Skip to content
feed: live
>_ 0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-20316
[ MEDIUM ] CVSS 5.3 kev

Hard-coded credential in Cisco Secure FMC enables unauthenticated login

Cisco Secure FMC ships a static low-privileged account; remote unauthenticated attackers can log in and access sensitive data. CISA KEV confirmed July 29, 2026.

Cisco / Cisco Secure Firewall Management Center (FMC)
CVE-2026-16812
[ CRITICAL ] CVSS 10.0 kev

Arista VeloCloud Orchestrator OS Command Injection

CVSS 10.0 critical. Remote attackers can inject OS commands into Arista VeloCloud Orchestrator On-Prem, compromising the SD-WAN management plane.

Arista / VeloCloud Orchestrator On-Prem
CVE-2026-16232
[ CRITICAL ] CVSS 9.1 kev

Check Point SmartConsole improper authentication

CVE-2026-16232 lets unauthenticated attackers grab an admin token from SmartConsole. CISA KEV addition July 22; Check Point confirms active exploitation.

Check Point / SmartConsole
CVE-2021-27137
[ HIGH ] CVSS 8.1 kev

DD-WRT SSDP Stack-Based Buffer Overflow (UPnP)

An unsafe strcpy in DD-WRT's SSDP handling lets an unauthenticated attacker overflow an internal buffer via the UPnP listener and trigger code execution. Added to CISA KEV on 2026-07-21.

DD-WRT / DD-WRT router firmware (builds prior to revision 45724)
CVE-2026-25089
[ CRITICAL ] CVSS 9.8 kev

Fortinet FortiSandbox unauthenticated OS command injection (4.2, 4.4, 5.0, Cloud, PaaS)

An unauthenticated OS command injection across FortiSandbox 4.2, 4.4, 5.0, plus FortiSandbox Cloud and PaaS 5.0 lets a network attacker run arbitrary commands via crafted HTTP requests. CVSS 9.8; CISA-listed KEV.

Fortinet / FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS (multiple 4.x and 5.0 lines — see body)
CVE-2026-46817
[ CRITICAL ] CVSS 9.8 kev

Oracle E-Business Suite Payments improper privilege management (unauth RCE)

A critical improper-privilege-management flaw in the Oracle Payments component of Oracle E-Business Suite (File Transmission) that lets an unauthenticated network attacker take over Oracle Payments. Patched in Oracle's May 2026 Critical Patch Update; added to CISA KEV on July 15, 2026.

Oracle / E-Business Suite — Oracle Payments (versions 12.2.3–12.2.15)
$ latest --more

From the desk

all articles →
~/articles/2026-07-30-azure-cosmos-db-cosmosescape-cross-tenant
Azure CosmosEscape Flaw Exposed Any Tenant's Database
cloud

Azure CosmosEscape Flaw Exposed Any Tenant's Database

Wiz's CosmosEscape attack chain escaped Azure Cosmos DB's Gremlin sandbox, gained platform code execution, and extracted a key granting cross-tenant read/write access. Now patched.

read →
~/articles/2026-07-30-teams-vishing-chaos-ransomware-north-america
Teams IT Vishing Drops Chaos Ransomware on US Firms
● Breaking
ransomware

Teams IT Vishing Drops Chaos Ransomware on US Firms

Microsoft Teams vishing campaign impersonates IT support, gains remote access, and drops Chaos ransomware on North American organizations.

read →
~/articles/2026-07-30-shinyhunters-brinks-home-breach
Brinks Home Confirms Breach; ShinyHunters Claims Credit
● Breaking
threat intel

Brinks Home Confirms Breach; ShinyHunters Claims Credit

Brinks Home confirmed unauthorized access to systems and file exfiltration. ShinyHunters claims credit and is threatening a data dump.

read →
~/articles/2026-07-30-analog-devices-data-breach-exfiltration
Analog Devices Confirms Breach, Files Exfiltrated
● Breaking
threat intel

Analog Devices Confirms Breach, Files Exfiltrated

Analog Devices disclosed that an unauthorized party accessed its systems and exfiltrated files. The U.S. semiconductor maker says operations remain unaffected.

read →
~/articles/2026-07-30-copilot-word-prompt-injection-propagation
Copilot Prompt Injection Can Rewrite Docs, Self-Propagate
microsoft

Copilot Prompt Injection Can Rewrite Docs, Self-Propagate

Hidden instructions in Word docs can make M365 Copilot falsify figures and embed the attack in output files, which then fire again in the next Copilot session. No patch announced.

read →
~/articles/2026-07-30-anysign4pc-korean-watering-hole-signbt-copperhedge
AnySign4PC Exploited in Korean Watering Hole Campaign
● Breaking
threat intel

AnySign4PC Exploited in Korean Watering Hole Campaign

State-sponsored attackers compromised trusted Korean websites to exploit AnySign4PC financial software, silently installing SIGNBT or COPPERHEDGE backdoors without user interaction.

read →