Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2025-39682
[ CRITICAL ]CVSS 9.8EPSS 1.2%kev

Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

Linux kernel TLS receive path: zero-length record bypasses recvmsg() handling, corrupting downstream TLS processing. CVSS 9.8. In CISA KEV Sept. 18, 2026.

Linux / Kernel
CVE-2025-39964
[ HIGH ]CVSS 7.8EPSS 0.8%kev

Linux Kernel Race Condition Vulnerability

Linux kernel AF_ALG race condition: concurrent writes corrupt state, crashing the system or corrupting cryptographic output. CVSS 7.8. CISA KEV Sept. 18.

Linux / Kernel
CVE-2026-53266
[ HIGH ]CVSS 8.8EPSS 0.3%kev

Linux Kernel Out-of-Bounds Write Vulnerability

OOB write in Linux kernel ebtables SNAT target. ARP address rewrite lands in a nonlinear socket buffer. CVSS 8.8, public exploits confirmed. CISA KEV Sept. 18.

Linux / Kernel
CVE-2026-58704
[ HIGH ]CVSS 8.8EPSS 0.2%kev

Google Pixel Cellular Modem Improper Authorization

Improper authorization in Google Pixel's cellular modem lets a nearby attacker bypass permission checks and escalate privileges without user interaction. CISA KEV, due 2026-09-19.

Google / Pixel
CVE-2026-76460
[ CRITICAL ]CVSS 10.0EPSS 0.8%kev

Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

CVSS 10.0 auth bypass in Cisco ISE and ISE-PIC. Unauthenticated attackers can bypass web management and gain root execution. Actively exploited; CISA KEV.

Cisco / Identity Services Engine
CVE-2026-87886
[ HIGH ]CVSS 7.8EPSS 0.3%kev

Acronis Backup Incorrect Default Permissions Vulnerability

Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.

Acronis / Backup
$ latest --more

From the desk

all articles →
~/articles/2026-09-19-microsoft-fabric-cve-2026-69843-cvss10-auth-bypass
Microsoft Fabric Auth Bypass Reaches CVSS 10.0
Analysis
microsoft

Microsoft Fabric Auth Bypass Reaches CVSS 10.0

Microsoft patched CVE-2026-69843, a CVSS 10.0 authentication bypass in Fabric that let unauthenticated attackers elevate privileges over a network.

read →
~/articles/2026-09-19-azure-ai-foundry-cve-2026-85889-cvss10-privilege-escalation
Microsoft Fixes CVSS 10.0 Flaw in Azure AI Foundry
microsoft

Microsoft Fixes CVSS 10.0 Flaw in Azure AI Foundry

Microsoft patched CVE-2026-85889, a CVSS 10.0 missing-authentication flaw in Azure AI Foundry that let unauthenticated attackers escalate privileges. No customer action required.

read →
~/articles/2026-09-19-waterplum-north-korea-job-seekers-30k-devices
WaterPlum: North Korea Targets Job Seekers, 30K Devices Hit
threat intel

WaterPlum: North Korea Targets Job Seekers, 30K Devices Hit

FBI and four allies confirm North Korea's WaterPlum campaign infected 30,000 devices across 100 countries via fake job interviews.

read →
~/articles/2026-09-19-cisa-kev-three-linux-kernel-exploited
CISA Adds Three Exploited Linux Kernel Flaws to KEV
● Breaking
linux kernel

CISA Adds Three Exploited Linux Kernel Flaws to KEV

CISA added CVE-2025-39682 (CVSS 9.8), CVE-2026-53266, and CVE-2025-39964 to KEV on Sept. 18. All three actively exploited. Federal deadline: Sept. 21.

read →
~/articles/2026-09-19-gyazo-breach-23m-records-oauth-tokens
Gyazo Breach Exposes 23M Records and OAuth Tokens
threat intel

Gyazo Breach Exposes 23M Records and OAuth Tokens

Helpfeel confirms 23.6 million Gyazo accounts breached September 11, exposing Google and X OAuth tokens. Revoke app access before changing passwords.

read →
~/articles/2026-09-18-ransomware-manufacturers-surge-supply-chain-2026
Ransomware Attacks on Manufacturers Up 40% in H1 2026
ransomware

Ransomware Attacks on Manufacturers Up 40% in H1 2026

Ransomware attacks on manufacturers rose 40 percent in the first half of 2026, with groups exploiting the supply-chain disruption that follows operational shutdowns.

read →