Vulnerabilities
Curated coverage and analysis in this editorial area.

ZDI-26-358: XSS in Allegra with a Classification Anomaly
Trend Micro's Zero Day Initiative published advisory ZDI-26-358 detailing an XSS flaw in Allegra's downloadAttachment method. The advi…

Langflow CVE-2026-5027: RCE Under Active Exploitation with 7,000 Instances Exposed
A critical path traversal vulnerability in Langflow is being exploited in the wild. CVE-2026-5027 (CVSS 8.8) enables unauthenticated r…

NVIDIA Transformers4Rec Flaw Enables RCE via Malicious ML Models
NVIDIA has patched a high-severity deserialization vulnerability (CVE-2026-24162, CVSS 7.8) in its Transformers4Rec library that allow…

CVE-2026-11645: Google Patches Fifth Chrome Zero-Day of 2026
Google has released a critical patch for CVE-2026-11645, a zero-day vulnerability in Chrome's V8 engine. With an exploit active in the…

ASUS MyASUS: SYSTEM Privilege Escalation Disclosed After 98 Days, Patch Link Remains Circular
CVE-2026-7480: A local privilege escalation vulnerability in MyASUS allows attackers to gain SYSTEM rights. While ASUS has issued an u…

RoguePlanet: Zero-Day Exploit (CVE-2026-42897) Hits Fully Patched Windows 10 and 11 Systems
RoguePlanet (CVE-2026-42897) leverages a race condition in Microsoft Defender to gain SYSTEM privileges on Windows 10 and 11 devices,…

ZDI-26-337: X.Org Server Vulnerability Enables Root Escalation on Linux
CVE-2026-34003 identifies a buffer overflow in the X.Org Server's CheckKeyTypes() function, allowing local privilege escalation to roo…

Kemp LoadMaster: Critical Pre-Auth RCE (CVSS 9.8) Triggers Urgent Patching
Progress Software has released a critical patch for Kemp LoadMaster following the coordinated disclosure of three pre-authentication R…

Adobe USD Plugin: GLTF Heap Overflow Enables Remote Code Execution
Adobe patches CVE-2026-48292, a CVSS 7.8 heap overflow in the usdGltf plugin. While no in-the-wild exploits are reported, 3D productio…

Gogs Patches Critical CVSS 9.4 Zero-Day; Over 2,300 Servers Exposed
Gogs 0.14.3 addresses a critical argument injection zero-day in the git rebase function. Default configurations allowing open registra…

RCI Hospitality Data Breach: IDOR Flaw Exposes PII of 40,000 Contractors
RCI Hospitality Holdings has confirmed a data breach stemming from an IDOR vulnerability on an IIS server, exposing the personal infor…

Microsoft Patched This Pwn2Own Edge RCE Weeks Ago—But the Disclosure Gap Leaves Enterprises Exposed
CVE-2026-45495: A directory traversal vulnerability in Microsoft Edge feedback logs enables remote code execution. While Microsoft rel…