ZCyberNews
中文

#zero-day

23 articles

Technology and government sectors bore the brunt of the 35 zero-day exploits tracked from April to August 2026, with 18 rated high and 16 critical. APT29, Chaotic Eclipse, and Claude Mythos were observed in campaigns spanning Global, Asia, Brazil, China, and Europe, affecting telecommunications, critical infrastructure, and enterprise networks. Top vulnerabilities included CVE-2026-22679 (CVSS 9.8), CVE-2026-34621 (CVSS 8.6), CVE-2026-3502 (CVSS 7.8), CVE-2026-32183 (CVSS 7.5), and CVE-2026-68820 (CVSS 7). One medium-severity issue rounded out the archive.

CISA logo and Windows error screen symbolizing the urgent patch deadline for the DPRK-exploited Winsock vulnerability.HIGH
Vulnerabilities

CISA Orders Federal Agencies to Patch DPRK-Exploited Windows Bug

CISA gives federal agencies until Aug 25 to patch CVE-2026-68820, a Winsock privilege-escalation flaw exploited by North Korea's Lazarus in Operation Dream Job.

CVE-2026-68820
5 min readLazarus Group
Abstract visualization of AI analyzing open-source code for vulnerabilitiesCRITICAL
AI Security

Frontier AI Finds 14,090 Zero-Days in OSS in 2 Months

Unit 42's NOVA system uncovered 14,090 novel vulnerabilities across 3,915 OSS projects in two months — 40% high or critical severity — collapsing the patch window to near zero.

4 min read
Microsoft Warns of Exchange Zero-Day CVE-2026-42897 Exploited inHIGH
Vulnerabilities

Microsoft Warns of Exchange Zero-Day CVE-2026-42897 Exploited in

CVE-2026-42897 is a high-severity Exchange Server spoofing flaw exploited in the wild, enabling XSS-based code execution via Outlook on the web.

CVE-2026-42897
4 min read
Pwn2Own Berlin 2026: Researchers Earn $523K Hacking Windows 11, EdgeCRITICAL
Industry News

Pwn2Own Berlin 2026: Researchers Earn $523K Hacking Windows 11, Edge

On day one of Pwn2Own Berlin 2026, researchers collected $523,000 for 24 zero-days, including a $175,000 Edge sandbox escape by Orange Tsai and three Windows 11 privilege...

3 min read
Apple Patches Everything: 0-Days, RCS Encryption RolloutCRITICAL
Industry News

Apple Patches Everything: 0-Days, RCS Encryption Rollout

Apple released emergency patches for two zero-days exploited in the wild alongside the beta rollout of end-to-end encrypted RCS messaging for iOS and macOS.

3 min read
Ivanti EPMM Zero-Day CVE-2026-6973 Exploited in Limited AttacksHIGH
Vulnerabilities

Ivanti EPMM Zero-Day CVE-2026-6973 Exploited in Limited Attacks

Ivanti warns CVE-2026-6973, a high-severity RCE in EPMM 12.8.0.0 and earlier, is under limited zero-day exploitation. Patches available; 850+ EPMM instances exposed online.

CVE-2026-6973CVE-2026-5786CVE-2026-5787+4
4 min read
Weaver E-cology Zero-Day CVE-2026-22679 Exploited Since MarchCRITICAL
Vulnerabilities

Weaver E-cology Zero-Day CVE-2026-22679 Exploited Since March

CVE-2026-22679 (CVSS 9.8) in Weaver E-cology OA has been exploited in the wild since mid-March 2026. Attackers run discovery commands post-exploit. No patch available.

CVE-2026-22679
3 min read
APT29, Intellexa, NSO Share Identical Exploit ChainsHIGH
Threat Intel

APT29, Intellexa, NSO Share Identical Exploit Chains

Google TAG finds APT29 using exploit chains identical to those deployed by Intellexa and NSO Group, suggesting shared access to zero-day suppliers or exploit resale.

3 min readAPT29
Google TAG: 97 Zero-Days Exploited in Wild During 2023HIGH
Threat Intel

Google TAG: 97 Zero-Days Exploited in Wild During 2023

Google TAG reports 97 zero-days were exploited in the wild in 2023, up from 62 in 2022. Commercial surveillance vendors drove 80% of targeted exploits. Full report released.

3 min read
Zero-Window Era: NDR Playbooks for Post-Mythos ExploitsHIGH
Industry News

Zero-Window Era: NDR Playbooks for Post-Mythos Exploits

Claude Mythos and Project Glasswing shrink exploit windows to near-zero. The Hacker News details NDR playbooks to contain AI-driven attacks before patching is possible.

2 min readClaude Mythos
TrueConf Zero-Day CVE-2026-3502 Hit Southeast Asian GovtsHIGH
Vulnerabilities

TrueConf Zero-Day CVE-2026-3502 Hit Southeast Asian Govts

Check Point Research uncovered CVE-2026-3502, a 7.8-CVSS privilege escalation in TrueConf client, exploited in targeted attacks against Southeast Asian government entities since…

CVE-2026-3502
2 min read
Interlock Ransomware Exploits Cisco FMC Zero-Day in Global AttacksCRITICAL
Threat Intel

Interlock Ransomware Exploits Cisco FMC Zero-Day in Global Attacks

The Interlock ransomware group is actively exploiting a zero-day vulnerability in Cisco Firepower Management Center to breach networks. Recorded Future identified 31 high-impact flaws in March 2026, a 139% monthly increase.

3 min readInterlock
Microsoft Windows Snipping Tool Vulnerability Enables Remote Code ExecutionHIGH
Vulnerabilities

Microsoft Windows Snipping Tool Vulnerability Enables Remote Code Execution

A vulnerability (CVE-2026-32183) in the Microsoft Windows Snipping Tool allows remote attackers to execute arbitrary code via a malicious file or webpage, requiring only user interaction to trigger the exploit.

CVE-2026-32183
4 min read
PoC Exploit Released for Critical FortiSandbox Command Injection FlawCRITICAL
Vulnerabilities

PoC Exploit Released for Critical FortiSandbox Command Injection Flaw

A proof-of-concept exploit for CVE-2026-39808, a critical command injection vulnerability in Fortinet FortiSandbox, has been released. The flaw allows unauthenticated attackers to execute arbitrary OS commands as root.

CVE-2026-39808
4 min read
Microsoft Patches Defender Zero-Day Allowing Local Privilege EscalationHIGH
Vulnerabilities

Microsoft Patches Defender Zero-Day Allowing Local Privilege Escalation

Microsoft patches CVE-2026-33825, an 'Important' zero-day flaw in the Microsoft Defender Antimalware Platform that allows local attackers to escalate privileges to SYSTEM. The vulnerability was publicly disclosed on April 14, 2026.

CVE-2026-33825
4 min read
Microsoft Confirms Active Exploitation of SharePoint Zero-Day Spoofing FlawHIGH
Vulnerabilities

Microsoft Confirms Active Exploitation of SharePoint Zero-Day Spoofing Flaw

Microsoft warns that a critical spoofing vulnerability, CVE-2026-32201, in SharePoint Server is being actively exploited. The flaw allows attackers to bypass authentication and access sensitive data.

CVE-2026-32201
4 min read
CISA Warns of Actively Exploited Windows, Adobe Acrobat VulnerabilitiesHIGH
Vulnerabilities

CISA Warns of Actively Exploited Windows, Adobe Acrobat Vulnerabilities

CISA adds two new vulnerabilities to its KEV catalog: a Windows SmartScreen bypass (CVE-2024-21412) and an Adobe Acrobat Reader code execution flaw (CVE-2024-20662), both under active exploitation.

CVE-2024-21412CVE-2024-20662
4 min read
Microsoft Patches Exploited SharePoint Zero-Day Among 161 VulnerabilitiesHIGH
Vulnerabilities

Microsoft Patches Exploited SharePoint Zero-Day Among 161 Vulnerabilities

Microsoft's April 2025 Patch Tuesday addresses 161 CVEs, including an actively exploited zero-day in SharePoint Server (CVE-2025-27088) and a critical RCE in Windows DNS (CVE-2025-27080).

CVE-2025-27088CVE-2025-27080
4 min read
Adobe Patches Acrobat Zero-Day Exploited via Malicious PDFs for MonthsCRITICAL
Vulnerabilities

Adobe Patches Acrobat Zero-Day Exploited via Malicious PDFs for Months

Adobe patches CVE-2024-34102, a critical zero-day vulnerability in Acrobat and Reader exploited via malicious PDFs for at least four months prior to discovery.

CVE-2024-34102
4 min read
CVE-2024-38112: BlueHammer PoC Escalates Windows to SYSTEMHIGH
Vulnerabilities

CVE-2024-38112: BlueHammer PoC Escalates Windows to SYSTEM

Researcher Chaotic Eclipse published a PoC for CVE-2024-38112, a Windows zero-day that grants local SYSTEM privileges, citing MS disclosure failures.

CVE-2024-38112
3 min readChaotic Eclipse
Critical PDF Zero-Day Exploited for Months, Infrastructure Espionage RevealedCRITICAL
Threat Intel

Critical PDF Zero-Day Exploited for Months, Infrastructure Espionage Revealed

A critical zero-day vulnerability in widely used PDF software has been actively exploited for months. Concurrently, state-sponsored actors have been targeting fiber optic infrastructure for espionage.

3 min read
Adobe Patches Critical Acrobat Reader Flaw Under Active ExploitationCRITICAL
Vulnerabilities

Adobe Patches Critical Acrobat Reader Flaw Under Active Exploitation

Adobe has released emergency updates for a critical vulnerability (CVE-2026-34621) in Acrobat Reader that is being actively exploited to execute arbitrary code.

CVE-2026-34621
3 min read
Stryker Hit by Cyberattack, Windows Zero-Day Exploited, China Supercomputer HackedHIGH
Threat Intel

Stryker Hit by Cyberattack, Windows Zero-Day Exploited, China Supercomputer Hacked

Medical device giant Stryker confirms a cyberattack, while a patched Windows zero-day is actively exploited and a Chinese supercomputer cluster is breached.

3 min read

Stay Updated

Get the latest cybersecurity news delivered to your inbox.