SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open CDPwn: Critical Zero-day flaws affecting millions of Cisco Devices.
CDPwn: Critical Zero-day flaws affecting millions of Cisco Devices.

CVE Research

CDPwn: Critical Zero-day flaws affecting millions of Cisco Devices.

Fig 1: Image credit: zdnet.com

Apr 30, 2026 • 8 min read

Open Critical Vulnerabilities in Palo Alto Networks PAN-OS devices
Critical Vulnerabilities in Palo Alto Networks PAN-OS devices

CVE Research

Critical Vulnerabilities in Palo Alto Networks PAN-OS devices

Palo Alto Network (PAN) has recently fixed a critical vulnerability related to the PAN-OS operating systems. The operating systems are known to power Palo Alto’s next-generation firewall. The vulnerability is tracked as CVE-2020-2021 with a CVSSv3 base score of 10. PAN-OS is the custom operating sys...

Apr 30, 2026 • 3 min read

Open Beware : Microsoft Warns of Active Attacks on Windows Using Unpatched Zero-Days
Beware : Microsoft Warns of Active Attacks on Windows Using Unpatched Zero-Days

CVE Research

Beware : Microsoft Warns of Active Attacks on Windows Using Unpatched Zero-Days

Microsoft and its updates are of utmost interest to the security community during the second Tuesday of every month, the Patch Tuesday. However, Microsoft has filled the headlines of the fourth Tuesday too with important information about two critical unpatched zero-days in Microsoft Windows operati...

Apr 30, 2026 • 5 min read

Open Unpatched Zero-Day Vulnerabilities Put IBM Data Risk Manager At Risk
Unpatched Zero-Day Vulnerabilities Put IBM Data Risk Manager At Risk

CVE Research

Unpatched Zero-Day Vulnerabilities Put IBM Data Risk Manager At Risk

A security researcher recently uncovered four vulnerabilities in IBM Data Risk Manager and publicly disclosed them following a refusal from the tech giant to act on the same. These Zero-Day vulnerabilities, which have not been assigned any CVEs yet, comprise 3 critical and 1 high severity bugs.

Apr 30, 2026 • 3 min read

Open The Missing Piece of Your IT Security Puzzle: Continuous Posture Anomaly Management
The Missing Piece of Your IT Security Puzzle: Continuous Posture Anomaly Management

CVE Research

The Missing Piece of Your IT Security Puzzle: Continuous Posture Anomaly Management

You might have a concrete vulnerability management plan and robust security practices, but sometimes, the most obvious outliers and attack vectors get missed, leading to a dangerous attacker entering your network. A Vulnerability Management Software can prevent these attacks.

Apr 30, 2026 • 4 min read

Open Are you Remediating High Risk and Critical Vulnerabilities First?
Are you Remediating High Risk and Critical Vulnerabilities First?

CVE Research

Are you Remediating High Risk and Critical Vulnerabilities First?

Organizations have been relying on CVSS scores to triage the vulnerabilities in their environment. They are a good place to start, but cannot be the only factor to assess the severity. CVSS scores are assigned at the time of discovery of the vulnerability. However, they do not account for the changi...

Apr 30, 2026 • 3 min read

Open WinRM servers are the latest prey for the Wormable Windows HTTP vulnerability
WinRM servers are the latest prey for the Wormable Windows HTTP vulnerability

CVE Research

WinRM servers are the latest prey for the Wormable Windows HTTP vulnerability

Microsoft recently patched a critical remote code execution vulnerability in the HTTP Protocol Stack (http. sys). Used by the Windows built-in IIS server for processing HTTP requests. The vulnerability is assigned with an identifier CVE-2021-31166 and has a CVSS score of 9.8. This is a wormable vuln...

Apr 30, 2026 • 4 min read

Open CVE-2013-7260: RealNetworks RealPlayer Stack-Based Buffer Overflow
CVE-2013-7260: RealNetworks RealPlayer Stack-Based Buffer Overflow

CVE Research

CVE-2013-7260: RealNetworks RealPlayer Stack-Based Buffer Overflow

RealPlayer is vulnerable to multiple stack-based buffer overflow vulnerabilities (CVE-2013-7260). This flaw allows attackers to execute arbitrary code and take complete control of the system remotely. Affected versions of RealPlayer are before 17.0.4.61 on Windows systems. This flaw can be mitigated...

Apr 30, 2026 • 2 min read

Open Delivering Ransomware with Windows Updates
Delivering Ransomware with Windows Updates

CVE Research

Delivering Ransomware with Windows Updates

Apr 30, 2026 • 2 min read