0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.
IBM Langflow Code Injection Vulnerability
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.
Hard-coded credential in Cisco Secure FMC enables unauthenticated login
Cisco Secure FMC ships a static low-privileged account; remote unauthenticated attackers can log in and access sensitive data. CISA KEV confirmed July 29, 2026.
Microsoft MSHTML security feature bypass
Protection mechanism failure in Microsoft MSHTML lets unauthenticated attackers bypass a security feature over the network. CVSS 8.8, patched in Microsoft's February 2026 Patch Tuesday.
From the desk

84 Flaws Found in Open-Source 4G and 5G Cores
Researchers at NTU Singapore found 84 flaws in open-source 4G/5G core software, enabling DoS and session hijacking via GTP-C and PFCP protocol weaknesses.

Coldcard Firmware Bug Behind $70M Bitcoin Theft
A 2021 Coldcard firmware error routed seed generation to a software PRNG. On July 30, an attacker swept 1,196 addresses in 41 minutes and took ~$70.2M in BTC.

Device Code Phishing Reaches Industrial Scale
OAuth device authorization flow abuse has scaled from red-team niche to industrial-scale enterprise credential theft in under six months, per threat researchers.

Adobe Patches Max-Severity RCE in Campaign Classic
Adobe patched CVE-2026-48449, a CVSS 10.0 incorrect authorization flaw in Campaign Classic that enables remote code execution without user interaction.

Midnight Blizzard Uses Hotel Wi-Fi to Deploy CornFlake RAT
Microsoft attributes CaptiveCrunch to Storm-2945, a Midnight Blizzard sub-cluster delivering CornFlake RAT via fake browser updates on hijacked hotel Wi-Fi.

HollowFrame and Matryoshka: Backdoor Chain Targets Law Firm
Blackpoint Cyber documents HollowFrame, a Go-based loader, and Matryoshka, a Rust backdoor, deployed against a law firm via spear-phishing and an encrypted LNK archive.




