// 4 ZERO-DAY · 5 CVE · 4 EXPLOIT IN THE LAST 24H
CYBERSECZERO-DAY

F5 Races Against Its Own Stolen Code: 45 Vulnerabilities Disclosed in a Single Quarter

Nation-state actors compromised F5's internal systems, exfiltrating portions of BIG-IP proprietary source code and details on undisclo…

Aug 03, 2026views - 1.1k

CYBERSECCRITICAL

Broadcom Patches Five VMware Vulnerabilities: Three Critical Flaws Up to CVSS 9.8

Broadcom released patches on July 29, 2026 for five vulnerabilities in VMware vCenter, ESXi, Workstation, and Fusion. Three are critic…

Aug 03, 2026views - 1.1k

CYBERSECCRITICAL

NGINX Rift and Fragnesia: Two Critical Flaws at the Heart of Internet Infrastructure

An 18-year-old heap overflow hits nearly 19 million NGINX servers with unauthenticated RCE, while a local Linux exploit corrupts the p…

Aug 03, 2026views - 1.2k

CYBERSECZERO-DAY

May 2026 Patch Tuesday: 161 CVEs, No Zero-Days, But Wormable Risks Loom

Microsoft's May 2026 Patch Tuesday fixes 161 vulnerabilities with no actively exploited zero-days — the first such month since June 20…

Aug 03, 2026views - 1.1k

VULNCRITICAL

GStreamer RCE Flaw in rtpsbcdepay Codec: Patch Available

ZDI-26-467 (CVE-2026-18299) details a use-after-free in GStreamer's RTP SBC depayloader enabling remote code execution. The primary ri…

Aug 03, 2026views - 1.1k

VULNCRITICAL

SSRF in Phoenix Contact MQTT Broker: The Assault on EV Chargers Starts Here

ZDI-26-518 reveals a flaw in the MQTT service of Phoenix Contact CHARX SEC-3150 EV chargers. An unauthenticated, network-adjacent atta…

Aug 03, 2026views - 1.1k

CYBERSEC

Estée Lauder's 10-Month Oracle EBS Breach: The Suspected Patch Gap That Let Clop In

Estée Lauder disclosed a 10-month breach of its Oracle E-Business Suite HR system. The Clop ransomware group exploited CVE-2025-61882,…

Aug 02, 2026views - 1.2k

pythonCVE

CVE-2026-6100: CPython Use-After-Free in Decompressors Rated CVSS 9.1 Critical

CVE-2026-6100 affects CPython with a use-after-free in the lzma, bz2, and gzip decompressors. The CVSS 4.0 score is 9.1 CRITICAL, thou…

Aug 02, 2026views - 1k

VULNCRITICAL

Aeon RCE via Pickle Dataset: ML Pipeline Risk

CVE-2026-18285: The Python library Aeon executed arbitrary code through pickle deserialization of seemingly legitimate datasets. The b…

Aug 02, 2026views - 1.1k

CYBERSECCVE

TrendAI Vision One and the 'Historical' CVE-2025-71387: Patched in December

Trend Micro published bulletin KA-0023937 for CVE-2025-71387, a privilege escalation vulnerability in TrendAI Vision One that was alre…

Aug 02, 2026views - 1.1k

CYBERSECCRITICAL

Heimdall Data Database Proxy: Root RCE via Directory Traversal in uploadJar

ZDI-26-479 reveals a critical flaw in the uploadJar method of Heimdall Data Database Proxy. An authenticated attacker can achieve arbi…

Aug 02, 2026views - 188

CYBERSEC

Kemp LoadMaster: Hard-Coded Key in enablexroot Exposes Appliance to Root

Progress Software has patched CVE-2026-59689, a CVSS 8.0 privilege-escalation vulnerability in Kemp LoadMaster caused by a hard-coded…

Aug 02, 2026views - 1.1k