// 3 ZERO-DAY · 7 CVE · 5 EXPLOIT · 1 ADVISORY IN THE LAST 24H
CYBERSECEXPLOIT

Adobe ColdFusion: July 1 Patch, Active Exploit Within Hours

Adobe released security updates for ColdFusion on July 1, 2026, fixing 11 vulnerabilities, six rated CVSS 10.0. Within hours, the Cana…

Jul 06, 2026views - 1.2k

CYBERSEC

Cisco Talos Releases ClamAV 1.5.3 and 1.4.5: Seven Legacy Vulnerabilities Patched

ClamAV 1.5.3 and 1.4.5 address vulnerabilities in PE file, archive, and disk image parsers. Two bugs survived roughly 20 years in crit…

Jul 05, 2026views - 1.3k

CYBERSECCVE

CVE-2026-9787: RCE in Quest NetVault Backup with SYSTEM Execution

A vulnerability in the NVBULogDaemon component of Quest NetVault Backup enables remote code execution with authentication bypass. The…

Jul 05, 2026views - 1.3k

CYBERSEC

Researcher Documents Real-Time Shared Access Between FortiBleed Operator and INC Ransom, Lynx Panels for First Time

SOCRadar documented that an operator with access to the FortiBleed infrastructure was simultaneously logged into the negotiation panel…

Jul 04, 2026views - 1.3k

apple

Apple Compresses Patch Cycle After AI Uncovers Four WebKit Flaws

On June 29, 2026, Apple released iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, and Safari 26.5.2, addressing over 30 vulnerabilities.…

Jul 04, 2026views - 1.5k

CYBERSECZERO-DAY

Bad Epoll: Linux Kernel Bug Roots Android, Escapes Chrome Sandbox

CVE-2026-46242 is a race condition in the Linux kernel's epoll subsystem that allows an unprivileged user to gain root privileges. The…

Jul 03, 2026views - 1.3k

CYBERSEC

Medtronic Begins Breach Notifications: 369,200+ Confirmed Victims vs. 9 Million Claimed by ShinyHunters

Medtronic has started notifying individuals affected by an April 2026 corporate IT breach. State regulator filings confirm over 369,20…

Jul 02, 2026views - 1.5k

CYBERSECEXPLOIT

Cisco Confirms: Unified CM SSRF Exploited, 48-Hour Window from PoC to Attacks

Cisco confirmed on July 1, 2026, that CVE-2026-20230, an SSRF vulnerability in Unified Communications Manager, is under active in-the-…

Jul 02, 2026views - 1.3k

VULNZERO-DAY

ZDI-26-396: Reversed Operator in X.Org Server Opens Door to Arbitrary Read

An elementary coding error in X.Org Server allows out-of-bounds reads with potential escalation: the details of ZDI-26-396.

Jul 02, 2026views - 1.4k

CYBERSEC

FortiBleed, the Missing Link: From 430,000 Targeted Firewalls to INC and Lynx Ransomware

SOCRadar ties the FortiBleed credential theft campaign to the INC and Lynx ransomware groups, revealing a single operator managing bot…

Jul 02, 2026views - 1.4k

CYBERSECCRITICAL

ZDI-26-377: XSS in NetVault Backup Enables Auth Bypass and SYSTEM RCE Chain

An XSS flaw in the viewclient page of Quest NetVault Backup lets a remote attacker bypass authentication and, when chained with other…

Jul 01, 2026views - 706

CYBERSECCRITICAL

Cursor Hit by Two Critical CVEs: RCE and Zero-Click via Sandbox Prompt Injection

Two vulnerabilities in Cursor rated CVSS 9.8 allow sandbox escape and remote code execution without user interaction. The fix is avail…

Jul 01, 2026views - 714