Vulnerabilities
Curated coverage and analysis in this editorial area.

AsyncAPI: Five npm Packages Compromised with Valid Provenance
Attackers hijacked the AsyncAPI project's CI/CD pipeline on July 14, 2026, stealing the asyncapi-bot service account token and publish…

AI-Assisted Kernel Exploit: Researcher Publishes Root Escalation Code for Linux
STAR Labs researcher Lee Jia Jie has released exploit code for CVE-2026-53264, a use-after-free vulnerability in the Linux kernel's ne…

Microsoft Patches RoguePlanet, the Defender Black Hole That Handed SYSTEM to Anyone
CVE-2026-50656: a race condition in the Windows 10 and 11 antivirus engine let a standard user gain SYSTEM privileges. The silent engi…

OWAReaper: The Malware That Survives Device Reimaging
Russia-aligned APT Laundry Bear (TA488) exploited CVE-2026-42897, an XSS flaw in Outlook Web Access, to deploy OWAReaper — a browser-b…

Aeon RCE Flaw in Benchmark Loading: The Risk Lies in the Datasets
Trend Micro's Zero Day Initiative published advisory ZDI-26-470 assigning CVE-2026-18287 to a code injection vulnerability in the Pyth…

GIMP: APNG Integer Overflow Enables Code Execution, Patch Released
An integer overflow in GIMP's APNG parser allows remote arbitrary code execution when a user opens a malicious file. Tracked as CVE-20…

GStreamer RCE Bug in MRF Parsing: Urgent Update Required
An out-of-bounds write vulnerability in GStreamer's MRF file parser enables remote code execution. User interaction is required, but t…

Cisco FMC CVE-2026-20316: Actively Exploited Zero-Day, CISA Sets August 1 Deadline
Cisco disclosed CVE-2026-20316, a zero-day static-credential vulnerability in FMC Software. CISA has ordered federal agencies to remed…

Sony XAV-9500ES: Bluetooth Turns Weapon — From Pwn2Own to the Parking Lot
ZDI advisory ZDI-26-475 details a heap-based buffer overflow in the AVRCP parser of the Sony XAV-9500ES head unit, enabling remote cod…

Adminer: A 2021 Patch Bug Returns as RCE — The CVE-2026-15686 Case
Vulnerability ZDI-26-478 shows how a fix for CVE-2021-43008 introduced a new RCE vector via catastrophic backtracking in preg_match().

NoMachine getstat Command Injection Opens Door to RCE, CVSS 8.8
ZDI-26-483 details a command injection flaw in NoMachine's getstat function that allows authenticated remote code execution. A patch i…

WatchGuard FireWare OS Buffer Overflow Turns Firewall Into a Backdoor
A vulnerability in the networkd process of WatchGuard FireWare OS allows an authenticated remote attacker to execute arbitrary code wi…