0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Cisco Catalyst SD-WAN Manager Authentication Bypass
Unauthenticated attackers can gain admin access to Cisco Catalyst SD-WAN Manager via a URI encoding flaw. CVSS 9.8, actively exploited, CISA KEV listed.
CoreGraphics memory confusion in Apple iOS 26, iPadOS, macOS 26, macOS 15
CoreGraphics memory confusion flaw in Apple iOS 26, iPadOS, macOS 26, and macOS 15. CVSS 8.8 high. Apple reports possible exploitation in targeted attacks.
Citrix NetScaler ADC/Gateway Unauthenticated RCE via Input Validation Flaw
Citrix NetScaler ADC and Gateway improper input validation flaw allows unauthenticated remote code execution; actively exploited and CISA KEV listed.
Citrix NetScaler ADC/Gateway RCE via Memory Buffer Mishandling
Citrix NetScaler ADC and Gateway memory buffer flaw allows remote code execution or denial of service; actively exploited and CISA KEV listed.
Microsoft SharePoint Code Injection Vulnerability
A code injection flaw in Microsoft Office SharePoint lets an authorized attacker execute code over a network. CVSS 8.8 (high), active exploitation confirmed, CISA KEV deadline September 28, 2026.
Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.
From the desk

FBI Warns ShinyHunters Members to Surrender After Arrest
Dutch police arrested an alleged ShinyHunters leader, prompting the FBI to warn remaining members of the extortion group to turn themselves in.

Ransomware Hits South Africa Air Traffic Control
A ransomware toolkit was installed on at least one operational network at South Africa's air traffic control authority, prompting a request for international cybersecurity assistance.

Firefox 157 Patches Two CVSS 9.6 Sandbox Escapes
Mozilla patched five vulnerabilities in Firefox 157, including two CVSS 9.6 sandbox escapes via use-after-free in the DOM Content Processes component.

OpenSSL and WolfSSL Patch High-Severity Flaws
OpenSSL and WolfSSL each patched roughly a dozen high-severity flaws this week. Admins running web services, VPN appliances, or embedded devices should check for updates.

NetScaler Web Shells Confirmed: KEV Deadline Is Today
Cybersecurity firms document the CVE-2026-88772 attack chain: web shells, tunneling malware, root access, and lateral movement. CISA KEV deadline expires today.

Arizona Supreme Court Confirms Resident Data Stolen
Hackers stole personal data from Arizona's court system. No ransomware; no ransom demands as of Monday. Breach scope and affected count undisclosed.




