VulnTracker Blog
  • Home
  • About

Ali Dak

Ali Dak
FortiClient EMS Gets a Second Zero-Day in One Week — CVE-2026-35616 Is Already Being Exploited

Zero-Day

FortiClient EMS Gets a Second Zero-Day in One Week — CVE-2026-35616 Is Already Being Exploited

Same product, different vulnerability class, same outcome: unauthenticated RCE on your endpoint management server. Exploitation started Easter weekend.

By Ali Dak 06 Apr 2026
Cisco's Critical Week: IMC Auth Bypass and SSM RCE — Both at CVSS 9.8

Security Alert

Cisco's Critical Week: IMC Auth Bypass and SSM RCE — Both at CVSS 9.8

Two CVSS 9.8 vulnerabilities hit Cisco management infrastructure. IMC auth bypass lets attackers take over any admin account. SSM On-Prem gives unauthenticated root access. Neither requires credentials.

By Ali Dak 03 Apr 2026
The Axios Supply Chain Attack: How North Korea Hijacked npm's Most Popular HTTP Client

Supply Chain

The Axios Supply Chain Attack: How North Korea Hijacked npm's Most Popular HTTP Client

For two hours on March 31, anyone who ran npm install axios got a North Korean RAT. The real package, the real registry, the real maintainer account — compromised.

By Ali Dak 02 Apr 2026
CVE-2026-21643: FortiClient EMS Critical SQL Injection — Actively Exploited, No Credentials Required

Security Alert

CVE-2026-21643: FortiClient EMS Critical SQL Injection — Actively Exploited, No Credentials Required

A critical SQL injection in FortiClient EMS 7.4.4 allows unauthenticated attackers to dump admin credentials, endpoint data, and certificates with a single HTTP request. Active exploitation confirmed.

By Ali Dak 31 Mar 2026
Chrome 146 Emergency Update: 8 High-Severity Vulnerabilities That Could Compromise Your Browser

Security Alert

Chrome 146 Emergency Update: 8 High-Severity Vulnerabilities That Could Compromise Your Browser

Google just released an urgent Chrome update patching eight high-severity vulnerabilities — all capable of enabling remote code execution, targeting GPU, audio, fonts, and federated auth components.

By Ali Dak 25 Mar 2026
One Week, Nine Vulnerabilities: OpenClaw's Security Meltdown Should Terrify Every Organization

Security Alert

One Week, Nine Vulnerabilities: OpenClaw's Security Meltdown Should Terrify Every Organization

Between March 12-19, 2026, OpenClaw had 9 high-severity CVEs published — more than one critical flaw per day. This isn't a bad week. It's a systemic security architecture failure.

By Ali Dak 20 Mar 2026
CVE-2026-3888: Ubuntu's Snap Sandbox Has a Ticking Time Bomb — Here's What You Need to Know

Security Alert

CVE-2026-3888: Ubuntu's Snap Sandbox Has a Ticking Time Bomb — Here's What You Need to Know

A high-severity vulnerability (CVSS 7.8) in Ubuntu Desktop 24.04+ allows any unprivileged local user to gain full root access. The exploit abuses a timing gap between snap-confine and systemd-tmpfiles — no memory corruption, no kernel exploit, just patience.

By Ali Dak 18 Mar 2026
Your Google Maps API Key Might Now Be a Gemini Credential — Here's What Happened

Security Alert

Your Google Maps API Key Might Now Be a Gemini Credential — Here's What Happened

Google API keys deployed years ago for Maps and Firebase now silently authenticate to Gemini endpoints. Over 2,800 live keys were found exposed on the public internet — belonging to financial institutions, security companies, and Google itself.

By Ali Dak 28 Feb 2026
Chrome Zero-Day CVE-2026-2441: Use-After-Free in CSS Enables Remote Code Execution

Security Alert

Chrome Zero-Day CVE-2026-2441: Use-After-Free in CSS Enables Remote Code Execution

A high-severity use-after-free vulnerability in Google Chrome's CSS engine (CVE-2026-2441) is being actively exploited. All Chromium-based browsers are affected — including headless deployments used in CI/CD pipelines and PDF generation services.

By Ali Dak 24 Feb 2026
Palo Alto PAN-OS Vulnerability (CVE-2026-0229) Can Trigger Firewall Reboot Loops

Security Alert

Palo Alto PAN-OS Vulnerability (CVE-2026-0229) Can Trigger Firewall Reboot Loops

A denial-of-service vulnerability in PAN-OS Advanced DNS Security (CVE-2026-0229) allows unauthenticated attackers to force firewalls into repeated reboot cycles, potentially pushing them into maintenance mode. Upgrade affected PAN-OS versions immediately.

By Ali Dak 13 Feb 2026
FortiCloud SSO Bypass (CVE-2026-24858): Active Exploitation and What You Need to Know

Security Alert

FortiCloud SSO Bypass (CVE-2026-24858): Active Exploitation and What You Need to Know

A critical authentication bypass in FortiCloud SSO (CVE-2026-24858, CVSS 9.4) is being actively exploited. Attackers with any FortiCloud account can potentially access devices belonging to other organizations. Patch immediately and audit your admin accounts.

By Ali Dak 28 Jan 2026
MongoBleed - CVE-2025-14847: The Vulnerability Isn't the Hard Part — Tracking It Is

Security

MongoBleed - CVE-2025-14847: The Vulnerability Isn't the Hard Part — Tracking It Is

When a new CVE like CVE-2025-14847 is published, the expectation is clear: teams should review it, assess impact, and take action if necessary. In reality, the hardest part usually isn't patching or mitigation...

By Ali Dak 03 Jan 2026
See all
VulnTracker Blog
  • Sign up
Powered by Ghost