Skip to content
feed: live
>_ 0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2021-27137
[ HIGH ] CVSS 8.1 kev

DD-WRT SSDP Stack-Based Buffer Overflow (UPnP)

An unsafe strcpy in DD-WRT's SSDP handling lets an unauthenticated attacker overflow an internal buffer via the UPnP listener and trigger code execution. Added to CISA KEV on 2026-07-21.

DD-WRT / DD-WRT router firmware (builds prior to revision 45724)
CVE-2026-25089
[ CRITICAL ] CVSS 9.8 kev

Fortinet FortiSandbox unauthenticated OS command injection (4.2, 4.4, 5.0, Cloud, PaaS)

An unauthenticated OS command injection across FortiSandbox 4.2, 4.4, 5.0, plus FortiSandbox Cloud and PaaS 5.0 lets a network attacker run arbitrary commands via crafted HTTP requests. CVSS 9.8; CISA-listed KEV.

Fortinet / FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS (multiple 4.x and 5.0 lines — see body)
CVE-2026-46817
[ CRITICAL ] CVSS 9.8 kev

Oracle E-Business Suite Payments improper privilege management (unauth RCE)

A critical improper-privilege-management flaw in the Oracle Payments component of Oracle E-Business Suite (File Transmission) that lets an unauthenticated network attacker take over Oracle Payments. Patched in Oracle's May 2026 Critical Patch Update; added to CISA KEV on July 15, 2026.

Oracle / E-Business Suite — Oracle Payments (versions 12.2.3–12.2.15)
CVE-2026-15409
[ CRITICAL ] CVSS 10.0 kev

SonicWall SMA1000 unauthenticated SSRF in Work Place portal

An unauthenticated server-side request forgery in the SonicWall SMA1000 Work Place web interface lets a remote attacker force the appliance to make requests to attacker-chosen destinations. Actively exploited; on CISA KEV.

SonicWall / SMA1000 Series (6210, 7210, 8200v)
CVE-2026-15410
[ HIGH ] CVSS 7.2 kev

SonicWall SMA1000 post-authentication OS command injection

A post-authentication OS command injection in the SonicWall SMA1000 lets an administrator execute arbitrary OS commands on the appliance. Actively exploited alongside CVE-2026-15409; on CISA KEV.

SonicWall / SMA1000 Series (6210, 7210, 8200v)
CVE-2026-56155
[ HIGH ] CVSS 7.8 kev

AD FS elevation of privilege — insufficient access-control granularity

Active Directory Federation Services access-control granularity flaw lets an authorized attacker escalate privileges locally. Exploited in the wild; added to CISA KEV 2026-07-14.

Microsoft / Active Directory Federation Services (AD FS) — see MSRC advisory for affected builds
$ latest --more

From the desk

all articles →
~/articles/2026-07-21-bit2watt-zhejiang-ches-2026-gpu-cloud-tenant-grid-swings-analysis
Bit2Watt: what the GPU cloud tenant abstracts away
Analysis
threat intel

Bit2Watt: what the GPU cloud tenant abstracts away

Three Zhejiang researchers say ordinary GPU access can swing a data-center's load fast enough to strain its grid. Worst-case sim; the gap under it is real.

read →
~/articles/2026-07-21-qilin-pan-os-cve-2026-0257-globalprotect-arctic-wolf-june-exploitation
Qilin exploits PAN-OS GlobalProtect CVE-2026-0257
● Breaking
palo alto networks

Qilin exploits PAN-OS GlobalProtect CVE-2026-0257

Arctic Wolf documents Qilin ransomware breaching networks through a two-month-old PAN-OS GlobalProtect authentication bypass, and assesses with moderate confidence that intrusions are ongoing.

read →
~/articles/2026-07-21-microsoft-wsus-manual-fix-susdb-cleanup-maxxml-reindex-iisreset
Microsoft ships manual WSUS fix: SUSDB cleanup, IISReset
microsoft

Microsoft ships manual WSUS fix: SUSDB cleanup, IISReset

Microsoft published the WSUS unstick procedure Monday: back up SUSDB, run the cleanup query, restore MaxXMLPerRequest, reindex, wizard, IISReset.

read →
~/articles/2026-07-21-acros-0patch-legacyhive-free-micropatches-windows-10-server-2019
0patch ships free unofficial fix for LegacyHive zero-day
microsoft

0patch ships free unofficial fix for LegacyHive zero-day

ACROS Security (0patch) shipped free micropatches for the unpatched LegacyHive LPE — Windows 10 2004 and Server 2019 up. Microsoft is still investigating.

read →
~/articles/2026-07-21-jetbrains-teamcity-cve-2024-27198-epss-0999-two-years-past-patch
TeamCity CVE-2024-27198: EPSS 0.999 two years past patch
● Breaking
jetbrains

TeamCity CVE-2024-27198: EPSS 0.999 two years past patch

JetBrains TeamCity's 2024 auth-bypass still ranks EPSS 0.999 more than two years post patch. Internet-facing build servers keep the exposed population alive.

read →
~/articles/2026-07-21-signature-was-there-trust-wasnt-week-retrospective
The signature was there. The trust wasn't.
Analysis
threat intel

The signature was there. The trust wasn't.

DigiCert's EV certs, WebEx and Zoom installers, ViPNet's signed updater. Three subverted trust chains this week, one design assumption behind them.

read →