Exploits

SonicWall Warns of Actively Exploited SMA 1000 Zero-Days as CISA Adds Flaws to KEV Catalog
SonicWall has patched two actively exploited SMA 1000 zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410. CISA added both to KEV

Windows BitLocker Zero-Day Allows Physical Bypass of Disk Encryption (CVE-2026-50661)
Microsoft fixes CVE-2026-50661, a publicly disclosed BitLocker zero-day that allows attackers with physical access to bypass Windows disk encryption

FortiSandbox Vulnerability Exposes Malware Analysis VMs Through Unauthenticated VNC Access
Fortinet has disclosed CVE-2026-59835, a high-severity FortiSandbox vulnerability that allows unauthenticated access to VNC servers of malware analysis VMs

Progress Confirms ShareFile Zero-Day Behind Emergency Storage Zone Shutdown, Releases Security Updates
Progress Software has released patches for a high-severity ShareFile Storage Zone Controller zero-day after previously urging customers to immediately shut down vulnerable Windows servers

SAP Warns of Critical NetWeaver and Commerce Cloud Vulnerabilities
SAP fixed 16 vulnerabilities in July 2026, including three critical flaws in NetWeaver ABAP, Approuter, and Commerce Cloud. Here is what to patch

GhostLock (CVE-2026-43499): a fifteen-year-old rtmutex bug just handed root to anyone with a shell
GhostLock (CVE-2026-43499) is a 15-year rtmutex use-after-free giving root to any local Linux user. Full technical breakdown of the exploit chain

Januscape (CVE-2026-53359): The 16-Year-Old KVM Bug That Lets a Guest VM Take Down Its Host
CVE-2026-53359, dubbed Januscape, is a 16-year-old KVM use-after-free letting guest VMs crash or escalate into the host. Here's the full technical breakdown

Two new Linux LPEs hit page cache from opposite ends of the kernel
Two new Linux kernel LPEs, CVE-2026-46331 (pedit COW) and CVE-2026-43503 (DirtyClone), corrupt page-cache memory to gain root without touching disk. Working exploits are public

Three Vulnerabilities, One Platform: Why Your Self-Hosted Gitea/Gogs Instance Is Probably Already Owned
Three critical Gitea and Gogs CVEs disclosed in 2026: a CVSS 9.8 auth bypass via X-WEBAUTH-USER header, a stored DOM XSS through Semantic UI's preserveHTML, and an incomplete SSRF fix exposing AWS IMDS credentials

Eight-year-old Samsung Knox flaw exposed Galaxy devices to kernel attacks
Samsung patched CVE-2026-20971, a long-running Knox PROCA use-after-free flaw that affected Galaxy devices and could lead to kernel memory corruption





