// 1 CRITICAL · 3 ZERO-DAY · 5 CVE · 3 EXPLOIT IN THE LAST 24H
CYBERSECCRITICAL

Siemens Simcenter Femap Memory Corruption Vulnerability: Coordinated Disclosure Set for May 2026

A high-severity memory corruption vulnerability in Simcenter Femap’s IPT file parser (ZDI-26-317) leaves users with a nine-month expos…

May 27, 2026views - 21

VULNCRITICAL

Progress Software Patches High-Severity Command Injection in Kemp LoadMaster (ZDI-26-319)

An authenticated command injection vulnerability in the customLocation parameter of Kemp LoadMaster carries a CVSS score of 8.8. While…

May 27, 2026views - 11

CYBERSECZERO-DAY

Adobe ColdFusion: Security Update Addresses Reported Authentication Bypass

Advisory ZDI-26-263 describes a reported remote authentication bypass in Adobe ColdFusion. With a CVSS score of 6.5, the vulnerability…

May 27, 2026views - 26

CYBERSECEXPLOIT

Cisco SD-WAN: Potential Targeted Activity Involving Controllers

A report describes potential exploitation of SD-WAN vulnerabilities, noting activity attributed to a group designated as UAT-8616 and…

May 27, 2026views - 24

VULNZERO-DAY

OpenAI Codex: Reported Sandbox Escape Disclosed (ZDI-26-305)

A reported sandbox escape in OpenAI Codex (ZDI-26-305) could potentially allow code execution via specific JavaScript repositories. Th…

May 27, 2026views - 29

CYBERSECEXPLOIT

Apple macOS USD Library Flaw Enables Information Disclosure and Exploit Chaining

A vulnerability in the macOS Universal Scene Description (USD) library (ZDI-26-315) allows for out-of-bounds reads and potential code…

May 26, 2026views - 66

VULN

Docker Desktop ECI Flaw: High-Severity LPE Vulnerability Enables Container Escapes

A vulnerability in Docker Desktop’s Enhanced Container Isolation (ECI) allows for local privilege escalation with a CVSS score of 8.8.…

May 26, 2026views - 47

CYBERSEC

India’s CERT-In Mandates 12-Hour Patch Window to Counter AI-Driven Exploitation

A new 38-page blueprint from CERT-In slashes the remediation window to just 12 hours for exposed systems, citing the rapid weaponizati…

May 26, 2026views - 22

CYBERSECCVE

CISA Adds Drupal SQL Injection Vulnerability to KEV Catalog Following Mass Exploitation

CISA has added the CVE-2026-9082 SQL injection flaw in Drupal Core to its Known Exploited Vulnerabilities catalog. The move follows re…

May 26, 2026views - 31

CYBERSECCVE

CVE-2026-5426: KnowledgeDeliver LMS Targeted by Zero-Day ViewState Exploit

Hard-coded ASP.NET machine keys in KnowledgeDeliver LMS have enabled unauthenticated RCE attacks. Threat actors deployed the BLUEBEAM…

May 26, 2026views - 25

CYBERSECZERO-DAY

300 WordPress Zero-Days in 72 Hours for $20: The Falling Economic Threshold of the Bug

TrendAI and CHT Security researchers have uncovered over 300 critical zero-day vulnerabilities in 72 hours using an AI pipeline develo…

May 25, 2026views - 71

CYBERSECZERO-DAY

Windows Hit by Post-Patch Tuesday Zero-Day Blitz

Security researcher Chaotic Eclipse has disclosed three new Windows zero-day vulnerabilities following the May 2026 Patch Tuesday. To…

May 25, 2026views - 484