Rce
Curated coverage and analysis in this editorial area.

Delta Electronics DTM Soft: Project BIN Files Become RCE Attack Vector
The ZDI-26-404 flaw in Delta Electronics DTM Soft industrial engineering software enables remote code execution via deserialization of…

Synology DS925+: Pre-Auth Root RCE via Weak Redis Passwords — Patch Available
ZDI-26-423 discloses a pre-authentication vulnerability in the MailPlus Redis component of the Synology DiskStation DS925+. Reversible…

NVIDIA NeMo Framework: RCE Vulnerability in ML Checkpoints
An unsafe deserialization flaw in NVIDIA NeMo Framework checkpoints enables remote code execution. User interaction is required, but t…

ZDI-26-438: RCE in Rockwell Arena Simulation via DOE File, Patch Available
The ZDI-26-438 vulnerability enables remote code execution in Rockwell Automation Arena Simulation through malicious DOE files. Coordi…

OpenSSL: Double-Free in OCSP Stapling — The Gap Between Theoretical Risk and Official Rating
CVE-2026-35188 is a double-free in OpenSSL's OCSP stapling verification. ZDI calls it RCE; the official CVE record rates it Moderate.…

7-Zip XZ Parser RCE Vulnerability: Opening an Archive Is Enough
A heap-based buffer overflow in 7-Zip's XZ parser enables remote code execution. The flaw, tracked as ZDI-26-444 and CVE-2026-14266, t…

Pre-Auth RCE in Autel EV Chargers: OCPP Protocol Becomes Attack Vector
Critical vulnerability in Autel MaxiCharger AC Elite Home: integer underflow in OCPP protocol enables unauthenticated remote code exec…

SonicWall SMA 1000: Two Actively Exploited Zero-Days and a Patch That Isn't Enough
SonicWall patched two zero-days under active exploitation in SMA 1000 Series appliances, but the vendor mandates full re-imaging or re…

CISA Adds Two Joomla Zero-Days to KEV Catalog: Deadline July 13
On July 10, 2026, CISA added two actively exploited zero-day vulnerabilities in Joomla extensions to its Known Exploited Vulnerabiliti…

Metasploit Arms FlowiseAI and macOS: Two Exploits Land in the Framework
Metasploit has merged exploit modules for CVE-2026-41264, an unauthenticated RCE in FlowiseAI's CSV Agent, and CVE-2024-27822, a local…

Adobe ColdFusion: 10 Critical CVEs With In-the-Wild RCE, Forced Update
Adobe patched 10 ColdFusion vulnerabilities, including CVE-2026-48282 with a CVSS 10.0 score and confirmed exploitation. The legacy RD…

Lorex 0-Day ZDI-26-399: Root RCE on Wi-Fi Camera, No Patch After 14 Months
The ZDI-26-399 vulnerability exposes Lorex 2K Indoor Wi-Fi Security Cameras to root-level remote code execution from the local network…