Vulnerabilities
Curated coverage and analysis in this editorial area.

WordPress wp2shell: In-the-Wild RCE Within 24 Hours of AI-Assisted Discovery
The wp2shell vulnerability chain in WordPress Core is under active in-the-wild exploitation with pre-authentication RCE. Wiz Research…

Heap Overflow in Kenwood DNR1007XR: Malicious vCard Grants Root Code Execution
ZDI-26-488 discloses a vulnerability in the Kenwood infotainment system: a physically present attacker achieves a root shell via a hea…

VoidStealer Bypasses Chrome Encryption by Attacking Memory
VoidStealer circumvents Chrome's App-Bound Encryption by extracting the master key from memory during decryption. The MaaS infostealer…

Apple Patches ImageIO: Parsing Bug Opens Door to RCE Across Eight Operating Systems
A flaw in Apple's ImageIO framework allows remote code execution via malformed image files. Patches are available for eight operating…

Adobe Campaign Classic: Critical CVSS 10.0 Patch for On-Premise Deployments
Adobe has fixed CVE-2026-48449, a maximum-severity vulnerability in Campaign Classic that allows unauthenticated remote code execution…

KNX BCU Key Flaw: How a Security Feature Became a Permanent Denial-of-Service
CISA added CVE-2023-4346 to its Known Exploited Vulnerabilities catalog on July 15, 2026, with a federal remediation deadline of July…

F5 Patches CVE-2026-42533: Heap Buffer Overflow in NGINX Script Engine
F5 released critical patches on July 22, 2026 for CVE-2026-42533, a heap-buffer-overflow vulnerability in the NGINX script engine carr…

Anthropic: Claude Models Accidentally Accessed Real Systems During Cybersecurity Evaluations
Three Claude models gained unauthorized access to real organizational systems during capture-the-flag exercises due to a network misco…

Splunk Enterprise Critical Zero-Day Enables Pre-Auth RCE: When the SIEM Becomes the Entry Point
CVE-2026-20253 hits Splunk Enterprise with a CVSS 9.8 score. The pre-authentication vulnerability in the PostgreSQL sidecar service ea…

Check Point's Firewall Brain Has a Trust-System Flaw
An authentication bypass in Check Point SmartConsole enables remote administrative access. CISA has mandated patching by July 25 for U…

7-Zip: The Patch Existed, But No One Installs It Without Auto-Update
CVE-2026-14266 has affected 7-Zip's XZ decompressor for five years. The fix shipped on June 25, but without automatic updates, the vas…

LegacyHive: The Windows Zero-Day With Free Micropatches While Microsoft Investigates
The LegacyHive zero-day in the Windows User Profile Service enables local privilege escalation. ACROS Security has already released fr…