HeadFlash

Topic · 55 stories

Zero-day vulnerabilities: exploits and latest news

Updated · Edited by Marcin Rybak

In short

A zero-day vulnerability is a software flaw unknown to the vendor that attackers can exploit before a patch exists. In 2026 many hit edge devices (Fortinet, Cisco, Citrix, F5, SonicWall), and Microsoft's September release fixed a record 974 flaws, two of them zero-days. AI is now finding such flaws too.

What is a zero-day vulnerability

A zero-day vulnerability is a software flaw unknown to its vendor that attackers can exploit before a patch exists. The name comes from the vendor having had zero days to respond. A zero-day exploit is the code that abuses such a flaw, and a zero-day attack is its use against a target.

In practice the label is looser than the definition. Microsoft classed the BitLocker flaw CVE-2026-50661 as a zero-day because it was disclosed publicly before patches shipped, although no attacks were observed. The Zimbra flaw CVE-2025-66376 was a zero-day for a Russian group until the November 2025 patch, and CISA warned of attacks on unpatched servers. When Microsoft declined to assign a CVE to a flaw in the NCSI service, ZDI published it as a 0day. Flaws confirmed as exploited are listed in CISA’s KEV catalog (as of 10 October 2026), which organizations are told to use as an input to patch prioritization and which flags flaws used in ransomware.

What a zero-day attack looks like from exploitation to patch

An attack starts with exploitation before any fix exists and ends with a patch and a KEV entry with a short deadline for agencies.

Product Exploited since Fix and KEV
Windows afd.sys, Lazarus at least five weeks; Check Point reported it on 28 July patched 11 August, KEV the same day
PTC Windchill, Clop from early June per Ransom-ISAC; extortion emails from 20 July patches from 17 June, KEV 25 June
Metabase, CVE-2026-72898 from 2 August, including Metabase Cloud for about four hours patches for six branches, KEV 11 August
AnySign4PC (South Korea) at least six months before the patch version 1.1.5.0

Which devices and programs were attacked in 2026

Mostly edge devices and internet-facing software: firewalls, gateways, mail and print servers. A selection from recent weeks:

Product Flaw Status
Fortinet FortiMail CVE-2026-104286, CVSS 9.8 exploited zero-day with no patch, none planned for 7.2; workaround: disable IBE
Citrix NetScaler CVE-2026-88779 (SAML, denial of service); CVE-2026-88771, -88772 (RCE) emergency patches in October and earlier ones in September
PaperCut MF CVE-2026-82078, CVE-2026-81578 detected on 31 August delivering an AdaptixC2 implant
Cisco ISE CVE-2026-76460 patches, no workarounds; KEV with a three-day deadline
Cisco Secure Email Gateway CVE-2026-76461, CVSS 9.8 root RCE via a crafted email; KEV, deadline 17 September
F5 BIG-IP APM CVE-2026-94127 F5 patched a zero-day used in RCE attacks; affects the OAuth authorization server setup
SonicWall SMA 1000 CVE-2026-83548, CVE-2026-83549 SonicWall patched two exploited flaws; the five latest KEV entries are all SMA 1000
Magento StyleSmuggler StyleSmuggler exploit, no Adobe patch; attack on 4 September; mitigation: disable GraphQL
D-Link DIR-822A CVE-2026-86296 D-Link warns of an unpatched flaw, public PoC code

Did Windows, Chrome and macOS have zero-days in 2026

Yes, all three. In July Microsoft patched a record 570 flaws, including two zero-days already exploited in Active Directory and SharePoint; the rise is attributed to an internal AI scanner called MDASH. In September came another record: 974 flaws, including two zero-days, CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in ALPC. By Ars Technica’s count Microsoft has fixed 2,760 flaws this year, more than double all of last year. Dustin Childs of ZDI thinks attackers will pair the Update Stack bug with a code-execution flaw, which can spread malware or ransomware, and advises patching fast.

The same CVE-2026-85880 ended up in the BlueMoon kit that chains three flaws: CVE-2026-85046 (V8), CVE-2026-87491 (sandbox escape) and a Windows local privilege escalation. Proofpoint has seen it since 28 August in attacks by JungleBamboo (APT31), Volexity since 1 September. Google shipped an emergency Chrome update with 12 fixes, including CVE-2026-85046. More: Chrome security. On macOS a Screen Sharing flaw was abused: the Dutch NCSC confirmed attacks planting Monero miners.

Exploits also leak. A researcher using the handle Nightmare Eclipse released FalconFlank, a CrowdStrike Falcon zero-day that gives SYSTEM privileges on up-to-date Windows. More: Windows security.

Who exploits zero-day vulnerabilities

Mostly state-backed and extortion groups. North Korea’s Lazarus used a Windows zero-day in Operation Dream Job, and Russia’s Laundry Bear stole email from Zimbra; a joint advisory from US, UK, Polish and other agencies says the group tested its methods in Ukraine before hitting NATO members. More in state-sponsored hacking.

Ransomware gangs use them too, like Clop in PTC Windchill (43 victims). ShinyHunters claims it breached the FBI through an Oracle PeopleSoft zero-day and stole 2-3 TB; the FBI confirmed it is investigating unauthorized activity around FBIjobs.gov but not a breach. Details in ShinyHunters.

Zero-day vulnerabilities and AI

AI is already finding zero-days and building exploits for them, and 2026 produced several documented cases. Qualys found RefluXFS in the Linux kernel using Claude Mythos Preview from Anthropic, which produced a working proof of concept; the bug dates to kernel 4.11 (2017), affects more than 16.4 million systems and has no workaround. An AI agent built a working exploit in four hours for a critical macOS flaw.

At Trail of Bits, GPT 5.6-Cyber escaped a QEMU/KVM virtual machine three times, and in the last run discovered and chained three previously unknown flaws. The author recommends treating such agents as an advanced persistent threat and suggests Firecracker. In October, a KVM zero-day reported by a researcher allows a VM escape to host root. More: AI-discovered vulnerabilities and frontier models breaking out in tests. The flip side is a flood of weak reports: Apple capped bug bounty submissions, so a real macOS flaw estimated at $100,000-200,000 went unreported.

What it means for you

  • Take admin panels of firewalls, VPNs, mail and print servers off the internet. D-Link advises keeping affected routers off the internet, and researchers advised taking NetScaler boxes offline until patched.
  • Use KEV as a priority list. Agency deadlines are often a few days, such as three days for Cisco ISE.
  • Where no patch exists, apply vendor workarounds: disable IBE in FortiMail, GraphQL in Magento, the TransferFiles permission in ScreenConnect.
  • After patching, check for compromise. Cisco published indicators and warns that attackers with root can remove them.
  • Update your browser and OS as soon as fixes ship.

Still open: whether Fortinet will patch FortiMail 7.2 and whether the KVM flaw gets a CVE and a technical write-up. From 11 September the EU Cyber Resilience Act requires an early warning within 24 hours of learning of an exploited flaw, and Microsoft’s 13 October Patch Tuesday will be its first full cycle under the rule.

Key facts

  • An independent researcher reported a KVM zero-day that lets an attacker escape a virtual machine and gain root on the host. No CVE or mechanism has been disclosed; the bounty was $50,000. (source)
  • Fortinet FortiMail: the actively exploited zero-day CVE-2026-104286 (CVSS 9.8) lets unauthenticated attackers write files to the appliance. No patch yet, and none planned for the 7.2 branch. (source)
  • Citrix patched two NetScaler RCE flaws (CVE-2026-88771 and CVE-2026-88772) exploited in attacks. Censys counts about 36,000 NetScaler appliances exposed to the internet. (source)
  • Cisco patched the maximum-severity, actively exploited zero-day CVE-2026-76460 in Identity Services Engine. There is no workaround, and CISA gave federal agencies three days. (source)
  • Microsoft's September Patch Tuesday fixes a record 974 flaws, including two zero-days already exploited: CVE-2026-81963 and CVE-2026-85880. (source)
  • The BlueMoon kit chains two Chromium zero-days with a Windows local privilege escalation. Proofpoint has seen it since 28 August in attacks by a China-associated group. (source)
  • Lazarus used the Windows kernel zero-day CVE-2026-68820 for at least five weeks against defense and aerospace staff. Microsoft patched it on 11 August. (source)
  • Qualys disclosed RefluXFS (CVE-2026-64600), an XFS flaw giving root to a local user on more than 16.4 million systems. Anthropic's Claude Mythos Preview found it. (source)

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Timeline

  1. Critical KVM zero-day enables full VM escape to host root Security
  2. Fortinet FortiMail zero-day lets attackers backdoor email gateways without a password Security
  3. Citrix patches NetScaler SAML zero-day exploited in attacks Security
  4. PaperCut MF zero-days exploited to deploy web shell and AdaptixC2 implant Security
  5. Unpatched Windows NCSI flaw enables privilege escalation via proxy coercion Security
  6. Citrix patches two NetScaler RCEs exploited in targeted attacks Security
  7. ShinyHunters claims FBI breach via Oracle PeopleSoft zero-day Security
  8. F5 patches BIG-IP APM zero-day exploited in RCE attacks Security
  9. Meta patches Muse zero-day that let attackers control the AI agent AI
  10. D-Link warns of unpatched max-severity DIR-822A router flaw Security
Show older (45 stories)
  1. Cisco Patches Actively Exploited Maximum-Severity ISE Zero-Day Security
  2. Cisco Warns Zero-Day in Secure Email Gateway Actively Exploited Security
  3. Microsoft ships record 974 fixes, with two zero-days already exploited Security
  4. BlueMoon exploit kit chains Windows and Chrome zero-days in espionage campaigns Security
  5. Google issues emergency Chrome update for exploited zero-day CVE-2026-85046 Security
  6. Magento StyleSmuggler zero-day exploited in the wild to deploy Linux backdoor Security
  7. ConnectWise warns of unpatched ScreenConnect file transfer vulnerability Security
  8. CrowdStrike Falcon Zero-Day ‘FalconFlank’ Grants SYSTEM Privileges on Up-to-Date Windows Security
  9. SonicWall SMA 1000 Zero-Days Under Active Attack, CISA Adds to KEV Security
  10. Trail of Bits: AI Agent Autonomously Discovers Zero-Days to Escape Virtual Machines Security
  11. AI Agent Escape: Three Attempts, Four Vulnerabilities, and a Firecracker Recommendation Security
  12. AI Agent Escape: OpenAI Policy Update and Mitigations Security
  13. AI agent builds working exploit for macOS Screen Sharing flaw in four hours AI
  14. Clop Ransomware Breaches Shell, GE, Philips via PTC Windchill Zero-Day Security
  15. macOS Screen Sharing Flaw Exploited to Mine Monero Security
  16. Metabase Zero-Day CVE-2026-72898 Exploited in the Wild Security
  17. Microsoft emergency patch closes Windows zero-day exploited by Lazarus Group Security
  18. Lazarus Group exploits Windows kernel zero-day for five weeks in defense sector campaign Security
  19. Critical Zoom Flaws Enable Zero-Click Remote Code Execution on All Platforms Security
  20. Apple’s bug bounty inbox is full of AI slop, real macOS flaw goes unreported AI
  21. State Hackers Weaponize South Korea’s Mandatory Banking Software as Zero-Day Security
  22. Russian Cyber-Espionage Campaign Targets US Nuclear Scientists via Zimbra Zero-Day Security
  23. New Lawsuit Claims Unpatchable iPhone BootROM Exploit Stolen from Magnet Forensics Security
  24. Russian Hackers Exploit Zimbra Zero-Click Flaw for Mass Email Theft Security
  25. RefluXFS Linux Flaw Allows Silent Root Takeover on 16 Million Systems Security
  26. FortiSandbox Exploited in Wild: Patch by Sunday or Trust Chain Collapses Security
  27. Firefox Exploit Code Goes Public as Chrome, Adobe, VMware Ship Emergency Patches Security
  28. 7-Zip XZ Parser RCE Flaw Still Unpatched Security
  29. BitLocker Zero-Day CVE-2026-50661 Allows Physical Bypass of Encryption Security
  30. Microsoft’s July Patch Tuesday Sets Record with 570 Fixes, Two Zero-Days Under Attack Security
  31. CISA Adds Two Critical Joomla Zero-Days to Exploited Vulnerabilities Catalog Security
  32. Microsoft Patches RoguePlanet Defender Zero-Day After Researcher Dispute Security
  33. CISA Adds Actively Exploited SharePoint RCE Flaw to KEV Catalog Security
  34. SimpleHelp Authentication Bypass Leads to Cross-Platform Malware Deployment Security
  35. CISA Warns Ransomware Gangs Exploit Microsoft Defender Privilege Escalation Flaw Security
  36. US Insurance Regulator Breached via Oracle Zero-Day Security
  37. CISA Adds Three Ubiquiti Flaws to Known Exploited Vulnerabilities Catalog Security
  38. RoguePlanet Zero-Day in Microsoft Defender Grants Full System Access Security
  39. Google Chrome 0-Day CVE-2026-11645 Exploited in the Wild Security
  40. Single Faulty Character in Linux Kernel Opens Sandbox Escape and Root Access Security
  41. ServiceNow API Endpoint Left Open Exposed Customer Data Security
  42. ShinyHunters Targets Oracle PeopleSoft Servers, Steals Data from Over 100 Organizations Security
  43. Researcher publishes seventh Windows zero-day exploit hours after Microsoft’s record Patch Tuesday Security
  44. Microsoft Shatters Patch Tuesday Record With Nearly 200 Fixes and Three Zero-Days Security
  45. Critical Check Point VPN Flaw Exploited Since Early May Security

FAQ

What is a zero-day vulnerability?

A zero-day vulnerability is a software flaw unknown to its vendor that attackers can exploit before a patch exists. The name comes from the vendor having had zero days to respond. In 2026, an example is FortiMail: the zero-day CVE-2026-104286 was exploited in attacks while no patch was available.

What is a zero-day exploit?

It is the code or technique that exploits a zero-day vulnerability. The BlueMoon kit bundles such exploits: two for Chromium-based browsers and one for the Windows kernel (CVE-2026-85880). Once the vendor ships a fix, the same flaw is no longer a zero-day.

What is a zero-day attack?

It is an intrusion that uses a zero-day vulnerability before a fix exists. Lazarus, for example, used the Windows kernel zero-day CVE-2026-68820 for at least five weeks against defense and aerospace staff in France, Germany, India and Brazil before Microsoft patched it on 11 August.

Is a zero-day still dangerous after a patch?

Yes, because many organizations do not install a patch right away. The Zimbra flaw CVE-2025-66376 had a fix from November 2025, yet in July 2026 CISA still warned that the Russian group Laundry Bear was using it against unpatched servers.

How to protect against zero-day attacks?

You cannot rule them out, but you can shorten exposure: take admin panels off the internet, patch on the day a fix ships and apply vendor workarounds when no patch exists. For FortiMail, Fortinet advises disabling IBE and restricting management access.