Cybersecurity Hacking News

Critical Zero-Days and Active Exploitation

Critical Zero-Days and Active Exploitation

Defenders face simultaneous exploitation of GitLab and PaperCut flaws, Zimbra SNMP RCE CVE-2026-73570, Oracle WebLogic CVE-2025-20989, and an Oracle Database oraexec attack that can affect fully patched systems. The GitLab issue is reportedly unauthenticated and capable of repository destruction or falsified merge history; PaperCut exploitation remains under limited disclosure. Entra ID’s CVSS 10.0 issue was fixed server-side without evidence of exploitation.

Sources (5)
Updated Aug 28, 2026