0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
JFrog Artifactory Incorrect Authorization Vulnerability
JFrog Artifactory validates token signature and issuer but not scope, creating a privilege escalation path. CVSS 8.1 (high), CISA KEV deadline September 25, 2026.
JFrog Artifactory Improper Authentication Vulnerability
JFrog Artifactory returns an internal anonymous-user token to unauthenticated callers even when anonymous access is disabled, allowing unauthorized resource access and enabling privilege escalation chains.
ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
ConnectWise ScreenConnect allows file transfer and execution through active remote sessions without authorization. CVSS 9.9 critical, CISA KEV due September 14.
GitLab Path Traversal Allows Unauthenticated File Read
GitLab CE/EE contains a path traversal flaw due to improper path confinement and missing access controls, allowing an unauthenticated attacker to read arbitrary files from the server.
MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
MikroTik RouterOS btest service missing authentication allows kernel memory disclosure. CVSS 8.2 (high), CISA KEV deadline September 13, 2026.
MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
MikroTik RouterOS SSH login path argument flaw allows unauthenticated privilege escalation. CVSS 9.8 (critical), CISA KEV deadline September 13, 2026.
From the desk

Events Calendar Plugin: Two CVSS 9.8 RCEs
Two unauthenticated CVSS 9.8 RCEs in The Events Calendar WordPress plugin affect all versions through 6.17.4. Disable or update immediately.

BlueMoon Exploit Kit Chains Chrome, Windows Zero-Days
BlueMoon exploit kit bundles Chrome renderer and Windows privilege-escalation zero-days into a two-stage chain, with espionage-motivated actors adopting it in rushed campaigns.

Dutch NCSC Warns Check Point VPN Exploitation Imminent
Dutch NCSC warns exploitation of two CVSS 9.8 Check Point VPN RCE flaws is imminent. If you haven't patched CVE-2026-85102 and CVE-2026-85103, do it now.

Authorizer CVSS 9.3 Flaw Enables OAuth Token Theft
Authorizer's /authorize endpoint accepted any redirect_uri before v2.2.1, exposing OAuth codes and tokens to theft via crafted flows. Patch to 2.2.1.

CISA KEV: RouterOS Deadline Today, ScreenConnect Tomorrow
CISA added five exploited flaws in MikroTik RouterOS, ConnectWise ScreenConnect, and JFrog Artifactory. Federal patch deadline for RouterOS is today, September 13.

Storm-3121 Fakes Passkey Portals to Steal M365 Data
Microsoft links Storm-3121 (ShinyHunters) and Storm-3032 (Helix) to AiTM and device-code phishing against corporate M365 accounts since May 2026.
This week's SITREP
Sep 11: Cisco FMC, Fortinet Hit KEV; Sept. 12 Deadline
Cisco FMC CVSS 10.0 auth bypass and Fortinet FortiOS heap overflow confirmed exploited, added to CISA KEV with September 12 deadline. Ivanti patches six critical RCEs. SAP closes CVSS 10.0 EPP flaw.




