The Same Code Injection Bug Hit Ivanti's Mobile Manager Twice in Two Months
Two nearly identical unauthenticated RCE vulnerabilities in Ivanti Endpoint Manager Mobile, plus a perfect-10 in Sentry and a credential-leaking bypass in Endpoint Manager.
Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.
Two nearly identical unauthenticated RCE vulnerabilities in Ivanti Endpoint Manager Mobile, plus a perfect-10 in Sentry and a credential-leaking bypass in Endpoint Manager.
A SQL injection and an access-control bug in FortiClient EMS, a path traversal and command injection pair in FortiWeb — Fortinet's endpoint management and WAF products join the list.
PeopleSoft and E-Business Suite together account for three ransomware-associated Oracle vulnerabilities in a single year — an unusually high concentration for one vendor.
V8, Dawn, Skia, ANGLE, and Chromium's CSS engine each produced confirmed-exploited vulnerabilities — ten total this year across five distinct browser subsystems.
Use-after-free, memory corruption, integer overflow — nine Apple vulnerabilities spanning nearly a decade of disclosure dates were confirmed exploited across the company's full platform range.
CVE-2026-20131 in Cisco FMC carries CISA's confirmed ransomware flag — the second FMC vulnerability covered in this series, alongside new findings in Email Gateway, ASA/FTD, and Unified CM.
From a perfect-10 peering authentication bypass to CLI privilege escalation, seven distinct vulnerabilities across Cisco's SD-WAN Controller, Manager, and underlying software were confirmed exploited.
Nine local privilege-escalation and access-control vulnerabilities in Windows were confirmed exploited over the past year. None individually dramatic, together they define how far an intrusion spreads.
Security software is software first: two local privilege-escalation bugs and a denial-of-service flaw in Microsoft Defender itself were confirmed exploited in the wild.
Weekly insights on software supply chain security, delivered to your inbox.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.