VulnTracker Blog
  • Home
  • About

Kaan Koç

CVE-2026-65414: Apple's CVSS 9.8 Bluetooth Bug, and Why "Network" Doesn't Mean Internet

CVE

CVE-2026-65414: Apple's CVSS 9.8 Bluetooth Bug, and Why "Network" Doesn't Mean Internet

CVE-2026-65414 is a CVSS 9.8 out-of-bounds write in Apple's Bluetooth stack, patched across iOS, macOS, watchOS, tvOS, and visionOS. No known exploitation yet, but the CVSS "Network" label is easy to misread.

By Kaan Koç 16 Sep 2026
CVE-2026-76461: A Root RCE in Cisco Secure Email Gateway, Already Exploited as a Zero-Day

CVE

CVE-2026-76461: A Root RCE in Cisco Secure Email Gateway, Already Exploited as a Zero-Day

CVE-2026-76461 lets an unauthenticated attacker reach root on Cisco Secure Email Gateway with nothing but a crafted email. Cisco found it while investigating an active intrusion, not before one.

By Kaan Koç 15 Sep 2026
CVE-2026-85706: A CVSS 10 Path Traversal in GitLab's Commits API, Now in CISA's KEV Catalog

CVE

CVE-2026-85706: A CVSS 10 Path Traversal in GitLab's Commits API, Now in CISA's KEV Catalog

CVE-2026-85706, a path traversal flaw in GitLab's commits API, hit CVSS 10.0 and CISA's KEV catalog within a day. But there's one exposure condition that determines whether your instance is actually at risk.

By Kaan Koç 12 Sep 2026
VulnTracker Blog
  • Sign up
Powered by Ghost