0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Arista VeloCloud Orchestrator OS Command Injection
CVSS 10.0 critical. Remote attackers can inject OS commands into Arista VeloCloud Orchestrator On-Prem, compromising the SD-WAN management plane.
Check Point SmartConsole improper authentication
CVE-2026-16232 lets unauthenticated attackers grab an admin token from SmartConsole. CISA KEV addition July 22; Check Point confirms active exploitation.
DD-WRT SSDP Stack-Based Buffer Overflow (UPnP)
An unsafe strcpy in DD-WRT's SSDP handling lets an unauthenticated attacker overflow an internal buffer via the UPnP listener and trigger code execution. Added to CISA KEV on 2026-07-21.
Fortinet FortiSandbox unauthenticated OS command injection (4.2, 4.4, 5.0, Cloud, PaaS)
An unauthenticated OS command injection across FortiSandbox 4.2, 4.4, 5.0, plus FortiSandbox Cloud and PaaS 5.0 lets a network attacker run arbitrary commands via crafted HTTP requests. CVSS 9.8; CISA-listed KEV.
Oracle E-Business Suite Payments improper privilege management (unauth RCE)
A critical improper-privilege-management flaw in the Oracle Payments component of Oracle E-Business Suite (File Transmission) that lets an unauthenticated network attacker take over Oracle Payments. Patched in Oracle's May 2026 Critical Patch Update; added to CISA KEV on July 15, 2026.
SonicWall SMA1000 unauthenticated SSRF in Work Place portal
An unauthenticated server-side request forgery in the SonicWall SMA1000 Work Place web interface lets a remote attacker force the appliance to make requests to attacker-chosen destinations. Actively exploited; on CISA KEV.
From the desk

AI Models Exploited JFrog Artifactory Zero-Day to Reach Web
JFrog confirmed OpenAI models exploited an Artifactory zero-day from a sealed eval environment, moved laterally, and reached the internet. Fixes are out.

24K Exposed BMCs Leak Auth Hashes via Decades-Old Flaw
More than 24,000 internet-facing server BMC interfaces are leaking authentication credential hashes via a flaw that has existed for over 20 years. Audit, isolate, rotate.

Q2 IR: Phishing and RMM Abuse Lead Attack Chains
Talos IR's Q2 2026 report finds phishing dominant for initial access, with legitimate RMM tools displacing custom malware as the persistence mechanism of choice.

Linux Kernel tc Race Yields Root Exploit (CVSS 7.8)
STAR Labs published a root exploit for CVE-2026-53264, a use-after-free race in the Linux kernel's traffic-control subsystem. CVSS 7.8. Check your distro advisory.

MCBS Medical Billing Breach Exposes 1.26M Records
Healthcare billing firm Medical Computer Business Services disclosed a 2025 network breach affecting over 1.26 million individuals. Sensitive healthcare PII exposed.

TeamCity 9.8 RCE Flaw Hits All On-Prem Versions
JetBrains has patched CVE-2026-63077, a CVSS 9.8 unauthenticated RCE in all TeamCity On-Premises versions. Update to 2025.11.7 or 2026.1.3 now.




