Cve
Curated coverage and analysis in this editorial area.

NVIDIA Transformers4Rec: RCE with CVSS 4.3 — The Risk Scoring Gap
A deserialization flaw in NVIDIA Transformers4Rec enables remote code execution, yet the official CVE record rates it 4.3 MEDIUM with…

GitLab's 'Future Field' Security Feature Turns Weapon: Emergency Patches for CVE-2026-19478
GitLab released critical patches on August 17, 2026 for CVE-2026-19478, a GraphQL code injection vulnerability with a CVSS 9.4 score t…

Microsoft Corrects Course: CVE-2026-69836 Was CVSS 10, But Not Exploited
Microsoft reclassified CVE-2026-69836, a critical Entra ID flaw, retracting its initial claim of active exploitation. The episode rais…

CVE-2026-59310: vCenter Exploited in 5 Days, 360+ IPs Compromised
A critical VMware vCenter vulnerability went from patch to in-the-wild exploitation in just five days. Over 360 IP addresses across 47…

CISA Adds Apple Zero-Day CVE-2025-43300 to KEV Catalog: CVSS 10, September 11 Deadline
CISA has cataloged CVE-2025-43300, an out-of-bounds write in Apple ImageIO rated CVSS 10.0 CRITICAL. Federal civilian agencies must pa…

CVE-2024-9042: SYSTEM-Level RCE on Kubernetes Windows Nodes via a Single curl Request
A vulnerability in Kubernetes' Log Query feature enables remote code execution with SYSTEM privileges on every Windows node in a clust…

Qualcomm BootROM Bug Lets Attackers Bypass Secure Boot in Minutes
Kaspersky ICS CERT disclosed CVE-2026-25262, a Write-What-Where condition in the BootROM of seven Qualcomm chipset series. Physical US…

Zimbra SNMP RCE Under Active Exploitation, CVSS 8.9, Over 12,000 Servers at Risk
CVE-2026-73570 enables unauthenticated RCE via Zimbra's optional SNMP component. CERT Polska confirms active exploitation; patch avail…

SonicWall SMA 1000 Under Attack: CVE-2026-15409 CVSS 10.0 and TOTP Seed Theft
CVE-2026-15409 and CVE-2026-15410 exposed SonicWall SMA 1000 appliances to unauthenticated root compromise. The theft of MFA seeds ren…

Cl0p Exploits PTC Windchill Zero-Day to Steal 100+ GB from Shell and Philips
The Cl0p ransomware group claims theft of over 100 GB of industrial data from Shell and Philips by exploiting CVE-2026-12569. The camp…

Trend Micro VPN: Local Privilege Escalation Flaw Allows SYSTEM Takeover
A local privilege escalation vulnerability in Trend Micro VPN, tracked as ZDI-26-577 and CVE-2026-67212, lets an attacker with low-pri…

NGINX DAV: Pre-Auth RCE Discovered by Calif.io in Collaboration with
CVE-2026-27654 in the NGINX HTTP DAV module: an integer underflow triggered by an alias in a prefix location enables unauthenticated r…