0dayNews — Vulnerability & Exploit News
Latest intelligence
all articles →Known Exploited Vulnerabilities
ProFTPD Improper Access Control Vulnerability
ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
ISC BIND Data Processing Errors Vulnerability
ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries.
Apache Struts Command Injection Vulnerability
Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.
ONLYOFFICE Docs Server Path Traversal Vulnerability
ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution.
Strapi Cleartext Storage of Sensitive Information Vulnerability
Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution.
Citrix NetScaler Memory Buffer Flaw Enables Denial-of-Service Attacks
NetScaler ADC and Gateway contain an exploited memory-buffer flaw enabling denial of service. CISA KEV listed October 4, federal deadline October 7.
Latest security news

MonsterCloud CEO Charged for Secret Ransom Scheme
Zohar Pinhasi charged with wire fraud after prosecutors allege he secretly paid ransomware operators while billing victims over $19 million for proprietary recovery services.

Critical LMCache Flaw Exposes LLM Servers to Unauth RCE
CVE-2026-105192, a CVSS 9.8 flaw in LMCache's multiprocess server, lets unauthenticated attackers run code on LLM inference infrastructure. No patch exists.

Atlassian CVE-2026-21589: Exploits Active, Patch Now
Active exploitation of CVE-2026-21589 began within hours of a public PoC. All eight affected Atlassian Data Center products need patching immediately.

Chrome 155 Patches 4 Critical UAF Bugs, 247 Total
Google shipped Chrome 155 with 247 fixes, including four critical use-after-free bugs in core browser components. No active exploitation reported yet.

CERT-UA: 100+ Sites Hijacked to Drop LunexStealer
Ukraine's CERT-UA tracked 100+ compromised sites serving LunexStealer through fake Cloudflare verification pages. Attributed to UAC-0277, observed September 2026.

Android October Patches Fix 25 Flaws, 7 Critical
Google's October 2026 Android update patches 25 vulnerabilities, including a critical System flaw that enables local privilege escalation without user interaction.






