Vulnerabilities are weaknesses or flaws in systems, software, hardware, configurations, or processes that adversaries can exploit to compromise confidentiality, integrity, or availability. The concept underpins vulnerability management, regulatory compliance, risk assessment, and security investment decisions across enterprise IT, cloud, and operational technology environments.
CISA’s update on CVE-2026-10629 says Verizon IMS SIP signaling for VoLTE omits IPsec ESP integrity, leaving REGISTER, INVITE, MESSAGE, BYE, and UPDATE traffic unprotected. The advisory cites expected 3GPP TS 33.203 and GSMA IR.92 behavior and notes Verizon’s “currently available” integrity support statement for later rollout.
Proofpoint announced Active Exploits Protection, a solution that uses Proofpoint telemetry to identify vulnerabilities actively exploited in the wild and translate that intelligence into rapid, automated protections across primary attack paths. The company cites time-to-protection metrics, detection precision, SOC integration, and API access, and states global availability.
JupiterOne launched AI Attack Surface Management (AI ASM) and Unified Vulnerability Management (UVM) to provide relationship-aware asset and vulnerability context.
Casdoor’s Local File System provider lets authenticated upload users traverse paths and write arbitrary files outside $CASDOOR/files/ via /api/upload-resource.