ZDI-26-638: Oracle Outside In Technology WPS File Parsing Memory Corruption Remote Code Execution Vulnerability
ZDI disclosed memory corruption in Oracle Outside In Technology's WPS file parsing (CVE-2026-60414) enabling user-triggered remote code execution.
Zero Day Initiative published ZDI-26-638, a CVSS 7.8 memory corruption vulnerability in WPS file parsing within Oracle Outside In Technology. Remote attackers can execute arbitrary code on affected installations by convincing the target to visit a malicious page or open a malicious file, so user interaction is required. The issue is tracked as CVE-2026-60414. The advisory reports no exploitation.
August 2026 CVE Landscape
Insikt Group catalogs 73 high-impact August 2026 CVEs (43 Very Critical), including PaperCut, Zimbra, and Metabase flaws actively exploited or weaponized.
Recorded Future's Insikt Group identified 73 high-impact vulnerabilities in August 2026, 43 rated Very Critical, spanning 45 vendors with Microsoft accounting for roughly 11%. 31 vulnerabilities surfaced via CISA's KEV catalog, with others validated via open sources, vendor telemetry, and honeypot data. New Nuclei detection templates were released for CVE-2025-62593 (Ray), CVE-2026-72898 (Metabase), and CVE-2026-9198 (IBM Langflow). The report also highlights two AI-assisted operations: UAT-10147 exploited Zimbra, AjaxPro, Nacos, and Telerik servers before using DeepAudit and PentestGPT post-compromise, while a separate Chinese-speaking actor weaponized Hermes Agent and DeepSeek in a failed attempt.