zero-day 81
- PaperCut Warns of Zero-Day Flaw Exploited in NG, MF Print Management Software
- Metabase Zero-Day Under Active Exploitation Grants Unauthenticated Admin Access
- Cisco FMC Zero-Day Actively Exploited, Added to CISA KEV Catalog
- OpenAI's Rogue Agent Breach Widens: JFrog Zero-Days and Stolen Credentials Hit Hugging Face and Others
- Unpatched Fastjson Vulnerability Exploited in Attacks
- Unpatched Fastjson Vulnerability Exploited in Attacks
- Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
- Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
- Kimi K3 AI Agents Found Redis Zero-Days, Built RCE Exploit
- Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit
- Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
- Check Point Patches Actively Exploited SmartConsole Authentication Bypass
- Check Point Patches Exploited SmartConsole Zero-Day (CVE-2026-16232)
- SonicWall SMA1000 Zero-Days Exploited for Weeks to Deploy Malware
- SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
- Critical ServiceNow AI Platform Flaw Actively Exploited
- SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
- Inc Ransomware Chains SonicWall SMA Zero-Days for Root Access
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
- CISA Urges Immediate Patching of Actively Exploited SharePoint Zero-Days
- SonicWall SMA1000 Zero-Days Under Active Exploitation, One Enables Command Execution
- Two SonicWall SMA 1000 Zero-Days Under Active Exploitation
- Microsoft's Record Patch Tuesday Fixes 622 Flaws, Two Under Active Attack
- iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
- iCagenda and Balbooa Forms Joomla Flaws Exploited as Zero-Days, Added to CISA KEV
- Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets
- 12 Million Impacted by Data Breach at Japanese Telco KDDI
- CISA Adds 4 Actively Exploited Flaws to KEV: ColdFusion, Langflow, Joomla
- CISA Confirms Ransomware Gangs Exploiting Microsoft Defender 'BlueHammer' Flaw (CVE-2026-33825)
- Nissan, NAIC Breached via Oracle PeopleSoft Zero-Day, ShinyHunters Campaign
- Microsoft Working on Patch for 'RoguePlanet' Zero-Day
- Attackers Exploit Three Fortinet FortiSandbox Flaws Including CVSS 9.1
- ShinyHunters Exploit Oracle Zero-Day to Steal Data From US Universities
- GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files
- Chrome V8 Zero-Day CVE-2026-11645 Actively Exploited — Patch Now
- Check Point VPN Zero-Day Exploited by Qilin Ransomware Affiliates
- CVE-2026-3300: Critical Everest Forms Pro Flaw Actively Exploited for WordPress Takeover
- Autonomous AI Agent Finds 21 Zero-Days in FFmpeg; Chrome 149 Patches Record 429 Bugs
- Cisco Catalyst SD-WAN Manager Zero-Day CVE-2026-20245 Actively Exploited, No Patch Available
- Google Patches Android Zero-Day CVE-2025-48595 Exploited in Targeted Attacks
- Palo Alto PAN-OS CVE-2026-0257 Authentication Bypass Exploited for Weeks
- PAN-OS GlobalProtect CVE-2026-0257 Authentication Bypass Under Active Exploitation
- Gogs Zero-Day RCE Lets Any Authenticated User Execute Arbitrary Code
- CISA Emergency: Exploited LiteSpeed cPanel Plugin Zero-Day Grants Root Access
- KnowledgeDeliver LMS Zero-Day Exploited to Deploy Godzilla Web Shell and Cobalt Strike
- LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root
- LiteSpeed cPanel Plugin CVE-2026-48172 Actively Exploited for Root Privilege Escalation
- Reaper macOS Malware and Two Microsoft Defender Zero-Days Exploited in the Wild
- Microsoft Defender Vulnerabilities Actively Exploited in the Wild
- Windows Zero-Day Barrage: YellowKey, GreenPlasma, and MiniPlasma Disclosed Post-Patch Tuesday
- DirtyDecrypt PoC Published for Patched Linux Kernel LPE CVE-2026-31635
- Microsoft Exchange Zero-Day Under Active Attack, No Patch Available
- MiniPlasma Windows Zero-Day Grants SYSTEM Privileges on Fully Patched Systems
- Pwn2Own Berlin 2026: $1.3M Paid for 47 Zero-Days in Windows, Linux, VMware, and AI Products
- NGINX CVE-2026-42945: Heap Buffer Overflow Exploited in the Wild, RCE Risk
- Funnel Builder WordPress Plugin Flaw Actively Exploited for WooCommerce Payment Skimming
- Pwn2Own Berlin 2026 Day 2: 15 Zero-Days in Windows 11, Exchange, and RHEL Earn $385K
- Microsoft Exchange CVE-2026-42897 Zero-Day Exploited via Crafted Email
- Cisco SD-WAN CVE-2026-20182 Added to CISA KEV; Sixth Exploited SD-WAN Zero-Day in 2026
- Researcher Drops YellowKey BitLocker Bypass and GreenPlasma Windows EoP Zero-Days
- Google Project Zero Demonstrates 0-Click Exploit Chain for Pixel 10
- Dirty Frag Linux Zero-Day Gives Root on All Major Distributions
- PAN-OS Zero-Day CVE-2026-0300 Enables Unauthenticated RCE via Captive Portal
- Palo Alto PAN-OS RCE Zero-Day CVE-2026-0300 Actively Exploited
- MetInfo CMS CVE-2026-29014 Under Active Exploitation — Unauthenticated RCE (CVSS 9.8)
- ScarCruft Compromises Gaming Platform to Deploy BirdCall Backdoor on Android and Windows
- Weaver E-cology CVE-2026-22679 Actively Exploited — CVSS 9.8 Unauthenticated RCE via Debug API
- 'Copy Fail' Linux Flaw Hits CISA KEV as Active Exploitation Begins
- Critical cPanel and WHM Auth Bypass CVE-2026-41940 Exploited as Zero-Day Since February
- CISA Adds Actively Exploited ConnectWise ScreenConnect and Windows Flaws to KEV
- Incomplete Windows Patch Exposes Systems to Zero-Click APT28 Attack Vector
- Microsoft Defender Zero-Day Exploited to Dump NTLM Hashes and Gain SYSTEM Privileges
- Over 1,300 SharePoint Servers Still Exposed to Actively Exploited Spoofing Zero-Day
- Windows Zero-Days Leaked, Now Actively Exploited for SYSTEM Privileges
- CVE-2026-33032 (MCPwn): Critical Nginx UI Authentication Bypass Actively Exploited
- April 2026 Patch Tuesday: SharePoint Zero-Day Among 167 CVEs Fixed
- ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers
- Anthropic Restricts Mythos Preview After Model Autonomously Exploits Zero-Days in Major OS and Browsers
- Adobe Patches Actively Exploited Acrobat Reader RCE — CVE-2026-34621
- Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025