Skip to content
feed: live
>_ 0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-20349
[ HIGH ] CVSS 8.6 EPSS 0.9% kev

Cisco ASA and FTD VPN Heap Inspection Denial-of-Service Flaw

Unauthenticated remote attackers can crash Cisco Secure Firewall ASA and FTD devices over VPN. Added to CISA KEV on 2026-08-11 with a three-day federal remediation deadline.

Cisco / Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
CVE-2026-68820
[ HIGH ] CVSS 7.0 EPSS 0.3% kev

Windows AFD WinSock Use-After-Free Privilege Escalation

Use-after-free in Windows Ancillary Function Driver for WinSock (afd.sys) lets local attackers gain SYSTEM privileges via race condition. Actively exploited by Lazarus.

Microsoft / Windows (multiple versions)
CVE-2026-72898
[ CRITICAL ] CVSS 10.0 EPSS 10.4% kev

Metabase SQL Injection Vulnerability

Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.

Metabase / Metabase
CVE-2026-18556
[ HIGH ] CVSS 7.4 EPSS 0.5% kev

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.

N-able / N-central
CVE-2026-34486
[ HIGH ] CVSS 7.5 EPSS 82.9% kev

Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.

Apache / Tomcat
CVE-2026-9198
[ CRITICAL ] CVSS 9.8 EPSS 17.4% kev

IBM Langflow Code Injection Vulnerability

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

IBM / Langflow
$ latest --more

From the desk

all articles →
~/articles/2026-08-14-geoserver-zero-day-rce-active-exploitation
GeoServer Zero-Day SQL Injection Exploited in Wild
● Breaking
threat intel

GeoServer Zero-Day SQL Injection Exploited in Wild

Threat actors are actively exploiting an unpatched SQL injection in GeoServer that enables remote code execution. No patch available; restrict exposure immediately.

read →
~/articles/2026-08-14-apple-mercenary-spyware-threat-notifications
Apple Notifies Users of Mercenary Spyware Attacks
● Breaking
apple

Apple Notifies Users of Mercenary Spyware Attacks

Apple issued Threat Notifications to iPhone users warning of active mercenary spyware attacks. If you received one, here is what to do immediately.

read →
~/articles/2026-08-14-belgium-eid-browser-extension-rce
Belgium eID Browser Extension Bugs Enable RCE
● Breaking
browser

Belgium eID Browser Extension Bugs Enable RCE

Severe vulnerabilities in Belgium's eID browser extension fully compromised the country's national identity trust framework, researchers confirmed, opening citizen accounts to remote code execution.

read →
~/articles/2026-08-13-legacyhive-windows-zero-day-patch
Microsoft Patches LegacyHive Windows Zero-Day
microsoft

Microsoft Patches LegacyHive Windows Zero-Day

Microsoft issued a patch for LegacyHive, a named Windows zero-day disclosed in the gap between July and August Patch Tuesday cycles.

read →
~/articles/2026-08-13-akira-edr-safe-mode-bypass-data-theft
Akira Disables EDR via Safe Mode Reboot, Steals Data
● Breaking
ransomware

Akira Disables EDR via Safe Mode Reboot, Steals Data

An Akira ransomware affiliate rebooted a compromised host into Safe Mode to kill EDR, exfiltrated data, then failed to encrypt. The exfiltration is the real threat.

read →
~/articles/2026-08-13-vcenter-cve-2026-59310-reverse-ssh-persistence
VMware vCenter Exploit Deploys Reverse SSH Backdoor
● Breaking
vmware

VMware vCenter Exploit Deploys Reverse SSH Backdoor

Threat actors exploiting CVE-2026-59310 are deploying a reverse SSH tool for persistent access on compromised vCenter management planes.

read →