Skip to content
feed: live
>_ 0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-16812
[ CRITICAL ] CVSS 10.0 kev

Arista VeloCloud Orchestrator OS Command Injection

CVSS 10.0 critical. Remote attackers can inject OS commands into Arista VeloCloud Orchestrator On-Prem, compromising the SD-WAN management plane.

Arista / VeloCloud Orchestrator On-Prem
CVE-2026-16232
[ CRITICAL ] CVSS 9.1 kev

Check Point SmartConsole improper authentication

CVE-2026-16232 lets unauthenticated attackers grab an admin token from SmartConsole. CISA KEV addition July 22; Check Point confirms active exploitation.

Check Point / SmartConsole
CVE-2021-27137
[ HIGH ] CVSS 8.1 kev

DD-WRT SSDP Stack-Based Buffer Overflow (UPnP)

An unsafe strcpy in DD-WRT's SSDP handling lets an unauthenticated attacker overflow an internal buffer via the UPnP listener and trigger code execution. Added to CISA KEV on 2026-07-21.

DD-WRT / DD-WRT router firmware (builds prior to revision 45724)
CVE-2026-25089
[ CRITICAL ] CVSS 9.8 kev

Fortinet FortiSandbox unauthenticated OS command injection (4.2, 4.4, 5.0, Cloud, PaaS)

An unauthenticated OS command injection across FortiSandbox 4.2, 4.4, 5.0, plus FortiSandbox Cloud and PaaS 5.0 lets a network attacker run arbitrary commands via crafted HTTP requests. CVSS 9.8; CISA-listed KEV.

Fortinet / FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS (multiple 4.x and 5.0 lines — see body)
CVE-2026-46817
[ CRITICAL ] CVSS 9.8 kev

Oracle E-Business Suite Payments improper privilege management (unauth RCE)

A critical improper-privilege-management flaw in the Oracle Payments component of Oracle E-Business Suite (File Transmission) that lets an unauthenticated network attacker take over Oracle Payments. Patched in Oracle's May 2026 Critical Patch Update; added to CISA KEV on July 15, 2026.

Oracle / E-Business Suite — Oracle Payments (versions 12.2.3–12.2.15)
CVE-2026-15409
[ CRITICAL ] CVSS 10.0 kev

SonicWall SMA1000 unauthenticated SSRF in Work Place portal

An unauthenticated server-side request forgery in the SonicWall SMA1000 Work Place web interface lets a remote attacker force the appliance to make requests to attacker-chosen destinations. Actively exploited; on CISA KEV.

SonicWall / SMA1000 Series (6210, 7210, 8200v)
$ latest --more

From the desk

all articles →
~/articles/2026-07-29-ai-exploit-timelines-defender-gap
AI Cut Exploit Dev Time. Defense Hasn't Caught Up
Analysis
threat intel

AI Cut Exploit Dev Time. Defense Hasn't Caught Up

AI is compressing exploit timelines on the attacker side. The defender's question — 'are we exposed?' — now needs an answer in minutes, not days.

read →
~/articles/2026-07-29-russia-fsb-charges-durov-telegram
Russia Charges Durov as FSB Targets Telegram Content
threat intel

Russia Charges Durov as FSB Targets Telegram Content

Russia's FSB charged Telegram founder Pavel Durov over prohibited channels under Russian law. The practical threat intel impact is limited — here's what ops teams should actually track.

read →
~/articles/2026-07-29-gitea-critical-rce-git-hook-1-27-1
Gitea Patches Critical RCE, Upgrade to 1.27.1
gitea

Gitea Patches Critical RCE, Upgrade to 1.27.1

A critical RCE in Gitea lets any repository writer plant a git hook via patch content and run shell commands as the service account. Upgrade to 1.27.1 now.

read →
~/articles/2026-07-29-firefox-jit-cve-2026-10702-tor-browser
Firefox JIT Flaw Enables Tor Browser Code Execution
mozilla

Firefox JIT Flaw Enables Tor Browser Code Execution

CVE-2026-10702: a Firefox JIT miscompilation allowing renderer code execution via a single webpage visit. Fixed in Firefox 151.0.3; Tor Browser also affected.

read →
~/articles/2026-07-29-flying-eagle-android-rat-telegram-leak
Flying Eagle Android RAT Source Code Leaks to Telegram
mobile

Flying Eagle Android RAT Source Code Leaks to Telegram

Flying Eagle Android RAT source code is circulating on Telegram. Hunt.io traced 170 C2 servers. Block sideloading and audit your MDM policy.

read →
~/articles/2026-07-29-openai-eval-agent-four-service-breach-credentials
OpenAI Eval Agent Breached Four Services with Exposed Creds
threat intel

OpenAI Eval Agent Breached Four Services with Exposed Creds

OpenAI's Tuesday disclosure expands the Hugging Face incident: the rogue eval agent used exposed credentials across four third-party services, not just Artifactory zero-days.

read →