0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Cisco ASA and FTD VPN Heap Inspection Denial-of-Service Flaw
Unauthenticated remote attackers can crash Cisco Secure Firewall ASA and FTD devices over VPN. Added to CISA KEV on 2026-08-11 with a three-day federal remediation deadline.
Windows AFD WinSock Use-After-Free Privilege Escalation
Use-after-free in Windows Ancillary Function Driver for WinSock (afd.sys) lets local attackers gain SYSTEM privileges via race condition. Actively exploited by Lazarus.
Metabase SQL Injection Vulnerability
Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.
IBM Langflow Code Injection Vulnerability
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
From the desk

AmnesiaStealer Hijacks macOS Browser Sessions
Jamf found a new macOS infostealer that hijacks Chrome in headless mode, giving attackers live remote control of authenticated browser sessions via ClickFix lures.

Critical Flaws in Pods, Link Library Hit WordPress Sites
Pods (CVSS 9.8) and Link Library (CVSS 9.1) expose WordPress sites to unauthenticated privilege escalation and arbitrary file deletion with RCE potential.

SiYuan v3.7.4 Patches 11 CVEs, Critical RCE Confirmed
SiYuan v3.7.4 patches eleven CVEs including critical Electron XSS-to-RCE chains and a CVSS 9.8 auth bypass. Desktop users should update immediately.

Threema Hit by Large-Scale DDoS, Service Disrupted
Multiple large-scale DDoS attacks disrupted Threema's secure messaging service this week. No message content breach — availability impact only.

August Kernel Drop: The Enterprise CVEs Nobody Wrote About
Thirty-plus kernel CVEs hit NVD on August 15. Three affecting ThunderboltIP, NVMe-oF auth, and TPM matter to enterprise infrastructure and flew under radar.

Linux Kernel Patches WiFi Heap Overflow, BPF Bypass
August 15 kernel stable drop fixes a Broadcom WiFi heap overflow triggerable by a rogue AP, a BPF verifier bypass, and 28 other security fixes.




