Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-88771
[ HIGH ]EPSS 1.0%kev

Citrix NetScaler ADC/Gateway Unauthenticated RCE via Input Validation Flaw

Citrix NetScaler ADC and Gateway improper input validation flaw allows unauthenticated remote code execution; actively exploited and CISA KEV listed.

Citrix / NetScaler ADC, NetScaler Gateway
CVE-2026-88772
[ HIGH ]EPSS 1.2%kev

Citrix NetScaler ADC/Gateway RCE via Memory Buffer Mishandling

Citrix NetScaler ADC and Gateway memory buffer flaw allows remote code execution or denial of service; actively exploited and CISA KEV listed.

Citrix / NetScaler ADC, NetScaler Gateway
CVE-2026-65660
[ HIGH ]CVSS 8.8EPSS 2.1%kev

Microsoft SharePoint Code Injection Vulnerability

A code injection flaw in Microsoft Office SharePoint lets an authorized attacker execute code over a network. CVSS 8.8 (high), active exploitation confirmed, CISA KEV deadline September 28, 2026.

Microsoft / SharePoint
CVE-2026-67279
[ MEDIUM ]CVSS 6.5EPSS 1.0%kev

Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.

MikroTik / RouterOS
CVE-2026-5430
[ CRITICAL ]CVSS 10.0EPSS 0.6%kev

WSO2 Multiple Products Path Traversal to RCE

WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway contain a path traversal flaw enabling unauthenticated file upload and remote code execution. CVSS 10.0. Actively exploited since September 13, 2026; added to CISA KEV September 24.

WSO2 / API Control Plane, API Manager, Traffic Manager, Universal Gateway
CVE-2026-87902
[ HIGH ]CVSS 8.1EPSS 22.5%kev

WordPress core get_page_template path traversal enables unauthenticated RCE

Path traversal in WordPress core's get_page_template() enables unauthenticated local PHP file inclusion and conditional RCE. Actively exploited within 24 hours of disclosure. CVSS 8.1 High.

WordPress / WordPress Core
$ latest --more

From the desk

all articles →
~/articles/2026-09-28-jadepuffer-azure-service-principals-resource-deletion
JADEPUFFER Uses Stolen Service Principals to Destroy Azure
cloud

JADEPUFFER Uses Stolen Service Principals to Destroy Azure

Microsoft Threat Intelligence tracks JADEPUFFER-linked attackers using compromised Azure service principals to delete cloud resources. Audit your tenant's non-human identities now.

read →
~/articles/2026-09-28-shinyhunters-fresh-peoplesoft-campaign-google
ShinyHunters Retooled PeopleSoft Exploit, Google Warns
● Breaking
oracle

ShinyHunters Retooled PeopleSoft Exploit, Google Warns

Google warns ShinyHunters has retooled its CVE-2026-35273 exploit and is running a fresh campaign against Oracle PeopleSoft. Patch or take exposed instances offline now.

read →
~/articles/2026-09-28-bitget-withdrawals-resume-387-million-crypto-heist
Bitget Resumes Withdrawals After $387.5M DPRK Heist
threat intel

Bitget Resumes Withdrawals After $387.5M DPRK Heist

Bitget restored Bitcoin withdrawals September 28, days after suspected North Korean hackers stole $387.5 million from the exchange in a backend compromise.

read →
~/articles/2026-09-28-citrix-netscaler-patches-cve-2026-88771-cve-2026-88772
Citrix Patches NetScaler Zero-Days CVE-2026-88771, -88772
● Breaking
citrix

Citrix Patches NetScaler Zero-Days CVE-2026-88771, -88772

Citrix patched CVE-2026-88771 and CVE-2026-88772 in NetScaler ADC and Gateway. CISA orders federal agencies to apply by September 30.

read →
~/articles/2026-09-28-obot-three-cves-mcp-docker-access-control
Obot AI Platform Patches Three CVEs, Two Critical
mcp

Obot AI Platform Patches Three CVEs, Two Critical

Three GitHub Security Advisories disclose an unauthenticated Docker exposure and two MCP endpoint access control failures in the Obot AI agent platform.

read →
~/articles/2026-09-27-budibase-3-45-0-six-cve-patch
Budibase 3.45.0 Fixes Six Security Flaws
cloud

Budibase 3.45.0 Fixes Six Security Flaws

Budibase 3.45.0 patches six CVEs including arbitrary file write (CVSS 8.8), SSO auth bypass (8.1), and SQL injection (8.0). Update now if Builder is exposed.

read →