Blog

EOL guides, CVE news, and upgrade paths for your stack.

CISA KEV July 2026: Every Critical Vulnerability Added This Month

July 9, 2026

CISA KEV July 2026: Every Critical Vulnerability Added This Month

CISA added 6 new vulnerabilities to its Known Exploited Vulnerabilities catalog in July 2026. Microsoft SharePoint, Langflow, Adobe ColdFusion and three Joomla extensions are actively being exploited right now.

EOLCanary TeamRead →
Critical CVEs June 2026: PTC Windchill, Cisco UCM, Ubiquiti UniFi Under Active Attack

July 7, 2026

Critical CVEs June 2026: PTC Windchill, Cisco UCM, Ubiquiti UniFi Under Active Attack

June 2026 closed with 6 new CISA KEV additions in a single week. PTC Windchill RCE (CVSS 9.3), Cisco UCM SSRF, and three Ubiquiti UniFi vulnerabilities are being actively exploited. Here is the full breakdown.

EOLCanary TeamRead →
Most Exploited CVEs in H1 2026: What Attackers Actually Targeted

July 5, 2026

Most Exploited CVEs in H1 2026: What Attackers Actually Targeted

The first half of 2026 saw ransomware groups and state-sponsored actors concentrate on enterprise platforms with broad administrative reach. SharePoint, Cisco UCM, Windchill, Langflow — here is the full picture.

EOLCanary TeamRead →
SharePoint CVE-2026-45659: RCE Exploit, Warlock Ransomware, and How to Patch

July 3, 2026

SharePoint CVE-2026-45659: RCE Exploit, Warlock Ransomware, and How to Patch

CVE-2026-45659 in Microsoft SharePoint Server is being actively exploited by the Storm-2603 ransomware group. Any authenticated user can trigger remote code execution. Here is everything your team needs to know.

EOLCanary TeamRead →
EOL Software and Compliance: What PCI-DSS and SOC2 Actually Require

June 24, 2026

EOL Software and Compliance: What PCI-DSS and SOC2 Actually Require

Running end-of-life software is not just a security risk — it is a compliance failure. Here is exactly what PCI-DSS 4.0 and SOC2 say about unsupported software versions.

EOLCanary TeamRead →
Node.js EOL History: Every Version, Every Date, Every CVE Count

June 21, 2026

Node.js EOL History: Every Version, Every Date, Every CVE Count

From Node.js 0.10 to Node.js 22, we mapped the complete end-of-life history of the JavaScript runtime and the CVE accumulation that followed each EOL date.

EOLCanary TeamRead →

11 articles — page 1 / 2