DEV Community

threataft profile picture

threataft

I run ThreatAft (threataft.com), an independent cybersecurity publication focused on CVE analysis and vulnerability intelligence. I publish daily articles covering critical CVEs, mass disclosures, and

Joined Joined on 
Splunk Patched an Unauthenticated RCE in Its Own SIEM — Here's What You Need to Know

Splunk Patched an Unauthenticated RCE in Its Own SIEM — Here's What You Need to Know

Comments
2 min read
Cisco Dropped 18 CVEs Yesterday — Here's What Actually Needs Your Attention

Cisco Dropped 18 CVEs Yesterday — Here's What Actually Needs Your Attention

Comments
1 min read
CVE-2026-94293: AAS Edge Client — CVSS 9.8 IIoT Data Tampering, No Patch, Decommission Now

CVE-2026-94293: AAS Edge Client — CVSS 9.8 IIoT Data Tampering, No Patch, Decommission Now

Comments
1 min read
HyperShift CVE-2026-101919 — CVSS 8.8 Tenant Isolation Bypass via Kubeconfig Passthrough

HyperShift CVE-2026-101919 — CVSS 8.8 Tenant Isolation Bypass via Kubeconfig Passthrough

Comments
1 min read
Legcord (Discord Client) — 2 CVEs: XSS in Discord Page Becomes RCE + Persistent Traffic Interception

Legcord (Discord Client) — 2 CVEs: XSS in Discord Page Becomes RCE + Persistent Traffic Interception

Comments
1 min read
ZITADEL Cluster: 7 CVEs, Peak CVSS 9.3 — Cross-Org Account Takeover via Passkey Enrollment

ZITADEL Cluster: 7 CVEs, Peak CVSS 9.3 — Cross-Org Account Takeover via Passkey Enrollment

Comments
1 min read
CVE-2026-88779 — Citrix NetScaler SAML Memory Overflow, Actively Exploited, CISA KEV

CVE-2026-88779 — Citrix NetScaler SAML Memory Overflow, Actively Exploited, CISA KEV

Comments
1 min read
YesWiki 9 CVEs — CVSS 8.6 SQL Injection Can Dump Your Entire Database

YesWiki 9 CVEs — CVSS 8.6 SQL Injection Can Dump Your Entire Database

Comments
1 min read
UTMStack Cluster — 7 CVEs, Peak CVSS 9.9 Missing Auth on STOMP Command WebSocket

UTMStack Cluster — 7 CVEs, Peak CVSS 9.9 Missing Auth on STOMP Command WebSocket

Comments
1 min read
WordPress Auth Bypass Cluster — 4 CVSS 9.8, Full Site Takeover via Plugin Flaws

WordPress Auth Bypass Cluster — 4 CVSS 9.8, Full Site Takeover via Plugin Flaws

Comments
1 min read
Ghost CMS Mass Disclosure — 6 CVEs Including CVSS 8.1 Staff Session Bypass

Ghost CMS Mass Disclosure — 6 CVEs Including CVSS 8.1 Staff Session Bypass

Comments
1 min read
Mooncake Mass Disclosure — CVSS 9.8 Arbitrary Memory Read/Write in KV Cache Transfer Engine

Mooncake Mass Disclosure — CVSS 9.8 Arbitrary Memory Read/Write in KV Cache Transfer Engine

Comments
1 min read
Dockhand CVE-2026-53988 — CVSS 10.0 Unauthenticated Webhook Auth Bypass

Dockhand CVE-2026-53988 — CVSS 10.0 Unauthenticated Webhook Auth Bypass

Comments
1 min read
Deno CVE-2026-103473 — CVSS 8.1 Command Injection in node:child_process on Windows

Deno CVE-2026-103473 — CVSS 8.1 Command Injection in node:child_process on Windows

Comments
1 min read
Cisco SD-WAN Manager CVE-2026-76504 — CVSS 9.8 Auth Bypass via URI Encoding, Actively Exploited

Cisco SD-WAN Manager CVE-2026-76504 — CVSS 9.8 Auth Bypass via URI Encoding, Actively Exploited

Comments
1 min read
Five vulnerabilities in AiSOC (the open-source SOC platform) were disclosed today.

Five vulnerabilities in AiSOC (the open-source SOC platform) were disclosed today.

Comments
1 min read
LightLLM Mass Disclosure — 2 CVSS 9.8 Unauthenticated RCE in LLM Serving Framework

LightLLM Mass Disclosure — 2 CVSS 9.8 Unauthenticated RCE in LLM Serving Framework

Comments
2 min read
CTranslate2 CVE-2026-102566 & CVE-2026-102567 — Heap Overflow in AI Model Loader

CTranslate2 CVE-2026-102566 & CVE-2026-102567 — Heap Overflow in AI Model Loader

Comments
2 min read
RaspAP Mass Disclosure — 3 CVEs, Privilege Escalation + RCE, No Patch

RaspAP Mass Disclosure — 3 CVEs, Privilege Escalation + RCE, No Patch

Comments
2 min read
loading...