// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
VULNCVE

CVE-2026-19478: GitLab Patches Critical GraphQL Flaw CVSS 9.4 for Self-Managed Instances

GitLab issued an out-of-cycle patch on August 17, 2026 for CVE-2026-19478, a GraphQL vulnerability rated CVSS 9.4 that allows an unaut…

Aug 18, 2026views - 1.1k

VULN

AMD Confirms Two High-Severity TPM 2.0 Flaws in Ryzen: Fixes Were Circulating Since May 2026

AMD published advisory AMD-SB-7064 on August 11, 2026, disclosing two high-severity TPM 2.0 vulnerabilities (CVE-2026-6726 and CVE-202…

Aug 17, 2026views - 1.1k

VULNZERO-DAY

ZDI-26-573: Pre-Auth Linux Kernel KSMBD Vulnerability Scores CVSS 9.3

A critical flaw in the in-kernel KSMBD SMB server allows unauthenticated out-of-bounds reads leading to information disclosure and pot…

Aug 17, 2026views - 328

VULNCRITICAL

NGINX WebDAV: Pre-Auth RCE Disclosed in ZDI-26-578

The ZDI-26-578 advisory reveals a critical RCE flaw in the NGINX HTTP DAV module. It is exploitable without authentication via an inte…

Aug 16, 2026views - 1.3k

VULNCRITICAL

NVIDIA Transformers4Rec Exposed to RCE: ML Checkpoint Turns Weapon

A deserialization flaw in NVIDIA's ML library enables remote code execution via malicious checkpoints. A documented discrepancy betwee…

Aug 16, 2026views - 1.1k

VULNZERO-DAY

dnsmasq: DNSSEC Bug Enables Unauthenticated Remote DoS

A vulnerability in dnsmasq's NSEC/NSEC3 DNSSEC record parsing allows remote denial-of-service attacks without authentication. The flaw…

Aug 16, 2026views - 1.2k

VULNCRITICAL

Flowise Removes Airtable and CSV Agents After Critical RCE (CVSS 9.4)

The low-code AI orchestration platform Flowise has entirely removed its AirtableAgent and CSVAgent components to address an unauthenti…

Aug 15, 2026views - 1.1k

VULN

TONTOU: The Attack That Nullifies Spectre v2 Mitigations and Leaks Linux Passwords

MIT CSAIL researchers demonstrated a bypass of Spectre v2 mitigations on Linux at Black Hat USA 2026. TONTOU extracts password hashes…

Aug 14, 2026views - 1.1k

VULNCRITICAL

ClamAV: The Guardian's Paradox — When the Antivirus Becomes an Attack Weapon

Trend Micro's Zero Day Initiative disclosed advisory ZDI-26-583 on August 13, 2026, detailing an integer overflow in ClamAV's 7z parse…

Aug 13, 2026views - 1.1k

VULNZERO-DAY

ZDI-26-573 Linux Kernel KSMBD Vulnerability Exposes Sensitive Information

An out-of-bounds read in init_smb2_rsp_hdr enables unauthenticated remote information disclosure on systems with KSMBD enabled.

Aug 13, 2026views - 1.1k

VULNZERO-DAY

CCleaner LPE to SYSTEM Bug: Patch Now, Maximum Risk on Shared Endpoints

The CVE-2026-12410 vulnerability in CCleaner's Uninstaller component allows local privilege escalation to SYSTEM via symlink. The patc…

Aug 13, 2026views - 1.2k

VULNZERO-DAY

Metabase Under Zero-Day Attack: Critical SQL Injection with CVSS 10.0 Exposes Entire Data Layers

The Metabase BI platform is under active zero-day exploitation via a critical SQL injection. The risk extends beyond Metabase itself t…

Aug 13, 2026views - 1.1k