Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-85046
[ HIGH ]CVSS 8.8EPSS 1.2%kev

Type confusion in Chrome V8 allows sandbox code execution

Type confusion in Chrome's V8 engine lets remote attackers run arbitrary code inside the browser sandbox via a crafted HTML page. Actively exploited; update to 152.0.7977.82.

Google / Chrome (before 152.0.7977.82)
CVE-2026-48710
[ MEDIUM ]CVSS 6.5EPSS 36.3%kev

Kludex Starlette HTTP Request/Response Smuggling Vulnerability

Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.

Kludex / Starlette
CVE-2026-49869
[ CRITICAL ]CVSS 10.0EPSS 1.9%kev

Kestra OSS OS Command Injection Vulnerability

Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.

Kestra / Kestra OSS
CVE-2026-59822
[ HIGH ]CVSS 8.2EPSS 0.9%kev

BerriAI LiteLLM Improper Authentication Vulnerability

BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.

BerriAI / LiteLLM
CVE-2026-9586
[ HIGH ]EPSS 11.8%kev

Sangoma Switchvox SQL Injection Vulnerability

Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

Sangoma / Switchvox
CVE-2026-83548
[ HIGH ]EPSS 0.7%kev

Pre-auth SSRF in SonicWall SMA1000 Workplace Interface

Unauthenticated SSRF in the SMA1000 Workplace interface allows remote attackers to reach internal functionality via an unintended access path. Exploited in the wild; chains with CVE-2026-83549 for RCE.

SonicWall / SMA1000
$ latest --more

From the desk

all articles →
~/articles/2026-09-07-n-central-cve-2026-86218-exploitation-confirmed
N-central Under Active Attack: Patch CVE-2026-86218 Now
● Breaking
supply chain

N-central Under Active Attack: Patch CVE-2026-86218 Now

BleepingComputer reports N-central servers under active attack one day after N-able's CVSS 10.0 pre-auth RCE disclosure. Update to version 2026.3.1.14 immediately.

read →
~/articles/2026-09-07-frontend-admin-wordpress-cve-2026-75816-auth-bypass
Frontend Admin Plugin Flaw Allows WordPress Account Takeover
wordpress

Frontend Admin Plugin Flaw Allows WordPress Account Takeover

CVE-2026-75816, scored CVSS 9.8, is an authentication bypass in the Frontend Admin by DynamiApps plugin that allows unauthenticated takeover of any WordPress account on affected sites.

read →
~/articles/2026-09-07-mikrotik-ssh-auth-bypass-exploited
MikroTik Patches Exploited SSH Auth Bypass
● Breaking
mikrotik

MikroTik Patches Exploited SSH Auth Bypass

CERT Polska confirmed active attacks hijacking MikroTik routers via SSH without credentials. Patch RouterOS to 6.49.21, 7.23.4, or 7.24.2 immediately.

read →
~/articles/2026-09-06-autoagent-cve-2026-86124-unauthenticated-root-rce
AutoAgent Critical Flaw: Root RCE via Unauthenticated TCP
● Breaking
ai tools

AutoAgent Critical Flaw: Root RCE via Unauthenticated TCP

AutoAgent's TCP server binds to all interfaces and runs commands without authentication, giving remote attackers root access on any exposed installation.

read →
~/articles/2026-09-06-vmware-workstation-fusion-critical-rce
Broadcom Patches Critical RCE in VMware Workstation, Fusion
● Breaking
vmware

Broadcom Patches Critical RCE in VMware Workstation, Fusion

Broadcom patched two vulnerabilities in VMware Workstation and Fusion, including a critical flaw that lets a VM administrator execute code on the host system.

read →
~/articles/2026-09-06-n-central-cve-2026-86218-preauth-rce
N-able Patches CVSS 10 Pre-Auth RCE in N-central
supply chain

N-able Patches CVSS 10 Pre-Auth RCE in N-central

N-able's N-central RMM platform has a pre-authentication remote code execution flaw, CVSS 4.0: 10.0, affecting all versions before 2026.3.1.14. Patch immediately.

read →