Active zero-day exploitation & patching crisis
Key Questions
Which VPN zero-day is under active exploitation?
Check Point VPN zero-day CVE-2026-50751 is being exploited by the Qilin affiliate, with CISA KEV deadline set for June 11.
What critical vulnerabilities were recently added to CISA KEV?
Microsoft Defender had two zero-days added and fixed; CitrixBleed 2, Android root zero-day, and active attacks on KNX smart building protocol were also listed.
How is AI affecting zero-day discovery and patching?
AI agents find bugs faster than humans can patch, with FFmpeg cited as an example of 21 bugs found for $1K compute. Darktrace reports pre-CVE detection 18 days before disclosure.
What new critical flaws were reported in services like ServiceNow and Zoom?
ServiceNow pre-auth RCE CVE-2026-6875 is exploited in the wild, and Zoom critical flaw CVE-2026-53412 allows unauthenticated account takeover.
What mitigation approaches are being recommended?
Recommendations include CISA's 3-day patch window mandate, Load-time Function Randomization, and threat-led prioritization tools like Tidal Cyber.
Check Point VPN zero-day (CVE-2026-50751) exploited by Qilin; MariaDB critical (CVSS 10.0); Chrome zero-day; Microsoft Defender zero-days; CISA 3-day patch window; Apple iOS 26.5.2 update; Tenda router backdoor; CitrixBleed 2; Android root zero-day; KNX smart building attacks; ServiceNow RCE; Zoom critical flaw; LegacyHive releases. Google doubles Chrome security patch cadence to outpace AI-driven exploits (1,072 bugs fixed in two milestones). Ransomware groups hammering VPNs, 24,650 exposed BMCs. Vulnerability disclosures on track to double; AI-discovered vulns exploited faster.