0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
JFrog Artifactory Incorrect Authorization Vulnerability
JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
JFrog Artifactory Improper Authentication Vulnerability
JFrog Artifactory returns an internal anonymous-user token to unauthenticated callers even when anonymous access is disabled, allowing unauthorized resource access and enabling privilege escalation chains.
ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation.
GitLab Path Traversal Allows Unauthenticated File Read
GitLab CE/EE contains a path traversal flaw due to improper path confinement and missing access controls, allowing an unauthenticated attacker to read arbitrary files from the server.
MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.
MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation.
From the desk

GitLab CVSS 10 Path Traversal Exploited Same Day as Patch
CVE-2026-85706 lets an unauthenticated attacker read any file on a GitLab server. Exploitation probes started within hours of Thursday's patch release. CISA has it in KEV.

Check Point Patches Two CVSS 9.8 VPN RCE Flaws
CVE-2026-85102 and CVE-2026-85103 allow unauthenticated RCE via VPN certificate handling in Check Point firewall products. Patches are out now.

Cisco FMC Hit by Qilin Ransomware, State-Sponsored Actors
Cisco Talos: three threat clusters exploit Cisco FMC CVE-2026-20079. Qilin ransomware deployed; credential theft observed. CISA deadline September 12.

PaperCut Issues Stable Fix as AI-Powered Attacks Widen
PaperCut's SMR replaces all emergency patches for CVE-2026-81578 and CVE-2026-82078. AI-assisted attacks are active against hundreds of organizations.

CISA Sept. 12: Patch Cisco, Citrix, Fortinet Today
CISA's September 12 deadline covers confirmed exploited flaws in Cisco FMC, Citrix NetScaler, and Fortinet FortiOS. Federal agencies must patch by tomorrow; everyone else should be moving too.

Nightmare Eclipse Drops Windows Defender Zero-Day
Nightmare Eclipse's ShieldCrash exploit achieves SYSTEM privileges on fully patched Windows systems by targeting Windows Defender itself.
This week's SITREP
Sep 11: Cisco FMC, Fortinet Hit KEV; Sept. 12 Deadline
Cisco FMC CVSS 10.0 auth bypass and Fortinet FortiOS heap overflow confirmed exploited, added to CISA KEV with September 12 deadline. Ivanti patches six critical RCEs. SAP closes CVSS 10.0 EPP flaw.




