Vulnerabilities
Curated coverage and analysis in this editorial area.

Synology MailPlus: Three Critical CVEs, 2,100+ Servers Exposed
Synology released MailPlus Server 4.0.1-31663 to fix three critical vulnerabilities enabling arbitrary file read/write and internal se…

CVE-2026-9779: RCE in ATEN Unizon via Flawed Cryptographic Signature Check
The ZDI-26-383 vulnerability enables remote code execution with SYSTEM privileges by exploiting a signature verification error in ATEN…

macOS: Standard Users Disable EDR/MDM Without Admin Rights
A privilege escalation technique on macOS exploits CDHash caching and NIB injection to silently disable enterprise security tools. App…

Path Traversal in Allegra: CVE-2026-11442 Exposes Arbitrary Files
The ZDI-26-357 vulnerability in Allegra's exportReport method allows an authenticated remote attacker to read arbitrary files via path…

DifyTap: Four CVEs Expose Broken Cross-Tenant Isolation in Dify
Zafran Security disclosed DifyTap, four vulnerabilities in Dify that allowed cross-tenant reading of conversations and files. Three we…

Atril RCE via EPUB: Patch Available Nine Days Before Disclosure
ZDI-26-360: A heap buffer overflow in the MATE Desktop's Atril document viewer enables remote code execution through malicious EPUB fi…

Gravity SMTP: 17M Attacks Exploit Info-Disclosure Bug
CVE-2026-4020 in the WordPress Gravity SMTP plugin is under active exploitation, exposing email credentials and infrastructure bluepri…

ZDI-26-358: Allegra Patches XSS in downloadAttachment Method
The ZDI-26-358 advisory from Trend Micro's Zero Day Initiative discloses a cross-site scripting vulnerability in Allegra's downloadAtt…

X.Org Server UAF CVE-2026-34001: Local Root Escalation on Linux
ZDI-26-335 discloses a use-after-free in X.Org Server's SyncTriggerList: CVSS 7.8, local attack with no user interaction, X.Org patch…

CISA Adds Joomla JCE to KEV: Pre-Auth RCE, CVSS 10.0
CISA added CVE-2026-48907 to the Known Exploited Vulnerabilities catalog on June 16, 2026, confirming active exploitation of a pre-aut…

Vertex AI SDK: Cross-Tenant Bucket Squatting Enabled RCE
Google Cloud Vertex AI SDK versions 1.139.0 through 1.140.0 were vulnerable to cross-tenant bucket squatting leading to remote code ex…

LiteSpeed cPanel: Two CVEs Added to KEV Catalog, Shared Hosting at Risk
CISA adds two distinct LiteSpeed cPanel plugin flaws to its Known Exploited Vulnerabilities catalog: root privilege escalation on shar…