Eight exploited CVEs hit Linux, F5, Check Point, Arista and Zyxel
A single day's CVE roundup lists eight vulnerabilities as confirmed exploited, and most sit in infrastructure that security teams rely on for control and visibility. Here is how to triage them.
CISA KEV adds Cisco ISE and Acronis Backup flaws: what defenders should patch first
CISA has added CVE-2026-76460 (Cisco Identity Services Engine) and CVE-2026-87886 (Acronis Backup) to its Known Exploited Vulnerabilities catalog. Both sit in infrastructure that attackers value: network access control and backup.
VM Escape via VMXNET3: Critical VMware Workstation/Fusion Flaw Patched
Broadcom has patched a critical integer-overflow bug in VMware Workstation and Fusion that lets an attacker with admin rights inside a VM run code on the host — plus a related HGFS buffer overflow. Neither is remotely exploitable, but both break the guest/host boundary that desktop virtualization depends on.
PostgreSQL Patches 12-Year-Old Logical Decoding Flaw (CVE-2026-6471)
A missing authorization check in PostgreSQL's logical decoding, present since 2014, let any account with the REPLICATION attribute run arbitrary code as the database's OS user. Patches shipped August 13, 2026.
Patch Discussion to Exploit Probe: Now Measured in Minutes, Not Days
Maintainers are reporting that automated attackers are weaponising vulnerability rumours before a patch even ships — collapsing the gap between disclosure and exploitation from days to minutes.
ServiceNow AI Platform Flaw (CVE-2026-6875) Now Under Active Exploitation
A pre-authentication sandbox-escape bug in ServiceNow's AI Platform is being exploited in the wild via a second gadget chain, weeks after a patch and public disclosure.
CVE-2026-14266: 7-Zip Heap Overflow in XZ Parsing Fixed in 26.02
A heap-based buffer overflow in 7-Zip's XZ decoder let a crafted archive corrupt memory on extraction. The fix landed quietly in June; ZDI's July 15 advisory is why you're hearing about it now.
OpenSSL's HollowByte DoS Flaw Shipped With No CVE — Here's Why That Matters
An 11-byte TLS handshake header can lock up hundreds of megabytes of server memory before authentication even starts. OpenSSL fixed it in June 2026 without a CVE, an advisory, or a changelog entry.