Vulnerabilities
Curated coverage and analysis in this editorial area.

ZDI-26-463: RCE in GStreamer via MRF File, Patch Available
Trend Micro's Zero Day Initiative published advisory ZDI-26-463 detailing a remote code execution vulnerability in GStreamer's MRF par…

Apple Patches ImageIO RCE: Numeric Truncation Fixed in macOS Tahoe 26.6
CVE-2026-43780 in Apple's ImageIO framework allowed remote code execution via malicious textures. The fix is available today across ei…

CVE-2026-66066: Unauthenticated RCE in Rails via Active Storage, Public Metasploit Exploit
A critical Ruby on Rails vulnerability enables arbitrary file read and unauthenticated RCE through Active Storage when using libvips.…

7-Zip XZ Decoder RCE: Silent Patch Leaves Users Exposed
CVE-2026-14266 enables code execution via a crafted XZ archive. The fix landed in 7-Zip 26.02 on June 25, but the lack of automatic up…

GStreamer RCE Flaw in rtpsbcdepay Codec: Patch Available
ZDI-26-467 (CVE-2026-18299) details a use-after-free in GStreamer's RTP SBC depayloader enabling remote code execution. The primary ri…

SSRF in Phoenix Contact MQTT Broker: The Assault on EV Chargers Starts Here
ZDI-26-518 reveals a flaw in the MQTT service of Phoenix Contact CHARX SEC-3150 EV chargers. An unauthenticated, network-adjacent atta…

Aeon RCE via Pickle Dataset: ML Pipeline Risk
CVE-2026-18285: The Python library Aeon executed arbitrary code through pickle deserialization of seemingly legitimate datasets. The b…

7-Zip: The Patch Existed, But No One Installs It Without Auto-Update
CVE-2026-14266 has affected 7-Zip's XZ decompressor for five years. The fix shipped on June 25, but without automatic updates, the vas…

LegacyHive: The Windows Zero-Day With Free Micropatches While Microsoft Investigates
The LegacyHive zero-day in the Windows User Profile Service enables local privilege escalation. ACROS Security has already released fr…

GIMP: APNG Integer Overflow Enables Code Execution, Patch Released
An integer overflow in GIMP's APNG parser allows remote arbitrary code execution when a user opens a malicious file. Tracked as CVE-20…

GStreamer RCE Bug in MRF Parsing: Urgent Update Required
An out-of-bounds write vulnerability in GStreamer's MRF file parser enables remote code execution. User interaction is required, but t…

Adminer: A 2021 Patch Bug Returns as RCE — The CVE-2026-15686 Case
Vulnerability ZDI-26-478 shows how a fix for CVE-2021-43008 introduced a new RCE vector via catastrophic backtracking in preg_match().