// 1 CRITICAL · 6 ZERO-DAY · 10 CVE · 11 EXPLOIT · 1 ADVISORY IN THE LAST 24H
CYBERSECEXPLOIT

Italy as Both Client and Target: The Graphite Case Exposes the Limits of Spyware

On July 18, 2026, forensic investigator Luca Cadonici presented a comprehensive reconstruction of the Graphite case at the Cyber Crime…

Jul 20, 2026views - 1.4k

CYBERSEC

AsyncAPI: The Supply Chain That Trusted Its Own Signatures

On July 14, 2026, an attacker compromised the AsyncAPI release pipeline. Five malicious versions of four npm packages, with over two m…

Jul 20, 2026views - 1.4k

CYBERSECEXPLOIT

Patch Day: Mozilla Confirms Public Exploits for Firefox as Adobe and VMware Ship CVSS 9+ Fixes

On July 15, 2026, four vendors released critical updates simultaneously. Mozilla broke with standard practice by explicitly confirming…

Jul 20, 2026views - 1.3k

zeroZERO-DAY

LegacyHive: Nightmare Eclipse's Ninth Zero-Day Pierces Fully Patched Windows

Nightmare Eclipse has released LegacyHive, a zero-day exploit targeting the Windows User Profile Service to load arbitrary registry hi…

Jul 20, 2026views - 1.4k

CYBERSECZERO-DAY

Three Chained Zero-Days in Siemens Switches: From xz Utility to Root Access

Three zero-day vulnerabilities in Siemens RUGGEDCOM ROX II switches enable full privilege escalation and persistent root access. Firmw…

Jul 20, 2026views - 1.2k

CYBERSECCVE

CVE-2026-40400: RCE in PowerShell via Help File, Patch Available

ZDI-26-414 discloses a directory traversal flaw in PowerShell help file parsing that leads to remote code execution with user interact…

Jul 20, 2026views - 1.3k

newsCVE

CVE-2026-42533: Heap Buffer Overflow in NGINX Spans 15 Years of Versions

A heap buffer overflow in NGINX's two-pass scripting engine puts 15 years of releases at risk. The patch landed July 15, 2026; F5 cond…

Jul 20, 2026views - 1.4k

CYBERSECCVE

Zoom Patches CVE-2026-53412: Critical Remote Account Takeover on Windows, CVSS 9.8

Zoom has patched a critical vulnerability in its Windows client that allows unauthenticated, zero-interaction account takeover. The fl…

Jul 20, 2026views - 1.5k

CYBERSECCVE

SharePoint: Patch for CVE-2026-55126, an Authenticated XSS Rated CVSS 8.1

Microsoft has fixed an XSS vulnerability in SharePoint's SPFieldMultiLineText class. The CVSS 8.1 score and ease of remote exploitatio…

Jul 20, 2026views - 1.5k

CYBERSECCVE

Cisco ISE Authenticated Directory Traversal (CVE-2026-20146) Exposes System Files

A directory traversal flaw in Cisco Identity Services Engine lets authenticated attackers read sensitive files. The vulnerability, rat…

Jul 20, 2026views - 1.4k

VULNCRITICAL

SharePoint Critical RCE via Cryptographic Signature Flaw: The Token Danger

CVE-2026-50522 enables unauthenticated remote code execution on SharePoint Server by bypassing cryptographic verification on session t…

Jul 17, 2026views - 1.4k

CYBERSECCRITICAL

SharePoint On-Premises Under Attack: Three Days to Patch Actively Exploited RCE

Microsoft confirmed active exploitation of CVE-2026-58644 in SharePoint Server on-premises. CISA added the flaw to the KEV catalog wit…

Jul 17, 2026views - 1.3k

CYBERSECCRITICAL

Delta Electronics DTM Soft: Project BIN Files Become RCE Attack Vector

The ZDI-26-404 flaw in Delta Electronics DTM Soft industrial engineering software enables remote code execution via deserialization of…

Jul 17, 2026views - 134

CYBERSEC

X.Org Server: GLX Use-After-Free Bug Enables Local Root Escalation on Linux

A use-after-free vulnerability in the CommonMakeCurrent function allows a local attacker to escalate privileges to root. The flaw was…

Jul 17, 2026views - 104

CYBERSEC

Windows WMI: ZDI-26-415 Vulnerability Allows Escalation to SYSTEM

CVE-2026-49805 in Windows WMI Providers enables local privilege escalation to SYSTEM. Microsoft has released patches and rates exploit…

Jul 17, 2026views - 1.4k

VULNZERO-DAY

ZDI-26-416: Hyper-V netvsc.sys Bug Lets Local VM Attacker Escalate to Kernel

The ZDI-26-416 vulnerability in Microsoft Hyper-V's netvsc.sys driver allows a low-privilege attacker inside a Windows VM to escalate…

Jul 17, 2026views - 1.6k

CYBERSEC

Adobe Creative Cloud Update Service Turned Into Privilege Escalation Weapon

ZDI-26-419 reveals a vulnerability in AdobeUpdateService that allows local privilege escalation from low-privilege user to SYSTEM on W…

Jul 16, 2026views - 1.3k

CYBERSECZERO-DAY

MSI Center: LPE Vulnerability in NTIOLib_X64.sys Kernel Driver

ZDI-26-430 discloses a local privilege escalation to SYSTEM in the NTIOLib_X64.sys driver used by MSI Center. The flaw affects OEM har…

Jul 16, 2026views - 1.5k

CYBERSECCRITICAL

Synology DS925+: Pre-Auth Root RCE via Weak Redis Passwords — Patch Available

ZDI-26-423 discloses a pre-authentication vulnerability in the MailPlus Redis component of the Synology DiskStation DS925+. Reversible…

Jul 16, 2026views - 1.5k

VULNCRITICAL

NVIDIA NeMo Framework: RCE Vulnerability in ML Checkpoints

An unsafe deserialization flaw in NVIDIA NeMo Framework checkpoints enables remote code execution. User interaction is required, but t…

Jul 16, 2026views - 1.3k

VULNZERO-DAY

G DATA Total Security: LPE in Backup Service, SYSTEM Compromised via Symlink

ZDI-26-432 (CVE-2026-13268, CVSS 7.8) details a symbolic link following attack in the G DATA Total Security Backup Service. Here is th…

Jul 16, 2026views - 1.4k

CYBERSECCRITICAL

ZDI-26-438: RCE in Rockwell Arena Simulation via DOE File, Patch Available

The ZDI-26-438 vulnerability enables remote code execution in Rockwell Automation Arena Simulation through malicious DOE files. Coordi…

Jul 16, 2026views - 1.3k

CYBERSECCRITICAL

OpenSSL: Double-Free in OCSP Stapling — The Gap Between Theoretical Risk and Official Rating

CVE-2026-35188 is a double-free in OpenSSL's OCSP stapling verification. ZDI calls it RCE; the official CVE record rates it Moderate.…

Jul 16, 2026views - 1.3k

VULNCRITICAL

7-Zip XZ Parser RCE Vulnerability: Opening an Archive Is Enough

A heap-based buffer overflow in 7-Zip's XZ parser enables remote code execution. The flaw, tracked as ZDI-26-444 and CVE-2026-14266, t…

Jul 16, 2026views - 1.6k