Skip to content
feed: live
>_ 0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-20316
[ MEDIUM ] CVSS 5.3 EPSS 0.8% kev

Hard-coded credential in Cisco Secure FMC enables unauthenticated login

Cisco Secure FMC ships a static low-privileged account; remote unauthenticated attackers can log in and access sensitive data. CISA KEV confirmed July 29, 2026.

Cisco / Cisco Secure Firewall Management Center (FMC)
CVE-2026-21513
[ HIGH ] CVSS 8.8 EPSS 15.4% kev

Microsoft MSHTML security feature bypass

Protection mechanism failure in Microsoft MSHTML lets unauthenticated attackers bypass a security feature over the network. CVSS 8.8, patched in Microsoft's February 2026 Patch Tuesday.

Microsoft / MSHTML Framework (Windows)
CVE-2026-16812
[ CRITICAL ] CVSS 10.0 EPSS 0.9% kev

Arista VeloCloud Orchestrator OS Command Injection

CVSS 10.0 critical. Remote attackers can inject OS commands into Arista VeloCloud Orchestrator On-Prem, compromising the SD-WAN management plane.

Arista / VeloCloud Orchestrator On-Prem
CVE-2026-16232
[ CRITICAL ] CVSS 9.1 EPSS 70.0% kev

Check Point SmartConsole improper authentication

CVE-2026-16232 lets unauthenticated attackers grab an admin token from SmartConsole. CISA KEV addition July 22; Check Point confirms active exploitation.

Check Point / SmartConsole
CVE-2026-60137
[ MEDIUM ] CVSS 5.9 EPSS 79.0% kev

WordPress WP_Query author__not_in SQL injection (wp2shell companion)

A medium-severity SQL injection in WordPress WP_Query's author__not_in parameter (CVE-2026-60137). Tracked as the wp2shell companion. Patched in 6.8.6, 6.9.5, and 7.0.2.

WordPress / WordPress Core (6.8.0-6.8.5, 6.9.0-6.9.4, 7.0.0-7.0.1)
CVE-2026-63030
[ CRITICAL ] CVSS 9.8 EPSS 98.4% kev

WordPress Core unauthenticated RCE (wp2shell)

A critical unauthenticated remote code execution flaw in WordPress Core (CVE-2026-63030). GitHub Security Advisory issued July 17, 2026; public PoC circulating.

WordPress / WordPress Core (6.9 and 7.0 branches per The Hacker News)
$ latest --more

From the desk

all articles →
~/articles/2026-07-31-amgen-cloud-breach-patient-health-data
Amgen Says Breach Exposed Patient Health Data
● Breaking
threat intel

Amgen Says Breach Exposed Patient Health Data

Amgen confirmed threat actors stole patient health information and proprietary corporate data from third-party cloud systems operated by outside service providers.

read →
~/articles/2026-07-31-arch-linux-aur-malware-lockdown
Arch Linux Locks Down AUR After Malware Takeover Surge
● Breaking
supply chain

Arch Linux Locks Down AUR After Malware Takeover Surge

Arch Linux disabled AUR package adoption after a surge of malicious takeovers by threat actors who exploited the mechanism to push backdoored updates to users.

read →
~/articles/2026-07-31-adform-ad-script-supply-chain-crypto-clipboard
Adform Ad Script Hijacked in Supply-Chain Crypto Attack
supply chain

Adform Ad Script Hijacked in Supply-Chain Crypto Attack

Adform's ad script was backdoored to swap crypto wallet addresses in visitor clipboards, silently stealing funds on sites running the compromised tag.

read →
~/articles/2026-07-31-vmware-vcenter-esxi-critical-auth-bypass-vm-escape-patch
Three Critical VMware Flaws Fixed: Auth Bypass, VM Escape
vmware

Three Critical VMware Flaws Fixed: Auth Bypass, VM Escape

Broadcom patched five CVEs in VMware vCenter, ESXi, Workstation, and Fusion. Three are critical: auth bypass, RCE, VM escape. Patch vCenter now.

read →
~/articles/2026-07-31-cisa-water-utilities-plc-attacks
CISA Warns of Rising Attacks on Water System PLCs
ics ot

CISA Warns of Rising Attacks on Water System PLCs

CISA flags a surge in attacks targeting internet-exposed PLCs in U.S. water and wastewater systems. Patch, segment, and remove direct internet exposure.

read →
~/articles/2026-07-31-google-chrome-ai-1442-security-bugs
AI Finds 1,442 Chrome Bugs in Three Recent Releases
● Breaking
browser

AI Finds 1,442 Chrome Bugs in Three Recent Releases

Google patched 1,442 security flaws across Chrome 149, 150, and 151 — more than the prior 23 releases combined. AI-assisted testing drove the surge.

read →