// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
VULNCRITICAL

SharePoint Critical RCE via Cryptographic Signature Flaw: The Token Danger

CVE-2026-50522 enables unauthenticated remote code execution on SharePoint Server by bypassing cryptographic verification on session t…

Jul 17, 2026views - 1.5k

VULNZERO-DAY

ZDI-26-416: Hyper-V netvsc.sys Bug Lets Local VM Attacker Escalate to Kernel

The ZDI-26-416 vulnerability in Microsoft Hyper-V's netvsc.sys driver allows a low-privilege attacker inside a Windows VM to escalate…

Jul 17, 2026views - 1.6k

VULNCRITICAL

NVIDIA NeMo Framework: RCE Vulnerability in ML Checkpoints

An unsafe deserialization flaw in NVIDIA NeMo Framework checkpoints enables remote code execution. User interaction is required, but t…

Jul 16, 2026views - 1.3k

VULNZERO-DAY

G DATA Total Security: LPE in Backup Service, SYSTEM Compromised via Symlink

ZDI-26-432 (CVE-2026-13268, CVSS 7.8) details a symbolic link following attack in the G DATA Total Security Backup Service. Here is th…

Jul 16, 2026views - 1.4k

VULNCRITICAL

7-Zip XZ Parser RCE Vulnerability: Opening an Archive Is Enough

A heap-based buffer overflow in 7-Zip's XZ parser enables remote code execution. The flaw, tracked as ZDI-26-444 and CVE-2026-14266, t…

Jul 16, 2026views - 1.7k

VULNCRITICAL

Lorex 0-Day ZDI-26-399: Root RCE on Wi-Fi Camera, No Patch After 14 Months

The ZDI-26-399 vulnerability exposes Lorex 2K Indoor Wi-Fi Security Cameras to root-level remote code execution from the local network…

Jul 08, 2026views - 1.4k

VULN

X.Org Server: A Forgotten Bug Returns as Privilege Escalation — The ZDI-26-395 Case

A use-after-free flaw in SyncChangeCounter enables local privilege escalation to root on X.Org Server. The bug mirrors a pattern alrea…

Jul 07, 2026views - 1.3k

VULN

Januscape: 16-Year-Old KVM Bug Enables Guest-to-Host Escape on Intel and AMD

CVE-2026-53359 strikes the shared shadow MMU code in Linux KVM used by both Intel and AMD. The flaw has existed since 2010 and require…

Jul 06, 2026views - 1.3k

VULNZERO-DAY

ZDI-26-396: Reversed Operator in X.Org Server Opens Door to Arbitrary Read

An elementary coding error in X.Org Server allows out-of-bounds reads with potential escalation: the details of ZDI-26-396.

Jul 02, 2026views - 1.5k

VULNCVE

CVE-2026-48558: Djinn Stealer Exploited In-the-Wild on SimpleHelp

Threat actors exploit CVE-2026-48558 to deploy Djinn Stealer and TaskWeaver. The new infostealer targets AI and cloud credentials. Rou…

Jun 29, 2026views - 1.1k

VULNZERO-DAY

ZDI-26-397: Use-After-Free in X.Org Server Opens Door to Local Privilege Escalation

A Use-After-Free flaw in X.Org Server's CreateSaverWindow function (CVE-2026-50263) lets a local low-privilege attacker leak sensitive…

Jun 28, 2026views - 1.7k

VULNEXPLOIT

DirtyClone: The Fourth Variant in the DirtyFrag Family

CVE-2026-43503, the fourth variant in the DirtyFrag family, exploits cloned packets to corrupt file-backed memory. JFrog published a f…

Jun 26, 2026views - 982