Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-48710
[ MEDIUM ]CVSS 6.5EPSS 2.1%kev

Kludex Starlette HTTP Request/Response Smuggling Vulnerability

Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.

Kludex / Starlette
CVE-2026-49869
[ CRITICAL ]CVSS 10.0EPSS 1.0%kev

Kestra OSS OS Command Injection Vulnerability

Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.

Kestra / Kestra OSS
CVE-2026-59822
[ HIGH ]CVSS 8.2EPSS 0.5%kev

BerriAI LiteLLM Improper Authentication Vulnerability

BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.

BerriAI / LiteLLM
CVE-2026-9586
[ HIGH ]EPSS 1.1%kev

Sangoma Switchvox SQL Injection Vulnerability

Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

Sangoma / Switchvox
CVE-2026-83548
[ HIGH ]EPSS 0.3%kev

Pre-auth SSRF in SonicWall SMA1000 Workplace Interface

Unauthenticated SSRF in the SMA1000 Workplace interface allows remote attackers to reach internal functionality via an unintended access path. Exploited in the wild; chains with CVE-2026-83549 for RCE.

SonicWall / SMA1000
CVE-2026-83549
[ HIGH ]CVSS 7.8EPSS 0.9%kev

OS Command Injection in SonicWall SMA1000 AMC

Post-auth OS command injection in the SonicWall SMA1000 AMC allows an authenticated administrator to execute arbitrary OS commands. CVSS 7.8 HIGH. Chains with CVE-2026-83548 for unauthenticated RCE.

SonicWall / SMA1000 Appliance Management Console
$ latest --more

From the desk

all articles →
~/articles/2026-09-02-langflow-cve-2026-0768-rce-credential-theft
Attackers Exploit Langflow to Steal OpenAI, AWS Keys
cloud

Attackers Exploit Langflow to Steal OpenAI, AWS Keys

CVE-2026-0768, a critical unauthenticated RCE in Langflow, is being actively exploited to drain AI API keys and cloud credentials from exposed instances.

read →
~/articles/2026-09-01-jfrog-artifactory-cve-2026-82329-exploited
JFrog Artifactory CVE-2026-82329 Now Exploited
● Breaking
supply chain

JFrog Artifactory CVE-2026-82329 Now Exploited

Active exploitation of the critical Artifactory authentication bypass has started, just days after public disclosure. If your instance is unpatched, that ends now.

read →
~/articles/2026-09-01-manchester-airports-fulcrumsec-extortion-claim
FulcrumSec Claims 80GB Manchester Airports Hack
● Breaking
ransomware

FulcrumSec Claims 80GB Manchester Airports Hack

FulcrumSec claims 80 GB of Manchester Airports Group data and threatens public release. No extortion group had claimed the breach when MAG disclosed it on August 28.

read →
~/articles/2026-09-01-mckesson-breach-shinyhunters-deadline
McKesson Breach: ShinyHunters Deadline Now Active
● Breaking
ransomware

McKesson Breach: ShinyHunters Deadline Now Active

McKesson confirmed the data breach. ShinyHunters has set a payment deadline covering 284 million claimed records. Developing situation as of September 1, 2026.

read →
~/articles/2026-09-01-aurora-ransomware-cursor-ai-attacks
Aurora Ransomware Uses AI Coding Tools in Attacks
Analysis
ai tools

Aurora Ransomware Uses AI Coding Tools in Attacks

CloudSEK and Gambit Security find Aurora operators used Cursor AI to plan Russian-language attacks on 20-plus organizations in nine countries.

read →
~/articles/2026-09-01-papercut-kev-active-intrusions
PaperCut Active Intrusions: CISA Adds Flaws to KEV
● Breaking
threat intel

PaperCut Active Intrusions: CISA Adds Flaws to KEV

CISA added CVE-2026-81578 and CVE-2026-82078 to KEV on Aug 31. Active intrusions now confirmed. Federal deadline: Sep 14. Emergency Patch Release 2 required.

read →