// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
VULNCVE

CVE-2026-8936: Docker Desktop VM Panic Triggered via grpcfuse Recursion

A low-privileged container can trigger a VM panic in Docker Desktop through uncontrolled recursion in the grpcfuse module. The vulnera…

Jun 04, 2026views - 885

VULNCVE

CVE-2026-48095: 7-Zip NTFS Handler Heap Overflow

A heap overflow in 7-Zip’s NTFS handler allows for RCE via crafted files. The vulnerability involves signature-based file routing that…

Jun 03, 2026views - 320

VULN

Microsoft Refuses to Patch Windows Search URI Flaw Enabling NTLM Hash Theft

Huntress has disclosed an unpatched vulnerability in the Windows search: URI handler that allows attackers to steal NTLMv2 hashes via…

Jun 03, 2026views - 283

VULNCVE

CVE-2026-0826: Root RCE Vulnerability Hits HP Poly Enterprise VoIP Phones

A critical stack-based buffer overflow in HP Poly Voice's SDP parsing allows unauthenticated remote code execution with root privilege…

Jun 03, 2026views - 250

VULNEXPLOIT

CIFSwitch: Linux Kernel Bug Grants Root Access on CentOS and Rocky Linux

CIFSwitch enables local privilege escalation to root across multiple Linux distributions. While a public PoC is available and an upstr…

May 30, 2026views - 266

VULNCVE

CVE-2026-0257: Active Exploitation Confirmed for GlobalProtect Authentication Bypass

Palo Alto Networks has confirmed active exploitation of CVE-2026-0257 affecting PAN-OS GlobalProtect. CISA has added the vulnerability…

May 30, 2026views - 728

VULNZERO-DAY

FortiClient EMS: EKZ Infostealer May Target VPN Management Channels

CVE-2026-35616 (CVSS 9.8): Compromised FortiClient EMS platforms could be transformed into malware delivery vehicles. Attacks in May 2…

May 29, 2026views - 214

VULNCVE

7-Zip CVE-2026-48095: NTFS Heap Overflow Enables Vtable Hijacking

A critical heap buffer overflow in 7-Zip 26.00 allows for Remote Code Execution (RCE) via specially crafted NTFS files, regardless of…

May 27, 2026views - 2.1k

VULNCRITICAL

Progress Software Patches High-Severity Command Injection in Kemp LoadMaster (ZDI-26-319)

An authenticated command injection vulnerability in the customLocation parameter of Kemp LoadMaster carries a CVSS score of 8.8. While…

May 27, 2026views - 238

VULNZERO-DAY

OpenAI Codex: Reported Sandbox Escape Disclosed (ZDI-26-305)

A reported sandbox escape in OpenAI Codex (ZDI-26-305) could potentially allow code execution via specific JavaScript repositories. Th…

May 27, 2026views - 364

VULN

Docker Desktop ECI Flaw: High-Severity LPE Vulnerability Enables Container Escapes

A vulnerability in Docker Desktop’s Enhanced Container Isolation (ECI) allows for local privilege escalation with a CVSS score of 8.8.…

May 26, 2026views - 298

VULNCRITICAL

CISA Adds Critical Langflow Vulnerability (CVE-2025-34291) to KEV Catalog Following Active Exploitation

CISA has added CVE-2025-34291, a critical origin validation flaw in the Langflow platform, to its Known Exploited Vulnerabilities cata…

May 24, 2026views - 261