Skip to content
feed: live
>_ 0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-20349
[ HIGH ] CVSS 8.6 kev

Cisco ASA and FTD VPN Heap Inspection Denial-of-Service Flaw

Unauthenticated remote attackers can crash Cisco Secure Firewall ASA and FTD devices over VPN. Added to CISA KEV on 2026-08-11 with a three-day federal remediation deadline.

Cisco / Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
CVE-2026-68820
[ HIGH ] CVSS 7.0 kev

Windows AFD WinSock Use-After-Free Privilege Escalation

Use-after-free in Windows Ancillary Function Driver for WinSock (afd.sys) lets local attackers gain SYSTEM privileges via race condition. Actively exploited by Lazarus.

Microsoft / Windows (multiple versions)
CVE-2026-72898
[ CRITICAL ] CVSS 10.0 EPSS 0.7% kev

Metabase SQL Injection Vulnerability

Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.

Metabase / Metabase
CVE-2026-18556
[ HIGH ] CVSS 7.4 EPSS 0.5% kev

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.

N-able / N-central
CVE-2026-34486
[ HIGH ] CVSS 7.5 EPSS 82.9% kev

Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.

Apache / Tomcat
CVE-2026-9198
[ CRITICAL ] CVSS 9.8 EPSS 17.4% kev

IBM Langflow Code Injection Vulnerability

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

IBM / Langflow
$ latest --more

From the desk

all articles →
~/articles/2026-08-11-cisco-asa-ftd-cve-2026-20349-kev-dos-vpn
Cisco ASA/FTD VPN Flaw Exploited, CISA Sets Aug 14 Deadline
● Breaking
cisco

Cisco ASA/FTD VPN Flaw Exploited, CISA Sets Aug 14 Deadline

CVE-2026-20349 added to CISA KEV today. Unauthenticated attackers can crash Cisco ASA and FTD devices over VPN — CISA's due date is August 14.

read →
~/articles/2026-08-11-zoom-annotation-zero-click-rce
Zero-Click RCE in Zoom Annotation — Patch Now
zoom

Zero-Click RCE in Zoom Annotation — Patch Now

A flaw in Zoom's annotation tool let any meeting participant execute code on another attendee's machine — zero clicks required. Update Zoom clients now.

read →
~/articles/2026-08-11-microsoft-patch-tuesday-august-2026
Microsoft Patches 400 Flaws, Lazarus Exploited One First
● Breaking
microsoft

Microsoft Patches 400 Flaws, Lazarus Exploited One First

Microsoft's August Patch Tuesday hits 400+ flaws. One is actively exploited by Lazarus via afd.sys. Two more are publicly disclosed. Here's your triage stack.

read →
~/articles/2026-08-11-adobe-coldfusion-campaign-classic-aug-patches
Adobe Patches Critical Flaws in ColdFusion, Campaign Classic
adobe

Adobe Patches Critical Flaws in ColdFusion, Campaign Classic

Adobe patches critical RCE and DoS flaws in ColdFusion and Campaign Classic. Arbitrary code execution risk confirmed. Adobe explicitly urges immediate patching — act now.

read →
~/articles/2026-08-11-malicious-sim-code-exec-cellular-iot-modules
Rogue SIM Cards Execute Attacker Code on Industrial Modems
ics ot

Rogue SIM Cards Execute Attacker Code on Industrial Modems

SIM Toolkit commands give rogue SIMs code execution on cellular modules in EV chargers, industrial routers, and car telematics units, University of Birmingham and Fuzzware researchers confirm.

read →
~/articles/2026-08-11-sharepoint-cve-2026-45659-ransomware-confirmed
SharePoint CVE-2026-45659 Ransomware Attacks Confirmed
● Breaking
microsoft

SharePoint CVE-2026-45659 Ransomware Attacks Confirmed

CISA confirms ransomware gangs are exploiting CVE-2026-45659, the SharePoint deserialization RCE on KEV since July. Patch the May update now.

read →