Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-58704
[ HIGH ]CVSS 8.0EPSS 0.1%kev

Google Pixel Improper Authorization Vulnerability

Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.

Google / Pixel
CVE-2026-76460
[ CRITICAL ]CVSS 10.0kev

Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

Cisco / Identity Services Engine
CVE-2026-76461
[ CRITICAL ]CVSS 9.8EPSS 2.0%kev

Cisco Secure Email Gateway SQL Injection Vulnerability

SQL injection in Cisco AsyncOS for Secure Email Gateway lets an unauthenticated remote attacker execute arbitrary OS commands with root privileges. CISA KEV since Sept. 14.

Cisco / Secure Email Gateway
CVE-2026-42016
[ HIGH ]CVSS 8.1EPSS 0.9%kev

JFrog Artifactory Incorrect Authorization Vulnerability

JFrog Artifactory validates token signature and issuer but not scope, creating a privilege escalation path. CVSS 8.1 (high), CISA KEV deadline September 25, 2026.

JFrog / Artifactory
CVE-2026-42018
[ HIGH ]CVSS 7.5EPSS 0.9%kev

JFrog Artifactory Improper Authentication Vulnerability

JFrog Artifactory returns an internal anonymous-user token to unauthenticated callers even when anonymous access is disabled, allowing unauthorized resource access and enabling privilege escalation chains.

JFrog / Artifactory
CVE-2026-84869
[ CRITICAL ]CVSS 9.9EPSS 0.7%kev

ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

ConnectWise ScreenConnect allows file transfer and execution through active remote sessions without authorization. CVSS 9.9 critical, CISA KEV due September 14.

ConnectWise / ScreenConnect
$ latest --more

From the desk

all articles →
~/articles/2026-09-16-jfrog-artifactory-three-flaws-backdoor
Three Artifactory Flaws Exploited to Plant Backdoors
● Breaking
supply chain

Three Artifactory Flaws Exploited to Plant Backdoors

SecurityWeek reports three JFrog Artifactory flaws actively exploited to reach admin access and deploy backdoors in enterprise build pipelines.

read →
~/articles/2026-09-15-microsoft-oob-windows-rds-hyper-v-fix
Microsoft OOB Fixes RDS, Hyper-V Failures from Sept Patches
microsoft

Microsoft OOB Fixes RDS, Hyper-V Failures from Sept Patches

Out-of-band Windows updates address Remote Desktop Services failures, Hyper-V errors, and USB audio problems introduced by September 2026 Patch Tuesday.

read →
~/articles/2026-09-15-apple-ios-27-macos-golden-gate-200-vulns-patched
Apple iOS 27, macOS Golden Gate Patch 200 Vulns
● Breaking
apple

Apple iOS 27, macOS Golden Gate Patch 200 Vulns

Apple released iOS 27 and macOS Golden Gate 27 on September 15, patching roughly 200 vulnerabilities including kernel flaws that enable privilege escalation and memory corruption.

read →
~/articles/2026-09-15-japan-digital-agency-vpn-breach-246k-personnel
Japan Digital Agency Breach Exposes 246K Staff Records
threat intel

Japan Digital Agency Breach Exposes 246K Staff Records

Japan's Digital Agency disclosed a VPN breach affecting roughly 246,000 rows of government employee personal information. The specific CVE and VPN vendor have not been named.

read →
~/articles/2026-09-15-grimwedge-china-chrome-windows-zero-day
China-Linked Group Deploys GRIMWEDGE via Zero-Day Chain
● Breaking
threat intel

China-Linked Group Deploys GRIMWEDGE via Zero-Day Chain

A China-linked group uses a Chrome-plus-Windows zero-day chain in targeted spear-phishing campaigns to drop GRIMWEDGE, a JavaScript backdoor, on victim systems.

read →
~/articles/2026-09-15-cisco-secure-email-gateway-cve-2026-76461-rce
Cisco Email Gateway SQLi Grants Root, Now in KEV
cisco

Cisco Email Gateway SQLi Grants Root, Now in KEV

CVE-2026-76461, a SQL injection in Cisco AsyncOS, lets unauthenticated attackers run OS commands as root. CISA added it to KEV on Sept. 14 with a Sept. 17 deadline.

read →