// 1 CRITICAL · 2 ZERO-DAY · 4 CVE · 7 EXPLOIT IN THE LAST 24H
zeroZERO-DAY

Exploitarium: The 'Recruitment by Chaos' That Shatters the CVD Model

Pseudonymous researcher 'bikini' dumped over 30 zero-day PoC exploits on GitHub on June 27, 2026, without any vendor coordination. CVE…

Aug 24, 2026views - 1k

zeroZERO-DAY

CISA Adds Apple Zero-Day CVE-2025-43300 to KEV Catalog: CVSS 10, September 11 Deadline

CISA has cataloged CVE-2025-43300, an out-of-bounds write in Apple ImageIO rated CVSS 10.0 CRITICAL. Federal civilian agencies must pa…

Aug 22, 2026views - 1.1k

zeroZERO-DAY

GeoServer Zero-Day Under Attack: The Regression Exposing Cracks in the Secure Development Lifecycle

Threat actors began probing a SQL injection zero-day in GeoServer within hours of its public disclosure on August 12, 2026. The vulner…

Aug 15, 2026views - 1.2k

zeroZERO-DAY

PAX Q80: 0-day ZDI-26-526 Leaves Payment Terminals Unpatched

Trend Micro's Zero Day Initiative has published advisory ZDI-26-526, a 0-day vulnerability with a CVSS 7.5 score that enables RCE as r…

Aug 11, 2026views - 1.3k

zeroZERO-DAY

Qualcomm Zero-Day Exploited in Targeted Attacks: Android Remains Exposed

Google confirms limited exploitation of CVE-2026-21385 in the Qualcomm graphics kernel. Patches have existed since January, but delive…

Aug 11, 2026views - 1.1k

zeroZERO-DAY

Commercial Spyware and Zero-Days: Smartphone Exploit Chains Are Now a Product

Zero-click exploit chains for iOS and Android have become commercial products. Bitdefender's dossier compiles confirmed cases and docu…

Jul 27, 2026views - 1.2k

zeroZERO-DAY

AnyDesk 0-Day ZDI-26-400: Vendor Ignored 16 Months of Coordinated Disclosure

ZDI published advisory ZDI-26-400 for CVE-2026-15681, a local denial-of-service vulnerability in AnyDesk rated CVSS 4.7. The vendor re…

Jul 23, 2026views - 1.5k

zeroZERO-DAY

LegacyHive: Nightmare Eclipse's Ninth Zero-Day Pierces Fully Patched Windows

Nightmare Eclipse has released LegacyHive, a zero-day exploit targeting the Windows User Profile Service to load arbitrary registry hi…

Jul 20, 2026views - 1.5k

zeroEXPLOIT

Exploitarium: The Speed Paradox — Public Exploits for Already-Patched Flaws

Pseudonymous researcher 'bikini' dumped 30+ zero-day PoCs on GitHub without coordinated disclosure. CVE-2026-55200 in libssh2 had a fi…

Jul 07, 2026views - 1.5k

zeroZERO-DAY

Active Exchange Zero-Day: Unpatched OWA Vulnerability Under Exploitation

Microsoft has confirmed CVE-2026-42897, a zero-day XSS vulnerability in on-premise Exchange servers currently under active attack. Wit…

May 18, 2026views - 244

zeroZERO-DAY

Palo Alto Networks Zero-Day: PAN-OS Vulnerability Grants Attackers Root Perimeter Control

CVE-2026-0300 enables unauthenticated root RCE on PAN-OS firewalls. With CISA Mandating mitigation within three days, we analyze the e…

May 16, 2026views - 294

zeroZERO-DAY

Ivanti EPMM Zero-Day: Admin-Authenticated RCE Triggers Urgent CISA Patch Mandate

Ivanti has disclosed CVE-2026-6973, a critical zero-day in Endpoint Manager Mobile (EPMM) allowing RCE with administrative privileges.…

May 16, 2026views - 155