// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSECCRITICAL

OpenSSL: Double-Free in OCSP Stapling — The Gap Between Theoretical Risk and Official Rating

CVE-2026-35188 is a double-free in OpenSSL's OCSP stapling verification. ZDI calls it RCE; the official CVE record rates it Moderate.…

Jul 16, 2026views - 1.3k

CYBERSECCRITICAL

Pre-Auth RCE in Autel EV Chargers: OCPP Protocol Becomes Attack Vector

Critical vulnerability in Autel MaxiCharger AC Elite Home: integer underflow in OCPP protocol enables unauthenticated remote code exec…

Jul 16, 2026views - 1.5k

CYBERSEC

ArcGIS Server Path Traversal Masqueraded as Moderate: CVSS Jumps from 7.5 to 9.8 in Two Days

Esri updated the CVE-2026-9181 record on July 8, 2026, raising the CVSS score from 7.5 to 9.8. The NVD–CNA discrepancy risked leaving…

Jul 14, 2026views - 1.7k

CYBERSEC

SAP Patches CVSS 9.9 ABAP Kernel Bug: Mandatory Downtime or SAP GUI for HTML Breaks

CVE-2026-44747 is an out-of-bounds write in the SAP NetWeaver ABAP kernel with total impact on confidentiality, integrity, and availab…

Jul 14, 2026views - 1.3k

CYBERSECEXPLOIT

SonicWall SMA 1000: Two Actively Exploited Zero-Days and a Patch That Isn't Enough

SonicWall patched two zero-days under active exploitation in SMA 1000 Series appliances, but the vendor mandates full re-imaging or re…

Jul 14, 2026views - 1.3k

CYBERSEC

Microsoft Revokes 11 Legacy UEFI Shims: Secure Boot Bypassed via Signed Bootloaders

Eleven Microsoft-signed UEFI shim bootloaders allowed Secure Boot bypass on any trusting system. Revocation arrived with the June 2026…

Jul 14, 2026views - 1.6k

CYBERSECZERO-DAY

SharePoint JWT Bypass and the AI Agent That Rewrites Zero-Day Discovery

Microsoft patched a SharePoint authentication bypass (CVE-2026-55040) discovered by Rapid7 using agentic AI. The CVSS 5.3 rating masks…

Jul 14, 2026views - 1.5k

CYBERSECZERO-DAY

FortiBleed: 75,000 Firewalls at Risk from Stolen Credentials, Not a Zero-Day

FortiBleed hits already-patched FortiGate devices: credentials stolen in prior incidents enable administrative access without exploiti…

Jul 14, 2026views - 1.4k

CYBERSEC

Security Vendor Jscrambler Becomes Supply-Chain Vector: 5 Malicious npm Versions

Threat actors compromised Jscrambler's npm publishing credentials and released five malicious versions of the jscrambler package conta…

Jul 13, 2026views - 1.3k

CYBERSECZERO-DAY

CISA Adds Two Joomla Zero-Days to KEV Catalog: Deadline July 13

On July 10, 2026, CISA added two actively exploited zero-day vulnerabilities in Joomla extensions to its Known Exploited Vulnerabiliti…

Jul 13, 2026views - 1.5k

CYBERSECZERO-DAY

ZDI Publishes 0-Day in Glary Utilities: LPE via Junction, No Patch

Trend Micro's Zero Day Initiative has disclosed ZDI-26-402, a local privilege escalation vulnerability in Glarysoft Glary Utilities. T…

Jul 12, 2026views - 1.4k

CYBERSECCRITICAL

Zimbra Patches Critical Stored XSS in Classic Web Client, Reported by Google TAG

Zimbra released ZCS 10.1.19 on July 7, 2026 to fix a stored cross-site scripting vulnerability in the Classic Web Client reported by G…

Jul 10, 2026views - 1k