2026-08-11 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-65775.
P15
2026-08-11 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows local attackers to disclose sensitive information on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-65776.
P5
2026-08-11 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-65773.
P15
2026-08-11 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows remote attackers to escalate privileges on affected installations of Microsoft Exchange. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-62911.
P15
2026-08-11 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-65814.
P15
2026-08-11 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-62735.
P15
2026-08-11 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Exchange. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-62911.
P20
2026-08-11 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows remote attackers to bypass authentication on affected installations of Microsoft Exchange. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-62911.
P15
2026-08-11 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows remote attackers to bypass authentication on affected installations of Cisco Secure Firewall Management Center. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-20316.
P15
2026-08-11 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of SonicWall Email Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-66149.
P15
2026-08-11 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of SonicWall GMS Virtual Appliance. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-66148.
P15
2026-08-11 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of SonicWall Email Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-66150.
P15
2026-08-11 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung Galaxy S25 devices. User interaction may be required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-21045.
P20
2026-08-11 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Wazuh. An attacker must first obtain the ability to execute low-privileged code on a worker node in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.9. The following CVEs are assigned: CVE-2026-28220.
P20
2026-08-11 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Wazuh. An attacker must first obtain the ability to execute low-privileged code on a worker node in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.9. The following CVEs are assigned: CVE-2026-44901.
P20
2026-08-10 21:02 UTC
Security Journalism
Dark Reading · Rob Wright · indexed 2026-08-15 18:55 UTC
The maximum-severity vulnerability, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users.
P25
2026-08-10 17:56 UTC
Security Journalism
Dark Reading · Shubham Paikrao · indexed 2026-08-15 18:55 UTC
It's time to turn from CVSS-backed patching to choke-point patching focused on breaking chains to critical assets.
P0
2026-08-10 16:35 UTC
Vendor Research
Tenable Research Advisories · Ben Smith · indexed 2026-08-15 18:55 UTC
Google Cloud Platform (GCP) Apigee Cross-Tenant Data Exfiltration via Confused Deputy Tenable Research has identified and responsibly disclosed a critical cross-tenant data exfiltration vulnerability in Google Cloud Apigee. This flaw allowed an attacker to abuse a "confused deputy" in Apigee's internal analytics infrastructure to read arbitrary Google Cloud Storage (GCS) objects across different tenants, as well as shared production infrastructure buckets. The vulnerability stems from how Apige…
P0
2026-08-10 15:00 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC
A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default. That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was supposed to stop them in the first place. That’s only part of it. Here’s
P25
2026-08-10 11:33 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC
The threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, IT, and software development sectors. Russian cybersecurity vendor Kaspersky said it detected the attacks in July 2026. The activity involves exploiting a vulnerability chain
P0
2026-08-08 06:58 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC
Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain
P45
2026-08-08 06:52 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary
P55
2026-08-07 21:26 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access control enforcement for specific template types that are not included in the encryption allowlist. A low-privileged attacker could exploit this vulnerability by viewing logs on the local system or on a remote logging server. A successful exploit coul…
P5
2026-08-07 19:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Apple’s latest macOS update addresses two vulnerabilities in its Screen Sharing server, including one that enables pre-authenticated remote code execution.
P20
2026-08-07 14:32 UTC
Vendor Research
Rapid7 · Stephen Fewer · indexed 2026-08-15 18:55 UTC
OverviewOn July 27, 2026, JetBrains published a security advisory for CVE-2026-63077, a critical unsafe deserialization vulnerability affecting JetBrains TeamCity. An attacker who can reach a TeamCity server over HTTP or HTTPS can exploit the agent polling protocol without credentials and execute operating system commands with the privileges of the TeamCity server process.JetBrains reported no known active exploitation when it disclosed the vulnerability. However, on August 5, 2026, CISA added …
P70
2026-08-07 12:56 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can be chained into PHP code execution on the server when a logged-in administrator interacts with an attacker-controlled page. Tracked as CVE-2026-64638 (CVSS score: 8.9), the high-severity
P5
2026-08-07 12:00 UTC
Vendor Research
Tenable Blog · Nick Hayes · indexed 2026-08-15 18:55 UTC
Agentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event.Key takeawaysBuilding defensive cybersecurity tooling no longer requires a developer. Agentic tooling drove the cost of finding and exploiting a vulnerability down to 1990s levels; it also removed the engineering barrier that kept defenders from buil…
P0
2026-08-07 10:09 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC
PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate desync vectors. PortSwigger said a separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where
P25
2026-08-05 16:01 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
On August 5, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026 CVE-2026-20303CVE-2026-20304CVE-2026-20310CVE-2026-20312CVE-2026-20313 Critical 9.9 Cisco IOS XE Software Security Hardening Release: August 2026 CVE-2026-20267CVE-2026-20268CVE-2026-20269CVE-2026-20270CVE-2026-20271CVE-2026-20272CVE-2026-20273 …
P5
2026-08-05 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-24 19:40 UTC
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues …
P30