Public HardBreacher Code Claims Kaspersky Privilege Escalation, but Evidence Remains Unverified
A public proof of concept called HardBreacher claims a local privilege-escalation weakness in Kaspersky Endpoint Security on Windows 11. The report remains unconfirmed, has no CVE, and is...
Critical cPanel Domain-Parking Flaw Lets Basic Users Seize Root Control
CVE-2026-65643 allows a low-privileged cPanel user with domain-parking rights to create arbitrary files and ultimately execute code as root. Hosting providers should verify patched builds immediately and restrict...
Five New TP-Link Flaws Let Attackers Hijack ISP-Managed Routers and Mesh Systems
TP-Link has disclosed five vulnerabilities affecting its carrier-supplied Aginet router, mesh, and modem lineup, the worst of which lets an attacker on the network bypass authentication entirely. Because...
Red Hat Patches Kubernetes Flaw That Let Developers Seize Full Cluster-Admin Rights
A critical privilege escalation vulnerability in Red Hat Advanced Cluster Management, tracked as CVE-2026-10090 and rated 9.9 in severity, allowed any user with basic namespace-level edit permissions to...
18-Year-Old Linux Kernel Bug Lets Attackers Seize Full Root and Break Out of Containers
A newly disclosed use-after-free vulnerability nicknamed SCTPhantom, tracked as CVE-2026-64564, traces back to Linux kernel code written in 2007 and lets a local attacker escalate to full root...
Foxit’s Own Update Service Can Be Turned Into a SYSTEM-Level Backdoor on Windows
A privilege-escalation flaw in Foxit PDF Reader's updater, tracked as CVE-2026-57239, lets an attacker who already has a foothold on a Windows machine ride the update service all...
Citrix Patches Privilege Escalation Flaw That Hands Standard Users Full SYSTEM Control
Cloud Software Group has disclosed two vulnerabilities in Citrix Secure Access and Endpoint Analysis clients for Windows, including a high-severity flaw (CVSS 8.5) that lets a low-privileged local...
Unpatched LegacyHive Bug Lets Standard Windows Users Hijack Admin Accounts
A newly disclosed Windows zero-day called LegacyHive abuses the User Profile Service to let a low-privileged user tamper with an administrator's registry hive, opening a path to persistence...