// 6 ZERO-DAY · 7 CVE · 6 EXPLOIT IN THE LAST 24H
nvidiaCRITICAL

NVIDIA NVTabular: RCE via Pickle, CVE-2026-24237 Rated CVSS 7.8

A deserialization flaw in NVIDIA NVTabular enables remote code execution through malicious pickle files. User interaction is required;…

Jul 26, 2026views - 1.1k

CYBERSECEXPLOIT

Public Scanner Released for NGINX Map Regex Flaw; Full RCE Exploit Expected Around August 5

Researcher Stan Shaw (cyberstan) has published an open-source static scanner for CVE-2026-42533, a heap buffer overflow in the NGINX s…

Jul 26, 2026views - 958

VULNCRITICAL

Fastjson 1.x Has No Exit: When Standard Mitigations Aren't Enough

CVE-2026-16723 hits Fastjson 1.2.68–1.2.83 with a CVSS 9.0. The exploit works with default settings, requires no AutoType or gadgets,…

Jul 26, 2026views - 966

CYBERSECCRITICAL

Autel Wallbox Exposed to Pre-Auth RCE: The Pwn2Own Bug Hitting Home EV Chargers

Trend Micro's Zero Day Initiative published advisory ZDI-26-437 on July 15, 2026, detailing a pre-authentication remote code execution…

Jul 26, 2026views - 984

VULNCRITICAL

Oracle Simphony: Four Critical CVEs Expose Hospitality POS to RCE

Four vulnerabilities in Oracle Hospitality Simphony enable unauthenticated remote code execution and NTLM hash theft. Patches released…

Jul 25, 2026views - 997

CYBERSECCRITICAL

Cl0p Hits PTC Windchill: Zero-Day RCE Exploited for Industrial IP Theft

The Cl0p ransomware group exploits CVE-2026-12569 in PTC Windchill and FlexPLM for unauthenticated remote code execution. CISA confirm…

Jul 25, 2026views - 1.4k

VULNCVE

Twenty-Day Gap: 7-Zip Patch for CVE-2026-14266 Exists, But No Auto-Update Means It Stays Unapplied

7-Zip version 26.02, released June 25, 2026, fixes a heap-based buffer overflow in the XZ decompressor tracked as CVE-2026-14266 and Z…

Jul 25, 2026views - 1.3k

VULNCVE

CVE-2026-6875: Active Attacks on Self-Hosted ServiceNow; Cloud Protected Since April

Threat actors are exploiting CVE-2026-6875 against unpatched self-hosted ServiceNow instances. The sandbox escape enables pre-authenti…

Jul 24, 2026views - 1.3k

VULNCRITICAL

wp2shell: Pre-Auth RCE in WordPress Core, Patched Without a CVE

Searchlight Cyber disclosed wp2shell, a pre-authentication remote code execution vulnerability in WordPress core. Patches landed in ve…

Jul 23, 2026views - 1.2k

CYBERSECCRITICAL

Langflow: CISA Orders 72-Hour Patch for Pre-Auth RCE as Root

CVE-2026-0770 enables unauthenticated remote code execution as root in Langflow. CISA mandates remediation by July 24, 2026 for federa…

Jul 23, 2026views - 1.2k

CYBERSECCRITICAL

BIN Project Files as Weapons: The Delta Electronics DTM Soft Flaw That Turns Engineering Data into Code Execution

A deserialization vulnerability in Delta Electronics DTM Soft allows remote code execution via malicious BIN project files. With a CVS…

Jul 23, 2026views - 1.2k

metasploitCRITICAL

Metasploit Drops Two Modules: FlowiseAI RCE and macOS Privilege Escalation

The Metasploit Framework adds exploit modules for CVE-2026-41264 in FlowiseAI and CVE-2024-27822 in macOS PackageKit. Both are product…

Jul 23, 2026views - 1.5k