July 18, 2026
- Windows AppResolver LPE (CVE-2026-50454) — a new write-up and PoC escalate from AppContainer to SYSTEM (David Carliez). Meanwhile the separately tracked LegacyHive User Profile Service zero-day exploit (earlier coverage) continues to circulate, now reported as granting admin on up-to-date systems (BleepingComputer). · Vulnerabilities & Exploits
in A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All