Monday , October 5 2026
Google

CVE-2026-0073
Google Confirms Critical Android 0-Click Flaw

Google has released the May 2026 Android Security Bulletin, warning everyone about a critical remote code execution (RCE) flaw. Tracked as CVE-2026-0073, this serious flaw is found in the core part of the Android System. It lets a bad actor to get remote shell access without needing the device owner to do anything.

Threat actors can make this zero-click attack from nearby, which means they just need to be on the same local network or close to a weak mobile device.

Citrix NetScaler SAML 0-Day Flaw Under Attack

Citrix has put out emergency security updates for a NetScaler SAML flaw that hackers are using. Known as CVE-2026-88779, this...
Read More
Citrix NetScaler SAML 0-Day Flaw Under Attack

Major Danish university breached, 200,000 users at risk

Hackers got into the identity and access management system at the Technical University of Denmark (DTU) and downloaded a lot...
Read More
Major Danish university breached, 200,000 users at risk

Microsoft’s X account hijacked to promote Clippy crypto scam

Microsoft's official X account was taken over to promote an unapproved Clippy-themed cryptocurrency. The tech giant’s X account, with 13...
Read More
Microsoft’s X account hijacked to promote Clippy crypto scam

Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

CPanel has put out security updates to fix three problems in cPanel & WHM. These problems could let attackers take...
Read More
Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Nearly 100,000 Bee Cheng Hiang customers had their email addresses leaked when an employee used an AI tool to generate...
Read More
Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. They send special emails that...
Read More
Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

Google has said that hackers are using two serious Citrix NetScaler security holes to get root access, set up hidden...
Read More
Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is alerting people about a major flaw in MikroTik RouterOS. This could...
Read More
CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

Apple has launched iOS 26.7.1 and iPadOS 26.7.1 to fix a serious zero-day flaw that it believes might have been...
Read More
Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

JadePuffer Agentic AI targets and destroys Azure’s cloud resources

The JadePuffer ransomware group is attacking Azure users with agent-based attacks that gather information, steal passwords, and damage key components. The...
Read More
JadePuffer Agentic AI targets and destroys Azure’s cloud resources

Android Zero-Click Vulnerability

The main issue of CVE-2026-0073 is in the adbd part, which stands for the Android Debug Bridge daemon. Developers usually use this system service to talk to a device, run terminal commands, and change how the system works.

The flaw lets attackers run remote code as a “shell” user, so they can get around normal app security. They do not need special permissions or user action to launch their harmful programs successfully.

Imagine the adbd service as a restricted maintenance door on a secure corporate building.This flaw is like a key that opens things wirelessly, letting a bad person unlock the door and control the building’s systems without the guard seeing it.

The adbd service is part of Project Mainline and is updated through Google Play. This issue affects many recent versions of the operating system.

Android 14, Android 15, Android 16, and Android 16-QPR2 devices are currently at risk.

Google fixed this flaw in the May 1, 2026, security update explained in the Android Security Bulletin May 2026. All Android device makers were told about this issue at least a month early to help them get ready for online firmware updates.

Source code updates are also being added to the Android Open Source Project (AOSP) to keep the platform stable for everyone.

To make sure a device is safe, go to system settings and check if the security patch level is May 1, 2026, or newer. Users should also check for Google Play system updates themselves. Some devices with Android 10 or newer might get special updates this way.

Check Also

Google

Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

Google has said that hackers are using two serious Citrix NetScaler security holes to get …