0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Hard-coded credential in Cisco Secure FMC enables unauthenticated login
Cisco Secure FMC ships a static low-privileged account; remote unauthenticated attackers can log in and access sensitive data. CISA KEV confirmed July 29, 2026.
Microsoft MSHTML security feature bypass
Protection mechanism failure in Microsoft MSHTML lets unauthenticated attackers bypass a security feature over the network. CVSS 8.8, patched in Microsoft's February 2026 Patch Tuesday.
Arista VeloCloud Orchestrator OS Command Injection
CVSS 10.0 critical. Remote attackers can inject OS commands into Arista VeloCloud Orchestrator On-Prem, compromising the SD-WAN management plane.
Check Point SmartConsole improper authentication
CVE-2026-16232 lets unauthenticated attackers grab an admin token from SmartConsole. CISA KEV addition July 22; Check Point confirms active exploitation.
WordPress WP_Query author__not_in SQL injection (wp2shell companion)
A medium-severity SQL injection in WordPress WP_Query's author__not_in parameter (CVE-2026-60137). Tracked as the wp2shell companion. Patched in 6.8.6, 6.9.5, and 7.0.2.
WordPress Core unauthenticated RCE (wp2shell)
A critical unauthenticated remote code execution flaw in WordPress Core (CVE-2026-63030). GitHub Security Advisory issued July 17, 2026; public PoC circulating.
From the desk

Amgen Says Breach Exposed Patient Health Data
Amgen confirmed threat actors stole patient health information and proprietary corporate data from third-party cloud systems operated by outside service providers.

Arch Linux Locks Down AUR After Malware Takeover Surge
Arch Linux disabled AUR package adoption after a surge of malicious takeovers by threat actors who exploited the mechanism to push backdoored updates to users.

Adform Ad Script Hijacked in Supply-Chain Crypto Attack
Adform's ad script was backdoored to swap crypto wallet addresses in visitor clipboards, silently stealing funds on sites running the compromised tag.

Three Critical VMware Flaws Fixed: Auth Bypass, VM Escape
Broadcom patched five CVEs in VMware vCenter, ESXi, Workstation, and Fusion. Three are critical: auth bypass, RCE, VM escape. Patch vCenter now.

CISA Warns of Rising Attacks on Water System PLCs
CISA flags a surge in attacks targeting internet-exposed PLCs in U.S. water and wastewater systems. Patch, segment, and remove direct internet exposure.

AI Finds 1,442 Chrome Bugs in Three Recent Releases
Google patched 1,442 security flaws across Chrome 149, 150, and 151 — more than the prior 23 releases combined. AI-assisted testing drove the surge.




