Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2025-25249
[ HIGH ]CVSS 8.1EPSS 0.8%kev

Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

CVSS 8.1 heap overflow in FortiOS, FortiSwitchManager, and FortiSASE allows code execution via crafted packets. Actively exploited in PivotC2 RAT attacks; patched January 2026.

Fortinet / FortiOS, FortiSwitchManager, FortiSASE
CVE-2026-20079
[ CRITICAL ]CVSS 10.0EPSS 35.9%kev

Cisco FMC Authentication Bypass Enables Root OS Access

CVE-2026-20079 is a CVSS 10.0 unauthenticated auth bypass in Cisco FMC with root OS access. Actively exploited; CISA KEV deadline September 12.

Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
CVE-2026-87491
[ HIGH ]CVSS 8.8EPSS 0.3%kev

Google Chromium V8 Out of Bounds Write Vulnerability

Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Google / Chromium V8
CVE-2026-75650
[ CRITICAL ]CVSS 10.0EPSS 2.1%kev

Adobe Commerce and Magento Template Engine Injection (StyleSmuggler)

CVSS 10.0 template-injection in Adobe Commerce and Magento Open Source. Unauthenticated RCE exploited to plant Rust backdoors; emergency patch released September 8, 2026.

Adobe / Commerce and Magento Open Source
CVE-2026-81963
[ HIGH ]CVSS 7.8EPSS 0.6%kev

Microsoft Windows Update Stack Link-Following Privilege Escalation

“Windows Update Stack link-following flaw lets a local attacker escalate to SYSTEM. CVSS 7.8, actively exploited, on CISA KEV.”

Microsoft / Windows
CVE-2026-85880
[ HIGH ]CVSS 7.8EPSS 0.6%kev

Microsoft Windows ALPC Heap Buffer Overflow Privilege Escalation

“Windows ALPC contains a heap buffer overflow allowing AppContainer sandbox escape to local privilege escalation. CVSS 7.8, actively exploited, on CISA KEV.”

Microsoft / Windows
$ latest --more

From the desk

all articles →
~/articles/2026-09-09-f5-big-ip-apm-linux-rootkit-fileless
Linux Rootkit Targets F5 BIG-IP APM, Lives in Memory
● Breaking
f5

Linux Rootkit Targets F5 BIG-IP APM, Lives in Memory

Attackers are breaching F5 BIG-IP APM devices to deploy a Linux rootkit that hooks PHP file loading and injects a fileless web shell into memory, leaving no disk artifacts.

read →
~/articles/2026-09-09-microsoft-patch-tuesday-974-vulns-zero-days
Microsoft Patches Record 974 Vulns, 2 Zero-Days
● Breaking
microsoft

Microsoft Patches Record 974 Vulns, 2 Zero-Days

September 2026 Patch Tuesday: Microsoft patches a record 974 CVEs, including two exploited Windows zero-days now on CISA's KEV catalog.

read →
~/articles/2026-09-09-chrome-seventh-zero-day-2026-exploited
Google Patches Chrome's 7th Exploited Zero-Day of 2026
● Breaking
browser

Google Patches Chrome's 7th Exploited Zero-Day of 2026

Google patched the seventh actively exploited Chrome zero-day of 2026 on September 9, in a 230-vulnerability update. CVE designation pending.

read →
~/articles/2026-09-09-n-able-n-central-kev-pre-auth-rce
CISA Adds N-able N-central Auth Bypass to KEV
● Breaking
cisa kev

CISA Adds N-able N-central Auth Bypass to KEV

CISA added a maximum-severity pre-auth RCE in N-able N-central to its KEV catalog on September 9. N-able patched it; audit deployments for new user accounts.

read →
~/articles/2026-09-09-adobe-stylesmuggler-cve-2026-75650-patch
Adobe Patches StyleSmuggler, CVSS 10 Magento Zero-Day
● Breaking
adobe

Adobe Patches StyleSmuggler, CVSS 10 Magento Zero-Day

Adobe's September 8 emergency update patches CVE-2026-75650, a CVSS 10.0 template-injection zero-day exploited to plant Rust backdoors in Commerce and Magento stores. CISA deadline: September 11.

read →
~/articles/2026-09-08-fake-it-calls-m365-data-theft-extortion
Fake IT Calls Drive M365 Exec Data Theft Campaign
● Breaking
microsoft

Fake IT Calls Drive M365 Exec Data Theft Campaign

Threat hunters have disclosed an active data theft and extortion cluster targeting Microsoft 365 executives via vishing: fake IT help desk calls that harvest credentials and SaaS access.

read →