MITRE ATT&CK Mapping
Articles mapped to MITRE ATT&CK techniques. Select a technique to view matching articles.
T1190 — Exploit Public-Facing Application (Initial Access)
Clear filter287 articles found
Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)
Microsoft has patched a critical remote code execution vulnerability (CVE-2026-69836) in Entra ID, reportedly exploited in the wild. Entra ID is Microsoft’s ...
Poland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw
CERT Polska confirmed active exploitation of CVE-2026-73570, a critical unauthenticated RCE in Zimbra Collaboration Suite patched on July 20. CERT Polska, Po...
Google Chrome 151 Update Fixes 7 Security Flaws Enabling Remote Code Execution and Sandbox Escape
Google has released Chrome version 151 to the Stable channel for desktop platforms, addressing seven security vulnerabilities. Among these vulnerabilities is...
Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution
Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer action i...
Microsoft Entra ID RCE Flaw Lets Unauthorized Attackers Execute Code Remotely
Microsoft has disclosed a critical remote code execution vulnerability in Microsoft Entra ID, identified as CVE-2026-69836. This flaw could enable unauthoriz...
Critical flaw patched in popular JavaScript sandbox used in AI projects
A critical sandbox escape vulnerability was discovered and patched in isolated-vm, a library for running JavaScript code inside an isolated process. If explo...
Critical Elementor Pro bug exposes WordPress sites to RCE attacks
A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server. [.
Critical Arbitrary File Upload Vulnerability Patched in Elementor Pro WordPress Plugin
On July 24th, 2026, we received a submission for an Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with an estimate...
Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency R...
Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities
The flaws could lead to remote code execution, authentication bypasses, and path traversal attacks. The post Cisco Patches Critical Crosswork, Secure Workloa...
Splunk Fixes 17 Vulnerabilities Including Critical MCP Server RCE
Splunk has released a security hardening update addressing 17 vulnerabilities across several applications and add-ons, including a critical remote code execu...
CyberPanel Pre-Auth RCE Flaws Let Attackers Gain Remote Server Access
Researchers have revealed a pre-authentication remote code execution (RCE) vulnerability chain in CyberPanel that could allow an internet-based attacker to e...
Zimbra RCE Vulnerability Lets Remote Attackers Execute System Commands
An urgent alert regarding an actively exploited remote code execution vulnerability affecting the Zimbra Collaboration Suite, a widely used enterprise email ...
Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remo...
Critical vulnerability in Ray framework allows remote code execution
The vulnerability, rated 9.4 under CVSS v4, was disclosed in November 2025 and allows attackers to exploit browsers like Firefox and Safari to achieve remote...
CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities
The flaws can be exploited for remote code execution, authentication bypass, and device takeover. The post CISA Urges Immediate Patching of Exploited Microso...
Critical RCE flaw in Windows IKE Extension now actively exploited
The U.S.
U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog
U.S.
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically desig...