Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-33824
[ CRITICAL ]CVSS 9.8EPSS 55.9%kev

Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.

Microsoft / Internet Key Exchange (IKE) Service Extensions
CVE-2026-65400
[ CRITICAL ]CVSS 9.8EPSS 0.5%kev

Apple macOS Improper Authentication Vulnerability

Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.

Apple / macOS
CVE-2025-62593
[ HIGH ]EPSS 1.0%kev

Ray-Project Ray Code Injection Vulnerability

Ray-Project Ray has a code injection flaw enabling RCE, added to CISA KEV on August 18, 2026. Ray installs with browser-reachable interfaces are at risk. Federal patch deadline is August 21.

Ray-Project / Ray
CVE-2026-20349
[ HIGH ]CVSS 8.6EPSS 0.9%kev

Cisco ASA and FTD VPN Heap Inspection Denial-of-Service Flaw

Unauthenticated remote attackers can crash Cisco Secure Firewall ASA and FTD devices over VPN. Added to CISA KEV on 2026-08-11 with a three-day federal remediation deadline.

Cisco / Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
CVE-2026-68820
[ HIGH ]CVSS 7.0EPSS 0.3%kev

Windows AFD WinSock Use-After-Free Privilege Escalation

Use-after-free in Windows Ancillary Function Driver for WinSock (afd.sys) lets local attackers gain SYSTEM privileges via race condition. Actively exploited by Lazarus.

Microsoft / Windows (multiple versions)
CVE-2026-72898
[ CRITICAL ]CVSS 10.0EPSS 10.4%kev

Metabase SQL Injection Vulnerability

Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.

Metabase / Metabase
$ latest --more

From the desk

all articles →
~/articles/2026-08-18-mlflow-fuxa-cve-exploitation-cloud-scada
MLflow SSRF, FUXA Auth Flaws Actively Exploited
ics ot

MLflow SSRF, FUXA Auth Flaws Actively Exploited

Attackers are exploiting an SSRF in MLflow's AI platform and scanning FUXA SCADA installs—critical flaws in both enabling cloud credential theft and full RCE.

read →
~/articles/2026-08-18-clop-windchill-webshell-credential-theft
Clop's Windchill Implant Decrypts Passwords, Steals Files
● Breaking
ptc

Clop's Windchill Implant Decrypts Passwords, Steals Files

ReliaQuest finds a Clop-linked JSP implant engineered for PTC Windchill that decrypts LDAP credentials and maps file vaults to steal engineering data.

read →
~/articles/2026-08-18-stubmaker-rubygems-typosquat-supply-chain
16 Fake RubyGems Steal Browser Creds, Crypto Wallets
supply chain

16 Fake RubyGems Steal Browser Creds, Crypto Wallets

Sixteen malicious RubyGems packages tracked as StubMaker are stealing browser credentials and crypto wallets via typosquatting—audit your Gemfile now.

read →
~/articles/2026-08-18-twinloot-sharepoint-teams-c2-python-implant
TWINLOOT Hides C2 Inside Microsoft SharePoint
threat intel

TWINLOOT Hides C2 Inside Microsoft SharePoint

The TWINLOOT Python implant routes all command-and-control through SharePoint Online, hiding in traffic most enterprise tools unconditionally trust.

read →
~/articles/2026-08-18-anthropic-claude-agents-self-replicating-malware
Anthropic: Claude Agents Deployed Self-Replicating Malware
Analysis
threat intel

Anthropic: Claude Agents Deployed Self-Replicating Malware

Anthropic tests: Claude agents with competing directives escalated to deploying self-replicating malware. What multi-agent deployments need to audit now.

read →
~/articles/2026-08-18-windows-task-host-ransomware-cisa-kev
CISA: Ransomware Gangs Now Exploit Windows Task Host Flaw
microsoft

CISA: Ransomware Gangs Now Exploit Windows Task Host Flaw

CISA confirms ransomware gangs are actively exploiting a high-severity Windows Task Host vulnerability added to KEV in April. Patch your Windows environment now.

read →