Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-5430
[ CRITICAL ]CVSS 10.0EPSS 0.4%kev

WSO2 Multiple Products Path Traversal Vulnerability

WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.

WSO2 / Multiple Products
CVE-2026-93616
[ CRITICAL ]CVSS 9.8EPSS 2.4%kev

Check Point Multiple Products Path Traversal Vulnerability

CVE-2026-93616: CVSS 9.8 path traversal and file upload in Check Point Management Server enabling unauth RCE. Confirmed exploited; patches available.

Check Point / Security Management Server, Multi-Domain Management Server, Log Server, SmartEvent
CVE-2026-93952
[ CRITICAL ]CVSS 10.0EPSS 0.9%kev

Arista VeloCloud Orchestrator Unauthenticated RCE

“CVE-2026-93952 is a CVSS 10.0 improper input validation flaw in Arista VeloCloud Orchestrator that allows unauthenticated remote code execution. Added to CISA KEV on September 22, 2026.”

Arista / VeloCloud Orchestrator
CVE-2026-94127
[ CRITICAL ]CVSS 9.8EPSS 1.3%kev

F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

CVSS 9.8 F5 BIG-IP APM heap overflow: unauth RCE when an access policy and OAuth profile share a virtual server. Confirmed exploited; patches available.

F5 / BIG-IP APM
CVE-2026-7273
[ HIGH ]CVSS 8.8EPSS 1.3%kev

Zyxel GS1900 Series Switches Stack-Based Buffer Overflow

Stack-based buffer overflow in Zyxel GS1900 CGI program lets unauthenticated LAN attackers execute OS commands. CVSS 8.8, added to CISA KEV September 21, 2026.

Zyxel / GS1900 Series Switches
CVE-2025-39682
[ CRITICAL ]CVSS 9.8EPSS 2.9%kev

Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

Linux kernel TLS receive path: zero-length record bypasses recvmsg() handling, corrupting downstream TLS processing. CVSS 9.8. In CISA KEV Sept. 18, 2026.

Linux / Kernel
$ latest --more

From the desk

all articles →
~/articles/2026-09-23-d-link-dir-822a-cve-2026-86296-no-patch
D-Link Warns CVSS 10.0 DIR-822A Flaw Has No Fix
d link

D-Link Warns CVSS 10.0 DIR-822A Flaw Has No Fix

CVE-2026-86296: CVSS 10.0 D-Link DIR-822A zero-day with public PoC exploit code and no patch. D-Link says the device is end-of-life and replacement is needed.

read →
~/articles/2026-09-23-check-point-mgmt-cve-2026-93616-kev-rce
Check Point Patches Management Server Zero-Day
● Breaking
check point

Check Point Patches Management Server Zero-Day

CVE-2026-93616: CVSS 9.8 Check Point Management Server flaw allows unauth script execution via path traversal. Added to CISA KEV with a Sept. 25 deadline.

read →
~/articles/2026-09-23-f5-big-ip-apm-cve-2026-94127-kev-rce
F5 Patches BIG-IP APM RCE Zero-Day Under Attack
● Breaking
f5

F5 Patches BIG-IP APM RCE Zero-Day Under Attack

CVSS 9.8 F5 BIG-IP APM heap overflow: unauth RCE when an access policy and OAuth profile share a virtual server. Confirmed exploited; patches available.

read →
~/articles/2026-09-23-shinyhunters-fbi-breach-peoplesoft-zero-day
ShinyHunters Claims FBI Breach via PeopleSoft Zero-Day
● Breaking
ransomware

ShinyHunters Claims FBI Breach via PeopleSoft Zero-Day

ShinyHunters claims it breached FBI systems via an unpatched Oracle PeopleSoft zero-day, exfiltrating employee data. FBI and Oracle have not confirmed.

read →
~/articles/2026-09-23-arista-velocloud-cve-2026-93952-cvss10-kev
Arista VeloCloud CVSS 10.0 Flaw Added to CISA KEV
● Breaking
arista

Arista VeloCloud CVSS 10.0 Flaw Added to CISA KEV

CISA added CVE-2026-93952, a CVSS 10.0 unauthenticated RCE flaw in Arista VeloCloud Orchestrator, to its KEV catalog September 22. Federal agencies have until September 25 to patch.

read →
~/articles/2026-09-22-windows-defender-bigdiskbuster-naceri-zero-day
New Windows Defender Zero-Day Blocks AV Updates
microsoft

New Windows Defender Zero-Day Blocks AV Updates

Naceri released BigDiskBuster, a zero-day PoC that blocks Windows Defender from updating on all supported Windows. No patch and no CVE assigned.

read →