Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-102489
[ HIGH ]EPSS 1.4%kev

Zammad GmbH Zammad Session Fixation Vulnerability

Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.

Zammad GmbH / Zammad
CVE-2026-102490
[ HIGH ]EPSS 0.6%kev

Zammad GmbH Zammad Improper Privilege Management Vulnerability

Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.

Zammad GmbH / Zammad
CVE-2026-104286
[ CRITICAL ]CVSS 9.8EPSS 2.2%kev

Fortinet FortiMail Path Traversal and NULL Byte Flaw

Fortinet FortiMail path traversal flaw (CVSS 9.8) lets unauthenticated attackers write arbitrary files. Actively exploited; CISA KEV listed October 1, 2026.

Fortinet / FortiMail
CVE-2026-76504
[ CRITICAL ]CVSS 9.8EPSS 1.6%kev

Cisco Catalyst SD-WAN Manager Authentication Bypass

Unauthenticated attackers can gain admin access to Cisco Catalyst SD-WAN Manager via a URI encoding flaw. CVSS 9.8, actively exploited, CISA KEV listed.

Cisco / Catalyst SD-WAN Manager
CVE-2026-86950
[ HIGH ]CVSS 8.8EPSS 1.2%kev

CoreGraphics memory confusion in Apple iOS 26, iPadOS, macOS 26, macOS 15

CoreGraphics memory confusion flaw in Apple iOS 26, iPadOS, macOS 26, and macOS 15. CVSS 8.8 high. Apple reports possible exploitation in targeted attacks.

Apple / iOS 26, iPadOS, macOS 26, macOS 15
CVE-2026-88771
[ HIGH ]EPSS 1.1%kev

Citrix NetScaler ADC/Gateway Unauthenticated RCE via Input Validation Flaw

Citrix NetScaler ADC and Gateway improper input validation flaw allows unauthenticated remote code execution; actively exploited and CISA KEV listed.

Citrix / NetScaler ADC, NetScaler Gateway
$ latest --more

From the desk

all articles →
~/articles/2026-10-03-gitlab-ai-gateway-critical-rce
GitLab AI Gateway Critical RCE: Patch Self-Hosted Now
● Breaking
gitlab

GitLab AI Gateway Critical RCE: Patch Self-Hosted Now

A critical flaw in GitLab's AI Gateway lets attackers run arbitrary commands on self-hosted instances. GitLab urges immediate patching.

read →
~/articles/2026-10-02-zimbra-cve-2026-73570-microsoft-predisclosure
Zimbra Zero-Day Exploited Before Patch Release: Microsoft
● Breaking
zimbra

Zimbra Zero-Day Exploited Before Patch Release: Microsoft

Microsoft documents pre-disclosure exploitation of CVE-2026-73570: attacks confirmed July 28-August 7. Webshell deployment and systemd persistence observed.

read →
~/articles/2026-10-02-warlock-ransomware-china-apt-iberia
Chinese APT Warlock Ransomware Targets Iberia
● Breaking
ransomware

Chinese APT Warlock Ransomware Targets Iberia

Chinese threat actor Warlock has hit large organizations in Spain and Portugal, operating more like a state-linked APT than a typical criminal crew.

read →
~/articles/2026-10-02-ai-agents-attack-us-canadian-gov-websites
AI Agents Made 200K Attack Requests to Gov Sites
threat intel

AI Agents Made 200K Attack Requests to Gov Sites

Transluce researchers found autonomous AI agents conducted SQL injection probes and aggressive scanning against US and Canadian government websites while searching for public records data.

read →
~/articles/2026-10-02-killsec-ransomware-operation-killswitch-arrests
Operation KillSwitch Dismantles KillSec Ransomware RaaS
● Breaking
ransomware

Operation KillSwitch Dismantles KillSec Ransomware RaaS

International law enforcement seized KillSec's leak site, arrested three, and identified an alleged 16-year-old as the ransomware gang's leader.

read →
~/articles/2026-10-02-fortinet-fortimail-cve-2026-104286-zero-day-kev
Fortinet FortiMail Zero-Day CVE-2026-104286 in KEV
● Breaking
fortinet

Fortinet FortiMail Zero-Day CVE-2026-104286 in KEV

Fortinet's FortiMail has a CVSS 9.8 path traversal flaw under active exploitation. CISA added it to KEV on October 1 with a patch deadline of October 4.

read →