Google Patches Actively Exploited Android Zero-Day on Pixel Devices
September 16, 2026 Google has released the September 2026 security patches for Pixel devices. This update fixes 110 vulnerabilities, including one zero-day flaw that is actively exploited in targeted attacks. The zero-day, tracked as CVE-2026-58704, is a…
Cisco Secure Email Gateway CVE Critical Zero-Day
September 15, 2026 Cisco has disclosed a critical zero-day vulnerability in its Secure Email Gateway that threat actors are actively exploiting to gain root-level command execution. The flaw, tracked as CVE-2026-76461, carries a CVSS score of 9.8 and was…
StyleSmuggler Magento and Adobe Commerce Zero-Day
September 06, 2026 Attackers are actively exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store’s server without logging in. Dutch e-commerce security company Sansec…
CrowdStrike FalconFlank Zero-Day EDR Platform Exploited
September 4, 2026 An anonymous security researcher operating under the handle “Nightmare Eclipse” has released a zero-day privilege escalation exploit targeting CrowdStrike Falcon, the widely deployed endpoint detection and response (EDR)…
Google Chrome V8 Zero-Day CVE Actively Exploited
September 3, 2026 Google released an emergency security update for Chrome on September 3, 2026, to patch an actively exploited zero-day vulnerability in the V8 JavaScript engine. The high-severity flaw, tracked as CVE-2026-85046, allows remote attackers…
SonicWall SMA1000 Zero-Day Flaws Under Active Exploitation
Threat actors are actively chaining two critical zero-day vulnerabilities in SonicWall SMA1000 remote access appliances to achieve remote code execution on enterprise devices. The vulnerabilities, tracked as CVE-2026-83548 and CVE-2026-83549, affect…
Lazarus Exploits Windows AFD.sys Zero-Day in Defense Sector Attacks
August 21, 2026 North Korean Lazarus hackers exploited CVE-2026-68820, a zero-day vulnerability in the Windows Ancillary Function Driver (AFD.sys), to deploy their FudModule rootkit and gain SYSTEM privileges on defense-sector targets. Microsoft patched…
Lazarus Exploits Windows Zero-Day to Deploy Troy Backdoor
August 17, 2026 The North Korean Lazarus Group has been caught exploiting a newly patched Windows zero-day vulnerability as part of its long-running Operation Dream Job campaign. The flaw, tracked as CVE-2026-68820, targets the Windows Ancillary Function…
Metabase SQLi Zero-Day Flaw Grants Attackers Admin Access and Steals Database Credentials
August 7, 2026 A critical SQL injection vulnerability in Metabase is under active zero-day exploitation, allowing unauthenticated attackers to seize administrator control of instances and steal connected database credentials. The flaw has already…
Check Point VPN Zero-Day CVE-2026-50751: Qilin Ransomware Exploit
June 8, 2026 Check Point has disclosed a critical zero-day vulnerability in its Remote Access VPN and Mobile Access deployments that allows unauthenticated attackers to bypass authentication and establish VPN connections. The flaw, tracked as…