Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-42016
[ HIGH ]CVSS 8.1EPSS 0.3%kev

JFrog Artifactory Incorrect Authorization Vulnerability

JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

JFrog / Artifactory
CVE-2026-42018
[ HIGH ]CVSS 7.5EPSS 0.3%kev

JFrog Artifactory Improper Authentication Vulnerability

JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

JFrog / Artifactory
CVE-2026-84869
[ CRITICAL ]CVSS 9.9EPSS 0.4%kev

ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation.

ConnectWise / ScreenConnect
CVE-2026-67277
[ HIGH ]EPSS 0.7%kev

MikroTik RouterOS Missing Authentication for Critical Function Vulnerability

MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.

MikroTik / RouterOS
CVE-2026-86060
[ HIGH ]EPSS 0.7%kev

MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation.

MikroTik / RouterOS
CVE-2025-25249
[ HIGH ]CVSS 8.1EPSS 2.4%kev

Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

CVSS 8.1 heap overflow in FortiOS, FortiSwitchManager, and FortiSASE allows code execution via crafted packets. Actively exploited in PivotC2 RAT attacks; patched January 2026.

Fortinet / FortiOS, FortiSwitchManager, FortiSASE
$ latest --more

From the desk

all articles →
~/articles/2026-09-11-watchguard-firebox-ransomware-kev-cve-2025-14733
Ransomware Gangs Exploiting WatchGuard Firebox CVSS 9.8 Flaw
● Breaking
cisa kev

Ransomware Gangs Exploiting WatchGuard Firebox CVSS 9.8 Flaw

CISA confirmed ransomware groups now exploit CVE-2025-14733 in WatchGuard Firebox. Patches shipped December 2025; about 9,000 appliances remain exposed.

read →
~/articles/2026-09-10-fortinet-cve-2025-25249-pivotc2-rat-kev
Fortinet Flaw CVE-2025-25249 Used in PivotC2 RAT Attacks
● Breaking
fortinet

Fortinet Flaw CVE-2025-25249 Used in PivotC2 RAT Attacks

CVSS 8.1 heap overflow in FortiOS is exploited with PivotC2 RAT. January 2026 patch available; CISA BOD 26-04 deadline for federal agencies is September 12.

read →
~/articles/2026-09-10-veradigm-patient-breach-gentlemen-ransomware
Veradigm Discloses Patient Breach After Ransomware Claim
● Breaking
ransomware

Veradigm Discloses Patient Breach After Ransomware Claim

Veradigm disclosed a patient data breach traced to a third-party vendor after the Gentlemen ransomware gang claimed responsibility for the attack.

read →
~/articles/2026-09-10-sap-september-patch-day-epp-cvss10-rce
SAP September Patches: CVSS 10 RCE in EPP Processing
sap

SAP September Patches: CVSS 10 RCE in EPP Processing

SAP's September 2026 Security Patch Day includes a CVSS 10.0 unauthenticated RCE in Extended Passport Processing and multiple additional critical updates.

read →
~/articles/2026-09-10-ivanti-september-patches-neurons-itsm-sentry-epmm
Ivanti Patches Critical RCE in Neurons, EPMM, Sentry
ivanti

Ivanti Patches Critical RCE in Neurons, EPMM, Sentry

Ivanti's September 2026 patches close six critical RCEs in Neurons for ITSM and authentication bypass flaws in Sentry and EPMM. Patch now.

read →
~/articles/2026-09-10-cisco-fmc-cve-2026-20079-exploited
Cisco Confirms FMC CVSS 10 Auth Bypass Exploited
● Breaking
cisco

Cisco Confirms FMC CVSS 10 Auth Bypass Exploited

Cisco confirms CVE-2026-20079, CVSS 10.0 FMC auth bypass, is actively exploited. Unauthenticated attackers gain root OS access. CISA KEV deadline September 12.

read →