ZDI-26-535: (Pwn2Own) Microsoft Exchange External Control of File Path Remote Code Execution Vulnerability
ZDI advisory discloses Microsoft Exchange remote code execution flaw (CVE-2026-62911, CVSS 7.2) with bypassable authentication.
ZDI advisory ZDI-26-535 describes an external control of file path vulnerability in Microsoft Exchange, tracked as CVE-2026-62911 with a CVSS score of 7.2. Remote attackers can execute arbitrary code on affected installations. Although authentication is required, the existing authentication mechanism can be bypassed.
Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
CERT Polska and CISA report active exploitation of Zimbra RCE CVE-2026-73570, with 267 instances compromised per Shadowserver.
CVE-2026-73570 (CVSS 8.9) enables unauthenticated command injection and remote code execution in Zimbra Collaboration before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled, via crafted SMTP requests. CISA added the flaw to its KEV catalog on August 21, 2026, with a federal patch deadline of August 24. The Shadowserver Foundation counted 267 compromised instances as of August 24, 2026, led by the US (46), Sweden (21), France (20) and Germany (17). Separately, Russia-linked Laundry Bear has weaponized Zimbra stored XSS CVE-2025-66376 against Western government and commercial mail servers since at least July 2025, delivering the ZimReaper payload.
Forgejo 16.0.4 has a critical security bug fix (RCE - Remote Code Execution)
Forgejo 16.0.4 fixes a critical remote code execution vulnerability in the self-hosted Git forge; administrators should update promptly.
The Forgejo project released version 16.0.4 of its self-hosted Git forge with a fix for a critical remote code execution vulnerability, as stated in the published release notes. The announcement provides no CVE identifier or technical exploitation details in the indexed text. Administrators running Forgejo instances should upgrade to 16.0.4 to apply the security fix.
ZDI-26-684: Linux Kernel KSMBD Query Directory Request Race Condition Remote Code Execution Vulnerability
ZDI discloses CVE-2026-64397, a CVSS 9.0 unauthenticated remote code execution race condition in Linux Kernel KSMBD.
ZDI-26-684 describes a race condition in the Linux Kernel KSMBD subsystem's Query Directory Request handling that allows unauthenticated remote attackers to execute arbitrary code. Only systems with KSMBD enabled are vulnerable. ZDI assigned a CVSS rating of 9.0 and CVE-2026-64397.
ZDI-26-657: ASUS Control Center Express Agent Missing Authentication Remote Code Execution Vulnerability
ZDI-26-657: ASUS Control Center Express Agent has an unauthenticated remote code execution flaw, CVE-2026-19397, rated CVSS 9.8.
The Zero Day Initiative published advisory ZDI-26-657 for ASUS Control Center Express Agent. The flaw, tracked as CVE-2026-19397, lets remote attackers execute arbitrary code without authentication. ZDI assigned a CVSS 9.8 rating. The advisory accompanies a vendor patch for affected installations.
ZDI-26-656: PAPPL Job Processing Heap-based Buffer Overflow Remote Code Execution Vulnerability
ZDI-26-656: Unauthenticated heap-based buffer overflow in PAPPL job processing allows remote code execution, rated CVSS 9.8.
The Zero Day Initiative published advisory ZDI-26-656 for PAPPL, the open-source printer application framework. A heap-based buffer overflow in job processing allows remote attackers to execute arbitrary code with no authentication required. ZDI assigned a CVSS 9.8 rating. No CVE identifier was listed in the advisory text.
ZDI-26-693: Linux Kernel ksmbd Share Configuration Race Condition Remote Code Execution Vulnerability
ZDI-26-693: authenticated race condition in Linux kernel ksmbd share configuration allows remote code execution on ksmbd-enabled systems; CVSS 8.5.
ZDI advisory ZDI-26-693 discloses a race condition in the Linux kernel's ksmbd share configuration that allows remote attackers to execute arbitrary code on affected installations. Exploitation requires authentication, and only systems with ksmbd enabled are vulnerable. ZDI assigned a CVSS rating of 8.5; no CVE is listed in the advisory text.
ZDI-26-583: Clam AntiVirus 7z Archive Parsing Integer Overflow Remote Code Execution Vulnerability
Zero Day Initiative discloses CVE-2026-20215, an integer overflow in ClamAV's 7z archive parsing enabling remote code execution, rated CVSS 8.4.
The Zero Day Initiative published ZDI-26-583 for an integer overflow in Clam AntiVirus's 7z archive parsing. A remote attacker can execute arbitrary code when the antivirus processes a crafted archive, with attack vectors varying by implementation. The flaw is tracked as CVE-2026-20215 and rated CVSS 8.4. The advisory does not mention active exploitation.
ZDI-26-590: libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
ZDI disclosed CVE-2026-19773, an unauthenticated out-of-bounds write allowing remote code execution in libwebsockets HTTP/2 HPACK parsing, rated CVSS 9.8.
The Zero Day Initiative published advisory ZDI-26-590 for an out-of-bounds write vulnerability in libwebsockets' HTTP/2 HPACK path header parsing. A remote attacker can execute arbitrary code on affected installations without authentication. The flaw is tracked as CVE-2026-19773 and carries a CVSS score of 9.8.
ZDI-26-695: Linux Kernel NFSv4 Server Race Condition Remote Code Execution Vulnerability
ZDI-26-695: Linux Kernel NFSv4 server race condition (CVE-2026-89688, CVSS 8.5) enables remote code execution on nfsd systems with authentication.
ZDI advisory ZDI-26-695 describes a race condition in the Linux Kernel NFSv4 server tracked as CVE-2026-89688 with a CVSS score of 8.5. Remote attackers can execute arbitrary code, but authentication is required and only systems with nfsd enabled are vulnerable. No in-the-wild exploitation is mentioned in the advisory.
ZDI-26-543: Microsoft Windows ICC File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
ZDI discloses an out-of-bounds write in Windows ICC file parsing via Mscms.dll enabling remote code execution (CVE-2026-54984, CVSS 7.8).
ZDI advisory ZDI-26-543 describes an out-of-bounds write in Microsoft Windows ICC file parsing that allows remote attackers to execute arbitrary code. Exploitation requires interaction with the Mscms.dll color management library, though attack vectors may vary by implementation. The flaw has a CVSS rating of 7.8 and is assigned CVE-2026-54984.
ZDI-26-546: Flowise Airtable_Agent Code Injection Remote Code Execution Vulnerability
ZDI discloses an unauthenticated code injection remote code execution flaw in Flowise's Airtable_Agent (CVE-2026-69264, CVSS 9.8).
ZDI advisory ZDI-26-546 describes a code injection vulnerability in the Flowise Airtable_Agent that allows remote attackers to execute arbitrary code. No authentication is required to exploit the flaw, which carries a CVSS rating of 9.8 and is assigned CVE-2026-69264. Flowise deployments exposing the vulnerable agent component are at risk of full server takeover.
ZDI-26-610: Apple Safari JavaScriptCore B3 ReduceStrength Phase Use-After-Free Remote Code Execution Vulnerability
ZDI details a use-after-free in Apple Safari's JavaScriptCore (CVE-2026-64715) that allows remote code execution after a user visits a malicious page.
The Zero Day Initiative published advisory ZDI-26-610 for a use-after-free in the B3 ReduceStrength phase of Apple Safari's JavaScriptCore. Successful exploitation allows remote attackers to execute arbitrary code, but user interaction is required, such as visiting a malicious page or opening a malicious file. ZDI rates the vulnerability 8.8 on CVSS and assigned CVE-2026-64715. The advisory does not report exploitation in the wild.
ZDI-26-544: Microsoft Windows Deployment Services Use-After-Free Remote Code Execution Vulnerability
ZDI discloses an unauthenticated use-after-free remote code execution flaw in Windows Deployment Services (CVE-2026-62893, CVSS 7.5).
ZDI advisory ZDI-26-544 describes a use-after-free in Microsoft Windows Server Deployment Services that allows network-adjacent attackers to execute arbitrary code without authentication. Only systems with Windows Deployment Services enabled are vulnerable. The flaw carries a CVSS rating of 7.5 and is tracked as CVE-2026-62893.
Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
Rapid7 published technical analysis of CVE-2026-63520, a remote code execution vulnerability in Microsoft SharePoint.
Rapid7 released an analysis covering CVE-2026-63520, a remote code execution flaw affecting Microsoft SharePoint. SharePoint is widely deployed in enterprise environments, making exposed, unpatched servers a likely target for exploitation. Defenders should consult the Rapid7 write-up for exposure checks and patch guidance. The available text does not confirm active exploitation at this time.
Zoom Patches “Zoomsday” Zero-Click Flaw Enabling Remote Code Execution
Zoom patched CVE-2026-53413, a zero-click annotation flaw dubbed "Zoomsday" allowing remote code execution on meeting participants' devices across all platforms.
Zoom patched four vulnerabilities, including CVE-2026-53413, a stack buffer overflow in CAnnoFormatBlock::Deserialize in the annotation protocol that allows zero-click remote code execution on another participant's device. A Security also found CVE-2026-53414, a buffer overread enabling denial-of-service crashes, and CVE-2026-53415, a use-after-free Zoom had already discovered internally. Updates shipped for Workplace 7.1.5 and 7.0.6, Rooms 7.1.5, and Meeting SDK 7.1.5 across all supported platforms.
Dell Secure Connect Gateway Critical Flaws Allow Unauthenticated Remote Code Execution and Admin Access
Dell patched three critical Secure Connect Gateway flaws (CVE-2026-80172 up to CVSS 9.8) enabling unauthenticated admin access, remote code execution, and host takeover.
Dell Security Advisory DSA-2026-382 fixes three critical vulnerabilities in Secure Connect Gateway (SCG) 5.0, affecting appliances earlier than 5.36.00.16 and applications earlier than 5.36.00.00. CVE-2026-80172 (CVSS 9.8) allows unauthenticated replay of captured requests to obtain ADMIN access due to missing nonce and time validation; CVE-2026-61410 (9.4) enables unauthenticated command execution via missing authorization; CVE-2026-80238 (9.3) involves an exposed Docker socket allowing root access and container escape. Dell urges immediate upgrades and recommends restricting management interfaces to trusted networks and rotating credentials if compromise is suspected.
UNISOC Modem Flaw Enables Remote Code Execution via Video Calls
A UNISOC modem flaw allows attackers to achieve kernel-level remote code execution through malicious video calls on affected devices.
UNISOC, whose modems are widely deployed in Android smartphones, has a flaw that enables kernel-level code execution triggered via video calls. Successful exploitation would give an attacker deep control over affected handsets. No exploitation activity is mentioned in the report.
Zero Day Initiative — CVE-2026-33824: Remote Code Execution in Windows ...
ZDI details CVE-2026-33824, a double-free in Windows IKEv2 fragment reassembly enabling unauthenticated remote code execution as SYSTEM on Windows.
Zero Day Initiative published technical analysis of CVE-2026-33824, a double-free in the Windows IKE Extension (ikeext.dll) caused by improper ownership handling of a heap blob pointer during IKEv2 fragment reassembly in IkeReinjectReassembledPacket(). A remote unauthenticated attacker can send a crafted IKE_SA_INIT message with a Security Realm Vendor ID followed by fragmented IKE_AUTH payloads to trigger the double free. Successful exploitation could yield arbitrary code execution under the IKEEXT service context (SYSTEM). ZDI also provided IDS detection guidance correlating the two-packet sequence on UDP ports 500 and 4500.