Top 5

Vulnerabilities & Breaches

Weekly Briefing

Top 5 Hacker-Relevant Vulnerabilities

Ranked from a decision-tree-based prioritization model trained on over 100,000 vulnerabilities, extending CVSS and EPSS with real-time attacker context.

Calendar Week 36 2026

0 vulnerabilities scanned this week
01

SonicWall SMA1000

Unauthenticated Remote Attack · Server-Side Request Forgery

CVE-2026-83548

02

HPE Networking Fabric Composer

Unauthenticated Remote Attack · Improper Authentication

CVE-2026-76658

03

GeoNetwork

Unauthenticated Remote Attack · Code Injection

CVE-2026-58400

04

N-able N-central

Unauthenticated Remote Attack · Static Code Injection

CVE-2026-86218

05

MikroTik RouterOS

Unauthenticated Remote Attack · Argument Injection

CVE-2026-86060

Severity distribution this week
316 critical 823 high 854 medium 81 low

Monthly Briefing

Top 5 Recent Breaches

The five most recent breaches from our monthly recap of security incidents caused by unpatched, hacker-relevant vulnerabilities.

August 2026 CVE-2026-12569

Philips

Cl0p exploited an unauthenticated input-validation flaw in PTC Windchill and FlexPLM to compromise an internal Philips server and exfiltrate data, naming Philips alongside Shell, GE, and Fiserv on its leak site as part of a wider campaign against exposed PLM instances

PTC Windchill and FlexPLM Report
July 2026 CVE-2026-35273

University of Nottingham

ShinyHunters exploited an Oracle PeopleSoft PeopleTools vulnerability to access the University of Nottingham's student records system, exposing data on 454,600 current and former students as part of a wider campaign spanning over 300 PeopleSoft instances

Oracle PeopleSoft Report
June 2026 CVE-2026-35273

Nissan

ShinyHunters exploited a missing-authentication flaw in Oracle PeopleSoft to access personal data of current and former Nissan employees across the US, Canada, Mexico, and Brazil, as part of a wider campaign claiming over 300 compromised PeopleSoft instances

Oracle PeopleSoft Report
May 2026 CVE-2026-45321

Grafana Labs

Attackers exfiltrated Grafana Labs' entire private GitHub codebase after a supply-chain compromise of 42 @tanstack/* npm packages leaked a GitHub workflow token that was missed during rotation

GitHub Actions Report
April 2026 CVE-2025-20333

U.S. Federal Civilian Executive Branch

A China-linked APT deployed the FIRESTARTER backdoor on a federal agency's Cisco Firepower device via two RCE and auth-bypass flaws, persisting through reboots and firmware updates despite an emergency patch directive

Cisco ASA/Firepower Report

Don't be the next name on this list

ENTRYZERO continuously monitors your attack surface and tells you which vulnerabilities are actually exploitable, before attackers find them

Building Digital Resilience with Automation

All Rights Reserved by ENTRYZERO GmbH

IMPRINT: ENTRYZERO GmbH, Technologiezentrum Ruhr, Konrad-Zuse-Straße 18, 44801 Bochum, Registered Office: Bochum, Registration Court: Local Court Bochum, Registration number: HRB 21709, VAT ID: DE369315057, Managing Directors: Dr. Mohamad Sbeiti, Samet Gökbayrak, Tel.: +49 234 94426026, Email: info@entryzero.ai

PRIVACY POLICY: This website does not collect any personal data. We do not use cookies, trackers, forms or similar technologies. However, by visiting our website you agree that for every site request the following non-personal information is stored on the webserver for statistical, intrusion detection/prevention and troubleshooting purposes: requested address (URL), request date and time, client IP address, user-agent and referer. No information is given to or shared with third parties