// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSECCVE

CVE-2026-40400: RCE in PowerShell via Help File, Patch Available

ZDI-26-414 discloses a directory traversal flaw in PowerShell help file parsing that leads to remote code execution with user interact…

Jul 20, 2026views - 1.3k

CYBERSECCVE

Zoom Patches CVE-2026-53412: Critical Remote Account Takeover on Windows, CVSS 9.8

Zoom has patched a critical vulnerability in its Windows client that allows unauthenticated, zero-interaction account takeover. The fl…

Jul 20, 2026views - 1.5k

CYBERSECCVE

SharePoint: Patch for CVE-2026-55126, an Authenticated XSS Rated CVSS 8.1

Microsoft has fixed an XSS vulnerability in SharePoint's SPFieldMultiLineText class. The CVSS 8.1 score and ease of remote exploitatio…

Jul 20, 2026views - 1.5k

CYBERSECCVE

Cisco ISE Authenticated Directory Traversal (CVE-2026-20146) Exposes System Files

A directory traversal flaw in Cisco Identity Services Engine lets authenticated attackers read sensitive files. The vulnerability, rat…

Jul 20, 2026views - 1.4k

CYBERSECEXPLOIT

SharePoint On-Premises Under Attack: Three Days to Patch Actively Exploited RCE

Microsoft confirmed active exploitation of CVE-2026-58644 in SharePoint Server on-premises. CISA added the flaw to the KEV catalog wit…

Jul 17, 2026views - 1.3k

CYBERSECCRITICAL

Delta Electronics DTM Soft: Project BIN Files Become RCE Attack Vector

The ZDI-26-404 flaw in Delta Electronics DTM Soft industrial engineering software enables remote code execution via deserialization of…

Jul 17, 2026views - 160

CYBERSEC

X.Org Server: GLX Use-After-Free Bug Enables Local Root Escalation on Linux

A use-after-free vulnerability in the CommonMakeCurrent function allows a local attacker to escalate privileges to root. The flaw was…

Jul 17, 2026views - 133

CYBERSEC

Windows WMI: ZDI-26-415 Vulnerability Allows Escalation to SYSTEM

CVE-2026-49805 in Windows WMI Providers enables local privilege escalation to SYSTEM. Microsoft has released patches and rates exploit…

Jul 17, 2026views - 1.4k

CYBERSEC

Adobe Creative Cloud Update Service Turned Into Privilege Escalation Weapon

ZDI-26-419 reveals a vulnerability in AdobeUpdateService that allows local privilege escalation from low-privilege user to SYSTEM on W…

Jul 16, 2026views - 1.3k

CYBERSECZERO-DAY

MSI Center: LPE Vulnerability in NTIOLib_X64.sys Kernel Driver

ZDI-26-430 discloses a local privilege escalation to SYSTEM in the NTIOLib_X64.sys driver used by MSI Center. The flaw affects OEM har…

Jul 16, 2026views - 1.5k

CYBERSECCRITICAL

Synology DS925+: Pre-Auth Root RCE via Weak Redis Passwords — Patch Available

ZDI-26-423 discloses a pre-authentication vulnerability in the MailPlus Redis component of the Synology DiskStation DS925+. Reversible…

Jul 16, 2026views - 1.6k

CYBERSECCRITICAL

ZDI-26-438: RCE in Rockwell Arena Simulation via DOE File, Patch Available

The ZDI-26-438 vulnerability enables remote code execution in Rockwell Automation Arena Simulation through malicious DOE files. Coordi…

Jul 16, 2026views - 1.4k