ZDI-26-492: Apple macOS ImageIO Numeric Truncation Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. Interaction with the ImageIO library... 30/07/2026 Zero-Day Initiative
ZDI-26-491: Apple macOS CoreAudio Out-Of-Bounds Write Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. User interaction is required to... 30/07/2026 Zero-Day Initiative
ZDI-26-490: (Pwn2Own) Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation Vulnerability This vulnerability allows physically present attackers to escalate privileges on affected installations of Kenwood DNR1007XR devices. An attacker must first... 30/07/2026 Zero-Day Initiative
ZDI-26-489: (Pwn2Own) Kenwood DNR1007XR startUpdateProcess Command Injection Vulnerability This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices. Authentication is not... 30/07/2026 Zero-Day Initiative
ZDI-26-488: (Pwn2Own) Kenwood DNR1007XR vCardParser Heap-based Buffer Overflow Code Execution Vulnerability This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices. Authentication is not... 30/07/2026 Zero-Day Initiative
ZDI-26-487: (Pwn2Own) Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local Privilege Escalation Vulnerability This vulnerability allows local attackers to escalate privileges on affected installations of Kenwood DNR1007XR devices. An attacker must first obtain... 30/07/2026 Zero-Day Initiative
Adobe Releases Patches for Multiple Critical Vulnerabilities Adobe released two security advisories addressing nine vulnerabilities affecting the Adobe Bridge and Adobe Format Plugins. All these vulnerabilities have critical severity ratings given by Adobe. Adobe Bridge... 29/07/2026 Qualys-Threat-Protect
ZDI-26-452: Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability This vulnerability allows remote attackers to disclose sensitive information on affected installations of Dify. User interaction is required to exploit... 24/07/2026 Zero-Day Initiative
ZDI-26-451: Docker Desktop for macOS Inference Server Permissive Allow List Sandbox Escape Vulnerability This vulnerability allows local attackers to escape the model runner sandbox on affected installations of Docker Desktop for macOS. An... 24/07/2026 Zero-Day Initiative
ZDI-26-450: AzeoTech DAQFactory CTL File Parsing Use-After-Free Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to... 24/07/2026 Zero-Day Initiative