0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.
IBM Langflow Code Injection Vulnerability
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.
Hard-coded credential in Cisco Secure FMC enables unauthenticated login
Cisco Secure FMC ships a static low-privileged account; remote unauthenticated attackers can log in and access sensitive data. CISA KEV confirmed July 29, 2026.
Microsoft MSHTML security feature bypass
Protection mechanism failure in Microsoft MSHTML lets unauthenticated attackers bypass a security feature over the network. CVSS 8.8, patched in Microsoft's February 2026 Patch Tuesday.
From the desk

Metabase Patches CVSS 10 Zero-Day Under Active Exploit
Metabase has released a patch for the max-severity unauthenticated SQL injection zero-day confirmed in active exploitation since August 8. Update now. No CVE assigned yet.

Levi Strauss Breach: Social Engineering, Data Exfil
A threat actor used social engineering to compromise three Levi Strauss employee computers and exfiltrate corporate data. Scope and attribution unconfirmed.

GStreamer Bugs Allow RCE Via Crafted Media Files
Two HIGH flaws in GStreamer's ADPCM decoder and ASF demuxer let crafted WAV, WMV, and WMA files trigger heap corruption and potential code execution.

Three CVEs Chain to Admin Takeover in WordPress Login Plugin
Three CVEs in the Login & Register Forms WordPress plugin before 4.0.2 enable unauthenticated account takeover, including site admins. Update now.

Metabase Zero-Day: CVSS 10 Exploited in the Wild
Unauthenticated SQL injection in Metabase BI gives attackers admin access. Exploitation confirmed, no CVE assigned. Take your instance offline if it's reachable from untrusted networks.

Perl Heap OOB in Regex Engine Through 5.45.1
CVE-2026-15534: signed 32-bit overflow in Perl's superlinear regex cache enables heap OOB on attacker-controlled input. Patch exists; CVSS pending.




