Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2025-62593
[ HIGH ]EPSS 0.4%kev

Ray-Project Ray Code Injection Vulnerability

Ray-Project Ray has a code injection flaw enabling RCE, added to CISA KEV on August 18, 2026. Ray installs with browser-reachable interfaces are at risk. Federal patch deadline is August 21.

Ray-Project / Ray
CVE-2026-20349
[ HIGH ]CVSS 8.6EPSS 0.9%kev

Cisco ASA and FTD VPN Heap Inspection Denial-of-Service Flaw

Unauthenticated remote attackers can crash Cisco Secure Firewall ASA and FTD devices over VPN. Added to CISA KEV on 2026-08-11 with a three-day federal remediation deadline.

Cisco / Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
CVE-2026-68820
[ HIGH ]CVSS 7.0EPSS 0.3%kev

Windows AFD WinSock Use-After-Free Privilege Escalation

Use-after-free in Windows Ancillary Function Driver for WinSock (afd.sys) lets local attackers gain SYSTEM privileges via race condition. Actively exploited by Lazarus.

Microsoft / Windows (multiple versions)
CVE-2026-72898
[ CRITICAL ]CVSS 10.0EPSS 10.4%kev

Metabase SQL Injection Vulnerability

Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.

Metabase / Metabase
CVE-2026-18556
[ HIGH ]CVSS 7.4EPSS 0.5%kev

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.

N-able / N-central
CVE-2026-34486
[ HIGH ]CVSS 7.5EPSS 82.9%kev

Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.

Apache / Tomcat
$ latest --more

From the desk

all articles →
~/articles/2026-08-17-gitlab-cve-2026-19478-graphql-unauth
Critical GitLab Flaw Lets Attackers Delete Projects
gitlab

Critical GitLab Flaw Lets Attackers Delete Projects

GitLab patched CVE-2026-19478 (CVSS 9.4): unauthenticated attackers can delete or modify public projects. Self-hosted instances need immediate manual update.

read →
~/articles/2026-08-17-apple-ios-macos-108-vulnerabilities-patched
Apple Patches 108 Flaws in iOS, iPadOS and macOS 26
apple

Apple Patches 108 Flaws in iOS, iPadOS and macOS 26

Apple's August 17 patch for iOS/iPadOS (versions 26 and 18) and macOS 26 closes 108 vulnerabilities across the full platform stack. Update devices now.

read →
~/articles/2026-08-17-discourse-cve-2026-55674-csp-bypass
Discourse: Critical CSP Bypass Fixed, Three More CVEs
discourse

Discourse: Critical CSP Bypass Fixed, Three More CVEs

Discourse patched CVSS 9.3 HTML injection bypassing nonce-CSP plus three info-disclosure flaws. Update: 2026.1.6, 2026.5.2, 2026.6.1, or 2026.7.0.

read →
~/articles/2026-08-17-how-cvss-scoring-works
How CVSS Scoring Works
Explainer
cvss

How CVSS Scoring Works

A plain-language guide to CVSS 3.1: what the base score components mean, the severity bands, and why the number alone doesn't tell you what to patch first.

read →
~/articles/2026-08-17-what-is-cisa-kev-catalog
What Is the CISA KEV Catalog?
Explainer
cisa kev

What Is the CISA KEV Catalog?

CISA's Known Exploited Vulnerabilities catalog explained: what gets added, why it matters beyond federal agencies, and how to use it to prioritize patching.

read →
~/articles/2026-08-17-clop-ransomware-ge-philips-data-theft
Clop Claims GE and Philips; Both Investigating
● Breaking
ransomware

Clop Claims GE and Philips; Both Investigating

General Electric and Philips confirm they are investigating data theft claims from the Clop ransomware gang. Neither company has confirmed exfiltration scope, affected systems, or breach date.

read →