0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
Linux kernel TLS receive path: zero-length record bypasses recvmsg() handling, corrupting downstream TLS processing. CVSS 9.8. In CISA KEV Sept. 18, 2026.
Linux Kernel Race Condition Vulnerability
Linux kernel AF_ALG race condition: concurrent writes corrupt state, crashing the system or corrupting cryptographic output. CVSS 7.8. CISA KEV Sept. 18.
Linux Kernel Out-of-Bounds Write Vulnerability
OOB write in Linux kernel ebtables SNAT target. ARP address rewrite lands in a nonlinear socket buffer. CVSS 8.8, public exploits confirmed. CISA KEV Sept. 18.
Google Pixel Cellular Modem Improper Authorization
Improper authorization in Google Pixel's cellular modem lets a nearby attacker bypass permission checks and escalate privileges without user interaction. CISA KEV, due 2026-09-19.
Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
CVSS 10.0 auth bypass in Cisco ISE and ISE-PIC. Unauthenticated attackers can bypass web management and gain root execution. Actively exploited; CISA KEV.
Acronis Backup Incorrect Default Permissions Vulnerability
Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.
From the desk

CISA Adds Three Exploited Linux Kernel Flaws to KEV
CISA added CVE-2025-39682 (CVSS 9.8), CVE-2026-53266, and CVE-2025-39964 to KEV on Sept. 18. All three actively exploited. Federal deadline: Sept. 21.

Gyazo Breach Exposes 23M Records and OAuth Tokens
Helpfeel confirms 23.6 million Gyazo accounts breached September 11, exposing Google and X OAuth tokens. Revoke app access before changing passwords.

Ransomware Attacks on Manufacturers Up 40% in H1 2026
Ransomware attacks on manufacturers rose 40 percent in the first half of 2026, with groups exploiting the supply-chain disruption that follows operational shutdowns.

Orkes Conductor RCE CVE-2026-58138 Exploited in Attacks
Attackers are exploiting CVE-2026-58138, a CVSS 9.8 unauthenticated RCE in Orkes Conductor triggered via crafted inline workflow definitions.

Unbound 1.26.1 Fixes Critical DNSSEC Heap Overflow
NLnet Labs patches a critical DNSSEC heap overflow in Unbound. All versions before 1.26.1 are affected; RCE is possible via attacker-controlled DNS zones.

BIND 9 Patches 14 Flaws Including Unauthenticated DoH Crash
ISC patched 14 vulnerabilities in BIND 9, including a flaw that lets unauthenticated attackers crash resolvers via DNS-over-HTTPS. Update to 9.20.29 or 9.21.26.




