Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-85046
[ HIGH ]CVSS 8.8EPSS 0.9%kev

Type confusion in Chrome V8 allows sandbox code execution

Type confusion in Chrome's V8 engine lets remote attackers run arbitrary code inside the browser sandbox via a crafted HTML page. Actively exploited; update to 152.0.7977.82.

Google / Chrome (before 152.0.7977.82)
CVE-2026-48710
[ MEDIUM ]CVSS 6.5EPSS 36.3%kev

Kludex Starlette HTTP Request/Response Smuggling Vulnerability

Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.

Kludex / Starlette
CVE-2026-49869
[ CRITICAL ]CVSS 10.0EPSS 1.9%kev

Kestra OSS OS Command Injection Vulnerability

Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.

Kestra / Kestra OSS
CVE-2026-59822
[ HIGH ]CVSS 8.2EPSS 0.9%kev

BerriAI LiteLLM Improper Authentication Vulnerability

BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.

BerriAI / LiteLLM
CVE-2026-9586
[ HIGH ]EPSS 11.8%kev

Sangoma Switchvox SQL Injection Vulnerability

Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

Sangoma / Switchvox
CVE-2026-83548
[ HIGH ]EPSS 0.7%kev

Pre-auth SSRF in SonicWall SMA1000 Workplace Interface

Unauthenticated SSRF in the SMA1000 Workplace interface allows remote attackers to reach internal functionality via an unintended access path. Exploited in the wild; chains with CVE-2026-83549 for RCE.

SonicWall / SMA1000
$ latest --more

From the desk

all articles →
~/articles/2026-09-05-postgresql-logical-decoding-replication-rce
PostgreSQL Patches 12-Year-Old Logical Decoding RCE
cloud

PostgreSQL Patches 12-Year-Old Logical Decoding RCE

PostgreSQL patches a 12-year-old flaw in its logical decoding subsystem. Accounts with the REPLICATION attribute could execute code on the underlying host.

read →
~/articles/2026-09-05-entra-id-cve-2026-62916-auth-bypass
Microsoft Patches Entra ID CVSS 9.1 Auth Bypass
microsoft

Microsoft Patches Entra ID CVSS 9.1 Auth Bypass

A CVSS 9.1 auth bypass in Microsoft Entra ID lets unauthenticated attackers escalate privileges. Second critical Entra flaw in three weeks; patch available.

read →
~/articles/2026-09-05-citrix-netscaler-cve-2026-19490-exploited
Citrix NetScaler Auth Bypass Now Exploited in Wild
citrix

Citrix NetScaler Auth Bypass Now Exploited in Wild

Attackers are actively targeting CVE-2026-19490, a critical auth bypass in Citrix NetScaler ADC and Gateway. Patches have been available since August 19.

read →
~/articles/2026-09-04-hpe-arubaos-cx-cve-2026-73749-critical-rce
HPE Patches CVSS 9.8 RCE in ArubaOS-CX Switches
threat intel

HPE Patches CVSS 9.8 RCE in ArubaOS-CX Switches

HPE's advisory for ArubaOS-CX covers 24 flaws, led by CVE-2026-73749 — an unauthenticated buffer overflow rated 9.8 that allows remote code execution on data center switches.

read →
~/articles/2026-09-04-chrome-v8-cve-2026-85046-zero-day-exploited
Chrome Patches Exploited V8 Zero-Day: Update Now
● Breaking
browser

Chrome Patches Exploited V8 Zero-Day: Update Now

CVE-2026-85046 is a type confusion bug in Chrome's V8 engine, CVSS 8.8, actively exploited in the wild. Update to Chrome 152.0.7977.82 or later immediately.

read →
~/articles/2026-09-04-all-in-one-wp-migration-cve-2026-19949-sql-injection
All-in-One WP Migration Flaw Hits 3M WordPress Sites
wordpress

All-in-One WP Migration Flaw Hits 3M WordPress Sites

Unauthenticated SQL injection in All-in-One WP Migration and Backup plugin (versions through 7.109) enables data theft and conditional RCE. Update immediately.

read →