Cve
Curated coverage and analysis in this editorial area.

Three Chained Zero-Days in Siemens Switches: From xz Utility to Root Access
Three zero-day vulnerabilities in Siemens RUGGEDCOM ROX II switches enable full privilege escalation and persistent root access. Firmw…

CVE-2026-40400: RCE in PowerShell via Help File, Patch Available
ZDI-26-414 discloses a directory traversal flaw in PowerShell help file parsing that leads to remote code execution with user interact…

Zoom Patches CVE-2026-53412: Critical Remote Account Takeover on Windows, CVSS 9.8
Zoom has patched a critical vulnerability in its Windows client that allows unauthenticated, zero-interaction account takeover. The fl…

SharePoint: Patch for CVE-2026-55126, an Authenticated XSS Rated CVSS 8.1
Microsoft has fixed an XSS vulnerability in SharePoint's SPFieldMultiLineText class. The CVSS 8.1 score and ease of remote exploitatio…

Cisco ISE Authenticated Directory Traversal (CVE-2026-20146) Exposes System Files
A directory traversal flaw in Cisco Identity Services Engine lets authenticated attackers read sensitive files. The vulnerability, rat…

SharePoint Critical RCE via Cryptographic Signature Flaw: The Token Danger
CVE-2026-50522 enables unauthenticated remote code execution on SharePoint Server by bypassing cryptographic verification on session t…

SharePoint On-Premises Under Attack: Three Days to Patch Actively Exploited RCE
Microsoft confirmed active exploitation of CVE-2026-58644 in SharePoint Server on-premises. CISA added the flaw to the KEV catalog wit…

Delta Electronics DTM Soft: Project BIN Files Become RCE Attack Vector
The ZDI-26-404 flaw in Delta Electronics DTM Soft industrial engineering software enables remote code execution via deserialization of…

X.Org Server: GLX Use-After-Free Bug Enables Local Root Escalation on Linux
A use-after-free vulnerability in the CommonMakeCurrent function allows a local attacker to escalate privileges to root. The flaw was…

Windows WMI: ZDI-26-415 Vulnerability Allows Escalation to SYSTEM
CVE-2026-49805 in Windows WMI Providers enables local privilege escalation to SYSTEM. Microsoft has released patches and rates exploit…

ZDI-26-416: Hyper-V netvsc.sys Bug Lets Local VM Attacker Escalate to Kernel
The ZDI-26-416 vulnerability in Microsoft Hyper-V's netvsc.sys driver allows a low-privilege attacker inside a Windows VM to escalate…

Adobe Creative Cloud Update Service Turned Into Privilege Escalation Weapon
ZDI-26-419 reveals a vulnerability in AdobeUpdateService that allows local privilege escalation from low-privilege user to SYSTEM on W…