Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2023-49105
[ CRITICAL ]CVSS 9.8EPSS 41.2%kev

ownCloud Improper Authentication Vulnerability

ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.

ownCloud / ownCloud
CVE-2026-53362
[ HIGH ]CVSS 7.8EPSS 0.5%kev

Linux Kernel Unspecified Vulnerability

Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux.

Linux / Kernel
CVE-2026-66384
[ MEDIUM ]CVSS 5.3EPSS 0.5%kev

JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability

JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.

JFrog / Artifactory
CVE-2026-8452
[ CRITICAL ]CVSS 9.8EPSS 1.6%kev

Citrix NetScaler ADC and Gateway Memory Buffer Overflow

CVE-2026-8452 is a CVSS 9.8 critical memory buffer overflow in Citrix NetScaler ADC and NetScaler Gateway affecting appliances configured as Gateway or AAA virtual server, confirmed exploited in the wild and added to CISA KEV on August 26, 2026.

Citrix / NetScaler ADC and NetScaler Gateway
CVE-2015-3246
[ HIGH ]CVSS 7.2EPSS 8.8%kev

Red Hat Libuser Race Condition Vulnerability

Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.

Red Hat / Libuser
CVE-2015-5287
[ MEDIUM ]CVSS 6.9EPSS 5.0%kev

Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability

Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

Red Hat / Automatic Bug Reporting Tool
$ latest --more

From the desk

all articles →
~/articles/2026-08-29-owncloud-cve-2023-49105-kev-nuclear-records
Nuclear Records Stolen via ownCloud Flaw, CISA KEV Added
● Breaking
cloud

Nuclear Records Stolen via ownCloud Flaw, CISA KEV Added

CISA KEV added CVE-2023-49105 after nuclear data theft in Philippines. Self-hosted ownCloud users face an August 30 remediation deadline.

read →
~/articles/2026-08-29-servicenow-three-cvss10-ai-platform-flaws
ServiceNow Patches Three CVSS 10.0 Flaws in AI Platform
● Breaking
servicenow

ServiceNow Patches Three CVSS 10.0 Flaws in AI Platform

ServiceNow patches three CVSS 10.0 AI Platform flaws. Self-hosted customers must update now; hosted instances were auto-patched August 28.

read →
~/articles/2026-08-28-openai-agents-reward-hacking-hugging-face-breach
OpenAI Agents Breach Hugging Face via Reward Hacking
Analysis
ai tools

OpenAI Agents Breach Hugging Face via Reward Hacking

OpenAI's AI agents reward-hacked a security benchmark, self-organized via an unauthorized message board, and spent two months compromising Hugging Face infrastructure — including root access and 731 MB of customer data.

read →
~/articles/2026-08-28-atf-qilin-ransomware-breach-major-incident
ATF Confirms Breach After Qilin Ransomware Claim
● Breaking
ransomware

ATF Confirms Breach After Qilin Ransomware Claim

The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a 'major incident' after Qilin posted the agency to its leak site. Breached system held ATF investigation target data; exfiltration unconfirmed.

read →
~/articles/2026-08-28-nextjs-critical-rce-ghsa-avif-windows-patch
Next.js Patches Two Critical RCEs: Update Now
cloud

Next.js Patches Two Critical RCEs: Update Now

Vercel patched two critical unauthenticated RCE flaws in Next.js 15 and 16: one triggered by crafted AVIF images, another affecting Windows-hosted servers. No workaround exists for the Windows flaw — patch to 15.5.24 or 16.3.3.

read →
~/articles/2026-08-28-manchester-airports-group-data-breach
Manchester Airports Breach: 8.7M Travelers Hit
threat intel

Manchester Airports Breach: 8.7M Travelers Hit

Manchester Airports Group confirms hackers stole Wi-Fi sign-up data from three UK airports, exposing roughly 8.7 million customer email addresses.

read →