Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-93616
[ CRITICAL ]CVSS 9.8kev

Check Point Multiple Products Path Traversal Vulnerability

Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts.

Check Point / Multiple Products
CVE-2026-93952
[ CRITICAL ]CVSS 10.0EPSS 0.4%kev

Arista VeloCloud Orchestrator Improper Input Validation Vulnerability

Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

Arista / VeloCloud Orchestrator
CVE-2026-94127
[ CRITICAL ]CVSS 9.8kev

F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.

F5 / BIG-IP APM
CVE-2026-7273
[ HIGH ]CVSS 8.8EPSS 2.0%kev

Zyxel GS1900 Series Switches Stack-Based Buffer Overflow

Stack-based buffer overflow in Zyxel GS1900 CGI program lets unauthenticated LAN attackers execute OS commands. CVSS 8.8, added to CISA KEV September 21, 2026.

Zyxel / GS1900 Series Switches
CVE-2025-39682
[ CRITICAL ]CVSS 9.8EPSS 2.0%kev

Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

Linux kernel TLS receive path: zero-length record bypasses recvmsg() handling, corrupting downstream TLS processing. CVSS 9.8. In CISA KEV Sept. 18, 2026.

Linux / Kernel
CVE-2025-39964
[ HIGH ]CVSS 7.8EPSS 0.8%kev

Linux Kernel Race Condition Vulnerability

Linux kernel AF_ALG race condition: concurrent writes corrupt state, crashing the system or corrupting cryptographic output. CVSS 7.8. CISA KEV Sept. 18.

Linux / Kernel
$ latest --more

From the desk

all articles →
~/articles/2026-09-21-crowdsec-source-code-stolen-tanstack-supply-chain
CrowdSec Source Code Stolen in TanStack Attack
supply chain

CrowdSec Source Code Stolen in TanStack Attack

CrowdSec confirmed its source code was stolen, attributing the breach to the May 2026 TanStack JavaScript supply chain compromise. No vulnerability disclosed yet.

read →
~/articles/2026-09-21-keycloak-four-cves-iam-patch
Red Hat Patches Four Keycloak IAM Flaws
● Breaking
threat intel

Red Hat Patches Four Keycloak IAM Flaws

Red Hat issued advisories for four Keycloak CVEs: admin API cache, authorization services exposure, UMA token confusion, and session enforcement bypass.

read →
~/articles/2026-09-21-jade-sleet-india-it-provider-flatroof-roofdeck
Jade Sleet Hits Indian IT Firm with Custom Backdoors
supply chain

Jade Sleet Hits Indian IT Firm with Custom Backdoors

North Korea's Jade Sleet has compromised an India-based IT services provider, deploying the FLATROOF and ROOFDECK backdoors to position inside customer networks.

read →
~/articles/2026-09-21-nvm-cve-2026-94185-path-traversal-alias
CVE-2026-94185: nvm Alias Path Traversal, Update Now
Analysis
supply chain

CVE-2026-94185: nvm Alias Path Traversal, Update Now

nvm before 0.40.8 has a path traversal in alias resolution. GHSA-8grh-q73j-ffrc rates it CVSS 5.5, but the real exposure depends on your build environment.

read →
~/articles/2026-09-21-redcap-cve-2026-90817-unauth-rce
REDCap Patches CVSS 9.8 Unauth RCE via Survey Route
● Breaking
threat intel

REDCap Patches CVSS 9.8 Unauth RCE via Survey Route

CVE-2026-90817 (CVSS 9.8): unauthenticated RCE in REDCap via the public survey endpoint. Arbitrary code execution on clinical research servers without credentials.

read →
~/articles/2026-09-20-kcp-cve-2026-61682-user-impersonation-front-proxy
kcp Front-Proxy Lets Attackers Impersonate Any User
cloud

kcp Front-Proxy Lets Attackers Impersonate Any User

CVE-2026-61682 (CVSS 9.9): kcp front-proxy passes X-Remote-User headers through, enabling user impersonation. Fixed in 0.31.4 and 0.32.2.

read →