Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-20349
[ HIGH ]CVSS 8.6EPSS 0.9%kev

Cisco ASA and FTD VPN Heap Inspection Denial-of-Service Flaw

Unauthenticated remote attackers can crash Cisco Secure Firewall ASA and FTD devices over VPN. Added to CISA KEV on 2026-08-11 with a three-day federal remediation deadline.

Cisco / Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
CVE-2026-68820
[ HIGH ]CVSS 7.0EPSS 0.3%kev

Windows AFD WinSock Use-After-Free Privilege Escalation

Use-after-free in Windows Ancillary Function Driver for WinSock (afd.sys) lets local attackers gain SYSTEM privileges via race condition. Actively exploited by Lazarus.

Microsoft / Windows (multiple versions)
CVE-2026-72898
[ CRITICAL ]CVSS 10.0EPSS 10.4%kev

Metabase SQL Injection Vulnerability

Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.

Metabase / Metabase
CVE-2026-18556
[ HIGH ]CVSS 7.4EPSS 0.5%kev

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.

N-able / N-central
CVE-2026-34486
[ HIGH ]CVSS 7.5EPSS 82.9%kev

Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.

Apache / Tomcat
CVE-2026-9198
[ CRITICAL ]CVSS 9.8EPSS 17.4%kev

IBM Langflow Code Injection Vulnerability

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

IBM / Langflow
$ latest --more

From the desk

all articles →
~/articles/2026-08-15-evooo1bot-linux-botnet-routers-socks5-relay
Evooo1Bot Turns Routers Into SOCKS5 Relay Nodes
Analysis
threat intel

Evooo1Bot Turns Routers Into SOCKS5 Relay Nodes

A Mirai-based modular Linux botnet is converting compromised routers into SOCKS5 relay nodes — the same ORB infrastructure pattern, repackaged again.

read →
~/articles/2026-08-15-mcp-memory-service-cve-2026-50027-auth-bypass
Unauth Access to AI Memory: CVE-2026-50027 Patched
mcp

Unauth Access to AI Memory: CVE-2026-50027 Patched

CVE-2026-50027: mcp-memory-service exposed all /api/documents/* routes without auth, letting anyone read, write, or delete AI memories. Patch to 10.67.1.

read →
~/articles/2026-08-15-cve-2026-69414-shieldbreak-malware-protection-engine
ShieldBreak: New Unpatched EoP in Defender Scan Engine
microsoft

ShieldBreak: New Unpatched EoP in Defender Scan Engine

CVE-2026-69414 is a second ShieldBreak-tagged EoP — this one in Defender's Malware Protection Engine, CVSS 7.8. No patch yet. MSRC advisory is live.

read →
~/articles/2026-08-15-cisa-icsa-26-225-01-ics-deserialization-cve-2025-7639
CISA ICS Advisory: SCADA Deserialization Bug CVE-2025-7639
ics ot

CISA ICS Advisory: SCADA Deserialization Bug CVE-2025-7639

CISA advisory ICSA-26-225-01 covers CVE-2025-7639, a deserialization flaw that lets authenticated ICS operators execute code at elevated privilege.

read →
~/articles/2026-08-15-nist-ai-cve-backlog-vulnerability-surge
NIST Bets on AI to Clear AI-Created CVE Backlog
Analysis
threat intel

NIST Bets on AI to Clear AI-Created CVE Backlog

AI tools are flooding the CVE pipeline faster than NVD can enrich them. NIST's proposed fix is more AI — a structural response to a structural problem, with real triage implications downstream.

read →
~/articles/2026-08-15-geoserver-sqli-rce-zero-day-exploited
GeoServer Zero-Day Under Active Attack, No Patch Available
threat intel

GeoServer Zero-Day Under Active Attack, No Patch Available

An unpatched SQL injection in GeoServer enables RCE on PostGIS and Oracle deployments. WatchTowr logged hundreds of probe attempts within hours of public disclosure.

read →