Skip to content
feed: live
0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-88779
[ HIGH ]CVSS 7.5EPSS 0.5%kev

Citrix NetScaler Memory Buffer Flaw Enables Denial-of-Service Attacks

NetScaler ADC and Gateway contain an exploited memory-buffer flaw enabling denial of service. CISA KEV listed October 4, federal deadline October 7.

Citrix / NetScaler ADC, NetScaler Gateway
CVE-2026-102489
[ HIGH ]EPSS 1.4%kev

Zammad GmbH Zammad Session Fixation Vulnerability

Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.

Zammad GmbH / Zammad
CVE-2026-102490
[ HIGH ]EPSS 0.6%kev

Zammad GmbH Zammad Improper Privilege Management Vulnerability

Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.

Zammad GmbH / Zammad
CVE-2026-104286
[ CRITICAL ]CVSS 9.8EPSS 2.2%kev

Fortinet FortiMail Path Traversal and NULL Byte Flaw

Fortinet FortiMail path traversal flaw (CVSS 9.8) lets unauthenticated attackers write arbitrary files. Actively exploited; CISA KEV listed October 1, 2026.

Fortinet / FortiMail
CVE-2026-76504
[ CRITICAL ]CVSS 9.8EPSS 1.6%kev

Cisco Catalyst SD-WAN Manager Authentication Bypass

Unauthenticated attackers can gain admin access to Cisco Catalyst SD-WAN Manager via a URI encoding flaw. CVSS 9.8, actively exploited, CISA KEV listed.

Cisco / Catalyst SD-WAN Manager
CVE-2026-86950
[ HIGH ]CVSS 8.8EPSS 1.2%kev

CoreGraphics memory confusion in Apple iOS 26, iPadOS, macOS 26, macOS 15

CoreGraphics memory confusion flaw in Apple iOS 26, iPadOS, macOS 26, and macOS 15. CVSS 8.8 high. Apple reports possible exploitation in targeted attacks.

Apple / iOS 26, iPadOS, macOS 26, macOS 15
$ latest --more

Latest security news

all articles →
~/articles/2026-10-05-rejetto-hfs-cve-2026-61500-rce-active-exploitation
threat intel

Rejetto HFS RCE Under Active Exploitation

CVE-2026-61500 is a critical CVSS 4.0 9.3 flaw in Rejetto HFS: attackers can recover the session-signing key, forge admin sessions, and execute code remotely.

read →
~/articles/2026-10-05-citrix-netscaler-cve-2026-88779-saml-zero-day
● Breaking
citrix

Citrix Patches Third NetScaler Zero-Day in Two Weeks

CVE-2026-88779 is a NetScaler DoS flaw exploited in zero-day attacks against SAML deployments, now in CISA KEV with a federal patch deadline of October 7.

read →
~/articles/2026-10-05-zitadel-four-auth-bypass-cves
● Breaking
threat intel

ZITADEL Patches Four Auth Bypass Flaws, Two Critical

ZITADEL patched four authentication bypass CVEs this week, including CVE-2026-105207 at CVSS 9.8 and CVE-2026-105215 at CVSS 9.1. None confirmed exploited in the wild.

read →
~/articles/2026-10-04-yeswiki-cve-2026-104445-104446-auth-bypass-smtp-relay
threat intel

YesWiki Flaws Let Attackers Spoof Identity, Hijack SMTP

Two auth bypass flaws fixed in YesWiki 4.6.7 let unauthenticated attackers forge federated identities via ActivityPub and relay email through the wiki's SMTP server.

read →
~/articles/2026-10-04-wordpress-plugin-auth-bypass-four-critical
Analysis
wordpress

Four WordPress Plugins at CVSS 9.8: Auth Bypass Persists

Four critical authentication bypass flaws in WordPress plugins this week affect a mobile app builder, a JSON auth module, a developer toolkit, and a membership system.

read →
~/articles/2026-10-04-mi5-china-mss-uk-academic-espionage
Analysis
threat intel

MI5: China MSS Used 100+ UK Academics for Spying

MI5 has identified more than 100 UK-linked academics who helped China's MSS with intelligence collection. What the disclosure means for research institutions.

read →