Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-42016
[ HIGH ]CVSS 8.1EPSS 0.3%kev

JFrog Artifactory Incorrect Authorization Vulnerability

JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

JFrog / Artifactory
CVE-2026-42018
[ HIGH ]CVSS 7.5EPSS 0.3%kev

JFrog Artifactory Improper Authentication Vulnerability

JFrog Artifactory returns an internal anonymous-user token to unauthenticated callers even when anonymous access is disabled, allowing unauthorized resource access and enabling privilege escalation chains.

JFrog / Artifactory
CVE-2026-84869
[ CRITICAL ]CVSS 9.9EPSS 0.4%kev

ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation.

ConnectWise / ScreenConnect
CVE-2026-85706
[ CRITICAL ]CVSS 10.0kev

GitLab Path Traversal Allows Unauthenticated File Read

GitLab CE/EE contains a path traversal flaw due to improper path confinement and missing access controls, allowing an unauthenticated attacker to read arbitrary files from the server.

GitLab / GitLab CE/EE
CVE-2026-67277
[ HIGH ]EPSS 0.7%kev

MikroTik RouterOS Missing Authentication for Critical Function Vulnerability

MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.

MikroTik / RouterOS
CVE-2026-86060
[ HIGH ]EPSS 0.7%kev

MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation.

MikroTik / RouterOS
$ latest --more

From the desk

all articles →
~/articles/2026-09-12-gitlab-cve-2026-85706-path-traversal-kev
GitLab CVSS 10 Path Traversal Exploited Same Day as Patch
● Breaking
gitlab

GitLab CVSS 10 Path Traversal Exploited Same Day as Patch

CVE-2026-85706 lets an unauthenticated attacker read any file on a GitLab server. Exploitation probes started within hours of Thursday's patch release. CISA has it in KEV.

read →
~/articles/2026-09-11-check-point-vpn-cve-2026-85102-85103-rce
Check Point Patches Two CVSS 9.8 VPN RCE Flaws
check point

Check Point Patches Two CVSS 9.8 VPN RCE Flaws

CVE-2026-85102 and CVE-2026-85103 allow unauthenticated RCE via VPN certificate handling in Check Point firewall products. Patches are out now.

read →
~/articles/2026-09-11-cisco-fmc-qilin-three-threat-clusters
Cisco FMC Hit by Qilin Ransomware, State-Sponsored Actors
● Breaking
cisco

Cisco FMC Hit by Qilin Ransomware, State-Sponsored Actors

Cisco Talos: three threat clusters exploit Cisco FMC CVE-2026-20079. Qilin ransomware deployed; credential theft observed. CISA deadline September 12.

read →
~/articles/2026-09-11-papercut-smr-ai-attacks
PaperCut Issues Stable Fix as AI-Powered Attacks Widen
● Breaking
threat intel

PaperCut Issues Stable Fix as AI-Powered Attacks Widen

PaperCut's SMR replaces all emergency patches for CVE-2026-81578 and CVE-2026-82078. AI-assisted attacks are active against hundreds of organizations.

read →
~/articles/2026-09-11-cisa-kev-sept12-cisco-citrix-fortinet
CISA Sept. 12: Patch Cisco, Citrix, Fortinet Today
● Breaking
cisa kev

CISA Sept. 12: Patch Cisco, Citrix, Fortinet Today

CISA's September 12 deadline covers confirmed exploited flaws in Cisco FMC, Citrix NetScaler, and Fortinet FortiOS. Federal agencies must patch by tomorrow; everyone else should be moving too.

read →
~/articles/2026-09-11-nightmare-eclipse-shieldcrash-windows-defender
Nightmare Eclipse Drops Windows Defender Zero-Day
microsoft

Nightmare Eclipse Drops Windows Defender Zero-Day

Nightmare Eclipse's ShieldCrash exploit achieves SYSTEM privileges on fully patched Windows systems by targeting Windows Defender itself.

read →