SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
CISA Confirms Active Exploitation of Cisco FMC Zero-Day - CVE-2026-20316
A hard-coded, low-privilege account built into Cisco Secure FMC's web interface is letting unauthenticated attackers log in remotely, and CISA confirms the flaw is already being exploited against internet-facing devices.

CVE Research
One Request, Total Persistence: Inside the SharePoint Flaw Attackers Are Exploiting
A critical SharePoint deserialization flaw, CVE-2026-50522 (CVSS 9.8), is under active exploitation just weeks after its July 2026 patch, following a public PoC. Attackers are using it to steal IIS machine keys in a single request, gaining persistence that survives patching alone. Now on CISA's KEV list, it's the third actively exploited SharePoint flaw in recent months, patch immediately and rotate machine keys.







