0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Cisco Secure Email Gateway SQL Injection Vulnerability
SQL injection in Cisco AsyncOS for Secure Email Gateway lets an unauthenticated remote attacker execute arbitrary OS commands with root privileges. CISA KEV since Sept. 14.
JFrog Artifactory Incorrect Authorization Vulnerability
JFrog Artifactory validates token signature and issuer but not scope, creating a privilege escalation path. CVSS 8.1 (high), CISA KEV deadline September 25, 2026.
JFrog Artifactory Improper Authentication Vulnerability
JFrog Artifactory returns an internal anonymous-user token to unauthenticated callers even when anonymous access is disabled, allowing unauthorized resource access and enabling privilege escalation chains.
ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
ConnectWise ScreenConnect allows file transfer and execution through active remote sessions without authorization. CVSS 9.9 critical, CISA KEV due September 14.
GitLab Path Traversal Allows Unauthenticated File Read
GitLab CE/EE contains a path traversal flaw due to improper path confinement and missing access controls, allowing an unauthenticated attacker to read arbitrary files from the server.
MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
MikroTik RouterOS btest service missing authentication allows kernel memory disclosure. CVSS 8.2 (high), CISA KEV deadline September 13, 2026.
From the desk

Japan Digital Agency Breach Exposes 246K Staff Records
Japan's Digital Agency disclosed a VPN breach affecting roughly 246,000 rows of government employee personal information. The specific CVE and VPN vendor have not been named.

China-Linked Group Deploys GRIMWEDGE via Zero-Day Chain
A China-linked group uses a Chrome-plus-Windows zero-day chain in targeted spear-phishing campaigns to drop GRIMWEDGE, a JavaScript backdoor, on victim systems.

Cisco Email Gateway SQLi Grants Root, Now in KEV
CVE-2026-76461, a SQL injection in Cisco AsyncOS, lets unauthenticated attackers run OS commands as root. CISA added it to KEV on Sept. 14 with a Sept. 17 deadline.

ScreenConnect Worm Attacks: CVE-2026-84869 Now Patched
Huntress documented worm-like ScreenConnect attacks active since August 20. ConnectWise has released version 26.6.5 patching CVE-2026-84869, a CVSS 9.9 flaw exploited in the campaign.

Revolut Breach Exposes Passports and Financial Data
A threat actor impersonated a government agency to obtain passport copies, identity documents, and complete transaction records from an undisclosed number of Revolut customers.

CVSS 10 Flaw in WordPress Payment Plugin Grants Admin Access
CVE-2026-81648 skips authorization on a CryptoPayment Gateway AJAX endpoint in versions 1.2.1-1.2.2, giving unauthenticated visitors admin-level access.
This week's SITREP
Sep 16: Cisco SEG in KEV, Apple 200 Patches, Japan VPN Breach
CVE-2026-76461 in Cisco Secure Email Gateway in CISA KEV with a Sept. 17 federal deadline; Apple patches ~200 flaws in iOS 27 and macOS Golden Gate; Japan Digital Agency loses 246K personnel records via VPN appliance flaw.




