0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Microsoft Entra ID Deserialization of Untrusted Data — RCE
Deserialization flaw in Microsoft Entra ID allows unauthenticated remote code execution over a network. CVSS 10.0. Actively exploited; added to CISA KEV on August 21, 2026.
Zimbra ZCS SNMP Command Injection — Unauthenticated RCE
CVE-2026-73570 — CVSS 8.9 command injection in Zimbra Collaboration Suite's SNMP handler enables unauthenticated remote code execution. Actively exploited in the wild. Patch: Zimbra 10.1.20.
TrueConf Server Missing Authentication for Critical Function Vulnerability
TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.
TrueConf Server Code Injection Vulnerability
TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
MLflow SSRF Lets Attackers Steal Cloud Credentials via Metadata Services
A server-side request forgery in MLflow before 3.15.0 allows unauthenticated access to internal endpoints including cloud metadata services, enabling cloud credential and IAM secret theft.
From the desk

SickKids Hit Again: Data Theft via Third-Party App
SickKids confirms employee data stolen via a third-party software application. Second major incident since a 2022 ransomware attack disabled the Toronto hospital's clinical systems.

Entra ID CVE-2026-69836: CVSS 10, Exploited, KEV
CISA added CVE-2026-69836, a critical deserialization flaw in Microsoft Entra ID, to the KEV catalog; federal agencies must act by August 24.

Russian Clusters Exploit OAuth Flows to Hijack Accounts
Three Russian espionage clusters are exploiting Google OAuth and WhatsApp linking flows to hijack accounts at academic, defense, and government targets.

Zimbra SNMP RCE Now Exploited in the Wild
CVE-2026-73570, a CVSS 8.9 command injection in Zimbra ZCS, is under active exploitation per CERT Polska. Patch to 10.1.20 or later immediately.

Backdoored Rust Crates Delivered Infostealer at Build Time
Three popular Rust crates ran infostealer malware on developer machines via a compromised maintainer account on crates.io. Malicious versions have been pulled.

CareCloud Breach Hits 3.7M Healthcare Records
Healthcare IT firm CareCloud confirmed 3.7 million patients' data was exposed after an attacker spent eight hours inside one of its EHR environments.




