Zero-Day News
Latest Zero-Day news and analysis — 19 articles tagged Zero-Day on The Robotics Media.
- Meta Rushes Muse Hotfix After Zero-Day Let Local Malware Hijack Its Mac AI Agent — — Meta patched a SEV-2 zero-day in the Mac version of its Muse AI assistant on 24 September after researcher Patrick Wardle showed that any locally runn...
- Meta Hot-Fixes Muse Zero-Day That Let Local Apps Hijack Its AI Agent On Mac — — An undocumented dictation endpoint in Meta's Muse Mac agent let unprivileged local processes redirect voice traffic to attacker servers. Meta shipped...
- Cisco Ships Emergency Patch For CVSS-10 ISE Zero-Day Under Attack — — Cisco is warning customers to install emergency patches for CVE-2026-76460, a CVSS 10.0 authentication bypass in ISE that is already being exploited t...
- SonicWall Warns Of Active CVE-2026-83548 Exploit Chain On SMA1000 VPN Gateways — — SonicWall is warning SMA1000 customers to patch two new zero-days (CVE-2026-83548 and CVE-2026-83549) that attackers are chaining for unauthenticated...
- HMD Fuse Sales Paused After 'Child-Safe' Phone Exposes Live GPS And Kill-Switch Bugs — — Security researcher Paul Moore says flaws in the HMD Fuse and HarmBlock+ platform let anyone remotely track a child's live GPS, toggle apps, read mess...
- PaperCut Ships Second Emergency Patch As Zero-Day Chain Is Actively Exploited — — PaperCut Software has released a second emergency patch after confirming that two chained vulnerabilities in PaperCut NG and PaperCut MF are being act...
- Microsoft Patches Max-Severity Entra ID Flaw CVE-2026-69836 — — Microsoft on Aug 21, 2026 disclosed CVE-2026-69836, a CVSS-10.0 deserialisation flaw in Entra ID that allowed unauthenticated remote code execution; t...
- Microsoft patches 421 CVEs in August 2026 Patch Tuesday, including exploited afd.sys zero-day — — Microsoft's August 2026 Patch Tuesday resolves 421 CVEs, including CVE-2026-68820, an actively exploited use-after-free in afd.sys that grants SYSTEM...
- Arista VeloCloud Orchestrator Zero-Day CVE-2026-16812 Under Active Attack — — A maximum-severity command-injection flaw in on-prem Arista VeloCloud Orchestrator is being exploited to fully compromise SD-WAN infrastructure, with...
- Broadcom Patches Three Critical VMware Flaws, Including vCenter Auth Bypass And ESXi VM Escape — — Broadcom's VMSA-2026-0006 advisory patches five flaws across vCenter, ESXi, Workstation and Fusion. Three are rated critical, including a CVSS 9.8 vCe...
- Public GitLab RCE PoC Lets Any User Run Commands As Git Via Oj Bugs — — Security researcher Yuhang Wu published a working proof-of-concept exploit that chains two Ruby Oj parser bugs to execute code as git on unpatched sel...
- GhostLock: 15-Year-Old Linux Kernel Flaw Enables Root And Container Escape — — Nebula Security's AI agent VEGA has disclosed GhostLock (CVE-2026-43499), a 15-year-old use-after-free in Linux futex code that grants local root and...
- Microsoft Patches Record 622 CVEs, SharePoint And AD FS Zero-Days Already Exploited — — Microsoft's July 2026 Patch Tuesday shipped 622 CVEs — the largest release in company history — including two actively exploited zero-days in SharePoi...
- WordPress Force-Patches wp2shell RCE Flaw Affecting Every 6.9 And 7.0 Site — — WordPress on July 17 shipped 6.9.5 and 7.0.2 to close wp2shell, a pre-authentication remote code execution flaw in core that let an anonymous HTTP req...
- AnyDesk CVE-2026-15682 Zero-Day Lets Local Attackers Crash Remote Desktop Installs — — A zero-day flaw in AnyDesk's Send Support Information feature tracked as CVE-2026-15682 lets local attackers write arbitrary files and crash the remot...
- SonicWall SMA 1000 Zero-Days Exploited As CISA Adds July 17 Patch Deadline — — SonicWall confirmed that two SMA 1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410, are being actively exploited in the wild and can be chained...
- Microsoft Ships Record 570 Patches As AI Bug Hunting Reshapes Patch Tuesday — — Microsoft's July 2026 Patch Tuesday fixed a record 570 security flaws, including two actively exploited zero-days in AD FS and SharePoint, as AI-assis...
- Chrome 151 Ships 382 Security Fixes, Including Actively Exploited V8 Bug — — Google released Chrome 151 with 382 security fixes on July 1, 2026 — a record single-release patch that includes 15 critical bugs and the actively exp...
- Adobe Rushes ColdFusion Fixes for Seven CVSS 10.0 Flaws — — Adobe published emergency bulletin APSB26-68 patching 11 ColdFusion vulnerabilities, including seven with CVSS 10.0 that allow unauthenticated remote...