U.S. CISA adds a flaw in Palo Alto Networks PAN-OS to its Known Exploited Vulnerabilities catalog
2026-05-07T08:51:56Z•9ef7b9318af2f140c175028e4c0fad595aba9d91b43b37905a64605edaea1540
AndroidAnodotApache HTTP ServerCISACVE-2026-0073CVE-2026-0300CVE-2026-23918Chaos RansomwareGavril SanduKarakurtKnown Exploited VulnerabilitiesMuddyWaterPAN-OSPalo Alto NetworksPyPIPyTorch LightningTaiwan High-Speed RailVimeocybercrimeextraditionrail securityransomwaresupply chainthird-party breach
What happened
Feed highlights multiple high‑impact security incidents and advisories: CISA added Palo Alto Networks PAN‑OS buffer‑overflow (CVE‑2026‑0300, CVSS 9.3) to its Known Exploited Vulnerabilities catalog amid active unauthenticated RCE exploitation; Apache HTTP Server patched a critical HTTP/2 double‑free RCE (CVE‑2026‑23918, CVSS 8.8); Google fixed a critical Android System RCE (CVE‑2026‑0073). Other notable items include a malicious PyTorch Lightning PyPI publish that briefly stole credentials (AI supply‑chain compromise), an Iran‑linked MuddyWater campaign using ransomware‑style tactics to mask (
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 9ef7b9318af2f140c175028e4c0fad595aba9d91b43b37905a64605edaea1540
- Enrichment time
- 2026-05-07T08:51:56Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.