// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
VULNZERO-DAY

macOS USD Library Bug ZDI-26-315 Exposes System Memory, Patch Issued May 12

Apple has addressed ZDI-26-315, an out-of-bounds read vulnerability in the macOS Universal Scene Description (USD) library. Rated CVSS…

May 23, 2026views - 228

VULNZERO-DAY

AI Unearths 300 WordPress Zero-Days for $20 Each: The Human Triage Crisis

A high-efficiency AI pipeline has discovered over 300 critical zero-day vulnerabilities in WordPress plugins at an estimated cost of $…

May 22, 2026views - 573

VULNCRITICAL

Kemp LoadMaster Vulnerability: Authenticated RCE Found in customLocation Parameter

Advisory ZDI-26-319 reveals a command injection flaw in Progress Software’s Kemp LoadMaster. Authenticated users can exploit the custo…

May 21, 2026views - 238

VULNCVE

CVE-2025-68670: Pre-auth RCE Vulnerability Identified in xrdp Server Domain Field

A technical breakdown of CVE-2025-68670: A stack buffer overflow within xrdp's domain name processing logic enables unauthenticated re…

May 21, 2026views - 264

VULNCRITICAL

ExifTool RCE: Kaspersky GReAT Uncovers macOS Command Injection via Metadata

CVE-2026-3102 impacts ExifTool versions 13.49 and earlier on macOS. The vulnerability allows for command injection within the SetMacOS…

May 20, 2026views - 196

VULNCRITICAL

Drupal to Release ‘Highly Critical’ Core Patch on May 20; Exploit Expected Within Hours

Drupal administrators are on high alert as the Security Team prepares a coordinated release for a major core vulnerability, warning th…

May 19, 2026views - 260

VULNCVE

18-Year-Old NGINX Bug CVE-2026-42945 Under Active Attack

Exploitation attempts are underway for CVE-2026-42945, an 18-year-old heap buffer overflow in the NGINX rewrite module. The flaw enabl…

May 19, 2026views - 200

VULNCVE

Ollama Vulnerability: CVE-2026-7482 Risks Memory Exposure for 300,000 AI Servers

A critical heap out-of-bounds read vulnerability in Ollama (CVE-2026-7482) allows for memory leakage via GGUF files, putting API keys…

May 19, 2026views - 233

VULNEXPLOIT

Ollama Flaws Expose Local LLM Memory and Enable Windows Malware Persistence

Three critical CVEs in Ollama allow unauthenticated remote attackers to leak LLM process memory via crafted GGUF files and achieve per…

May 18, 2026views - 253

VULNCVE

CVE-2026-42945: Active Exploitation of NGINX Servers Underway

CVE-2026-42945 is being actively exploited in the wild, targeting NGINX rewrite modules to trigger immediate DoS or conditional RCE. C…

May 18, 2026views - 210

VULNCRITICAL

NGINX Rift: Critical CVE-2026-42945 Exploitation Detected In-the-Wild

The NGINX Rift vulnerability (CVE-2026-42945) has seen active exploitation since May 16, leveraging a long-dormant heap buffer overflo…

May 18, 2026views - 190

VULNCRITICAL

Safari Regex Engine Vulnerability Allows Remote Code Execution via Duplicate Named Groups

Apple has patched a high-severity (CVSS 8.8) remote code execution vulnerability in Safari. The flaw involves a heap-based buffer over…

May 18, 2026views - 169