NVIDIA fixed 114 CVEs across GPU display drivers and vGPU. GeForce users need 616.56 (R615), 610.88 (R610), or 582.78 (R580). Here is how to verify versions.
Hacktron AI disclosed a 72-hour exploit chain reaching OpenAI's internal monorepo openai/openai: a silent upstream fix in libheif, ASLR bypass via Claude Opus 5, and an OpenAI SSO identity flaw allowing ChatGPT/Codex account takeovers.
CVE-2026-82079 affects Nintendo Switch systems before 23.0.0. Exploitation requires a malicious third party to directly scan a QR code shown by Album or Mario Kart Live: Home Circuit; update to 23.0.0.
Probes for percent-encoded traversal hit the cohttp maintainer's logs 10 minutes after the fix PR opened. Mandiant now puts mean time-to-exploit at -7 days, VulnCheck's data disagrees.
Checked August 17, 2026 via the GitHub Advisory Database API: all six fake SQLite CVEs rejected by MITRE still show CVSS up to 9.8 as type unreviewed, withdrawn_at null.
WordPress 7.0.3 (Aug 6, 2026) closes CVE-2026-64638 / XSS2Shell (CVSS 8.9): a whitespace tag like `< area` slips past strip_tags but KSES restores it, giving pre-auth login XSS that chains to PHP RCE. All versions affected; fix backported to 4.7.
54 of 55 advisories from one GitHub account were fabricated, likely by AI. How six fake SQLite CVEs passed MITRE and NVD unchecked, and why scanner hits for them are false positives.
15 formats renamed to .png, then Rails 8.1.3 vs 8.1.3.1 on one attachment: SVG logged 123x45 on the vulnerable build, nothing on the patched one. Plus the matload entry point and the libvips 8.13 floor that stops boot.
Fastjson 1.2.68–1.2.83 is exploited with no AutoType and no gadgets. What gates it: Spring Boot executable fat-JAR, SafeMode off, and Object/Map fields in your DTO.
Russian state actors ran ZimReaper stored XSS in Zimbra Classic UI. What to check before and after updating to 10.1.20: mailbox.log SOAP bursts, ZimbraWeb app passwords, IMAP flips, DNS exfil.
WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1 are vulnerable to pre-auth RCE via batch-route confusion plus SQLi. Update to 7.0.2/6.9.5 (6.8.6 for 6.8.x), how to block /wp-json/batch/v1, and where to look in REST logs.