0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
Linux Kernel Race Condition Vulnerability
Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.
Linux Kernel Out-of-Bounds Write Vulnerability
Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
Google Pixel Cellular Modem Improper Authorization
Improper authorization in Google Pixel's cellular modem lets a nearby attacker bypass permission checks and escalate privileges without user interaction. CISA KEV, due 2026-09-19.
Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
CVSS 10.0 auth bypass in Cisco ISE and ISE-PIC. Unauthenticated attackers can bypass web management and gain root execution. Actively exploited; CISA KEV.
Acronis Backup Incorrect Default Permissions Vulnerability
Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.
From the desk

Unbound 1.26.1 Fixes Critical DNSSEC Heap Overflow
NLnet Labs patches a critical DNSSEC heap overflow in Unbound. All versions before 1.26.1 are affected; RCE is possible via attacker-controlled DNS zones.

BIND 9 Patches 14 Flaws Including Unauthenticated DoH Crash
ISC patched 14 vulnerabilities in BIND 9, including a flaw that lets unauthenticated attackers crash resolvers via DNS-over-HTTPS. Update to 9.20.29 or 9.21.26.

CVE-2026-91843: Check Point Management Server RCE
A stack overflow in the Check Point Security Management Server login handler allows unauthenticated RCE as root. CVSS 9.8. Patch available via sk1000155.

WSO2 CVSS 10 JWT Bypass Exploited in the Wild
CVE-2026-5430 lets unauthenticated attackers forge JWTs and gain administrative access to WSO2 deployments. Active exploitation confirmed. Patch immediately.
Google Patches Pixel Modem Zero-Day Under Attack
Google's September 2026 Pixel update patches 110 vulnerabilities including CVE-2026-58704, a high-severity modem flaw already under active exploitation. CISA deadline is September 19.

Cisco ISE Zero-Day CVSS 10.0 Under Active Exploitation
CVE-2026-76460, a CVSS 10.0 auth bypass in Cisco ISE and ISE-PIC, is under active exploitation. Patches cover all supported releases; no workarounds exist.




