Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-75650
[ CRITICAL ]CVSS 10.0EPSS 0.7%kev

Adobe Commerce and Magento Template Engine Injection (StyleSmuggler)

CVSS 10.0 template-injection in Adobe Commerce and Magento Open Source. Unauthenticated RCE exploited to plant Rust backdoors; emergency patch released September 8, 2026.

Adobe / Commerce and Magento Open Source
CVE-2026-81963
[ HIGH ]CVSS 7.8kev

Microsoft Windows Update Stack Link-Following Privilege Escalation

“Windows Update Stack link-following flaw lets a local attacker escalate to SYSTEM. CVSS 7.8, actively exploited, on CISA KEV.”

Microsoft / Windows
CVE-2026-85880
[ HIGH ]CVSS 7.8kev

Microsoft Windows ALPC Heap Buffer Overflow Privilege Escalation

“Windows ALPC contains a heap buffer overflow allowing AppContainer sandbox escape to local privilege escalation. CVSS 7.8, actively exploited, on CISA KEV.”

Microsoft / Windows
CVE-2026-86218
[ CRITICAL ]CVSS 10.0EPSS 0.4%kev

N-central Pre-Authentication Remote Code Execution

Pre-authentication remote code execution in N-able N-central via static code injection. Network-accessible, no credentials required. Fixed in 2026.3.1.14.

N-able / N-central
CVE-2026-85046
[ HIGH ]CVSS 8.8EPSS 1.2%kev

Type confusion in Chrome V8 allows sandbox code execution

Type confusion in Chrome's V8 engine lets remote attackers run arbitrary code inside the browser sandbox via a crafted HTML page. Actively exploited; update to 152.0.7977.82.

Google / Chrome (before 152.0.7977.82)
CVE-2026-48710
[ MEDIUM ]CVSS 6.5EPSS 36.3%kev

Kludex Starlette HTTP Request/Response Smuggling Vulnerability

Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.

Kludex / Starlette
$ latest --more

From the desk

all articles →
~/articles/2026-09-08-fake-it-calls-m365-data-theft-extortion
Fake IT Calls Drive M365 Exec Data Theft Campaign
● Breaking
microsoft

Fake IT Calls Drive M365 Exec Data Theft Campaign

Threat hunters have disclosed an active data theft and extortion cluster targeting Microsoft 365 executives via vishing: fake IT help desk calls that harvest credentials and SaaS access.

read →
~/articles/2026-09-08-vietnam-apis-220-million-traveler-records-breach
220M Passport Records Exposed in Vietnam APIS Leak
threat intel

220M Passport Records Exposed in Vietnam APIS Leak

An exposed Vietnam-linked APIS database held 220 million traveler records: names, passport numbers, birth dates, nationalities, and flight routes.

read →
~/articles/2026-09-08-nightmare-eclipse-crowdstrike-nvidia-avast-zero-days
Nightmare Eclipse: Zero-Days Hit CrowdStrike, Nvidia, Avast
● Breaking
threat intel

Nightmare Eclipse: Zero-Days Hit CrowdStrike, Nvidia, Avast

Nightmare Eclipse published PoC privilege-escalation exploits for CrowdStrike Falcon, Nvidia drivers, and Avast antivirus. No CVE IDs or vendor patches yet.

read →
~/articles/2026-09-08-advantech-wise-6610-cve-2026-79697-rce
Advantech WISE-6610 Firmware Hit by CVSS 9.9 RCE
ics ot

Advantech WISE-6610 Firmware Hit by CVSS 9.9 RCE

A command injection in the WISE-6610 LoRaWAN gateway's Basic Station handler allows remote code execution. Exploit is public. Patch: firmware 1.2.4_20260821.

read →
~/articles/2026-09-08-telerik-ui-rce-chain-cve-2026-13181-poc-public
Telerik UI RCE Chain: PoC Published, Patch Is Out
● Breaking
progress

Telerik UI RCE Chain: PoC Published, Patch Is Out

TantoSec's public exploit chains seven Telerik UI CVEs into unauthenticated RCE. Non-default configs only. Patch to 2026 Q2 SP1 now.

read →
~/articles/2026-09-07-n-central-hotfix-4-patch-again
Patch N-central Again: Hotfix 4 Is Out
● Breaking
supply chain

Patch N-central Again: Hotfix 4 Is Out

N-able's fourth N-central hotfix in five weeks renders Hotfix 3 obsolete. Update to 2026.3.1.14 now: CVE-2026-86218 is actively exploited.

read →