Skip to content
feed: live
>_ 0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-16232
[ CRITICAL ] CVSS 9.1 kev

Check Point SmartConsole improper authentication

CVE-2026-16232 lets unauthenticated attackers grab an admin token from SmartConsole. CISA KEV addition July 22; Check Point confirms active exploitation.

Check Point / SmartConsole
CVE-2021-27137
[ HIGH ] CVSS 8.1 kev

DD-WRT SSDP Stack-Based Buffer Overflow (UPnP)

An unsafe strcpy in DD-WRT's SSDP handling lets an unauthenticated attacker overflow an internal buffer via the UPnP listener and trigger code execution. Added to CISA KEV on 2026-07-21.

DD-WRT / DD-WRT router firmware (builds prior to revision 45724)
CVE-2026-25089
[ CRITICAL ] CVSS 9.8 kev

Fortinet FortiSandbox unauthenticated OS command injection (4.2, 4.4, 5.0, Cloud, PaaS)

An unauthenticated OS command injection across FortiSandbox 4.2, 4.4, 5.0, plus FortiSandbox Cloud and PaaS 5.0 lets a network attacker run arbitrary commands via crafted HTTP requests. CVSS 9.8; CISA-listed KEV.

Fortinet / FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS (multiple 4.x and 5.0 lines — see body)
CVE-2026-46817
[ CRITICAL ] CVSS 9.8 kev

Oracle E-Business Suite Payments improper privilege management (unauth RCE)

A critical improper-privilege-management flaw in the Oracle Payments component of Oracle E-Business Suite (File Transmission) that lets an unauthenticated network attacker take over Oracle Payments. Patched in Oracle's May 2026 Critical Patch Update; added to CISA KEV on July 15, 2026.

Oracle / E-Business Suite — Oracle Payments (versions 12.2.3–12.2.15)
CVE-2026-15409
[ CRITICAL ] CVSS 10.0 kev

SonicWall SMA1000 unauthenticated SSRF in Work Place portal

An unauthenticated server-side request forgery in the SonicWall SMA1000 Work Place web interface lets a remote attacker force the appliance to make requests to attacker-chosen destinations. Actively exploited; on CISA KEV.

SonicWall / SMA1000 Series (6210, 7210, 8200v)
CVE-2026-15410
[ HIGH ] CVSS 7.2 kev

SonicWall SMA1000 post-authentication OS command injection

A post-authentication OS command injection in the SonicWall SMA1000 lets an administrator execute arbitrary OS commands on the appliance. Actively exploited alongside CVE-2026-15409; on CISA KEV.

SonicWall / SMA1000 Series (6210, 7210, 8200v)
$ latest --more

From the desk

all articles →
~/articles/2026-07-23-fedramp-20x-rev5-transition-continuous-monitoring-loop
FedRAMP 20x Ends Point-in-Time Authorization
cloud

FedRAMP 20x Ends Point-in-Time Authorization

FedRAMP 20x moves federal cloud authorization from periodic 3PAO assessments to continuous, machine-readable control evidence — what that shift requires from cloud operators.

read →
~/articles/2026-07-23-github-actions-packagist-cpanel-whm-supply-chain
Attackers Weaponize GitHub Actions Against cPanel Hosts
supply chain

Attackers Weaponize GitHub Actions Against cPanel Hosts

Ten malicious Packagist packages turned GitHub Actions runners into attack infrastructure targeting cPanel and WHM hosting control panels.

read →
~/articles/2026-07-23-refluxfs-cve-2026-64600-linux-kernel-lpe-rhel
RefluXFS LPE Hits Default RHEL, Fedora, Amazon Linux
linux kernel

RefluXFS LPE Hits Default RHEL, Fedora, Amazon Linux

Nine-year-old XFS race condition in the Linux kernel lets an unprivileged local user gain root on default RHEL, Fedora Server, and Amazon Linux.

read →
~/articles/2026-07-23-chaos-ransomware-msarat-browser-c2-webrtc-airgap
Chaos Ransomware's msaRAT Hides C2 in Browser Traffic
● Breaking
ransomware

Chaos Ransomware's msaRAT Hides C2 in Browser Traffic

The Chaos group's new msaRAT backdoor routes C2 through Chrome or Edge via WebRTC TURN relay, hiding attacker infrastructure behind the browser process.

read →
~/articles/2026-07-23-exchange-online-mailbox-quarantine-error-airgap
Exchange Online Quarantining Mailboxes in Error Since Sunday
● Breaking
microsoft

Exchange Online Quarantining Mailboxes in Error Since Sunday

Microsoft is investigating an Exchange Online incident that has incorrectly quarantined customer mailboxes since July 20. No ETA on resolution as of July 23.

read →
~/articles/2026-07-23-eclypsium-infratrust-pulse-firmware-patch-priority
Eclypsium Launches InfraTrust for Firmware Patch Priority
threat intel

Eclypsium Launches InfraTrust for Firmware Patch Priority

Eclypsium's new InfraTrust knowledge base and monthly Pulse report gives network teams a prioritized view of firmware and edge-device vulnerabilities.

read →