<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
  <channel>
    <atom:link href="https://www.zerodayinitiative.com/rss/published/" rel="self" type="application/xml" />
    <title><![CDATA[ZDI: Published Advisories]]></title>
    <link>http://www.zerodayinitiative.com/advisories/published/</link>
    <description><![CDATA[The following is a list of publicly disclosed vulnerabilities discovered by
                   Zero Day Initiative researchers. While the affected vendor is working on a patch for these
                   vulnerabilities, TrendAI customers are protected from exploitation by security filters
                   delivered ahead of public disclosure. All security vulnerabilities that are acquired by the
                   Zero Day Initiative are handled according to the ZDI Disclosure Policy.
        ]]></description>
    <pubDate>Sat, 26 Sep 2026 02:13:32 -0500</pubDate>
    <copyright>Trend Micro, all rights reserved</copyright>
    <language>en</language>
    
    <item>
      <title><![CDATA[ZDI-26-748: Luxion KeyShot BIP File Parsing Uncontrolled Search Path Element Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29268</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-748/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-92202.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-747: Wireshark RF4CE Packet Parsing Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31780</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-747/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Wireshark. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-96417.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-746: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-33990</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-746/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91818.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-745: Foxit PDF Reader AcroForm Out-of-Bounds Read Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-33989</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-745/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91817.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-744: Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-33987</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-744/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91816.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-743: Foxit PDF Reader JPEG2000 Parsing Memory Corruption Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-33570</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-743/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91815.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-742: Foxit PDF Reader FoxitUpdater Race Condition Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-32454</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-742/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91813.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-741: Foxit PDF Reader FoxitUpdater Improper Certificate Validation Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-32452</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-741/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2026-91812.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-740: Foxit PDF Reader PRC Stream Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-32817</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-740/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91811.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-739: Foxit PDF Reader Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-32757</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-739/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91810.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-738: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-32755</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-738/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91809.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-737: Foxit PDF Reader JPEG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-32754</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-737/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91808.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-736: Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-32666</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-736/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91807.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-735: Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-32665</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-735/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91806.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-734: Foxit PDF Reader RichMedia Annotation Directory Traversal Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31605</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-734/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91801.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-733: Foxit PDF Reader Portfolio Directory Traversal Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31364</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-733/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91797.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-732: Foxit PDF Reader importIcon NTLM Response Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31048</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-732/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose NTLM responses on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91796.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-731: Foxit PDF Reader FileOpen Uninitialized Variable Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30795</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-731/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91795.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-730: Foxit PDF Reader DeviceN Colorspace Out-Of-Bounds Write Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31319</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-730/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91794.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-729: Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31175</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-729/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91793.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-728: Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31172</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-728/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-57238.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-727: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31171</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-727/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-13128.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-726: Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31169</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-726/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-13129.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-725: Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31168</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-725/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-57256.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-724: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31166</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-724/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91792.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-723: Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31160</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-723/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91790.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-722: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31163</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-722/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91791.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-721: Foxit PDF Reader U3D File Parsing Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31135</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-721/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91789.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-720: Foxit PDF Reader activeDocs Missing Authorization Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30962</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-720/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 4.7. The following CVEs are assigned: CVE-2026-91788.]]></description>
      <pubDate>Wed, 23 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-719: Cisco ThousandEyes Virtual Appliance DHCP Client Command Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31647</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-719/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco ThousandEyes Virtual Appliance. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20350.]]></description>
      <pubDate>Tue, 22 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-718: Cisco Identity Services Engine MnTRESTLivelogService XML External Entity Processing Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31322</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-718/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.9. The following CVEs are assigned: CVE-2026-20235.]]></description>
      <pubDate>Fri, 18 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-717: Cisco Identity Services Engine AlarmMessageDiskQueue Deserialization of Untrusted Data Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31320</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-717/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20211.]]></description>
      <pubDate>Fri, 18 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-716: Cisco Identity Services Engine createDBLink Command Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30945</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-716/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20176.]]></description>
      <pubDate>Fri, 18 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-715: Linux Mint Xreader PDF File Parsing Type Confusion Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30793</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-715/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19772.]]></description>
      <pubDate>Fri, 18 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-714: Samsung rlottie Stack-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31927</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-714/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung rlottie. Interaction with the rlottie library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91826.]]></description>
      <pubDate>Thu, 17 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-713: GIMP APNG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29400</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-713/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-92183.]]></description>
      <pubDate>Wed, 16 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-712: NoMachine nxhtd Server-Side Request Forgery Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31619</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-712/</link>
      <description><![CDATA[This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of NoMachine. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-92210.]]></description>
      <pubDate>Wed, 16 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-711: NoMachine Redis Improper Authentication Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30984</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-711/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-92209.]]></description>
      <pubDate>Wed, 16 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-710: NoMachine mDNS Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30982</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-710/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NoMachine. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-92208.]]></description>
      <pubDate>Wed, 16 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-709: Cisco Secure Firewall Management Center CommandSinkRmi Deserialization of Untrusted Data Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30946</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-709/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Secure Firewall Management Center. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-20242.]]></description>
      <pubDate>Wed, 16 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-708: (0Day) Microsoft Windows HTTP Proxy Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29849</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-708/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3.]]></description>
      <pubDate>Wed, 16 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-707: (0Day) MindsDB OpenBBtable Code Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28388</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-707/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of MindsDB. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-92207.]]></description>
      <pubDate>Wed, 16 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-706: (0Day) CrewAI crewAI Framework Agent Loading Unsafe Reflection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28387</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-706/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of CrewAI crewAI. User interaction is required to exploit this vulnerability in that the target must load a malicious agent configuration from the repository. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-92206.]]></description>
      <pubDate>Wed, 16 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-705: (0Day) BusyBox libarchive Symlink Directory Traversal Arbitrary File Creation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27556</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-705/</link>
      <description><![CDATA[This vulnerability allows remote attackers to create arbitrary files on affected installations of BusyBox. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-92205.]]></description>
      <pubDate>Wed, 16 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-704: (0Day) Airbyte OneDrive Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28216</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-704/</link>
      <description><![CDATA[This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Airbyte. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.7. The following CVEs are assigned: CVE-2026-92204.]]></description>
      <pubDate>Wed, 16 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-703: (0Day) Airbyte SharePoint Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28215</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-703/</link>
      <description><![CDATA[This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Airbyte. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.7. The following CVEs are assigned: CVE-2026-92203.]]></description>
      <pubDate>Wed, 16 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-702: Linux Kernel usbnet Driver Race Condition Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-22166</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-702/</link>
      <description><![CDATA[This vulnerability allows physically present attackers to escalate privileges on affected installations of Linux Kernel. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2025-22050.]]></description>
      <pubDate>Mon, 14 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-701: Linux Kernel TLS Protocol Out-Of-Bounds Read Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30511</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-701/</link>
      <description><![CDATA[This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.7. The following CVEs are assigned: CVE-2026-64046.]]></description>
      <pubDate>Mon, 14 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-700: Linux Kernel QFQ Plus Scheduler Use-After-Free Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-26601</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-700/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-22999.]]></description>
      <pubDate>Mon, 14 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-699: Linux Kernel NTFS3 Out-of-Bounds Read Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31582</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-699/</link>
      <description><![CDATA[This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.2.]]></description>
      <pubDate>Mon, 14 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-698: Linux Kernel NTFS3 Out-Of-Bounds Read Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31573</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-698/</link>
      <description><![CDATA[This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.2.]]></description>
      <pubDate>Mon, 14 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-697: Linux Kernel NTFS3 Out-Of-Bounds Read Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30482</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-697/</link>
      <description><![CDATA[This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.3.]]></description>
      <pubDate>Mon, 14 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-696: Linux Kernel NTFS3 Journal Heap-based Buffer Overflow Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30226</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-696/</link>
      <description><![CDATA[This vulnerability allows local attackers to execute arbitrary code on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-72196.]]></description>
      <pubDate>Mon, 14 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-695: Linux Kernel NFSv4 Server Race Condition Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30500</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-695/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Kernel. Authentication is required to exploit this vulnerability. Furthermore, only systems with nfsd enabled are vulnerable. The ZDI has assigned a CVSS rating of 8.5. The following CVEs are assigned: CVE-2026-89688.]]></description>
      <pubDate>Mon, 14 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-694: Linux Kernel Net Scheduler Clsact Qdisc Use-After-Free Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28821</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-694/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2026-23413.]]></description>
      <pubDate>Mon, 14 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-693: Linux Kernel ksmbd Share Configuration Race Condition Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29790</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-693/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Kernel. Authentication is required to exploit this vulnerability. Furthermore, only systems with ksmbd enabled are vulnerable. The ZDI has assigned a CVSS rating of 8.5.]]></description>
      <pubDate>Mon, 14 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-692: Linux Kernel eMPIA USB Device Driver Race Condition Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30389</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-692/</link>
      <description><![CDATA[This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Linux Kernel. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2026-31583.]]></description>
      <pubDate>Mon, 14 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-691: Linux Kernel Netlink-based Wireless Configuration Integer Overflow Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31133</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-691/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2026-53182.]]></description>
      <pubDate>Mon, 14 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-690: Linux Kernel MCTP Routing Uninitialized Memory Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28534</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-690/</link>
      <description><![CDATA[This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.0. The following CVEs are assigned: CVE-2026-45930.]]></description>
      <pubDate>Mon, 14 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-689: Linux Kernel SCTP Subsystem Race Condition Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30223</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-689/</link>
      <description><![CDATA[This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2026-46227.]]></description>
      <pubDate>Mon, 14 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-688: Linux Kernel OpenvSwitch Race Condition Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31642</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-688/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-74465.]]></description>
      <pubDate>Mon, 14 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-687: Linux Kernel Open vSwitch Flow Delete Use-After-Free Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-32042</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-687/</link>
      <description><![CDATA[This vulnerability allows local attackers to disclose sensitive information on affected installations of the Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2026-80994.]]></description>
      <pubDate>Mon, 14 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-686: Linux Kernel nftables Race Condition Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30931</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-686/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-74565.]]></description>
      <pubDate>Mon, 14 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-685: Linux Kernel NFC NCI UART Driver Race Condition Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27262</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-685/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-38416.]]></description>
      <pubDate>Mon, 14 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-684: Linux Kernel KSMBD Query Directory Request Race Condition Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30527</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-684/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Kernel KSMBD. Authentication is not required to exploit this vulnerability. Furthermore, only systems with KSMBD enabled are vulnerable. The ZDI has assigned a CVSS rating of 9.0. The following CVEs are assigned: CVE-2026-64397.]]></description>
      <pubDate>Mon, 14 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-683: Linux Kernel IPv6 VTI Subsystem Use-After-Free Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30930</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-683/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-72463.]]></description>
      <pubDate>Mon, 14 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-682: Linux Kernel IPv6 Neighbour Discovery Uninitialized Memory Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28594</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-682/</link>
      <description><![CDATA[This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.0. The following CVEs are assigned: CVE-2026-43040.]]></description>
      <pubDate>Mon, 14 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-681: Linux Kernel FUSE Subsystem Race Condition Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31610</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-681/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-64265.]]></description>
      <pubDate>Mon, 14 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-680: Linux Kernel Crypto Subsystem Use-After-Free Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29316</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-680/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-31719.]]></description>
      <pubDate>Mon, 14 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-679: Adobe Photoshop DCM JPEG Image Parsing Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31973</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-679/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-75862.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-678: Adobe Photoshop DCM File Parsing Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31752</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-678/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-75863.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-677: Adobe Photoshop DCM JPEG-LS Image Parsing Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-32027</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-677/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-75771.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-676: Adobe Acrobat Reader DC DigSig Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31613</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-676/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81973.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-675: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31386</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-675/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81976.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-674: Adobe Acrobat Reader DC Annotation Out-Of-Bounds Write Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31079</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-674/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81981.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-673: Adobe Acrobat Pro DC Doc Object Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31180</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-673/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81988.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-672: Adobe Acrobat Reader DC PDF File Parsing Integer Underflow Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30998</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-672/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-81977.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-671: Adobe Acrobat Reader DC Dialog Object Type Confusion Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31643</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-671/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-80161.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-670: Adobe Acrobat Pro DC Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30877</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-670/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-81991.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-669: Adobe Acrobat Reader DC JBIG2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31150</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-669/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-81978.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-668: Adobe Acrobat Reader DC Annotation Use-After-Free Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31082</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-668/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-81984.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-667: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31374</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-667/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81975.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-666: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31535</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-666/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-79910.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-665: Adobe Acrobat Reader DC Annots Report Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31909</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-665/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-79909.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-664: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31012</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-664/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81986.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-663: Adobe Acrobat Pro DC Annotation Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30785</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-663/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81989.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-662: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30878</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-662/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81990.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-661: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31010</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-661/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81985.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-660: Adobe Acrobat Reader DC Font Parsing Use-After-Free Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-32181</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-660/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-80162.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-659: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-32516</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-659/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-80160.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-658: Adobe Acrobat Pro DC JPEG Parsing Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31740</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-658/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81987.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-657: ASUS Control Center Express Agent Missing Authentication Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29986</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-657/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of ASUS Control Center Express Agent. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-19397.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-656: PAPPL Job Processing Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-32307</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-656/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of PAPPL. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-655: PAPPL Printer IPP Processing Stack-based Buffer Overflow Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-32306</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-655/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of PAPPL. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-654: TrendAI Apex One Incomplete Cleanup Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27868</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-654/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of TrendAI Apex One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-71414.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-653: TrendAI Apex One Security Agent Cache Mechanism Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27896</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-653/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of TrendAI Apex One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-71415.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-652: TrendAI Apex One Security Agent Cache Mechanism Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27921</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-652/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of TrendAI Apex One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-71416.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-651: (Pwn2Own) OpenAI Codex External Control of System or Configuration Setting Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31264</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-651/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenAI Codex. User interaction is required to exploit this vulnerability in that the target must open a malicious folder. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19593.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-650: (Pwn2Own) OpenAI Codex External Control of Configuration Setting Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31277</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-650/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenAI Codex. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19592.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-649: (Pwn2Own) OpenAI Codex Improper Neutralization of Control Sequences Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31270</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-649/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenAI Codex. User interaction is required to exploit this vulnerability in that the target must open a malicious folder. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19591.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-648: (Pwn2Own) OpenAI Codex External Control of System or Configuration Setting Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31274</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-648/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenAI Codex. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19590.]]></description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-647: VMware Workstation VMXNET3 TSO Segmentation Integer Overflow Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31013</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-647/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of VMware Workstation. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-59346.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-646: Progress Software Kemp LoadMaster escape_quotes Uninitialized Memory Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31117</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-646/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-8037.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-645: Fortinet FortiSandbox write_remote_backup_to_crontab cronValue Command Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30081</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-645/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fortinet FortiSandbox. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-84387.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-644: Oracle VirtualBox VMSVGA Race Condition Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30083</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-644/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-60155.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-643: Oracle VirtualBox VMSVGA Out-Of-Bounds Read Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29835</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-643/</link>
      <description><![CDATA[This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-60162.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-642: Oracle VirtualBox IDisplay Out-Of-Bounds Read Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31121</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-642/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-60159.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-641: Oracle VirtualBox VirtioSCSI Out-Of-Bounds Read Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31532</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-641/</link>
      <description><![CDATA[This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-71114.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-640: Oracle VirtualBox VirtioSCSI Uninitialized Memory Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31625</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-640/</link>
      <description><![CDATA[This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2026-71132.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-639: Oracle VirtualBox VMSVGA Heap-based Buffer Overflow Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30184</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-639/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-71116.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-638: Oracle Outside In Technology WPS File Parsing Memory Corruption Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29542</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-638/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-60414.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-637: Oracle Outside In Technology GEM File Parsing Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29541</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-637/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-60413.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-636: Oracle Outside In Technology PostScript File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29543</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-636/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-60412.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-635: Oracle Outside In Technology PDF File Parsing Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29370</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-635/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must open a malicious file or visit a malicious page. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-60392.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-634: Flowise CSV Agent Prompt Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30459</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-634/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-70477.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-633: GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29397</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-633/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-4153.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-632: WatchGuard FireWare OS epm connect Stack-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30460</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-632/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-13086.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-631: NI LabVIEW VI File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29954</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-631/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of NI LabVIEW. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-18444.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-630: NI LabVIEW VI File Parsing Integer Overflow Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29955</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-630/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of NI LabVIEW. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-18445.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-629: Microsoft Azure Entra ID OAuth Device Code Grant Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30176</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-629/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Azure. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.8.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-628: Backblaze Personal Computer Backup bzreports Link Following Denial-of-Service Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29328</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-628/</link>
      <description><![CDATA[This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-627: Backblaze Personal Computer Backup bztransmit Link Following Denial-of-Service Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29330</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-627/</link>
      <description><![CDATA[This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-626: Backblaze Personal Computer Backup bzfilelist Link Following Denial-of-Service Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29326</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-626/</link>
      <description><![CDATA[This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-625: Backblaze Personal Computer Backup bzserv Link Following Denial-of-Service Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29324</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-625/</link>
      <description><![CDATA[This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-624: Backblaze Personal Computer Backup bzbackup Link Following Denial-of-Service Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29327</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-624/</link>
      <description><![CDATA[This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-623: Linux Kernel IPv6 Multicast Routing Use-After-Free Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31770</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-623/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-622: Microsoft Windows IKEv2 AES-GCM Decryption Integer Underflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31212</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-622/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. Authentication is not required to exploit this vulnerability, but only systems with specific IPsec configurations are vulnerable. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-50696.]]></description>
      <pubDate>Tue, 08 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-621: Microsoft Windows UMPDDrvRealizeBrush Improper Object Management Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30744</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-621/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.]]></description>
      <pubDate>Tue, 08 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-620: Microsoft Windows UMPDDrvPlgBlt Improper Object Management Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30743</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-620/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.]]></description>
      <pubDate>Tue, 08 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-619: Microsoft Windows UMPDDrvStretchBltROP Improper Object Management Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30745</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-619/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.]]></description>
      <pubDate>Tue, 08 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-618: Microsoft Windows UMPDDrvStretchBlt Improper Object Management Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30746</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-618/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.]]></description>
      <pubDate>Tue, 08 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-617: Microsoft Windows MIDI Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30483</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-617/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-66804.]]></description>
      <pubDate>Tue, 08 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-616: Koha Eval Code Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29165</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-616/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Koha. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-19780.]]></description>
      <pubDate>Tue, 08 Sep 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-615: (0Day) pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29536</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-615/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architect. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8.]]></description>
      <pubDate>Mon, 31 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-614: (0Day) pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29219</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-614/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.]]></description>
      <pubDate>Mon, 31 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-613: (0Day) pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28916</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-613/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.]]></description>
      <pubDate>Mon, 31 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-612: (0Day) pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28673</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-612/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.]]></description>
      <pubDate>Mon, 31 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-611: (0Day) pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28570</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-611/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.]]></description>
      <pubDate>Mon, 31 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-610: Apple Safari JavaScriptCore B3 ReduceStrength Phase Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-32069</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-610/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple Safari. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-64715.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-609: Linux Kernel Net Scheduler Packet Classifier Use-After-Free Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31524</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-609/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-608: Linux Kernel KVM IOAPIC Use-After-Free Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31468</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-608/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-607: Microsoft Office HTML Injection Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29320</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-607/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Office. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.6.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-606: Microsoft Windows Compatibility Appraiser Link Following Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28205</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-606/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code in the context of LOCAL SERVICE on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-605: Microsoft Windows Localized Filenames Improper Input Validation NTLM Response Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29223</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-605/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose NTLM responses on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-50508.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-604: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30246</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-604/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-13126.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-603: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30248</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-603/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-13127.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-602: Foxit PDF Reader Doc Object Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30270</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-602/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-13128.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-601: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30310</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-601/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-13129.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-600: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30311</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-600/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-57237.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-599: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30312</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-599/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-57238.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-598: Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30661</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-598/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-57242.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-597: Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30696</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-597/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-57252.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-596: Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30755</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-596/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-57253.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-595: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31158</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-595/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-57254.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-594: NVIDIA Megatron Bridge load_model_config Code Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30353</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-594/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA Megatron Bridge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24251.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-593: NVIDIA TensorRT ONNX File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30321</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-593/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA TensorRT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24268.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-592: NVIDIA TensorRT ONNX File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30322</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-592/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA TensorRT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24238.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-591: NVIDIA TensorRT ONNX File Parsing  Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30323</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-591/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA TensorRT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24272.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-590: libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31036</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-590/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of libwebsockets. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-19773.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-589: BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29429</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-589/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2026-19774.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-588: Fabric.js loadFromJSON Server-Side Request Forgery Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29318</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-588/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Fabric.js. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 4.0. The following CVEs are assigned: CVE-2026-19504.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-587: Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28173</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-587/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19781.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-586: OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29340</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-586/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19886.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-585: OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29337</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-585/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19885.]]></description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-584: dnsmasq DNSSEC NSEC/NSEC3 Type Bitmap Processing Infinite Loop Denial-of-Service Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30607</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-584/</link>
      <description><![CDATA[This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of dnsmasq. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-4890.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-583: Clam AntiVirus 7z Archive Parsing Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29416</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-583/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Clam AntiVirus. Interaction with this product is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 8.4. The following CVEs are assigned: CVE-2026-20215.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-582: Cisco Identity Services Engine PatchUpdateListener Directory Traversal Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28708</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-582/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.9. The following CVEs are assigned: CVE-2026-20148.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-581: Cisco Identity Services Engine invokeScript Command Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28709</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-581/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20147.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-580: Cisco Identity Services Engine Missing Authentication for Critical Function Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29246</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-580/</link>
      <description><![CDATA[The vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-20190.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-579: Cisco Identity Services Engine zipFiles Directory Traversal Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29197</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-579/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20181.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-578: NGINX HTTP Dav Module Alias Directive Integer Underflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29287</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-578/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of NGINX. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-27654.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-577: Trend Micro VPN OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29830</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-577/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro VPN. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-67212.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-576: Linux Kernel XFRM Race Condition Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31423</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-576/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-575: Linux Kernel Net Scheduler Packet Classifier API Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31419</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-575/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-574: Linux Kernel Net Scheduler Connection Tracking Race Condition Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29413</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-574/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-46319.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-573: Linux Kernel KSMBD Response Header Out-Of-Bounds Read Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31063</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-573/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Linux Kernel KSMBD. Authentication is not required to exploit this vulnerability. However, only systems with ksmbd enabled are vulnerable. The ZDI has assigned a CVSS rating of 9.3. The following CVEs are assigned: CVE-2026-68431.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-572: Linux Kernel XFRM Race Condition Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30499</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-572/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-571: Linux Kernel Net Scheduler Packet Classifier API Use-After-Free Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31222</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-571/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-64530.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-570: Linux Kernel IGMP Subsystem Race Condition Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31149</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-570/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-569: Linux Kernel Net Scheduler True Link Equalizer Race Condition Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30840</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-569/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-568: Linux Kernel Net Scheduler Race Condition Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31523</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-568/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-567: Norton Utilities Ultimate NortonUtilitiesSvc Link Following Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-25569</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-567/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Norton Utilities Ultimate. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-13962.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-566: BlackBerry QNX  KEV File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30346</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-566/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of BlackBerry QNX. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-40272.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-565: Gen Digital CCleaner Link Following Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28680</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-565/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Gen Digital CCleaner. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-12410.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-564: NVIDIA Transformers4Rec load_model_trainer_states_from_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28536</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-564/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA Transformers4Rec. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24232.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-563: (Pwn2Own) Home Assistant Green Simple Service Discovery Protocol Server-Side Request Forgery Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28279</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-563/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to initiate arbitrary server-side requests on affected installations of Home Assistant Green. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.4. The following CVEs are assigned: CVE-2026-91131.]]></description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-562: (Pwn2Own) Home Assistant Green mDNS Server-Side Request Forgery Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28336</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-562/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to initiate arbitrary server-side requests on affected installations of Home Assistant Green. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.4. The following CVEs are assigned: CVE-2026-91129.]]></description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-561: (Pwn2Own) Home Assistant Green go2rtc Command Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28429</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-561/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Home Assistant Green. An attacker must first obtain the ability to access the device&#x27;s localhost interface. The ZDI has assigned a CVSS rating of 7.5.]]></description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-560: (Pwn2Own) Home Assistant Green go2rtc Command Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28340</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-560/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Home Assistant Green. An attacker must first obtain the ability to access the device&#x27;s localhost interface. The ZDI has assigned a CVSS rating of 7.5.]]></description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-559: (Pwn2Own) Amazon Smart Plug OTA Update Process Out-Of-Bounds Write Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28459</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-559/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Amazon Smart Plug. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.]]></description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-558: (Pwn2Own) Amazon Smart Plug OTA Update Process Improper Certificate Validation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28460</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-558/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to bypass certificate validation for OTA updates on affected installations of Amazon Smart Plug. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8.]]></description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-557: (Pwn2Own) Amazon Smart Plug Insecure Fallback Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28367</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-557/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Amazon Smart Plug. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.3.]]></description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-556: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28886</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-556/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18263.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-555: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28885</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-555/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18262.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-554: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29220</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-554/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-13121.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-553: OriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29338</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-553/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18294.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-552: OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29336</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-552/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18293.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-551: OriginLab OriginPro OGG File Parsing Memory Corruption Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29335</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-551/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro . User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18292.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-550: OriginLab OriginPro OGW File Parsing Memory Corruption Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29334</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-550/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18291.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-549: OriginLab OriginPro OGG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29333</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-549/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18290.]]></description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
  </channel>
</rss>
