SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
Tunnel Trouble: 4.2 Million Hosts, VPNs, and Routers Vulnerable
“Attackers? Good luck getting past my VPN wall!”. Maybe it’s time to reconsider that. New research just uncovered security vulnerabilities in multiple tunneling protocols that could allow attackers to perform a wide range of attacks in your “private” network.

CVE Research
Urgent: Patch Now! Critical Zero-Day CVE-2025-23006 Targets SonicWall SMA Appliances
CVE-2025-23006 is a critical zero-day vulnerability affecting SonicWall Secure Mobile Access (SMA) 1000 series appliances. This vulnerability, categorized as a deserialization of untrusted data flaws, resides within the Appliance Management Console (AMC) and Central Management Console (CMC). Exploit...

CVE Research
The Cybersecurity Landscape of 2024: Key Insights from the Annual Vulnerability Report
The 2024 Annual Vulnerability Report from SecPod reveals a staggering increase in global vulnerabilities, highlighting the ever-evolving nature of cyber threats. With 40,704 vulnerabilities identified in 2024—a 30% increase compared to the previous year—this report serves as a critical resource for ...

CVE Research
Critical Code Execution Vulnerability (CVE-2025-0411) Detected in 7-Zip
A critical security vulnerability identified as CVE-2025-0411 has been detected in 7-Zip, a widely used file archiver. With a CVSS score of 7.0, this vulnerability allows attackers to bypass the Windows “Mark-of-the-Web” (MotW) security feature. If exploited, it could lead to the execution of malici...

CVE Research
CVE-2025-23114: Critical Vulnerability in Veeam Backup Products
A critical security vulnerability identified as CVE-2025-23114 affects multiple Veeam backup products. This vulnerability resides within the Veeam Updater component and allows attackers to execute arbitrary code on the affected server through a Man-in-the-Middle (MitM) attack. The issue arises from ...

CVE Research
Reducing R&D Costs and Speeding Up Time-to-Market – How Integrating SecPod Can Help Businesses
When it comes to product development, Technology Vendors are under immense pressure to innovate rapidly, reduce costs, and maintain end-to-end security. This trifecta of challenges often strains resources, delays launches and impacts customer satisfaction. However, integrating SecPod’s advanced tech...

CVE Research
F5 Issues Warning: BIG-IP Vulnerability Used In Active Exploit Chain
According to F5, a critical security vulnerability in BIG-IP is being actively exploited after its public disclosure. CVE-2023-46747, resulting in remote code execution, is being further used to exploit CVE-2023-46748, an SQL injection vulnerability.


