// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
VULNCRITICAL

Fastjson 1.x Has No Exit: When Standard Mitigations Aren't Enough

CVE-2026-16723 hits Fastjson 1.2.68–1.2.83 with a CVSS 9.0. The exploit works with default settings, requires no AutoType or gadgets,…

Jul 26, 2026views - 1k

VULNCRITICAL

Oracle Simphony: Four Critical CVEs Expose Hospitality POS to RCE

Four vulnerabilities in Oracle Hospitality Simphony enable unauthenticated remote code execution and NTLM hash theft. Patches released…

Jul 25, 2026views - 1.1k

VULNCVE

Twenty-Day Gap: 7-Zip Patch for CVE-2026-14266 Exists, But No Auto-Update Means It Stays Unapplied

7-Zip version 26.02, released June 25, 2026, fixes a heap-based buffer overflow in the XZ decompressor tracked as CVE-2026-14266 and Z…

Jul 25, 2026views - 1.4k

VULNEXPLOIT

Multi-vendor patch day: public exploit for Firefox, four critical vendors

Mozilla confirms public exploit code for two Firefox flaws. Google, Adobe, and VMware ship critical patches on July 15, 2026. No activ…

Jul 24, 2026views - 1.3k

VULNCVE

CVE-2026-6875: Active Attacks on Self-Hosted ServiceNow; Cloud Protected Since April

Threat actors are exploiting CVE-2026-6875 against unpatched self-hosted ServiceNow instances. The sandbox escape enables pre-authenti…

Jul 24, 2026views - 1.4k

VULNCRITICAL

wp2shell: Pre-Auth RCE in WordPress Core, Patched Without a CVE

Searchlight Cyber disclosed wp2shell, a pre-authentication remote code execution vulnerability in WordPress core. Patches landed in ve…

Jul 23, 2026views - 1.3k

VULNEXPLOIT

Windmill Under Attack: Active Path Traversal on 170 Exposed Servers

CVE-2026-29059 hits the Windmill automation platform with an unauthenticated path traversal. A patch has existed since January, yet th…

Jul 23, 2026views - 470

VULNZERO-DAY

OpenSSL's Unsettling Discrepancy: An X.509 Flaw Caught Between Information Disclosure and DoS

CVE-2026-42771 hits OpenSSL with a CVSS 6.5. ZDI calls it information disclosure; CVE.org points to likely DoS. The split complicates…

Jul 23, 2026views - 1.2k

VULNZERO-DAY

WatchGuard FireWare OS: IKEv2 Bug Enables Remote DoS with a Single Packet

A null pointer dereference in WatchGuard FireWare OS exposes firewalls with active IKEv2 VPN to remote denial-of-service. CVE-2026-130…

Jul 23, 2026views - 1.3k

VULNCRITICAL

Samsung rlottie: RCE Bug in Lottie Files Masked by a "Medium" CVSS

A numeric truncation flaw in Samsung rlottie enables remote code execution via malicious Lottie animations. The CVSS 5.5 rating unders…

Jul 23, 2026views - 1.6k

VULNCRITICAL

Autel EV Charger: Remote RCE via OCPP WebSocket, Discovered at Pwn2Own

The ZDI-26-437 vulnerability in the Autel MaxiCharger AC Elite Home enables pre-authentication remote code execution via an integer un…

Jul 22, 2026views - 1.3k

VULNCVE

CVE-2026-31431 "Copy Fail": 732 Bytes of Code Breaks the Linux Kernel Since 2017

A vulnerability in the algif_aead module enables root privilege escalation via a 732-byte exploit. CISA has added CVE-2026-31431 to th…

Jul 21, 2026views - 1.6k