Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-76504
[ CRITICAL ]CVSS 9.8EPSS 1.1%kev

Cisco Catalyst SD-WAN Manager Authentication Bypass

Unauthenticated attackers can gain admin access to Cisco Catalyst SD-WAN Manager via a URI encoding flaw. CVSS 9.8, actively exploited, CISA KEV listed.

Cisco / Catalyst SD-WAN Manager
CVE-2026-86950
[ HIGH ]CVSS 8.8EPSS 1.2%kev

CoreGraphics memory confusion in Apple iOS 26, iPadOS, macOS 26, macOS 15

CoreGraphics memory confusion flaw in Apple iOS 26, iPadOS, macOS 26, and macOS 15. CVSS 8.8 high. Apple reports possible exploitation in targeted attacks.

Apple / iOS 26, iPadOS, macOS 26, macOS 15
CVE-2026-88771
[ HIGH ]EPSS 1.1%kev

Citrix NetScaler ADC/Gateway Unauthenticated RCE via Input Validation Flaw

Citrix NetScaler ADC and Gateway improper input validation flaw allows unauthenticated remote code execution; actively exploited and CISA KEV listed.

Citrix / NetScaler ADC, NetScaler Gateway
CVE-2026-88772
[ HIGH ]EPSS 1.3%kev

Citrix NetScaler ADC/Gateway RCE via Memory Buffer Mishandling

Citrix NetScaler ADC and Gateway memory buffer flaw allows remote code execution or denial of service; actively exploited and CISA KEV listed.

Citrix / NetScaler ADC, NetScaler Gateway
CVE-2026-65660
[ HIGH ]CVSS 8.8EPSS 2.1%kev

Microsoft SharePoint Code Injection Vulnerability

A code injection flaw in Microsoft Office SharePoint lets an authorized attacker execute code over a network. CVSS 8.8 (high), active exploitation confirmed, CISA KEV deadline September 28, 2026.

Microsoft / SharePoint
CVE-2026-67279
[ MEDIUM ]CVSS 6.5EPSS 1.0%kev

Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.

MikroTik / RouterOS
$ latest --more

From the desk

all articles →
~/articles/2026-09-30-shinyhunters-dutch-arrest-fbi-warning
FBI Warns ShinyHunters Members to Surrender After Arrest
ransomware

FBI Warns ShinyHunters Members to Surrender After Arrest

Dutch police arrested an alleged ShinyHunters leader, prompting the FBI to warn remaining members of the extortion group to turn themselves in.

read →
~/articles/2026-09-30-south-africa-atc-ransomware-operational-network
Ransomware Hits South Africa Air Traffic Control
ics ot

Ransomware Hits South Africa Air Traffic Control

A ransomware toolkit was installed on at least one operational network at South Africa's air traffic control authority, prompting a request for international cybersecurity assistance.

read →
~/articles/2026-09-30-firefox-157-cve-2026-100770-sandbox-escape
Firefox 157 Patches Two CVSS 9.6 Sandbox Escapes
mozilla

Firefox 157 Patches Two CVSS 9.6 Sandbox Escapes

Mozilla patched five vulnerabilities in Firefox 157, including two CVSS 9.6 sandbox escapes via use-after-free in the DOM Content Processes component.

read →
~/articles/2026-09-30-openssl-wolfssl-high-severity-patch
OpenSSL and WolfSSL Patch High-Severity Flaws
threat intel

OpenSSL and WolfSSL Patch High-Severity Flaws

OpenSSL and WolfSSL each patched roughly a dozen high-severity flaws this week. Admins running web services, VPN appliances, or embedded devices should check for updates.

read →
~/articles/2026-09-30-citrix-netscaler-cve-2026-88772-web-shell-campaign
NetScaler Web Shells Confirmed: KEV Deadline Is Today
● Breaking
citrix

NetScaler Web Shells Confirmed: KEV Deadline Is Today

Cybersecurity firms document the CVE-2026-88772 attack chain: web shells, tunneling malware, root access, and lateral movement. CISA KEV deadline expires today.

read →
~/articles/2026-09-30-arizona-supreme-court-breach-resident-data
Arizona Supreme Court Confirms Resident Data Stolen
threat intel

Arizona Supreme Court Confirms Resident Data Stolen

Hackers stole personal data from Arizona's court system. No ransomware; no ransom demands as of Monday. Breach scope and affected count undisclosed.

read →