Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > 0-Day
#0-Day

StyleSmuggler Zero-Day Leaves Every Current Magento and Adobe Commerce Store Exposed to Takeover

14 September 2026  |  dark6  |  Vulnerability

A newly disclosed zero-day dubbed StyleSmuggler lets attackers hijack Magento Open Source and Adobe Commerce stores by smuggling PHP code through routine GraphQL requests and triggering it via...

>> read more

Microsoft Confirms Entra ID Zero-Day Was Exploited Before the Fix Went Live

21 August 2026  |  dark6  |  Vulnerability

Microsoft has disclosed CVE-2026-69836, a maximum-severity deserialization flaw in Entra ID that attackers exploited in the wild before the company silently patched it server-side. There is no customer...

>> read more

Unpatched GeoServer Zero-Day Under Active Attack as Researchers Warn of RCE Risk

15 August 2026  |  dark6  |  Vulnerability

A newly disclosed, unpatched SQL injection flaw in the open-source mapping platform GeoServer is already being probed by attackers just hours after it went public. Under certain database...

>> read more

Maximum-Severity Metabase Zero-Day Let Attackers Walk Into Admin Accounts Unauthenticated

10 August 2026  |  dark6  |  Vulnerability

A CVSS 10.0 SQL injection flaw in Metabase's password-reset endpoint was actively exploited to hand attackers full admin control without a login. Metabase Cloud was breached before a...

>> read more

SonicWall VPN Gateways Hit by Zero-Click Root Takeover Chain Tied to INC Ransomware

4 August 2026  |  dark6  |  Vulnerability

Attackers are chaining two SonicWall SMA 1000 series flaws to gain root access to VPN gateways without a password or any user interaction. Researchers at Resecurity tie the...

>> read more

Unpatched LegacyHive Bug Lets Standard Windows Users Hijack Admin Accounts

18 July 2026  |  dark6  |  Vulnerability

A newly disclosed Windows zero-day called LegacyHive abuses the User Profile Service to let a low-privileged user tamper with an administrator's registry hive, opening a path to persistence...

>> read more

CISA Confirms Active Exploitation of Critical SharePoint Deserialization Flaw

18 July 2026  |  dark6  |  Vulnerability

CISA has added CVE-2026-58644, a critical unauthenticated remote code execution flaw in Microsoft SharePoint, to its Known Exploited Vulnerabilities catalog after confirming real-world attacks. Federal agencies must remediate...

>> read more

SonicWall SMA1000 Zero-Days Under Active Attack: Perfect-10 Flaw Chained for Root Access

17 July 2026  |  dark6  |  Vulnerability

Attackers were exploiting a maximum-severity SonicWall SMA1000 flaw before the vendor's advisory even landed, chaining it with a privilege-escalation bug to seize root and pivot into corporate Active...

>> read more