Skip to content
feed: live
>_0dayNews
$ news

Vulnerability & Exploit Coverage

646 articles · sorted newest first

~/news --filter

~/articles/2026-09-11-check-point-vpn-cve-2026-85102-85103-rce
Check Point Patches Two CVSS 9.8 VPN RCE Flaws
check point

Check Point Patches Two CVSS 9.8 VPN RCE Flaws

CVE-2026-85102 and CVE-2026-85103 allow unauthenticated RCE via VPN certificate handling in Check Point firewall products. Patches are out now.

read →
~/articles/2026-09-11-cisco-fmc-qilin-three-threat-clusters
Cisco FMC Hit by Qilin Ransomware, State-Sponsored Actors
● Breaking
cisco

Cisco FMC Hit by Qilin Ransomware, State-Sponsored Actors

Cisco Talos: three threat clusters exploit Cisco FMC CVE-2026-20079. Qilin ransomware deployed; credential theft observed. CISA deadline September 12.

read →
~/articles/2026-09-11-papercut-smr-ai-attacks
PaperCut Issues Stable Fix as AI-Powered Attacks Widen
● Breaking
threat intel

PaperCut Issues Stable Fix as AI-Powered Attacks Widen

PaperCut's SMR replaces all emergency patches for CVE-2026-81578 and CVE-2026-82078. AI-assisted attacks are active against hundreds of organizations.

read →
~/articles/2026-09-11-cisa-kev-sept12-cisco-citrix-fortinet
CISA Sept. 12: Patch Cisco, Citrix, Fortinet Today
● Breaking
cisa kev

CISA Sept. 12: Patch Cisco, Citrix, Fortinet Today

CISA's September 12 deadline covers confirmed exploited flaws in Cisco FMC, Citrix NetScaler, and Fortinet FortiOS. Federal agencies must patch by tomorrow; everyone else should be moving too.

read →
~/articles/2026-09-11-nightmare-eclipse-shieldcrash-windows-defender
Nightmare Eclipse Drops Windows Defender Zero-Day
microsoft

Nightmare Eclipse Drops Windows Defender Zero-Day

Nightmare Eclipse's ShieldCrash exploit achieves SYSTEM privileges on fully patched Windows systems by targeting Windows Defender itself.

read →
~/articles/2026-09-11-watchguard-firebox-ransomware-kev-cve-2025-14733
Ransomware Gangs Exploiting WatchGuard Firebox CVSS 9.8 Flaw
● Breaking
cisa kev

Ransomware Gangs Exploiting WatchGuard Firebox CVSS 9.8 Flaw

CISA confirmed ransomware groups now exploit CVE-2025-14733 in WatchGuard Firebox. Patches shipped December 2025; about 9,000 appliances remain exposed.

read →
~/articles/2026-09-10-fortinet-cve-2025-25249-pivotc2-rat-kev
Fortinet Flaw CVE-2025-25249 Used in PivotC2 RAT Attacks
● Breaking
fortinet

Fortinet Flaw CVE-2025-25249 Used in PivotC2 RAT Attacks

CVSS 8.1 heap overflow in FortiOS is exploited with PivotC2 RAT. January 2026 patch available; CISA BOD 26-04 deadline for federal agencies is September 12.

read →
~/articles/2026-09-10-veradigm-patient-breach-gentlemen-ransomware
Veradigm Discloses Patient Breach After Ransomware Claim
● Breaking
ransomware

Veradigm Discloses Patient Breach After Ransomware Claim

Veradigm disclosed a patient data breach traced to a third-party vendor after the Gentlemen ransomware gang claimed responsibility for the attack.

read →
~/articles/2026-09-10-sap-september-patch-day-epp-cvss10-rce
SAP September Patches: CVSS 10 RCE in EPP Processing
sap

SAP September Patches: CVSS 10 RCE in EPP Processing

SAP's September 2026 Security Patch Day includes a CVSS 10.0 unauthenticated RCE in Extended Passport Processing and multiple additional critical updates.

read →
~/articles/2026-09-10-ivanti-september-patches-neurons-itsm-sentry-epmm
Ivanti Patches Critical RCE in Neurons, EPMM, Sentry
ivanti

Ivanti Patches Critical RCE in Neurons, EPMM, Sentry

Ivanti's September 2026 patches close six critical RCEs in Neurons for ITSM and authentication bypass flaws in Sentry and EPMM. Patch now.

read →
~/articles/2026-09-10-cisco-fmc-cve-2026-20079-exploited
Cisco Confirms FMC CVSS 10 Auth Bypass Exploited
● Breaking
cisco

Cisco Confirms FMC CVSS 10 Auth Bypass Exploited

Cisco confirms CVE-2026-20079, CVSS 10.0 FMC auth bypass, is actively exploited. Unauthenticated attackers gain root OS access. CISA KEV deadline September 12.

read →
~/articles/2026-09-09-f5-big-ip-apm-linux-rootkit-fileless
Linux Rootkit Targets F5 BIG-IP APM, Lives in Memory
f5

Linux Rootkit Targets F5 BIG-IP APM, Lives in Memory

Attackers are breaching F5 BIG-IP APM devices to deploy a Linux rootkit that hooks PHP file loading and injects a fileless web shell into memory, leaving no disk artifacts.

read →
~/articles/2026-09-09-microsoft-patch-tuesday-974-vulns-zero-days
Microsoft Patches Record 974 Vulns, 2 Zero-Days
microsoft

Microsoft Patches Record 974 Vulns, 2 Zero-Days

September 2026 Patch Tuesday: Microsoft patches a record 974 CVEs, including two exploited Windows zero-days now on CISA's KEV catalog.

read →
~/articles/2026-09-09-chrome-seventh-zero-day-2026-exploited
Google Patches Chrome's 7th Exploited Zero-Day of 2026
browser

Google Patches Chrome's 7th Exploited Zero-Day of 2026

Google patched the seventh actively exploited Chrome zero-day of 2026 on September 9, in a 230-vulnerability update. CVE designation pending.

read →
~/articles/2026-09-09-n-able-n-central-kev-pre-auth-rce
CISA Adds N-able N-central Auth Bypass to KEV
cisa kev

CISA Adds N-able N-central Auth Bypass to KEV

CISA added a maximum-severity pre-auth RCE in N-able N-central to its KEV catalog on September 9. N-able patched it; audit deployments for new user accounts.

read →
~/articles/2026-09-09-adobe-stylesmuggler-cve-2026-75650-patch
Adobe Patches StyleSmuggler, CVSS 10 Magento Zero-Day
adobe

Adobe Patches StyleSmuggler, CVSS 10 Magento Zero-Day

Adobe's September 8 emergency update patches CVE-2026-75650, a CVSS 10.0 template-injection zero-day exploited to plant Rust backdoors in Commerce and Magento stores. CISA deadline: September 11.

read →
~/articles/2026-09-08-fake-it-calls-m365-data-theft-extortion
Fake IT Calls Drive M365 Exec Data Theft Campaign
microsoft

Fake IT Calls Drive M365 Exec Data Theft Campaign

Threat hunters have disclosed an active data theft and extortion cluster targeting Microsoft 365 executives via vishing: fake IT help desk calls that harvest credentials and SaaS access.

read →
~/articles/2026-09-08-vietnam-apis-220-million-traveler-records-breach
220M Passport Records Exposed in Vietnam APIS Leak
threat intel

220M Passport Records Exposed in Vietnam APIS Leak

An exposed Vietnam-linked APIS database held 220 million traveler records: names, passport numbers, birth dates, nationalities, and flight routes.

read →
~/articles/2026-09-08-nightmare-eclipse-crowdstrike-nvidia-avast-zero-days
Nightmare Eclipse: Zero-Days Hit CrowdStrike, Nvidia, Avast
threat intel

Nightmare Eclipse: Zero-Days Hit CrowdStrike, Nvidia, Avast

Nightmare Eclipse published PoC privilege-escalation exploits for CrowdStrike Falcon, Nvidia drivers, and Avast antivirus. No CVE IDs or vendor patches yet.

read →
~/articles/2026-09-08-advantech-wise-6610-cve-2026-79697-rce
Advantech WISE-6610 Firmware Hit by CVSS 9.9 RCE
ics ot

Advantech WISE-6610 Firmware Hit by CVSS 9.9 RCE

A command injection in the WISE-6610 LoRaWAN gateway's Basic Station handler allows remote code execution. Exploit is public. Patch: firmware 1.2.4_20260821.

read →
~/articles/2026-09-08-telerik-ui-rce-chain-cve-2026-13181-poc-public
Telerik UI RCE Chain: PoC Published, Patch Is Out
progress

Telerik UI RCE Chain: PoC Published, Patch Is Out

TantoSec's public exploit chains seven Telerik UI CVEs into unauthenticated RCE. Non-default configs only. Patch to 2026 Q2 SP1 now.

read →
~/articles/2026-09-07-n-central-hotfix-4-patch-again
Patch N-central Again: Hotfix 4 Is Out
supply chain

Patch N-central Again: Hotfix 4 Is Out

N-able's fourth N-central hotfix in five weeks renders Hotfix 3 obsolete. Update to 2026.3.1.14 now: CVE-2026-86218 is actively exploited.

read →
~/articles/2026-09-07-jsceal-malware-google-auth-bypass
JSCeal Malware Bypasses Google Auth with Stolen Cookies
threat intel

JSCeal Malware Bypasses Google Auth with Stolen Cookies

JSCeal is compiled V8 JavaScript malware with credential harvesting and traffic interception. It bypasses Google Authentication using stolen session cookies.

read →
~/articles/2026-09-07-n-central-cve-2026-86218-exploitation-confirmed
N-central Under Active Attack: Patch CVE-2026-86218 Now
supply chain

N-central Under Active Attack: Patch CVE-2026-86218 Now

BleepingComputer reports N-central servers under active attack one day after N-able's CVSS 10.0 pre-auth RCE disclosure. Update to version 2026.3.1.14 immediately.

read →