Skip to content
feed: live
>_ 0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-16232
[ CRITICAL ] CVSS 9.1 kev

Check Point SmartConsole improper authentication

CVE-2026-16232 lets unauthenticated attackers grab an admin token from SmartConsole. CISA KEV addition July 22; Check Point confirms active exploitation.

Check Point / SmartConsole
CVE-2021-27137
[ HIGH ] CVSS 8.1 kev

DD-WRT SSDP Stack-Based Buffer Overflow (UPnP)

An unsafe strcpy in DD-WRT's SSDP handling lets an unauthenticated attacker overflow an internal buffer via the UPnP listener and trigger code execution. Added to CISA KEV on 2026-07-21.

DD-WRT / DD-WRT router firmware (builds prior to revision 45724)
CVE-2026-25089
[ CRITICAL ] CVSS 9.8 kev

Fortinet FortiSandbox unauthenticated OS command injection (4.2, 4.4, 5.0, Cloud, PaaS)

An unauthenticated OS command injection across FortiSandbox 4.2, 4.4, 5.0, plus FortiSandbox Cloud and PaaS 5.0 lets a network attacker run arbitrary commands via crafted HTTP requests. CVSS 9.8; CISA-listed KEV.

Fortinet / FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS (multiple 4.x and 5.0 lines — see body)
CVE-2026-46817
[ CRITICAL ] CVSS 9.8 kev

Oracle E-Business Suite Payments improper privilege management (unauth RCE)

A critical improper-privilege-management flaw in the Oracle Payments component of Oracle E-Business Suite (File Transmission) that lets an unauthenticated network attacker take over Oracle Payments. Patched in Oracle's May 2026 Critical Patch Update; added to CISA KEV on July 15, 2026.

Oracle / E-Business Suite — Oracle Payments (versions 12.2.3–12.2.15)
CVE-2026-15409
[ CRITICAL ] CVSS 10.0 kev

SonicWall SMA1000 unauthenticated SSRF in Work Place portal

An unauthenticated server-side request forgery in the SonicWall SMA1000 Work Place web interface lets a remote attacker force the appliance to make requests to attacker-chosen destinations. Actively exploited; on CISA KEV.

SonicWall / SMA1000 Series (6210, 7210, 8200v)
CVE-2026-15410
[ HIGH ] CVSS 7.2 kev

SonicWall SMA1000 post-authentication OS command injection

A post-authentication OS command injection in the SonicWall SMA1000 lets an administrator execute arbitrary OS commands on the appliance. Actively exploited alongside CVE-2026-15409; on CISA KEV.

SonicWall / SMA1000 Series (6210, 7210, 8200v)
$ latest --more

From the desk

all articles →
~/articles/2026-07-27-cruciferra-crypter-byovd-process-ghosting-india-tax
Cruciferra Crypter: BYOVD and Process Ghosting on the Market
Analysis
threat intel

Cruciferra Crypter: BYOVD and Process Ghosting on the Market

Proofpoint's analysis of Cruciferra shows a crypter-as-a-service bundling BYOVD and Process Ghosting — now serving multiple unrelated threat clusters.

read →
~/articles/2026-07-27-github-pypi-dependabot-cooldown-supply-chain
Dependabot Gets 3-Day Cooldown to Block Package Poisoning
supply chain

Dependabot Gets 3-Day Cooldown to Block Package Poisoning

GitHub's Dependabot now waits three days before auto-updating packages. PyPI adds parallel controls. Here's what to configure in your pipeline.

read →
~/articles/2026-07-27-teleshim-east-asia-apt-telegram-c2-middle-east
TELESHIM Uses Telegram C2 Against Middle East Governments
● Breaking
threat intel

TELESHIM Uses Telegram C2 Against Middle East Governments

Zscaler ThreatLabz flags three new malware families targeting Middle East government entities. The C2 channel: Telegram. Attribution: East Asia-linked.

read →
~/articles/2026-07-27-steam-forum-clickfix-xmrig-cryptominer
Steam Forums Used to Deliver XMRig via ClickFix
threat intel

Steam Forums Used to Deliver XMRig via ClickFix

Steam game forums are being seeded with fake troubleshooting posts that use ClickFix to deliver XMRig cryptomining malware on unsuspecting players.

read →
~/articles/2026-07-26-insurance-phishing-realtime-aitm-account-hijacking
Insurance Phishing Moves to Real-Time Account Hijacking
Analysis
threat intel

Insurance Phishing Moves to Real-Time Account Hijacking

CTM360 finds insurance phishing has upgraded from credential harvesting to real-time session hijacking — MFA alone isn't enough anymore.

read →
~/articles/2026-07-26-github-pypi-dependabot-time-based-supply-chain-defenses
GitHub, PyPI Add Time-Gated Supply Chain Defenses
supply chain

GitHub, PyPI Add Time-Gated Supply Chain Defenses

GitHub adds a 72-hour Dependabot cooldown on new package versions; PyPI blocks release updates after 14 days. Both changes buy detection time before malicious code spreads.

read →