Zero-Day
Unpatched GeoServer Zero-Day Lets Unauthenticated Attackers Turn SQL Injection Into RCE
An unpatched, unauthenticated SQL injection in GeoServer's jsonArrayContains filter function is under active probing days after public disclosure, with a documented path to remote code execution on PostgreSQL-backed instances.
Microsoft Patches a Wormable Windows DNS Server RCE Alongside Three More Critical DNS Flaws
CVE-2026-62878, a CVSS 9.8 stack-based buffer overflow in Windows DNS Server, is wormable and needs no authentication — and it shipped alongside three more critical DNS Server RCEs in the same Patch Tuesday round.
Lazarus Burned a Windows Kernel Zero-Day to Deploy FudModule Before Patch Tuesday Shipped
CVE-2026-68820, a use-after-free in the Windows AFD.sys WinSock driver, was exploited by North Korea's Lazarus group to deploy an upgraded FudModule rootkit weeks before Microsoft's August Patch Tuesday fix shipped.
XSS2Shell: WordPress Pre-Auth Login XSS Chains to Full RCE (CVE-2026-64638)
CVE-2026-64638 lets an unauthenticated attacker plant XSS on WordPress's login screen with a single failed-login attempt, then chain DOM clobbering and a REST API JSONP callback to steal an admin's Application Password and execute PHP. Patch to 7.0.3.
SCTPhantom (CVE-2026-64564): An 18-Year-Old Linux Kernel SCTP Bug Gives Local Root and Escapes Containers
A use-after-free in the Linux kernel's SCTP ASCONF transport handling, present since 2008, lets a local attacker with SCTP reachability escalate to root and, on affected configurations, escape containers.
CVE-2026-16812: Max-Severity Command Injection in Arista VeloCloud Orchestrator, Actively Exploited — CISA Sets July 30 Deadline
An unauthenticated OS command injection flaw (CVSS 10.0) in on-premises Arista VeloCloud Orchestrator is under active exploitation. CISA added it to the KEV catalog on July 27 with a July 30 remediation deadline for federal agencies.
Fastjson 1.x RCE (CVE-2026-16723) Under Active Attack — No Patch Coming
A pre-auth RCE in Fastjson 1.2.68–1.2.83 requires no AutoType and no gadget chain, is already under active attack across US, Singapore, and Canadian targets, and Alibaba has confirmed the 1.x line will not get a fix.
Negative Time-to-Exploit: AI Bug Hunting Just Broke the One Assumption Your Patch Cycle Depends On
Kimi K3 found 19 Redis zero-days in 90 minutes. XBOW is #1 on HackerOne's global leaderboard. Anthropic's Mythos Preview found thousands of unpatched flaws across every major OS and browser. Meanwhile the average critical vulnerability still takes 252 days to fix. That gap is now the whole game.
AI Agents Find Two New Redis RCE Chains in Under 90 Minutes
Kimi K3 agents surfaced a stream shared-NACK double-free and a RedisBloom TDigest heap overflow across Redis 6.2 through 8.8, both yielding authenticated remote code execution. Patches are out; no in-the-wild exploitation reported yet.
CVE-2026-16232: Check Point SmartConsole Auth Bypass Grants Full Admin — Actively Exploited, Added to CISA KEV
An unauthenticated attacker can steal a SmartConsole application login token and log into Check Point's Security Management Server with full admin rights. CVE-2026-16232 (CVSS 9.3) is under active exploitation and now sits in CISA's KEV catalog with a July 25 remediation deadline.
CVE-2026-50522: SharePoint RCE Under Active Exploitation, Attackers Stealing Machine Keys for Post-Patch Persistence
CVE-2026-50522, a critical 9.8 CVSS SharePoint deserialization RCE, is being actively exploited to steal machine keys that let attackers forge auth tokens and keep access even after the box is patched.
ServiceNow AI Platform Sandbox-Escape RCE (CVE-2026-6875) Under Active Exploitation
A pre-authentication sandbox-escape flaw in ServiceNow's AI Platform is being exploited in the wild against unpatched instances, with attackers reaching the same code-execution primitive through a gadget chain that diverges from the published proof-of-concept.
LegacyHive: Unpatched Windows Zero-Day Lets Standard Users Mount Another Account's Registry Hive
Researcher Nightmare Eclipse has dropped LegacyHive, a working PoC against the Windows User Profile Service that lets a standard user load another account's registry hive — no CVE, no patch, works on fully updated July 2026 systems.
CVE-2026-15409 & CVE-2026-15410: SonicWall SMA1000 Zero-Days Chained for Unauthenticated RCE, CISA Deadline July 17
Two SonicWall SMA1000 zero-days — a CVSS 10.0 SSRF and a post-auth code injection flaw — are being chained in the wild for unauthenticated remote code execution. CISA KEV deadline is July 17, 2026.
Microsoft's July Patch Tuesday Breaks Its Own Record Again: 570 Flaws, Two Zero-Days Under Active Attack
Microsoft's largest Patch Tuesday ever fixes 570 vulnerabilities, including an exploited AD FS privilege-escalation zero-day, an exploited SharePoint EoP zero-day, and a publicly disclosed BitLocker bypass.
GhostLock (CVE-2026-43499): A 15-Year-Old Futex Bug Gives Any Local User Root — and Breaks Out of Containers
A use-after-free in the Linux kernel's futex requeue-PI code, present since 2011, lets any unprivileged local user gain root with a public, 97%-reliable exploit that also escapes Docker and Kubernetes containers.
Bad Epoll (CVE-2026-46242): A Six-Instruction Race in epoll() Roots Linux 6.4+ and Android
A use-after-free race in the Linux epoll subsystem, introduced by a 2023 commit, lets an unprivileged local user gain root with a 99%-reliable exploit — and the same code path may be reachable from Chrome's renderer sandbox on Android.
Squidbleed: 29-Year-Old Heap Over-Read in Squid Proxy Leaks Cleartext HTTP Traffic (CVE-2026-47729)
A Heartbleed-style heap buffer over-read in Squid's FTP gateway, tracing to a 1997 commit, lets trusted proxy users drain other users' cleartext HTTP requests including credentials, cookies, and session tokens.
Arista EOS CVE-2026-7473: Tunnel Decap Flaw Bypasses Segmentation — and Arista Won't Patch It
CVE-2026-7473 lets an unauthenticated attacker push arbitrary tunneled traffic through Arista data-center switches that decapsulate it without checking the protocol. Exploited in the wild, on CISA's KEV list with a deadline of today — and Arista has confirmed no patch is coming.
RoguePlanet Gets a CVE: Microsoft Confirms Patch in Progress for Defender SYSTEM Race Condition (CVE-2026-50656)
One week after a public PoC dropped during Patch Tuesday, Microsoft has assigned CVE-2026-50656 to RoguePlanet — a Defender Malware Protection Engine race condition that hands SYSTEM on fully patched Windows 10 and 11 — and confirmed a fix is in flight. No patch yet.