Foxit PDF Reader out-of-bounds read in PDF parsing (CVE-2026-57253, CVSS 3.3) can leak sensitive information via malicious files.
ZDI-26-596 covers an out-of-bounds read in Foxit PDF Reader's PDF file parsing, tracked as CVE-2026-57253 and rated CVSS 3.3. Successful exploitation allows remote attackers to disclose sensitive information and requires the target to open a malicious file or page. The advisory was published by the Zero Day Initiative on August 24, 2026.
Foxit PDF Reader AcroForm use-after-free (CVE-2026-57242, CVSS 7.8) permits remote code execution through malicious PDF files or pages.
ZDI-26-598 details a use-after-free in the AcroForm component of Foxit PDF Reader, tracked as CVE-2026-57242 and rated CVSS 7.8. A remote attacker can execute arbitrary code if the target opens a malicious file or visits a malicious page. The advisory was published by the Zero Day Initiative on August 24, 2026.
Foxit PDF Reader has a use-after-free vulnerability (CVE-2026-57254, CVSS 7.8) allowing remote code execution when a user opens a malicious file or page.
ZDI-26-595 describes a use-after-free vulnerability in the annotation feature of Foxit PDF Reader, tracked as CVE-2026-57254 with a CVSS score of 7.8. Successful exploitation allows remote attackers to execute arbitrary code, but requires user interaction such as visiting a malicious page or opening a malicious file. The advisory does not mention any exploitation in the wild.
A fake PoC for WinRAR RCE CVE-2023-40477 posted on GitHub actually deploys VenomRAT through a multi-step infection chain targeting researchers.
Four days after Zero Day Initiative publicly disclosed the WinRAR RCE vulnerability CVE-2023-40477 on August 17, 2023, an actor using the alias whalersplonk published a fake proof-of-concept on GitHub. The Python script actually repurposed public PoC code for GeoServer SQL injection CVE-2023-25157 and triggered an infection chain ending in VenomRAT. The README and an accompanying video lured users into running the script; the video drew over 100 plays. Unit 42 assesses the actor was opportunistic, targeting other miscreants adopting new vulnerabilities rather than researchers specifically.
ZDI discloses an unauthenticated, network-adjacent RCE in PAX Technology Q80 payment terminals via installer signature bypass, rated CVSS 7.5.
ZDI-26-526 describes a signature verification bypass in the PAX Technology Q80 application installer that lets network-adjacent attackers execute arbitrary code without authentication. The 0-day is tracked as CVE-2026-19910 and CVE-2026-19911 and carries a CVSS score of 7.5. No public patch was noted at the time of disclosure.
ZDI details CVE-2026-20147, an authenticated command injection in Cisco Identity Services Engine allowing remote code execution, rated CVSS 7.2.
ZDI-26-581 describes a command injection flaw in Cisco Identity Services Engine reachable through the invokeScript function. Remote attackers who authenticate can execute arbitrary code on affected installations. The issue is tracked as CVE-2026-20147 and carries a CVSS rating of 7.2. No exploitation activity is reported in the advisory.
ZDI disclosed a race condition local privilege escalation flaw in the Linux Kernel XFRM subsystem, CVSS 7.5, with no CVE assigned.
The Zero Day Initiative published ZDI-26-576 describing a race condition in the Linux Kernel XFRM subsystem. Local attackers can escalate privileges, but the advisory states an attacker must first be able to execute high-privileged code on the target. ZDI assigned a CVSS score of 7.5; no CVE identifier is listed in the advisory text.
ZDI disclosed an authenticated directory traversal flaw (CVE-2026-20181) in Cisco Identity Services Engine allowing remote code execution, CVSS 7.2.
The Zero Day Initiative published ZDI-26-579 describing a directory traversal in the zipFiles functionality of Cisco Identity Services Engine. Authenticated remote attackers can execute arbitrary code on affected installations. ZDI assigned a CVSS score of 7.2 and the identifier CVE-2026-20181.
ZDI publishes ZDI-26-575, a CVSS 7.5 TOCTOU local privilege escalation in the Linux kernel net scheduler packet classifier API.
The Zero Day Initiative disclosed a time-of-check time-of-use flaw in the Linux kernel's net scheduler packet classifier API that permits local privilege escalation. Exploitation requires the attacker to first execute high-privileged code on the target system. ZDI assigned a CVSS rating of 7.5; no CVE id is provided in the text.
ZDI disclosed an unauthenticated out-of-bounds read (CVE-2026-68431) in Linux Kernel KSMBD causing sensitive information disclosure, CVSS 9.3.
The Zero Day Initiative published ZDI-26-573 describing an out-of-bounds read in the Linux Kernel KSMBD response header handling. Unauthenticated remote attackers can disclose sensitive information, but only systems with ksmbd enabled are affected. ZDI assigned a CVSS score of 9.3 and the identifier CVE-2026-68431.
ZDI disclosed an unauthenticated infinite-loop denial-of-service flaw (CVE-2026-4890) in dnsmasq DNSSEC NSEC/NSEC3 bitmap processing.
The Zero Day Initiative published ZDI-26-584 describing an infinite loop in dnsmasq's processing of DNSSEC NSEC/NSEC3 type bitmaps. Remote unauthenticated attackers can trigger a denial-of-service condition on affected installations. ZDI assigned a CVSS score of 7.5 and the identifier CVE-2026-4890.
ZDI discloses CVE-2026-20190, a missing-authentication flaw in Cisco Identity Services Engine permitting unauthenticated sensitive information disclosure, rated CVSS 7.5.
ZDI-26-580 covers a missing authentication for critical function flaw in Cisco Identity Services Engine. Unauthenticated remote attackers can disclose sensitive information from affected installations. The vulnerability is tracked as CVE-2026-20190 and rated CVSS 7.5. The advisory does not indicate exploitation in the wild.
ZDI discloses CVE-2026-24232, a CVSS 7.8 deserialization RCE in NVIDIA Transformers4Rec's load_model_trainer_states_from_checkpoint function.
The Zero Day Initiative published ZDI-26-564, a deserialization of untrusted data vulnerability in NVIDIA Transformers4Rec. Remote code execution is possible, but exploitation requires user interaction such as visiting a malicious page or opening a malicious file. The flaw is tracked as CVE-2026-24232 with a CVSS score of 7.8.
ZDI disclosed a use-after-free local privilege escalation flaw (CVE-2026-64530) in the Linux Kernel net scheduler packet classifier API.
The Zero Day Initiative published ZDI-26-571 describing a use-after-free in the Linux Kernel net scheduler packet classifier API. Local attackers who can already execute low-privileged code can escalate privileges. ZDI assigned a CVSS score of 8.8 and the identifier CVE-2026-64530.
ZDI publishes ZDI-26-572, a CVSS 7.5 race condition local privilege escalation in the Linux kernel's XFRM subsystem.
The Zero Day Initiative disclosed a race condition in the Linux kernel's XFRM (transform) subsystem allowing local attackers to escalate privileges. Exploitation requires the attacker to first run high-privileged code on the affected system. The advisory carries a CVSS rating of 7.5; no CVE id is listed in the disclosure text.
Zero Day Initiative discloses CVE-2026-20215, an integer overflow in ClamAV's 7z archive parsing enabling remote code execution, rated CVSS 8.4.
The Zero Day Initiative published ZDI-26-583 for an integer overflow in Clam AntiVirus's 7z archive parsing. A remote attacker can execute arbitrary code when the antivirus processes a crafted archive, with attack vectors varying by implementation. The flaw is tracked as CVE-2026-20215 and rated CVSS 8.4. The advisory does not mention active exploitation.
ZDI publishes ZDI-26-569, a CVSS 7.5 race condition local privilege escalation in the Linux kernel net scheduler true link equalizer.
The Zero Day Initiative disclosed a race condition in the Linux kernel's net scheduler true link equalizer component enabling local privilege escalation. Exploitation requires the attacker to first run high-privileged code on the target system. The advisory carries a CVSS rating of 7.5; no CVE id is listed in the disclosure text.
ZDI disclosed an out-of-bounds write flaw (CVE-2026-40272) in BlackBerry QNX KEV file parsing enabling remote code execution.
The Zero Day Initiative published ZDI-26-566 describing an out-of-bounds write vulnerability in BlackBerry QNX KEV file parsing. Remote code execution requires user interaction, such as visiting a malicious page or opening a malicious file. ZDI assigned a CVSS score of 7.8 and the CVE identifier CVE-2026-40272.
ZDI discloses CVE-2024-13962, a CVSS 7.8 link-following local privilege escalation flaw in Norton Utilities Ultimate's NortonUtilitiesSvc service.
The Zero Day Initiative published ZDI-26-567, a local privilege escalation vulnerability in Norton Utilities Ultimate. An attacker must already be able to execute low-privileged code on the system before exploiting the symlink/link-following flaw in NortonUtilitiesSvc. The issue carries a CVSS score of 7.8 and is tracked as CVE-2024-13962.
ZDI publishes ZDI-26-570, a CVSS 7.5 race condition local privilege escalation in the Linux kernel's IGMP subsystem.
The Zero Day Initiative disclosed a race condition in the Linux kernel's IGMP subsystem that allows local attackers to escalate privileges. Exploitation requires the attacker to first execute high-privileged code on the target system. ZDI assigned a CVSS rating of 7.5 to this finding; no CVE id is stated in the advisory text.
ZDI disclosed another Pwn2Own command injection flaw (CVSS 7.5) in Home Assistant Green's go2rtc, enabling network-adjacent code execution after obtaining localhost access.
The Zero Day Initiative published ZDI-26-560 for a second command injection remote code execution flaw in go2rtc on Home Assistant Green, demonstrated at Pwn2Own. Network-adjacent attackers can execute arbitrary code after first obtaining access to the device's localhost interface. ZDI rated the issue CVSS 7.5.
ZDI disclosed a Pwn2Own command injection flaw (CVSS 7.5) in Home Assistant Green's go2rtc, enabling network-adjacent attackers to execute arbitrary code via localhost access.
The Zero Day Initiative published ZDI-26-561 for a command injection remote code execution flaw in go2rtc on Home Assistant Green, demonstrated at Pwn2Own. Network-adjacent attackers can execute arbitrary code after first gaining access to the device's localhost interface. ZDI rated the issue CVSS 7.5.
ZDI disclosed a Pwn2Own information disclosure flaw (CVSS 4.3) in Amazon Smart Plug, letting unauthenticated network-adjacent attackers access sensitive information.
The Zero Day Initiative published ZDI-26-557 for an insecure fallback information disclosure flaw in Amazon Smart Plug, demonstrated at Pwn2Own. Unauthenticated network-adjacent attackers can disclose sensitive information on affected installations. ZDI rated the issue CVSS 4.3.
ZDI disclosed a Pwn2Own out-of-bounds write RCE (CVSS 7.5) in Amazon Smart Plug's OTA process, exploitable by unauthenticated network-adjacent attackers.
The Zero Day Initiative published ZDI-26-559 for an out-of-bounds write remote code execution flaw in the Amazon Smart Plug OTA update process, demonstrated at Pwn2Own. Unauthenticated network-adjacent attackers can execute arbitrary code on affected installations. ZDI rated the issue CVSS 7.5.
ZDI disclosed a Pwn2Own SSRF flaw (CVSS 5.4) in Home Assistant Green's SSDP server, letting unauthenticated network-adjacent attackers trigger arbitrary server-side requests.
The Zero Day Initiative published ZDI-26-563 for a server-side request forgery in the Simple Service Discovery Protocol server on Home Assistant Green. The bug was demonstrated at Pwn2Own and allows network-adjacent, unauthenticated attackers to initiate arbitrary server-side requests on affected installations. ZDI rated the issue CVSS 5.4.
ZDI-26-562 details an unauthenticated, network-adjacent SSRF in the Home Assistant Green mDNS server, rated CVSS 5.4 and originally demonstrated at Pwn2Own.
A server-side request forgery in Home Assistant Green's mDNS service lets network-adjacent attackers initiate arbitrary server-side requests without authentication. The Zero Day Initiative assigned the flaw a CVSS 5.4 rating under advisory ZDI-26-562. The finding originated from Pwn2Own, and no exploitation in the wild is reported.
ZDI disclosed a Pwn2Own certificate validation flaw (CVSS 6.8) in Amazon Smart Plug's OTA process, allowing network-adjacent attackers to bypass update verification.
The Zero Day Initiative published ZDI-26-558 for an improper certificate validation flaw in the Amazon Smart Plug OTA update process, demonstrated at Pwn2Own. Network-adjacent attackers need no authentication to bypass certificate validation for over-the-air updates. ZDI rated the issue CVSS 6.8.
Heap-Based Buffer Overflow in Windows ALPC Enables Local Privilege Escalation
CVE-2026-85880 is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), the Windows mechanism for local inter-process communication. An authorized local attacker can trigger the overflow by submitting crafted input over ALPC, corrupting heap memory in the component that handles the request. Successful exploitation allows the attacker to execute code with elevated privileges, typically gaining SYSTEM-level control of the local host, which is especially valuable as a post-exploitation or sandbox-escape step. Affected products include Windows 10 (1607, 1809, 21H2, 22H2) and Windows Server 2012, 2016, 2019, and 2022, meaning most on-premises Windows estates are in scope. The flaw was fixed in Microsoft's record 974-CVE September 2026 Patch Tuesday and was added to CISA's KEV on 2026-09-08, confirming exploitation in the wild; press reports describe Windows zero-days being chained with a Chrome zero-day in 'BlueMoon' kit attacks, though the data does not explicitly confirm this CVE is the Windows flaw in that chain.
· Microsoft Windows 10 1607, 1809, 21H2, 22H2 · Microsoft Windows Server 2012, 2016, 2019, 2022 KEVmass
Local Privilege Escalation via Link Following in Windows Update Stack
CVE-2026-81963 is a link-following flaw (CWE-59, improper link resolution before file access) in the Microsoft Windows Update Stack, in which the component fails to correctly resolve file links before opening them. A local attacker with low privileges can plant or manipulate a link (symlink/junction) that the privileged update stack follows during operation, redirecting its file access to an attacker-controlled target. The result is local privilege escalation — CVSS 3.1 rates this 7.8 (high) with high confidentiality, integrity, and availability impact — allowing an authorized local user or malware already on the machine to gain elevated rights. Affected products are Windows 11 23H2, 24H2, 25H2, and 26H1 and Windows Server 2025; any unpatched system on those versions is exposed to any local account holder. The flaw was fixed in Microsoft's record September 2026 Patch Tuesday (974 CVEs), was added to CISA's KEV on 2026-09-08 as one of two Windows zero-days reported as exploited in the wild, and has no known public PoC or confirmed ransomware use.
· Microsoft Windows 11 23H2, 24H2, 25H2, 26H1 · Microsoft Windows Server 2025 KEVmass
CVE-2026-69730 is a use-after-free memory corruption flaw (CWE-416) in the Windows DNS service that allows an unauthenticated, remote attacker to execute arbitrary code by sending crafted network traffic to the affected system. Because the flaw is network-exploitable with no privileges or user interaction required (CVSS 3.1 9.8), any system running the vulnerable DNS service is a direct target. Successful exploitation would give the attacker code execution in the context of the DNS service, which on Windows Server typically runs with high privileges such as SYSTEM, and could enable wormable spread between vulnerable hosts. Affected organizations are those running the Windows DNS Server role — a component deployed on virtually all Windows Server domain controllers and on dedicated Windows DNS servers, especially those exposed to untrusted networks. As of the September 2026 Patch Tuesday release, there is no known public proof-of-concept, the flaw is not listed in CISA's KEV, and it has not been confirmed exploited in the wild, though it was flagged among roughly 20 'wormable' bugs and described in press coverage as a successor to the 2020 SigRed Windows DNS RCE.
· Microsoft Windows DNS Server role (Windows Server)mass
Double Free Enables Unauthenticated RCE in Microsoft Exchange Server
CVE-2026-55007 is a double-free memory corruption flaw (CWE-415) in Microsoft Exchange Server in which the same heap allocation is freed twice, corrupting memory. A remote, unauthenticated attacker can trigger the flaw over the network, though the high attack complexity (AC:H) means reliable exploitation likely depends on favorable heap/timing conditions, making it harder to weaponize than typical pre-auth RCEs. Successful exploitation yields arbitrary code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.1). Any organization running on-premises Microsoft Exchange Server is in scope, with the greatest risk on servers reachable from untrusted networks. As of now there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.7% chance of exploitation within 30 days; it was disclosed amid Microsoft's record September 2026 Patch Tuesday (974 CVEs), which press coverage highlighted for notable Exchange flaws.
Use-After-Free RCE in Windows Remote Desktop Services
CVE-2026-69525 is a use-after-free memory corruption flaw (CWE-416) in Windows Remote Desktop Services, rated critical at CVSS 9.8. Per the CVSS vector, a remote, unauthenticated attacker can reach the vulnerable code path over the network with no privileges and no user interaction, presumably by sending crafted input to the RDP/RDS service. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability. Any Windows system running Remote Desktop Services is affected, and organizations exposing RDP (TCP 3389) to the internet are the primary concern, since public scans show millions of such endpoints. There is no public proof-of-concept or CISA KEV listing yet, and EPSS estimates a ~1.1% (63rd percentile) chance of exploitation within 30 days; the fix shipped as part of Microsoft's record 974-CVE Patch Tuesday, which separately included two exploited Windows zero-days and 20 wormable bugs.
Unbootable-System Denial of Service via Link Following in Backblaze Windows Backup Client
CVE-2026-19820 is a link-following flaw (CWE-59) in the Backblaze Personal Computer Backup client for Windows, whose backup components (bzserv, bztransmit, bzfilelist, bzbackup, and bzreports) do not properly resolve links in the folders they traverse. A local user can create a link from Backblaze's folder to Windows OS system files during a backup; when the client follows the link, the affected machine can be rendered unbootable. Successful exploitation requires that an administrator-level system change has removed the specific Windows OS security controls that normally govern link resolution, allowing the link to be planted in this way. The impact is loss of availability of the whole system (high impact on the system's ability to boot), not data theft. Exploitation is not currently known: no public PoC exists, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at about 0.3%.
· Backblaze Personal Computer Backup (Backblaze Client) for Windows, including the bzserv, bztransmit, bzfilelist, bzbackup, and bzrlarge
Use-After-Free Privilege Escalation in Microsoft Windows ALPC
CVE-2023-21674 is a use-after-free flaw (CWE-416) in the Windows Advanced Local Procedure Call (ALPC) facility, the kernel-level mechanism Windows uses for fast communication between processes and system services. An attacker who can already run code on a Windows machine can trigger the bug by sending crafted ALPC requests, corrupting memory in a privileged process. Successful exploitation allows a local, low-privileged attacker to elevate to SYSTEM/administrator privileges, typically to gain full control of the host or to complete an exploit chain after an initial compromise. Essentially all supported Windows client and server installations from Microsoft are affected; the source data does not list specific versions, and the fix shipped with Microsoft's January 2023 Patch Tuesday, which addressed a record 974 vulnerabilities including this and one other actively exploited Windows zero-day. CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2023-01-10, confirming exploitation in the wild; no public proof-of-concept is known, ransomware use is undetermined, and EPSS estimates a 41.8% probability of exploitation in the next 30 days (99th percentile).
Injection Flaw in Microsoft SQL Server Enables Network Privilege Escalation
Microsoft SQL Server contains an injection vulnerability (CWE-74) in which special elements in output used by a downstream component are not properly neutralized. An unauthorized attacker can trigger the flaw remotely over a network, though the CVSS vector indicates that some form of user interaction is required in the attack path. Successful exploitation allows elevation of privileges with high impact on confidentiality, integrity, and availability, and the changed-scope metric suggests the attack crosses a security boundary into another component. Any organization running affected Microsoft SQL Server versions is potentially exposed, although the data provided does not specify exact affected version ranges. No public proof of concept, CISA KEV listing, or known exploitation exists; EPSS estimates only a 0.7% probability of exploitation in the next 30 days, and the fix shipped with Microsoft's record-setting September 2026 Patch Tuesday release (974 flaws patched).
Improper Authentication in Microsoft Authenticator Enables Local Privilege Escalation
CVE-2026-80097 is an improper authentication flaw (CWE-287) in Microsoft Authenticator that allows an unauthorized attacker to elevate privileges locally, rated 8.6 (high) with no privileges required, required user interaction, and a changed scope. Exploitation requires local access to a device running the app plus user interaction, and because the scope is changed, a successful attack crosses a security boundary beyond the Authenticator component itself. A successful exploit yields local privilege elevation with high impact to confidentiality, integrity, and availability. Anyone running affected versions of Microsoft Authenticator is affected; the app is Microsoft's standard multi-factor authentication app for Entra ID/Microsoft 365 and is widely deployed across enterprise and personal mobile devices. As of the September 2026 disclosure it is not known to be exploited - no public PoC, not in CISA KEV, EPSS 0.4% (33rd percentile) - and it was patched amid the record 974-flaw Patch Tuesday, though the two actively exploited zero-days in that release are Windows flaws, not this one.
Heap Buffer Overflow in Windows Win32K Enables Local Privilege Escalation
CVE-2026-62712 is a heap-based buffer overflow (CWE-122) in the Windows Win32K kernel component, with Microsoft's related advisories (ZDI-26-542/618/619/620/621) tying the flaw to user-mode printer driver (UMPD) graphics callbacks such as UMPDDrvBitBlt, UMPDDrvStretchBlt and UMPDDrvRealizeBrush. A local attacker with valid low-privileged credentials can trigger the overflow through crafted GDI/printer-driver operations, with no user interaction required. Successful exploitation elevates the attacker from a standard user to kernel/SYSTEM level, yielding high confidentiality, integrity and availability impact on the host. Every Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2 through 26H1) and Windows Server (2012, 2016, 2019, 2022) installation on the listed builds is affected, which spans most of the supported Windows fleet. There is no public proof-of-concept, no CISA KEV listing, and a low EPSS of 0.4%, indicating no confirmed exploitation to date.
· Microsoft Windows 10 1607, 1809, 21H2, 22H2 · Microsoft Windows 11 23H2, 24H2, 25H2, 26H1mass
Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.