SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open Microsoft Issues Out-of-Band Security Update for Windows 11 RRAS Vulnerabilities
Microsoft Issues Out-of-Band Security Update for Windows 11 RRAS Vulnerabilities

CVE Research

Microsoft Issues Out-of-Band Security Update for Windows 11 RRAS Vulnerabilities

Microsoft has deployed an emergency out-of-band update (KB5084597) to fix critical vulnerabilities in the Windows Routing and Remote Access Service (RRAS). The patch applies to Windows 11 Enterprise environments utilizing hotpatch functionality. If left unpatched, these issues could be exploited to ...

Apr 28, 2026 • 3 min read

Open CVE-2026-33017: Critical Langflow Vulnerability Exploited Within 20 Hours of Disclosure
CVE-2026-33017: Critical Langflow Vulnerability Exploited Within 20 Hours of Disclosure

CVE Research

CVE-2026-33017: Critical Langflow Vulnerability Exploited Within 20 Hours of Disclosure

The discovery of CVE-2026-33017 reveals a critical remote code execution vulnerability in Langflow that is being actively exploited in the wild within 20 hours of public disclosure. Successful exploitation could allow unauthenticated attackers to execute arbitrary code on affected servers, potential...

Apr 28, 2026 • 3 min read

Open Immediate Action Required: Critical NetScaler Vulnerability Exposes Sensitive Memory Data
Immediate Action Required: Critical NetScaler Vulnerability Exposes Sensitive Memory Data

CVE Research

Immediate Action Required: Critical NetScaler Vulnerability Exposes Sensitive Memory Data

Citrix has released a security advisory addressing two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical vulnerability tracked as CVE-2026-3055 (CVSS score: 9.3) and a high-severity vulnerability tracked as CVE-2026-4368 (CVSS score: 7.7).

Apr 28, 2026 • 3 min read

Open UNC1069 and the Axios npm Attack: Google Reveals North Korean Attribution
UNC1069 and the Axios npm Attack: Google Reveals North Korean Attribution

CVE Research

UNC1069 and the Axios npm Attack: Google Reveals North Korean Attribution

Cybercriminal and nation-state threat actors are increasingly shifting toward developer-ecosystem compromise and software supply chain abuse as a reliable avenue for mass access. Rather than exploiting hardened enterprise perimeters directly, these actors target trusted package repositories, build p...

Apr 28, 2026 • 5 min read

Open FortiClient EMS Under Fire: Critical CVE-2026-21643 Exploited in Real-World Attacks
FortiClient EMS Under Fire: Critical CVE-2026-21643 Exploited in Real-World Attacks

CVE Research

FortiClient EMS Under Fire: Critical CVE-2026-21643 Exploited in Real-World Attacks

A critical SQL injection vulnerability, CVE-2026-21643, has been identified in FortiClient Endpoint Management Server (EMS), a centralized management platform for FortiClient endpoint agents across multiple environments.

Apr 28, 2026 • 3 min read

Open Node.js Security Bulletin: CVE-2026-21637 and Other Fixes Explained
Node.js Security Bulletin: CVE-2026-21637 and Other Fixes Explained

CVE Research

Node.js Security Bulletin: CVE-2026-21637 and Other Fixes Explained

The Node.js project has recently released a series of security updates to address multiple vulnerabilities across its active release lines. These updates span versions 20.x, 22.x, 24.x, and 25.x, and include fixes for issues ranging from high to low severity. Among the most critical is CVE-2026-2163...

Apr 28, 2026 • 4 min read

Open Oracle Identity Manager Under Threat: Analyzing CVE-2026-21992 Remote Code Execution Flaw
Oracle Identity Manager Under Threat: Analyzing CVE-2026-21992 Remote Code Execution Flaw

CVE Research

Oracle Identity Manager Under Threat: Analyzing CVE-2026-21992 Remote Code Execution Flaw

A critical vulnerability, tracked as CVE-2026-21992, has been identified in Oracle Identity Manager (OIM) and Oracle Web Services Manager (OWSM). This flaw enables unauthenticated remote code execution (RCE), posing a severe risk to organizations that rely on these platforms for identity and access ...

Apr 28, 2026 • 3 min read

Open Backup Infrastructure at Risk: Critical RCE Flaws Patched in Veeam Backup & Replication
Backup Infrastructure at Risk: Critical RCE Flaws Patched in Veeam Backup & Replication

CVE Research

Backup Infrastructure at Risk: Critical RCE Flaws Patched in Veeam Backup & Replication

Veeam has fixed several critical vulnerabilities in its Backup & Replication platform that could allow remote code execution and privilege escalation if exploited. Given the platform’s widespread adoption, especially among large enterprises, these flaws present a significant security risk. Ransomwar...

Apr 28, 2026 • 4 min read

Open Google Chrome Security Update: patches for Actively Exploited Vulnerabilities (CVE-2026-3909 and CVE-2026-3910)
Google Chrome_emergency update_CVE-2026-3909 and CVE-2026

CVE Research

Google Chrome Security Update: patches for Actively Exploited Vulnerabilities (CVE-2026-3909 and CVE-2026-3910)

Google Chrome has released another emergency update to patch two critical zero-day vulnerabilities, CVE-2026-3909 and CVE-2026-3910.

Apr 28, 2026 • 5 min read