0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Oracle WebLogic/HTTP Server unauthenticated data access via HTTP
Unauthenticated HTTP access exposes critical data on Oracle HTTP Server and WebLogic Server. CVSS 10.0. CISA added to KEV August 25, 2026; active exploitation confirmed.
Microsoft Entra ID Deserialization of Untrusted Data — RCE
Deserialization flaw in Microsoft Entra ID allows unauthenticated remote code execution over a network. CVSS 10.0. Actively exploited; added to CISA KEV on August 21, 2026.
Zimbra ZCS SNMP Command Injection — Unauthenticated RCE
CVE-2026-73570 — CVSS 8.9 command injection in Zimbra Collaboration Suite's SNMP handler enables unauthenticated remote code execution. Actively exploited in the wild. Patch: Zimbra 10.1.20.
TrueConf Server Missing Authentication for Critical Function Vulnerability
TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.
TrueConf Server Code Injection Vulnerability
TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
From the desk

rConfig Auth Bypass Grants Unauthenticated Admin Access
rConfig 8.0.0–8.2.12 carries a CVSS 9.8 auth bypass: unauth users can self-register as admins. A second path traversal flaw also patched in 8.2.13.

Iran ICS Attack Shuts UK Power Plant; US Sanctions
A UK power plant went dark for four days after an Iran-linked cyberattack; the U.S. has now sanctioned Iranian nationals tied to the critical infrastructure campaign.

StackGres CVSS 9.9 Bug Escalates DB Tenant to Admin
CVE-2026-78155 (CVSS 9.9): StackGres Kubernetes operator lets a low-privilege database tenant escalate to administrator. Patch immediately.

GitLab Patches RCE in Package Registry (CVE-2026-10053)
GitLab CE/EE authenticated RCE via path traversal in the package registry affects 18.8 through 19.2. Upgrade to 19.0.6, 19.1.4, or 19.2.2 now.

Velociraptor Flaw Lets Analysts Overwrite Artifacts
CVE-2026-19200 (CVSS 8.9) lets Velociraptor analysts overwrite global artifacts, bypassing permission controls. Update your deployment.

ToxicPanda Blocks Play Store via Android VPN Trick
Zimperium: ToxicPanda 2.0 abuses VPN service permissions to block Google Play, now targeting 349 financial apps across 16 countries.



