0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Microsoft Entra ID Deserialization of Untrusted Data Vulnerability
Microsoft Entra ID formerly known as Azure Active Directory contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
Zimbra ZCS SNMP Command Injection — Unauthenticated RCE
CVE-2026-73570 — CVSS 8.9 command injection in Zimbra Collaboration Suite's SNMP handler enables unauthenticated remote code execution. Actively exploited in the wild. Patch: Zimbra 10.1.20.
TrueConf Server Missing Authentication for Critical Function Vulnerability
TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.
TrueConf Server Code Injection Vulnerability
TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
MLflow SSRF Lets Attackers Steal Cloud Credentials via Metadata Services
A server-side request forgery in MLflow before 3.15.0 allows unauthenticated access to internal endpoints including cloud metadata services, enabling cloud credential and IAM secret theft.
From the desk

Citrix Patches Critical NetScaler Auth Bypass
Citrix patches CVE-2026-19490, critical auth bypass in NetScaler ADC and Gateway, CVSS 9.3. No exploitation observed yet — here's what to patch before that changes.

Ransomware Affiliate Poses as Data Recovery Service
A ransomware affiliate calling itself Ransom Busters is emailing victims and offering to delete their stolen data from ransomware groups' servers for fees of $20,000 to $60,000.

Apple Patches 27 Flaws in iOS, iPadOS, and macOS Tahoe
Apple released updates fixing 27 vulnerabilities across iOS, iPadOS, and macOS Tahoe. One image-processing flaw carries code execution risk — patch this week, not next.

China-Linked AI Framework Hits APAC Government Targets
A Chinese-language operator used a complex AI framework to compromise APAC government agencies in what researchers call the first purported near-autonomous nation-state attack.

CISA, FBI: Medusa Ransomware Has 500+ Victims
CISA and the FBI updated their Medusa ransomware advisory, confirming the group has hit more than 500 organizations in critical infrastructure since 2021.

CoSnitch: Three Copilot Flaws Enable One-Click Data Theft
Varonis Threat Labs found three flaws in Microsoft Copilot Personal, named CoSnitch, that let attackers silently pull data from all connected apps in one click.




