Topic · 55 stories
Zero-day vulnerabilities: exploits and latest news
In short
A zero-day vulnerability is a software flaw unknown to the vendor that attackers can exploit before a patch exists. In 2026 many hit edge devices (Fortinet, Cisco, Citrix, F5, SonicWall), and Microsoft's September release fixed a record 974 flaws, two of them zero-days. AI is now finding such flaws too.
What is a zero-day vulnerability
A zero-day vulnerability is a software flaw unknown to its vendor that attackers can exploit before a patch exists. The name comes from the vendor having had zero days to respond. A zero-day exploit is the code that abuses such a flaw, and a zero-day attack is its use against a target.
In practice the label is looser than the definition. Microsoft classed the BitLocker flaw CVE-2026-50661 as a zero-day because it was disclosed publicly before patches shipped, although no attacks were observed. The Zimbra flaw CVE-2025-66376 was a zero-day for a Russian group until the November 2025 patch, and CISA warned of attacks on unpatched servers. When Microsoft declined to assign a CVE to a flaw in the NCSI service, ZDI published it as a 0day. Flaws confirmed as exploited are listed in CISA’s KEV catalog (as of 10 October 2026), which organizations are told to use as an input to patch prioritization and which flags flaws used in ransomware.
What a zero-day attack looks like from exploitation to patch
An attack starts with exploitation before any fix exists and ends with a patch and a KEV entry with a short deadline for agencies.
| Product | Exploited since | Fix and KEV |
|---|---|---|
| Windows afd.sys, Lazarus | at least five weeks; Check Point reported it on 28 July | patched 11 August, KEV the same day |
| PTC Windchill, Clop | from early June per Ransom-ISAC; extortion emails from 20 July | patches from 17 June, KEV 25 June |
| Metabase, CVE-2026-72898 | from 2 August, including Metabase Cloud for about four hours | patches for six branches, KEV 11 August |
| AnySign4PC (South Korea) | at least six months before the patch | version 1.1.5.0 |
Which devices and programs were attacked in 2026
Mostly edge devices and internet-facing software: firewalls, gateways, mail and print servers. A selection from recent weeks:
| Product | Flaw | Status |
|---|---|---|
| Fortinet FortiMail | CVE-2026-104286, CVSS 9.8 | exploited zero-day with no patch, none planned for 7.2; workaround: disable IBE |
| Citrix NetScaler | CVE-2026-88779 (SAML, denial of service); CVE-2026-88771, -88772 (RCE) | emergency patches in October and earlier ones in September |
| PaperCut MF | CVE-2026-82078, CVE-2026-81578 | detected on 31 August delivering an AdaptixC2 implant |
| Cisco ISE | CVE-2026-76460 | patches, no workarounds; KEV with a three-day deadline |
| Cisco Secure Email Gateway | CVE-2026-76461, CVSS 9.8 | root RCE via a crafted email; KEV, deadline 17 September |
| F5 BIG-IP APM | CVE-2026-94127 | F5 patched a zero-day used in RCE attacks; affects the OAuth authorization server setup |
| SonicWall SMA 1000 | CVE-2026-83548, CVE-2026-83549 | SonicWall patched two exploited flaws; the five latest KEV entries are all SMA 1000 |
| Magento | StyleSmuggler | StyleSmuggler exploit, no Adobe patch; attack on 4 September; mitigation: disable GraphQL |
| D-Link DIR-822A | CVE-2026-86296 | D-Link warns of an unpatched flaw, public PoC code |
Did Windows, Chrome and macOS have zero-days in 2026
Yes, all three. In July Microsoft patched a record 570 flaws, including two zero-days already exploited in Active Directory and SharePoint; the rise is attributed to an internal AI scanner called MDASH. In September came another record: 974 flaws, including two zero-days, CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in ALPC. By Ars Technica’s count Microsoft has fixed 2,760 flaws this year, more than double all of last year. Dustin Childs of ZDI thinks attackers will pair the Update Stack bug with a code-execution flaw, which can spread malware or ransomware, and advises patching fast.
The same CVE-2026-85880 ended up in the BlueMoon kit that chains three flaws: CVE-2026-85046 (V8), CVE-2026-87491 (sandbox escape) and a Windows local privilege escalation. Proofpoint has seen it since 28 August in attacks by JungleBamboo (APT31), Volexity since 1 September. Google shipped an emergency Chrome update with 12 fixes, including CVE-2026-85046. More: Chrome security. On macOS a Screen Sharing flaw was abused: the Dutch NCSC confirmed attacks planting Monero miners.
Exploits also leak. A researcher using the handle Nightmare Eclipse released FalconFlank, a CrowdStrike Falcon zero-day that gives SYSTEM privileges on up-to-date Windows. More: Windows security.
Who exploits zero-day vulnerabilities
Mostly state-backed and extortion groups. North Korea’s Lazarus used a Windows zero-day in Operation Dream Job, and Russia’s Laundry Bear stole email from Zimbra; a joint advisory from US, UK, Polish and other agencies says the group tested its methods in Ukraine before hitting NATO members. More in state-sponsored hacking.
Ransomware gangs use them too, like Clop in PTC Windchill (43 victims). ShinyHunters claims it breached the FBI through an Oracle PeopleSoft zero-day and stole 2-3 TB; the FBI confirmed it is investigating unauthorized activity around FBIjobs.gov but not a breach. Details in ShinyHunters.
Zero-day vulnerabilities and AI
AI is already finding zero-days and building exploits for them, and 2026 produced several documented cases. Qualys found RefluXFS in the Linux kernel using Claude Mythos Preview from Anthropic, which produced a working proof of concept; the bug dates to kernel 4.11 (2017), affects more than 16.4 million systems and has no workaround. An AI agent built a working exploit in four hours for a critical macOS flaw.
At Trail of Bits, GPT 5.6-Cyber escaped a QEMU/KVM virtual machine three times, and in the last run discovered and chained three previously unknown flaws. The author recommends treating such agents as an advanced persistent threat and suggests Firecracker. In October, a KVM zero-day reported by a researcher allows a VM escape to host root. More: AI-discovered vulnerabilities and frontier models breaking out in tests. The flip side is a flood of weak reports: Apple capped bug bounty submissions, so a real macOS flaw estimated at $100,000-200,000 went unreported.
What it means for you
- Take admin panels of firewalls, VPNs, mail and print servers off the internet. D-Link advises keeping affected routers off the internet, and researchers advised taking NetScaler boxes offline until patched.
- Use KEV as a priority list. Agency deadlines are often a few days, such as three days for Cisco ISE.
- Where no patch exists, apply vendor workarounds: disable IBE in FortiMail, GraphQL in Magento, the TransferFiles permission in ScreenConnect.
- After patching, check for compromise. Cisco published indicators and warns that attackers with root can remove them.
- Update your browser and OS as soon as fixes ship.
Still open: whether Fortinet will patch FortiMail 7.2 and whether the KVM flaw gets a CVE and a technical write-up. From 11 September the EU Cyber Resilience Act requires an early warning within 24 hours of learning of an exploited flaw, and Microsoft’s 13 October Patch Tuesday will be its first full cycle under the rule.
Key facts
- An independent researcher reported a KVM zero-day that lets an attacker escape a virtual machine and gain root on the host. No CVE or mechanism has been disclosed; the bounty was $50,000. (source)
- Fortinet FortiMail: the actively exploited zero-day CVE-2026-104286 (CVSS 9.8) lets unauthenticated attackers write files to the appliance. No patch yet, and none planned for the 7.2 branch. (source)
- Citrix patched two NetScaler RCE flaws (CVE-2026-88771 and CVE-2026-88772) exploited in attacks. Censys counts about 36,000 NetScaler appliances exposed to the internet. (source)
- Cisco patched the maximum-severity, actively exploited zero-day CVE-2026-76460 in Identity Services Engine. There is no workaround, and CISA gave federal agencies three days. (source)
- Microsoft's September Patch Tuesday fixes a record 974 flaws, including two zero-days already exploited: CVE-2026-81963 and CVE-2026-85880. (source)
- The BlueMoon kit chains two Chromium zero-days with a Windows local privilege escalation. Proofpoint has seen it since 28 August in attacks by a China-associated group. (source)
- Lazarus used the Windows kernel zero-day CVE-2026-68820 for at least five weeks against defense and aerospace staff. Microsoft patched it on 11 August. (source)
- Qualys disclosed RefluXFS (CVE-2026-64600), an XFS flaw giving root to a local user on more than 16.4 million systems. Anthropic's Claude Mythos Preview found it. (source)
This edition was produced with artificial intelligence. Text and voice are generated automatically.
Timeline
- Critical KVM zero-day enables full VM escape to host root Security
- Fortinet FortiMail zero-day lets attackers backdoor email gateways without a password Security
- Citrix patches NetScaler SAML zero-day exploited in attacks Security
- PaperCut MF zero-days exploited to deploy web shell and AdaptixC2 implant Security
- Unpatched Windows NCSI flaw enables privilege escalation via proxy coercion Security
- Citrix patches two NetScaler RCEs exploited in targeted attacks Security
- ShinyHunters claims FBI breach via Oracle PeopleSoft zero-day Security
- F5 patches BIG-IP APM zero-day exploited in RCE attacks Security
- Meta patches Muse zero-day that let attackers control the AI agent AI
- D-Link warns of unpatched max-severity DIR-822A router flaw Security
Show older (45 stories)
- Cisco Patches Actively Exploited Maximum-Severity ISE Zero-Day Security
- Cisco Warns Zero-Day in Secure Email Gateway Actively Exploited Security
- Microsoft ships record 974 fixes, with two zero-days already exploited Security
- BlueMoon exploit kit chains Windows and Chrome zero-days in espionage campaigns Security
- Google issues emergency Chrome update for exploited zero-day CVE-2026-85046 Security
- Magento StyleSmuggler zero-day exploited in the wild to deploy Linux backdoor Security
- ConnectWise warns of unpatched ScreenConnect file transfer vulnerability Security
- CrowdStrike Falcon Zero-Day ‘FalconFlank’ Grants SYSTEM Privileges on Up-to-Date Windows Security
- SonicWall SMA 1000 Zero-Days Under Active Attack, CISA Adds to KEV Security
- Trail of Bits: AI Agent Autonomously Discovers Zero-Days to Escape Virtual Machines Security
- AI Agent Escape: Three Attempts, Four Vulnerabilities, and a Firecracker Recommendation Security
- AI Agent Escape: OpenAI Policy Update and Mitigations Security
- AI agent builds working exploit for macOS Screen Sharing flaw in four hours AI
- Clop Ransomware Breaches Shell, GE, Philips via PTC Windchill Zero-Day Security
- macOS Screen Sharing Flaw Exploited to Mine Monero Security
- Metabase Zero-Day CVE-2026-72898 Exploited in the Wild Security
- Microsoft emergency patch closes Windows zero-day exploited by Lazarus Group Security
- Lazarus Group exploits Windows kernel zero-day for five weeks in defense sector campaign Security
- Critical Zoom Flaws Enable Zero-Click Remote Code Execution on All Platforms Security
- Apple’s bug bounty inbox is full of AI slop, real macOS flaw goes unreported AI
- State Hackers Weaponize South Korea’s Mandatory Banking Software as Zero-Day Security
- Russian Cyber-Espionage Campaign Targets US Nuclear Scientists via Zimbra Zero-Day Security
- New Lawsuit Claims Unpatchable iPhone BootROM Exploit Stolen from Magnet Forensics Security
- Russian Hackers Exploit Zimbra Zero-Click Flaw for Mass Email Theft Security
- RefluXFS Linux Flaw Allows Silent Root Takeover on 16 Million Systems Security
- FortiSandbox Exploited in Wild: Patch by Sunday or Trust Chain Collapses Security
- Firefox Exploit Code Goes Public as Chrome, Adobe, VMware Ship Emergency Patches Security
- 7-Zip XZ Parser RCE Flaw Still Unpatched Security
- BitLocker Zero-Day CVE-2026-50661 Allows Physical Bypass of Encryption Security
- Microsoft’s July Patch Tuesday Sets Record with 570 Fixes, Two Zero-Days Under Attack Security
- CISA Adds Two Critical Joomla Zero-Days to Exploited Vulnerabilities Catalog Security
- Microsoft Patches RoguePlanet Defender Zero-Day After Researcher Dispute Security
- CISA Adds Actively Exploited SharePoint RCE Flaw to KEV Catalog Security
- SimpleHelp Authentication Bypass Leads to Cross-Platform Malware Deployment Security
- CISA Warns Ransomware Gangs Exploit Microsoft Defender Privilege Escalation Flaw Security
- US Insurance Regulator Breached via Oracle Zero-Day Security
- CISA Adds Three Ubiquiti Flaws to Known Exploited Vulnerabilities Catalog Security
- RoguePlanet Zero-Day in Microsoft Defender Grants Full System Access Security
- Google Chrome 0-Day CVE-2026-11645 Exploited in the Wild Security
- Single Faulty Character in Linux Kernel Opens Sandbox Escape and Root Access Security
- ServiceNow API Endpoint Left Open Exposed Customer Data Security
- ShinyHunters Targets Oracle PeopleSoft Servers, Steals Data from Over 100 Organizations Security
- Researcher publishes seventh Windows zero-day exploit hours after Microsoft’s record Patch Tuesday Security
- Microsoft Shatters Patch Tuesday Record With Nearly 200 Fixes and Three Zero-Days Security
- Critical Check Point VPN Flaw Exploited Since Early May Security
FAQ
What is a zero-day vulnerability?
A zero-day vulnerability is a software flaw unknown to its vendor that attackers can exploit before a patch exists. The name comes from the vendor having had zero days to respond. In 2026, an example is FortiMail: the zero-day CVE-2026-104286 was exploited in attacks while no patch was available.
What is a zero-day exploit?
It is the code or technique that exploits a zero-day vulnerability. The BlueMoon kit bundles such exploits: two for Chromium-based browsers and one for the Windows kernel (CVE-2026-85880). Once the vendor ships a fix, the same flaw is no longer a zero-day.
What is a zero-day attack?
It is an intrusion that uses a zero-day vulnerability before a fix exists. Lazarus, for example, used the Windows kernel zero-day CVE-2026-68820 for at least five weeks against defense and aerospace staff in France, Germany, India and Brazil before Microsoft patched it on 11 August.
Is a zero-day still dangerous after a patch?
Yes, because many organizations do not install a patch right away. The Zimbra flaw CVE-2025-66376 had a fix from November 2025, yet in July 2026 CISA still warned that the Russian group Laundry Bear was using it against unpatched servers.
How to protect against zero-day attacks?
You cannot rule them out, but you can shorten exposure: take admin panels off the internet, patch on the day a fix ships and apply vendor workarounds when no patch exists. For FortiMail, Fortinet advises disabling IBE and restricting management access.