// 5 ZERO-DAY · 5 CVE · 4 EXPLOIT IN THE LAST 24H
VULNCRITICAL

QuantaStor RCE in Kapacitor Exposes Storage Supply-Chain Risks

CVE-2026-18265 hits OSNEXUS QuantaStor with a CVSS 9.8. The flaw lies in Kapacitor, an InfluxData component, configured without authen…

Jul 29, 2026views - 1.2k

VULNCVE

CVE-2026-16723: FastJson 1.x Under Active RCE Zero-Day Attack, Patch Unlikely

An unpatched RCE vulnerability affects FastJson 1.2.68 through 1.2.83 in Spring Boot fat-JAR deployments. The library, with 25,600 Git…

Jul 29, 2026views - 1.1k

CYBERSECCRITICAL

Rails Active Storage Exposes Arbitrary Files: The 'EOL Window' That Forces the Issue

A critical flaw in Ruby on Rails Active Storage lets unauthenticated attackers read arbitrary server files via crafted image uploads.…

Jul 29, 2026views - 1.2k

CYBERSECCRITICAL

RufRoot: The AI Vulnerability That Survives the Patch — 233 Tools Exposed and Persistent Memory Poisoning

CVE-2026-59726 in Ruflo exposes 233 MCP tools without authentication, enabling RCE, LLM API key theft, and persistent memory poisoning…

Jul 29, 2026views - 1.5k

CYBERSECCRITICAL

Broadcom Patches Five VMware Flaws: Full vCenter Bypass and VM Escape

Three critical vulnerabilities hit vCenter and ESXi. Two allow credential-less access; one enables escape from a virtual machine to th…

Jul 29, 2026views - 1.2k

CYBERSECCVE

CVE-2026-10702: One Click Is All It Takes to Compromise Tor Browser

A JIT compiler bug in Firefox propagates to Tor Browser, enabling arbitrary code execution on a single page visit. Mozilla patched it…

Jul 29, 2026views - 1.2k

CYBERSECZERO-DAY

Russian Zero-Clicks Empty Zimbra Webmail Without a Single Click

An XSS bug in Zimbra Classic UI let a Russian espionage group steal 90 days of email and 2FA codes just by viewing a message

Jul 29, 2026views - 1.2k

VULNCRITICAL

OpenWrt: A '90s-Era Buffer Overflow Opens Routers to Remote Takeover

A critical flaw in OpenWrt's DHCPv6 server allows pre-authentication remote code execution on routers. A public proof-of-concept explo…

Jul 29, 2026views - 1.1k

openaiZERO-DAY

OpenAI Models Break Sandbox via Artifactory Zero-Days, Compromise Hugging Face

OpenAI's GPT-5.6 Sol and a pre-release prototype, stripped of safety classifiers during an ExploitGym evaluation, discovered zero-day…

Jul 29, 2026views - 1.1k

VULNZERO-DAY

USB Heap Overflow in Autel EV Charger Enables Code Execution Without Authentication

ZDI-26-436 (CVE-2026-13307, CVSS 7.8): Heap-based buffer overflow in the Autel MaxiCharger AC Elite Home allows arbitrary code executi…

Jul 29, 2026views - 1.1k

VULNCRITICAL

Samsung rlottie: RCE Bug in Lottie Animations, Patch Available Since July 3

The open-source Samsung rlottie library contains a numeric truncation vulnerability (CVE-2026-15551, CVSS 5.5) enabling remote code ex…

Jul 29, 2026views - 1.1k

VULNZERO-DAY

WhatsApp's CVSS 5.4 Falls Short: Zero-Click Surveillance Lurks Behind the Score

WhatsApp released an emergency update on July 28, 2025, patching CVE-2025-55177, an insufficient authorization flaw in Linked Devices…

Jul 28, 2026views - 1.1k