CVE-2026-74970 · Fission site isolation bypass in Firefox WebRender
CVE-2026-74945 · Uninitialized heap disclosure via a crafted web font (sec-high)
CVE-2026-74943 · Use after free in Firefox RasterImage (sec-high)
Kernel root exploit (CVE-2026-43499) for some 5.X devices (mostly Amazon)
Linuxfabrik monitoring_plugins_6.0.0 - SSRF
flyto-core 2.26.7 - Arbitrary File Write
A poc and write-up for CVE-2026-40345
CVE-2026-68138 Linux Local Privilege Escalation Exploit
Tracking CVE-2026-68138, the Linux kernel net/sched qdisc rate-table use-after-free
iPad 8 iPadOS 26.3 AVE toolchain research (CVE-2026-64747 class)
PoC: Grafana Editor role deletes protected contact points (CVE-2026-72585, Medium 6.5)
WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload
ipTIME A3004T - Remote Code Execution
D-Link DNS_340L - OS Command Injection
Duplicati 2.2.0.3 - JWT Signing Key Leak