Patch
Curated coverage and analysis in this editorial area.

WinRAR CVE-2025-8088: Russian and Chinese APTs Exploit N-Day Patched Six Months Ago
Google Threat Intelligence Group confirms active exploitation of CVE-2025-8088 by Russian and Chinese state actors and financially mot…

Metabase Zero-Day CVSS 10.0 Actively Exploited for Corporate Data Theft
A maximum-severity SQL injection zero-day without a CVE has compromised Metabase cloud and self-hosted instances. Framework, Tally, an…

7-Zip 26.00: Any .zip File Can Trigger the Most Severe Heap Overflow Yet
CVE-2026-48095 is a heap overflow in 7-Zip's NTFS parser caused by undefined behavior in a 32-bit shift. An apparently harmless archiv…

CISA Adds CVE-2026-8037 to KEV: 792 Exploit Attempts Against LoadMaster
CISA added CVE-2026-8037 to the Known Exploited Vulnerabilities catalog on August 7, 2026, after KEVIntel telemetry recorded 792 explo…

June 2026 Patch Tuesday: Microsoft's Largest Ever, With Three Publicly Disclosed Zero-Days
Microsoft fixed nearly 200 vulnerabilities in the June 2026 Patch Tuesday, the most voluminous monthly cycle in the company's history.…

Cisco Confirms Active Exploitation of Hard-Coded Credentials in Secure Firewall Management Center
Cisco has confirmed active in-the-wild exploitation of CVE-2026-20316, a static credential vulnerability in Secure Firewall Management…

Swiss Federal SharePoint Breach Compromises 200 Accounts
The Federal Office for Information Technology and Telecommunication (BIT/FOITT) confirms exploitation of already-patched SharePoint fl…

VMware vCenter Hit by Two Critical Flaws With No Workarounds: The Remediation Plan
Broadcom has patched two critical vulnerabilities in vCenter Server, both rated CVSS 9.8. No workarounds exist for CVE-2026-59309 and…

Samsung Patches Android Zero-Day Discovered by Meta: The Invisible Chain of Responsibility
Samsung has patched CVE-2025-21043, an out-of-bounds write in libimagecodec.quram.so enabling remote code execution. The flaw was repo…

ZDI-26-520: Pre-auth RCE in Phoenix Contact EV Charging Controller
A path-validation flaw in the firmware-update endpoint of the Phoenix Contact CHARX SEC-3150 EV charging controller allows unauthentic…

CISA Orders 3-Day Patch Deadline for CVE-2026-18577 in N-able N-central
CISA added CVE-2026-18577 to its Known Exploited Vulnerabilities catalog with a three-day patching deadline for federal agencies. The…

ChainDrop: The npm Worm That Compromised 444 Packages in Under Four Hours
Analysis of the August 4, 2026 ChainDrop attack: a self-replicating npm worm that abused OIDC Trusted Publishing with valid SLSA prove…