Cybersecurity Hacking News

Patch & zero-day surge

Patch & zero-day surge

Key Questions

What zero-day vulnerabilities are under active exploitation?

Check Point SmartConsole CVE-2026-16232 (CVSS 9.1) and FastJson 1.x RCE (CVE-2026-16723, CVSS 9.0) are being actively exploited with no patch available for FastJson. Additional threats include Certighost AD CS CVE-2026-54121 and WordPress plugin issues.

How quickly are patches now needed due to AI-driven exploits?

Patch windows have collapsed to as little as 9 hours because of AI-driven exploit generation. This shift is highlighted in the opinion piece on runtime security in the Mythos era.

What recent WordPress update addresses critical RCE flaws?

WordPress 7.0.2 patches a critical RCE chain involving CVE-2026-63030 and CVE-2026-60137 through forced auto-updates, though many sites remain vulnerable.

Which Linux kernel vulnerability remains unpatched?

CVE-2026-64425 (CVSS 9.8) in the Linux kernel io_uring/io-wq affects Debian and other distributions with no patch available yet.

What is the impact of the 7-Zip heap overflow CVE-2026-14266?

The flaw, hidden in XZ archives since 2021, allows heap-based buffer overflow with CVSS 7.8 and no auto-update mechanism, affecting users who handle crafted archives.

How many CVEs are in Oracle's July CPU release?

Oracle's July CPU addresses 1,434 CVEs across its products, contributing to the record-breaking volume of security issues this period.

What new Microsoft tools address the surge in threats?

Microsoft unveiled Project Perception and MAI-Cyber-1-Flash for agentic defense to help counter AI-accelerated exploits and technical debt risks.

Why are n-day vulnerabilities becoming n-hour threats?

AI tools now generate working exploits rapidly, turning previously slower n-day issues into immediate risks, as seen with multiple public PoCs and ransomware adoption.

Widespread exploitation of zero-days and N-days. New: macOS Screen Sharing CVE-2026-65400 (CISA KEV, active cryptomining), Kemp LoadMaster RCE (pre-auth, PoC), isolated-vm sandbox escape in AI projects. Microsoft patches 751 vulns (23 in dev tools). BOD 26-04 shifts to risk-based patching. Also: GitLab GraphQL CVE-2026-19478 (CVSS 9.4) actively exploited; NetScaler CVE-2026-19490 (CVSS 9.3) auth bypass; Oracle CSPU August 2026 with 943 CVEs; Zimbra SNMP RCE (CVE-2026-73570) under active exploitation (CERT Polska). vCenter exploited in 47-country Babuk campaign; CISA adds Windows IKE, SharePoint, vCenter, macOS Screen Sharing to KEV. GeoServer SQLi, MLflow SSRF, FUXA RCE, Windows Task Host, Apple ImageIO, Microsoft IKE. Rapid7 reports 76% YoY surge in PoC code. Additionally, a large-scale WordPress compromise campaign weaponized 2000+ sites with fake CAPTCHAs delivering multi-tool malware (ransomware, stealer, worm).

Sources (70)
Updated Aug 21, 2026
What zero-day vulnerabilities are under active exploitation? - Cybersecurity Hacking News | NBot | nbot.ai