// 4 ZERO-DAY · 5 CVE · 4 EXPLOIT IN THE LAST 24H
CYBERSECEXPLOIT

TP-Link Omada: 15 Zero-Touch Provisioning Flaws Expose Enterprise Networks

Forescout discovered 15 vulnerabilities in TP-Link Omada's Zero-Touch Provisioning. An attack chain combining CVE-2025-7850 and CVE-20…

Aug 05, 2026views - 1.3k

cveCVE

CISA Orders 3-Day Patch Deadline for CVE-2026-18577 in N-able N-central

CISA added CVE-2026-18577 to its Known Exploited Vulnerabilities catalog with a three-day patching deadline for federal agencies. The…

Aug 05, 2026views - 1.3k

VULNCRITICAL

Sony XAV-9500ES: Bluetooth RCE Found at Pwn2Own, Fix Available

A heap-based buffer overflow in the AVRCP parser of the Sony XAV-9500ES allows remote code execution by an attacker with a paired Blue…

Aug 05, 2026views - 1.3k

VULNCRITICAL

ZDI-26-463: RCE in GStreamer via MRF File, Patch Available

Trend Micro's Zero Day Initiative published advisory ZDI-26-463 detailing a remote code execution vulnerability in GStreamer's MRF par…

Aug 05, 2026views - 1.3k

CYBERSECEXPLOIT

Kenwood DNR1007XR Command Injection: Root Code Execution Without Authentication

CVE-2026-18272 in the Kenwood DNR1007XR multimedia system allows physically present attackers to execute arbitrary code as root withou…

Aug 05, 2026views - 1.3k

CYBERSEC

ChainDrop: The npm Worm That Compromised 444 Packages in Under Four Hours

Analysis of the August 4, 2026 ChainDrop attack: a self-replicating npm worm that abused OIDC Trusted Publishing with valid SLSA prove…

Aug 05, 2026views - 1.3k

VULNCRITICAL

Apple Patches ImageIO RCE: Numeric Truncation Fixed in macOS Tahoe 26.6

CVE-2026-43780 in Apple's ImageIO framework allowed remote code execution via malicious textures. The fix is available today across ei…

Aug 05, 2026views - 1.3k

CYBERSEC

Bitdefender Shredder Privilege Escalation to SYSTEM: Update Immediately to 27.0.58.315

ZDI-26-448 exploits Bitdefender's File Shredder to escalate local privileges to SYSTEM. CVE-2026-6851 carries a CVSS 4.0 score of 7.0;…

Aug 05, 2026views - 1.1k

CYBERSECCVE

CVE-2026-63077: Critical RCE in JetBrains TeamCity, CVSS 9.8

JetBrains has patched a deserialization vulnerability in TeamCity On-Premises with a CVSS 9.8 score. The unauthenticated RCE via the a…

Aug 05, 2026views - 1.2k

CYBERSECCRITICAL

WatchGuard FireWare OS: Directory Traversal in sigd Service Opens Path to Code Execution

A directory traversal vulnerability in the sigd service of WatchGuard FireWare OS allows an authenticated remote attacker to create ar…

Aug 05, 2026views - 1.2k

VULNCVE

CVE-2026-66066: Unauthenticated RCE in Rails via Active Storage, Public Metasploit Exploit

A critical Ruby on Rails vulnerability enables arbitrary file read and unauthenticated RCE through Active Storage when using libvips.…

Aug 04, 2026views - 1.2k

CYBERSEC

Three Decades of Forensic DNA Evidence Left Without Digital Signatures

A CVSS 8.2 vulnerability in Thermo Fisher Applied Biosystems software allows tampering with forensic DNA files. The patch adds digital…

Aug 04, 2026views - 1.2k