0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Adobe Commerce and Magento Template Engine Injection (StyleSmuggler)
CVSS 10.0 template-injection in Adobe Commerce and Magento Open Source. Unauthenticated RCE exploited to plant Rust backdoors; emergency patch released September 8, 2026.
Microsoft Windows Update Stack Link-Following Privilege Escalation
“Windows Update Stack link-following flaw lets a local attacker escalate to SYSTEM. CVSS 7.8, actively exploited, on CISA KEV.”
Microsoft Windows ALPC Heap Buffer Overflow Privilege Escalation
“Windows ALPC contains a heap buffer overflow allowing AppContainer sandbox escape to local privilege escalation. CVSS 7.8, actively exploited, on CISA KEV.”
N-central Pre-Authentication Remote Code Execution
Pre-authentication remote code execution in N-able N-central via static code injection. Network-accessible, no credentials required. Fixed in 2026.3.1.14.
Type confusion in Chrome V8 allows sandbox code execution
Type confusion in Chrome's V8 engine lets remote attackers run arbitrary code inside the browser sandbox via a crafted HTML page. Actively exploited; update to 152.0.7977.82.
Kludex Starlette HTTP Request/Response Smuggling Vulnerability
Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.
From the desk

Fake IT Calls Drive M365 Exec Data Theft Campaign
Threat hunters have disclosed an active data theft and extortion cluster targeting Microsoft 365 executives via vishing: fake IT help desk calls that harvest credentials and SaaS access.

220M Passport Records Exposed in Vietnam APIS Leak
An exposed Vietnam-linked APIS database held 220 million traveler records: names, passport numbers, birth dates, nationalities, and flight routes.

Nightmare Eclipse: Zero-Days Hit CrowdStrike, Nvidia, Avast
Nightmare Eclipse published PoC privilege-escalation exploits for CrowdStrike Falcon, Nvidia drivers, and Avast antivirus. No CVE IDs or vendor patches yet.

Advantech WISE-6610 Firmware Hit by CVSS 9.9 RCE
A command injection in the WISE-6610 LoRaWAN gateway's Basic Station handler allows remote code execution. Exploit is public. Patch: firmware 1.2.4_20260821.

Telerik UI RCE Chain: PoC Published, Patch Is Out
TantoSec's public exploit chains seven Telerik UI CVEs into unauthenticated RCE. Non-default configs only. Patch to 2026 Q2 SP1 now.

Patch N-central Again: Hotfix 4 Is Out
N-able's fourth N-central hotfix in five weeks renders Hotfix 3 obsolete. Update to 2026.3.1.14 now: CVE-2026-86218 is actively exploited.




