Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-65660
[ HIGH ]CVSS 8.8EPSS 2.1%kev

Microsoft SharePoint Code Injection Vulnerability

A code injection flaw in Microsoft Office SharePoint lets an authorized attacker execute code over a network. CVSS 8.8 (high), active exploitation confirmed, CISA KEV deadline September 28, 2026.

Microsoft / SharePoint
CVE-2026-67279
[ MEDIUM ]CVSS 6.5EPSS 1.0%kev

Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.

MikroTik / RouterOS
CVE-2026-5430
[ CRITICAL ]CVSS 10.0EPSS 0.6%kev

WSO2 Multiple Products Path Traversal to RCE

WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway contain a path traversal flaw enabling unauthenticated file upload and remote code execution. CVSS 10.0. Actively exploited since September 13, 2026; added to CISA KEV September 24.

WSO2 / API Control Plane, API Manager, Traffic Manager, Universal Gateway
CVE-2026-87902
[ HIGH ]CVSS 8.1EPSS 18.2%kev

WordPress core get_page_template path traversal enables unauthenticated RCE

Path traversal in WordPress core's get_page_template() enables unauthenticated local PHP file inclusion and conditional RCE. Actively exploited within 24 hours of disclosure. CVSS 8.1 High.

WordPress / WordPress Core
CVE-2026-93616
[ CRITICAL ]CVSS 9.8EPSS 19.7%kev

Check Point Multiple Products Path Traversal Vulnerability

CVE-2026-93616: CVSS 9.8 path traversal and file upload in Check Point Management Server enabling unauth RCE. Confirmed exploited; patches available.

Check Point / Security Management Server, Multi-Domain Management Server, Log Server, SmartEvent
CVE-2026-93952
[ CRITICAL ]CVSS 10.0EPSS 1.1%kev

Arista VeloCloud Orchestrator Unauthenticated RCE

“CVE-2026-93952 is a CVSS 10.0 improper input validation flaw in Arista VeloCloud Orchestrator that allows unauthenticated remote code execution. Added to CISA KEV on September 22, 2026.”

Arista / VeloCloud Orchestrator
$ latest --more

From the desk

all articles →
~/articles/2026-09-26-elementor-csrf-admin-account-creation
Elementor CSRF Flaw Lets Attackers Create Admin Accounts
wordpress

Elementor CSRF Flaw Lets Attackers Create Admin Accounts

A CSRF flaw in the Elementor WordPress plugin lets attackers create administrator accounts without valid credentials. Site owners should update the plugin immediately.

read →
~/articles/2026-09-26-mikrotik-cve-2026-67279-cisa-kev-chain
CISA Adds MikroTik RouterOS Chain Flaw to KEV Catalog
● Breaking
mikrotik

CISA Adds MikroTik RouterOS Chain Flaw to KEV Catalog

CISA added CVE-2026-67279 to KEV on September 25. The medium-severity flaw chains with CVE-2026-86060 to enable full unauthenticated exploitation of MikroTik RouterOS. Federal deadline is September 28.

read →
~/articles/2026-09-26-kiteworks-zero-day-warning-server-shutdown
Kiteworks Flags Potential Zero-Day, Urges Server Shutdown
threat intel

Kiteworks Flags Potential Zero-Day, Urges Server Shutdown

Kiteworks warned customers Thursday of potential zero-day attack activity and asked them to take servers offline for a six-hour window on Saturday, September 26.

read →
~/articles/2026-09-26-clop-moves-leak-site-grav-cms-attack-confirmed
Clop Moves Leak Site After Grav CMS Attack Confirmed
● Breaking
ransomware

Clop Moves Leak Site After Grav CMS Attack Confirmed

Clop ransomware confirmed its Tor leak site was breached via an unpatched Grav CMS path traversal flaw. The group has migrated to a new Tor address.

read →
~/articles/2026-09-26-soldier-70-months-att-verizon-telecom-extortion
U.S. Soldier Gets 70 Months for Telecom Extortion
● Breaking
threat intel

U.S. Soldier Gets 70 Months for Telecom Extortion

A U.S. Army soldier sentenced to 70 months for hacking AT&T and Verizon and extorting the carriers using 100 million customers' stolen call and text metadata.

read →
~/articles/2026-09-25-bitget-dprk-crypto-theft-351-million
Suspected DPRK Hackers Steal $351.6M from Bitget
threat intel

Suspected DPRK Hackers Steal $351.6M from Bitget

Bitget says suspected North Korean actors stole $351.6 million from hot and warm wallets in a backend compromise detected at 18:31 UTC on September 24.

read →