Cursor DuneSlide: two critical sandbox escapes in the AI IDE (CVE-2026-50548 / -50549)
Two CVSS 9.3 flaws let a prompt-injected agent write outside Cursor's workspace and reach OS-level RCE. Patched in Cursor 3.0. Credit: Cato AI Labs.
Two CVSS 9.3 flaws let a prompt-injected agent write outside Cursor's workspace and reach OS-level RCE. Patched in Cursor 3.0. Credit: Cato AI Labs.
JetBrains Hub 2026.1.13757 fixes CVE-2026-50242 (CVSS 10.0 auth bypass) and CVE-2026-56141 (CVSS 9.8 account takeover via predictable restore codes). LTS backports available.
A race-condition use-after-free in the Linux kernel epoll subsystem lets an unprivileged process reach root on desktops, servers, and Android. Reported to Google kernelCTF by Jaeyoung Chung.
Seven FatFs bugs disclosed July 1 by runZero — FAT32, exFAT and long-filename paths across ESP-IDF, STM32Cube, Zephyr, MicroPython. Only CVE-2026-6684 has an upstream fix.
Defused honeypots caught in-the-wild exploitation of CVE-2026-46817 (CVSS 9.8) on June 27, six weeks after Oracle's May patch. ~950 EBS instances are internet-exposed.
Citrix's CTX696604 fixes six NetScaler ADC/Gateway CVEs on June 30. CVE-2026-8451, a pre-auth memory overread on the SAML IdP path, echoes CitrixBleed 2. Patch 14.1-72.61 or 13.1-63.18.
CISA added SharePoint RCE CVE-2026-45659 to the KEV catalog on July 1 after confirmed exploitation. Deserialization bug patched OOB May 21; FCEB agencies have three days.
APSB26-68 fixes 11 ColdFusion CVEs on June 30 — six at CVSS 10, all pre-auth RCE. Priority 1. Patch to 2025.10 or 2023.21 today.
Progress patches an unauth pre-auth command-injection RCE in Kemp LoadMaster. CVSS 9.8. GA 7.2.63.2 and LTSF 7.2.54.18 ship the fix; watchTowr posted the full chain on June 29.