LIVE · cybersecurity feed
Live wire

zero-day news

106 stories · page 1 of 3
zero-day

Hackers exploit 32 zero-days on first day of Pwn2Own Ireland

Security researchers collectively uncovered 32 zero-day vulnerabilities on the first day of the Pwn2Own Ireland 2026 competition, earning a total of $388,500. The event, organized by the Zero Day Initiative (ZDI), aims to identify critical flaws in various products before malicious actors can exploit them.

CVE-2026-88779high

Citrix NetScaler Hit by Third Actively Exploited Zero-Day

Citrix has disclosed a third actively exploited zero-day vulnerability affecting its NetScaler products, identified as CVE-2026-88779. This latest flaw, a denial-of-service vulnerability, specifically impacts NetScaler instances where Security Assertion Markup Language (SAML) is enabled. While inconvenient, security researchers generally consider its impact to be lower compared to the two…

CVE-2026-88779

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix has confirmed the active exploitation of a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler appliances. This new flaw reportedly emerged and was exploited just days after the company released patches for two other previously exploited vulnerabilities in the same product line.

CVE-2026-88779

Citrix patches NetScaler SAML zero-day exploited in attacks

Citrix has issued urgent security updates for a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler ADC and NetScaler Gateway appliances. The flaw, described as a memory buffer issue, has been actively exploited in targeted attacks, primarily leading to denial-of-service conditions.

CVE-2026-88779high

NetScaler CVE-2026-88779 Exploited Before Publication

NetScaler's CVE-2026-88779 was exploited before its official publication date, leaving no patch window. The European Union's EUVD catalogue lists it as exploited.

CVE-2026-88771critical

Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploited

A 16-year-old security researcher has identified a vulnerability in Microsoft's internal analytics service, Titan, which could have exposed employee records and Bing search analytics. The flaw reportedly provided access to 17 trillion rows of data. Microsoft has not yet issued a public statement confirming the details of the vulnerability or its remediation.

CVE-2023-54405high

CVE-2023-54405 Exploited Same Day as Publication

A vulnerability, CVE-2023-54405, was reported as exploited on the same day it was published. This flaw has an 'Unrestricted Upload of File with Dangerous Type' vulnerability.

CVE-2014-125130high

CVE-2014-125130 Exploited Same Day as Publication

A path traversal vulnerability, CVE-2014-125130, was reported as exploited on the same day its CVE record was published. The vulnerability is listed in the VulnCheck KEV catalogue but not in CISA KEV or EUVD.

CVE-2020-37278high

CVE-2020-37278 SSRF Exploited Same Day as Publication

A server-side request forgery vulnerability, CVE-2020-37278, was reportedly exploited on the same day it was published. The flaw has a zero-day patch window.

divdhigh

Dutch Vulnerability Institute Breached Via Zammad 0-Days

The Dutch Institute for Vulnerability Disclosure (DIVD) has reportedly suffered a security breach, with attackers exploiting two zero-day vulnerabilities in the Zammad ticketing system. The incident led to remote code execution and ultimately granted the attackers root access to affected systems.

zero-day

Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response

Recent security incidents involving Kiteworks and Citrix have highlighted the significant challenges organizations face in responding to zero-day vulnerabilities, particularly concerning communication and mitigation strategies. The incidents presented contrasting approaches to managing critical security flaws, with one vendor issuing an immediate and drastic mitigation directive while the…

CVE-2026-102489critical

Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Disclosure

The Dutch Institute for Vulnerability Disclosure (DIVD), a cybersecurity non-profit, recently disclosed that it was compromised in an attack that exploited two zero-day vulnerabilities in its Zammad helpdesk platform. The incident, detected on September 24, involved the use of what DIVD describes as an "agentic AI" to execute the attack.

CVE-2026-104286critical

Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

A critical-severity zero-day vulnerability, tracked as CVE-2026-104286, has been reported in Fortinet's FortiMail email security gateway. The flaw is described as a path traversal vulnerability that permits attackers to write arbitrary files to the underlying system. Organizations leveraging FortiMail deployments are advised to take immediate mitigation steps due to the active exploitation of…

CVE-2026-104286critical

Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

Fortinet has issued a warning regarding a critical vulnerability in its FortiMail email security platform, identified as CVE-2026-104286, which is actively being exploited in zero-day attacks. The flaw, rated with a CVSS score of 9.8, affects the FortiMail management interface and could allow an unauthenticated attacker to execute arbitrary code or commands.

CVE-2023-54403high

Yonyou U8 CRM Path Traversal Flaw Exploited Same Day as Disclosure

CVE-2023-54403, a path traversal vulnerability in Yonyou U8 CRM, was reported as exploited on the same day its CVE record was published. The flaw has no patch window.

CVE-2024-58387high

Inspur Haiyue HCM Cloud Path Traversal Flaw Exploited Same Day

CVE-2024-58387, a path traversal vulnerability in Inspur Haiyue HCM Cloud, was reported as exploited on the same day it was published. The flaw is listed in the VulnCheck KEV catalogue but not in CISA KEV or EUVD.

CVE-2026-104286high

Fortinet FortiMail Path Traversal Flaw Exploited Same Day as Disclosure

A path traversal vulnerability in Fortinet FortiMail was exploited on the same day it was disclosed, leaving no patch window for affected organizations.

breach

AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit

The Dutch Institute for Vulnerability Disclosure (DIVD), a non-profit organization that identifies and reports software vulnerabilities, confirmed it was breached on September 21 through the exploitation of two zero-day vulnerabilities in Zammad, an open-source helpdesk and customer support ticketing system. The attack was attributed to an "agentic AI" system, which reportedly used the flaws…

vulnerability

Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft

Cryptocurrency exchange Bitget has confirmed that a recent theft of $387.5 million was facilitated by the exploitation of a zero-day vulnerability in third-party security products. The confirmation, based on ongoing investigation findings from blockchain security firm SlowMist, indicates that malicious activity involved these external security solutions. Investigators reportedly recovered a…

CVE-2026-88771

Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks

Reports indicate that government and finance organizations have been targeted in weeks-long attacks exploiting zero-day vulnerabilities in NetScaler products. The attacks leverage two specific vulnerabilities, identified as CVE-2026-88771 and CVE-2026-88772, with multiple security firms confirming observed exploitation.

CVE-2026-88772

Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)

Suspected state-sponsored threat actors have been exploiting a zero-day vulnerability in NetScaler Application Delivery Controllers (ADCs) and Gateways, identified as CVE-2026-88772, since at least early September 2026. This flaw, along with a related vulnerability, CVE-2026-88771, allows for remote code execution on affected appliances. Citrix confirmed the active exploitation of both…

CVE-2026-86950

Apple Zero-Day Vulnerability Weaponized in Targeted Attacks

Apple has reported that a zero-day vulnerability, identified as CVE-2026-86950, is actively being exploited in targeted attacks. The company described the exploitation as highly sophisticated, indicating a significant level of attacker capability. This out-of-bounds write flaw affects Apple products, though specific affected versions or devices were not detailed in the announcement.

zero-day

Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected

Attackers exploited a critical zero-day vulnerability in Citrix NetScaler appliances for at least three weeks before its public disclosure and the release of patches, according to security researchers. The vulnerability, identified as CVE-2026-88772, was first exploited on September 3, with widespread attacks affecting dozens of organizations across North America and Europe. These…

CVE-2015-20122high

CVE-2015-20122 Exploited Same Day as Publication

A SQL injection vulnerability, CVE-2015-20122, was reported as exploited on the same day its CVE record was published. The flaw has no patch window.

CVE-2023-54400high

SQL Injection Flaw Exploited Same Day CVE Was Published

CVE-2023-54400, an SQL injection vulnerability, was reported as exploited on the same day its CVE record was published. The flaw is listed in the VulnCheck KEV catalogue but not in CISA KEV or EUVD.

CVE-2026-88771critical

Hackers exploit Citrix NetScaler zero-day to deploy web shells

Attackers have been exploiting two zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, designated CVE-2026-88771 and CVE-2026-88772, to gain root access, deploy web shells, and infiltrate internal networks. Citrix confirmed the active exploitation of both flaws and released security updates to address them.

CVE-2026-88771critical

Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services

Attackers have exploited two critical zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances, designated CVE-2026-88771 and CVE-2026-88772, to compromise government agencies, financial services firms, educational institutions, and legal and professional services organizations across North America and Europe. The exploitation campaign began in early September, weeks…

CVE-2026-84434high

CVE-2026-84434 Exploited Before Publication, No Patch Window

A critical vulnerability, CVE-2026-84434, was reported as exploited on September 18, 2026, one day before its official publication. This flaw has no patch window and is listed in the VulnCheck KEV but not in CISA KEV or EUVD.

CVE-2017-20284high

CVE-2017-20284 Exploited Same Day as Publication

A path traversal vulnerability, CVE-2017-20284, was reported as exploited on the same day it was published. The flaw is listed in the VulnCheck KEV catalogue but not in CISA or EUVD catalogues.

CVE-2026-87886high

Acronis Backup Flaw Exploited Before CVE Publication

The Acronis Backup Incorrect Default Permissions Vulnerability (CVE-2026-87886) was reported as exploited two days before its official CVE publication date, leaving no patch window for affected organizations.

CVE-2026-76460

Cisco Zero-Day Highlights API Endpoint Authentication Issues

A critical authentication bypass vulnerability, designated CVE-2026-76460, has been reported in Cisco's Identity Services Engine (ISE). The flaw has been assigned a maximum CVSS score of 10.0, indicating its severe potential impact. This zero-day issue reportedly allows for an authentication bypass, highlighting significant concerns regarding API endpoint security within the affected product.

vulnerabilityhigh

Cisco alerts customers to second actively exploited zero-day in as many days

Cisco has issued an alert to customers regarding a second actively exploited zero-day vulnerability discovered within days, affecting its Identity Services Engine (ISE) product. The flaw, identified as CVE-2026-76460, carries a maximum severity rating of 10.0 and was exploited in the wild prior to Cisco's disclosure and subsequent patch release on Wednesday, September 17, 2026.

vulnerabilityhigh

Cisco warns of max severity ISE zero-day exploited in attacks

Cisco has issued an urgent warning regarding a maximum-severity zero-day vulnerability in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products, which is actively being exploited in the wild. The flaw, identified as CVE-2026-76460, allows remote attackers to bypass authentication by exploiting an API weakness, regardless of the system's configuration.

vulnerability

Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day

Cisco has released an emergency security patch for a zero-day vulnerability affecting its Identity Services Engine (ISE) product, following reports of active exploitation. The flaw allows remote, unauthenticated attackers to bypass authentication mechanisms by sending specially crafted requests to affected ISE instances. This critical update addresses a significant security risk given the…

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Cisco Secure Email Gateway, identified as CVE-2026-76461, to its Known Exploited Vulnerabilities (KEV) catalog. This addition mandates that federal civilian executive branch (FCEB) agencies address the flaw by September 17, 2026, to protect their networks from active exploitation.

zero-day

BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

Reports indicate that the BlueMoon exploit kit is actively being used by several espionage-motivated threat actors. This kit is notable for chaining together recently discovered zero-day vulnerabilities affecting both Google Chrome and Microsoft Windows. The adoption of BlueMoon appears to be opportunistic, with threat actors deploying it in what are described as rushed operations.

CVE-2025-66516high

Metasploit Wrap Up: This One Goes to Sixteen!

A recent update to the Metasploit framework has introduced sixteen new modules, including ten exploit modules, five of which address vulnerabilities listed on the CISA Known Exploited Vulnerabilities (KEV) catalog. The new exploits target products from Cisco, PaperCut, SonicWall, JetBrains, and Langflow, among others.

vulnerability

New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

Multiple cyber-espionage groups have deployed an exploit kit dubbed BlueMoon, which leverages zero-day vulnerabilities in Microsoft Windows and Google Chrome. The kit combines two security issues in Chromium-based browsers that enable remote code execution and sandbox escape, with a kernel local privilege escalation flaw in Windows.

vulnerabilitycritical

Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026

Microsoft's September 2026 Patch Tuesday release included fixes for a record-breaking 974 Common Vulnerabilities and Exposures (CVEs), significantly surpassing its previous record of 570 CVEs set in July 2026. This substantial increase in patched vulnerabilities follows a warning issued by Microsoft in July, advising customers to anticipate a surge in security updates for Windows products due…

CVE-2026-87491high

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google has reportedly issued an urgent update for its Chrome browser, addressing a critical zero-day vulnerability that has been actively exploited in the wild. The flaw, identified as an out-of-bounds write bug within the V8 JavaScript and WebAssembly engine, allows for code execution within the browser's sandbox environment. This update is part of a broader patch release addressing numerous…

CVE-2026-69414

September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor

Microsoft's September 2026 Patch Tuesday release included a record number of fixes, addressing two zero-day vulnerabilities that have been actively exploited in the wild. The update also contained patches for several other critical issues, including a cluster of 20 "wormable" bugs and a DNS flaw described as a successor to SigRed.

vulnerabilityhigh

Microsoft discloses two actively exploited zero-days among 974 vulnerabilities

Microsoft has released its monthly Patch Tuesday security update, addressing a record 974 vulnerabilities across its product suite. This extensive update includes fixes for two actively exploited zero-day vulnerabilities, CVE-2026-81963 and CVE-2026-85880, both of which allow for privilege escalation and have a CVSS rating of 7.8.

CVE-2026-16759high

Themeum Tutor LMS Vulnerability Exploited Same Day as Disclosure

A critical vulnerability in the Themeum Tutor LMS plugin was exploited on the same day its CVE was published, leaving no patch window for users. The flaw is listed in VulnCheck's Known Exploited Vulnerabilities catalogue.

CVE-2026-19632critical

TranslatePress Flaw Exploited Before CVE Published

A critical vulnerability in the TranslatePress WordPress plugin was exploited before its official CVE publication date, leaving no patch window for administrators.

CVE-2026-76904critical

GeoTools SQL Injection Flaw Exploited Same Day as Disclosure

A critical SQL injection vulnerability in GeoTools was exploited on the same day it was publicly disclosed, leaving no patch window for affected users. The flaw impacts versions prior to 33.6, 34.5, and 33.6.

CVE-2026-77136high

TYPO3 Powermail Extension Exploited Same Day CVE Published

CVE-2026-77136, a template engine vulnerability in TYPO3's Powermail extension, was reportedly exploited on the same day its CVE record was published. No patch window existed.

CVE-2024-58374high

CVE-2024-58374: Hongjing e-HR SQL Injection Exploited on Disclosure Day

A critical SQL injection vulnerability in Hongjing Century e-HR was exploited on the same day it was publicly disclosed, leaving no patch window for affected organizations.

CVE-2023-7330high

Ruijie Networks Routers Exploited Same Day CVE-2023-7330 Was Published

CVE-2023-7330, an unrestricted file upload vulnerability in Ruijie Networks NBR Series Routers, was exploited on the same day it was disclosed, leaving no patch window.