CVE-2026-92206: CrewAI framework hit by critical zero-day RCE (CVSS 8.8). Unsafe reflection in load_agent_from_repository allows arbitrary code execution when loading https:// deafnews.it/en/article/c
8).
8).
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
CVE-2026-92206: CrewAI framework hit by critical zero-day RCE (CVSS 8.8). Unsafe reflection in load_agent_from_repository allows arbitrary code execution when loading https:// deafnews.it/en/article/crewai- zero-day-rce-malicious-agents-execute-arbitrary-code-via-repository
MindsDB hit by unpatched zero-day RCE (CVE-2026-92207, CVSS 8.8). The OpenBBtable class executes Python code without validation. Vendor silent for nearly ten https:// deafnews.it/en/article/mindsdb -exposed-to-0-day-rce-openbbtable-class-executes-python-code-without-validation
Trend Micro's ZDI discloses a zero-day in BusyBox (ZDI-26-705): a symlink-based directory traversal in libarchive allows arbitrary file creation. The https:// deafnews.it/en/article/zdi-dis closes-zero-day-in-busybox-symlink-directory-traversal-enables-arbitrary-file-creation
Microsoft will not patch ZDI-26-708, a Windows zero-day exposing machine-account NTLM credentials. The company reversed its September 2026 fix plan, leaving https:// deafnews.it/en/article/microso ft-leaves-windows-zero-day-unpatched-ntlm-credential-theft-without-a-fix
Microsoft declines to patch ZDI-26-708, a zero-day in Windows HTTP Proxy that enables local privilege escalation. The vulnerability remains unaddressed. # Cybersecurity https:// deafnews.it/en/article/microso ft-leaves-0-day-open-refuses-patch-for-http-proxy-privilege-escalation
CVE-2026-92204: SSRF flaw in Airbyte's OneDrive connector sits unpatched for 10 months, exposing service-account data with a 7.7 CVSS score. Trend ZDI disclosed the https:// deafnews.it/en/article/airbyte -onedrive-zero-day-cve-2026-92204-remains-unpatched-after-10-months