Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-65660
[ HIGH ]CVSS 8.8EPSS 1.2%kev

Microsoft SharePoint Code Injection Vulnerability

Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.

Microsoft / SharePoint
CVE-2026-67279
[ MEDIUM ]CVSS 6.5EPSS 0.7%kev

Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.

MikroTik / RouterOS
CVE-2026-5430
[ CRITICAL ]CVSS 10.0EPSS 0.6%kev

WSO2 Multiple Products Path Traversal to RCE

WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway contain a path traversal flaw enabling unauthenticated file upload and remote code execution. CVSS 10.0. Actively exploited since September 13, 2026; added to CISA KEV September 24.

WSO2 / API Control Plane, API Manager, Traffic Manager, Universal Gateway
CVE-2026-87902
[ HIGH ]CVSS 8.1EPSS 2.9%kev

WordPress core get_page_template path traversal enables unauthenticated RCE

Path traversal in WordPress core's get_page_template() enables unauthenticated local PHP file inclusion and conditional RCE. Actively exploited within 24 hours of disclosure. CVSS 8.1 High.

WordPress / WordPress Core
CVE-2026-93616
[ CRITICAL ]CVSS 9.8EPSS 19.7%kev

Check Point Multiple Products Path Traversal Vulnerability

CVE-2026-93616: CVSS 9.8 path traversal and file upload in Check Point Management Server enabling unauth RCE. Confirmed exploited; patches available.

Check Point / Security Management Server, Multi-Domain Management Server, Log Server, SmartEvent
CVE-2026-93952
[ CRITICAL ]CVSS 10.0EPSS 0.9%kev

Arista VeloCloud Orchestrator Unauthenticated RCE

“CVE-2026-93952 is a CVSS 10.0 improper input validation flaw in Arista VeloCloud Orchestrator that allows unauthenticated remote code execution. Added to CISA KEV on September 22, 2026.”

Arista / VeloCloud Orchestrator
$ latest --more

From the desk

all articles →
~/articles/2026-09-24-roundcube-cve-2026-48842-active-exploit-sql-injection
Roundcube SQL Injection Flaw Under Active Attack
threat intel

Roundcube SQL Injection Flaw Under Active Attack

Canada's CCCS confirmed active exploitation of CVE-2026-48842, a SQL injection in Roundcube Webmail patched in May. Upgrade to 1.6.16 or 1.7.1 now.

read →
~/articles/2026-09-24-solarwinds-observability-cve-2026-28324-28325-rce
SolarWinds Fixes Two Unauth RCE Flaws in Observability
solarwinds

SolarWinds Fixes Two Unauth RCE Flaws in Observability

SolarWinds patches CVE-2026-28324 (CVSS 9.8) and CVE-2026-28325 (CVSS 8.8), two unauthenticated RCE flaws in Observability Self-Hosted. No active exploitation reported.

read →
~/articles/2026-09-24-teamcity-cve-2026-63077-cisa-ransomware-kev
CISA: Ransomware Gangs Exploiting TeamCity RCE Flaw
● Breaking
ransomware

CISA: Ransomware Gangs Exploiting TeamCity RCE Flaw

CISA warns federal agencies that ransomware groups are exploiting CVE-2026-63077, a CVSS 9.8 unauthenticated RCE in JetBrains TeamCity. Patch released July 28.

read →
~/articles/2026-09-24-infratrust-nms-network-management-attacks-rising
InfraTrust: Network Management Systems Under Attack
threat intel

InfraTrust: Network Management Systems Under Attack

InfraTrust's September report finds attackers targeting network management and control infrastructure at or before patch availability. Here's what to prioritize.

read →
~/articles/2026-09-24-wordpress-core-cve-2026-87902-path-traversal-exploited
WordPress Core RCE Flaw CVE-2026-87902 Under Active Exploit
● Breaking
wordpress

WordPress Core RCE Flaw CVE-2026-87902 Under Active Exploit

WordPress core path traversal CVE-2026-87902 allows unauthenticated RCE under specific conditions. Exploitation confirmed within 24 hours. CVSS 8.1 High.

read →
~/articles/2026-09-23-d-link-dir-822a-cve-2026-86296-no-patch
D-Link Warns CVSS 10.0 DIR-822A Flaw Has No Fix
d link

D-Link Warns CVSS 10.0 DIR-822A Flaw Has No Fix

CVE-2026-86296: CVSS 10.0 D-Link DIR-822A zero-day with public PoC exploit code and no patch. D-Link says the device is end-of-life and replacement is needed.

read →