Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-21962
[ CRITICAL ]CVSS 10.0EPSS 42.0%kev

Oracle WebLogic/HTTP Server unauthenticated data access via HTTP

Unauthenticated HTTP access exposes critical data on Oracle HTTP Server and WebLogic Server. CVSS 10.0. CISA added to KEV August 25, 2026; active exploitation confirmed.

Oracle / WebLogic Server / HTTP Server
CVE-2026-69836
[ CRITICAL ]CVSS 10.0EPSS 1.6%kev

Microsoft Entra ID Deserialization of Untrusted Data — RCE

Deserialization flaw in Microsoft Entra ID allows unauthenticated remote code execution over a network. CVSS 10.0. Actively exploited; added to CISA KEV on August 21, 2026.

Microsoft / Entra ID (formerly Azure Active Directory)
CVE-2026-73570
[ HIGH ]CVSS 8.9EPSS 1.5%kev

Zimbra ZCS SNMP Command Injection — Unauthenticated RCE

CVE-2026-73570 — CVSS 8.9 command injection in Zimbra Collaboration Suite's SNMP handler enables unauthenticated remote code execution. Actively exploited in the wild. Patch: Zimbra 10.1.20.

Synacor / Zimbra Collaboration Suite (ZCS)
CVE-2026-72529
[ CRITICAL ]CVSS 9.8EPSS 1.6%kev

TrueConf Server Missing Authentication for Critical Function Vulnerability

TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.

TrueConf / Server
CVE-2026-72530
[ CRITICAL ]CVSS 9.0EPSS 1.8%kev

TrueConf Server Code Injection Vulnerability

TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.

TrueConf / Server
CVE-2026-33824
[ CRITICAL ]CVSS 9.8EPSS 72.7%kev

Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.

Microsoft / Internet Key Exchange (IKE) Service Extensions
$ latest --more

From the desk

all articles →
~/articles/2026-08-25-rconfig-cve-2026-77915-admin-auth-bypass
rConfig Auth Bypass Grants Unauthenticated Admin Access
● Breaking
threat intel

rConfig Auth Bypass Grants Unauthenticated Admin Access

rConfig 8.0.0–8.2.12 carries a CVSS 9.8 auth bypass: unauth users can self-register as admins. A second path traversal flaw also patched in 8.2.13.

read →
~/articles/2026-08-25-iran-uk-power-plant-shutdown-sanctions
Iran ICS Attack Shuts UK Power Plant; US Sanctions
ics ot

Iran ICS Attack Shuts UK Power Plant; US Sanctions

A UK power plant went dark for four days after an Iran-linked cyberattack; the U.S. has now sanctioned Iranian nationals tied to the critical infrastructure campaign.

read →
~/articles/2026-08-24-stackgres-cve-2026-78155-tenant-priv-escalation
StackGres CVSS 9.9 Bug Escalates DB Tenant to Admin
cloud

StackGres CVSS 9.9 Bug Escalates DB Tenant to Admin

CVE-2026-78155 (CVSS 9.9): StackGres Kubernetes operator lets a low-privilege database tenant escalate to administrator. Patch immediately.

read →
~/articles/2026-08-24-gitlab-cve-2026-10053-rce-package-registry
GitLab Patches RCE in Package Registry (CVE-2026-10053)
gitlab

GitLab Patches RCE in Package Registry (CVE-2026-10053)

GitLab CE/EE authenticated RCE via path traversal in the package registry affects 18.8 through 19.2. Upgrade to 19.0.6, 19.1.4, or 19.2.2 now.

read →
~/articles/2026-08-24-velociraptor-cve-2026-19200-artifact-overwrite
Velociraptor Flaw Lets Analysts Overwrite Artifacts
threat intel

Velociraptor Flaw Lets Analysts Overwrite Artifacts

CVE-2026-19200 (CVSS 8.9) lets Velociraptor analysts overwrite global artifacts, bypassing permission controls. Update your deployment.

read →
~/articles/2026-08-23-toxicpanda-vpn-permission-google-play-block
ToxicPanda Blocks Play Store via Android VPN Trick
mobile

ToxicPanda Blocks Play Store via Android VPN Trick

Zimperium: ToxicPanda 2.0 abuses VPN service permissions to block Google Play, now targeting 349 financial apps across 16 countries.

read →