Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2025-39682
[ CRITICAL ]CVSS 9.8EPSS 0.5%kev

Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

Linux / Kernel
CVE-2025-39964
[ HIGH ]CVSS 7.8EPSS 0.3%kev

Linux Kernel Race Condition Vulnerability

Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.

Linux / Kernel
CVE-2026-53266
[ HIGH ]CVSS 8.8EPSS 0.1%kev

Linux Kernel Out-of-Bounds Write Vulnerability

Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

Linux / Kernel
CVE-2026-58704
[ HIGH ]CVSS 8.8EPSS 0.2%kev

Google Pixel Cellular Modem Improper Authorization

Improper authorization in Google Pixel's cellular modem lets a nearby attacker bypass permission checks and escalate privileges without user interaction. CISA KEV, due 2026-09-19.

Google / Pixel
CVE-2026-76460
[ CRITICAL ]CVSS 10.0EPSS 0.8%kev

Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

CVSS 10.0 auth bypass in Cisco ISE and ISE-PIC. Unauthenticated attackers can bypass web management and gain root execution. Actively exploited; CISA KEV.

Cisco / Identity Services Engine
CVE-2026-87886
[ HIGH ]CVSS 7.8EPSS 0.3%kev

Acronis Backup Incorrect Default Permissions Vulnerability

Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.

Acronis / Backup
$ latest --more

From the desk

all articles →
~/articles/2026-09-18-unbound-cve-2026-81642-dnssec-rce
Unbound 1.26.1 Fixes Critical DNSSEC Heap Overflow
cloud

Unbound 1.26.1 Fixes Critical DNSSEC Heap Overflow

NLnet Labs patches a critical DNSSEC heap overflow in Unbound. All versions before 1.26.1 are affected; RCE is possible via attacker-controlled DNS zones.

read →
~/articles/2026-09-18-bind9-14-cves-doh-crash-patch
BIND 9 Patches 14 Flaws Including Unauthenticated DoH Crash
cloud

BIND 9 Patches 14 Flaws Including Unauthenticated DoH Crash

ISC patched 14 vulnerabilities in BIND 9, including a flaw that lets unauthenticated attackers crash resolvers via DNS-over-HTTPS. Update to 9.20.29 or 9.21.26.

read →
~/articles/2026-09-18-check-point-management-cve-2026-91843-rce-root
CVE-2026-91843: Check Point Management Server RCE
● Breaking
check point

CVE-2026-91843: Check Point Management Server RCE

A stack overflow in the Check Point Security Management Server login handler allows unauthenticated RCE as root. CVSS 9.8. Patch available via sk1000155.

read →
~/articles/2026-09-17-wso2-cve-2026-5430-cvss10-jwt-bypass-exploited
WSO2 CVSS 10 JWT Bypass Exploited in the Wild
wso2

WSO2 CVSS 10 JWT Bypass Exploited in the Wild

CVE-2026-5430 lets unauthenticated attackers forge JWTs and gain administrative access to WSO2 deployments. Active exploitation confirmed. Patch immediately.

read →
~/articles/2026-09-17-google-pixel-september-2026-modem-zero-day-cve-2026-58704
Google Patches Pixel Modem Zero-Day Under Attack
● Breaking
google

Google Patches Pixel Modem Zero-Day Under Attack

Google's September 2026 Pixel update patches 110 vulnerabilities including CVE-2026-58704, a high-severity modem flaw already under active exploitation. CISA deadline is September 19.

read →
~/articles/2026-09-17-cisco-ise-cve-2026-76460-cvss10-auth-bypass
Cisco ISE Zero-Day CVSS 10.0 Under Active Exploitation
● Breaking
cisco

Cisco ISE Zero-Day CVSS 10.0 Under Active Exploitation

CVE-2026-76460, a CVSS 10.0 auth bypass in Cisco ISE and ISE-PIC, is under active exploitation. Patches cover all supported releases; no workarounds exist.

read →