0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.
MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation.
Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
CVSS 8.1 heap overflow in FortiOS, FortiSwitchManager, and FortiSASE allows code execution via crafted packets. Actively exploited in PivotC2 RAT attacks; patched January 2026.
Cisco FMC Authentication Bypass Enables Root OS Access
CVE-2026-20079 is a CVSS 10.0 unauthenticated auth bypass in Cisco FMC with root OS access. Actively exploited; CISA KEV deadline September 12.
Google Chromium V8 Out of Bounds Write Vulnerability
Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Adobe Commerce and Magento Template Engine Injection (StyleSmuggler)
CVSS 10.0 template-injection in Adobe Commerce and Magento Open Source. Unauthenticated RCE exploited to plant Rust backdoors; emergency patch released September 8, 2026.
From the desk

SAP September Patches: CVSS 10 RCE in EPP Processing
SAP's September 2026 Security Patch Day includes a CVSS 10.0 unauthenticated RCE in Extended Passport Processing and multiple additional critical updates.

Ivanti Patches Critical RCE in Neurons, EPMM, Sentry
Ivanti's September 2026 patches close six critical RCEs in Neurons for ITSM and authentication bypass flaws in Sentry and EPMM. Patch now.

Cisco Confirms FMC CVSS 10 Auth Bypass Exploited
Cisco confirms CVE-2026-20079, CVSS 10.0 FMC auth bypass, is actively exploited. Unauthenticated attackers gain root OS access. CISA KEV deadline September 12.

Linux Rootkit Targets F5 BIG-IP APM, Lives in Memory
Attackers are breaching F5 BIG-IP APM devices to deploy a Linux rootkit that hooks PHP file loading and injects a fileless web shell into memory, leaving no disk artifacts.

Microsoft Patches Record 974 Vulns, 2 Zero-Days
September 2026 Patch Tuesday: Microsoft patches a record 974 CVEs, including two exploited Windows zero-days now on CISA's KEV catalog.

Google Patches Chrome's 7th Exploited Zero-Day of 2026
Google patched the seventh actively exploited Chrome zero-day of 2026 on September 9, in a 230-vulnerability update. CVE designation pending.
This week's SITREP
Sep 11: Cisco FMC, Fortinet Hit KEV; Sept. 12 Deadline
Cisco FMC CVSS 10.0 auth bypass and Fortinet FortiOS heap overflow confirmed exploited, added to CISA KEV with September 12 deadline. Ivanti patches six critical RCEs. SAP closes CVSS 10.0 EPP flaw.




