Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-69836
[ CRITICAL ]CVSS 10.0EPSS 1.4%kev

Microsoft Entra ID Deserialization of Untrusted Data Vulnerability

Microsoft Entra ID formerly known as Azure Active Directory contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.

Microsoft / Entra ID
CVE-2026-73570
[ HIGH ]CVSS 8.9EPSS 0.5%kev

Zimbra ZCS SNMP Command Injection — Unauthenticated RCE

CVE-2026-73570 — CVSS 8.9 command injection in Zimbra Collaboration Suite's SNMP handler enables unauthenticated remote code execution. Actively exploited in the wild. Patch: Zimbra 10.1.20.

Synacor / Zimbra Collaboration Suite (ZCS)
CVE-2026-72529
[ CRITICAL ]CVSS 9.8EPSS 0.8%kev

TrueConf Server Missing Authentication for Critical Function Vulnerability

TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.

TrueConf / Server
CVE-2026-72530
[ CRITICAL ]CVSS 9.0EPSS 1.0%kev

TrueConf Server Code Injection Vulnerability

TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.

TrueConf / Server
CVE-2026-33824
[ CRITICAL ]CVSS 9.8EPSS 77.9%kev

Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.

Microsoft / Internet Key Exchange (IKE) Service Extensions
CVE-2026-64849
[ CRITICAL ]CVSS 9.3EPSS 8.2%kev

MLflow SSRF Lets Attackers Steal Cloud Credentials via Metadata Services

A server-side request forgery in MLflow before 3.15.0 allows unauthenticated access to internal endpoints including cloud metadata services, enabling cloud credential and IAM secret theft.

MLflow / MLflow (< 3.15.0)
$ latest --more

From the desk

all articles →
~/articles/2026-08-20-citrix-netscaler-auth-bypass-cve-2026-19490
Citrix Patches Critical NetScaler Auth Bypass
citrix

Citrix Patches Critical NetScaler Auth Bypass

Citrix patches CVE-2026-19490, critical auth bypass in NetScaler ADC and Gateway, CVSS 9.3. No exploitation observed yet — here's what to patch before that changes.

read →
~/articles/2026-08-19-ransom-busters-ransomware-recovery-scam
Ransomware Affiliate Poses as Data Recovery Service
ransomware

Ransomware Affiliate Poses as Data Recovery Service

A ransomware affiliate calling itself Ransom Busters is emailing victims and offering to delete their stolen data from ransomware groups' servers for fees of $20,000 to $60,000.

read →
~/articles/2026-08-19-apple-ios-ipados-macos-tahoe-27-vulns-patch
Apple Patches 27 Flaws in iOS, iPadOS, and macOS Tahoe
apple

Apple Patches 27 Flaws in iOS, iPadOS, and macOS Tahoe

Apple released updates fixing 27 vulnerabilities across iOS, iPadOS, and macOS Tahoe. One image-processing flaw carries code execution risk — patch this week, not next.

read →
~/articles/2026-08-19-china-ai-apac-nation-state-attack
China-Linked AI Framework Hits APAC Government Targets
threat intel

China-Linked AI Framework Hits APAC Government Targets

A Chinese-language operator used a complex AI framework to compromise APAC government agencies in what researchers call the first purported near-autonomous nation-state attack.

read →
~/articles/2026-08-18-medusa-ransomware-500-victims-cisa-fbi
CISA, FBI: Medusa Ransomware Has 500+ Victims
ransomware

CISA, FBI: Medusa Ransomware Has 500+ Victims

CISA and the FBI updated their Medusa ransomware advisory, confirming the group has hit more than 500 organizations in critical infrastructure since 2021.

read →
~/articles/2026-08-18-cosnitch-copilot-personal-data-exfiltration
CoSnitch: Three Copilot Flaws Enable One-Click Data Theft
microsoft

CoSnitch: Three Copilot Flaws Enable One-Click Data Theft

Varonis Threat Labs found three flaws in Microsoft Copilot Personal, named CoSnitch, that let attackers silently pull data from all connected apps in one click.

read →