Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-81578
[ HIGH ]CVSS 8.8EPSS 0.8%kev

PaperCut NG/MF Authentication Bypass

Authentication bypass in PaperCut NG/MF (CVSS 8.8) lets unauthenticated attackers access admin functions via malformed requests. Actively exploited; apply Emergency Patch Release 2.

PaperCut Software / PaperCut NG and PaperCut MF (versions 24, 25, 26)
CVE-2026-82078
[ CRITICAL ]CVSS 9.4EPSS 0.9%kev

PaperCut NG/MF Unsafe Class-Loading RCE

PaperCut NG/MF (CVSS 9.4 Critical): unsafe dynamic class-loading enables unauthenticated RCE. Actively exploited; apply Emergency Patch Release 2 immediately.

PaperCut Software / PaperCut NG and PaperCut MF (versions 24, 25, 26)
CVE-2023-49105
[ CRITICAL ]CVSS 9.8EPSS 43.2%kev

ownCloud Improper Authentication Vulnerability

ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.

ownCloud / ownCloud
CVE-2026-53362
[ HIGH ]CVSS 7.8EPSS 0.5%kev

Linux Kernel Unspecified Vulnerability

Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux.

Linux / Kernel
CVE-2026-66384
[ MEDIUM ]CVSS 5.3EPSS 0.6%kev

JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability

JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.

JFrog / Artifactory
CVE-2026-8452
[ CRITICAL ]CVSS 9.8EPSS 1.6%kev

Citrix NetScaler ADC and Gateway Memory Buffer Overflow

CVE-2026-8452 is a CVSS 9.8 critical memory buffer overflow in Citrix NetScaler ADC and NetScaler Gateway affecting appliances configured as Gateway or AAA virtual server, confirmed exploited in the wild and added to CISA KEV on August 26, 2026.

Citrix / NetScaler ADC and NetScaler Gateway
$ latest --more

From the desk

all articles →
~/articles/2026-08-31-fire-ant-cisco-ios-xr-gre-spy-tunnels
Chinese Fire Ant Buries Spy Tunnels in Cisco IOS XR
threat intel

Chinese Fire Ant Buries Spy Tunnels in Cisco IOS XR

State-linked Fire Ant planted covert GRE tunnel interfaces on Cisco IOS XR routers absent from running configs. Here's what to check on your own gear.

read →
~/articles/2026-08-31-tooljet-seven-auth-bypass-cvss-9-9
ToolJet Patches Seven Auth Flaws, Worst CVSS 9.9
● Breaking
supply chain

ToolJet Patches Seven Auth Flaws, Worst CVSS 9.9

ToolJet patches seven authorization bypass flaws, the worst rated CVSS 9.9. Any authenticated Builder can read or modify data across other organizations' ToolJet DB instances.

read →
~/articles/2026-08-31-ash-phoenix-four-cves-multi-tenant-auth
ash_phoenix Patches Four Auth-Bypass Flaws
supply chain

ash_phoenix Patches Four Auth-Bypass Flaws

The Elixir Ash framework's Phoenix integration disclosed four CVEs covering tenant isolation bypass, authorization bypass via user-controlled keys, and sensitive parameter exposure in logs.

read →
~/articles/2026-08-31-profile-builder-unauth-file-upload-cve-2026-82607
Profile Builder Plugin Flaw Allows Unauth File Upload
wordpress

Profile Builder Plugin Flaw Allows Unauth File Upload

Cozmoslabs Profile Builder for WordPress up to 3.16.1 lets unauthenticated attackers upload files via the avatar AJAX endpoint. Patch or mitigate now.

read →
~/articles/2026-08-31-ashadmin-ashai-13-cves-rce
13 CVEs in AshAdmin and AshAI Include Critical RCE
ai tools

13 CVEs in AshAdmin and AshAI Include Critical RCE

ERLEF CNA disclosed 13 vulnerabilities in the ash-project Elixir framework today, topped by an unauthenticated remote code execution flaw in AshAI. Elixir developers should audit their deployments immediately.

read →
~/articles/2026-08-30-oidcc-cve-2026-75759-oidc-signature-bypass
oidcc Auth Bypass Lets Attackers Impersonate Users
threat intel

oidcc Auth Bypass Lets Attackers Impersonate Users

CVE-2026-75759 in the Elixir oidcc library lets an unauthenticated attacker impersonate any user by supplying an encrypted OIDC token with an attacker-controlled algorithm. Update oidcc now.

read →