Zero Day Initiative
zdi · B · active
https://www.zerodayinitiative.com/blog/
Trend Micro ZDI vulnerability disclosure programme. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://www.zerodayinitiative.com/blog/ (listing) then webfetch each /blog/YYYY/M/D/<slug> article. AVOID: Nothing to avoid — WebFetch works on listing and articles.. | 2026-07-05 admiralty audit: B — established original vuln-disclosure programme (ZDI advisories, Pwn2Own); primary for its own disclosures but third-party products so not A. No status change (active).
Cited in 10 entries
Citation cadence
Citation days per ISO week (12 weeks of coverage span, total 8).
- Both standard prioritisation feeds failed in the same week — an exploited flaw absent from KEV, and four critical flaws with no fix to apply2026-08-02
- 2026-W31 looking ahead — items already in motion: a committed firmware date of 12 August, WebSphere fix packs not due before 3Q2026, an extortion campaign between exfiltration and publication, three flaws with no fix at all, and the CRA reporting clock at six weeks2026-08-02
- CVE-2026-0769 — Langflow: an unpatched pre-auth eval-injection RCE that VulnCheck observes being exploited, and that CISA KEV does not list2026-07-29
- Langflow correction — 1.10.1 is not the endpoint: CVE-2026-14499 needs 1.10.2, and CVE-2026-0770 has no AUTO_LOGIN precondition2026-07-26
- CVE-2026-0770 — Langflow: CISA confirms active exploitation of an unauthenticated exec_globals RCE the same day a 15-CVE batch (incl. unauthenticated account creation) is patched in 1.10.12026-07-22
- Microsoft July 2026 Patch Tuesday ships two actively-exploited zero-days — AD FS local EoP (CVE-2026-56155) and unauthenticated SharePoint EoP (CVE-2026-56164)2026-07-14
- CVE-2026-47291 — Windows HTTP.sys pre-auth RCE (CVSS 9.8): ZDI publishes full exploitation mechanics and a detection signature2026-07-11
- CVE-2026-8037 — Progress Kemp LoadMaster: pre-auth RCE via uninitialized heap in the /accessv2 API2026-06-30
- Pwn2Own Berlin 2026: Master-of-Pwn outcomes, the new AI Agents category, and the compound-Exchange-threat picture for European defenders2026-05-17
- Exchange CVE-2026-42897 — Pwn2Own DEVCORE three-bug SYSTEM RCE chain emerges alongside active OWA-XSS exploitation2026-05-17