0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Check Point Multiple Products Path Traversal Vulnerability
Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts.
Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.
Zyxel GS1900 Series Switches Stack-Based Buffer Overflow
Stack-based buffer overflow in Zyxel GS1900 CGI program lets unauthenticated LAN attackers execute OS commands. CVSS 8.8, added to CISA KEV September 21, 2026.
Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
Linux kernel TLS receive path: zero-length record bypasses recvmsg() handling, corrupting downstream TLS processing. CVSS 9.8. In CISA KEV Sept. 18, 2026.
Linux Kernel Race Condition Vulnerability
Linux kernel AF_ALG race condition: concurrent writes corrupt state, crashing the system or corrupting cryptographic output. CVSS 7.8. CISA KEV Sept. 18.
From the desk

CrowdSec Source Code Stolen in TanStack Attack
CrowdSec confirmed its source code was stolen, attributing the breach to the May 2026 TanStack JavaScript supply chain compromise. No vulnerability disclosed yet.

Red Hat Patches Four Keycloak IAM Flaws
Red Hat issued advisories for four Keycloak CVEs: admin API cache, authorization services exposure, UMA token confusion, and session enforcement bypass.

Jade Sleet Hits Indian IT Firm with Custom Backdoors
North Korea's Jade Sleet has compromised an India-based IT services provider, deploying the FLATROOF and ROOFDECK backdoors to position inside customer networks.

CVE-2026-94185: nvm Alias Path Traversal, Update Now
nvm before 0.40.8 has a path traversal in alias resolution. GHSA-8grh-q73j-ffrc rates it CVSS 5.5, but the real exposure depends on your build environment.

REDCap Patches CVSS 9.8 Unauth RCE via Survey Route
CVE-2026-90817 (CVSS 9.8): unauthenticated RCE in REDCap via the public survey endpoint. Arbitrary code execution on clinical research servers without credentials.

kcp Front-Proxy Lets Attackers Impersonate Any User
CVE-2026-61682 (CVSS 9.9): kcp front-proxy passes X-Remote-User headers through, enabling user impersonation. Fixed in 0.31.4 and 0.32.2.
This week's SITREP
Sep 22: Cl0p Extorted, CrowdSec Source Code, BigCommerce
ShinyHunters escalates against Cl0p with an eight-figure demand and threatens to expose ransom-payer records. CrowdSec confirms source code theft. BigCommerce merchants hit via Ribon apps.




