// 1 CRITICAL · 6 ZERO-DAY · 8 CVE · 6 EXPLOIT IN THE LAST 24H
CYBERSECCRITICAL

Synology DS925+: Root RCE via Redis MailPlus, Patch Available

ZDI-26-423 reveals a cryptographic flaw in the Synology DS925+ MailPlus Redis component. Network-adjacent attackers achieve unauthenti…

Jul 23, 2026views - 1.2k

VULNCRITICAL

Samsung rlottie: RCE Bug in Lottie Files Masked by a "Medium" CVSS

A numeric truncation flaw in Samsung rlottie enables remote code execution via malicious Lottie animations. The CVSS 5.5 rating unders…

Jul 23, 2026views - 1.5k

VULNCRITICAL

Autel EV Charger: Remote RCE via OCPP WebSocket, Discovered at Pwn2Own

The ZDI-26-437 vulnerability in the Autel MaxiCharger AC Elite Home enables pre-authentication remote code execution via an integer un…

Jul 22, 2026views - 1.2k

CYBERSECCVE

CVE-2026-6071: RCE in Rockwell Arena Simulation via Malicious DOE File

Trend Micro's Zero Day Initiative disclosed CVE-2026-6071, an out-of-bounds write in Rockwell Automation Arena Simulation's DOE file p…

Jul 22, 2026views - 1.2k

CYBERSECCRITICAL

Zimbra 10.1.20 Patches Critical Command Injection Among Nine Vulnerabilities

Zimbra released version 10.1.20 of the Collaboration Suite on July 20, 2026, fixing nine security flaws. The most severe is a command…

Jul 22, 2026views - 1.2k

oracleZERO-DAY

Oracle Patches PeopleSoft Flaw That Emptied 300 Servers in Six Weeks

The July 2026 Critical Patch Update fixes CVE-2026-35278 and CVE-2026-35273, the pre-auth RCE and privilege-escalation chain exploited…

Jul 22, 2026views - 1.3k

CYBERSECEXPLOIT

WordPress: wp2shell Chain Exploited in the Wild 24 Hours After AI-Assisted Discovery

The wp2shell vulnerability chain in WordPress Core was discovered using AI for roughly $25, published July 17, and actively exploited…

Jul 21, 2026views - 1.4k

CYBERSECCRITICAL

IngressNightmare: The Design Flaw That Breaches the Kubernetes Perimeter

CVE-2025-1974 in the Ingress NGINX Controller enables unauthenticated RCE and full cluster takeover. Over 6,500 clusters are publicly…

Jul 20, 2026views - 1.3k

CYBERSECEXPLOIT

Patch Day: Mozilla Confirms Public Exploits for Firefox as Adobe and VMware Ship CVSS 9+ Fixes

On July 15, 2026, four vendors released critical updates simultaneously. Mozilla broke with standard practice by explicitly confirming…

Jul 20, 2026views - 1.3k

CYBERSECCVE

CVE-2026-40400: RCE in PowerShell via Help File, Patch Available

ZDI-26-414 discloses a directory traversal flaw in PowerShell help file parsing that leads to remote code execution with user interact…

Jul 20, 2026views - 1.2k

VULNCRITICAL

SharePoint Critical RCE via Cryptographic Signature Flaw: The Token Danger

CVE-2026-50522 enables unauthenticated remote code execution on SharePoint Server by bypassing cryptographic verification on session t…

Jul 17, 2026views - 1.4k

CYBERSECCRITICAL

SharePoint On-Premises Under Attack: Three Days to Patch Actively Exploited RCE

Microsoft confirmed active exploitation of CVE-2026-58644 in SharePoint Server on-premises. CISA added the flaw to the KEV catalog wit…

Jul 17, 2026views - 1.3k