Cybersecurity
Cybersecurity collects analysis on vulnerabilities, exploits, patch management, ransomware, supply chain, AI security and threat intelligence. These articles help IT professionals, developers and security analysts follow operational threats, vendor updates and technical trends.

CVE-2026-40400: RCE in PowerShell via Help File, Patch Available
ZDI-26-414 discloses a directory traversal flaw in PowerShell help file parsing that leads to remote code execution with user interact…

Zoom Patches CVE-2026-53412: Critical Remote Account Takeover on Windows, CVSS 9.8
Zoom has patched a critical vulnerability in its Windows client that allows unauthenticated, zero-interaction account takeover. The fl…

SharePoint: Patch for CVE-2026-55126, an Authenticated XSS Rated CVSS 8.1
Microsoft has fixed an XSS vulnerability in SharePoint's SPFieldMultiLineText class. The CVSS 8.1 score and ease of remote exploitatio…

Cisco ISE Authenticated Directory Traversal (CVE-2026-20146) Exposes System Files
A directory traversal flaw in Cisco Identity Services Engine lets authenticated attackers read sensitive files. The vulnerability, rat…

SharePoint On-Premises Under Attack: Three Days to Patch Actively Exploited RCE
Microsoft confirmed active exploitation of CVE-2026-58644 in SharePoint Server on-premises. CISA added the flaw to the KEV catalog wit…

Delta Electronics DTM Soft: Project BIN Files Become RCE Attack Vector
The ZDI-26-404 flaw in Delta Electronics DTM Soft industrial engineering software enables remote code execution via deserialization of…

X.Org Server: GLX Use-After-Free Bug Enables Local Root Escalation on Linux
A use-after-free vulnerability in the CommonMakeCurrent function allows a local attacker to escalate privileges to root. The flaw was…

Windows WMI: ZDI-26-415 Vulnerability Allows Escalation to SYSTEM
CVE-2026-49805 in Windows WMI Providers enables local privilege escalation to SYSTEM. Microsoft has released patches and rates exploit…

Adobe Creative Cloud Update Service Turned Into Privilege Escalation Weapon
ZDI-26-419 reveals a vulnerability in AdobeUpdateService that allows local privilege escalation from low-privilege user to SYSTEM on W…

MSI Center: LPE Vulnerability in NTIOLib_X64.sys Kernel Driver
ZDI-26-430 discloses a local privilege escalation to SYSTEM in the NTIOLib_X64.sys driver used by MSI Center. The flaw affects OEM har…

Synology DS925+: Pre-Auth Root RCE via Weak Redis Passwords — Patch Available
ZDI-26-423 discloses a pre-authentication vulnerability in the MailPlus Redis component of the Synology DiskStation DS925+. Reversible…

ZDI-26-438: RCE in Rockwell Arena Simulation via DOE File, Patch Available
The ZDI-26-438 vulnerability enables remote code execution in Rockwell Automation Arena Simulation through malicious DOE files. Coordi…