Vulnerabilities
Curated coverage and analysis in this editorial area.

Fastjson 1.x Has No Exit: When Standard Mitigations Aren't Enough
CVE-2026-16723 hits Fastjson 1.2.68–1.2.83 with a CVSS 9.0. The exploit works with default settings, requires no AutoType or gadgets,…

Oracle Simphony: Four Critical CVEs Expose Hospitality POS to RCE
Four vulnerabilities in Oracle Hospitality Simphony enable unauthenticated remote code execution and NTLM hash theft. Patches released…

Twenty-Day Gap: 7-Zip Patch for CVE-2026-14266 Exists, But No Auto-Update Means It Stays Unapplied
7-Zip version 26.02, released June 25, 2026, fixes a heap-based buffer overflow in the XZ decompressor tracked as CVE-2026-14266 and Z…

Multi-vendor patch day: public exploit for Firefox, four critical vendors
Mozilla confirms public exploit code for two Firefox flaws. Google, Adobe, and VMware ship critical patches on July 15, 2026. No activ…

CVE-2026-6875: Active Attacks on Self-Hosted ServiceNow; Cloud Protected Since April
Threat actors are exploiting CVE-2026-6875 against unpatched self-hosted ServiceNow instances. The sandbox escape enables pre-authenti…

wp2shell: Pre-Auth RCE in WordPress Core, Patched Without a CVE
Searchlight Cyber disclosed wp2shell, a pre-authentication remote code execution vulnerability in WordPress core. Patches landed in ve…

Windmill Under Attack: Active Path Traversal on 170 Exposed Servers
CVE-2026-29059 hits the Windmill automation platform with an unauthenticated path traversal. A patch has existed since January, yet th…

OpenSSL's Unsettling Discrepancy: An X.509 Flaw Caught Between Information Disclosure and DoS
CVE-2026-42771 hits OpenSSL with a CVSS 6.5. ZDI calls it information disclosure; CVE.org points to likely DoS. The split complicates…

WatchGuard FireWare OS: IKEv2 Bug Enables Remote DoS with a Single Packet
A null pointer dereference in WatchGuard FireWare OS exposes firewalls with active IKEv2 VPN to remote denial-of-service. CVE-2026-130…

Samsung rlottie: RCE Bug in Lottie Files Masked by a "Medium" CVSS
A numeric truncation flaw in Samsung rlottie enables remote code execution via malicious Lottie animations. The CVSS 5.5 rating unders…

Autel EV Charger: Remote RCE via OCPP WebSocket, Discovered at Pwn2Own
The ZDI-26-437 vulnerability in the Autel MaxiCharger AC Elite Home enables pre-authentication remote code execution via an integer un…

CVE-2026-31431 "Copy Fail": 732 Bytes of Code Breaks the Linux Kernel Since 2017
A vulnerability in the algif_aead module enables root privilege escalation via a 732-byte exploit. CISA has added CVE-2026-31431 to th…