Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3089 articles · 184076 vulns · 37/41 feeds (7d)
18
+4 today
Exploited (7d)
207
+41 today
Critical (7d)
1723
CISA KEV
410
Pre-CVE
3089
+620 today
Articles (7d)

Threat Briefing

Global

Loading...

About Zero Day Monitor

Open-source vulnerability intelligence for security teams. The platform scans 41 security feeds, analyzes articles with AI, and surfaces the threats that matter. Track trending CVEs, discover zero-days before they get a CVE ID, and monitor your vendor stack for supply-chain risks.

Trending
Ranked by source count
Zero-Days
Pre-CVE detection
Verification
Community-driven
Open Source
AGPL-3.0 licensed
Learn more about the projectSign in for personalized features

Vulnerabilities

9.8
ibm · CVE-2026-9198 — Unauthenticated Remote Code Execution via Auto-Login Bypass and Code ValidationKEVEXPLOITEDPATCHED
langflow· CVSS 9.8· CWE-94
153🔥
5 art.
0
Jul 17, 2026
9.3
checkpoint · CVE-2026-50751 — User Authentication Bypass in VPN Remote Access and Mobile AccessKEVEXPLOITED
PATCHED
gaia_os· CVSS 9.3· CWE-287
146🔥
23 art.
0
Jun 8, 2026
8.1
microsoft · CVE-2026-42897 — Microsoft Exchange Server Spoofing VulnerabilityKEVEXPLOITEDPATCHED
exchange_server· CVSS 8.1· CWE-79
116🔥
30 art.
0
May 14, 2026
8.1
f5 · CVE-2026-42945 — NGINX ngx_http_rewrite_module vulnerabilityKEVEXPLOITEDPATCHED
dos· CVSS 8.1· CWE-122
105🔥
25 art.
0
May 13, 2026
10.0
sonicwall · CVE-2026-15409 — CVE-2026-15409: A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A EXPLOITEDPATCHED
sma6210_firmware· CVSS 10.0· CWE-918
92
23 art.
0
Jul 14, 2026
7.8
palo alto networks · CVE-2026-0257 — PAN-OS: GlobalProtect Authentication Bypass VulnerabilitiesEXPLOITEDPATCHED
pan-os· CVSS 7.8· CWE-565
87
23 art.
0
May 13, 2026
—
rubygems · CVE-2026-66066 — Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processingPATCHED
activestorage· CWE-1188
83
14 art.
0
Jul 30, 2026
7.2
sonicwall · CVE-2026-15410 — CVE-2026-15410: Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SEXPLOITEDPATCHED
sma6210_firmware· CVSS 7.2· CWE-94
83
23 art.
0
Jul 14, 2026
—
n-able · CVE-2026-18577 — Incomplete patch leads to administrative account takeoverPATCHED
n-central· CWE-288
71
9 art.
0
Aug 2, 2026
7.8
linux · CVE-2026-64600 — xfs: resample the data fork mapping after cycling ILOCKEXPLOITEDPATCHED
linux kernel· CVSS 7.8
68
14 art.
0
Jul 23, 2026
→ View full list

Pre-CVE Events

View all
ZERO-DAYCisco Advance Notification for Publication of July 1, 2026, Security Advisories
cisco1 sourcesverified
ZERO-DAYMalicious Code Injection via Axios npm Package Maintainer Account Takeover
axiosMEDIUM1 sourcesverified
ZERO-DAYADV990001 Latest Servicing Stack Updates
1 sourcesverified
Serendipity 2.6.0 Multiple Security Vulnerabilities Including Username Takeover and XSS
serendipity projectCRITICAL1 sources
CrowdStrike Falcon Platform Helps Meet U.S. Government Mandates for CISA BOD-26-04
1 sources

Latest news

View all
[B]microsoft
Security Alert: Microsoft Releases March 2026 Security Updates
[B]trend microCVE-2026-34926
Security Alert: Alert Regarding Multiple Vulnerabilities in Trend Micro Products Including TrendAI Apex One
[B]adobeCVE-2026-27220
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-26)
[B]microsoftCVE-2026-20805
Security Alert: Microsoft Releases January 2026 Security Updates
[B]adobe
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-63)
[B]microsoftCVE-2026-21510
Security Alert: Microsoft Releases February 2026 Security Updates
[B]microsoftCVE-2025-62221
Security Alert: Microsoft Releases December 2025 Security Updates
[B]microsoftCVE-2026-56164
Security Alert: Microsoft Releases July 2026 Security Updates