Top 5

Vulnerabilities & Breaches

Weekly Briefing

Top 5 Hacker-Relevant Vulnerabilities

Ranked from a decision-tree-based prioritization model trained on over 100,000 vulnerabilities, extending CVSS and EPSS with real-time attacker context.

Calendar Week 35 2026

0 vulnerabilities scanned this week
01

Next.js

Unauthenticated Remote Attack · Path Traversal

CVE-2026-75604

02

Redis

Unauthenticated Remote Attack · Use-After-Free

CVE-2026-81934

03

OAuth2 Proxy

Unauthenticated Remote Attack · Authentication Bypass

CVE-2026-76835

04

JFrog Artifactory

Unauthenticated Remote Attack · Authentication Bypass

CVE-2026-82329

05

ServiceNow

Unauthenticated Remote Attack · Code Injection

CVE-2026-18885

Severity distribution this week
362 critical 1028 high 905 medium 102 low

Monthly Briefing

Top 5 Recent Breaches

The five most recent breaches from our monthly recap of security incidents caused by unpatched, hacker-relevant vulnerabilities.

July 2026 CVE-2026-35273

University of Nottingham

ShinyHunters exploited an Oracle PeopleSoft PeopleTools vulnerability to access the University of Nottingham's student records system, exposing data on 454,600 current and former students as part of a wider campaign spanning over 300 PeopleSoft instances

Oracle PeopleSoft Report
June 2026 CVE-2026-35273

Nissan

ShinyHunters exploited a missing-authentication flaw in Oracle PeopleSoft to access personal data of current and former Nissan employees across the US, Canada, Mexico, and Brazil, as part of a wider campaign claiming over 300 compromised PeopleSoft instances

Oracle PeopleSoft Report
May 2026 CVE-2026-45321

Grafana Labs

Attackers exfiltrated Grafana Labs' entire private GitHub codebase after a supply-chain compromise of 42 @tanstack/* npm packages leaked a GitHub workflow token that was missed during rotation

GitHub Actions Report
April 2026 CVE-2025-20333

U.S. Federal Civilian Executive Branch

A China-linked APT deployed the FIRESTARTER backdoor on a federal agency's Cisco Firepower device via two RCE and auth-bypass flaws, persisting through reboots and firmware updates despite an emergency patch directive

Cisco ASA/Firepower Report
March 2026 CVE-2025-55182

LexisNexis Legal & Professional

FulcrumSec used the React2Shell vulnerability to breach LexisNexis' AWS environment, exfiltrating roughly 2 GB of structured data including Redshift tables and plaintext Secrets Manager secrets spanning 21,000+ customer accounts

React Server Components Report

Don't be the next name on this list

ENTRYZERO continuously monitors your attack surface and tells you which vulnerabilities are actually exploitable, before attackers find them

Building Digital Resilience with Automation

All Rights Reserved by ENTRYZERO GmbH

IMPRINT: ENTRYZERO GmbH, Technologiezentrum Ruhr, Konrad-Zuse-Straße 18, 44801 Bochum, Registered Office: Bochum, Registration Court: Local Court Bochum, Registration number: HRB 21709, VAT ID: DE369315057, Managing Directors: Dr. Mohamad Sbeiti, Samet Gökbayrak, Tel.: +49 234 94426026, Email: info@entryzero.ai

PRIVACY POLICY: This website does not collect any personal data. We do not use cookies, trackers, forms or similar technologies. However, by visiting our website you agree that for every site request the following non-personal information is stored on the webserver for statistical, intrusion detection/prevention and troubleshooting purposes: requested address (URL), request date and time, client IP address, user-agent and referer. No information is given to or shared with third parties