Critical flaw in Protobuf library enables JavaScript code execution

2026-04-19T13:23:33Z19fbb0290f58b4dbabb533b686f6a340f1662850ed4fdcd4edfa87a41d6aea5c
active-exploitationapache-activemqcisacrypto-heistddosendpoint-evasiongrinexjavascriptmarimomicrosoft-defender-redsunmicrosoft-edge-bugnakivonkabuseoperation-poweroffoperational-technologypayouts-kingprotobuf.jsqemuransomwarercewater-treatment-targetingwindows-reboot-loopwindows-zero-dayzionsiphon

What happened

Multiple high-impact security events and active exploitations were reported: a proof-of-concept for a critical remote code execution flaw in protobuf.js was published, enabling JavaScript code execution; CISA warned of active exploitation of a high-severity Apache ActiveMQ vulnerability; a proof-of-concept for a Microsoft Defender zero-day (“RedSun”) that grants SYSTEM privileges was released; recently leaked Windows zero-days are being exploited in the wild; a critical Marimo notebook vulnerability is being abused to deploy NKAbuse malware from Hugging Face; Payouts King ransomware uses QEMU‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
19fbb0290f58b4dbabb533b686f6a340f1662850ed4fdcd4edfa87a41d6aea5c
Enrichment time
2026-04-19T13:23:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.