Zero-days
Previously unknown vulnerabilities exploited or disclosed before a patch existed.
PaperCut print servers are under active attack through a login-free code-execution flaw
Attackers are exploiting an unauthenticated flaw in PaperCut NG and MF print servers to run code as the host account. Restrict access and patch now.
GeoServer zero-day: unauthenticated SQL injection can reach remote code execution, and there is no patch yet
A GeoServer zero-day lets unauthenticated attackers run SQL injection that can reach remote code execution. No CVE, no patch, and probing has already started.
North Korea's Lazarus used fake job offers and a Windows zero-day to hijack defense firms' PCs
North Korea's Lazarus group used fake job offers and a Windows zero-day (CVE-2026-68820) to seize SYSTEM control of defense and aerospace PCs. Patch now.
Metabase zero-day (CVSS 10.0): unauthenticated SQL injection hands attackers admin and data. Patch now.
Metabase's SQL injection zero-day (CVSS 10.0) gives unauthenticated attackers admin access and stored database credentials. Exploited now: patch and rotate.
Zimbra webmail zero-day (CVE-2025-66376) let Russian spies steal mail and mint MFA-bypass passwords
Russian group Void Blizzard exploited Zimbra webmail flaw CVE-2025-66376 as a zero-day to steal 90 days of mail and mint app passwords that survive resets.
Inc ransomware used the SonicWall SMA zero-days to steal MFA seeds. Resetting passwords will not evict it.
Rapid7 ties the SonicWall SMA 1000 zero-days to an Inc ransomware actor that stole credentials, sessions, and TOTP seeds. A password reset won't evict it.
Fully patched Windows, no fix: a new local privilege zero-day
LegacyHive is a Windows User Profile Service privilege-escalation zero-day that works on fully patched systems, with no CVE and no fix yet.
Two SonicWall remote-access zero-days are under attack, and patching alone will not clean the box
SonicWall patched two actively exploited SMA 1000 zero-days, CVE-2026-15409 and CVE-2026-15410.
Two Microsoft zero-days were exploited before the fix shipped
Microsoft's July 2026 Patch Tuesday fixes two zero-days already exploited in the wild: an ADFS and a SharePoint Server privilege bug.
A logged-in user can hijack the Linux graphics server, and on many systems that means root
X.Org patched two memory-corruption bugs in the X server and XWayland. A local client can reach root where Xorg runs as root. Update to 21.1.24 and 24.1.13.
We said a password reset wouldn't stop FortiBleed. Now it is deploying ransomware.
FortiBleed harvested 110 million Fortinet credentials. SOCRadar links that access to INC and Lynx ransomware, with 12 encryptions and a Nextcloud zero-day.
Two flaws in Unraid's control panel let a logged-in user seize the whole server
Two command injection flaws in Unraid's web panel, CVE-2026-9772 and CVE-2026-9773, let any logged-in user run code as www-data.
INC ransomware never used a zero-day. It used your patch backlog.
INC reached top-tier RaaS in 2026 with no zero-days. Every edge-device flaw it exploits was patched months earlier. Here is what to actually fix.
PeopleSoft's PSEMHUB zero-day turns the patch service into the breach
CVE-2026-35273 sits in PeopleSoft's Updates Environment Management module. Mandiant ties active exploitation to ShinyHunters, with 100+ orgs already breached.
Ready to meet the Guardians?
Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.