Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-20349
[ HIGH ]CVSS 8.6EPSS 0.9%kev

Cisco ASA and FTD VPN Heap Inspection Denial-of-Service Flaw

Unauthenticated remote attackers can crash Cisco Secure Firewall ASA and FTD devices over VPN. Added to CISA KEV on 2026-08-11 with a three-day federal remediation deadline.

Cisco / Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
CVE-2026-68820
[ HIGH ]CVSS 7.0EPSS 0.3%kev

Windows AFD WinSock Use-After-Free Privilege Escalation

Use-after-free in Windows Ancillary Function Driver for WinSock (afd.sys) lets local attackers gain SYSTEM privileges via race condition. Actively exploited by Lazarus.

Microsoft / Windows (multiple versions)
CVE-2026-72898
[ CRITICAL ]CVSS 10.0EPSS 10.4%kev

Metabase SQL Injection Vulnerability

Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.

Metabase / Metabase
CVE-2026-18556
[ HIGH ]CVSS 7.4EPSS 0.5%kev

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.

N-able / N-central
CVE-2026-34486
[ HIGH ]CVSS 7.5EPSS 82.9%kev

Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.

Apache / Tomcat
CVE-2026-9198
[ CRITICAL ]CVSS 9.8EPSS 17.4%kev

IBM Langflow Code Injection Vulnerability

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

IBM / Langflow
$ latest --more

From the desk

all articles →
~/articles/2026-08-14-amnesiastealer-macos-clickfix-browser-hijack
AmnesiaStealer Hijacks macOS Browser Sessions
apple

AmnesiaStealer Hijacks macOS Browser Sessions

Jamf finds AmnesiaStealer: macOS infostealer that hijacks live browser sessions, steals keychain data, and destroys saved passwords via ClickFix terminal prompts.

read →
~/articles/2026-08-14-macos-screen-sharing-auth-bypass-exploited
macOS Screen Sharing Auth Bypass Exploited in Wild
● Breaking
apple

macOS Screen Sharing Auth Bypass Exploited in Wild

Netherlands NCSC confirms active exploitation of a macOS Screen Sharing authentication bypass after public PoC release. Attackers deploying Monero cryptocurrency miners.

read →
~/articles/2026-08-14-sap-commerce-cloud-rce-exploitation
SAP Commerce Cloud RCE Exploit Hits Days After Patch
sap

SAP Commerce Cloud RCE Exploit Hits Days After Patch

Defused flagged active exploitation of a max-severity SAP Commerce Cloud RCE within 72 hours of patching. Unpatched instances are live targets now.

read →
~/articles/2026-08-14-shell-clop-89gb-data-theft-claim
Clop Claims 89GB Shell Theft; Investigation Open
● Breaking
ransomware

Clop Claims 89GB Shell Theft; Investigation Open

Shell confirms investigating a potential incident after Clop listed the oil giant on its extortion site, claiming 89GB of exfiltrated data. No breach confirmed; initial access vector undisclosed.

read →
~/articles/2026-08-14-ringcentral-breach-shinyhunters-1-6m-accounts
ShinyHunters Hits RingCentral: 1.6M Accounts Exposed
● Breaking
threat intel

ShinyHunters Hits RingCentral: 1.6M Accounts Exposed

ShinyHunters breached RingCentral in July, exposing 1.6 million accounts. Names, addresses, emails, and phone numbers are now published by the group.

read →
~/articles/2026-08-14-beacon-crm-breach-charities-aws-key
Beacon CRM Breach Hits 1,000+ Charities via AWS Key
● Breaking
cloud

Beacon CRM Breach Hits 1,000+ Charities via AWS Key

Over 1,000 UK charities had supporter data exposed after attackers used an AWS access key found in Beacon's public JavaScript build artifacts.

read →