Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-76504
[ CRITICAL ]CVSS 9.8kev

Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability

Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.

Cisco / Catalyst SD-WAN Manager
CVE-2026-86950
[ HIGH ]CVSS 8.8EPSS 1.2%kev

CoreGraphics memory confusion in Apple iOS 26, iPadOS, macOS 26, macOS 15

CoreGraphics memory confusion flaw in Apple iOS 26, iPadOS, macOS 26, and macOS 15. CVSS 8.8 high. Apple reports possible exploitation in targeted attacks.

Apple / iOS 26, iPadOS, macOS 26, macOS 15
CVE-2026-88771
[ HIGH ]EPSS 1.1%kev

Citrix NetScaler ADC/Gateway Unauthenticated RCE via Input Validation Flaw

Citrix NetScaler ADC and Gateway improper input validation flaw allows unauthenticated remote code execution; actively exploited and CISA KEV listed.

Citrix / NetScaler ADC, NetScaler Gateway
CVE-2026-88772
[ HIGH ]EPSS 1.3%kev

Citrix NetScaler ADC/Gateway RCE via Memory Buffer Mishandling

Citrix NetScaler ADC and Gateway memory buffer flaw allows remote code execution or denial of service; actively exploited and CISA KEV listed.

Citrix / NetScaler ADC, NetScaler Gateway
CVE-2026-65660
[ HIGH ]CVSS 8.8EPSS 2.1%kev

Microsoft SharePoint Code Injection Vulnerability

A code injection flaw in Microsoft Office SharePoint lets an authorized attacker execute code over a network. CVSS 8.8 (high), active exploitation confirmed, CISA KEV deadline September 28, 2026.

Microsoft / SharePoint
CVE-2026-67279
[ MEDIUM ]CVSS 6.5EPSS 1.0%kev

Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.

MikroTik / RouterOS
$ latest --more

From the desk

all articles →
~/articles/2026-09-30-arizona-supreme-court-breach-resident-data
Arizona Supreme Court Confirms Resident Data Stolen
threat intel

Arizona Supreme Court Confirms Resident Data Stolen

Hackers stole personal data from Arizona's court system. No ransomware; no ransom demands as of Monday. Breach scope and affected count undisclosed.

read →
~/articles/2026-09-29-sailpoint-identityiq-cve-2026-12342-unauth-rce
SailPoint Patches Critical Unauth RCE in IdentityIQ
threat intel

SailPoint Patches Critical Unauth RCE in IdentityIQ

SailPoint patches CVE-2026-12342, a CVSS 9.6 unauthenticated RCE in IdentityIQ. All versions are affected. Apply the vendor patch immediately.

read →
~/articles/2026-09-29-apple-cve-2026-86950-coregraphics-targeted-attacks
Apple Patches CVE-2026-86950: CoreGraphics, Targeted Attacks
● Breaking
apple

Apple Patches CVE-2026-86950: CoreGraphics, Targeted Attacks

Apple patched CVE-2026-86950 in CoreGraphics on September 28 with an emergency update for iOS 26, macOS 26, and macOS 15. Apple's advisory states it may have been exploited in targeted attacks.

read →
~/articles/2026-09-29-kiteworks-patches-critical-flaw-lifts-shutdown
Kiteworks Patches Critical Flaw, Lifts Shutdown Order
threat intel

Kiteworks Patches Critical Flaw, Lifts Shutdown Order

Kiteworks patched the flaw behind its September 26 emergency shutdown advisory. Apply the update before restoring any Kiteworks instance to service.

read →
~/articles/2026-09-29-keio-railway-ransomware-japan
Keio Railway Confirms Ransomware Attack
● Breaking
ransomware

Keio Railway Confirms Ransomware Attack

Japan's Keio Corporation, a major Tokyo-area railway operator, confirmed ransomware struck its network over the weekend, knocking out business systems.

read →
~/articles/2026-09-29-apache-roller-four-cves-patched
Apache Roller Patches Critical XML-RPC Deserialization Bug
apache

Apache Roller Patches Critical XML-RPC Deserialization Bug

Apache Roller 6.1.5 has four patched vulnerabilities, including a CVSS 9.8 deserialization flaw allowing unauthenticated RCE via the XML-RPC endpoint.

read →