tagCve

  • Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
    Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes

    Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Google downgrading two Antigravity findings.

    July 20, 2026
  • // no cover
    ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)

    Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About the vulnerability ServiceNow AI is a Platform-as-a-Service that lets organizations build and automate digital workflows. CVE-2026-6875 is a code injection vulnerability that lets unauthenticated attackers escape ServiceNow’s script sandbox and execute code remotely on a targeted instance. The vulnerability was unearthed by Searchlight Cyber researchers and reported to ServiceNow in early April 2026. The

    July 20, 2026
  • Mythos Didn't Break Your Security Program. Your Exposure Window Could.
    Mythos Didn't Break Your Security Program. Your Exposure Window Could.

    The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long would it take adversaries to weaponize Mythos findings at scale? Those questions were and remain valid. Yet they all stop short of

    July 20, 2026
  • Critical ServiceNow code execution flaw now exploited in attacks
    Critical ServiceNow code execution flaw now exploited in attacks

    Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused.

    July 20, 2026
  • New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
    New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

    Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro's Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02. The overflow lets an attacker "execute code in the context of the current process," per the

    July 20, 2026
  • Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
    Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

    F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in NGINX Plus 37.0.3.1; anyone on an earlier build should upgrade. Triggering it can crash or restart the worker, causing a denial of

    July 19, 2026
  • Two new high severity WordPress vulnerabilities, patch immediately!
    Two new high severity WordPress vulnerabilities, patch immediately!

    The 7.0.2 WordPress security release addresses one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: CVE-2026-60137 – A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo CVE-2026-60137 – A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution reported by Adam Kues at Assetnote / Searchlight Cyber Which versions of WordPress are vulnerable? WordPress 6.9 is affected by

    July 18, 2026
  • OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
    OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

    Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no changelog entry pointing at it. Okta's Red Team, which reported the denial-of-service bug and named it, published the

    July 17, 2026
  • CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
    CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026. The vulnerability in question is CVE-2026-58644 (CVSS score: 9.8), a critical deserialization

    July 17, 2026
  • Zoom Patches Critical Windows Flaw That Could Enable Account Takeover
    Zoom Patches Critical Windows Flaw That Could Enable Account Takeover

    Zoom has released security updates for a critical security flaw impacting Zoom Workplace for Windows that could facilitate account takeover. The vulnerability, tracked as CVE-2026-53412 (CVSS score: 9.8), affects Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows. "Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for

    July 16, 2026
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 104
Go to
Total 1040