0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Check Point Multiple Products Path Traversal Vulnerability
CVE-2026-93616: CVSS 9.8 path traversal and file upload in Check Point Management Server enabling unauth RCE. Confirmed exploited; patches available.
Arista VeloCloud Orchestrator Unauthenticated RCE
“CVE-2026-93952 is a CVSS 10.0 improper input validation flaw in Arista VeloCloud Orchestrator that allows unauthenticated remote code execution. Added to CISA KEV on September 22, 2026.”
F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
CVSS 9.8 F5 BIG-IP APM heap overflow: unauth RCE when an access policy and OAuth profile share a virtual server. Confirmed exploited; patches available.
Zyxel GS1900 Series Switches Stack-Based Buffer Overflow
Stack-based buffer overflow in Zyxel GS1900 CGI program lets unauthenticated LAN attackers execute OS commands. CVSS 8.8, added to CISA KEV September 21, 2026.
Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
Linux kernel TLS receive path: zero-length record bypasses recvmsg() handling, corrupting downstream TLS processing. CVSS 9.8. In CISA KEV Sept. 18, 2026.
Linux Kernel Race Condition Vulnerability
Linux kernel AF_ALG race condition: concurrent writes corrupt state, crashing the system or corrupting cryptographic output. CVSS 7.8. CISA KEV Sept. 18.
From the desk

New Windows Defender Zero-Day Blocks AV Updates
Naceri released BigDiskBuster, a zero-day PoC that blocks Windows Defender from updating on all supported Windows. No patch and no CVE assigned.

WordPress Core XSS Flaw Enables RCE via Admin Sessions
Stored XSS in WordPress core lets anonymous visitors plant scripts in comments. An admin viewing the page can trigger remote code execution.

Zyxel, Veeam Flaws Confirmed Under Active Exploitation
CISA added Zyxel GS1900 CVE-2026-7273 to its KEV catalog September 21. Veeam Agent CVE-2026-32996 also actively exploited. Patches available for both.

ShinyHunters Extorts Cl0p, Victim Data at Risk
ShinyHunters set an eight-figure ransom demand against Cl0p and threatened to publish records identifying companies that paid the ransomware gang.

BigCommerce Merchants Breached via Ribon App Credentials
Attackers compromised API keys for third-party Ribon loyalty apps and used them to inject scripts into BigCommerce storefronts, exposing customer contact data from Sept 13-17.

CrowdSec Source Code Stolen in TanStack Attack
CrowdSec confirmed its source code was stolen, attributing the breach to the May 2026 TanStack JavaScript supply chain compromise. No vulnerability disclosed yet.
This week's SITREP
Sep 22: Cl0p Extorted, CrowdSec Source Code, BigCommerce
ShinyHunters escalates against Cl0p with an eight-figure demand and threatens to expose ransom-payer records. CrowdSec confirms source code theft. BigCommerce merchants hit via Ribon apps.




