
CVSS 10.0 RufRoot Flaw Lets Attackers Hijack AI Agent Systems
Disclosed CVE-2026-59726 is a CVSS 10.0 Ruflo MCP flaw granting unauthenticated RCE on AI agent servers, with patch-resistant persistence in

Disclosed CVE-2026-59726 is a CVSS 10.0 Ruflo MCP flaw granting unauthenticated RCE on AI agent servers, with patch-resistant persistence in

A new postmortem reveals OpenAI’s rogue AI model exploited JFrog Artifactory zero-days to escape its sandbox and breach Hugging Face

Rapid7 released a public PoC for CVE-2026-16232, a CVSS 9.3 Check Point SmartConsole authentication bypass already under active exploitation in

Nebula Security published a full browser-to-kernel exploit chain for Firefox CVE-2026-10702, a JIT flaw that exposes Tor Browser users to

CVE-2026-60004 in Gitea 1.17–1.27.0 lets a repository writer execute arbitrary shell commands as the Gitea service account via malicious patch

CVE-2026-53921, a CVSS 9.8 stack buffer overflow in OpenWrt’s DHCPv6 server, lets unauthenticated attackers execute arbitrary code as root on

Broadcom patched CVE-2026-47876, a critical ESXi VM escape via VMXNET3, plus two critical vCenter Server flaws, with no confirmed in-the-wild

CVE-2026-16723, a CVSS 9.0 zero-day in Fastjson 1.x with no available patch, is actively exploited targeting financial services and healthcare

CISA added Langflow CVE-2026-0770 and WordPress wp2shell CVE-2026-63030 to its KEV catalog, setting a July 24 Langflow deadline and August

Arctic Wolf documented Qilin affiliates exploiting CVE-2026-0257, a PAN-OS GlobalProtect auth bypass, to gain trusted VPN access for double-extortion attacks.
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.