0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Type confusion in Chrome V8 allows sandbox code execution
Type confusion in Chrome's V8 engine lets remote attackers run arbitrary code inside the browser sandbox via a crafted HTML page. Actively exploited; update to 152.0.7977.82.
Kludex Starlette HTTP Request/Response Smuggling Vulnerability
Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.
Kestra OSS OS Command Injection Vulnerability
Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.
BerriAI LiteLLM Improper Authentication Vulnerability
BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.
Sangoma Switchvox SQL Injection Vulnerability
Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
Pre-auth SSRF in SonicWall SMA1000 Workplace Interface
Unauthenticated SSRF in the SMA1000 Workplace interface allows remote attackers to reach internal functionality via an unintended access path. Exploited in the wild; chains with CVE-2026-83549 for RCE.
From the desk

All-in-One WP Migration Flaw Hits 3M WordPress Sites
Unauthenticated SQL injection in All-in-One WP Migration and Backup plugin (versions through 7.109) enables data theft and conditional RCE. Update immediately.

Elementor Pro Flaw Exploited to Backdoor WordPress Sites
Attackers are exploiting CVE-2026-32475, a critical file upload flaw in Elementor Pro, to deliver webshells to WordPress sites running version 4.2.1 or earlier.

Cisco Patches Critical RCE in Nexus 9000 Switches
Cisco has patched a CVSS 9.8 flaw in ten Silicon One Nexus 9000 switches letting unauthenticated remote attackers execute arbitrary code as root. No workaround available.

OpenAI's Astra Crosses Critical Cybersecurity Threshold
OpenAI's Astra is the first AI model formally designated as capable of autonomously finding and exploiting zero-days across well-defended systems.

FalconFlank PoC: Privilege Escalation in CrowdStrike Falcon
Researcher Chaotic Eclipse released a public PoC for FalconFlank, a privilege escalation zero-day in CrowdStrike Falcon. No CVE assigned. No patch confirmed as of September 3.

CISA Adds Seven Exploited Flaws to KEV Catalog
CISA added seven actively exploited vulnerabilities to KEV on September 3, including a critical Sangoma Switchvox SQL injection. Federal agencies face BOD 26-04 remediation deadlines.




