0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Google Pixel Cellular Modem Improper Authorization
Improper authorization in Google Pixel's cellular modem lets a nearby attacker bypass permission checks and escalate privileges without user interaction. CISA KEV, due 2026-09-19.
Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
CVSS 10.0 auth bypass in Cisco ISE and ISE-PIC. Unauthenticated attackers can bypass web management and gain root execution. Actively exploited; CISA KEV.
Acronis Backup Incorrect Default Permissions Vulnerability
Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.
Cisco Secure Email Gateway SQL Injection Vulnerability
SQL injection in Cisco AsyncOS for Secure Email Gateway lets an unauthenticated remote attacker execute arbitrary OS commands with root privileges. CISA KEV since Sept. 14.
JFrog Artifactory Incorrect Authorization Vulnerability
JFrog Artifactory validates token signature and issuer but not scope, creating a privilege escalation path. CVSS 8.1 (high), CISA KEV deadline September 25, 2026.
JFrog Artifactory Improper Authentication Vulnerability
JFrog Artifactory returns an internal anonymous-user token to unauthenticated callers even when anonymous access is disabled, allowing unauthorized resource access and enabling privilege escalation chains.
From the desk

CVE-2026-90895: MISP CLI Exposes Auth Creds, Bypasses ACLs
MISP through 2.5.45 has CLI access controls separate from the web app, exposing feed HTTP credentials and sync authkeys to unauthorized users.

Mattermost CVE-2026-14344: Board Permission Check Skipped
CVE-2026-14344 lets any authenticated Mattermost user create boards regardless of role assignments. Four active release branches affected; upgrade per the security advisory.

D-Link DWR Routers Hit by Three Critical Command Injections
Three critical command injection flaws in D-Link DWR-M920 and DWR-M921 firmware. Researcher H3rmesk1t disclosed all three; no D-Link patch available.
Rapid7 Tracks Active Exploits Against GitLab Path Traversal
Rapid7's ETR on CVE-2026-85706 confirms active exploitation the day CISA's federal deadline expired. Unpatched GitLab instances are overdue.

Apache Syncope Patches 7 Critical Flaws
Apache Syncope patches seven critical CVEs: JWT forgery, Cypher injection, and search injection across 3.x and 4.x. Upgrade and rotate connector credentials.

LightLLM Config Server Has Unauthenticated RCE
CVE-2026-90919 (CVSS 9.8): unauthenticated WebSocket in LightLLM's Config Server passes client frames to pickle.loads, enabling RCE on any exposed instance.



