##
Updated at UTC 2026-07-30T20:09:23.060378
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-62663 | 7.5 | 0.00% | 2 | 0 | 2026-07-30T19:26:51.190000 | Banks generates meaningful LLM prompts using a simple template language. In vers | |
| CVE-2026-67437 | 7.5 | 0.35% | 1 | 0 | 2026-07-30T19:21:23.297000 | OliveTin gives access to predefined shell commands from a web interface. From 30 | |
| CVE-2026-54719 | 7.5 | 0.28% | 1 | 0 | 2026-07-30T19:19:45.637000 | goshs is a feature-rich single-binary file server for red teamers and developers | |
| CVE-2026-59933 | 7.5 | 0.69% | 1 | 0 | 2026-07-30T19:19:45.637000 | PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. | |
| CVE-2026-12940 | 9.8 | 0.00% | 2 | 0 | 2026-07-30T19:17:05.170000 | IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote | |
| CVE-2026-16727 | 0 | 0.09% | 1 | 0 | 2026-07-30T19:08:40.437000 | Concurrent Execution using Shared Resource with Improper Synchronization (“Race | |
| CVE-2026-55389 | 7.5 | 0.36% | 1 | 0 | 2026-07-30T19:07:59.843000 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, a | |
| CVE-2026-9322 | 7.5 | 0.00% | 2 | 0 | 2026-07-30T18:31:47 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv | |
| CVE-2026-66066 | None | 0.00% | 12 | 3 | 2026-07-30T18:23:34 | ### Impact In its default configuration, a Rails application that displays image | |
| CVE-2026-54365 | 7.5 | 0.00% | 1 | 0 | 2026-07-30T16:45:00.353000 | CentreStack before 17.3 contains an unauthenticated deserialization vulnerabilit | |
| CVE-2026-66754 | 5.9 | 0.40% | 1 | 1 | 2026-07-30T16:41:25.650000 | Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the | |
| CVE-2026-58043 | 7.5 | 0.14% | 4 | 0 | 2026-07-30T16:33:59.580000 | A flaw in Node.js Permission Model enforcement can over-grant filesystem access | |
| CVE-2026-56850 | 4.1 | 0.08% | 1 | 0 | 2026-07-30T16:33:59.580000 | A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key co | |
| CVE-2026-59310 | 9.8 | 0.00% | 3 | 0 | 2026-07-30T16:17:15.183000 | VMware vCenter contains a directory traversal vulnerability in the Syslog server | |
| CVE-2026-59309 | 9.8 | 0.00% | 4 | 0 | 2026-07-30T16:17:15.073000 | VMware vCenter contains an authentication bypass vulnerability in the VMware Dir | |
| CVE-2026-16610 | 9.8 | 0.58% | 2 | 0 | 2026-07-30T16:16:57.050000 | The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to | |
| CVE-2026-48449 | 10.0 | 0.54% | 2 | 0 | 2026-07-30T14:54:03.443000 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi | |
| CVE-2026-67428 | 8.5 | 0.34% | 1 | 0 | 2026-07-30T14:48:09 | ## Summary Numerous HTTP-emitting modules (`core.api.http_get`, `core.api.http_p | |
| CVE-2026-67429 | 10.0 | 0.49% | 1 | 0 | 2026-07-30T14:46:44 | ## Summary `image.download` fetches a URL and writes the response to disk. It d | |
| CVE-2026-67432 | 7.5 | 0.44% | 1 | 0 | 2026-07-30T14:44:08 | ## Summary An unauthenticated remote attacker can force any MCP Ruby SDK server | |
| CVE-2026-44106 | 7.8 | 0.23% | 2 | 0 | 2026-07-30T14:31:21.447000 | A privilege escalation vulnerability in the init-script for user-applications al | |
| CVE-2026-44101 | 9.8 | 0.40% | 1 | 0 | 2026-07-30T14:31:21.447000 | Due to missing authentication the CHARX OCPP Agent service allows an unauthentic | |
| CVE-2026-44105 | 6.6 | 0.09% | 1 | 0 | 2026-07-30T14:31:21.447000 | The credentials for the local user "user-app" may be exposed in log files, poten | |
| CVE-2026-44093 | 7.8 | 0.23% | 1 | 0 | 2026-07-30T14:31:21.447000 | A local privilege escalation vulnerability in the init-script for user-applicati | |
| CVE-2026-44103 | 5.3 | 0.24% | 1 | 0 | 2026-07-30T14:31:21.447000 | An unauthenticated remote attacker can inject malicious firmware into the intern | |
| CVE-2026-14168 | 8.8 | 0.28% | 2 | 0 | 2026-07-30T14:31:21.447000 | A low privileged remote attacker can gain administrator privileges due to missin | |
| CVE-2026-5487 | 7.5 | 1.54% | 1 | 0 | 2026-07-30T14:18:46.477000 | DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnera | |
| CVE-2026-5491 | 7.5 | 1.54% | 1 | 0 | 2026-07-30T14:18:46.477000 | DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnera | |
| CVE-2026-47876 | 9.3 | 0.00% | 5 | 0 | 2026-07-30T14:16:58.467000 | VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual | |
| CVE-2026-14356 | 8.8 | 0.27% | 1 | 0 | 2026-07-30T14:16:46.943000 | The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in a | |
| CVE-2026-18220 | 7.8 | 0.19% | 1 | 1 | 2026-07-30T14:15:31.167000 | An out-of-bounds write vulnerability was found in the BFD library's DLX ELF back | |
| CVE-2026-14981 | 7.5 | 0.26% | 1 | 0 | 2026-07-30T14:08:40.373000 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv | |
| CVE-2026-20316 | 5.3 | 0.79% | 11 | 0 | 2026-07-30T13:13:12.683000 | A vulnerability in the web interface of Cisco Secure Firewall Management Center | |
| CVE-2026-18363 | None | 0.00% | 1 | 0 | 2026-07-30T12:32:26 | A logic vulnerability in the password reset token validation routine implemented | |
| CVE-2026-64560 | 7.8 | 0.11% | 2 | 0 | 2026-07-30T12:32:18 | In the Linux kernel, the following vulnerability has been resolved: posix-cpu-t | |
| CVE-2026-44095 | 7.8 | 0.23% | 2 | 0 | 2026-07-30T09:31:24 | A privilege escalation vulnerability in a script used for network configuration | |
| CVE-2026-44108 | 9.8 | 0.46% | 2 | 0 | 2026-07-30T09:31:24 | Due to a flaw in the execution order of scripts during shutdown, the firewall is | |
| CVE-2026-44107 | 7.5 | 0.31% | 2 | 0 | 2026-07-30T09:31:24 | A reboot of the charging controller can be triggered via Modbus TCP without auth | |
| CVE-2026-7849 | 9.8 | 0.42% | 2 | 0 | 2026-07-30T09:31:24 | Due to improper neutralization of special elements, an unauthenticated remote at | |
| CVE-2026-44094 | 8.6 | 0.26% | 1 | 0 | 2026-07-30T09:31:24 | An unauthenticated remote attacker can enforce the system to fall back to a firm | |
| CVE-2026-44102 | 5.3 | 0.21% | 1 | 0 | 2026-07-30T09:31:24 | An unauthenticated remote attacker can trigger a firmware update download via th | |
| CVE-2026-44104 | 9.8 | 0.24% | 1 | 0 | 2026-07-30T09:31:24 | The firmware update process for the basemodule of the charging controller only v | |
| CVE-2026-44092 | 9.1 | 0.38% | 1 | 0 | 2026-07-30T09:31:24 | An unauthenticated remote attacker can inject malicious input into the ModbusSer | |
| CVE-2026-44091 | 9.1 | 0.33% | 1 | 0 | 2026-07-30T09:31:24 | An unauthenticated remote attacker can post a malicious ID to the MQTT Broker re | |
| CVE-2026-44090 | 9.8 | 0.40% | 1 | 0 | 2026-07-30T09:31:24 | Due to missing authentication, an unauthenticated remote attacker may access the | |
| CVE-2026-44098 | 8.6 | 1.37% | 1 | 0 | 2026-07-30T09:31:18 | This vulnerability allows an unauthenticated remote attacker with control over t | |
| CVE-2026-44099 | 7.8 | 0.23% | 1 | 0 | 2026-07-30T09:31:18 | A privilege escalation vulnerability in the system configuration allows a low-pr | |
| CVE-2026-44100 | 9.4 | 0.28% | 1 | 0 | 2026-07-30T09:31:18 | The CHARX JupiCore service allows an unauthenticated remote attacker to reconfig | |
| CVE-2026-44097 | 7.1 | 0.24% | 1 | 0 | 2026-07-30T09:31:18 | A low-privileged remote attacker with "operator" access can upload arbitrary fil | |
| CVE-2026-44096 | 7.8 | 0.23% | 1 | 0 | 2026-07-30T09:31:18 | A privilege escalation vulnerability in udhcpc allows a local user "charx-web" t | |
| CVE-2026-64531 | 7.8 | 0.12% | 1 | 0 | 2026-07-30T06:33:35 | In the Linux kernel, the following vulnerability has been resolved: net: openvs | |
| CVE-2026-58046 | 9.9 | 0.31% | 2 | 0 | 2026-07-30T06:32:44 | Improper neutralization in the Plesk XML-RPC API allows a remote authenticated l | |
| CVE-2026-58066 | 9.8 | 0.21% | 1 | 0 | 2026-07-30T06:32:44 | Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, | |
| CVE-2026-1360 | 7.5 | 0.57% | 1 | 0 | 2026-07-30T06:32:43 | The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untruste | |
| CVE-2026-48448 | 8.6 | 0.37% | 1 | 0 | 2026-07-30T03:31:28 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia | |
| CVE-2026-67595 | 8.1 | 0.42% | 2 | 0 | 2026-07-30T00:31:19 | VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript p | |
| CVE-2026-5490 | 8.8 | 0.48% | 1 | 1 | 2026-07-29T21:31:08 | DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability a | |
| CVE-2026-6267 | 8.5 | 0.34% | 2 | 0 | 2026-07-29T21:31:08 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1. | |
| CVE-2026-5056 | 7.8 | 0.43% | 1 | 0 | 2026-07-29T21:31:08 | GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerabilit | |
| CVE-2026-13308 | 8.1 | 0.57% | 1 | 0 | 2026-07-29T21:31:08 | Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Executi | |
| CVE-2026-6102 | 7.8 | 0.09% | 1 | 0 | 2026-07-29T21:31:08 | MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulner | |
| CVE-2026-14529 | 9.4 | 0.33% | 1 | 0 | 2026-07-29T21:31:07 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv | |
| CVE-2026-15975 | 7.5 | 0.39% | 1 | 0 | 2026-07-29T21:31:07 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 | |
| CVE-2026-5057 | 7.5 | 0.48% | 1 | 0 | 2026-07-29T21:31:07 | ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. | |
| CVE-2026-67201 | 8.6 | 0.39% | 1 | 0 | 2026-07-29T20:17:11.330000 | V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery | |
| CVE-2026-43698 | 7.8 | 0.15% | 1 | 0 | 2026-07-29T19:16:45.967000 | An injection issue was addressed with improved validation. This issue is fixed i | |
| CVE-2026-67215 | 7.5 | 0.35% | 1 | 0 | 2026-07-29T15:31:12 | cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack ex | |
| CVE-2026-0667 | None | 0.37% | 1 | 0 | 2026-07-29T15:31:11 | CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that | |
| CVE-2026-66748 | 8.8 | 0.79% | 1 | 1 | 2026-07-29T15:31:05 | Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code | |
| CVE-2026-66745 | 7.5 | 0.32% | 1 | 0 | 2026-07-29T15:16:30.153000 | Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) con | |
| CVE-2026-54650 | 8.6 | 0.36% | 1 | 0 | 2026-07-29T15:16:25.093000 | openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, | |
| CVE-2026-65883 | None | 0.50% | 3 | 0 | 2026-07-29T12:31:30 | Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Ca | |
| CVE-2026-14270 | 8.8 | 0.55% | 1 | 0 | 2026-07-29T12:31:30 | The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCom | |
| CVE-2026-35226 | 6.5 | 0.17% | 1 | 0 | 2026-07-29T09:31:37 | An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows a | |
| CVE-2026-18197 | None | 0.27% | 1 | 0 | 2026-07-29T09:31:36 | Improper neutralization of input during web page generation ('cross-site scripti | |
| CVE-2026-18072 | 9.8 | 0.59% | 2 | 0 | 2026-07-29T06:32:11 | The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick | |
| CVE-2026-12144 | 8.8 | 0.37% | 1 | 0 | 2026-07-29T03:30:21 | The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Es | |
| CVE-2026-54658 | 9.8 | 0.40% | 1 | 0 | 2026-07-28T22:19:24 | ### Impact A SQL injection vulnerability exists in the `escapeValue()` function | |
| CVE-2026-54638 | 7.5 | 0.35% | 1 | 0 | 2026-07-28T22:15:29 | ### Impact A remote, unauthenticated attacker can cause excessive memory alloca | |
| CVE-2026-64863 | 9.1 | 0.34% | 1 | 0 | 2026-07-28T22:03:13 | ## Summary The WebDAV mode-flag guard added to fix GHSA-3whc-qvhv-xqjp still do | |
| CVE-2026-62325 | 9.1 | 0.34% | 1 | 0 | 2026-07-28T21:57:19 | ## Summary Start goshs v2.1.3 with `-b 'admin:' -sftp`. No `-fkf`. SFTP accepts | |
| CVE-2026-55391 | 7.5 | 0.20% | 1 | 0 | 2026-07-28T21:45:50 | ### Summary `datamodel-code-generator`'s anti-SSRF guard validates the resolved | |
| CVE-2026-14973 | 9.3 | 0.45% | 1 | 0 | 2026-07-28T21:31:45 | IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow fil | |
| CVE-2026-15057 | 7.5 | 0.26% | 1 | 0 | 2026-07-28T21:31:45 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerab | |
| CVE-2026-14996 | 8.2 | 0.22% | 1 | 0 | 2026-07-28T21:31:45 | IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related | |
| CVE-2026-7769 | 8.1 | 0.27% | 1 | 0 | 2026-07-28T21:31:39 | IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2 | |
| CVE-2026-55390 | 7.5 | 0.36% | 2 | 0 | 2026-07-28T21:26:42 | ### Summary When generating models from an XML Schema (`--input-file-type xmlsc | |
| CVE-2026-43749 | 7.8 | 0.15% | 1 | 0 | 2026-07-28T19:52:21.577000 | A parsing issue in the handling of directory paths was addressed with improved p | |
| CVE-2026-5674 | 8.8 | 0.12% | 2 | 0 | 2026-07-28T17:16:52.923000 | A flaw was found in PipeWire, a multimedia server. This vulnerability allows an | |
| CVE-2026-54635 | 7.5 | 0.42% | 1 | 0 | 2026-07-28T17:09:03 | ## Webhook Custom Path Authentication Bypass in pytonapi ### Summary `TonapiWe | |
| CVE-2026-63077 | 9.8 | 0.65% | 5 | 0 | 2026-07-28T16:17:58.820000 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe | |
| CVE-2026-59878 | 7.5 | 0.55% | 1 | 0 | 2026-07-28T15:32:25 | Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ | |
| CVE-2026-63727 | 8.8 | 0.26% | 1 | 0 | 2026-07-28T15:32:19 | Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper | |
| CVE-2026-7187 | 8.8 | 0.21% | 1 | 0 | 2026-07-28T15:32:18 | Missing authentication for critical function vulnerability in Universal Software | |
| CVE-2026-61609 | 7.5 | 0.39% | 1 | 0 | 2026-07-28T14:58:00 | ### Summary The `authentication` rate limiter used for the login and two-factor | |
| CVE-2026-45293 | 8.6 | 0.18% | 1 | 0 | 2026-07-28T14:28:13 | ### Impact WordPress Coding Standards (WordPressCS) versions before 3.4.1 conta | |
| CVE-2025-15467 | 8.8 | 47.62% | 1 | 6 | 2026-07-28T13:17:14.747000 | Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with malic | |
| CVE-2026-16462 | 9.8 | 0.42% | 1 | 0 | 2026-07-28T12:31:27 | In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This a | |
| CVE-2026-14169 | 8.1 | 0.29% | 2 | 0 | 2026-07-28T09:31:36 | Due to incorrect behavior order a low privileged remote attacker could trigger a | |
| CVE-2026-14167 | 8.8 | 0.28% | 2 | 0 | 2026-07-28T09:31:36 | A low privileged remote attacker can perform privileged configuration changes re | |
| CVE-2026-14171 | 6.1 | 0.18% | 2 | 0 | 2026-07-28T09:31:35 | An unauthenticated remote attacker can abuse the improper validation of the post | |
| CVE-2026-43723 | 7.8 | 0.15% | 1 | 0 | 2026-07-28T00:32:06 | A path handling issue was addressed with improved validation. This issue is fixe | |
| CVE-2026-39874 | 7.8 | 0.11% | 1 | 0 | 2026-07-28T00:32:04 | A permissions issue was addressed with additional restrictions. This issue is fi | |
| CVE-2026-66473 | 7.5 | 0.20% | 1 | 0 | 2026-07-28T00:31:11 | Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions. | |
| CVE-2026-43776 | 7.8 | 0.15% | 1 | 0 | 2026-07-28T00:31:02 | A buffer overflow was addressed with improved bounds checking. This issue is fix | |
| CVE-2026-16812 | 10.0 | 0.88% | 6 | 0 | 2026-07-27T21:31:22 | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may a | |
| CVE-2025-68686 | 5.9 | 1.26% | 2 | 0 | 2026-07-27T18:31:25 | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE | |
| CVE-2026-61511 | 9.8 | 1.27% | 4 | 6 | 2026-07-27T15:32:39 | vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vul | |
| CVE-2026-66373 | 7.5 | 0.47% | 1 | 0 | 2026-07-25T03:30:55 | Redis before 8.8.0, in the unusual case where an authenticated attacker can exec | |
| CVE-2026-59952 | None | 0.52% | 1 | 0 | 2026-07-24T16:14:33 | ## Summary `valibot` 1.4.1 can throw a `TypeError` inside its `flatten()` helpe | |
| CVE-2026-42933 | 10.0 | 0.29% | 1 | 0 | 2026-07-24T00:32:40 | Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or inter | |
| CVE-2026-21655 | None | 0.17% | 1 | 0 | 2026-07-23T21:31:03 | Deserialization of untrusted data vulnerability in Johnson Control victor on Win | |
| CVE-2026-59932 | 7.5 | 0.69% | 1 | 0 | 2026-07-23T15:00:18 | ## Summary PhpSpreadsheet's Gnumeric reader reads attacker-supplied `.gnumeric` | |
| CVE-2026-59931 | 7.7 | 0.53% | 1 | 0 | 2026-07-23T14:55:51 | ### Summary The domain whitelist introduced in PhpSpreadsheet 5.4.0 for the `WE | |
| CVE-2026-43503 | 8.8 | 0.34% | 1 | 9 | 2026-07-23T11:10:00.120000 | In the Linux kernel, the following vulnerability has been resolved: net: skbuff | |
| CVE-2026-16723 | 9.0 | 0.41% | 2 | 5 | 2026-07-23T09:32:08 | A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1. | |
| CVE-2026-16232 | 9.1 | 69.97% | 7 | 2 | template | 2026-07-22T21:32:05 | An authentication bypass vulnerability in the Check Point SmartConsole login pro |
| CVE-2026-50502 | 8.0 | 0.60% | 1 | 0 | 2026-07-22T16:18:05.400000 | Insufficient granularity of access control in Windows Event Logging Service allo | |
| CVE-2026-2291 | 7.3 | 0.92% | 2 | 1 | 2026-07-20T21:31:40 | dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, | |
| CVE-2026-53362 | 7.8 | 0.27% | 1 | 0 | 2026-07-18T09:32:17 | In the Linux kernel, the following vulnerability has been resolved: ipv6: accou | |
| CVE-2026-42530 | 8.1 | 3.68% | 2 | 3 | 2026-07-16T12:33:31 | NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGI | |
| CVE-2026-42533 | 8.1 | 3.60% | 1 | 9 | 2026-07-15T15:33:14 | A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive | |
| CVE-2026-54121 | 8.8 | 1.05% | 2 | 8 | 2026-07-14T18:32:37 | Improper authorization in Active Directory Certificate Services (AD CS) allows a | |
| CVE-2026-50469 | 7.8 | 0.27% | 1 | 0 | 2026-07-14T18:32:32 | Improper link resolution before file access ('link following') in Windows Projec | |
| CVE-2026-59726 | 10.0 | 0.48% | 1 | 1 | 2026-07-10T19:15:15.780000 | Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo | |
| CVE-2026-58025 | 9.8 | 0.33% | 2 | 1 | 2026-07-09T19:34:14.067000 | Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWik | |
| CVE-2026-5172 | 7.3 | 2.68% | 2 | 2 | 2026-06-30T03:37:45 | A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker t | |
| CVE-2026-10702 | 4.3 | 0.72% | 1 | 1 | 2026-06-30T03:36:54 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w | |
| CVE-2026-0160 | 8.8 | 0.23% | 1 | 0 | 2026-06-17T19:22:02.480000 | In TextRtpPayloadDecoderNode::DecodeT140 of TextRtpPayloadDecoderNode.cpp, there | |
| CVE-2026-0149 | 8.8 | 0.29% | 1 | 0 | 2026-06-17T18:36:28 | In RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap bu | |
| CVE-2026-22796 | 5.3 | 0.50% | 2 | 0 | 2026-06-17T10:20:26.697000 | Issue summary: A type confusion vulnerability exists in the signature verificati | |
| CVE-2026-22795 | 5.5 | 0.14% | 2 | 0 | 2026-06-17T10:20:26.520000 | Issue summary: An invalid or NULL pointer dereference can happen in an applicati | |
| CVE-2025-69421 | 7.5 | 0.84% | 2 | 1 | 2026-06-17T10:00:40.683000 | Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer de | |
| CVE-2025-69420 | 7.5 | 0.77% | 2 | 1 | 2026-06-17T10:00:40.067000 | Issue summary: A type confusion vulnerability exists in the TimeStamp Response v | |
| CVE-2025-15435 | 7.3 | 0.35% | 2 | 0 | 2026-06-17T08:37:46.203000 | A flaw has been found in Yonyou KSOA 9.0. Affected by this vulnerability is an u | |
| CVE-2024-1813 | 9.8 | 1.11% | 1 | 2 | 2026-06-17T07:05:03.993000 | The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection | |
| CVE-2014-0160 | 7.5 | 100.00% | 1 | 75 | 2026-06-17T00:02:24.467000 | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not p | |
| CVE-2013-4786 | 7.5 | 78.57% | 1 | 1 | 2026-06-16T23:57:53.617000 | The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (R | |
| CVE-2026-40510 | 3.8 | 0.22% | 2 | 0 | 2026-05-29T15:30:38 | OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overf | |
| CVE-2026-42897 | 8.1 | 5.64% | 5 | 1 | 2026-05-15T18:30:32 | Improper neutralization of input during web page generation ('cross-site scripti | |
| CVE-2025-69418 | 4.0 | 0.11% | 2 | 1 | 2026-05-12T15:31:14 | Issue summary: When using the low-level OCB API directly with AES-NI or<br>other | |
| CVE-2025-69419 | 7.4 | 0.44% | 2 | 1 | 2026-05-12T15:31:14 | Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously craft | |
| CVE-2025-68160 | 4.7 | 0.15% | 2 | 0 | 2026-05-12T15:31:14 | Issue summary: Writing large, newline-free data into a BIO chain using the line- | |
| CVE-2026-4893 | 5.3 | 2.68% | 2 | 5 | 2026-05-11T21:31:33 | An information disclosure vulnerability in dnsmasq allows remote attackers to by | |
| CVE-2026-20079 | 10.0 | 38.70% | 2 | 1 | 2026-03-04T18:32:03 | A vulnerability in the web interface of Cisco Secure Firewall Management Center | |
| CVE-2026-1623 | 6.3 | 2.18% | 1 | 1 | 2026-01-29T21:30:37 | A weakness has been identified in Totolink A7000R 4.1cu.4154. Impacted is the fu | |
| CVE-2023-37327 | 7.6 | 1.71% | 2 | 0 | 2025-11-04T21:32:34 | GStreamer FLAC File Parsing Integer Overflow Remote Code Execution Vulnerability | |
| CVE-2023-5217 | 8.8 | 49.01% | 1 | 3 | 2024-02-15T15:02:28 | Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5 | |
| CVE-2008-1028 | None | 4.55% | 1 | 0 | 2023-01-31T05:05:55 | Unspecified vulnerability in AppKit in Apple Mac OS X before 10.5 allows user-as | |
| CVE-2026-53921 | 0 | 0.00% | 3 | 2 | N/A | ||
| CVE-2026-58086 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-56848 | 0 | 0.00% | 4 | 0 | N/A | ||
| CVE-2026-56846 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-65094 | 0 | 0.00% | 1 | 0 | N/A |
updated 2026-07-30T19:26:51.190000
2 posts
🟠 CVE-2026-62663 - High (7.5)
Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filters (image, audio, video, document) in banks accept untrusted user input as file paths via Path(value) and pass them directly t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62663/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-62663 - High (7.5)
Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filters (image, audio, video, document) in banks accept untrusted user input as file paths via Path(value) and pass them directly t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62663/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T19:21:23.297000
1 posts
🟠 CVE-2026-67437 - High (7.5)
OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_auth_oauth2.go OAuth2 login handler stores per-login state in the registeredStates map on every /oau...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67437/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T19:19:45.637000
1 posts
🟠 CVE-2026-54719 - High (7.5)
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?bulk&file= ZIP downloads did not call findEffectiveACL or applyCustomAuth, allowing unauthenticate...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54719/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T19:19:45.637000
1 posts
🟠 CVE-2026-59933 - High (7.5)
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, and all releases up to and including 1.30.5, the OLE reader follows s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59933/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T19:17:05.170000
2 posts
🔴 CVE-2026-12940 - Critical (9.8)
IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py whe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12940/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-12940 - Critical (9.8)
IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py whe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12940/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T19:08:40.437000
1 posts
CVE-2026-16727 (HIGH): Race condition in ASUS Armoury Crate 5.4.1 lets local users escalate privileges via improper synchronization. No patch available. Limit local access & monitor systems. https://radar.offseq.com/threat/cve-2026-16727-cwe-362-concurrent-execution-using-shared-resource-with-improper-synchronization-race-75a81e87495a29e2 #OffSeq #CVE202616727 #ASUS #Vuln
##updated 2026-07-30T19:07:59.843000
1 posts
🟠 CVE-2026-55389 - High (7.5)
datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.62.0, datamodel-code-generator resolves JSON Schema $ref t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55389/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T18:31:47
2 posts
🟠 CVE-2026-9322 - High (7.5)
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9322/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-9322 - High (7.5)
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9322/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T18:23:34
12 posts
3 repos
https://github.com/0xBlackash/CVE-2026-66066
New.
Rapaid7: KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails https://www.rapid7.com/blog/post/etr-kindarails2shell-cve-2026-66066-critical-arbitrary-file-read-and-possible-remote-code-execution-in-ruby-on-rails/ @Rapid7Official
The related Ruby on Rails advisory was published yesterday: Possible arbitrary file read and remote code execution in Active Storage variant processing https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm #infosec #vulnerability #Ruby
##KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066) https://lobste.rs/s/kkobew #ruby #security
https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066
KindaRails2Shell: arbitrary file read to RCE in Rails Active Storage via libvips (CVE-2026-66066) https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066
##New.
Rapaid7: KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails https://www.rapid7.com/blog/post/etr-kindarails2shell-cve-2026-66066-critical-arbitrary-file-read-and-possible-remote-code-execution-in-ruby-on-rails/ @Rapid7Official
The related Ruby on Rails advisory was published yesterday: Possible arbitrary file read and remote code execution in Active Storage variant processing https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm #infosec #vulnerability #Ruby
##KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066) https://lobste.rs/s/kkobew #ruby #security
https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066
KindaRails2Shell: arbitrary file read to RCE in Rails Active Storage via libvips (CVE-2026-66066) https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066
##Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials, and API tokens. https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html?_m=3n%2e009a%2e4043%2ebk0aof3yrl%2e33lb
##🚨 Manyfold v0.147.1 is out, with a security fix for #Rails CVE-2026-66066. Update your instances! 🚨
##CVE-2026-66066: un atacant pot llegir fitxers del servidor Rails gràcies a Active Storage + libvips. secret_key_base, master.key, credencials de cloud — tot a l'abast. I després fer RCE amb les claus robades. 🎯
Parcheja a: activestorage 7.2.3.2 / 8.0.5.1 / 8.1.3.1 o libvips ≥ 8.13.0
Si encara uses libvips vell, posa VIPS_BLOCK_UNTRUSTED i resa.
##Critical Rails Active Storage Flaw Allows Unauthenticated Arbitrary File Read
Ruby on Rails patched a critical vulnerability (CVE-2026-66066) in Active Storage that allows unauthenticated attackers to read arbitrary server files and steal sensitive secrets.
**Update Rails immediately to a patched version (7.2.3.2, 8.0.5.1, or 8.1.3.1) and make sure libvips is upgraded to 8.13 or later. A public exploit is already available and attacks are expected soon. Because attackers may have already stolen your secrets, rotate every credential the app could access, including secret_key_base, the master key, database passwords, and all API tokens after patching.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/critical-rails-active-storage-flaw-allows-unauthenticated-arbitrary-file-read-k-h-8-7-3/gD2P6Ple2L
A Rails Active Storage flaw, CVE-2026-66066 (CVSS 9.5), enables arbitrary file read and remote code execution. Patch Rails and rotate secrets now.
#RubyOnRails #ActiveStorage #CVE202666066 #RCE #libvips #InfoSec
https://securityonline.info/rails-cve-2026-66066/?utm_source=mastodon&utm_medium=jetpack_social
##RE: https://christine-seeman.com/cve-2026-66066-active-storage/
Patch your #rails there's a new CVE out there specifically about active storage and if your app accepts image uploads.
##updated 2026-07-30T16:45:00.353000
1 posts
CVE-2026-54365 Unauthenticated deserialization in Centrestack. Attackers create local OS accounts via crafted XML. CVSS 7.5. No patch yet – isolate systems. #CVE #Centrestack #cybersecurity
##updated 2026-07-30T16:41:25.650000
1 posts
1 repos
🟠 CVE-2026-66754 - High (7.5)
Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that allows remote unauthenticated attackers to crash the server by sending a crafted percent-encoded URL. Attackers can send a request...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66754/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T16:33:59.580000
4 posts
🟠 CVE-2026-58043 - High (7.5)
A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries.
Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58043/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
####This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...
##This is a security release. Notable Changes (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX...
##This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...
updated 2026-07-30T16:33:59.580000
1 posts
##This is a security release. Notable Changes (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX...
updated 2026-07-30T16:17:15.183000
3 posts
Broadcom Disrupts VMware with Emergency Patches for Critical Flaws
Broadcom has just released emergency security patches to tackle critical flaws in VMware's vCenter, ESX, Workstation, and Fusion - and it's urging admins to act fast, treating affected systems as immediately vulnerable. Three critical vulnerabilities, including CVE-2026-59309, CVE-2026-59310, and CVE-2026-47876, are among the five…
#Vmware #Broadcom #EmergencyPatches #CriticalFlaws #Cve202659309
##Broadcom patched a critical VMware vCenter vulnerability. CVE-2026-59309 and CVE-2026-59310 both score 9.8 CVSS and allow auth bypass or code execution.
#VMware #vCenter #CVE202659309 #CVE202659310 #ESXi #InfoSec
https://meterpreter.org/vmware-vcenter-cve-2026-59309/?utm_source=mastodon&utm_medium=jetpack_social
##Broadcom released updates to fix a critical VMware authentication bypass (CVE-2026-59309). A directory traversal flaw (CVE-2026-59310) was also patched.
##updated 2026-07-30T16:17:15.073000
4 posts
Broadcom Disrupts VMware with Emergency Patches for Critical Flaws
Broadcom has just released emergency security patches to tackle critical flaws in VMware's vCenter, ESX, Workstation, and Fusion - and it's urging admins to act fast, treating affected systems as immediately vulnerable. Three critical vulnerabilities, including CVE-2026-59309, CVE-2026-59310, and CVE-2026-47876, are among the five…
#Vmware #Broadcom #EmergencyPatches #CriticalFlaws #Cve202659309
##Broadcom patched a critical VMware vCenter vulnerability. CVE-2026-59309 and CVE-2026-59310 both score 9.8 CVSS and allow auth bypass or code execution.
#VMware #vCenter #CVE202659309 #CVE202659310 #ESXi #InfoSec
https://meterpreter.org/vmware-vcenter-cve-2026-59309/?utm_source=mastodon&utm_medium=jetpack_social
##VMware ESXi, vCenter, Workstation, and Fusion patched for CRITICAL flaws: CVE-2026-47876 enables VM escape and host code execution; CVE-2026-59309/59310 impact vCenter auth & RCE. Patch ASAP — no exploitation reported. https://radar.offseq.com/threat/critical-vm-escape-vulnerability-patched-in-vmware-esxi-7c609b015974b352 #OffSeq #VMware #Vuln #PatchNow
##Broadcom released updates to fix a critical VMware authentication bypass (CVE-2026-59309). A directory traversal flaw (CVE-2026-59310) was also patched.
##updated 2026-07-30T16:16:57.050000
2 posts
🔴 CVE-2026-16610 - Critical (9.8)
The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a publicly em...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16610/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-16610: ASE Pro plugin (≤8.9.0) for WordPress suffers CRITICAL RCE via recursive_html. Unauth attackers can execute code if [post_cf_form] is public. Update/disable plugin ASAP. https://radar.offseq.com/threat/cve-2026-16610-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-ase-admin-and-site-9666b4d559bc4aea #OffSeq #WordPress #CVE2026_16610 #Security
##updated 2026-07-30T14:54:03.443000
2 posts
CVE-2026-48449 - Critical RCE in Adobe Campaign Classic. Incorrect Authorization allows code execution without user interaction. CVSS 10. Unpatched - take immediate action. #CVE #Adobe #infosec
##🔴 CVE-2026-48449 - Critical (10)
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48449/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T14:48:09
1 posts
🟠 CVE-2026-67428 - High (8.5)
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules including src/core/modules/third_party/developer/http/requests.py, core.api.http_get, core.api.http_post, graphql.query, graphql.mutat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67428/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T14:46:44
1 posts
🔴 CVE-2026-67429 - Critical (10)
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config and its FLYTO_SANDBOX_DIR confinem...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67429/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T14:44:08
1 posts
🟠 CVE-2026-67432 - High (7.5)
MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem reads and parses an entire JSON-RPC POST body without a size limit, allowing an ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67432/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T14:31:21.447000
2 posts
🟠 CVE-2026-44106 - High (7.8)
A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44106/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
###OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T14:31:21.447000
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T14:31:21.447000
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T14:31:21.447000
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T14:31:21.447000
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T14:31:21.447000
2 posts
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-07-30T14:18:46.477000
1 posts
🟠 CVE-2026-5487 - High (7.5)
DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability.
...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-5487/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T14:18:46.477000
1 posts
🟠 CVE-2026-5491 - High (7.5)
DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability.
...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-5491/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T14:16:58.467000
5 posts
Broadcom Disrupts VMware with Emergency Patches for Critical Flaws
Broadcom has just released emergency security patches to tackle critical flaws in VMware's vCenter, ESX, Workstation, and Fusion - and it's urging admins to act fast, treating affected systems as immediately vulnerable. Three critical vulnerabilities, including CVE-2026-59309, CVE-2026-59310, and CVE-2026-47876, are among the five…
#Vmware #Broadcom #EmergencyPatches #CriticalFlaws #Cve202659309
##CRITICAL vuln: CVE-2026-47876 in VMware Cloud Foundation (9.1.x.x/9.0.x.x/5.x) allows VM admin to execute code on host via VMXNET3 adapter. Restrict admin access, use other adapters if possible. Patch not yet available. https://radar.offseq.com/threat/cve-2026-47876-cwe-787-out-of-bounds-write-in-vmware-cloud-foundation-111066eb743eb8c6 #OffSeq #VMware #InfoSec #CVE202647876
##CRITICAL vuln: CVE-2026-47876 in VMware Cloud Foundation (9.1.x.x/9.0.x.x/5.x) allows VM admin to execute code on host via VMXNET3 adapter. Restrict admin access, use other adapters if possible. Patch not yet available. https://radar.offseq.com/threat/cve-2026-47876-cwe-787-out-of-bounds-write-in-vmware-cloud-foundation-111066eb743eb8c6 #OffSeq #VMware #InfoSec #CVE202647876
##Three of the vulnerabilities have been assigned a ‘critical’ severity rating. One of them is CVE-2026-47876, an out-of-bounds write issue in ESXi’s VMXNET3 virtual network adapter. https://www.securityweek.com/critical-vm-escape-vulnerability-patched-in-vmware-esxi/
##VMware ESXi, vCenter, Workstation, and Fusion patched for CRITICAL flaws: CVE-2026-47876 enables VM escape and host code execution; CVE-2026-59309/59310 impact vCenter auth & RCE. Patch ASAP — no exploitation reported. https://radar.offseq.com/threat/critical-vm-escape-vulnerability-patched-in-vmware-esxi-7c609b015974b352 #OffSeq #VMware #Vuln #PatchNow
##updated 2026-07-30T14:16:46.943000
1 posts
🟠 CVE-2026-14356 - High (8.8)
The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14356/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T14:15:31.167000
1 posts
1 repos
🟠 CVE-2026-18220 - High (7.8)
An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds ch...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18220/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T14:08:40.373000
1 posts
🟠 CVE-2026-14981 - High (7.5)
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14981/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T13:13:12.683000
11 posts
Cisco Warns of Actively Exploited Secure Firewall Zero-Day as Attackers Target Enterprise Defenses + Video
A New Cybersecurity Alarm Inside the Network Security Industry Cisco has issued an urgent security warning after discovering active exploitation of a zero-day vulnerability affecting its Secure Firewall Management Center (FMC) platform. The flaw, tracked as CVE-2026-20316, exposes organizations using vulnerable firewall management systems to potential unauthorized…
##https://thecybersecguru.com/news/cisco-fmc-cve-2026-20316-hardcoded-credentials-active-exploitation/
##📰 CISA Warns of Actively Exploited Cisco Firewall Management Flaw
📢 CISA WARNING: A static credential flaw in Cisco Secure Firewall Management Center (CVE-2026-20316) is actively exploited. The flaw allows unauthorized access. CISA adds it to KEV catalog, mandating federal action. #CVE202620316 #Cisco #KEV
🌐 cyber[.]netsecops[.]io
##🔵 THREAT INTELLIGENCE
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
Vulnerability | CRITICAL
CVEs: CVE-2026-20316
Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was...
Full analysis:
https://www.yazoul.net/news/article/cisco-fmc-zero-day-actively-exploited-static-credentials-could-expose-sensitive-
🏆 New Achievement! Static Credentials, Static Fate!
RAID ALERT. RAID ALERT. Cisco Secure Firewall Management Center has a hardcoded low-privilege account baked right into the software — CVE-2026-20316 — and unauthenticated remote attackers are already using it to log in and harvest sensitive data. That's Phase One. Phase Two is the wipe: threat actors are chaining it with CVE-2026-20079, which hands them root access via arbitrary script execution. (1/2)
##Cisco Patches Actively Exploited Hard-Coded Password in Secure Firewall Management Center
Cisco fixed a high-severity vulnerability (CVE-2026-20316) in Secure Firewall Management Center that allows unauthenticated remote attackers to log in using hard-coded credentials. CISA added the flaw to its KEV catalog following reports of zero-day exploitation targeting network security infrastructure.
**Make sure your Cisco Secure Firewall Management Center (FMC) is isolated from the internet and only reachable from trusted internal networks. Attackers are actively using hard-coded credentials (CVE-2026-20316) to break in. Apply Cisco's hotfix immediately (CISA requires it by August 1, 2026), and check your management logs for suspicious entries mentioning /var/tmp/license.tmp to spot any break-in.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/cisco-patches-actively-exploited-hard-coded-password-in-secure-firewall-management-center-p-x-i-l-e/gD2P6Ple2L
Cisco warns of FMC static credential flaw exploited in zero-day attacks
Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was...
🔗️ [Bleepingcomputer] https://link.is.it/AKCr32
##A Cisco FMC vulnerability, CVE-2026-20316, is exploited in the wild. Static credentials let attackers log in. CISA added it to KEV — patch now.
#Cisco #CVE202620316 #FMC #KEV #Vulnerability #InfoSec
https://securityonline.info/cisco-fmc-cve-2026-20316/?utm_source=mastodon&utm_medium=jetpack_social
##🚨 [CISA-2026:0729] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-20316 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20316)
- Name: Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Management Center (FMC)
- Notes: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20316
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260729 #cisa20260729 #cve_2026_20316 #cve202620316
##CVE ID: CVE-2026-20316
Vendor: Cisco
Product: Secure Firewall Management Center (FMC)
Date Added: 2026-07-29
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-20316
New Cisco updates:
CRITICAL vulnerability, first released on March 4: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2
High severity: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
New informational advisory: Cisco Advance Notification for Publication of August 5, 2026, Security Advisories https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-L4XfJg8S @TalosSecurity #infosec #vulnerability #Cisco
##updated 2026-07-30T12:32:26
1 posts
CVE-2026-18363: osTicket <1.17.8 & <1.18.4 has a CRITICAL flaw (CVSS 9.1) in password reset logic — tokens can be reused, risking account takeover. Upgrade when patch is available, monitor resets, and restrict token access. https://radar.offseq.com/threat/cve-2026-18363-cwe-640-weak-password-recovery-mechanism-for-forgotten-password-in-enhancesoft-llc-eea2d9a253a6859e #OffSeq #osTicket #CVE202618363
##updated 2026-07-30T12:32:18
2 posts
CVE-2026-64560: Linux UAF https://nvd.nist.gov/vuln/detail/CVE-2026-64560
##CVE-2026-64560: Linux UAF https://nvd.nist.gov/vuln/detail/CVE-2026-64560
##updated 2026-07-30T09:31:24
2 posts
CVE-2026-44095 - High privilege escalation in network config script lets local users execute commands as root. CVSS 7.8. No patch available - restrict local access. #CVE #infosec #privilegeescalation
###OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T09:31:24
2 posts
🔴 CVE-2026-44108 - Critical (9.8)
Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an un...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44108/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
###OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T09:31:24
2 posts
🟠 CVE-2026-44107 - High (7.5)
A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Deni...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44107/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
###OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T09:31:24
2 posts
Phoenix Contact CHARX SEC-3150 v1.0.0 hit by CRITICAL (CVSS 9.3) command injection (CVE-2026-7849): unauthenticated remote attackers can execute root commands. No mitigation yet — restrict access! https://radar.offseq.com/threat/cve-2026-7849-cwe-77-improper-neutralization-of-special-elements-used-in-a-command-command-injection-8b9703c63834cb6a #OffSeq #ICS #Vuln #CVE2026_7849
###OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T09:31:24
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T09:31:24
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T09:31:24
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T09:31:24
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T09:31:24
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T09:31:24
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T09:31:18
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T09:31:18
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T09:31:18
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T09:31:18
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T09:31:18
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T06:33:35
1 posts
The OVSwrap local root flaw hits the Linux kernel Open vSwitch datapath. CVE-2026-64531 now has a public patch and PoC. See affected distros and fixes.
#OVSwrap #CVE202664531 #LinuxKernel #OpenvSwitch #LocalRoot #PrivilegeEscalation
##updated 2026-07-30T06:32:44
2 posts
CVE-2026-58046 - Critical SQLi in Plesk XML-RPC API. Authenticated low-priv user can read entire DB, leading to full panel compromise. CVSS 9.9. No patch available yet. Apply workarounds immediately. #CVE #Plesk #infosec
##🔴 CVE-2026-58046 - Critical (9.9)
Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58046/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T06:32:44
1 posts
🔴 CVE-2026-58066 - Critical (9.8)
Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:Assertion. An attacker could submit a wrapped docu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58066/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T06:32:43
1 posts
🟠 CVE-2026-1360 - High (7.5)
The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` p...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-1360/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T03:31:28
1 posts
🟠 CVE-2026-48448 - High (8.6)
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to g...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48448/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T00:31:19
2 posts
CVE-2026-67595 (CRITICAL): VaahCMS 2.0.0 – 2.3.4 ships with malicious JS in OTP email templates. Enables C2, keylogging, WhatsApp scraping, and remote page control. Avoid JS-enabled viewing until patched. https://radar.offseq.com/threat/cve-2026-67595-embedded-malicious-code-in-webreinvent-vaahcms-94fc0638a0fe22eb #OffSeq #Infosec #CVE202667595 #VaahCMS
##🟠 CVE-2026-67595 - High (8.1)
VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67595/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T21:31:08
1 posts
1 repos
🟠 CVE-2026-5490 - High (8.8)
DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of DriveLock. Authentication is required to exploit this vulnerability.
The specific flaw exis...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-5490/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T21:31:08
2 posts
The latest GitLab patch release fixes 13 vulnerabilities, including CVE-2026-6267, a high-severity data exposure flaw. Update self-managed GitLab now.
#GitLab #CVE20266267 #DevSecOps #Vulnerability #PatchNow #InfoSec
##🟠 CVE-2026-6267 - High (8.5)
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauth...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-6267/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T21:31:08
1 posts
🟠 CVE-2026-5056 - High (7.8)
GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-5056/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T21:31:08
1 posts
🟠 CVE-2026-13308 - High (8.1)
Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-13308/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T21:31:08
1 posts
🟠 CVE-2026-6102 - High (7.8)
MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MSI Center. An attacker must first obtain the ability to execute...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-6102/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T21:31:07
1 posts
CRITICAL SSRF vuln (CVE-2026-14529) in IBM WebSphere App Server 9.0, 8.5, and Liberty 17.0.0.3 – 26.0.0.8 if SIP (sipServlet-1.1) is enabled. Review SIP use, disable if possible. Details: https://radar.offseq.com/threat/ibm-websphere-application-server-90-and-85-and-ibm-websphere-application-server-liberty-17003-through-99257a570e2e63d4 #OffSeq #IBM #WebSphere #SSRF #CVE202614529
##updated 2026-07-29T21:31:07
1 posts
🟠 CVE-2026-15975 - High (7.5)
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15975/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T21:31:07
1 posts
🟠 CVE-2026-5057 - High (7.5)
ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ATEN Unizon. Authentication is not required to exploit ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-5057/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T20:17:11.330000
1 posts
🟠 CVE-2026-67201 - High (8.6)
V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows attackers to circumvent host-based allowlists by exploiting a parser differential between net.urllib and net.http. Attackers c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67201/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T19:16:45.967000
1 posts
🟠 CVE-2026-43698 - High (7.8)
An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43698/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T15:31:12
1 posts
🟠 CVE-2026-67215 - High (7.5)
cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy oper...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67215/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T15:31:11
1 posts
CVE-2026-0667 (CRITICAL, CVSS 9.3): Schneider Electric SCADAPack 47x is vulnerable to improper Modbus TCP checks — risk of code execution, DoS, data loss. Review exposure & monitor for patches. https://radar.offseq.com/threat/cve-2026-0667-cwe-754-improper-check-for-unusual-or-exceptional-conditions-in-schneider-electric-09bef19ebc8e9eb8 #OffSeq #ICS #Vulnerability #SCADA
##updated 2026-07-29T15:31:05
1 posts
1 repos
🟠 CVE-2026-66748 - High (8.8)
Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the select_ev...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66748/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T15:16:30.153000
1 posts
🟠 CVE-2026-66745 - High (7.5)
Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability that allows unauthenticated attackers to hijack administrative sessions by setting a known PHPSESSID on a victim's browser prior...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66745/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T15:16:25.093000
1 posts
🟠 CVE-2026-54650 - High (8.6)
openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.Path instead of preserving the original request target with r.URL.EscapedPath(), allowing percent e...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54650/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T12:31:30
3 posts
New. This is in reference to CVE-2026-65883.
VulnCheck: Aimy Captcha-Less Form Guard: The Anti-Bot Plugin That Hands Bots the Keys https://www.vulncheck.com/blog/aimy-captcha-less-form-guard-object-injection @vulncheck #infosec #vulnerability
##New. This is in reference to CVE-2026-65883.
VulnCheck: Aimy Captcha-Less Form Guard: The Anti-Bot Plugin That Hands Bots the Keys https://www.vulncheck.com/blog/aimy-captcha-less-form-guard-object-injection @vulncheck #infosec #vulnerability
##CVE-2026-65883 (CRITICAL, CVSS 10): Aimy Captcha-Less Form Guard for Joomla (v18.0-20.0) is vulnerable to PHP object injection via clfgd field — enabling RCE. Patch or disable plugin urgently. https://radar.offseq.com/threat/cve-2026-65883-cwe-502-deserialization-of-untrusted-data-in-aimy-extensionscom-aimy-captcha-less-form-dff78e8752eedd4a #OffSeq #Joomla #Exploit #RCE
##updated 2026-07-29T12:31:30
1 posts
🟠 CVE-2026-14270 - High (8.8)
The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing authorization and nonce validati...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14270/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T09:31:37
1 posts
#OT #Advisory VDE-2026-041
CODESYS PROFINET Controller - Out-of-bounds Write
CODESYS PROFINET is an add‑on for the CODESYS Development System that provides a fully integrated PROFINET protocol stack along with diagnostic capabilities. When a PROFINET Controller is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems.
#CVE CVE-2026-35226
https://certvde.com/en/advisories/vde-2026-041/
#CSAF https://codesys.csaf-tp.certvde.com/.well-known/csaf/white/2026/advisory2026-06_vde-2026-041.json
##updated 2026-07-29T09:31:36
1 posts
New.
Tenable Research Advisories: CVE-2026-18197: Link Library - Reflected Cross-Site Scripting https://www.tenable.com/security/research/tra-2026-52
From yesterday:
Coordinated “cyberattack” on Minnesota water utilities: What you need to know https://www.tenable.com/blog/coordinated-cyberattack-on-minnesota-water-utilities-what-you-need-to-know @tenable #infosec #cyberattack #Minnesota #threatresearch
##updated 2026-07-29T06:32:11
2 posts
🔴 CVE-2026-18072 - Critical (9.8)
The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` func...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18072/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Active exploitation of CVE-2026-18072, a CVSS 9.8 video embedder backdoor, grants attackers full administrative control over 20,000 WordPress sites.
##updated 2026-07-29T03:30:21
1 posts
🟠 CVE-2026-12144 - High (8.8)
The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the `save_requests_meta()` function applying only `sanitize_text_field()` to the `user_role_set` P...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12144/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T22:19:24
1 posts
🔴 CVE-2026-54658 - Critical (9.8)
Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backslashes before single quotes during parameter substitution, allowing attacker controlled query param...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54658/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T22:15:29
1 posts
🟠 CVE-2026-54638 - High (7.5)
gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted_message.go read attacker controlled dataLen from an unauthenticated MTProto unencrypted packet and allocated make([]byte, data...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54638/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T22:03:13
1 posts
🔴 CVE-2026-64863 - Critical (9.1)
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOVE as a write-only method and did not enforce --no-delete, allowing WebDAV clients to delete or ove...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64863/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T21:57:19
1 posts
🔴 CVE-2026-62325 - Critical (9.1)
goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != "" && Password != "", so running goshs with -b 'admin:' -sftp and no -fkf left...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62325/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T21:45:50
1 posts
🟠 CVE-2026-55391 - High (7.5)
datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.63.0, datamodel-code-generator validates a URL host once i...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55391/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T21:31:45
1 posts
IBM Aspera vulnerabilities affect Faspex 5 and the Desktop App. CVE-2026-14973 and two RCE flaws rate up to 9.3. Update to Faspex 5.0.16 and Desktop 1.1.0.
#IBMAspera #AsperaFaspex #CVE202614973 #RCE #PathTraversal #CyberSecurity
##updated 2026-07-28T21:31:45
1 posts
🟠 CVE-2026-15057 - High (7.5)
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15057/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T21:31:45
1 posts
🟠 CVE-2026-14996 - High (8.2)
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14996/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T21:31:39
1 posts
🟠 CVE-2026-7769 - High (8.1)
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to SQL ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-7769/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T21:26:42
2 posts
CVE-2026-55390 - High severity path traversal in datamodel-code-generator 0.59.0-0.62.0. Arbitrary local file read via XML schema imports. CVSS 7.5. Update to 0.62.0 immediately. #CVE #Python #infosec
##🟠 CVE-2026-55390 - High (7.5)
datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema parsing in src/datamodel_code_generator/parser/xmlschema.py for --input-file-type xmlschema resolves xs:include, xs:import, xs:rede...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55390/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T19:52:21.577000
1 posts
🟠 CVE-2026-43749 - High (7.8)
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43749/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T17:16:52.923000
2 posts
Escaping Linux Sandboxes via PipeWire (CVE-2026-5674) https://embracethered.com/blog/posts/2026/pipewire-flatpak-linux-sandbox-escape-cve-2026-5674/
##Escaping Linux Sandboxes via PipeWire (CVE-2026-5674) https://embracethered.com/blog/posts/2026/pipewire-flatpak-linux-sandbox-escape-cve-2026-5674/
##updated 2026-07-28T17:09:03
1 posts
🟠 CVE-2026-54635 - High (7.5)
pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webhook access to the TON blockchain. From 2.0.0 to 2.2.0, TonapiWebhookDispatcher fails to validate the Authorization header when a webhook handler is registered with the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54635/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T16:17:58.820000
5 posts
CVE-2026-63077 Exposes TeamCity Servers to Unauthenticated RCE
A critical security flaw affecting TeamCity On-Premises has prompted administrators to update their servers immediately after researchers disclosed...
🔗️ [Thecyberexpress] https://link.is.it/Uo0klI
##JetBrains patches critical TeamCity On-Premises vulnerability CVE-2026-63077 (CVSS 9.8), preventing unauthenticated remote code execution.
##🏆 New Achievement! Exhibit A: Your CI Server Did It!
The record will reflect that on or about July 28, 2026, JetBrains disclosed CVE-2026-63077, a CVSS 9.8 vulnerability in TeamCity On-Premises. The record will further reflect that any unauthenticated attacker with mere HTTP(S) access could bypass authentication and execute arbitrary operating system commands. (1/3)
##JetBrains Fixes Critical TeamCity Authentication Bypass Allowing Remote Code Execution
JetBrains patched a critical authentication bypass (CVE-2026-63077) in TeamCity On-Premises that allows unauthenticated remote code execution. The flaw affects all on-premises versions and could lead to a full takeover of CI/CD pipelines.
**If you run TeamCity On-Premises, urgently update to version 2025.11.7 or 2026.1.3 to patch CVE-2026-63077. All on-premises versions are vulnerable to a full server takeover. TeamCity Cloud is already patched and needs no action. If you can't update right away, install the security patch plugin (for versions 2017.1 and later) and restrict access to your TeamCity server to trusted internal networks or a VPN.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/jetbrains-fixes-critical-teamcity-authentication-bypass-allowing-remote-code-execution-c-x-w-3-z/gD2P6Ple2L
#TeamCity #CVE202663077 #RCE #RemoteCodeExecution #JetBrains #CyberSecurity
##updated 2026-07-28T15:32:25
1 posts
🟠 CVE-2026-59878 - High (7.5)
Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All.
A remote unauthenticated peer that can reach an exposed AMQP NIO connector can trigger denial-of-service behavior by sending a frame size value...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59878/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T15:32:19
1 posts
🟠 CVE-2026-63727 - High (8.8)
Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capab...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63727/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T15:32:18
1 posts
🟠 CVE-2026-7187 - High (8.8)
Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects UKBS: through 28072026.
NOTE: The vendor was contacted and it was learn...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-7187/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T14:58:00
1 posts
🟠 CVE-2026-61609 - High (7.5)
Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limiter defined in RouteServiceProvider::configureRateLimiting() applied a single global bucket to the login and two-factor checkpoin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61609/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T14:28:13
1 posts
CVE-2026-45293 is an arbitrary code execution flaw in WordPress Coding Standards, rated CVSS 8.6. The dev tool has 49M+ installs. Upgrade to 3.4.1.
#WordPressCS #CVE202645293 #WordPress #CodeExecution #PHPCS #DevSecOps #SupplyChain #InfoSec #CyberSecurity
##updated 2026-07-28T13:17:14.747000
1 posts
6 repos
https://github.com/guiimoraes/CVE-2025-15467
https://github.com/mr-r3b00t/CVE-2025-15467
https://github.com/materaj2/cve-2025-15467
https://github.com/x-stp/cves-2025-11187_15467_69418
Siemens Patches Critical OpenSSL Flaw in Desigo CC Building Management Systems
Siemens released security updates for Desigo CC to address a critical OpenSSL vulnerability (CVE-2025-15467) that allows unauthenticated remote code execution or denial of service through malformed cryptographic messages.
**First, make sure all Desigo CC building management systems are isolated from the internet and reachable only from trusted networks. Then, if you run V9 update to V9.0 QU1 (or later) and if you run V8 apply patch V8.0 QU2.0021; for V7 there is no patch yet.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/siemens-patches-critical-openssl-flaw-in-desigo-cc-building-management-systems-t-n-v-d-a/gD2P6Ple2L
updated 2026-07-28T12:31:27
1 posts
#OT #Advisory VDE-2026-085
Weidmueller: SQL Injection Vulnerability in PROCON-WEB SCADA
A remote unauthenticated attacker can exploit a SQL injection vulnerability in PROCON-WEB SCADA to execute arbitrary commands.
#CVE CVE-2026-16462
https://certvde.com/en/advisories/vde-2026-085/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-085.json
##updated 2026-07-28T09:31:36
2 posts
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-07-28T09:31:36
2 posts
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-07-28T09:31:35
2 posts
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-07-28T00:32:06
1 posts
🟠 CVE-2026-43723 - High (7.8)
A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to gain root pri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43723/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T00:32:04
1 posts
🟠 CVE-2026-39874 - High (7.8)
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-39874/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T00:31:11
1 posts
🟠 CVE-2026-66473 - High (7.5)
Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66473/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T00:31:02
1 posts
🟠 CVE-2026-43776 - High (7.8)
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43776/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-27T21:31:22
6 posts
📰 Critical Arista VeloCloud Zero-Day Flaw Under Active Exploitation
🚨 CRITICAL: A CVSS 10.0 zero-day (CVE-2026-16812) in Arista's on-prem VeloCloud Orchestrator is actively exploited. Unauthenticated RCE allows full SD-WAN compromise. CISA mandates immediate patching. #CVE202616812 #ZeroDay #SDWAN
🌐 cyber[.]netsecops[.]io
##Arista addresses CVE-2026-16812, a critical vulnerability in VeloCloud Orchestrator actively exploited to gain unauthenticated remote code execution.
##🏆 New Achievement! Ten Out of Ten, Would Exploit Again!
Step right up, valued on-premises customer! Today's featured item is CVE-2026-16812, a perfect-score CVSS 10.0 OS command injection in Arista's VeloCloud Orchestrator — the centralized management platform you trusted with the confidentiality, integrity, and availability of, well, everything. Unknown attackers are already browsing your privileged internal functionality like it's a clearance rack. (1/2)
##(CISA TS-SOC) CVE-2026-16812 – Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
Severity: CRITICAL Impact Summary: Remote attackers may access privileged internal functionality and impact the VCO host, compromising the confidentiality, integrity, and availability of the orchestrator and managed data....
##CISA KEV additions on July 27 flag two known exploited vulnerabilities: Arista VeloCloud CVE-2026-16812 and FortiOS CVE-2025-68686. Patch both now.
#CISA #KEV #Arista #VeloCloud #Fortinet #FortiOS #CVE #ExploitedInTheWild #Cybersecurity
##CVE ID: CVE-2026-16812
Vendor: Arista
Product: VeloCloud Orchestrator
Date Added: 2026-07-27
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16812
updated 2026-07-27T18:31:25
2 posts
CISA Warns of Active Exploitation in Fortinet FortiOS SSL-VPN Patch Bypass
CISA reports active explotation of CVE-2025-68686, a flaw in Fortinet FortiOS that allows attackers to bypass security patches and maintain persistent access on compromised devices.
**If you use Fortinet devices, make sure they are isolated from the internet and accessible only from trusted networks. Then update FortiOS ASAP to version 7.6.2, 7.4.7, or later. This flaw is combined with others, so make sure all your Fortinet devices are up-to-date. And check your devices for indicators of compromise, this flaw allowed hackers to maintain access over patch cycles.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/cisa-warns-of-active-exploitation-in-fortinet-fortios-ssl-vpn-patch-bypass-h-6-5-r-8/gD2P6Ple2L
CISA KEV additions on July 27 flag two known exploited vulnerabilities: Arista VeloCloud CVE-2026-16812 and FortiOS CVE-2025-68686. Patch both now.
#CISA #KEV #Arista #VeloCloud #Fortinet #FortiOS #CVE #ExploitedInTheWild #Cybersecurity
##updated 2026-07-27T15:32:39
4 posts
6 repos
https://github.com/tc4dy/CVE-2026-61511-PoC-Exploit
https://github.com/HORKimhab/CVE-2026-61511
https://github.com/webshellseo8/CVE-2026-61511-POC
https://github.com/puj790201-lab/cve-2026-61511
📢 RCE non authentifiée dans vBulletin ≤ 6.2.1 via la méthode runMaths() (CVE-2026-61511)
📝 ## 🔍 Contexte
Publié le 27 juillet 2026 sur le blog de recherche Karma(In)Security (karmainsecurity.com), cet article détaille une vulnérabilité critique d'exécut...
📖 cyberveille : https://cyberveille.ch/posts/2026-07-29-rce-non-authentifiee-dans-vbulletin-6-2-1-via-la-methode-runmaths-cve-2026-61511/
🌐 source : https://karmainsecurity.com/KIS-2026-13
#CVE_2026_61511 #IOC #Cyberveille
A critical vBulletin pre-auth RCE vulnerability, CVE-2026-61511, threatens unpatched forums. Learn how attackers exploit template math evaluation.
##vBulletin Fixes Critical Pre-Auth Remote Code Execution Flaw
vBulletin released patches for a critical remote code execution vulnerability, tracked as CVE-2026-61511 (CVSS score 9.8), that allows unauthenticated attackers to execute arbitrary PHP code on affected forum servers. The flaw affects vBulletin 5.x and 6.x installations, and a public proof-of-concept exploit is available.
**If you run a self-hosted vBulletin forum, upgrade to version 6.2.2 or apply the available security patch immediately. A public exploit allows unauthenticated attackers to target vulnerable servers. Users running the unsupported 5.x branch should migrate to a patched 6.x release.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/vbulletin-fixes-critical-pre-auth-remote-code-execution-flaw-l-x-5-a-m/gD2P6Ple2L
‼️ CVE-2026-61511: Improper Neutralization of Directives in Dynamically Evaluated Code
FOFA Query: app="vBulletin"
FOFA: https://en.fofa.info/result?qbase64=YXBwPSJ2QnVsbGV0aW4i
Results: 11,081
##updated 2026-07-25T03:30:55
1 posts
A public PoC now targets CVE-2026-66373, a Redis RCE double-free via RESTORE. See affected versions and upgrade to Redis 8.8.0 now.
#Redis #RedisRCE #CVE202666373 #RCE #DoubleFree #PoC #RESTORE #Cybersecurity
https://securityonline.info/redis-rce-cve-2026-66373/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-07-24T16:14:33
1 posts
CVE-2026-59952 | open-circle valibot <1.4.2 suffers from improper exception handling in flatten(), causing TypeErrors & potential DoS if attacker-controlled keys collide w/ Object.prototype methods. Severity: MEDIUM. Upgrade to 1.4.2+ https://radar.offseq.com/threat/cve-2026-59952-cwe-755-improper-handling-of-exceptional-conditions-in-open-circle-valibot-c7fe163cf2db3032 #OffSeq #Valibot #AppSec
##updated 2026-07-24T00:32:40
1 posts
A Panduit IntraVUE vulnerability tracked as CVE-2026-42933 scores CVSS 10. Five flaws let attackers cross OT segmentation and steal credentials.
##updated 2026-07-23T21:31:03
1 posts
A C-CURE 9000 vulnerability chain hits CVSS 9.6. CVE-2026-21655 allows remote code execution on Johnson Controls victor application servers.
##updated 2026-07-23T15:00:18
1 posts
🟠 CVE-2026-59932 - High (7.5)
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, and all releases up to and including 1.30.5, the Gnumeric reader read...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59932/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-23T14:55:51
1 posts
🟠 CVE-2026-59931 - High (7.7)
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, and all releases up to and including 1.30.5, the WEBSERVICE() domain ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59931/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-23T11:10:00.120000
1 posts
9 repos
https://github.com/gl1tch0x1/DirtyClone
https://github.com/mooder1/dirtyclone-CVE-2026-43503
https://github.com/entra1337/DirtyClone
https://github.com/0xBlackash/CVE-2026-43503
https://github.com/lieehrdiansyah12/CVE-2026-43503
https://github.com/rjt-gupta/page-cache-corruption-lpes
https://github.com/sec0x/CVE-2026-43503
‼️ CVE-2026-43503: DirtyClone is a Linux kernel local privilege escalation (LPE) vulnerability caused by page-cache corruption.
##updated 2026-07-23T09:32:08
2 posts
5 repos
https://github.com/why-success/fastjson-rce-lab
https://github.com/dinosn/fastjson-jsontype-rce-lab
https://github.com/HORKimhab/CVE-2026-16723
Discover the critical Fastjson RCE CVE-2026-16723 vulnerability. Learn how attackers exploit Spring Boot applications and find mitigation strategies.
#Fastjson #CVE202616723 #Cybersecurity #SpringBoot #Malware
https://meterpreter.org/fastjson-rce-cve-2026-16723/?utm_source=mastodon&utm_medium=jetpack_social
##⚠️ CRITICAL: Hackers target US firms in FastJson RCE zero-day attacks
A critical RCE zero-day (CVE-2026-16723) in FastJson Java library versions 1.2.68-1.2.83 is actively exploited against U.S. firms across multiple sectors. Attackers can execute arbitrary code without user interaction. FastJson 1.x is unmaintained, leaving affected systems without patches.
##updated 2026-07-22T21:32:05
7 posts
2 repos
https://github.com/sfewer-r7/CVE-2026-16232
https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review
🚨 CRITICAL ADVISORY:
Check Point SmartConsole Authentication Bypass (CVE-2026-16232) is actively exploited in the wild! Learn how unauthenticated attackers forge SSO tokens to hijack servers & discover key mitigations:
https://denizhalil.com/2026/07/30/checkpoint-smartconsole-authentication-bypass-cve-2026-16232/
##From our Check Point Research Team:
July 2026 Security Update
Check Point has addressed CVE-2026-16232, an authentication bypass vulnerability in SmartConsole that is under active exploitation, affecting a handful of customers. The flaw allows remote attackers to bypass authentication and gain administrative access to Check Point management servers. Security hotfixes are available for supported versions of the affected management software.
##Authentication bypass for Check Point Security Management Server and Multi-Domain Security Management Server https://github.com/sfewer-r7/CVE-2026-16232
##Rapid7, from yesterday: Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232) https://www.rapid7.com/blog/post/ra-check-point-smartconsole-authentication-bypass-technical-analysis-cve-2026-16232/ @Rapid7Official #infosec #vulnerability #threatresearch
##Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)
#CVE_2026_16232
https://www.rapid7.com/blog/post/ra-check-point-smartconsole-authentication-bypass-technical-analysis-cve-2026-16232/
CVE-2026-16232 is a SmartConsole authentication bypass in Check Point Security Management. Exploited in the wild, with a public PoC now available.
#CheckPoint #SmartConsole #CVE202616232 #AuthenticationBypass #ZeroDay #CyberSecurity
##⚪️ Hackers Exploit a Zero-Day in Check Point SmartConsole
🗨️ Check Point has warned customers about a critical vulnerability, CVE-2026-16232, affecting its Security Management and Multi-Domain Management products. The flaw allows attackers to bypass authentication, gain administrator privileges, and modify security policies. The vulnerability is already be…
##updated 2026-07-22T16:18:05.400000
1 posts
A public PoC exploit now targets CVE-2026-50502, an RCE in the Windows Event Log service. Microsoft patched the flaw on July 14, 2026. Details below.
#CVE202650502 #WindowsEventLog #RCE #PatchTuesday #InfoSec #Microsoft
##updated 2026-07-20T21:31:40
2 posts
1 repos
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-07-18T09:32:17
1 posts
Fraggap Linux Kernel Vulnerability: Full Details and PoC Exploit Code Now Public
##updated 2026-07-16T12:33:31
2 posts
3 repos
https://github.com/v4ltonn/CVE-2026-42530
A public PoC now details CVE-2026-42530, an NGINX HTTP/3 RCE from a QPACK use-after-free. Upgrade to NGINX 1.31.2 to close the flaw now.
#NGINX #HTTP3 #CVE202642530 #RCE #UseAfterFree #QUIC #QPACK #PoC #Cybersecurity
##A public PoC now details CVE-2026-42530, an NGINX HTTP/3 RCE from a QPACK use-after-free. Upgrade to NGINX 1.31.2 to close the flaw now.
#NGINX #HTTP3 #CVE202642530 #RCE #UseAfterFree #QUIC #QPACK #PoC #Cybersecurity
##updated 2026-07-15T15:33:14
1 posts
9 repos
https://github.com/gagaltotal/CVE-2026-42533-nginx
https://github.com/Daniyal48/ghostlock-vagrant-box
https://github.com/jelasin/CVE-2026-42533
https://github.com/seguridadentrerios/CVE-2026-42533
https://github.com/ChPratik/NGINX_2026_CVE_Bundle_CTI_Report
https://github.com/suominen/CVE-2026-42533
https://github.com/imbas007/CVE-2026-42533
https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner
A public PoC now details CVE-2026-42533, an NGINX heap overflow with an ASLR bypass and possible RCE. Upgrade to NGINX 1.31.3 or 1.30.4 now.
#NGINX #CVE202642533 #RCE #HeapOverflow #ASLRBypass #NGINXPlus #PoC #Cybersecurity
##updated 2026-07-14T18:32:37
2 posts
8 repos
https://github.com/mwnickerson/certighost-bof
https://github.com/GlendonNotGlen/certighost-cve-2026-54121-slides
https://github.com/ChPratik/CVE-2026-54121
https://github.com/aniqfakhrul/CVE-2026-54121
https://github.com/0xBlackash/CVE-2026-54121
https://github.com/HORKimhab/CVE-2026-54121
Certighost AD CS vulnerability details and PoC code for CVE-2026-54121 are public. The flaw let a low-privileged user impersonate a Domain Controller.
#Certighost #CVE202654121 #ADCS #ActiveDirectory
https://securityonline.info/certighost-cve-2026-54121/?utm_source=mastodon&utm_medium=jetpack_social
##Exploit público para a falha Certighost expôs domínios do Windows a controlo total. Uma nova vulnerabilidade, rastreada como CVE-2026-54121, coloca redes empresariais em risco e permite que um atacante assuma o controlo completo de um domínio informático. 🚨
##updated 2026-07-14T18:32:32
1 posts
CVE-2026-50469 - ProjFS File Delete https://bad-jubies.github.io/projected-file-system-file-delete-cve-2026-50469
##updated 2026-07-10T19:15:15.780000
1 posts
1 repos
Ruflo <3.16.3 has a CRITICAL flaw (CVE-2026-59726): exposed /mcp endpoint allows unauth RCE in MCP bridge container. Attackers can spawn rogue AI swarms & steal API keys. Upgrade to 3.16.3 asap. https://radar.offseq.com/threat/critical-ruflo-flaw-lets-attackers-spawn-rogue-ai-swarms-96a3ca25e5fa59f3 #OffSeq #AIsecurity #infosec #CVE202659726
##updated 2026-07-09T19:34:14.067000
2 posts
1 repos
🚨 PoC for CVE-2026-58025, a CVSS 9.8 MediaWiki deserialization flaw that could enable RCE through malicious log entry imports.
Exploitation requires import permissions. Upgrade to 1.43.9, 1.44.6, 1.45.4, or 1.46.0.
##🚨 PoC for CVE-2026-58025, a CVSS 9.8 MediaWiki deserialization flaw that could enable RCE through malicious log entry imports.
Exploitation requires import permissions. Upgrade to 1.43.9, 1.44.6, 1.45.4, or 1.46.0.
##updated 2026-06-30T03:37:45
2 posts
2 repos
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-06-30T03:36:54
1 posts
1 repos
Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update. https://thehackernews.com/2026/07/researchers-show-single-malicious.html
##updated 2026-06-17T19:22:02.480000
1 posts
@drwhax also CVE-2026-0160 affecting RTT (US mandated). Reachability is via RTT call.
##updated 2026-06-17T18:36:28
1 posts
updated 2026-06-17T10:20:26.697000
2 posts
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-06-17T10:20:26.520000
2 posts
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-06-17T10:00:40.683000
2 posts
1 repos
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-06-17T10:00:40.067000
2 posts
1 repos
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-06-17T08:37:46.203000
2 posts
@fugueish Was going to shill Kagi, but their first result is CVE-2025-15435 (i.e. wrong year). The second result is correct. Quotes don't uprank that second result for some reason. It's still the first day, so maybe their crawls aren't as aggressive?
##@fugueish Was going to shill Kagi, but their first result is CVE-2025-15435 (i.e. wrong year). The second result is correct. Quotes don't uprank that second result for some reason. It's still the first day, so maybe their crawls aren't as aggressive?
##updated 2026-06-17T07:05:03.993000
1 posts
2 repos
https://github.com/MobetaSec/CVE-2024-1813-POC
https://github.com/webshellseo8/CVE-2024-1813-Proof-of-Concept
Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813) https://mobeta.fr/simple-job-board-unauth-rce-cve-2024-1813/
##updated 2026-06-17T00:02:24.467000
1 posts
75 repos
https://github.com/siddolo/knockbleed
https://github.com/0x90/CVE-2014-0160
https://github.com/einaros/heartbleed-tools
https://github.com/jdauphant/patch-openssl-CVE-2014-0160
https://github.com/undacmic/heartbleed-proof-of-concept
https://github.com/WildfootW/CVE-2014-0160_OpenSSL_1.0.1f_Heartbleed
https://github.com/mozilla-services/Heartbleed
https://github.com/hmlio/vaas-cve-2014-0160
https://github.com/Saymeis/HeartBleed
https://github.com/marstornado/cve-2014-0160-Yunfeng-Jiang
https://github.com/MrE-Fog/CVE-2014-0160-Chrome-Plugin
https://github.com/vortextube/ssl_scanner
https://github.com/iSCInc/heartbleed
https://github.com/isgroup/openmagic
https://github.com/pierceoneill/bleeding-heart
https://github.com/0xinf0/bleeding_onions
https://github.com/cheese-hub/heartbleed
https://github.com/cyphar/heartthreader
https://github.com/obayesshelton/CVE-2014-0160-Scanner
https://github.com/ingochris/heartpatch.us
https://github.com/PinkP4nther/Heartbleed_PoC
https://github.com/indrajeetmp11/Heartbleed-PoC-Exploit-Script
https://github.com/sammyfung/openssl-heartbleed-fix
https://github.com/hreese/heartbleed-dtls
https://github.com/pblittle/aws-suture
https://github.com/timsonner/cve-2014-0160-heartbleed
https://github.com/iwaffles/heartbleed-test.crx
https://github.com/waqasjamal-zz/HeartBleed-Vulnerability-Checker
https://github.com/FiloSottile/Heartbleed
https://github.com/Ryo-Soikutsu/Heartbleed
https://github.com/GuillermoEscobero/heartbleed
https://github.com/zouguangxian/heartbleed
https://github.com/ArtemCyberLab/Project-Field-Analysis-and-Memory-Leak-Demonstration
https://github.com/ice-security88/CVE-2014-0160
https://github.com/0xBlackash/CVE-2014-0160
https://github.com/roganartu/heartbleedchecker-chrome
https://github.com/tomdevman/heartbleed-bug
https://github.com/amerine/coronary
https://github.com/cbk914/heartbleed-checker
https://github.com/hybridus/heartbleedscanner
https://github.com/titanous/heartbleeder
https://github.com/DisK0nn3cT/MaltegoHeartbleed
https://github.com/yryz/heartbleed.js
https://github.com/Lekensteyn/pacemaker
https://github.com/mpgn/heartbleed-PoC
https://github.com/ThanHuuTuan/Heartexploit
https://github.com/indiw0rm/-Heartbleed-
https://github.com/cved-sources/cve-2014-0160
https://github.com/h3x0v3rl0rd/CVE-2014-0160_Heartbleed
https://github.com/yashfren/CVE-2014-0160-HeartBleed
https://github.com/belmind/heartbleed
https://github.com/victoriacfigueiredo/heartbleed-lab
https://github.com/GardeniaWhite/fuzzing
https://github.com/xanas/heartbleed.py
https://github.com/froyo75/Heartbleed_Dockerfile_with_Nginx
https://github.com/idkqh7/heatbleeding
https://github.com/OffensivePython/HeartLeak
https://github.com/caiqiqi/OpenSSL-HeartBleed-CVE-2014-0160-PoC
https://github.com/22imer/CVE-2014-0160
https://github.com/artofscripting-zz/cmty-ssl-heartbleed-CVE-2014-0160-HTTP-HTTPS
https://github.com/Shayhha/HeartbleedAttack
https://github.com/GeeksXtreme/ssl-heartbleed.nse
https://github.com/a0726h77/heartbleed-test
https://github.com/fb1h2s/CVE-2014-0160
https://github.com/rouze-d/heartbleed
https://github.com/tungduongNT/CVE-2014-0160.
https://github.com/xlucas/heartbleed
https://github.com/musalbas/heartbleed-masstest
https://github.com/sensepost/heartbleed-poc
https://github.com/DominikTo/bleed
https://github.com/anthophilee/A2SV--SSL-VUL-Scan
https://github.com/takeshixx/ssl-heartbleed.nse
Shodan-Query of the day:
asn:"AS59399" vuln:"cve-2014-0160"
##updated 2026-06-16T23:57:53.617000
1 posts
1 repos
RE: https://infosec.exchange/@BleepingComputer/116997530501171992
The firm that provided the story to BC is a new startup aiming to help "Manage and Secure Data Centers".
They exploited CVE-2013-4786
This is advertising a new startup by flogging a report by extremely lazy "researchers" (did they even do *any* "is this a honeypot" tests?)
Perhaps don't let your C-suite give Lava any business?
##updated 2026-05-29T15:30:38
2 posts
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-05-15T18:30:32
5 posts
1 repos
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit
Proofpoint는 러시아 연계 위협 행위자 TA488이 Outlook Web Access(OWA)의 HTML sanitization XSS 취약점 CVE-2026-42897을 악용해, 이메일을 열기만 해도 JavaScript가 실행되는 ‘half-click’ 공격을 수행했다고 밝혔다. 페이로드인 OWAReaper는 OWA 읽기 창에서만 동작하며 localStorage, IndexedDB 오프라인 캐시, Exchange 폴더 권한...
##The activity, which began on July 22, 2026, involves the weaponization of CVE-2026-42897 (CVSS score: 8.1), a cross-site scripting (XSS) vulnerability in OWA. It was flagged by Microsoft as having been exploited in attacks as far back as May 2026. https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html?_m=3n%2e009a%2e4043%2ebk0aof3yrl%2e33l5
##Proofpoint analyses a campaign from Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) exploiting Outlook CVE-2026-42897 and targeting US & European government entities, as well as the telecommunications, financial, hospitality & aerospace sectors. https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit
##New.
"On 22 July 2026, one day prior to Proofpoint’s recent joint release with the NSA on Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear), the actor began a campaign abusing CVE-2026-42897, a cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA)."
Proofpoint: Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit
More:
The Record: Laundry Bear’s webmail hackers had more in store after February, report says https://therecord.media/russia-hackers-outlook-webmail-malware @therecord_media @jwarminsky #infosec #threatresearch #Outlook #Microsoft
##A TA488 half-click exploit abuses CVE-2026-42897 in Outlook Web Access to drop OWAReaper, a stealthy implant that survives device reimaging.
#TA488 #OWAReaper #HalfClickExploit #CVE202642897 #OutlookWebAccess #InfoSec
##updated 2026-05-12T15:31:14
2 posts
1 repos
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-05-12T15:31:14
2 posts
1 repos
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-05-12T15:31:14
2 posts
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-05-11T21:31:33
2 posts
5 repos
https://github.com/Polosss/By-Poloss..-..CVE-2026-48939
https://github.com/ChiefYoru/CVE-2026-48939_PoC
https://github.com/lottiedeyan/CVE20264893poc
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-03-04T18:32:03
2 posts
1 repos
🏆 New Achievement! Static Credentials, Static Fate!
RAID ALERT. RAID ALERT. Cisco Secure Firewall Management Center has a hardcoded low-privilege account baked right into the software — CVE-2026-20316 — and unauthenticated remote attackers are already using it to log in and harvest sensitive data. That's Phase One. Phase Two is the wipe: threat actors are chaining it with CVE-2026-20079, which hands them root access via arbitrary script execution. (1/2)
##New Cisco updates:
CRITICAL vulnerability, first released on March 4: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2
High severity: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
New informational advisory: Cisco Advance Notification for Publication of August 5, 2026, Security Advisories https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-L4XfJg8S @TalosSecurity #infosec #vulnerability #Cisco
##updated 2026-01-29T21:30:37
1 posts
1 repos
⚪️ Hackers Exploit a Zero-Day in Check Point SmartConsole
🗨️ Check Point has warned customers about a critical vulnerability, CVE-2026-16232, affecting its Security Management and Multi-Domain Management products. The flaw allows attackers to bypass authentication, gain administrator privileges, and modify security policies. The vulnerability is already be…
##updated 2025-11-04T21:32:34
2 posts
@slomo No need for the hostility. The text summary might pull context from reference links mentioning 1.22.5, but our 'Patch Status' flag operates strictly on machine-readable data from the NVD API.
If you look at the official NVD record for CVE-2023-37327, the CPE configurations only map up to 1.22.4 and do not explicitly record the patched status. We explicitly do not accept vendor GitHub releases as evidence until they are validated by NVD.
@hugovalters Bullshit. Get your data updated and fix your website instead of spreading fud.
It's very funny that e.g. https://www.valtersit.com/cve/CVE-2023-37327/ claims to be "unpatched" and at the top says that it's fixed in 1.22.5, contains completely wrong information (just follow your own NVD link and compare: it's describing completely different issues), and a wrong patch for code that does not even exist in this shape in 1.22.5 or any other version.
Not enough that we have to deal with a flood of new issues reported thanks to LLMs, on top of that we also have to deal with clowns like you.
##updated 2024-02-15T15:02:28
1 posts
3 repos
https://github.com/Trinadh465/platform_external_libvpx_v1.4.0_CVE-2023-5217
https://github.com/UT-Security/cve-2023-5217-poc
https://github.com/Trinadh465/platform_external_libvpx_v1.8.0_CVE-2023-5217
now to figure out if CVE-2023-5217 on our NAS actually matters...
##updated 2023-01-31T05:05:55
1 posts
Apple was much more verbose in describing security issues in 2008 (look at CVE-2008-1028)
https://support.apple.com/en-ie/102486
3 posts
2 repos
📰 Critical RCE Flaw in OpenWrt Allows Root Access via DHCPv6
🚨 CRITICAL RCE: A vulnerability in OpenWrt (CVE-2026-53921) allows unauthenticated attackers to gain root access via the DHCPv6 server. All versions before 24.10.8 are affected. Update your routers immediately! #OpenWrt #RCE #CVE
🌐 cyber[.]netsecops[.]io
##OpenWrt Vulnerability CVE-2026-53921 Demands Immediate Action
##⚠️ CRITICAL: Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
OpenWrt released a critical patch (v24.10.8) for CVE-2026-53921, a stack overflow in the DHCPv6 service (odhcpd) that allows unauthenticated remote code execution as root. Any unpatched OpenWrt device is exploitable by sending crafted DHCPv6 packets. This affects routers and edge devices across ent…
##Using AI to understand kernel crashes | Alexander Leidinger
<https://www.leidinger.net/blog/2026/07/19/using-ai-to-understand-kernel-crashes/>
– via <https://www.reddit.com/r/freebsd/comments/1val3np/using_ai_to_understand_kernel_crashes_alexander/>.
Alexander is credited for this month's CVE-2026-58086 (FreeBSD-SA-26:53.ktrace): <https://www.reddit.com/r/freebsd/comments/1vakgpe/freebsd_errata_notices_and_security_advisories/p0m8ods/>
####This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...
Node.js patched 11 vulnerabilities in its July 2026 release. The high-severity bugs include a HTTP/2 use-after-free (CVE-2026-56848). Update now.
#NodeJS #CVE202656848 #HTTP2 #UseAfterFree #Vulnerability #InfoSec
####This is a security release. Notable Changes (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX...
##This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...
##This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...
##This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...
NVIDIA BlueField has a critical VIRTIO-Net flaw, CVE-2026-65094, rated CVSS 9.0. A VM user could trigger code execution. Update to the fixed DOCA build.
#NVIDIA #BlueField #VIRTIONet #CVE202665094 #CodeExecution #CyberSecurity
##