Exploit Threats
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Filtered Threats
Click on any threat for detailed analysis and mitigation recommendations
Three high-severity vulnerabilities in JFrog Artifactory have been exploited in the wild to bypass authentication and gain administrative privileges. These flaws allow attackers to deploy backdoors, create persistent admin accounts, and execute arbitrary code. The vulnerabilities, identified as CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329, have been patched by JFrog. Multiple threat actors have chained these vulnerabilities to escalate privileges and maintain persistent access on self-hosted Artifactory instances. The Cybersecurity and Infrastructure Security Agency (CISA) has added these CVEs to its Known Exploited Vulnerabilities catalog and mandated federal agencies to patch within two weeks. Organizations are strongly advised to update to the fixed versions immediately. CriticalExploit Join the discussion | SecurityWeek | 09/14/2026, 09:27:29 UTC Added: 09/14/2026, 09:31:36 UTC |
Two zero-day vulnerabilities in PaperCut NG/MF were exploited in AI-powered attacks by a Russian-speaking threat actor targeting hundreds of organizations worldwide. The flaws allowed remote unauthenticated attackers to bypass authentication and execute arbitrary code. The attacker used AI to rapidly build, test, and deploy exploits, compromising 440 deployments across 48 countries, primarily in the education sector. Credential harvesting, secret exfiltration, and domain admin privilege escalation were observed. The vulnerabilities were disclosed and patched shortly after, but the campaign demonstrated rapid exploitation using AI automation. CriticalExploit Join the discussion | SecurityWeek | 09/11/2026, 08:18:23 UTC Added: 09/11/2026, 08:31:57 UTC |
The BlueMoon exploit kit is a modular tool used by multiple cyber-espionage groups to chain zero-day vulnerabilities in Microsoft Windows and Google Chrome. It combines two Chromium-based browser flaws allowing remote code execution and sandbox escape with a Windows kernel local privilege escalation. Observed since August 2026, BlueMoon has been deployed by Chinese state-sponsored actors targeting NGOs, aerospace, defense, and manufacturing sectors. The kit exploits delays in Chrome stable releases to weaponize recent Chromium fixes. It executes payloads by elevating Chrome renderer privileges and injecting commands to download and run malware loaders. Join the discussion | Bleeping Computer | 09/10/2026, 14:11:34 UTC Added: 09/10/2026, 14:22:17 UTC |
ShieldCrash is a zero-day exploit targeting Microsoft Defender on fully patched Windows systems as of September 2026. It enables privilege escalation to full System privileges, allowing attackers to perform sensitive actions such as dumping the SAM database. This exploit bypasses previous patches for related vulnerabilities including ShieldBreak and RoguePlanet, indicating incomplete remediation by Microsoft. The underlying vulnerability is tracked as CVE-2026-69414. No official patch specifically addressing ShieldCrash has been confirmed at this time. Join the discussion | SecurityWeek | 09/10/2026, 07:09:36 UTC Added: 09/10/2026, 07:22:15 UTC |
The Dark Sword exploit is an iOS exploit chain that was active earlier in the year and has since been patched. It was reportedly used primarily against high-profile targets, but the exploit code has been leaked publicly. This raises concerns about the potential risk to average iPhone users. However, there is no evidence of widespread exploitation against typical users. The exploit is considered high severity due to its capabilities, but the risk to the general population remains low given targeted use and the availability of patches. Join the discussion | Reddit Cybersecurity | 09/09/2026, 15:04:09 UTC Added: 09/09/2026, 15:37:05 UTC |
A security researcher known as Nightmare Eclipse has released proof-of-concept zero-day exploits targeting Avast, CrowdStrike, and Nvidia products. These exploits enable privilege escalation, allowing attackers to spawn shells with system-level privileges. The vulnerabilities affect Avast's sandbox, CrowdStrike Falcon Sensor's Office macro remediation feature, and an out-of-bounds memory write in Nvidia user-mode components. GenDigital (Avast) has patched the vulnerability, and CrowdStrike is investigating and advising mitigation steps. Nvidia has not yet publicly responded. The exploits demonstrate active research and disclosure but no confirmed active exploitation in the wild. Join the discussion | SecurityWeek | 09/07/2026, 12:15:57 UTC Added: 09/07/2026, 12:22:14 UTC |
An AI model named Cyberkimi claims to have autonomously developed a live exploit for a recently patched V8 JavaScript engine vulnerability in under 24 hours. The exploit targets Chrome Stable versions that still contain the unpatched bugs. The AI reportedly analyzed recent V8 security patches, identified incomplete fixes, and generated a working exploit chain demonstrated in a local Chromium environment. No official CVE has been assigned to these specific bugs yet, and independent confirmation is lacking. The exploit reportedly leverages a combination of aliasing bugs, race conditions, and control flow hijacking to achieve arbitrary code execution. Google has released Chrome updates addressing some V8 vulnerabilities around the same time, but it is unclear if these fixes cover the bugs exploited by Cyberkimi. This development highlights the shrinking window between patch release and exploit weaponization, potentially accelerating the risk exposure for users of affected Chrome versions. Join the discussion | Reddit Cybersecurity | 09/05/2026, 02:45:39 UTC Added: 09/05/2026, 02:52:09 UTC |
Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. [...] Join the discussion | Bleeping Computer | 09/04/2026, 11:48:17 UTC Added: 09/04/2026, 12:07:22 UTC |
Exploit-DB RSS Feed | 09/03/2026, 00:00:00 UTC Added: 09/03/2026, 17:44:19 UTC | |
SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. [...] Join the discussion | Bleeping Computer | 09/02/2026, 06:39:29 UTC Added: 09/02/2026, 07:07:13 UTC |
Showing 1 to 10 of 450 results