Vulnerabilities
Curated coverage and analysis in this editorial area.

macOS USD Library Bug ZDI-26-315 Exposes System Memory, Patch Issued May 12
Apple has addressed ZDI-26-315, an out-of-bounds read vulnerability in the macOS Universal Scene Description (USD) library. Rated CVSS…

AI Unearths 300 WordPress Zero-Days for $20 Each: The Human Triage Crisis
A high-efficiency AI pipeline has discovered over 300 critical zero-day vulnerabilities in WordPress plugins at an estimated cost of $…

Kemp LoadMaster Vulnerability: Authenticated RCE Found in customLocation Parameter
Advisory ZDI-26-319 reveals a command injection flaw in Progress Software’s Kemp LoadMaster. Authenticated users can exploit the custo…

CVE-2025-68670: Pre-auth RCE Vulnerability Identified in xrdp Server Domain Field
A technical breakdown of CVE-2025-68670: A stack buffer overflow within xrdp's domain name processing logic enables unauthenticated re…

ExifTool RCE: Kaspersky GReAT Uncovers macOS Command Injection via Metadata
CVE-2026-3102 impacts ExifTool versions 13.49 and earlier on macOS. The vulnerability allows for command injection within the SetMacOS…

Drupal to Release ‘Highly Critical’ Core Patch on May 20; Exploit Expected Within Hours
Drupal administrators are on high alert as the Security Team prepares a coordinated release for a major core vulnerability, warning th…

18-Year-Old NGINX Bug CVE-2026-42945 Under Active Attack
Exploitation attempts are underway for CVE-2026-42945, an 18-year-old heap buffer overflow in the NGINX rewrite module. The flaw enabl…

Ollama Vulnerability: CVE-2026-7482 Risks Memory Exposure for 300,000 AI Servers
A critical heap out-of-bounds read vulnerability in Ollama (CVE-2026-7482) allows for memory leakage via GGUF files, putting API keys…

Ollama Flaws Expose Local LLM Memory and Enable Windows Malware Persistence
Three critical CVEs in Ollama allow unauthenticated remote attackers to leak LLM process memory via crafted GGUF files and achieve per…

CVE-2026-42945: Active Exploitation of NGINX Servers Underway
CVE-2026-42945 is being actively exploited in the wild, targeting NGINX rewrite modules to trigger immediate DoS or conditional RCE. C…

NGINX Rift: Critical CVE-2026-42945 Exploitation Detected In-the-Wild
The NGINX Rift vulnerability (CVE-2026-42945) has seen active exploitation since May 16, leveraging a long-dormant heap buffer overflo…

Safari Regex Engine Vulnerability Allows Remote Code Execution via Duplicate Named Groups
Apple has patched a high-severity (CVSS 8.8) remote code execution vulnerability in Safari. The flaw involves a heap-based buffer over…