// 3 CRITICAL · 2 ZERO-DAY · 4 CVE · 3 EXPLOIT · 1 ADVISORY IN THE LAST 24H
VULNCRITICAL

GIMP: APNG Integer Overflow Enables Code Execution, Patch Released

An integer overflow in GIMP's APNG parser allows remote arbitrary code execution when a user opens a malicious file. Tracked as CVE-20…

Jul 30, 2026views - 1.4k

VULNCRITICAL

GStreamer RCE Bug in MRF Parsing: Urgent Update Required

An out-of-bounds write vulnerability in GStreamer's MRF file parser enables remote code execution. User interaction is required, but t…

Jul 30, 2026views - 1.3k

CYBERSECCRITICAL

Sony XAV-9500ES: Bluetooth Turns Weapon — From Pwn2Own to the Parking Lot

ZDI advisory ZDI-26-475 details a heap-based buffer overflow in the AVRCP parser of the Sony XAV-9500ES head unit, enabling remote cod…

Jul 30, 2026views - 1.3k

VULNCRITICAL

Adminer: A 2021 Patch Bug Returns as RCE — The CVE-2026-15686 Case

Vulnerability ZDI-26-478 shows how a fix for CVE-2021-43008 introduced a new RCE vector via catastrophic backtracking in preg_match().

Jul 30, 2026views - 1.2k

CYBERSECCRITICAL

NoMachine getstat Command Injection Opens Door to RCE, CVSS 8.8

ZDI-26-483 details a command injection flaw in NoMachine's getstat function that allows authenticated remote code execution. A patch i…

Jul 30, 2026views - 1.3k

CYBERSECCRITICAL

WatchGuard FireWare OS Buffer Overflow Turns Firewall Into a Backdoor

A vulnerability in the networkd process of WatchGuard FireWare OS allows an authenticated remote attacker to execute arbitrary code wi…

Jul 30, 2026views - 1.2k

VULNCRITICAL

macOS USD Library Buffer Overflow Enables RCE via Malicious 3D Files

CVE-2026-43729 is a heap-based buffer overflow in Apple's USD library that allows arbitrary code execution through crafted 3D scene fi…

Jul 29, 2026views - 1.3k

VULNCRITICAL

QuantaStor RCE in Kapacitor Exposes Storage Supply-Chain Risks

CVE-2026-18265 hits OSNEXUS QuantaStor with a CVSS 9.8. The flaw lies in Kapacitor, an InfluxData component, configured without authen…

Jul 29, 2026views - 1.2k

VULNCVE

CVE-2026-16723: FastJson 1.x Under Active RCE Zero-Day Attack, Patch Unlikely

An unpatched RCE vulnerability affects FastJson 1.2.68 through 1.2.83 in Spring Boot fat-JAR deployments. The library, with 25,600 Git…

Jul 29, 2026views - 1.2k

CYBERSECCRITICAL

Rails Active Storage Exposes Arbitrary Files: The 'EOL Window' That Forces the Issue

A critical flaw in Ruby on Rails Active Storage lets unauthenticated attackers read arbitrary server files via crafted image uploads.…

Jul 29, 2026views - 1.3k

CYBERSECCRITICAL

RufRoot: The AI Vulnerability That Survives the Patch — 233 Tools Exposed and Persistent Memory Poisoning

CVE-2026-59726 in Ruflo exposes 233 MCP tools without authentication, enabling RCE, LLM API key theft, and persistent memory poisoning…

Jul 29, 2026views - 1.6k

CYBERSECCRITICAL

Broadcom Patches Five VMware Flaws: Full vCenter Bypass and VM Escape

Three critical vulnerabilities hit vCenter and ESXi. Two allow credential-less access; one enables escape from a virtual machine to th…

Jul 29, 2026views - 1.2k