VulnTracker Blog
  • Home
  • About

Ali Dak

Ali Dak
MikroTik RouterOS Under Active Attack (CVE-2026-86060): When There's No CVSS Score to Wait For

Security Alert

MikroTik RouterOS Under Active Attack (CVE-2026-86060): When There's No CVSS Score to Wait For

MikroTik RouterOS is being actively exploited, and CVE-2026-86060 is in the CISA KEV catalog. Here is the interesting part for anyone who prioritizes by severity score: at the time of writing, this CVE has no CVSS score. NVD has not analyzed it yet. If your triage process starts with "

By Ali Dak 11 Sep 2026
Redis TLS Use-After-Free (CVE-2026-81934): A Case Study in Reading Severity Correctly

Guide

Redis TLS Use-After-Free (CVE-2026-81934): A Case Study in Reading Severity Correctly

CVE-2026-81934 is a use-after-free in Redis that was first published as a CVSS 9.8 Critical, then reassessed down to High once the real exploitation conditions were weighed. It's a clean lesson in why the number on a CVE is a starting point, not the answer.

By Ali Dak 03 Sep 2026
Windows 11 KB5120998: What a Non-Security Preview Update Still Means for Security Teams

Guide

Windows 11 KB5120998: What a Non-Security Preview Update Still Means for Security Teams

KB5120998 is an optional, non-security preview for Windows 11 24H2 and 25H2 — no CVE fixes. But two changes matter to security teams: Administrator Protection starts rolling out, and WMIC is finally removed. Here's what to pilot and what to weigh before deploying.

By Ali Dak 31 Aug 2026
Metabase Pre-Auth SQL Injection (CVE-2026-72898): CVSS 10.0, Actively Exploited

Security Alert

Metabase Pre-Auth SQL Injection (CVE-2026-72898): CVSS 10.0, Actively Exploited

CVE-2026-72898 is an unauthenticated SQL injection in Metabase, scored CVSS 10.0 and already in CISA KEV. One request to /api/session/reset_password gives an attacker admin access and the credentials for every connected database. If you run Metabase, patch today.

By Ali Dak 27 Aug 2026
PostgreSQL to_char Heap Buffer Overflow (CVE-2026-14669): What It Is and How to Read It Fast

Security Alert

PostgreSQL to_char Heap Buffer Overflow (CVE-2026-14669): What It Is and How to Read It Fast

CVE-2026-14669 is a CVSS 8.8 HIGH heap buffer overflow in PostgreSQL's to_char function that can run arbitrary code as the database OS user, patched August 13, 2026. Two questions decide your workload: is Postgres in your stack, and is your version older than 18.5 / 17.11 / 16.15 / 15.19 / 14.24?

By Ali Dak 25 Aug 2026
Critical and Already Being Exploited: PAN-OS GlobalProtect Auth Bypass (CVE-2026-0257)

Security Alert

Critical and Already Being Exploited: PAN-OS GlobalProtect Auth Bypass (CVE-2026-0257)

A 9.1 critical authentication bypass in PAN-OS GlobalProtect, actively exploited and now in CISA KEV. But it only bites under a specific config. The two questions that decide your workload: is the product in your stack, and does your config meet the exposure conditions?

By Ali Dak 02 Jun 2026
Palo Alto Firewall Has an Unpatched Critical RCE Today (CVE-2026-0300)

Security Alert

Palo Alto Firewall Has an Unpatched Critical RCE Today (CVE-2026-0300)

Active exploitation of an unauthenticated root RCE in PAN-OS firewalls. No patch until May 13. The one question your team needs to answer in the next two hours: is the User-ID Authentication Portal exposed to the internet?

By Ali Dak 06 May 2026
Copy Fail (CVE-2026-31431): An AI-Assisted Audit Surfaced a Linux Kernel Bug That Roots Every Distribution Since 2017

Security Alert

Copy Fail (CVE-2026-31431): An AI-Assisted Audit Surfaced a Linux Kernel Bug That Roots Every Distribution Since 2017

732-byte exploit. First-try root on every modern Linux distribution. Page-cache-only corruption that on-disk integrity tools miss. Crosses container boundaries. Surfaced by an AI-assisted audit in roughly an hour.

By Ali Dak 30 Apr 2026
What is a CVE? A Plain-English Guide for Engineering Teams

Guide

What is a CVE? A Plain-English Guide for Engineering Teams

A CVE is a license plate for vulnerabilities. You don't need to memorize acronyms — you need three things: how to tell if a CVE matters to you, what the score means, and what to do when one shows up in your stack.

By Ali Dak 27 Apr 2026
MCPwn: The nginx-ui Flaw That Exposes a Bigger Problem With MCP Adoption (CVE-2026-33032)

Security Alert

MCPwn: The nginx-ui Flaw That Exposes a Bigger Problem With MCP Adoption (CVE-2026-33032)

A 27-character omission gave any network-adjacent attacker full control over 2,689+ publicly exposed nginx servers. The real story: every other app bolting MCP onto existing auth stacks.

By Ali Dak 20 Apr 2026
Microsoft Patches Actively Exploited SharePoint Zero-Day in Massive April Update

Security Alert

Microsoft Patches Actively Exploited SharePoint Zero-Day in Massive April Update

CVE-2026-32201 allows unauthenticated spoofing on SharePoint Server. CISA added it to KEV immediately. Third SharePoint zero-day in under a year — ToolShell echoes loom large.

By Ali Dak 15 Apr 2026
Adobe Reader Zero-Day Exploited for Months Before Emergency Patch

Zero-Day

Adobe Reader Zero-Day Exploited for Months Before Emergency Patch

CVE-2026-34621 chains two logic bugs to escape Adobe Reader's sandbox — no memory corruption needed. Exploited since December 2025, patched April 11. Russian-language lures targeting oil & gas sector.

By Ali Dak 13 Apr 2026
See all
VulnTracker Blog
  • Sign up
Powered by Ghost