New at Horizon3

Resource Center

Welcome to our cybersecurity resource center where we uncover how malicious actors exploit weaknesses in systems, while going beyond the technical aspects and examining real-world perspectives across various industries.

LATEST VULNERABILITIES

Bomb Streamline Icon: https://streamlinehq.com

CVE-2026-23734

CVE-2026-23734 is a critical path traversal vulnerability affecting XWiki’s xwiki-commons-classloader-api component. The flaw may allow unauthenticated attackers to access sensitive configuration files through crafted ssx and jsx endpoint requests.
Read More →
Bomb Streamline Icon: https://streamlinehq.com

CVE-2026-44578

CVE-2026-44578 is a high-severity server-side request forgery vulnerability affecting self-hosted Next.js applications using the built-in Node.js server.
Read More →

WEBINAR REPLAY

SEARCH

CATEGORIES

TAGS

SEARCH

    CVE-2025-11250

    January 15, 2026
    ManageEngine ADSelfService Plus Authentication Bypass

    CVE-2025-37164

    January 14, 2026
    HPE OneView Remote Code Execution Vulnerability | CISA KEV

    From Patch Tuesday to Pentest Wednesday®: When Proving Compliance Becomes Cyber Resilience

    January 14, 2026
    A Pentest Wednesday® story showing how one of the world’s largest payments providers replaced point-in-time compliance testing with continuous, attacker-aligned validation.

    CVE-2025-64155 | Fortinet FortiSIEM

    January 13, 2026
    Fortinet FortiSIEM Arbitrary File Write Remote Code Execution Vulnerability

    CVE-2025-64155: Three Years of Remotely Rooting the Fortinet FortiSIEM

    January 13, 2026
    CVE-2025-64155 chains argument injection and privilege escalation flaws in FortiSIEM to achieve remote root compromise.

    CVE-2026-22200

    January 12, 2026
    osTicket PHP Filter Chain Injection Vulnerability

    CVE-2025-52691

    January 12, 2026
    SmarterTools SmarterMail Remote Code Execution via Unauthenticated Arbitrary File Upload | Critical

    From Honeypots to Active Directory Tripwires

    January 9, 2026
    Traditional deception tools promised high signal but failed at scale. This page explores how NodeZero® Active Directory Tripwires transform deception into a practical, enterprise-ready detection strategy—using real attacker behavior to deliver early, high-fidelity alerts where identity attacks matter most.

    The Ni8mare Test: n8n RCE Under the Microscope (CVE-2026-21858)

    CVE-2026-21858, the so-called “Ni8mare” n8n RCE, drew significant attention—but real-world impact appears limited. Horizon3 breaks down the technical prerequisites, observed exposure, and why most organizations are unlikely to be affected.

    CVE-2025-14847

    January 6, 2026
    MongoDB Server Uninitialized Heap Memory Disclosure (MongoBleed) | Active Exploitation