Vulnerabilities
Curated coverage and analysis in this editorial area.

ZDI-26-393: Stack Buffer Overflow in X.Org Server XKB Subsystem Enables Local Root Escalation
The Zero Day Initiative disclosed ZDI-26-393 on June 24, 2026, detailing a local privilege escalation vulnerability in X.Org Server. A…

CVE-2026-12957: Cloud Credential Theft via Amazon Q Developer
A high-severity vulnerability (CVSS 8.5) in the Amazon Q Developer extension for VS Code allowed automatic execution of malicious MCP…

Unit 42 Uncovers Universal Bucket Hijacking Across Multiple Clouds
Unit 42/Palo Alto Networks research: globally unique bucket names in Google Cloud, AWS, and Azure allow data-flow hijacking without co…

CVE-2026-46331: Linux 'pedit COW' Exploit Gains Root in 24 Hours
A Linux kernel bug corrupts the page cache of setuid binaries such as /bin/su without touching disk, bypassing all integrity checks.

DirtyClone: The Fourth Variant in the DirtyFrag Family
CVE-2026-43503, the fourth variant in the DirtyFrag family, exploits cloned packets to corrupt file-backed memory. JFrog published a f…

Linux Foundation Launches Akrites: A Shared SIRT for Open Source Software
Akrites brings 19 tech giants under one shared SIRT for open source vulnerabilities. A 5% patch rate and Dolan's admission: the road a…

Synology MailPlus: Three Critical CVEs, 2,100+ Servers Exposed
Synology released MailPlus Server 4.0.1-31663 to fix three critical vulnerabilities enabling arbitrary file read/write and internal se…

PTC Windchill: First In-the-Wild Exploitation of a PLM System
CVE-2026-12569 is the first PTC vulnerability added to the CISA KEV catalog. Active exploitation with persistent JSP webshells, patche…

ThreatsDay June 2026: Miasma Toolkit Leaked, Claude Code Patched, AI Agent Phishing
The June 2026 ThreatsDay Bulletin, published June 11 by Rescana, is an aggregated cyber threat digest. This analysis relies primarily…

Adobe Reader: Patch Now for CVE-2026-27278, RCE via PDF
Adobe has released APSB26-26 for CVE-2026-27278, a Use-After-Free vulnerability in Acrobat Reader DC that enables remote code executio…

FlowiseAI CSV Agent RCE: Arbitrary Python Code Execution with Authentication Bypass
ZDI-26-365 discloses a remote code execution vulnerability in FlowiseAI's CSV Agent: Python code injection via customReadCSV with auth…

Docker MCP Plugin: RCE via OCI Label, Urgent Patch
ZDI-26-363: The YAML label io.docker.server.metadata in the Docker MCP Gateway enables remote code execution as root. The fix isolates…