Skip to content
feed: live
>_0dayNews
$ briefings

Briefings

Periodic SITREPs that compress the week's vulnerability and exploit news into a single readable digest, sourced throughout.

28
editions
172
items covered
19
critical flags
~/briefings/2026-09-03 --latest
Latest edition·September 3, 2026

Sep 3: Elasticsearch ML RCE, Seven KEV Additions, FalconFlank PoC

Elasticsearch patches CVSS 8.8 RCE in its machine learning module. CISA adds seven exploited flaws to KEV. CrowdStrike Falcon privilege escalation PoC published.

1c2h1m
KEV0-DAYOT/ICS
  • Elasticsearch patches CVE-2026-72649 (CVSS 8.8): deserialization flaw in the machine learning module enables RCE via crafted model artifact. Affected versions in the 8.x and 9.x branches.
  • CISA adds seven exploited flaws to KEV. Confirmed entry: CVE-2026-9586 (Sangoma Switchvox unauthenticated SQL injection, CVSS 9.8). Attackers deploying reverse shells and crypto miners across affected products.
  • CrowdStrike Falcon: researcher Chaotic Eclipse releases FalconFlank PoC for a privilege escalation zero-day. No CVE assigned publicly as of this briefing.
  • Forescout Vedere Labs used Claude to port a working pre-auth RCE exploit across WAGO PLC models. Cross-vendor ICS exploit reuse demonstrated with AI assistance.
Read full briefing →
$ archive

September 2026

August 2026

July 2026

June 2026

Archive begins June 29, 2026.