Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-69836
[ CRITICAL ]CVSS 10.0EPSS 1.4%kev

Microsoft Entra ID Deserialization of Untrusted Data — RCE

Deserialization flaw in Microsoft Entra ID allows unauthenticated remote code execution over a network. CVSS 10.0. Actively exploited; added to CISA KEV on August 21, 2026.

Microsoft / Entra ID (formerly Azure Active Directory)
CVE-2026-73570
[ HIGH ]CVSS 8.9EPSS 1.0%kev

Zimbra ZCS SNMP Command Injection — Unauthenticated RCE

CVE-2026-73570 — CVSS 8.9 command injection in Zimbra Collaboration Suite's SNMP handler enables unauthenticated remote code execution. Actively exploited in the wild. Patch: Zimbra 10.1.20.

Synacor / Zimbra Collaboration Suite (ZCS)
CVE-2026-72529
[ CRITICAL ]CVSS 9.8EPSS 0.8%kev

TrueConf Server Missing Authentication for Critical Function Vulnerability

TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.

TrueConf / Server
CVE-2026-72530
[ CRITICAL ]CVSS 9.0EPSS 1.0%kev

TrueConf Server Code Injection Vulnerability

TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.

TrueConf / Server
CVE-2026-33824
[ CRITICAL ]CVSS 9.8EPSS 77.9%kev

Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.

Microsoft / Internet Key Exchange (IKE) Service Extensions
CVE-2026-64849
[ CRITICAL ]CVSS 9.3EPSS 8.2%kev

MLflow SSRF Lets Attackers Steal Cloud Credentials via Metadata Services

A server-side request forgery in MLflow before 3.15.0 allows unauthenticated access to internal endpoints including cloud metadata services, enabling cloud credential and IAM secret theft.

MLflow / MLflow (< 3.15.0)
$ latest --more

From the desk

all articles →
~/articles/2026-08-23-banking-trojans-manic-grandoreiro-toxicpanda
Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 Active
● Breaking
mobile

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 Active

Three banking trojans are active: spyware-equipped Manic, persistent Grandoreiro across Latin America and Europe, and an expanded ToxicPanda 2.0.

read →
~/articles/2026-08-22-weechat-relay-timing-attack-cve-2026-53525
WeeChat Relay Flaw Exposes Auth to Timing Attack
threat intel

WeeChat Relay Flaw Exposes Auth to Timing Attack

WeeChat versions 0.3.1–4.9.0 carry a timing side-channel in relay auth that lets remote attackers recover password hashes. A decompression DoS affects the same range. Both patched in 4.9.1.

read →
~/articles/2026-08-22-android-car-head-unit-proxy-botnet
Car Infotainment Units Hijacked via Supply-Chain Attack
● Breaking
supply chain

Car Infotainment Units Hijacked via Supply-Chain Attack

A supply-chain attack against Android-based car head units trojanizes a legitimate device update app to install proxy botnet or ad fraud malware.

read →
~/articles/2026-08-22-defender-btr-sys-boot-driver-security-bypass
Defender's Own Boot Driver Can Kill Security Software
Analysis
microsoft

Defender's Own Boot Driver Can Kill Security Software

Check Point: Defender's signed BTR.sys driver can delete security software at kernel level before OS load. Affects Windows 7–11 25H2, no exploit required.

read →
~/articles/2026-08-22-redc2-npm-backdoor-supply-chain
AI-Powered RedC2 Backdoor Hidden in 14 npm Packages
supply chain

AI-Powered RedC2 Backdoor Hidden in 14 npm Packages

TrendAI found 14 trojanized npm packages delivering RedC2 4.0, an AI-assisted Linux backdoor that silently executes at module load time.

read →
~/articles/2026-08-22-sickkids-hospital-data-breach-third-party
SickKids Hit Again: Data Theft via Third-Party App
ransomware

SickKids Hit Again: Data Theft via Third-Party App

SickKids confirms employee data stolen via a third-party software application. Second major incident since a 2022 ransomware attack disabled the Toronto hospital's clinical systems.

read →