<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
  <channel>
    <atom:link href="https://www.zerodayinitiative.com/rss/published/" rel="self" type="application/xml" />
    <title><![CDATA[ZDI: Published Advisories]]></title>
    <link>http://www.zerodayinitiative.com/advisories/published/</link>
    <description><![CDATA[The following is a list of publicly disclosed vulnerabilities discovered by
                   Zero Day Initiative researchers. While the affected vendor is working on a patch for these
                   vulnerabilities, TrendAI customers are protected from exploitation by security filters
                   delivered ahead of public disclosure. All security vulnerabilities that are acquired by the
                   Zero Day Initiative are handled according to the ZDI Disclosure Policy.
        ]]></description>
    <pubDate>Tue, 11 Aug 2026 01:15:06 -0500</pubDate>
    <copyright>Trend Micro, all rights reserved</copyright>
    <language>en</language>
    
    <item>
      <title><![CDATA[ZDI-26-526: (0Day) PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30585</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-526/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.]]></description>
      <pubDate>Wed, 05 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-525: (0Day) PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30583</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-525/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.]]></description>
      <pubDate>Wed, 05 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-524: (0Day) PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30584</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-524/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to disclose sensitive information and modify configuration on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1.]]></description>
      <pubDate>Wed, 05 Aug 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-523: Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27987</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-523/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face PyTorch Image Models. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-15679.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-522: Phoenix Contact CHARX SEC-3000 Insertion of Sensitive Information into Log File Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27763</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-522/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Phoenix Contact CHARX SEC-3000 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-41032.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-521: Phoenix Contact CHARX SEC-3000 Command Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27762</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-521/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3000 devices. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-44095.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-520: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Jupicore External Control of Path Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29093</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-520/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-44103.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-519: (Pwn2Own) Phoenix Contact CHARX SEC-3150 CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29077</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-519/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-44099.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-518: (Pwn2Own) Phoenix Contact CHARX SEC-3150 MQTT Service Server-Side Request Forgery Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29073</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-518/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to access internal resources on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.3. The following CVEs are assigned: CVE-2026-44091.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-517: (Pwn2Own) Phoenix Contact CHARX SEC-3150 BackendURL WebSocket Command Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29054</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-517/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3150 devices. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-44098.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-516: (Pwn2Own) Phoenix Contact CHARX SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29055</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-516/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-44090.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-515: (Pwn2Own) Phoenix Contact CHARX SEC-3150 charx-jupicore Missing Authentication Configuration Modification Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28999</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-515/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to modify configuration on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.2. The following CVEs are assigned: CVE-2026-44100.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-514: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Failing Open Authentication Bypass Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29076</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-514/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-44094.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-513: (Pwn2Own) Phoenix Contact CHARX SEC-3150 update2-upload Arbitrary File Upload Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29110</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-513/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to upload arbitrary files on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 2.4. The following CVEs are assigned: CVE-2026-44097.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-512: (Pwn2Own) Phoenix Contact CHARX SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29052</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-512/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-44107.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-511: (Pwn2Own) Phoenix Contact CHARX SEC-3150 user-applications Symlink Following Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29075</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-511/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Phoenix Contact CHARX SEC-3150 devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-44093.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-510: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Missing Cryptographic Signature Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29094</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-510/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to bypass firmware validation on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-44104.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-509: (Pwn2Own) Phoenix Contact CHARX SEC-3150 OCPP Missing Authentication for Critical Function Authentication Bypass Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29091</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-509/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to modify configuration on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.0. The following CVEs are assigned: CVE-2026-44101.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-508: (Pwn2Own) Phoenix Contact CHARX SEC-3150 charx_set_ip_address Improper Input Validation Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29108</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-508/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Phoenix Contact CHARX SEC-3150 devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-44095.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-507: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Privilege Defined With Unsafe Actions Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29109</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-507/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Phoenix Contact CHARX SEC-3150 devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-44096.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-506: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Insertion of Sensitive Information into Log File Authentication Bypass Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29050</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-506/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2026-44105.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-505: (Pwn2Own) Phoenix Contact CHARX SEC-3150 charx-system-config-manager Service CRLF Injection Firewall Bypass Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29074</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-505/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to bypass firewall rules on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.0. The following CVEs are assigned: CVE-2026-44092.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-504: (Pwn2Own) Phoenix Contact CHARX SEC-3150 CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29059</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-504/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-7849.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-503: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Race Condition Firewall Bypass Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29058</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-503/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to bypass firewall rules on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2026-44108.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-502: (Pwn2Own) Phoenix Contact CHARX SEC-3150 user-applications Link Following Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29085</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-502/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Phoenix Contact CHARX SEC-3150 devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-44106.]]></description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-501: WatchGuard FireWare OS sigd comp_start_cb Directory Traversal Arbitrary File Creation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31457</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-501/</link>
      <description><![CDATA[This vulnerability allows remote attackers to create arbitrary files on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-13054.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-500: WatchGuard FireWare OS networkd network_wireless_kick_off_user_cb Stack-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31458</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-500/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-13050.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-499: WatchGuard FireWare OS cli Token Parser Stack-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31459</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-499/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.7. The following CVEs are assigned: CVE-2026-13053.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-498: TrendAI Vision One Incorrect Privilege Assignment Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28122</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-498/</link>
      <description><![CDATA[This vulnerability allows remote attackers to escalate privileges on affected installations of TrendAI Vision One. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2025-71387.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-497: TrendAI Vision One Service Gateway Logs Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28148</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-497/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of TrendAI Vision One. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.7. The following CVEs are assigned: CVE-2025-71386.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-496: Trend AI Cleaner One Pro Link Following Arbitrary File Deletion Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28718</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-496/</link>
      <description><![CDATA[This vulnerability allows local attackers to delete arbitrary files on affected installations of TrendLife Cleaner One Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.6. The following CVEs are assigned: CVE-2026-62660.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-495: (Pwn2Own) VMware ESXi VMXNET3 espQueueMask Out-Of-Bounds Write Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31293</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-495/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of VMware ESXi. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2026-47876.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-494: Apple macOS USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30380</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-494/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. Interaction with the USD library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-43729.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-493: Apple macOS USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29483</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-493/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. Interaction with the USD library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-43733.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-492: Apple macOS ImageIO Numeric Truncation Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29252</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-492/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. Interaction with the ImageIO library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-43780.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-491: Apple macOS CoreAudio Out-Of-Bounds Write Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29143</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-491/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-43673.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-490: (Pwn2Own) Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29070</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-490/</link>
      <description><![CDATA[This vulnerability allows physically present attackers to escalate privileges on affected installations of Kenwood DNR1007XR devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.6. The following CVEs are assigned: CVE-2026-18273.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-489: (Pwn2Own) Kenwood DNR1007XR startUpdateProcess Command Injection Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28981</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-489/</link>
      <description><![CDATA[This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-18272.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-488: (Pwn2Own) Kenwood DNR1007XR vCardParser Heap-based Buffer Overflow Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28974</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-488/</link>
      <description><![CDATA[This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-18271.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-487: (Pwn2Own) Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29111</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-487/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Kenwood DNR1007XR devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18270.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-486: (Pwn2Own) Kenwood DNR1007XR tchdr_bytestream_read Out-Of-Bounds Write Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28980</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-486/</link>
      <description><![CDATA[This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-18269.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-485: (Pwn2Own) Kenwood DNR1007XR JKGenService Command Injection Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29066</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-485/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Kenwood DNR1007XR devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-18268.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-484: (Pwn2Own) Kenwood DNR1007XR Firmware Update Link Following Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28751</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-484/</link>
      <description><![CDATA[This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-18267.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-483: NoMachine getstat Command Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30634</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-483/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of NoMachine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-18264.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-482: Progress Software Kemp LoadMaster enablexroot Use of Hard-Coded Cryptographic Key Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30687</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-482/</link>
      <description><![CDATA[This vulnerability allows remote attackers to escalate privileges on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-59689.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-481: Progress Software Kemp LoadMaster access Missing Authorization Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30735</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-481/</link>
      <description><![CDATA[This vulnerability allows remote attackers to escalate privileges on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-59690.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-480: OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30036</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-480/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of OSNEXUS QuantaStor. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-18265.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-479: Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28603</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-479/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-18274.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-478: Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28201</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-478/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adminer. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-15686.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-477: (Pwn2Own) Sony XAV-9500ES Crash Dump Handler Command Injection Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29061</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-477/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18284.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-476: (Pwn2Own) Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28992</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-476/</link>
      <description><![CDATA[This vulnerability allows physically present attackers to bypass authorization on affected installations on Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 2.4. The following CVEs are assigned: CVE-2026-18283.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-475: (Pwn2Own) Sony XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28995</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-475/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.0. The following CVEs are assigned: CVE-2026-18282.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-474: (Pwn2Own) Sony XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29072</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-474/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.0. The following CVEs are assigned: CVE-2026-18281.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-473: (Pwn2Own) Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29060</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-473/</link>
      <description><![CDATA[This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 3.9. The following CVEs are assigned: CVE-2026-18280.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-472: (Pwn2Own) Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29042</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-472/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-18279.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-471: (Pwn2Own) Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28990</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-471/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 3.5. The following CVEs are assigned: CVE-2026-18278.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-470: Aeon load_time_series_segmentation_benchmark Code Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29159</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-470/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of aeon. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18287.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-469: Aeon load_human_activity_segmentation_datasets Code Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29160</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-469/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of aeon. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18286.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-468: Aeon load_rehab_pile_dataset Deserialization of Untrusted Data Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28749</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-468/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Aeon. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18285.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-467: GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29787</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-467/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18299.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-466: GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29581</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-466/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18298.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-465: GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29584</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-465/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18297.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-464: GStreamer MRF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29608</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-464/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18296.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-463: GStreamer MRF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29510</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-463/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18295.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-462: GIMP APNG File Parsing Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29401</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-462/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18309.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-461: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29405</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-461/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18308.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-460: GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29404</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-460/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18307.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-459: GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29396</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-459/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18306.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-458: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29406</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-458/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18305.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-457: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29403</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-457/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18304.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-456: GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29399</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-456/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18303.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-455: GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29398</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-455/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18302.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-454: GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29395</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-454/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18301.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-453: GIMP HDR File Parsing Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29289</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-453/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18300.]]></description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-452: Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29196</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-452/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Dify. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 5.4. The following CVEs are assigned: CVE-2026-18266.]]></description>
      <pubDate>Thu, 23 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-451: Docker Desktop for macOS Inference Server Permissive Allow List Sandbox Escape Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29308</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-451/</link>
      <description><![CDATA[This vulnerability allows local attackers to escape the model runner sandbox on affected installations of Docker Desktop for macOS. An attacker must first obtain the ability to execute low-privileged code within the sandbox in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8.]]></description>
      <pubDate>Thu, 23 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-450: AzeoTech DAQFactory CTL File Parsing Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28831</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-450/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-12921.]]></description>
      <pubDate>Thu, 23 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-449: AzeoTech DAQFactory CTL File Parsing Type Confusion Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28876</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-449/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-12390.]]></description>
      <pubDate>Thu, 23 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-448: Bitdefender Total Security Shredder Link Following Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28703</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-448/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Bitdefender Total Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.3. The following CVEs are assigned: CVE-2026-6851.]]></description>
      <pubDate>Thu, 23 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-447: Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29251</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-447/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-12357.]]></description>
      <pubDate>Thu, 23 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-446: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-32968</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-446/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-50297.]]></description>
      <pubDate>Tue, 21 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-445: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-32967</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-445/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-50325.]]></description>
      <pubDate>Tue, 21 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-444: 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30169</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-444/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-14266.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-443: Linux Kernel vmwgfx Integer Overflow Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31467</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-443/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-442: Linux Kernel CAN ISO-TP Protocol Race Condition Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31764</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-442/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-441: dnsmasq DNS Response Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29496</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-441/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of dnsmasq. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-2291.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-440: Fuji Electric Tellus pcid64 Driver Untrusted Pointer Dereference Denial of Service Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27744</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-440/</link>
      <description><![CDATA[This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Fuji Electric Tellus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.5. The following CVEs are assigned: CVE-2026-8108.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-439: Fuji Electric Tellus pcid64 Driver Exposed Dangerous Method Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27670</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-439/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Fuji Electric Tellus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-8108.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-438: Rockwell Automation Arena Simulation DOE File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27055</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-438/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Rockwell Automation Arena Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-6071.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-437: (Pwn2Own) Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29113</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-437/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-13308.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-436: (Pwn2Own) Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29048</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-436/</link>
      <description><![CDATA[This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-13307.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-435: (Pwn2Own) Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29044</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-435/</link>
      <description><![CDATA[This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-13309.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-434: (Pwn2Own) Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29046</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-434/</link>
      <description><![CDATA[This vulnerability allows physically present attackers to bypass authentication on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.3. The following CVEs are assigned: CVE-2026-13306.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-433: (Pwn2Own) Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29062</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-433/</link>
      <description><![CDATA[This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2026-13305.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-432: G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28665</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-432/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of G DATA Total Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-13268.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-431: ASUS Business Manager Service Client-Side Authentication Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28776</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-431/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of ASUS Business Manager. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-8921.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-430: MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28935</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-430/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of MSI Center. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-6102.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-429: NVIDIA NeMo Framework Deserialization of Untrusted Data Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28090</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-429/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA NeMo Framework. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24157.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-428: WatchGuard FireWare OS admd Stack-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30173</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-428/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-8247.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-427: WatchGuard FireWare OS iked ike2_hmac Null Pointer Dereference Denial-of-Service Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30097</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-427/</link>
      <description><![CDATA[This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of WatchGuard FireWare OS. Authentication is not required to exploit this vulnerability, but only systems using VPN with IKEv2 are vulnerable. The ZDI has assigned a CVSS rating of 5.9. The following CVEs are assigned: CVE-2026-13084.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-426: OpenSSL X.509 Email Validation Out-Of-Bounds Read Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30378</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-426/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of OpenSSL. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-42771.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-425: OpenSSL OCSP Stapling Verification Double Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30391</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-425/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenSSL. User interaction is required to exploit this vulnerability in that the target must make a request to a malicious server. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-35188.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-424: Synology DiskStation DS925+ MailPlus Improper Restriction of Communication Channel to Intended Endpoints Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28485</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-424/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to access the Redis instance on affected installations of Synology DiskStation DS925+ devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.3. The following CVEs are assigned: CVE-2026-13135.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-423: Synology DiskStation DS925+ MailPlus Redis Weak Cryptography for Passwords Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28554</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-423/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology DiskStation DS925+ devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-15660.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-422: Samsung rlottie Numeric Truncation Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30236</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-422/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung rlottie. Interaction with the rlottie library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-15551.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-421: Cisco Identity Services Engine validFileNameOrPath Directory Traversal Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28724</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-421/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.5. The following CVEs are assigned: CVE-2026-20146.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-420: Adobe Creative Cloud AGSService Incorrect Permission Assignment Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29867</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-420/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Adobe Creative Cloud Desktop Application. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-48344.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-419: Adobe Creative Cloud AdobeUpdateService Uncontrolled Search Path Element Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29588</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-419/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Adobe Creative Cloud. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-48272.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-418: Microsoft SharePoint SPFieldMultiLineText Cross-Site Scripting Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30803</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-418/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute web requests with a target user&#x27;s privileges on affected installations of Microsoft SharePoint. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.3. The following CVEs are assigned: CVE-2026-55126.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-417: Microsoft Windows ServerManager Exposed Dangerous Method Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30003</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-417/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-50311.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-416: Microsoft Hyper-V netvsc Out-Of-Bounds Read Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28769</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-416/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Hyper-V. An attacker must first obtain the ability to execute low-privileged code within a Windows virtual machine under Hyper-V in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-54129.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-415: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30052</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-415/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-49805.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-414: Microsoft PowerShell Help Directory Traversal Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31478</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-414/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft PowerShell. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-40400.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-413: (Pwn2Own) Microsoft SharePoint Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31261</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-413/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft SharePoint. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-50522.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-412: (Pwn2Own) Microsoft SharePoint Deserialization of Untrusted Data Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31490</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-412/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft SharePoint. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-50522.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-411: NVIDIA NVTabular Pickle File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28693</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-411/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA NVTabular. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24237.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-410: NVIDIA NeMo Framework Deserialization of Untrusted Data Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28677</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-410/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA NeMo Framework. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24228.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-409: X.Org Server Glamor Font Heap-based Buffer Overflow Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30498</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-409/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-55999.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-408: X.Org Server ComputeScaledProperties Heap-based Buffer Overflow Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30560</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-408/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-56003.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-407: X.Org Server PCF Font Parsing Heap-based Buffer Overflow Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30559</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-407/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-56002.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-406: X.Org Server BitmapScaleBitmaps Integer Overflow Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30558</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-406/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-56001.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-405: X.Org Server GLX Extension Use-After-Free Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30561</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-405/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-56000.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-404: Delta Electronics DTM Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27843</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-404/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DTM Soft. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-12578.]]></description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-403: (0Day) Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27277</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-403/</link>
      <description><![CDATA[This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-15685.]]></description>
      <pubDate>Wed, 08 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-402: (0Day) Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27004</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-402/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Glarysoft Glary Utilities. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.3. The following CVEs are assigned: CVE-2026-15684.]]></description>
      <pubDate>Wed, 08 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-401: (0Day) AnyDesk Support Information Link Following Denial-of-Service Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-26645</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-401/</link>
      <description><![CDATA[This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.7. The following CVEs are assigned: CVE-2026-15682.]]></description>
      <pubDate>Wed, 08 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-400: (0Day) AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-26591</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-400/</link>
      <description><![CDATA[This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.7. The following CVEs are assigned: CVE-2026-15681.]]></description>
      <pubDate>Mon, 13 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-399: (0Day) (Pwn2Own) Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-26851</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-399/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lorex 2K Indoor Wi-Fi Security Cameras. User interaction is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-15683.]]></description>
      <pubDate>Wed, 08 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-398: (0Day) (Pwn2Own) Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-25884</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-398/</link>
      <description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lorex 2K Indoor Wi-Fi Security Cameras. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-15680.]]></description>
      <pubDate>Wed, 08 Jul 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-397: X.Org Server CreateSaverWindow Use-After-Free Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30168</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-397/</link>
      <description><![CDATA[This vulnerability allows local attackers to disclose sensitive information on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.5. The following CVEs are assigned: CVE-2026-50263.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-396: X.Org Server ChangeDrawableAttributes Out-Of-Bounds Read Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30165</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-396/</link>
      <description><![CDATA[This vulnerability allows local attackers to disclose sensitive information on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.5. The following CVEs are assigned: CVE-2026-50262.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-395: X.Org Server SyncChangeCounter Use-After-Free Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30164</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-395/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-50261.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-394: X.Org Server FreeCounter Use-After-Free Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30163</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-394/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-50260.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-393: X.Org Server SetMap Request Stack-based Buffer Overflow Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30161</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-393/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-50259.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-392: X.Org Server Xkb Key Types Stack-based Buffer Overflow Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30160</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-392/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-50258.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-391: X.Org Server miSyncDestroyFence Use-After-Free Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30159</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-391/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-50257.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-390: X.Org Server Font Alias Stack-based Buffer Overflow Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30136</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-390/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-50256.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-389: Oracle PeopleSoft ExecuteProcessActivityCommand External Control of File Path Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31818</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-389/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle PeopleSoft. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-35273.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-388: Oracle PeopleSoft HubMBeanPersistance Deserialization of Untrusted Data Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31817</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-388/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle PeopleSoft. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-35273.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-387: Oracle PeopleSoft HttpListeningConnector Server-Side Request Forgery Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31816</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-387/</link>
      <description><![CDATA[This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Oracle PeopleSoft. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.3. The following CVEs are assigned: CVE-2026-35273.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-386: Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30134</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-386/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Unraid. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-9773.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-385: Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30116</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-385/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Unraid. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-9772.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-384: MosaicML Composer Deserialization of Untrusted Data Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27990</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-384/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of MosaicML Composer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-10043.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-383: ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28590</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-383/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of ATEN Unizon. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-9779.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-382: ATEN Unizon ImportDeviceList Directory Traversal Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28579</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-382/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of ATEN Unizon. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-9778.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-381: ATEN Unizon restoreDB Directory Traversal Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28578</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-381/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of ATEN Unizon. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-9777.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-380: ATEN Unizon writeFileToHttpServletResponse Directory Traversal Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28505</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-380/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of ATEN Unizon. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-9776.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-379: ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28503</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-379/</link>
      <description><![CDATA[This vulnerability allows remote attackers to delete arbitrary files on affected installations of ATEN Unizon. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.5. The following CVEs are assigned: CVE-2026-9775.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-378: ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28502</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-378/</link>
      <description><![CDATA[This vulnerability allows remote attackers to delete arbitrary files on affected installations of ATEN Unizon. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.5. The following CVEs are assigned: CVE-2026-9774.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-377: Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28202</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-377/</link>
      <description><![CDATA[This vulnerability allows remote attackers to bypass authentication on affected installations of Quest NetVault Backup. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-7569.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-376: Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27625</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-376/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-9787.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-375: Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27626</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-375/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-9786.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-374: Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27630</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-374/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-9785.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-373: Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27631</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-373/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-9784.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-372: Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27632</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-372/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-9783.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-371: Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27633</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-371/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-9782.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-370: Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27648</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-370/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-9781.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-369: Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27666</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-369/</link>
      <description><![CDATA[This vulnerability allows remote attackers to bypass authentication on affected installations of Quest NetVault Backup. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-9780.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-368: Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27809</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-368/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-7570.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-367: Fuji Electric Tellus pcid64 Driver Registry APIs Exposed Dangerous Method Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27671</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-367/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Fuji Electric Tellus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-8108.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-366: Fuji Electric Tellus pcid64 Driver File APIs Exposed Dangerous Method Arbitrary File Deletion Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27673</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-366/</link>
      <description><![CDATA[This vulnerability allows local attackers to delete arbitrary files on affected installations of Fuji Electric Tellus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-8108.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-365: FlowiseAI Flowise CSV Agent customReadCSV Code Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29410</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-365/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-41137.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-364: FlowiseAI Flowise CSV Agent  Prompt Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29411</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-364/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-41264.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-363: Docker MCP Plugin OCI Image Label Parsing Argument Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29539</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-363/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Docker MCP Plugin. User interaction is required to exploit this vulnerability in that the target must reference a malicious Docker image via a docker URI scheme. The ZDI has assigned a CVSS rating of 8.6. The following CVEs are assigned: CVE-2026-55887.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-362: Oracle VirtualBox VMSVGA Stack-based Buffer Overflow Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29271</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-362/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-46873.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-361: Adobe Acrobat Reader DC Field signatureInfo Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29178</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-361/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-27278.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-360: MATE Desktop Atril Document Viewer EPUB File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30289</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-360/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of MATE Desktop Atril Document Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-52849.]]></description>
      <pubDate>Thu, 11 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-359: Samsung rlottie Numeric Truncation Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30288</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-359/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung rlottie. Interaction with the rlottie library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-8916.]]></description>
      <pubDate>Thu, 11 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-358: Allegra downloadAttachment Cross-Site Scripting Authentication Bypass Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28236</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-358/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary script on affected installations of Allegra. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 4.6. The following CVEs are assigned: CVE-2026-11443.]]></description>
      <pubDate>Thu, 11 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-357: Allegra exportReport Directory Traversal Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28208</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-357/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Allegra. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-11442.]]></description>
      <pubDate>Thu, 11 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-356: Apache HTTP Server mod_proxy_ajp Out-Of-Bounds Read Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30089</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-356/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Apache HTTP Server. An attacker must first obtain the ability to compromise an AJP backend associated with the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 3.7. The following CVEs are assigned: CVE-2026-34032.]]></description>
      <pubDate>Thu, 11 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-355: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28816</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-355/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-27220.]]></description>
      <pubDate>Wed, 10 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-354: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29987</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-354/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-47919.]]></description>
      <pubDate>Tue, 09 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-353: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30387</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-353/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-47918.]]></description>
      <pubDate>Tue, 09 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-352: Adobe Acrobat Pro DC AcroForm Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30689</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-352/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-47917.]]></description>
      <pubDate>Tue, 09 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-351: Adobe USD-Fileformat-plugins Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30375</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-351/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe USD-Fileformat-plugins. Interaction with the USD library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-48292.]]></description>
      <pubDate>Tue, 09 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-350: Adobe USD-Fileformat-plugins Heap-based Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29653</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-350/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe USD-Fileformat-plugins. Interaction with the USD library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-48291.]]></description>
      <pubDate>Tue, 09 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-349: Adobe Acrobat Pro DC Annots.api Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29886</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-349/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-47915.]]></description>
      <pubDate>Tue, 09 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-348: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29896</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-348/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-47914.]]></description>
      <pubDate>Tue, 09 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-347: Adobe Acrobat Reader DC Multimedia Rendition Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29409</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-347/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-47913.]]></description>
      <pubDate>Tue, 09 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-346: Adobe Acrobat Reader DC Annotation Use-After-Free Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29433</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-346/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-47924.]]></description>
      <pubDate>Tue, 09 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-345: Adobe Acrobat Reader DC Font Handling Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30015</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-345/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-47912.]]></description>
      <pubDate>Tue, 09 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-344: Adobe Acrobat Reader DC Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29477</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-344/</link>
      <description><![CDATA[This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-47923.]]></description>
      <pubDate>Tue, 09 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-343: Adobe Acrobat Reader DC TIF File Parsing Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-29828</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-343/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-47911.]]></description>
      <pubDate>Tue, 09 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-342: Progress Software Kemp LoadMaster apiuser Uninitialized Memory Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30437</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-342/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-8037.]]></description>
      <pubDate>Tue, 09 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-341: Progress Software Kemp LoadMaster dolistapikeys Uninitialized Memory Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30439</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-341/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-8037.]]></description>
      <pubDate>Tue, 09 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-340: Progress Software Kemp LoadMaster dodelapikey Uninitialized Memory Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30438</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-340/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-8037.]]></description>
      <pubDate>Tue, 09 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-339: Microsoft Windows Narrator Braille Support brlapi Exposed Dangerous Function Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28792</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-339/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Additionally, Braille support for Narrator must be installed. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-48565.]]></description>
      <pubDate>Tue, 09 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-338: NVIDIA Transformers4Rec Model.load Deserialization of Untrusted Data Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28649</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-338/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA Transformers4Rec. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24162.]]></description>
      <pubDate>Tue, 09 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-337: X.Org Server CheckKeyTypes Buffer Overflow Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28736</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-337/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-34003.]]></description>
      <pubDate>Tue, 09 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-336: X.Org Server CheckKeyActions Out-Of-Bounds Read Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28737</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-336/</link>
      <description><![CDATA[This vulnerability allows local attackers to disclose sensitive information on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-34002.]]></description>
      <pubDate>Tue, 09 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-335: X.Org Server SyncAwaitFence Use-After-Free Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28706</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-335/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-34001.]]></description>
      <pubDate>Tue, 09 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-334: X.Org Server CheckSetGeom Out-Of-Bounds Read Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28679</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-334/</link>
      <description><![CDATA[This vulnerability allows local attackers to disclose sensitive information on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-34000.]]></description>
      <pubDate>Tue, 09 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-333: X.Org Server XkbSetCompatMap Integer Underflow Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28593</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-333/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-33999.]]></description>
      <pubDate>Tue, 09 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-332: QEMU calc_image_hostmem Integer Overflow Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-27578</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-332/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of QEMU. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-3886.]]></description>
      <pubDate>Tue, 09 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-331: (Pwn2Own) Microsoft Edge Feedback Log File Handling Directory Traversal Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31431</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-331/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Edge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-45495.]]></description>
      <pubDate>Thu, 04 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-330: (Pwn2Own) Microsoft Edge Navigation Handling Universal Cross-Site Scripting Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31430</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-330/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary cross-origin script on affected installations of Microsoft Edge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 5.0. The following CVEs are assigned: CVE-2026-45494.]]></description>
      <pubDate>Thu, 04 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-329: (Pwn2Own) Microsoft Edge Origin Validation Error Security Bypass Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-31429</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-329/</link>
      <description><![CDATA[This vulnerability allows remote attackers to access restricted functionality on affected installations of Microsoft Edge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 4.3. The following CVEs are assigned: CVE-2026-45492.]]></description>
      <pubDate>Thu, 04 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-328: ASUS MyASUS Origin Validation Error Local Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-28489</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-328/</link>
      <description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of ASUS MyASUS. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-7480.]]></description>
      <pubDate>Wed, 10 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-26-327: Docker Desktop grpcfuse Kernel Module Uncontrolled Recursion Denial-of-Service Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-30796</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-26-327/</link>
      <description><![CDATA[This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Docker Desktop. An attacker must first obtain the ability to execute low-privileged code within a container on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-8936.]]></description>
      <pubDate>Wed, 03 Jun 2026 00:00:00 -0500</pubDate>
    </item>
    
  </channel>
</rss>
