0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
JFrog Artifactory Incorrect Authorization Vulnerability
JFrog Artifactory validates token signature and issuer but not scope, creating a privilege escalation path. CVSS 8.1 (high), CISA KEV deadline September 25, 2026.
JFrog Artifactory Improper Authentication Vulnerability
JFrog Artifactory returns an internal anonymous-user token to unauthenticated callers even when anonymous access is disabled, allowing unauthorized resource access and enabling privilege escalation chains.
ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
ConnectWise ScreenConnect allows file transfer and execution through active remote sessions without authorization. CVSS 9.9 critical, CISA KEV due September 14.
GitLab Path Traversal Allows Unauthenticated File Read
GitLab CE/EE contains a path traversal flaw due to improper path confinement and missing access controls, allowing an unauthenticated attacker to read arbitrary files from the server.
MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
MikroTik RouterOS btest service missing authentication allows kernel memory disclosure. CVSS 8.2 (high), CISA KEV deadline September 13, 2026.
MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
MikroTik RouterOS SSH login path argument flaw allows unauthenticated privilege escalation. CVSS 9.8 (critical), CISA KEV deadline September 13, 2026.
From the desk

Authorizer CVSS 9.3 Flaw Enables OAuth Token Theft
Authorizer's /authorize endpoint accepted any redirect_uri before v2.2.1, exposing OAuth codes and tokens to theft via crafted flows. Patch to 2.2.1.

CISA KEV: RouterOS Deadline Today, ScreenConnect Tomorrow
CISA added five exploited flaws in MikroTik RouterOS, ConnectWise ScreenConnect, and JFrog Artifactory. Federal patch deadline for RouterOS is today, September 13.

Storm-3121 Fakes Passkey Portals to Steal M365 Data
Microsoft links Storm-3121 (ShinyHunters) and Storm-3032 (Helix) to AiTM and device-code phishing against corporate M365 accounts since May 2026.

Forgejo Patches CVSS 9.9 Template RCE in 16.0.4
Forgejo 16.0.4 fixes CVE-2026-89094, a CVSS 9.9 critical flaw enabling remote code execution via a crafted template repository. No workaround; upgrade now.

Ukrainian Conti Developer Gets 4 Years in US Prison
A Conti ransomware developer arrested in Ireland in 2023 was sentenced to four years in US federal prison for attacks on over 1,000 victims worldwide.

Metasploit Drops 16 Modules, Five on CISA KEV
Rapid7 adds 16 Metasploit modules, 10 exploits, five targeting KEV-listed CVEs in Cisco, PaperCut, SonicWall, JetBrains, and Langflow.
This week's SITREP
Sep 11: Cisco FMC, Fortinet Hit KEV; Sept. 12 Deadline
Cisco FMC CVSS 10.0 auth bypass and Fortinet FortiOS heap overflow confirmed exploited, added to CISA KEV with September 12 deadline. Ivanti patches six critical RCEs. SAP closes CVSS 10.0 EPP flaw.




