CPEs, Known Affected Configurations, Affected Products… what exactly is the difference? 🤔 We take a closer look at how these pieces fit together — and what they mean for vulnerability matching. basefortify.eu/posts/2026/1... #NVD #CVE #CyberSecurity
BaseFortify.eu
@basefortify.bsky.social
🔐 BaseFortify.eu We show you which vulnerabilities actually affect YOUR systems. No noise. No endless CVE lists. Just clear, actionable risk. → Know what to patch. First. #CyberSecurity #SMB #InfoSec
🚨 Two critical Citrix NetScaler zero-days are under active exploitation. CVE-2026-88771 & CVE-2026-88772 both score 9.5 — and attackers were active before patches arrived. Our guide 👇 basefortify.eu/posts/2026/0... #Citrix #NetScaler #CyberSecurity
🚨 Microsoft just delivered a record-breaking Patch Tuesday: 974 unique vulnerabilities fixed in September. More than 100 are Critical — and two Windows vulnerabilities were already being exploited. basefortify.eu/posts/2026/0... #CyberSecurity #PatchTuesday #Microsoft
🚨 Google fixed 38 Chrome security vulnerabilities in just a few days — and one is already being actively exploited. CVE-2026-85046 affects the V8 JavaScript engine and can enable code execution inside the browser sandbox. basefortify.eu/posts/2026/0... #CyberSecurity #Chrome #CVE
🚨 Dutch NCSC warns about CVE-2026-18963, a critical Keycloak password-reset vulnerability. 🔐 Affected systems may be exposed to unauthenticated account takeover. What to check and how to fix it: basefortify.eu/posts/2026/0... #Keycloak #CyberSecurity
🚨 Serious CVE disclosures are surging. But does that mean software is suddenly less secure? Our latest article looks beyond the headline numbers — and at why vulnerability management must change. 🔗 basefortify.eu/posts/2026/0... #CyberSecurity #CVE
🎉 We've reached 200 followers on Bluesky! Thank you all for your support. 💙 At BaseFortify we help security professionals stay ahead with real-time CVE tracking, threat intelligence, exploit insights & cybersecurity news. Sign up for free: basefortify.eu #CyberSecurity #InfoSec #ThreatIntel #CVE
🚨 Cisco has confirmed active exploitation of CVE-2026-20316, a hardcoded credential vulnerability affecting Secure Firewall Management Center. We've published a summary and analysis: basefortify.eu/posts/2026/0... 🔐🛡️ #CyberSecurity #Cisco #InfoSec #CVE202620316
Cisco Warns of Active Exploitation of Hardcoded Password Vulnerability in Secure Firewall Management Center
After a short summer break, we're back with our regular cybersecurity updates. Unfortunately, the first major advisory upon our return concerns an actively expl...
basefortify.eu
🚨 A vulnerability in Microsoft Defender is now reportedly being used in ransomware attacks. CVE-2026-33825 evolved quickly from a local privilege escalation issue into a much more operationally significant threat. 👇 basefortify.eu/posts/2026/0... #CyberSecurity #Microsoft #Ransomware #CVE
🚨 Cisco is urging organizations to patch CVE-2026-20230 after reports of active exploitation against Unified Communications Manager. Public exploit code is online and the EPSS score jumped sharply after attack reports surfaced. 👇 basefortify.eu/posts/2026/0... #CyberSecurity #Cisco #CVE #InfoSec
⚠️ Not every CVE is actively exploited. CISA’s KEV Catalog highlights vulnerabilities that are already being used in real-world attacks. That makes KEV one of the most important signals for prioritization. #CyberSecurity #KEV #CVE basefortify.eu/cve_reports
🛡️ Over the last few years vulnerability management moved beyond just CVSS scores. Now CISA’s BOD 26-04 introduces a more systematic risk-based approach using KEV, exposure, exploitability, and technical impact 👇 basefortify.eu/posts/2026/0... #CyberSecurity #VulnerabilityManagement #CISA #InfoSec
🇪🇺 Can Nextcloud become a real alternative to Microsoft 365 for governments and businesses? Digital sovereignty is important — but sovereignty does not automatically equal security. Read our latest article 👇 basefortify.eu/posts/2026/0... #CyberSecurity #Nextcloud #Microsoft365 #DigitalSovereignty
📈 CVSS tells you how severe a vulnerability is. EPSS answers a different question: 👉 “How likely is this vulnerability to actually be exploited?” A rapidly increasing EPSS score can be an important signal for defenders prioritizing threats. #CyberSecurity #EPSS #CVE basefortify.eu/cve_reports
✨ We’ve refreshed the AI experience inside BaseFortify CVE reports. 🔹 AI Quick Actions 🔹 Improved Chat Assistant 🔹 Faster vulnerability explanations 🔹 Cleaner UI for mitigation & impact insights Try it yourself with any CVE: basefortify.eu/cve_reports #CyberSecurity #AI #CVE
🚨 CVSS scores are everywhere in cybersecurity. But what do they actually mean? CVSS measures the technical severity of a vulnerability from 0–10. It helps prioritize large numbers of CVEs. Useful? Absolutely. The full picture? Not always. #CyberSecurity #CVE #CVSS basefortify.eu/cves
🚨 Anthropic’s Mythos and Project Glasswing reportedly uncovered 10,000+ vulnerabilities in weeks. But what happens when AI vulnerability discovery becomes industrialized? New article by BaseFortify: basefortify.eu/posts/2026/0... #CyberSecurity #AI #Mythos #Anthropic #ProjectGlasswing
🚨 OTRS users should take note of CVE-2026-48188 A critical unauthenticated SQL injection vulnerability may allow authentication bypass under specific MySQL/MariaDB configurations. 🎫 Affects multiple OTRS generations and Community Edition. 🔗 basefortify.eu/cve_reports/... #OTRS #SQLInjection #CVE
🚨 Critical SQL injection flaw in dotCMS Core: CVE-2026-8054 (CVSS 10.0) Unauthenticated attackers can read, modify, or destroy database content through exposed Publish Audit API endpoints. 🔗 basefortify.eu/cve_reports/... #CVE #dotCMS #CyberSecurity
🚨 Critical WordPress flaw: CVE-2026-6279 impacts Avada Builder with unauthenticated remote code execution (CVSS 9.8). Attackers can abuse exposed AJAX functionality and unsafe PHP calls to fully compromise affected sites. 🔗 basefortify.eu/cve_reports/... #WordPress #CVE #CyberSecurity
🚨 Critical AI infrastructure flaw: CVE-2026-7304 affects SGLang runtimes with CVSS 9.8. Unsafe Python deserialization via dill.loads() can lead to unauthenticated remote code execution. 🔗 basefortify.eu/cve_reports/... #CVE #AI #CyberSecurity
🛡️ BaseFortify.eu was added to the awesome-hacker-search-engines GitHub list. Nice to see the platform included among many well-known security and vulnerability intelligence resources. 👏 #CyberSecurity #InfoSec #CVE #ThreatIntel
⚠️ A high-severity flaw in CVE-2026-35228 affects Oracle MCP Server Helper Tool (CVSS 8.7). Unauthenticated attackers can execute malicious SQL via HTTP. 🔗 basefortify.eu/cve_reports/... #CVE #CyberSecurity #Oracle
🚨 What if a Linux exploit never touched disk? Copy Fail (CVE-2026-31431) lets attackers become root by corrupting the page cache in memory. No file changes No integrity alerts Harder to detect CVSS 7.8 (High) 👉 basefortify.eu/posts/2026/0... #Linux #CyberSecurity #CopyFail
Yeah it was probably uncovered using AI scanning, I believe that is a positive thing but of course AI being used by bad actors will be bad.
Severe Linux Copy Fail security flaw uncovered using AI scanning help
🚨 Critical flaw in CVE-2026-42369 affects GeoVision GV-VMS V20 (CVSS 10.0). Unauthenticated attackers can gain full SYSTEM access via the WebCam Server. 🔗 basefortify.eu/cve_reports/... #CVE #CyberSecurity #GeoVision
🚀 We’ve switched from OpenAI to @MistralAI for BaseFortify.eu! Better sovereignty, transparency & performance. 🇪🇺 Read why: basefortify.eu/posts/2026/0... #Cybersecurity #AI #Privacy #Mistral
🎯 High severity XSS uncovered in GCHQ CyberChef ⚠️ A flaw in the “Show Base64 offsets” feature allows script injection via crafted input (CVE-2026-42615). 🔗 basefortify.eu/cve_reports/... #CyberSecurity #CVE #GCHQ #XSS
Do you actually know which vulnerabilities affect YOUR systems right now? Or are you just looking at CVE lists? That gap = real risk. Most teams don’t see it. #CyberSecurity #InfoSec