Skip to content
feed: live
>_ 0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-18556
[ HIGH ] CVSS 7.4 EPSS 0.5% kev

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.

N-able / N-central
CVE-2026-34486
[ HIGH ] CVSS 7.5 EPSS 81.2% kev

Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.

Apache / Tomcat
CVE-2026-9198
[ CRITICAL ] CVSS 9.8 EPSS 17.1% kev

IBM Langflow Code Injection Vulnerability

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

IBM / Langflow
CVE-2026-18577
[ HIGH ] EPSS 4.1% kev

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.

N-able / N-central
CVE-2026-20316
[ MEDIUM ] CVSS 5.3 EPSS 0.8% kev

Hard-coded credential in Cisco Secure FMC enables unauthenticated login

Cisco Secure FMC ships a static low-privileged account; remote unauthenticated attackers can log in and access sensitive data. CISA KEV confirmed July 29, 2026.

Cisco / Cisco Secure Firewall Management Center (FMC)
CVE-2026-21513
[ HIGH ] CVSS 8.8 EPSS 15.4% kev

Microsoft MSHTML security feature bypass

Protection mechanism failure in Microsoft MSHTML lets unauthenticated attackers bypass a security feature over the network. CVSS 8.8, patched in Microsoft's February 2026 Patch Tuesday.

Microsoft / MSHTML Framework (Windows)
$ latest --more

From the desk

all articles →
~/articles/2026-08-10-metabase-zero-day-patched
Metabase Patches CVSS 10 Zero-Day Under Active Exploit
● Breaking
ai tools

Metabase Patches CVSS 10 Zero-Day Under Active Exploit

Metabase has released a patch for the max-severity unauthenticated SQL injection zero-day confirmed in active exploitation since August 8. Update now. No CVE assigned yet.

read →
~/articles/2026-08-10-levi-strauss-social-engineering-breach
Levi Strauss Breach: Social Engineering, Data Exfil
● Breaking
threat intel

Levi Strauss Breach: Social Engineering, Data Exfil

A threat actor used social engineering to compromise three Levi Strauss employee computers and exfiltrate corporate data. Scope and attribution unconfirmed.

read →
~/articles/2026-08-10-gstreamer-cve-2026-19387-cve-2026-19389
GStreamer Bugs Allow RCE Via Crafted Media Files
threat intel

GStreamer Bugs Allow RCE Via Crafted Media Files

Two HIGH flaws in GStreamer's ADPCM decoder and ASF demuxer let crafted WAV, WMV, and WMA files trigger heap corruption and potential code execution.

read →
~/articles/2026-08-10-wp-login-register-cve-2026-18468-18469-18470
Three CVEs Chain to Admin Takeover in WordPress Login Plugin
● Breaking
wordpress

Three CVEs Chain to Admin Takeover in WordPress Login Plugin

Three CVEs in the Login & Register Forms WordPress plugin before 4.0.2 enable unauthenticated account takeover, including site admins. Update now.

read →
~/articles/2026-08-10-metabase-cvss10-zero-day-exploited
Metabase Zero-Day: CVSS 10 Exploited in the Wild
ai tools

Metabase Zero-Day: CVSS 10 Exploited in the Wild

Unauthenticated SQL injection in Metabase BI gives attackers admin access. Exploitation confirmed, no CVE assigned. Take your instance offline if it's reachable from untrusted networks.

read →
~/articles/2026-08-09-perl-cve-2026-15534-regex-heap-oob
Perl Heap OOB in Regex Engine Through 5.45.1
● Breaking
threat intel

Perl Heap OOB in Regex Engine Through 5.45.1

CVE-2026-15534: signed 32-bit overflow in Perl's superlinear regex cache enables heap OOB on attacker-controlled input. Patch exists; CVSS pending.

read →