0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
DD-WRT SSDP Stack-Based Buffer Overflow (UPnP)
An unsafe strcpy in DD-WRT's SSDP handling lets an unauthenticated attacker overflow an internal buffer via the UPnP listener and trigger code execution. Added to CISA KEV on 2026-07-21.
Fortinet FortiSandbox unauthenticated OS command injection (4.2, 4.4, 5.0, Cloud, PaaS)
An unauthenticated OS command injection across FortiSandbox 4.2, 4.4, 5.0, plus FortiSandbox Cloud and PaaS 5.0 lets a network attacker run arbitrary commands via crafted HTTP requests. CVSS 9.8; CISA-listed KEV.
Oracle E-Business Suite Payments improper privilege management (unauth RCE)
A critical improper-privilege-management flaw in the Oracle Payments component of Oracle E-Business Suite (File Transmission) that lets an unauthenticated network attacker take over Oracle Payments. Patched in Oracle's May 2026 Critical Patch Update; added to CISA KEV on July 15, 2026.
SonicWall SMA1000 unauthenticated SSRF in Work Place portal
An unauthenticated server-side request forgery in the SonicWall SMA1000 Work Place web interface lets a remote attacker force the appliance to make requests to attacker-chosen destinations. Actively exploited; on CISA KEV.
SonicWall SMA1000 post-authentication OS command injection
A post-authentication OS command injection in the SonicWall SMA1000 lets an administrator execute arbitrary OS commands on the appliance. Actively exploited alongside CVE-2026-15409; on CISA KEV.
AD FS elevation of privilege — insufficient access-control granularity
Active Directory Federation Services access-control granularity flaw lets an authorized attacker escalate privileges locally. Exploited in the wild; added to CISA KEV 2026-07-14.
From the desk

Zimbra 10.1.20 patches nine, SNMP injection at the top
Zimbra 10.1.20 fixes nine vulnerabilities including an SNMP command injection when notifications are enabled. Patch if you self-host — CVEs pending.

Kratos phishing platform seized. M365 exposure is not.
German BKA and US authorities dismantled Kratos PhaaS and arrested its developer in Indonesia. Passkey rollout still matters more than the takedown headline.

SharePoint attackers stealing keys — rotate credentials now
watchTowr says attackers exploiting CVE-2026-50522 are stealing SharePoint machine keys for post-patch persistence. Rotate credentials — patching alone won't help.

Patch-to-exploit is hours. Patching still isn't optional.
A vendor-sponsored piece at The Hacker News argues N-day exploitation now runs on N-hour timescales. The observation is right. The takeaway isn't.

Anubis claims Fairlife hit, 1TB and Nutanix encrypted
Anubis ransomware has claimed the July 16 Coca-Cola Fairlife attack, alleging ~1TB stolen and full Nutanix encryption. Coca-Cola declined to comment; BleepingComputer could not verify.

Apple fixes Hide My Email leak, year after disclosure
Apple deployed a July 3 fix for a Hide My Email flaw that unmasked real addresses in Mail logs — disclosed to Apple over a year earlier per 404 Media.




