0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Ray-Project Ray Code Injection Vulnerability
Ray-Project Ray has a code injection flaw enabling RCE, added to CISA KEV on August 18, 2026. Ray installs with browser-reachable interfaces are at risk. Federal patch deadline is August 21.
Cisco ASA and FTD VPN Heap Inspection Denial-of-Service Flaw
Unauthenticated remote attackers can crash Cisco Secure Firewall ASA and FTD devices over VPN. Added to CISA KEV on 2026-08-11 with a three-day federal remediation deadline.
Windows AFD WinSock Use-After-Free Privilege Escalation
Use-after-free in Windows Ancillary Function Driver for WinSock (afd.sys) lets local attackers gain SYSTEM privileges via race condition. Actively exploited by Lazarus.
Metabase SQL Injection Vulnerability
Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.
From the desk

Critical GitLab Flaw Lets Attackers Delete Projects
GitLab patched CVE-2026-19478 (CVSS 9.4): unauthenticated attackers can delete or modify public projects. Self-hosted instances need immediate manual update.

Apple Patches 108 Flaws in iOS, iPadOS and macOS 26
Apple's August 17 patch for iOS/iPadOS (versions 26 and 18) and macOS 26 closes 108 vulnerabilities across the full platform stack. Update devices now.

Discourse: Critical CSP Bypass Fixed, Three More CVEs
Discourse patched CVSS 9.3 HTML injection bypassing nonce-CSP plus three info-disclosure flaws. Update: 2026.1.6, 2026.5.2, 2026.6.1, or 2026.7.0.

How CVSS Scoring Works
A plain-language guide to CVSS 3.1: what the base score components mean, the severity bands, and why the number alone doesn't tell you what to patch first.

What Is the CISA KEV Catalog?
CISA's Known Exploited Vulnerabilities catalog explained: what gets added, why it matters beyond federal agencies, and how to use it to prioritize patching.

Clop Claims GE and Philips; Both Investigating
General Electric and Philips confirm they are investigating data theft claims from the Clop ransomware gang. Neither company has confirmed exfiltration scope, affected systems, or breach date.




