<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
  <channel>
    <atom:link href="https://www.zerodayinitiative.com/rss/published/" rel="self" type="application/xml" />
    <title><![CDATA[ZDI: Published Advisories]]></title>
    <link>http://www.zerodayinitiative.com/advisories/published/</link>
    <description><![CDATA[The following is a list of publicly disclosed vulnerabilities discovered by
                   Zero Day Initiative researchers. While the affected vendor is working on a patch for these
                   vulnerabilities, TrendAI customers are protected from exploitation by security filters
                   delivered ahead of public disclosure. All security vulnerabilities that are acquired by the
                   Zero Day Initiative are handled according to the ZDI Disclosure Policy.
        ]]></description>
    <pubDate>Sat, 05 Sep 2026 03:25:25 -0500</pubDate>
    <copyright>Trend Micro, all rights reserved</copyright>
    <language>en</language>
    
    <item>
      <title><![CDATA[ZDI-26-615: (0Day) pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29536</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-615/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architect. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8.]]></description>
      <pubDate>Mon, 31 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-614: (0Day) pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29219</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-614/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.]]></description>
      <pubDate>Mon, 31 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-613: (0Day) pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28916</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-613/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.]]></description>
      <pubDate>Mon, 31 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-612: (0Day) pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28673</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-612/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.]]></description>
      <pubDate>Mon, 31 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-611: (0Day) pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28570</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-611/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.]]></description>
      <pubDate>Mon, 31 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-610: Apple Safari JavaScriptCore B3 ReduceStrength Phase Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-32069</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-610/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple Safari. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-64715.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-609: Linux Kernel Net Scheduler Packet Classifier Use-After-Free Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31524</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-609/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-608: Linux Kernel KVM IOAPIC Use-After-Free Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31468</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-608/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-607: Microsoft Office HTML Injection Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29320</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-607/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Office. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.6.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-606: Microsoft Windows Compatibility Appraiser Link Following Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28205</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-606/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code in the context of LOCAL SERVICE on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-605: Microsoft Windows Localized Filenames Improper Input Validation NTLM Response Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29223</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-605/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose NTLM responses on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-50508.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-604: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30246</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-604/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-13126.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-603: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30248</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-603/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-13127.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-602: Foxit PDF Reader Doc Object Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30270</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-602/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-13128.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-601: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30310</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-601/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-13129.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-600: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30311</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-600/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-57237.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-599: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30312</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-599/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-57238.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-598: Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30661</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-598/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-57242.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-597: Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30696</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-597/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-57252.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-596: Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30755</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-596/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-57253.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-595: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31158</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-595/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-57254.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-594: NVIDIA Megatron Bridge load_model_config Code Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30353</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-594/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA Megatron Bridge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24251.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-593: NVIDIA TensorRT ONNX File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30321</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-593/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA TensorRT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24268.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-592: NVIDIA TensorRT ONNX File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30322</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-592/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA TensorRT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24238.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-591: NVIDIA TensorRT ONNX File Parsing  Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30323</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-591/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA TensorRT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24272.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-590: libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31036</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-590/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of libwebsockets. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-19773.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-589: BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29429</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-589/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2026-19774.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-588: Fabric.js loadFromJSON Server-Side Request Forgery Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29318</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-588/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Fabric.js. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 4.0. The following CVEs are assigned: CVE-2026-19504.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-587: Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28173</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-587/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19781.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-586: OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29340</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-586/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19886.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-585: OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29337</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-585/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19885.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-584: dnsmasq DNSSEC NSEC/NSEC3 Type Bitmap Processing Infinite Loop Denial-of-Service Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30607</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-584/</link>
      <description><![CDATA[This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of dnsmasq. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-4890.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-583: Clam AntiVirus 7z Archive Parsing Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29416</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-583/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Clam AntiVirus. Interaction with this product is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 8.4. The following CVEs are assigned: CVE-2026-20215.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-582: Cisco Identity Services Engine PatchUpdateListener Directory Traversal Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28708</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-582/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.9. The following CVEs are assigned: CVE-2026-20148.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-581: Cisco Identity Services Engine invokeScript Command Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28709</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-581/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20147.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-580: Cisco Identity Services Engine Missing Authentication for Critical Function Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29246</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-580/</link>
      <description><![CDATA[The vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-20190.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-579: Cisco Identity Services Engine zipFiles Directory Traversal Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29197</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-579/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20181.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-578: NGINX HTTP Dav Module Alias Directive Integer Underflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29287</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-578/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of NGINX. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-27654.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-577: Trend Micro VPN OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29830</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-577/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro VPN. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-67212.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-576: Linux Kernel XFRM Race Condition Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31423</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-576/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-575: Linux Kernel Net Scheduler Packet Classifier API Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31419</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-575/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-574: Linux Kernel Net Scheduler Connection Tracking Race Condition Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29413</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-574/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-46319.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-573: Linux Kernel KSMBD Response Header Out-Of-Bounds Read Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31063</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-573/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Linux Kernel KSMBD. Authentication is not required to exploit this vulnerability. However, only systems with ksmbd enabled are vulnerable. The ZDI has assigned a CVSS rating of 9.3. The following CVEs are assigned: CVE-2026-68431.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-572: Linux Kernel XFRM Race Condition Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30499</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-572/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-571: Linux Kernel Net Scheduler Packet Classifier API Use-After-Free Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31222</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-571/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-64530.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-570: Linux Kernel IGMP Subsystem Race Condition Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31149</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-570/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-569: Linux Kernel Net Scheduler True Link Equalizer Race Condition Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30840</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-569/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-568: Linux Kernel Net Scheduler Race Condition Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31523</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-568/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-567: Norton Utilities Ultimate NortonUtilitiesSvc Link Following Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-25569</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-567/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Norton Utilities Ultimate. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-13962.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-566: BlackBerry QNX  KEV File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30346</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-566/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of BlackBerry QNX. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-40272.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-565: Gen Digital CCleaner Link Following Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28680</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-565/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Gen Digital CCleaner. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-12410.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-564: NVIDIA Transformers4Rec load_model_trainer_states_from_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28536</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-564/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA Transformers4Rec. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24232.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-563: (Pwn2Own) Home Assistant Green Simple Service Discovery Protocol Server-Side Request Forgery Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28279</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-563/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to initiate arbitrary server-side requests on affected installations of Home Assistant Green. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.4.]]></description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-562: (Pwn2Own) Home Assistant Green mDNS Server-Side Request Forgery Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28336</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-562/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to initiate arbitrary server-side requests on affected installations of Home Assistant Green. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.4.]]></description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-561: (Pwn2Own) Home Assistant Green go2rtc Command Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28429</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-561/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Home Assistant Green. An attacker must first obtain the ability to access the device&#x27;s localhost interface. The ZDI has assigned a CVSS rating of 7.5.]]></description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-560: (Pwn2Own) Home Assistant Green go2rtc Command Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28340</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-560/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Home Assistant Green. An attacker must first obtain the ability to access the device&#x27;s localhost interface. The ZDI has assigned a CVSS rating of 7.5.]]></description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-559: (Pwn2Own) Amazon Smart Plug OTA Update Process Out-Of-Bounds Write Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28459</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-559/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Amazon Smart Plug. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.]]></description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-558: (Pwn2Own) Amazon Smart Plug OTA Update Process Improper Certificate Validation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28460</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-558/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to bypass certificate validation for OTA updates on affected installations of Amazon Smart Plug. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8.]]></description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-557: (Pwn2Own) Amazon Smart Plug Insecure Fallback Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28367</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-557/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Amazon Smart Plug. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.3.]]></description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-556: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28886</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-556/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18263.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-555: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28885</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-555/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18262.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-554: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29220</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-554/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-13121.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-553: OriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29338</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-553/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18294.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-552: OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29336</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-552/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18293.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-551: OriginLab OriginPro OGG File Parsing Memory Corruption Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29335</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-551/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro . User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18292.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-550: OriginLab OriginPro OGW File Parsing Memory Corruption Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29334</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-550/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18291.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-549: OriginLab OriginPro OGG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29333</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-549/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18290.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-548: OriginLab OriginPro OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29332</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-548/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18289.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-547: OriginLab OriginPro OPJU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29331</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-547/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18288.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-546: Flowise Airtable_Agent Code Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30458</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-546/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-69264.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-545: Flowise CSV_Agent customReadCSV Code Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30461</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-545/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-69256.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-544: Microsoft Windows Deployment Services Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31889</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-544/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Microsoft Windows Server. Authentication is not required to exploit this vulnerability. However, only systems with Windows Deployment Services enabled are vulnerable. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-62893.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-543: Microsoft Windows ICC File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30441</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-543/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. Interaction with the Mscms.dll color management library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-54984.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-542: Microsoft Windows UMPDDrvBitBlt Improper Object Management Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30747</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-542/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-541: (Pwn2Own) Microsoft Windows win32kfull Use-After-Free Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31479</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-541/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-65775.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-540: (Pwn2Own) Microsoft Windows win32kfull Use-After-Free Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31276</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-540/</link>
      <description><![CDATA[This vulnerability allows local attackers to disclose sensitive information on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-65776.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-539: (Pwn2Own) Microsoft Windows ipt.sys Incorrect Permission Assignment Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31260</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-539/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-65773.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-538: (Pwn2Own) Microsoft Exchange Improper Authorization Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31480</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-538/</link>
      <description><![CDATA[This vulnerability allows remote attackers to escalate privileges on affected installations of Microsoft Exchange. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-62911.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-537: (Pwn2Own) Microsoft Windows storport Integer Overflow Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31299</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-537/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-65814.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-536: (Pwn2Own) Microsoft Windows http.sys Integer Overflow Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31294</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-536/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-62735.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-535: (Pwn2Own) Microsoft Exchange External Control of File Path Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31481</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-535/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Exchange. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-62911.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-534: (Pwn2Own) Microsoft Exchange Capture-Replay Authentication Bypass Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31262</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-534/</link>
      <description><![CDATA[This vulnerability allows remote attackers to bypass authentication on affected installations of Microsoft Exchange. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-62911.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-533: Cisco Secure Firewall Management Center login.cgi Authentication Bypass Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30390</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-533/</link>
      <description><![CDATA[This vulnerability allows remote attackers to bypass authentication on affected installations of Cisco Secure Firewall Management Center. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-20316.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-532: SonicWall Email Security updateNetIf Command Injection Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29025</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-532/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of SonicWall Email Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-66149.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-531: SonicWall GMS Virtual Appliance interface Command Injection Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29024</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-531/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of SonicWall GMS Virtual Appliance. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-66148.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-530: SonicWall Email Security snmp Command Injection Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29029</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-530/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of SonicWall Email Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-66150.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-529: Samsung Galaxy S25 TIFF File Processing Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29432</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-529/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung Galaxy S25 devices. User interaction may be required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-21045.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-528: Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30062</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-528/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Wazuh. An attacker must first obtain the ability to execute low-privileged code on a worker node in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.9. The following CVEs are assigned: CVE-2026-28220.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-527: Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30086</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-527/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Wazuh. An attacker must first obtain the ability to execute low-privileged code on a worker node in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.9. The following CVEs are assigned: CVE-2026-44901.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-526: (0Day) PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30585</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-526/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-19910, CVE-2026-19911.]]></description>
      <pubDate>Fri, 14 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-525: (0Day) PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30583</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-525/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-19909.]]></description>
      <pubDate>Wed, 05 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-524: (0Day) PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30584</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-524/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to disclose sensitive information and modify configuration on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2026-19908.]]></description>
      <pubDate>Wed, 05 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-523: Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27987</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-523/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face PyTorch Image Models. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-15679.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-522: Phoenix Contact CHARX SEC-3000 Insertion of Sensitive Information into Log File Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27763</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-522/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Phoenix Contact CHARX SEC-3000 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-41032.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-521: Phoenix Contact CHARX SEC-3000 Command Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27762</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-521/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3000 devices. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-44095.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-520: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Jupicore External Control of Path Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29093</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-520/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-44103.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-519: (Pwn2Own) Phoenix Contact CHARX SEC-3150 CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29077</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-519/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-44099.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-518: (Pwn2Own) Phoenix Contact CHARX SEC-3150 MQTT Service Server-Side Request Forgery Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29073</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-518/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to access internal resources on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.3. The following CVEs are assigned: CVE-2026-44091.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-517: (Pwn2Own) Phoenix Contact CHARX SEC-3150 BackendURL WebSocket Command Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29054</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-517/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3150 devices. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-44098.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-516: (Pwn2Own) Phoenix Contact CHARX SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29055</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-516/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-44090.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-515: (Pwn2Own) Phoenix Contact CHARX SEC-3150 charx-jupicore Missing Authentication Configuration Modification Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28999</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-515/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to modify configuration on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.2. The following CVEs are assigned: CVE-2026-44100.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-514: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Failing Open Authentication Bypass Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29076</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-514/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-44094.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-513: (Pwn2Own) Phoenix Contact CHARX SEC-3150 update2-upload Arbitrary File Upload Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29110</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-513/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to upload arbitrary files on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 2.4. The following CVEs are assigned: CVE-2026-44097.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-512: (Pwn2Own) Phoenix Contact CHARX SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29052</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-512/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-44107.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-511: (Pwn2Own) Phoenix Contact CHARX SEC-3150 user-applications Symlink Following Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29075</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-511/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Phoenix Contact CHARX SEC-3150 devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-44093.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-510: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Missing Cryptographic Signature Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29094</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-510/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to bypass firmware validation on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-44104.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-509: (Pwn2Own) Phoenix Contact CHARX SEC-3150 OCPP Missing Authentication for Critical Function Authentication Bypass Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29091</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-509/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to modify configuration on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.0. The following CVEs are assigned: CVE-2026-44101.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-508: (Pwn2Own) Phoenix Contact CHARX SEC-3150 charx_set_ip_address Improper Input Validation Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29108</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-508/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Phoenix Contact CHARX SEC-3150 devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-44095.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-507: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Privilege Defined With Unsafe Actions Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29109</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-507/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Phoenix Contact CHARX SEC-3150 devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-44096.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-506: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Insertion of Sensitive Information into Log File Authentication Bypass Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29050</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-506/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2026-44105.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-505: (Pwn2Own) Phoenix Contact CHARX SEC-3150 charx-system-config-manager Service CRLF Injection Firewall Bypass Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29074</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-505/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to bypass firewall rules on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.0. The following CVEs are assigned: CVE-2026-44092.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-504: (Pwn2Own) Phoenix Contact CHARX SEC-3150 CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29059</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-504/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-7849.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-503: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Race Condition Firewall Bypass Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29058</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-503/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to bypass firewall rules on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2026-44108.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-502: (Pwn2Own) Phoenix Contact CHARX SEC-3150 user-applications Link Following Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29085</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-502/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Phoenix Contact CHARX SEC-3150 devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-44106.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-501: WatchGuard FireWare OS sigd comp_start_cb Directory Traversal Arbitrary File Creation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31457</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-501/</link>
      <description><![CDATA[This vulnerability allows remote attackers to create arbitrary files on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-13054.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-500: WatchGuard FireWare OS networkd network_wireless_kick_off_user_cb Stack-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31458</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-500/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-13050.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-499: WatchGuard FireWare OS cli Token Parser Stack-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31459</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-499/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.7. The following CVEs are assigned: CVE-2026-13053.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-498: TrendAI Vision One Incorrect Privilege Assignment Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28122</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-498/</link>
      <description><![CDATA[This vulnerability allows remote attackers to escalate privileges on affected installations of TrendAI Vision One. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2025-71387.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-497: TrendAI Vision One Service Gateway Logs Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28148</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-497/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of TrendAI Vision One. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.7. The following CVEs are assigned: CVE-2025-71386.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-496: Trend AI Cleaner One Pro Link Following Arbitrary File Deletion Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28718</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-496/</link>
      <description><![CDATA[This vulnerability allows local attackers to delete arbitrary files on affected installations of TrendLife Cleaner One Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.6. The following CVEs are assigned: CVE-2026-62660.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-495: (Pwn2Own) VMware ESXi VMXNET3 espQueueMask Out-Of-Bounds Write Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31293</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-495/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of VMware ESXi. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2026-47876.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-494: Apple macOS USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30380</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-494/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. Interaction with the USD library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-43729.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-493: Apple macOS USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29483</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-493/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. Interaction with the USD library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-43733.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-492: Apple macOS ImageIO Numeric Truncation Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29252</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-492/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. Interaction with the ImageIO library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-43780.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-491: Apple macOS CoreAudio Out-Of-Bounds Write Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29143</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-491/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-43673.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-490: (Pwn2Own) Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29070</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-490/</link>
      <description><![CDATA[This vulnerability allows physically present attackers to escalate privileges on affected installations of Kenwood DNR1007XR devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.6. The following CVEs are assigned: CVE-2026-18273.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-489: (Pwn2Own) Kenwood DNR1007XR startUpdateProcess Command Injection Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28981</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-489/</link>
      <description><![CDATA[This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-18272.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-488: (Pwn2Own) Kenwood DNR1007XR vCardParser Heap-based Buffer Overflow Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28974</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-488/</link>
      <description><![CDATA[This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-18271.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-487: (Pwn2Own) Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29111</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-487/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Kenwood DNR1007XR devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18270.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-486: (Pwn2Own) Kenwood DNR1007XR tchdr_bytestream_read Out-Of-Bounds Write Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28980</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-486/</link>
      <description><![CDATA[This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-18269.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-485: (Pwn2Own) Kenwood DNR1007XR JKGenService Command Injection Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29066</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-485/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Kenwood DNR1007XR devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-18268.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-484: (Pwn2Own) Kenwood DNR1007XR Firmware Update Link Following Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28751</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-484/</link>
      <description><![CDATA[This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-18267.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-483: NoMachine getstat Command Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30634</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-483/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of NoMachine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-18264.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-482: Progress Software Kemp LoadMaster enablexroot Use of Hard-Coded Cryptographic Key Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30687</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-482/</link>
      <description><![CDATA[This vulnerability allows remote attackers to escalate privileges on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-59689.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-481: Progress Software Kemp LoadMaster access Missing Authorization Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30735</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-481/</link>
      <description><![CDATA[This vulnerability allows remote attackers to escalate privileges on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-59690.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-480: OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30036</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-480/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of OSNEXUS QuantaStor. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-18265.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-479: Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28603</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-479/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-18274.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-478: Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28201</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-478/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adminer. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-15686.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-477: (Pwn2Own) Sony XAV-9500ES Crash Dump Handler Command Injection Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29061</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-477/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18284.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-476: (Pwn2Own) Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28992</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-476/</link>
      <description><![CDATA[This vulnerability allows physically present attackers to bypass authorization on affected installations on Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 2.4. The following CVEs are assigned: CVE-2026-18283.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-475: (Pwn2Own) Sony XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28995</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-475/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.0. The following CVEs are assigned: CVE-2026-18282.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-474: (Pwn2Own) Sony XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29072</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-474/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.0. The following CVEs are assigned: CVE-2026-18281.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-473: (Pwn2Own) Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29060</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-473/</link>
      <description><![CDATA[This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 3.9. The following CVEs are assigned: CVE-2026-18280.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-472: (Pwn2Own) Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29042</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-472/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-18279.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-471: (Pwn2Own) Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28990</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-471/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 3.5. The following CVEs are assigned: CVE-2026-18278.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-470: Aeon load_time_series_segmentation_benchmark Code Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29159</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-470/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of aeon. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18287.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-469: Aeon load_human_activity_segmentation_datasets Code Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29160</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-469/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of aeon. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18286.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-468: Aeon load_rehab_pile_dataset Deserialization of Untrusted Data Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28749</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-468/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Aeon. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18285.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-467: GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29787</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-467/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18299.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-466: GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29581</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-466/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18298.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-465: GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29584</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-465/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18297.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-464: GStreamer MRF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29608</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-464/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18296.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-463: GStreamer MRF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29510</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-463/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18295.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-462: GIMP APNG File Parsing Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29401</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-462/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18309.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-461: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29405</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-461/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18308.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-460: GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29404</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-460/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18307.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-459: GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29396</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-459/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18306.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-458: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29406</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-458/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18305.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-457: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29403</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-457/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18304.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-456: GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29399</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-456/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18303.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-455: GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29398</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-455/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18302.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-454: GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29395</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-454/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18301.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-453: GIMP HDR File Parsing Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29289</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-453/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18300.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-452: Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29196</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-452/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Dify. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 5.4. The following CVEs are assigned: CVE-2026-18266.]]></description>
      <pubDate>Thu, 23 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-451: Docker Desktop for macOS Inference Server Permissive Allow List Sandbox Escape Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29308</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-451/</link>
      <description><![CDATA[This vulnerability allows local attackers to escape the model runner sandbox on affected installations of Docker Desktop for macOS. An attacker must first obtain the ability to execute low-privileged code within the sandbox in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8.]]></description>
      <pubDate>Thu, 23 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-450: AzeoTech DAQFactory CTL File Parsing Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28831</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-450/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-12921.]]></description>
      <pubDate>Thu, 23 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-449: AzeoTech DAQFactory CTL File Parsing Type Confusion Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28876</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-449/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-12390.]]></description>
      <pubDate>Thu, 23 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-448: Bitdefender Total Security Shredder Link Following Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28703</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-448/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Bitdefender Total Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.3. The following CVEs are assigned: CVE-2026-6851.]]></description>
      <pubDate>Thu, 23 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-447: Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29251</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-447/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-12357.]]></description>
      <pubDate>Thu, 23 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-446: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-32968</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-446/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-50297.]]></description>
      <pubDate>Tue, 21 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-445: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-32967</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-445/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-50325.]]></description>
      <pubDate>Tue, 21 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-444: 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30169</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-444/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-14266.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-443: Linux Kernel vmwgfx Integer Overflow Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31467</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-443/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-442: Linux Kernel CAN ISO-TP Protocol Race Condition Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31764</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-442/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-441: dnsmasq DNS Response Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29496</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-441/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of dnsmasq. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-2291.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-440: Fuji Electric Tellus pcid64 Driver Untrusted Pointer Dereference Denial of Service Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27744</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-440/</link>
      <description><![CDATA[This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Fuji Electric Tellus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.5. The following CVEs are assigned: CVE-2026-8108.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-439: Fuji Electric Tellus pcid64 Driver Exposed Dangerous Method Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27670</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-439/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Fuji Electric Tellus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-8108.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-438: Rockwell Automation Arena Simulation DOE File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27055</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-438/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Rockwell Automation Arena Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-6071.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-437: (Pwn2Own) Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29113</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-437/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-13308.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-436: (Pwn2Own) Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29048</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-436/</link>
      <description><![CDATA[This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-13307.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-435: (Pwn2Own) Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29044</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-435/</link>
      <description><![CDATA[This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-13309.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-434: (Pwn2Own) Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29046</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-434/</link>
      <description><![CDATA[This vulnerability allows physically present attackers to bypass authentication on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.3. The following CVEs are assigned: CVE-2026-13306.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-433: (Pwn2Own) Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29062</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-433/</link>
      <description><![CDATA[This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2026-13305.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-432: G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28665</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-432/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of G DATA Total Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-13268.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-431: ASUS Business Manager Service Client-Side Authentication Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28776</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-431/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of ASUS Business Manager. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-8921.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-430: MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28935</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-430/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of MSI Center. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-6102.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-429: NVIDIA NeMo Framework Deserialization of Untrusted Data Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28090</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-429/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA NeMo Framework. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24157.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-428: WatchGuard FireWare OS admd Stack-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30173</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-428/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-8247.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-427: WatchGuard FireWare OS iked ike2_hmac Null Pointer Dereference Denial-of-Service Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30097</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-427/</link>
      <description><![CDATA[This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of WatchGuard FireWare OS. Authentication is not required to exploit this vulnerability, but only systems using VPN with IKEv2 are vulnerable. The ZDI has assigned a CVSS rating of 5.9. The following CVEs are assigned: CVE-2026-13084.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-426: OpenSSL X.509 Email Validation Out-Of-Bounds Read Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30378</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-426/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of OpenSSL. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-42771.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-425: OpenSSL OCSP Stapling Verification Double Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30391</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-425/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenSSL. User interaction is required to exploit this vulnerability in that the target must make a request to a malicious server. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-35188.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-424: Synology DiskStation DS925+ MailPlus Improper Restriction of Communication Channel to Intended Endpoints Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28485</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-424/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to access the Redis instance on affected installations of Synology DiskStation DS925+ devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.3. The following CVEs are assigned: CVE-2026-13135.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-423: Synology DiskStation DS925+ MailPlus Redis Weak Cryptography for Passwords Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28554</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-423/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology DiskStation DS925+ devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-15660.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-422: Samsung rlottie Numeric Truncation Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30236</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-422/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung rlottie. Interaction with the rlottie library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-15551.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-421: Cisco Identity Services Engine validFileNameOrPath Directory Traversal Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28724</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-421/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.5. The following CVEs are assigned: CVE-2026-20146.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-420: Adobe Creative Cloud AGSService Incorrect Permission Assignment Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29867</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-420/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Adobe Creative Cloud Desktop Application. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-48344.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-419: Adobe Creative Cloud AdobeUpdateService Uncontrolled Search Path Element Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29588</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-419/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Adobe Creative Cloud. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-48272.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-418: Microsoft SharePoint SPFieldMultiLineText Cross-Site Scripting Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30803</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-418/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute web requests with a target user&#x27;s privileges on affected installations of Microsoft SharePoint. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.3. The following CVEs are assigned: CVE-2026-55126.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-417: Microsoft Windows ServerManager Exposed Dangerous Method Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30003</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-417/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-50311.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-416: Microsoft Hyper-V netvsc Out-Of-Bounds Read Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28769</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-416/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Hyper-V. An attacker must first obtain the ability to execute low-privileged code within a Windows virtual machine under Hyper-V in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-54129.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
  </channel>
</rss>
