0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
PaperCut NG/MF Authentication Bypass
Authentication bypass in PaperCut NG/MF (CVSS 8.8) lets unauthenticated attackers access admin functions via malformed requests. Actively exploited; apply Emergency Patch Release 2.
PaperCut NG/MF Unsafe Class-Loading RCE
PaperCut NG/MF (CVSS 9.4 Critical): unsafe dynamic class-loading enables unauthenticated RCE. Actively exploited; apply Emergency Patch Release 2 immediately.
ownCloud Improper Authentication Vulnerability
ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.
Linux Kernel Unspecified Vulnerability
Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux.
JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.
Citrix NetScaler ADC and Gateway Memory Buffer Overflow
CVE-2026-8452 is a CVSS 9.8 critical memory buffer overflow in Citrix NetScaler ADC and NetScaler Gateway affecting appliances configured as Gateway or AAA virtual server, confirmed exploited in the wild and added to CISA KEV on August 26, 2026.
From the desk

oidcc Auth Bypass Lets Attackers Impersonate Users
CVE-2026-75759 in the Elixir oidcc library lets an unauthenticated attacker impersonate any user by supplying an encrypted OIDC token with an attacker-controlled algorithm. Update oidcc now.

TerminalFix: New ClickFix Drops Reverse-Tunnel Backdoor
Microsoft has detailed TerminalFix, a ClickFix variant that lures users into running commands in Windows Terminal or PowerShell and then plants a persistent reverse-tunnel backdoor.

Microsoft Edge Patches CVSS 8.8 Type Confusion RCE
Microsoft patched eight Edge CVEs in late August, led by CVE-2026-72984, a CVSS 8.8 type confusion flaw enabling unauthenticated remote code execution over a network.

Berlin Confirms State Network Breach, Refuses Ransom
Berlin confirmed its state administrative network was compromised in August. The city is refusing extortion demands, with attacker identity unconfirmed.

JFrog Artifactory Flaw Gives Unauthenticated Admin Access
CVE-2026-82329, scored 9.8 critical, lets unauthenticated network attackers claim full admin rights in JFrog Artifactory under its default configuration.

PaperCut Issues Second Patch as Bypasses Found
PaperCut's first emergency patch had bypasses. CVE-2026-81578 (auth bypass, CVSS 8.8) and CVE-2026-82078 (RCE, CVSS 9.4) remain exploitable on EP1 installs. Apply Emergency Patch Release 2.




