0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.
CoreGraphics memory confusion in Apple iOS 26, iPadOS, macOS 26, macOS 15
CoreGraphics memory confusion flaw in Apple iOS 26, iPadOS, macOS 26, and macOS 15. CVSS 8.8 high. Apple reports possible exploitation in targeted attacks.
Citrix NetScaler ADC/Gateway Unauthenticated RCE via Input Validation Flaw
Citrix NetScaler ADC and Gateway improper input validation flaw allows unauthenticated remote code execution; actively exploited and CISA KEV listed.
Citrix NetScaler ADC/Gateway RCE via Memory Buffer Mishandling
Citrix NetScaler ADC and Gateway memory buffer flaw allows remote code execution or denial of service; actively exploited and CISA KEV listed.
Microsoft SharePoint Code Injection Vulnerability
A code injection flaw in Microsoft Office SharePoint lets an authorized attacker execute code over a network. CVSS 8.8 (high), active exploitation confirmed, CISA KEV deadline September 28, 2026.
Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.
From the desk

Arizona Supreme Court Confirms Resident Data Stolen
Hackers stole personal data from Arizona's court system. No ransomware; no ransom demands as of Monday. Breach scope and affected count undisclosed.

SailPoint Patches Critical Unauth RCE in IdentityIQ
SailPoint patches CVE-2026-12342, a CVSS 9.6 unauthenticated RCE in IdentityIQ. All versions are affected. Apply the vendor patch immediately.

Apple Patches CVE-2026-86950: CoreGraphics, Targeted Attacks
Apple patched CVE-2026-86950 in CoreGraphics on September 28 with an emergency update for iOS 26, macOS 26, and macOS 15. Apple's advisory states it may have been exploited in targeted attacks.

Kiteworks Patches Critical Flaw, Lifts Shutdown Order
Kiteworks patched the flaw behind its September 26 emergency shutdown advisory. Apply the update before restoring any Kiteworks instance to service.

Keio Railway Confirms Ransomware Attack
Japan's Keio Corporation, a major Tokyo-area railway operator, confirmed ransomware struck its network over the weekend, knocking out business systems.

Apache Roller Patches Critical XML-RPC Deserialization Bug
Apache Roller 6.1.5 has four patched vulnerabilities, including a CVSS 9.8 deserialization flaw allowing unauthenticated RCE via the XML-RPC endpoint.




