0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Microsoft SharePoint Code Injection Vulnerability
Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.
Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.
WSO2 Multiple Products Path Traversal to RCE
WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway contain a path traversal flaw enabling unauthenticated file upload and remote code execution. CVSS 10.0. Actively exploited since September 13, 2026; added to CISA KEV September 24.
WordPress core get_page_template path traversal enables unauthenticated RCE
Path traversal in WordPress core's get_page_template() enables unauthenticated local PHP file inclusion and conditional RCE. Actively exploited within 24 hours of disclosure. CVSS 8.1 High.
Check Point Multiple Products Path Traversal Vulnerability
CVE-2026-93616: CVSS 9.8 path traversal and file upload in Check Point Management Server enabling unauth RCE. Confirmed exploited; patches available.
Arista VeloCloud Orchestrator Unauthenticated RCE
“CVE-2026-93952 is a CVSS 10.0 improper input validation flaw in Arista VeloCloud Orchestrator that allows unauthenticated remote code execution. Added to CISA KEV on September 22, 2026.”
From the desk

Suspected DPRK Hackers Steal $351.6M from Bitget
Bitget says suspected North Korean actors stole $351.6 million from hot and warm wallets in a backend compromise detected at 18:31 UTC on September 24.

SalesBleed: Agentforce Flaws Enable Data Exfiltration
Three SalesBleed flaws in Salesforce Agentforce allow attackers to hijack AI agents and exfiltrate data via trusted Slack channels without user interaction.

CISA KEV: WSO2 and Adobe Commerce Flaws Exploited
CISA added CVE-2026-5430 (WSO2, CVSS 10.0) and CVE-2026-71362 (Adobe Commerce, CVSS 9.1) to KEV on September 24. Federal patch deadline: September 27.

MacSync macOS Malware Abuses Public iCloud Calendars
Kaspersky found a new MacSync variant that hides C2 commands inside public iCloud calendar events, bypassing domain-based network controls on macOS.

Ryuk Member Gets 2 Years for $1.2M Ransomware Attacks
Armenian national Karen Vardanyan sentenced to 2 years in US federal prison for Ryuk ransomware attacks, ordered to pay over $1.2M in restitution to victims.

Roundcube SQL Injection Flaw Under Active Attack
Canada's CCCS confirmed active exploitation of CVE-2026-48842, a SQL injection in Roundcube Webmail patched in May. Upgrade to 1.6.16 or 1.7.1 now.
This week's SITREP
Sep 22: Cl0p Extorted, CrowdSec Source Code, BigCommerce
ShinyHunters escalates against Cl0p with an eight-figure demand and threatens to expose ransom-payer records. CrowdSec confirms source code theft. BigCommerce merchants hit via Ribon apps.




