// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSECZERO-DAY

X.Org Server: Root LPE via XkbSetCompatMap; Patch Released

CVE-2026-33999 in X.Org Server enables local privilege escalation to root. Discovered by ZDI, the fix follows a coordinated disclosure…

Jun 13, 2026views - 991

linuxCRITICAL

ZDI-26-360: RCE Vulnerability in MATE’s Atril Document Viewer Patched in Version 1.26.4

A heap-based buffer overflow in the Atril EPUB parser (MATE Desktop) allows for remote code execution. The vulnerability is addressed…

Jun 11, 2026views - 790

VULN

ZDI-26-337: X.Org Server Vulnerability Enables Root Escalation on Linux

CVE-2026-34003 identifies a buffer overflow in the X.Org Server's CheckKeyTypes() function, allowing local privilege escalation to roo…

Jun 10, 2026views - 1k

CYBERSEC

ZDI-26-336: X.Org Bug Exposes Sensitive Data, Enables Root Escalation

An out-of-bounds (OOB) read in X.Org Server’s CheckKeyActions allows local users to disclose sensitive memory. While the CVSS 6.1 scor…

Jun 10, 2026views - 1.4k

CYBERSECZERO-DAY

Gogs Zero-Day RCE: CVSS 9.4 Critical Flaw Remains Unpatched After Two Months

A critical argument injection vulnerability in Gogs' git rebase functionality enables remote code execution. Despite disclosure to mai…

Jun 09, 2026views - 1k

linuxCVE

CVE-2026-23111: Single-Character Logic Error Grants Root Access on Linux

An inverted check in the nf_tables subsystem enables local privilege escalation and container breakouts. With public exploits already…

Jun 08, 2026views - 2.2k

cybersec

DockSec: The Open-Source AI Healing Containers, Not Just Scanning Them

DockSec, an OWASP Incubator project, leverages LLMs to correlate data from three Docker scanners and generate line-specific fixes. Its…

Jun 08, 2026views - 1.5k

malware

C0XMO: Gafgyt Variant Targets DD-WRT Routers with Modular Scanner and Competitor-Killing Routine

The C0XMO variant of the Gafgyt botnet exploits CVE-2021-27137 in DD-WRT firmware, utilizing a modular architecture with a standalone…

Jun 07, 2026views - 933

CYBERSEC

Emphere Secures $2.1M to Automate Vulnerability Remediation with AI

Seattle-based startup Emphere raises $2.1 million to automate open-source vulnerability remediation as the NVD backlog exceeds 27,000…

Jun 07, 2026views - 855

VULNCVE

CVE-2026-8936: Docker Desktop VM Panic Triggered via grpcfuse Recursion

A low-privileged container can trigger a VM panic in Docker Desktop through uncontrolled recursion in the grpcfuse module. The vulnera…

Jun 04, 2026views - 885

cybersec

SI-CERT: How a 13-Person Team Manages 6,000 Annual Incidents

Slovenia’s national CSIRT, SI-CERT, processes 6,000 cyber incidents annually with a core staff of just 13. By deploying a specialized…

Jun 03, 2026views - 251

CYBERSEC

Gitea Bug Exposed Private Container Images for Four Years

CVE-2026-27771: A critical flaw in Gitea’s container registry left approximately 31,750 instances vulnerable for nearly four years. Di…

Jun 02, 2026views - 195