0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Microsoft SharePoint Code Injection Vulnerability
A code injection flaw in Microsoft Office SharePoint lets an authorized attacker execute code over a network. CVSS 8.8 (high), active exploitation confirmed, CISA KEV deadline September 28, 2026.
Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.
WSO2 Multiple Products Path Traversal to RCE
WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway contain a path traversal flaw enabling unauthenticated file upload and remote code execution. CVSS 10.0. Actively exploited since September 13, 2026; added to CISA KEV September 24.
WordPress core get_page_template path traversal enables unauthenticated RCE
Path traversal in WordPress core's get_page_template() enables unauthenticated local PHP file inclusion and conditional RCE. Actively exploited within 24 hours of disclosure. CVSS 8.1 High.
Check Point Multiple Products Path Traversal Vulnerability
CVE-2026-93616: CVSS 9.8 path traversal and file upload in Check Point Management Server enabling unauth RCE. Confirmed exploited; patches available.
Arista VeloCloud Orchestrator Unauthenticated RCE
“CVE-2026-93952 is a CVSS 10.0 improper input validation flaw in Arista VeloCloud Orchestrator that allows unauthenticated remote code execution. Added to CISA KEV on September 22, 2026.”
From the desk

Elementor CSRF Flaw Lets Attackers Create Admin Accounts
A CSRF flaw in the Elementor WordPress plugin lets attackers create administrator accounts without valid credentials. Site owners should update the plugin immediately.

CISA Adds MikroTik RouterOS Chain Flaw to KEV Catalog
CISA added CVE-2026-67279 to KEV on September 25. The medium-severity flaw chains with CVE-2026-86060 to enable full unauthenticated exploitation of MikroTik RouterOS. Federal deadline is September 28.

Kiteworks Flags Potential Zero-Day, Urges Server Shutdown
Kiteworks warned customers Thursday of potential zero-day attack activity and asked them to take servers offline for a six-hour window on Saturday, September 26.

Clop Moves Leak Site After Grav CMS Attack Confirmed
Clop ransomware confirmed its Tor leak site was breached via an unpatched Grav CMS path traversal flaw. The group has migrated to a new Tor address.

U.S. Soldier Gets 70 Months for Telecom Extortion
A U.S. Army soldier sentenced to 70 months for hacking AT&T and Verizon and extorting the carriers using 100 million customers' stolen call and text metadata.

Suspected DPRK Hackers Steal $351.6M from Bitget
Bitget says suspected North Korean actors stole $351.6 million from hot and warm wallets in a backend compromise detected at 18:31 UTC on September 24.
This week's SITREP
Sep 22: Cl0p Extorted, CrowdSec Source Code, BigCommerce
ShinyHunters escalates against Cl0p with an eight-figure demand and threatens to expose ransom-payer records. CrowdSec confirms source code theft. BigCommerce merchants hit via Ribon apps.




