Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-65660
[ HIGH ]CVSS 8.8EPSS 2.1%kev

Microsoft SharePoint Code Injection Vulnerability

Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.

Microsoft / SharePoint
CVE-2026-67279
[ MEDIUM ]CVSS 6.5EPSS 1.0%kev

Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.

MikroTik / RouterOS
CVE-2026-5430
[ CRITICAL ]CVSS 10.0EPSS 0.6%kev

WSO2 Multiple Products Path Traversal to RCE

WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway contain a path traversal flaw enabling unauthenticated file upload and remote code execution. CVSS 10.0. Actively exploited since September 13, 2026; added to CISA KEV September 24.

WSO2 / API Control Plane, API Manager, Traffic Manager, Universal Gateway
CVE-2026-87902
[ HIGH ]CVSS 8.1EPSS 18.2%kev

WordPress core get_page_template path traversal enables unauthenticated RCE

Path traversal in WordPress core's get_page_template() enables unauthenticated local PHP file inclusion and conditional RCE. Actively exploited within 24 hours of disclosure. CVSS 8.1 High.

WordPress / WordPress Core
CVE-2026-93616
[ CRITICAL ]CVSS 9.8EPSS 19.7%kev

Check Point Multiple Products Path Traversal Vulnerability

CVE-2026-93616: CVSS 9.8 path traversal and file upload in Check Point Management Server enabling unauth RCE. Confirmed exploited; patches available.

Check Point / Security Management Server, Multi-Domain Management Server, Log Server, SmartEvent
CVE-2026-93952
[ CRITICAL ]CVSS 10.0EPSS 0.9%kev

Arista VeloCloud Orchestrator Unauthenticated RCE

“CVE-2026-93952 is a CVSS 10.0 improper input validation flaw in Arista VeloCloud Orchestrator that allows unauthenticated remote code execution. Added to CISA KEV on September 22, 2026.”

Arista / VeloCloud Orchestrator
$ latest --more

From the desk

all articles →
~/articles/2026-09-25-bitget-dprk-crypto-theft-351-million
Suspected DPRK Hackers Steal $351.6M from Bitget
● Breaking
threat intel

Suspected DPRK Hackers Steal $351.6M from Bitget

Bitget says suspected North Korean actors stole $351.6 million from hot and warm wallets in a backend compromise detected at 18:31 UTC on September 24.

read →
~/articles/2026-09-25-salesbleed-salesforce-agentforce-zero-click-data-exfiltration
SalesBleed: Agentforce Flaws Enable Data Exfiltration
cloud

SalesBleed: Agentforce Flaws Enable Data Exfiltration

Three SalesBleed flaws in Salesforce Agentforce allow attackers to hijack AI agents and exfiltrate data via trusted Slack channels without user interaction.

read →
~/articles/2026-09-25-wso2-adobe-commerce-cisa-kev-cve-2026-5430-cve-2026-71362
CISA KEV: WSO2 and Adobe Commerce Flaws Exploited
● Breaking
cisa kev

CISA KEV: WSO2 and Adobe Commerce Flaws Exploited

CISA added CVE-2026-5430 (WSO2, CVSS 10.0) and CVE-2026-71362 (Adobe Commerce, CVSS 9.1) to KEV on September 24. Federal patch deadline: September 27.

read →
~/articles/2026-09-25-macsync-macos-icloud-calendar-c2
MacSync macOS Malware Abuses Public iCloud Calendars
apple

MacSync macOS Malware Abuses Public iCloud Calendars

Kaspersky found a new MacSync variant that hides C2 commands inside public iCloud calendar events, bypassing domain-based network controls on macOS.

read →
~/articles/2026-09-25-vardanyan-ryuk-ransomware-sentenced-two-years
Ryuk Member Gets 2 Years for $1.2M Ransomware Attacks
● Breaking
ransomware

Ryuk Member Gets 2 Years for $1.2M Ransomware Attacks

Armenian national Karen Vardanyan sentenced to 2 years in US federal prison for Ryuk ransomware attacks, ordered to pay over $1.2M in restitution to victims.

read →
~/articles/2026-09-24-roundcube-cve-2026-48842-active-exploit-sql-injection
Roundcube SQL Injection Flaw Under Active Attack
threat intel

Roundcube SQL Injection Flaw Under Active Attack

Canada's CCCS confirmed active exploitation of CVE-2026-48842, a SQL injection in Roundcube Webmail patched in May. Upgrade to 1.6.16 or 1.7.1 now.

read →