Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-88771
[ HIGH ]kev

Citrix NetScaler ADC/Gateway Unauthenticated RCE via Input Validation Flaw

Citrix NetScaler ADC and Gateway improper input validation flaw allows unauthenticated remote code execution; actively exploited and CISA KEV listed.

Citrix / NetScaler ADC, NetScaler Gateway
CVE-2026-88772
[ HIGH ]kev

Citrix NetScaler ADC/Gateway RCE via Memory Buffer Mishandling

Citrix NetScaler ADC and Gateway memory buffer flaw allows remote code execution or denial of service; actively exploited and CISA KEV listed.

Citrix / NetScaler ADC, NetScaler Gateway
CVE-2026-65660
[ HIGH ]CVSS 8.8EPSS 2.1%kev

Microsoft SharePoint Code Injection Vulnerability

A code injection flaw in Microsoft Office SharePoint lets an authorized attacker execute code over a network. CVSS 8.8 (high), active exploitation confirmed, CISA KEV deadline September 28, 2026.

Microsoft / SharePoint
CVE-2026-67279
[ MEDIUM ]CVSS 6.5EPSS 1.0%kev

Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.

MikroTik / RouterOS
CVE-2026-5430
[ CRITICAL ]CVSS 10.0EPSS 0.6%kev

WSO2 Multiple Products Path Traversal to RCE

WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway contain a path traversal flaw enabling unauthenticated file upload and remote code execution. CVSS 10.0. Actively exploited since September 13, 2026; added to CISA KEV September 24.

WSO2 / API Control Plane, API Manager, Traffic Manager, Universal Gateway
CVE-2026-87902
[ HIGH ]CVSS 8.1EPSS 18.2%kev

WordPress core get_page_template path traversal enables unauthenticated RCE

Path traversal in WordPress core's get_page_template() enables unauthenticated local PHP file inclusion and conditional RCE. Actively exploited within 24 hours of disclosure. CVSS 8.1 High.

WordPress / WordPress Core
$ latest --more

From the desk

all articles →
~/articles/2026-09-27-budibase-3-45-0-six-cve-patch
Budibase 3.45.0 Fixes Six Security Flaws
cloud

Budibase 3.45.0 Fixes Six Security Flaws

Budibase 3.45.0 patches six CVEs including arbitrary file write (CVSS 8.8), SSO auth bypass (8.1), and SQL injection (8.0). Update now if Builder is exposed.

read →
~/articles/2026-09-27-citrix-netscaler-two-unpatched-rce-zero-days
Citrix NetScaler: Two Unpatched RCEs Actively Exploited
● Breaking
citrix

Citrix NetScaler: Two Unpatched RCEs Actively Exploited

Two unpatched RCEs in Citrix NetScaler ADC and Gateway are actively exploited in the wild. CVE IDs are pending assignment; Citrix expects patches by end of September 2026.

read →
~/articles/2026-09-27-woocommerce-request-quote-cve-2026-18143-file-upload
Critical File Upload Bug in WooCommerce Quote Plugin
wordpress

Critical File Upload Bug in WooCommerce Quote Plugin

CVE-2026-18143 is a CVSS 9.8 arbitrary file upload flaw in the Request a Quote for WooCommerce plugin through version 2.9.2. Update to 2.9.3.

read →
~/articles/2026-09-27-sharepoint-code-injection-cve-2026-65660-kev
SharePoint Code Injection CVE-2026-65660 Added to KEV
● Breaking
cisa kev

SharePoint Code Injection CVE-2026-65660 Added to KEV

CISA added a SharePoint code injection flaw to its KEV catalog on September 25. CVSS 8.8, active exploitation confirmed, federal patch deadline September 28.

read →
~/articles/2026-09-27-shinyhunters-waf-bypass-oracle-peoplesoft-cve-2026-35273
ShinyHunters WAF Bypass Keeps PeopleSoft Attacks Alive
● Breaking
oracle

ShinyHunters WAF Bypass Keeps PeopleSoft Attacks Alive

ShinyHunters uses URL encoding to bypass WAF rules protecting against Oracle PeopleSoft CVE-2026-35273, continuing to deploy web shells on servers organizations thought were protected.

read →
~/articles/2026-09-26-elementor-csrf-admin-account-creation
Elementor CSRF Flaw Lets Attackers Create Admin Accounts
wordpress

Elementor CSRF Flaw Lets Attackers Create Admin Accounts

A CSRF flaw in the Elementor WordPress plugin lets attackers create administrator accounts without valid credentials. Site owners should update the plugin immediately.

read →