0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Cisco Secure Email Gateway SQL Injection Vulnerability
SQL injection in Cisco AsyncOS for Secure Email Gateway lets an unauthenticated remote attacker execute arbitrary OS commands with root privileges. CISA KEV since Sept. 14.
JFrog Artifactory Incorrect Authorization Vulnerability
JFrog Artifactory validates token signature and issuer but not scope, creating a privilege escalation path. CVSS 8.1 (high), CISA KEV deadline September 25, 2026.
JFrog Artifactory Improper Authentication Vulnerability
JFrog Artifactory returns an internal anonymous-user token to unauthenticated callers even when anonymous access is disabled, allowing unauthorized resource access and enabling privilege escalation chains.
ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
ConnectWise ScreenConnect allows file transfer and execution through active remote sessions without authorization. CVSS 9.9 critical, CISA KEV due September 14.
GitLab Path Traversal Allows Unauthenticated File Read
GitLab CE/EE contains a path traversal flaw due to improper path confinement and missing access controls, allowing an unauthenticated attacker to read arbitrary files from the server.
MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
MikroTik RouterOS btest service missing authentication allows kernel memory disclosure. CVSS 8.2 (high), CISA KEV deadline September 13, 2026.
From the desk

China-Linked UNC3569 Deploys GrayRabbit via Sogou Flaw
Gen Threat Labs links China-aligned UNC3569 to GrayRabbit backdoor deployments through a chained flaw in Tencent's Sogou Input Method for Windows. Patch to v16.3.0.3498.

Events Calendar Plugin: Two CVSS 9.8 RCEs
Two unauthenticated CVSS 9.8 RCEs in The Events Calendar WordPress plugin affect all versions through 6.17.4. Disable or update immediately.

BlueMoon Exploit Kit Chains Chrome, Windows Zero-Days
BlueMoon exploit kit bundles Chrome renderer and Windows privilege-escalation zero-days into a two-stage chain, with espionage-motivated actors adopting it in rushed campaigns.

Dutch NCSC Warns Check Point VPN Exploitation Imminent
Dutch NCSC warns exploitation of two CVSS 9.8 Check Point VPN RCE flaws is imminent. If you haven't patched CVE-2026-85102 and CVE-2026-85103, do it now.

Authorizer CVSS 9.3 Flaw Enables OAuth Token Theft
Authorizer's /authorize endpoint accepted any redirect_uri before v2.2.1, exposing OAuth codes and tokens to theft via crafted flows. Patch to 2.2.1.

CISA KEV: RouterOS Deadline Today, ScreenConnect Tomorrow
CISA added five exploited flaws in MikroTik RouterOS, ConnectWise ScreenConnect, and JFrog Artifactory. Federal patch deadline for RouterOS is today, September 13.




