Patch
Curated coverage and analysis in this editorial area.

CISA Adds Six CVEs to KEV: From Citrix RCE to SQL Server with Seven Years of Attacks
On August 26, 2026, CISA added six vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog, triggering Binding Operationa…

ICS Isn't Safer — Just More Selective. Biometric Sector Remains Top Target
In Q2 2026, the global share of ICS computers with blocked malicious objects fell to 19.15%, the lowest since 2022. Yet the biometric…

Chrome 152 Patches 327 Vulnerabilities, Including Sandbox-Escape RCE
Google released Chrome 152.0.7977.64/.65 on August 26, 2026, with a record 327 security fixes — 10 rated critical. CVE-2026-79282, a u…

Hugging Face Kubernetes AI Agent Intrusion
Qualys mapped the stages of an autonomous AI agent's multi-day intrusion against Hugging Face's Kubernetes environment on July 9, 2026…

Citrix NetScaler: CVE-2026-19490, Critical Authentication Bypass with CVSS 9.3
Citrix has released patches for CVE-2026-19490, a critical authentication bypass in NetScaler ADC/Gateway carrying a CVSS 9.3 score. T…

CVE-2026-32475: Elementor Pro ≤4.2.1 Exposed to Unauthenticated RCE
A critical CVSS 9.0 vulnerability in Elementor Pro allows unauthenticated PHP file upload. The fix sat ready for 34 days before releas…

Foxit PDF Reader: UAF Bug in Annotation Parser Enables Remote Code Execution
ZDI-26-604 (CVE-2026-13126) is a Use-After-Free in Foxit PDF Reader's Annotation object parsing. Opening a malicious PDF allows arbitr…

libwebsockets: RCE via HTTP/2 HPACK, Single-Line Patch Available
ZDI-26-590 discloses an unauthenticated remote code execution vulnerability in libwebsockets. A missing bounds check in the HTTP/2 HPA…

Windows Compatibility Appraiser: LPE Bug Escalates from LOCAL SERVICE to SYSTEM
ZDI-26-606 discloses a local privilege escalation vulnerability in the Microsoft Windows Compatibility Appraiser. Symbolic link manipu…

CVE-2026-65775: Microsoft Patches win32kfull UAF Discovered at Pwn2Own
Microsoft fixed CVE-2026-65775, a Use-After-Free in the Windows win32kfull driver discovered by Kentaro Kawane at Pwn2Own. The flaw en…

CVE-2026-18963: Keycloak Account Takeover in Seconds, Bypassing MFA
A critical flaw in Keycloak's password-reset flow lets an unauthenticated attacker seize any account — including admins — in roughly f…

AMD Confirms Two TPM 2.0 Flaws: False Attestations on Ryzen from 3000 Series to AI
Two vulnerabilities in AMD's TPM 2.0 firmware jeopardize the hardware attestation chain on Ryzen processors. Patched firmware has been…