// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
VULNCVE

CVE-2026-32475: Elementor Pro ≤4.2.1 Exposed to Unauthenticated RCE

A critical CVSS 9.0 vulnerability in Elementor Pro allows unauthenticated PHP file upload. The fix sat ready for 34 days before releas…

Aug 25, 2026views - 1.2k

VULN

Fabric.js JSON Parsing Turns Attack Vector: SSRF Bug Discovered

CVE-2026-19504 in Fabric.js' loadFromJSON method enables SSRF attacks for sensitive data disclosure. The fix requires implementing a U…

Aug 25, 2026views - 1k

VULNCRITICAL

Home Assistant Green: Root RCE via Localhost Exploit Disclosed by ZDI

ZDI-26-561 reveals a command injection in the Home Assistant Green go2rtc process. The flaw allows arbitrary code execution as root fo…

Aug 24, 2026views - 1.2k

VULNCVE

CVE-2026-18963: Keycloak Account Takeover in Seconds, Bypassing MFA

A critical flaw in Keycloak's password-reset flow lets an unauthenticated attacker seize any account — including admins — in roughly f…

Aug 24, 2026views - 2.8k

VULNCVE

CVE-2026-4342: A Five-Day Window, Technical Debt With No Exit

The ingress-nginx vulnerability CVE-2026-4342 (CVSS 8.8) was patched in March 2026 but remains unapplied in thousands of clusters. The…

Aug 23, 2026views - 1.2k

VULNZERO-DAY

Amazon Smart Plug: OTA Certificate Bypass Allows Malicious Firmware

The ZDI-26-558 vulnerability in the Amazon Smart Plug's Over-The-Air update process lets a network-adjacent attacker bypass TLS certif…

Aug 22, 2026views - 1.2k

VULNCRITICAL

isolated-vm: C++ Binding Layer Bug Enables Sandbox Escape to Host RCE

A TOCTOU vulnerability in the Node.js isolated-vm library allows guest-to-host escape with potential RCE. Versions 6.2.0 and 7.0.1 pat…

Aug 21, 2026views - 1.1k

VULNZERO-DAY

Trend Micro VPN: Local Privilege Escalation Flaw Allows SYSTEM Takeover

A local privilege escalation vulnerability in Trend Micro VPN, tracked as ZDI-26-577 and CVE-2026-67212, lets an attacker with low-pri…

Aug 20, 2026views - 1.1k

VULN

Notepad++: Institutional Alert Arrives Four Months After the Fix

Singapore's Cyber Security Agency published an advisory on CVE-2026-3008, a string injection flaw in Notepad++ 8.9.3 with a CVSS 6.6 s…

Aug 20, 2026views - 1.2k

VULNZERO-DAY

Copy Fail: The 732-Byte Linux Kernel Bug That Slept Since 2017

An unprivileged local user gains root deterministically. The exploit weighs 732 bytes. The bug had been in the kernel since 2017. This…

Aug 19, 2026views - 1.2k

VULNZERO-DAY

Apple Patches Decade-Old iOS Zero-Day: dyld Exposed to Commercial Spyware

Apple has fixed CVE-2026-20700, a vulnerability in dyld present for over a decade and exploited in targeted attacks. The exploit chain…

Aug 18, 2026views - 1.5k

VULN

Parallels RAS Client: LPE to SYSTEM After 168 Days of Waiting

ZDI-26-556 reveals an exposed dangerous function in the RAS RDP Backend Service. Local escalation to SYSTEM after 168 days of coordina…

Aug 18, 2026views - 1.1k