This day 02:02 06:02 10:02 14:03 18:03 22:04
⚠ exploit status: CVE-2026-59310 · KEV·R
Info  2026-08-17 14:03Z · last 4h · 37 findings · glm-5.2:cloud

Threat Brief — 2026-08-17 — Zero-Days Outpace Patches

Executive summary: Multiple unpatched zero-days are under active exploitation today — GeoServer SQLi-to-RCE and a WordPress XSS2Shell flaw affecting 11,000+ sites lead the pack. A China-nexus APT is chaining a VMware vCenter flaw into Babuk-derived ransomware, while the PATCHCORD backdoor quietly targets South Asian critical infrastructure. On the mobile front, an Unisoc VoLTE exploit chain grants full Android kernel access with no vendor fix, and the DragonDoll spyware campaign has spread across 26 countries. Enterprise AI adopters should note a new MCP server secret-exposure advisory and the first court precedent punishing hidden prompt injection in legal filings.

Top items

Themes

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db