Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2473 articles · 111827 vulns · 37/41 feeds (7d)
529
+7 today
Exploited (7d)
153
+8 today
Critical (7d)
1551
CISA KEV
18
Pre-CVE
2473
+133 today
Articles (7d)

Threat Briefing

Global

Loading...

About Zero Day Monitor

Open-source vulnerability intelligence for security teams. The platform scans 41 security feeds, analyzes articles with AI, and surfaces the threats that matter. Track trending CVEs, discover zero-days before they get a CVE ID, and monitor your vendor stack for supply-chain risks.

Trending
Ranked by source count
Zero-Days
Pre-CVE detection
Verification
Community-driven
Open Source
AGPL-3.0 licensed
Learn more about the projectSign in for personalized features

Vulnerabilities

8.6
adobe · CVE-2026-34621 — Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)KEVEXPLOITEDPATCHED
acrobat_dc· CVSS 8.6· CWE-1321
140🔥
16 art.
0
Apr 11, 2026
8.8
apache · CVE-2026-34197 — Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeansKEV
EXPLOITED
PATCHED
activemq· CVSS 8.8· CWE-20
102🔥
14 art.
0
Apr 7, 2026
9.8
nginxui · CVE-2026-33032 — Nginx UI: Unauthenticated MCP Endpoint Allows Remote Nginx TakeoverKEVEXPLOITEDPATCHED
nginx_ui· CVSS 9.8· CWE-306
102🔥
9 art.
0
Mar 30, 2026
7.8
microsoft · CVE-2026-33825 — Microsoft Defender Elevation of Privilege VulnerabilityKEVEXPLOITEDPATCHED
defender· CVSS 7.8· CWE-1220
95
11 art.
0
Apr 14, 2026
9.1
fortinet · CVE-2026-39808 — CVE-2026-39808: A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FEXPLOITEDPATCHED
fortisandbox· CVSS 9.1· CWE-78
80
7 art.
0
Apr 14, 2026
9.1
fortinet · CVE-2026-39813 — CVE-2026-39813: A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.EXPLOITEDPATCHED
fortisandbox· CVSS 9.1· CWE-24
80
7 art.
0
Apr 14, 2026
6.5
microsoft · CVE-2026-32201 — Microsoft SharePoint Server Spoofing VulnerabilityKEVEXPLOITEDPATCHED
sharepoint_server· CVSS 6.5· CWE-20
78
14 art.
0
Apr 14, 2026
9.1
fortinet · CVE-2026-21643 — CVE-2026-21643: An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiCKEVEXPLOITEDPATCHED
forticlientems· CVSS 9.1· CWE-89
70
13 art.
0
Feb 6, 2026
—
linux · CVE-2026-23400 — rust_binder: call set_notification_done() without proc lockEXPLOITEDPATCHED
linux kernel
65
25 art.
0
Mar 29, 2026
—
python · CVE-2026-6100 — Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressureEXPLOITEDPATCHED
cpython· CWE-416
59
5 art.
0
Apr 13, 2026
→ View full list

Pre-CVE Events

View all
ZERO-DAYMalicious Code Injection via Axios npm Package Maintainer Account Takeover
axiosMEDIUM1 sourcesverified
ZERO-DAYADV990001 Latest Servicing Stack Updates
1 sourcesverified
Local Code Execution Vulnerability in Perl
the perl foundationMEDIUM1 sources
Multiple Denial of Service Vulnerabilities in binutils
LOW1 sources
Memory Safety Issues in Go Compiler
Go1 sources

Latest news

View all
[B]microsoftCVE-2026-21510
Security Alert: Microsoft Releases February 2026 Security Updates
[B]microsoftCVE-2026-32201
Security Alert: Microsoft Releases April 2026 Security Updates
[B]adobe
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-44)
[B]microsoft
Security Alert: Microsoft Releases March 2026 Security Updates
[B]microsoftCVE-2025-62221
Security Alert: Microsoft Releases December 2025 Security Updates
[B]adobeCVE-2026-27220
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-26)
[B]microsoftCVE-2026-20805
Security Alert: Microsoft Releases January 2026 Security Updates
[B]adobe
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB25-119)