// 4 CVE · 2 EXPLOIT IN THE LAST 24H
CYBERSECCVE

CVE-2026-63077: Critical RCE in JetBrains TeamCity, CVSS 9.8

JetBrains has patched a deserialization vulnerability in TeamCity On-Premises with a CVSS 9.8 score. The unauthenticated RCE via the a…

Aug 05, 2026views - 1.3k

linux

Arch Linux Halts AUR Package Adoptions: Third Supply-Chain Attack in Two Months

On July 30, 2026, Arch Linux suspended package adoptions in the Arch User Repository to stop an active supply-chain campaign. It is th…

Aug 04, 2026views - 1.3k

malware

QLNX: The Linux RAT Targeting Software Supply Chain Keys

Trend Micro discovered QLNX, a previously undocumented Linux RAT that combines a dual-tier rootkit, PAM backdoor, and P2P network to s…

Aug 04, 2026views - 1.3k

CYBERSECZERO-DAY

Exploitarium Turns Zero-Day Disclosure into Permanent Infrastructure

The Exploitarium repository has published 204 zero-day exploits for open-source projects without vendor notification. CVE-2026-55200 a…

Aug 04, 2026views - 1.2k

CYBERSECEXPLOIT

GhostLock: The Exploit That Unlocks Linux in 5 Seconds — 15 Years in the Shadows

On July 7, 2026, Nebula Security disclosed GhostLock, a working exploit for CVE-2026-43499, a use-after-free in the Linux kernel's fut…

Aug 04, 2026views - 1.2k

CYBERSECCRITICAL

NGINX Rift and Fragnesia: Two Critical Flaws at the Heart of Internet Infrastructure

An 18-year-old heap overflow hits nearly 19 million NGINX servers with unauthenticated RCE, while a local Linux exploit corrupts the p…

Aug 03, 2026views - 1.3k

VULNCRITICAL

GStreamer RCE Flaw in rtpsbcdepay Codec: Patch Available

ZDI-26-467 (CVE-2026-18299) details a use-after-free in GStreamer's RTP SBC depayloader enabling remote code execution. The primary ri…

Aug 03, 2026views - 1.2k

pythonCVE

CVE-2026-6100: CPython Use-After-Free in Decompressors Rated CVSS 9.1 Critical

CVE-2026-6100 affects CPython with a use-after-free in the lzma, bz2, and gzip decompressors. The CVSS 4.0 score is 9.1 CRITICAL, thou…

Aug 02, 2026views - 1.1k

VULNCRITICAL

Aeon RCE via Pickle Dataset: ML Pipeline Risk

CVE-2026-18285: The Python library Aeon executed arbitrary code through pickle deserialization of seemingly legitimate datasets. The b…

Aug 02, 2026views - 1.2k

CYBERSECEXPLOIT

AsyncAPI: Five npm Packages Compromised with Valid Provenance

Attackers hijacked the AsyncAPI project's CI/CD pipeline on July 14, 2026, stealing the asyncapi-bot service account token and publish…

Jul 31, 2026views - 996

linuxEXPLOIT

AI-Assisted Kernel Exploit: Researcher Publishes Root Escalation Code for Linux

STAR Labs researcher Lee Jia Jie has released exploit code for CVE-2026-53264, a use-after-free vulnerability in the Linux kernel's ne…

Jul 30, 2026views - 1.4k

CYBERSECCRITICAL

Aeon RCE Flaw in Benchmark Loading: The Risk Lies in the Datasets

Trend Micro's Zero Day Initiative published advisory ZDI-26-470 assigning CVE-2026-18287 to a code injection vulnerability in the Pyth…

Jul 30, 2026views - 1.4k