<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CVE on Lynx Tech Blog</title><link>https://blog.lynxflow.co/en/tags/cve/</link><description>Recent content in CVE on Lynx Tech Blog</description><generator>Hugo -- gohugo.io</generator><language>en</language><lastBuildDate>Wed, 02 Sep 2026 01:00:00 +0800</lastBuildDate><atom:link href="https://blog.lynxflow.co/en/tags/cve/index.xml" rel="self" type="application/rss+xml"/><item><title>How a Monitoring Probe Became a Master Key: The Nezha Panel Compromise, Retraced in Full, with a Cross-Domain Table of Major Vulnerabilities</title><link>https://blog.lynxflow.co/en/posts/nezha-probe-panel-takeover-vuln-history/</link><pubDate>Wed, 02 Sep 2026 01:00:00 +0800</pubDate><guid>https://blog.lynxflow.co/en/posts/nezha-probe-panel-takeover-vuln-history/</guid><description>&lt;img src="https://blog.lynxflow.co/images/nezha-probe-panel-takeover-vuln-history.png?v=090818" alt="Featured image of post How a Monitoring Probe Became a Master Key: The Nezha Panel Compromise, Retraced in Full, with a Cross-Domain Table of Major Vulnerabilities" /&gt;Introduction: the official list it never made In November 2021, the U.S. government opened a special catalog: every vulnerability &amp;ldquo;proven to be used in real attacks&amp;rdquo; would be recorded there, and federal agencies would be ordered to patch on a deadline. It&amp;rsquo;s called CISA KEV — the Known Exploited Vulnerabilities catalog. (For the terminology — what CVE/KEV actually mean and where they come from, see this site&amp;rsquo;s explainer.) As of the August 31, 2026 release, KEV holds 1,687</description></item><item><title>The Secret Language of the Vulnerability World: 0day, 1day, nday, CVE, CNVD, NVD Explained</title><link>https://blog.lynxflow.co/en/posts/vulnerability-jargon-0day-cve-cnvd-nvd/</link><pubDate>Tue, 01 Sep 2026 11:00:00 +0800</pubDate><guid>https://blog.lynxflow.co/en/posts/vulnerability-jargon-0day-cve-cnvd-nvd/</guid><description>&lt;img src="https://blog.lynxflow.co/images/vuln-jargon-cover.png" alt="Featured image of post The Secret Language of the Vulnerability World: 0day, 1day, nday, CVE, CNVD, NVD Explained" /&gt;Log4Shell and the Vocabulary of Vulnerabilities: A Fact-Check and Field Guide Late on the night of December 9, 2021, Alibaba Cloud&amp;rsquo;s security team publicly disclosed a remote code execution vulnerability in the Java logging library Log4j (CVE-2021-44228), forcing engineers across half the internet to crawl out of bed on a weekend and work overtime on emergency response. &amp;ldquo;Log4Shell&amp;rdquo; thus became the most famous vulnerability storm of the past decade: Check Point&amp;rsquo;s monitorin</description></item></channel></rss>