Skip to content
feed: live
>_ 0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-18556
[ HIGH ] CVSS 7.4 EPSS 0.5% kev

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.

N-able / N-central
CVE-2026-34486
[ HIGH ] CVSS 7.5 EPSS 81.2% kev

Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.

Apache / Tomcat
CVE-2026-9198
[ CRITICAL ] CVSS 9.8 EPSS 17.1% kev

IBM Langflow Code Injection Vulnerability

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

IBM / Langflow
CVE-2026-18577
[ HIGH ] EPSS 4.1% kev

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.

N-able / N-central
CVE-2026-20316
[ MEDIUM ] CVSS 5.3 EPSS 0.8% kev

Hard-coded credential in Cisco Secure FMC enables unauthenticated login

Cisco Secure FMC ships a static low-privileged account; remote unauthenticated attackers can log in and access sensitive data. CISA KEV confirmed July 29, 2026.

Cisco / Cisco Secure Firewall Management Center (FMC)
CVE-2026-21513
[ HIGH ] CVSS 8.8 EPSS 15.4% kev

Microsoft MSHTML security feature bypass

Protection mechanism failure in Microsoft MSHTML lets unauthenticated attackers bypass a security feature over the network. CVSS 8.8, patched in Microsoft's February 2026 Patch Tuesday.

Microsoft / MSHTML Framework (Windows)
$ latest --more

From the desk

all articles →
~/articles/2026-08-09-mcp-server-ssrf-path-traversal-ten-cves-one-day
Ten MCP Server CVEs Drop in a Single Day
Analysis
threat intel

Ten MCP Server CVEs Drop in a Single Day

Ten MCP server CVEs hit NVD on August 9 — all SSRF or path traversal. Same two classes, ten different projects, most maintainers silent on coordinated disclosure.

read →
~/articles/2026-08-09-ash-framework-cve-2026-69659-cve-2026-70395
Ash Framework: OOM Cursor Bomb and Auth Bypass
threat intel

Ash Framework: OOM Cursor Bomb and Auth Bypass

Ash (Elixir) gets two CVEs: an OOM-bomb via keyset pagination cursor and an auth bypass via query injection in managed relationships. Upgrade now.

read →
~/articles/2026-08-08-kemp-loadmaster-cve-2026-8037-cisa-kev
Kemp LoadMaster CVE-2026-8037 Lands on CISA KEV
● Breaking
progress

Kemp LoadMaster CVE-2026-8037 Lands on CISA KEV

CISA added the critical Kemp LoadMaster command-injection flaw to its KEV catalog Friday after 792 reported exploitation attempts. If you haven't patched since June 4, that window is closed.

read →
~/articles/2026-08-07-langflow-cve-2026-9198-unauth-rce-public-poc
Public PoC Lands for Langflow's 9.8 Unauth RCE — Patch to 1.10.1 Now
langflow

Public PoC Lands for Langflow's 9.8 Unauth RCE — Patch to 1.10.1 Now

CVE-2026-9198 lets an unauthenticated network caller reach full remote code execution on default Langflow deployments. It's on CISA's KEV list, it's exploited, and a public proof-of-concept is now out.

read →
~/articles/2026-08-06-apache-tomcat-cve-2026-34486-encryptinterceptor-kev
Apache Tomcat EncryptInterceptor Bypass Added to KEV — Patch by Aug 7
apache

Apache Tomcat EncryptInterceptor Bypass Added to KEV — Patch by Aug 7

CVE-2026-34486 lets attackers bypass Tomcat's EncryptInterceptor, exposing clustered node traffic. CISA added it to KEV on Aug 4 after active exploitation. Fixed builds are out.

read →
~/articles/2026-08-06-n-able-n-central-cve-2026-18577-kev-auth-bypass
CISA Flags N-able N-central Auth Bypass — Patch Before Today's Deadline
supply chain

CISA Flags N-able N-central Auth Bypass — Patch Before Today's Deadline

CVE-2026-18577, an authentication bypass in N-able N-central, is on CISA's KEV list after active exploitation. It's an incomplete fix for an earlier flaw, and MSPs are the blast radius.

read →