Vulnerabilities
Curated coverage and analysis in this editorial area.

CVE-2026-32475: Elementor Pro ≤4.2.1 Exposed to Unauthenticated RCE
A critical CVSS 9.0 vulnerability in Elementor Pro allows unauthenticated PHP file upload. The fix sat ready for 34 days before releas…

Fabric.js JSON Parsing Turns Attack Vector: SSRF Bug Discovered
CVE-2026-19504 in Fabric.js' loadFromJSON method enables SSRF attacks for sensitive data disclosure. The fix requires implementing a U…

Home Assistant Green: Root RCE via Localhost Exploit Disclosed by ZDI
ZDI-26-561 reveals a command injection in the Home Assistant Green go2rtc process. The flaw allows arbitrary code execution as root fo…

CVE-2026-18963: Keycloak Account Takeover in Seconds, Bypassing MFA
A critical flaw in Keycloak's password-reset flow lets an unauthenticated attacker seize any account — including admins — in roughly f…

CVE-2026-4342: A Five-Day Window, Technical Debt With No Exit
The ingress-nginx vulnerability CVE-2026-4342 (CVSS 8.8) was patched in March 2026 but remains unapplied in thousands of clusters. The…

Amazon Smart Plug: OTA Certificate Bypass Allows Malicious Firmware
The ZDI-26-558 vulnerability in the Amazon Smart Plug's Over-The-Air update process lets a network-adjacent attacker bypass TLS certif…

isolated-vm: C++ Binding Layer Bug Enables Sandbox Escape to Host RCE
A TOCTOU vulnerability in the Node.js isolated-vm library allows guest-to-host escape with potential RCE. Versions 6.2.0 and 7.0.1 pat…

Trend Micro VPN: Local Privilege Escalation Flaw Allows SYSTEM Takeover
A local privilege escalation vulnerability in Trend Micro VPN, tracked as ZDI-26-577 and CVE-2026-67212, lets an attacker with low-pri…

Notepad++: Institutional Alert Arrives Four Months After the Fix
Singapore's Cyber Security Agency published an advisory on CVE-2026-3008, a string injection flaw in Notepad++ 8.9.3 with a CVSS 6.6 s…

Copy Fail: The 732-Byte Linux Kernel Bug That Slept Since 2017
An unprivileged local user gains root deterministically. The exploit weighs 732 bytes. The bug had been in the kernel since 2017. This…

Apple Patches Decade-Old iOS Zero-Day: dyld Exposed to Commercial Spyware
Apple has fixed CVE-2026-20700, a vulnerability in dyld present for over a decade and exploited in targeted attacks. The exploit chain…

Parallels RAS Client: LPE to SYSTEM After 168 Days of Waiting
ZDI-26-556 reveals an exposed dangerous function in the RAS RDP Backend Service. Local escalation to SYSTEM after 168 days of coordina…