0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Kludex Starlette HTTP Request/Response Smuggling Vulnerability
Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.
Kestra OSS OS Command Injection Vulnerability
Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.
BerriAI LiteLLM Improper Authentication Vulnerability
BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.
Sangoma Switchvox SQL Injection Vulnerability
Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
Pre-auth SSRF in SonicWall SMA1000 Workplace Interface
Unauthenticated SSRF in the SMA1000 Workplace interface allows remote attackers to reach internal functionality via an unintended access path. Exploited in the wild; chains with CVE-2026-83549 for RCE.
OS Command Injection in SonicWall SMA1000 AMC
Post-auth OS command injection in the SonicWall SMA1000 AMC allows an authenticated administrator to execute arbitrary OS commands. CVSS 7.8 HIGH. Chains with CVE-2026-83548 for unauthenticated RCE.
From the desk

Forescout Uses Claude to Port RCE Across WAGO PLCs
Vedere Labs used Claude to port a pre-auth RCE exploit between WAGO PLC models, showing AI tools can lower barriers to ICS exploitation.

Switchvox Flaw Exploited for Unauthenticated RCE
Attackers are exploiting a critical vulnerability in Sangoma Switchvox enterprise VoIP to deploy reverse shells without credentials. No CVE identifier publicly disclosed yet.

Sality Botnet Takedown: DOJ Seizes P2P Network
DOJ and international partners dismantled the Sality botnet by turning its own P2P relay infrastructure against itself. Infected Windows endpoints remain in the wild.

Ransomware Gang Claims Nutex Health Patient Data
Ransomware group breached Nutex Health, taking patient, employee, provider, and financial data. The Houston-based operator disclosed the incident to the SEC.

SonicWall SMA1000 Zero-Days Exploited in Attacks
SonicWall confirms active exploitation of two SMA1000 zero-days: CVE-2026-83548 (pre-auth SSRF) and CVE-2026-83549 (OS command injection). Chained, they enable unauthenticated RCE.

Attackers Exploit Langflow to Steal OpenAI, AWS Keys
CVE-2026-0768, a critical unauthenticated RCE in Langflow, is being actively exploited to drain AI API keys and cloud credentials from exposed instances.




