// 5 ZERO-DAY · 5 CVE · 4 EXPLOIT IN THE LAST 24H
VULNCRITICAL

Heimdall Data: Root RCE in Database Proxy Poses Infrastructure-Wide Risk

ZDI-26-479 reveals a directory traversal flaw in the uploadJar method of Heimdall Data Database Proxy. Authentication is required, but…

Aug 08, 2026views - 1.1k

CYBERSECCVE

CISA Adds CVE-2026-8037 to KEV: 792 Exploit Attempts Against LoadMaster

CISA added CVE-2026-8037 to the Known Exploited Vulnerabilities catalog on August 7, 2026, after KEVIntel telemetry recorded 792 explo…

Aug 08, 2026views - 1k

VULNZERO-DAY

Samsung Patches Android Zero-Day Discovered by Meta: The Invisible Chain of Responsibility

Samsung has patched CVE-2025-21043, an out-of-bounds write in libimagecodec.quram.so enabling remote code execution. The flaw was repo…

Aug 06, 2026views - 1.1k

CYBERSECCRITICAL

Gitea: Critical File Read via Org-mode, RCE Risk with CVSS 9.8

CVE-2026-59774 affects Gitea 1.22.1 through 1.27.0: an unauthenticated attack exploits Org-mode markup to read arbitrary files and pot…

Aug 06, 2026views - 1.2k

VULNCRITICAL

ZDI-26-520: Pre-auth RCE in Phoenix Contact EV Charging Controller

A path-validation flaw in the firmware-update endpoint of the Phoenix Contact CHARX SEC-3150 EV charging controller allows unauthentic…

Aug 06, 2026views - 1.2k

CYBERSECEXPLOIT

TP-Link Omada: 15 Zero-Touch Provisioning Flaws Expose Enterprise Networks

Forescout discovered 15 vulnerabilities in TP-Link Omada's Zero-Touch Provisioning. An attack chain combining CVE-2025-7850 and CVE-20…

Aug 05, 2026views - 1.3k

VULNCRITICAL

Sony XAV-9500ES: Bluetooth RCE Found at Pwn2Own, Fix Available

A heap-based buffer overflow in the AVRCP parser of the Sony XAV-9500ES allows remote code execution by an attacker with a paired Blue…

Aug 05, 2026views - 1.3k

VULNCRITICAL

ZDI-26-463: RCE in GStreamer via MRF File, Patch Available

Trend Micro's Zero Day Initiative published advisory ZDI-26-463 detailing a remote code execution vulnerability in GStreamer's MRF par…

Aug 05, 2026views - 1.3k

VULNCRITICAL

Apple Patches ImageIO RCE: Numeric Truncation Fixed in macOS Tahoe 26.6

CVE-2026-43780 in Apple's ImageIO framework allowed remote code execution via malicious textures. The fix is available today across ei…

Aug 05, 2026views - 1.3k

CYBERSECCVE

CVE-2026-63077: Critical RCE in JetBrains TeamCity, CVSS 9.8

JetBrains has patched a deserialization vulnerability in TeamCity On-Premises with a CVSS 9.8 score. The unauthenticated RCE via the a…

Aug 05, 2026views - 1.2k

CYBERSECCRITICAL

WatchGuard FireWare OS: Directory Traversal in sigd Service Opens Path to Code Execution

A directory traversal vulnerability in the sigd service of WatchGuard FireWare OS allows an authenticated remote attacker to create ar…

Aug 05, 2026views - 1.2k

VULNCVE

CVE-2026-66066: Unauthenticated RCE in Rails via Active Storage, Public Metasploit Exploit

A critical Ruby on Rails vulnerability enables arbitrary file read and unauthenticated RCE through Active Storage when using libvips.…

Aug 04, 2026views - 1.2k