// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
VULNEXPLOIT

CopyEscape: A Simple docker cp Opens the Door to Container Escape

CVE-2026-17106 turns docker cp into a container escape vector. Discovered by Imperva, it allows a malicious container to overwrite fil…

Aug 12, 2026views - 1.3k

VULNZERO-DAY

Windows: win32kfull Driver Bug Allows Escalation to SYSTEM

Microsoft released a fix on August 11, 2026 for CVE-2026-62712, a vulnerability in the win32kfull driver that allows code running with…

Aug 12, 2026views - 1.2k

VULNCRITICAL

Phoenix Contact CHARX SEC-3000: RCE as Root via Command Injection

CVE-2026-44095 in EV charging security appliances lets an authenticated, network-adjacent attacker execute arbitrary code as root.

Aug 12, 2026views - 1.1k

VULN

Parallels RAS Client: Local Privilege Escalation to SYSTEM via Exposed Dangerous Function

ZDI advisory ZDI-26-556 discloses a local privilege escalation flaw in the Parallels RAS Client RAS RDP Backend Service. An attacker w…

Aug 12, 2026views - 1.2k

VULNCRITICAL

Galaxy S25: RCE TIFF Flaw Patched in July, Disclosure Arrives in August

Trend Micro's Zero Day Initiative published advisory ZDI-26-529 on August 12, 2026, detailing a heap-based buffer overflow in the Sams…

Aug 12, 2026views - 1.2k

VULN

CISA Confirms SharePoint Ransomware Exploitation; Microsoft Stays Silent

The U.S. cybersecurity agency confirmed on August 11, 2026, that ransomware groups are actively exploiting CVE-2026-45659 in on-premis…

Aug 11, 2026views - 1.2k

VULN

Trend Cleaner One Pro: Cleanup Service Turned Weapon for Arbitrary File Deletion

ZDI-26-496 reveals a vulnerability in Cleaner One Pro's Junk Files Cleanup service that allows a local attacker to delete arbitrary fi…

Aug 11, 2026views - 1.1k

VULNEXPLOIT

Dirty Frag: Linux Kernel LPE Chain with Public PoC and Patches Available

Dirty Frag is a two-vulnerability chain in the Linux kernel that enables root escalation on nearly all distributions. Mainline patches…

Aug 09, 2026views - 1.2k

VULNCRITICAL

Heimdall Data: Root RCE in Database Proxy Poses Infrastructure-Wide Risk

ZDI-26-479 reveals a directory traversal flaw in the uploadJar method of Heimdall Data Database Proxy. Authentication is required, but…

Aug 08, 2026views - 1.2k

VULNZERO-DAY

Samsung Patches Android Zero-Day Discovered by Meta: The Invisible Chain of Responsibility

Samsung has patched CVE-2025-21043, an out-of-bounds write in libimagecodec.quram.so enabling remote code execution. The flaw was repo…

Aug 06, 2026views - 1.2k

VULNCRITICAL

ZDI-26-520: Pre-auth RCE in Phoenix Contact EV Charging Controller

A path-validation flaw in the firmware-update endpoint of the Phoenix Contact CHARX SEC-3150 EV charging controller allows unauthentic…

Aug 06, 2026views - 1.2k

VULNCRITICAL

Sony XAV-9500ES: Bluetooth RCE Found at Pwn2Own, Fix Available

A heap-based buffer overflow in the AVRCP parser of the Sony XAV-9500ES allows remote code execution by an attacker with a paired Blue…

Aug 05, 2026views - 1.4k