Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-7273
[ HIGH ]CVSS 8.8EPSS 0.3%kev

Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability

Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

Zyxel / GS1900 Series Switches
CVE-2025-39682
[ CRITICAL ]CVSS 9.8EPSS 1.2%kev

Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

Linux kernel TLS receive path: zero-length record bypasses recvmsg() handling, corrupting downstream TLS processing. CVSS 9.8. In CISA KEV Sept. 18, 2026.

Linux / Kernel
CVE-2025-39964
[ HIGH ]CVSS 7.8EPSS 0.8%kev

Linux Kernel Race Condition Vulnerability

Linux kernel AF_ALG race condition: concurrent writes corrupt state, crashing the system or corrupting cryptographic output. CVSS 7.8. CISA KEV Sept. 18.

Linux / Kernel
CVE-2026-53266
[ HIGH ]CVSS 8.8EPSS 0.3%kev

Linux Kernel Out-of-Bounds Write Vulnerability

OOB write in Linux kernel ebtables SNAT target. ARP address rewrite lands in a nonlinear socket buffer. CVSS 8.8, public exploits confirmed. CISA KEV Sept. 18.

Linux / Kernel
CVE-2026-58704
[ HIGH ]CVSS 8.8EPSS 0.2%kev

Google Pixel Cellular Modem Improper Authorization

Improper authorization in Google Pixel's cellular modem lets a nearby attacker bypass permission checks and escalate privileges without user interaction. CISA KEV, due 2026-09-19.

Google / Pixel
CVE-2026-76460
[ CRITICAL ]CVSS 10.0EPSS 0.8%kev

Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

CVSS 10.0 auth bypass in Cisco ISE and ISE-PIC. Unauthenticated attackers can bypass web management and gain root execution. Actively exploited; CISA KEV.

Cisco / Identity Services Engine
$ latest --more

From the desk

all articles →
~/articles/2026-09-20-kcp-cve-2026-61682-user-impersonation-front-proxy
kcp Front-Proxy Lets Attackers Impersonate Any User
cloud

kcp Front-Proxy Lets Attackers Impersonate Any User

CVE-2026-61682 (CVSS 9.9): kcp front-proxy passes X-Remote-User headers through, enabling user impersonation. Fixed in 0.31.4 and 0.32.2.

read →
~/articles/2026-09-20-icinga2-cve-2026-61550-auth-bypass-dos-patched
Icinga 2 Patches CVSS 9.8 Auth Bypass and Stack Overflow
threat intel

Icinga 2 Patches CVSS 9.8 Auth Bypass and Stack Overflow

Icinga 2 patches CVSS 9.8 cluster node injection (CVE-2026-61550) and CVSS 8.6 stack overflow (CVE-2026-61551). Upgrade to 2.14.9, 2.15.4, or 2.16.2.

read →
~/articles/2026-09-20-bragjack-ai-browser-agent-hijack
BragJack PoC Hijacks AI Browser Agents via Extensions
browser

BragJack PoC Hijacks AI Browser Agents via Extensions

A PoC from security researcher Gal Weizman shows a single malicious extension can intercept and manipulate AI assistants in Chrome, Edge, and other browsers.

read →
~/articles/2026-09-20-solarwinds-arm-cve-2026-28326-hardcoded-key-rce
SolarWinds ARM Hard-Coded Key Allows Unauthenticated RCE
● Breaking
solarwinds

SolarWinds ARM Hard-Coded Key Allows Unauthenticated RCE

CVE-2026-28326 (CVSS 8.8) in SolarWinds Access Rights Manager through 2026.2 lets unauthenticated attackers execute code. Patch ARM 2026.2.1 is available now.

read →
~/articles/2026-09-20-shinyhunters-hacks-clop-tor-site
ShinyHunters Breaches Clop Tor Site, Steals Onion Keys
● Breaking
ransomware

ShinyHunters Breaches Clop Tor Site, Steals Onion Keys

ShinyHunters defaced Clop's data leak site Friday via a Grav CMS upload flaw, claiming server data and private onion keys. A 72-hour extortion deadline is running.

read →
~/articles/2026-09-19-microsoft-fabric-cve-2026-69843-cvss10-auth-bypass
Microsoft Fabric Auth Bypass Reaches CVSS 10.0
Analysis
microsoft

Microsoft Fabric Auth Bypass Reaches CVSS 10.0

Microsoft patched CVE-2026-69843, a CVSS 10.0 authentication bypass in Fabric that let unauthenticated attackers elevate privileges over a network.

read →