Dell RecoverPoint's Perfect-10 Bug Was a Zero-Day Before It Was a Patch
CVE-2026-22769's hardcoded credential in Dell RecoverPoint for VMs was already being exploited by a tracked threat group, UNC6201, before Dell shipped a fix.
Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.
CVE-2026-22769's hardcoded credential in Dell RecoverPoint for VMs was already being exploited by a tracked threat group, UNC6201, before Dell shipped a fix.
CVE-2026-34197 turns ActiveMQ's Jolokia JMX-HTTP bridge into a code execution chain, exploiting an ordering flaw where Spring instantiates beans before the broker validates configuration.
CVE-2023-27351 in PaperCut's SecurityRequestFilter class bypasses authentication with no credentials at all, and CISA flags it with a confirmed ransomware association.
An unrestricted JSP upload and a stored XSS bug in OpenPLC's ScadaBR, both disclosed the same day in 2021, were confirmed exploited within a week of each other in late 2025.
A near-maximum-severity PHP deserialization RCE and a stored XSS bug via SVG animate tags landed in CISA's KEV catalogue on the same date, describing a realistic foothold-to-RCE chain.
From a 2020 SSRF bug to three related XSS bypasses and an unauthenticated file-inclusion flaw, five Synacor Zimbra vulnerabilities were confirmed exploited within a single KEV window.
An APT-linked WinRAR path traversal, a FileZen command injection hiding behind its own antivirus feature, and a Secure Boot bypass in IGEL OS show KEV's reach beyond headline platforms.
CVE-2025-11953 lets unauthenticated attackers run arbitrary commands on developer machines through React Native's Metro Development Server, which binds to external interfaces by default.
CVE-2026-3502, a separate TrueConf Client finding beyond this series' earlier coverage, let attackers substitute tampered update payloads, tied to Operation TrueChaos against Southeast Asian governments.
Weekly insights on software supply chain security, delivered to your inbox.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.