// 1 CRITICAL · 6 ZERO-DAY · 8 CVE · 7 EXPLOIT IN THE LAST 24H
CYBERSEC

Citrix Patches Six NetScaler Flaws: The Trap Is Manual

Citrix released patches on June 30, 2026 for six vulnerabilities in NetScaler ADC and NetScaler Gateway, including a new CitrixBleed i…

Jul 01, 2026views - 1.1k

CYBERSECEXPLOIT

CISA Confirms: BlueHammer Now Exploited by Ransomware

CISA has elevated CVE-2026-33825 to a confirmed ransomware vector. Microsoft has not updated its advisory, creating an intelligence ga…

Jun 30, 2026views - 1.3k

CYBERSECCVE

CVE-2026-46817: Oracle EBS Under Attack, 450+ Servers Exposed

Defused detects active exploitation of CVE-2026-46817 on Oracle EBS honeypots. CVSS 9.8, patch available since May, over 450 instances…

Jun 29, 2026views - 772

CYBERSEC

ATEN Unizon: Authenticated Bug Deletes Files, CVSS 5.5 Understates Risk

Directory traversal in ATEN Unizon's uploadSSL lets an authenticated attacker delete arbitrary files. The CVSS 5.5 rating masks real o…

Jun 28, 2026views - 1.5k

CYBERSECZERO-DAY

ZDI-26-393: Stack Buffer Overflow in X.Org Server XKB Subsystem Enables Local Root Escalation

The Zero Day Initiative disclosed ZDI-26-393 on June 24, 2026, detailing a local privilege escalation vulnerability in X.Org Server. A…

Jun 28, 2026views - 1.4k

CYBERSEC

Linux Foundation Launches Akrites: A Shared SIRT for Open Source Software

Akrites brings 19 tech giants under one shared SIRT for open source vulnerabilities. A 5% patch rate and Dolan's admission: the road a…

Jun 26, 2026views - 1.2k

VULNCRITICAL

Synology MailPlus: Three Critical CVEs, 2,100+ Servers Exposed

Synology released MailPlus Server 4.0.1-31663 to fix three critical vulnerabilities enabling arbitrary file read/write and internal se…

Jun 26, 2026views - 755

CYBERSECCRITICAL

PTC Windchill: First In-the-Wild Exploitation of a PLM System

CVE-2026-12569 is the first PTC vulnerability added to the CISA KEV catalog. Active exploitation with persistent JSP webshells, patche…

Jun 26, 2026views - 1.1k

CYBERSECCVE

Adobe Reader: Patch Now for CVE-2026-27278, RCE via PDF

Adobe has released APSB26-26 for CVE-2026-27278, a Use-After-Free vulnerability in Acrobat Reader DC that enables remote code executio…

Jun 25, 2026views - 1.1k

CYBERSECCRITICAL

FlowiseAI CSV Agent RCE: Arbitrary Python Code Execution with Authentication Bypass

ZDI-26-365 discloses a remote code execution vulnerability in FlowiseAI's CSV Agent: Python code injection via customReadCSV with auth…

Jun 25, 2026views - 1.3k

CYBERSECCRITICAL

Docker MCP Plugin: RCE via OCI Label, Urgent Patch

ZDI-26-363: The YAML label io.docker.server.metadata in the Docker MCP Gateway enables remote code execution as root. The fix isolates…

Jun 25, 2026views - 998

CYBERSECCRITICAL

ZDI-26-376: RCE in Quest NetVault Backup with Authentication Bypass

Command injection in NVBULogDaemon enables remote code execution as SYSTEM. Patch available but no CVE or CVSS assigned.

Jun 25, 2026views - 784