LegacyHive drops Windows profsvc zero-day PoC after Patch Tuesday
Nightmare Eclipse published LegacyHive on GitHub the same day as Microsoft's July 2026 Patch Tuesday. It's an unpatched profsvc LPE that still works on fully-updated Windows.
Nightmare Eclipse published LegacyHive on GitHub the same day as Microsoft's July 2026 Patch Tuesday. It's an unpatched profsvc LPE that still works on fully-updated Windows.
SonicWall confirms in-the-wild chaining of an unauth SSRF (CVE-2026-15409, CVSS 10.0) and a post-auth command injection (CVE-2026-15410, CVSS 7.2) on SMA1000 6210/7210/8200v. CISA KEV due 2026-07-17.
Google's June 8 Stable Channel pushes 149.0.7827.102/.103 for an actively exploited V8 out-of-bounds read/write. CISA added the CVE to KEV the next day.
Oracle ships an out-of-band Security Alert for an unauthenticated RCE in PeopleTools 8.61/8.62. Mandiant ties exploitation since May 27 to ShinyHunters (UNC6240).
Tunnel-decap logic flaw in Arista EOS lets crafted VXLAN/GRE/decap-group packets reach configured decap IPs. Exploited in the wild. Arista will not patch — mitigate with ACLs.
Microsoft's June 9 Patch Tuesday fixes around 200 CVEs and 33 Critical flaws, including publicly disclosed zero-days in BitLocker, HTTP.sys (HTTP/2 Bomb) and CTFMON.
Check Point hotfixes a CVSS 9.3 cert-validation bypass on Remote Access and Mobile Access VPN. Exploitation since May 7, 2026 — one case linked to a Qilin affiliate.
Cisco disclosed a command-injection zero-day in Catalyst SD-WAN Manager on June 5. Mandiant credited as reporter. CVSS 7.8, exploitation observed, no fix available.
Google's June 2026 Android Security Bulletin fixes 124 flaws, including a Framework integer overflow under limited, targeted exploitation. CISA wants federal agencies patched by 5 June.