Patch
Curated coverage and analysis in this editorial area.

LegacyHive: Zero-Day Windows Flaw Patched by 0Patch Before Microsoft
The LegacyHive vulnerability in the Windows User Profile Service enables local privilege escalation. ACROS Security has released free…

ZDI-26-419: AdobeUpdateService Bug Allows Local Privilege Escalation to SYSTEM
The ZDI-26-419 vulnerability (CVE-2026-48272) in Adobe Creative Cloud Desktop enables local privilege escalation to SYSTEM via CWE-427…

ZDI-26-443: Linux Kernel vmwgfx Integer Overflow Enables Local Privilege Escalation at CVSS 8.8
An integer overflow in the Linux kernel's vmwgfx graphics driver allows local privilege escalation to kernel context. Published July 1…

Public Scanner Released for NGINX Map Regex Flaw; Full RCE Exploit Expected Around August 5
Researcher Stan Shaw (cyberstan) has published an open-source static scanner for CVE-2026-42533, a heap buffer overflow in the NGINX s…

Twenty-Day Gap: 7-Zip Patch for CVE-2026-14266 Exists, But No Auto-Update Means It Stays Unapplied
7-Zip version 26.02, released June 25, 2026, fixes a heap-based buffer overflow in the XZ decompressor tracked as CVE-2026-14266 and Z…

Multi-vendor patch day: public exploit for Firefox, four critical vendors
Mozilla confirms public exploit code for two Firefox flaws. Google, Adobe, and VMware ship critical patches on July 15, 2026. No activ…

CVE-2026-6875: Active Attacks on Self-Hosted ServiceNow; Cloud Protected Since April
Threat actors are exploiting CVE-2026-6875 against unpatched self-hosted ServiceNow instances. The sandbox escape enables pre-authenti…

wp2shell: Pre-Auth RCE in WordPress Core, Patched Without a CVE
Searchlight Cyber disclosed wp2shell, a pre-authentication remote code execution vulnerability in WordPress core. Patches landed in ve…

Microsoft Patch Tuesday July 2026: Two Zero-Days, and the CVSS 5.3 Is More Dangerous Than the 7.8
Microsoft's July 2026 Patch Tuesday addressed 570 CVEs, including two actively exploited zero-days: CVE-2026-56164 in SharePoint Serve…

BIN Project Files as Weapons: The Delta Electronics DTM Soft Flaw That Turns Engineering Data into Code Execution
A deserialization vulnerability in Delta Electronics DTM Soft allows remote code execution via malicious BIN project files. With a CVS…

OpenSSL's Unsettling Discrepancy: An X.509 Flaw Caught Between Information Disclosure and DoS
CVE-2026-42771 hits OpenSSL with a CVSS 6.5. ZDI calls it information disclosure; CVE.org points to likely DoS. The split complicates…

Synology DS925+: Root RCE via Redis MailPlus, Patch Available
ZDI-26-423 reveals a cryptographic flaw in the Synology DS925+ MailPlus Redis component. Network-adjacent attackers achieve unauthenti…