Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-69836
[ CRITICAL ]CVSS 10.0EPSS 1.4%kev

Microsoft Entra ID Deserialization of Untrusted Data — RCE

Deserialization flaw in Microsoft Entra ID allows unauthenticated remote code execution over a network. CVSS 10.0. Actively exploited; added to CISA KEV on August 21, 2026.

Microsoft / Entra ID (formerly Azure Active Directory)
CVE-2026-73570
[ HIGH ]CVSS 8.9EPSS 1.0%kev

Zimbra ZCS SNMP Command Injection — Unauthenticated RCE

CVE-2026-73570 — CVSS 8.9 command injection in Zimbra Collaboration Suite's SNMP handler enables unauthenticated remote code execution. Actively exploited in the wild. Patch: Zimbra 10.1.20.

Synacor / Zimbra Collaboration Suite (ZCS)
CVE-2026-72529
[ CRITICAL ]CVSS 9.8EPSS 0.8%kev

TrueConf Server Missing Authentication for Critical Function Vulnerability

TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.

TrueConf / Server
CVE-2026-72530
[ CRITICAL ]CVSS 9.0EPSS 1.0%kev

TrueConf Server Code Injection Vulnerability

TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.

TrueConf / Server
CVE-2026-33824
[ CRITICAL ]CVSS 9.8EPSS 77.9%kev

Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.

Microsoft / Internet Key Exchange (IKE) Service Extensions
CVE-2026-64849
[ CRITICAL ]CVSS 9.3EPSS 8.2%kev

MLflow SSRF Lets Attackers Steal Cloud Credentials via Metadata Services

A server-side request forgery in MLflow before 3.15.0 allows unauthenticated access to internal endpoints including cloud metadata services, enabling cloud credential and IAM secret theft.

MLflow / MLflow (< 3.15.0)
$ latest --more

From the desk

all articles →
~/articles/2026-08-24-velociraptor-cve-2026-19200-artifact-overwrite
Velociraptor Flaw Lets Analysts Overwrite Artifacts
threat intel

Velociraptor Flaw Lets Analysts Overwrite Artifacts

CVE-2026-19200 (CVSS 8.9) lets Velociraptor analysts overwrite global artifacts, bypassing permission controls. Update your deployment.

read →
~/articles/2026-08-23-toxicpanda-vpn-permission-google-play-block
ToxicPanda Blocks Play Store via Android VPN Trick
mobile

ToxicPanda Blocks Play Store via Android VPN Trick

Zimperium: ToxicPanda 2.0 abuses VPN service permissions to block Google Play, now targeting 349 financial apps across 16 countries.

read →
~/articles/2026-08-23-strongswan-cve-2026-47895-double-free-eap
strongSwan 6.0.7 Patches Double-Free in IKE Auth
threat intel

strongSwan 6.0.7 Patches Double-Free in IKE Auth

CVE-2026-47895 is a CVSS 7.5 double-free triggered during IKE authentication in strongSwan before 6.0.7. Upgrade now — crash risk is confirmed, heap corruption is possible.

read →
~/articles/2026-08-23-banking-trojans-manic-grandoreiro-toxicpanda
Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 Active
mobile

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 Active

Three banking trojans are active: spyware-equipped Manic, persistent Grandoreiro across Latin America and Europe, and an expanded ToxicPanda 2.0.

read →
~/articles/2026-08-22-weechat-relay-timing-attack-cve-2026-53525
WeeChat Relay Flaw Exposes Auth to Timing Attack
threat intel

WeeChat Relay Flaw Exposes Auth to Timing Attack

WeeChat versions 0.3.1–4.9.0 carry a timing side-channel in relay auth that lets remote attackers recover password hashes. A decompression DoS affects the same range. Both patched in 4.9.1.

read →
~/articles/2026-08-22-android-car-head-unit-proxy-botnet
Car Infotainment Units Hijacked via Supply-Chain Attack
supply chain

Car Infotainment Units Hijacked via Supply-Chain Attack

A supply-chain attack against Android-based car head units trojanizes a legitimate device update app to install proxy botnet or ad fraud malware.

read →