SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
Three Zero-Days, 114 Flaws Fixed: Microsoft Kicks Off 2026 with a Major Patch Tuesday
This month’s Patch Tuesday marks a significant start to the year, with Microsoft delivering a heavy volume of updates to address 114 vulnerabilities. This includes 3 zero-day flaws, one of which is actively exploited.

CVE Research
Unmasking UAT-8837: The Zero-Day Exploit That Could Ruin Your Year
A sophisticated China-linked threat actor, identified as UAT-8837, has been observed exploiting a critical zero-day vulnerability in the Sitecore platform. Tracked as CVE-2025-53690, this insecure deserialization flaw allows attackers to bypass authentication and execute remote code (RCE). The prima...

CVE Research
MongoBleed: MongoDB Zlib Vulnerability (CVE-2025-14847) and how to remediate it
A high-severity vulnerability known as MongoBleed (CVE-2025-14847), was recently identified and patched in MongoDB, the widely used open-source NoSQL database. The issue, named for its ability to “bleed” uninitialized memory from the server, stems from improper handling of zlib-compressed wire proto...

CVE Research
Public PoC Released for Cisco ISE Information Disclosure Flaw
Cisco has recently addressed a medium-severity security vulnerability in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). The vulnerability, identified as CVE-2026-20029, has a public proof-of-concept (PoC) exploit available, prompting a swift response from the networ...

CVE Research
Severe Veeam Backup Vulnerability Could Lead to Code Execution
Veeam, a prominent provider of data protection and disaster recovery solutions, has recently addressed multiple security vulnerabilities in its Backup & Replication software. These flaws could potentially allow attackers to perform remote code execution (RCE) and gain unauthorized access to systems....

CVE Research
RondoDox Rampage: A Multivendor “Exploit-Shotgun” Botnet (Updated)
RondoDox is an emerging, multivector botnet that has been observed weaponizing 56 distinct vulnerabilities across 30+ device and vendor types (routers, DVRs/NVRs, CCTV, SOHO appliances, web servers, and more) to build large-scale DDoS-capable botnets and deploy secondary payloads (Mirai/Morte varian...

CVE Research
Mass Exploitation Campaign Targeting Adobe ColdFusion Servers Detected During Christmas Holiday
A coordinated exploitation campaign targeted Adobe ColdFusion servers across the globe during the Christmas 2025 holiday period, generating 5,940 malicious requests that probed 10+ ColdFusion CVEs disclosed between 2023 and 2024. Telemetry indicates 68% of the activity occurred on December 25, sugge...

CVE Research
Understanding CVE-2025-66516: Critical XXE Exposure in Apache Tika
A maximum severity vulnerability has been identified in Apache Tika, a widely used open-source content analysis toolkit. This vulnerability, designated as CVE-2025-66516, has a CVSS score of 10.0, indicating its critical impact. The flaw allows XML External Entity (XXE) injection attacks, potentiall...

CVE Research
Three Zero-Days and 57 Fixes: A Critical Year-End Patch Tuesday from Microsoft
This month’s Patch Tuesday delivers a modest-sized update, but with high-impact fixes. Microsoft has patched 57 vulnerabilities, including 3 zero-day flaws (one actively exploited and two publicly disclosed) along with several critical-severity bugs.
