Skip to content
feed: live
>_ 0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-16232
[ CRITICAL ] CVSS 9.1 kev

Check Point SmartConsole improper authentication

CVE-2026-16232 lets unauthenticated attackers grab an admin token from SmartConsole. CISA KEV addition July 22; Check Point confirms active exploitation.

Check Point / SmartConsole
CVE-2021-27137
[ HIGH ] CVSS 8.1 kev

DD-WRT SSDP Stack-Based Buffer Overflow (UPnP)

An unsafe strcpy in DD-WRT's SSDP handling lets an unauthenticated attacker overflow an internal buffer via the UPnP listener and trigger code execution. Added to CISA KEV on 2026-07-21.

DD-WRT / DD-WRT router firmware (builds prior to revision 45724)
CVE-2026-25089
[ CRITICAL ] CVSS 9.8 kev

Fortinet FortiSandbox unauthenticated OS command injection (4.2, 4.4, 5.0, Cloud, PaaS)

An unauthenticated OS command injection across FortiSandbox 4.2, 4.4, 5.0, plus FortiSandbox Cloud and PaaS 5.0 lets a network attacker run arbitrary commands via crafted HTTP requests. CVSS 9.8; CISA-listed KEV.

Fortinet / FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS (multiple 4.x and 5.0 lines — see body)
CVE-2026-46817
[ CRITICAL ] CVSS 9.8 kev

Oracle E-Business Suite Payments improper privilege management (unauth RCE)

A critical improper-privilege-management flaw in the Oracle Payments component of Oracle E-Business Suite (File Transmission) that lets an unauthenticated network attacker take over Oracle Payments. Patched in Oracle's May 2026 Critical Patch Update; added to CISA KEV on July 15, 2026.

Oracle / E-Business Suite — Oracle Payments (versions 12.2.3–12.2.15)
CVE-2026-15409
[ CRITICAL ] CVSS 10.0 kev

SonicWall SMA1000 unauthenticated SSRF in Work Place portal

An unauthenticated server-side request forgery in the SonicWall SMA1000 Work Place web interface lets a remote attacker force the appliance to make requests to attacker-chosen destinations. Actively exploited; on CISA KEV.

SonicWall / SMA1000 Series (6210, 7210, 8200v)
CVE-2026-15410
[ HIGH ] CVSS 7.2 kev

SonicWall SMA1000 post-authentication OS command injection

A post-authentication OS command injection in the SonicWall SMA1000 lets an administrator execute arbitrary OS commands on the appliance. Actively exploited alongside CVE-2026-15409; on CISA KEV.

SonicWall / SMA1000 Series (6210, 7210, 8200v)
$ latest --more

From the desk

all articles →
~/articles/2026-07-26-hotel-wifi-dns-hijack-m365-credential-theft
Hotel Wi-Fi DNS Hijacked to Serve Fake M365 Pages
microsoft

Hotel Wi-Fi DNS Hijacked to Serve Fake M365 Pages

Attackers are reconfiguring DNS on hotel Wi-Fi devices to redirect guests to fake Microsoft 365 login pages and harvest corporate credentials.

read →
~/articles/2026-07-25-steam-clickfix-xmrig-cryptominer-gamers
Steam Forums Weaponized in ClickFix Cryptominer Campaign
threat intel

Steam Forums Weaponized in ClickFix Cryptominer Campaign

Fake fix posts on Steam discussion forums are walking gamers into running commands that silently install XMRig cryptominers. What happened and what to check.

read →
~/articles/2026-07-25-bing-images-cve-2026-32194-32191-svg-system-rce
Bing Image Workers Ran SYSTEM Commands via Crafted SVGs
microsoft

Bing Image Workers Ran SYSTEM Commands via Crafted SVGs

Microsoft patched two critical CVEs after XBOW found Bing's image processing ran arbitrary commands as NT AUTHORITY\SYSTEM on crafted SVG input.

read →
~/articles/2026-07-25-certighost-ad-cs-domain-controller-exploit
Certighost: Working Exploit Reaches AD Domain Controllers
microsoft

Certighost: Working Exploit Reaches AD Domain Controllers

Researchers published a working Certighost exploit: any AD user can obtain a Domain Controller certificate and run DCSync to extract the krbtgt hash. No CVE assigned.

read →
~/articles/2026-07-25-ctm360-aitm-insurance-phishing-real-time-mfa
Insurance Sector Phishing Has Evolved to Real-Time AiTM
Analysis
threat intel

Insurance Sector Phishing Has Evolved to Real-Time AiTM

CTM360 research traces how insurance-focused phishing campaigns evolved from credential theft to real-time session hijacking that defeats standard MFA entirely.

read →
~/articles/2026-07-25-shinyhunters-breach-data-sextortion-2000-bitcoin
ShinyHunters Breach Data Now Fueling Sextortion Emails
● Breaking
ransomware

ShinyHunters Breach Data Now Fueling Sextortion Emails

Threat actors are targeting email addresses from ShinyHunters data leaks with $2,000 Bitcoin sextortion demands. What the campaign looks like and what to do.

read →