Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-67277
[ HIGH ]EPSS 0.4%kev

MikroTik RouterOS Missing Authentication for Critical Function Vulnerability

MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.

MikroTik / RouterOS
CVE-2026-86060
[ HIGH ]EPSS 0.4%kev

MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation.

MikroTik / RouterOS
CVE-2025-25249
[ HIGH ]CVSS 8.1EPSS 1.7%kev

Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

CVSS 8.1 heap overflow in FortiOS, FortiSwitchManager, and FortiSASE allows code execution via crafted packets. Actively exploited in PivotC2 RAT attacks; patched January 2026.

Fortinet / FortiOS, FortiSwitchManager, FortiSASE
CVE-2026-20079
[ CRITICAL ]CVSS 10.0EPSS 74.7%kev

Cisco FMC Authentication Bypass Enables Root OS Access

CVE-2026-20079 is a CVSS 10.0 unauthenticated auth bypass in Cisco FMC with root OS access. Actively exploited; CISA KEV deadline September 12.

Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
CVE-2026-87491
[ HIGH ]CVSS 8.8EPSS 0.8%kev

Google Chromium V8 Out of Bounds Write Vulnerability

Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Google / Chromium V8
CVE-2026-75650
[ CRITICAL ]CVSS 10.0EPSS 2.1%kev

Adobe Commerce and Magento Template Engine Injection (StyleSmuggler)

CVSS 10.0 template-injection in Adobe Commerce and Magento Open Source. Unauthenticated RCE exploited to plant Rust backdoors; emergency patch released September 8, 2026.

Adobe / Commerce and Magento Open Source
$ latest --more

From the desk

all articles →
~/articles/2026-09-10-sap-september-patch-day-epp-cvss10-rce
SAP September Patches: CVSS 10 RCE in EPP Processing
sap

SAP September Patches: CVSS 10 RCE in EPP Processing

SAP's September 2026 Security Patch Day includes a CVSS 10.0 unauthenticated RCE in Extended Passport Processing and multiple additional critical updates.

read →
~/articles/2026-09-10-ivanti-september-patches-neurons-itsm-sentry-epmm
Ivanti Patches Critical RCE in Neurons, EPMM, Sentry
ivanti

Ivanti Patches Critical RCE in Neurons, EPMM, Sentry

Ivanti's September 2026 patches close six critical RCEs in Neurons for ITSM and authentication bypass flaws in Sentry and EPMM. Patch now.

read →
~/articles/2026-09-10-cisco-fmc-cve-2026-20079-exploited
Cisco Confirms FMC CVSS 10 Auth Bypass Exploited
● Breaking
cisco

Cisco Confirms FMC CVSS 10 Auth Bypass Exploited

Cisco confirms CVE-2026-20079, CVSS 10.0 FMC auth bypass, is actively exploited. Unauthenticated attackers gain root OS access. CISA KEV deadline September 12.

read →
~/articles/2026-09-09-f5-big-ip-apm-linux-rootkit-fileless
Linux Rootkit Targets F5 BIG-IP APM, Lives in Memory
● Breaking
f5

Linux Rootkit Targets F5 BIG-IP APM, Lives in Memory

Attackers are breaching F5 BIG-IP APM devices to deploy a Linux rootkit that hooks PHP file loading and injects a fileless web shell into memory, leaving no disk artifacts.

read →
~/articles/2026-09-09-microsoft-patch-tuesday-974-vulns-zero-days
Microsoft Patches Record 974 Vulns, 2 Zero-Days
● Breaking
microsoft

Microsoft Patches Record 974 Vulns, 2 Zero-Days

September 2026 Patch Tuesday: Microsoft patches a record 974 CVEs, including two exploited Windows zero-days now on CISA's KEV catalog.

read →
~/articles/2026-09-09-chrome-seventh-zero-day-2026-exploited
Google Patches Chrome's 7th Exploited Zero-Day of 2026
● Breaking
browser

Google Patches Chrome's 7th Exploited Zero-Day of 2026

Google patched the seventh actively exploited Chrome zero-day of 2026 on September 9, in a 230-vulnerability update. CVE designation pending.

read →