Emerging BETA · EXPERIMENTAL RSS ↗
Emerging is a BETA feed that watches a curated set of trusted security-news outlets and links what they report to the 638 products IsItPatched tracks — often ahead of full NVD enrichment. Every item is attributed to its source and links out; IsItPatched never asserts its own findings here. Right now it surfaces 105 machine-linked reports, 10 describing active exploitation.
⚠ Items are machine-linked third-party reporting and may be wrong. Each shows its source and links out — we never assert our own findings here. Treat low-confidence items as leads, and always verify against the source and the vendor advisory.
Sunday 2 August
Saturday 1 August
Windows 11 Gets More Taskbar Control and AI Integration as Microsoft Details Quality Progress
Ruby on Rails Patches Critical Vulnerability
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
Friday 31 July
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
No items match.
Critical Code Execution Vulnerability Patched in TeamCity
JetBrains warns of critical TeamCity remote code execution flaw
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
CVE-2026-54128 Windows DHCP Client Remote Code Execution Vulnerability
CVE-2026-55129 Microsoft Office Remote Code Execution Vulnerability
CVE-2026-56197 Windows Admin Center (WAC) Remote Code Execution Vulnerability
CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability
CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerability
NASA Core Flight System (cFS) Health & Safety (HS) Application
MikroTik RouterOS
Toptech Systems RCU II+ and Multiload II+
Watchfire Controller Software
Johnson Controls OpenBlue Employee
MZ Automation GmbH libiec61850
MZ Automation lib60870
Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module
o6 Automation open62541
Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)
Russian spies take their half-click email attack from Zimbra to Outlook
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
ZDI-26-523: Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability
ZDI-26-522: Phoenix Contact CHARX SEC-3000 Insertion of Sensitive Information into Log File Information Disclosure Vulnerability
ZDI-26-521: Phoenix Contact CHARX SEC-3000 Command Injection Remote Code Execution Vulnerability
ZDI-26-520: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Jupicore External Control of Path Remote Code Execution Vulnerability
ZDI-26-519: (Pwn2Own) Phoenix Contact CHARX SEC-3150 CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerability
ZDI-26-518: (Pwn2Own) Phoenix Contact CHARX SEC-3150 MQTT Service Server-Side Request Forgery Remote Code Execution Vulnerability
ZDI-26-517: (Pwn2Own) Phoenix Contact CHARX SEC-3150 BackendURL WebSocket Command Injection Remote Code Execution Vulnerability
ZDI-26-516: (Pwn2Own) Phoenix Contact CHARX SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability
ZDI-26-515: (Pwn2Own) Phoenix Contact CHARX SEC-3150 charx-jupicore Missing Authentication Configuration Modification Vulnerability
ZDI-26-514: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Failing Open Authentication Bypass Vulnerability
ZDI-26-513: (Pwn2Own) Phoenix Contact CHARX SEC-3150 update2-upload Arbitrary File Upload Vulnerability
ZDI-26-512: (Pwn2Own) Phoenix Contact CHARX SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability
ZDI-26-511: (Pwn2Own) Phoenix Contact CHARX SEC-3150 user-applications Symlink Following Local Privilege Escalation Vulnerability
ZDI-26-510: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Missing Cryptographic Signature Remote Code Execution Vulnerability
ZDI-26-509: (Pwn2Own) Phoenix Contact CHARX SEC-3150 OCPP Missing Authentication for Critical Function Authentication Bypass Vulnerability
ZDI-26-508: (Pwn2Own) Phoenix Contact CHARX SEC-3150 charx_set_ip_address Improper Input Validation Local Privilege Escalation Vulnerability
ZDI-26-507: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Privilege Defined With Unsafe Actions Local Privilege Escalation Vulnerability
ZDI-26-506: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Insertion of Sensitive Information into Log File Authentication Bypass Vulnerability
Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
CISA Adds One Known Exploited Vulnerability to Catalog
Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
GitLab Patch Release: 19.2.1, 19.1.3, 19.0.5
Chromium: CVE-2026-13037 Use after free in WebView
Chromium: CVE-2026-13032 Use after free in WebGL
Chromium: CVE-2026-13030 Uninitialized Use in GPU
Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)
'Certighost' Flaw Haunts Microsoft Active Directory Certificates
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
igloohome Smart Lock Mobile Application
Siemens SIMATIC S7-PLCSIM Advanced
MikroTik RouterOS and Cloud Hosted Router
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework
Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update
CISA Adds Two Known Exploited Vulnerabilities to Catalog
Researchers replace downloaded macOS apps with evil twins, Apple shrugs
Johnson Controls XAAP Android
CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
Fake Bahrain Alert App Deploys Android Surveillance Malware
Linux kernel team publishes 432 CVEs in two days
RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600)
CVE-2026-8933: Local Privilege Escalation in Set-Capabilities snap-confine
Attackers pummel critical WordPress vuln to create all sorts of mischief
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
CVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild
Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)
SVD-2026-0705: Third-Party Package Updates in Splunk Enterprise - July 2026
SVD-2026-0704: Sensitive Information Disclosure through the storage/passwords REST Endpoint in Splunk Enterprise
SVD-2026-0703: Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise
SVD-2026-0702: SPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in Deployment Server in Splunk Enterprise
July 2026 Patch Tuesday
CVE-2026-0279 PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities (Severity: LOW)
CVE-2026-0283 PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN) (Severity: MEDIUM)
CVE-2026-0282 PAN-OS: File Deletion Vulnerability in Management Web Interface (Severity: LOW)
CVE-2026-0277 Prisma Access Agent: Improper Certificate Validation on iOS (Severity: MEDIUM)
CVE-2026-0280 PAN-OS: IPv6 Firewall Policy Bypass (Severity: LOW)
CVE-2026-0281 PAN-OS: Information Disclosure Vulnerability in Management Web Interface (Severity: LOW)
CVE-2026-0278 Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows (Severity: MEDIUM)
CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent (Severity: HIGH)
CVE-2026-0285 PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface (Severity: MEDIUM)
CVE-2026-0286 PAN-OS: Authenticated Command Injection in CLI (Severity: MEDIUM)
CVE-2026-0276 Cortex XDR Broker VM: Privilege Escalation (PE) Vulnerability (Severity: LOW)
CVE-2026-0287 PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing (Severity: MEDIUM)
CVE-2026-0284 PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN) (Severity: MEDIUM)
GitLab Patch Release: 19.1.2, 19.0.4, 18.11.7
GitLab Patch Release: 18.8.11
SVD-2026-0701: Third-Party Package Updates in Python for Scientific Computing - July 2026
GitLab Patch Release: 19.1.1, 19.0.3, 18.11.6
How this week’s reporting connects — 17 products, 50 CVEs and 13 sources. Lines are attributed links from the items above; positions are illustrative. Tap a node to open it. Violet = software in your stack.
Prefer the list? Switch back to . The graph is a visual aid; the timeline above carries every item with full attribution.
About this BETA
Emerging ingests only a hard-coded allow-list of trusted outlets — first-party vendor advisories (Microsoft MSRC, Cisco PSIRT, Fortinet, Palo Alto, Ivanti), security research (Google Project Zero, Rapid7, Qualys) and established reporting (CISA, Krebs on Security, BleepingComputer, The Hacker News, SecurityWeek, Dark Reading, The Register) — no open-web crawl, no social feeds, no user submissions. We store and show only a headline, the source, the time, an outbound link and (where available) a short own-words takeaway — never article text. Links between a report and a product or CVE are made by software and carry a confidence level; they can be wrong. This is an early experiment in linking breaking reporting to the software you actually run — tell us when we get a link wrong →.
Newest first · refreshes on every sync · sources retain all rights to their reporting. See our disclaimer.