Skip to content
feed: live
>_ 0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-20349
[ HIGH ] CVSS 8.6 EPSS 0.9% kev

Cisco ASA and FTD VPN Heap Inspection Denial-of-Service Flaw

Unauthenticated remote attackers can crash Cisco Secure Firewall ASA and FTD devices over VPN. Added to CISA KEV on 2026-08-11 with a three-day federal remediation deadline.

Cisco / Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
CVE-2026-68820
[ HIGH ] CVSS 7.0 EPSS 0.3% kev

Windows AFD WinSock Use-After-Free Privilege Escalation

Use-after-free in Windows Ancillary Function Driver for WinSock (afd.sys) lets local attackers gain SYSTEM privileges via race condition. Actively exploited by Lazarus.

Microsoft / Windows (multiple versions)
CVE-2026-72898
[ CRITICAL ] CVSS 10.0 EPSS 10.4% kev

Metabase SQL Injection Vulnerability

Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.

Metabase / Metabase
CVE-2026-18556
[ HIGH ] CVSS 7.4 EPSS 0.5% kev

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.

N-able / N-central
CVE-2026-34486
[ HIGH ] CVSS 7.5 EPSS 82.9% kev

Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.

Apache / Tomcat
CVE-2026-9198
[ CRITICAL ] CVSS 9.8 EPSS 17.4% kev

IBM Langflow Code Injection Vulnerability

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

IBM / Langflow
$ latest --more

From the desk

all articles →
~/articles/2026-08-13-ics-patch-tuesday-siemens-schneider-phoenix-contact
ICS Patch Tuesday: Siemens, Schneider, Phoenix Contact
ics ot

ICS Patch Tuesday: Siemens, Schneider, Phoenix Contact

Siemens, Schneider Electric, and Phoenix Contact issued security bulletins on August 12. CISA published parallel ICS advisories the same day. OT operators should review now.

read →
~/articles/2026-08-13-android-windrelay-spynote-nfc-relay-fraud
Android Malware Relays NFC Cards, Takes Out Loans
● Breaking
mobile

Android Malware Relays NFC Cards, Takes Out Loans

WindRelay, a new Android NFC relay malware, is deployed alongside SpyNote RAT to steal live card data and take out fraudulent loans in victims' names.

read →
~/articles/2026-08-12-city-forum-salesforce-servicenow-data-theft
City-Forum Campaign Targets Salesforce, ServiceNow
threat intel

City-Forum Campaign Targets Salesforce, ServiceNow

A data-theft operation running since March 2025 harvests records exposed through anonymous-access endpoints in Salesforce Experience Cloud and ServiceNow portals — no CVE required.

read →
~/articles/2026-08-12-colombia-justice-ministry-ransomware
Colombia Justice Ministry Hit With Ransomware
● Breaking
ransomware

Colombia Justice Ministry Hit With Ransomware

Ransomware disrupted Colombia's Ministry of Justice days before the presidential transition, part of a documented pattern of attacks on Latin American government institutions.

read →
~/articles/2026-08-12-adobe-commerce-cve-2026-71362-active-exploit
Attackers Exploiting Critical Adobe Commerce Flaw
● Breaking
adobe

Attackers Exploiting Critical Adobe Commerce Flaw

Active exploitation of CVE-2026-71362 targets Adobe Commerce and Magento storefronts. CVSS 9.1 critical flaw enables account hijacking without user interaction.

read →
~/articles/2026-08-12-chrome-vpn-extensions-proxy-hijack
737 Fake Chrome VPN Extensions Route Traffic via Proxies
browser

737 Fake Chrome VPN Extensions Route Traffic via Proxies

737 Chrome extensions impersonated VPN services while routing users' traffic through a single SOCKS5 proxy. Over 75,000 installs affected across the Store.

read →