0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Type confusion in Chrome V8 allows sandbox code execution
Type confusion in Chrome's V8 engine lets remote attackers run arbitrary code inside the browser sandbox via a crafted HTML page. Actively exploited; update to 152.0.7977.82.
Kludex Starlette HTTP Request/Response Smuggling Vulnerability
Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.
Kestra OSS OS Command Injection Vulnerability
Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.
BerriAI LiteLLM Improper Authentication Vulnerability
BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.
Sangoma Switchvox SQL Injection Vulnerability
Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
Pre-auth SSRF in SonicWall SMA1000 Workplace Interface
Unauthenticated SSRF in the SMA1000 Workplace interface allows remote attackers to reach internal functionality via an unintended access path. Exploited in the wild; chains with CVE-2026-83549 for RCE.
From the desk

N-able Patches CVSS 10 Pre-Auth RCE in N-central
N-able's N-central RMM platform has a pre-authentication remote code execution flaw, CVSS 4.0: 10.0, affecting all versions before 2026.3.1.14. Patch immediately.

JetBrains Cadence Breached via Unpatched TeamCity RCE
AWS keys, source code, and a server backup stolen from JetBrains Cadence after its TeamCity server went unpatched for weeks against CVE-2026-63077.

Magento Zero-Day Exploited to Backdoor Online Stores
Attackers exploit an unpatched unauthenticated RCE in Magento Open Source and Adobe Commerce to install backdoors in online stores. No patch available.

PaperCut Attackers Steal Credentials From Schools
Arctic Wolf finds PaperCut exploitation now targeting US and European schools with credential theft as the post-exploitation objective.

IDScan Sued Over Breach of 153M Driver Licenses
Multiple lawsuits target identity verification firm IDScan after hackers allegedly accessed and offered to sell more than 153 million driver records.

PostgreSQL Patches 12-Year-Old Logical Decoding RCE
PostgreSQL patches a 12-year-old flaw in its logical decoding subsystem. Accounts with the REPLICATION attribute could execute code on the underlying host.




