ZeroHour

Search: “api”

484 stories

2026-002: Multiple Vulnerabilities in Cisco Products

Cisco fixed SD-WAN Controller auth bypass CVE-2026-20127 (CVSS 10) exploited in the wild since 2023, plus several critical and high flaws in SD-WAN Manager.

On 25 February 2026 Cisco released advisories for multiple flaws in Catalyst SD-WAN Controller and SD-WAN Manager, potentially granting administrative access to attackers. CVE-2026-20127 (CVSS 10.0) is an authentication bypass in the Controller's peering authentication mechanism, exploited in the wild since 2023, allowing unauthenticated admin access via NETCONF, rogue device injection, and persistent access. SD-WAN Manager flaws include CVE-2026-20129 (9.8, unauthenticated API auth bypass to netadmin), CVE-2026-20126 (7.8, local privesc to root), CVE-2026-20133 (7.5, info disclosure), CVE-2026-20122 (7.1, arbitrary file overwrite), and CVE-2026-20128 (5.5, DCA info disclosure). CERT-EU recommends patching, capturing forensic evidence, IOC hunting, and restricting management-plane internet exposure.

CERT-EU Advisories · Feb 10, 2026Exploit / PoC in the wildCVE-2026-20127CVE-2026-20129CVE-2026-20126+3 CVEs

"WP2Shell" Critical WordPress RCE Chain (CVE-2026-63030 & CVE-2026-60137)

CISA added the WordPress core pre-auth RCE chain (CVE-2026-63030, CVE-2026-60137) to KEV after confirmed exploitation; WordPress 6.9.5 and 7.0.2 fix the flaws.

On July 17, 2026 WordPress disclosed CVE-2026-63030, a REST API route-confusion flaw, and CVE-2026-60137, a SQL injection in WP_Query, which chain to unauthenticated remote code execution on default installs of WordPress 6.9.0-6.9.4 and 7.0.0-7.0.1. CISA has added both to the Known Exploited Vulnerabilities Catalog and active exploitation is confirmed. Cloudflare deployed WAF rules at 17:03 UTC on July 17, and patches are available in WordPress 6.9.5 and 7.0.2.

Critical N-able N-central Vulnerability and Active Exploitation

N-able N-central pre-auth RCE zero-day CVE-2026-86218 (CVSS 10.0) is exploited in the wild; on-prem admins must upgrade to 2026.3 HF4.

N-able disclosed a third N-central vulnerability, CVE-2026-86218, a pre-authentication RCE rated CVSS 10.0, and released hotfix 2026.3 HF4 superseding build 2026.3.1.13. Huntress reproduced an exploit chain involving an authentication bypass (CVE-2026-86206/CVE-2026-86207) after a fully patched customer's N-central production server was compromised on September 4. Attackers appended strings like .invalid to account names and probed the /remoteControlAction.do?method=getPierDetails endpoint; Huntress worked with Cloudflare to disable adversary tunnel infrastructure. Hosted N-central instances are already patched; on-prem administrators must upgrade immediately.

Huntress · 9d agoExploit / PoC in the wildCVE-2026-86218CVE-2026-86206CVE-2026-86207+2 CVEs