0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.
IBM Langflow Code Injection Vulnerability
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.
Hard-coded credential in Cisco Secure FMC enables unauthenticated login
Cisco Secure FMC ships a static low-privileged account; remote unauthenticated attackers can log in and access sensitive data. CISA KEV confirmed July 29, 2026.
Microsoft MSHTML security feature bypass
Protection mechanism failure in Microsoft MSHTML lets unauthenticated attackers bypass a security feature over the network. CVSS 8.8, patched in Microsoft's February 2026 Patch Tuesday.
From the desk

Ten MCP Server CVEs Drop in a Single Day
Ten MCP server CVEs hit NVD on August 9 — all SSRF or path traversal. Same two classes, ten different projects, most maintainers silent on coordinated disclosure.

Ash Framework: OOM Cursor Bomb and Auth Bypass
Ash (Elixir) gets two CVEs: an OOM-bomb via keyset pagination cursor and an auth bypass via query injection in managed relationships. Upgrade now.

Kemp LoadMaster CVE-2026-8037 Lands on CISA KEV
CISA added the critical Kemp LoadMaster command-injection flaw to its KEV catalog Friday after 792 reported exploitation attempts. If you haven't patched since June 4, that window is closed.

Public PoC Lands for Langflow's 9.8 Unauth RCE — Patch to 1.10.1 Now
CVE-2026-9198 lets an unauthenticated network caller reach full remote code execution on default Langflow deployments. It's on CISA's KEV list, it's exploited, and a public proof-of-concept is now out.

Apache Tomcat EncryptInterceptor Bypass Added to KEV — Patch by Aug 7
CVE-2026-34486 lets attackers bypass Tomcat's EncryptInterceptor, exposing clustered node traffic. CISA added it to KEV on Aug 4 after active exploitation. Fixed builds are out.

CISA Flags N-able N-central Auth Bypass — Patch Before Today's Deadline
CVE-2026-18577, an authentication bypass in N-able N-central, is on CISA's KEV list after active exploitation. It's an incomplete fix for an earlier flaw, and MSPs are the blast radius.




