July 19, 2026
- Two Windows kernel write-ups drop with technical detail. A deep dive covers CVE-2026-58532, an unsigned 64-bit integer overflow during deserialization in
tcpip.syspatched in July (write-up); separately, a PoC and write-up for CVE-2026-50416 exploits a win32k desktop-heap info leak to disclose stable kernel pointers and bypass KASLR from an unprivileged process (PoC/write-up). · Vulnerabilities & Exploits
in WordPress "wp2shell" Escalates From Proof-of-Concept to Active Exploitation