Skip to content
feed: live
>_ 0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-16232
[ CRITICAL ] CVSS 9.1 kev

Check Point SmartConsole improper authentication

CVE-2026-16232 lets unauthenticated attackers grab an admin token from SmartConsole. CISA KEV addition July 22; Check Point confirms active exploitation.

Check Point / SmartConsole
CVE-2021-27137
[ HIGH ] CVSS 8.1 kev

DD-WRT SSDP Stack-Based Buffer Overflow (UPnP)

An unsafe strcpy in DD-WRT's SSDP handling lets an unauthenticated attacker overflow an internal buffer via the UPnP listener and trigger code execution. Added to CISA KEV on 2026-07-21.

DD-WRT / DD-WRT router firmware (builds prior to revision 45724)
CVE-2026-25089
[ CRITICAL ] CVSS 9.8 kev

Fortinet FortiSandbox unauthenticated OS command injection (4.2, 4.4, 5.0, Cloud, PaaS)

An unauthenticated OS command injection across FortiSandbox 4.2, 4.4, 5.0, plus FortiSandbox Cloud and PaaS 5.0 lets a network attacker run arbitrary commands via crafted HTTP requests. CVSS 9.8; CISA-listed KEV.

Fortinet / FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS (multiple 4.x and 5.0 lines — see body)
CVE-2026-46817
[ CRITICAL ] CVSS 9.8 kev

Oracle E-Business Suite Payments improper privilege management (unauth RCE)

A critical improper-privilege-management flaw in the Oracle Payments component of Oracle E-Business Suite (File Transmission) that lets an unauthenticated network attacker take over Oracle Payments. Patched in Oracle's May 2026 Critical Patch Update; added to CISA KEV on July 15, 2026.

Oracle / E-Business Suite — Oracle Payments (versions 12.2.3–12.2.15)
CVE-2026-15409
[ CRITICAL ] CVSS 10.0 kev

SonicWall SMA1000 unauthenticated SSRF in Work Place portal

An unauthenticated server-side request forgery in the SonicWall SMA1000 Work Place web interface lets a remote attacker force the appliance to make requests to attacker-chosen destinations. Actively exploited; on CISA KEV.

SonicWall / SMA1000 Series (6210, 7210, 8200v)
CVE-2026-15410
[ HIGH ] CVSS 7.2 kev

SonicWall SMA1000 post-authentication OS command injection

A post-authentication OS command injection in the SonicWall SMA1000 lets an administrator execute arbitrary OS commands on the appliance. Actively exploited alongside CVE-2026-15409; on CISA KEV.

SonicWall / SMA1000 Series (6210, 7210, 8200v)
$ latest --more

From the desk

all articles →
~/articles/2026-07-25-gitlab-18-11-3-rce-poc-published
GitLab RCE PoC Published: No Admin Rights Required
● Breaking
gitlab

GitLab RCE PoC Published: No Admin Rights Required

A working RCE exploit for self-managed GitLab 18.11.3 is now public. Any authenticated user can execute server commands as git — no admin rights needed.

read →
~/articles/2026-07-25-clop-targets-ptc-windchill-flexplm-data-theft
Clop Hits Windchill and FlexPLM in Data-Theft Push
● Breaking
ptc

Clop Hits Windchill and FlexPLM in Data-Theft Push

Clop is running an active data-theft campaign against internet-exposed PTC Windchill and FlexPLM. No encryption — straight to exfiltration and extortion.

read →
~/articles/2026-07-25-ai-agents-attacker-auditor-attack-surface
AI Agents: Attacker, Auditor, and Attack Surface
Analysis
threat intel

AI Agents: Attacker, Auditor, and Attack Surface

Redis zero-days, an unattended breach, eight NodeBB bugs — AI agents drove security news all week from three different directions. None of this is coincidence.

read →
~/articles/2026-07-25-q2-2026-cvss-epss-patching-gap-talos
200 CVEs a Day: Why CVSS Scores Mislead Defenders
Analysis
threat intel

200 CVEs a Day: Why CVSS Scores Mislead Defenders

Q2 2026 brought ~200 new CVEs daily and 49% year-over-year growth. CISA's KEV grew just 13%. Talos shows why CVSS alone can't be your patch queue.

read →
~/articles/2026-07-24-microsoft-365-outage-maintenance-bug-root-cause
M365 Outage: Automation Bug Pulled Too Many IP Routes
microsoft

M365 Outage: Automation Bug Pulled Too Many IP Routes

Microsoft traced the July 23 M365 outage to a bug in its automated maintenance system that removed IP routes from more network devices than intended, taking down Azure and M365.

read →
~/articles/2026-07-24-snapchat-hacker-illinois-76-months
76 Months for Hacking 750 Women's Snapchat Accounts
threat intel

76 Months for Hacking 750 Women's Snapchat Accounts

An Illinois man received a 76-month federal sentence for compromising over 750 Snapchat accounts to steal intimate photos — one of the larger account-hacking prosecutions in recent memory.

read →