Skip to content
tag — zero-day

grep -rl "zero-day" ./articles

#zero-day

13 articles

974 flaws, and the two that matter are both privilege escalation

2026-09-09Security

Microsoft patched 974 vulnerabilities in September, a 70% jump over the previous record, with 723 of them in Windows and more than 110 rated critical. Two are being exploited. Both are CVSS 7.8 local privilege escalation, which means the attacker is already on the machine — and that is the whole triage.

One researcher dropped three exploits. Only Gen Digital has shipped a fix

2026-09-08Security

PrettyPrague, FalconFlank and GreenSection target Avast's sandbox, CrowdStrike Falcon's macro remediation and NVIDIA's display driver. Gen Digital has patched. CrowdStrike's advice is to turn the affected protection off. NVIDIA is still investigating. And the FalconFlank claim this site called single-source last week now has independent confirmation.

Adobe has patched StyleSmuggler. The first confirmed victim was fully patched too

2026-09-08Security

CVE-2026-75650 is rated CVSS 10.0 and Adobe shipped the fix on 8 September, four days into active exploitation. Applying it is only half the remediation — the encryption keys have to be rotated as well. And the first confirmed victim was already running the August patches, which is why patching is not the same as being clear.

A Chrome V8 zero-day paid $1,000. The lowest published tier is $7,000

2026-09-07Security

CVE-2026-85046 is a V8 type confusion, rated 8.8, exploited in the wild, and the sixth actively exploited Chrome zero-day of 2026. It was reported on 4 August and awarded $1,000 — an amount that does not appear anywhere on Chrome's published memory-corruption reward schedule. Several explanations fit. Google has offered none.

PaperCut is being exploited, and one of the signs is that your log file is missing

2026-08-29Security

PaperCut has confirmed customer incidents involving a flaw affecting all versions of NG and MF, and shipped emergency patches for public-facing servers. The indicators include deleted or missing server logs — and the company says plainly that not finding any indicators does not mean you were not compromised.