zero-day news
106 stories · page 1 of 3
Hackers exploit 32 zero-days on first day of Pwn2Own Ireland
Security researchers collectively uncovered 32 zero-day vulnerabilities on the first day of the Pwn2Own Ireland 2026 competition, earning a total of $388,500. The event, organized by the Zero Day Initiative (ZDI), aims to identify critical flaws in various products before malicious actors can exploit them.

Citrix NetScaler Hit by Third Actively Exploited Zero-Day
Citrix has disclosed a third actively exploited zero-day vulnerability affecting its NetScaler products, identified as CVE-2026-88779. This latest flaw, a denial-of-service vulnerability, specifically impacts NetScaler instances where Security Assertion Markup Language (SAML) is enabled. While inconvenient, security researchers generally consider its impact to be lower compared to the two…

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier
Citrix has confirmed the active exploitation of a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler appliances. This new flaw reportedly emerged and was exploited just days after the company released patches for two other previously exploited vulnerabilities in the same product line.

Citrix patches NetScaler SAML zero-day exploited in attacks
Citrix has issued urgent security updates for a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler ADC and NetScaler Gateway appliances. The flaw, described as a memory buffer issue, has been actively exploited in targeted attacks, primarily leading to denial-of-service conditions.

NetScaler CVE-2026-88779 Exploited Before Publication
NetScaler's CVE-2026-88779 was exploited before its official publication date, leaving no patch window. The European Union's EUVD catalogue lists it as exploited.

Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploited
A 16-year-old security researcher has identified a vulnerability in Microsoft's internal analytics service, Titan, which could have exposed employee records and Bing search analytics. The flaw reportedly provided access to 17 trillion rows of data. Microsoft has not yet issued a public statement confirming the details of the vulnerability or its remediation.

CVE-2023-54405 Exploited Same Day as Publication
A vulnerability, CVE-2023-54405, was reported as exploited on the same day it was published. This flaw has an 'Unrestricted Upload of File with Dangerous Type' vulnerability.

CVE-2014-125130 Exploited Same Day as Publication
A path traversal vulnerability, CVE-2014-125130, was reported as exploited on the same day its CVE record was published. The vulnerability is listed in the VulnCheck KEV catalogue but not in CISA KEV or EUVD.

CVE-2020-37278 SSRF Exploited Same Day as Publication
A server-side request forgery vulnerability, CVE-2020-37278, was reportedly exploited on the same day it was published. The flaw has a zero-day patch window.

Dutch Vulnerability Institute Breached Via Zammad 0-Days
The Dutch Institute for Vulnerability Disclosure (DIVD) has reportedly suffered a security breach, with attackers exploiting two zero-day vulnerabilities in the Zammad ticketing system. The incident led to remote code execution and ultimately granted the attackers root access to affected systems.

Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response
Recent security incidents involving Kiteworks and Citrix have highlighted the significant challenges organizations face in responding to zero-day vulnerabilities, particularly concerning communication and mitigation strategies. The incidents presented contrasting approaches to managing critical security flaws, with one vendor issuing an immediate and drastic mitigation directive while the…

Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Disclosure
The Dutch Institute for Vulnerability Disclosure (DIVD), a cybersecurity non-profit, recently disclosed that it was compromised in an attack that exploited two zero-day vulnerabilities in its Zammad helpdesk platform. The incident, detected on September 24, involved the use of what DIVD describes as an "agentic AI" to execute the attack.

Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action
A critical-severity zero-day vulnerability, tracked as CVE-2026-104286, has been reported in Fortinet's FortiMail email security gateway. The flaw is described as a path traversal vulnerability that permits attackers to write arbitrary files to the underlying system. Organizations leveraging FortiMail deployments are advised to take immediate mitigation steps due to the active exploitation of…

Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
Fortinet has issued a warning regarding a critical vulnerability in its FortiMail email security platform, identified as CVE-2026-104286, which is actively being exploited in zero-day attacks. The flaw, rated with a CVSS score of 9.8, affects the FortiMail management interface and could allow an unauthenticated attacker to execute arbitrary code or commands.

Yonyou U8 CRM Path Traversal Flaw Exploited Same Day as Disclosure
CVE-2023-54403, a path traversal vulnerability in Yonyou U8 CRM, was reported as exploited on the same day its CVE record was published. The flaw has no patch window.

Inspur Haiyue HCM Cloud Path Traversal Flaw Exploited Same Day
CVE-2024-58387, a path traversal vulnerability in Inspur Haiyue HCM Cloud, was reported as exploited on the same day it was published. The flaw is listed in the VulnCheck KEV catalogue but not in CISA KEV or EUVD.

Fortinet FortiMail Path Traversal Flaw Exploited Same Day as Disclosure
A path traversal vulnerability in Fortinet FortiMail was exploited on the same day it was disclosed, leaving no patch window for affected organizations.

AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit
The Dutch Institute for Vulnerability Disclosure (DIVD), a non-profit organization that identifies and reports software vulnerabilities, confirmed it was breached on September 21 through the exploitation of two zero-day vulnerabilities in Zammad, an open-source helpdesk and customer support ticketing system. The attack was attributed to an "agentic AI" system, which reportedly used the flaws…

Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
Cryptocurrency exchange Bitget has confirmed that a recent theft of $387.5 million was facilitated by the exploitation of a zero-day vulnerability in third-party security products. The confirmation, based on ongoing investigation findings from blockchain security firm SlowMist, indicates that malicious activity involved these external security solutions. Investigators reportedly recovered a…

Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks
Reports indicate that government and finance organizations have been targeted in weeks-long attacks exploiting zero-day vulnerabilities in NetScaler products. The attacks leverage two specific vulnerabilities, identified as CVE-2026-88771 and CVE-2026-88772, with multiple security firms confirming observed exploitation.

Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)
Suspected state-sponsored threat actors have been exploiting a zero-day vulnerability in NetScaler Application Delivery Controllers (ADCs) and Gateways, identified as CVE-2026-88772, since at least early September 2026. This flaw, along with a related vulnerability, CVE-2026-88771, allows for remote code execution on affected appliances. Citrix confirmed the active exploitation of both…

Apple Zero-Day Vulnerability Weaponized in Targeted Attacks
Apple has reported that a zero-day vulnerability, identified as CVE-2026-86950, is actively being exploited in targeted attacks. The company described the exploitation as highly sophisticated, indicating a significant level of attacker capability. This out-of-bounds write flaw affects Apple products, though specific affected versions or devices were not detailed in the announcement.

Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected
Attackers exploited a critical zero-day vulnerability in Citrix NetScaler appliances for at least three weeks before its public disclosure and the release of patches, according to security researchers. The vulnerability, identified as CVE-2026-88772, was first exploited on September 3, with widespread attacks affecting dozens of organizations across North America and Europe. These…

CVE-2015-20122 Exploited Same Day as Publication
A SQL injection vulnerability, CVE-2015-20122, was reported as exploited on the same day its CVE record was published. The flaw has no patch window.

SQL Injection Flaw Exploited Same Day CVE Was Published
CVE-2023-54400, an SQL injection vulnerability, was reported as exploited on the same day its CVE record was published. The flaw is listed in the VulnCheck KEV catalogue but not in CISA KEV or EUVD.

Hackers exploit Citrix NetScaler zero-day to deploy web shells
Attackers have been exploiting two zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, designated CVE-2026-88771 and CVE-2026-88772, to gain root access, deploy web shells, and infiltrate internal networks. Citrix confirmed the active exploitation of both flaws and released security updates to address them.

Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services
Attackers have exploited two critical zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances, designated CVE-2026-88771 and CVE-2026-88772, to compromise government agencies, financial services firms, educational institutions, and legal and professional services organizations across North America and Europe. The exploitation campaign began in early September, weeks…
CVE-2026-84434 Exploited Before Publication, No Patch Window
A critical vulnerability, CVE-2026-84434, was reported as exploited on September 18, 2026, one day before its official publication. This flaw has no patch window and is listed in the VulnCheck KEV but not in CISA KEV or EUVD.

CVE-2017-20284 Exploited Same Day as Publication
A path traversal vulnerability, CVE-2017-20284, was reported as exploited on the same day it was published. The flaw is listed in the VulnCheck KEV catalogue but not in CISA or EUVD catalogues.

Acronis Backup Flaw Exploited Before CVE Publication
The Acronis Backup Incorrect Default Permissions Vulnerability (CVE-2026-87886) was reported as exploited two days before its official CVE publication date, leaving no patch window for affected organizations.

Cisco Zero-Day Highlights API Endpoint Authentication Issues
A critical authentication bypass vulnerability, designated CVE-2026-76460, has been reported in Cisco's Identity Services Engine (ISE). The flaw has been assigned a maximum CVSS score of 10.0, indicating its severe potential impact. This zero-day issue reportedly allows for an authentication bypass, highlighting significant concerns regarding API endpoint security within the affected product.

Cisco alerts customers to second actively exploited zero-day in as many days
Cisco has issued an alert to customers regarding a second actively exploited zero-day vulnerability discovered within days, affecting its Identity Services Engine (ISE) product. The flaw, identified as CVE-2026-76460, carries a maximum severity rating of 10.0 and was exploited in the wild prior to Cisco's disclosure and subsequent patch release on Wednesday, September 17, 2026.

Cisco warns of max severity ISE zero-day exploited in attacks
Cisco has issued an urgent warning regarding a maximum-severity zero-day vulnerability in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products, which is actively being exploited in the wild. The flaw, identified as CVE-2026-76460, allows remote attackers to bypass authentication by exploiting an API weakness, regardless of the system's configuration.

Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day
Cisco has released an emergency security patch for a zero-day vulnerability affecting its Identity Services Engine (ISE) product, following reports of active exploitation. The flaw allows remote, unauthenticated attackers to bypass authentication mechanisms by sending specially crafted requests to affected ISE instances. This critical update addresses a significant security risk given the…

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Cisco Secure Email Gateway, identified as CVE-2026-76461, to its Known Exploited Vulnerabilities (KEV) catalog. This addition mandates that federal civilian executive branch (FCEB) agencies address the flaw by September 17, 2026, to protect their networks from active exploitation.

BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
Reports indicate that the BlueMoon exploit kit is actively being used by several espionage-motivated threat actors. This kit is notable for chaining together recently discovered zero-day vulnerabilities affecting both Google Chrome and Microsoft Windows. The adoption of BlueMoon appears to be opportunistic, with threat actors deploying it in what are described as rushed operations.

Metasploit Wrap Up: This One Goes to Sixteen!
A recent update to the Metasploit framework has introduced sixteen new modules, including ten exploit modules, five of which address vulnerabilities listed on the CISA Known Exploited Vulnerabilities (KEV) catalog. The new exploits target products from Cisco, PaperCut, SonicWall, JetBrains, and Langflow, among others.

New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws
Multiple cyber-espionage groups have deployed an exploit kit dubbed BlueMoon, which leverages zero-day vulnerabilities in Microsoft Windows and Google Chrome. The kit combines two security issues in Chromium-based browsers that enable remote code execution and sandbox escape, with a kernel local privilege escalation flaw in Windows.

Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026
Microsoft's September 2026 Patch Tuesday release included fixes for a record-breaking 974 Common Vulnerabilities and Exposures (CVEs), significantly surpassing its previous record of 570 CVEs set in July 2026. This substantial increase in patched vulnerabilities follows a warning issued by Microsoft in July, advising customers to anticipate a surge in security updates for Windows products due…

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
Google has reportedly issued an urgent update for its Chrome browser, addressing a critical zero-day vulnerability that has been actively exploited in the wild. The flaw, identified as an out-of-bounds write bug within the V8 JavaScript and WebAssembly engine, allows for code execution within the browser's sandbox environment. This update is part of a broader patch release addressing numerous…

September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor
Microsoft's September 2026 Patch Tuesday release included a record number of fixes, addressing two zero-day vulnerabilities that have been actively exploited in the wild. The update also contained patches for several other critical issues, including a cluster of 20 "wormable" bugs and a DNS flaw described as a successor to SigRed.

Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Microsoft has released its monthly Patch Tuesday security update, addressing a record 974 vulnerabilities across its product suite. This extensive update includes fixes for two actively exploited zero-day vulnerabilities, CVE-2026-81963 and CVE-2026-85880, both of which allow for privilege escalation and have a CVSS rating of 7.8.

Themeum Tutor LMS Vulnerability Exploited Same Day as Disclosure
A critical vulnerability in the Themeum Tutor LMS plugin was exploited on the same day its CVE was published, leaving no patch window for users. The flaw is listed in VulnCheck's Known Exploited Vulnerabilities catalogue.

TranslatePress Flaw Exploited Before CVE Published
A critical vulnerability in the TranslatePress WordPress plugin was exploited before its official CVE publication date, leaving no patch window for administrators.

GeoTools SQL Injection Flaw Exploited Same Day as Disclosure
A critical SQL injection vulnerability in GeoTools was exploited on the same day it was publicly disclosed, leaving no patch window for affected users. The flaw impacts versions prior to 33.6, 34.5, and 33.6.

TYPO3 Powermail Extension Exploited Same Day CVE Published
CVE-2026-77136, a template engine vulnerability in TYPO3's Powermail extension, was reportedly exploited on the same day its CVE record was published. No patch window existed.

CVE-2024-58374: Hongjing e-HR SQL Injection Exploited on Disclosure Day
A critical SQL injection vulnerability in Hongjing Century e-HR was exploited on the same day it was publicly disclosed, leaving no patch window for affected organizations.

Ruijie Networks Routers Exploited Same Day CVE-2023-7330 Was Published
CVE-2023-7330, an unrestricted file upload vulnerability in Ruijie Networks NBR Series Routers, was exploited on the same day it was disclosed, leaving no patch window.