0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Microsoft SharePoint Code Injection Vulnerability
Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.
Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.
WSO2 Multiple Products Path Traversal to RCE
WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway contain a path traversal flaw enabling unauthenticated file upload and remote code execution. CVSS 10.0. Actively exploited since September 13, 2026; added to CISA KEV September 24.
WordPress core get_page_template path traversal enables unauthenticated RCE
Path traversal in WordPress core's get_page_template() enables unauthenticated local PHP file inclusion and conditional RCE. Actively exploited within 24 hours of disclosure. CVSS 8.1 High.
Check Point Multiple Products Path Traversal Vulnerability
CVE-2026-93616: CVSS 9.8 path traversal and file upload in Check Point Management Server enabling unauth RCE. Confirmed exploited; patches available.
Arista VeloCloud Orchestrator Unauthenticated RCE
“CVE-2026-93952 is a CVSS 10.0 improper input validation flaw in Arista VeloCloud Orchestrator that allows unauthenticated remote code execution. Added to CISA KEV on September 22, 2026.”
From the desk

Roundcube SQL Injection Flaw Under Active Attack
Canada's CCCS confirmed active exploitation of CVE-2026-48842, a SQL injection in Roundcube Webmail patched in May. Upgrade to 1.6.16 or 1.7.1 now.

SolarWinds Fixes Two Unauth RCE Flaws in Observability
SolarWinds patches CVE-2026-28324 (CVSS 9.8) and CVE-2026-28325 (CVSS 8.8), two unauthenticated RCE flaws in Observability Self-Hosted. No active exploitation reported.

CISA: Ransomware Gangs Exploiting TeamCity RCE Flaw
CISA warns federal agencies that ransomware groups are exploiting CVE-2026-63077, a CVSS 9.8 unauthenticated RCE in JetBrains TeamCity. Patch released July 28.

InfraTrust: Network Management Systems Under Attack
InfraTrust's September report finds attackers targeting network management and control infrastructure at or before patch availability. Here's what to prioritize.

WordPress Core RCE Flaw CVE-2026-87902 Under Active Exploit
WordPress core path traversal CVE-2026-87902 allows unauthenticated RCE under specific conditions. Exploitation confirmed within 24 hours. CVSS 8.1 High.

D-Link Warns CVSS 10.0 DIR-822A Flaw Has No Fix
CVE-2026-86296: CVSS 10.0 D-Link DIR-822A zero-day with public PoC exploit code and no patch. D-Link says the device is end-of-life and replacement is needed.
This week's SITREP
Sep 22: Cl0p Extorted, CrowdSec Source Code, BigCommerce
ShinyHunters escalates against Cl0p with an eight-figure demand and threatens to expose ransom-payer records. CrowdSec confirms source code theft. BigCommerce merchants hit via Ribon apps.




