A new Microsoft Defender zero-day called ‘RoguePlanet’ lets attackers gain SYSTEM privileges on fully patched Windows 10 and 11 machines. The race condition exploit published by researcher Nightmare Eclipse works against June 2026 Patch Tuesday systems — and there’s no fix yet.
Microsoft’s latest Patch Tuesday fixed a zero-day vulnerability disclosed by researcher Nightmare Eclipse, as the two remain locked in a heated public dispute over responsible disclosure practices. The same patch bundle also addressed another flaw originally thought fixed six years ago.
Cisco’s SD-WAN platform has its seventh actively exploited zero-day of 2026 — CVE-2026-20245 lets attackers run commands as root, and there’s still no patch available.
Google patched CVE-2026-11645, a fifth Chrome zero-day this year, involving a V8 out-of-bounds read/write that can bypass ASLR. The exploit is already in the wild — here’s what to do.
Cisco disclosed its seventh SD-WAN zero-day of 2026 — CVE-2026-20245 — a command injection flaw allowing root access on Catalyst SD-WAN Manager. No patch is available yet, and there’s no workaround.
Cisco disclosed its 7th actively exploited SD-WAN zero-day in 2026. CVE-2026-20245 allows root command execution with no patch available yet. Here’s what defenders need to know.
Cisco disclosed its seventh exploited SD-WAN zero-day of 2026. CVE-2026-20245 allows root command execution with no patch available yet. Here’s what defenders need to know.
Cisco disclosed its seventh exploited SD-WAN zero-day of 2026. CVE-2026-20245 allows root-level command execution with no patch available yet. Here’s what organizations need to know and do right now.