Patch
Curated coverage and analysis in this editorial area.

GeoServer Zero-Day Under Fire: Hundreds of Exploit Attempts in Hours, Patches Released
A zero-day SQL injection in GeoServer was massively probed within hours of disclosure. The flaw is a regression of a 2023 vulnerabilit…

Apple Patches Decade-Old iOS Zero-Day: dyld Exposed to Commercial Spyware
Apple has fixed CVE-2026-20700, a vulnerability in dyld present for over a decade and exploited in targeted attacks. The exploit chain…

Parallels RAS Client: LPE to SYSTEM After 168 Days of Waiting
ZDI-26-556 reveals an exposed dangerous function in the RAS RDP Backend Service. Local escalation to SYSTEM after 168 days of coordina…

GhostLock: Public Exploit Grants Root in 5 Seconds on Linux Since 2011
CVE-2026-43499 has existed in the Linux kernel for 15 years. The public proof-of-concept requires only a local user to obtain root in…

ZDI-26-575: TOCTOU in Linux Kernel Net Scheduler Enables Local Privilege Escalation
A TOCTOU race condition in the Linux kernel's Net Scheduler packet classifier API allows local privilege escalation. The fix introduce…

WordPress 7.0.3 Fixes Login XSS That Can Lead to RCE via Social Engineering
CVE-2026-64638 is a pre-authentication reflected XSS in the WordPress login screen, discovered by pwn.ai using AI-assisted systems. Ex…

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The Greatness phishing-as-a-service toolkit has integrated device code phishing, abusing the OAuth 2.0 Device Authorization Grant to b…

GeoServer Zero-Day Under Attack: The Regression Exposing Cracks in the Secure Development Lifecycle
Threat actors began probing a SQL injection zero-day in GeoServer within hours of its public disclosure on August 12, 2026. The vulner…

SonicWall Email Security: Local Privilege Escalation from CLI to Root via Command Injection
CVE-2026-66149 enables local privilege escalation in SonicWall Email Security. A patch is available, but the security perimeter remain…

Galaxy S25: A TIFF File Can Trigger Remote Code Execution
CVE-2026-21045 strikes the Galaxy S25's Quram library. Heap overflow in TIFF parsing carries a CVSS 8.4 score, with a three-month gap…

Gunra Hits Critical Infrastructure with Dual Fortinet Exploit
CISA, FBI, NSA, and South Korean police issued joint advisory AA26-222A on Gunra: 51 confirmed victims, MFA bypass, and persistence th…

TONTOU: The Attack That Nullifies Spectre v2 Mitigations and Leaks Linux Passwords
MIT CSAIL researchers demonstrated a bypass of Spectre v2 mitigations on Linux at Black Hat USA 2026. TONTOU extracts password hashes…