Cybersecurity Hacking News

Active zero-day exploitation & patching crisis

Active zero-day exploitation & patching crisis

Key Questions

Which VPN zero-day is under active exploitation?

Check Point VPN zero-day CVE-2026-50751 is being exploited by the Qilin affiliate, with CISA KEV deadline set for June 11.

What critical vulnerabilities were recently added to CISA KEV?

Microsoft Defender had two zero-days added and fixed; CitrixBleed 2, Android root zero-day, and active attacks on KNX smart building protocol were also listed.

How is AI affecting zero-day discovery and patching?

AI agents find bugs faster than humans can patch, with FFmpeg cited as an example of 21 bugs found for $1K compute. Darktrace reports pre-CVE detection 18 days before disclosure.

What new critical flaws were reported in services like ServiceNow and Zoom?

ServiceNow pre-auth RCE CVE-2026-6875 is exploited in the wild, and Zoom critical flaw CVE-2026-53412 allows unauthenticated account takeover.

What mitigation approaches are being recommended?

Recommendations include CISA's 3-day patch window mandate, Load-time Function Randomization, and threat-led prioritization tools like Tidal Cyber.

Check Point VPN zero-day (CVE-2026-50751) exploited by Qilin; MariaDB critical (CVSS 10.0); Chrome zero-day; Microsoft Defender zero-days; CISA 3-day patch window; Apple iOS 26.5.2 update; Tenda router backdoor; CitrixBleed 2; Android root zero-day; KNX smart building attacks; ServiceNow RCE; Zoom critical flaw; LegacyHive releases. Google doubles Chrome security patch cadence to outpace AI-driven exploits (1,072 bugs fixed in two milestones). Ransomware groups hammering VPNs, 24,650 exposed BMCs. Vulnerability disclosures on track to double; AI-discovered vulns exploited faster.

Sources (8)
Updated Jul 31, 2026