0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
CVSS 8.1 heap overflow in FortiOS, FortiSwitchManager, and FortiSASE allows code execution via crafted packets. Actively exploited in PivotC2 RAT attacks; patched January 2026.
Cisco FMC Authentication Bypass Enables Root OS Access
CVE-2026-20079 is a CVSS 10.0 unauthenticated auth bypass in Cisco FMC with root OS access. Actively exploited; CISA KEV deadline September 12.
Google Chromium V8 Out of Bounds Write Vulnerability
Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Adobe Commerce and Magento Template Engine Injection (StyleSmuggler)
CVSS 10.0 template-injection in Adobe Commerce and Magento Open Source. Unauthenticated RCE exploited to plant Rust backdoors; emergency patch released September 8, 2026.
Microsoft Windows Update Stack Link-Following Privilege Escalation
“Windows Update Stack link-following flaw lets a local attacker escalate to SYSTEM. CVSS 7.8, actively exploited, on CISA KEV.”
Microsoft Windows ALPC Heap Buffer Overflow Privilege Escalation
“Windows ALPC contains a heap buffer overflow allowing AppContainer sandbox escape to local privilege escalation. CVSS 7.8, actively exploited, on CISA KEV.”
From the desk

Linux Rootkit Targets F5 BIG-IP APM, Lives in Memory
Attackers are breaching F5 BIG-IP APM devices to deploy a Linux rootkit that hooks PHP file loading and injects a fileless web shell into memory, leaving no disk artifacts.

Microsoft Patches Record 974 Vulns, 2 Zero-Days
September 2026 Patch Tuesday: Microsoft patches a record 974 CVEs, including two exploited Windows zero-days now on CISA's KEV catalog.

Google Patches Chrome's 7th Exploited Zero-Day of 2026
Google patched the seventh actively exploited Chrome zero-day of 2026 on September 9, in a 230-vulnerability update. CVE designation pending.

CISA Adds N-able N-central Auth Bypass to KEV
CISA added a maximum-severity pre-auth RCE in N-able N-central to its KEV catalog on September 9. N-able patched it; audit deployments for new user accounts.

Adobe Patches StyleSmuggler, CVSS 10 Magento Zero-Day
Adobe's September 8 emergency update patches CVE-2026-75650, a CVSS 10.0 template-injection zero-day exploited to plant Rust backdoors in Commerce and Magento stores. CISA deadline: September 11.

Fake IT Calls Drive M365 Exec Data Theft Campaign
Threat hunters have disclosed an active data theft and extortion cluster targeting Microsoft 365 executives via vishing: fake IT help desk calls that harvest credentials and SaaS access.




