Patch
Curated coverage and analysis in this editorial area.

CVE-2026-9779: RCE in ATEN Unizon via Flawed Cryptographic Signature Check
The ZDI-26-383 vulnerability enables remote code execution with SYSTEM privileges by exploiting a signature verification error in ATEN…

Unraid: Command Injection in ToggleState.php Enables RCE
CVE-2026-9773 in the Unraid web server: command injection in ToggleState.php allows authenticated remote code execution. CVSS 8.8, fix…

Path Traversal in Allegra: CVE-2026-11442 Exposes Arbitrary Files
The ZDI-26-357 vulnerability in Allegra's exportReport method allows an authenticated remote attacker to read arbitrary files via path…

OpenAI Shifts the Remediation Paradox: From Finding Bugs to Patching Them
OpenAI releases GPT-5.5-Cyber and the Patch the Planet initiative. AI has solved vulnerability discovery, creating a larger problem: t…

SonicWall: CVE Patched, but Risk Persists Across All 14 Audited Firewalls
A SANS audit of 14 SonicWall Gen7 firewalls shows the CVE-2024-40766 firmware patch fixed the bug, but 12 of 14 devices retained stale…

Samsung rlottie: RCE via Integer Truncation, Open-Source Patch Available
A short-vs-int type error in Samsung's rlottie graphics library enables remote code execution through a malicious animation file. A pa…

Atril RCE via EPUB: Patch Available Nine Days Before Disclosure
ZDI-26-360: A heap buffer overflow in the MATE Desktop's Atril document viewer enables remote code execution through malicious EPUB fi…

F5 Patches Critical NGINX Flaws: Conditional RCE at CVSS 9.2 Demands Immediate Action
F5 released out-of-band patches on June 17, 2026 for two critical vulnerabilities in NGINX Open Source. Both carry a CVSS v4.0 score o…

ZDI-26-358: Allegra Patches XSS in downloadAttachment Method
The ZDI-26-358 advisory from Trend Micro's Zero Day Initiative discloses a cross-site scripting vulnerability in Allegra's downloadAtt…

X.Org Server UAF CVE-2026-34001: Local Root Escalation on Linux
ZDI-26-335 discloses a use-after-free in X.Org Server's SyncTriggerList: CVSS 7.8, local attack with no user interaction, X.Org patch…

CISA Adds Joomla JCE to KEV: Pre-Auth RCE, CVSS 10.0
CISA added CVE-2026-48907 to the Known Exploited Vulnerabilities catalog on June 16, 2026, confirming active exploitation of a pre-aut…

Cisco SD-WAN, CVE-2026-20262: Internal Discovery, External Exploitation
Cisco disclosed CVE-2026-20262, a path traversal vulnerability in Catalyst SD-WAN Manager actively exploited in the wild. It requires…