0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Citrix NetScaler ADC/Gateway Unauthenticated RCE via Input Validation Flaw
Citrix NetScaler ADC and Gateway improper input validation flaw allows unauthenticated remote code execution; actively exploited and CISA KEV listed.
Citrix NetScaler ADC/Gateway RCE via Memory Buffer Mishandling
Citrix NetScaler ADC and Gateway memory buffer flaw allows remote code execution or denial of service; actively exploited and CISA KEV listed.
Microsoft SharePoint Code Injection Vulnerability
A code injection flaw in Microsoft Office SharePoint lets an authorized attacker execute code over a network. CVSS 8.8 (high), active exploitation confirmed, CISA KEV deadline September 28, 2026.
Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.
WSO2 Multiple Products Path Traversal to RCE
WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway contain a path traversal flaw enabling unauthenticated file upload and remote code execution. CVSS 10.0. Actively exploited since September 13, 2026; added to CISA KEV September 24.
WordPress core get_page_template path traversal enables unauthenticated RCE
Path traversal in WordPress core's get_page_template() enables unauthenticated local PHP file inclusion and conditional RCE. Actively exploited within 24 hours of disclosure. CVSS 8.1 High.
From the desk

Budibase 3.45.0 Fixes Six Security Flaws
Budibase 3.45.0 patches six CVEs including arbitrary file write (CVSS 8.8), SSO auth bypass (8.1), and SQL injection (8.0). Update now if Builder is exposed.

Citrix NetScaler: Two Unpatched RCEs Actively Exploited
Two unpatched RCEs in Citrix NetScaler ADC and Gateway are actively exploited in the wild. CVE IDs are pending assignment; Citrix expects patches by end of September 2026.

Critical File Upload Bug in WooCommerce Quote Plugin
CVE-2026-18143 is a CVSS 9.8 arbitrary file upload flaw in the Request a Quote for WooCommerce plugin through version 2.9.2. Update to 2.9.3.

SharePoint Code Injection CVE-2026-65660 Added to KEV
CISA added a SharePoint code injection flaw to its KEV catalog on September 25. CVSS 8.8, active exploitation confirmed, federal patch deadline September 28.

ShinyHunters WAF Bypass Keeps PeopleSoft Attacks Alive
ShinyHunters uses URL encoding to bypass WAF rules protecting against Oracle PeopleSoft CVE-2026-35273, continuing to deploy web shells on servers organizations thought were protected.

Elementor CSRF Flaw Lets Attackers Create Admin Accounts
A CSRF flaw in the Elementor WordPress plugin lets attackers create administrator accounts without valid credentials. Site owners should update the plugin immediately.
This week's SITREP
Sep 22: Cl0p Extorted, CrowdSec Source Code, BigCommerce
ShinyHunters escalates against Cl0p with an eight-figure demand and threatens to expose ransom-payer records. CrowdSec confirms source code theft. BigCommerce merchants hit via Ribon apps.




