0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Microsoft Entra ID Deserialization of Untrusted Data — RCE
Deserialization flaw in Microsoft Entra ID allows unauthenticated remote code execution over a network. CVSS 10.0. Actively exploited; added to CISA KEV on August 21, 2026.
Zimbra ZCS SNMP Command Injection — Unauthenticated RCE
CVE-2026-73570 — CVSS 8.9 command injection in Zimbra Collaboration Suite's SNMP handler enables unauthenticated remote code execution. Actively exploited in the wild. Patch: Zimbra 10.1.20.
TrueConf Server Missing Authentication for Critical Function Vulnerability
TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.
TrueConf Server Code Injection Vulnerability
TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
MLflow SSRF Lets Attackers Steal Cloud Credentials via Metadata Services
A server-side request forgery in MLflow before 3.15.0 allows unauthenticated access to internal endpoints including cloud metadata services, enabling cloud credential and IAM secret theft.
From the desk

Velociraptor Flaw Lets Analysts Overwrite Artifacts
CVE-2026-19200 (CVSS 8.9) lets Velociraptor analysts overwrite global artifacts, bypassing permission controls. Update your deployment.

ToxicPanda Blocks Play Store via Android VPN Trick
Zimperium: ToxicPanda 2.0 abuses VPN service permissions to block Google Play, now targeting 349 financial apps across 16 countries.

strongSwan 6.0.7 Patches Double-Free in IKE Auth
CVE-2026-47895 is a CVSS 7.5 double-free triggered during IKE authentication in strongSwan before 6.0.7. Upgrade now — crash risk is confirmed, heap corruption is possible.

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 Active
Three banking trojans are active: spyware-equipped Manic, persistent Grandoreiro across Latin America and Europe, and an expanded ToxicPanda 2.0.

WeeChat Relay Flaw Exposes Auth to Timing Attack
WeeChat versions 0.3.1–4.9.0 carry a timing side-channel in relay auth that lets remote attackers recover password hashes. A decompression DoS affects the same range. Both patched in 4.9.1.

Car Infotainment Units Hijacked via Supply-Chain Attack
A supply-chain attack against Android-based car head units trojanizes a legitimate device update app to install proxy botnet or ad fraud malware.




