ZeroHour
Vendor

Zero Day Initiative

39 mentions in 7 days · 65 in 30 days · 88 total · first seen · last

Timeline

The September 2026 Security Update Review

ZDI's September 2026 Microsoft update review lists two already-exploited Windows EoP zero-days and dozens of critical RCEs across Office, SQL Server, and Windows services.

The review catalogs Microsoft's September 2026 fixes, marking CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack) as already exploited elevation-of-privilege issues. It also lists critical RCE flaws in Office, Word, Excel, PowerPoint, Outlook, SQL Server, Windows DNS, DHCP and Failover Cluster, plus graphics component RCEs. Azure-side fixes include Entra ID, Copilot Studio, Azure AI Language and Azure AD B2C elevation-of-privilege flaws.

ZDI-26-619: Microsoft Windows UMPDDrvStretchBltROP Improper Object Management Local Privilege Escalation Vulnerability

ZDI disclosed CVE-2026-62712, a CVSS 7.8 improper object management flaw in Windows UMPDDrvStretchBltROP enabling local privilege escalation from low-privileged code.

The Zero Day Initiative published ZDI-26-619 covering a local privilege escalation vulnerability in Microsoft Windows' UMPDDrvStretchBltROP function, stemming from improper object management. Exploitation requires that the attacker first obtain the ability to run low-privileged code on the target system. ZDI rated the issue CVSS 7.8 and assigned CVE-2026-62712, the same identifier listed in the companion UMPDDrvRealizeBrush advisory.

ZDI-26-622: Microsoft Windows IKEv2 AES-GCM Decryption Integer Underflow Remote Code Execution Vulnerability

ZDI disclosed CVE-2026-50696, a CVSS 8.1 integer underflow in Windows IKEv2 AES-GCM decryption enabling unauthenticated remote code execution on specific IPsec configurations.

The Zero Day Initiative published ZDI-26-622 describing a remote code execution vulnerability in Microsoft Windows' IKEv2 AES-GCM decryption path, caused by an integer underflow. Authentication is not required for exploitation, but only systems using specific IPsec configurations are affected. ZDI assigned the vulnerability a CVSS score of 8.1 and the identifier CVE-2026-50696.

ZDI-26-618: Microsoft Windows UMPDDrvStretchBlt Improper Object Management Local Privilege Escalation Vulnerability

ZDI disclosed CVE-2026-62712, a CVSS 7.8 Windows UMPDDrvStretchBlt improper object-management flaw enabling local privilege escalation.

Zero Day Initiative advisory ZDI-26-618 describes an improper object management issue in Microsoft Windows' UMPDDrvStretchBlt component. A local attacker who can already execute low-privileged code on the system can escalate privileges. The flaw carries a CVSS 3.0 rating of 7.8; details on affected versions and patch availability are limited in the advisory.

ZDI-26-620: Microsoft Windows UMPDDrvPlgBlt Improper Object Management Local Privilege Escalation Vulnerability

ZDI disclosed CVE-2026-62712, a CVSS 7.8 Windows UMPDDrvPlgBlt improper object-management flaw enabling local privilege escalation.

Zero Day Initiative advisory ZDI-26-620 describes an improper object management flaw in Microsoft Windows' UMPDDrvPlgBlt component, sharing CVE-2026-62712 with the related UMPDDrvStretchBlt advisory. A local attacker able to run low-privileged code can escalate privileges on affected installations. The issue carries a CVSS 3.0 rating of 7.8.

ZDI-26-616: Koha Eval Code Injection Remote Code Execution Vulnerability

ZDI disclosed CVE-2026-19780, a CVSS 8.8 authenticated eval code-injection flaw in Koha enabling remote code execution.

Zero Day Initiative advisory ZDI-26-616 describes a code injection vulnerability in the Eval component of Koha, the open-source integrated library system. A remote attacker must authenticate before injecting and executing arbitrary code on affected installations. ZDI assigned the flaw a CVSS 3.0 rating of 8.8.

ZDI-26-621: Microsoft Windows UMPDDrvRealizeBrush Improper Object Management Local Privilege Escalation Vulnerability

ZDI disclosed CVE-2026-62712, a CVSS 7.8 improper object management flaw in Windows UMPDDrvRealizeBrush enabling local privilege escalation after low-privileged code execution.

The Zero Day Initiative published ZDI-26-621 covering a local privilege escalation vulnerability in Microsoft Windows' UMPDDrvRealizeBrush component, caused by improper object management. An attacker must already be able to execute low-privileged code on the target system before exploiting the flaw. ZDI assigned the vulnerability a CVSS score of 7.8 and the CVE identifier CVE-2026-62712.

ZDI-26-617: Microsoft Windows MIDI Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability

ZDI disclosed CVE-2026-66804, a CVSS 7.8 incorrect permission assignment in Windows MIDI Service allowing local privilege escalation.

Zero Day Initiative advisory ZDI-26-617 details an incorrect permission assignment flaw in the Microsoft Windows MIDI Service. An attacker with the ability to run low-privileged code on an affected system can escalate privileges. ZDI rated the issue CVSS 7.8; the advisory provides no evidence of active exploitation.

Zero Day Initiative — CVE-2026-33824: Remote Code Execution in Windows ...

ZDI details CVE-2026-33824, a double-free in Windows IKEv2 fragment reassembly enabling unauthenticated remote code execution as SYSTEM on Windows.

Zero Day Initiative published technical analysis of CVE-2026-33824, a double-free in the Windows IKE Extension (ikeext.dll) caused by improper ownership handling of a heap blob pointer during IKEv2 fragment reassembly in IkeReinjectReassembledPacket(). A remote unauthenticated attacker can send a crafted IKE_SA_INIT message with a Security Realm Vendor ID followed by fragmented IKE_AUTH payloads to trigger the double free. Successful exploitation could yield arbitrary code execution under the IKEEXT service context (SYSTEM). ZDI also provided IDS detection guidance correlating the two-packet sequence on UDP ports 500 and 4500.

Hackers Target Langflow in CVE-2026

Threat actors are actively exploiting CVE-2026-0768, an unauthenticated Python RCE in Langflow, hunting OpenAI, AWS, and SSH credentials.

Attackers began exploiting CVE-2026-0768 (CVSS 9.8), an unauthenticated remote code execution flaw in the code validator of the Langflow AI low-code platform, affecting all versions up to 1.4.2. VulnCheck observed 50+ Canary detections on the first day of exploitation, with attackers checking Langflow, OpenAI, and AWS keys in environment variables, reading the secret key, and looking for SSH access and shell history; most traffic originates from Russia and targeted UK-based canaries. The flaw was reported via ZDI by Trend Research in July 2025 and disclosed in January 2026; six other Langflow CVEs were added to VulnCheck's KEV list this year.

Security Affairs · 13d agoExploit / PoC in the wildCVE-2026-07681

ZDI-26-615: (0Day) pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

Zero Day Initiative disclosed an uncontrolled search path flaw in pdfforge PDF Architect's update service, allowing local privilege escalation (CVSS 7.8).

ZDI published advisory ZDI-26-615 describing a local privilege escalation vulnerability in the activation-service Update Service of pdfforge PDF Architect. An uncontrolled search path element lets local attackers escalate privileges, but they must first be able to execute low-privileged code on the target. ZDI rated the issue 7.8 and tagged it as a 0-day disclosure.

ZDI Published Advisories · 15d agoVulnerability

ZDI-26-593: NVIDIA TensorRT ONNX File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

ZDI disclosed a second TensorRT heap-based buffer overflow RCE (CVE-2026-24268, CVSS 7.8) in ONNX file parsing, requiring user interaction.

The Zero Day Initiative published advisory ZDI-26-593 covering another heap-based buffer overflow in NVIDIA TensorRT's ONNX file parsing. A remote attacker can execute arbitrary code if the target opens a malicious file or visits a crafted page. ZDI rated the vulnerability CVSS 7.8 and assigned CVE-2026-24268.

ZDI-26-587: Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

ZDI advisory ZDI-26-587 details a heap-based buffer overflow RCE (CVE-2026-19781, CVSS 7.8) in Ashlar-Vellum Cobalt VS file parsing, requiring user interaction.

The Zero Day Initiative released advisory ZDI-26-587 covering a heap-based buffer overflow in Ashlar-Vellum Cobalt's VS file parsing. A remote attacker can execute arbitrary code when the target opens a malicious file or visits a crafted page. ZDI rated the vulnerability CVSS 7.8 and assigned CVE-2026-19781.

ZDI-26-607: Microsoft Office HTML Injection Information Disclosure Vulnerability

ZDI disclosed an HTML injection flaw in Microsoft Office (CVSS 7.6) that lets remote attackers disclose sensitive information via malicious pages or files.

Zero Day Initiative advisory ZDI-26-607 describes an HTML injection vulnerability in Microsoft Office that leads to information disclosure. Remote attackers need the target to visit a malicious page or open a malicious file to trigger it. ZDI rated the issue 7.6 on the CVSS scale and the advisory lists no CVE identifier. The advisory does not indicate active exploitation.

ZDI Published Advisories · 22d agoVulnerability1

ZDI-26-588: Fabric.js loadFromJSON Server-Side Request Forgery Vulnerability

ZDI disclosed a server-side request forgery in Fabric.js loadFromJSON (CVE-2026-19504) that can leak sensitive information from affected implementations.

Zero Day Initiative advisory ZDI-26-588 describes a server-side request forgery vulnerability in the Fabric.js canvas library's loadFromJSON function. Exploitation requires interaction with the library and attack vectors vary by implementation, potentially exposing sensitive information. The issue is rated 4.0 on the CVSS scale and tracked as CVE-2026-19504. The advisory does not report exploitation in the wild.

ZDI-26-591: NVIDIA TensorRT ONNX File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

ZDI disclosed a heap-based buffer overflow RCE (CVE-2026-24272, CVSS 7.8) in NVIDIA TensorRT ONNX parsing, requiring user interaction to exploit.

The Zero Day Initiative published advisory ZDI-26-591 covering a heap-based buffer overflow in NVIDIA TensorRT's ONNX file parsing. Successful exploitation allows remote code execution when a user opens a malicious ONNX file or visits a crafted page. ZDI rated the vulnerability CVSS 7.8 and assigned CVE-2026-24272.

ZDI-26-602: Foxit PDF Reader Doc Object Use-After-Free Remote Code Execution Vulnerability

ZDI disclosed a use-after-free in Foxit PDF Reader (CVE-2026-13128) enabling remote code execution when a user opens a malicious file.

Zero Day Initiative advisory ZDI-26-602 describes a use-after-free flaw in Foxit PDF Reader's document object handling. Exploitation yields arbitrary code execution but requires the target to open a malicious page or file. ZDI assigned CVSS 7.8 and CVE-2026-13128. The advisory does not report active exploitation.

ZDI-26-590: libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

ZDI disclosed CVE-2026-19773, an unauthenticated out-of-bounds write allowing remote code execution in libwebsockets HTTP/2 HPACK parsing, rated CVSS 9.8.

The Zero Day Initiative published advisory ZDI-26-590 for an out-of-bounds write vulnerability in libwebsockets' HTTP/2 HPACK path header parsing. A remote attacker can execute arbitrary code on affected installations without authentication. The flaw is tracked as CVE-2026-19773 and carries a CVSS score of 9.8.

ZDI-26-610: Apple Safari JavaScriptCore B3 ReduceStrength Phase Use-After-Free Remote Code Execution Vulnerability

ZDI details a use-after-free in Apple Safari's JavaScriptCore (CVE-2026-64715) that allows remote code execution after a user visits a malicious page.

The Zero Day Initiative published advisory ZDI-26-610 for a use-after-free in the B3 ReduceStrength phase of Apple Safari's JavaScriptCore. Successful exploitation allows remote attackers to execute arbitrary code, but user interaction is required, such as visiting a malicious page or opening a malicious file. ZDI rates the vulnerability 8.8 on CVSS and assigned CVE-2026-64715. The advisory does not report exploitation in the wild.

ZDI-26-605: Microsoft Windows Localized Filenames Improper Input Validation NTLM Response Information Disclosure Vulnerability

ZDI advisory ZDI-26-605 details an improper input validation flaw (CVE-2026-50508, CVSS 3.3) in Microsoft Windows localized filenames that leaks NTLM responses.

The Zero Day Initiative released advisory ZDI-26-605 describing improper input validation in Microsoft Windows handling of localized filenames. Remote attackers can disclose NTLM authentication responses if the target opens a malicious file or visits a crafted page. ZDI rated the issue CVSS 3.3 and assigned CVE-2026-50508. Leaked NTLM responses could enable offline credential cracking.

ZDI Published Advisories · 22d agoAdvisoryCVE-2026-505081

ZDI-26-585: OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

ZDI reported an out-of-bounds write in OriginLab Origin Viewer's OGWU parsing (CVE-2026-19885) that allows remote code execution via crafted files.

ZDI-26-585 details an out-of-bounds write vulnerability when OriginLab Origin Viewer parses OGWU files, leading to remote code execution. A successful attack requires the user to open a malicious file or visit a malicious page. The flaw carries a CVSS rating of 7.8 and is tracked as CVE-2026-19885. No in-the-wild exploitation is mentioned.

ZDI-26-589: BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability

ZDI details a network-adjacent stack buffer overflow in BlueZ's A2DP stack (CVE-2026-19774, CVSS 7.1) allowing remote code execution after pairing a malicious Bluetooth device.

The Zero Day Initiative published advisory ZDI-26-589 for a stack-based buffer overflow in BlueZ, the Linux Bluetooth protocol stack. A network-adjacent attacker who can pair a malicious Bluetooth device with the target can execute arbitrary code on the affected installation. The flaw carries a CVSS 7.1 rating and is tracked as CVE-2026-19774.

ZDI-26-606: Microsoft Windows Compatibility Appraiser Link Following Local Privilege Escalation Vulnerability

ZDI disclosed a link-following flaw in Windows Compatibility Appraiser (CVSS 7.0) enabling local privilege escalation from the LOCAL SERVICE context.

ZDI-26-606 describes a link-following vulnerability in the Windows Compatibility Appraiser component that permits local privilege escalation. An attacker must already be able to execute low-privileged code in the LOCAL SERVICE context on the target system. ZDI rated the issue 7.0 on the CVSS scale; the advisory lists no CVE identifier. No active exploitation is reported.

ZDI Published Advisories · 22d agoVulnerability2

ZDI-26-586: OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability

ZDI advisory ZDI-26-586 reports a memory corruption RCE (CVE-2026-19886, CVSS 7.8) in OriginLab Origin Viewer OGM file parsing, needing user interaction.

The Zero Day Initiative published advisory ZDI-26-586 describing a memory corruption vulnerability in OriginLab Origin Viewer's OGM file parsing. Exploitation allows remote code execution when a user opens a malicious file or visits a crafted page. ZDI rated the issue CVSS 7.8 and assigned CVE-2026-19886.

ZDI-26-599: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability

ZDI published advisory ZDI-26-599 for a use-after-free information disclosure flaw (CVE-2026-57238, CVSS 3.3) in Foxit PDF Reader requiring user interaction.

The Zero Day Initiative released advisory ZDI-26-599 describing a use-after-free vulnerability in Foxit PDF Reader's annotation handling. The flaw allows remote attackers to disclose sensitive information when a target opens a malicious file or visits a malicious page. ZDI rated the issue CVSS 3.3 and assigned CVE-2026-57238.

ZDI-26-582: Cisco Identity Services Engine PatchUpdateListener Directory Traversal Information Disclosure Vulnerability

Cisco Identity Services Engine's PatchUpdateListener has an authenticated directory traversal (CVE-2026-20148, CVSS 4.9) enabling sensitive information disclosure.

ZDI advisory ZDI-26-582 describes a directory traversal information disclosure vulnerability in the PatchUpdateListener component of Cisco Identity Services Engine. Remote attackers can disclose sensitive information, but valid authentication is required to exploit the flaw. ZDI assigned a CVSS rating of 4.9 and CVE-2026-20148.

ZDI Published Advisories · Aug 13, 2026VulnerabilityCVE-2026-20148

ZDI-26-577: Trend Micro VPN OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

ZDI disclosed a local privilege escalation (CVE-2026-67212, CVSS 7.0) in Trend Micro VPN's OpenSSL configuration, requiring prior low-privileged code execution.

The Zero Day Initiative published advisory ZDI-26-577 describing an uncontrolled search path element vulnerability in Trend Micro VPN's OpenSSL configuration. Local attackers who can already execute low-privileged code on an affected installation can escalate privileges. ZDI rated the issue 7.0 on CVSS and assigned CVE-2026-67212.

ZDI Published Advisories · Aug 13, 2026VulnerabilityCVE-2026-67212

ZDI-26-573: Linux Kernel KSMBD Response Header Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI disclosed an unauthenticated out-of-bounds read (CVE-2026-68431) in Linux Kernel KSMBD causing sensitive information disclosure, CVSS 9.3.

The Zero Day Initiative published ZDI-26-573 describing an out-of-bounds read in the Linux Kernel KSMBD response header handling. Unauthenticated remote attackers can disclose sensitive information, but only systems with ksmbd enabled are affected. ZDI assigned a CVSS score of 9.3 and the identifier CVE-2026-68431.

ZDI Published Advisories · Aug 13, 2026VulnerabilityCVE-2026-68431

ZDI-26-568: Linux Kernel Net Scheduler Race Condition Local Privilege Escalation Vulnerability

ZDI disclosed a race condition (CVSS 7.5) in the Linux kernel net scheduler enabling local privilege escalation; no CVE assigned in the advisory text.

ZDI advisory ZDI-26-568 describes a race condition in the Linux kernel's net scheduler that allows local attackers to escalate privileges on affected installations. Exploitation requires the attacker to first execute high-privileged code on the target system. ZDI assigned a CVSS rating of 7.5; no CVE identifier is listed in the advisory text.

ZDI Published Advisories · Aug 13, 2026Vulnerability

ZDI-26-571: Linux Kernel Net Scheduler Packet Classifier API Use-After-Free Local Privilege Escalation Vulnerability

ZDI disclosed a use-after-free local privilege escalation flaw (CVE-2026-64530) in the Linux Kernel net scheduler packet classifier API.

The Zero Day Initiative published ZDI-26-571 describing a use-after-free in the Linux Kernel net scheduler packet classifier API. Local attackers who can already execute low-privileged code can escalate privileges. ZDI assigned a CVSS score of 8.8 and the identifier CVE-2026-64530.

ZDI Published Advisories · Aug 13, 2026VulnerabilityCVE-2026-645301

ZDI-26-576: Linux Kernel XFRM Race Condition Local Privilege Escalation Vulnerability

ZDI disclosed a race condition local privilege escalation flaw in the Linux Kernel XFRM subsystem, CVSS 7.5, with no CVE assigned.

The Zero Day Initiative published ZDI-26-576 describing a race condition in the Linux Kernel XFRM subsystem. Local attackers can escalate privileges, but the advisory states an attacker must first be able to execute high-privileged code on the target. ZDI assigned a CVSS score of 7.5; no CVE identifier is listed in the advisory text.

ZDI Published Advisories · Aug 13, 2026Vulnerability

ZDI-26-583: Clam AntiVirus 7z Archive Parsing Integer Overflow Remote Code Execution Vulnerability

Zero Day Initiative discloses CVE-2026-20215, an integer overflow in ClamAV's 7z archive parsing enabling remote code execution, rated CVSS 8.4.

The Zero Day Initiative published ZDI-26-583 for an integer overflow in Clam AntiVirus's 7z archive parsing. A remote attacker can execute arbitrary code when the antivirus processes a crafted archive, with attack vectors varying by implementation. The flaw is tracked as CVE-2026-20215 and rated CVSS 8.4. The advisory does not mention active exploitation.

ZDI Published Advisories · Aug 13, 2026VulnerabilityCVE-2026-20215

ZDI-26-574: Linux Kernel Net Scheduler Connection Tracking Race Condition Local Privilege Escalation Vulnerability

A race condition (CVE-2026-46319, CVSS 7.5) in the Linux kernel net scheduler connection tracking allows local privilege escalation.

ZDI advisory ZDI-26-574 documents a race condition in the Linux kernel's net scheduler connection tracking component. Local attackers who can execute high-privileged code on a target can exploit the flaw to escalate privileges. ZDI rated the vulnerability 7.5 on CVSS and assigned CVE-2026-46319.

ZDI Published Advisories · Aug 13, 2026VulnerabilityCVE-2026-46319

ZDI-26-580: Cisco Identity Services Engine Missing Authentication for Critical Function Information Disclosure Vulnerability

ZDI discloses CVE-2026-20190, a missing-authentication flaw in Cisco Identity Services Engine permitting unauthenticated sensitive information disclosure, rated CVSS 7.5.

ZDI-26-580 covers a missing authentication for critical function flaw in Cisco Identity Services Engine. Unauthenticated remote attackers can disclose sensitive information from affected installations. The vulnerability is tracked as CVE-2026-20190 and rated CVSS 7.5. The advisory does not indicate exploitation in the wild.

ZDI Published Advisories · Aug 13, 2026VulnerabilityCVE-2026-20190

ZDI-26-581: Cisco Identity Services Engine invokeScript Command Injection Remote Code Execution Vulnerability

ZDI details CVE-2026-20147, an authenticated command injection in Cisco Identity Services Engine allowing remote code execution, rated CVSS 7.2.

ZDI-26-581 describes a command injection flaw in Cisco Identity Services Engine reachable through the invokeScript function. Remote attackers who authenticate can execute arbitrary code on affected installations. The issue is tracked as CVE-2026-20147 and carries a CVSS rating of 7.2. No exploitation activity is reported in the advisory.

ZDI Published Advisories · Aug 13, 2026VulnerabilityCVE-2026-20147

ZDI-26-578: NGINX HTTP Dav Module Alias Directive Integer Underflow Remote Code Execution Vulnerability

An unauthenticated integer underflow (CVE-2026-27654, CVSS 8.1) in NGINX's HTTP Dav module alias directive enables remote code execution.

ZDI advisory ZDI-26-578 describes an integer underflow in the alias directive of the NGINX HTTP Dav module that allows remote attackers to execute arbitrary code. Authentication is not required to exploit the vulnerability. ZDI rated the issue 8.1 on CVSS and assigned CVE-2026-27654.

ZDI Published Advisories · Aug 13, 2026VulnerabilityCVE-2026-27654

ZDI-26-565: Gen Digital CCleaner Link Following Local Privilege Escalation Vulnerability

A link-following flaw (CVE-2026-12410, CVSS 7.8) in Gen Digital CCleaner allows local privilege escalation after low-privileged code execution.

ZDI advisory ZDI-26-565 details a link following vulnerability in Gen Digital CCleaner that permits local privilege escalation. An attacker must first be able to run low-privileged code on the affected installation. ZDI rated the issue 7.8 on CVSS and assigned CVE-2026-12410.

ZDI Published Advisories · Aug 13, 2026VulnerabilityCVE-2026-12410

ZDI-26-584: dnsmasq DNSSEC NSEC/NSEC3 Type Bitmap Processing Infinite Loop Denial-of-Service Vulnerability

ZDI disclosed an unauthenticated infinite-loop denial-of-service flaw (CVE-2026-4890) in dnsmasq DNSSEC NSEC/NSEC3 bitmap processing.

The Zero Day Initiative published ZDI-26-584 describing an infinite loop in dnsmasq's processing of DNSSEC NSEC/NSEC3 type bitmaps. Remote unauthenticated attackers can trigger a denial-of-service condition on affected installations. ZDI assigned a CVSS score of 7.5 and the identifier CVE-2026-4890.

ZDI Published Advisories · Aug 13, 2026VulnerabilityCVE-2026-4890

ZDI-26-566: BlackBerry QNX KEV File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

ZDI disclosed an out-of-bounds write flaw (CVE-2026-40272) in BlackBerry QNX KEV file parsing enabling remote code execution.

The Zero Day Initiative published ZDI-26-566 describing an out-of-bounds write vulnerability in BlackBerry QNX KEV file parsing. Remote code execution requires user interaction, such as visiting a malicious page or opening a malicious file. ZDI assigned a CVSS score of 7.8 and the CVE identifier CVE-2026-40272.

ZDI Published Advisories · Aug 13, 2026VulnerabilityCVE-2026-40272

ZDI-26-579: Cisco Identity Services Engine zipFiles Directory Traversal Remote Code Execution Vulnerability

ZDI disclosed an authenticated directory traversal flaw (CVE-2026-20181) in Cisco Identity Services Engine allowing remote code execution, CVSS 7.2.

The Zero Day Initiative published ZDI-26-579 describing a directory traversal in the zipFiles functionality of Cisco Identity Services Engine. Authenticated remote attackers can execute arbitrary code on affected installations. ZDI assigned a CVSS score of 7.2 and the identifier CVE-2026-20181.

ZDI Published Advisories · Aug 13, 2026VulnerabilityCVE-2026-20181

Related CVEs

  • Heap-Based Buffer Overflow in Windows ALPC Enables Local Privilege Escalation
    CVE-2026-85880 is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), the Windows mechanism for local inter-process communication. An authorized local attacker can trigger the overflow by submitting crafted input over ALPC, corrupting heap memory in the component that handles the request. Successful exploitation allows the attacker to execute code with elevated privileges, typically gaining SYSTEM-level control of the local host, which is especially valuable as a post-exploitation or sandbox-escape step. Affected products include Windows 10 (1607, 1809, 21H2, 22H2) and Windows Server 2012, 2016, 2019, and 2022, meaning most on-premises Windows estates are in scope. The flaw was fixed in Microsoft's record 974-CVE September 2026 Patch Tuesday and was added to CISA's KEV on 2026-09-08, confirming exploitation in the wild; press reports describe Windows zero-days being chained with a Chrome zero-day in 'BlueMoon' kit attacks, though the data does not explicitly confirm this CVE is the Windows flaw in that chain.
    · Microsoft Windows 10 1607, 1809, 21H2, 22H2 · Microsoft Windows Server 2012, 2016, 2019, 2022 KEVmass
  • Local Privilege Escalation via Link Following in Windows Update Stack
    CVE-2026-81963 is a link-following flaw (CWE-59, improper link resolution before file access) in the Microsoft Windows Update Stack, in which the component fails to correctly resolve file links before opening them. A local attacker with low privileges can plant or manipulate a link (symlink/junction) that the privileged update stack follows during operation, redirecting its file access to an attacker-controlled target. The result is local privilege escalation — CVSS 3.1 rates this 7.8 (high) with high confidentiality, integrity, and availability impact — allowing an authorized local user or malware already on the machine to gain elevated rights. Affected products are Windows 11 23H2, 24H2, 25H2, and 26H1 and Windows Server 2025; any unpatched system on those versions is exposed to any local account holder. The flaw was fixed in Microsoft's record September 2026 Patch Tuesday (974 CVEs), was added to CISA's KEV on 2026-09-08 as one of two Windows zero-days reported as exploited in the wild, and has no known public PoC or confirmed ransomware use.
    · Microsoft Windows 11 23H2, 24H2, 25H2, 26H1 · Microsoft Windows Server 2025 KEVmass
  • Heap Buffer Overflow in Windows Win32K Enables Local Privilege Escalation
    CVE-2026-62712 is a heap-based buffer overflow (CWE-122) in the Windows Win32K kernel component, with Microsoft's related advisories (ZDI-26-542/618/619/620/621) tying the flaw to user-mode printer driver (UMPD) graphics callbacks such as UMPDDrvBitBlt, UMPDDrvStretchBlt and UMPDDrvRealizeBrush. A local attacker with valid low-privileged credentials can trigger the overflow through crafted GDI/printer-driver operations, with no user interaction required. Successful exploitation elevates the attacker from a standard user to kernel/SYSTEM level, yielding high confidentiality, integrity and availability impact on the host. Every Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2 through 26H1) and Windows Server (2012, 2016, 2019, 2022) installation on the listed builds is affected, which spans most of the supported Windows fleet. There is no public proof-of-concept, no CISA KEV listing, and a low EPSS of 0.4%, indicating no confirmed exploitation to date.
    · Microsoft Windows 10 1607, 1809, 21H2, 22H2 · Microsoft Windows 11 23H2, 24H2, 25H2, 26H1mass
  • Pre-auth use-after-free RCE in Microsoft Windows Deployment Services (WDS)
    Microsoft Windows Deployment Services (WDS) contains a use-after-free memory-safety flaw (CWE-416) that an unauthenticated attacker can trigger by sending crafted network traffic to the WDS service, leading to remote code execution on the target system. The vulnerability affects Windows 10 1607 and 1809 and Windows Server 2012, 2016, 2019, 2022, and 2025 on systems where WDS is deployed, a role typically used for network-based (PXE) operating system imaging. A successful exploit grants the attacker code execution with high confidentiality, integrity, and availability impact, reflected in the critical CVSS 3.1 score of 9.8 with network vector, low complexity, and no privileges or user interaction required. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is currently known, although EPSS estimates a 2.7% probability of exploitation within 30 days (85th percentile). The flaw was disclosed alongside Microsoft's record September 2026 Patch Tuesday, which shipped nearly 1,000 fixes including two Windows zero-days.
    · microsoft Windows 10 1607 · microsoft Windows 10 1809large
  • Unbootable-System Denial of Service via Link Following in Backblaze Windows Backup Client
    CVE-2026-19820 is a link-following flaw (CWE-59) in the Backblaze Personal Computer Backup client for Windows, whose backup components (bzserv, bztransmit, bzfilelist, bzbackup, and bzreports) do not properly resolve links in the folders they traverse. A local user can create a link from Backblaze's folder to Windows OS system files during a backup; when the client follows the link, the affected machine can be rendered unbootable. Successful exploitation requires that an administrator-level system change has removed the specific Windows OS security controls that normally govern link resolution, allowing the link to be planted in this way. The impact is loss of availability of the whole system (high impact on the system's ability to boot), not data theft. Exploitation is not currently known: no public PoC exists, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at about 0.3%.
    · Backblaze Personal Computer Backup (Backblaze Client) for Windows, including the bzserv, bztransmit, bzfilelist, bzbackup, and bzrlarge
  • Actively Exploited V8 Type Confusion in Google Chrome (CVE-2026-85046)
    Google Chrome versions prior to 152.0.7977.82 contain a type confusion flaw (CWE-843) in the V8 JavaScript engine, which mishandles object types during engine operations (public proof-of-concept writeups indicate it is reachable through array sorting and WebAssembly-related code paths). A remote attacker triggers the flaw simply by getting a user to open a crafted HTML page, with no privileges or authentication required. Successful exploitation lets the attacker execute arbitrary code inside the browser's sandbox, and public reporting shows it being chained with Windows zero-days (the 'BlueMoon' exploit kit) by Chinese espionage groups for broader compromise. Any user of an unpatched Chrome or another build embedding the affected V8 engine is exposed. The vulnerability is a zero-day that was actively exploited in the wild before patching, was added to CISA's KEV on 2026-09-04, and has five public proof-of-concept references.
    · Google Chrome prior to 152.0.7977.82 · Google Chromium V8 V8 engine versions bundled with Chrome prior to 152.0.7977.82 KEV PoC ×5mass
  • Langflow code Code Injection Remote Code Execution Vulnerability.
    Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the code parameter provided to the validate endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of root. . Was ZDI-CAN-27322.
    · langflow langflow
  • A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an af
    A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. In…
    · cisco identity services engine · cisco identity services engine passive identity connector
  • Oracle Outside In Technology GEM File Parsing Integer Overflow Allows Takeover
    CVE-2026-60413 is a vulnerability in the Outside In Core component of Oracle Outside In Technology 8.5.8, Oracle's document parsing and conversion engine that is bundled within Oracle Fusion Middleware. An unauthenticated attacker who can log on to the infrastructure where Outside In Technology executes (CVSS attack vector AV:L, no privileges required) can trigger the flaw, and successful attacks require interaction from a user other than the attacker — consistent with a crafted file being submitted for parsing. The related ZDI advisory (ZDI-26-637) characterizes the issue as an integer overflow when parsing GEM files that can lead to remote code execution, while Oracle's entry maps the weakness to CWE-200 and rates it 7.8 (high) with high confidentiality, integrity, and availability impacts, resulting in takeover of Outside In Technology. Any deployment running the affected 8.5.8 release of Outside In Technology — typically embedded inside Oracle Fusion Middleware or other products that use the engine for document conversion — is affected. There is currently no public proof-of-concept, the issue is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation within 30 days, so no exploitation is known.
    · Oracle Outside In Technology (Outside In Core, product of Oracle Fusion Middleware) 8.5.8 (supported version listed as affected)
  • Heap Buffer Overflow in Microsoft Windows Codecs Library Enables Local Code Execution
    CVE-2026-58599 is a heap-based buffer overflow (CWE-122) in the Microsoft Windows Codecs Library, patched by Microsoft as part of the September 2026 Patch Tuesday. The CVSS vector (AV:L, UI:R, no privileges required) indicates the flaw is triggered locally when the codecs library processes specially crafted content, requiring user interaction such as opening a malicious media or image file. A successful attacker can execute arbitrary code in the context of the local user with no prior privileges, with high impact on confidentiality, integrity, and availability. Any Windows system containing the affected Windows Codecs Library is exposed, though the source data does not enumerate specific Windows versions or builds. Exploitation is currently quiet: there is no public proof-of-concept, no CISA KEV listing, and EPSS estimates only about a 0.3% probability of exploitation within 30 days (25th percentile).
    · Microsoft Windows (Windows Codecs Library component)mass

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.