Radar
A personal hobby project. Radar aggregates security advisories from CISA, Zero Day Initiative and CERT-EU and adds short editorial highlights on what I find notable from a European infrastructure perspective — not a threat-intel service, not exhaustive, just what catches my eye.
-
ZDI-26-568: Linux Kernel Net Scheduler Race Condition Local Privilege Escalation Vulnerability
A race condition in the Linux kernel net scheduler can be leveraged for local privilege escalation. CVSS is rated 7.5.
Read more → -
ZDI-26-569: Linux Kernel Net Scheduler True Link Equalizer Race Condition Local Privilege Escalation Vulnerability
A race condition in the Linux kernel’s Net Scheduler True Link Equalizer can be used for local privilege escalation.
Read more → -
ZDI-26-570: Linux Kernel IGMP Subsystem Race Condition Local Privilege Escalation Vulnerability
The advisory identifies a race condition in the Linux kernel's IGMP subsystem that can be used for local privilege escalation.
Read more → -
ZDI-26-571: Linux Kernel Net Scheduler Packet Classifier API Use-After-Free Local Privilege Escalation Vulnerability
The flaw is a use-after-free in the Linux kernel’s Net Scheduler packet classifier API. It enables local privilege escalation after low-privilege code execution.
Read more → -
ZDI-26-572: Linux Kernel XFRM Race Condition Local Privilege Escalation Vulnerability
The advisory notes a race condition in the Linux kernel XFRM subsystem that can be leveraged for local privilege escalation.
Read more → -
ZDI-26-573: Linux Kernel KSMBD Response Header Out-Of-Bounds Read Information Disclosure Vulnerability
An out-of-bounds read in ksmbd response header handling can disclose information without authentication.
Read more → -
ZDI-26-574: Linux Kernel Net Scheduler Connection Tracking Race Condition Local Privilege Escalation Vulnerability
The issue is a race condition in the Linux kernel net scheduler connection tracking code. It enables local privilege escalation.
Read more → -
ZDI-26-575: Linux Kernel Net Scheduler Packet Classifier API Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability
The vulnerability is a local TOCTOU privilege escalation in the Linux kernel's Net Scheduler packet classifier API.
Read more → -
ZDI-26-576: Linux Kernel XFRM Race Condition Local Privilege Escalation Vulnerability
The advisory notes a race condition in the Linux kernel's XFRM subsystem that can be exploited for local privilege escalation.
Read more → -
ZDI-26-577: Trend Micro VPN OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
Trend Micro VPN contains an uncontrolled OpenSSL search path element that enables local privilege escalation.
Read more → -
ZDI-26-578: NGINX HTTP Dav Module Alias Directive Integer Underflow Remote Code Execution Vulnerability
The advisory notes an integer underflow in the NGINX HTTP Dav module’s alias directive.
Read more → -
ZDI-26-579: Cisco Identity Services Engine zipFiles Directory Traversal Remote Code Execution Vulnerability
Exploitation requires valid authentication and leverages a directory traversal in the zipFiles component.
Read more → -
ZDI-26-580: Cisco Identity Services Engine Missing Authentication for Critical Function Information Disclosure Vulnerability
Authentication is not required to retrieve sensitive information from Cisco Identity Services Engine.
Read more → -
ZDI-26-581: Cisco Identity Services Engine invokeScript Command Injection Remote Code Execution Vulnerability
Remote code execution is possible via an authenticated invokeScript command injection.
Read more → -
ZDI-26-582: Cisco Identity Services Engine PatchUpdateListener Directory Traversal Information Disclosure Vulnerability
Remote authenticated attackers can exploit a directory traversal in PatchUpdateListener to disclose sensitive information.
Read more → -
ZDI-26-583: Clam AntiVirus 7z Archive Parsing Integer Overflow Remote Code Execution Vulnerability
Clam AntiVirus 7z archive parsing contains an integer overflow that can be remotely triggered.
Read more → -
ZDI-26-584: dnsmasq DNSSEC NSEC/NSEC3 Type Bitmap Processing Infinite Loop Denial-of-Service Vulnerability
dnsmasq can enter an infinite loop while processing DNSSEC NSEC/NSEC3 type bitmap, causing a denial of service.
Read more → -
ZDI-26-564: NVIDIA Transformers4Rec load_model_trainer_states_from_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability
Remote code execution is possible via deserialization of untrusted data in Transformers4Rec's load_model_trainer_states_from_checkpoint function.
Read more → -
ZDI-26-565: Gen Digital CCleaner Link Following Local Privilege Escalation Vulnerability
Local privilege escalation in Gen Digital CCleaner (CVE-2026-12410) with CVSS 7.8.
Read more → -
ZDI-26-566: BlackBerry QNX KEV File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Exploitation requires the victim to open a malicious file or visit a malicious web page.
Read more → -
ZDI-26-567: Norton Utilities Ultimate NortonUtilitiesSvc Link Following Local Privilege Escalation Vulnerability
The vulnerability enables local privilege escalation via the NortonUtilitiesSvc component.
Read more → -
ZDI-26-557: (Pwn2Own) Amazon Smart Plug Insecure Fallback Information Disclosure Vulnerability
Unauthenticated network-adjacent attackers can retrieve sensitive information from Amazon Smart Plug devices.
Read more → -
ZDI-26-558: (Pwn2Own) Amazon Smart Plug OTA Update Process Improper Certificate Validation Vulnerability
Network-adjacent attackers can bypass certificate validation for OTA updates on Amazon Smart Plug.
Read more → -
ZDI-26-559: (Pwn2Own) Amazon Smart Plug OTA Update Process Out-Of-Bounds Write Remote Code Execution Vulnerability
Unauthenticated attackers on the same network can trigger an out-of-bounds write via the OTA update process.
Read more → -
ZDI-26-560: (Pwn2Own) Home Assistant Green go2rtc Command Injection Remote Code Execution Vulnerability
The vulnerability enables remote code execution after an attacker reaches the localhost interface.
Read more → -
ZDI-26-561: (Pwn2Own) Home Assistant Green go2rtc Command Injection Remote Code Execution Vulnerability
The Home Assistant Green device is vulnerable to command injection. This allows for remote code execution.
Read more → -
ZDI-26-562: (Pwn2Own) Home Assistant Green mDNS Server-Side Request Forgery Vulnerability
Home Assistant Green's mDNS server-side request forgery vulnerability allows network-adjacent attackers to initiate arbitrary server-side requests. Authentication is not required.
Read more → -
ZDI-26-563: (Pwn2Own) Home Assistant Green Simple Service Discovery Protocol Server-Side Request Forgery Vulnerability
Unauthenticated network-adjacent attackers can trigger arbitrary server-side requests via Home Assistant Green's Simple Service Discovery Protocol server.
Read more → -
ZDI-26-542: Microsoft Windows UMPDDrvBitBlt Improper Object Management Local Privilege Escalation Vulnerability
Local attackers can exploit an improper object management flaw in UMPDDrvBitBlt to gain higher privileges.
Read more → -
ZDI-26-543: Microsoft Windows ICC File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Exploitation requires interaction with the Mscms.dll color management library.
Read more → -
ZDI-26-544: Microsoft Windows Deployment Services Use-After-Free Remote Code Execution Vulnerability
A use-after-free in Windows Deployment Services can be triggered without authentication by a network-adjacent attacker.
Read more → -
ZDI-26-545: Flowise CSV_Agent customReadCSV Code Injection Remote Code Execution Vulnerability
Remote code execution is possible on Flowise installations, but exploitation requires authentication.
Read more → -
ZDI-26-546: Flowise Airtable_Agent Code Injection Remote Code Execution Vulnerability
Unauthenticated remote code execution via code injection in Flowise Airtable_Agent.
Read more → -
ZDI-26-547: OriginLab OriginPro OPJU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Exploitation requires the victim to open a malicious OPJU file or visit a crafted web page.
Read more → -
ZDI-26-548: OriginLab OriginPro OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
OriginLab OriginPro can be compromised via a crafted OPJ file that triggers an out-of-bounds write.
Read more → -
ZDI-26-549: OriginLab OriginPro OGG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
OriginPro's OGG file parser contains an out-of-bounds write that can be triggered by a crafted OGG file.
Read more → -
ZDI-26-550: OriginLab OriginPro OGW File Parsing Memory Corruption Remote Code Execution Vulnerability
OriginPro's OGW file parser can be triggered remotely via a crafted file, causing memory corruption.
Read more → -
ZDI-26-551: OriginLab OriginPro OGG File Parsing Memory Corruption Remote Code Execution Vulnerability
OriginLab OriginPro can be remotely compromised via a crafted OGG file, but exploitation requires the victim to open the file or visit a malicious page.
Read more → -
ZDI-26-552: OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
A crafted OPJ file can trigger an out-of-bounds write in Origin Viewer, enabling remote code execution.
Read more → -
ZDI-26-553: OriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution Vulnerability
Origin Viewer can execute arbitrary code when parsing a malicious OGW file opened by a user. Exploitation requires the victim to visit a malicious page or open a crafted file.
Read more → -
ZDI-26-554: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability
Local privilege escalation in Parallels RAS Client requires prior low-privileged code execution.
Read more → -
ZDI-26-555: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability
The Parallels RAS Client RDP Backend Service has a vulnerability allowing local attackers to escalate privileges. The ZDI has assigned the CVE-2026-18262.
Read more → -
ZDI-26-556: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability
The advisory notes a local privilege escalation in the Parallels RAS Client RDP backend service.
Read more → -
ZDI-26-527: Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerability
Exploitation requires a prior low-privileged foothold on a Wazuh worker node. The flaw is a deserialization of untrusted data in the Cluster DAPI protocol.
Read more → -
ZDI-26-528: Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerability
Exploitation requires prior low-privileged code execution on a Wazuh worker node. The flaw is a deserialization of untrusted data in the Cluster DAPI protocol.
Read more → -
ZDI-26-529: Samsung Galaxy S25 TIFF File Processing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Heap-based buffer overflow in TIFF file processing on Samsung Galaxy S25 enables remote code execution.
Read more → -
ZDI-26-530: SonicWall Email Security snmp Command Injection Local Privilege Escalation Vulnerability
The vulnerability is a local SNMP command injection that enables privilege escalation.
Read more → -
ZDI-26-531: SonicWall GMS Virtual Appliance interface Command Injection Local Privilege Escalation Vulnerability
The vulnerability enables local privilege escalation on SonicWall GMS Virtual Appliance.
Read more → -
ZDI-26-532: SonicWall Email Security updateNetIf Command Injection Local Privilege Escalation Vulnerability
Local command injection in the updateNetIf function can be leveraged for privilege escalation on SonicWall Email Security.
Read more → -
ZDI-26-533: Cisco Secure Firewall Management Center login.cgi Authentication Bypass Vulnerability
Authentication can be bypassed without credentials on Cisco Secure Firewall Management Center login.cgi.
Read more → -
ZDI-26-534: (Pwn2Own) Microsoft Exchange Capture-Replay Authentication Bypass Vulnerability
Remote attackers can bypass authentication on Microsoft Exchange without credentials.
Read more → -
ZDI-26-535: (Pwn2Own) Microsoft Exchange External Control of File Path Remote Code Execution Vulnerability
Authentication can be bypassed to achieve remote code execution on Microsoft Exchange.
Read more → -
ZDI-26-536: (Pwn2Own) Microsoft Windows http.sys Integer Overflow Local Privilege Escalation Vulnerability
An integer overflow in the Windows http.sys driver enables local privilege escalation.
Read more → -
ZDI-26-537: (Pwn2Own) Microsoft Windows storport Integer Overflow Local Privilege Escalation Vulnerability
The advisory reports an integer overflow in the Windows storport driver that enables local privilege escalation.
Read more → -
ZDI-26-538: (Pwn2Own) Microsoft Exchange Improper Authorization Privilege Escalation Vulnerability
Remote attackers can bypass authentication to gain higher privileges on Microsoft Exchange.
Read more → -
ZDI-26-539: (Pwn2Own) Microsoft Windows ipt.sys Incorrect Permission Assignment Local Privilege Escalation Vulnerability
The advisory notes that ipt.sys has incorrect permission assignment enabling local privilege escalation.
Read more → -
ZDI-26-540: (Pwn2Own) Microsoft Windows win32kfull Use-After-Free Information Disclosure Vulnerability
The win32kfull subsystem contains a use-after-free that can disclose sensitive data after low-privilege code execution.
Read more → -
ZDI-26-541: (Pwn2Own) Microsoft Windows win32kfull Use-After-Free Local Privilege Escalation Vulnerability
The advisory reports a use-after-free flaw in win32kfull that enables local privilege escalation.
Read more → -
ZDI-26-524: (0Day) PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability
The Q80 XCB daemon accepts unauthenticated requests that can read and alter configuration data.
Read more → -
ZDI-26-525: (0Day) PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability
Unauthenticated attackers can achieve remote code execution on PAX Technology Q80 via crafted AIP files.
Read more → -
ZDI-26-526: (0Day) PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability
Unauthenticated attackers can bypass the Q80 Application Installer’s signature verification to execute code remotely.
Read more → -
ZDI-26-502: (Pwn2Own) Phoenix Contact CHARX SEC-3150 user-applications Link Following Local Privilege Escalation Vulnerability
The advisory notes a local privilege escalation on Phoenix Contact CHARX SEC-3150 devices.
Read more → -
ZDI-26-503: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Race Condition Firewall Bypass Vulnerability
Unauthenticated network-adjacent attackers can bypass firewall rules on Phoenix Contact CHARX SEC-3150 devices.
Read more → -
ZDI-26-504: (Pwn2Own) Phoenix Contact CHARX SEC-3150 CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerability
Unauthenticated remote code execution is possible on Phoenix Contact CHARX SEC-3150 devices via configuration injection.
Read more → -
ZDI-26-505: (Pwn2Own) Phoenix Contact CHARX SEC-3150 charx-system-config-manager Service CRLF Injection Firewall Bypass Vulnerability
Unauthenticated network-adjacent attackers can bypass firewall rules on Phoenix Contact CHARX SEC-3150 devices.
Read more → -
ZDI-26-506: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Insertion of Sensitive Information into Log File Authentication Bypass Vulnerability
Authentication can be bypassed without credentials on Phoenix Contact CHARX SEC-3150 devices.
Read more → -
ZDI-26-507: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Privilege Defined With Unsafe Actions Local Privilege Escalation Vulnerability
Local privilege escalation on Phoenix Contact CHARX SEC-3150 requires prior low-privileged code execution.
Read more → -
ZDI-26-508: (Pwn2Own) Phoenix Contact CHARX SEC-3150 charx_set_ip_address Improper Input Validation Local Privilege Escalation Vulnerability
Improper input validation in charx_set_ip_address enables local privilege escalation on Phoenix Contact CHARX SEC-3150 devices.
Read more → -
ZDI-26-509: (Pwn2Own) Phoenix Contact CHARX SEC-3150 OCPP Missing Authentication for Critical Function Authentication Bypass Vulnerability
Unauthenticated network-adjacent attackers can modify configuration on Phoenix Contact CHARX SEC-3150 devices.
Read more → -
ZDI-26-510: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Missing Cryptographic Signature Remote Code Execution Vulnerability
Network-adjacent attackers can bypass firmware validation on Phoenix Contact CHARX SEC-3150 devices without authentication.
Read more → -
ZDI-26-511: (Pwn2Own) Phoenix Contact CHARX SEC-3150 user-applications Symlink Following Local Privilege Escalation Vulnerability
The advisory notes a local privilege escalation via symlink following on Phoenix Contact CHARX SEC-3150 devices.
Read more → -
ZDI-26-512: (Pwn2Own) Phoenix Contact CHARX SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability
Unauthenticated network-adjacent attackers can cause a denial-of-service on the Phoenix Contact CHARX SEC-3150 ModBus server.
Read more → -
ZDI-26-513: (Pwn2Own) Phoenix Contact CHARX SEC-3150 update2-upload Arbitrary File Upload Vulnerability
Authenticated, network-adjacent attackers can upload arbitrary files to Phoenix Contact CHARX SEC-3150 devices.
Read more → -
ZDI-26-514: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Failing Open Authentication Bypass Vulnerability
Authentication can be bypassed without credentials on Phoenix Contact CHARX SEC-3150 devices.
Read more → -
ZDI-26-515: (Pwn2Own) Phoenix Contact CHARX SEC-3150 charx-jupicore Missing Authentication Configuration Modification Vulnerability
Unauthenticated configuration modification is possible on Phoenix Contact CHARX SEC-3150 devices.
Read more → -
ZDI-26-516: (Pwn2Own) Phoenix Contact CHARX SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability
Unauthenticated attackers can trigger a denial-of-service on Phoenix Contact CHARX SEC-3150 ModBus servers.
Read more → -
ZDI-26-517: (Pwn2Own) Phoenix Contact CHARX SEC-3150 BackendURL WebSocket Command Injection Remote Code Execution Vulnerability
The advisory notes that authentication can be bypassed, enabling remote code execution via a WebSocket BackendURL command injection.
Read more → -
ZDI-26-518: (Pwn2Own) Phoenix Contact CHARX SEC-3150 MQTT Service Server-Side Request Forgery Remote Code Execution Vulnerability
Unauthenticated network-adjacent attackers can exploit an SSRF flaw in the MQTT service of Phoenix Contact CHARX SEC-3150 devices. The issue is identified as CVE-2026-44091 with a CVSS score of 6.3.
Read more → -
ZDI-26-519: (Pwn2Own) Phoenix Contact CHARX SEC-3150 CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerability
Unauthenticated remote code execution is possible on Phoenix Contact CHARX SEC-3150 devices.
Read more → -
ZDI-26-520: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Jupicore External Control of Path Remote Code Execution Vulnerability
Unauthenticated remote code execution is possible on Phoenix Contact CHARX SEC-3150 devices.
Read more → -
ZDI-26-521: Phoenix Contact CHARX SEC-3000 Command Injection Remote Code Execution Vulnerability
Authentication is required to exploit the command injection on CHARX SEC-3000 devices.
Read more → -
ZDI-26-522: Phoenix Contact CHARX SEC-3000 Insertion of Sensitive Information into Log File Information Disclosure Vulnerability
Unauthenticated network-adjacent attackers can retrieve sensitive data from the CHARX SEC-3000 log file.
Read more → -
ZDI-26-523: Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability
Deserialization of untrusted checkpoint files can lead to remote code execution.
Read more → -
ZDI-26-487: (Pwn2Own) Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local Privilege Escalation Vulnerability
The udhcpd daemon on Kenwood DNR1007XR devices has an incorrect permission assignment that enables local privilege escalation.
Read more → -
ZDI-26-488: (Pwn2Own) Kenwood DNR1007XR vCardParser Heap-based Buffer Overflow Code Execution Vulnerability
The vulnerability is a heap-based buffer overflow in the vCardParser of Kenwood DNR1007XR.
Read more → -
ZDI-26-489: (Pwn2Own) Kenwood DNR1007XR startUpdateProcess Command Injection Vulnerability
Unauthenticated command injection in startUpdateProcess enables arbitrary code execution on Kenwood DNR1007XR devices.
Read more → -
ZDI-26-490: (Pwn2Own) Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation Vulnerability
The advisory notes that the vulnerability stems from incorrect default USB permissions on the Kenwood DNR1007XR, allowing local privilege escalation. Exploitation requires a low-privileged code execution step and physical presence.
Read more → -
ZDI-26-491: Apple macOS CoreAudio Out-Of-Bounds Write Remote Code Execution Vulnerability
Exploitation requires the victim to open a malicious file or visit a malicious webpage.
Read more → -
ZDI-26-492: Apple macOS ImageIO Numeric Truncation Remote Code Execution Vulnerability
The issue is a numeric truncation flaw in macOS’s ImageIO library.
Read more → -
ZDI-26-493: Apple macOS USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Exploitation requires interaction with the macOS USD library and triggers a heap-based buffer overflow.
Read more → -
ZDI-26-494: Apple macOS USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Exploitation requires interaction with the macOS USD library and triggers a heap-based buffer overflow.
Read more → -
ZDI-26-495: (Pwn2Own) VMware ESXi VMXNET3 espQueueMask Out-Of-Bounds Write Local Privilege Escalation Vulnerability
The advisory notes a local privilege escalation vulnerability in VMware ESXi.
Read more → -
ZDI-26-496: Trend AI Cleaner One Pro Link Following Arbitrary File Deletion Vulnerability
Local low-privileged code can delete arbitrary files via the link-following feature in Trend Micro Cleaner One Pro.
Read more → -
ZDI-26-497: TrendAI Vision One Service Gateway Logs Information Disclosure Vulnerability
Remote authenticated attackers can obtain sensitive information from TrendAI Vision One Service Gateway logs.
Read more → -
ZDI-26-498: TrendAI Vision One Incorrect Privilege Assignment Privilege Escalation Vulnerability
Remote authenticated attackers can elevate privileges on TrendAI Vision One.
Read more → -
ZDI-26-499: WatchGuard FireWare OS cli Token Parser Stack-based Buffer Overflow Remote Code Execution Vulnerability
Authentication is required to exploit a stack-based buffer overflow in the WatchGuard FireWare OS CLI token parser.
Read more → -
ZDI-26-500: WatchGuard FireWare OS networkd network_wireless_kick_off_user_cb Stack-based Buffer Overflow Remote Code Execution Vulnerability
Exploitation requires valid authentication credentials.
Read more → -
ZDI-26-501: WatchGuard FireWare OS sigd comp_start_cb Directory Traversal Arbitrary File Creation Vulnerability
Remote authenticated attackers can create arbitrary files via the sigd comp_start_cb directory traversal in WatchGuard FireWare OS.
Read more → -
ZDI-26-453: GIMP HDR File Parsing Integer Overflow Remote Code Execution Vulnerability
Exploitation requires a user to open a malicious HDR file or visit a crafted webpage.
Read more → -
ZDI-26-454: GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability
Integer overflow in GIMP's PSD file parser can lead to remote code execution.
Read more →
Page 1 of 5 · 489 advisories