2026-07-30 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of Phoenix Contact CHARX SEC-3150 devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-44093.
P15
2026-07-30 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows network-adjacent attackers to bypass firmware validation on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-44104.
P20
2026-07-30 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows network-adjacent attackers to modify configuration on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.0. The following CVEs are assigned: CVE-2026-44101.
P15
2026-07-30 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of Phoenix Contact CHARX SEC-3150 devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-44095.
P15
2026-07-30 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of Phoenix Contact CHARX SEC-3150 devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-44096.
P15
2026-07-30 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2026-44105.
P15
2026-07-30 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows network-adjacent attackers to bypass firewall rules on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.0. The following CVEs are assigned: CVE-2026-44092.
P5
2026-07-30 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-7849.
P20
2026-07-30 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows network-adjacent attackers to bypass firewall rules on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2026-44108.
P5
2026-07-30 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of Phoenix Contact CHARX SEC-3150 devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-44106.
P15
2026-07-30 01:00 UTC
Security Journalism
Dark Reading · Robert Lemos · indexed 2026-08-15 18:55 UTC
The organized crime groups have moved from goods to services and continue to traffic people from at least 80 countries, costing nations in the region at least $88 billion in 2025 alone.
P0
2026-07-29 21:00 UTC
Vendor Research
AWS Security Blog · CJ Moses · indexed 2026-08-15 18:55 UTC
Amazon is sharing new findings about how a threat actor linked to the Democratic People’s Republic of Korea (DPRK) is targeting open source software libraries, the shared building blocks that companies around the world use to develop applications. Amazon Threat Intelligence has linked several recent compromises of popular Node Package Manager (NPM) libraries to the […]
P0
2026-07-29 16:16 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-08-15 18:55 UTC
OverviewOn July 27, 2026, JetBrains published a security advisory for CVE-2026-63077, a critical unauthenticated vulnerability affecting all versions of TeamCity On-Premises. The issue is classified as deserialization of untrusted data and has a CVSS score of 9.8. An unauthenticated remote attacker with HTTP(S) access to a TeamCity server can exploit the agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity ser…
P50
2026-07-29 16:00 UTC
Vendor Research
Google Security Blog · Alex Kilian · indexed 2026-08-15 18:55 UTC
Since its launch in 2016, OSS-Fuzz has contributed significantly to making open-source secure by finding and reporting tens of thousands of bugs. But finding more vulner…
P0
2026-07-29 16:00 UTC
Vendor Research
Microsoft Security Blog · Aarti Borkar · indexed 2026-08-15 18:55 UTC
Learn how better questions, trusted AI, and human judgment help security leaders make confident decisions and build resilient systems. The post Better security starts with better questions appeared first on Microsoft Security Blog.
P0
2026-07-29 14:53 UTC
Vendor Research
AWS Security Blog · Norbert Manthey · indexed 2026-08-15 18:55 UTC
If you use and install packages from npm or PyPI, the first hours after a package is published are the riskiest because scanners can’t analyze packages before publication. Recent supply chain events affecting NodeJS and Python packages have been detected and removed within hours. However, while those packages were available to the general public, it’s […]
P0
2026-07-29 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
We reverse-engineered MacSync, a six-stage macOS stealer and RAT, recovered from attacker infrastructure after the victim’s host was taken offline.
P0
2026-07-29 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress Webhooks push incidents and escalations straight to Slack, your PSA, or SIEM in real time with no polling. See how you can set them up in minutes.
P0
2026-07-29 13:00 UTC
Vendor Research
Rapid7 · Joel Alcon · indexed 2026-08-15 18:55 UTC
The scenario is all too familiar for any cybersecurity professional: It’s late in the day, and a critical zero-day vulnerability is disclosed. When this happens, CISOs from every industry immediately turn to their Security Operations Centers (SOC) with the single most important, and often most difficult, question: "Are we exposed?”Answering questions like these when zero-days drop tends to trigger a frantic, high-stress fire drill. Analysts scramble to cross-reference outdated Configuration Man…
P45
2026-07-29 06:40 UTC
Vendor Research
Tenable Research Advisories · Joshua Martinelle · indexed 2026-08-15 18:55 UTC
Link Library - Reflected Cross-Site Scripting The WordPress Plugin Link Library version below 7.9.4 is affected by an unauthenticated Reflected XSS.The 'thumbs_rating_add_vote' AJAX handler reads the 'likelabel' parameter without any sanitization and echoes it back into an HTML response. Joshua Martinelle Wed, 07/29/2026 - 02:40
P0
2026-07-29 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows remote attackers to create arbitrary files on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-13054.
P5
2026-07-29 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-13050.
P20
2026-07-29 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.7. The following CVEs are assigned: CVE-2026-13053.
P20
2026-07-29 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows remote attackers to escalate privileges on affected installations of TrendAI Vision One. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2025-71387.
P15
2026-07-29 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows remote attackers to disclose sensitive information on affected installations of TrendAI Vision One. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.7. The following CVEs are assigned: CVE-2025-71386.
P5
2026-07-29 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows local attackers to delete arbitrary files on affected installations of TrendLife Cleaner One Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.6. The following CVEs are assigned: CVE-2026-62660.
P5
2026-07-29 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of VMware ESXi. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2026-47876.
P15
2026-07-29 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. Interaction with the USD library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-43729.
P20
2026-07-29 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. Interaction with the USD library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-43733.
P20
2026-07-29 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-07 17:35 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. Interaction with the ImageIO library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-43780.
P20