// 3 CRITICAL · 2 ZERO-DAY · 4 CVE · 3 EXPLOIT · 1 ADVISORY IN THE LAST 24H
CYBERSECCVE

CVE-2026-18294: RCE in OriginLab Origin Viewer via Malformed OGW File

The CVE-2026-18294 vulnerability in OriginLab Origin Viewer's OGW parser enables remote code execution with a CVSS 7.8 score. Exploita…

Aug 24, 2026views - 1.1k

CYBERSECCVE

CISA Adds CVE-2025-62593 to KEV Catalog: Ray at Risk of RCE

CISA added CVE-2025-62593 to its Known Exploited Vulnerabilities catalog on August 17, 2026. The critical flaw in the Ray framework ex…

Aug 24, 2026views - 1.1k

CYBERSECCRITICAL

CISA Orders September Patches: Two Critical TrueConf Flaws Actively Exploited

CISA added two critical TrueConf Server vulnerabilities to the KEV catalog, already exploited by the Head Mare group to deploy Phantom…

Aug 23, 2026views - 1.1k

CYBERSECCVE

Microsoft Corrects Course: CVE-2026-69836 Was CVSS 10, But Not Exploited

Microsoft reclassified CVE-2026-69836, a critical Entra ID flaw, retracting its initial claim of active exploitation. The episode rais…

Aug 22, 2026views - 1k

CYBERSECCVE

CVE-2026-59310: vCenter Exploited in 5 Days, 360+ IPs Compromised

A critical VMware vCenter vulnerability went from patch to in-the-wild exploitation in just five days. Over 360 IP addresses across 47…

Aug 22, 2026views - 1.4k

CYBERSECCVE

CVE-2024-9042: SYSTEM-Level RCE on Kubernetes Windows Nodes via a Single curl Request

A vulnerability in Kubernetes' Log Query feature enables remote code execution with SYSTEM privileges on every Windows node in a clust…

Aug 22, 2026views - 1k

VULNCRITICAL

isolated-vm: C++ Binding Layer Bug Enables Sandbox Escape to Host RCE

A TOCTOU vulnerability in the Node.js isolated-vm library allows guest-to-host escape with potential RCE. Versions 6.2.0 and 7.0.1 pat…

Aug 21, 2026views - 1.1k

CYBERSECCRITICAL

Zimbra SNMP RCE Under Active Exploitation, CVSS 8.9, Over 12,000 Servers at Risk

CVE-2026-73570 enables unauthenticated RCE via Zimbra's optional SNMP component. CERT Polska confirms active exploitation; patch avail…

Aug 20, 2026views - 1.1k

CYBERSECCRITICAL

NGINX DAV: Pre-Auth RCE Discovered by Calif.io in Collaboration with

CVE-2026-27654 in the NGINX HTTP DAV module: an integer underflow triggered by an alias in a prefix location enables unauthenticated r…

Aug 20, 2026views - 1k

CYBERSECZERO-DAY

GeoServer Zero-Day Under Fire: Hundreds of Exploit Attempts in Hours, Patches Released

A zero-day SQL injection in GeoServer was massively probed within hours of disclosure. The flaw is a regression of a 2023 vulnerabilit…

Aug 19, 2026views - 1.1k

CYBERSECCRITICAL

Cisco ISE: Authenticated RCE in invokeScript With Root Escalation Path

CVE-2026-20147 enables authenticated remote code execution as the iseadminportal user on Cisco Identity Services Engine, with a docume…

Aug 16, 2026views - 1.2k

VULNCRITICAL

NGINX WebDAV: Pre-Auth RCE Disclosed in ZDI-26-578

The ZDI-26-578 advisory reveals a critical RCE flaw in the NGINX HTTP DAV module. It is exploitable without authentication via an inte…

Aug 16, 2026views - 1.3k