Back to Blog

Vulnerability Management

5 articles on this topic.

Threat Intelligence28 August 2026

Patch Discussion to Exploit Probe: Now Measured in Minutes, Not Days

Maintainers are reporting that automated attackers are weaponising vulnerability rumours before a patch even ships — collapsing the gap between disclosure and exploitation from days to minutes.

vulnerability-managementpatch-managementai-security
4 min readRead
Vulnerability Management11 August 2026

CISA KEV Alert: Langflow RCE Exploited at Scale, AI Agents in the Loop

CISA added an unauthenticated Langflow RCE, an Apache Tomcat cluster-encryption bypass, and two N-able N-central auth-bypass bugs to its KEV catalog on August 5 — one of them already chained by an actor using agentic AI tooling.

kev-cataloglangflowai-agent-security
4 min readRead
Firmware & Boot Security29 July 2026

11 Old Microsoft-Signed UEFI Shims Left Secure Boot Bypassable for 13 Years

ESET found that 11 old UEFI shim bootloaders, still validly signed under Microsoft's third-party CA, let attackers bypass Secure Boot on any UEFI machine that trusts that certificate — no exploit development required.

uefisecure-booteset
4 min readRead
CI/CD & DevSecOps28 July 2026

CVE-2026-63077: Critical TeamCity Flaw Enables Unauthenticated RCE

A critical bug in the agent polling protocol lets an unauthenticated attacker with network access to a TeamCity On-Premises server run arbitrary OS commands — no credentials required.

teamcitycicd-securityvulnerability-management
4 min readRead
Vulnerability Management18 July 2026

OpenSSL's HollowByte DoS Flaw Shipped With No CVE — Here's Why That Matters

An 11-byte TLS handshake header can lock up hundreds of megabytes of server memory before authentication even starts. OpenSSL fixed it in June 2026 without a CVE, an advisory, or a changelog entry.

openssldenial-of-servicevulnerability-management
4 min readRead