#zero-day-exploit
14 articles
News14

CVE-2026-41940: Critical cPanel Zero-Day Exploited for Months
A critical authentication bypass vulnerability in cPanel and WHM has been actively exploited since February 2026.

CISA Orders Federal Agencies to Patch Windows Zero-Day
CISA adds actively exploited Windows privilege escalation vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agency patches.

1,300+ SharePoint Servers Remain Unpatched Against Active Exploits
Over 1,300 Microsoft SharePoint servers exposed online stay vulnerable to a spoofing flaw actively exploited in ongoing attacks.

Microsoft Defender Zero-Days Under Active Attack
Threat actors are exploiting three zero-day vulnerabilities in Microsoft Defender to escalate privileges on compromised Windows systems.

Microsoft Defender Hit by Second Zero-Day in Two Weeks
Security researcher releases proof-of-concept exploit for new Microsoft Defender zero-day dubbed RedSun, marking second critical flaw disclosed this month.

Microsoft Patches 161 CVEs in Record-Breaking April Update
Microsoft's April 2026 Patch Tuesday addresses 161 vulnerabilities including an actively exploited SharePoint zero-day, marking the second-largest patch release ever.

Adobe Patches Zero-Day CVE-2026-34621 in Emergency Update
Adobe released an emergency Acrobat Reader security update fixing CVE-2026-34621, actively exploited since December 2025.

Adobe Patches Critical Acrobat Reader Zero-Day Under Attack
Adobe released emergency patches for CVE-2026-34621, a critical Acrobat Reader vulnerability actively exploited by attackers worldwide.

Adobe Reader Zero-Day Exploited via Malicious PDFs Since December
Attackers have been exploiting a zero-day vulnerability in Adobe Reader through weaponized PDF documents since December 2025.

Storm-1175 Deploys Zero-Day Exploits in Medusa Ransomware Attacks
Microsoft warns that China-based Storm-1175 cybercriminal group is deploying zero-day and n-day exploits in high-velocity Medusa ransomware campaigns targeting organizations worldwide.

Fortinet Patches Critical FortiClient EMS Zero-Day Under Attack
Fortinet released emergency patches for CVE-2026-35616, a critical FortiClient EMS vulnerability actively exploited by attackers worldwide.

Fortinet FortiClient EMS Hit by Active Zero-Day Attacks
Attackers are actively exploiting CVE-2026-21643, a critical remote code execution vulnerability in Fortinet's FortiClient EMS platform.

CISA Orders Federal Agencies to Patch Zimbra Zero-Day
CISA adds actively exploited Zimbra Collaboration Suite vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agency patches.

Interlock Ransomware Exploits Cisco FMC Zero-Day Since January
Interlock ransomware gang has been actively exploiting a critical Cisco Secure Firewall Management Center zero-day vulnerability in attacks since late January 2026.

