// 1 CRITICAL · 4 ZERO-DAY · 7 CVE · 8 EXPLOIT · 1 ADVISORY IN THE LAST 24H
CYBERSECEXPLOIT

WordPress: wp2shell Chain Exploited in the Wild 24 Hours After AI-Assisted Discovery

The wp2shell vulnerability chain in WordPress Core was discovered using AI for roughly $25, published July 17, and actively exploited…

Jul 21, 2026views - 1.3k

CYBERSECCRITICAL

IngressNightmare: The Design Flaw That Breaches the Kubernetes Perimeter

CVE-2025-1974 in the Ingress NGINX Controller enables unauthenticated RCE and full cluster takeover. Over 6,500 clusters are publicly…

Jul 20, 2026views - 1.2k

CYBERSECCVE

CISA Adds CVE-2008-4128 to KEV: An 18-Year-Old Cisco IOS Bug Resurfaces

CISA's Known Exploited Vulnerabilities catalog now includes CVE-2008-4128, an 18-year-old CSRF flaw in Cisco IOS 12.4. Federal agencie…

Jul 20, 2026views - 1.2k

CYBERSECEXPLOIT

Italy as Both Client and Target: The Graphite Case Exposes the Limits of Spyware

On July 18, 2026, forensic investigator Luca Cadonici presented a comprehensive reconstruction of the Graphite case at the Cyber Crime…

Jul 20, 2026views - 1.3k

CYBERSECEXPLOIT

Patch Day: Mozilla Confirms Public Exploits for Firefox as Adobe and VMware Ship CVSS 9+ Fixes

On July 15, 2026, four vendors released critical updates simultaneously. Mozilla broke with standard practice by explicitly confirming…

Jul 20, 2026views - 1.2k

zeroZERO-DAY

LegacyHive: Nightmare Eclipse's Ninth Zero-Day Pierces Fully Patched Windows

Nightmare Eclipse has released LegacyHive, a zero-day exploit targeting the Windows User Profile Service to load arbitrary registry hi…

Jul 20, 2026views - 1.4k

CYBERSECZERO-DAY

Three Chained Zero-Days in Siemens Switches: From xz Utility to Root Access

Three zero-day vulnerabilities in Siemens RUGGEDCOM ROX II switches enable full privilege escalation and persistent root access. Firmw…

Jul 20, 2026views - 1.2k

CYBERSECCVE

CVE-2026-40400: RCE in PowerShell via Help File, Patch Available

ZDI-26-414 discloses a directory traversal flaw in PowerShell help file parsing that leads to remote code execution with user interact…

Jul 20, 2026views - 1.2k

CYBERSECCVE

Zoom Patches CVE-2026-53412: Critical Remote Account Takeover on Windows, CVSS 9.8

Zoom has patched a critical vulnerability in its Windows client that allows unauthenticated, zero-interaction account takeover. The fl…

Jul 20, 2026views - 1.4k

CYBERSECCVE

SharePoint: Patch for CVE-2026-55126, an Authenticated XSS Rated CVSS 8.1

Microsoft has fixed an XSS vulnerability in SharePoint's SPFieldMultiLineText class. The CVSS 8.1 score and ease of remote exploitatio…

Jul 20, 2026views - 1.4k

CYBERSECCVE

Cisco ISE Authenticated Directory Traversal (CVE-2026-20146) Exposes System Files

A directory traversal flaw in Cisco Identity Services Engine lets authenticated attackers read sensitive files. The vulnerability, rat…

Jul 20, 2026views - 1.3k

VULNCRITICAL

SharePoint Critical RCE via Cryptographic Signature Flaw: The Token Danger

CVE-2026-50522 enables unauthenticated remote code execution on SharePoint Server by bypassing cryptographic verification on session t…

Jul 17, 2026views - 1.4k