0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Check Point SmartConsole improper authentication
CVE-2026-16232 lets unauthenticated attackers grab an admin token from SmartConsole. CISA KEV addition July 22; Check Point confirms active exploitation.
DD-WRT SSDP Stack-Based Buffer Overflow (UPnP)
An unsafe strcpy in DD-WRT's SSDP handling lets an unauthenticated attacker overflow an internal buffer via the UPnP listener and trigger code execution. Added to CISA KEV on 2026-07-21.
Fortinet FortiSandbox unauthenticated OS command injection (4.2, 4.4, 5.0, Cloud, PaaS)
An unauthenticated OS command injection across FortiSandbox 4.2, 4.4, 5.0, plus FortiSandbox Cloud and PaaS 5.0 lets a network attacker run arbitrary commands via crafted HTTP requests. CVSS 9.8; CISA-listed KEV.
Oracle E-Business Suite Payments improper privilege management (unauth RCE)
A critical improper-privilege-management flaw in the Oracle Payments component of Oracle E-Business Suite (File Transmission) that lets an unauthenticated network attacker take over Oracle Payments. Patched in Oracle's May 2026 Critical Patch Update; added to CISA KEV on July 15, 2026.
SonicWall SMA1000 unauthenticated SSRF in Work Place portal
An unauthenticated server-side request forgery in the SonicWall SMA1000 Work Place web interface lets a remote attacker force the appliance to make requests to attacker-chosen destinations. Actively exploited; on CISA KEV.
SonicWall SMA1000 post-authentication OS command injection
A post-authentication OS command injection in the SonicWall SMA1000 lets an administrator execute arbitrary OS commands on the appliance. Actively exploited alongside CVE-2026-15409; on CISA KEV.
From the desk

GitLab RCE PoC Published: No Admin Rights Required
A working RCE exploit for self-managed GitLab 18.11.3 is now public. Any authenticated user can execute server commands as git — no admin rights needed.

Clop Hits Windchill and FlexPLM in Data-Theft Push
Clop is running an active data-theft campaign against internet-exposed PTC Windchill and FlexPLM. No encryption — straight to exfiltration and extortion.

AI Agents: Attacker, Auditor, and Attack Surface
Redis zero-days, an unattended breach, eight NodeBB bugs — AI agents drove security news all week from three different directions. None of this is coincidence.

200 CVEs a Day: Why CVSS Scores Mislead Defenders
Q2 2026 brought ~200 new CVEs daily and 49% year-over-year growth. CISA's KEV grew just 13%. Talos shows why CVSS alone can't be your patch queue.

M365 Outage: Automation Bug Pulled Too Many IP Routes
Microsoft traced the July 23 M365 outage to a bug in its automated maintenance system that removed IP routes from more network devices than intended, taking down Azure and M365.

76 Months for Hacking 750 Women's Snapchat Accounts
An Illinois man received a 76-month federal sentence for compromising over 750 Snapchat accounts to steal intimate photos — one of the larger account-hacking prosecutions in recent memory.




