0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
DD-WRT SSDP Stack-Based Buffer Overflow (UPnP)
An unsafe strcpy in DD-WRT's SSDP handling lets an unauthenticated attacker overflow an internal buffer via the UPnP listener and trigger code execution. Added to CISA KEV on 2026-07-21.
Fortinet FortiSandbox unauthenticated OS command injection (4.2, 4.4, 5.0, Cloud, PaaS)
An unauthenticated OS command injection across FortiSandbox 4.2, 4.4, 5.0, plus FortiSandbox Cloud and PaaS 5.0 lets a network attacker run arbitrary commands via crafted HTTP requests. CVSS 9.8; CISA-listed KEV.
Oracle E-Business Suite Payments improper privilege management (unauth RCE)
A critical improper-privilege-management flaw in the Oracle Payments component of Oracle E-Business Suite (File Transmission) that lets an unauthenticated network attacker take over Oracle Payments. Patched in Oracle's May 2026 Critical Patch Update; added to CISA KEV on July 15, 2026.
SonicWall SMA1000 unauthenticated SSRF in Work Place portal
An unauthenticated server-side request forgery in the SonicWall SMA1000 Work Place web interface lets a remote attacker force the appliance to make requests to attacker-chosen destinations. Actively exploited; on CISA KEV.
SonicWall SMA1000 post-authentication OS command injection
A post-authentication OS command injection in the SonicWall SMA1000 lets an administrator execute arbitrary OS commands on the appliance. Actively exploited alongside CVE-2026-15409; on CISA KEV.
AD FS elevation of privilege — insufficient access-control granularity
Active Directory Federation Services access-control granularity flaw lets an authorized attacker escalate privileges locally. Exploited in the wild; added to CISA KEV 2026-07-14.
From the desk

Bit2Watt: what the GPU cloud tenant abstracts away
Three Zhejiang researchers say ordinary GPU access can swing a data-center's load fast enough to strain its grid. Worst-case sim; the gap under it is real.

Qilin exploits PAN-OS GlobalProtect CVE-2026-0257
Arctic Wolf documents Qilin ransomware breaching networks through a two-month-old PAN-OS GlobalProtect authentication bypass, and assesses with moderate confidence that intrusions are ongoing.

Microsoft ships manual WSUS fix: SUSDB cleanup, IISReset
Microsoft published the WSUS unstick procedure Monday: back up SUSDB, run the cleanup query, restore MaxXMLPerRequest, reindex, wizard, IISReset.

0patch ships free unofficial fix for LegacyHive zero-day
ACROS Security (0patch) shipped free micropatches for the unpatched LegacyHive LPE — Windows 10 2004 and Server 2019 up. Microsoft is still investigating.

TeamCity CVE-2024-27198: EPSS 0.999 two years past patch
JetBrains TeamCity's 2024 auth-bypass still ranks EPSS 0.999 more than two years post patch. Internet-facing build servers keep the exposed population alive.

The signature was there. The trust wasn't.
DigiCert's EV certs, WebEx and Zoom installers, ViPNet's signed updater. Three subverted trust chains this week, one design assumption behind them.




