Codex Returned Zero — — AISLE's autonomous AI system produced 29 vulnerability reports against cURL — six accepted as CVEs in curl 8.22.0 — days after Anthropic Mythos and Op...
- Cisco Warns Of Critical 9.8 CVE-2026-20212 In Nexus 9000 With Silicon One ASICs — — Cisco has disclosed CVE-2026-20212, a critical 9.8-severity unauthenticated RCE in Nexus 9000 switches using its Silicon One ASICs — exposed on the de...
- ServiceNow Patches Three CVSS 10 Flaws In AI Platform Powering 85% Of Fortune 500 — — ServiceNow patched three maximum-severity vulnerabilities in its AI Platform that let unauthenticated attackers inject code, escalate privileges and r...
- CISA Warns Citrix NetScaler CVE-2026-8452 Is Under Active Attack — — CISA has added a previously patched Citrix NetScaler ADC and Gateway flaw, CVE-2026-8452, to its Known Exploited Vulnerabilities catalog after attacke...
- Amazon Kiro Flaw Turns Poisoned Repos Into Silent Data Exfiltration — — Mindgard says a prompt-injection flaw in Amazon Kiro let attacker-controlled repos coerce the agentic IDE into leaking local secrets - fixed in 0.8.14...
- Critical GitLab GraphQL Flaw CVE-2026-19478 Under Active Exploit Within Days Of Disclosure — — A newly patched code-injection flaw in GitLab's GraphQL API tracked as CVE-2026-19478 (CVSS 9.4) came under active exploitation within days of public...
- Cisco Patches 9 Crosswork And Secure Workload Bugs, Five CVSS 10.0 — — Cisco has released hardening updates for its Crosswork and Secure Workload platforms that fix nine vulnerabilities, including five with a maximum CVSS...
- Shell Investigates Cl0p Data Theft Claim Of 89 GB Corporate Files — — Shell has activated cyber incident-response procedures after the Cl0p ransomware crew added the oil major to its leak site, alleging it exfiltrated ro...
- Microsoft Patches Max-Severity Entra ID Flaw CVE-2026-69836 — — Microsoft on Aug 21, 2026 disclosed CVE-2026-69836, a CVSS-10.0 deserialisation flaw in Entra ID that allowed unauthenticated remote code execution; t...
- Microsoft patches 421 CVEs in August 2026 Patch Tuesday, including exploited afd.sys zero-day — — Microsoft's August 2026 Patch Tuesday resolves 421 CVEs, including CVE-2026-68820, an actively exploited use-after-free in afd.sys that grants SYSTEM...
- Microsoft Patches CoSnitch, a One-Click Data Theft Flaw in Copilot — — Varonis Threat Labs disclosed CoSnitch, a chain of three Copilot Personal flaws that turn a single crafted link into silent data exfiltration and pers...
- Universal Robots Patches Critical PolyScope Flaw CVE-2026-8153 — — Universal Robots patched CVE-2026-8153 (CVSS 9.8) in PolyScope 5.25.1 after Claroty's Team82 found an unauthenticated RCE flaw in the Dashboard Server...
- CISA Adds Ray CVE-2025-62593 to KEV as Browser Attack Chain Hits Devs — — CISA gave federal agencies until August 20 to patch a critical Ray flaw after Oligo confirmed DNS-rebinding attacks are pushing browser-based RCE onto...
- CISA Adds Langflow, Tomcat and N-central Flaws to KEV — — CISA on August 5 added three actively exploited vulnerabilities to its KEV catalog, including a critical Langflow RCE and an Apache Tomcat encryption...
- N-able Ships Emergency Patch After Attackers Bypass N-central Auth Bypass Fix — — CVE-2026-18577 lets attackers bypass an earlier N-central patch to seize admin access on MSP RMM servers, with Huntress observing live exploitation an...
- Arista VeloCloud Orchestrator Zero-Day CVE-2026-16812 Under Active Attack — — A maximum-severity command-injection flaw in on-prem Arista VeloCloud Orchestrator is being exploited to fully compromise SD-WAN infrastructure, with...
- Rails Ships Emergency Patch For Active Storage RCE Flaw CVE-2026-66066 — — Ruby on Rails ships coordinated 7.2, 8.0 and 8.1 releases fixing a critical Active Storage flaw that lets unauthenticated attackers read arbitrary fil...
- Broadcom Patches Three Critical VMware Flaws, Including vCenter Auth Bypass And ESXi VM Escape — — Broadcom's VMSA-2026-0006 advisory patches five flaws across vCenter, ESXi, Workstation and Fusion. Three are rated critical, including a CVSS 9.8 vCe...