New at Horizon3

Resource Center

Welcome to our cybersecurity resource center where we uncover how malicious actors exploit weaknesses in systems, while going beyond the technical aspects and examining real-world perspectives across various industries.

LATEST VULNERABILITIES

Bomb Streamline Icon: https://streamlinehq.com

 CVE-2026-9181

CVE-2026-9181 is a critical path traversal vulnerability affecting Esri ArcGIS Server that could allow unauthenticated attackers to access sensitive files. Validate exposure with NodeZero® Rapid Response.
Read More →
Bomb Streamline Icon: https://streamlinehq.com

CVE-2026-48283 / CVE-2026-48313

CVE-2026-48283 / CVE-2026-48313: Adobe ColdFusion Pre-Authentication Unrestricted File Upload and Path Traversal Vulnerabilities
Read More →

SEARCH

CATEGORIES

TAGS

SEARCH

    CVE-2026-47729

    June 24, 2026
    CVE-2026-47729 (Squidbleed) can expose credentials, cookies, API keys, and session tokens from memory in vulnerable Squid proxy deployments.

    Autonomy Is Earned, Not Claimed

    June 17, 2026
    After more than 250,000 production pentests, Horizon3 explores why trust, reliability, exploitability, and verification matter more than autonomous security claims.

    CVE-2026-50751

    June 16, 2026
    CVE-2026-50751 is an authentication bypass vulnerability affecting Check Point Security Gateway VPN services. Check Point has confirmed active exploitation against vulnerable deployments.

    CVE-2026-20253

    June 16, 2026
    CVE-2026-20253 is a critical unauthenticated arbitrary file write vulnerability affecting Splunk Enterprise. The flaw may allow attackers to create or truncate files and potentially achieve remote code execution.

    CVE-2026-48558

    June 15, 2026
    CVE-2026-48558 is an authentication bypass vulnerability affecting SimpleHelp OIDC deployments. The flaw may allow attackers to create unauthorized Technician accounts and gain privileged access to managed endpoints.

    AI-Accelerated Exploitation: The Mythos-Era Threat Model

    June 13, 2026
    AI models like Mythos collapse the gap between discovery and exploitation. Learn how to rethink your threat model before attackers do.

    CVE-2026-35273

    June 12, 2026
    CVE-2026-35273 is a critical unauthenticated remote code execution vulnerability affecting Oracle PeopleSoft PeopleTools. Threat intelligence confirms active exploitation by ShinyHunters prior to disclosure.

    CVE-2026-48558: SimpleHelp Authentication Bypass Indicators of Compromise

    June 12, 2026
    Horizon3 details indicators of compromise, affected configurations, and mitigation guidance for CVE-2026-48558, a SimpleHelp OIDC authentication bypass vulnerability.

    AI-Powered Exploit Generation: Speed, Scale & Cyber Risk

    June 12, 2026
    Learn how AI-powered exploit generation collapses the discovery-to-impact gap, accelerates attack chains, and why exploitability-first validation is now essential.

    CVE-2026-10520

    June 11, 2026
    CVE-2026-10520 is a critical pre-authenticated OS command injection vulnerability in Ivanti Sentry that allows remote attackers to execute arbitrary commands as root.