Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-93616
[ CRITICAL ]CVSS 9.8kev

Check Point Multiple Products Path Traversal Vulnerability

CVE-2026-93616: CVSS 9.8 path traversal and file upload in Check Point Management Server enabling unauth RCE. Confirmed exploited; patches available.

Check Point / Security Management Server, Multi-Domain Management Server, Log Server, SmartEvent
CVE-2026-93952
[ CRITICAL ]CVSS 10.0EPSS 0.4%kev

Arista VeloCloud Orchestrator Unauthenticated RCE

“CVE-2026-93952 is a CVSS 10.0 improper input validation flaw in Arista VeloCloud Orchestrator that allows unauthenticated remote code execution. Added to CISA KEV on September 22, 2026.”

Arista / VeloCloud Orchestrator
CVE-2026-94127
[ CRITICAL ]CVSS 9.8kev

F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

CVSS 9.8 F5 BIG-IP APM heap overflow: unauth RCE when an access policy and OAuth profile share a virtual server. Confirmed exploited; patches available.

F5 / BIG-IP APM
CVE-2026-7273
[ HIGH ]CVSS 8.8EPSS 2.0%kev

Zyxel GS1900 Series Switches Stack-Based Buffer Overflow

Stack-based buffer overflow in Zyxel GS1900 CGI program lets unauthenticated LAN attackers execute OS commands. CVSS 8.8, added to CISA KEV September 21, 2026.

Zyxel / GS1900 Series Switches
CVE-2025-39682
[ CRITICAL ]CVSS 9.8EPSS 2.0%kev

Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

Linux kernel TLS receive path: zero-length record bypasses recvmsg() handling, corrupting downstream TLS processing. CVSS 9.8. In CISA KEV Sept. 18, 2026.

Linux / Kernel
CVE-2025-39964
[ HIGH ]CVSS 7.8EPSS 0.8%kev

Linux Kernel Race Condition Vulnerability

Linux kernel AF_ALG race condition: concurrent writes corrupt state, crashing the system or corrupting cryptographic output. CVSS 7.8. CISA KEV Sept. 18.

Linux / Kernel
$ latest --more

From the desk

all articles →
~/articles/2026-09-22-windows-defender-bigdiskbuster-naceri-zero-day
New Windows Defender Zero-Day Blocks AV Updates
● Breaking
microsoft

New Windows Defender Zero-Day Blocks AV Updates

Naceri released BigDiskBuster, a zero-day PoC that blocks Windows Defender from updating on all supported Windows. No patch and no CVE assigned.

read →
~/articles/2026-09-22-wordpress-comment2shell-xss-rce-core
WordPress Core XSS Flaw Enables RCE via Admin Sessions
wordpress

WordPress Core XSS Flaw Enables RCE via Admin Sessions

Stored XSS in WordPress core lets anonymous visitors plant scripts in comments. An admin viewing the page can trigger remote code execution.

read →
~/articles/2026-09-22-zyxel-veeam-kev-active-exploitation
Zyxel, Veeam Flaws Confirmed Under Active Exploitation
● Breaking
cisa kev

Zyxel, Veeam Flaws Confirmed Under Active Exploitation

CISA added Zyxel GS1900 CVE-2026-7273 to its KEV catalog September 21. Veeam Agent CVE-2026-32996 also actively exploited. Patches available for both.

read →
~/articles/2026-09-22-shinyhunters-extorts-clop-victim-data-at-risk
ShinyHunters Extorts Cl0p, Victim Data at Risk
Analysis
ransomware

ShinyHunters Extorts Cl0p, Victim Data at Risk

ShinyHunters set an eight-figure ransom demand against Cl0p and threatened to publish records identifying companies that paid the ransomware gang.

read →
~/articles/2026-09-22-bigcommerce-ribon-app-supply-chain-breach
BigCommerce Merchants Breached via Ribon App Credentials
● Breaking
supply chain

BigCommerce Merchants Breached via Ribon App Credentials

Attackers compromised API keys for third-party Ribon loyalty apps and used them to inject scripts into BigCommerce storefronts, exposing customer contact data from Sept 13-17.

read →
~/articles/2026-09-21-crowdsec-source-code-stolen-tanstack-supply-chain
CrowdSec Source Code Stolen in TanStack Attack
supply chain

CrowdSec Source Code Stolen in TanStack Attack

CrowdSec confirmed its source code was stolen, attributing the breach to the May 2026 TanStack JavaScript supply chain compromise. No vulnerability disclosed yet.

read →