Skip to content
feed: live
>_ 0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-20316
[ MEDIUM ] CVSS 5.3 kev

Hard-coded credential in Cisco Secure FMC enables unauthenticated login

Cisco Secure FMC ships a static low-privileged account; remote unauthenticated attackers can log in and access sensitive data. CISA KEV confirmed July 29, 2026.

Cisco / Cisco Secure Firewall Management Center (FMC)
CVE-2026-16812
[ CRITICAL ] CVSS 10.0 kev

Arista VeloCloud Orchestrator OS Command Injection

CVSS 10.0 critical. Remote attackers can inject OS commands into Arista VeloCloud Orchestrator On-Prem, compromising the SD-WAN management plane.

Arista / VeloCloud Orchestrator On-Prem
CVE-2026-16232
[ CRITICAL ] CVSS 9.1 kev

Check Point SmartConsole improper authentication

CVE-2026-16232 lets unauthenticated attackers grab an admin token from SmartConsole. CISA KEV addition July 22; Check Point confirms active exploitation.

Check Point / SmartConsole
CVE-2021-27137
[ HIGH ] CVSS 8.1 kev

DD-WRT SSDP Stack-Based Buffer Overflow (UPnP)

An unsafe strcpy in DD-WRT's SSDP handling lets an unauthenticated attacker overflow an internal buffer via the UPnP listener and trigger code execution. Added to CISA KEV on 2026-07-21.

DD-WRT / DD-WRT router firmware (builds prior to revision 45724)
CVE-2026-25089
[ CRITICAL ] CVSS 9.8 kev

Fortinet FortiSandbox unauthenticated OS command injection (4.2, 4.4, 5.0, Cloud, PaaS)

An unauthenticated OS command injection across FortiSandbox 4.2, 4.4, 5.0, plus FortiSandbox Cloud and PaaS 5.0 lets a network attacker run arbitrary commands via crafted HTTP requests. CVSS 9.8; CISA-listed KEV.

Fortinet / FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS (multiple 4.x and 5.0 lines — see body)
CVE-2026-46817
[ CRITICAL ] CVSS 9.8 kev

Oracle E-Business Suite Payments improper privilege management (unauth RCE)

A critical improper-privilege-management flaw in the Oracle Payments component of Oracle E-Business Suite (File Transmission) that lets an unauthenticated network attacker take over Oracle Payments. Patched in Oracle's May 2026 Critical Patch Update; added to CISA KEV on July 15, 2026.

Oracle / E-Business Suite — Oracle Payments (versions 12.2.3–12.2.15)
$ latest --more

From the desk

all articles →
~/articles/2026-07-30-void-blizzard-owa-credential-rotation
OWAReaper Backdoor Outlasts Credential Rotation
● Breaking
microsoft

OWAReaper Backdoor Outlasts Credential Rotation

Updated: OWAReaper maintains Exchange mailbox access after credential rotation. Targeted sectors confirmed: US and EU government, telecom, finance, aerospace.

read →
~/articles/2026-07-30-fcc-covered-list-foreign-robots-power-inverters
FCC Bars New Foreign Robots, Power Inverters on Cyber Risk
threat intel

FCC Bars New Foreign Robots, Power Inverters on Cyber Risk

The FCC added foreign-produced mobile robots and networked power inverters to its Covered List on July 28, blocking new models from US equipment authorization.

read →
~/articles/2026-07-30-sapphire-sleet-npm-debug-chalk-north-korea
Amazon Ties Sapphire Sleet to npm debug, chalk Hijack
● Breaking
supply chain

Amazon Ties Sapphire Sleet to npm debug, chalk Hijack

Amazon attributes the September 2025 npm hijack of debug and chalk — over 2 billion combined weekly downloads — to North Korea's Sapphire Sleet APT group.

read →
~/articles/2026-07-30-ir-gap-coordination-not-tools
73% Not Ready: The IR Gap Is Coordination, Not Tools
Analysis
threat intel

73% Not Ready: The IR Gap Is Coordination, Not Tools

New IR readiness research finds most security teams have the plans, tools, and staff — but still lack the coordination and exec alignment that determine whether any of it works under pressure.

read →
~/articles/2026-07-30-claude-mythos-hawk256-aes-cryptanalysis
AI Cracks HAWK-256 Post-Quantum Scheme, Speeds AES
Analysis
threat intel

AI Cracks HAWK-256 Post-Quantum Scheme, Speeds AES

Anthropic's Claude Mythos broke HAWK-256 and found a 200–800x speedup on 7-round AES-128, tightening post-quantum migration timelines.

read →
~/articles/2026-07-29-linux-cve-2026-53264-ai-exploit-root
AI Speeds Linux Kernel Exploit: CVE-2026-53264 Local Root
linux kernel

AI Speeds Linux Kernel Exploit: CVE-2026-53264 Local Root

STAR Labs published a working exploit for CVE-2026-53264 (CVSS 7.8), a use-after-free race in the Linux kernel traffic-control subsystem. AI accelerated discovery and exploit development on CentOS Stream 9.

read →