Vulnerabilities
Curated coverage and analysis in this editorial area.

macOS USD Library Buffer Overflow Enables RCE via Malicious 3D Files
CVE-2026-43729 is a heap-based buffer overflow in Apple's USD library that allows arbitrary code execution through crafted 3D scene fi…

QuantaStor RCE in Kapacitor Exposes Storage Supply-Chain Risks
CVE-2026-18265 hits OSNEXUS QuantaStor with a CVSS 9.8. The flaw lies in Kapacitor, an InfluxData component, configured without authen…

CVE-2026-16723: FastJson 1.x Under Active RCE Zero-Day Attack, Patch Unlikely
An unpatched RCE vulnerability affects FastJson 1.2.68 through 1.2.83 in Spring Boot fat-JAR deployments. The library, with 25,600 Git…

OpenWrt: A '90s-Era Buffer Overflow Opens Routers to Remote Takeover
A critical flaw in OpenWrt's DHCPv6 server allows pre-authentication remote code execution on routers. A public proof-of-concept explo…

USB Heap Overflow in Autel EV Charger Enables Code Execution Without Authentication
ZDI-26-436 (CVE-2026-13307, CVSS 7.8): Heap-based buffer overflow in the Autel MaxiCharger AC Elite Home allows arbitrary code executi…

Samsung rlottie: RCE Bug in Lottie Animations, Patch Available Since July 3
The open-source Samsung rlottie library contains a numeric truncation vulnerability (CVE-2026-15551, CVSS 5.5) enabling remote code ex…

WhatsApp's CVSS 5.4 Falls Short: Zero-Click Surveillance Lurks Behind the Score
WhatsApp released an emergency update on July 28, 2025, patching CVE-2025-55177, an insufficient authorization flaw in Linked Devices…

Apple Patches iOS 26 dyld Zero-Day: Targeted Attacks Already Underway
Apple has released iOS 26.3 to address CVE-2026-20700, a zero-day vulnerability in the dyld component exploited in sophisticated attac…

SCADA DAQFactory: RCE via Engineered .ctl File, Patch Available
ZDI-26-450 (CVE-2026-12921) exposes AzeoTech DAQFactory 21.1 and earlier to remote code execution through a use-after-free in the .ctl…

ZDI-26-419: AdobeUpdateService Bug Allows Local Privilege Escalation to SYSTEM
The ZDI-26-419 vulnerability (CVE-2026-48272) in Adobe Creative Cloud Desktop enables local privilege escalation to SYSTEM via CWE-427…

MSI Center's Ghost Driver: Local Escalation to SYSTEM in One Command
ZDI-26-430 discloses an origin validation flaw in the MSI Center kernel driver NTIOLib_X64.sys, tracked as CVE-2026-6102 (CVSS 7.8). A…

ZDI-26-443: Linux Kernel vmwgfx Integer Overflow Enables Local Privilege Escalation at CVSS 8.8
An integer overflow in the Linux kernel's vmwgfx graphics driver allows local privilege escalation to kernel context. Published July 1…