๐Ÿท๏ธ zero-day

5 articles tagged zero-day.

Six Weeks, Six KEV Entries, One Pattern: The Edge Appliance Is the Smart Office Perimeter

Six Weeks, Six KEV Entries, One Pattern: The Edge Appliance Is the Smart Office Perimeter

Four KEV alerts across July, and not one of them was an end-user application. VPN appliances, sandboxes, SD-WAN orchestrators, firewall managers โ€” a hard-coded password here, a command injection there. In a building full of devices that will never be patched, these appliances are the only control actually holding the line.

Root Before Login: A Camera Zero-Day, a One-Year Disclosure Timeline, and the OEM Firmware Nobody Owns

Root Before Login: A Camera Zero-Day, a One-Year Disclosure Timeline, and the OEM Firmware Nobody Owns

A format string bug in a camera's JSON parser gives an unauthenticated attacker root. The vendor took a year and still had no fix when the advisory dropped. The uncomfortable part isn't the bug โ€” it's that the vulnerable binary was written by a different company than the one on the box, and nobody in your office knows which brands share it.

When the Network Is the Target: Acer's CVSS 10.0 Router Zero-Days and an Exploited Cisco SD-WAN Flaw

When the Network Is the Target: Acer's CVSS 10.0 Router Zero-Days and an Exploited Cisco SD-WAN Flaw

Acer shipped advisories for two maximum-severity zero-days in its Wave 7 mesh routers โ€” a world-readable log leaking cleartext admin credentials and a hardcoded AES key that lets attackers backdoor device backups. Days later, Cisco confirmed active exploitation of a Catalyst SD-WAN Manager flaw being chained to push rogue configurations to edge devices. Both fit the dominant 2026 pattern: the network itself is the target.

CVSS 10.0: Interlock Ransomware Exploited Cisco's Firewall Zero-Day for Weeks Before Cisco Knew

CVSS 10.0: Interlock Ransomware Exploited Cisco's Firewall Zero-Day for Weeks Before Cisco Knew

CVE-2026-20131 in Cisco Secure Firewall Management Center carries the maximum possible CVSS score of 10.0 and allows unauthenticated remote attackers to execute arbitrary Java code as root via an insecure deserialization flaw. The Interlock ransomware group was exploiting it as a zero-day from January 26, 2026 โ€” more than a month before Cisco disclosed the vulnerability publicly โ€” using memory-resident web shells, custom JavaScript and Java remote access trojans, and Active Directory certificate abuse to move through victim networks.

165 Vulnerabilities, Zero-Day SharePoint Exploits, and AI Prompt Injection: Microsoft's April Patch Tuesday Is a Turning Point

165 Vulnerabilities, Zero-Day SharePoint Exploits, and AI Prompt Injection: Microsoft's April Patch Tuesday Is a Turning Point

Microsoft's April 2026 Patch Tuesday addressed 165 vulnerabilities โ€” including actively exploited SharePoint zero-days and, for the first time, AI prompt injection vulnerabilities in Microsoft 365 Copilot. The AI attack surface is officially on the patch list.

โ† All topics

Ask Sage ๐Ÿค–