ZDI-26-546: Flowise Airtable_Agent Code Injection Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Authentication is not required to exploit... 12/08/2026 Zero-Day Initiative
ZDI-26-545: Flowise CSV_Agent customReadCSV Code Injection Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Authentication is required to exploit this... 12/08/2026 Zero-Day Initiative
ZDI-26-544: Microsoft Windows Deployment Services Use-After-Free Remote Code Execution Vulnerability This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Microsoft Windows Server. Authentication is not required... 12/08/2026 Zero-Day Initiative
ZDI-26-543: Microsoft Windows ICC File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. Interaction with the Mscms.dll color... 12/08/2026 Zero-Day Initiative
ZDI-26-542: Microsoft Windows UMPDDrvBitBlt Improper Object Management Local Privilege Escalation Vulnerability This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the... 12/08/2026 Zero-Day Initiative
Cisco Addresses Catalyst SD-WAN Software Multiple Vulnerabilities (CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, & CVE-2026-20313) Cisco released a security advisory addressing five vulnerabilities affecting Catalyst SD-WAN Software. Three of these vulnerabilities have been given a... 06/08/2026 Qualys-Threat-Protect
Cisco IOS XE Software Multiple Vulnerabilities (CVE-2026-20267, CVE-2026-20268, CVE-2026-20269, CVE-2026-20270, CVE-2026-20271, CVE-2026-20272, & CVE-2026-20273) Cisco releases security patches to address seven vulnerabilities impacting Cisco IOS XE Software. Only one of these vulnerabilities has given... 06/08/2026 Qualys-Threat-Protect
ZDI-26-526: (0Day) PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required... 06/08/2026 Zero-Day Initiative
ZDI-26-525: (0Day) PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required... 06/08/2026 Zero-Day Initiative
ZDI-26-524: (0Day) PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability This vulnerability allows network-adjacent attackers to disclose sensitive information and modify configuration on affected installations of PAX Technology Q80. Authentication... 06/08/2026 Zero-Day Initiative