Skip to content
feed: live
>_ 0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2021-27137
[ HIGH ] CVSS 8.1 kev

DD-WRT SSDP Stack-Based Buffer Overflow (UPnP)

An unsafe strcpy in DD-WRT's SSDP handling lets an unauthenticated attacker overflow an internal buffer via the UPnP listener and trigger code execution. Added to CISA KEV on 2026-07-21.

DD-WRT / DD-WRT router firmware (builds prior to revision 45724)
CVE-2026-25089
[ CRITICAL ] CVSS 9.8 kev

Fortinet FortiSandbox unauthenticated OS command injection (4.2, 4.4, 5.0, Cloud, PaaS)

An unauthenticated OS command injection across FortiSandbox 4.2, 4.4, 5.0, plus FortiSandbox Cloud and PaaS 5.0 lets a network attacker run arbitrary commands via crafted HTTP requests. CVSS 9.8; CISA-listed KEV.

Fortinet / FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS (multiple 4.x and 5.0 lines — see body)
CVE-2026-46817
[ CRITICAL ] CVSS 9.8 kev

Oracle E-Business Suite Payments improper privilege management (unauth RCE)

A critical improper-privilege-management flaw in the Oracle Payments component of Oracle E-Business Suite (File Transmission) that lets an unauthenticated network attacker take over Oracle Payments. Patched in Oracle's May 2026 Critical Patch Update; added to CISA KEV on July 15, 2026.

Oracle / E-Business Suite — Oracle Payments (versions 12.2.3–12.2.15)
CVE-2026-15409
[ CRITICAL ] CVSS 10.0 kev

SonicWall SMA1000 unauthenticated SSRF in Work Place portal

An unauthenticated server-side request forgery in the SonicWall SMA1000 Work Place web interface lets a remote attacker force the appliance to make requests to attacker-chosen destinations. Actively exploited; on CISA KEV.

SonicWall / SMA1000 Series (6210, 7210, 8200v)
CVE-2026-15410
[ HIGH ] CVSS 7.2 kev

SonicWall SMA1000 post-authentication OS command injection

A post-authentication OS command injection in the SonicWall SMA1000 lets an administrator execute arbitrary OS commands on the appliance. Actively exploited alongside CVE-2026-15409; on CISA KEV.

SonicWall / SMA1000 Series (6210, 7210, 8200v)
CVE-2026-56155
[ HIGH ] CVSS 7.8 kev

AD FS elevation of privilege — insufficient access-control granularity

Active Directory Federation Services access-control granularity flaw lets an authorized attacker escalate privileges locally. Exploited in the wild; added to CISA KEV 2026-07-14.

Microsoft / Active Directory Federation Services (AD FS) — see MSRC advisory for affected builds
$ latest --more

From the desk

all articles →
~/articles/2026-07-21-zimbra-10-1-20-nine-bugs-snmp-command-injection-tops-list
Zimbra 10.1.20 patches nine, SNMP injection at the top
zimbra

Zimbra 10.1.20 patches nine, SNMP injection at the top

Zimbra 10.1.20 fixes nine vulnerabilities including an SNMP command injection when notifications are enabled. Patch if you self-host — CVEs pending.

read →
~/articles/2026-07-21-kratos-phaas-olympus-blade-takedown-m365-passkeys-fuse
Kratos phishing platform seized. M365 exposure is not.
threat intel

Kratos phishing platform seized. M365 exposure is not.

German BKA and US authorities dismantled Kratos PhaaS and arrested its developer in Indonesia. Passkey rollout still matters more than the takedown headline.

read →
~/articles/2026-07-21-sharepoint-cve-2026-50522-machine-keys-stolen-rotate-credentials-fuse
SharePoint attackers stealing keys — rotate credentials now
● Breaking
microsoft

SharePoint attackers stealing keys — rotate credentials now

watchTowr says attackers exploiting CVE-2026-50522 are stealing SharePoint machine keys for post-patch persistence. Rotate credentials — patching alone won't help.

read →
~/articles/2026-07-21-thn-picus-n-hour-patching-mythos-verizon-dbir-analysis
Patch-to-exploit is hours. Patching still isn't optional.
Analysis
threat intel

Patch-to-exploit is hours. Patching still isn't optional.

A vendor-sponsored piece at The Hacker News argues N-day exploitation now runs on N-hour timescales. The observation is right. The takeaway isn't.

read →
~/articles/2026-07-21-anubis-fairlife-1tb-nutanix-claim-declines-comment
Anubis claims Fairlife hit, 1TB and Nutanix encrypted
● Breaking
ransomware

Anubis claims Fairlife hit, 1TB and Nutanix encrypted

Anubis ransomware has claimed the July 16 Coca-Cola Fairlife attack, alleging ~1TB stolen and full Nutanix encryption. Coca-Cola declined to comment; BleepingComputer could not verify.

read →
~/articles/2026-07-21-apple-hide-my-email-mail-logs-july3-fix-year-disclosure
Apple fixes Hide My Email leak, year after disclosure
● Breaking
apple

Apple fixes Hide My Email leak, year after disclosure

Apple deployed a July 3 fix for a Hide My Email flaw that unmasked real addresses in Mail logs — disclosed to Apple over a year earlier per 404 Media.

read →