vulnerabilities

Vulnerabilities — Mad Hatter Security
CVE-2026-11645 CVSS 9.8
Critical · Exploited

Chrome V8 zero-day exploited in the wild — patch now

A type-confusion bug in V8's JIT compiler allows remote code execution via a crafted web page. Active exploitation confirmed.

Jun 19, 2026
Google Chrome
CVE-2026-09812 CVSS 9.1
Critical · RCE

Record Patch Tuesday: 206 flaws fixed, including three zero-days

This month's update addresses a record number of vulnerabilities, with three under active exploitation and one critical RCE in a core service.

Jun 19, 2026
Windows Server
CVE-2026-07734 CVSS 8.6
High · Unauthenticated

Critical Splunk-style flaw lets attackers run code without authentication

An unauthenticated deserialization flaw in a popular log management platform allows full remote code execution on the management node.

Jun 18, 2026
Log Management Platform
CVE-2026-04421 CVSS 7.9 · Unpatchable
High · Hardware

'usbliter8' breaks Apple A12 and A13 Secure Boot ROM chain

A boot-ROM exploit achieves arbitrary code execution at the hardware root of trust. Because the flaw lives in silicon, no software patch can fully close it.

Jun 19, 2026
Apple A12 / A13 SoC
CVE-2026-15290 CVSS 6.4
Medium · PoC available

AutoJack flaw lets a web page hijack an AI browsing agent

A prompt-injection chain embedded in page content can redirect an autonomous browsing agent into executing code on the host machine.

Jun 19, 2026
AI Browsing Agents
CVE-2026-02218 CVSS 4.2
Low · Patched

Minor information disclosure fixed in popular CMS plugin

A low-severity flaw allowed limited metadata disclosure under specific misconfigurations. A patch is available and adoption is now over 80%.

Jun 9, 2026
WordPress Plugin

© 2026 the-madhatter.com — Security research worth losing your head over.