0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Cisco ASA and FTD VPN Heap Inspection Denial-of-Service Flaw
Unauthenticated remote attackers can crash Cisco Secure Firewall ASA and FTD devices over VPN. Added to CISA KEV on 2026-08-11 with a three-day federal remediation deadline.
Windows AFD WinSock Use-After-Free Privilege Escalation
Use-after-free in Windows Ancillary Function Driver for WinSock (afd.sys) lets local attackers gain SYSTEM privileges via race condition. Actively exploited by Lazarus.
Metabase SQL Injection Vulnerability
Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.
IBM Langflow Code Injection Vulnerability
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
From the desk

Ransomware Gang Seizes Hospital's Facebook Page
Ransomware attackers hijacked a hospital system's Facebook page during an active breach, claiming 6TB including mental health, abortion, and sexual assault records.

DeadLock Moves Extortion Infra to Polygon Blockchain
DeadLock ransomware has shifted victim comms and data-leak ops to Polygon smart contracts and Session messaging to resist law enforcement seizures.

Sandworm Targets IT Pros With Trojanized WireGuard Client
CERT-UA links UAC-0145 to fake recruiting ops targeting sysadmins since May. The lure delivers a trojanized WireGuard client with remote command execution.

Cisco ASA/FTD VPN Flaw Exploited, CISA Sets Aug 14 Deadline
CVE-2026-20349 added to CISA KEV today. Unauthenticated attackers can crash Cisco ASA and FTD devices over VPN — CISA's due date is August 14.

Zero-Click RCE in Zoom Annotation — Patch Now
A flaw in Zoom's annotation tool let any meeting participant execute code on another attendee's machine — zero clicks required. Update Zoom clients now.

Microsoft Patches 400 Flaws, Lazarus Exploited One First
Microsoft's August Patch Tuesday hits 400+ flaws. One is actively exploited by Lazarus via afd.sys. Two more are publicly disclosed. Here's your triage stack.




