Archive
All articles, newest first. Page 14.

Italy as Both Client and Target: The Graphite Case Exposes the Limits of Spyware
On July 18, 2026, forensic investigator Luca Cadonici presented a comprehensive reconstruction of the Graphite case at the Cyber Crime…

AsyncAPI: The Supply Chain That Trusted Its Own Signatures
On July 14, 2026, an attacker compromised the AsyncAPI release pipeline. Five malicious versions of four npm packages, with over two m…

Patch Day: Mozilla Confirms Public Exploits for Firefox as Adobe and VMware Ship CVSS 9+ Fixes
On July 15, 2026, four vendors released critical updates simultaneously. Mozilla broke with standard practice by explicitly confirming…

LegacyHive: Nightmare Eclipse's Ninth Zero-Day Pierces Fully Patched Windows
Nightmare Eclipse has released LegacyHive, a zero-day exploit targeting the Windows User Profile Service to load arbitrary registry hi…

Three Chained Zero-Days in Siemens Switches: From xz Utility to Root Access
Three zero-day vulnerabilities in Siemens RUGGEDCOM ROX II switches enable full privilege escalation and persistent root access. Firmw…

CVE-2026-40400: RCE in PowerShell via Help File, Patch Available
ZDI-26-414 discloses a directory traversal flaw in PowerShell help file parsing that leads to remote code execution with user interact…

CVE-2026-42533: Heap Buffer Overflow in NGINX Spans 15 Years of Versions
A heap buffer overflow in NGINX's two-pass scripting engine puts 15 years of releases at risk. The patch landed July 15, 2026; F5 cond…

Zoom Patches CVE-2026-53412: Critical Remote Account Takeover on Windows, CVSS 9.8
Zoom has patched a critical vulnerability in its Windows client that allows unauthenticated, zero-interaction account takeover. The fl…

SharePoint: Patch for CVE-2026-55126, an Authenticated XSS Rated CVSS 8.1
Microsoft has fixed an XSS vulnerability in SharePoint's SPFieldMultiLineText class. The CVSS 8.1 score and ease of remote exploitatio…

Cisco ISE Authenticated Directory Traversal (CVE-2026-20146) Exposes System Files
A directory traversal flaw in Cisco Identity Services Engine lets authenticated attackers read sensitive files. The vulnerability, rat…

SharePoint Critical RCE via Cryptographic Signature Flaw: The Token Danger
CVE-2026-50522 enables unauthenticated remote code execution on SharePoint Server by bypassing cryptographic verification on session t…

SharePoint On-Premises Under Attack: Three Days to Patch Actively Exploited RCE
Microsoft confirmed active exploitation of CVE-2026-58644 in SharePoint Server on-premises. CISA added the flaw to the KEV catalog wit…

Delta Electronics DTM Soft: Project BIN Files Become RCE Attack Vector
The ZDI-26-404 flaw in Delta Electronics DTM Soft industrial engineering software enables remote code execution via deserialization of…

X.Org Server: GLX Use-After-Free Bug Enables Local Root Escalation on Linux
A use-after-free vulnerability in the CommonMakeCurrent function allows a local attacker to escalate privileges to root. The flaw was…

Windows WMI: ZDI-26-415 Vulnerability Allows Escalation to SYSTEM
CVE-2026-49805 in Windows WMI Providers enables local privilege escalation to SYSTEM. Microsoft has released patches and rates exploit…

ZDI-26-416: Hyper-V netvsc.sys Bug Lets Local VM Attacker Escalate to Kernel
The ZDI-26-416 vulnerability in Microsoft Hyper-V's netvsc.sys driver allows a low-privilege attacker inside a Windows VM to escalate…

Adobe Creative Cloud Update Service Turned Into Privilege Escalation Weapon
ZDI-26-419 reveals a vulnerability in AdobeUpdateService that allows local privilege escalation from low-privilege user to SYSTEM on W…

MSI Center: LPE Vulnerability in NTIOLib_X64.sys Kernel Driver
ZDI-26-430 discloses a local privilege escalation to SYSTEM in the NTIOLib_X64.sys driver used by MSI Center. The flaw affects OEM har…

Synology DS925+: Pre-Auth Root RCE via Weak Redis Passwords — Patch Available
ZDI-26-423 discloses a pre-authentication vulnerability in the MailPlus Redis component of the Synology DiskStation DS925+. Reversible…

NVIDIA NeMo Framework: RCE Vulnerability in ML Checkpoints
An unsafe deserialization flaw in NVIDIA NeMo Framework checkpoints enables remote code execution. User interaction is required, but t…

G DATA Total Security: LPE in Backup Service, SYSTEM Compromised via Symlink
ZDI-26-432 (CVE-2026-13268, CVSS 7.8) details a symbolic link following attack in the G DATA Total Security Backup Service. Here is th…

ZDI-26-438: RCE in Rockwell Arena Simulation via DOE File, Patch Available
The ZDI-26-438 vulnerability enables remote code execution in Rockwell Automation Arena Simulation through malicious DOE files. Coordi…

OpenSSL: Double-Free in OCSP Stapling — The Gap Between Theoretical Risk and Official Rating
CVE-2026-35188 is a double-free in OpenSSL's OCSP stapling verification. ZDI calls it RCE; the official CVE record rates it Moderate.…

7-Zip XZ Parser RCE Vulnerability: Opening an Archive Is Enough
A heap-based buffer overflow in 7-Zip's XZ parser enables remote code execution. The flaw, tracked as ZDI-26-444 and CVE-2026-14266, t…