Skip to content
feed: live
0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-88779
[ HIGH ]CVSS 7.5EPSS 0.6%kev

Citrix NetScaler Memory Buffer Flaw Enables Denial-of-Service Attacks

NetScaler ADC and Gateway contain an exploited memory-buffer flaw enabling denial of service. CISA KEV listed October 4, federal deadline October 7.

Citrix / NetScaler ADC, NetScaler Gateway
CVE-2026-102489
[ HIGH ]EPSS 1.4%kev

Zammad GmbH Zammad Session Fixation Vulnerability

Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.

Zammad GmbH / Zammad
CVE-2026-102490
[ HIGH ]EPSS 0.6%kev

Zammad GmbH Zammad Improper Privilege Management Vulnerability

Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.

Zammad GmbH / Zammad
CVE-2026-104286
[ CRITICAL ]CVSS 9.8EPSS 2.2%kev

Fortinet FortiMail Path Traversal and NULL Byte Flaw

Fortinet FortiMail path traversal flaw (CVSS 9.8) lets unauthenticated attackers write arbitrary files. Actively exploited; CISA KEV listed October 1, 2026.

Fortinet / FortiMail
CVE-2026-76504
[ CRITICAL ]CVSS 9.8EPSS 1.8%kev

Cisco Catalyst SD-WAN Manager Authentication Bypass

Unauthenticated attackers can gain admin access to Cisco Catalyst SD-WAN Manager via a URI encoding flaw. CVSS 9.8, actively exploited, CISA KEV listed.

Cisco / Catalyst SD-WAN Manager
CVE-2026-86950
[ HIGH ]CVSS 8.8EPSS 1.2%kev

CoreGraphics memory confusion in Apple iOS 26, iPadOS, macOS 26, macOS 15

CoreGraphics memory confusion flaw in Apple iOS 26, iPadOS, macOS 26, and macOS 15. CVSS 8.8 high. Apple reports possible exploitation in targeted attacks.

Apple / iOS 26, iPadOS, macOS 26, macOS 15
$ latest --more

Latest security news

all articles →
~/articles/2026-10-06-shinyhunters-jordan-arrest-fbi
ransomware

ShinyHunters Member Arrested in Jordan, Aiding FBI

Saif al-Din Khader, detained in Jordan, is cooperating with the FBI over a major breach linked to ShinyHunters, the second arrest in the group within a week.

read →
~/articles/2026-10-06-perforce-p4search-cve-2026-100102-rce-auth-bypass
cloud

Perforce P4 Search Containers Expose RCE, Auth Bypass

Perforce P4 Search containers before 2026.4.2 expose an unauthenticated JDWP debug interface (RCE, CVSS 9.8) and reset auth tokens to a documented default (CVSS 9.1).

read →
~/articles/2026-10-06-exchange-cve-2026-96940-mailbox-privilege-escalation
● Breaking
microsoft

Exchange Server OOB Patch Closes Mailbox-Read Flaw

CVE-2026-96940, a CVSS 8.8 privilege escalation flaw in on-prem Microsoft Exchange, lets authenticated attackers read other users' mailboxes. Patch available now; Exchange Online already fixed.

read →
~/articles/2026-10-05-atb-ukraine-cyberattack-data-leak-threatened
● Breaking
ransomware

ATB Ukraine: Cyberattack Confirmed, Data Leak Threatened

Ukraine's largest grocery chain ATB confirmed a cyberattack after hackers posted an extortion demand on its website and threatened to release stolen data.

read →
~/articles/2026-10-05-uic-college-medicine-ransomware-data-stolen
● Breaking
ransomware

Ransomware Hits UIC Medical School, Data Stolen

Ransomware struck the University of Illinois Chicago College of Medicine. Data was stolen from servers. Threat group, scope, and ransomware demand all unconfirmed.

read →
~/articles/2026-10-05-rejetto-hfs-cve-2026-61500-rce-active-exploitation
threat intel

Rejetto HFS RCE Under Active Exploitation

CVE-2026-61500 is a critical CVSS 4.0 9.3 flaw in Rejetto HFS: attackers can recover the session-signing key, forge admin sessions, and execute code remotely.

read →