Vulnerabilities Cisco Secure FMC Zero-Day Exploited in the Wild The vulnerability tracked as CVE-2026-20316 can be exploited by a remote, unauthenticated attacker to log into affected devices. Eduard KovacsJuly 30, 2026
Artificial Intelligence JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given. Ionut ArghireJuly 29, 2026
Vulnerabilities Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality. Ionut ArghireJuly 28, 2026
Vulnerabilities New Check Point Zero-Day Vulnerability Exploited in the Wild The vulnerability tracked as CVE-2026-16232 has been exploited against customers with certain configurations. Eduard KovacsJuly 23, 2026
Malware & Threats SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533. Eduard KovacsJuly 20, 2026
Vulnerabilities Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day The researcher stripped the proof-of-concept (PoC) exploit to prevent immediate exploitation of the vulnerability. Ionut ArghireJuly 16, 2026
Vulnerabilities Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption The company has rolled out a fix and is restoring access for Storage Zones Controller customers who apply it. Ionut ArghireJuly 15, 2026
Vulnerabilities SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits SonicWall SMA1000 zero-day vulnerabilities CVE-2026-15409 and CVE-2026-15410 can be exploited for remote code execution. Eduard KovacsJuly 15, 2026
Vulnerabilities Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days Two flaws in Active Directory and SharePoint Server have been exploited as zero-days, and a BitLocker bug was publicly disclosed. Ionut ArghireJuly 14, 2026
Vulnerabilities Cisco SD-WAN Zero-Day Exploited Months Before Patching CVE-2026-20245, the 7th Cisco SD-WAN vulnerability exploited in 2026, was used for months prior to its disclosure and patching. Eduard KovacsJune 25, 2026
Vulnerabilities Microsoft Working on Patch for ‘RoguePlanet’ Zero-Day The public PoC code exploits a race condition in Microsoft Defender to spawn a command prompt with System privileges. Ionut ArghireJune 17, 2026
Network Security Cisco Patches Another SD-WAN Zero-Day Exploited in Attacks Cisco recently became aware of the exploitation of CVE-2026-20262, a Catalyst SD-WAN Manager zero-day that allows arbitrary file write. Eduard KovacsJune 16, 2026
Cybercrime Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters Oracle has mitigated CVE-2026-35273, but it has not publicly confirmed the vulnerability’s in-the-wild exploitation. Eduard KovacsJune 12, 2026
Vulnerabilities Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks Oracle has released mitigations for CVE-2026-35273, but it has not said whether it’s a zero-day exploited in ShinyHunters attacks. Eduard KovacsJune 11, 2026
Endpoint Security ‘GreatXML’ Zero-Day Exploit Bypasses BitLocker The PoC exploits Microsoft Defender’s offline scan to spawn a SYSTEM shell when rebooting in Recovery Mode. Ionut ArghireJune 11, 2026
Vulnerabilities No Patch Planned for Exploited Arista EOS Vulnerability Organizations are advised to apply vendor-supplied mitigations or discontinue the vulnerable devices. Ionut ArghireJune 10, 2026
Ransomware Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks The authentication bypass vulnerability allows attackers to establish VPN connections without a valid password. Ionut ArghireJune 9, 2026
Vulnerabilities Google Patches 5th Chrome Zero-Day Exploited in 2026 The vulnerability is tracked as CVE-2026-11645 and it was reported in late April by an anonymous researcher. Eduard KovacsJune 9, 2026
Vulnerabilities Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026 The vulnerability is tracked as CVE-2026-20245 and it can allow arbitrary command execution as root, but no patch yet. Eduard KovacsJune 5, 2026
Vulnerabilities VS Code Vulnerability Allows One-Click GitHub Token Theft A researcher has disclosed the full details of the vulnerability and released a PoC without notifying Microsoft in advance. Eduard KovacsJune 4, 2026