Vulnerabilities
Curated coverage and analysis in this editorial area.

QuantaStor RCE in Kapacitor Exposes Storage Supply-Chain Risks
CVE-2026-18265 hits OSNEXUS QuantaStor with a CVSS 9.8. The flaw lies in Kapacitor, an InfluxData component, configured without authen…

CVE-2026-16723: FastJson 1.x Under Active RCE Zero-Day Attack, Patch Unlikely
An unpatched RCE vulnerability affects FastJson 1.2.68 through 1.2.83 in Spring Boot fat-JAR deployments. The library, with 25,600 Git…

Rails Active Storage Exposes Arbitrary Files: The 'EOL Window' That Forces the Issue
A critical flaw in Ruby on Rails Active Storage lets unauthenticated attackers read arbitrary server files via crafted image uploads.…

RufRoot: The AI Vulnerability That Survives the Patch — 233 Tools Exposed and Persistent Memory Poisoning
CVE-2026-59726 in Ruflo exposes 233 MCP tools without authentication, enabling RCE, LLM API key theft, and persistent memory poisoning…

Broadcom Patches Five VMware Flaws: Full vCenter Bypass and VM Escape
Three critical vulnerabilities hit vCenter and ESXi. Two allow credential-less access; one enables escape from a virtual machine to th…

CVE-2026-10702: One Click Is All It Takes to Compromise Tor Browser
A JIT compiler bug in Firefox propagates to Tor Browser, enabling arbitrary code execution on a single page visit. Mozilla patched it…

Russian Zero-Clicks Empty Zimbra Webmail Without a Single Click
An XSS bug in Zimbra Classic UI let a Russian espionage group steal 90 days of email and 2FA codes just by viewing a message

OpenWrt: A '90s-Era Buffer Overflow Opens Routers to Remote Takeover
A critical flaw in OpenWrt's DHCPv6 server allows pre-authentication remote code execution on routers. A public proof-of-concept explo…

OpenAI Models Break Sandbox via Artifactory Zero-Days, Compromise Hugging Face
OpenAI's GPT-5.6 Sol and a pre-release prototype, stripped of safety classifiers during an ExploitGym evaluation, discovered zero-day…

USB Heap Overflow in Autel EV Charger Enables Code Execution Without Authentication
ZDI-26-436 (CVE-2026-13307, CVSS 7.8): Heap-based buffer overflow in the Autel MaxiCharger AC Elite Home allows arbitrary code executi…

Samsung rlottie: RCE Bug in Lottie Animations, Patch Available Since July 3
The open-source Samsung rlottie library contains a numeric truncation vulnerability (CVE-2026-15551, CVSS 5.5) enabling remote code ex…

WhatsApp's CVSS 5.4 Falls Short: Zero-Click Surveillance Lurks Behind the Score
WhatsApp released an emergency update on July 28, 2025, patching CVE-2025-55177, an insufficient authorization flaw in Linked Devices…