Cve
Curated coverage and analysis in this editorial area.

Public Scanner Released for NGINX Map Regex Flaw; Full RCE Exploit Expected Around August 5
Researcher Stan Shaw (cyberstan) has published an open-source static scanner for CVE-2026-42533, a heap buffer overflow in the NGINX s…

Russia Exploits Zimbra Zero-Day: Patching Alone Won't Evict the Spies
A zero-click XSS flaw in Zimbra Collaboration Suite let a Russian espionage group harvest emails, 2FA codes, and persistent app passwo…

Fastjson 1.x Has No Exit: When Standard Mitigations Aren't Enough
CVE-2026-16723 hits Fastjson 1.2.68–1.2.83 with a CVSS 9.0. The exploit works with default settings, requires no AutoType or gadgets,…

Oracle Simphony: Four Critical CVEs Expose Hospitality POS to RCE
Four vulnerabilities in Oracle Hospitality Simphony enable unauthenticated remote code execution and NTLM hash theft. Patches released…

Cl0p Hits PTC Windchill: Zero-Day RCE Exploited for Industrial IP Theft
The Cl0p ransomware group exploits CVE-2026-12569 in PTC Windchill and FlexPLM for unauthenticated remote code execution. CISA confirm…

Twenty-Day Gap: 7-Zip Patch for CVE-2026-14266 Exists, But No Auto-Update Means It Stays Unapplied
7-Zip version 26.02, released June 25, 2026, fixes a heap-based buffer overflow in the XZ decompressor tracked as CVE-2026-14266 and Z…

F5 BIG-IP: Source Code Stolen, 45 Patches in One Quarter, CISA on Alert
A nation-state actor stole F5 BIG-IP source code and information on undisclosed vulnerabilities. CISA issued Emergency Directive ED 26…

GhostLock: 15-Year Linux Bug Found by AI, Patches Still Incomplete
CVE-2026-43499 allows local users to escalate to root and escape containers. Exploit code is public, but patch availability remains fr…

EncForge: JadePuffer Hits Irrecoverable AI Models With Agentic Ransomware
The agentic threat actor JadePuffer has deployed EncForge, ransomware purpose-built for AI/ML assets. Encrypted models cannot be recov…

CVE-2026-6875: Active Attacks on Self-Hosted ServiceNow; Cloud Protected Since April
Threat actors are exploiting CVE-2026-6875 against unpatched self-hosted ServiceNow instances. The sandbox escape enables pre-authenti…

Langflow: CISA Orders 72-Hour Patch for Pre-Auth RCE as Root
CVE-2026-0770 enables unauthenticated remote code execution as root in Langflow. CISA mandates remediation by July 24, 2026 for federa…

Three Chained Zero-Days in Siemens ROX II: From File Leak to Root Control
Unit 42 and Siemens disclosed three zero-days in RUGGEDCOM ROX II industrial switches. The chain enables arbitrary file disclosure, pr…