Windows
TeamViewer Patches Five High-Severity Flaws, Including Remote Session Access Control Bypass to RCE
TeamViewer bulletin TV-2026-1010 fixes five high-severity client and host flaws, led by CVE-2026-92370, a remote-session access control bypass that can lead to code execution. Update to 15.82.
FamousSparrow's New SparroWocky Backdoor Hits Latin American Governments Through Exposed Exchange Servers
ESET details SparroWocky, a new C++ backdoor deployed by the China-aligned FamousSparrow group via public-facing Microsoft Exchange servers against Latin American governments since mid-2025.
The WannaCry Bugs Never Left: Windows' Core Network Stack Just Had Its Worst Year Since EternalBlue
Netlogon, DNS Client, DHCP Server, DNS Server — four unauthenticated, network-reachable, CVSS-9.8-class memory corruption bugs in Windows' core infrastructure services in five months. This is not four unlucky patch cycles. It's a pattern, and most vulnerability-management programs are triaging it wrong.
FalconFlank: Unpatched Local Privilege Escalation Zero-Day in CrowdStrike Falcon Sensor, PoC Public
A public PoC dubbed FalconFlank abuses CrowdStrike Falcon Sensor's malicious-macro remediation to escalate a local user to SYSTEM on fully patched Windows 11 and Server 2025. No CVE, no vendor fix yet — only a workaround.
Critical Veeam ONE Flaw Lets Unauthenticated Attackers Coerce SMB Auth From the Service Account
CVE-2026-65641 (CVSS 9.3) lets an unauthenticated network attacker force Veeam ONE's service account into an SMB authentication attempt, exposing Net-NTLM material for relay or offline cracking.
ShieldBreak (CVE-2026-69414): A Full Bypass of Microsoft's RoguePlanet Defender Patch, Still Unfixed
Nightmare Eclipse's ShieldBreak fully bypasses the fix for RoguePlanet, Microsoft Defender's earlier SYSTEM-privilege zero-day. Microsoft has assigned CVE-2026-69414 and confirmed a patch is in progress, but none has shipped.
Critical Use-After-Free in Microsoft QUIC Allows Unauthenticated RCE (CVE-2026-62815)
CVE-2026-62815, a CVSS 9.8 use-after-free in Microsoft's QUIC/HTTP-3 implementation, lets an unauthenticated remote attacker execute code with a single crafted packet — no user interaction required.
Microsoft Patches a Wormable Windows DNS Server RCE Alongside Three More Critical DNS Flaws
CVE-2026-62878, a CVSS 9.8 stack-based buffer overflow in Windows DNS Server, is wormable and needs no authentication — and it shipped alongside three more critical DNS Server RCEs in the same Patch Tuesday round.
Lazarus Burned a Windows Kernel Zero-Day to Deploy FudModule Before Patch Tuesday Shipped
CVE-2026-68820, a use-after-free in the Windows AFD.sys WinSock driver, was exploited by North Korea's Lazarus group to deploy an upgraded FudModule rootkit weeks before Microsoft's August Patch Tuesday fix shipped.
Head Mare Exploits Unpatched TrueConf Servers to Trojanize Client Installers with PhantomCore and PhantomGraph
Head Mare is chaining two unpatched TrueConf videoconferencing server flaws to reach SYSTEM, then replacing legitimate client installers with trojanized builds that drop the PhantomCore and PhantomGraph backdoors.
QuickFox VPN Installer Trojanized for a Year to Deliver Mustang Panda's FDMTP Backdoor
A trojanized QuickFox VPN Windows installer quietly delivered the FDMTP backdoor for roughly a year, with Fortinet linking the campaign to Chinese state-sponsored actor Mustang Panda.
OctLurk and SilkLurk: New Backdoors Hit Central Asian Government Networks
Kaspersky attributes a year-plus cyberespionage campaign against Central Asian and Syrian government networks to a suspected Chinese-speaking actor wielding two new memory-resident backdoors, OctLurk and SilkLurk, plus a custom proxy tool called LurkProxy.
TELESHIM: An East Asia-Linked APT Hides Its C2 Inside Telegram to Backdoor Middle East Governments
Zscaler ThreatLabz uncovers TELESHIM, MIXEDKEY, and BINDCLOAK — a new East Asia-linked malware toolset that abuses the Telegram Bot API for command-and-control against Middle East government targets.
7-Zip CVE-2026-14266: Heap Overflow in XZ Decoder Lets Crafted Archives Run Code on Extraction
A heap-based buffer overflow in 7-Zip's XZ chunk decoder (CVE-2026-14266) lets a crafted .xz or .7z archive corrupt memory during extraction. Patched in 26.02; no in-the-wild exploitation reported yet, but the affected code path sits in build agents and CI unpacking steps everywhere.
Certighost (CVE-2026-54121): A Low-Privileged AD User Can Impersonate Your Domain Controller
A working exploit for CVE-2026-54121 lets any domain user request a certificate for a Domain Controller through an AD CS enrollment fallback, then use it to DCSync the krbtgt hash. No admin rights, no user interaction.
CVE-2026-50518: Unauthenticated Heap Overflow RCE in Windows DHCP Server, No Exploit Required to Care
CVE-2026-50518 is a CVSS 9.8 heap-based buffer overflow in Windows DHCP Server, exploitable pre-auth over the network with no user interaction. Microsoft rates it Exploitation More Likely.
LegacyHive: Unpatched Windows Zero-Day Lets Standard Users Mount Another Account's Registry Hive
Researcher Nightmare Eclipse has dropped LegacyHive, a working PoC against the Windows User Profile Service that lets a standard user load another account's registry hive — no CVE, no patch, works on fully updated July 2026 systems.
Progress Tells ShareFile Customers to Power Down Storage Zone Controllers Over 'Credible' Threat
Progress Software is telling on-prem ShareFile Storage Zone Controller admins to physically shut down their Windows servers over an unnamed 'credible external security threat' — no CVE, no patch, no explanation.
RoguePlanet Gets a CVE: Microsoft Confirms Patch in Progress for Defender SYSTEM Race Condition (CVE-2026-50656)
One week after a public PoC dropped during Patch Tuesday, Microsoft has assigned CVE-2026-50656 to RoguePlanet — a Defender Malware Protection Engine race condition that hands SYSTEM on fully patched Windows 10 and 11 — and confirmed a fix is in flight. No patch yet.
7-Zip CVE-2026-48095: NTFS Parser Heap Overflow Lets Any Double-Clicked Archive Hijack a vtable
A signed-shift bug in 7-Zip's NTFS handler under-allocates a 1-byte buffer, then writes up to 256 MB of attacker-controlled data straight through the adjacent stream object's vtable pointer. Patched in 26.01.