Cyber News
Zimbra CVE-2026-73570: Exploited Unauth SNMP RCE
Zimbra CVE-2026-73570: an actively exploited unauth RCE (CVSS 8.9) in zimbra-snmp, in CISA KEV. Affected versions, fix, PoC status, and detection.
// TRENDING
HighSolarWinds ARM CVE-2026-28326: Unauthenticated RCE
SolarWinds ARM CVE-2026-28326 is a CVSS 8.8 unauthenticated RCE via a hard-coded key. Affects Access Rights Manager 2026.2 and earlier; patch to 2026.2.1.
CriticalLinux Kernel CVE-2025-39682: 3 Flaws Exploited (CISA KEV)
Linux kernel CVE-2025-39682 and two more are in CISA KEV, exploited in the wild, plus 4 public local-root exploits. Which kernel flaws to patch now.
CriticalAzure AI Foundry CVE-2026-85889: CVSS 10.0 Privesc
Azure AI Foundry CVE-2026-85889 is a CVSS 10.0 missing-authentication privilege-escalation flaw. Microsoft mitigated it server-side; no customer action.
NotableClaude Opus 5 Used to Breach OpenAI Staff Accounts
Hacktron researchers used Claude Opus 5 to chain libheif CVE-2026-32882 with an OpenAI SSO flaw and reach internal OpenAI code. What defenders should learn.
VMware Workstation CVE-2026-59346: 9.3 VM-to-Host Escape
VMware Workstation and Fusion CVE-2026-59346 is a CVSS 9.3 VMXNET3 flaw letting a VM admin run code on the host. Affected versions and how to patch to 26H1u1.
OpenAI AI Agents Linked to RubyGems Supply-Chain Attack
Researchers link OpenAI AI agents to a RubyGems supply-chain attack: hundreds of malicious AI-generated packages and RCE on RubyDoc.info. What to know.
Cisco Secure Email Gateway CVE-2026-76461 Exploited
CVE-2026-76461 is a CVSS 9.8 SQL injection in Cisco Secure Email Gateway giving unauthenticated root RCE. Actively exploited, in CISA KEV. Patch AsyncOS now.
WSO2 API Manager CVE-2026-5430: JWT Bypass Exploited
WSO2 API Manager CVE-2026-5430 is a critical JWT auth bypass (CVSS 10.0) accepting forged admin tokens. Actively exploited per watchTowr. Patch now.
Google Pixel CVE-2026-58704: Android Zero-Day Exploited
Google Pixel CVE-2026-58704 is an actively exploited Android modem zero-day (CVSS 8.0). Install the September 2026 update (2026-09-05 patch level).
Check Point VPN CVE-2026-85102: RCE, Exploit Imminent
Check Point VPN CVE-2026-85102 and CVE-2026-85103 are two CVSS 9.8 remote code execution flaws in Security Gateways. The Dutch NCSC warns exploitation is imminent. Patch now.
GitLab CVE-2026-85706: CVSS 10 Path Traversal in KEV
GitLab CVE-2026-85706 is a CVSS 10.0 unauthenticated path traversal letting attackers read arbitrary files in one request. It is in CISA KEV with in-the-wild probes. Patch now.
HighBlueMoon Exploit Kit Chains Chrome, Windows Zero-Days
The BlueMoon exploit kit chains two Chrome V8 zero-days and a Windows ALPC privilege-escalation bug into a browser-to-SYSTEM attack, and multiple China-linked APTs are using it.