0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Hard-coded credential in Cisco Secure FMC enables unauthenticated login
Cisco Secure FMC ships a static low-privileged account; remote unauthenticated attackers can log in and access sensitive data. CISA KEV confirmed July 29, 2026.
Arista VeloCloud Orchestrator OS Command Injection
CVSS 10.0 critical. Remote attackers can inject OS commands into Arista VeloCloud Orchestrator On-Prem, compromising the SD-WAN management plane.
Check Point SmartConsole improper authentication
CVE-2026-16232 lets unauthenticated attackers grab an admin token from SmartConsole. CISA KEV addition July 22; Check Point confirms active exploitation.
DD-WRT SSDP Stack-Based Buffer Overflow (UPnP)
An unsafe strcpy in DD-WRT's SSDP handling lets an unauthenticated attacker overflow an internal buffer via the UPnP listener and trigger code execution. Added to CISA KEV on 2026-07-21.
Fortinet FortiSandbox unauthenticated OS command injection (4.2, 4.4, 5.0, Cloud, PaaS)
An unauthenticated OS command injection across FortiSandbox 4.2, 4.4, 5.0, plus FortiSandbox Cloud and PaaS 5.0 lets a network attacker run arbitrary commands via crafted HTTP requests. CVSS 9.8; CISA-listed KEV.
Oracle E-Business Suite Payments improper privilege management (unauth RCE)
A critical improper-privilege-management flaw in the Oracle Payments component of Oracle E-Business Suite (File Transmission) that lets an unauthenticated network attacker take over Oracle Payments. Patched in Oracle's May 2026 Critical Patch Update; added to CISA KEV on July 15, 2026.
From the desk

OWAReaper Backdoor Outlasts Credential Rotation
Updated: OWAReaper maintains Exchange mailbox access after credential rotation. Targeted sectors confirmed: US and EU government, telecom, finance, aerospace.

FCC Bars New Foreign Robots, Power Inverters on Cyber Risk
The FCC added foreign-produced mobile robots and networked power inverters to its Covered List on July 28, blocking new models from US equipment authorization.

Amazon Ties Sapphire Sleet to npm debug, chalk Hijack
Amazon attributes the September 2025 npm hijack of debug and chalk — over 2 billion combined weekly downloads — to North Korea's Sapphire Sleet APT group.

73% Not Ready: The IR Gap Is Coordination, Not Tools
New IR readiness research finds most security teams have the plans, tools, and staff — but still lack the coordination and exec alignment that determine whether any of it works under pressure.

AI Cracks HAWK-256 Post-Quantum Scheme, Speeds AES
Anthropic's Claude Mythos broke HAWK-256 and found a 200–800x speedup on 7-round AES-128, tightening post-quantum migration timelines.

AI Speeds Linux Kernel Exploit: CVE-2026-53264 Local Root
STAR Labs published a working exploit for CVE-2026-53264 (CVSS 7.8), a use-after-free race in the Linux kernel traffic-control subsystem. AI accelerated discovery and exploit development on CentOS Stream 9.




