CVE Tools
Back to feed
PoC public Windows Defender zero-day BitLocker Microsoft privilege-escalation

Exploits and vulnerabilities in Q2 2026

Kaspersky Securelist·By Alexander Kolesnikov··16 min read
CVE Tools coverage

Kaspersky's Q2 2026 report confirms that proof-of-concept exploits are now publicly available for critical weaknesses in Microsoft Windows Defender, BitLocker, and the Linux kernel. The release of functional code for issues like the "BlueHammer" TOCTOU vulnerability in Windows Defender and local privilege escalation bugs in the Linux page cache allows attackers to immediately target unpatched systems. Organizations should apply patches urgently to mitigate these newly exposed risks.

The vulnerability landscape shifted significantly in Q2 2026. First, the number of registered CVEs reached an unprecedented level. This is driven primarily by the widespread adoption of AI, both for application development and search for security flaws. This resulted in entire new classes of vulnerabilities emerging, particularly in the Linux networking subsystem.…

Continue reading on Kaspersky Securelist