0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
JFrog Artifactory Incorrect Authorization Vulnerability
JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
JFrog Artifactory Improper Authentication Vulnerability
JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation.
MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.
MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation.
Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
CVSS 8.1 heap overflow in FortiOS, FortiSwitchManager, and FortiSASE allows code execution via crafted packets. Actively exploited in PivotC2 RAT attacks; patched January 2026.
From the desk

Ransomware Gangs Exploiting WatchGuard Firebox CVSS 9.8 Flaw
CISA confirmed ransomware groups now exploit CVE-2025-14733 in WatchGuard Firebox. Patches shipped December 2025; about 9,000 appliances remain exposed.

Fortinet Flaw CVE-2025-25249 Used in PivotC2 RAT Attacks
CVSS 8.1 heap overflow in FortiOS is exploited with PivotC2 RAT. January 2026 patch available; CISA BOD 26-04 deadline for federal agencies is September 12.

Veradigm Discloses Patient Breach After Ransomware Claim
Veradigm disclosed a patient data breach traced to a third-party vendor after the Gentlemen ransomware gang claimed responsibility for the attack.

SAP September Patches: CVSS 10 RCE in EPP Processing
SAP's September 2026 Security Patch Day includes a CVSS 10.0 unauthenticated RCE in Extended Passport Processing and multiple additional critical updates.

Ivanti Patches Critical RCE in Neurons, EPMM, Sentry
Ivanti's September 2026 patches close six critical RCEs in Neurons for ITSM and authentication bypass flaws in Sentry and EPMM. Patch now.

Cisco Confirms FMC CVSS 10 Auth Bypass Exploited
Cisco confirms CVE-2026-20079, CVSS 10.0 FMC auth bypass, is actively exploited. Unauthenticated attackers gain root OS access. CISA KEV deadline September 12.
This week's SITREP
Sep 11: Cisco FMC, Fortinet Hit KEV; Sept. 12 Deadline
Cisco FMC CVSS 10.0 auth bypass and Fortinet FortiOS heap overflow confirmed exploited, added to CISA KEV with September 12 deadline. Ivanti patches six critical RCEs. SAP closes CVSS 10.0 EPP flaw.




