0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Google Pixel Improper Authorization Vulnerability
Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.
Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
Cisco Secure Email Gateway SQL Injection Vulnerability
SQL injection in Cisco AsyncOS for Secure Email Gateway lets an unauthenticated remote attacker execute arbitrary OS commands with root privileges. CISA KEV since Sept. 14.
JFrog Artifactory Incorrect Authorization Vulnerability
JFrog Artifactory validates token signature and issuer but not scope, creating a privilege escalation path. CVSS 8.1 (high), CISA KEV deadline September 25, 2026.
JFrog Artifactory Improper Authentication Vulnerability
JFrog Artifactory returns an internal anonymous-user token to unauthenticated callers even when anonymous access is disabled, allowing unauthorized resource access and enabling privilege escalation chains.
ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
ConnectWise ScreenConnect allows file transfer and execution through active remote sessions without authorization. CVSS 9.9 critical, CISA KEV due September 14.
From the desk

Three Artifactory Flaws Exploited to Plant Backdoors
SecurityWeek reports three JFrog Artifactory flaws actively exploited to reach admin access and deploy backdoors in enterprise build pipelines.

Microsoft OOB Fixes RDS, Hyper-V Failures from Sept Patches
Out-of-band Windows updates address Remote Desktop Services failures, Hyper-V errors, and USB audio problems introduced by September 2026 Patch Tuesday.

Apple iOS 27, macOS Golden Gate Patch 200 Vulns
Apple released iOS 27 and macOS Golden Gate 27 on September 15, patching roughly 200 vulnerabilities including kernel flaws that enable privilege escalation and memory corruption.

Japan Digital Agency Breach Exposes 246K Staff Records
Japan's Digital Agency disclosed a VPN breach affecting roughly 246,000 rows of government employee personal information. The specific CVE and VPN vendor have not been named.

China-Linked Group Deploys GRIMWEDGE via Zero-Day Chain
A China-linked group uses a Chrome-plus-Windows zero-day chain in targeted spear-phishing campaigns to drop GRIMWEDGE, a JavaScript backdoor, on victim systems.

Cisco Email Gateway SQLi Grants Root, Now in KEV
CVE-2026-76461, a SQL injection in Cisco AsyncOS, lets unauthenticated attackers run OS commands as root. CISA added it to KEV on Sept. 14 with a Sept. 17 deadline.



