ZeroHour

Search: “cve-2017-8627”

29 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Check Point Patches Critical VPN Vulnerabilities

Check Point patches two critical unauthenticated RCE flaws (CVE-2026-85102, CVE-2026-85103) in VPN gateways and firewalls; no exploitation observed.

Check Point released patches for CVE-2026-85102 and CVE-2026-85103, two critical vulnerabilities (CVSS 9.8) enabling unauthenticated remote code execution in products using VPN functionality. CVE-2026-85102 involves improper validation of certificate data during VPN negotiation, while CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoding flow. Updates cover versions R82.10, R82, and R81.20; manually defining VPN rules is offered as a mitigation, though it does not apply to locally managed Spark Firewall instances. Check Point discovered both flaws internally and reports no evidence of exploitation in the wild.

SecurityWeekupdated · 14m agofirst · 5d agoVulnerability 10 sourcesCVE-2026-85102CVE-2026-85103CVE-2026-16232+1 CVEs1

SAP Patches Critical Extended Passport Processing Vulnerability

SAP patches CVSS 10.0 flaw CVE-2026-44756 (OVERPASS) enabling unauthenticated RCE in S/4HANA and NetWeaver, plus three other criticals; no in-the-wild exploitation reported.

CVE-2026-44756 is a CVSS 10.0 memory corruption flaw in Extended Passport (EPP) deserialization, triggered when a user session opens across web, SAP GUI, and RFC vectors. Exploitation yields command execution as the SAP OS account, database credential and password hash recovery, session reading, and data or binary modification; affected products include S/4HANA, ERP/ECC, NetWeaver, Web Dispatcher, and BW/4HANA. Three other criticals were patched: CVE-2026-58240 (S4GET, missing authentication affecting all S/4HANA 2025 and earlier releases), CVE-2026-76969 (CAP credential disclosure), and CVE-2026-66768 (NetWeaver access control). Onapsis and SAP report no indicators of in-the-wild exploitation.

ConnectWise security advisory (AV26-903)

ConnectWise patches ScreenConnect CVE-2026-84869, reported exploited in the wild; administrators should update to 26.6.5.

ConnectWise shipped ScreenConnect 26.6.5 to fix a vulnerability tracked as CVE-2026-84869 affecting versions prior to 26.6.5. Open-source reporting indicates the flaw is being exploited in the wild. The Canadian Centre for Cyber Security issued advisory AV26-903 urging users and administrators to apply the patch.

Canadian Centre for Cyber Security · 7d agoAdvisory in the wildCVE-2026-84869

[0day-rubbish] OP5 Monitor 9.20 Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective) (8.8)

OP5 Monitor 9.20 remains vulnerable to CVSS 8.8 command injection because the CVE-2025-34115 fix is opt-in and ineffective.

0day Rubbish Research Team disclosed a command injection (CWE-78) in OP5 Monitor 9.20 that survives the existing CVE-2025-34115 patch, which is opt-in and described as ineffective. The issue scores CVSS 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Administrators who previously applied the vendor fix may still be exposed.

ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks

ConnectWise patched critical ScreenConnect flaw CVE-2026-84869 (CVSS 9.9) exploited since August 20 in worm-like attacks; CISA added it to KEV.

ConnectWise released urgent patches for CVE-2026-84869 (CVSS 9.9), a missing authorization and improper privilege management flaw in ScreenConnect allowing file transfer and execution through active remote sessions without host confirmation. Huntress reported in-the-wild exploitation since August 20, with attackers using rogue ScreenConnect clients to push four VBScript files for persistence and worm-like propagation to other ScreenConnect clients. The flaw is fixed in ScreenConnect 26.6.5, with disabling the TransferFiles permission as a temporary mitigation. CISA added the CVE to its KEV catalog, requiring federal agencies to patch within three days under BOD 26-04.

SecurityWeekupdated · 14h agofirst · 2d agoExploit / PoC in the wild 4 sourcesCVE-2026-848691

Citrix security advisory (AV26-645) – Update 3

Canada's Cyber Centre updates Citrix advisory as CVE-2026-8451 and CVE-2026-8452 in NetScaler ADC/Gateway are confirmed exploited in the wild.

The Canadian Centre for Cyber Security updated advisory AV26-645 on August 26, 2026, covering critical vulnerabilities in Citrix NetScaler ADC and Gateway (versions 14.1 before 14.1-72.61 and 13.1 before 13.1-63.18, plus FIPS builds). Open-source reporting indicates CVE-2026-8451 and CVE-2026-8452 are being exploited in the wild. Update 3 references related CISA action, and patched builds were released starting June 30, 2026.

USN-8675-2: Perl vulnerabilities

Ubuntu issued USN-8675-2 fixing two Perl flaws (CVE-2026-12087, CVE-2026-13221) enabling information disclosure and regex-based security bypass on 26.04 LTS.

Ubuntu released USN-8675-2, extending the fixes from USN-8675-1 to Perl packages on Ubuntu 26.04 LTS. The update addresses CVE-2026-12087, an out-of-bounds heap read in the Socket module when handling short source addresses, which could lead to information disclosure. It also fixes CVE-2026-13221, where regular expressions containing many fixed string alternatives could produce incorrect matches and bypass security restrictions. No exploitation is reported in the notice.

N-able security advisory (AV26-885)

N-able says CVE-2026-86218 in N-central is exploited in the wild; MSPs must apply hotfix 2026.3.1.14 (2026.3 HF4).

Canadian Centre for Cyber Security advisory AV26-885 covers CVE-2026-86218 in N-able N-central, which the vendor confirms is being exploited in the wild. Versions prior to 2026.3.1.14 are affected, and the fix ships as N-central 2026.3 Hotfix 4. The Cyber Centre urges users and administrators to apply the update promptly.

Canadian Centre for Cyber Security · 8d agoAdvisory in the wildCVE-2026-86218

CVE-2026-73749: HPE ArubaOS-CX RCE

HPE patched CVE-2026-73749, a critical unauthenticated remote code execution flaw in ArubaOS-CX network switch software; affected devices need prompt updates.

HPE released patches for CVE-2026-73749, a critical unauthenticated remote code execution vulnerability in HPE Aruba Networking AOS-CX switch operating system. Published details are limited, but the flaw allows unauthenticated attackers to execute code on affected AOS-CX devices. Administrators running ArubaOS-CX should prioritize applying HPE's update.

SOCRadar · 12d agoVulnerabilityCVE-2026-73749

Check Point security advisory (AV26-902)

Canada's Cyber Centre issued advisory AV26-902 warning of two Check Point RCE flaws, including VPN authentication bypass CVE-2026-85102.

The Canadian Centre for Cyber Security released advisory AV26-902 on September 9, 2026, covering vulnerabilities in Check Point Security Gateway, Spark Firewall with Site-to-Site or Remote Access VPN, and Security Management Server across multiple versions. CVE-2026-85102 is an authentication bypass and remote code execution flaw in Remote Access and Site-to-Site VPN, while CVE-2026-85103 is an ASN.1 decoding heap overflow enabling remote code execution. Administrators are urged to review the linked advisories and apply updates as they become available.

CVE-2026-89775: Guest-to-Host Escape in KVM/arm64

Disclosed CVE-2026-89775 lets a guest VM escape to the host on KVM/arm64 systems with nested virtualization enabled.

Researcher Hyunwoo Kim disclosed CVE-2026-89775, a guest-to-host escape in KVM/arm64, after the embargo agreed with linux-distros maintainers expired. The root cause is a type truncation of the stage-1 walk level that makes a size computation return 0, the value meaning 'size unknown'. The VNCR pseudo-TLB invalidation path then interprets that 0 as a valid value on ARM64 hosts where nested virtualization is enabled.

oss-security · 13h agoVulnerabilityCVE-2026-89775

CVE-2026-34908: Ubiquiti Networks UniFi OS Server access control ...

CVE-2026-34908, a CVSS 10.0 access-control bypass in Ubiquiti UniFi OS, was added to CISA's KEV catalog amid reported active exploitation.

CISA added CVE-2026-34908 to the Known Exploited Vulnerabilities catalog on June 23, 2026, with remediation due June 26 under BOD 26-04 guidance. The CVSS 10.0 improper access control flaw (CWE-284) in Ubiquiti UniFi OS allows unauthorized system changes without authentication. Multiple news reports referenced by the page describe the max-severity UniFi flaws being exploited in attacks, and an official patch is available.

OpenVPN security advisory (AV26-889)

Canada's Cyber Centre advisory AV26-889 flags CVE-2026-84732 in OpenVPN 2.6.22 and earlier and 2.7.6 and earlier, urging administrators to apply updates.

The Canadian Centre for Cyber Security issued advisory AV26-889 noting that OpenVPN versions up to and including 2.6.22 and 2.7.6 are affected by CVE-2026-84732. The flaw involves unbounded TLS timeouts and acknowledgements for non-outstanding packets in the reliability layer. Administrators are encouraged to review the linked OpenVPN guidance and apply updates as they become available. No exploitation is reported.

CVE-2026-86218 | N-able N-central Pre-Authentication Remote Code Execution Vulnerability

N-able N-central pre-auth RCE CVE-2026-86218 (CVSS 10.0) is actively exploited; CISA added it to KEV and a hotfix is available.

CVE-2026-86218 is a critical pre-authentication remote code execution flaw (CWE-96 static code injection) in N-able N-central servers, scored 10.0 CVSS 4.0 by N-able and 9.8 CVSS 3.1 by NIST. N-able fixed it in N-central 2026.3 Hotfix 4 (build 2026.3.1.14) on September 5, 2026, and has already patched hosted NCOD environments. CISA added the CVE to its Known Exploited Vulnerabilities catalog on September 8, 2026, citing evidence of active exploitation, though researchers have not attributed every reported N-central compromise to this flaw. Horizon3 released a NodeZero Rapid Response test to validate exposure and recommends log review for prior compromise.

Horizon3.ai · 13h agoExploit / PoC in the wild 13 sourcesCVE-2026-862183· 1 read

CVE-2019-1068: A remote code execution vulnerability exists in ...

CISA added CVE-2019-1068, a high-severity remote code execution flaw in Microsoft SQL Server, to its KEV catalog after confirming exploitation in the wild.

CVE-2019-1068 (CVSS 8.8, CWE-20) is an improper input validation flaw allowing unauthenticated RCE in Microsoft SQL Server 2014 SP2/SP3, 2016, and 2017 on 32-bit and x64 builds. Exploitation requires low complexity and low privileges with no user interaction, and CISA formally added it to the KEV catalog on August 26, 2026. The CVE was originally published on July 15, 2019 and carries an EPSS score of 52.8%. Administrators must inventory affected SQL Server assets and apply vendor patches on an accelerated timeline.

Microsoft fixes record 964 flaws, including 2 exploited zero-days

Microsoft's September Patch Tuesday fixes a record 964 CVEs, including two actively exploited Windows privilege-escalation zero-days, CVE-2026-81963 and CVE-2026-85880.

Microsoft's September 2026 Patch Tuesday addresses 964 customer-patchable CVEs (104 Critical, 860 Important), the largest release on record, out of 974 total listed. Two actively exploited zero-days are fixed: CVE-2026-81963, a link-following elevation-of-privilege flaw in the Windows Update Stack, and CVE-2026-85880, a Windows ALPC heap overflow enabling AppContainer sandbox escape, both with CVSS 7.8. Both zero-days were exploited before a patch was available and grant SYSTEM-level access after an initial foothold. The release also includes high-severity RCE fixes for Windows DNS Server, Remote Desktop Services, Exchange Server, SharePoint, and SQL Server.

Malwarebytes Labs · 7d agoExploit / PoC in the wildCVE-2026-81963CVE-2026-858801

Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)

Microsoft's August 2026 Patch Tuesday fixes 400+ vulnerabilities, including an actively exploited Windows zero-day (CVE-2026-68820) used by North Korean attackers.

Microsoft's August 2026 Patch Tuesday fixes over 400 vulnerabilities, including CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver exploited in the wild by North Korean actors deploying a kernel-mode rootkit in Operation Dream Job. Critical unauthenticated remote code execution flaws in Microsoft QUIC (CVE-2026-62815) and Windows DNS (CVE-2026-62878) were also patched, alongside a SharePoint RCE chain combining CVE-2026-63520 with CVE-2026-55040. Researcher Nightmare-Eclipse released ShieldBreak, a PoC bypassing the July RoguePlanet Microsoft Defender patch (CVE-2026-50656), confirmed working by Will Dormann on Windows 11.

Help Net Security · Aug 12, 2026Exploit / PoC in the wildCVE-2026-68820CVE-2026-62832CVE-2026-72971+6 CVEs1

Microsoft breaks Patch Tuesday record with 974-CVE deluge

Microsoft's record 974-CVE Patch Tuesday ships two exploited Windows zero-days, while Adobe's StyleSmuggler zero-day (CVE-2026-75650) gives unauthenticated RCE in Magento.

Microsoft's September Patch Tuesday addresses 974 CVEs, including two zero-days already under exploitation: CVE-2026-85880, a Windows ALPC privilege escalation leading to SYSTEM via sandbox escape, and CVE-2026-81963, a Windows Update Stack privilege escalation. Adobe patched 172 CVEs, including the max-severity StyleSmuggler zero-day CVE-2026-75650 in Magento and Adobe Commerce, which Sansec reports is being exploited since September 4 to inject PHP into templates and install a C2-connected backdoor. CISA added CVE-2026-85880, CVE-2026-81963, and CVE-2026-75650 to its Known Exploited Vulnerabilities Catalog with patch deadlines of September 22 and September 11. The piece also notes Google-patched Chrome V8 zero-day CVE-2026-85046 lacks a Microsoft advisory for Edge, and flags nine Exchange Server flaws including remote unauthenticated RCE CVE-2026-55007.

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

SAP patched CVE-2026-44756 (CVSS 10.0), an unauthenticated kernel memory corruption allowing OS command execution, plus three other critical flaws.

SAP's September security updates include CVE-2026-44756 (OVERPASS, CVSS 10.0), a missing boundary validation during deserialization of Extended Passport (EPP) data in the SAP kernel, enabling unauthenticated attackers to run arbitrary OS commands with SAP administrative privileges. Also patched: CVE-2026-58240 (S4GET, CVSS 9.8), a missing authentication check in SAP NetWeaver Message Server yielding RCE as <sid>adm; CVE-2026-76969 (9.4), credential disclosure in SAP Cloud Application Programming Model multi-tenant apps; and CVE-2026-66768 (9.0), improper access control in SAP NetWeaver SAP GUI for Java. Onapsis, which discovered the flaws, says none have been exploited to date and recommends prioritizing internet-facing SAP systems.

CISA Warns of SonicWall SMA1000 Vulnerabilities Active Exploitation (CVE-2026-83548 & CVE-2026-83549)

CISA added two actively exploited SonicWall SMA1000 flaws to KEV: pre-auth SSRF CVE-2026-83548 (CVSS 10) and post-auth RCE CVE-2026-83549; patch by September 5.

CISA added CVE-2026-83548 and CVE-2026-83549 to the Known Exploited Vulnerabilities Catalog with a September 5, 2026 patch deadline. CVE-2026-83548 is a critical (CVSS 10.0) pre-authentication SSRF in the SMA1000 Appliance Work Place interface; CVE-2026-83549 is a high (CVSS 7.8) post-authentication OS command injection leading to RCE in the Appliance Management Console. SMA1000 models 6210, 7210, and 8200v running 12.4.3-03453 or 12.5.0-02835 platform-hotfix and older are affected; fixes ship in 12.4.3-03526 and 12.5.0-02952. Qualys customers can detect vulnerable assets via QID 388624.

Qualys ThreatPROTECT · 13d agoExploit / PoC in the wildCVE-2026-83548CVE-2026-83549

USN-8740-1: .NET vulnerabilities

Ubuntu issued USN-8740-1 fixing two .NET watch flaws, CVE-2026-58649 and CVE-2026-69806, enabling information exposure and privilege escalation.

Ubuntu Security Notice USN-8740-1 addresses two vulnerabilities in .NET watch components. CVE-2026-58649 involves missing cross-origin WebSocket validation in BrowserRefreshServer that could expose sensitive information. CVE-2026-69806 involves improper information exposure through AspireServerService arguments, potentially allowing privilege elevation and arbitrary code execution.

Ubuntu Security Noticesupdated · 9h agofirst · 6d agoAdvisory 15 sourcesCVE-2026-58649CVE-2026-69806

Windows Remote Desktop Client Vulnerability Allows Attackers to Execute Remote Code

Microsoft patched CVE-2026-69485, an 8.8 CVSS RCE flaw in the Windows Remote Desktop Client affecting Windows 10/11 and Server 2016-2025.

Microsoft's September 2026 updates fix CVE-2026-69485, an Important-rated remote code execution vulnerability (CVSS 3.1: 8.8, temporal 7.7) in the Windows Remote Desktop Client caused by use of an uninitialized resource. An authenticated attacker with low privileges could send a specially crafted network request to execute code on an affected server, with no user interaction required. Microsoft says the flaw was not publicly disclosed before patching and rates exploitation as 'Less Likely' with no evidence of active exploitation. Affected products span Windows Server 2016, 2019, 2022 and 2025 and Windows 10 (1607-22H2) and Windows 11 (23H2-26H1), with fixes delivered via KBs including KB5123099, KB5122876 and KB5122882.

Mikrotik security advisory (AV26-887)

Canada's Cyber Centre urges MikroTik RouterOS updates as CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060 are reported exploited in the wild.

Canadian Centre for Cyber Security advisory AV26-887 covers MikroTik RouterOS vulnerabilities affecting versions prior to 6.49.21, 7.23.4, 7.24.2 and 7.25 beta 3. Open-source reporting indicates CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060 are being exploited in the wild. The Cyber Centre urges users and administrators to review the vendor advisories and apply the necessary updates.

Broadcom Patches Critical VMware Workstation and Fusion VM

Broadcom patched critical VMware Workstation and Fusion VM-escape flaws CVE-2026-59346 (CVSS 9.3) and CVE-2026-59347 (CVSS 8.1); update to 26H1u1.

Advisory VMSA-2026-0007 fixes CVE-2026-59346 (CVSS 9.3), an integer overflow in the VMXNET3 virtual network adapter, and CVE-2026-59347 (CVSS 8.1), a stack-based buffer overflow in HGFS. A malicious actor with local administrative privileges inside a VM could execute code on the host in both cases. The flaws affect Workstation and Fusion 25H2 and 26H1 and are fixed in version 26H1u1 with no workarounds available. The bugs were reported independently by researchers working with Trend Micro Zero Day Initiative and by Tencent Xuanwu Lab.

Microsoft’s Biggest Patch Tuesday: 974 CVEs, 2 Zero-Days and 20 Wormable Bugs

Microsoft's record September 2026 Patch Tuesday fixes 974 CVEs, including two exploited Windows privilege-escalation zero-days and 20 wormable bugs.

Microsoft's September 2026 Patch Tuesday fixes a record 974 CVEs, including two actively exploited zero-days: CVE-2026-85880, an ALPC heap buffer overflow, and CVE-2026-81963 in the Windows Update Stack, both CVSS 7.8 local privilege escalations. It also addresses an unauthenticated Exchange RCE (CVE-2026-55007) triggered by Visio attachment content indexing under memory pressure, an RDP use-after-free (CVE-2026-69525, CVSS 9.8), and 20 wormable flaws in DNS, DHCP, SMB, Active Directory, and other components. ZDI attributed the rising volume partly to AI-assisted vulnerability discovery, noting no corresponding spike in active exploits yet.

Security Affairs · 7d agoVulnerability in the wildCVE-2026-85880CVE-2026-81963CVE-2026-55007+3 CVEs2

USN-8741-1: Flatpak vulnerabilities

Ubuntu patched two Flatpak flaws, including a sandbox escape via app-controlled symlinks allowing host code execution (CVE-2026-34078).

Ubuntu security notice USN-8741-1 fixes two Flatpak vulnerabilities in Ubuntu 20.04 LTS, 22.04 LTS, and 24.04 LTS. CVE-2026-34078 stems from improper path validation in sandbox-expose options, letting a malicious or compromised Flatpak app use app-controlled symlinks to access arbitrary host files and gain code execution in the host context. CVE-2026-34079 involves improper path validation when removing outdated ld.so cache files, allowing a compromised app to delete arbitrary files on the host.

Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)

Microsoft's September 2026 Patch Tuesday fixes a record 964 CVEs, including two zero-days actively exploited in the wild.

Microsoft patched a record 964 CVEs in its September 2026 Patch Tuesday release, with 101 rated critical and 824 rated important, making it the largest Patch Tuesday to date. The release includes fixes for two zero-days that were exploited in the wild, with CVE-2026-81963 and CVE-2026-85880 highlighted in the release. Affected products span Windows core components, Office, Exchange, .NET, Visual Studio, Active Directory services (including AD CS and AD FS) and numerous Azure services. Tenable notes the release surpasses July's as the biggest ever.

Tenable Blog · 8d agoVulnerability in the wildCVE-2026-81963CVE-2026-858801

You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))

watchTowr Labs details a pre-authentication remote code execution flaw, tracked as CVE-2026-8452, in Citrix NetScaler appliances.

watchTowr Labs published technical analysis of a pre-authentication remote code execution vulnerability in Citrix NetScaler, tentatively assigned CVE-2026-8452. The CVE identifier is marked as provisional in the write-up. No confirmation of in-the-wild exploitation is provided in the available text.

watchTowr Labs · Aug 14, 2026Exploit / PoCCVE-2026-8452

AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489

Canadian Cyber Centre alerts on Citrix NetScaler ADC/Gateway flaws CVE-2026-19490 (authentication bypass) and CVE-2026-19489 (buffer overflow), urging emergency patching.

The Canadian Centre for Cyber Security issued alert AL26-019 covering two Citrix NetScaler vulnerabilities disclosed in a vendor advisory on August 19, 2026. CVE-2026-19490 (CWE-288) allows a remote unauthenticated attacker to bypass authentication on appliances configured as a Gateway for SSL VPN, ICA Proxy, CVPN, RDP Proxy, or as an AAA virtual server. CVE-2026-19489 (CWE-120) is a classic buffer overflow that may cause memory overflow, unpredictable behavior, or denial-of-service conditions. Affected appliances are vulnerable when configured as a SAML IdP; fixed versions include 14.1-73.32, 13.1-63.21, and 13.1-37.277 for FIPS.