Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-102489
[ HIGH ]EPSS 0.6%kev

Zammad GmbH Zammad Session Fixation Vulnerability

Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.

Zammad GmbH / Zammad
CVE-2026-102490
[ HIGH ]EPSS 0.3%kev

Zammad GmbH Zammad Improper Privilege Management Vulnerability

Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.

Zammad GmbH / Zammad
CVE-2026-104286
[ CRITICAL ]CVSS 9.8EPSS 1.8%kev

Fortinet FortiMail Path Traversal and NULL Byte Flaw

Fortinet FortiMail path traversal flaw (CVSS 9.8) lets unauthenticated attackers write arbitrary files. Actively exploited; CISA KEV listed October 1, 2026.

Fortinet / FortiMail
CVE-2026-76504
[ CRITICAL ]CVSS 9.8EPSS 1.6%kev

Cisco Catalyst SD-WAN Manager Authentication Bypass

Unauthenticated attackers can gain admin access to Cisco Catalyst SD-WAN Manager via a URI encoding flaw. CVSS 9.8, actively exploited, CISA KEV listed.

Cisco / Catalyst SD-WAN Manager
CVE-2026-86950
[ HIGH ]CVSS 8.8EPSS 1.2%kev

CoreGraphics memory confusion in Apple iOS 26, iPadOS, macOS 26, macOS 15

CoreGraphics memory confusion flaw in Apple iOS 26, iPadOS, macOS 26, and macOS 15. CVSS 8.8 high. Apple reports possible exploitation in targeted attacks.

Apple / iOS 26, iPadOS, macOS 26, macOS 15
CVE-2026-88771
[ HIGH ]EPSS 1.1%kev

Citrix NetScaler ADC/Gateway Unauthenticated RCE via Input Validation Flaw

Citrix NetScaler ADC and Gateway improper input validation flaw allows unauthenticated remote code execution; actively exploited and CISA KEV listed.

Citrix / NetScaler ADC, NetScaler Gateway
$ latest --more

From the desk

all articles →
~/articles/2026-10-02-pentagon-dmdc-breach-3-million-personnel-records
Pentagon DMDC Breach Hits 3 Million Personnel Files
threat intel

Pentagon DMDC Breach Hits 3 Million Personnel Files

The Pentagon's DMDC is notifying over 3 million service members after attackers breached its HR management system and stole personnel records.

read →
~/articles/2026-10-01-bitget-third-party-zero-day-387m-confirmed
Bitget Confirms Zero-Day Behind $387.5M Crypto Theft
threat intel

Bitget Confirms Zero-Day Behind $387.5M Crypto Theft

Bitget says the $387.5 million theft last week came from a zero-day in an unnamed third-party security product. The CVE and vendor remain undisclosed as the investigation continues.

read →
~/articles/2026-10-01-apple-cve-2026-86950-poc-released-kev-deadline
Apple CoreGraphics PoC Released, KEV Deadline Oct 2
● Breaking
apple

Apple CoreGraphics PoC Released, KEV Deadline Oct 2

A public PoC for CVE-2026-86950 is available as of October 1. CISA's patch deadline for federal agencies is October 2. Affected: iOS 26, iPadOS, macOS 26, macOS 15.

read →
~/articles/2026-10-01-git-hash-chain-malleability-supply-chain-risk
Git Hash Chain Malleability: The Supply Chain Risk
Analysis
supply chain

Git Hash Chain Malleability: The Supply Chain Risk

SHA-1 is still the default in most Git repositories. Here is what hash chain malleability means, what it puts at risk, and how to close the gap.

read →
~/articles/2026-10-01-divd-zammad-zero-day-breach
DIVD Breached via Zammad Zero-Day Chain
threat intel

DIVD Breached via Zammad Zero-Day Chain

The Dutch Institute for Vulnerability Disclosure confirms attackers exploited two unpatched Zammad zero-days to breach its internal network. No CVE IDs assigned yet.

read →
~/articles/2026-10-01-cisco-sd-wan-manager-cve-2026-76504-exploited
Cisco SD-WAN Manager Auth Bypass Exploited: Patch Now
● Breaking
cisco

Cisco SD-WAN Manager Auth Bypass Exploited: Patch Now

CVE-2026-76504, an authentication bypass in Cisco SD-WAN Manager rated CVSS 9.8, is under active exploitation. Federal agencies must patch by October 3.

read →