TL;DR Qualys disclosed RefluXFS on July 22, 2026. Tracked as CVE-2026-64600, it is a Linux kernel XFS...
privilege escalation
TL;DR The Exim team published advisory EXIM-Security-2026-06-22.1 on July 22, 2026. It describes an Exim vulnerability that...
TL;DR SolarWinds fixed 15 critical SolarWinds Serv-U vulnerabilities on July 21, 2026. They allow privilege escalation, account...
TL;DR Qualys found a snap-confine privilege escalation flaw, tracked as CVE-2026-8933. It lets any local user reach...
TL;DR A critical Kyverno vulnerability, CVE-2026-54523 (CVSS 9.6), has been publicly disclosed with full technical details and...
TL;DR Cloud Software Group published bulletin CTX696734 for two flaws in Citrix Windows clients. CVE-2026-53565, a Citrix...
TL;DR Zoom has patched four flaws across its Windows products. The most severe Zoom vulnerability, CVE-2026-53412 (CVSS...
TL;DR Four critical Coolify vulnerabilities now have patches. Three score CVSS 9.9, and they let low-privileged members...
TL;DR A researcher known as Nightmare-Eclipse has published details and proof-of-concept code for LegacyHive, a Windows User...
TL;DR Two Linux kernel flaws now have public proof-of-concept exploit code and full technical write-ups. Bad Epoll...
TL;DR Bad Epoll is a Linux kernel use-after-free that turns any unprivileged user into root. It is...
TL;DR The WinFsp project has fixed two WinFsp vulnerabilities, CVE-2026-3006 (CVSS 7.0) and CVE-2026-7162 (CVSS 7.8). Both...
Hydro-Québec recently disclosed a severe privilege escalation flaw impacting its electric vehicle charging network. This critical vulnerability...
TL;DR On June 30, 2026, the FreeBSD Project shipped three advisories covering FreeBSD privilege escalation bugs in...
TL;DR The GNU Guix project disclosed four GNU Guix vulnerabilities in early July 2026. Three affect the...
TL;DR A researcher has published a full technical write-up and proof-of-concept exploit for a Linux kernel privilege...
TL;DR Microsoft patched a Microsoft Defender zero-day named RoguePlanet, tracked as CVE-2026-50656. The flaw is a race...
TL;DR Researchers have published full details and proof-of-concept code for GhostLock. This Linux kernel bug, tracked as...
TL;DR Researchers have published full technical details and proof-of-concept exploit code for a Linux kernel vulnerability tracked...
TL;DR Synacktiv publicly disclosed a Kerberos reflection bypass tracked as CVE-2026-26128. The flaw lets a domain user...
Security researcher Massimiliano Oldani has published IPV6_FRAG_ESCAPE, a working proof-of-concept for an IPv6 container escape on CentOS...
TL;DR Synacktiv publicly disclosed a new NTLM reflection bypass tracked as CVE-2026-24294. The flaw gives a local...