Skip to content
feed: live
>_ 0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-18556
[ HIGH ] CVSS 7.4 EPSS 0.5% kev

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.

N-able / N-central
CVE-2026-34486
[ HIGH ] CVSS 7.5 EPSS 81.2% kev

Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.

Apache / Tomcat
CVE-2026-9198
[ CRITICAL ] CVSS 9.8 EPSS 17.1% kev

IBM Langflow Code Injection Vulnerability

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

IBM / Langflow
CVE-2026-18577
[ HIGH ] EPSS 4.1% kev

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.

N-able / N-central
CVE-2026-20316
[ MEDIUM ] CVSS 5.3 EPSS 0.8% kev

Hard-coded credential in Cisco Secure FMC enables unauthenticated login

Cisco Secure FMC ships a static low-privileged account; remote unauthenticated attackers can log in and access sensitive data. CISA KEV confirmed July 29, 2026.

Cisco / Cisco Secure Firewall Management Center (FMC)
CVE-2026-21513
[ HIGH ] CVSS 8.8 EPSS 15.4% kev

Microsoft MSHTML security feature bypass

Protection mechanism failure in Microsoft MSHTML lets unauthenticated attackers bypass a security feature over the network. CVSS 8.8, patched in Microsoft's February 2026 Patch Tuesday.

Microsoft / MSHTML Framework (Windows)
$ latest --more

From the desk

all articles →
~/articles/2026-08-06-apache-tomcat-cve-2026-34486-encryptinterceptor-kev
Apache Tomcat EncryptInterceptor Bypass Added to KEV — Patch by Aug 7
apache

Apache Tomcat EncryptInterceptor Bypass Added to KEV — Patch by Aug 7

CVE-2026-34486 lets attackers bypass Tomcat's EncryptInterceptor, exposing clustered node traffic. CISA added it to KEV on Aug 4 after active exploitation. Fixed builds are out.

read →
~/articles/2026-08-06-n-able-n-central-cve-2026-18577-kev-auth-bypass
CISA Flags N-able N-central Auth Bypass — Patch Before Today's Deadline
supply chain

CISA Flags N-able N-central Auth Bypass — Patch Before Today's Deadline

CVE-2026-18577, an authentication bypass in N-able N-central, is on CISA's KEV list after active exploitation. It's an incomplete fix for an earlier flaw, and MSPs are the blast radius.

read →
~/articles/2026-08-02-eset-malicious-ai-skills-quishing-h1-2026
ESET Report: Malicious AI Skills, Record Quishing in H1 2026
threat intel

ESET Report: Malicious AI Skills, Record Quishing in H1 2026

ESET's mid-year threat report tracks attackers weaponizing AI platform skills, record QR phishing volume, ClickFix escalation, and ransomware tooling built to silence endpoint defenses.

read →
~/articles/2026-08-02-ntu-84-flaws-4g-5g-core-networks
84 Flaws Found in Open-Source 4G and 5G Cores
ics ot

84 Flaws Found in Open-Source 4G and 5G Cores

Researchers at NTU Singapore found 84 flaws in open-source 4G/5G core software, enabling DoS and session hijacking via GTP-C and PFCP protocol weaknesses.

read →
~/articles/2026-08-01-coldcard-prng-flaw-bitcoin-wallet-70m-theft
Coldcard Firmware Bug Behind $70M Bitcoin Theft
Analysis
threat intel

Coldcard Firmware Bug Behind $70M Bitcoin Theft

A 2021 Coldcard firmware error routed seed generation to a software PRNG. On July 30, an attacker swept 1,196 addresses in 41 minutes and took ~$70.2M in BTC.

read →
~/articles/2026-08-01-device-code-phishing-industrial-scale
Device Code Phishing Reaches Industrial Scale
threat intel

Device Code Phishing Reaches Industrial Scale

OAuth device authorization flow abuse has scaled from red-team niche to industrial-scale enterprise credential theft in under six months, per threat researchers.

read →