SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open Critical Code Execution Vulnerability in Adobe ColdFusion
Critical Code Execution Vulnerability in Adobe ColdFusion

CVE Research

Critical Code Execution Vulnerability in Adobe ColdFusion

Adobe has released a critical security update that impacted Adobe ColdFusion and is assigned with a priority rating of 2. The Adobe Coldfusion Exploit found in the product affects ColdFusion versions 2016, 2018, and 2021 that would lead to arbitrary code execution. Using a patch management tool can ...

Apr 30, 2026 • 2 min read

Open SanerNow’s Role in Strengthening Compliance Posture
SanerNow’s Role in Strengthening Compliance Posture

CVE Research

SanerNow’s Role in Strengthening Compliance Posture

Millions of people are robbed of personal data like their credentials, social security numbers, bank account-credit card details, among others, on social media. These can be stopped by using a vulnerability management tool. Cybercriminals are engaged in their thieving escapade to impersonate people ...

Apr 30, 2026 • 6 min read

Open 5 Questions to Ask While Choosing a Network Vulnerability Scanner
5 Questions to Ask While Choosing a Network Vulnerability Scanner

CVE Research

5 Questions to Ask While Choosing a Network Vulnerability Scanner

The CISO and the sysadmin at the_Teckies were desperately looking for a network vulnerability scanner. Talks of a dangerous misconfiguration in JIRA were in the news, and it seemed to have escaped from their existing scanner. It is essential to have a vulnerability management software.

Apr 30, 2026 • 3 min read

Open Critical Remote Code Execution Vulnerabilities in MyBB Forum Software
Critical Remote Code Execution Vulnerabilities in MyBB Forum Software

CVE Research

Critical Remote Code Execution Vulnerabilities in MyBB Forum Software

Two critical vulnerabilities have been found in popular bulletin board software called MyBB. The vulnerabilities can be chained together to get remote code execution without prior access to a privileged account. The independent security researchers Simon Scannell and Carl Smith found the flaws. They...

Apr 30, 2026 • 3 min read

Open Alert! Zerologon: Your Windows Domain Controller Can’t Handle Zero Properly (CVE-2020-1472)
Alert! Zerologon: Your Windows Domain Controller Can’t Handle Zero Properly (CVE-2020-1472)

CVE Research

Alert! Zerologon: Your Windows Domain Controller Can’t Handle Zero Properly (CVE-2020-1472)

Microsoft team patched a critical and exciting vulnerability in the Netlogon Remote Protocol of the Windows server last month. zero logon vulnerability discovered by the Cybersecurity firm Secura (dubbed as Zerologon), has received the highest severity score of 10.0. The vulnerability is identified ...

Apr 30, 2026 • 4 min read

Open Sophos UTM Creating a ‘Big’ Bounty with Remote Code Execution Flaw
Sophos UTM Creating a ‘Big’ Bounty with Remote Code Execution Flaw

CVE Research

Sophos UTM Creating a ‘Big’ Bounty with Remote Code Execution Flaw

A critical and high severity remote code execution vulnerability CVE-2020-25223 with CVSS 3. x severe base score 9.8 is present in Sophos SG UTM. Sophos reported this vulnerability on  September 18, 2020, in their Advisory. A reliable vulnerability management tool can help to combat these vulnerabil...

Apr 30, 2026 • 3 min read

Open A Critical Vulnerability ‘SMBleed’ Impacts Windows SMB Protocol
A Critical Vulnerability ‘SMBleed’ Impacts Windows SMB Protocol

CVE Research

A Critical Vulnerability ‘SMBleed’ Impacts Windows SMB Protocol

The Server Message Block Protocol (SMB protocol), which runs over TCP port 445, is a client-server communication protocol for sharing access to files, printers, network browsing, and inter-process communication.

Apr 30, 2026 • 3 min read

Open Critical Command Injection Vulnerabilities in D-Link DSR VPN Routers
Critical Command Injection Vulnerabilities in D-Link DSR VPN Routers

CVE Research

Critical Command Injection Vulnerabilities in D-Link DSR VPN Routers

Multiple critical command injection vulnerabilities have identified in the D-Link DSR VPN router family products. These vulnerabilities are identified with CVE-2020-25757, CVE-2020-25759, CVE-2020-25758 and can allow an attacker to gain complete root access to the affected device. Vulnerability mana...

Apr 30, 2026 • 3 min read

Open Kaseya’s Virtual System/Server Administrator (VSA) Zero-Day Under Active Exploitation By REvil Ransomware
Kaseya’s Virtual System/Server Administrator (VSA) Zero-Day Under Active Exploitation By REvil Ransomware

CVE Research

Kaseya’s Virtual System/Server Administrator (VSA) Zero-Day Under Active Exploitation By REvil Ransomware

Kaseya is a US-based organization that provides IT and security management solutions for managed service providers (MSPs) and small to medium-sized businesses (SMBs) worldwide. One of its tools, called Kaseya’s VSA, is under active exploitation and used as an attack vector to install REvil ransomwar...

Apr 30, 2026 • 6 min read