zero-day 32
- Gogs Zero-Day RCE Lets Any Authenticated User Execute Arbitrary Code
- KnowledgeDeliver LMS Zero-Day Exploited to Deploy Godzilla Web Shell and Cobalt Strike
- LiteSpeed cPanel Plugin CVE-2026-48172 Actively Exploited for Root Privilege Escalation
- Reaper macOS Malware and Two Microsoft Defender Zero-Days Exploited in the Wild
- Windows Zero-Day Barrage: YellowKey, GreenPlasma, and MiniPlasma Disclosed Post-Patch Tuesday
- DirtyDecrypt PoC Published for Patched Linux Kernel LPE CVE-2026-31635
- MiniPlasma Windows Zero-Day Grants SYSTEM Privileges on Fully Patched Systems
- Pwn2Own Berlin 2026: $1.3M Paid for 47 Zero-Days in Windows, Linux, VMware, and AI Products
- Pwn2Own Berlin 2026 Day 2: 15 Zero-Days in Windows 11, Exchange, and RHEL Earn $385K
- Microsoft Exchange CVE-2026-42897 Zero-Day Exploited via Crafted Email
- Cisco SD-WAN CVE-2026-20182 Added to CISA KEV; Sixth Exploited SD-WAN Zero-Day in 2026
- Researcher Drops YellowKey BitLocker Bypass and GreenPlasma Windows EoP Zero-Days
- Google Project Zero Demonstrates 0-Click Exploit Chain for Pixel 10
- Dirty Frag Linux Zero-Day Gives Root on All Major Distributions
- PAN-OS Zero-Day CVE-2026-0300 Enables Unauthenticated RCE via Captive Portal
- Palo Alto PAN-OS RCE Zero-Day CVE-2026-0300 Actively Exploited
- MetInfo CMS CVE-2026-29014 Under Active Exploitation — Unauthenticated RCE (CVSS 9.8)
- ScarCruft Compromises Gaming Platform to Deploy BirdCall Backdoor on Android and Windows
- Weaver E-cology CVE-2026-22679 Actively Exploited — CVSS 9.8 Unauthenticated RCE via Debug API
- 'Copy Fail' Linux Flaw Hits CISA KEV as Active Exploitation Begins
- Critical cPanel and WHM Auth Bypass CVE-2026-41940 Exploited as Zero-Day Since February
- CISA Adds Actively Exploited ConnectWise ScreenConnect and Windows Flaws to KEV
- Incomplete Windows Patch Exposes Systems to Zero-Click APT28 Attack Vector
- Microsoft Defender Zero-Day Exploited to Dump NTLM Hashes and Gain SYSTEM Privileges
- Over 1,300 SharePoint Servers Still Exposed to Actively Exploited Spoofing Zero-Day
- Windows Zero-Days Leaked, Now Actively Exploited for SYSTEM Privileges
- CVE-2026-33032 (MCPwn): Critical Nginx UI Authentication Bypass Actively Exploited
- April 2026 Patch Tuesday: SharePoint Zero-Day Among 167 CVEs Fixed
- ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers
- Anthropic Restricts Mythos Preview After Model Autonomously Exploits Zero-Days in Major OS and Browsers
- Adobe Patches Actively Exploited Acrobat Reader RCE — CVE-2026-34621
- Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025