VPSVaultVPSVault
Browse allStreaming optimizedDedicated serversVPS hosting
Knowledge base
Sign inRegister
VPSVaultVPSVault

High-performance VPS, dedicated servers, and managed hosting.

Network status

Help

  • Knowledge base
  • Open a ticket
  • [email protected]

Community

  • Telegram @VpsVaultHostt
Join the group

© 2026 VPSVault. All rights reserved.

·AS215925
  • Privacy
  • Terms
  • Fair use

Feed updates every 3 hours

Security advisories

Vulnerabilities being exploited in the wild against the software people actually run on a server. We publish what is affected and the exact version that fixes it — never how to exploit it.

Sources
CISA KEV · EPSS · OSV · GitHub
Selected on
Exploited & server-relevant
Published
3

Actively exploited — patch these first

  • ExploitedCVE-2026-9586SwitchvoxCVSS 9.312%2 Sept

    Sangoma Switchvox SQL Injection Vulnerability

    Unauthenticated SQL injection in Sangoma Switchvox allows remote code execution; confirmed exploited in the wild, no patch yet — restrict network access now.

  • ExploitedCVE-2026-73570Zimbra Collaboration Suite (ZCS)CVSS 8.932%31 Aug

    Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

    Zimbra Collaboration Suite has a confirmed exploited command injection flaw in its SMTP handling, allowing unauthenticated code execution. Patch to 10.1.20 now.

  • ExploitedCVE-2026-60004GiteaCVSS 9.887%30 Aug

    Gitea Code Injection Vulnerability

    Gitea has a critical code injection flaw, confirmed exploited, letting attackers with repo write access run commands as the service account. Patch to 1.27.1 now.

How we choose what to publish

There were more than 40,000 CVEs published last year. Almost none of them matter to someone running a Linux server, and a feed that repeats all of them is noise. We publish a vulnerability only when it clears a gate that runs on every ingest:

  • Confirmed exploitation. Listed in CISA’s Known Exploited Vulnerabilities catalogue, or carrying an EPSS score high enough to expect opportunistic scanning. EPSS models the probability of exploitation in the next 30 days, and it predicts real-world attack far better than severity alone does.
  • Reachable and unauthenticated. We read the CVSS vector rather than the headline: network attack vector, no privileges, no user interaction. That combination is what automated botnet scanning sweeps up within days of a public exploit.
  • Server-relevant. Software people actually run on a VPS. A flaw in a desktop application is not our readers’ problem, however severe it scores.

Where the fix versions come from

Every version number on this site is looked up from OSV.dev and the GitHub Advisory Database, then rendered from that record — never written as prose. A wrong upgrade command in a security advisory is worse than no advisory at all, so the remediation table and the article text come from different places by design. Where no fixed version has been published yet, we say so rather than guessing.

What we deliberately leave out

No exploit code, no proof-of-concept, and no detail sufficient to reproduce an attack. We describe where a flaw lives, because that is what lets you judge your own exposure, and we stop there. Our readers are the people patching these systems, not the people scanning for them.

Vulnerability data from the CISA Known Exploited Vulnerabilities catalogue (CC0), the CVE Program (© MITRE, used under the CVE Terms of Use), EPSS by FIRST, OSV.dev (CC BY 4.0) and the GitHub Advisory Database (CC BY 4.0). This product uses the NVD API but is not endorsed or certified by the NVD.