Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-20349
[ HIGH ]CVSS 8.6EPSS 0.9%kev

Cisco ASA and FTD VPN Heap Inspection Denial-of-Service Flaw

Unauthenticated remote attackers can crash Cisco Secure Firewall ASA and FTD devices over VPN. Added to CISA KEV on 2026-08-11 with a three-day federal remediation deadline.

Cisco / Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
CVE-2026-68820
[ HIGH ]CVSS 7.0EPSS 0.3%kev

Windows AFD WinSock Use-After-Free Privilege Escalation

Use-after-free in Windows Ancillary Function Driver for WinSock (afd.sys) lets local attackers gain SYSTEM privileges via race condition. Actively exploited by Lazarus.

Microsoft / Windows (multiple versions)
CVE-2026-72898
[ CRITICAL ]CVSS 10.0EPSS 10.4%kev

Metabase SQL Injection Vulnerability

Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.

Metabase / Metabase
CVE-2026-18556
[ HIGH ]CVSS 7.4EPSS 0.5%kev

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.

N-able / N-central
CVE-2026-34486
[ HIGH ]CVSS 7.5EPSS 82.9%kev

Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.

Apache / Tomcat
CVE-2026-9198
[ CRITICAL ]CVSS 9.8EPSS 17.4%kev

IBM Langflow Code Injection Vulnerability

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

IBM / Langflow
$ latest --more

From the desk

all articles →
~/articles/2026-08-16-amnesiastealer-macos-browser-hijack
AmnesiaStealer Hijacks macOS Browser Sessions
● Breaking
threat intel

AmnesiaStealer Hijacks macOS Browser Sessions

Jamf found a new macOS infostealer that hijacks Chrome in headless mode, giving attackers live remote control of authenticated browser sessions via ClickFix lures.

read →
~/articles/2026-08-16-wordpress-pods-link-library-critical-vulns
Critical Flaws in Pods, Link Library Hit WordPress Sites
wordpress

Critical Flaws in Pods, Link Library Hit WordPress Sites

Pods (CVSS 9.8) and Link Library (CVSS 9.1) expose WordPress sites to unauthenticated privilege escalation and arbitrary file deletion with RCE potential.

read →
~/articles/2026-08-16-siyuan-v374-eleven-cves-critical-rce
SiYuan v3.7.4 Patches 11 CVEs, Critical RCE Confirmed
● Breaking
threat intel

SiYuan v3.7.4 Patches 11 CVEs, Critical RCE Confirmed

SiYuan v3.7.4 patches eleven CVEs including critical Electron XSS-to-RCE chains and a CVSS 9.8 auth bypass. Desktop users should update immediately.

read →
~/articles/2026-08-16-threema-ddos-service-disruption
Threema Hit by Large-Scale DDoS, Service Disrupted
● Breaking
threat intel

Threema Hit by Large-Scale DDoS, Service Disrupted

Multiple large-scale DDoS attacks disrupted Threema's secure messaging service this week. No message content breach — availability impact only.

read →
~/articles/2026-08-16-august-kernel-drop-enterprise-cves
August Kernel Drop: The Enterprise CVEs Nobody Wrote About
Analysis
linux kernel

August Kernel Drop: The Enterprise CVEs Nobody Wrote About

Thirty-plus kernel CVEs hit NVD on August 15. Three affecting ThunderboltIP, NVMe-oF auth, and TPM matter to enterprise infrastructure and flew under radar.

read →
~/articles/2026-08-16-linux-kernel-brcmfmac-wifi-heap-overflow-bpf-bypass
Linux Kernel Patches WiFi Heap Overflow, BPF Bypass
● Breaking
linux kernel

Linux Kernel Patches WiFi Heap Overflow, BPF Bypass

August 15 kernel stable drop fixes a Broadcom WiFi heap overflow triggerable by a rogue AP, a BPF verifier bypass, and 28 other security fixes.

read →