vulnerability Universal Robots Polyscope 5 A critical vulnerability has been identified in Universal Robots Polyscope 5 software versions prior to 5.25.1, allowing for unauthenticated code execution via OS command injection. This poses a significant risk to criti… CISA Advisories · May 14, 2026 Critical CVE-2026-8153WOcommand injectionroboticscve-2026-8153
vulnerability Siemens Ruggedcom Rox This advisory details a vulnerability in Siemens Ruggedcom Rox devices due to improper input validation within the JSON-RPC interface. An authenticated remote attacker could potentially read arbitrary files from the devi… CISA Advisories · May 14, 2026 High CVE-2025-40948DEjson-rpcroot accessfile disclosure
vulnerability Siemens gWAP A remote code execution vulnerability has been identified in Siemens gWAP, stemming from a prototype pollution issue within the Axios HTTP client library. This vulnerability, exploitable through a ‘Gadget’ attack chain,… CISA Advisories · May 14, 2026 High CVE-2026-40175DEremote code executionprototype pollutionaxios
vulnerability Siemens Solid Edge Siemens Solid Edge SE2026 is affected by two file parsing vulnerabilities that could allow an attacker to crash the application or execute arbitrary code when processing specially crafted PAR files. Siemens has released… CISA Advisories · May 14, 2026 High CVE-2026-44411CVE-2026-44412DEbuffer overflowfile parsingstack overflow
vulnerability OpenAI’s GPT-5.5 is as Good as Mythos at Finding Security Vulnerabilities The UK’s AI Security Institute evaluated GPT-5.5’s ability to find security vulnerabilities, and found that it is comparable to Claude Mythos. Note that the OpenAI model is generally available. Here is the Institute’s ev… Schneier on Security · May 13, 2026
vulnerability Breaking things to keep them safe with Philippe Laulheret This article details the work of Philippe Laulheret, a Senior Vulnerability Researcher at Cisco Talos, focusing on his unique career path and approach to identifying security flaws. Laulheret’s background includes a stro… Cisco Talos · May 13, 2026 Medium vulnerability researchreverse engineeringctf
vulnerability Microsoft Patch Tuesday for May 2026 — Snort rules and prominent vulnerabilities Microsoft released its May 2026 Patch Tuesday update, addressing 137 vulnerabilities across its product suite. The update includes a significant number of critical vulnerabilities, primarily remote code execution (RCE) f… Cisco Talos · May 12, 2026 High CVE-2026-32161CVE-2026-33109CVE-2026-33844rcebuffer overflowuse after free
vulnerability Copy.Fail Linux Vulnerability This is the worst Linux vulnerability in years. TL;DR copy.fail is a Linux kernel local privilege escalation, not a browser or clipboard attack. Disclosed by Theori on 29 April 2026 with a working PoC. It abuses the kern… Schneier on Security · May 12, 2026 High
vulnerability Vulnérabilité dans LibreNMS (12 mai 2026) A vulnerability in LibreNMS allows for remote code injection via cross-site scripting (XSS). This affects versions prior to 26.3.0, potentially enabling attackers to execute malicious code on vulnerable systems. Users ar… CERT-FR · May 12, 2026 Medium CVE-2026-2728xssvulnerabilityremote
vulnerability CVE-2025-68670: discovering an RCE vulnerability in xrdp This report details a remote code execution (RCE) vulnerability, CVE-2025-68670, discovered in the Kaspersky xrdp server. The vulnerability exists within the xrdp_wm_parse_domain_information function due to a buffer over… Securelist · May 8, 2026 Critical CVE-2025-68670buffer_overflowrcexrdp
vulnerability Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution Unit 42 details CVE-2026-0300, a buffer overflow vulnerability in the PAN-OS User-ID Authentication Portal. Read now for details. The post Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated… Palo Alto Unit 42 · May 7, 2026 Critical CVE-2026-0300
vulnerability Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years A critical Linux kernel vulnerability, dubbed 'Copy Fail' (CVE-2026-31431), has been discovered allowing unprivileged local attackers to escalate their access to root across numerous Linux distributions since 2017. The f… Palo Alto Unit 42 · May 5, 2026 Critical CVE-2026-31431CVE-2026-314331USlinuxkernellpe
vulnerability Feds Disrupt IoT Botnets Behind Huge DDoS Attacks The U.S. Justice Department joined authorities in Canada and Germany in dismantling the online infrastructure behind four highly disruptive botnets that compromised more than three million hacked Internet of Things (IoT)… Krebs on Security · Mar 20, 2026 High
vulnerability Multiples vulnérabilités dans Roundcube (19 mars 2026) Multiple vulnerabilities have been discovered in Roundcube Webmail, impacting versions 1.5.x through 1.5.14, 1.6.x through 1.6.14, and 1.7.x through 1.7-rc5. These flaws include data confidentiality breaches, SSRF attack… CERT-FR · Mar 19, 2026 Medium CVE-2026-35537CVE-2026-35544CVE-2026-35545roundcubevulnerabilitywebmail
vulnerability On the Effectiveness of Mutational Grammar Fuzzing This blog post discusses the limitations of mutational grammar fuzzing, a technique used to find bugs in structured languages like XSLT. The primary issue is that while it increases coverage, it doesn't necessarily lead… Google Project Zero · Mar 5, 2026 High
vulnerability Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529 Researchers at Google Project Zero discovered and exploited a type confusion vulnerability (CVE-2024-54529) within the coreaudiod system daemon in macOS. The vulnerability, stemming from a double-free, allowed for heap m… Google Project Zero · Jan 30, 2026 Critical CVE-2024-54529CVE-2025-31235macosvulnerabilityheap
vulnerability A 0-click exploit chain for the Pixel 9 Part 3: Where do we go from here? Project Zero researchers discovered a 0-click exploit chain targeting the Pixel 9 and other Android devices, leveraging a vulnerability in the Dolby UDC audio codec. The exploit chain, requiring only two software defects… Google Project Zero · Jan 14, 2026 High CVE-2025-54957CVE-2025-369340-clickaudiodriver
vulnerability A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby Google Project Zero discovered a 0-click exploit chain targeting the Dolby Unified Decoder (UDC) within the Google Messages app on Pixel 9 devices. The vulnerability stems from a buffer overrun and a memory leak, allowin… Google Project Zero · Jan 14, 2026 High CVE-2025-49415CVE-2025-54957CVE-2025-369340-clickbuffer overflowmemory leak
vulnerability Welcome to the new Project Zero Blog Project Zero has revived older research to highlight the ongoing need for zero-day defenses. The blog post focuses on past exploitation techniques, specifically a 2016 article detailing race conditions in Windows path lo… Google Project Zero · Dec 16, 2025 Medium vulnerabilitywindowsexploitation