Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-76461
[ CRITICAL ]CVSS 9.8kev

Cisco Secure Email Gateway SQL Injection Vulnerability

SQL injection in Cisco AsyncOS for Secure Email Gateway lets an unauthenticated remote attacker execute arbitrary OS commands with root privileges. CISA KEV since Sept. 14.

Cisco / Secure Email Gateway
CVE-2026-42016
[ HIGH ]CVSS 8.1EPSS 0.9%kev

JFrog Artifactory Incorrect Authorization Vulnerability

JFrog Artifactory validates token signature and issuer but not scope, creating a privilege escalation path. CVSS 8.1 (high), CISA KEV deadline September 25, 2026.

JFrog / Artifactory
CVE-2026-42018
[ HIGH ]CVSS 7.5EPSS 0.9%kev

JFrog Artifactory Improper Authentication Vulnerability

JFrog Artifactory returns an internal anonymous-user token to unauthenticated callers even when anonymous access is disabled, allowing unauthorized resource access and enabling privilege escalation chains.

JFrog / Artifactory
CVE-2026-84869
[ CRITICAL ]CVSS 9.9EPSS 0.7%kev

ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

ConnectWise ScreenConnect allows file transfer and execution through active remote sessions without authorization. CVSS 9.9 critical, CISA KEV due September 14.

ConnectWise / ScreenConnect
CVE-2026-85706
[ CRITICAL ]CVSS 10.0EPSS 11.1%kev

GitLab Path Traversal Allows Unauthenticated File Read

GitLab CE/EE contains a path traversal flaw due to improper path confinement and missing access controls, allowing an unauthenticated attacker to read arbitrary files from the server.

GitLab / GitLab CE/EE
CVE-2026-67277
[ HIGH ]CVSS 8.2EPSS 0.9%kev

MikroTik RouterOS Missing Authentication for Critical Function Vulnerability

MikroTik RouterOS btest service missing authentication allows kernel memory disclosure. CVSS 8.2 (high), CISA KEV deadline September 13, 2026.

MikroTik / RouterOS
$ latest --more

From the desk

all articles →
~/articles/2026-09-14-grayrabbit-sogou-input-method-unc3569
China-Linked UNC3569 Deploys GrayRabbit via Sogou Flaw
threat intel

China-Linked UNC3569 Deploys GrayRabbit via Sogou Flaw

Gen Threat Labs links China-aligned UNC3569 to GrayRabbit backdoor deployments through a chained flaw in Tencent's Sogou Input Method for Windows. Patch to v16.3.0.3498.

read →
~/articles/2026-09-13-events-calendar-cve-2026-78159-78006-rce
Events Calendar Plugin: Two CVSS 9.8 RCEs
wordpress

Events Calendar Plugin: Two CVSS 9.8 RCEs

Two unauthenticated CVSS 9.8 RCEs in The Events Calendar WordPress plugin affect all versions through 6.17.4. Disable or update immediately.

read →
~/articles/2026-09-13-bluemoon-exploit-kit-chrome-windows-zero-days
BlueMoon Exploit Kit Chains Chrome, Windows Zero-Days
browser

BlueMoon Exploit Kit Chains Chrome, Windows Zero-Days

BlueMoon exploit kit bundles Chrome renderer and Windows privilege-escalation zero-days into a two-stage chain, with espionage-motivated actors adopting it in rushed campaigns.

read →
~/articles/2026-09-13-check-point-vpn-dutch-ncsc-exploitation-warning
Dutch NCSC Warns Check Point VPN Exploitation Imminent
● Breaking
check point

Dutch NCSC Warns Check Point VPN Exploitation Imminent

Dutch NCSC warns exploitation of two CVSS 9.8 Check Point VPN RCE flaws is imminent. If you haven't patched CVE-2026-85102 and CVE-2026-85103, do it now.

read →
~/articles/2026-09-13-authorizer-cve-2026-54072-open-redirect
Authorizer CVSS 9.3 Flaw Enables OAuth Token Theft
threat intel

Authorizer CVSS 9.3 Flaw Enables OAuth Token Theft

Authorizer's /authorize endpoint accepted any redirect_uri before v2.2.1, exposing OAuth codes and tokens to theft via crafted flows. Patch to 2.2.1.

read →
~/articles/2026-09-13-cisa-kev-routeros-screenconnect-artifactory-deadlines
CISA KEV: RouterOS Deadline Today, ScreenConnect Tomorrow
cisa kev

CISA KEV: RouterOS Deadline Today, ScreenConnect Tomorrow

CISA added five exploited flaws in MikroTik RouterOS, ConnectWise ScreenConnect, and JFrog Artifactory. Federal patch deadline for RouterOS is today, September 13.

read →