Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-42016
[ HIGH ]CVSS 8.1EPSS 0.9%kev

JFrog Artifactory Incorrect Authorization Vulnerability

JFrog Artifactory validates token signature and issuer but not scope, creating a privilege escalation path. CVSS 8.1 (high), CISA KEV deadline September 25, 2026.

JFrog / Artifactory
CVE-2026-42018
[ HIGH ]CVSS 7.5EPSS 0.9%kev

JFrog Artifactory Improper Authentication Vulnerability

JFrog Artifactory returns an internal anonymous-user token to unauthenticated callers even when anonymous access is disabled, allowing unauthorized resource access and enabling privilege escalation chains.

JFrog / Artifactory
CVE-2026-84869
[ CRITICAL ]CVSS 9.9EPSS 0.7%kev

ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

ConnectWise ScreenConnect allows file transfer and execution through active remote sessions without authorization. CVSS 9.9 critical, CISA KEV due September 14.

ConnectWise / ScreenConnect
CVE-2026-85706
[ CRITICAL ]CVSS 10.0EPSS 1.2%kev

GitLab Path Traversal Allows Unauthenticated File Read

GitLab CE/EE contains a path traversal flaw due to improper path confinement and missing access controls, allowing an unauthenticated attacker to read arbitrary files from the server.

GitLab / GitLab CE/EE
CVE-2026-67277
[ HIGH ]CVSS 8.2EPSS 0.9%kev

MikroTik RouterOS Missing Authentication for Critical Function Vulnerability

MikroTik RouterOS btest service missing authentication allows kernel memory disclosure. CVSS 8.2 (high), CISA KEV deadline September 13, 2026.

MikroTik / RouterOS
CVE-2026-86060
[ CRITICAL ]CVSS 9.8EPSS 1.0%kev

MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

MikroTik RouterOS SSH login path argument flaw allows unauthenticated privilege escalation. CVSS 9.8 (critical), CISA KEV deadline September 13, 2026.

MikroTik / RouterOS
$ latest --more

From the desk

all articles →
~/articles/2026-09-13-events-calendar-cve-2026-78159-78006-rce
Events Calendar Plugin: Two CVSS 9.8 RCEs
wordpress

Events Calendar Plugin: Two CVSS 9.8 RCEs

Two unauthenticated CVSS 9.8 RCEs in The Events Calendar WordPress plugin affect all versions through 6.17.4. Disable or update immediately.

read →
~/articles/2026-09-13-bluemoon-exploit-kit-chrome-windows-zero-days
BlueMoon Exploit Kit Chains Chrome, Windows Zero-Days
browser

BlueMoon Exploit Kit Chains Chrome, Windows Zero-Days

BlueMoon exploit kit bundles Chrome renderer and Windows privilege-escalation zero-days into a two-stage chain, with espionage-motivated actors adopting it in rushed campaigns.

read →
~/articles/2026-09-13-check-point-vpn-dutch-ncsc-exploitation-warning
Dutch NCSC Warns Check Point VPN Exploitation Imminent
● Breaking
check point

Dutch NCSC Warns Check Point VPN Exploitation Imminent

Dutch NCSC warns exploitation of two CVSS 9.8 Check Point VPN RCE flaws is imminent. If you haven't patched CVE-2026-85102 and CVE-2026-85103, do it now.

read →
~/articles/2026-09-13-authorizer-cve-2026-54072-open-redirect
Authorizer CVSS 9.3 Flaw Enables OAuth Token Theft
threat intel

Authorizer CVSS 9.3 Flaw Enables OAuth Token Theft

Authorizer's /authorize endpoint accepted any redirect_uri before v2.2.1, exposing OAuth codes and tokens to theft via crafted flows. Patch to 2.2.1.

read →
~/articles/2026-09-13-cisa-kev-routeros-screenconnect-artifactory-deadlines
CISA KEV: RouterOS Deadline Today, ScreenConnect Tomorrow
● Breaking
cisa kev

CISA KEV: RouterOS Deadline Today, ScreenConnect Tomorrow

CISA added five exploited flaws in MikroTik RouterOS, ConnectWise ScreenConnect, and JFrog Artifactory. Federal patch deadline for RouterOS is today, September 13.

read →
~/articles/2026-09-12-shinyhunters-passkey-phishing-m365-aitm
Storm-3121 Fakes Passkey Portals to Steal M365 Data
microsoft

Storm-3121 Fakes Passkey Portals to Steal M365 Data

Microsoft links Storm-3121 (ShinyHunters) and Storm-3032 (Helix) to AiTM and device-code phishing against corporate M365 accounts since May 2026.

read →