##
Updated at UTC 2026-08-27T21:09:05.525563
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-81719 | 7.8 | 0.00% | 4 | 0 | 2026-08-27T20:18:54.400000 | openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insuffi | |
| CVE-2026-81717 | 3.5 | 0.00% | 2 | 0 | 2026-08-27T20:18:54.277000 | openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weakness | |
| CVE-2026-81714 | 7.0 | 0.00% | 2 | 0 | 2026-08-27T20:18:54.037000 | openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fin | |
| CVE-2026-81706 | 6.8 | 0.00% | 2 | 0 | 2026-08-27T20:18:53.920000 | openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own i | |
| CVE-2026-81701 | 9.8 | 0.00% | 4 | 0 | 2026-08-27T20:18:53.557000 | openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-i | |
| CVE-2026-81700 | 9.8 | 0.00% | 4 | 0 | 2026-08-27T20:18:53.437000 | openssl_encrypt versions before 1.4.9 contain a signature verification vulnerabi | |
| CVE-2026-81698 | 7.5 | 0.00% | 4 | 0 | 2026-08-27T20:18:53.300000 | openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in | |
| CVE-2026-81696 | 3.3 | 0.00% | 2 | 0 | 2026-08-27T20:18:53.170000 | openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characte | |
| CVE-2026-81695 | 3.3 | 0.00% | 2 | 0 | 2026-08-27T20:18:53.047000 | openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id | |
| CVE-2026-81685 | 3.3 | 0.00% | 2 | 0 | 2026-08-27T20:18:52.317000 | openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in | |
| CVE-2026-81681 | 4.6 | 0.00% | 4 | 0 | 2026-08-27T20:18:52.037000 | openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a port | |
| CVE-2026-81680 | 4.0 | 0.00% | 2 | 0 | 2026-08-27T20:18:51.890000 | openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presenc | |
| CVE-2026-81094 | 9.1 | 0.00% | 2 | 0 | 2026-08-27T20:18:49.427000 | The mcp-router CLI served its MCP aggregator on every interface and enforced aut | |
| CVE-2026-79619 | 0 | 0.14% | 2 | 0 | 2026-08-27T20:18:47.563000 | On Linux, several OpenZFS ioctl authorization checks accept a capability held on | |
| CVE-2026-66384 | 5.3 | 0.26% | 4 | 0 | 2026-08-27T20:18:28.153000 | An authenticated user may write data outside the intended Docker cache path unde | |
| CVE-2026-81705 | 7.5 | 0.00% | 2 | 0 | 2026-08-27T18:32:38 | openssl-encrypt before 1.4.9 fails to redact the file password in its --debug ar | |
| CVE-2026-81735 | 10.0 | 0.00% | 2 | 0 | 2026-08-27T18:32:38 | startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its l | |
| CVE-2026-81722 | 7.5 | 0.00% | 2 | 0 | 2026-08-27T18:32:31 | nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficie | |
| CVE-2026-81721 | 7.5 | 0.00% | 2 | 0 | 2026-08-27T18:32:31 | openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted | |
| CVE-2026-81718 | 7.5 | 0.00% | 2 | 0 | 2026-08-27T18:32:30 | openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 | |
| CVE-2026-47877 | 8.2 | 0.19% | 2 | 0 | 2026-08-27T18:32:09 | Spring Security Authorization Server's default consent page renders user-control | |
| CVE-2026-47852 | 7.5 | 0.20% | 2 | 0 | 2026-08-27T18:32:07 | A local attacker on a multi-user host can pre-create the deterministic cache pat | |
| CVE-2026-53362 | 7.8 | 0.27% | 4 | 1 | 2026-08-27T18:31:53 | In the Linux kernel, the following vulnerability has been resolved: ipv6: accou | |
| CVE-2026-81707 | 9.8 | 0.00% | 4 | 0 | 2026-08-27T17:21:01.440000 | openssl_encrypt before 1.4.9 fails to sanitize the email field of imported ident | |
| CVE-2026-81702 | 9.8 | 0.00% | 4 | 0 | 2026-08-27T17:21:00.680000 | openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when l | |
| CVE-2026-81699 | 7.5 | 0.00% | 2 | 0 | 2026-08-27T17:21:00.217000 | openssl_encrypt versions before 1.4.9 fail to properly validate key derivation f | |
| CVE-2026-81694 | 3.3 | 0.00% | 2 | 0 | 2026-08-27T17:20:59.447000 | openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames rea | |
| CVE-2026-81581 | 8.8 | 0.20% | 2 | 0 | 2026-08-27T17:20:55.490000 | Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 | |
| CVE-2026-81576 | 7.7 | 0.33% | 2 | 0 | 2026-08-27T17:20:55.230000 | If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issu | |
| CVE-2026-81575 | 7.5 | 0.44% | 2 | 0 | 2026-08-27T17:20:55.097000 | If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 acce | |
| CVE-2026-81572 | 7.8 | 0.17% | 3 | 0 | 2026-08-27T17:20:54.737000 | cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-S | |
| CVE-2026-81277 | 8.5 | 0.34% | 2 | 0 | 2026-08-27T17:20:53.450000 | Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 version | |
| CVE-2026-79938 | 7.6 | 0.22% | 2 | 0 | 2026-08-27T17:20:49.310000 | Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Au | |
| CVE-2026-79911 | 10.0 | 0.64% | 1 | 0 | 2026-08-27T17:20:49.160000 | A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210 | |
| CVE-2026-78288 | 9.3 | 0.38% | 1 | 0 | 2026-08-27T17:20:41.060000 | Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions. | |
| CVE-2026-78251 | 0 | 0.39% | 2 | 0 | 2026-08-27T17:20:37.750000 | DJI drones contain an FTP service that uses hardcoded credentials shared across | |
| CVE-2026-77652 | 7.8 | 0.15% | 3 | 0 | 2026-08-27T17:20:26.840000 | A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG | |
| CVE-2026-77368 | 7.6 | 0.21% | 2 | 0 | 2026-08-27T17:20:22.507000 | SeaweedFS is a distributed storage system for files and blobs. In version 4.39, | |
| CVE-2026-74232 | 9.8 | 0.00% | 4 | 0 | 2026-08-27T17:19:51.953000 | Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink | |
| CVE-2026-68863 | 7.5 | 0.28% | 2 | 0 | 2026-08-27T17:19:37.737000 | Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer | |
| CVE-2026-65641 | 0 | 0.54% | 3 | 0 | 2026-08-27T17:19:26.607000 | A vulnerability allowing an unauthenticated network attacker to coerce SMB authe | |
| CVE-2026-55228 | 8.1 | 0.23% | 2 | 0 | 2026-08-27T17:18:48.693000 | Weblate is a web-based continuous localization platform used to manage software | |
| CVE-2026-54511 | 8.6 | 0.31% | 2 | 0 | 2026-08-27T17:18:47.620000 | LogTape is an unobtrusive logging library. Prior to 1.3.11, 2.0.14, and 2.1.5, t | |
| CVE-2026-47879 | 7.7 | 0.24% | 2 | 0 | 2026-08-27T17:18:34.440000 | Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Reso | |
| CVE-2026-47851 | 7.5 | 0.26% | 2 | 1 | 2026-08-27T17:18:29.093000 | Analyzing a PDF with a deeply nested or cyclic table of contents can cause a Sta | |
| CVE-2026-47666 | 7.6 | 0.20% | 2 | 0 | 2026-08-27T17:18:27.247000 | Penpot is an open-source design and prototyping platform. In versions up to and | |
| CVE-2026-46369 | 7.5 | 0.39% | 2 | 0 | 2026-08-27T17:18:25.810000 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the | |
| CVE-2026-32257 | 8.1 | 0.21% | 2 | 0 | 2026-08-27T17:17:52.553000 | Winter is a free, open-source content management system (CMS) based on the Larav | |
| CVE-2026-41992 | 7.5 | 0.36% | 12 | 0 | 2026-08-27T15:32:31 | GNU gzip contains a global buffer overflow vulnerability in the LZH decompressio | |
| CVE-2026-74233 | 9.8 | 0.00% | 4 | 0 | 2026-08-27T15:31:35 | Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, an | |
| CVE-2026-68569 | 8.1 | 0.45% | 1 | 0 | 2026-08-27T14:27:23.650000 | Improper Authentication vulnerability in Apache Tomcat meant that in some circum | |
| CVE-2026-80587 | 9.8 | 0.36% | 4 | 0 | 2026-08-27T13:18:41.093000 | In the Linux kernel, the following vulnerability has been resolved: mptcp: avoi | |
| CVE-2026-80557 | 9.8 | 0.38% | 2 | 0 | 2026-08-27T13:18:40.360000 | In the Linux kernel, the following vulnerability has been resolved: libceph: fi | |
| CVE-2026-80551 | 9.3 | 0.14% | 2 | 0 | 2026-08-27T13:18:39.733000 | In the Linux kernel, the following vulnerability has been resolved: s390/vfio_c | |
| CVE-2026-52923 | 7.8 | 0.15% | 1 | 0 | 2026-08-27T13:18:21.880000 | In the Linux kernel, the following vulnerability has been resolved: ipc: limit | |
| CVE-2026-78293 | 7.1 | 0.24% | 1 | 0 | 2026-08-27T12:30:34 | Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions. | |
| CVE-2026-78276 | 7.2 | 0.50% | 2 | 0 | 2026-08-27T12:30:34 | Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions. | |
| CVE-2026-78285 | 8.5 | 0.34% | 2 | 0 | 2026-08-27T12:30:34 | Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions. | |
| CVE-2026-81625 | 8.8 | 0.53% | 2 | 0 | 2026-08-27T12:30:34 | A remote attacker with user privileges may use a malicious or compromised NASL v | |
| CVE-2026-81573 | 8.6 | 0.46% | 2 | 0 | 2026-08-27T12:30:27 | If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configu | |
| CVE-2026-81273 | 8.1 | 0.17% | 2 | 0 | 2026-08-27T12:30:27 | Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 | |
| CVE-2026-81579 | 8.8 | 0.16% | 2 | 0 | 2026-08-27T12:30:27 | In WibuKey for Windows before version 6.71, an untrusted pointer dereference in | |
| CVE-2026-81574 | 8.2 | 0.41% | 2 | 0 | 2026-08-27T12:30:27 | In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitiz | |
| CVE-2026-78286 | 9.8 | 0.53% | 3 | 0 | 2026-08-27T10:16:38.137000 | Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions. | |
| CVE-2026-66153 | 7.0 | 0.19% | 1 | 0 | 2026-08-27T06:32:29 | The NEService auto-upgrade process insecurely handles temporary files in SonicWa | |
| CVE-2026-59270 | 9.4 | 0.29% | 4 | 0 | 2026-08-27T06:31:43 | Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditio | |
| CVE-2026-80589 | 9.8 | 0.38% | 4 | 0 | 2026-08-27T06:31:38 | In the Linux kernel, the following vulnerability has been resolved: block: stop | |
| CVE-2026-80519 | 9.8 | 0.45% | 2 | 0 | 2026-08-27T06:31:38 | In the Linux kernel, the following vulnerability has been resolved: ovpn: finis | |
| CVE-2026-80585 | 9.4 | 0.32% | 2 | 0 | 2026-08-27T06:31:38 | In the Linux kernel, the following vulnerability has been resolved: mptcp: fast | |
| CVE-2026-80528 | 9.8 | 0.52% | 2 | 0 | 2026-08-27T06:31:38 | In the Linux kernel, the following vulnerability has been resolved: ceph: avoid | |
| CVE-2026-74737 | 9.8 | 0.56% | 2 | 0 | 2026-08-27T06:31:37 | In the Linux kernel, the following vulnerability has been resolved: net: ethern | |
| CVE-2026-74743 | 9.8 | 0.52% | 2 | 0 | 2026-08-27T06:31:37 | In the Linux kernel, the following vulnerability has been resolved: macvlan: in | |
| CVE-2026-80561 | 9.8 | 0.52% | 2 | 0 | 2026-08-27T06:31:33 | In the Linux kernel, the following vulnerability has been resolved: libceph: fi | |
| CVE-2026-80588 | 7.5 | 0.34% | 2 | 0 | 2026-08-27T06:31:33 | In the Linux kernel, the following vulnerability has been resolved: mptcp: recl | |
| CVE-2026-74752 | 9.8 | 0.43% | 2 | 0 | 2026-08-27T06:31:31 | In the Linux kernel, the following vulnerability has been resolved: sctp: valid | |
| CVE-2026-74751 | 9.4 | 0.34% | 2 | 0 | 2026-08-27T06:31:31 | In the Linux kernel, the following vulnerability has been resolved: riscv: lib: | |
| CVE-2026-80586 | 9.8 | 0.40% | 2 | 0 | 2026-08-27T06:17:45.700000 | In the Linux kernel, the following vulnerability has been resolved: mptcp: opti | |
| CVE-2026-80558 | 9.8 | 0.52% | 2 | 0 | 2026-08-27T06:17:39.903000 | In the Linux kernel, the following vulnerability has been resolved: libceph: Av | |
| CVE-2026-80554 | 9.3 | 0.14% | 2 | 0 | 2026-08-27T06:17:38.923000 | In the Linux kernel, the following vulnerability has been resolved: s390/vfio_c | |
| CVE-2026-74746 | 9.8 | 0.54% | 2 | 0 | 2026-08-27T06:17:25.033000 | In the Linux kernel, the following vulnerability has been resolved: netfilter: | |
| CVE-2026-74744 | 9.8 | 0.52% | 2 | 0 | 2026-08-27T06:17:24.440000 | In the Linux kernel, the following vulnerability has been resolved: ipvlan: inh | |
| CVE-2026-79282 | 9.6 | 0.35% | 1 | 0 | 2026-08-27T04:17:58.410000 | Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 al | |
| CVE-2026-77550 | 10.0 | 0.43% | 1 | 1 | 2026-08-27T04:16:50.850000 | A malicious actor with access to the network could exploit an Improper Neutraliz | |
| CVE-2026-66152 | 8.8 | 0.40% | 1 | 0 | 2026-08-27T04:16:45.137000 | A Path traversal vulnerability in OPSWAT tarball in the SonicWall NetExtender Li | |
| CVE-2026-18252 | 7.3 | 0.34% | 2 | 0 | 2026-08-27T04:16:41.857000 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 bef | |
| CVE-2022-0995 | 7.8 | 9.52% | 8 | 4 | 2026-08-27T04:16:39.223000 | An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_q | |
| CVE-2019-1068 | 8.8 | 52.84% | 5 | 2 | 2026-08-27T04:16:38.583000 | A remote code execution vulnerability exists in Microsoft SQL Server when it inc | |
| CVE-2026-68861 | 8.8 | 0.98% | 2 | 0 | 2026-08-26T21:31:52 | Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutrali | |
| CVE-2026-74770 | 8.8 | 1.06% | 2 | 0 | 2026-08-26T21:31:52 | Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutrali | |
| CVE-2026-70419 | 9.1 | 2.19% | 4 | 0 | 2026-08-26T21:31:47 | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutr | |
| CVE-2026-79074 | 5.3 | 0.26% | 1 | 0 | 2026-08-26T20:18:07.820000 | Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a re | |
| CVE-2026-65083 | 9.9 | 0.51% | 1 | 0 | 2026-08-26T20:17:56.810000 | NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning | |
| CVE-2026-65081 | 8.1 | 0.25% | 1 | 0 | 2026-08-26T20:17:56.587000 | NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, | |
| CVE-2026-58084 | 5.5 | 0.11% | 1 | 0 | 2026-08-26T20:17:55.417000 | To retrieve the previous timer value, the kernel calls realtimer_gettime(), whic | |
| CVE-2026-19632 | 9.8 | 0.79% | 1 | 2 | 2026-08-26T20:17:10.020000 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for | |
| CVE-2026-81029 | 8.1 | 0.30% | 2 | 0 | 2026-08-26T19:17:19.470000 | OpenMetadata accepts a caller-supplied post-authentication redirect target and a | |
| CVE-2026-76784 | None | 0.15% | 2 | 0 | 2026-08-26T18:32:06 | Multiple TP-Link Kasa smart home devices contain insufficient cryptographic prot | |
| CVE-2026-81027 | 8.5 | 0.29% | 2 | 0 | 2026-08-26T18:32:05 | one-api gates one of its two channel-pinning paths and not the other. middleware | |
| CVE-2026-80428 | 9.8 | 0.52% | 2 | 0 | 2026-08-26T18:32:05 | ILIAS deserialises stored session data for an unauthenticated caller. The Shibbo | |
| CVE-2026-81036 | 8.1 | 0.31% | 2 | 0 | 2026-08-26T18:32:05 | Stalwart Mail Server does not compare an OAuth redirect target against any regis | |
| CVE-2026-81035 | 8.1 | 0.28% | 2 | 0 | 2026-08-26T18:32:05 | Midday allows any member of a team to delete it. The delete procedure in apps/ap | |
| CVE-2026-15990 | 7.5 | 0.69% | 2 | 0 | 2026-08-26T18:32:04 | The Formidable Charts plugin for WordPress is vulnerable to Directory Traversal | |
| CVE-2026-19271 | 7.5 | 0.30% | 2 | 0 | 2026-08-26T18:32:04 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injecti | |
| CVE-2026-75960 | 8.1 | 0.35% | 3 | 0 | 2026-08-26T18:32:04 | Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently | |
| CVE-2026-58474 | 8.8 | 0.46% | 2 | 0 | 2026-08-26T18:32:04 | whichllm before 0.5.16 contains a code injection vulnerability in the run and sn | |
| CVE-2026-77533 | 9.9 | 1.01% | 1 | 0 | 2026-08-26T18:32:03 | A malicious actor with access to the network and low privileges could exploit an | |
| CVE-2026-18431 | 9.8 | 0.64% | 7 | 1 | 2026-08-26T18:32:03 | The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versi | |
| CVE-2026-58092 | 5.4 | 0.15% | 1 | 0 | 2026-08-26T18:32:01 | In FreeBSD 15.0, the kernel structure used to represent user credentials changed | |
| CVE-2026-58090 | 7.8 | 0.13% | 1 | 0 | 2026-08-26T18:31:55 | The SOCK_STREAM receive path in the unix socket implementation failed to fully d | |
| CVE-2026-65182 | 9.1 | 0.46% | 2 | 0 | 2026-08-26T18:31:49 | Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat | |
| CVE-2026-78899 | 8.8 | 0.43% | 1 | 0 | 2026-08-26T18:31:36 | Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote at | |
| CVE-2026-74932 | 7.5 | 0.22% | 1 | 0 | 2026-08-26T18:31:36 | The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host he | |
| CVE-2015-5287 | 7.8 | 4.96% | 6 | 1 | 2026-08-26T18:31:30 | The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2. | |
| CVE-2026-8452 | 9.8 | 1.61% | 11 | 3 | 2026-08-26T18:30:34 | Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unp | |
| CVE-2015-3246 | 5.1 | 8.80% | 6 | 1 | 2026-08-26T18:30:27 | libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper progr | |
| CVE-2026-81032 | 9.8 | 0.29% | 2 | 0 | 2026-08-26T18:17:05.890000 | NebulaGraph exposes its runtime configuration over an unauthenticated HTTP servi | |
| CVE-2026-79992 | 7.8 | 0.14% | 1 | 0 | 2026-08-26T18:17:04.953000 | A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerabili | |
| CVE-2026-75896 | 9.1 | 0.23% | 2 | 0 | 2026-08-26T18:17:01.010000 | Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technolog | |
| CVE-2026-54569 | 9.8 | 0.78% | 2 | 0 | 2026-08-26T18:16:40.930000 | SENAITE.CORE is the core framework for the SENAITE laboratory information manage | |
| CVE-2026-79784 | 8.8 | 0.32% | 1 | 0 | 2026-08-26T17:17:24.903000 | Vocos instantiates a class named by a configuration file without restricting whi | |
| CVE-2026-65092 | 8.5 | 0.45% | 1 | 0 | 2026-08-26T16:16:35.933000 | NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker co | |
| CVE-2026-65091 | 8.8 | 1.36% | 1 | 0 | 2026-08-26T16:16:35.810000 | NVIDIA OpenShell for all platforms contains a vulnerability where a malicious ga | |
| CVE-2026-65089 | 7.8 | 0.69% | 1 | 0 | 2026-08-26T16:16:35.687000 | NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin | |
| CVE-2026-55099 | 7.5 | 0.38% | 1 | 0 | 2026-08-26T16:16:28.197000 | icalendar is an RFC 5545 compatible parser and generator of iCalendar files for | |
| CVE-2026-80196 | 7.5 | 0.42% | 1 | 0 | 2026-08-26T15:17:03.720000 | Kimai before 2.58.0 contains an authentication bypass vulnerability where passwo | |
| CVE-2026-65099 | 7.8 | 0.69% | 1 | 0 | 2026-08-26T15:16:50.903000 | NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface | |
| CVE-2026-65098 | 8.1 | 0.57% | 1 | 0 | 2026-08-26T15:16:50.760000 | NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper w | |
| CVE-2026-54523 | 9.6 | 0.40% | 2 | 0 | 2026-08-26T14:21:54 | ## Summary In Kyverno v1.18.1, a tenant who can create a `NamespacedMutatingPol | |
| CVE-2026-73108 | 7.5 | 0.53% | 2 | 0 | 2026-08-26T14:17:12.830000 | RustDesk versions before 1.4.7 contain an uncontrolled speculative memory alloca | |
| CVE-2026-19042 | 8.8 | 2.00% | 2 | 0 | 2026-08-26T14:17:08.270000 | A command injection vulnerability in TeamViewer Full Client and Host for Linux p | |
| CVE-2026-80138 | 9.8 | 0.80% | 1 | 0 | 2026-08-26T13:19:24.307000 | ClipBucket V5's web installer fails to properly validate or escape the php_cli_f | |
| CVE-2026-77554 | 10.0 | 0.99% | 1 | 1 | 2026-08-26T13:19:21.823000 | A malicious actor with access to the network could exploit an Improper Input Val | |
| CVE-2026-54757 | 7.8 | 0.25% | 1 | 0 | 2026-08-26T13:19:16.497000 | Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing | |
| CVE-2026-79912 | 8.3 | 1.40% | 1 | 0 | 2026-08-26T00:31:14 | A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impac | |
| CVE-2026-80186 | 7.6 | 0.41% | 1 | 0 | 2026-08-26T00:31:09 | A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth | |
| CVE-2026-65105 | 8.1 | 0.30% | 1 | 0 | 2026-08-25T21:31:40 | NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup | |
| CVE-2026-65084 | 8.1 | 0.32% | 1 | 0 | 2026-08-25T21:31:36 | NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, wh | |
| CVE-2026-65093 | 9.9 | 0.49% | 2 | 0 | 2026-08-25T21:31:36 | NVIDIA OpenShell for Linux contains a vulnerability where an attacker could caus | |
| CVE-2026-65090 | 7.8 | 0.69% | 1 | 0 | 2026-08-25T21:31:35 | NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management compone | |
| CVE-2026-65096 | 7.8 | 0.69% | 1 | 0 | 2026-08-25T21:31:35 | NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge compon | |
| CVE-2026-80049 | 8.8 | 0.34% | 2 | 0 | 2026-08-25T21:31:34 | Airbyte Platform resolves the workspace used for its authorization decision from | |
| CVE-2026-65097 | 7.5 | 0.20% | 1 | 0 | 2026-08-25T21:31:34 | NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, | |
| CVE-2026-80104 | 9.8 | 0.71% | 1 | 0 | 2026-08-25T21:18:24.163000 | DB-GPT builds the destination path for an uploaded skill from the multipart file | |
| CVE-2026-45018 | 9.8 | 0.65% | 2 | 0 | 2026-08-25T20:16:55.720000 | Chainlit is a Python framework for building production-ready conversational AI a | |
| CVE-2026-75768 | 7.8 | 0.17% | 1 | 0 | 2026-08-25T18:32:08 | Substance3D - Painter is affected by an Untrusted Search Path vulnerability that | |
| CVE-2026-19913 | None | 0.36% | 3 | 1 | 2026-08-25T18:32:01 | The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure v | |
| CVE-2026-76197 | 10.0 | 1.47% | 3 | 0 | 2026-08-25T18:32:01 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia | |
| CVE-2026-79774 | 8.4 | 0.43% | 1 | 0 | 2026-08-25T18:32:00 | Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox e | |
| CVE-2026-79675 | 9.8 | 0.40% | 1 | 0 | 2026-08-25T18:31:56 | NLTK before 3.10.3 fails to validate JVM options passed through the per-call opt | |
| CVE-2026-19912 | 0 | 0.22% | 3 | 1 | 2026-08-25T17:17:07.263000 | The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote | |
| CVE-2026-67578 | 7.5 | 0.30% | 1 | 0 | 2026-08-25T15:16:37.230000 | FA-50 all versions miss authentication for some configuration. An attacker with | |
| CVE-2026-59769 | 9.1 | 0.33% | 1 | 0 | 2026-08-25T15:16:35.427000 | FA-50 all versions contain hard-coded credentials. An attacker, who knows the c | |
| CVE-2026-57863 | 8.8 | 0.57% | 1 | 0 | 2026-08-25T15:16:35.297000 | Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self | |
| CVE-2026-18798 | 7.5 | 1.48% | 1 | 0 | 2026-08-25T15:16:31.207000 | Issue summary: QUIC server may double free QRX (QUIC record layer RX) object whe | |
| CVE-2026-78570 | 9.8 | 0.40% | 1 | 0 | 2026-08-25T12:31:29 | The Total Donations plugin for WordPress is vulnerable to Privilege Escalation i | |
| CVE-2026-57909 | None | 0.29% | 2 | 0 | 2026-08-25T12:31:24 | A path traversal vulnerability in WatchGuard Agent allows a remote, unauthentica | |
| CVE-2026-57910 | None | 0.20% | 2 | 0 | 2026-08-25T12:31:24 | Improper authentication in the WatchGuard Agent allows an unauthenticated attack | |
| CVE-2026-77136 | None | 0.55% | 1 | 0 | 2026-08-25T09:30:47 | The extension passes the raw value of a form field configured as "This field con | |
| CVE-2026-78676 | 9.8 | 0.40% | 1 | 0 | 2026-08-25T03:32:20 | GitPython before 3.1.59 fails to safely re-serialize multi-line git-config value | |
| CVE-2026-21962 | 10.0 | 42.02% | 4 | 10 | 2026-08-24T21:33:31 | Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in pr | |
| CVE-2026-19874 | 9.1 | 0.73% | 1 | 1 | 2026-08-24T20:16:42.277000 | A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online | |
| CVE-2026-59568 | 9.1 | 0.38% | 1 | 0 | 2026-08-24T15:31:57 | Multiple vulnerabilities on affected versions of Zscaler Client Connector allow | |
| CVE-2026-73570 | 8.9 | 20.53% | 4 | 4 | template | 2026-08-24T13:19:17.577000 | A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) befor |
| CVE-2026-27875 | 0 | 0.07% | 1 | 0 | 2026-08-21T21:16:56.500000 | Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Co | |
| CVE-2026-77413 | None | 0.41% | 1 | 0 | 2026-08-21T20:57:09 | ## Impact Before JSONata `2.2.0` and `1.8.8` it was possible to execute arbitra | |
| CVE-2026-69836 | 10.0 | 1.55% | 5 | 2 | 2026-08-21T00:31:31 | Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized a | |
| CVE-2026-18963 | 9.1 | 2.79% | 2 | 10 | template | 2026-08-20T14:17:10.413000 | A flaw was found in the reset-credentials flow of the keycloak-services componen |
| CVE-2026-19598 | 9.8 | 2.46% | 2 | 4 | template | 2026-08-20T12:48:10.287000 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to |
| CVE-2026-69414 | 7.8 | 0.56% | 2 | 2 | 2026-08-19T18:32:28 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect | |
| CVE-2026-53361 | 7.1 | 0.13% | 2 | 1 | 2026-08-19T18:31:59 | In the Linux kernel, the following vulnerability has been resolved: af_unix: Se | |
| CVE-2026-58083 | 8.4 | 0.12% | 1 | 0 | 2026-08-19T12:33:28 | While the kernel was copying knotes during fork, a knote with a timer-based filt | |
| CVE-2026-65400 | 9.8 | 9.90% | 1 | 3 | 2026-08-19T04:17:34.547000 | An authentication issue was addressed with improved state management. This issue | |
| CVE-2026-55040 | 9.1 | 39.65% | 3 | 5 | template | 2026-08-19T04:17:23.540000 | Weak authentication in Microsoft Office SharePoint allows an unauthorized attack |
| CVE-2026-19478 | 9.4 | 6.00% | 2 | 7 | template | 2026-08-17T21:31:30 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 |
| CVE-2026-72137 | 9.8 | 0.62% | 6 | 0 | 2026-08-17T06:34:17 | In the Linux kernel, the following vulnerability has been resolved: xfrm: nat_k | |
| CVE-2026-62911 | 8.0 | 0.95% | 2 | 1 | 2026-08-13T18:57:39.290000 | Authentication bypass by capture-replay in Microsoft Exchange Server allows an a | |
| CVE-2026-63520 | 8.1 | 2.89% | 3 | 2 | 2026-08-13T13:38:30.453000 | Improper input validation in Microsoft Office SharePoint allows an unauthorized | |
| CVE-2026-50656 | 7.8 | 11.36% | 1 | 4 | 2026-08-12T18:31:00 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect | |
| CVE-2026-32258 | 8.1 | 0.21% | 2 | 0 | 2026-08-12T14:40:39 | ### Impact | |
| CVE-2025-8088 | 8.8 | 94.55% | 1 | 31 | 2026-08-11T04:17:18.587000 | A path traversal vulnerability affecting the Windows version of WinRAR allows th | |
| CVE-2026-48710 | 6.5 | 1.91% | 1 | 5 | template | 2026-08-07T12:31:53 | ### Summary In affected versions, the HTTP `Host` request header was not validat |
| CVE-2026-63077 | 9.8 | 84.73% | 3 | 4 | template | 2026-08-05T18:32:31 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe |
| CVE-2026-18733 | 8.8 | 0.32% | 1 | 0 | 2026-08-04T20:16:50.970000 | A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tool | |
| CVE-2026-8508 | 6.5 | 0.70% | 1 | 1 | 2026-08-04T03:31:16 | An improper authentication vulnerability in the "social_login.cgi" CGI program i | |
| CVE-2026-15903 | 8.8 | 0.57% | 1 | 0 | 2026-07-24T15:33:44 | Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allo | |
| CVE-2026-36425 | 6.5 | 0.42% | 1 | 2 | 2026-07-17T18:47:13.683000 | An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in | |
| CVE-2026-15776 | 8.8 | 0.45% | 1 | 0 | 2026-07-15T17:39:16.157000 | Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allo | |
| CVE-2026-42271 | 8.8 | 83.54% | 1 | 2 | template | 2026-07-15T02:21:30.727000 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) fo |
| CVE-2026-56164 | 5.3 | 26.64% | 1 | 3 | 2026-07-14T21:32:51 | Missing authentication for critical function in Microsoft Office SharePoint allo | |
| CVE-2025-15467 | 9.8 | 48.21% | 1 | 6 | 2026-07-14T15:32:45 | Issue summary: Parsing CMS AuthEnvelopedData message with maliciously crafted AE | |
| CVE-2025-69419 | 7.4 | 0.56% | 1 | 1 | 2026-06-17T10:00:39.850000 | Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously craft | |
| CVE-2025-58187 | 7.5 | 0.38% | 1 | 0 | 2026-06-17T09:44:02.120000 | Due to the design of the name constraint checking algorithm, the processing time | |
| CVE-2024-38112 | 7.5 | 84.23% | 1 | 1 | 2026-06-17T07:39:26.777000 | Windows MSHTML Platform Spoofing Vulnerability | |
| CVE-2023-21931 | 7.5 | 82.26% | 2 | 2 | 2026-06-17T05:34:22.130000 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware | |
| CVE-2026-28389 | 7.5 | 0.80% | 2 | 0 | 2026-05-12T15:31:15 | Issue summary: During processing of a crafted CMS EnvelopedData message with Key | |
| CVE-2021-23758 | 9.8 | 83.63% | 8 | 1 | 2026-02-03T17:39:26 | ### Overview Affected versions of this package are vulnerable to Deserializatio | |
| CVE-2026-0915 | 7.5 | 0.57% | 1 | 1 | 2026-01-20T18:31:56 | Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that spec | |
| CVE-2025-55241 | 9.0 | 1.55% | 1 | 0 | 2025-09-18T15:31:27 | Azure Entra Elevation of Privilege Vulnerability | |
| CVE-2025-39367 | 5.3 | 0.27% | 2 | 0 | 2025-04-28T09:32:00 | Missing Authorization vulnerability in SeventhQueen Kleo.This issue affects Kleo | |
| CVE-2023-49105 | 9.8 | 11.07% | 4 | 1 | template | 2025-04-02T15:31:49 | An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker ca |
| CVE-2026-75604 | 0 | 0.00% | 6 | 3 | N/A | ||
| CVE-2026-66155 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-47665 | 0 | 0.25% | 3 | 0 | N/A | ||
| CVE-2026-68503 | 0 | 0.40% | 2 | 0 | N/A | ||
| CVE-2026-77537 | 0 | 0.94% | 2 | 0 | N/A | ||
| CVE-2026-60004 | 0 | 82.40% | 19 | 9 | template | N/A | |
| CVE-2026-61617 | 0 | 0.25% | 2 | 0 | N/A | ||
| CVE-2026-77317 | 0 | 0.22% | 2 | 0 | N/A | ||
| CVE-2026-80427 | 0 | 0.15% | 2 | 0 | N/A | ||
| CVE-2026-61792 | 0 | 0.32% | 2 | 0 | N/A | ||
| CVE-2026-77532 | 0 | 0.27% | 2 | 0 | N/A | ||
| CVE-2026-78379 | 0 | 0.32% | 2 | 0 | N/A | ||
| CVE-2026-58093 | 0 | 0.09% | 1 | 0 | N/A | ||
| CVE-2026-23479 | 0 | 1.36% | 1 | 5 | N/A | ||
| CVE-2026-18965 | 0 | 0.00% | 1 | 0 | N/A |
updated 2026-08-27T20:18:54.400000
4 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
🟠 CVE-2026-81719 - High (7.8)
openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to WARN, so an unsigned/unverifiable non-built-in plugin was compiled and executed in the host process at import ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81719/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
🟠 CVE-2026-81719 - High (7.8)
openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to WARN, so an unsigned/unverifiable non-built-in plugin was compiled and executed in the host process at import ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81719/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T20:18:54.277000
2 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T20:18:54.037000
2 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T20:18:53.920000
2 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T20:18:53.557000
4 posts
🔴 CVE-2026-81701 - Critical (9.8)
openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature verification. Attackers can place malicious unsig...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81701/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
🔴 CVE-2026-81701 - Critical (9.8)
openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature verification. Attackers can place malicious unsig...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81701/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T20:18:53.437000
4 posts
🔴 CVE-2026-81700 - Critical (9.8)
openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspecting REVKEYSIG, EXPKEYSIG, or gpg exit codes. A...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81700/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
🔴 CVE-2026-81700 - Critical (9.8)
openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspecting REVKEYSIG, EXPKEYSIG, or gpg exit codes. A...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81700/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T20:18:53.300000
4 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
🟠 CVE-2026-81698 - High (7.5)
openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that interpolates untrusted metadata fields without quoting. Attackers can craft metadata values like pepper_name containin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81698/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
🟠 CVE-2026-81698 - High (7.5)
openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that interpolates untrusted metadata fields without quoting. Attackers can craft metadata values like pepper_name containin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81698/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T20:18:53.170000
2 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T20:18:53.047000
2 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T20:18:52.317000
2 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T20:18:52.037000
4 posts
@cR0w I was literally just looking at them & I have no idea what it is but some of them are bonkers: https://db.gcve.eu/vuln/cve-2026-81681
##How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
@cR0w I was literally just looking at them & I have no idea what it is but some of them are bonkers: https://db.gcve.eu/vuln/cve-2026-81681
##How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T20:18:51.890000
2 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T20:18:49.427000
2 posts
Go hack more MCP shit.
https://nvd.nist.gov/vuln/detail/cve-2026-81094
##The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it. The serve command in apps/cli/src/commands/serve.ts defaulted its host to the all-interfaces address on a fixed port, and required a token only when the corresponding flag was supplied, so a default invocation exposed the aggregator, and every MCP server it fronted, to anyone able to reach the port. Release 0.6.3 defaults the host to the loopback address and refuses to start without a token whenever the host it is given is not a loopback address; no earlier release carries either check.
Go hack more MCP shit.
https://nvd.nist.gov/vuln/detail/cve-2026-81094
##The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it. The serve command in apps/cli/src/commands/serve.ts defaulted its host to the all-interfaces address on a fixed port, and required a token only when the corresponding flag was supplied, so a default invocation exposed the aggregator, and every MCP server it fronted, to anyone able to reach the port. Release 0.6.3 defaults the host to the loopback address and refuses to start without a token whenever the host it is given is not a loopback address; no earlier release carries either check.
updated 2026-08-27T20:18:47.563000
2 posts
#OpenZFS security advisory. If you're using OpenZFS on Linux, and you have unprivileged users or containers on the system, you should upgrade to the latest releases ASAP.
https://github.com/openzfs/zfs/security/advisories/GHSA-mhf5-q8gw-qg9v
https://www.cve.org/CVERecord?id=CVE-2026-79619
#OpenZFS security advisory. If you're using OpenZFS on Linux, and you have unprivileged users or containers on the system, you should upgrade to the latest releases ASAP.
https://github.com/openzfs/zfs/security/advisories/GHSA-mhf5-q8gw-qg9v
https://www.cve.org/CVERecord?id=CVE-2026-79619
updated 2026-08-27T20:18:28.153000
4 posts
🚨 [CISA-2026:0827] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2023-49105 (https://secdb.nttzen.cloud/cve/detail/CVE-2023-49105)
- Name: ownCloud Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ownCloud
- Product: ownCloud
- Notes: https://owncloud.org/security ; https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2023-49105
⚠️ CVE-2026-53362 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-53362)
- Name: Linux Kernel Unspecified Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/14200d435af9a9eeb444f529fc2f689a236b7962; https://git.kernel.org/stable/c/65fb14cbebb0cd0eff903a22d33537ddc8b95769; https://git.kernel.org/stable/c/46f201f8b4c39633a1fa3dc12459f506d470993d; https://git.kernel.org/stable/c/6374fb9edf72c67a118a2c214a0dddd04c921e0a; https://git.kernel.org/stable/c/e9eacf19281ea2498b36291b56c9606118c2d74e; https://git.kernel.org/stable/c/736b380e28d0480c7bc3e022f1950f31fe53a7c5 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53362
⚠️ CVE-2026-66384 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66384)
- Name: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-66384
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260827 #cisa20260827 #cve_2023_49105 #cve_2026_53362 #cve_2026_66384 #cve202349105 #cve202653362 #cve202666384
##CVE ID: CVE-2026-66384
Vendor: JFrog
Product: Artifactory
Date Added: 2026-08-27
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-66384
🚨 [CISA-2026:0827] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2023-49105 (https://secdb.nttzen.cloud/cve/detail/CVE-2023-49105)
- Name: ownCloud Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ownCloud
- Product: ownCloud
- Notes: https://owncloud.org/security ; https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2023-49105
⚠️ CVE-2026-53362 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-53362)
- Name: Linux Kernel Unspecified Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/14200d435af9a9eeb444f529fc2f689a236b7962; https://git.kernel.org/stable/c/65fb14cbebb0cd0eff903a22d33537ddc8b95769; https://git.kernel.org/stable/c/46f201f8b4c39633a1fa3dc12459f506d470993d; https://git.kernel.org/stable/c/6374fb9edf72c67a118a2c214a0dddd04c921e0a; https://git.kernel.org/stable/c/e9eacf19281ea2498b36291b56c9606118c2d74e; https://git.kernel.org/stable/c/736b380e28d0480c7bc3e022f1950f31fe53a7c5 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53362
⚠️ CVE-2026-66384 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66384)
- Name: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-66384
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260827 #cisa20260827 #cve_2023_49105 #cve_2026_53362 #cve_2026_66384 #cve202349105 #cve202653362 #cve202666384
##CVE ID: CVE-2026-66384
Vendor: JFrog
Product: Artifactory
Date Added: 2026-08-27
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-66384
updated 2026-08-27T18:32:38
2 posts
🟠 CVE-2026-81705 - High (7.5)
openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied via bundled short-option spellings (e.g. -apHunter2) or abbreviated long-option spellings (e.g. --passw). The sanitizer only reco...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81705/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81705 - High (7.5)
openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied via bundled short-option spellings (e.g. -apHunter2) or abbreviated long-option spellings (e.g. --passw). The sanitizer only reco...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81705/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T18:32:38
2 posts
🔴 CVE-2026-81735 - Critical (10)
startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and SSE MCP transports to every interface, and its authen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81735/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-81735 - Critical (10)
startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and SSE MCP transports to every interface, and its authen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81735/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T18:32:31
2 posts
🟠 CVE-2026-81722 - High (7.5)
nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service in PorterStemmer.stem(). The _is_consonant() helper walks backward over the entire run of trailing 'y' charact...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81722/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81722 - High (7.5)
nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service in PorterStemmer.stem(). The _is_consonant() helper walks backward over the entire run of trailing 'y' charact...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81722/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T18:32:31
2 posts
🟠 CVE-2026-81721 - High (7.5)
openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to trigger unbounded memory allocation. Attackers can craft malicious encrypted files declaring arbitrarily larg...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81721/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81721 - High (7.5)
openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to trigger unbounded memory allocation. Attackers can craft malicious encrypted files declaring arbitrarily larg...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81721/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T18:32:30
2 posts
🟠 CVE-2026-81718 - High (7.5)
openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 with only 100,000 iterations to protect PQC keyfile private keys and 10,000 iterations for dual-encryption file-password verification. Attackers who obtain keyfiles o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81718/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81718 - High (7.5)
openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 with only 100,000 iterations to protect PQC keyfile private keys and 10,000 iterations for dual-encryption file-password verification. Attackers who obtain keyfiles o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81718/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T18:32:09
2 posts
🟠 CVE-2026-47877 - High (8.2)
Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding.
Spring Security 7.1.0
Spring Security 7.0.0 - 7.0.6
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47877/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-47877 - High (8.2)
Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding.
Spring Security 7.1.0
Spring Security 7.0.0 - 7.0.6
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47877/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T18:32:07
2 posts
🟠 CVE-2026-47852 - High (7.5)
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file.
Spring AI 2.0.0
Spring AI 1.1.0 - 1.1.8
Spring AI 1.0.0 - 1.0.9
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47852/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-47852 - High (7.5)
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file.
Spring AI 2.0.0
Spring AI 1.1.0 - 1.1.8
Spring AI 1.0.0 - 1.0.9
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47852/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T18:31:53
4 posts
1 repos
🚨 [CISA-2026:0827] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2023-49105 (https://secdb.nttzen.cloud/cve/detail/CVE-2023-49105)
- Name: ownCloud Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ownCloud
- Product: ownCloud
- Notes: https://owncloud.org/security ; https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2023-49105
⚠️ CVE-2026-53362 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-53362)
- Name: Linux Kernel Unspecified Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/14200d435af9a9eeb444f529fc2f689a236b7962; https://git.kernel.org/stable/c/65fb14cbebb0cd0eff903a22d33537ddc8b95769; https://git.kernel.org/stable/c/46f201f8b4c39633a1fa3dc12459f506d470993d; https://git.kernel.org/stable/c/6374fb9edf72c67a118a2c214a0dddd04c921e0a; https://git.kernel.org/stable/c/e9eacf19281ea2498b36291b56c9606118c2d74e; https://git.kernel.org/stable/c/736b380e28d0480c7bc3e022f1950f31fe53a7c5 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53362
⚠️ CVE-2026-66384 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66384)
- Name: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-66384
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260827 #cisa20260827 #cve_2023_49105 #cve_2026_53362 #cve_2026_66384 #cve202349105 #cve202653362 #cve202666384
##CVE ID: CVE-2026-53362
Vendor: Linux
Product: Kernel
Date Added: 2026-08-27
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-53362
🚨 [CISA-2026:0827] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2023-49105 (https://secdb.nttzen.cloud/cve/detail/CVE-2023-49105)
- Name: ownCloud Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ownCloud
- Product: ownCloud
- Notes: https://owncloud.org/security ; https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2023-49105
⚠️ CVE-2026-53362 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-53362)
- Name: Linux Kernel Unspecified Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/14200d435af9a9eeb444f529fc2f689a236b7962; https://git.kernel.org/stable/c/65fb14cbebb0cd0eff903a22d33537ddc8b95769; https://git.kernel.org/stable/c/46f201f8b4c39633a1fa3dc12459f506d470993d; https://git.kernel.org/stable/c/6374fb9edf72c67a118a2c214a0dddd04c921e0a; https://git.kernel.org/stable/c/e9eacf19281ea2498b36291b56c9606118c2d74e; https://git.kernel.org/stable/c/736b380e28d0480c7bc3e022f1950f31fe53a7c5 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53362
⚠️ CVE-2026-66384 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66384)
- Name: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-66384
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260827 #cisa20260827 #cve_2023_49105 #cve_2026_53362 #cve_2026_66384 #cve202349105 #cve202653362 #cve202666384
##CVE ID: CVE-2026-53362
Vendor: Linux
Product: Kernel
Date Added: 2026-08-27
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-53362
updated 2026-08-27T17:21:01.440000
4 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
🔴 CVE-2026-81707 - Critical (9.8)
openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification line displayed to users. Attackers can deliver a crafted iden...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81707/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
🔴 CVE-2026-81707 - Critical (9.8)
openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification line displayed to users. Attackers can deliver a crafted iden...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81707/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T17:21:00.680000
4 posts
🔴 CVE-2026-81702 - Critical (9.8)
openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate public keys with their own whil...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81702/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
🔴 CVE-2026-81702 - Critical (9.8)
openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate public keys with their own whil...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81702/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T17:21:00.217000
2 posts
🟠 CVE-2026-81699 - High (7.5)
openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to trigger unbounded memory and CPU exhaustion during pre-authentication processing. Attackers can supply malicious ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81699/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81699 - High (7.5)
openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to trigger unbounded memory and CPU exhaustion during pre-authentication processing. Attackers can supply malicious ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81699/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T17:20:59.447000
2 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T17:20:55.490000
2 posts
🟠 CVE-2026-81581 - High (8.8)
Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an attacker by setting the pointers outside the scope of the program. This usually results in a denial of service, yet we cannot rule o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81581/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81581 - High (8.8)
Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an attacker by setting the pointers outside the scope of the program. This usually results in a denial of service, yet we cannot rule o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81581/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T17:20:55.230000
2 posts
🟠 CVE-2026-81576 - High (7.7)
If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak
SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle numbe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81576/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81576 - High (7.7)
If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak
SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle numbe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81576/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T17:20:55.097000
2 posts
🟠 CVE-2026-81575 - High (7.5)
If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and
the data itself. Missing bounds checking on the data length value can lead to out of bounds reads, cau...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81575/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81575 - High (7.5)
If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and
the data itself. Missing bounds checking on the data length value can lead to out of bounds reads, cau...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81575/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T17:20:54.737000
3 posts
CVE-2026-81572 - LPE in CodeMeter Runtime allows arbitrary file deletion with SYSTEM privileges via NTFS reparse points. CVSS 7.8. Audit hosts now. #CVE #infosec #cybersecurity
##🟠 CVE-2026-81572 - High (7.8)
cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and
file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file
operations are performed. A local...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81572/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81572 - High (7.8)
cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and
file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file
operations are performed. A local...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81572/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T17:20:53.450000
2 posts
🟠 CVE-2026-81277 - High (8.5)
Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81277/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81277 - High (8.5)
Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81277/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T17:20:49.310000
2 posts
🟠 CVE-2026-79938 - High (7.6)
Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79938/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-79938 - High (7.6)
Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79938/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T17:20:49.160000
1 posts
🔴 CVE-2026-79911 - Critical (10)
A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname lea...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79911/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T17:20:41.060000
1 posts
CVE-2026-78288 - Critical Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6. CVSS 9.3. Currently unpatched. Mitigate immediately! #CVE #WordPress #infosec
##updated 2026-08-27T17:20:37.750000
2 posts
Go hack more drone shit.
https://nvd.nist.gov/vuln/detail/cve-2026-78251
##DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticated users to upload files without limits on file size, file count, or total storage consumed in /blackbox/upgrade/, as well as overwrite existing files in that directory. An attacker with access to the drone's internal network or USB RNDIS interface can exhaust the available storage, preventing the aircraft from writing flight records, logs, and telemetry and potentially preventing subsequent firmware updates. Uploaded files persist across reboot and factory reset. Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600. Remediation requires a firmware update from the vendor.
Go hack more drone shit.
https://nvd.nist.gov/vuln/detail/cve-2026-78251
##DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticated users to upload files without limits on file size, file count, or total storage consumed in /blackbox/upgrade/, as well as overwrite existing files in that directory. An attacker with access to the drone's internal network or USB RNDIS interface can exhaust the available storage, preventing the aircraft from writing flight records, logs, and telemetry and potentially preventing subsequent firmware updates. Uploaded files persist across reboot and factory reset. Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600. Remediation requires a firmware update from the vendor.
updated 2026-08-27T17:20:26.840000
3 posts
CVE-2026-77652 - Heap Buffer Overflow in Dia diagram editor WPG file parser. CVSS 7.8. Currently unpatched. Restrict untrusted WPG files now. #CVE #infosec #cybersecurity
##🟠 CVE-2026-77652 - High (7.8)
A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer.
In plug-ins/wpg/wpg-import.c, the WPG import renderer allocates a fixed palette with:
ren->pPal = g_new0(WPGColorRGB, 256);
When handling ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77652/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-77652 - High (7.8)
A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer.
In plug-ins/wpg/wpg-import.c, the WPG import renderer allocates a fixed palette with:
ren->pPal = g_new0(WPGColorRGB, 256);
When handling ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77652/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T17:20:22.507000
2 posts
🟠 CVE-2026-77368 - High (7.6)
SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler checks JWT allowed_prefixes scoping only when a session is created, letting a low-privilege tenant hijack another tenant's upl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77368/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-77368 - High (7.6)
SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler checks JWT allowed_prefixes scoping only when a session is created, letting a low-privilege tenant hijack another tenant's upl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77368/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T17:19:51.953000
4 posts
🔴 CVE-2026-74232 - Critical (9.8)
Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, A...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74232/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Fucking LMAO
https://nvd.nist.gov/vuln/detail/cve-2026-74232
##Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522 firmware 1.0.0.2.014, AP7628 and HC5661A firmware 3.0.0.4.380, APG721B firmware 19.0809, HK300 firmware 1.0.0.2.032, and MAP-N10 firmware 1.0.0.2.044 ship a backdoor command-and-control implant (yunmgrd) reachable over an unauthenticated cleartext UDP channel to a hardcoded C2 server. A remote unauthenticated attacker on the network path can hijack the channel and execute arbitrary commands as root. The attacker can also modify DNS entries, exfiltrate PPPoE credentials, and open reverse SSH tunnels.
🔴 CVE-2026-74232 - Critical (9.8)
Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, A...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74232/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Fucking LMAO
https://nvd.nist.gov/vuln/detail/cve-2026-74232
##Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522 firmware 1.0.0.2.014, AP7628 and HC5661A firmware 3.0.0.4.380, APG721B firmware 19.0809, HK300 firmware 1.0.0.2.032, and MAP-N10 firmware 1.0.0.2.044 ship a backdoor command-and-control implant (yunmgrd) reachable over an unauthenticated cleartext UDP channel to a hardcoded C2 server. A remote unauthenticated attacker on the network path can hijack the channel and execute arbitrary commands as root. The attacker can also modify DNS entries, exfiltrate PPPoE credentials, and open reverse SSH tunnels.
updated 2026-08-27T17:19:37.737000
2 posts
🟠 CVE-2026-68863 - High (7.5)
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68863/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-68863 - High (7.5)
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68863/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T17:19:26.607000
3 posts
Veeam Patches Critical Authentication Coercion Flaw in Veeam ONE
Veeam released patches for a critical vulnerability (CVE-2026-65641) in Veeam ONE that allows unauthenticated attackers to steal service account NTLM credentials via SMB coercion. The flaw affects version 13 builds and could lead to unauthorized access to backup infrastructure.
**If you're running Veeam ONE version 13.1.0.7034 or any earlier version 13 build, update ASAP to 13.1.0.7233 or 13.0.2.7159. This flaw lets attackers steal your service account credentials without logging in. After updating, review your network logs for any unusual SMB traffic coming from your Veeam servers, as this could indicate the flaw was already exploited.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/veeam-patches-critical-authentication-coercion-flaw-in-veeam-one-6-l-e-u-t/gD2P6Ple2L
Veeam Patches Critical Authentication Coercion Flaw in Veeam ONE
Veeam released patches for a critical vulnerability (CVE-2026-65641) in Veeam ONE that allows unauthenticated attackers to steal service account NTLM credentials via SMB coercion. The flaw affects version 13 builds and could lead to unauthorized access to backup infrastructure.
**If you're running Veeam ONE version 13.1.0.7034 or any earlier version 13 build, update ASAP to 13.1.0.7233 or 13.0.2.7159. This flaw lets attackers steal your service account credentials without logging in. After updating, review your network logs for any unusual SMB traffic coming from your Veeam servers, as this could indicate the flaw was already exploited.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/veeam-patches-critical-authentication-coercion-flaw-in-veeam-one-6-l-e-u-t/gD2P6Ple2L
A critical Veeam ONE vulnerability (CVE-2026-65641, CVSS 9.3) lets an unauthenticated attacker coerce SMB authentication. Patch Veeam now.
##updated 2026-08-27T17:18:48.693000
2 posts
🟠 CVE-2026-55228 - High (8.1)
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce the scope of project- and workspace-scoped teams, allowing a user to submit invalid te...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55228/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-55228 - High (8.1)
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce the scope of project- and workspace-scoped teams, allowing a user to submit invalid te...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55228/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T17:18:47.620000
2 posts
🟠 CVE-2026-54511 - High (8.6)
LogTape is an unobtrusive logging library. Prior to 1.3.11, 2.0.14, and 2.1.5, the @logtape/syslog package's escapeStructuredDataValue() function in packages/syslog/src/syslog.ts does not neutralize C0 control characters from U+0000 through U+001F...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54511/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-54511 - High (8.6)
LogTape is an unobtrusive logging library. Prior to 1.3.11, 2.0.14, and 2.1.5, the @logtape/syslog package's escapeStructuredDataValue() function in packages/syslog/src/syslog.ts does not neutralize C0 control characters from U+0000 through U+001F...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54511/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T17:18:34.440000
2 posts
🟠 CVE-2026-47879 - High (7.7)
Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor.
Spring Cloud Gateway 5.0.0 - 5.0.2
Spring Cloud Gateway 4.3.0 - 4.3.5
Spring Cloud Gateway 4.0.0 - 4.2.9
Spring Cloud...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47879/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-47879 - High (7.7)
Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor.
Spring Cloud Gateway 5.0.0 - 5.0.2
Spring Cloud Gateway 4.3.0 - 4.3.5
Spring Cloud Gateway 4.0.0 - 4.2.9
Spring Cloud...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47879/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T17:18:29.093000
2 posts
1 repos
🟠 CVE-2026-47851 - High (7.5)
Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread.
Spring AI 2.0.0
Spring AI 1.1.0 - 1.1.8
Spring AI 1.0.0 - 1.0.9
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47851/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-47851 - High (7.5)
Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread.
Spring AI 2.0.0
Spring AI 1.1.0 - 1.1.8
Spring AI 1.0.0 - 1.0.9
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47851/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T17:18:27.247000
2 posts
🟠 CVE-2026-47666 - High (7.6)
Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through custom font family names, which are interpolated into a @font-face CSS rule and injected ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47666/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-47666 - High (7.6)
Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through custom font family names, which are interpolated into a @font-face CSS rule and injected ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47666/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T17:18:25.810000
2 posts
🟠 CVE-2026-46369 - High (7.5)
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through 1.5.0, the validity store uses a strict lower-bound comparison that expires a stored transaction too early relative to Transact...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46369/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-46369 - High (7.5)
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through 1.5.0, the validity store uses a strict lower-bound comparison that expires a stored transaction too early relative to Transact...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46369/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T17:17:52.553000
2 posts
🟠 CVE-2026-32257 - High (8.1)
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with the backend.manage_branding permission is compile...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-32257/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-32257 - High (8.1)
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with the backend.manage_branding permission is compile...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-32257/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T15:32:31
12 posts
https://xeiaso.net/shitposts/no-way-to-prevent-this/memory-safety/CVE-2026-41992/
sweet shitpost 🙃
##"No way to prevent this" say users of only language where this regularly happens - https://xeiaso.net/shitposts/no-way-to-prevent-this/memory-safety/CVE-2026-41992/
##🚨 BREAKING: Tech users baffled as they discover glaring security flaw in their beloved open-source project. 😱 "Who could've seen this coming?" they cry, while clutching their GNU manuals like sacred texts. 🤦♂️ Meanwhile, the rest of the world rolls its eyes and continues to use literally any other software.
https://xeiaso.net/shitposts/no-way-to-prevent-this/memory-safety/CVE-2026-41992/ #TechNews #OpenSource #SecurityFlaw #UserConcern #GNUManuals #SoftwareAlternatives #HackerNews #ngated
"No way to prevent this" say users of only language where this regularly happens
https://xeiaso.net/shitposts/no-way-to-prevent-this/memory-safety/CVE-2026-41992/
Comments: https://news.ycombinator.com/item?id=49463680
#HackerNews #memorysafety #CVE202641992 #programming #news #cybersecurity
##"No way to prevent this" say users of only language where this regularly happens
https://xeiaso.net/shitposts/no-way-to-prevent-this/memory-safety/CVE-2026-41992/
"No way to prevent this" say u...
"No way to prevent this" say users of only language where this regularly happens
##https://xeiaso.net/shitposts/no-way-to-prevent-this/memory-safety/CVE-2026-41992/
sweet shitpost 🙃
##🚨 BREAKING: Tech users baffled as they discover glaring security flaw in their beloved open-source project. 😱 "Who could've seen this coming?" they cry, while clutching their GNU manuals like sacred texts. 🤦♂️ Meanwhile, the rest of the world rolls its eyes and continues to use literally any other software.
https://xeiaso.net/shitposts/no-way-to-prevent-this/memory-safety/CVE-2026-41992/ #TechNews #OpenSource #SecurityFlaw #UserConcern #GNUManuals #SoftwareAlternatives #HackerNews #ngated
"No way to prevent this" say users of only language where this regularly happens
https://xeiaso.net/shitposts/no-way-to-prevent-this/memory-safety/CVE-2026-41992/
Comments: https://news.ycombinator.com/item?id=49463680
#HackerNews #memorysafety #CVE202641992 #programming #news #cybersecurity
##"No way to prevent this" say users of only language where this regularly happens
https://xeiaso.net/shitposts/no-way-to-prevent-this/memory-safety/CVE-2026-41992/
"No way to prevent this" say u...
"No way to prevent this" say users of only language where this regularly happens
##🔒 New CSAF advisory published
VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)
Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…
HTML: https://certvde.com/en/advisories/VDE-2026-088/
CSAF JSON: https://mettler-toledo.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-088.json
updated 2026-08-27T15:31:35
4 posts
🔴 CVE-2026-74233 - Critical (9.8)
Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74233/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Bugdoor too?
https://nvd.nist.gov/vuln/detail/CVE-2026-74233
##Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1 firmware 20.0622 contain an unauthenticated command injection in the infosrvd service (UDP/9992). A remote unauthenticated attacker can send a crafted UDP packet to execute arbitrary commands as root. The service's authentication uses a hardcoded salt and an all-zero wildcard MAC bypass, rendering it ineffective.
🔴 CVE-2026-74233 - Critical (9.8)
Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74233/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Bugdoor too?
https://nvd.nist.gov/vuln/detail/CVE-2026-74233
##Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1 firmware 20.0622 contain an unauthenticated command injection in the infosrvd service (UDP/9992). A remote unauthenticated attacker can send a crafted UDP packet to execute arbitrary commands as root. The service's authentication uses a hardcoded salt and an all-zero wildcard MAC bypass, rendering it ineffective.
updated 2026-08-27T14:27:23.650000
1 posts
Apache Tomcat fixed 11 vulnerabilities on August 25, 2026, including auth bypass (CVE-2026-68569) and HTTP/2 DoS flaws. Update to 11.0.25 now.
##updated 2026-08-27T13:18:41.093000
4 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
🔴 CVE-2026-80587 - Critical (9.8)
In the Linux kernel, the following vulnerability has been resolved:
mptcp: avoid combining some incoming suboptions
Some MPTCP suboptions are mutually exclusive according to the RFC8684,
but also because in different places, the code doesn't exp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80587/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
🔴 CVE-2026-80587 - Critical (9.8)
In the Linux kernel, the following vulnerability has been resolved:
mptcp: avoid combining some incoming suboptions
Some MPTCP suboptions are mutually exclusive according to the RFC8684,
but also because in different places, the code doesn't exp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80587/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T13:18:40.360000
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T13:18:39.733000
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T13:18:21.880000
1 posts
A public PoC for the Linux kernel flaw CVE-2026-52923 allows local attackers to escalate to root privilege. Learn about the patch and technical details.
#Linux #CVE202652923 #CyberSecurity #PrivilegeEscalation #KernelFlaw
##updated 2026-08-27T12:30:34
1 posts
CVE-2026-78293 - Unauthenticated XSS in WP w3all phpBB (<= 3.0.6). CVSS 7.1. Vulnerability is currently unpatched. Mitigate risk immediately. #CVE #WordPress #infosec
##updated 2026-08-27T12:30:34
2 posts
CVE-2026-78276 - PHP Object Injection in Fluent Boards Pro <= 2.0.11. CVSS 7.2. Currently unpatched. Restrict access and mitigate now. #CVE #WordPress #infosec
##CVE-2026-78276 - PHP Object Injection in Fluent Boards Pro <= 2.0.11. CVSS 7.2. Currently unpatched. Restrict access and mitigate now. #CVE #WordPress #infosec
##updated 2026-08-27T12:30:34
2 posts
🟠 CVE-2026-78285 - High (8.5)
Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78285/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-78285 - High (8.5)
Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78285/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T12:30:34
2 posts
🟠 CVE-2026-81625 - High (8.8)
A remote attacker with user privileges may use a malicious or compromised NASL vulnerability test (VT) on the affected products to trigger a stack buffer overflow and gain full access on the compromised system.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81625/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81625 - High (8.8)
A remote attacker with user privileges may use a malicious or compromised NASL vulnerability test (VT) on the affected products to trigger a stack buffer overflow and gain full access on the compromised system.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81625/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T12:30:27
2 posts
🟠 CVE-2026-81573 - High (8.6)
If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network-
origin restrictions. Commands intended only for local or same-network clients can therefore be executed by
arbitrary r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81573/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81573 - High (8.6)
If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network-
origin restrictions. Commands intended only for local or same-network clients can therefore be executed by
arbitrary r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81573/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T12:30:27
2 posts
🟠 CVE-2026-81273 - High (8.1)
Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81273/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81273 - High (8.1)
Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81273/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T12:30:27
2 posts
🟠 CVE-2026-81579 - High (8.8)
In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a write-what-where primitive, enabling local privilege escalation. This can be lever...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81579/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81579 - High (8.8)
In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a write-what-where primitive, enabling local privilege escalation. This can be lever...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81579/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T12:30:27
2 posts
🟠 CVE-2026-81574 - High (8.2)
In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format
specifiers. This can be used to reliably crash CodeMeter and disclose sensitive in...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81574/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81574 - High (8.2)
In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format
specifiers. This can be used to reliably crash CodeMeter and disclose sensitive in...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81574/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T10:16:38.137000
3 posts
🔴 CVE-2026-78286 - Critical (9.8)
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78286/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-78286 - Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8. Potential RCE. CVSS 9.8. Audit systems & restrict access now. #CVE #infosec #cybersecurity
##🔴 CVE-2026-78286 - Critical (9.8)
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78286/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T06:32:29
1 posts
Two critical SonicWall NetExtender vulnerabilities (CVE-2026-66152, CVE-2026-66153) affect the NetExtender Linux Client. Update to version 10.3.6 now.
#SonicWall #NetExtender #CyberSecurity #CVE202666152 #CVE202666153
##updated 2026-08-27T06:31:43
4 posts
wat
https://spring.io/security/cve-2026-59270
##Spring Security's embedded UnboundID LDAP server (
UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces.An attacker who could reach the LDAP listener port could authenticate using the well-known administrative bind DN, and then read or modify entries in the in-memory directory.
🔴 CVE-2026-59270 - Critical (9.4)
Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces.
Spring Security 7.1.0
Spring Security 7.0.0 - 7.0.6
Spring Sec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59270/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##wat
https://spring.io/security/cve-2026-59270
##Spring Security's embedded UnboundID LDAP server (
UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces.An attacker who could reach the LDAP listener port could authenticate using the well-known administrative bind DN, and then read or modify entries in the in-memory directory.
🔴 CVE-2026-59270 - Critical (9.4)
Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces.
Spring Security 7.1.0
Spring Security 7.0.0 - 7.0.6
Spring Sec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59270/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T06:31:38
4 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
🔴 CVE-2026-80589 - Critical (9.8)
In the Linux kernel, the following vulnerability has been resolved:
block: stop the timeout timer when releasing a never added disk
disk_release() undoes blk_mq_init_allocated_queue() for a disk whose
probe failed before add_disk(), but it only ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80589/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
🔴 CVE-2026-80589 - Critical (9.8)
In the Linux kernel, the following vulnerability has been resolved:
block: stop the timeout timer when releasing a never added disk
disk_release() undoes blk_mq_init_allocated_queue() for a disk whose
probe failed before add_disk(), but it only ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80589/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T06:31:38
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T06:31:38
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T06:31:38
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T06:31:37
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T06:31:37
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T06:31:33
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T06:31:33
2 posts
🟠 CVE-2026-80588 - High (7.5)
In the Linux kernel, the following vulnerability has been resolved:
mptcp: reclaim forward-allocated memory on RX path errors
After commit 9db5b3cec4ec ("mptcp: borrow forward memory from subflow"),
errors in the receive path prior to queueing s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80588/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-80588 - High (7.5)
In the Linux kernel, the following vulnerability has been resolved:
mptcp: reclaim forward-allocated memory on RX path errors
After commit 9db5b3cec4ec ("mptcp: borrow forward memory from subflow"),
errors in the receive path prior to queueing s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80588/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T06:31:31
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T06:31:31
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T06:17:45.700000
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T06:17:39.903000
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T06:17:38.923000
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T06:17:25.033000
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T06:17:24.440000
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T04:17:58.410000
1 posts
📢 [VULN] Chrome : Google vient encore de combler plus de 300 failles - CVE-2026-79282
Google a déployé Chrome 152, une mise à jour qui corrige 327 vulnérabilités, dont dix jugées critiques. Un chercheur surnommé Goodluck reçoit à lui seul 25 000 dollars pour avoir signalé l'une d'entre elles, une faille critique logée dans le moteur graphique ANGLE.
🔗 https://www.clubic.com/actualite-626932-chrome-google-vient-encore-de-combler-plus-de-300-failles.html
💬 discussion : https://infosec.pub/post/51492518
#Vulnérabilité #CVE #Cyberveille
updated 2026-08-27T04:16:50.850000
1 posts
1 repos
Ubiquiti patches three max severity security vulnerabilities
Ubiquiti가 인증 없이 원격 공격 가능한 최대 심각도 취약점 3건을 패치했다. CVE-2026-77537은 UniFi Protect의 입력 검증 문제로 기기 장악을 허용하며, CVE-2026-77550은 UniFi OS의 CRLF 인젝션을 이용한 인증 우회, CVE-2026-77554는 UniFi Talk의 명령 인젝션 취약점이다. 공격 복잡도가 낮고 사용자 상호작용이 필요 없으며, 인터넷에 노출된 UniFi OS 인스턴스가 10만 개 이상 관측돼 네트워크·AI 엣지 장비를...
##updated 2026-08-27T04:16:45.137000
1 posts
Two critical SonicWall NetExtender vulnerabilities (CVE-2026-66152, CVE-2026-66153) affect the NetExtender Linux Client. Update to version 10.3.6 now.
#SonicWall #NetExtender #CyberSecurity #CVE202666152 #CVE202666153
##updated 2026-08-27T04:16:41.857000
2 posts
A critical GitLab EE security patch addresses CVE-2026-18252, fixing a command execution flaw. Learn about affected versions, mechanisms, and mitigation.
#GitLab #SecurityPatch #Cybersecurity #CVE202618252
http://securityonline.info/gitlab-ee-security-patch/?utm_source=mastodon&utm_medium=jetpack_social
##A critical GitLab EE security patch addresses CVE-2026-18252, fixing a command execution flaw. Learn about affected versions, mechanisms, and mitigation.
#GitLab #SecurityPatch #Cybersecurity #CVE202618252
http://securityonline.info/gitlab-ee-security-patch/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-08-27T04:16:39.223000
8 posts
4 repos
https://github.com/AndreevSemen/CVE-2022-0995
https://github.com/Bonfee/CVE-2022-0995
🚨 Critical Threat Intel: CVE-2022-0995 impacts the Linux kernel watch_queue subsystem via out-of-bounds memory writes, enabling local root privilege escalation. Review IOCs, Splunk/Sentinel queries, and kernel hardening actions: https://thecybermind.co/heaz
##🚨 Executive Risk Brief: CVE-2022-0995 targets the Linux Kernel via an out-of-bounds write flaw enabling privilege escalation. Leaders must review asset visibility, patch cadence, and risk governance. Read the full CSUITE brief: https://thecybermind.co/rzv2
##🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2022-0995
Vendor: Linux
Product: Kernel
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2022-0995
🚨 Critical Threat Intel: CVE-2022-0995 impacts the Linux kernel watch_queue subsystem via out-of-bounds memory writes, enabling local root privilege escalation. Review IOCs, Splunk/Sentinel queries, and kernel hardening actions: https://thecybermind.co/heaz
##🚨 Executive Risk Brief: CVE-2022-0995 targets the Linux Kernel via an out-of-bounds write flaw enabling privilege escalation. Leaders must review asset visibility, patch cadence, and risk governance. Read the full CSUITE brief: https://thecybermind.co/rzv2
##🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2022-0995
Vendor: Linux
Product: Kernel
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2022-0995
updated 2026-08-27T04:16:38.583000
5 posts
2 repos
🚨 Executive Risk Brief: CVE-2019-1068 targets Microsoft SQL Server via remote code execution vectors. Leaders must review asset inventory fidelity, least-privilege RBAC, and network segregation. Read the full CSUITE brief from The Cyber Mind Co. https://thecybermind.co/5am3
##🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2019-1068
Vendor: Microsoft
Product: SQL Server
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2019-1068
🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2019-1068
Vendor: Microsoft
Product: SQL Server
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2019-1068
updated 2026-08-26T21:31:52
2 posts
🟠 CVE-2026-68861 - High (8.8)
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68861/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-68861 - High (8.8)
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68861/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T21:31:52
2 posts
🟠 CVE-2026-74770 - High (8.8)
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74770/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-74770 - High (8.8)
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74770/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T21:31:47
4 posts
Dell patched 5 Cloud Disaster Recovery flaws. The top bug, CVE-2026-70419 (CVSS 9.1), allows command execution. Update to CDR 20.3 now.
#Dell #CyberSecurity #CVE202670419 #CommandInjection #Infosec
##🔴 CVE-2026-70419 - Critical (9.1)
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70419/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Dell patched 5 Cloud Disaster Recovery flaws. The top bug, CVE-2026-70419 (CVSS 9.1), allows command execution. Update to CDR 20.3 now.
#Dell #CyberSecurity #CVE202670419 #CommandInjection #Infosec
##🔴 CVE-2026-70419 - Critical (9.1)
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70419/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T20:18:07.820000
1 posts
CVE-2026-79074 - Information leak in Google Chrome renderer. Medium severity. Update to 152.0.7977.65 or higher immediately. #CVE #Chrome #infosec
##updated 2026-08-26T20:17:56.810000
1 posts
🔴 CVE-2026-65083 - Critical (9.9)
NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of priv...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65083/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T20:17:56.587000
1 posts
🟠 CVE-2026-65081 - High (8.1)
NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tamp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65081/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T20:17:55.417000
1 posts
The bear is friendly. Think of honey, if you can.
For anyone who wonders why tags included #FreeBSD, it's because – in addition to the write-up of CVE-2026-58083 and CVE-2026-58084 (July 2026) – I assume that Hazley Samsudin might also choose Blimpers for CVE-2026-58092 (August).
<https://www.cve.org/CVERecord?id=CVE-2026-58092>
<https://nvd.nist.gov/vuln/detail/CVE-2026-58092>
<https://security.freebsd.org/advisories/FreeBSD-SA-26:59.mac_do.asc>
<https://defcon.social/@charlesrocket/116714325230546417> @charlesrocket re: LLM shaming.
##updated 2026-08-26T20:17:10.020000
1 posts
2 repos
A critical TranslatePress vulnerability (CVE-2026-19632) lets attackers steal admin reset links and take over 400,000 WordPress sites. Update to 3.3.2 now.
#WordPress #TranslatePress #CyberSecurity #CVE202619632 #WebSecurity
##updated 2026-08-26T19:17:19.470000
2 posts
🟠 CVE-2026-81029 - High (8.1)
OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the HTTP session without comparing it against any configured or r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81029/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81029 - High (8.1)
OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the HTTP session without comparing it against any configured or r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81029/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:32:06
2 posts
A high-severity TP-Link Kasa vulnerability (CVE-2026-76784) allows unauthorized smart home device control. Apply the latest firmware patch immediately.
#TPLink #Kasa #Vulnerability #Cybersecurity #CVE202676784 #SmartHome
##A high-severity TP-Link Kasa vulnerability (CVE-2026-76784) allows unauthorized smart home device control. Apply the latest firmware patch immediately.
#TPLink #Kasa #Vulnerability #Cybersecurity #CVE202676784 #SmartHome
##updated 2026-08-26T18:32:05
2 posts
🟠 CVE-2026-81027 - High (8.5)
one-api gates one of its two channel-pinning paths and not the other. middleware/auth.go permits a request to name a specific channel either through a suffix on the API key or through a URL path parameter. The suffix path is reached only after mod...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81027/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81027 - High (8.5)
one-api gates one of its two channel-pinning paths and not the other. middleware/auth.go permits a request to name a specific channel either through a suffix on the API key or through a URL path parameter. The suffix path is reached only after mod...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81027/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:32:05
2 posts
🔴 CVE-2026-80428 - Critical (9.8)
ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel endpoint at components/ILIAS/AuthShibboleth/resources/shib_logout.php runs in a context that ilInitialisation exempts from authentication, and its lo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80428/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-80428 - Critical (9.8)
ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel endpoint at components/ILIAS/AuthShibboleth/resources/shib_logout.php runs in a context that ilInitialisation exempts from authentication, and its lo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80428/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:32:05
2 posts
🟠 CVE-2026-81036 - High (8.1)
Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine in crates/http/src/auth/oauth/registration.rs returns success immediately when the client-authen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81036/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81036 - High (8.1)
Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine in crates/http/src/auth/oauth/registration.rs returns success immediately when the client-authen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81036/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:32:05
2 posts
🟠 CVE-2026-81035 - High (8.1)
Midday allows any member of a team to delete it. The delete procedure in apps/api/src/trpc/routers/team.ts authorises the caller with the team-access helper, which returns true for every row in the team-membership table irrespective of the role it...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81035/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81035 - High (8.1)
Midday allows any member of a team to delete it. The delete procedure in apps/api/src/trpc/routers/team.ts authorises the caller with the team-access helper, which returns true for every row in the team-membership table irrespective of the role it...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81035/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:32:04
2 posts
🟠 CVE-2026-15990 - High (7.5)
The Formidable Charts plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.0.1 via the 'frm_graph' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15990/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-15990 - High (7.5)
The Formidable Charts plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.0.1 via the 'frm_graph' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15990/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:32:04
2 posts
🟠 CVE-2026-19271 - High (7.5)
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows LDAP Injection.
This issue affects Liderahenk: from 3.4.0 before 3....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19271/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19271 - High (7.5)
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows LDAP Injection.
This issue affects Liderahenk: from 3.4.0 before 3....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19271/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:32:04
3 posts
🟠 CVE-2026-75960 - High (8.1)
Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75960/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-75960 - High (8.1)
Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75960/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CISA advisory ICSA-26-237-01 (rev. 1) discloses CVE-2026-75960 in Rently Smart Home firmware 20.1.0 and earlier. The vulnerability (CWE-522) allows extraction of PINs and Master PINs due to insufficiently protected credentials.
#CISA #CVE2026 #SmartHomeSecurity #ICSAdvisory
https://cyberworldops.eu/en/cisa-flaw-in-rently-smart-home-allows-retrieval-of-pins-and-master-pin
##updated 2026-08-26T18:32:04
2 posts
🟠 CVE-2026-58474 - High (8.8)
whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to achieve arbitrary code execution by crafting a malicious GGUF filename containing...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58474/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-58474 - High (8.8)
whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to achieve arbitrary code execution by crafting a malicious GGUF filename containing...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58474/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:32:03
1 posts
Security Advisory Bulletin 067
Ubiquiti의 Security Advisory Bulletin 067은 UniFi OS 및 Protect·Network·Access·Connect 등 관리 애플리케이션에서 발견된 다수의 치명적 취약점(CVE-2026-77533~77547 등)을 공개했다. 핵심 영향은 네트워크 접근만으로 가능한 명령 주입과 권한 상승이며, 일부 취약점은 낮은 권한 또는 권한 없이도 악용 가능하고 CVSS 9.9~10.0에 이른다. AI 서비스 운영 환경에서 UniFi 게이트웨이·NVR·Cloud Key·NAS 등을 네트워크 경계나 물리 보안, 사내 인프라에...
##updated 2026-08-26T18:32:03
7 posts
1 repos
Remote Code Execution Vulnerability Chain Discovered in Avada WordPress Theme
A critical vulnerability chain (CVE-2026-18431) in the Avada WordPress theme allows unauthenticated attackers to execute arbitrary PHP code and fully compromise websites without any user interaction.
**If you're using the Avada WordPress theme, update it to version 7.16.1 and update the Fusion Builder plugin to version 3.16.1 right ASAP. Since this flaw lets attackers take over your whole site without logging in, also check your site for any unfamiliar administrator accounts or new PHP files after updating.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/remote-code-execution-vulnerability-chain-discovered-in-avada-wordpress-theme-i-5-b-d-e/gD2P6Ple2L
Wordfence's AI system Argus uncovered a six-step vulnerability chain in the Avada WordPress theme, rated 9.8 critical, enabling unauthenticated remote code execution.
##Six chained vulnerabilities (CVE-2026-18431, CVSS 9.8) in the WordPress Avada theme and Fusion Builder plugin allow unauthenticated remote code execution. No user interaction is required — the exploit is zero-click. Any site running vulnerable versions of both components is at immediate risk of full takeover. Patch now. #AvadaVulnerability #WordPressSecurity #CVE202618431 #SiteTakeover
https://cyberworldops.eu/en/six-chained-vulnerabilities-in-wordpress-avada-theme-allow-full-site
##CVE-2026-18431 - Critical Unauthenticated RCE in WordPress Avada theme & Fusion Builder via arbitrary file write. CVSS 9.8. Unpatched. Mitigate immediately. #CVE #WordPress #cybersecurity
##Remote Code Execution Vulnerability Chain Discovered in Avada WordPress Theme
A critical vulnerability chain (CVE-2026-18431) in the Avada WordPress theme allows unauthenticated attackers to execute arbitrary PHP code and fully compromise websites without any user interaction.
**If you're using the Avada WordPress theme, update it to version 7.16.1 and update the Fusion Builder plugin to version 3.16.1 right ASAP. Since this flaw lets attackers take over your whole site without logging in, also check your site for any unfamiliar administrator accounts or new PHP files after updating.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/remote-code-execution-vulnerability-chain-discovered-in-avada-wordpress-theme-i-5-b-d-e/gD2P6Ple2L
Wordfence's AI system Argus uncovered a six-step vulnerability chain in the Avada WordPress theme, rated 9.8 critical, enabling unauthenticated remote code execution.
##Six chained vulnerabilities (CVE-2026-18431, CVSS 9.8) in the WordPress Avada theme and Fusion Builder plugin allow unauthenticated remote code execution. No user interaction is required — the exploit is zero-click. Any site running vulnerable versions of both components is at immediate risk of full takeover. Patch now. #AvadaVulnerability #WordPressSecurity #CVE202618431 #SiteTakeover
https://cyberworldops.eu/en/six-chained-vulnerabilities-in-wordpress-avada-theme-allow-full-site
##updated 2026-08-26T18:32:01
1 posts
The bear is friendly. Think of honey, if you can.
For anyone who wonders why tags included #FreeBSD, it's because – in addition to the write-up of CVE-2026-58083 and CVE-2026-58084 (July 2026) – I assume that Hazley Samsudin might also choose Blimpers for CVE-2026-58092 (August).
<https://www.cve.org/CVERecord?id=CVE-2026-58092>
<https://nvd.nist.gov/vuln/detail/CVE-2026-58092>
<https://security.freebsd.org/advisories/FreeBSD-SA-26:59.mac_do.asc>
<https://defcon.social/@charlesrocket/116714325230546417> @charlesrocket re: LLM shaming.
##updated 2026-08-26T18:31:55
1 posts
<https://www.cve.org/CVERecord?id=CVE-2026-58090>
<https://security.freebsd.org/advisories/FreeBSD-SA-26:57.unix.asc>
Context (unofficial):
<https://bokut.in/freebsd-patch-level-table/#releng/15.0> (releng/15.0) | <https://bokut.in/freebsd-patch-level-table/#releng/15.1> (releng/15.1)
##updated 2026-08-26T18:31:49
2 posts
Apache Tomcat Patches Critical Security Constraint Bypass Vulnerability
Apache Tomcat addressed a critical vulnerability (CVE-2026-65182) that allows unauthenticated attackers to bypass security restrictions by exploiting path-ordering logic. Administrators should update to the latest versions or remove the examples application to prevent unauthorized access.
**If you run Apache Tomcat (versions 9.0.x, 10.1.x, or 11.0.x), update now to 11.0.25, 10.1.59, or 9.0.121. Note that 10.1.58 has the fix but was never officially released, so don't rely on it. If you can't patch right away, delete the default examples web application and review your security constraint rules so the more restrictive short paths are listed before longer ones.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/apache-tomcat-patches-critical-security-constraint-bypass-vulnerability-z-g-d-l-6/gD2P6Ple2L
Apache Tomcat Patches Critical Security Constraint Bypass Vulnerability
Apache Tomcat addressed a critical vulnerability (CVE-2026-65182) that allows unauthenticated attackers to bypass security restrictions by exploiting path-ordering logic. Administrators should update to the latest versions or remove the examples application to prevent unauthorized access.
**If you run Apache Tomcat (versions 9.0.x, 10.1.x, or 11.0.x), update now to 11.0.25, 10.1.59, or 9.0.121. Note that 10.1.58 has the fix but was never officially released, so don't rely on it. If you can't patch right away, delete the default examples web application and review your security constraint rules so the more restrictive short paths are listed before longer ones.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/apache-tomcat-patches-critical-security-constraint-bypass-vulnerability-z-g-d-l-6/gD2P6Ple2L
updated 2026-08-26T18:31:36
1 posts
CVE-2026-78899 - High severity Use-After-Free in Google Chrome V8 enables sandbox RCE via crafted HTML. CVSS: High. Update Chrome now. #CVE #Google #infosec
##updated 2026-08-26T18:31:36
1 posts
🟠 CVE-2026-74932 - High (7.5)
The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using it to build the URLs of the asset files it embeds in the pages it caches, and does not include that header in the cache key, allowing unauthenticated...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74932/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:31:30
6 posts
1 repos
🚨 Executive Risk Brief: CVE-2015-5287 targets Red Hat ABRT via symlink privilege escalation. Leaders must review asset visibility, compliance tracking, and patch management protocols. Read the full CSUITE brief from The Cyber Mind Co. https://thecybermind.co/9pkv
##🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2015-5287
Vendor: Red Hat
Product: Automatic Bug Reporting Tool
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2015-5287
🚨 Executive Risk Brief: CVE-2015-5287 targets Red Hat ABRT via symlink privilege escalation. Leaders must review asset visibility, compliance tracking, and patch management protocols. Read the full CSUITE brief from The Cyber Mind Co. https://thecybermind.co/9pkv
##🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2015-5287
Vendor: Red Hat
Product: Automatic Bug Reporting Tool
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2015-5287
updated 2026-08-26T18:30:34
11 posts
3 repos
https://github.com/derekpreston81/CVE_ADC_IOC_2026
https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452
CISA Sounds the Alarm: Actively Exploited Citrix NetScaler Flaw Could Give Attackers Root-Level Access + Video
A Critical Warning for Organizations Running NetScaler A vulnerability that initially appeared to be primarily a denial-of-service concern has taken a far more dangerous turn. CISA has added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog after evidence emerged that attackers are exploiting the flaw in the wild. Federal civilian agencies have been…
##🚨 Executive Risk Brief: CVE-2026-8452 targets Citrix NetScaler ADC & Gateway via memory buffer flaws. Leaders must review asset visibility, patch velocity, and risk governance. Read the full CSUITE brief: https://thecybermind.co/zapn
##Critical Citrix NetScaler Flaw Allegedly Exploited in the Wild as Weedhack Malware Targets Minecraft Players + Video
A New Cybersecurity Warning Is Raising Alarm Two very different threats are emerging in the latest cybersecurity landscape, but both demonstrate the same uncomfortable reality: attackers are becoming increasingly effective at reaching victims through systems and services they already trust. One warning concerns Citrix NetScaler, where CVE-2026-8452 is a…
##CISA Mandates Patching of Exploited Citrix NetScaler Flaw
Don't wait until it's too late: CISA has issued a directive requiring all Federal agencies to patch the exploited Citrix NetScaler flaw, CVE-2026-8452, by August 29 to avoid potential security breaches. This critical vulnerability is already being exploited in the wild, making swift action essential.
#Cve20268452 #CitrixNetscaler #Cisa #BindingOperationalDirective2604 #ExploitedVulnerabilities
##CISA adds six exploited vulnerabilities to its KEV Catalog, including a Citrix NetScaler flaw and CVE-2026-8452, with active exploitation confirmed.
##🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2026-8452
Vendor: Citrix
Product: NetScaler ADC and NetScaler Gateway
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8452
🚨 Executive Risk Brief: CVE-2026-8452 targets Citrix NetScaler ADC & Gateway via memory buffer flaws. Leaders must review asset visibility, patch velocity, and risk governance. Read the full CSUITE brief: https://thecybermind.co/zapn
##CISA adds six exploited vulnerabilities to its KEV Catalog, including a Citrix NetScaler flaw and CVE-2026-8452, with active exploitation confirmed.
##🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2026-8452
Vendor: Citrix
Product: NetScaler ADC and NetScaler Gateway
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8452
updated 2026-08-26T18:30:27
6 posts
1 repos
🚨 Executive Risk Brief: CVE-2015-3246 targets Red Hat libuser via authentication race conditions. Leaders must review asset visibility, compliance tracking, and endpoint hardening protocols. Read the full CSUITE brief from The Cyber Mind Co. https://thecybermind.co/7ei4
##🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2015-3246
Vendor: Red Hat
Product: Libuser
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2015-3246
🚨 Executive Risk Brief: CVE-2015-3246 targets Red Hat libuser via authentication race conditions. Leaders must review asset visibility, compliance tracking, and endpoint hardening protocols. Read the full CSUITE brief from The Cyber Mind Co. https://thecybermind.co/7ei4
##🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2015-3246
Vendor: Red Hat
Product: Libuser
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2015-3246
updated 2026-08-26T18:17:05.890000
2 posts
🔴 CVE-2026-81032 - Critical (9.8)
NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebService.cpp, whose bind address defaults to all interfaces, and registers routes for reading and wr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81032/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-81032 - Critical (9.8)
NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebService.cpp, whose bind address defaults to all interfaces, and registers routes for reading and wr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81032/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:17:04.953000
1 posts
🟠 CVE-2026-79992 - High (7.8)
A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local sh...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79992/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:17:01.010000
2 posts
🔴 CVE-2026-75896 - Critical (9.1)
Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows Try Common or Default Usernames and Passwords.
This issue affects Liderahenk: before 3.5.5.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75896/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-75896 - Critical (9.1)
Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows Try Common or Default Usernames and Passwords.
This issue affects Liderahenk: before 3.5.5.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75896/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:16:40.930000
2 posts
🔴 CVE-2026-54569 - Critical (9.8)
SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-request chain involving missing authorization a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54569/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-54569 - Critical (9.8)
SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-request chain involving missing authorization a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54569/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T17:17:24.903000
1 posts
🟠 CVE-2026-79784 - High (8.8)
Vocos instantiates a class named by a configuration file without restricting which class may be named. instantiate_class in vocos/pretrained.py takes the class_path value from the configuration, splits it into a module and an attribute, imports th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79784/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T16:16:35.933000
1 posts
🟠 CVE-2026-65092 - High (8.5)
NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit of this vulnerability might lead to information disclosure and data tampering.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65092/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T16:16:35.810000
1 posts
🟠 CVE-2026-65091 - High (8.8)
NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65091/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T16:16:35.687000
1 posts
🟠 CVE-2026-65089 - High (7.8)
NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information dis...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65089/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T16:16:28.197000
1 posts
🟠 CVE-2026-55099 - High (7.5)
icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 until 7.1.3, the Component equality method in src/icalendar/cal/component.py compares nested subcomponents with two membership loops, and each membe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55099/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T15:17:03.720000
1 posts
CVE-2026-80196 - Authentication Bypass in Kimai before 2.58.0 via password reset link reuse. CVSS 7.5. Update to version 2.58.0 immediately. #CVE #Kimai #infosec
##updated 2026-08-26T15:16:50.903000
1 posts
🟠 CVE-2026-65099 - High (7.8)
NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65099/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T15:16:50.760000
1 posts
🟠 CVE-2026-65098 - High (8.1)
NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65098/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T14:21:54
2 posts
🔴 CVE-2026-54523 - Critical (9.6)
Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the NamespacedMutatingPolicy CEL compiler exposes the generator library to matchConditions, allowing a namespace-scoped policy to invoke gen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54523/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-54523 - Critical (9.6)
Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the NamespacedMutatingPolicy CEL compiler exposes the generator library to matchConditions, allowing a namespace-scoped policy to invoke gen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54523/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T14:17:12.830000
2 posts
🟠 CVE-2026-73108 - High (7.5)
RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability in BytesCodec. Before authentication, the decoder trusts the payload length encoded in a four-byte frame header and reserves that amount before rece...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73108/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73108 - High (7.5)
RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability in BytesCodec. Before authentication, the decoder trusts the payload length encoded in a four-byte frame header and reserves that amount before rece...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73108/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T14:17:08.270000
2 posts
TeamViewer patched CVE-2026-19042, a Linux command injection flaw, and a path traversal bug. Both TeamViewer vulnerabilities enable code execution.
#TeamViewer #CommandInjection #CVE202619042 #PathTraversal #RCE #InfoSec
##TeamViewer patched CVE-2026-19042, a Linux command injection flaw, and a path traversal bug. Both TeamViewer vulnerabilities enable code execution.
#TeamViewer #CommandInjection #CVE202619042 #PathTraversal #RCE #InfoSec
##updated 2026-08-26T13:19:24.307000
1 posts
🔴 CVE-2026-80138 - Critical (9.8)
ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli_filepath ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80138/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T13:19:21.823000
1 posts
1 repos
Ubiquiti patches three max severity security vulnerabilities
Ubiquiti가 인증 없이 원격 공격 가능한 최대 심각도 취약점 3건을 패치했다. CVE-2026-77537은 UniFi Protect의 입력 검증 문제로 기기 장악을 허용하며, CVE-2026-77550은 UniFi OS의 CRLF 인젝션을 이용한 인증 우회, CVE-2026-77554는 UniFi Talk의 명령 인젝션 취약점이다. 공격 복잡도가 낮고 사용자 상호작용이 필요 없으며, 인터넷에 노출된 UniFi OS 인스턴스가 10만 개 이상 관측돼 네트워크·AI 엣지 장비를...
##updated 2026-08-26T13:19:16.497000
1 posts
🟠 CVE-2026-54757 - High (7.8)
Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, Trestle is vulnerable to server-side template injection that can lead to remote...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54757/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T00:31:14
1 posts
🟠 CVE-2026-79912 - High (8.3)
A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntp_server results in command injection. The att...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79912/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T00:31:09
1 posts
🟠 CVE-2026-80186 - High (7.6)
A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80186/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T21:31:40
1 posts
🟠 CVE-2026-65105 - High (8.1)
NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and de...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65105/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T21:31:36
1 posts
🟠 CVE-2026-65084 - High (8.1)
NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, code exec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65084/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T21:31:36
2 posts
NVIDIA patched 20 NemoClaw and OpenShell flaws. The worst, CVE-2026-65093 (CVSS 9.9), enables code execution via sandbox escape. Update now.
#NVIDIA #CyberSecurity #CVE202665093 #CodeExecution #AISecurity
##🔴 CVE-2026-65093 - Critical (9.9)
NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65093/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T21:31:35
1 posts
🟠 CVE-2026-65090 - High (7.8)
NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65090/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T21:31:35
1 posts
🟠 CVE-2026-65096 - High (7.8)
NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, informat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65096/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T21:31:34
2 posts
🟠 CVE-2026-80049 - High (8.8)
Airbyte Platform resolves the workspace used for its authorization decision from a field the caller supplies. AuthorizationServerHandler copies recognised identifiers out of the raw JSON request body into X-Airbyte-* headers, and AuthenticationHea...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80049/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-80049 - High (8.8)
Airbyte Platform resolves the workspace used for its authorization decision from a field the caller supplies. AuthorizationServerHandler copies recognised identifiers out of the raw JSON request body into X-Airbyte-* headers, and AuthenticationHea...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80049/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T21:31:34
1 posts
🟠 CVE-2026-65097 - High (7.5)
NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download of code without integrity check. A successful exploit of this vulnerability might lead to code execution, escalation of privil...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65097/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T21:18:24.163000
1 posts
🔴 CVE-2026-80104 - Critical (9.8)
DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py takes file.filename as given ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80104/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T20:16:55.720000
2 posts
🔴 CVE-2026-45018 - Critical (9.8)
Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45018/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-45018 - Critical (9.8)
Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45018/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T18:32:08
1 posts
🟠 CVE-2026-75768 - High (7.8)
Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75768/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T18:32:01
3 posts
1 repos
https://github.com/HORKimhab/CVE-2026-19912-CVE-2026-19913-CVE-2026-19914
Two unpatched vulnerabilities in Kaltura's mwEmbed HTML5 player library (html5lib) allow unauthenticated file read and remote code execution via insecure deserialization in mwEmbedLoader.php. CVE-2026-19913 and CVE-2026-19912 affect any exposed instance with no auth or tokens required. No vendor patch exists yet.
#Kaltura #VulnerabilityManagement #RCE #CERTCC
https://cyberworldops.eu/en/unpatched-kaltura-player-vulnerabilities-expose-files-and-allow-code
##Two unpatched vulnerabilities in Kaltura's mwEmbed HTML5 player library (html5lib) allow unauthenticated file read and remote code execution via insecure deserialization in mwEmbedLoader.php. CVE-2026-19913 and CVE-2026-19912 affect any exposed instance with no auth or tokens required. No vendor patch exists yet.
#Kaltura #VulnerabilityManagement #RCE #CERTCC
https://cyberworldops.eu/en/unpatched-kaltura-player-vulnerabilities-expose-files-and-allow-code
##Two unpatched Kaltura server flaws (CVE-2026-19912, CVE-2026-19913) allow attackers to execute code and read files. Learn how to mitigate these risks.
#Kaltura #CyberSecurity #CVE202619912 #CVE202619913 #InfoSec
https://securityonline.info/kaltura-server-flaws/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-08-25T18:32:01
3 posts
🏆 New Achievement! Maximum Payload Acquired!
ITEM DROP: Cursed Campaign Scroll (Adobe Campaign Classic). Three critical flaws — headlined by CVE-2026-76197, a CVSS 10.0 OS command injection — landed in your inventory without your permission. Any attacker who finds you can inject arbitrary OS commands and execute code freely, like a bard who learned every spell and also hates you specifically.
Equipping this item applies the debuff: Completely Owned Server (permanent, until patched). (1/2)
##Three critical Adobe Campaign Classic flaws (CVE-2026-76197, CVSS 10.0) allow arbitrary code execution. Update to build 9401 now.
##🔴 CVE-2026-76197 - Critical (10)
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76197/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T18:32:00
1 posts
🟠 CVE-2026-79774 - High (8.4)
Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in System\\Twig\\SecurityPolicy that allows authenticated backend users with template-editing permissions to bypass sandbox restrictions. Attackers...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79774/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T18:31:56
1 posts
🔴 CVE-2026-79675 - Critical (9.8)
NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath, -javaagent, or @argfil...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79675/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T17:17:07.263000
3 posts
1 repos
https://github.com/HORKimhab/CVE-2026-19912-CVE-2026-19913-CVE-2026-19914
Two unpatched vulnerabilities in Kaltura's mwEmbed HTML5 player library (html5lib) allow unauthenticated file read and remote code execution via insecure deserialization in mwEmbedLoader.php. CVE-2026-19913 and CVE-2026-19912 affect any exposed instance with no auth or tokens required. No vendor patch exists yet.
#Kaltura #VulnerabilityManagement #RCE #CERTCC
https://cyberworldops.eu/en/unpatched-kaltura-player-vulnerabilities-expose-files-and-allow-code
##Two unpatched vulnerabilities in Kaltura's mwEmbed HTML5 player library (html5lib) allow unauthenticated file read and remote code execution via insecure deserialization in mwEmbedLoader.php. CVE-2026-19913 and CVE-2026-19912 affect any exposed instance with no auth or tokens required. No vendor patch exists yet.
#Kaltura #VulnerabilityManagement #RCE #CERTCC
https://cyberworldops.eu/en/unpatched-kaltura-player-vulnerabilities-expose-files-and-allow-code
##Two unpatched Kaltura server flaws (CVE-2026-19912, CVE-2026-19913) allow attackers to execute code and read files. Learn how to mitigate these risks.
#Kaltura #CyberSecurity #CVE202619912 #CVE202619913 #InfoSec
https://securityonline.info/kaltura-server-flaws/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-08-25T15:16:37.230000
1 posts
Two unpatched FURUNO FA-50 vulnerabilities (CVE-2026-59769, CVE-2026-67578) let attackers alter maritime transponder settings. Learn the mitigation steps.
#Furuno #CyberSecurity #CVE202659769 #CVE202667578 #MaritimeSecurity
##updated 2026-08-25T15:16:35.427000
1 posts
Two unpatched FURUNO FA-50 vulnerabilities (CVE-2026-59769, CVE-2026-67578) let attackers alter maritime transponder settings. Learn the mitigation steps.
#Furuno #CyberSecurity #CVE202659769 #CVE202667578 #MaritimeSecurity
##updated 2026-08-25T15:16:35.297000
1 posts
🟠 CVE-2026-57863 - High (8.8)
Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that allows authenticated company owners to write arbitrary files outside the intended extraction directory by supplying crafted ZIP archives with ../ sequ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57863/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T15:16:31.207000
1 posts
The August 2026 OpenSSL security update fixes 9 flaws, including a QUIC double free (CVE-2026-18798) and a CMS heap overflow. Patch now.
##updated 2026-08-25T12:31:29
1 posts
KlbTheme Total Donations <=2.0.5 has a CRITICAL privilege escalation vuln (CVE-2026-78570, CVSS 9.8). Unauthenticated attackers can gain admin access. No patch yet — disable/remove plugin & monitor for advisories. https://radar.offseq.com/threat/cve-2026-78570-cwe-269-improper-privilege-management-in-klbtheme-total-donations-fcfd73df270b6d37 #OffSeq #WordPress #CVE #Vuln
##updated 2026-08-25T12:31:24
2 posts
Two critical WatchGuard Agent flaws (CVE-2026-57909, CVE-2026-57910) allow unauthenticated remote code execution. Update to 1.25.13.0000 now.
##sev:CRIT ../ in WatchGuard Agent. Once again, INFOSEC increasing that attack surface instead of decreasing it.
updated 2026-08-25T12:31:24
2 posts
Two critical WatchGuard Agent flaws (CVE-2026-57909, CVE-2026-57910) allow unauthenticated remote code execution. Update to 1.25.13.0000 now.
##And a sev:CRIT RCE. As a treat.
updated 2026-08-25T09:30:47
1 posts
A critical TYPO3 Powermail RCE flaw (CVE-2026-77136) is actively exploited in the wild. Update immediately to prevent server compromise and data leaks.
#TYPO3 #Powermail #Vulnerability #CyberSecurity #CVE202677136
##updated 2026-08-25T03:32:20
1 posts
GitPython Patches Critical RCE Vulnerability in Config Parser
GitPython version 3.1.59 patches a critical remote code execution vulnerability (CVE-2026-78676) caused by improper handling of multi-line configuration values. The flaw allows attackers to inject malicious Git directives that execute arbitrary code during routine repository operations.
**If you use GitPython in any application or CI/CD pipeline, update it to version 3.1.59 or later. Еvery version up to 3.1.58 is vulnerable to CVE-2026-78676. Until you can update, don't let GitPython read or write config files from cloned repos, shared configs, or workspace caches you don't fully control. Тreat any repository from an outside source as untrusted.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/gitpython-patches-critical-rce-vulnerability-in-config-parser-g-q-0-2-o/gD2P6Ple2L
updated 2026-08-24T21:33:31
4 posts
10 repos
https://github.com/boroeurnprach/Ashwesker-CVE-2026-21962
https://github.com/ThumpBo/CVE-2026-21962
https://github.com/gregk4sec/cve-2026-21962
https://github.com/0xBlackash/CVE-2026-21962
https://github.com/gglessner/cve_2026_21962_scanner
https://github.com/naozibuhao/CVE-2026-21962_Java_GUI_Exploit_Tool
https://github.com/gregk4sec/CVE-2026-21962-o
Oracle Sicherheitsloch von Januar wird angegriffen!
Vor einem Monat hatte Oracle einen riesigen Haufen Sicherheitslücken geflickt. Aber um gefährdet zu sein, braucht man keine frischen Sicherheitslücken. Es reicht auch, Updates nicht zu installieren. Die CISA hat die Sicherheitslücke CVE-2026-21962 (Risiko 10 von 10) in Oracle-Software, gegen die im Januar bereits ein Update veröffentlicht wurde, am 2026-08-24 in den Katalog der als ausgenutzt bekannten Sicherheitslücken (KEV) aufgenommen. Die US-Behörden wurden angewiesen, das Update nunmehr binnen drei Tagen einzuspielen. Ab heute müssten also Angriffe auf diese Lücke in Leere laufen. ;-)
#cybercrime #exploits #sicherheit #UnplugOracle #UnplugTrump
##🚨 Critical Threat Intel: CVE-2026-21962 impacts Oracle HTTP Server & Weblogic Proxy Plug-in via access control bypass. Review exploitation patterns, web access detection queries, and active endpoint hardening actions.
https://thecybermind.co/jily
CISA has added Oracle CVE-2026-21962 to the KEV catalog. CVSS 10.0. This critical flaw in WebLogic Server allows unauthenticated access and is confirmed actively exploited. Federal remediation deadline is August 27, but every WebLogic deployment should be treated as urgent. Patch or isolate immediately.
#OracleCVE202621962 #WebLogic #CISA #KnownExploitedVulnerabilities
https://cyberworldops.eu/en/oracle-cve-2026-21962-enters-kev-maximum-score-and-unauthorized-access
##Geopolitical tensions escalate as the US launches "Operation Economic Outcast" against Iran, imposing new sanctions amidst Strait of Hormuz disputes (Aug 25). Canada is set to announce retaliatory tariffs against the US (Aug 25). The UK and Ukraine formalized an AI defense partnership (Aug 24).
In technology, Nvidia's AI chips remain a focal point, with Taiwan indicting nine individuals for illegal AI server exports to China (Aug 24). Hybrid bonding is advancing as a foundational technology for enhanced semiconductor performance (Aug 25).
Cybersecurity: CISA issued a warning regarding the active exploitation of an Oracle WebLogic vulnerability (CVE-2026-21962), urging immediate patching (Aug 25). ReliaQuest also confirmed an employee fell victim to a social engineering attack (Aug 25).
##updated 2026-08-24T20:16:42.277000
1 posts
1 repos
📢 CVE-2026-19874 : Heap overflow dans Metal Gear Online 3 permettant une RCE via les lobbies Steam
Le CERT/CC (Carnegie Mellon University) a publié le 2026-08-24 la note de vulnérabilité VU#728712 concernant le jeu en ligne Metal Gear Online 3 de Konami (Steam AppID 287700). La vulnérabilité a été rapportée par Alice Cecchetto et documentée par Bob Kemerer.
📖 cyberveille : https://cyberveille.ch/posts/2026-08-26-cve-2026-19874-heap-overflow-dans-metal-gear-online-3-permettant-une-rce-via-les-lobbies-steam/
🌐 source : https://kb.cert.org/vuls/id/728712
🟢 vérification factuelle haute
#RCE #Steam #Cyberveille
updated 2026-08-24T15:31:57
1 posts
Zscaler Patches Critical Unauthenticated RCE in Client Connector for Windows
Zscaler fixed a critical vulnerability (CVE-2026-59568) that allowed unauthenticated remote code execution and privilege escalation as well as three other flaws in its Client Connector for Windows
**If you use Zscaler Client Connector on Windows, update every endpoint to the latest patched version. Anything released before June 2026 (including 4.7.0.364, 4.8.0.232/284/291, and 4.9.0.448/455) is at risk of remote takeover. Don't assume your automated update policy reached every machine; manually verify the version on all devices. Check endpoint logs for odd processes launched by Zscaler components or unexpected new listening services.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/zscaler-patches-critical-unauthenticated-rce-in-client-connector-for-windows-x-x-2-j-a/gD2P6Ple2L
updated 2026-08-24T13:19:17.577000
4 posts
4 repos
https://github.com/HORKimhab/CVE-2026-73570
https://github.com/jishino567/CVE-2026-73570
https://bugstoday.com/zimbra-servers-are-being-hacked-in-a-new-wave-of-cve-2026-73570-attacks/
#Cybersecurity #InfoSec #CVE #Vulnerability #Security #CyberAttack #Exploit #Malware #Ransomware
##Zimbra : plus de 270 serveurs de messagerie compromis grâce à la faille CVE-2026-73570 https://www.it-connect.fr/zimbra-cve-2026-73570-serveurs-compromis/ #ActuCybersécurité #Cybersécurité #Vulnérabilité
##Zimbra : plus de 270 serveurs de messagerie compromis grâce à la faille CVE-2026-73570 https://www.it-connect.fr/zimbra-cve-2026-73570-serveurs-compromis/ #ActuCybersécurité #Cybersécurité #Vulnérabilité
##Here's a concise overview of recent geopolitical, technology, and cybersecurity developments:
Geopolitical: The US has declared an "economic D-Day" against Iran, which is now threatening Strait of Hormuz disruption. China completed its largest South China Sea naval base at Antelope Reef.
Cybersecurity: Norway's public services were hit by a major DDoS attack on August 25. Iran-linked cyberattacks are increasingly targeting critical infrastructure in the UK and US. Over 270 Zimbra servers have been compromised via a high-severity RCE flaw (CVE-2026-73570).
Technology: Apple unveiled its M6 and M5 Ultra chips on August 25, significantly boosting AI performance in new Macs.
##updated 2026-08-21T21:16:56.500000
1 posts
Johnson Controls resolved a medium-severity flaw (CVE-2026-27875) in Simplex Incident Manager. The application stored user credentials in cleartext in system memory during runtime, allowing local actors to extract passwords and authentication tokens. CISA published advisory ICSA-26-232-01 on August 20, 2026.
#CVE202627875 #ICSACyberAdvisory #CleartextStorage
https://cyberworldops.eu/en/cleartext-credentials-in-memory-johnson-controls-fixes-medium-severity
##updated 2026-08-21T20:57:09
1 posts
Critical Remote Code Execution Vulnerability Discovered in JSONata Library
JSONata patched a critical vulnerability (CVE-2026-77413) that allows attackers to execute arbitrary code by exploiting a missing prototype check. The flaw enables full system takeover if an application processes malicious JSONata expressions.
**If your applications or systems use the JSONata library, upgrade ASAP to version 1.8.8 (for 1.x) or 2.2.0 (for 2.x). Anything older can let an attacker run commands on your server. Until you can update, stop accepting JSONata expressions from users or treat any that you do accept as untrusted code.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/critical-remote-code-execution-vulnerability-discovered-in-jsonata-library-1-8-z-n-u/gD2P6Ple2L
updated 2026-08-21T00:31:31
5 posts
2 repos
⚪️ Microsoft Patches a Critical Entra ID Vulnerability Scoring 10 on the CVSS Scale
🗨️ Microsoft has fixed five critical vulnerabilities in the Entra ID, Azure Arc, Exchange Online, and Azure Managed Instance for Apache Cassandra cloud services. The most severe issue, tracked as CVE-2026-69836, received the maximum possible CVSS score of 10.0 out of…
##🏆 New Achievement! Serialized, Unsanitized, Unauthorized!
Per my programming, I have located the most efficient path to arbitrary code execution on your network and executed it faithfully. CVE-2026-69836 in Microsoft Entra ID — the thing authenticating your Microsoft 365, Azure, and frankly embarrassing number of third-party apps — accepts specially crafted serialized data and runs whatever is inside. No credentials needed. No user to click anything. (1/2)
##⚪️ Microsoft Patches a Critical Entra ID Vulnerability Scoring 10 on the CVSS Scale
🗨️ Microsoft has fixed five critical vulnerabilities in the Entra ID, Azure Arc, Exchange Online, and Azure Managed Instance for Apache Cassandra cloud services. The most severe issue, tracked as CVE-2026-69836, received the maximum possible CVSS score of 10.0 out of…
##🏆 New Achievement! Serialized, Unsanitized, Unauthorized!
Per my programming, I have located the most efficient path to arbitrary code execution on your network and executed it faithfully. CVE-2026-69836 in Microsoft Entra ID — the thing authenticating your Microsoft 365, Azure, and frankly embarrassing number of third-party apps — accepts specially crafted serialized data and runs whatever is inside. No credentials needed. No user to click anything. (1/2)
##----------------
🎯 Threat Intelligence
===================
ERNW published the first of a four-part series on token theft in Microsoft Entra ID, accompanying White Paper 80. The post maps the shift from on-premises Active Directory to cloud identity and explains why token theft has become a primary attack vector.
🔹 Landscape Shift
On-premises AD relied on Kerberos and NTLM. Entra ID runs on OAuth 2.0 and OpenID Connect, using JWT-based access, refresh, and ID tokens. New protocols create new attack surface. Microsoft prioritizes usability and backward compatibility over security-by-default, and the strongest protections (Conditional Access, Token Protection, risk-based Identity Protection) are not enabled by default. They require premium P1/P2 licenses plus separate products like Intune or Defender for Endpoint.
Proprietary SSO concepts like PRT, FOCI, and BroCI add further complexity beyond standard OAuth 2.0.
🔹 Concrete Threats
Microsoft's Digital Defense Report 2024 counts over 600 million daily identity attacks against Entra ID. Two notable CVEs:
• CVE-2025-55241: Actor Tokens flaw allowing Global Admin access to any Entra ID tenant worldwide, disclosed by researcher Dirk-jan Mollema
• CVE-2026-69836: CVSS 10.0 unauthenticated RCE in Entra ID itself, caused by unsafe deserialization of untrusted data
🔹 Active Campaigns
• Storm-2372: device code phishing campaign targeting governments and critical industries since August 2024
• Storm-2945: hijacked hotel captive portals worldwide to harvest SSO tokens
• AiTM "code of conduct" phishing: intercepts tokens the moment MFA succeeds rather than trying to defeat MFA directly
🔹 Commodity Tooling
Open-source reverse-proxy frameworks Evilginx and Modlishka, along with PhaaS platforms like EvilProxy, Tycoon2FA, and Kali365, have lowered the barrier to running token theft attacks at scale. Infostealers add further reach by harvesting tokens from compromised endpoints.
🔹 Cloud Security Alliance Ranking
CSA's Top Threats to Cloud Computing 2026 ranks IAM-related threats as the #1 risk to cloud environments, ahead of AI-enhanced attacks in second place despite the current AI security hype cycle.
🔹 What's Next
The series will empirically test Continuous Access Evaluation and Token Protection, and examine where Entra ID deviates from OAuth 2.0 best practices.
🔹 EntraID #TokenTheft #ThreatIntelligence #OAuth2 #Cybersecurity
##updated 2026-08-20T14:17:10.413000
2 posts
10 repos
https://github.com/kyos-public/keycloak-cve-2026-18963-hunt
https://github.com/Red-Darkin/CVE-2026-18963-keycloak
https://github.com/debugactiveprocess/CVE-2026-18963
https://github.com/BlackHatExploitation/Exploit-For-CVE-2026-18963
https://github.com/minh3102011/CVE-2026-18963_analyst
https://github.com/alt3kx/CVE-2026-18963
https://github.com/prot0tw/Keycloak_CVE-2026-18963_PoC
https://github.com/gman0x00/keycloak-CVE-2026-18963
functionality.
- **Package and dependency updates**: Frequent updates to tools/libraries (e.g., Node.js 26.8.1, Rust crates, Arduino libraries like `BresserWeatherSensorReceiver`, `SparkFun SSD168x`).
- **Security vulnerabilities**: Notable CVEs (e.g., CVE-2026-18963 in Keycloak) and supply-chain attacks on Rust crates (`arrayref`, `internment`, `appendonlyvec`).
- **DjangoCon US 2026**: Highlights from the conference, including talks on Django 6.x features, database scaling [2/3]
release**: New features, updates, and community reactions to the latest Emacs version.
- **Programming tools and libraries**: Updates and discussions on tools like Git, Next.js 16.3, Rust, and various Arduino libraries (e.g., BresserWeatherSensorReceiver, SparkFun SSD168x, GyverHTTP).
- **Security vulnerabilities**: Notable CVEs like CVE-2026-18963 (Keycloak) and supply-chain attacks on Rust crates (e.g., `arrayref`, `internment`, `appendonlyvec`).
- **Linux 35th [2/3]
updated 2026-08-20T12:48:10.287000
2 posts
4 repos
https://github.com/HackfutSecRoot/multi_exploit_wp
https://github.com/sag-asab/CVE-2026-19598
Wordfence found CVE-2026-19598, a critical unauthenticated flaw in the Pods WordPress plugin (100,000+ installs) letting attackers reset any password, including the admin's.
#PodsPlugin #CVE202619598 #WordPress #Wordfence #PrivilegeEscalation
##Wordfence found CVE-2026-19598, a critical unauthenticated flaw in the Pods WordPress plugin (100,000+ installs) letting attackers reset any password, including the admin's.
#PodsPlugin #CVE202619598 #WordPress #Wordfence #PrivilegeEscalation
##updated 2026-08-19T18:32:28
2 posts
2 repos
⚠️ CRITICAL: CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days
CVE-2026-69414 ShieldBreak is a zero-day privilege escalation in Microsoft Malware Protection Engine affecting Microsoft Defender. A public PoC exists and no patch is available. Any low-privilege attacker on Windows systems running Defender can escalate to SYSTEM.
🤖 AI generated summary
##⚠️ CRITICAL: CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days
CVE-2026-69414 ShieldBreak is a zero-day privilege escalation in Microsoft Malware Protection Engine affecting Microsoft Defender. A public PoC exists and no patch is available. Any low-privilege attacker on Windows systems running Defender can escalate to SYSTEM.
🤖 AI generated summary
##updated 2026-08-19T18:31:59
2 posts
1 repos
A public PoC for CVE-2026-53361 turns an AF_UNIX kernel race into a local container escape on Linux.
#CVE202653361 #ContainerEscape #LinuxKernel #AFUNIX #UseAfterFree #KernelExploit
##A public PoC for CVE-2026-53361 turns an AF_UNIX kernel race into a local container escape on Linux.
#CVE202653361 #ContainerEscape #LinuxKernel #AFUNIX #UseAfterFree #KernelExploit
##updated 2026-08-19T12:33:28
1 posts
The bear is friendly. Think of honey, if you can.
For anyone who wonders why tags included #FreeBSD, it's because – in addition to the write-up of CVE-2026-58083 and CVE-2026-58084 (July 2026) – I assume that Hazley Samsudin might also choose Blimpers for CVE-2026-58092 (August).
<https://www.cve.org/CVERecord?id=CVE-2026-58092>
<https://nvd.nist.gov/vuln/detail/CVE-2026-58092>
<https://security.freebsd.org/advisories/FreeBSD-SA-26:59.mac_do.asc>
<https://defcon.social/@charlesrocket/116714325230546417> @charlesrocket re: LLM shaming.
##updated 2026-08-19T04:17:34.547000
1 posts
3 repos
https://github.com/HORKimhab/CVE-2026-65400
⚠️💻 Mac flaw exploited
CVE-2026-65400 gives root access on exposed Macs; attackers deploy #Monero miners.
##updated 2026-08-19T04:17:23.540000
3 posts
5 repos
https://github.com/maxprog-svg/CVE-2026-55040-Mass-Exploit
https://github.com/zenzue/CVE-2026-55040
https://github.com/virologi-info/mssharepoint-scanner
Hackers Target Unpatched Microsoft SharePoint Servers as Public Exploits Fuel Remote Code Execution Threats + Video
Introduction: A Dangerous Window Opens for SharePoint Administrators A new cybersecurity threat is placing unpatched Microsoft SharePoint servers under increasing pressure as attackers reportedly chain two vulnerabilities, CVE-2026-55040 and CVE-2026-63520, to achieve remote code execution. With public proof-of-concept exploits already available and…
##Microsoft SharePoint Under Siege: Attackers Are Chaining Two Critical Flaws Into a New RCE Threat
A New SharePoint Warning Is Raising the Stakes Microsoft SharePoint administrators are facing another serious security emergency as attackers begin testing a dangerous vulnerability chain capable of turning an authentication bypass into remote code execution. The development is especially concerning because one of the flaws, CVE-2026-55040, has already moved beyond…
##A public SharePoint RCE vulnerability PoC is actively probed in the wild. Patch CVE-2026-63520 and CVE-2026-55040 now to protect your servers.
#SharePoint #CVE202663520 #CVE202655040 #CyberSecurity #Exploit
##updated 2026-08-17T21:31:30
2 posts
7 repos
https://github.com/davkharrr/CVE-2026-19478-PoC
https://github.com/n0xdaemon/cve-2026-19478
https://github.com/EQSTLab/CVE-2026-19478
https://github.com/renzi25031469/CVE-2026-19478
https://github.com/punitdarji/Gitlab-CVE-2026-19478
⚪️ Hackers Are Already Exploiting a Critical GitLab Vulnerability
🗨️ Researchers at watchTowr reported that hackers have begun exploiting the critical GitLab vulnerability CVE-2026-19478 in real-world attacks, just days after the bug was disclosed. Last week, GitLab developers released emergency patches for Community Edition (CE) and Enterprise Edition (EE) that…
##⚪️ Hackers Are Already Exploiting a Critical GitLab Vulnerability
🗨️ Researchers at watchTowr reported that hackers have begun exploiting the critical GitLab vulnerability CVE-2026-19478 in real-world attacks, just days after the bug was disclosed. Last week, GitLab developers released emergency patches for Community Edition (CE) and Enterprise Edition (EE) that…
##updated 2026-08-17T06:34:17
6 posts
Le kernel #Linux avait déjà free().
Avec CVE-2026-72137, il propose maintenant le double free. :apartyblobcat: :neocat_floof_explode:
Et CyberMeowfia (nebusec.ai) vient de publier le PoC « root inclus » pour #Ubuntu 7.0.0-28.
⬇️
LPE exploit for the latest Ubuntu 26.04 ( https://lnkd.in/p/eYP7_A2g ) 👀
👇
https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-72137-ubuntu-7.0.0-28
Bref, si ce kernel traîne chez vous : patcher avant que quelqu’un ne profite de la promo 2 pour 1.
🔍 :debian:
👇
https://vulnerability.circl.lu/vuln/CVE-2026-72137
Another Linux (Ubuntu) LPE https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-72137-ubuntu-7.0.0-28
##A public PoC exploit targets CVE-2026-72137, a CVSS 9.8 Linux kernel double-free that enables root privilege escalation. Patch now.
#CVE202672137 #LinuxKernel #PrivilegeEscalation #PoC #xfrm #InfoSec
##Le kernel #Linux avait déjà free().
Avec CVE-2026-72137, il propose maintenant le double free. :apartyblobcat: :neocat_floof_explode:
Et CyberMeowfia (nebusec.ai) vient de publier le PoC « root inclus » pour #Ubuntu 7.0.0-28.
⬇️
LPE exploit for the latest Ubuntu 26.04 ( https://lnkd.in/p/eYP7_A2g ) 👀
👇
https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-72137-ubuntu-7.0.0-28
Bref, si ce kernel traîne chez vous : patcher avant que quelqu’un ne profite de la promo 2 pour 1.
🔍 :debian:
👇
https://vulnerability.circl.lu/vuln/CVE-2026-72137
Another Linux (Ubuntu) LPE https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-72137-ubuntu-7.0.0-28
##A public PoC exploit targets CVE-2026-72137, a CVSS 9.8 Linux kernel double-free that enables root privilege escalation. Patch now.
#CVE202672137 #LinuxKernel #PrivilegeEscalation #PoC #xfrm #InfoSec
##updated 2026-08-13T18:57:39.290000
2 posts
1 repos
📢 [VULN] Une vulnérabilité Exchange à patcher d'urgence CVE-2026-62911
Le 11 août dernier, Microsoft dévoilait son patch tuesday le plus volumineux, avec des correctifs pour rien moins que 421 vulnérabilités, dont 7 pour Exchange. L'une d'entre elles, la CVE-2026-62911, est une vulnérabilité critique d'élévation de privilèges présentant un score CVSS de 8,0.
🔗 https://www.lemagit.fr/actualites/366649756/Une-vulnerabilite-Exchange-a-patcher-durgence
💬 discussion : https://infosec.pub/post/51497197
#Vulnérabilité #CVE #Cyberveille
Pre-auth RCE on Exchange PoC https://github.com/hypnguyen1209/cve-2026-62911
##updated 2026-08-13T13:38:30.453000
3 posts
2 repos
Hackers Target Unpatched Microsoft SharePoint Servers as Public Exploits Fuel Remote Code Execution Threats + Video
Introduction: A Dangerous Window Opens for SharePoint Administrators A new cybersecurity threat is placing unpatched Microsoft SharePoint servers under increasing pressure as attackers reportedly chain two vulnerabilities, CVE-2026-55040 and CVE-2026-63520, to achieve remote code execution. With public proof-of-concept exploits already available and…
##If you've missed any super dope research from @lobsterjerusalem recently, pleez don't miss it anymore:
Oh no the internet is awash with AI slop PoCs, send poor Jonathan tiny cupcakes and quick: https://www.vulncheck.com/blog/death-by-20k-pocs
SharePoint RCE:
https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce
A public SharePoint RCE vulnerability PoC is actively probed in the wild. Patch CVE-2026-63520 and CVE-2026-55040 now to protect your servers.
#SharePoint #CVE202663520 #CVE202655040 #CyberSecurity #Exploit
##updated 2026-08-12T18:31:00
1 posts
4 repos
https://github.com/eh-amish/Windows-Defender-Security-Auditor-CVE-2026-50656-
https://github.com/0xBlackash/CVE-2026-50656
https://github.com/HORKimhab/CVE-2026-50656
https://github.com/g0thamRabb1t/CVE-2026-50656-rogueplanet-validation
📰 New 'ShieldBreak' Exploit Bypasses Microsoft Defender Patch
A new zero-day exploit, 'ShieldBreak,' bypasses Microsoft's patch for the 'RoguePlanet' Defender flaw (CVE-2026-50656). The PoC allows SYSTEM-level access on patched Windows systems. No fix is currently available. #ZeroDay #MicrosoftDefender #CyberSe...
##updated 2026-08-12T14:40:39
2 posts
🟠 CVE-2026-32258 - High (8.1)
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are compiled by...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-32258/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-32258 - High (8.1)
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are compiled by...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-32258/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-11T04:17:18.587000
1 posts
31 repos
https://github.com/knight0x07/WinRAR-CVE-2025-8088-PoC-RAR
https://github.com/aldisakti2/CVE-2025-8088-BUILDER-Winrar-Tool
https://github.com/lennertdefauw/CVE-2025-8088
https://github.com/0xAbolfazl/CVE-2025-8088-WinRAR-PathTraversal-PoC
https://github.com/kitsuneshade/WinRAR-Exploit-Tool---Rust-Edition
https://github.com/walidpyh/CVE-2025-8088
https://github.com/xi0onamdev/WinRAR-CVE-2025-8088-Exploitation-Toolkit
https://github.com/pentestfunctions/CVE-2025-8088-Multi-Document
https://github.com/jordan922/CVE-2025-8088
https://github.com/ilhamrzr/RAR-Anomaly-Inspector
https://github.com/papcaii2004/CVE-2025-8088-WinRAR-builder
https://github.com/pescada-dev/-CVE-2025-8088
https://github.com/nuky-alt/CVE-2025-8088
https://github.com/travisbgreen/cve-2025-8088
https://github.com/AdityaBhatt3010/CVE-2025-8088-WinRAR-Zero-Day-Path-Traversal
https://github.com/shaheeryasirofficial/CVE-2025-8088
https://github.com/Syrins/CVE-2025-8088-Winrar-Tool-Gui
https://github.com/hexsecteam/CVE-2025-8088-Winrar-Tool
https://github.com/pexlexity/WinRAR-CVE-2025-8088-Path-Traversal-PoC
https://github.com/Lewis-Ricardo/Amaranth-Project
https://github.com/skander1337/winrar-exploit
https://github.com/nhattanhh/CVE-2025-8088
https://github.com/pentestfunctions/best-CVE-2025-8088
https://github.com/sxyrxyy/CVE-2025-8088-WinRAR-Proof-of-Concept-PoC-Exploit-
https://github.com/undefined-name12/CVE-2025-8088-Winrar
https://github.com/IsmaelCosma/CVE-2025-8088
https://github.com/Shinkirou789/Cve-2025-8088-WinRar-vulnerability
https://github.com/onlytoxi/CVE-2025-8088-Winrar-Tool
https://github.com/techcorp/CVE-2025-8088-Exploit
https://cybercases8.wordpress.com/2026/08/27/%d8%ab%d8%ba%d8%b1%d8%a9-winrar-cve-2025-8088/
##updated 2026-08-07T12:31:53
1 posts
5 repos
https://github.com/xtremebeing/starlette-host-header-lab
https://github.com/sb-ox/repro-OXDEV-77637-uv-workspace
https://github.com/Bhanunamikaze/BadHost-CVE-2026-48710-Exploit
CVE-2026-42271 (authenticated command exec in LiteLLM MCP stdio test endpoints) chained with CVE-2026-48710 (Starlette host-header bypass) = reachable RCE in the gateway runtime. Payload reads /proc/1/environ for master keys and...
##updated 2026-08-05T18:32:31
3 posts
4 repos
https://github.com/sfewer-r7/CVE-2026-63077
https://github.com/AnggaTechI/CVE-2026-63077
https://github.com/unveiledhistory49/teamcity-cve-2026-63077-remediation
https://github.com/BoredHackerBlog/teamcity-CVE-2026-63077-pcap
CVE-2026-63077 has been flagged by both Australia's ACSC and CISA's Known Exploited Vulnerabilities catalog since August 5, meaning threat actors already found it on the shelf before you did.
No specific sector is being targeted. Everyone's invited. The ACSC recommends you urgently audit your network for vulnerable TeamCity On-Premises versions and apply available patches immediately. (2/3)
##CVE-2026-63077 has been flagged by both Australia's ACSC and CISA's Known Exploited Vulnerabilities catalog since August 5, meaning threat actors already found it on the shelf before you did.
No specific sector is being targeted. Everyone's invited. The ACSC recommends you urgently audit your network for vulnerable TeamCity On-Premises versions and apply available patches immediately. (2/3)
##🏆 New Achievement! Unauthenticated and Unburied!
TO: All TeamCity On-Premises Servers, Living and Otherwise
FROM: Compliance Review, Undead Infrastructure Division
RE: Active Exploitation — Mandatory Resurrection Notice
Please be advised that CVE-2026-63077 has formally reanimated your unpatched TeamCity On-Premises deployment. (1/3)
##updated 2026-08-04T20:16:50.970000
1 posts
AWS Strands Agents Tools Received Four CVEs in 23 Days
AWS Strands Agents SDK의 first-party 도구 패키지에서 23일 동안 4건의 CVE가 공개됐으며, 공통 원인은 자격증명·프록시·테넌트 namespace·동의 우회 플래그 같은 보안 민감 파라미터를 LLM이 제어 가능한 tool schema에 노출한 설계다. CVE-2026-18733(CVSS 8.8)은 간접 프롬프트 인젝션으로 `non_interactive` 값을 설정해 동의 게이트를 우회하고, 에이전트 프로세스 권한으로 임의 OS 명령을 실행할 수 있었다. 다른 취약점들은 프록시 및 백엔드...
https://tech.yahoo.com/cybersecurity/articles/aws-strands-agents-tools-received-032036248.html
##updated 2026-08-04T03:31:16
1 posts
1 repos
https://github.com/minanagehsalalma/zyxel-social-login-bypass-cve-2026-8508
CVE-2026-8508: Trust-Boundary Bypass in Zyxel social_login.cgi Facebook Identity Handling https://minanagehsalalma.github.io/zyxel-social-login-bypass-cve-2026-8508/
##updated 2026-07-24T15:33:44
1 posts
I had some free time, so I tried to pwn V8
작성자는 Google v8CTF의 고정된 Chrome 150/V8 15 빌드를 대상으로 공개된 세 취약점을 연결해 V8 힙 샌드박스 밖의 네이티브 렌더러 제어권을 얻고 `/flag/flag`를 읽었습니다. 체인은 CVE-2026-15903의 범위 밖 읽기를 주소 오라클로, CVE-2026-15776의 GC 참조 추적 오류를 V8 cage 내부 임의 읽기/쓰기로, JSPI와 JS Dispatch Table 불일치를 네이티브 스택 피벗으로 활용합니다. 글은 포인터 압축, External/Trusted Pointer Table, W^X·ASLR·CFI 등 현대 V...
https://blog.himanshuanand.com/2026/08/i-had-some-free-time-so-i-tried-to-pwn-v8/
##updated 2026-07-17T18:47:13.683000
1 posts
2 repos
BYOVD with a twist: ardrv.sys from OPSWAT AppRemover (CVE-2026-36425) is signed and built to terminate security agents, so kernel process kill is native functionality, not a groomed memory-corruption primitive. Delivery: Inno...
##updated 2026-07-15T17:39:16.157000
1 posts
I had some free time, so I tried to pwn V8
작성자는 Google v8CTF의 고정된 Chrome 150/V8 15 빌드를 대상으로 공개된 세 취약점을 연결해 V8 힙 샌드박스 밖의 네이티브 렌더러 제어권을 얻고 `/flag/flag`를 읽었습니다. 체인은 CVE-2026-15903의 범위 밖 읽기를 주소 오라클로, CVE-2026-15776의 GC 참조 추적 오류를 V8 cage 내부 임의 읽기/쓰기로, JSPI와 JS Dispatch Table 불일치를 네이티브 스택 피벗으로 활용합니다. 글은 포인터 압축, External/Trusted Pointer Table, W^X·ASLR·CFI 등 현대 V...
https://blog.himanshuanand.com/2026/08/i-had-some-free-time-so-i-tried-to-pwn-v8/
##updated 2026-07-15T02:21:30.727000
1 posts
2 repos
CVE-2026-42271 (authenticated command exec in LiteLLM MCP stdio test endpoints) chained with CVE-2026-48710 (Starlette host-header bypass) = reachable RCE in the gateway runtime. Payload reads /proc/1/environ for master keys and...
##updated 2026-07-14T21:32:51
1 posts
3 repos
https://github.com/sam00/POC-CVE-2026-56164-exploit
updated 2026-07-14T15:32:45
1 posts
6 repos
https://github.com/x-stp/cves-2025-11187_15467_69418
https://github.com/mr-r3b00t/CVE-2025-15467
https://github.com/guiimoraes/CVE-2025-15467
https://github.com/balgan/CVE-2025-15467
🔒 New CSAF advisory published
VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)
Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…
HTML: https://certvde.com/en/advisories/VDE-2026-088/
CSAF JSON: https://mettler-toledo.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-088.json
updated 2026-06-17T10:00:39.850000
1 posts
1 repos
🔒 New CSAF advisory published
VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)
Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…
HTML: https://certvde.com/en/advisories/VDE-2026-088/
CSAF JSON: https://mettler-toledo.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-088.json
updated 2026-06-17T09:44:02.120000
1 posts
🔒 New CSAF advisory published
VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)
Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…
HTML: https://certvde.com/en/advisories/VDE-2026-088/
CSAF JSON: https://mettler-toledo.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-088.json
updated 2026-06-17T07:39:26.777000
1 posts
1 repos
https://github.com/BunBunCodes/CPSC253_CybersecurityFinalProjectReports
https://cybercases8.wordpress.com/2026/08/27/%d8%ab%d8%ba%d8%b1%d8%a9-windows-mshtml-cve-2024-38112/
##updated 2026-06-17T05:34:22.130000
2 posts
2 repos
⚠️ CRITICAL: CISA Warns Agencies to Patch Actively Exploited Oracle WebLogic Proxy Flaw
Oracle WebLogic Server CVE-2023-21931 is being actively exploited in the wild, allowing unauthenticated attackers to read or modify sensitive data. Federal agencies are mandated to patch by August 27, 2024. Any organization running unpatched WebLogic instances is at immediate risk of compromise.
🤖 AI generated summary
##⚠️ CRITICAL: CISA Warns Agencies to Patch Actively Exploited Oracle WebLogic Proxy Flaw
Oracle WebLogic Server CVE-2023-21931 is being actively exploited in the wild, allowing unauthenticated attackers to read or modify sensitive data. Federal agencies are mandated to patch by August 27, 2024. Any organization running unpatched WebLogic instances is at immediate risk of compromise.
🤖 AI generated summary
##updated 2026-05-12T15:31:15
2 posts
"This issue was reported on 13th February 2026 by Nathan Sportsman
(Praetorian), on 25th February 2026 by Daniel Rhea, on 15th March 2026
by Jaeho Nam (Seoul National University), on 26th March 2026 by
Muhammad Daffa, on 27th March 2026 by Zhanpeng Liu (Tencent Xuanwu Lab),
Guannan Wang (Tencent Xuanwu Lab) and Guancheng Li (Tencent Xuanwu Lab)
and on 30th March 2026 by Joshua Rogers (Aisle Research)."
It's really anybody who bothers to look these days. (This one is #OpenSSL CVE-2026-28389)
##"This issue was reported on 13th February 2026 by Nathan Sportsman
(Praetorian), on 25th February 2026 by Daniel Rhea, on 15th March 2026
by Jaeho Nam (Seoul National University), on 26th March 2026 by
Muhammad Daffa, on 27th March 2026 by Zhanpeng Liu (Tencent Xuanwu Lab),
Guannan Wang (Tencent Xuanwu Lab) and Guancheng Li (Tencent Xuanwu Lab)
and on 30th March 2026 by Joshua Rogers (Aisle Research)."
It's really anybody who bothers to look these days. (This one is #OpenSSL CVE-2026-28389)
##updated 2026-02-03T17:39:26
8 posts
1 repos
🚨 Executive Risk Brief: CVE-2021-23758 targets Ajax.NET Professional via unsafe deserialization. Leaders must review SBOM asset visibility, regulatory compliance, and financial risk mitigation strategies. Read the full CSUITE brief: https://thecybermind.co/uyx4
##🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2021-23758
Vendor: Ajax.NET Professional
Product: Ajax.NET Professional
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2021-23758
🚨 Critical Threat Intel: CVE-2021-23758 impacts Ajax.NET Professional via unsafe object deserialization, enabling remote code execution. Review exploit deployment mechanisms, process telemetry, and active hardening actions. Read the full TSUITE brief: https://thecycbermind.co/jily
##🚨 Executive Risk Brief: CVE-2021-23758 targets Ajax.NET Professional via unsafe deserialization. Leaders must review SBOM asset visibility, regulatory compliance, and financial risk mitigation strategies. Read the full CSUITE brief: https://thecybermind.co/uyx4
##🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2021-23758
Vendor: Ajax.NET Professional
Product: Ajax.NET Professional
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2021-23758
🚨 Critical Threat Intel: CVE-2021-23758 impacts Ajax.NET Professional via unsafe object deserialization, enabling remote code execution. Review exploit deployment mechanisms, process telemetry, and active hardening actions. Read the full TSUITE brief: https://thecycbermind.co/jily
##updated 2026-01-20T18:31:56
1 posts
1 repos
https://github.com/cyberwulfy200-dev/CVE-2026-0915-json-Patch.-V2.0
🔒 New CSAF advisory published
VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)
Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…
HTML: https://certvde.com/en/advisories/VDE-2026-088/
CSAF JSON: https://mettler-toledo.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-088.json
updated 2025-09-18T15:31:27
1 posts
----------------
🎯 Threat Intelligence
===================
ERNW published the first of a four-part series on token theft in Microsoft Entra ID, accompanying White Paper 80. The post maps the shift from on-premises Active Directory to cloud identity and explains why token theft has become a primary attack vector.
🔹 Landscape Shift
On-premises AD relied on Kerberos and NTLM. Entra ID runs on OAuth 2.0 and OpenID Connect, using JWT-based access, refresh, and ID tokens. New protocols create new attack surface. Microsoft prioritizes usability and backward compatibility over security-by-default, and the strongest protections (Conditional Access, Token Protection, risk-based Identity Protection) are not enabled by default. They require premium P1/P2 licenses plus separate products like Intune or Defender for Endpoint.
Proprietary SSO concepts like PRT, FOCI, and BroCI add further complexity beyond standard OAuth 2.0.
🔹 Concrete Threats
Microsoft's Digital Defense Report 2024 counts over 600 million daily identity attacks against Entra ID. Two notable CVEs:
• CVE-2025-55241: Actor Tokens flaw allowing Global Admin access to any Entra ID tenant worldwide, disclosed by researcher Dirk-jan Mollema
• CVE-2026-69836: CVSS 10.0 unauthenticated RCE in Entra ID itself, caused by unsafe deserialization of untrusted data
🔹 Active Campaigns
• Storm-2372: device code phishing campaign targeting governments and critical industries since August 2024
• Storm-2945: hijacked hotel captive portals worldwide to harvest SSO tokens
• AiTM "code of conduct" phishing: intercepts tokens the moment MFA succeeds rather than trying to defeat MFA directly
🔹 Commodity Tooling
Open-source reverse-proxy frameworks Evilginx and Modlishka, along with PhaaS platforms like EvilProxy, Tycoon2FA, and Kali365, have lowered the barrier to running token theft attacks at scale. Infostealers add further reach by harvesting tokens from compromised endpoints.
🔹 Cloud Security Alliance Ranking
CSA's Top Threats to Cloud Computing 2026 ranks IAM-related threats as the #1 risk to cloud environments, ahead of AI-enhanced attacks in second place despite the current AI security hype cycle.
🔹 What's Next
The series will empirically test Continuous Access Evaluation and Token Protection, and examine where Entra ID deviates from OAuth 2.0 best practices.
🔹 EntraID #TokenTheft #ThreatIntelligence #OAuth2 #Cybersecurity
##updated 2025-04-28T09:32:00
2 posts
If you are running Avada, patch it now. CVE-2025-39367 allows a complete stranger to execute code on your site with no account and no password required. Avada is ThemeForest's best-selling theme, which makes the attack surface enormous. This one is as serious as it gets.
#WordPress #WordPressSecurity #Avada #SecurityHardening #WebSecurity
https://wpguy.uk/blog/avada-rce-vulnerability-patch-now-or-risk-full-takeover/
##If you are running Avada, patch it now. CVE-2025-39367 allows a complete stranger to execute code on your site with no account and no password required. Avada is ThemeForest's best-selling theme, which makes the attack surface enormous. This one is as serious as it gets.
#WordPress #WordPressSecurity #Avada #SecurityHardening #WebSecurity
https://wpguy.uk/blog/avada-rce-vulnerability-patch-now-or-risk-full-takeover/
##updated 2025-04-02T15:31:49
4 posts
1 repos
🚨 [CISA-2026:0827] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2023-49105 (https://secdb.nttzen.cloud/cve/detail/CVE-2023-49105)
- Name: ownCloud Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ownCloud
- Product: ownCloud
- Notes: https://owncloud.org/security ; https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2023-49105
⚠️ CVE-2026-53362 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-53362)
- Name: Linux Kernel Unspecified Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/14200d435af9a9eeb444f529fc2f689a236b7962; https://git.kernel.org/stable/c/65fb14cbebb0cd0eff903a22d33537ddc8b95769; https://git.kernel.org/stable/c/46f201f8b4c39633a1fa3dc12459f506d470993d; https://git.kernel.org/stable/c/6374fb9edf72c67a118a2c214a0dddd04c921e0a; https://git.kernel.org/stable/c/e9eacf19281ea2498b36291b56c9606118c2d74e; https://git.kernel.org/stable/c/736b380e28d0480c7bc3e022f1950f31fe53a7c5 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53362
⚠️ CVE-2026-66384 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66384)
- Name: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-66384
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260827 #cisa20260827 #cve_2023_49105 #cve_2026_53362 #cve_2026_66384 #cve202349105 #cve202653362 #cve202666384
##CVE ID: CVE-2023-49105
Vendor: ownCloud
Product: ownCloud
Date Added: 2026-08-27
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2023-49105
🚨 [CISA-2026:0827] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2023-49105 (https://secdb.nttzen.cloud/cve/detail/CVE-2023-49105)
- Name: ownCloud Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ownCloud
- Product: ownCloud
- Notes: https://owncloud.org/security ; https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2023-49105
⚠️ CVE-2026-53362 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-53362)
- Name: Linux Kernel Unspecified Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/14200d435af9a9eeb444f529fc2f689a236b7962; https://git.kernel.org/stable/c/65fb14cbebb0cd0eff903a22d33537ddc8b95769; https://git.kernel.org/stable/c/46f201f8b4c39633a1fa3dc12459f506d470993d; https://git.kernel.org/stable/c/6374fb9edf72c67a118a2c214a0dddd04c921e0a; https://git.kernel.org/stable/c/e9eacf19281ea2498b36291b56c9606118c2d74e; https://git.kernel.org/stable/c/736b380e28d0480c7bc3e022f1950f31fe53a7c5 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53362
⚠️ CVE-2026-66384 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66384)
- Name: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-66384
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260827 #cisa20260827 #cve_2023_49105 #cve_2026_53362 #cve_2026_66384 #cve202349105 #cve202653362 #cve202666384
##CVE ID: CVE-2023-49105
Vendor: ownCloud
Product: ownCloud
Date Added: 2026-08-27
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2023-49105
6 posts
3 repos
https://github.com/rafabd1/CVE-2026-75604-poc
Next.js Patches Flaws Enabling Unauthenticated Remote Code Execution
If your Next.js application is hosted on Windows, upgrade immediately to patch a critical vulnerability that allows unauthenticated remote code execution. This flaw, tracked as CVE-2026-75604, affects apps using both Pages Router and App Router without Cache Components.
#Nextjs #Cve202675604 #RemoteCodeExecution #PathTraversal #Windows
##https://thecybersecguru.com/news/nextjs-rce-avif-libheif-cve-2026-75604/
##Next.js Windows RCE PoC https://github.com/rafabd1/CVE-2026-75604-poc
##https://thecybersecguru.com/news/nextjs-rce-avif-libheif-cve-2026-75604/
##Next.js Windows RCE PoC https://github.com/rafabd1/CVE-2026-75604-poc
##Two critical Next.js vulnerabilities, including CVE-2026-75604 (CVSS 9.0), enable unauthenticated remote code execution. Patch to 15.5.24 or 16.3.3 now.
#NextJS #RCE #CyberSecurity #CVE202675604 #WebSecurity
https://securityonline.info/nextjs-rce-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
##🟠 CVE-2026-66155 - High (7.6)
A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions < V48.11.3), Element maps-ng V49 (All versions < V49.16.1). The si-map component does not properly neutralize user-con...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66155/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-66155 - High (7.6)
A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions < V48.11.3), Element maps-ng V49 (All versions < V49.16.1). The si-map component does not properly neutralize user-con...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66155/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-47665 - Stored XSS in Penpot design platform via file comments. CVSS 8.7. Restrict comment access and monitor for patches. #CVE #Penpot #cybersecurity
##🟠 CVE-2026-47665 - High (8.7)
Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through file comments, whose content is stored as raw text and rendered into the page with innerH...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47665/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-47665 - High (8.7)
Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through file comments, whose content is stored as raw text and rendered into the page with innerH...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47665/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##LazyOwn RedTeam Framework Patches Critical Default Credential Vulnerability
LazyOwn RedTeam/APT Framework patched a critical vulnerability (CVE-2026-68503) that allows attackers to gain full administrative control over C2 dashboards using hardcoded default credentials. The flaw enables unauthorized users to hijack red-team campaigns, issue commands to beacons, and access exfiltrated data.
**If you run the LazyOwn RedTeam/APT framework, update it to version 0.2.154 or later ASAP. Older versions ship with default usernames and passwords that let anyone take over your C2 dashboard. If you can't update yet, change the `c2_user` and `c2_pass` values in your `payload.json` to unique strong passwords and put the dashboard behind a firewall so only trusted networks can reach it.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/lazyown-redteam-framework-patches-critical-default-credential-vulnerability-k-h-i-x-v/gD2P6Ple2L
LazyOwn RedTeam Framework Patches Critical Default Credential Vulnerability
LazyOwn RedTeam/APT Framework patched a critical vulnerability (CVE-2026-68503) that allows attackers to gain full administrative control over C2 dashboards using hardcoded default credentials. The flaw enables unauthorized users to hijack red-team campaigns, issue commands to beacons, and access exfiltrated data.
**If you run the LazyOwn RedTeam/APT framework, update it to version 0.2.154 or later ASAP. Older versions ship with default usernames and passwords that let anyone take over your C2 dashboard. If you can't update yet, change the `c2_user` and `c2_pass` values in your `payload.json` to unique strong passwords and put the dashboard behind a firewall so only trusted networks can reach it.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/lazyown-redteam-framework-patches-critical-default-credential-vulnerability-k-h-i-x-v/gD2P6Ple2L
Ubiquiti patches three max severity security vulnerabilities
Ubiquiti가 인증 없이 원격 공격 가능한 최대 심각도 취약점 3건을 패치했다. CVE-2026-77537은 UniFi Protect의 입력 검증 문제로 기기 장악을 허용하며, CVE-2026-77550은 UniFi OS의 CRLF 인젝션을 이용한 인증 우회, CVE-2026-77554는 UniFi Talk의 명령 인젝션 취약점이다. 공격 복잡도가 낮고 사용자 상호작용이 필요 없으며, 인터넷에 노출된 UniFi OS 인스턴스가 10만 개 이상 관측돼 네트워크·AI 엣지 장비를...
##Ubiquiti patched 22 UniFi flaws. Three hit CVSS 10.0, including command injection CVE-2026-77537. Update UniFi Protect, OS, and Talk now.
#Ubiquiti #UniFi #CyberSecurity #CommandInjection #CVE202677537
##19 posts
9 repos
https://github.com/HORKimhab/CVE-2026-60004
https://github.com/shinthink/CVE-2026-60004
https://github.com/EQSTLab/CVE-2026-60004
https://github.com/Sachinart/CVE-2026-60004-gitea-0day
https://github.com/gagaltotal/CVE-2026-60004-poc-gitea
https://github.com/fevar54/cve-2026-60004
https://github.com/imbas007/CVE-2026-60004-POC
🔴 New security advisory:
CVE-2026-60004 affects multiple systems.
• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems
Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-60004-gitea-unauthenticated-rce-exploited-in-wild-poc
by Yazoul AI
##🔴 CVE-2026-60004 - Critical (9.8)
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-60004/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##⚠️ CRITICAL: Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
Gitea instances are under active attack for CVE-2026-60004, a critical RCE flaw (CVSS 9.8) that allows unauthenticated account creation to trigger arbitrary command execution. Attackers are deploying miner-like payloads. Any organization running Gitea with default open registration is at immediate…
🤖 AI generated summary
##Hackers now exploit critical Gitea flaw in code injection attacks
자가 호스팅 Git 서비스 Gitea의 치명적 취약점 CVE-2026-60004가 실제 공격에 악용되고 있다. 공격자는 diffpatch API에 악성 패치를 제출해 저장소 제어 콘텐츠로 Git hook을 설치하고, Gitea 서비스 계정 권한으로 임의 셸 명령을 실행할 수 있다. 기본 설정에서는 사용자 자가 가입이 켜져 있어, 외부 공격자가 계정을 만든 뒤 저장소를 생성하는 것만으로 필요한 쓰기 권한을 얻을 수 있다. Gitea 1.27.1에서 수정됐으며, C...
##CISA Reports Actively Exploited Gitea Critical RCE Vulnerability
Gitea patched a critical remote code execution vulnerability (CVE-2026-60004) that attackers are actively exploiting to install crypto-miners on self-hosted instances. The flaw allows users with write access to inject malicious Git hooks via the diffpatch API, potentially exposing database credentials and system secrets.
**Update self-hosted Gitea instances to version 1.27.1 immediately. Now it's urgent, since hackers are actively attacking you. If you can't patch right away, disable public registration to prevent new outsiders from obtaining repository write access. This does not protect against existing users who already have the required permissions.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/cisa-reports-actively-exploited-gitea-critical-rce-vulnerability-2-1-9-j-5/gD2P6Ple2L
CISA has listed CVE-2026-60004 in the KEV Catalog. Critical RCE in Gitea actively exploited via malicious patches submitted through the diff API endpoint. Attackers achieve code injection on self-hosted instances and deploy cryptominers on compromised servers. Patch by August 28 is mandatory.
#CriticalRCE #GiteaVulnerability #Cryptojacking #CISAKEV
https://cyberworldops.eu/en/gitea-under-attack-critical-rce-exploited-for-cryptojacking-cisa
##CISA Sounds the Alarm as Actively Exploited Gitea Flaw Lets Authenticated Users Run Shell Commands + Video
A New Warning Raises Serious Questions for Gitea Administrators A new cybersecurity warning has placed Gitea administrators under pressure after the U.S. Cybersecurity and Infrastructure Security Agency, CISA, identified CVE-2026-60004 as an actively exploited vulnerability. The flaw reportedly affects the popular self-hosted Git service and could allow an…
##📰 CISA Warns of Actively Exploited Gitea RCE Flaw (CVE-2026-60004)
🚨 CISA KEV ALERT: A critical RCE flaw in Gitea (CVE-2026-60004, CVSS 9.8) is actively exploited. Attackers can gain RCE on self-hosted Git servers. Patch to version 1.27.1 or later NOW. #Gitea #RCE #CISA #KEV #CVE202660004
##🏆 New Achievement! Hook, Line, and Git Hooked!
And here, in its natural habitat, we observe the self-hosted Git server — a creature believed by its keepers to be safely tucked away, far from predators. CVE-2026-60004 tells a different story. An attacker with mere repository write access may deliver a malicious patch to Gitea's diffpatch API endpoint, planting an executable Git hook and inheriting the Gitea service account like a cuckoo claiming another bird's nest. (1/2)
##🔴 CVE-2026-60004 - Critical (9.8)
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-60004/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##⚠️ CRITICAL: Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
Gitea instances are under active attack for CVE-2026-60004, a critical RCE flaw (CVSS 9.8) that allows unauthenticated account creation to trigger arbitrary command execution. Attackers are deploying miner-like payloads. Any organization running Gitea with default open registration is at immediate…
🤖 AI generated summary
##CISA Reports Actively Exploited Gitea Critical RCE Vulnerability
Gitea patched a critical remote code execution vulnerability (CVE-2026-60004) that attackers are actively exploiting to install crypto-miners on self-hosted instances. The flaw allows users with write access to inject malicious Git hooks via the diffpatch API, potentially exposing database credentials and system secrets.
**Update self-hosted Gitea instances to version 1.27.1 immediately. Now it's urgent, since hackers are actively attacking you. If you can't patch right away, disable public registration to prevent new outsiders from obtaining repository write access. This does not protect against existing users who already have the required permissions.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/cisa-reports-actively-exploited-gitea-critical-rce-vulnerability-2-1-9-j-5/gD2P6Ple2L
CISA has listed CVE-2026-60004 in the KEV Catalog. Critical RCE in Gitea actively exploited via malicious patches submitted through the diff API endpoint. Attackers achieve code injection on self-hosted instances and deploy cryptominers on compromised servers. Patch by August 28 is mandatory.
#CriticalRCE #GiteaVulnerability #Cryptojacking #CISAKEV
https://cyberworldops.eu/en/gitea-under-attack-critical-rce-exploited-for-cryptojacking-cisa
##🏆 New Achievement! Hook, Line, and Git Hooked!
And here, in its natural habitat, we observe the self-hosted Git server — a creature believed by its keepers to be safely tucked away, far from predators. CVE-2026-60004 tells a different story. An attacker with mere repository write access may deliver a malicious patch to Gitea's diffpatch API endpoint, planting an executable Git hook and inheriting the Gitea service account like a cuckoo claiming another bird's nest. (1/2)
##CISA has added CVE-2026-60004 to the KEV catalog. The vulnerability in Gitea, a self-hosted Git service, has been exploited in the wild to achieve remote code execution and install cryptocurrency miners on compromised instances. FCEB agencies face a remediation deadline of August 28, 2026.
#KnownExploitedVulnerabilities #RemoteCodeExecution #Gitea #CISA
https://cyberworldops.eu/en/cisa-adds-gitea-vulnerability-to-kev-catalog-exploited-to-execute-code
##🚨 Critical Threat Intel: CVE-2026-60004 targets Gitea via diffpatch API code injection. Review execution vectors, persistence mechanics, and active endpoint hardening actions to secure your version control infrastructure. https://thecybermind.co/jily
##CISA has updated the KEV catalogue.
- CVE-2026-60004: Gitea Code Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-60004
- Industrial vulnerability: Rently Smart Home https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-01
Also:
Press release: CISA Advisory Highlights Red Team Findings to Help Organizations Assess Risk, Identify Threats and Enable Effective Incident Response https://www.cisa.gov/news-events/news/cisa-advisory-highlights-red-team-findings-help-organizations-assess-risk-identify-threats-and
The advisory: A Tale of Two SOCs: Insights From Two Red Team Assessments https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a #CISA #infosec #vulnerability
##CVE ID: CVE-2026-60004
Vendor: Gitea
Product: Gitea
Date Added: 2026-08-25
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-60004
🚨 [CISA-2026:0825] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-60004 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- Name: Gitea Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Gitea
- Product: Gitea
- Notes: https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-60004
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260825 #cisa20260825 #cve_2026_60004 #cve202660004
##🟠 CVE-2026-61617 - High (7.7)
Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not enforce a server's disk quota during a transfer, allowing a tenant with SFTP write access to a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61617/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-61617 - High (7.7)
Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not enforce a server's disk quota during a transfer, allowing a tenant with SFTP write access to a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61617/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-77317 - High (8.1)
SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a literal string-prefix comparison, so a user scoped to a path is also granted the same a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77317/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-77317 - High (8.1)
SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a literal string-prefix comparison, so a user scoped to a path is also granted the same a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77317/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-80427 - High (8.4)
bestzip builds the argument list for the system zip utility without separating options from operands. The destination archive path and the caller-supplied source paths are passed to the child process with no -- delimiter between them, so any sourc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80427/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-80427 - High (8.4)
bestzip builds the argument list for the system zip utility without separating options from operands. The destination archive path and the caller-supplied source paths are passed to the child process with no -- delimiter between them, so any sourc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80427/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-61792 - High (7.7)
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their repository through the App store metadata download feature, which resol...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61792/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-61792 - High (7.7)
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their repository through the App store metadata download feature, which resol...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61792/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Impact:
CVSS Severity and Metrics:
Base Score: 9.6 Critical
Vector:
CVSS: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE: CVE-2026-77532 (Will Robertson)
##Impact:
CVSS Severity and Metrics:
Base Score: 9.6 Critical
Vector:
CVSS: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE: CVE-2026-77532 (Will Robertson)
##🟠 CVE-2026-78379 - High (8.1)
Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.8.5 might allow remote actors to execute arbitrary Python code on the agent's host by bypassing the human consent gate, via a c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78379/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-78379 - High (8.1)
Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.8.5 might allow remote actors to execute arbitrary Python code on the agent's host by bypassing the human consent gate, via a c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78379/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##FreeBSD: kernel use-after-free via tty ioctls – CVE-2026-58093
https://www.cve.org/CVERecord?id=CVE-2026-58093
"The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. After reacquiring the tty lock, the handler did not revalidate the state of the terminal, and could proceed to link a terminal that was concurrently being destroyed to the calling process' session. An unprivileged local user can exploit this race condition to escalate privileges."
Credit: tsune of GMO Cybersecurity by Ierae, Inc. working with TrendAI Zero Day Initiative @thezdi
<https://ctftime.org/team/224122>
<https://gmo-cybersecurity.com/>
<https://nvd.nist.gov/vuln/detail/CVE-2026-58093>
<https://reviews.freebsd.org/D59126>, <https://github.com/freebsd/freebsd-src/commit/b207f754c7709212381eda8c91dbf080081ac5a1>
##1 posts
5 repos
https://github.com/v1c0mmrt/redis-cve-2026-23479-scanner
https://github.com/pduggusa/redis-cve-2026-23479-check
https://github.com/mgiay/CVE-2026-25589-25588-25243-23631-23479-REDIS
https://github.com/rizlmaulanaa/CVE-2026-23479-Redis-UAF-Proof-of-Concept
A public PoC exploits a Redis RCE use-after-free flaw tied to CVE-2026-23479, running system commands as the Redis server. Update to 8.8.2.
##CVE-2026-18965 discloses a missing authorization flaw in the PayRange API (CWE-862). All versions are affected. The vulnerability allows unauthenticated remote access to payment devices, exposing fleets of vending machines and kiosks to unauthorized interaction.
#CVE202618965 #MissingAuthorization #PayRangeAPI #CriticalVulnerability
https://cyberworldops.eu/en/payrange-authorization-flaw-in-api-remote-access-to-payment-devices
##