One cPanel account with mail rights could reach root on a shared server before this week's fix.
ConnectWise closed a ScreenConnect gap that let live sessions move and run files without consent.
Two GitLab flaws, one a perfect 10.0, drew automated probes within hours of the patch.
Three exploited networking flaws now carry a three-day federal patch deadline.
HPE's AOS-CX updates close 34 CVEs including a 9.8-rated unauthenticated RCE cluster.
Broadcom's 26H1u1 update closes two guest-to-host escape bugs with no workarounds available.
VulnCheck says KindaRails2Shell is under attack roughly a month after patches shipped.
CISA added six actively exploited flaws to KEV, including a Citrix NetScaler bug now under attack in the wild.