0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Hard-coded credential in Cisco Secure FMC enables unauthenticated login
Cisco Secure FMC ships a static low-privileged account; remote unauthenticated attackers can log in and access sensitive data. CISA KEV confirmed July 29, 2026.
Arista VeloCloud Orchestrator OS Command Injection
CVSS 10.0 critical. Remote attackers can inject OS commands into Arista VeloCloud Orchestrator On-Prem, compromising the SD-WAN management plane.
Check Point SmartConsole improper authentication
CVE-2026-16232 lets unauthenticated attackers grab an admin token from SmartConsole. CISA KEV addition July 22; Check Point confirms active exploitation.
DD-WRT SSDP Stack-Based Buffer Overflow (UPnP)
An unsafe strcpy in DD-WRT's SSDP handling lets an unauthenticated attacker overflow an internal buffer via the UPnP listener and trigger code execution. Added to CISA KEV on 2026-07-21.
Fortinet FortiSandbox unauthenticated OS command injection (4.2, 4.4, 5.0, Cloud, PaaS)
An unauthenticated OS command injection across FortiSandbox 4.2, 4.4, 5.0, plus FortiSandbox Cloud and PaaS 5.0 lets a network attacker run arbitrary commands via crafted HTTP requests. CVSS 9.8; CISA-listed KEV.
Oracle E-Business Suite Payments improper privilege management (unauth RCE)
A critical improper-privilege-management flaw in the Oracle Payments component of Oracle E-Business Suite (File Transmission) that lets an unauthenticated network attacker take over Oracle Payments. Patched in Oracle's May 2026 Critical Patch Update; added to CISA KEV on July 15, 2026.
From the desk

Azure CosmosEscape Flaw Exposed Any Tenant's Database
Wiz's CosmosEscape attack chain escaped Azure Cosmos DB's Gremlin sandbox, gained platform code execution, and extracted a key granting cross-tenant read/write access. Now patched.

Teams IT Vishing Drops Chaos Ransomware on US Firms
Microsoft Teams vishing campaign impersonates IT support, gains remote access, and drops Chaos ransomware on North American organizations.

Brinks Home Confirms Breach; ShinyHunters Claims Credit
Brinks Home confirmed unauthorized access to systems and file exfiltration. ShinyHunters claims credit and is threatening a data dump.

Analog Devices Confirms Breach, Files Exfiltrated
Analog Devices disclosed that an unauthorized party accessed its systems and exfiltrated files. The U.S. semiconductor maker says operations remain unaffected.

Copilot Prompt Injection Can Rewrite Docs, Self-Propagate
Hidden instructions in Word docs can make M365 Copilot falsify figures and embed the attack in output files, which then fire again in the next Copilot session. No patch announced.

AnySign4PC Exploited in Korean Watering Hole Campaign
State-sponsored attackers compromised trusted Korean websites to exploit AnySign4PC financial software, silently installing SIGNBT or COPPERHEDGE backdoors without user interaction.




