Vulnerabilities
Curated coverage and analysis in this editorial area.

DirtyDecrypt: Linux Local Privilege Escalation Exploit Surfaces for Unpatched Systems
A proof-of-concept for 'DirtyDecrypt'—a local privilege escalation flaw in the Linux kernel's RXGK module—is now public. Organizations…

Ivanti EPMM Zero-Day Under Active Exploitation: CISA Adds CVE-2026-6973 to KEV Catalog
A newly disclosed zero-day in Ivanti Endpoint Manager Mobile (EPMM), tracked as CVE-2026-6973, is being actively exploited in the wild…

Ivanti EPMM RCE Under Active Exploitation as Federal Patch Deadline Lapses
CVE-2026-6973, a critical RCE vulnerability in Ivanti EPMM on-premise, is currently being exploited in the wild. The CISA remediation…

Apple Safari WebCore Vulnerability: ZDI-26-312 Enables Remote Code Execution
A use-after-free vulnerability in Safari’s WebCore style resolver allows for remote code execution through user interaction, affecting…

Siemens Simcenter Femap: Malicious IPT Files Trigger RCE via Heap Overflow
Siemens has patched a high-severity heap overflow vulnerability in Simcenter Femap’s Datakit library. The flaw allows remote code exec…

GitHub Enterprise RCE: A Single 'git push' Puts Corporate Backends at Risk
CVE-2026-3854 allows Remote Code Execution on GitHub Enterprise Server via user-controlled push options. Reports indicate that 88% of…

GitHub RCE: Crafted 'git push' Commands Compromised Backend Servers
CVE-2026-3854: An X-Stat header injection vulnerability in GitHub enabled remote code execution via a single push operation. Approxima…

CVE-2026-7482: Technical Analysis of Ollama’s Memory Leak Vulnerability via GGUF
Technical breakdown of CVE-2026-7482 in Ollama. Discovered by Cyera, the vulnerability enables unauthenticated remote attackers to exf…

Exim 'Dead.Letter' Vulnerability: Critical RCE Risk for GnuTLS-Based Builds
CVE-2026-45185 is a use-after-free vulnerability in the Exim SMTP BDAT parser that allows unauthenticated RCE on GnuTLS-compiled serve…

CVE-2026-7482: Malicious GGUF Files Trigger Memory Leaks in Ollama
A heap out-of-bounds read vulnerability in Ollama allows unauthenticated remote attackers to exfiltrate the entire memory of the infer…

Critical GitHub RCE: A Single Git Push Can Trigger Remote Code Execution
A critical RCE vulnerability (CVE-2026-3854) affecting GitHub.com and Enterprise Server allows arbitrary code execution via crafted gi…

Exim Patches Critical Unauthenticated RCE Vulnerability in GnuTLS-Linked Servers
CVE-2026-45185 allows unauthenticated remote code execution on Exim mail servers compiled with GnuTLS. Since there are no available wo…