Zero Day Initiative Upcoming Advisories

ZDI: Upcoming Advisories The following is a list of vulnerabilities discovered by Zero Day Initiative researchers that are yet to be publicly disclosed. The affected vendor has been contacted on the specified date and while they work on a patch for these vulnerabilities, Trend Micro customers are protected from exploitation by IPS filters delivered ahead of public disclosure. Once the affected vendor patches the vulnerability, we publish an accompanying security advisory which describes the issue, including links to the vendor’s fixes.

  • ZDI-CAN-28491: Microsoft
    on November 7, 2025 at 6:00 am

    A CVSS score 3.3 AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N severity vulnerability discovered by ‘Jonathan Lein of Trend Research’ was reported to the affected vendor on: 2025-11-07, 2 days ago. The vendor is given until 2026-03-07 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-28159: Microsoft
    on November 7, 2025 at 6:00 am

    A CVSS score 8.8 AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by ‘Marcin Wiazowski’ was reported to the affected vendor on: 2025-11-07, 2 days ago. The vendor is given until 2026-03-07 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-28417: Autodesk
    on November 6, 2025 at 6:00 am

    A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Rocco Calvi (@TecR0c) with TecSecurity’ was reported to the affected vendor on: 2025-11-06, 3 days ago. The vendor is given until 2026-03-06 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-28421: Autodesk
    on November 6, 2025 at 6:00 am

    A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Rocco Calvi (@TecR0c) with TecSecurity’ was reported to the affected vendor on: 2025-11-06, 3 days ago. The vendor is given until 2026-03-06 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-28529: llama.cpp
    on November 6, 2025 at 6:00 am

    A CVSS score 4.0 AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N severity vulnerability discovered by ‘Nitesh Surana (niteshsurana.com) of Trend Research’ was reported to the affected vendor on: 2025-11-06, 3 days ago. The vendor is given until 2026-03-06 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-27899: JumpCloud
    on November 5, 2025 at 6:00 am

    A CVSS score 6.7 AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Hillel Pinto’ was reported to the affected vendor on: 2025-11-05, 4 days ago. The vendor is given until 2026-03-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-28382: ByteDance
    on November 5, 2025 at 6:00 am

    A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Peter Girnus (@gothburz), Demeng Chen, and Brandon Niemczyk of Trend Zero Day Initiative’ was reported to the affected vendor on: 2025-11-05, 4 days ago. The vendor is given until 2026-03-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-28477: Lexmark
    on November 5, 2025 at 6:00 am

    A CVSS score 7.8 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Interrupt Labs’ was reported to the affected vendor on: 2025-11-05, 4 days ago. The vendor is given until 2026-03-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-28379: Docker
    on November 5, 2025 at 6:00 am

    A CVSS score 7.3 AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H severity vulnerability discovered by ‘Nitesh Surana (niteshsurana.com) of Trend Research’ was reported to the affected vendor on: 2025-11-05, 4 days ago. The vendor is given until 2026-03-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-28081: Apple
    on November 5, 2025 at 6:00 am

    A CVSS score 3.3 AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N severity vulnerability discovered by ‘George Karchemsky (@gkarchemsky)’ was reported to the affected vendor on: 2025-11-05, 4 days ago. The vendor is given until 2026-03-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-28299: ALGO
    on November 5, 2025 at 6:00 am

    A CVSS score 5.3 AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N severity vulnerability discovered by ‘Vera Mensa of Claroty Research – Team82’ was reported to the affected vendor on: 2025-11-05, 4 days ago. The vendor is given until 2026-03-05 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-28404: Dassault Systèmes
    on November 4, 2025 at 6:00 am

    A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Anonymous’ was reported to the affected vendor on: 2025-11-04, 5 days ago. The vendor is given until 2026-03-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-28403: Foxit
    on November 4, 2025 at 6:00 am

    A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘KX.H’ was reported to the affected vendor on: 2025-11-04, 5 days ago. The vendor is given until 2026-03-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-28306: Foxit
    on November 4, 2025 at 6:00 am

    A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Anonymous’ was reported to the affected vendor on: 2025-11-04, 5 days ago. The vendor is given until 2026-03-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-28315: Dassault Systèmes
    on November 4, 2025 at 6:00 am

    A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Anonymous’ was reported to the affected vendor on: 2025-11-04, 5 days ago. The vendor is given until 2026-03-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-28378: Dassault Systèmes
    on November 4, 2025 at 6:00 am

    A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Anonymous’ was reported to the affected vendor on: 2025-11-04, 5 days ago. The vendor is given until 2026-03-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-28523: Foxit
    on November 4, 2025 at 6:00 am

    A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Mat Powell of Trend Zero Day Initiative’ was reported to the affected vendor on: 2025-11-04, 5 days ago. The vendor is given until 2026-03-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-28531: Foxit
    on November 4, 2025 at 6:00 am

    A CVSS score 3.3 AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N severity vulnerability discovered by ‘Mat Powell of Trend Zero Day Initiative’ was reported to the affected vendor on: 2025-11-04, 5 days ago. The vendor is given until 2026-03-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-28532: Foxit
    on November 4, 2025 at 6:00 am

    A CVSS score 3.3 AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N severity vulnerability discovered by ‘Mat Powell of Trend Zero Day Initiative’ was reported to the affected vendor on: 2025-11-04, 5 days ago. The vendor is given until 2026-03-04 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-28290: ALGO
    on October 31, 2025 at 5:00 am

    A CVSS score 7.2 AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Vera Mensa of Claroty Research – Team82’ was reported to the affected vendor on: 2025-10-31, 9 days ago. The vendor is given until 2026-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-28292: ALGO
    on October 31, 2025 at 5:00 am

    A CVSS score 7.2 AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Vera Mensa of Claroty Research – Team82’ was reported to the affected vendor on: 2025-10-31, 9 days ago. The vendor is given until 2026-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-28294: ALGO
    on October 31, 2025 at 5:00 am

    A CVSS score 7.5 AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Vera Mensa of Claroty Research – Team82’ was reported to the affected vendor on: 2025-10-31, 9 days ago. The vendor is given until 2026-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-28295: ALGO
    on October 31, 2025 at 5:00 am

    A CVSS score 7.5 AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Vera Mensa of Claroty Research – Team82’ was reported to the affected vendor on: 2025-10-31, 9 days ago. The vendor is given until 2026-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-28296: ALGO
    on October 31, 2025 at 5:00 am

    A CVSS score 8.1 AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Vera Mensa of Claroty Research – Team82’ was reported to the affected vendor on: 2025-10-31, 9 days ago. The vendor is given until 2026-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-28291: ALGO
    on October 31, 2025 at 5:00 am

    A CVSS score 7.2 AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Vera Mensa of Claroty Research – Team82’ was reported to the affected vendor on: 2025-10-31, 9 days ago. The vendor is given until 2026-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-28322: ALGO
    on October 31, 2025 at 5:00 am

    A CVSS score 7.2 AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Vera Mensa of Claroty Research – Team82’ was reported to the affected vendor on: 2025-10-31, 9 days ago. The vendor is given until 2026-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-28289: ALGO
    on October 31, 2025 at 5:00 am

    A CVSS score 7.2 AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Vera Mensa of Claroty Research – Team82’ was reported to the affected vendor on: 2025-10-31, 9 days ago. The vendor is given until 2026-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-28297: ALGO
    on October 31, 2025 at 5:00 am

    A CVSS score 5.3 AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N severity vulnerability discovered by ‘Vera Mensa of Claroty Research – Team82’ was reported to the affected vendor on: 2025-10-31, 9 days ago. The vendor is given until 2026-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-28301: ALGO
    on October 31, 2025 at 5:00 am

    A CVSS score 8.1 AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Vera Mensa of Claroty Research – Team82’ was reported to the affected vendor on: 2025-10-31, 9 days ago. The vendor is given until 2026-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

  • ZDI-CAN-28293: ALGO
    on October 31, 2025 at 5:00 am

    A CVSS score 7.2 AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Vera Mensa of Claroty Research – Team82’ was reported to the affected vendor on: 2025-10-31, 9 days ago. The vendor is given until 2026-02-28 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.

Share Websitecyber
We are an ethical website cyber security team and we perform security assessments to protect our clients.