Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-76461
[ CRITICAL ]CVSS 9.8EPSS 2.2%kev

Cisco Secure Email Gateway SQL Injection Vulnerability

SQL injection in Cisco AsyncOS for Secure Email Gateway lets an unauthenticated remote attacker execute arbitrary OS commands with root privileges. CISA KEV since Sept. 14.

Cisco / Secure Email Gateway
CVE-2026-42016
[ HIGH ]CVSS 8.1EPSS 0.9%kev

JFrog Artifactory Incorrect Authorization Vulnerability

JFrog Artifactory validates token signature and issuer but not scope, creating a privilege escalation path. CVSS 8.1 (high), CISA KEV deadline September 25, 2026.

JFrog / Artifactory
CVE-2026-42018
[ HIGH ]CVSS 7.5EPSS 0.9%kev

JFrog Artifactory Improper Authentication Vulnerability

JFrog Artifactory returns an internal anonymous-user token to unauthenticated callers even when anonymous access is disabled, allowing unauthorized resource access and enabling privilege escalation chains.

JFrog / Artifactory
CVE-2026-84869
[ CRITICAL ]CVSS 9.9EPSS 0.7%kev

ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

ConnectWise ScreenConnect allows file transfer and execution through active remote sessions without authorization. CVSS 9.9 critical, CISA KEV due September 14.

ConnectWise / ScreenConnect
CVE-2026-85706
[ CRITICAL ]CVSS 10.0EPSS 12.0%kev

GitLab Path Traversal Allows Unauthenticated File Read

GitLab CE/EE contains a path traversal flaw due to improper path confinement and missing access controls, allowing an unauthenticated attacker to read arbitrary files from the server.

GitLab / GitLab CE/EE
CVE-2026-67277
[ HIGH ]CVSS 8.2EPSS 0.9%kev

MikroTik RouterOS Missing Authentication for Critical Function Vulnerability

MikroTik RouterOS btest service missing authentication allows kernel memory disclosure. CVSS 8.2 (high), CISA KEV deadline September 13, 2026.

MikroTik / RouterOS
$ latest --more

From the desk

all articles →
~/articles/2026-09-15-japan-digital-agency-vpn-breach-246k-personnel
Japan Digital Agency Breach Exposes 246K Staff Records
threat intel

Japan Digital Agency Breach Exposes 246K Staff Records

Japan's Digital Agency disclosed a VPN breach affecting roughly 246,000 rows of government employee personal information. The specific CVE and VPN vendor have not been named.

read →
~/articles/2026-09-15-grimwedge-china-chrome-windows-zero-day
China-Linked Group Deploys GRIMWEDGE via Zero-Day Chain
● Breaking
threat intel

China-Linked Group Deploys GRIMWEDGE via Zero-Day Chain

A China-linked group uses a Chrome-plus-Windows zero-day chain in targeted spear-phishing campaigns to drop GRIMWEDGE, a JavaScript backdoor, on victim systems.

read →
~/articles/2026-09-15-cisco-secure-email-gateway-cve-2026-76461-rce
Cisco Email Gateway SQLi Grants Root, Now in KEV
● Breaking
cisco

Cisco Email Gateway SQLi Grants Root, Now in KEV

CVE-2026-76461, a SQL injection in Cisco AsyncOS, lets unauthenticated attackers run OS commands as root. CISA added it to KEV on Sept. 14 with a Sept. 17 deadline.

read →
~/articles/2026-09-14-screenconnect-worm-attacks-cve-2026-84869-patched
ScreenConnect Worm Attacks: CVE-2026-84869 Now Patched
● Breaking
threat intel

ScreenConnect Worm Attacks: CVE-2026-84869 Now Patched

Huntress documented worm-like ScreenConnect attacks active since August 20. ConnectWise has released version 26.6.5 patching CVE-2026-84869, a CVSS 9.9 flaw exploited in the campaign.

read →
~/articles/2026-09-14-revolut-breach-passport-financial-data
Revolut Breach Exposes Passports and Financial Data
threat intel

Revolut Breach Exposes Passports and Financial Data

A threat actor impersonated a government agency to obtain passport copies, identity documents, and complete transaction records from an undisclosed number of Revolut customers.

read →
~/articles/2026-09-14-cryptopayment-gateway-cve-2026-81648-admin-bypass
CVSS 10 Flaw in WordPress Payment Plugin Grants Admin Access
wordpress

CVSS 10 Flaw in WordPress Payment Plugin Grants Admin Access

CVE-2026-81648 skips authorization on a CryptoPayment Gateway AJAX endpoint in versions 1.2.1-1.2.2, giving unauthenticated visitors admin-level access.

read →