Proof-of-concept (PoC) exploit code has now been released for a recently patched security flaw in the Linux kernel that could allow for local privilege escalation (LPE).
Dubbed DirtyDecrypt (aka DirtyCBC), the vulnerability was discovered and reported by the Zellic and V12 security team on May 9, 2026, only to be informed by the maintainers that it was a duplicate of a vulnerability that had
Threat actors earlier today published more than 600 malicious packages to the Node Package Manager (npm) index as part of a new Shai-Hulud supply-chain campaign. [...]
Convenience store chain giant 7-Eleven confirmed that its systems were breached in a cyberattack claimed by the ShinyHunters extortion group last month. [...]
Microsoft's total vulnerability count stayed steady in 2025, but critical flaws surged year over year. BeyondTrust breaks down why attackers are increasingly focused on privilege escalation and identity abuse. [...]
A vulnerability described as problematic has been identified in Mozilla Firefox up to 150 on Android. Affected by this issue is some unknown functionality of the component Toolbar. Executing a manipulation can lead to improper restriction of rendered ui layers.
The identification of this vulnerability is CVE-2026-8951. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability marked as critical has been reported in Mozilla Firefox up to 150 on Android. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in sandbox issue.
This vulnerability was named CVE-2026-8945. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
A vulnerability labeled as critical has been found in Mozilla Firefox up to 150. Affected is an unknown function of the component Audio/Video. Such manipulation leads to Remote Code Execution.
This vulnerability is uniquely identified as CVE-2026-8972. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
A vulnerability identified as problematic has been detected in Mozilla Firefox up to 150. This impacts an unknown function of the component JAR. This manipulation causes permissive cross-domain policy with untrusted domains.
This vulnerability is handled as CVE-2026-8971. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
A vulnerability categorized as problematic has been discovered in Mozilla Firefox up to 140.10/150. This affects an unknown function of the component Security Component. The manipulation results in privilege escalation.
This vulnerability is known as CVE-2026-8970. Access to the local network is required for this attack. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability was found in Mozilla Firefox up to 140.10/150. It has been rated as problematic. The impacted element is an unknown function of the component Form Autofill. The manipulation leads to an unknown weakness.
This vulnerability is traded as CVE-2026-8961. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability was found in Mozilla Firefox up to 150. It has been declared as problematic. The affected element is an unknown function of the component WebExtensions. Executing a manipulation can lead to an unknown weakness.
This vulnerability appears as CVE-2026-8960. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability was found in Mozilla Firefox up to 140.10/150. It has been classified as problematic. Impacted is an unknown function of the component Enterprise Policies. Performing a manipulation results in privilege escalation.
This vulnerability is reported as CVE-2026-8957. The attacker must have access to the local network to execute the attack. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability was found in Mozilla Firefox up to 140.10/150 and classified as critical. This issue affects some unknown processing of the component JAR. Such manipulation leads to integer overflow.
This vulnerability is documented as CVE-2026-8956. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.