Cve
Curated coverage and analysis in this editorial area.

Zimbra 10.1.20 Patches Critical Command Injection Among Nine Vulnerabilities
Zimbra released version 10.1.20 of the Collaboration Suite on July 20, 2026, fixing nine security flaws. The most severe is a command…

DarkSword and Coruna: Government-Grade Spyware Turns Mass Crime on iOS
Apple issued rare retroactive patches for legacy iOS versions to address two APT-grade spyware frameworks now weaponized in zero-click…

Oracle Patches PeopleSoft Flaw That Emptied 300 Servers in Six Weeks
The July 2026 Critical Patch Update fixes CVE-2026-35278 and CVE-2026-35273, the pre-auth RCE and privilege-escalation chain exploited…

CVE-2026-31431 "Copy Fail": 732 Bytes of Code Breaks the Linux Kernel Since 2017
A vulnerability in the algif_aead module enables root privilege escalation via a 732-byte exploit. CISA has added CVE-2026-31431 to th…

GhostApproval, 14 UniFi CVEs, and Roundcube Espionage: A Triple Threat Convergence
Three critical attack vectors converged in July 2026: the GhostApproval symlink vulnerability in six AI coding assistants, 14 new crit…

From VPN Bypass to Encrypted Domain: How CVE-2026-0257 Fuels Qilin Ransomware
Arctic Wolf Labs confirms active exploitation of CVE-2026-0257 to deploy Qilin ransomware. Specific TTPs reveal shared infrastructure…

Apple Patches Zero-Day in dyld: A Flaw Hidden for Over a Decade
CVE-2026-20700 carries a CVSS 7.8 rating and is actively exploited against targeted individuals. Apple released patches on February 11…

WordPress: wp2shell Chain Exploited in the Wild 24 Hours After AI-Assisted Discovery
The wp2shell vulnerability chain in WordPress Core was discovered using AI for roughly $25, published July 17, and actively exploited…

IngressNightmare: The Design Flaw That Breaches the Kubernetes Perimeter
CVE-2025-1974 in the Ingress NGINX Controller enables unauthenticated RCE and full cluster takeover. Over 6,500 clusters are publicly…

CISA Adds CVE-2008-4128 to KEV: An 18-Year-Old Cisco IOS Bug Resurfaces
CISA's Known Exploited Vulnerabilities catalog now includes CVE-2008-4128, an 18-year-old CSRF flaw in Cisco IOS 12.4. Federal agencie…

Italy as Both Client and Target: The Graphite Case Exposes the Limits of Spyware
On July 18, 2026, forensic investigator Luca Cadonici presented a comprehensive reconstruction of the Graphite case at the Cyber Crime…

Patch Day: Mozilla Confirms Public Exploits for Firefox as Adobe and VMware Ship CVSS 9+ Fixes
On July 15, 2026, four vendors released critical updates simultaneously. Mozilla broke with standard practice by explicitly confirming…