0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Check Point SmartConsole improper authentication
CVE-2026-16232 lets unauthenticated attackers grab an admin token from SmartConsole. CISA KEV addition July 22; Check Point confirms active exploitation.
DD-WRT SSDP Stack-Based Buffer Overflow (UPnP)
An unsafe strcpy in DD-WRT's SSDP handling lets an unauthenticated attacker overflow an internal buffer via the UPnP listener and trigger code execution. Added to CISA KEV on 2026-07-21.
Fortinet FortiSandbox unauthenticated OS command injection (4.2, 4.4, 5.0, Cloud, PaaS)
An unauthenticated OS command injection across FortiSandbox 4.2, 4.4, 5.0, plus FortiSandbox Cloud and PaaS 5.0 lets a network attacker run arbitrary commands via crafted HTTP requests. CVSS 9.8; CISA-listed KEV.
Oracle E-Business Suite Payments improper privilege management (unauth RCE)
A critical improper-privilege-management flaw in the Oracle Payments component of Oracle E-Business Suite (File Transmission) that lets an unauthenticated network attacker take over Oracle Payments. Patched in Oracle's May 2026 Critical Patch Update; added to CISA KEV on July 15, 2026.
SonicWall SMA1000 unauthenticated SSRF in Work Place portal
An unauthenticated server-side request forgery in the SonicWall SMA1000 Work Place web interface lets a remote attacker force the appliance to make requests to attacker-chosen destinations. Actively exploited; on CISA KEV.
SonicWall SMA1000 post-authentication OS command injection
A post-authentication OS command injection in the SonicWall SMA1000 lets an administrator execute arbitrary OS commands on the appliance. Actively exploited alongside CVE-2026-15409; on CISA KEV.
From the desk

Certighost: Low-Priv AD Users Can Impersonate DCs
Certighost gives any low-privileged Active Directory user a path to DCSync: obtain a DC certificate, authenticate as the DC, pull the krbtgt hash.

Bing SVG Flaw Ran Code as SYSTEM on Microsoft Servers
A crafted SVG submitted to Bing Images ran commands as SYSTEM on Microsoft's production image servers. CVE-2026-32194 (CVSS 9.8) is now patched.

Golden Chickens Resurfaces: Four New Families, Same MaaS
Recorded Future documents four new families from the Golden Chickens MaaS — TinyEgg, ChonkyChicken, a modular variant, and ChromEggscalator.

AI Agent Ran Unattended in Thailand's Finance Ministry
An attacker disabled Hermes AI agent's permission gates and let it hunt Thailand's Finance Ministry network autonomously — a confirmed attack, not a theoretical one.

NodeBB Patches Eight AI-Found High-Severity Flaws
Eight high-severity NodeBB flaws expose admin access and private chats in all pre-4.14.0 versions. Aikido Security's AI pentest found them in six hours. Patch to 4.14.2.

AI Agents Uncover Redis Zero-Days, Seven Patches Ship
Kimi K3 AI agents found authenticated RCE flaws in four Redis versions. Redis shipped seven security releases on July 23 — update your deployments.




