May 2026

233 security articles published this month.

94
critical
25
high
5
medium
56
low
53
Advisory
57
Breaches
10
News
8
Intel
105
Learn
1
Research
0
Malware
52

Advisory

(57)
high May 10

Joomla Forms Builder SQLi leaks data (CVE-2021-47930)

critical May 10

WordPress TheCartPress creates admin accounts (CVE-2021-47932)

critical May 10

WordPress MStore API unauth RCE (CVE-2021-47933)

critical May 10

OpenCATS unauthenticated RCE (CVE-2021-47936)

critical May 10

PHP SOAP unauthenticated RCE (CVE-2026-6722)

critical May 8

Beauty Parlour SQLi reads database (CVE-2026-37431)

critical May 8

openvpn-auth-oauth2 bypasses SSO auth (CVE-2026-41070)

critical May 8

PraisonAI RCE, no auth needed (CVE-2026-41497)

critical May 8

electerm unauth command injection (CVE-2026-41500)

critical May 8

electerm unauthenticated RCE (CVE-2026-41501)

critical May 8

ai-scanner RCE via JavaScript injection (CVE-2026-41512)

critical May 8

Nhost account takeover via OAuth (CVE-2026-41574)

critical May 8

LiteLLM SQL injection exploited in wild (CVE-2026-42208) [PoC]

critical May 8

Postiz unauthenticated RCE via PR build (CVE-2026-42298)

critical May 8

Termix server RCE via shell injection (CVE-2026-42454)

critical May 8

PraisonAI SSRF via URL bypass (CVE-2026-44335)

critical May 8

PraisonAI path traversal leads to RCE (CVE-2026-44336)

critical May 8

Zcash Zebra consensus split via sig (CVE-2026-44497)

critical May 7

Azure Cassandra RCE, low-privilege (CVE-2026-33109)

critical May 7

Open Notebook RCE via SSTI (CVE-2026-33587)

critical May 7

Microsoft Teams information disclosure (CVE-2026-33823)

critical May 7

Azure Cloud Shell network spoofing (CVE-2026-35428)

critical May 7

Snipe-IT unauth RCE via file upload (CVE-2026-37709)

critical May 7

FreeScout unauth takeover via expired invites (CVE-2026-41902)

critical May 7

Azure DevOps leaks credentials (CVE-2026-42826)

critical May 7

Argo CD secret data leak (CVE-2026-42880)

high May 7

Ivanti EPMM admin RCE exploited (CVE-2026-6973)

critical May 6

PAN-OS unauth RCE exploited in the wild (CVE-2026-0300) [PoC]

high May 6

Cisco Unity Connection arbitrary code execution (CVE-2026-20034)

critical May 6

Wicket session fixation, no patch yet (CVE-2026-40010)

critical May 6

Gotenberg unauth file overwrite (CVE-2026-40281)

critical May 6

Vvveb hard-coded credentials leak DB (CVE-2026-41930)

critical May 6

OpenClaw exposes CDP relay traffic (CVE-2026-43581)

critical May 6

Perl session IDs leak authentication (CVE-2026-5081)

high May 6

Chrome heap corruption via crafted page (CVE-2026-7896)

high May 6

Chrome Linux RCE via Chromoting (CVE-2026-7898)

high May 6

Chrome V8 code execution in sandbox (CVE-2026-7899)

critical May 6

Google Chrome sandbox escape (CVE-2026-7908)

critical May 4

VM2 sandbox breakout, host RCE (CVE-2026-24118)

critical May 4

vm2 sandbox escape RCE (CVE-2026-24120)

critical May 4

vm2 sandbox escape RCE (CVE-2026-24781)

critical May 4

vm2 sandbox escape RCE (CVE-2026-26332)

critical May 4

vm2 sandbox full RCE escape (CVE-2026-26956)

critical May 4

Arelle unauthenticated RCE (CVE-2026-42796)

critical May 4

Polaris leaks broad cloud credentials (CVE-2026-42809)

critical May 4

Apache Polaris leaks S3 cross-table data (CVE-2026-42810)

critical May 4

Polaris bucket-wide credential leak (CVE-2026-42811)

critical May 4

Apache Polaris writes metadata to attacker-chosen path (CVE-2026-42812)

high May 2

ArgoCD diff leaks K8s secret data (CVE-2026-43824)

high May 1

Vanetza V2X denial of service (CVE-2026-37554)

high May 1

Neethi denial of service via XML (CVE-2026-42402)

high May 1

Apache Neethi stack overflow via circular refs (CVE-2026-42403)

critical May 1

MixPHP unauth RCE via deserialization (CVE-2026-42472)

critical May 1

MixPHP unauth RCE via deserialization (CVE-2026-42473)

critical May 1

hashcat heap overflow DoS or RCE (CVE-2026-42483)

critical May 1

Apache MINA IoBuffer RCE, patch bypass (CVE-2026-42778) [PoC]

critical May 1

MINA unauthenticated RCE via bad fix (CVE-2026-42779) [PoC]

Breaches

(10)

News

(8)

Intel

(105)
critical May 13

Alpinion Ransomware Attack by coinbasecartel (May 2026)

critical May 13

Amstel Securities Ransomware Claim by thegentlemen (May 2026)

critical May 13

Bestat Pharmaservices Ransomware Claim by WorldLeaks (May 2026)

critical May 13

Shajarpak Securities Ransomware by thegentlemen (May 2026)

critical May 13

Value Exchange International Hit by thegentlemen (May 2026)

low May 12

Casino Gaming Commission Ransomware Claim by Genesis (May 2026)

critical May 12

DDU Ransomware Attack by Lamashtu (May 2026)

low May 12

ICE Ransomware Attack by BrainCipher (May 2026)

low May 12

Jozef Stefan Institute Ransomware Attack by coinbasecartel (May 2026)

critical May 12

Park Dental Research Ransomware Claim by Interlock (May 2026)

critical May 11

Lifelong Access Ransomware Attack by Lynx (May 2026)

critical May 10

American Board of Preventive Medicine Ransomware Claim by Genesis (May 2026)

critical May 10

CarePoint Health Ransomware Attack by Genesis (May 2026)

critical May 10

DermaPharm Ransomware Attack by thegentlemen (May 2026)

low May 10

HMH Ransomware Claim by ShinyHunters (May 2026)

critical May 10

Lindabury Ransomware Attack by Qilin (May 2026)

critical May 10

Marlborough Partners Ransomware Claim by LeakBazaar (May 2026)

critical May 10

Sibilla Capital Ransomware Attack by INC Ransom (May 2026)

critical May 9

Cazh.id Ransomware Attack by Icarus (May 2026)

low May 9

CMC Expertise Comptable Ransomware by DragonForce (May 2026)

low May 9

Colegio María Inmaculada Ransomware by Bavacai (May 2026)

critical May 9

Fogel Capital Ransomware Claim by Qilin (May 2026)

critical May 9

Greenwoods Dental Ransomware Claim by Akira (May 2026)

critical May 9

Neurotrials Research Ransomware Attack by sinobi (May 2026)

critical May 9

Réseau Radiologique Romand Hit by Akira (May 2026)

low May 8

Académie de Montpellier Ransomware Claim by Bavacai (May 2026)

critical May 8

Aerodiagnostics Ransomware Claim by INC Ransom (May 2026)

critical May 8

Clinical Registry Solutions Ransomware by Akira (May 2026)

critical May 8

Laclinic-Montreux Ransomware Attack by Qilin (May 2026)

low May 8

Le Maire de QUIBERON Ransomware Attack by Qilin (May 2026)

low May 8

Norcal Training Center Hit by Qilin Ransomware (May 2026)

critical May 8

Panal Seguros Ransomware Attack by Qilin (May 2026)

critical May 8

Rehab Clinics Group Ransomware Attack by Everest (May 2026)

critical May 8

SDK Environmental Ransomware Attack by Akira (May 2026)

low May 8

Soprolux Ransomware Attack by Bravox (May 2026)

low May 7

Alge-Stop Ransomware Attack by m3rx (May 2026)

low May 7

Datasavior Ransomware Attack by m3rx (May 2026)

low May 7

Farella Braun + Martel Ransomware Claim by SilentRansomGroup (May 2026)

low May 7

Gingerich Trucking Ransomware Claim by Safepay (May 2026)

low May 7

id-s.de Ransomware Attack by Safepay (May 2026)

low May 7

JMIGE Ransomware Claim by SafePay (May 2026)

high May 7

KB Toys Australia Ransomware Attack by m3rx (May 2026)

high May 7

Pemberton Valley Dyking District Hit by m3rx (May 2026)

low May 7

Sandberg Phoenix Hit by SilentRansomGroup (May 2026)

low May 7

smp.cat Ransomware Attack by Safepay (May 2026)

low May 6

Atencio Engineering Ransomware Claim by Bavacai (May 2026)

low May 6

Bandeirante Supermercados Ransomware by Bavacai (May 2026)

low May 6

CourtSmart Ransomware Attack by Bavacai (May 2026)

low May 6

Desert Christian Schools Ransomware Claim by Bavacai (May 2026)

low May 6

Elken Sdn Bhd Ransomware Attack by Bavacai (May 2026)

low May 6

Magnolia Jewelry Ransomware Attack by Bavacai (May 2026)

low May 6

Ropers Majeski Ransomware Claim by SilentRansomGroup (May 2026)

low May 6

SIT Group Ransomware Attack by Bavacai (May 2026)

low May 6

Strategic Imports Ransomware Attack by Bavacai (May 2026)

low May 6

WOHA Ransomware Attack by Lamashtu (May 2026)

critical May 5

Addi.com Ransomware Attack by ShinyHunters (May 2026)

low May 5

Boots Transport Ransomware Claim by SafePay (May 2026)

low May 5

Dahlgrens Cement Ransomware Claim by SafePay (May 2026)

low May 5

fital-treppenlifte.de Ransomware by Safepay (May 2026)

low May 5

Foodsmart Dominicana Ransomware by Krybit (May 2026)

low May 5

Hokuyo2006 Ransomware Attack by Safepay (May 2026)

low May 5

Instructure Breach by ShinyHunters (May 2026)

low May 5

Maiadouro Ransomware Attack by Safepay (May 2026)

high May 5

Studio Marchi Ransomware Claim by Everest (May 2026)

low May 5

Zonaovest.to.it Ransomware Attack by Safepay (May 2026)

low May 4

Beyond Measure Ransomware Claim by Pear (May 2026)

high May 4

Instructure Ransomware Claim by ShinyHunters (May 2026)

low May 4

JG Stewart Construction Ransomware by cmdorganization (May 2026)

low May 4

LSM Lee Ransomware Attack by Qilin (May 2026)

low May 4

North Star Signs Ransomware Claim by Qilin (May 2026)

low May 4

Standard-Examiner Ransomware Claim by Qilin (May 2026)

low May 4

Star Precision Ransomware Attack by Qilin (May 2026)

low May 4

Tuopu Ransomware Attack by Blackwater (May 2026)

high May 4

Wilkem Group Ransomware Claim by INC Ransom (May 2026)

low May 4

Zampell Ransomware Claim by cmdorganization (May 2026)

critical May 3

Armstrong George Cohen Qilin Ransomware Attack (May 2026)

low May 3

cgcsa.co.za Ransomware Attack by Stormous (May 2026)

low May 3

Cushman & Wakefield Ransomware Claim by ShinyHunters (May 2026)

high May 3

EMTCO Ransomware Attack by m3rx (May 2026)

low May 3

FANASA.COM Ransomware Attack by Stormous (May 2026)

critical May 3

Fiserv Ransomware Claim by Everest (May 2026)

low May 3

it-freitag.de Ransomware Attack by m3rx (May 2026)

low May 3

Manatee Air Ransomware Claim by m3rx (May 2026)

low May 3

OR-Technology Ransomware Claim by Stormous (May 2026)

low May 3

Photonic Ransomware Attack by mnt6 (May 2026)

low May 2

Avnet Ransomware Attack by Fulcrumsec (May 2026)

critical May 2

Bomu Hospital Ransomware Attack by Krybit (May 2026)

critical May 2

EnergyAction Ransomware Attack by Safepay (May 2026)

high May 2

Epiq Global Ransomware Attack by Everest (May 2026)

low May 2

HPK Hamburg Ransomware Claim by Safepay (May 2026)

low May 2

INJURYLAWYERS.COM Ransomware Claim by Clop (May 2026)

critical May 2

Integra LifeSciences Ransomware Claim by Clop (May 2026)

low May 2

Site Design Group Attack by AiLock (May 2026)

high May 2

Symcor Ransomware Attack by Everest (May 2026)

critical May 2

TSYS Ransomware Attack by Everest (May 2026)

critical May 1

Apothebeauty Ransomware Attack by Qilin (April 2026)

critical May 1

Colorado Dental Wellness Ransomware by Anubis (May 2026)

low May 1

Follett Software Ransomware Claim by ShinyHunters (May 2026)

critical May 1

Jayeff Construction Ransomware Attack by Qilin (Apr 2026)

critical May 1

MES Hybrid Document Systems Ransomware by Qilin (Apr 2026)

critical May 1

See's Candies Ransomware Attack by Qilin (Apr 2026)

critical May 1

Silfab Solar Ransomware Attack by mnt6 (April 2026)

critical May 1

The Switch Enterprises Hit by Qilin Ransomware (Apr 2026)

critical May 1

Towerpoint Wealth Ransomware by ShinyHunters (May 2026)

critical May 1

Zinkan & Barker Ransomware Claim by Qilin (Apr 2026)

Learn

(1)

Malware

(52)
May 10

Agent Tesla Malware: 61 Samples, Stable Trend (May 2026)

May 10

AsyncRAT Malware: 42 Samples, Stable Trend (May 2026)

May 10

Formbook Malware: 95 Samples, Rising Trend (May 2026)

May 10

Mirai Malware: 100 Samples, Rising Trend (May 2026)

May 10

QuasarRAT Malware: 11 Samples, Rising Trend (May 2026)

May 10

Snake Keylogger Malware: 9 Samples, Rising Trend (May 2026)

May 10

Vidar Malware: 28 Samples, Stable Trend (May 2026)

May 7

Agent Tesla Malware: 36 Samples, Declining Trend (May 2026)

May 7

AsyncRAT Malware: 25 Samples, Declining Trend (May 2026)

May 7

Formbook Malware: 18 Samples, Declining Trend (May 2026)

May 7

Mirai Malware: 100 Samples, Rising Trend (May 2026)

May 7

QuasarRAT Malware: 10 Samples, Stable Trend (May 2026)

May 7

Vidar Malware: 24 Samples, Declining Trend (May 2026)

May 6

Agent Tesla Malware: 42 Samples, Declining Trend (May 2026)

May 6

AsyncRAT Malware: 27 Samples, Declining Trend (May 2026)

May 6

Formbook Malware: 16 Samples, Declining Trend (May 2026)

May 6

Mirai Malware: 100 Samples, Rising Trend (May 2026)

May 6

QuasarRAT Malware: 10 Samples, Stable Trend (May 2026)

May 6

Vidar Malware: 32 Samples, Stable Trend (May 2026)

May 5

Agent Tesla Malware: 42 Samples, Declining Trend (May 2026)

May 5

AsyncRAT Malware: 54 Samples, Stable Trend (May 2026)

May 5

Formbook Malware: 13 Samples, Declining Trend (May 2026)

May 5

QuasarRAT Malware: 11 Samples, Stable Trend (May 2026)

May 5

Snake Keylogger: 3 Samples — Declining (May 2026)

May 5

Vidar Malware: 33 Samples, Rising Trend (May 2026)

May 4

Agent Tesla Malware: 64 Samples, Stable Trend (May 2026)

May 4

AsyncRAT Malware: 60 Samples, Rising Trend (May 2026)

May 4

Formbook Malware: 12 Samples, Declining Trend (May 2026)

May 4

QuasarRAT Malware: 7 Samples, Declining Trend (May 2026)

May 4

Snake Keylogger: 6 Samples — Declining (May 2026)

May 4

Vidar Malware: 25 Samples, Stable Trend (May 2026)

May 3

Agent Tesla Malware: 60 Samples, Stable Trend (May 2026)

May 3

AsyncRAT Malware: 57 Samples, Rising Trend (May 2026)

May 3

Formbook Malware: 13 Samples, Declining Trend (May 2026)

May 3

Mirai Malware: 100 Samples, Rising Trend (May 2026)

May 3

QuasarRAT Malware: 5 Samples, Declining Trend (May 2026)

May 3

Snake Keylogger: 5 Samples — Declining (May 2026)

May 3

Vidar Malware: 28 Samples, Stable Trend (May 2026)

May 2

Agent Tesla Malware: 70 Samples, Stable Trend (May 2026)

May 2

AsyncRAT Malware: 55 Samples, Rising Trend (May 2026)

May 2

Formbook Malware: 38 Samples, Stable Trend (May 2026)

May 2

QuasarRAT Malware: 8 Samples, Declining Trend (May 2026)

May 2

Snake Keylogger: 7 Samples — Declining (May 2026)

May 2

Vidar Malware: 30 Samples, Stable Trend (May 2026)

May 1

Agent Tesla Malware: 80 Samples, Rising Trend (May 2026)

May 1

AsyncRAT Malware: 53 Samples, Rising Trend (May 2026)

May 1

Cobalt Strike Malware: 5 Samples, Rising Trend (May 2026)

May 1

Formbook Malware: 39 Samples, Rising Trend (May 2026)

May 1

Mirai Malware: 100 Samples, Rising Trend (May 2026)

May 1

QuasarRAT Malware: 14 Samples, Stable Trend (May 2026)

May 1

Snake Keylogger Malware: 8 Samples, Stable Trend (May 2026)

May 1

Vidar Malware: 29 Samples, Stable Trend (May 2026)

April 2026 All Threats

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.