Vulnerability Management — Cybersecurity News

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph is an open-source network investigation and threat hunting tool that transforms packet cap...

Open-Source Network Discovery & Topology Mapping

Open-Source Network Discovery & Topology Mapping

RedSide Security has open-sourced NETMAPPER, a network discovery and visualization tool designed to ...

 RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

When an incident unfolds and all you have left are Windows event logs, understanding attacker moveme...

Latest Posts

Adobe ColdFusion Critical Vulnerabilities Enable Unauthenticated Remote Code Execution

Adobe ColdFusion Critical Vulnerabilities Enable Unauthenticated Remote Code Execution

RedSide Security August 12, 2026 CVE 46 views

Adobe has released urgent security updates for ColdFusion 2025 and 2023, fixing multiple critical vulnerabilities including a CVSS 10.0 unauthenticated OS command injection flaw that could enable remote code execution and full server compromise. Organizations should patch exposed ColdFusion deployments immediately.

Continue reading: Adobe ColdFusion Critical Vulnerabilities Enable U…
15-Year-Old NGINX Vulnerability (CVE-2026-42533) Enables Pre-Auth Remote Code Execution

15-Year-Old NGINX Vulnerability (CVE-2026-42533) Enables Pre-Auth Remote Code Execution

RedSide Security July 20, 2026 CVE 88 views

A newly disclosed NGINX vulnerability, CVE-2026-42533, has reportedly been exploitable since 2011 and allows unauthenticated attackers to achieve remote code execution through a flaw in the NGINX script engine. The bug affects both NGINX Open Source and NGINX Plus and has now been patched in versions 1.30.4 and 1.31.3.

Continue reading: 15-Year-Old NGINX Vulnerability (CVE-2026-42533) E…
Critical "wp2shell" WordPress Core RCE Vulnerability Puts 500M+ Sites at Risk

Critical "wp2shell" WordPress Core RCE Vulnerability Puts 500M+ Sites at Risk

RedSide Security July 18, 2026 Vulnerability 65 views

A critical WordPress Core vulnerability dubbed wp2shell allows unauthenticated attackers to achieve remote code execution on affected websites without requiring plugins or user credentials. WordPress has released emergency patches and is force-pushing updates to vulnerable installations worldwide.

Continue reading: Critical "wp2shell" WordPress Core RCE Vulnerabili…
Citrix Secure Access Client Flaws Allow SYSTEM Privilege Escalation on Windows Endpoints

Citrix Secure Access Client Flaws Allow SYSTEM Privilege Escalation on Windows Endpoints

RedSide Security July 18, 2026 Vulnerability 55 views

Cloud Software Group has patched two vulnerabilities affecting Citrix Secure Access Client and Endpoint Analysis Client for Windows, including CVE-2026-53565, a high-severity privilege escalation flaw that allows low-privileged users to gain full SYSTEM access. Organizations are urged to upgrade immediately.

Continue reading: Citrix Secure Access Client Flaws Allow SYSTEM Pri…
Introducing CVEAlertor: Now With Public PoC & Exploit Monitoring

Introducing CVEAlertor: Now With Public PoC & Exploit Monitoring

RedSide Security July 02, 2026 Tools & Technology 92 views

CVEAlertor now monitors GitHub for newly released proof-of-concept exploits tied to tracked vulnerabilities. Security teams receive instant Telegram alerts when new CVEs are published and when public exploit code becomes available, helping prioritize patching before attackers strike.

Continue reading: Introducing CVEAlertor: Now With Public PoC & Expl…
curl Patches 18 Vulnerabilities, Including a 25-Year-Old Security Flaw

curl Patches 18 Vulnerabilities, Including a 25-Year-Old Security Flaw

RedSide Security June 29, 2026 Vulnerability 103 views

curl has released a security update fixing 18 vulnerabilities, including a 25-year-old flaw dating back to 2001. The vulnerabilities affect curl and libcurl components used by billions of devices worldwide, highlighting the ongoing importance of security auditing even in mature open-source projects.

Continue reading: curl Patches 18 Vulnerabilities, Including a 25-Ye…
DirtyClone Linux Kernel Vulnerability Enables Root Privilege Escalation

DirtyClone Linux Kernel Vulnerability Enables Root Privilege Escalation

RedSide Security June 29, 2026 Vulnerability 92 views

DirtyClone (CVE-2026-43503) is a newly disclosed Linux kernel privilege escalation vulnerability that allows local attackers to gain root access by abusing packet cloning and page-cache corruption. Researchers have released a working exploit, making immediate patching essential for affected Linux systems.

Continue reading: DirtyClone Linux Kernel Vulnerability Enables Root…