0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Microsoft Entra ID Deserialization of Untrusted Data — RCE
Deserialization flaw in Microsoft Entra ID allows unauthenticated remote code execution over a network. CVSS 10.0. Actively exploited; added to CISA KEV on August 21, 2026.
Zimbra ZCS SNMP Command Injection — Unauthenticated RCE
CVE-2026-73570 — CVSS 8.9 command injection in Zimbra Collaboration Suite's SNMP handler enables unauthenticated remote code execution. Actively exploited in the wild. Patch: Zimbra 10.1.20.
TrueConf Server Missing Authentication for Critical Function Vulnerability
TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.
TrueConf Server Code Injection Vulnerability
TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
MLflow SSRF Lets Attackers Steal Cloud Credentials via Metadata Services
A server-side request forgery in MLflow before 3.15.0 allows unauthenticated access to internal endpoints including cloud metadata services, enabling cloud credential and IAM secret theft.
From the desk

Zimbra SNMP RCE Now Exploited in the Wild
CVE-2026-73570, a CVSS 8.9 command injection in Zimbra ZCS, is under active exploitation per CERT Polska. Patch to 10.1.20 or later immediately.

Backdoored Rust Crates Delivered Infostealer at Build Time
Three popular Rust crates ran infostealer malware on developer machines via a compromised maintainer account on crates.io. Malicious versions have been pulled.

CareCloud Breach Hits 3.7M Healthcare Records
Healthcare IT firm CareCloud confirmed 3.7 million patients' data was exposed after an attacker spent eight hours inside one of its EHR environments.

NSA, FBI Warn of AI-Powered Attacks on Siemens PLCs
NSA and FBI warn that AI-generated scripts are actively targeting Siemens S7 PLCs in U.S. critical infrastructure. Inventory, segment, and patch now.

Citrix Patches Critical NetScaler Auth Bypass
Citrix patches CVE-2026-19490, critical auth bypass in NetScaler ADC and Gateway, CVSS 9.3. No exploitation observed yet — here's what to patch before that changes.

Ransomware Affiliate Poses as Data Recovery Service
A ransomware affiliate calling itself Ransom Busters is emailing victims and offering to delete their stolen data from ransomware groups' servers for fees of $20,000 to $60,000.




