0dayNews — Vulnerability & Exploit News
Latest intelligence
all articles →Known Exploited Vulnerabilities
ProFTPD Improper Access Control Vulnerability
ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
ISC BIND Data Processing Errors Vulnerability
ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries.
Apache Struts Command Injection Vulnerability
Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.
ONLYOFFICE Docs Server Path Traversal Vulnerability
ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution.
Strapi Cleartext Storage of Sensitive Information Vulnerability
Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution.
Citrix NetScaler Memory Buffer Flaw Enables Denial-of-Service Attacks
NetScaler ADC and Gateway contain an exploited memory-buffer flaw enabling denial of service. CISA KEV listed October 4, federal deadline October 7.
Latest security news

AhsayCBS Backup Platform Exploited, No Patch Ready
Two AhsayCBS flaws, including a CVSS 10.0 auth bypass, are chained to drop webshells and XMRig miners on MSP networks. No patch is available.

SonicWall SMA1000 Max-Severity Flaw Exploited
CVE-2026-102255 (CVSS 10.0) in SonicWall SMA1000 hit active exploitation within 72 hours of the October 7 patch. Patch immediately; attribution not yet confirmed.

CISA: Five Flax Typhoon CVEs Added, Feds Have Until Oct 11
CISA added five vulnerabilities tied to China's Flax Typhoon to its KEV catalog on Oct 8; federal agencies must patch or discontinue use by October 11.

Pwn2Own Ireland Closes: $1.26M for 98 Zero-Days
Pwn2Own Ireland 2026 wrapped with 98 unique zero-day vulnerabilities exploited and $1,262,000 in prizes paid out to competing security researchers.

IDCF Cloud Ransomware Hits Japanese Gov Clients
IDC Frontier confirmed a ransomware attack took down an IDCF Cloud data center cluster serving government and enterprise clients in Japan.

Citrix NetScaler: Critical CVSS 9.5 RCE, Patch Now
CVE-2026-107406, CVSS 9.5, is a memory overflow in Citrix NetScaler that allows unauthenticated RCE or DoS in SAML-configured deployments. Patch now.






