// 3 CRITICAL · 2 ZERO-DAY · 4 CVE · 3 EXPLOIT · 1 ADVISORY IN THE LAST 24H
CYBERSECZERO-DAY

GeoServer Zero-Day Under Fire: Hundreds of Exploit Attempts in Hours, Patches Released

A zero-day SQL injection in GeoServer was massively probed within hours of disclosure. The flaw is a regression of a 2023 vulnerabilit…

Aug 19, 2026views - 1.1k

VULNZERO-DAY

Apple Patches Decade-Old iOS Zero-Day: dyld Exposed to Commercial Spyware

Apple has fixed CVE-2026-20700, a vulnerability in dyld present for over a decade and exploited in targeted attacks. The exploit chain…

Aug 18, 2026views - 1.5k

VULN

Parallels RAS Client: LPE to SYSTEM After 168 Days of Waiting

ZDI-26-556 reveals an exposed dangerous function in the RAS RDP Backend Service. Local escalation to SYSTEM after 168 days of coordina…

Aug 18, 2026views - 1.1k

linuxEXPLOIT

GhostLock: Public Exploit Grants Root in 5 Seconds on Linux Since 2011

CVE-2026-43499 has existed in the Linux kernel for 15 years. The public proof-of-concept requires only a local user to obtain root in…

Aug 17, 2026views - 1.1k

linux

ZDI-26-575: TOCTOU in Linux Kernel Net Scheduler Enables Local Privilege Escalation

A TOCTOU race condition in the Linux kernel's Net Scheduler packet classifier API allows local privilege escalation. The fix introduce…

Aug 16, 2026views - 1.1k

CYBERSECCRITICAL

WordPress 7.0.3 Fixes Login XSS That Can Lead to RCE via Social Engineering

CVE-2026-64638 is a pre-authentication reflected XSS in the WordPress login screen, discovered by pwn.ai using AI-assisted systems. Ex…

Aug 16, 2026views - 1.1k

CYBERSEC

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

The Greatness phishing-as-a-service toolkit has integrated device code phishing, abusing the OAuth 2.0 Device Authorization Grant to b…

Aug 16, 2026views - 1.2k

zeroZERO-DAY

GeoServer Zero-Day Under Attack: The Regression Exposing Cracks in the Secure Development Lifecycle

Threat actors began probing a SQL injection zero-day in GeoServer within hours of its public disclosure on August 12, 2026. The vulner…

Aug 15, 2026views - 1.2k

CYBERSECZERO-DAY

SonicWall Email Security: Local Privilege Escalation from CLI to Root via Command Injection

CVE-2026-66149 enables local privilege escalation in SonicWall Email Security. A patch is available, but the security perimeter remain…

Aug 15, 2026views - 1.1k

CYBERSECCRITICAL

Galaxy S25: A TIFF File Can Trigger Remote Code Execution

CVE-2026-21045 strikes the Galaxy S25's Quram library. Heap overflow in TIFF parsing carries a CVSS 8.4 score, with a three-month gap…

Aug 15, 2026views - 1.1k

ransomwareEXPLOIT

Gunra Hits Critical Infrastructure with Dual Fortinet Exploit

CISA, FBI, NSA, and South Korean police issued joint advisory AA26-222A on Gunra: 51 confirmed victims, MFA bypass, and persistence th…

Aug 15, 2026views - 1.1k

VULN

TONTOU: The Attack That Nullifies Spectre v2 Mitigations and Leaks Linux Passwords

MIT CSAIL researchers demonstrated a bypass of Spectre v2 mitigations on Linux at Black Hat USA 2026. TONTOU extracts password hashes…

Aug 14, 2026views - 1.1k