// 1 CRITICAL · 6 ZERO-DAY · 6 CVE · 8 EXPLOIT IN THE LAST 24H
CYBERSECZERO-DAY

MSI Center: LPE Vulnerability in NTIOLib_X64.sys Kernel Driver

ZDI-26-430 discloses a local privilege escalation to SYSTEM in the NTIOLib_X64.sys driver used by MSI Center. The flaw affects OEM har…

Jul 16, 2026views - 1.5k

CYBERSECCRITICAL

Synology DS925+: Pre-Auth Root RCE via Weak Redis Passwords — Patch Available

ZDI-26-423 discloses a pre-authentication vulnerability in the MailPlus Redis component of the Synology DiskStation DS925+. Reversible…

Jul 16, 2026views - 1.5k

VULNZERO-DAY

G DATA Total Security: LPE in Backup Service, SYSTEM Compromised via Symlink

ZDI-26-432 (CVE-2026-13268, CVSS 7.8) details a symbolic link following attack in the G DATA Total Security Backup Service. Here is th…

Jul 16, 2026views - 1.4k

CYBERSECCRITICAL

OpenSSL: Double-Free in OCSP Stapling — The Gap Between Theoretical Risk and Official Rating

CVE-2026-35188 is a double-free in OpenSSL's OCSP stapling verification. ZDI calls it RCE; the official CVE record rates it Moderate.…

Jul 16, 2026views - 1.2k

VULNCRITICAL

7-Zip XZ Parser RCE Vulnerability: Opening an Archive Is Enough

A heap-based buffer overflow in 7-Zip's XZ parser enables remote code execution. The flaw, tracked as ZDI-26-444 and CVE-2026-14266, t…

Jul 16, 2026views - 1.6k

CYBERSEC

ArcGIS Server Path Traversal Masqueraded as Moderate: CVSS Jumps from 7.5 to 9.8 in Two Days

Esri updated the CVE-2026-9181 record on July 8, 2026, raising the CVSS score from 7.5 to 9.8. The NVD–CNA discrepancy risked leaving…

Jul 14, 2026views - 1.6k

CYBERSEC

SAP Patches CVSS 9.9 ABAP Kernel Bug: Mandatory Downtime or SAP GUI for HTML Breaks

CVE-2026-44747 is an out-of-bounds write in the SAP NetWeaver ABAP kernel with total impact on confidentiality, integrity, and availab…

Jul 14, 2026views - 1.3k

CYBERSECZERO-DAY

SonicWall SMA 1000: Two Actively Exploited Zero-Days and a Patch That Isn't Enough

SonicWall patched two zero-days under active exploitation in SMA 1000 Series appliances, but the vendor mandates full re-imaging or re…

Jul 14, 2026views - 1.3k

CYBERSEC

Microsoft Revokes 11 Legacy UEFI Shims: Secure Boot Bypassed via Signed Bootloaders

Eleven Microsoft-signed UEFI shim bootloaders allowed Secure Boot bypass on any trusting system. Revocation arrived with the June 2026…

Jul 14, 2026views - 1.3k

CYBERSECZERO-DAY

FortiBleed: 75,000 Firewalls at Risk from Stolen Credentials, Not a Zero-Day

FortiBleed hits already-patched FortiGate devices: credentials stolen in prior incidents enable administrative access without exploiti…

Jul 14, 2026views - 1.4k

exploitEXPLOIT

Metasploit Arms FlowiseAI and macOS: Two Exploits Land in the Framework

Metasploit has merged exploit modules for CVE-2026-41264, an unauthenticated RCE in FlowiseAI's CSV Agent, and CVE-2024-27822, a local…

Jul 11, 2026views - 1.3k

cveCRITICAL

Adobe ColdFusion: 10 Critical CVEs With In-the-Wild RCE, Forced Update

Adobe patched 10 ColdFusion vulnerabilities, including CVE-2026-48282 with a CVSS 10.0 score and confirmed exploitation. The legacy RD…

Jul 11, 2026views - 1.3k