Windows
ShieldBreak (CVE-2026-69414): A Full Bypass of Microsoft's RoguePlanet Defender Patch, Still Unfixed
Nightmare Eclipse's ShieldBreak fully bypasses the fix for RoguePlanet, Microsoft Defender's earlier SYSTEM-privilege zero-day. Microsoft has assigned CVE-2026-69414 and confirmed a patch is in progress, but none has shipped.
Critical Use-After-Free in Microsoft QUIC Allows Unauthenticated RCE (CVE-2026-62815)
CVE-2026-62815, a CVSS 9.8 use-after-free in Microsoft's QUIC/HTTP-3 implementation, lets an unauthenticated remote attacker execute code with a single crafted packet — no user interaction required.
Microsoft Patches a Wormable Windows DNS Server RCE Alongside Three More Critical DNS Flaws
CVE-2026-62878, a CVSS 9.8 stack-based buffer overflow in Windows DNS Server, is wormable and needs no authentication — and it shipped alongside three more critical DNS Server RCEs in the same Patch Tuesday round.
Lazarus Burned a Windows Kernel Zero-Day to Deploy FudModule Before Patch Tuesday Shipped
CVE-2026-68820, a use-after-free in the Windows AFD.sys WinSock driver, was exploited by North Korea's Lazarus group to deploy an upgraded FudModule rootkit weeks before Microsoft's August Patch Tuesday fix shipped.
Head Mare Exploits Unpatched TrueConf Servers to Trojanize Client Installers with PhantomCore and PhantomGraph
Head Mare is chaining two unpatched TrueConf videoconferencing server flaws to reach SYSTEM, then replacing legitimate client installers with trojanized builds that drop the PhantomCore and PhantomGraph backdoors.
QuickFox VPN Installer Trojanized for a Year to Deliver Mustang Panda's FDMTP Backdoor
A trojanized QuickFox VPN Windows installer quietly delivered the FDMTP backdoor for roughly a year, with Fortinet linking the campaign to Chinese state-sponsored actor Mustang Panda.
OctLurk and SilkLurk: New Backdoors Hit Central Asian Government Networks
Kaspersky attributes a year-plus cyberespionage campaign against Central Asian and Syrian government networks to a suspected Chinese-speaking actor wielding two new memory-resident backdoors, OctLurk and SilkLurk, plus a custom proxy tool called LurkProxy.
TELESHIM: An East Asia-Linked APT Hides Its C2 Inside Telegram to Backdoor Middle East Governments
Zscaler ThreatLabz uncovers TELESHIM, MIXEDKEY, and BINDCLOAK — a new East Asia-linked malware toolset that abuses the Telegram Bot API for command-and-control against Middle East government targets.
7-Zip CVE-2026-14266: Heap Overflow in XZ Decoder Lets Crafted Archives Run Code on Extraction
A heap-based buffer overflow in 7-Zip's XZ chunk decoder (CVE-2026-14266) lets a crafted .xz or .7z archive corrupt memory during extraction. Patched in 26.02; no in-the-wild exploitation reported yet, but the affected code path sits in build agents and CI unpacking steps everywhere.
Certighost (CVE-2026-54121): A Low-Privileged AD User Can Impersonate Your Domain Controller
A working exploit for CVE-2026-54121 lets any domain user request a certificate for a Domain Controller through an AD CS enrollment fallback, then use it to DCSync the krbtgt hash. No admin rights, no user interaction.
CVE-2026-50518: Unauthenticated Heap Overflow RCE in Windows DHCP Server, No Exploit Required to Care
CVE-2026-50518 is a CVSS 9.8 heap-based buffer overflow in Windows DHCP Server, exploitable pre-auth over the network with no user interaction. Microsoft rates it Exploitation More Likely.
LegacyHive: Unpatched Windows Zero-Day Lets Standard Users Mount Another Account's Registry Hive
Researcher Nightmare Eclipse has dropped LegacyHive, a working PoC against the Windows User Profile Service that lets a standard user load another account's registry hive — no CVE, no patch, works on fully updated July 2026 systems.
Progress Tells ShareFile Customers to Power Down Storage Zone Controllers Over 'Credible' Threat
Progress Software is telling on-prem ShareFile Storage Zone Controller admins to physically shut down their Windows servers over an unnamed 'credible external security threat' — no CVE, no patch, no explanation.
RoguePlanet Gets a CVE: Microsoft Confirms Patch in Progress for Defender SYSTEM Race Condition (CVE-2026-50656)
One week after a public PoC dropped during Patch Tuesday, Microsoft has assigned CVE-2026-50656 to RoguePlanet — a Defender Malware Protection Engine race condition that hands SYSTEM on fully patched Windows 10 and 11 — and confirmed a fix is in flight. No patch yet.
7-Zip CVE-2026-48095: NTFS Parser Heap Overflow Lets Any Double-Clicked Archive Hijack a vtable
A signed-shift bug in 7-Zip's NTFS handler under-allocates a 1-byte buffer, then writes up to 256 MB of attacker-controlled data straight through the adjacent stream object's vtable pointer. Patched in 26.01.
Two More Defender Zero-Days in the Wild: CVE-2026-41091 Link-Resolution Bug Lands SYSTEM, Added to CISA KEV
Microsoft confirms two Defender flaws — an LPE to SYSTEM and a DoS — are publicly disclosed and exploited in the wild. A third RCE ships in the same engine update. CISA gives federal agencies until June 3.
MiniPlasma: Public PoC Hands SYSTEM on Fully Patched Windows 11 via cldflt.sys
Chaotic Eclipse published a working PoC for MiniPlasma, a Cloud Filter driver LPE that abuses CfAbortHydration to forge .DEFAULT-hive registry keys — the same bug Microsoft was told about in 2020 and claimed to have fixed.
YellowKey and GreenPlasma: Same Researcher Drops Two More Windows Zero-Days, BitLocker Bypass via WinRE USB
The anonymous researcher behind BlueHammer is back with YellowKey, a BitLocker bypass that drops a CMD shell on protected drives via crafted FsTx files in WinRE, plus GreenPlasma, a CTFMON privilege escalation. No CVE, no patch.
NTLM Coercion's Quiet Resurgence: Why 2026's Zero-Click Attacks Look Like 2021
Two unrelated bugs in the last month — an incomplete APT28 patch and an unpatched RPC defect — both hand attackers a 1990s-era credential primitive. The fact that NTLM coercion still works in 2026 is not a series of accidents. It is the model.
Every Windows Endpoint is a Target: CVE-2026-41096 Heap Overflow in DNS Client Enables Remote Code Execution
CVE-2026-41096 is a CVSS 9.8 heap overflow in the Windows DNS Client. A single malicious DNS response can yield code execution on any Windows host — no auth, no user click, no document opened. The blast radius is every Windows endpoint that resolves a name.