Daily digest
What broke on Tuesday, July 28, 2026
0 KEV additions . 1 fresh critical . 0 EPSS movers
Actively exploited
0Just added to the CISA KEV catalog
No new KEV additions in this window.
Fresh criticals
1Published in this 24h window with CVSS greater than or equal to 7
7.5
HIGH
Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching mechanism for path validation during the extraction process. An attacker can bypass security checks designed to prevent directory traversal. The intended security function, isOutsid
AV:NETWORK . published 2026-07-28 06:16:41
Climbing fast
0EPSS percentile jumped 20 points or more overnight
Movers need two consecutive daily snapshots. Come back tomorrow.