Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-69836
[ CRITICAL ]CVSS 10.0EPSS 1.4%kev

Microsoft Entra ID Deserialization of Untrusted Data — RCE

Deserialization flaw in Microsoft Entra ID allows unauthenticated remote code execution over a network. CVSS 10.0. Actively exploited; added to CISA KEV on August 21, 2026.

Microsoft / Entra ID (formerly Azure Active Directory)
CVE-2026-73570
[ HIGH ]CVSS 8.9EPSS 0.5%kev

Zimbra ZCS SNMP Command Injection — Unauthenticated RCE

CVE-2026-73570 — CVSS 8.9 command injection in Zimbra Collaboration Suite's SNMP handler enables unauthenticated remote code execution. Actively exploited in the wild. Patch: Zimbra 10.1.20.

Synacor / Zimbra Collaboration Suite (ZCS)
CVE-2026-72529
[ CRITICAL ]CVSS 9.8EPSS 0.8%kev

TrueConf Server Missing Authentication for Critical Function Vulnerability

TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.

TrueConf / Server
CVE-2026-72530
[ CRITICAL ]CVSS 9.0EPSS 1.0%kev

TrueConf Server Code Injection Vulnerability

TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.

TrueConf / Server
CVE-2026-33824
[ CRITICAL ]CVSS 9.8EPSS 77.9%kev

Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.

Microsoft / Internet Key Exchange (IKE) Service Extensions
CVE-2026-64849
[ CRITICAL ]CVSS 9.3EPSS 8.2%kev

MLflow SSRF Lets Attackers Steal Cloud Credentials via Metadata Services

A server-side request forgery in MLflow before 3.15.0 allows unauthenticated access to internal endpoints including cloud metadata services, enabling cloud credential and IAM secret theft.

MLflow / MLflow (< 3.15.0)
$ latest --more

From the desk

all articles →
~/articles/2026-08-21-zimbra-snmp-rce-exploited
Zimbra SNMP RCE Now Exploited in the Wild
● Breaking
zimbra

Zimbra SNMP RCE Now Exploited in the Wild

CVE-2026-73570, a CVSS 8.9 command injection in Zimbra ZCS, is under active exploitation per CERT Polska. Patch to 10.1.20 or later immediately.

read →
~/articles/2026-08-20-rust-arrayref-supply-chain-infostealer
Backdoored Rust Crates Delivered Infostealer at Build Time
● Breaking
supply chain

Backdoored Rust Crates Delivered Infostealer at Build Time

Three popular Rust crates ran infostealer malware on developer machines via a compromised maintainer account on crates.io. Malicious versions have been pulled.

read →
~/articles/2026-08-20-carecloud-breach-3-7-million-patients
CareCloud Breach Hits 3.7M Healthcare Records
threat intel

CareCloud Breach Hits 3.7M Healthcare Records

Healthcare IT firm CareCloud confirmed 3.7 million patients' data was exposed after an attacker spent eight hours inside one of its EHR environments.

read →
~/articles/2026-08-20-nsa-fbi-ai-siemens-plc-attacks
NSA, FBI Warn of AI-Powered Attacks on Siemens PLCs
ics ot

NSA, FBI Warn of AI-Powered Attacks on Siemens PLCs

NSA and FBI warn that AI-generated scripts are actively targeting Siemens S7 PLCs in U.S. critical infrastructure. Inventory, segment, and patch now.

read →
~/articles/2026-08-20-citrix-netscaler-auth-bypass-cve-2026-19490
Citrix Patches Critical NetScaler Auth Bypass
citrix

Citrix Patches Critical NetScaler Auth Bypass

Citrix patches CVE-2026-19490, critical auth bypass in NetScaler ADC and Gateway, CVSS 9.3. No exploitation observed yet — here's what to patch before that changes.

read →
~/articles/2026-08-19-ransom-busters-ransomware-recovery-scam
Ransomware Affiliate Poses as Data Recovery Service
ransomware

Ransomware Affiliate Poses as Data Recovery Service

A ransomware affiliate calling itself Ransom Busters is emailing victims and offering to delete their stolen data from ransomware groups' servers for fees of $20,000 to $60,000.

read →