Alerts

Security advisories, patches, and warnings

PAN-OS Authentication Bypass Under Active Exploitation — Attackers Initiating Unauthorized VPN Sessions via GlobalProtect (CVE-2026-0257)

Alerts

PAN-OS Authentication Bypass Under Active Exploitation — Attackers Initiating Unauthorized VPN Sessions via GlobalProtect (CVE-2026-0257)

Palo Alto Networks Unit 42 has confirmed active exploitation of CVE-2026-0257, an authentication bypass vulnerability in the portal and gateway components of PAN-OS that allows unauthorized attackers to circumvent security controls and initiate VPN connections through GlobalProtect. CISA added the flaw to its Known Exploited Vulnerabilities catalog

By Zero Day Wire
Chaotic Eclipse Releases MiniPlasma — A Five-Year-Old Windows Zero-Day That Still Grants SYSTEM Privileges on Fully Patched Systems

Alerts

Chaotic Eclipse Releases MiniPlasma — A Five-Year-Old Windows Zero-Day That Still Grants SYSTEM Privileges on Fully Patched Systems

Chaotic Eclipse has released a third wave of Windows zero-day disclosures, publishing a proof-of-concept for a privilege escalation vulnerability codenamed MiniPlasma that grants SYSTEM privileges on fully patched Windows systems — including those running the latest May 2026 updates. The flaw resides in cldflt.sys, the Windows Cloud

By Zero Day Wire
Chaotic Eclipse Returns With Two More Windows Zero-Days — BitLocker Bypass YellowKey and CTFMON Privilege Escalation GreenPlasma

Alerts

Chaotic Eclipse Returns With Two More Windows Zero-Days — BitLocker Bypass YellowKey and CTFMON Privilege Escalation GreenPlasma

The anonymous security researcher known as Chaotic Eclipse — responsible for the BlueHammer, RedSun, and UnDefend Microsoft Defender zero-days that ZDW covered last month — has returned with two additional Windows zero-days, escalating an increasingly public confrontation with Microsoft over vulnerability disclosure handling. The first vulnerability, codenamed YellowKey, is a

By Zero Day Wire
Critical MetInfo and Weaver E-cology Flaws Under Active Exploitation — Unauthenticated RCE Targeting Chinese Enterprise Infrastructure

Alerts

Critical MetInfo and Weaver E-cology Flaws Under Active Exploitation — Unauthenticated RCE Targeting Chinese Enterprise Infrastructure

Two critical vulnerabilities in widely deployed Chinese enterprise software are under active exploitation, with threat actors leveraging unauthenticated remote code execution flaws in MetInfo CMS and Weaver E-cology to compromise servers without requiring any credentials. CVE-2026-29014 (CVSS 9.8) affects MetInfo, a PHP and MySQL-based enterprise

By Zero Day Wire
Microsoft Defender Zero-Day Exploited in the Wild — BlueHammer Attack Chain Extracts SAM Hashes and Kills Defender via Race Condition

Alerts

Microsoft Defender Zero-Day Exploited in the Wild — BlueHammer Attack Chain Extracts SAM Hashes and Kills Defender via Race Condition

A privilege escalation vulnerability in Microsoft Defender is under active exploitation using publicly available proof-of-concept code, with Huntress confirming attacks began on April 10 — four days before Microsoft released a patch. CISA added the flaw to its Known Exploited Vulnerabilities catalog on Wednesday, setting a May 6 federal

By Zero Day Wire
CISA Adds Eight Exploited Vulnerabilities to KEV Catalog Including Three Cisco SD-WAN Manager Flaws and Quest KACE CVSS 10.0

Alerts

CISA Adds Eight Exploited Vulnerabilities to KEV Catalog Including Three Cisco SD-WAN Manager Flaws and Quest KACE CVSS 10.0

CISA added eight new vulnerabilities to its Known Exploited Vulnerabilities catalog on Monday, setting aggressive federal patching deadlines after confirming active exploitation across a range of enterprise products. Three of the flaws target Cisco Catalyst SD-WAN Manager, while the remaining five affect Quest KACE, PaperCut, JetBrains TeamCity, Kentico Xperience,

By Zero Day Wire