Patch
Curated coverage and analysis in this editorial area.

Sony XAV-9500ES: AVRCP Heap Overflow Enables RCE via Bluetooth
The ZDI-26-475 vulnerability (CVE-2026-18282, CVSS 8.0) in the Sony XAV-9500ES Bluetooth AVRCP parser allows remote code execution aft…

PAX Q80: 0-day ZDI-26-526 Leaves Payment Terminals Unpatched
Trend Micro's Zero Day Initiative has published advisory ZDI-26-526, a 0-day vulnerability with a CVSS 7.5 score that enables RCE as r…

Trend Cleaner One Pro: Cleanup Service Turned Weapon for Arbitrary File Deletion
ZDI-26-496 reveals a vulnerability in Cleaner One Pro's Junk Files Cleanup service that allows a local attacker to delete arbitrary fi…

WatchGuard FireWare OS: Stack Buffer Overflow Enables Root RCE, Patch Available
A stack-based buffer overflow in the WatchGuard FireWare OS networkd daemon allows remote code execution with root privileges. Tracked…

Cisco FMC Under Attack: Static Credentials Exploited, No Workaround Available
CVE-2026-20316 in Cisco Secure Firewall Management Center involves hard-coded static credentials, confirmed active exploitation, and n…

Microsoft Uses AI to Find Windows Flaws Before Attackers Could Exploit Them
In the May 2026 Patch Tuesday, Microsoft fixed 138 vulnerabilities. Sixteen were discovered by the MDASH AI system before they could b…

CVE-2025-23266: NVIDIA Container Escape in Three Lines of Dockerfile
NVIDIA's GPU orchestration toolkit contains a critical vulnerability enabling container escape and privilege escalation on cloud AI in…

Adobe ColdFusion: Active Exploit in 2 Hours, Critical Patch for CVE-2026-48282
CVE-2026-48282 in ColdFusion carries a maximum CVSS 10.0 score with in-the-wild exploitation detected within two hours. CCCS confirms…

WinRAR CVE-2025-8088: Russian and Chinese APTs Exploit N-Day Patched Six Months Ago
Google Threat Intelligence Group confirms active exploitation of CVE-2025-8088 by Russian and Chinese state actors and financially mot…

Metabase Zero-Day CVSS 10.0 Actively Exploited for Corporate Data Theft
A maximum-severity SQL injection zero-day without a CVE has compromised Metabase cloud and self-hosted instances. Framework, Tally, an…

7-Zip 26.00: Any .zip File Can Trigger the Most Severe Heap Overflow Yet
CVE-2026-48095 is a heap overflow in 7-Zip's NTFS parser caused by undefined behavior in a 32-bit shift. An apparently harmless archiv…

CISA Adds CVE-2026-8037 to KEV: 792 Exploit Attempts Against LoadMaster
CISA added CVE-2026-8037 to the Known Exploited Vulnerabilities catalog on August 7, 2026, after KEVIntel telemetry recorded 792 explo…