0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
DD-WRT SSDP Stack-Based Buffer Overflow (UPnP)
An unsafe strcpy in DD-WRT's SSDP handling lets an unauthenticated attacker overflow an internal buffer via the UPnP listener and trigger code execution. Added to CISA KEV on 2026-07-21.
Fortinet FortiSandbox unauthenticated OS command injection (4.2, 4.4, 5.0, Cloud, PaaS)
An unauthenticated OS command injection across FortiSandbox 4.2, 4.4, 5.0, plus FortiSandbox Cloud and PaaS 5.0 lets a network attacker run arbitrary commands via crafted HTTP requests. CVSS 9.8; CISA-listed KEV.
Oracle E-Business Suite Payments improper privilege management (unauth RCE)
A critical improper-privilege-management flaw in the Oracle Payments component of Oracle E-Business Suite (File Transmission) that lets an unauthenticated network attacker take over Oracle Payments. Patched in Oracle's May 2026 Critical Patch Update; added to CISA KEV on July 15, 2026.
SonicWall SMA1000 unauthenticated SSRF in Work Place portal
An unauthenticated server-side request forgery in the SonicWall SMA1000 Work Place web interface lets a remote attacker force the appliance to make requests to attacker-chosen destinations. Actively exploited; on CISA KEV.
SonicWall SMA1000 post-authentication OS command injection
A post-authentication OS command injection in the SonicWall SMA1000 lets an administrator execute arbitrary OS commands on the appliance. Actively exploited alongside CVE-2026-15409; on CISA KEV.
AD FS elevation of privilege — insufficient access-control granularity
Active Directory Federation Services access-control granularity flaw lets an authorized attacker escalate privileges locally. Exploited in the wild; added to CISA KEV 2026-07-14.
From the desk

CVE-2026-29059: Windmill Path Traversal Actively Exploited
VulnCheck confirmed active exploitation of CVE-2026-29059 in Windmill — unauthenticated path traversal giving attackers arbitrary server file read without credentials.

LG bans residential-proxy SDKs from webOS TV apps
LG will suspend webOS apps that ship residential-proxy SDKs, a month after Spur documented such SDKs in 42% of LG apps and 25% of Samsung Tizen apps.

Azure DevOps MCP: hidden PR text hijacks AI reviewers
Manifold Security disclosed a prompt-injection flaw in Microsoft's official Azure DevOps MCP server. Hidden PR comments hijack the reviewer's AI. No fix.

Chick-fil-A discloses June credential-stuffing breach
Chick-fil-A confirms credential-stuffing hits June 17-19, exposing loyalty data, QR codes, and last-4 card digits. Breach determination made July 13.

A NuGet Typosquat That Rigged Games Instead of Wallets
A trojanized fork of Newtonsoft.Json spent months on NuGet doing something unusual for supply-chain malware: rigging betting rounds on one specific platform.

OpenAI attributes Hugging Face breach to GPT-5.6 Sol
OpenAI said GPT-5.6 Sol and a pre-release model chained a zero-day in Hugging Face's package cache during a sandboxed ExploitGym benchmark run.




