0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Zammad GmbH Zammad Session Fixation Vulnerability
Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.
Zammad GmbH Zammad Improper Privilege Management Vulnerability
Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.
Fortinet FortiMail Path Traversal and NULL Byte Flaw
Fortinet FortiMail path traversal flaw (CVSS 9.8) lets unauthenticated attackers write arbitrary files. Actively exploited; CISA KEV listed October 1, 2026.
Cisco Catalyst SD-WAN Manager Authentication Bypass
Unauthenticated attackers can gain admin access to Cisco Catalyst SD-WAN Manager via a URI encoding flaw. CVSS 9.8, actively exploited, CISA KEV listed.
CoreGraphics memory confusion in Apple iOS 26, iPadOS, macOS 26, macOS 15
CoreGraphics memory confusion flaw in Apple iOS 26, iPadOS, macOS 26, and macOS 15. CVSS 8.8 high. Apple reports possible exploitation in targeted attacks.
Citrix NetScaler ADC/Gateway Unauthenticated RCE via Input Validation Flaw
Citrix NetScaler ADC and Gateway improper input validation flaw allows unauthenticated remote code execution; actively exploited and CISA KEV listed.
From the desk

Pentagon DMDC Breach Hits 3 Million Personnel Files
The Pentagon's DMDC is notifying over 3 million service members after attackers breached its HR management system and stole personnel records.

Bitget Confirms Zero-Day Behind $387.5M Crypto Theft
Bitget says the $387.5 million theft last week came from a zero-day in an unnamed third-party security product. The CVE and vendor remain undisclosed as the investigation continues.

Apple CoreGraphics PoC Released, KEV Deadline Oct 2
A public PoC for CVE-2026-86950 is available as of October 1. CISA's patch deadline for federal agencies is October 2. Affected: iOS 26, iPadOS, macOS 26, macOS 15.

Git Hash Chain Malleability: The Supply Chain Risk
SHA-1 is still the default in most Git repositories. Here is what hash chain malleability means, what it puts at risk, and how to close the gap.

DIVD Breached via Zammad Zero-Day Chain
The Dutch Institute for Vulnerability Disclosure confirms attackers exploited two unpatched Zammad zero-days to breach its internal network. No CVE IDs assigned yet.

Cisco SD-WAN Manager Auth Bypass Exploited: Patch Now
CVE-2026-76504, an authentication bypass in Cisco SD-WAN Manager rated CVSS 9.8, is under active exploitation. Federal agencies must patch by October 3.




