Critical flaw in Protobuf library enables JavaScript code execution
2026-04-19T13:23:33Z•19fbb0290f58b4dbabb533b686f6a340f1662850ed4fdcd4edfa87a41d6aea5c
active-exploitationapache-activemqcisacrypto-heistddosendpoint-evasiongrinexjavascriptmarimomicrosoft-defender-redsunmicrosoft-edge-bugnakivonkabuseoperation-poweroffoperational-technologypayouts-kingprotobuf.jsqemuransomwarercewater-treatment-targetingwindows-reboot-loopwindows-zero-dayzionsiphon
What happened
Multiple high-impact security events and active exploitations were reported: a proof-of-concept for a critical remote code execution flaw in protobuf.js was published, enabling JavaScript code execution; CISA warned of active exploitation of a high-severity Apache ActiveMQ vulnerability; a proof-of-concept for a Microsoft Defender zero-day (“RedSun”) that grants SYSTEM privileges was released; recently leaked Windows zero-days are being exploited in the wild; a critical Marimo notebook vulnerability is being abused to deploy NKAbuse malware from Hugging Face; Payouts King ransomware uses QEMU‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 19fbb0290f58b4dbabb533b686f6a340f1662850ed4fdcd4edfa87a41d6aea5c
- Enrichment time
- 2026-04-19T13:23:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.