Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-58704
[ HIGH ]CVSS 8.8EPSS 0.2%kev

Google Pixel Cellular Modem Improper Authorization

Improper authorization in Google Pixel's cellular modem lets a nearby attacker bypass permission checks and escalate privileges without user interaction. CISA KEV, due 2026-09-19.

Google / Pixel
CVE-2026-76460
[ CRITICAL ]CVSS 10.0EPSS 0.9%kev

Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

CVSS 10.0 auth bypass in Cisco ISE and ISE-PIC. Unauthenticated attackers can bypass web management and gain root execution. Actively exploited; CISA KEV.

Cisco / Identity Services Engine
CVE-2026-87886
[ HIGH ]CVSS 7.8kev

Acronis Backup Incorrect Default Permissions Vulnerability

Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.

Acronis / Backup
CVE-2026-76461
[ CRITICAL ]CVSS 9.8EPSS 2.0%kev

Cisco Secure Email Gateway SQL Injection Vulnerability

SQL injection in Cisco AsyncOS for Secure Email Gateway lets an unauthenticated remote attacker execute arbitrary OS commands with root privileges. CISA KEV since Sept. 14.

Cisco / Secure Email Gateway
CVE-2026-42016
[ HIGH ]CVSS 8.1EPSS 0.9%kev

JFrog Artifactory Incorrect Authorization Vulnerability

JFrog Artifactory validates token signature and issuer but not scope, creating a privilege escalation path. CVSS 8.1 (high), CISA KEV deadline September 25, 2026.

JFrog / Artifactory
CVE-2026-42018
[ HIGH ]CVSS 7.5EPSS 0.9%kev

JFrog Artifactory Improper Authentication Vulnerability

JFrog Artifactory returns an internal anonymous-user token to unauthenticated callers even when anonymous access is disabled, allowing unauthorized resource access and enabling privilege escalation chains.

JFrog / Artifactory
$ latest --more

From the desk

all articles →
~/articles/2026-09-17-misp-cve-2026-90895-cli-auth-bypass
CVE-2026-90895: MISP CLI Exposes Auth Creds, Bypasses ACLs
● Breaking
threat intel

CVE-2026-90895: MISP CLI Exposes Auth Creds, Bypasses ACLs

MISP through 2.5.45 has CLI access controls separate from the web app, exposing feed HTTP credentials and sync authkeys to unauthorized users.

read →
~/articles/2026-09-17-mattermost-cve-2026-14344-board-auth-bypass
Mattermost CVE-2026-14344: Board Permission Check Skipped
mattermost

Mattermost CVE-2026-14344: Board Permission Check Skipped

CVE-2026-14344 lets any authenticated Mattermost user create boards regardless of role assignments. Four active release branches affected; upgrade per the security advisory.

read →
~/articles/2026-09-16-d-link-dwr-m921-m920-command-injection-three-cves
D-Link DWR Routers Hit by Three Critical Command Injections
d link

D-Link DWR Routers Hit by Three Critical Command Injections

Three critical command injection flaws in D-Link DWR-M920 and DWR-M921 firmware. Researcher H3rmesk1t disclosed all three; no D-Link patch available.

read →
~/articles/2026-09-16-gitlab-cve-2026-85706-rapid7-exploitation-tracking
Rapid7 Tracks Active Exploits Against GitLab Path Traversal
● Breaking
gitlab

Rapid7 Tracks Active Exploits Against GitLab Path Traversal

Rapid7's ETR on CVE-2026-85706 confirms active exploitation the day CISA's federal deadline expired. Unpatched GitLab instances are overdue.

read →
~/articles/2026-09-16-apache-syncope-seven-critical-cves-patch
Apache Syncope Patches 7 Critical Flaws
apache

Apache Syncope Patches 7 Critical Flaws

Apache Syncope patches seven critical CVEs: JWT forgery, Cypher injection, and search injection across 3.x and 4.x. Upgrade and rotate connector credentials.

read →
~/articles/2026-09-16-lightllm-cve-2026-90919-rce-pickle
LightLLM Config Server Has Unauthenticated RCE
ai tools

LightLLM Config Server Has Unauthenticated RCE

CVE-2026-90919 (CVSS 9.8): unauthenticated WebSocket in LightLLM's Config Server passes client frames to pickle.loads, enabling RCE on any exposed instance.

read →