0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Check Point SmartConsole improper authentication
CVE-2026-16232 lets unauthenticated attackers grab an admin token from SmartConsole. CISA KEV addition July 22; Check Point confirms active exploitation.
DD-WRT SSDP Stack-Based Buffer Overflow (UPnP)
An unsafe strcpy in DD-WRT's SSDP handling lets an unauthenticated attacker overflow an internal buffer via the UPnP listener and trigger code execution. Added to CISA KEV on 2026-07-21.
Fortinet FortiSandbox unauthenticated OS command injection (4.2, 4.4, 5.0, Cloud, PaaS)
An unauthenticated OS command injection across FortiSandbox 4.2, 4.4, 5.0, plus FortiSandbox Cloud and PaaS 5.0 lets a network attacker run arbitrary commands via crafted HTTP requests. CVSS 9.8; CISA-listed KEV.
Oracle E-Business Suite Payments improper privilege management (unauth RCE)
A critical improper-privilege-management flaw in the Oracle Payments component of Oracle E-Business Suite (File Transmission) that lets an unauthenticated network attacker take over Oracle Payments. Patched in Oracle's May 2026 Critical Patch Update; added to CISA KEV on July 15, 2026.
SonicWall SMA1000 unauthenticated SSRF in Work Place portal
An unauthenticated server-side request forgery in the SonicWall SMA1000 Work Place web interface lets a remote attacker force the appliance to make requests to attacker-chosen destinations. Actively exploited; on CISA KEV.
SonicWall SMA1000 post-authentication OS command injection
A post-authentication OS command injection in the SonicWall SMA1000 lets an administrator execute arbitrary OS commands on the appliance. Actively exploited alongside CVE-2026-15409; on CISA KEV.
From the desk

Cruciferra Crypter: BYOVD and Process Ghosting on the Market
Proofpoint's analysis of Cruciferra shows a crypter-as-a-service bundling BYOVD and Process Ghosting — now serving multiple unrelated threat clusters.

Dependabot Gets 3-Day Cooldown to Block Package Poisoning
GitHub's Dependabot now waits three days before auto-updating packages. PyPI adds parallel controls. Here's what to configure in your pipeline.

TELESHIM Uses Telegram C2 Against Middle East Governments
Zscaler ThreatLabz flags three new malware families targeting Middle East government entities. The C2 channel: Telegram. Attribution: East Asia-linked.

Steam Forums Used to Deliver XMRig via ClickFix
Steam game forums are being seeded with fake troubleshooting posts that use ClickFix to deliver XMRig cryptomining malware on unsuspecting players.

Insurance Phishing Moves to Real-Time Account Hijacking
CTM360 finds insurance phishing has upgraded from credential harvesting to real-time session hijacking — MFA alone isn't enough anymore.

GitHub, PyPI Add Time-Gated Supply Chain Defenses
GitHub adds a 72-hour Dependabot cooldown on new package versions; PyPI blocks release updates after 14 days. Both changes buy detection time before malicious code spreads.




