Exchange Authentication Bypass Vulnerability Now Exploitable

A public exploit for an Exchange authentication bypass vulnerability is live, and 85% of German on-prem servers remain unpatched, BSI warns.

A working exploit for an Exchange authentication bypass vulnerability is now public on GitHub, and heise.de reports that roughly 85% of on-premises Exchange servers in Germany remain vulnerable three weeks after Microsoft shipped a fix. The catch: for organizations still running Exchange 2016 or 2019, that fix is locked behind Microsoft’s paid Extended Security Update…

Read More

Windows IKE RCE: Patched in April, Exploited Now

CVE-2026-33824 Windows IKE RCE is now actively exploited despite an April patch. CVSS 9.8, no auth needed. See who's affected and what to check today.

CVE-2026-33824 Windows IKE RCE has gone from a quietly patched bug in April to an actively exploited flaw four months later: CISA added it to its Known Exploited Vulnerabilities catalog on August 18, 2026, giving U.S. federal agencies until August 21 to patch — while Microsoft’s own advisory still lists it as not exploited. What…

Read More

CVE-2026-48282 Adobe ColdFusion RCE Exploited in 2 Hours

CVE-2026-48282 Adobe ColdFusion RCE

CVE-2026-48282 Adobe ColdFusion RCE is now the fastest-weaponized CVSS-10.0 flaw DIESEC has tracked in 2026: attackers began exploiting Adobe’s maximum-severity ColdFusion vulnerability within two hours of public disclosure, and CISA has given US federal agencies until July 10 to patch. What Happened Adobe’s APSB26-68 security bulletin, released June 30, 2026, patched 11 CVEs across ColdFusion,…

Read More

SharePoint RCE CVE-2026-45659: Active Exploits

SharePoint RCE CVE-2026-45659

SharePoint RCE CVE-2026-45659 is now under active exploitation, and the federal patch deadline set by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) is July 4 — tomorrow. The CVSS 8.8 deserialization flaw lets any authenticated user with nothing more than baseline Site Member permissions run code remotely on the server. Shadowserver currently counts more…

Read More

Top 5 Cybersecurity News Stories April 17, 2026

News Stories April 17

This week’s Top 5 Cybersecurity News Stories April 17, 2026 are not a recap, they are a strategic read of where risk is concentrating. This week highlights simultaneous stress across patching ecosystems, financial systems, AI‑driven vulnerability discovery, trusted SaaS integrations, and critical infrastructure. These signals point to quiet but compounding failures inside platforms many organisations…

Read More