0dayNews — Vulnerability & Exploit News
Latest intelligence
all articles →Known Exploited Vulnerabilities
Citrix NetScaler Memory Buffer Flaw Enables Denial-of-Service Attacks
NetScaler ADC and Gateway contain an exploited memory-buffer flaw enabling denial of service. CISA KEV listed October 4, federal deadline October 7.
Zammad GmbH Zammad Session Fixation Vulnerability
Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.
Zammad GmbH Zammad Improper Privilege Management Vulnerability
Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.
Fortinet FortiMail Path Traversal and NULL Byte Flaw
Fortinet FortiMail path traversal flaw (CVSS 9.8) lets unauthenticated attackers write arbitrary files. Actively exploited; CISA KEV listed October 1, 2026.
Cisco Catalyst SD-WAN Manager Authentication Bypass
Unauthenticated attackers can gain admin access to Cisco Catalyst SD-WAN Manager via a URI encoding flaw. CVSS 9.8, actively exploited, CISA KEV listed.
CoreGraphics memory confusion in Apple iOS 26, iPadOS, macOS 26, macOS 15
CoreGraphics memory confusion flaw in Apple iOS 26, iPadOS, macOS 26, and macOS 15. CVSS 8.8 high. Apple reports possible exploitation in targeted attacks.
Latest security news

ShinyHunters Member Arrested in Jordan, Aiding FBI
Saif al-Din Khader, detained in Jordan, is cooperating with the FBI over a major breach linked to ShinyHunters, the second arrest in the group within a week.

Perforce P4 Search Containers Expose RCE, Auth Bypass
Perforce P4 Search containers before 2026.4.2 expose an unauthenticated JDWP debug interface (RCE, CVSS 9.8) and reset auth tokens to a documented default (CVSS 9.1).

Exchange Server OOB Patch Closes Mailbox-Read Flaw
CVE-2026-96940, a CVSS 8.8 privilege escalation flaw in on-prem Microsoft Exchange, lets authenticated attackers read other users' mailboxes. Patch available now; Exchange Online already fixed.

ATB Ukraine: Cyberattack Confirmed, Data Leak Threatened
Ukraine's largest grocery chain ATB confirmed a cyberattack after hackers posted an extortion demand on its website and threatened to release stolen data.

Ransomware Hits UIC Medical School, Data Stolen
Ransomware struck the University of Illinois Chicago College of Medicine. Data was stolen from servers. Threat group, scope, and ransomware demand all unconfirmed.

Rejetto HFS RCE Under Active Exploitation
CVE-2026-61500 is a critical CVSS 4.0 9.3 flaw in Rejetto HFS: attackers can recover the session-signing key, forge admin sessions, and execute code remotely.






