Zero Day Initiative
zdi · B · active
https://www.zerodayinitiative.com/blog/
Trend Micro ZDI vulnerability disclosure programme. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://www.zerodayinitiative.com/blog/ (listing) then webfetch each /blog/YYYY/M/D/<slug> article. AVOID: Nothing to avoid; WebFetch works on listing and articles.. | 2026-07-05 admiralty audit: B, established original vuln-disclosure programme (ZDI advisories, Pwn2Own); primary for its own disclosures but third-party products so not A. No status change (active). | 2026-09-15 intel run: zerodayinitiative.com/blog listing returned only monthly patch-Tuesday roundups, latest dated 2026-09-08, outside this run's window.
Cited in 9 entries
Citation cadence
Citation days per ISO week (18 weeks of coverage span, total 8).
- September 2026 Patch Tuesday: two actively exploited Windows privilege-escalation zero-days (CVE-2026-81963 Update Stack, CVE-2026-85880 ALPC)2026-09-09
- CVE-2026-0768, Langflow: a code-injection RCE patched since January sees renewed mass exploitation, harvesting AWS and OpenAI credentials from environment variables2026-09-03
- CVE-2026-0769, Langflow: an unpatched pre-auth eval-injection RCE that VulnCheck observes being exploited, and that CISA KEV does not list2026-07-29
- CVE-2026-0770, Langflow: CISA confirms active exploitation of an unauthenticated exec_globals RCE the same day a 15-CVE batch (incl. unauthenticated account creation) is patched in 1.10.12026-07-22
- Microsoft July 2026 Patch Tuesday ships two actively-exploited zero-days, AD FS local EoP (CVE-2026-56155) and unauthenticated SharePoint EoP (CVE-2026-56164)2026-07-14
- CVE-2026-8037, Progress Kemp LoadMaster: pre-auth RCE via uninitialized heap in the /accessv2 API2026-06-30
- CVE-2026-47291, Microsoft June Patch Tuesday: HTTP.sys pre-auth RCE (CVSS 9.8) headlines the largest-ever release (198 CVEs)2026-06-10
- Pwn2Own Berlin 2026: Master-of-Pwn outcomes, the new AI Agents category, and the compound-Exchange-threat picture for European defenders2026-05-17
- Exchange CVE-2026-42897, Pwn2Own DEVCORE three-bug SYSTEM RCE chain emerges alongside active OWA-XSS exploitation2026-05-17