Cybersecurity Hacking News

Patch & zero-day surge

Patch & zero-day surge

Key Questions

What zero-day vulnerabilities are under active exploitation?

Check Point SmartConsole CVE-2026-16232 (CVSS 9.1) and FastJson 1.x RCE (CVE-2026-16723, CVSS 9.0) are being actively exploited with no patch available for FastJson. Additional threats include Certighost AD CS CVE-2026-54121 and WordPress plugin issues.

How quickly are patches now needed due to AI-driven exploits?

Patch windows have collapsed to as little as 9 hours because of AI-driven exploit generation. This shift is highlighted in the opinion piece on runtime security in the Mythos era.

What recent WordPress update addresses critical RCE flaws?

WordPress 7.0.2 patches a critical RCE chain involving CVE-2026-63030 and CVE-2026-60137 through forced auto-updates, though many sites remain vulnerable.

Which Linux kernel vulnerability remains unpatched?

CVE-2026-64425 (CVSS 9.8) in the Linux kernel io_uring/io-wq affects Debian and other distributions with no patch available yet.

What is the impact of the 7-Zip heap overflow CVE-2026-14266?

The flaw, hidden in XZ archives since 2021, allows heap-based buffer overflow with CVSS 7.8 and no auto-update mechanism, affecting users who handle crafted archives.

How many CVEs are in Oracle's July CPU release?

Oracle's July CPU addresses 1,434 CVEs across its products, contributing to the record-breaking volume of security issues this period.

What new Microsoft tools address the surge in threats?

Microsoft unveiled Project Perception and MAI-Cyber-1-Flash for agentic defense to help counter AI-accelerated exploits and technical debt risks.

Why are n-day vulnerabilities becoming n-hour threats?

AI tools now generate working exploits rapidly, turning previously slower n-day issues into immediate risks, as seen with multiple public PoCs and ransomware adoption.

Widespread exploitation of zero-days and N-days. New: Ingress-NGINX CVE-2026-4342 unpatched due to EOL, permanent risk. Windows WinSock zero-day exploited by Lazarus, added to CISA KEV. Microsoft Patch Tuesday 421 CVEs including Windows IKE, SharePoint, vCenter auth bypass, Cisco hard-coded creds. Microsoft 22 fresh patches including Entra ID zero-day (CVE-2026-69836) server-side patched, plus CVSS 10.0 bugs in Azure SQL, Arc, Exchange. Google Chrome 151 critical patch for Chromoting use-after-free. GitLab CVE-2026-19478 actively exploited. Zimbra RCE (CVE-2026-73570) added to CISA KEV. TrueConf zero-days (4 critical) added to CISA KEV. MLflow SSRF, vCenter Babuk campaign, macOS Screen Sharing, Kemp LoadMaster RCE, isolated-vm sandbox escape. BOD 26-04 risk-based patching. Also: NetScaler auth bypass, Oracle CSPU 943 CVEs. Rapid7 reports 76% YoY surge in PoC code. Large-scale WordPress compromise weaponized 2000+ sites. Samsung Internet browser patch gap leaves millions exposed to N-days. New: wp2shell exploit attempts hit 45 million, confirming shrinking response window. New: SharePoint CVE-2026-55040 actively exploited (CISA KEV Aug 18, EPSS 77%) – patch now. New: Ledger bug (race condition) patched Aug 12, discovered by AI agent. New: Keycloak CVE-2026-18963 (CVSS 9.1) – unauthenticated account takeover via password reset bypass; patch in v26.7.2. New: Microsoft August Patch Tuesday includes WinSock zero-day (CVE-2026-68820) and SharePoint CVE-2026-63520. New: Hardware attack bypasses Windows security via unprotected SPD chips on consumer RAM; one-click script automates; Secure Boot mitigation but many systems vulnerable. New: WordPress plugin vulnerability allows admin account takeover. New: Microsoft reversed 'Exploited: Yes' on Entra ID flaw without explanation. New: Spring Framework 91 CVEs patched including critical RCE in GraphQL and AI prompt injection risks. New: Woo Essential plugin SQLi (CVE-2026-32551, CVSS 9.3) unpatched. New: Silent patching debate – Broadcom Spring Enterprise Repository case study highlights defender blindness.

Sources (66)
Updated Aug 25, 2026
What zero-day vulnerabilities are under active exploitation? - Cybersecurity Hacking News | NBot | nbot.ai