// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSEC

ZDI-26-336: X.Org Bug Exposes Sensitive Data, Enables Root Escalation

An out-of-bounds (OOB) read in X.Org Server’s CheckKeyActions allows local users to disclose sensitive memory. While the CVSS 6.1 scor…

Jun 10, 2026views - 1.4k

CYBERSECZERO-DAY

Microsoft June 2026 Patch Tuesday: 200 Flaws Fixed, 3 Public Zero-Days Addressed

Microsoft’s June 2026 security update addresses approximately 200 vulnerabilities, including three publicly disclosed zero-days: the '…

Jun 09, 2026views - 1.2k

CYBERSECCVE

LiteLLM CVE-2026-42271: CISA Confirms Active Exploitation of CVSS 10.0 RCE Chain

CISA has added CVE-2026-42271 to its KEV catalog, confirming active exploitation of a command injection vulnerability in LiteLLM. When…

Jun 09, 2026views - 816

CYBERSECZERO-DAY

Gogs Zero-Day RCE: CVSS 9.4 Critical Flaw Remains Unpatched After Two Months

A critical argument injection vulnerability in Gogs' git rebase functionality enables remote code execution. Despite disclosure to mai…

Jun 09, 2026views - 1k

CYBERSECCVE

CVE-2026-50751: Check Point VPN Zero-Day Exploited by Qilin Affiliate; Patch Released June 8

A Qilin ransomware affiliate exploited a critical zero-day in Check Point VPN’s IKEv1 protocol for over a month. The flaw (CVSS 9.3) a…

Jun 08, 2026views - 1.1k

CYBERSECZERO-DAY

Edge Tab-Splitting and Invisible Phishing: The Pwn2Own Flaw

CVE-2026-45494: A Universal XSS in Microsoft Edge discovered by Orange Tsai leverages tab-splitting to mask malicious URLs. Update to…

Jun 08, 2026views - 1.9k

CYBERSEC

Emphere Secures $2.1M to Automate Vulnerability Remediation with AI

Seattle-based startup Emphere raises $2.1 million to automate open-source vulnerability remediation as the NVD backlog exceeds 27,000…

Jun 07, 2026views - 855

CYBERSECCRITICAL

CISA Adds Critical Magento Mirasvit RCE to KEV Catalog, Sets 72-Hour Patch Deadline

CISA added CVE-2026-45247 to its Known Exploited Vulnerabilities (KEV) catalog on June 3, 2026. The flaw is a PHP object injection in…

Jun 07, 2026views - 1.5k

CYBERSECZERO-DAY

AI-Driven Vulnerability Discovery Hits FFmpeg: 21 Zero-Days Found for $1,000

An autonomous security agent has identified 21 zero-day vulnerabilities in the FFmpeg multimedia library, spending approximately $1,00…

Jun 06, 2026views - 1.2k

CYBERSECEXPLOIT

CISA: SolarWinds Serv-U Vulnerable to Remote Crashes via HTTP Header

CISA confirms active exploitation of CVE-2026-28318 in SolarWinds Serv-U. A single 'Content-Encoding: deflate' header is sufficient to…

Jun 05, 2026views - 1.7k

CYBERSECCRITICAL

Everest Forms Pro: Critical RCE Exploited Months After Patch Release

Threat actors are actively exploiting CVE-2026-3300 in the Everest Forms Pro WordPress plugin. Although version 1.9.13 has been availa…

Jun 05, 2026views - 1.3k

CYBERSEC

Child Identity Theft Surges 40%: The Decade-Long 'Shelf Life' of Stolen Minor Data

Data belonging to minors offers fraudsters a ten-year shelf life due to pristine credit scores and delayed detection. The FTC reports…

Jun 05, 2026views - 1.7k