Cve
Curated coverage and analysis in this editorial area.

Gitea CVE-2026-60004: Real-World Victim Reports CPU Spike and Dropper
A Russian sysadmin documented an attack on their self-hosted Gitea instance via CVE-2026-60004. Hosting provider HOSTKEY flagged susta…

Citrix NetScaler: CVE-2026-19490, Critical Authentication Bypass with CVSS 9.3
Citrix has released patches for CVE-2026-19490, a critical authentication bypass in NetScaler ADC/Gateway carrying a CVSS 9.3 score. T…

Lazarus Exploits Windows AFD.sys Zero-Day for SYSTEM: Third Time in Two Years
The North Korean group used CVE-2026-68820 for local privilege escalation to SYSTEM, deploying the FudModule 3.1 rootkit and Troy back…

French Cyber-Spies Used GitHub Code to Hack EncroChat
A reverse-engineering report reveals French malware targeting EncroChat was copied from GitHub. Thousands of convictions across Europe…

CVE-2026-32475: Elementor Pro ≤4.2.1 Exposed to Unauthenticated RCE
A critical CVSS 9.0 vulnerability in Elementor Pro allows unauthenticated PHP file upload. The fix sat ready for 34 days before releas…

Windows: Localized Filename Bug Steals NTLM Credentials with a Single Click
CVE-2026-50508: A flaw in Windows localized filenames enables NTLM hash theft simply by opening a file or visiting a web page. Microso…

Fabric.js JSON Parsing Turns Attack Vector: SSRF Bug Discovered
CVE-2026-19504 in Fabric.js' loadFromJSON method enables SSRF attacks for sensitive data disclosure. The fix requires implementing a U…

Foxit PDF Reader: UAF Bug in Annotation Parser Enables Remote Code Execution
ZDI-26-604 (CVE-2026-13126) is a Use-After-Free in Foxit PDF Reader's Annotation object parsing. Opening a malicious PDF allows arbitr…

Safari UAF in JavaScriptCore: Apple Patches Already Available
CVE-2026-64715 in Safari's JavaScript engine enables remote code execution simply by visiting a malicious page. Patches were released…

NVIDIA TensorRT: ONNX Parsing Flaw Enables RCE with CVSS 7.8
CVE-2026-24268 strikes the ONNX parser in NVIDIA TensorRT. A heap-based buffer overflow with CVSS 7.8, minimal user interaction, and a…

libwebsockets: RCE via HTTP/2 HPACK, Single-Line Patch Available
ZDI-26-590 discloses an unauthenticated remote code execution vulnerability in libwebsockets. A missing bounds check in the HTTP/2 HPA…

CVE-2026-65775: Microsoft Patches win32kfull UAF Discovered at Pwn2Own
Microsoft fixed CVE-2026-65775, a Use-After-Free in the Windows win32kfull driver discovered by Kentaro Kawane at Pwn2Own. The flaw en…