0dayNews — Vulnerability & Exploit News
Latest intelligence
all articles →Known Exploited Vulnerabilities
ProFTPD Improper Access Control Vulnerability
ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
ISC BIND Data Processing Errors Vulnerability
ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries.
Apache Struts Command Injection Vulnerability
Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.
ONLYOFFICE Docs Server Path Traversal Vulnerability
ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution.
Strapi Cleartext Storage of Sensitive Information Vulnerability
Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution.
Citrix NetScaler Memory Buffer Flaw Enables Denial-of-Service Attacks
NetScaler ADC and Gateway contain an exploited memory-buffer flaw enabling denial of service. CISA KEV listed October 4, federal deadline October 7.
Latest security news

Citrix NetScaler: Critical CVSS 9.5 RCE, Patch Now
CVE-2026-107406, CVSS 9.5, is a memory overflow in Citrix NetScaler that allows unauthenticated RCE or DoS in SAML-configured deployments. Patch now.

FBI Seizes Domains for Flax Typhoon Breach Tools
The FBI seized seven domains used by Chinese state-sponsored Flax Typhoon to operate MicroScan and FishHub tools in critical infrastructure intrusions.

Cisco Patches Five CVSS 9.8 Flaws in NX-OS
Cisco issued advisories for five critical NX-OS vulnerabilities, all CVSS 9.8, enabling unauthenticated remote code execution with root on Nexus data center switches.

Fake Rabby, OKX Extensions Steal Recovery Phrases
Researchers found 16 malicious Firefox extensions posing as Rabby and OKX wallets, capable of extracting recovery phrases and private keys from cryptocurrency users.

Pwn2Own Ireland Day 2: 45 More Zero-Days, $232K
Day two at Pwn2Own Ireland 2026 added 45 zero-day vulnerabilities and $232,500 in prizes. Samsung Galaxy S26 fell three more times. Vendors have 90 days to patch.

MonsterCloud CEO Charged for Secret Ransom Scheme
Zohar Pinhasi charged with wire fraud after prosecutors allege he secretly paid ransomware operators while billing victims over $19 million for proprietary recovery services.






