July 7, 2026
- Windows Installer CVE-2025-27727 (patched April 2025) lets a low-privilege attacker register arbitrary folders for SYSTEM-level deletion via the
TempPackagesCOM interface, escalating to SYSTEM — Exodus Intelligence published the technical writeup. · Vulnerabilities & Exploits
in A 16-Year-Old KVM Flaw Punches Through the Hypervisor Boundary