30
60
55
60
42
30
60
55
30
60
ZDI-26-648: (Pwn2Own) OpenAI Codex External Control of System or Configuration Setting Remote Code Execution Vulnerability
ZDI published a Pwn2Own advisory for CVE-2026-19590, enabling remote code execution in OpenAI's Codex agent via system or configuration control.
Zero Day Initiative advisory ZDI-26-648 documents an External Control of System or Configuration Setting vulnerability in OpenAI Codex, demonstrated at Pwn2Own. A remote attacker could achieve arbitrary code execution, with user interaction required such as opening malicious content. The flaw is tracked as CVE-2026-19590 with a CVSS rating of 7.8. No exploitation in the wild is reported.
52
30
42
30
Week in review: Exploited newly patched BeyondTrust RCE, United Airlines CISO on building resilience
60
30
60
55
30
30
55
42
30
60
55
55
60
42
55
55
55
30
55
30
55
30
55
55
60
30