0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
Linux kernel TLS receive path: zero-length record bypasses recvmsg() handling, corrupting downstream TLS processing. CVSS 9.8. In CISA KEV Sept. 18, 2026.
Linux Kernel Race Condition Vulnerability
Linux kernel AF_ALG race condition: concurrent writes corrupt state, crashing the system or corrupting cryptographic output. CVSS 7.8. CISA KEV Sept. 18.
Linux Kernel Out-of-Bounds Write Vulnerability
OOB write in Linux kernel ebtables SNAT target. ARP address rewrite lands in a nonlinear socket buffer. CVSS 8.8, public exploits confirmed. CISA KEV Sept. 18.
Google Pixel Cellular Modem Improper Authorization
Improper authorization in Google Pixel's cellular modem lets a nearby attacker bypass permission checks and escalate privileges without user interaction. CISA KEV, due 2026-09-19.
Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
CVSS 10.0 auth bypass in Cisco ISE and ISE-PIC. Unauthenticated attackers can bypass web management and gain root execution. Actively exploited; CISA KEV.
Acronis Backup Incorrect Default Permissions Vulnerability
Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.
From the desk

Microsoft Fabric Auth Bypass Reaches CVSS 10.0
Microsoft patched CVE-2026-69843, a CVSS 10.0 authentication bypass in Fabric that let unauthenticated attackers elevate privileges over a network.

Microsoft Fixes CVSS 10.0 Flaw in Azure AI Foundry
Microsoft patched CVE-2026-85889, a CVSS 10.0 missing-authentication flaw in Azure AI Foundry that let unauthenticated attackers escalate privileges. No customer action required.

WaterPlum: North Korea Targets Job Seekers, 30K Devices Hit
FBI and four allies confirm North Korea's WaterPlum campaign infected 30,000 devices across 100 countries via fake job interviews.

CISA Adds Three Exploited Linux Kernel Flaws to KEV
CISA added CVE-2025-39682 (CVSS 9.8), CVE-2026-53266, and CVE-2025-39964 to KEV on Sept. 18. All three actively exploited. Federal deadline: Sept. 21.

Gyazo Breach Exposes 23M Records and OAuth Tokens
Helpfeel confirms 23.6 million Gyazo accounts breached September 11, exposing Google and X OAuth tokens. Revoke app access before changing passwords.

Ransomware Attacks on Manufacturers Up 40% in H1 2026
Ransomware attacks on manufacturers rose 40 percent in the first half of 2026, with groups exploiting the supply-chain disruption that follows operational shutdowns.




