TL;DR A maximum-severity SQL injection flaw sits in the Android Contacts Provider. Tracked as CVE-2026-28576 with a...
proof-of-concept
TL;DR A researcher published ShieldCrash, a Windows Defender 0day that bypasses Microsoft’s patch for the ShieldBreak vulnerability...
Security team NebuSec published technical details and functional exploit code for a critical Linux flaw. This Linux...
TL;DR A researcher using the handle MSNightmare says they found a CrowdStrike Falcon vulnerability. They published a...
TL;DR Proxmox published advisory PSA-2026-00043-1 on September 1, 2026. It warns of a critical Proxmox VE authentication...
TL;DR A critical Redis vulnerability, tracked as CVE-2026-81934, allows remote code execution on TLS-enabled servers. It carries...
TL;DR A double-free flaw in the Linux kernel, tracked as CVE-2026-72137, carries a CVSS score of 9.8....
TL;DR Researchers published full details and proof-of-concept exploit code for CVE-2026-53361, a use-after-free in the Linux kernel...
TL;DR Researchers published proof-of-concept exploit code for a Redis RCE vulnerability. The heap use-after-free lets a remote...
TL;DR A researcher released VsockDrop, a proof-of-concept exploit for CVE-2026-53365 in the Linux kernel. The flaw enables...
A newly disclosed flaw in the Linux kernel enables local Linux kernel privilege escalation. Tracked as CVE-2026-74480...
TL;DR CVE-2026-52912 is a use-after-free flaw in the Linux kernel’s netfilter nf_queue code. It carries a CVSS...
GitLab has patched a critical flaw that lets unauthenticated attackers delete public projects and user data. The...
TL;DR A researcher published proof-of-concept exploit code for CVE-2026-52929, a Linux kernel SCTP flaw rated CVSS 7.5....
TL;DR Microsoft patched CVE-2026-47301, an elevation of privilege flaw in Configuration Manager (SCCM). A researcher published proof-of-concept...
TL;DR Google patched CVE-2026-0075, an Android elevation of privilege flaw in ContactsProvider2. The bug can expose the...
TL;DR A researcher released proof-of-concept exploit code for CVE-2026-68138, a race condition in the Linux kernel traffic-control...
TL;DR A GeoServer unauthenticated SQL injection flaw is under active attack. It lives in the jsonArrayContains filter...
TL;DR Microsoft patched CVE-2026-66804, an elevation of privilege flaw in the Windows Cross Device Service. A standard...
TL;DR CISA added CVE-2025-62593 to its Known Exploited Vulnerabilities catalog. The flaw is a code injection bug...
TL;DR A researcher published a proof-of-concept exploit for a Linux kernel AF_PACKET race condition. The flaw enables...
Researchers at watchTowr published a working exploit for a Citrix NetScaler RCE flaw this week. The bug,...