0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Citrix NetScaler ADC/Gateway Unauthenticated RCE via Input Validation Flaw
Citrix NetScaler ADC and Gateway improper input validation flaw allows unauthenticated remote code execution; actively exploited and CISA KEV listed.
Citrix NetScaler ADC/Gateway RCE via Memory Buffer Mishandling
Citrix NetScaler ADC and Gateway memory buffer flaw allows remote code execution or denial of service; actively exploited and CISA KEV listed.
Microsoft SharePoint Code Injection Vulnerability
A code injection flaw in Microsoft Office SharePoint lets an authorized attacker execute code over a network. CVSS 8.8 (high), active exploitation confirmed, CISA KEV deadline September 28, 2026.
Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.
WSO2 Multiple Products Path Traversal to RCE
WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway contain a path traversal flaw enabling unauthenticated file upload and remote code execution. CVSS 10.0. Actively exploited since September 13, 2026; added to CISA KEV September 24.
WordPress core get_page_template path traversal enables unauthenticated RCE
Path traversal in WordPress core's get_page_template() enables unauthenticated local PHP file inclusion and conditional RCE. Actively exploited within 24 hours of disclosure. CVSS 8.1 High.
From the desk

JADEPUFFER Uses Stolen Service Principals to Destroy Azure
Microsoft Threat Intelligence tracks JADEPUFFER-linked attackers using compromised Azure service principals to delete cloud resources. Audit your tenant's non-human identities now.

ShinyHunters Retooled PeopleSoft Exploit, Google Warns
Google warns ShinyHunters has retooled its CVE-2026-35273 exploit and is running a fresh campaign against Oracle PeopleSoft. Patch or take exposed instances offline now.

Bitget Resumes Withdrawals After $387.5M DPRK Heist
Bitget restored Bitcoin withdrawals September 28, days after suspected North Korean hackers stole $387.5 million from the exchange in a backend compromise.

Citrix Patches NetScaler Zero-Days CVE-2026-88771, -88772
Citrix patched CVE-2026-88771 and CVE-2026-88772 in NetScaler ADC and Gateway. CISA orders federal agencies to apply by September 30.

Obot AI Platform Patches Three CVEs, Two Critical
Three GitHub Security Advisories disclose an unauthenticated Docker exposure and two MCP endpoint access control failures in the Obot AI agent platform.

Budibase 3.45.0 Fixes Six Security Flaws
Budibase 3.45.0 patches six CVEs including arbitrary file write (CVSS 8.8), SSO auth bypass (8.1), and SQL injection (8.0). Update now if Builder is exposed.




