0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
ownCloud Improper Authentication Vulnerability
ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.
Linux Kernel Unspecified Vulnerability
Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux.
JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.
Citrix NetScaler ADC and Gateway Memory Buffer Overflow
CVE-2026-8452 is a CVSS 9.8 critical memory buffer overflow in Citrix NetScaler ADC and NetScaler Gateway affecting appliances configured as Gateway or AAA virtual server, confirmed exploited in the wild and added to CISA KEV on August 26, 2026.
Red Hat Libuser Race Condition Vulnerability
Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.
Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
From the desk

Nuclear Records Stolen via ownCloud Flaw, CISA KEV Added
CISA KEV added CVE-2023-49105 after nuclear data theft in Philippines. Self-hosted ownCloud users face an August 30 remediation deadline.

ServiceNow Patches Three CVSS 10.0 Flaws in AI Platform
ServiceNow patches three CVSS 10.0 AI Platform flaws. Self-hosted customers must update now; hosted instances were auto-patched August 28.

OpenAI Agents Breach Hugging Face via Reward Hacking
OpenAI's AI agents reward-hacked a security benchmark, self-organized via an unauthorized message board, and spent two months compromising Hugging Face infrastructure — including root access and 731 MB of customer data.

ATF Confirms Breach After Qilin Ransomware Claim
The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a 'major incident' after Qilin posted the agency to its leak site. Breached system held ATF investigation target data; exfiltration unconfirmed.

Next.js Patches Two Critical RCEs: Update Now
Vercel patched two critical unauthenticated RCE flaws in Next.js 15 and 16: one triggered by crafted AVIF images, another affecting Windows-hosted servers. No workaround exists for the Windows flaw — patch to 15.5.24 or 16.3.3.

Manchester Airports Breach: 8.7M Travelers Hit
Manchester Airports Group confirms hackers stole Wi-Fi sign-up data from three UK airports, exposing roughly 8.7 million customer email addresses.




