ZDI-26-619: Microsoft Windows UMPDDrvStretchBltROP Improper Object Management Local Privilege Escalation Vulnerability This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the... 09/09/2026 Zero-Day Initiative
ZDI-26-618: Microsoft Windows UMPDDrvStretchBlt Improper Object Management Local Privilege Escalation Vulnerability This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the... 09/09/2026 Zero-Day Initiative
ZDI-26-617: Microsoft Windows MIDI Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the... 09/09/2026 Zero-Day Initiative
ZDI-26-616: Koha Eval Code Injection Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Koha. Authentication is required to exploit this... 09/09/2026 Zero-Day Initiative
Google Chrome Zero-day Vulnerability Exploited in the Wild (CVE-2026-85046) Google released security updates to address 12 vulnerabilities impacting the Chrome browser. One of these vulnerabilities, tracked as CVE-2026-85046, is... 07/09/2026 Qualys-Threat-Protect
CISA Warns of SonicWall SMA1000 Vulnerabilities Active Exploitation (CVE-2026-83548 & CVE-2026-83549) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns users about the active exploitation of two vulnerabilities affecting the SonicWall... 03/09/2026 Qualys-Threat-Protect
CISA Added JFrog Artifactory Vulnerability to its Known Exploited Vulnerabilities Catalog (CVE-2026-82329) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns users about the active exploitation of a vulnerability impacting JFrog Artifactory,... 03/09/2026 Qualys-Threat-Protect
Langflow Remote Code Execution Vulnerability Exploited in Attacks (CVE-2026-0768) A vulnerability impacting Langflow is being exploited in the wild. Tracked as CVE-2026-0768, the vulnerability has a critical severity rating with a CVSS score of 9.8.... 02/09/2026 Qualys-Threat-Protect
ZDI-26-615: (0Day) pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architect. An attacker must first obtain... 01/09/2026 Zero-Day Initiative
ZDI-26-614: (0Day) pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required... 01/09/2026 Zero-Day Initiative