Zero-Day Security News

Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.

A zero-day is a vulnerability under active exploitation before the vendor has shipped, or even discovered, a fix, leaving defenders with nothing to patch against yet. Disclosures and in-the-wild exploitation show up here, along with the emergency patches that usually follow. These are the highest-urgency items in the feed: attackers already have working exploits by the time most zero-days go public.

Recent Zero-Day items

Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway 🚨 The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC an…
@cibsecurity · Sep 28, 2026
Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway https://ift.tt/limhOQp
@ctinow · Sep 28, 2026
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild https://securityaffairs.com/199882/security/roundcube-sql-injection-cve-2026-48842-is-now-being-exploited-in-the-wild.html
@PentestingNews · Sep 28, 2026
Citrix Confirmed Two New NetScaler Flaws Exploited as Zero-Day https://securityaffairs.com/199873/security/citrix-confirmed-two-new-netscaler-flaws-exploited-as-zero-day.html
@PentestingNews · Sep 28, 2026
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild https://ift.tt/domk749
@ctinow · Sep 28, 2026
Citrix Confirmed Two New NetScaler Flaws Exploited as Zero-Day https://ift.tt/KrOvaZ6
@ctinow · Sep 27, 2026
Researchers Warn of Citrix NetScaler Zero Day Exploitation https://decipher.sc/2026/09/27/researchers-warn-of-citrix-netscaler-exploitation/
@secharvester · Sep 27, 2026
Citrix admins warned to shut down NetScalers over 2 exploited zero-days Two unpatched Citrix NetScaler zero-day vulnerabilities are reportedly being exploited in attacks, with cybersecurity agencies,…
@bleepingcomputer · Sep 27, 2026
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation 🖋️ Two new unpatched zeroday vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote…
@cibsecurity · Sep 27, 2026
WARNING — Citrix NetScaler is facing two unpatched RCE 0-days under active exploitation. Researchers at watchTowr say the flaws are being exploited in the wild. Citrix has not confirmed them or releas…
@thehackernews · Sep 27, 2026
SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild 🖋️ The U.S. Cybersecurity and Infrastructure Security Agency CISA on Friday added two security flaws impacting Microsoft Share…
@cibsecurity · Sep 27, 2026
Kiteworks Warns Users to Take Systems Offline Amid Suspected Zero-Day Threat https://gbhackers.com/kiteworks-systems-offline-amid-suspected-zero-day/
@PentestingNews · Sep 26, 2026
SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild https://ift.tt/n6aSfcu
@ctinow · Sep 26, 2026
Kiteworks urges 6-hour server shutdown over potential zero-day attacks Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday f…
@bleepingcomputer · Sep 25, 2026
Kiteworks urges 6-hour server shutdown over potential zero-day attacks https://ift.tt/Yo0mPVk
@ctinow · Sep 25, 2026
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild https://ift.tt/tL6ZIA3
@ctinow · Sep 25, 2026
Hackers now exploit critical Roundcube flaw in code injection attacks A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadi…
@bleepingcomputer · Sep 24, 2026
Hackers Exploit Check Point VPN RCE and Management Zero-Day in Attacks https://gbhackers.com/hackers-exploit-check-point-vpn-rce-and-management-zero-day/
@PentestingNews · Sep 24, 2026
New Windows Defender zero-day blocks Microsoft antivirus updates https://www.bleepingcomputer.com/news/security/new-windows-defender-zero-day-blocks-microsoft-antivirus-updates/
@secharvester · Sep 23, 2026
GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks https://ift.tt/fVxtuj2
@ctinow · Sep 23, 2026
F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks https://ift.tt/yEb3vtq
@ctinow · Sep 23, 2026
NightmareEclipse's latest zero-day leaves Microsoft Defender stuck in the past https://www.theregister.com/security/2026/09/22/nightmareeclipses-latest-zero-day-leaves-microsoft-defender-stuck-in-the-…
@secharvester · Sep 23, 2026
ShinyHunters claims FBI breach after alleged PeopleSoft zero-day attack https://securityaffairs.com/199612/cyber-crime/shinyhunters-claims-fbi-breach-after-alleged-peoplesoft-zero-day-attack.html
@PentestingNews · Sep 23, 2026
InfraTrust report warns network management systems under attack Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabili…
@bleepingcomputer · Sep 23, 2026
ShinyHunters claims FBI breach after alleged PeopleSoft zero-day attack https://ift.tt/j7l5Xh3
@ctinow · Sep 23, 2026
Arista patches actively exploited VeloCloud Orchestrator zero-day Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator…
@bleepingcomputer · Sep 23, 2026
Arista patches actively exploited VeloCloud Orchestrator zero-day https://ift.tt/PYZr5QB
@ctinow · Sep 23, 2026
F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks https://www.bleepingcomputer.com/news/security/f5-warns-of-big-ip-apm-remote-code-execution-zero-day-exploited-in-attacks/
@secharvester · Sep 23, 2026
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach https://www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/
@secharvester · Sep 23, 2026
Zero-day hackers ditch exploits for a fake image file in new DarkMe campaign https://ift.tt/cKviuty
@ctinow · Sep 23, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds: new IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Data Breach
Confirmed and reported data breaches: what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.
Patch
Vendor patches, security updates and fix releases for previously disclosed vulnerabilities.