## Updated at UTC 2026-09-11T00:28:27.102909

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-88044 9.1 0.00% 2 0 2026-09-10T22:47:10 ## Summary `serve/start` accepts protocol options in a per-server `proxyOpt` ob
CVE-2026-88045 7.5 0.00% 2 0 2026-09-10T22:45:14 ## Summary In streamed multipart mode, `serve s3` passes the request's declared
CVE-2026-87011 7.5 0.34% 2 0 2026-09-10T22:45:10 ## Summary The OIDC back-channel logout endpoint is unauthenticated by design,
CVE-2026-87958 8.1 0.00% 2 0 2026-09-10T22:17:04.760000 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a deni
CVE-2026-86093 7.5 0.00% 2 0 2026-09-10T22:17:04.620000 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker
CVE-2026-84889 8.8 0.00% 2 0 2026-09-10T22:17:04.347000 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacke
CVE-2026-82107 9.6 0.00% 2 0 2026-09-10T22:17:04.220000 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a
CVE-2026-82100 9.6 0.00% 2 0 2026-09-10T22:17:04.090000 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a
CVE-2026-81940 8.8 0.00% 2 0 2026-09-10T22:17:03.083000 IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacke
CVE-2026-19646 9.1 0.00% 2 0 2026-09-10T22:16:55.697000 IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0
CVE-2026-41870 8.8 0.43% 1 0 2026-09-10T21:32:31 Missing Authorization, Improper Control of Generation of Code ('Code Injection')
CVE-2026-89054 8.2 0.00% 2 0 2026-09-10T21:31:41 A missing authorization vulnerability in OpenNMS Horizon allows configuration ch
CVE-2026-89086 9.1 0.00% 2 0 2026-09-10T21:31:41 In the jose package before 0.11.0 for OCaml, library calls to validate an RSA si
CVE-2026-67277 None 0.43% 4 0 2026-09-10T21:31:20 RouterOS accepts a "related" btest connection before the corresponding primary s
CVE-2026-87016 8.1 0.33% 2 0 2026-09-10T21:23:26 ## Summary On SQLite deployments, the lookup that maps an external identity to
CVE-2026-89094 9.9 0.00% 2 0 2026-09-10T21:17:53.160000 Forgejo before 16.0.4 allows remote code execution via a crafted template reposi
CVE-2026-53932 8.0 0.91% 1 0 2026-09-10T20:41:33.140000 laravel-backup-restore restores database backups made with spatie/laravel-backup
CVE-2026-86060 0 0.40% 4 1 2026-09-10T20:17:28.953000 RouterOS contains an argument-handling flaw in the SSH login path involving user
CVE-2026-87794 8.4 0.19% 1 0 2026-09-10T19:58:20.507000 bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in
CVE-2026-53939 9.1 0.20% 1 0 2026-09-10T19:57:48.533000 OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encr
CVE-2026-85704 3.7 0.27% 1 0 2026-09-10T19:17:36.650000 A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3df
CVE-2026-89046 8.2 0.00% 2 0 2026-09-10T18:33:05 zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnera
CVE-2026-89042 9.1 0.00% 2 0 2026-09-10T18:33:04 passport-saml-encrypted through 0.1.13 makes SAML signature verification conditi
CVE-2026-85228 9.1 0.00% 2 0 2026-09-10T18:33:04 An integer overflow in the tensor buffer validation component in Amazon Deep Jav
CVE-2026-87995 8.7 0.22% 2 0 2026-09-10T18:18:11.740000 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI plat
CVE-2026-79323 7.5 0.33% 1 0 2026-09-10T17:48:35.100000 Information disclosure in the blogComments GraphQL query in Magefan Blog GraphQL
CVE-2026-88889 7.8 0.00% 2 0 2026-09-10T16:18:11.693000 Renovate before 44.14.7 contains a command injection vulnerability in the Maven
CVE-2026-88289 7.5 0.33% 2 0 2026-09-10T16:18:10.657000 GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variab
CVE-2026-67593 9.1 0.29% 2 0 2026-09-10T16:17:45.273000 A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause
CVE-2026-15913 7.7 0.39% 2 0 2026-09-10T15:53:23.707000 In versions prior to 7.10.2 a path traversal vulnerability in theย /attachRemoteF
CVE-2026-21096 None 0.41% 1 0 2026-09-10T15:34:15 Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SM
CVE-2026-88890 8.5 0.00% 2 0 2026-09-10T15:33:28 OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the
CVE-2026-88887 8.6 0.00% 2 0 2026-09-10T15:33:28 Renovate is a dependency update automation tool. When listing tags/digests for a
CVE-2026-88891 8.3 0.00% 2 0 2026-09-10T15:33:27 OpenPanel fails to enforce read-only project access level on 26 of 29 mutating p
CVE-2026-73786 7.5 0.33% 1 1 2026-09-10T15:33:12 A vulnerability in the web-based management interface of CPPM could allow an una
CVE-2026-85983 7.8 0.14% 1 0 2026-09-10T15:17:50.033000 The Auth0 AD/LDAP Connector improperly processes a configuration value during se
CVE-2026-82533 9.6 0.42% 1 0 2026-09-10T15:17:47.593000 DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerab
CVE-2026-6485 8.2 0.12% 1 0 2026-09-10T15:17:39.427000 UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands
CVE-2026-69420 7.8 0.32% 1 0 2026-09-10T15:17:37.937000 Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker
CVE-2026-87996 7.7 0.21% 2 0 2026-09-10T15:10:12 ## Summary With the Playwright web loader enabled, Open WebUI checks the address
CVE-2026-0307 0 0.10% 1 0 2026-09-10T14:50:07.813000 Multiple local privilege escalation vulnerabilities in the Palo Alto Networks Gl
CVE-2026-15019 7.5 0.68% 2 0 2026-09-10T14:39:13.757000 The Direct Download for WooCommerce plugin for WordPress is vulnerable to Direct
CVE-2026-4800 8.1 2.76% 2 2 2026-09-10T13:20:23.210000 Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h
CVE-2026-39821 9.6 0.69% 2 0 2026-09-10T13:19:50.873000 The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels t
CVE-2026-87491 8.8 0.76% 13 1 2026-09-10T12:49:02.630000 Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remo
CVE-2026-19490 9.8 6.00% 2 2 2026-09-10T12:48:10.453000 Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: f
CVE-2025-25249 8.1 1.70% 5 0 2026-09-10T12:47:59.933000 A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6
CVE-2026-78082 None 0.49% 2 0 2026-09-10T12:31:26 Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Se
CVE-2026-8323 9.3 0.25% 2 0 2026-09-10T09:31:48 URL redirection to untrusted site ('open redirect') vulnerability in Armiya Info
CVE-2026-88290 7.5 0.26% 2 0 2026-09-10T09:31:48 GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare un
CVE-2026-13745 None 0.30% 2 0 2026-09-10T09:31:37 A vulnerability in the Gemini CLI and associated GitHub Action allowed an unpriv
CVE-2026-87931 9.6 0.45% 2 0 2026-09-10T06:32:50 A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral
CVE-2026-0310 None 0.34% 6 0 2026-09-10T06:31:55 A buffer overflow vulnerability in the XML processing functionality of Palo Alto
CVE-2026-14873 8.0 0.24% 2 0 2026-09-10T06:31:42 The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalati
CVE-2026-87628 8.3 0.17% 1 0 2026-09-10T04:18:29.850000 Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjace
CVE-2026-69730 9.8 1.05% 4 0 2026-09-10T04:18:14.773000 Use after free in Windows DNS allows an unauthorized attacker to execute code ov
CVE-2016-7255 7.8 80.97% 2 5 2026-09-10T04:17:32.400000 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2
CVE-2026-19584 7.7 0.19% 2 0 2026-09-10T03:30:27 Velociraptor allows for the creation of notebook backups in its default enabled
CVE-2026-18351 9.8 0.77% 2 0 2026-09-10T03:30:27 The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulner
CVE-2026-19583 9.9 0.60% 2 0 2026-09-10T03:30:26 Velociraptor allows some sensitive artifacts to be gated by additional permissio
CVE-2026-88069 None 0.33% 2 0 2026-09-10T00:30:34 Pandora contains a path traversal vulnerability in its archive extraction worker
CVE-2026-79324 7.5 0.32% 1 0 2026-09-09T21:32:03 Missing authorization in the Address Delete controller in Mageplaza GDPR for Mag
CVE-2026-79322 8.6 0.28% 2 0 2026-09-09T21:31:56 SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (magep
CVE-2026-20079 10.0 74.70% 21 2 2026-09-09T21:31:33 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2026-12855 8.2 0.12% 1 0 2026-09-09T21:17:01.313000 Unvalidated memory boundary could result in arbitrary code execution. The vulner
CVE-2026-85061 10.0 0.31% 1 0 2026-09-09T21:09:13.080000 MapLibre GL JS is an interactive vector tile map library for web browsers. Prior
CVE-2026-87874 8.1 0.43% 1 0 2026-09-09T20:13:26.720000 A flaw was found in the memcached cache plugin of the community.general Ansible
CVE-2026-17469 5.3 0.21% 2 0 2026-09-09T18:32:16 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause
CVE-2026-87929 9.8 0.29% 2 0 2026-09-09T18:32:12 MaxSite CMS through 109.6 ships with a hardcoded session encryption key in appli
CVE-2026-87927 8.2 0.34% 1 0 2026-09-09T18:32:12 MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the a
CVE-2026-67401 9.9 0.96% 3 3 2026-09-09T18:32:06 A vulnerability in cPanel allows a mail-enabled account to achieve remote code e
CVE-2026-83970 7.8 0.31% 1 0 2026-09-09T17:17:48.473000 Heap-based buffer overflow in Windows Biometric Service allows an authorized att
CVE-2026-85103 9.8 0.36% 7 0 2026-09-09T15:35:15 A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unau
CVE-2026-85102 9.8 0.33% 5 0 2026-09-09T15:35:15 Improper certificate trust validation during VPN negotiation in Check Point Quan
CVE-2026-81953 7.8 0.43% 1 0 2026-09-09T15:03:00.630000 Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized att
CVE-2026-80172 9.8 0.27% 1 0 2026-09-09T12:32:22 Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application
CVE-2026-79641 7.5 0.67% 1 0 2026-09-09T12:32:21 Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application
CVE-2026-87795 8.2 0.34% 1 0 2026-09-09T12:32:12 zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters
CVE-2026-79696 None 0.44% 1 0 2026-09-09T09:33:06 A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit
CVE-2026-16272 9.1 0.14% 1 0 2026-09-09T09:33:00 Use of less trusted source vulnerability in PayTR Payment and Electronic Money I
CVE-2026-76009 8.1 0.52% 2 0 2026-09-09T06:31:48 The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable
CVE-2026-87734 7.5 0.29% 1 0 2026-09-09T06:31:40 An issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-order
CVE-2026-15667 7.5 0.56% 1 0 2026-09-09T03:30:51 The Eventin โ€“ Event Calendar, Event Registration, Tickets & Booking (AI Powered)
CVE-2026-81994 8.2 0.30% 1 0 2026-09-08T21:34:41 Acrobat Reader is affected by an Improperly Controlled Modification of Object Pr
CVE-2026-84869 9.9 0.38% 3 0 2026-09-08T21:34:37 A condition in the ScreenConnect client may allow files to be transferred and ex
CVE-2026-84942 8.7 0.33% 1 0 2026-09-08T21:34:37 Improper input validation in the Vega expression function implementation in Open
CVE-2026-82007 7.8 0.23% 1 0 2026-09-08T21:34:36 Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability
CVE-2026-85880 7.8 0.57% 9 0 2026-09-08T21:34:12 Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elev
CVE-2026-81963 7.8 0.63% 9 0 2026-09-08T21:34:09 Improper link resolution before file access ('link following') in Windows Update
CVE-2026-75650 10.0 2.15% 11 4 2026-09-08T21:33:09 Adobe Commerce is affected by an Improper Neutralization of Special Elements Use
CVE-2026-86218 9.8 0.74% 12 1 2026-09-08T21:33:02 N-central is vulnerable to a pre-auth remote code execution This issue affects N
CVE-2026-57162 0 0.35% 1 0 2026-09-08T21:14:35.567000 PJSIP is a free and open source multimedia communication library written in C. P
CVE-2026-84372 9.8 0.41% 1 0 2026-09-08T20:57:52 ### Summary An improper CRLF neutralization flaw in Predis' pipeline handling o
CVE-2026-86721 7.5 0.29% 1 0 2026-09-08T19:53:13.400000 AVideo through commit c3edcc274c contains an authorization bypass vulnerability
CVE-2026-86730 8.8 0.39% 1 0 2026-09-08T19:53:13.400000 Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-la
CVE-2026-44756 10.0 0.32% 5 0 2026-09-08T19:12:59.557000 A memory safety vulnerability exists in the Extended Passport Protocol (EPP) pro
CVE-2026-83972 7.8 0.31% 1 0 2026-09-08T18:34:21 Heap-based buffer overflow in Windows Biometric Service allows an authorized att
CVE-2026-81954 7.8 0.32% 1 0 2026-09-08T18:34:18 Use after free in Microsoft Office Excel allows an unauthorized attacker to exec
CVE-2026-83991 5.5 0.34% 1 2 2026-09-08T18:34:14 Missing authentication for critical function in Windows Cloud Files Mini Filter
CVE-2026-80081 8.8 0.47% 1 0 2026-09-08T18:34:00 Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to
CVE-2026-69829 9.8 1.05% 1 0 2026-09-08T18:33:17 Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to e
CVE-2026-20293 7.1 0.13% 2 0 2026-09-08T18:32:05 A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implem
CVE-2026-82067 8.1 0.28% 2 0 2026-09-08T18:32:04 Improper handling of case sensitivity in the configuration validation component
CVE-2026-86738 8.7 0.27% 1 0 2026-09-08T18:32:01 Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Cust
CVE-2026-86728 7.5 0.32% 1 0 2026-09-08T18:32:00 AVideo through 29.0 contains an authentication bypass vulnerability in plugin/Pl
CVE-2026-86727 7.5 0.31% 1 0 2026-09-08T18:31:59 AVideo through 29.0 contains an information disclosure vulnerability in plugin/L
CVE-2026-86732 8.8 0.51% 1 0 2026-09-08T18:31:59 Craft CMS versions before 5.10.12 contain a remote code execution vulnerability
CVE-2026-26084 9.9 0.24% 1 0 2026-09-08T18:31:56 A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5
CVE-2025-20701 8.8 7.77% 1 2 2026-09-08T18:31:36 In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth aud
CVE-2026-33197 0 0.12% 2 0 2026-09-08T16:18:08.077000 AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause th
CVE-2026-31431 7.8 99.91% 1 100 2026-09-08T15:13:07.273000 In the Linux kernel, the following vulnerability has been resolved: crypto: alg
CVE-2026-85012 8.0 1.06% 2 0 2026-09-08T14:00:33.017000 Improper neutralization of special elements used in an OS command (CWE-78) in th
CVE-2026-78234 9.9 0.21% 1 0 2026-09-08T12:31:35 A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA
CVE-2026-50093 9.0 0.19% 1 0 2026-09-08T09:35:45 A vulnerability has been identified in Siveillance Control Pro V3.0 (All version
CVE-2026-18963 9.1 3.18% 1 15 2026-09-08T09:17:43.063000 A flaw was found in the reset-credentials flow of the keycloak-services componen
CVE-2026-86206 None 0.68% 2 0 2026-09-05T21:31:26 A vulnerability in the N-central internal API access control filter allows unaut
CVE-2026-67276 None 0.24% 1 4 2026-09-05T21:31:20 RouterOS does not compare the complete RSA public key when matching an SSH authe
CVE-2026-86207 None 0.73% 2 0 2026-09-05T21:31:20 An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypa
CVE-2026-86090 7.1 0.25% 1 0 2026-09-05T00:31:10 ntopng before 6.7.260717 fails to perform authorization checks in the delete end
CVE-2026-80119 7.8 0.12% 1 0 2026-09-04T21:31:59 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 10
CVE-2026-80905 None 0.15% 1 0 2026-09-04T18:31:46 In the Linux kernel, the following vulnerability has been resolved: net: tap: f
CVE-2026-9317 8.1 0.68% 1 0 2026-09-04T18:31:46 Nango before 0.71.6 contains a missing authentication vulnerability in the runne
CVE-2026-80874 None 0.14% 1 0 2026-09-04T18:31:40 In the Linux kernel, the following vulnerability has been resolved: arm64: dts:
CVE-2026-17255 4.3 0.40% 1 0 2026-09-04T18:31:40 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of
CVE-2026-80872 None 0.15% 1 0 2026-09-04T18:31:40 In the Linux kernel, the following vulnerability has been resolved: ALSA: hda/t
CVE-2026-17440 5.5 0.10% 1 0 2026-09-04T18:31:40 IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.
CVE-2026-17057 6.5 0.38% 1 0 2026-09-04T18:31:40 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of
CVE-2026-16660 5.3 0.36% 1 0 2026-09-04T18:31:39 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a
CVE-2026-75754 None 0.21% 1 0 2026-09-04T03:31:07 Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF)
CVE-2026-20355 5.9 0.15% 1 0 2026-09-02T19:23:13.660000 Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/
CVE-2026-20354 5.9 0.15% 1 0 2026-09-02T18:32:31 Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/
CVE-2026-20212 9.8 0.53% 1 1 2026-09-02T18:32:26 A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switc
CVE-2026-83548 10.0 4.67% 1 3 2026-09-02T18:32:06 A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Pla
CVE-2026-81578 9.8 1.62% 4 2 2026-09-01T04:18:01.990000 An improper access control vulnerability exists in the web management interface
CVE-2026-82078 9.1 1.69% 4 2 2026-08-31T21:31:56 An unsafe dynamic class loading vulnerability exists in the database connection
CVE-2026-77237 6.5 0.13% 2 0 2026-08-25T16:44:12.343000 Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel bef
CVE-2026-69836 10.0 1.55% 1 2 2026-08-25T16:08:43.290000 Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized a
CVE-2026-69414 7.8 0.56% 6 2 2026-08-19T18:32:28 Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect
CVE-2026-68820 7.0 6.18% 1 4 2026-08-16T19:17:24.183000 Use after free in Windows Ancillary Function Driver for WinSock allows an author
CVE-2026-19311 8.1 0.41% 2 0 2026-08-12T21:31:44 Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting p
CVE-2025-14733 9.8 26.51% 9 1 2026-08-10T21:33:00 An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remot
CVE-2026-20316 5.3 11.15% 7 0 2026-08-01T05:16:55.973000 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2026-15409 10.0 83.66% 2 6 2026-07-14T21:32:22 A Server-side request forgery (SSRF) vulnerability has been identified in the SM
CVE-2026-52774 6.1 0.51% 1 1 2026-07-09T21:01:12 ### Summary YesWiki's Bazar widget handler reflects the `id` `GET` parameter int
CVE-2026-11387 9.8 2.21% 2 2 2026-07-01T09:30:33 The SMS Alert โ€“ SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart
CVE-2026-43502 7.8 0.12% 2 1 2026-06-01T18:31:32 In the Linux kernel, the following vulnerability has been resolved: net/rds: ha
CVE-2026-8510 7.5 0.21% 1 0 2026-05-15T00:31:36 Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 all
CVE-2026-33671 7.5 0.40% 2 1 2026-03-27T21:36:14 ### Impact `picomatch` is vulnerable to Regular Expression Denial of Service (Re
CVE-2026-33186 9.1 1.56% 2 1 2026-03-25T18:12:09 ### Impact _What kind of vulnerability is it? Who is impacted?_ It is an **Auth
CVE-2026-0915 7.5 0.59% 2 1 2026-01-20T18:31:56 Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that spec
CVE-2019-0859 7.8 4.15% 2 1 2025-10-22T00:32:43 An elevation of privilege vulnerability exists in Windows when the Win32k compon
CVE-2022-41352 9.8 95.48% 2 4 2025-10-22T00:32:37 An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacke
CVE-2025-2524 4.8 0.30% 1 0 2025-06-17T21:31:59 The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape som
CVE-2026-89049 0 0.00% 4 0 N/A
CVE-2026-88052 0 0.00% 2 0 N/A
CVE-2026-72898 0 94.22% 2 8 N/A
CVE-2026-73453 0 0.00% 1 0 N/A
CVE-2026-84388 0 0.00% 2 0 N/A
CVE-2026-84390 0 0.00% 3 0 N/A
CVE-2026-87911 0 0.99% 3 0 N/A
CVE-2026-85786 0 0.33% 1 0 N/A
CVE-2026-75936 0 0.44% 1 0 N/A
CVE-2026-77234 0 0.12% 2 0 N/A
CVE-2026-77236 0 0.11% 2 0 N/A
CVE-2026-77235 0 0.11% 2 0 N/A
CVE-2026-54694 0 0.28% 1 0 N/A
CVE-2026-85982 0 0.22% 1 0 N/A
CVE-2026-85083 0 0.00% 1 0 N/A
CVE-2026-53938 0 0.24% 1 0 N/A
CVE-2026-53581 0 0.33% 2 0 N/A

CVE-2026-88044
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-10T22:47:10

2 posts

## Summary `serve/start` accepts protocol options in a per-server `proxyOpt` object. The FTP and S3 RC adapters parse that object and pass it to their server constructors, but the constructors decide whether proxy authentication is enabled by checking the process-global `proxy.Opt.AuthProxy` instead of the supplied `proxyOpt.AuthProxy`. When the process-global option is emptyโ€”the normal case whe

thehackerwire@mastodon.social at 2026-09-10T18:00:11.000Z ##

๐Ÿ”ด CVE-2026-88044 - Critical (9.1)

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 constructors in...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T18:00:11.000Z ##

๐Ÿ”ด CVE-2026-88044 - Critical (9.1)

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 constructors in...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88045
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-10T22:45:14

2 posts

## Summary In streamed multipart mode, `serve s3` passes the request's declared part length to `multipart.NewRW().Reserve(contentLength)` before reading any part data. `Reserve` immediately obtains enough 1 MiB pool pages for the entire declared length. The request handler therefore allocates attacker-selected memory based only on `Content-Length` or `X-Amz-Decoded-Content-Length`; the client doe

thehackerwire@mastodon.social at 2026-09-10T18:00:22.000Z ##

๐ŸŸ  CVE-2026-88045 - High (7.5)

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.75.0 until 1.75.1, the serve S3 streamed multipart path in cmd/serve/s3/multipart.go passes attacker-controlled contentLength to m...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T18:00:22.000Z ##

๐ŸŸ  CVE-2026-88045 - High (7.5)

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.75.0 until 1.75.1, the serve S3 streamed multipart path in cmd/serve/s3/multipart.go passes attacker-controlled contentLength to m...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87011
(7.5 HIGH)

EPSS: 0.34%

updated 2026-09-10T22:45:10

2 posts

## Summary The OIDC back-channel logout endpoint is unauthenticated by design, because the identity provider calls it without a browser session. Before checking whether the submitted logout token was genuine, the handler fetched the provider's discovery document and its signing keys over the network, and repeated both fetches on every request because nothing was cached. The signing-key fetch also

thehackerwire@mastodon.social at 2026-09-09T21:59:49.000Z ##

๐ŸŸ  CVE-2026-87011 - High (7.5)

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, the unauthenticated POST /oauth/backchannel-logout handler in backend/open_webui/utils/oauth.py fetched the OIDC discovery document and ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-09T21:59:49.000Z ##

๐ŸŸ  CVE-2026-87011 - High (7.5)

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, the unauthenticated POST /oauth/backchannel-logout handler in backend/open_webui/utils/oauth.py fetched the OIDC discovery document and ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87958
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-10T22:17:04.760000

2 posts

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.

thehackerwire@mastodon.social at 2026-09-11T00:02:05.000Z ##

๐ŸŸ  CVE-2026-87958 - High (8.1)

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-11T00:02:05.000Z ##

๐ŸŸ  CVE-2026-87958 - High (8.1)

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86093
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-10T22:17:04.620000

2 posts

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly copies user-controlled data into a fixed-size stack buffer without bounds checking.

thehackerwire@mastodon.social at 2026-09-11T00:01:55.000Z ##

๐ŸŸ  CVE-2026-86093 - High (7.5)

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly co...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-11T00:01:55.000Z ##

๐ŸŸ  CVE-2026-86093 - High (7.5)

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly co...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84889
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-10T22:17:04.347000

2 posts

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.

thehackerwire@mastodon.social at 2026-09-10T23:00:18.000Z ##

๐ŸŸ  CVE-2026-84889 - High (8.8)

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T23:00:18.000Z ##

๐ŸŸ  CVE-2026-84889 - High (8.8)

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82107
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-09-10T22:17:04.220000

2 posts

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.

thehackerwire@mastodon.social at 2026-09-10T23:00:08.000Z ##

๐Ÿ”ด CVE-2026-82107 - Critical (9.6)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T23:00:08.000Z ##

๐Ÿ”ด CVE-2026-82107 - Critical (9.6)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82100
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-09-10T22:17:04.090000

2 posts

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.

thehackerwire@mastodon.social at 2026-09-10T22:59:59.000Z ##

๐Ÿ”ด CVE-2026-82100 - Critical (9.6)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T22:59:59.000Z ##

๐Ÿ”ด CVE-2026-82100 - Critical (9.6)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81940
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-10T22:17:03.083000

2 posts

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.

thehackerwire@mastodon.social at 2026-09-11T00:02:16.000Z ##

๐ŸŸ  CVE-2026-81940 - High (8.8)

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-11T00:02:16.000Z ##

๐ŸŸ  CVE-2026-81940 - High (8.8)

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19646
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-10T22:16:55.697000

2 posts

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host header.

offseq at 2026-09-11T00:00:36.046Z ##

CVE-2026-19646 (CRITICAL, CVSS 9.1) affects IBM Common Licensing 9.0.x & ART 9.0. Improper Host header validation enables remote redirection to attacker domains. No patch yet โ€” monitor IBM guidance. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-11T00:00:36.000Z ##

CVE-2026-19646 (CRITICAL, CVSS 9.1) affects IBM Common Licensing 9.0.x & ART 9.0. Improper Host header validation enables remote redirection to attacker domains. No patch yet โ€” monitor IBM guidance. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IBM #InfoSec

##

CVE-2026-41870
(8.8 HIGH)

EPSS: 0.43%

updated 2026-09-10T21:32:31

1 posts

Missing Authorization, Improper Control of Generation of Code ('Code Injection'), Improper Control of Dynamically-Managed Code Resources, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerabilityย in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.11 through 1.22. Users are recommended to upgrade to version 1.23, which remo

CVE-2026-89054
(8.2 HIGH)

EPSS: 0.00%

updated 2026-09-10T21:31:41

2 posts

A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for every HTTP method except PATCH, so the shipped @PATCH configuration endpoints for event configuration and SNMP data collection (which enable and disable event definitions and data-collection sources) are re

thehackerwire@mastodon.social at 2026-09-10T21:00:08.000Z ##

๐ŸŸ  CVE-2026-89054 - High (8.2)

A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for every HTTP method except PATCH, so the shipped @patch...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T21:00:08.000Z ##

๐ŸŸ  CVE-2026-89054 - High (8.2)

A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for every HTTP method except PATCH, so the shipped @patch...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89086
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-10T21:31:41

2 posts

In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.

thehackerwire@mastodon.social at 2026-09-10T20:59:58.000Z ##

๐Ÿ”ด CVE-2026-89086 - Critical (9.1)

In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T20:59:58.000Z ##

๐Ÿ”ด CVE-2026-89086 - Critical (9.1)

In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67277(CVSS UNKNOWN)

EPSS: 0.43%

updated 2026-09-10T21:31:20

4 posts

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragment

secdb at 2026-09-10T21:00:32.914Z ##

๐Ÿšจ [CISA-2026:0910] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

โš ๏ธ CVE-2026-67277 (secdb.nttzen.cloud/cve/detail/)
- Name: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: mikrotik.com/supportsec/septem ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-86060 (secdb.nttzen.cloud/cve/detail/)
- Name: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-09-10T20:01:17.000Z ##

CVE ID: CVE-2026-67277
Vendor: MikroTik
Product: RouterOS
Date Added: 2026-09-10
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-09-10T21:00:32.000Z ##

๐Ÿšจ [CISA-2026:0910] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

โš ๏ธ CVE-2026-67277 (secdb.nttzen.cloud/cve/detail/)
- Name: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: mikrotik.com/supportsec/septem ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-86060 (secdb.nttzen.cloud/cve/detail/)
- Name: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260910 #cisa20260910 #cve_2026_67277 #cve_2026_86060 #cve202667277 #cve202686060

##

cisakevtracker@mastodon.social at 2026-09-10T20:01:17.000Z ##

CVE ID: CVE-2026-67277
Vendor: MikroTik
Product: RouterOS
Date Added: 2026-09-10
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-87016
(8.1 HIGH)

EPSS: 0.33%

updated 2026-09-10T21:23:26

2 posts

## Summary On SQLite deployments, the lookup that maps an external identity to a local account does a substring match instead of an exact match. A subject value containing SQL wildcard characters therefore matches accounts the value was never issued for, and the sign-in binds to whichever account the database returns first, which can be an administrator. The same defect affects SCIM external-ID r

thehackerwire@mastodon.social at 2026-09-09T23:00:46.000Z ##

๐ŸŸ  CVE-2026-87016 - High (8.1)

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.41 until 0.11.1, get_user_by_oauth_sub and get_user_by_scim_external_id in backend/open_webui/models/users.py used JSON contains matching that compiled ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-09T23:00:46.000Z ##

๐ŸŸ  CVE-2026-87016 - High (8.1)

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.41 until 0.11.1, get_user_by_oauth_sub and get_user_by_scim_external_id in backend/open_webui/models/users.py used JSON contains matching that compiled ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89094
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-10T21:17:53.160000

2 posts

Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

cR0w at 2026-09-10T21:42:08.433Z ##

RE: infosec.exchange/@cR0w/1172478

CVE for this one:

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.9 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

##

cR0w@infosec.exchange at 2026-09-10T21:42:08.000Z ##

RE: infosec.exchange/@cR0w/1172478

CVE for this one:

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.9 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

##

CVE-2026-53932
(8.0 HIGH)

EPSS: 0.91%

updated 2026-09-10T20:41:33.140000

1 posts

laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during database restore. This issue has been patched in version 1.9.4.

hugovalters@mastodon.social at 2026-09-10T05:00:01.000Z ##

CVE-2026-53932: OS command injection in laravel-backup-restore via crafted backup archives. CVSS 8. Unpatched before v1.9.4. If you restore Spatie backups, update now. Details: valtersit.com/cve/CVE-2026-539 #CVE #infosec #Laravel

##

CVE-2026-86060
(0 None)

EPSS: 0.40%

updated 2026-09-10T20:17:28.953000

4 posts

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy maskย to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions:ย 6.49.21 (Long-term),ย 7.23.4 (Long-term)ย andย 7.24.2 (Stable

1 repos

https://github.com/bahirul/cve-2026-86060

secdb at 2026-09-10T21:00:32.914Z ##

๐Ÿšจ [CISA-2026:0910] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

โš ๏ธ CVE-2026-67277 (secdb.nttzen.cloud/cve/detail/)
- Name: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: mikrotik.com/supportsec/septem ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-86060 (secdb.nttzen.cloud/cve/detail/)
- Name: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-09-10T20:01:01.000Z ##

CVE ID: CVE-2026-86060
Vendor: MikroTik
Product: RouterOS
Date Added: 2026-09-10
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-09-10T21:00:32.000Z ##

๐Ÿšจ [CISA-2026:0910] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

โš ๏ธ CVE-2026-67277 (secdb.nttzen.cloud/cve/detail/)
- Name: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: mikrotik.com/supportsec/septem ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-86060 (secdb.nttzen.cloud/cve/detail/)
- Name: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260910 #cisa20260910 #cve_2026_67277 #cve_2026_86060 #cve202667277 #cve202686060

##

cisakevtracker@mastodon.social at 2026-09-10T20:01:01.000Z ##

CVE ID: CVE-2026-86060
Vendor: MikroTik
Product: RouterOS
Date Added: 2026-09-10
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-87794
(8.4 HIGH)

EPSS: 0.19%

updated 2026-09-10T19:58:20.507000

1 posts

bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands with Node.js process privileges. Fixed in 2.2.7 and 3.0.3.

thehackerwire@mastodon.social at 2026-09-09T12:00:25.000Z ##

๐ŸŸ  CVE-2026-87794 - High (8.4)

bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with cra...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53939
(9.1 CRITICAL)

EPSS: 0.20%

updated 2026-09-10T19:57:48.533000

1 posts

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS384`, or `A256CBC-HS512`) together with any key-management algorithm that generates a fresh content-encryption key (CEK), the CEK is all zero bytes instead of being

thehackerwire@mastodon.social at 2026-09-09T01:00:19.000Z ##

๐Ÿ”ด CVE-2026-53939 - Critical (9.1)

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS384`, or `A...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85704
(3.7 LOW)

EPSS: 0.27%

updated 2026-09-10T19:17:36.650000

1 posts

A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function getJailbreak of the file server/config.py of the component Jailbreak Mode. The manipulation results in race condition. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is assessed as difficu

hugovalters@mastodon.social at 2026-09-10T12:50:16.000Z ##

CVE-2026-85704: Race condition in Freegpt Webui (Jailbreak Mode, server/config.py) allows remote attacks, but high complexity makes exploitation difficult. CVSS 3.7. Public exploit exists. No patch available.

Update or monitor immediately. More: valtersit.com/cve/CVE

##

CVE-2026-89046
(8.2 HIGH)

EPSS: 0.00%

updated 2026-09-10T18:33:05

2 posts

zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnerability in Zstd.getFrameContentSize that fails to validate negative srcPosition arguments. Attackers can supply negative offset values that bypass bounds checks and reach the native frame-header parser, causing out-of-bounds memory reads that lead to information disclosure or JVM crashes.

thehackerwire@mastodon.social at 2026-09-10T19:00:33.000Z ##

๐ŸŸ  CVE-2026-89046 - High (8.2)

zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnerability in Zstd.getFrameContentSize that fails to validate negative srcPosition arguments. Attackers can supply negative offset values that bypass bounds checks and rea...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T19:00:33.000Z ##

๐ŸŸ  CVE-2026-89046 - High (8.2)

zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnerability in Zstd.getFrameContentSize that fails to validate negative srcPosition arguments. Attackers can supply negative offset values that bypass bounds checks and rea...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89042
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-10T18:33:04

2 posts

passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbitrary NameID and attributes to the assertion consumer service endpoint to receive authenticated profiles without valid signatures.

thehackerwire@mastodon.social at 2026-09-10T19:00:43.000Z ##

๐Ÿ”ด CVE-2026-89042 - Critical (9.1)

passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbit...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T19:00:43.000Z ##

๐Ÿ”ด CVE-2026-89042 - Critical (9.1)

passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbit...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85228
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-10T18:33:04

2 posts

An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted tensor payload. To remediate this issue, users should upgrade to version 0.37.0 or above.

thehackerwire@mastodon.social at 2026-09-10T18:00:33.000Z ##

๐Ÿ”ด CVE-2026-85228 - Critical (9.1)

An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a de...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T18:00:33.000Z ##

๐Ÿ”ด CVE-2026-85228 - Critical (9.1)

An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a de...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87995
(8.7 HIGH)

EPSS: 0.22%

updated 2026-09-10T18:18:11.740000

2 posts

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 until 0.11.1, src/lib/components/chat/FileNav/PortPreview.svelte rendered terminal port content in an iframe sandbox containing both allow-scripts and allow-same-origin. Because the terminal proxy serves that content from the Open WebUI origin, an authenticated user with access to a shared terminal se

thehackerwire@mastodon.social at 2026-09-09T23:00:25.000Z ##

๐ŸŸ  CVE-2026-87995 - High (8.7)

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 until 0.11.1, src/lib/components/chat/FileNav/PortPreview.svelte rendered terminal port content in an iframe sandbox containing both allow-scripts an...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-09T23:00:25.000Z ##

๐ŸŸ  CVE-2026-87995 - High (8.7)

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 until 0.11.1, src/lib/components/chat/FileNav/PortPreview.svelte rendered terminal port content in an iframe sandbox containing both allow-scripts an...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79323
(7.5 HIGH)

EPSS: 0.33%

updated 2026-09-10T17:48:35.100000

1 posts

Information disclosure in the blogComments GraphQL query in Magefan Blog GraphQL for Magento 2 (magefan/module-blog-graph-ql) through 2.2.1 allows remote unauthenticated attackers to obtain blog commenter email addresses and internal customer and admin identifiers via a POST request to /graphql.

thehackerwire@mastodon.social at 2026-09-09T21:04:34.000Z ##

๐ŸŸ  CVE-2026-79323 - High (7.5)

Information disclosure in the blogComments GraphQL query in Magefan Blog GraphQL for Magento 2 (magefan/module-blog-graph-ql) through 2.2.1 allows remote unauthenticated attackers to obtain blog commenter email addresses and internal customer and ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88889
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-10T16:18:11.693000

2 posts

Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attackers can inject shell commands through unescaped distributionType values to achieve remote code execution when Renovate processes Maven Wrapper updates in binarySour

thehackerwire@mastodon.social at 2026-09-10T15:00:03.000Z ##

๐ŸŸ  CVE-2026-88889 - High (7.8)

Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attackers can inj...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T15:00:03.000Z ##

๐ŸŸ  CVE-2026-88889 - High (7.8)

Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attackers can inj...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88289
(7.5 HIGH)

EPSS: 0.33%

updated 2026-09-10T16:18:10.657000

2 posts

GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR service.

thehackerwire@mastodon.social at 2026-09-10T11:00:14.000Z ##

๐ŸŸ  CVE-2026-88289 - High (7.5)

GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR s...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T11:00:14.000Z ##

๐ŸŸ  CVE-2026-88289 - High (7.5)

GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR s...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67593
(9.1 CRITICAL)

EPSS: 0.29%

updated 2026-09-10T16:17:45.273000

2 posts

A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes

DailyCyberSecurity at 2026-09-10T02:55:57.475Z ##

Critical Apache Artemis vulnerabilities, including CVE-2026-67593 and other ActiveMQ Artemis flaws, expose systems to denial of service and data exposure.

securityonline.info/apache-art

##

DailyCyberSecurity@infosec.exchange at 2026-09-10T02:55:57.000Z ##

Critical Apache Artemis vulnerabilities, including CVE-2026-67593 and other ActiveMQ Artemis flaws, expose systems to denial of service and data exposure.

#ApacheArtemis #Cybersecurity #Vulnerabilities #ActiveMQ #CVE202667593

securityonline.info/apache-art

##

CVE-2026-15913
(7.7 HIGH)

EPSS: 0.39%

updated 2026-09-10T15:53:23.707000

2 posts

In versions prior to 7.10.2 a path traversal vulnerability in theย /attachRemoteFiles endpointย of Fortra's GoAnywhere MFT allows Web Users with bothย Secure Folders and Secure Mail permissionsย to escape their sandboxed home directory, achieving arbitrary file read.

thehackerwire@mastodon.social at 2026-09-10T00:04:36.000Z ##

๐ŸŸ  CVE-2026-15913 - High (7.7)

In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T00:04:36.000Z ##

๐ŸŸ  CVE-2026-15913 - High (7.7)

In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-21096(CVSS UNKNOWN)

EPSS: 0.41%

updated 2026-09-10T15:34:15

1 posts

Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

cR0w@infosec.exchange at 2026-09-09T15:35:49.000Z ##

CATTE OVERFLOW I REPEAT CATTE OVERFLOW THIS IS NOT A DRILL :catte:

nvd.nist.gov/vuln/detail/cve-2

Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

##

CVE-2026-88890
(8.5 HIGH)

EPSS: 0.00%

updated 2026-09-10T15:33:28

2 posts

OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root export credentials can inject arbitrary ClickHouse SQL to bypass project isolation and read other organizations' analyti

thehackerwire@mastodon.social at 2026-09-10T15:00:12.000Z ##

๐ŸŸ  CVE-2026-88890 - High (8.5)

OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T15:00:12.000Z ##

๐ŸŸ  CVE-2026-88890 - High (8.5)

OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88887
(8.6 HIGH)

EPSS: 0.00%

updated 2026-09-10T15:33:28

2 posts

Renovate is a dependency update automation tool. When listing tags/digests for a container image, Renovate follows pagination links supplied by the remote registry in the HTTP Link header and attaches the registry credentials to the follow-up request without verifying that the pagination URL has the same origin as the original registry. A malicious or compromised container registry can therefore s

offseq at 2026-09-10T13:30:26.740Z ##

CRITICAL: CVE-2026-88887 in renovatebot renovate enables open redirect โ€” malicious registries can steal credentials using crafted Link headers. Upgrade to 44.11.2+ ASAP. More info: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-10T13:30:26.000Z ##

CRITICAL: CVE-2026-88887 in renovatebot renovate enables open redirect โ€” malicious registries can steal credentials using crafted Link headers. Upgrade to 44.11.2+ ASAP. More info: radar.offseq.com/threat/cve-20 #OffSeq #CVE202688887 #SupplyChain #ContainerSecurity

##

CVE-2026-88891
(8.3 HIGH)

EPSS: 0.00%

updated 2026-09-10T15:33:27

2 posts

OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedule entire projects for deletion, publish private analytics to public share links, and modify alerting rules by exploiting missing access level validation

thehackerwire@mastodon.social at 2026-09-10T15:00:22.000Z ##

๐ŸŸ  CVE-2026-88891 - High (8.3)

OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedul...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T15:00:22.000Z ##

๐ŸŸ  CVE-2026-88891 - High (8.3)

OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedul...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73786
(7.5 HIGH)

EPSS: 0.33%

updated 2026-09-10T15:33:12

1 posts

A vulnerability in the web-based management interface of CPPM could allow an unauthenticated remote attacker to conduct a Denial-of-Service (DoS) attack. Successful exploitation could allow an attacker to cause instability and degrade performance of the vulnerable CPPM server.

1 repos

https://github.com/promasu/CVE-2026-73786

thehackerwire@mastodon.social at 2026-09-09T21:01:11.000Z ##

๐ŸŸ  CVE-2026-73786 - High (7.5)

A vulnerability in the web-based management interface of CPPM could allow an unauthenticated remote attacker to conduct a Denial-of-Service (DoS) attack. Successful exploitation could allow an attacker to cause instability and degrade performance ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85983
(7.8 HIGH)

EPSS: 0.14%

updated 2026-09-10T15:17:50.033000

1 posts

The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's configuration. When the service restarts, the modified configuration can lead to code execution with the privileges of the service account.

thehackerwire@mastodon.social at 2026-09-09T03:00:18.000Z ##

๐ŸŸ  CVE-2026-85983 - High (7.8)

The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's configuration. When the service restarts, the modified configuration can ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82533
(9.6 CRITICAL)

EPSS: 0.42%

updated 2026-09-10T15:17:47.593000

1 posts

DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that grants unauthenticated access to its local HTTP agent-control API by accepting a client-supplied loopback Host header in place of validating the actual TCP connection origin. On the default configuration, a confined tool-executed process can reach the loopback API without any port exposure and use it to esca

blog@spcnet.it at 2026-09-10T11:05:13.000Z ##

CVE-2026-82533: la falla in DeepSeek Harness che lasciava agli agenti AI le chiavi della propria sandbox

Un'interfaccia locale priva di autenticazione e vulnerabile a host header spoofing permetteva agli agenti di DeepSeek Harness di disattivare la propria sandbox con un solo comando. Analisi tecnica di CVE-2026-82533 (CVSS 9.4) e consigli pratici per proteggere gli ambienti dove girano coding agent AI.

spcnet.it/cve-2026-82533-la-fa

##

CVE-2026-6485
(8.2 HIGH)

EPSS: 0.12%

updated 2026-09-10T15:17:39.427000

1 posts

UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.

thehackerwire@mastodon.social at 2026-09-09T09:01:59.000Z ##

๐ŸŸ  CVE-2026-6485 - High (8.2)

UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-69420
(7.8 HIGH)

EPSS: 0.32%

updated 2026-09-10T15:17:37.937000

1 posts

Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to elevate privileges locally.

winterknight1337@infosec.exchange at 2026-09-08T22:18:42.000Z ##

CVE-2026-69420 is a heap based buffer overflow on Windows resulting in an LPE. Couldnโ€™t have come up with a more memey CVE for 69420 if I tried.

##

CVE-2026-87996
(7.7 HIGH)

EPSS: 0.21%

updated 2026-09-10T15:10:12

2 posts

## Summary With the Playwright web loader enabled, Open WebUI checks the address behind a user-submitted URL before allowing the request, then handed the request to the browser to perform. The browser resolved the hostname a second time, on its own, and that answer was never checked. An attacker who controls the authoritative DNS for a hostname they submit can answer the first lookup with a public

thehackerwire@mastodon.social at 2026-09-09T23:00:35.000Z ##

๐ŸŸ  CVE-2026-87996 - High (7.7)

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.1, SafePlaywrightURLLoader in backend/open_webui/retrieval/web/utils.py validated a user-controlled hostname in Python and then let the Pla...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-09T23:00:35.000Z ##

๐ŸŸ  CVE-2026-87996 - High (7.7)

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.1, SafePlaywrightURLLoader in backend/open_webui/retrieval/web/utils.py validated a user-controlled hostname in Python and then let the Pla...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-0307
(0 None)

EPSS: 0.10%

updated 2026-09-10T14:50:07.813000

1 posts

Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtectโ„ข app allows a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges. This GlobalProtect app on iOS, Android and ChromeOS is not impacted.

CVE-2026-15019
(7.5 HIGH)

EPSS: 0.68%

updated 2026-09-10T14:39:13.757000

2 posts

The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The product ownership check only verifies that some free, virtual, downloada

thehackerwire@mastodon.social at 2026-09-10T06:01:01.000Z ##

๐ŸŸ  CVE-2026-15019 - High (7.5)

The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible for unauthenticated attackers to read the content...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T06:01:01.000Z ##

๐ŸŸ  CVE-2026-15019 - High (7.5)

The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible for unauthenticated attackers to read the content...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-4800
(8.1 HIGH)

EPSS: 2.76%

updated 2026-09-10T13:20:23.210000

2 posts

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions tha

2 repos

https://github.com/threalwinky/CVE-2026-4800-POC

https://github.com/SvenLie/next-rep-CVE-2026-4800

certvde at 2026-09-10T07:33:05.830Z ##

๐Ÿ”„ CSAF advisory updated (version 2.0.0)

VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)

Changes: corrected version

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

##

certvde@infosec.exchange at 2026-09-10T07:33:05.000Z ##

๐Ÿ”„ CSAF advisory updated (version 2.0.0)

VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)

Changes: corrected version

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

#OT #Advisory

##

CVE-2026-39821
(9.6 CRITICAL)

EPSS: 0.69%

updated 2026-09-10T13:19:50.873000

2 posts

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "examp

certvde at 2026-09-10T07:33:05.830Z ##

๐Ÿ”„ CSAF advisory updated (version 2.0.0)

VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)

Changes: corrected version

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

##

certvde@infosec.exchange at 2026-09-10T07:33:05.000Z ##

๐Ÿ”„ CSAF advisory updated (version 2.0.0)

VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)

Changes: corrected version

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

#OT #Advisory

##

CVE-2026-87491
(8.8 HIGH)

EPSS: 0.76%

updated 2026-09-10T12:49:02.630000

13 posts

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

1 repos

https://github.com/SneakyNachos/CVE-2026-87491-and-CVE-2026-85046-the-bagel-fell-off-the-counter

hackmag at 2026-09-10T22:32:52.684Z ##

โšช๏ธ Google Chrome Patches Another Zero-Day Vulnerability

๐Ÿ—จ๏ธ Google developers have released an update for the Chrome browser that fixes 230 vulnerabilities, including a zero-day flaw in the V8 engine (CVE-2026-87491) that is already being exploited in attacks. The bug allows a remote attacker to achieve arbitrary codeโ€ฆ

๐Ÿ”— hackmag.com/news/chrome-7th-0d

##

beyondmachines1 at 2026-09-10T08:01:13.314Z ##

Google Patches Chrome Zero-Day and 229 Other Flaws in Version 153

Google released Chrome 153 to fix 230 vulnerabilities, including an actively exploited V8 zero-day (CVE-2026-87491) and five critical flaws in WebGL and Cast.

**This one is urgent, again. Actively exploited flaw and a bunch of fixes. Update Google Chrome to version 153.0.8010.36/.37 for Windows and macOS, or 153.0.8010.36 for Linux. Users of Microsoft Edge, Brave, Opera, Vivaldi, and other Chromium-based browsers. Don't delay, the tabs reopen after an update.**

beyondmachines.net/event_detai

##

Matchbook3469@mastodon.social at 2026-09-10T00:33:59.000Z ##

๐ŸŸ  New security advisory:

CVE-2026-87491 affects Google Chrome.

โ€ข Impact: Significant security breach potential
โ€ข Risk: Unauthorized access or data exposure
โ€ข Mitigation: Apply patches within 24-48 hours

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#Cybersecurity #ZeroDay #ThreatIntel

##

threatnoir at 2026-09-10T00:06:04.781Z ##

โš ๏ธ CRITICAL: Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google patched CVE-2026-87491, a zero-day out-of-bounds write in Chrome's V8 engine actively exploited in the wild. Attackers can execute arbitrary code within the browser sandbox via crafted HTML, potentially compromising any user visiting a malicious page. This is the seventh exploited Chrome zerโ€ฆ

threatnoir.com/focus

๐Ÿค– AI generated summary

##

hackmag@infosec.exchange at 2026-09-10T22:32:52.000Z ##

โšช๏ธ Google Chrome Patches Another Zero-Day Vulnerability

๐Ÿ—จ๏ธ Google developers have released an update for the Chrome browser that fixes 230 vulnerabilities, including a zero-day flaw in the V8 engine (CVE-2026-87491) that is already being exploited in attacks. The bug allows a remote attacker to achieve arbitrary codeโ€ฆ

๐Ÿ”— hackmag.com/news/chrome-7th-0d

#news

##

beyondmachines1@infosec.exchange at 2026-09-10T08:01:13.000Z ##

Google Patches Chrome Zero-Day and 229 Other Flaws in Version 153

Google released Chrome 153 to fix 230 vulnerabilities, including an actively exploited V8 zero-day (CVE-2026-87491) and five critical flaws in WebGL and Cast.

**This one is urgent, again. Actively exploited flaw and a bunch of fixes. Update Google Chrome to version 153.0.8010.36/.37 for Windows and macOS, or 153.0.8010.36 for Linux. Users of Microsoft Edge, Brave, Opera, Vivaldi, and other Chromium-based browsers. Don't delay, the tabs reopen after an update.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

threatnoir@infosec.exchange at 2026-09-10T00:06:04.000Z ##

โš ๏ธ CRITICAL: Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google patched CVE-2026-87491, a zero-day out-of-bounds write in Chrome's V8 engine actively exploited in the wild. Attackers can execute arbitrary code within the browser sandbox via crafted HTML, potentially compromising any user visiting a malicious page. This is the seventh exploited Chrome zerโ€ฆ

threatnoir.com/focus

#infosec #cybersecurity

๐Ÿค– AI generated summary

##

secdb@infosec.exchange at 2026-09-09T21:00:26.000Z ##

๐Ÿšจ [CISA-2026:0909] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

โš ๏ธ CVE-2025-25249 (secdb.nttzen.cloud/cve/detail/)
- Name: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Fortinet
- Product: Multiple Products
- Notes: fortiguard.fortinet.com/psirt/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-19490 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: support.citrix.com/external/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-20079 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-87491 (secdb.nttzen.cloud/cve/detail/)
- Name: Google Chromium V8 Out of Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Chromium V8
- Notes: chromereleases.googleblog.com/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260909 #cisa20260909 #cve_2025_25249 #cve_2026_19490 #cve_2026_20079 #cve_2026_87491 #cve202525249 #cve202619490 #cve202620079 #cve202687491

##

cisakevtracker@mastodon.social at 2026-09-09T20:01:25.000Z ##

CVE ID: CVE-2026-87491
Vendor: Google
Product: Chromium V8
Date Added: 2026-09-09
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

jbhall56@infosec.exchange at 2026-09-09T12:46:30.000Z ##

The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. thehackernews.com/2026/09/chro

##

ssvc@infosec.exchange at 2026-09-09T12:33:54.000Z ##

Google Chrome #zeroday

Google is aware that an exploit for CVE-2026-87491 exists in the wild.

chromereleases.googleblog.com/

#Google #Chrome #CVE

##

cyberworldops@infosec.exchange at 2026-09-09T11:40:01.000Z ##

Google fixed CVE-2026-87491, an out-of-bounds write in Chrome V8 exploited in the wild via crafted HTML. It enables arbitrary code execution inside the sandbox with risk of heap corruption and memory disclosure. Patch to version 153 immediately and hunt for anomalous browser activity. #ChromeSecurity #ZeroDay #ThreatIntel

cyberworldops.eu/en/chrome-v8-

##

DailyCyberSecurity@infosec.exchange at 2026-09-09T00:17:29.000Z ##

Google patched a Chrome zero-day, CVE-2026-87491, exploited in the wild. Chrome 153 fixes 230 flaws including critical WebGL bugs. Update now.

#Chrome #ZeroDay #Google #CyberSecurity #CVE #V8 #BrowserSecurity #Infosec

securityonline.info/chrome-zer

##

CVE-2026-19490
(9.8 CRITICAL)

EPSS: 6.00%

updated 2026-09-10T12:48:10.453000

2 posts

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

2 repos

https://github.com/BishopFox/CVE-2026-19490-check

https://github.com/TarPeg007/CVE-2026-19490

secdb@infosec.exchange at 2026-09-09T21:00:26.000Z ##

๐Ÿšจ [CISA-2026:0909] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

โš ๏ธ CVE-2025-25249 (secdb.nttzen.cloud/cve/detail/)
- Name: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Fortinet
- Product: Multiple Products
- Notes: fortiguard.fortinet.com/psirt/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-19490 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: support.citrix.com/external/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-20079 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-87491 (secdb.nttzen.cloud/cve/detail/)
- Name: Google Chromium V8 Out of Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Chromium V8
- Notes: chromereleases.googleblog.com/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260909 #cisa20260909 #cve_2025_25249 #cve_2026_19490 #cve_2026_20079 #cve_2026_87491 #cve202525249 #cve202619490 #cve202620079 #cve202687491

##

cisakevtracker@mastodon.social at 2026-09-09T20:00:53.000Z ##

CVE ID: CVE-2026-19490
Vendor: Citrix
Product: NetScaler
Date Added: 2026-09-09
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2025-25249
(8.1 HIGH)

EPSS: 1.70%

updated 2026-09-10T12:47:59.933000

5 posts

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets

cyberworldops at 2026-09-10T08:30:00.916Z ##

Fortinet CVE-2025-25249, an unauthenticated heap-based buffer overflow RCE, is being exploited at scale to deploy PivotC2 RAT. CISA added it to KEV on 2026-09-09 with remediation due 2026-09-12. Unpatched Fortinet perimeter devices should be assumed compromised and investigated for RAT persistence.

cyberworldops.eu/en/fortinet-c

##

cyberworldops@infosec.exchange at 2026-09-10T08:30:00.000Z ##

Fortinet CVE-2025-25249, an unauthenticated heap-based buffer overflow RCE, is being exploited at scale to deploy PivotC2 RAT. CISA added it to KEV on 2026-09-09 with remediation due 2026-09-12. Unpatched Fortinet perimeter devices should be assumed compromised and investigated for RAT persistence. #Fortinet #PivotC2 #ThreatIntel

cyberworldops.eu/en/fortinet-c

##

secdb@infosec.exchange at 2026-09-09T21:00:26.000Z ##

๐Ÿšจ [CISA-2026:0909] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

โš ๏ธ CVE-2025-25249 (secdb.nttzen.cloud/cve/detail/)
- Name: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Fortinet
- Product: Multiple Products
- Notes: fortiguard.fortinet.com/psirt/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-19490 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: support.citrix.com/external/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-20079 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-87491 (secdb.nttzen.cloud/cve/detail/)
- Name: Google Chromium V8 Out of Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Chromium V8
- Notes: chromereleases.googleblog.com/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260909 #cisa20260909 #cve_2025_25249 #cve_2026_19490 #cve_2026_20079 #cve_2026_87491 #cve202525249 #cve202619490 #cve202620079 #cve202687491

##

cisakevtracker@mastodon.social at 2026-09-09T20:01:09.000Z ##

CVE ID: CVE-2025-25249
Vendor: Fortinet
Product: Multiple Products
Date Added: 2026-09-09
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

threatcodex@infosec.exchange at 2026-09-08T17:20:17.000Z ##

CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT
#CVE_2025_25249 #PivotC2
socradar.io/blog/cve-2025-2524

##

CVE-2026-78082(CVSS UNKNOWN)

EPSS: 0.49%

updated 2026-09-10T12:31:26

2 posts

Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 - The property search and listing query builders assembled several WHERE and ORDER BY clauses (zipcode, sorting, price_range_dropdown, and psize_range_dropdown) by directly concatenating raw request parameters into SQL strings without quoting or type casting. An unauthentic

offseq at 2026-09-10T10:30:24.303Z ##

CVE-2026-78082: SP Property extension for Joomla v1.0.0-4.1.3 suffers CRITICAL SQL injection (CVSS 9.3). Unauthenticated attackers can extract DB data via blind injection. Patch status unknown โ€” check vendor guidance. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-10T10:30:24.000Z ##

CVE-2026-78082: SP Property extension for Joomla v1.0.0-4.1.3 suffers CRITICAL SQL injection (CVSS 9.3). Unauthenticated attackers can extract DB data via blind injection. Patch status unknown โ€” check vendor guidance. radar.offseq.com/threat/cve-20 #OffSeq #Joomla #SQLi #Infosec

##

CVE-2026-8323
(9.3 CRITICAL)

EPSS: 0.25%

updated 2026-09-10T09:31:48

2 posts

URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the Source of Data. This issue affects Access Control System: before Versiyon 2.

thehackerwire@mastodon.social at 2026-09-10T11:00:35.000Z ##

๐Ÿ”ด CVE-2026-8323 - Critical (9.3)

URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the Source of Data.

This issue affects Access Control System: before Versiyon 2.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T11:00:35.000Z ##

๐Ÿ”ด CVE-2026-8323 - Critical (9.3)

URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the Source of Data.

This issue affects Access Control System: before Versiyon 2.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88290
(7.5 HIGH)

EPSS: 0.26%

updated 2026-09-10T09:31:48

2 posts

GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR frame lengths and indefinitely delay blocking receives, allowing remote exhaustion of memory, connection, and worker resources.

thehackerwire@mastodon.social at 2026-09-10T11:00:24.000Z ##

๐ŸŸ  CVE-2026-88290 - High (7.5)

GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR frame lengths and indefinitely delay blocking receives, allowing remote exhaustion of memory, connection, and worker resources.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T11:00:24.000Z ##

๐ŸŸ  CVE-2026-88290 - High (7.5)

GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR frame lengths and indefinitely delay blocking receives, allowing remote exhaustion of memory, connection, and worker resources.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13745(CVSS UNKNOWN)

EPSS: 0.30%

updated 2026-09-10T09:31:37

2 posts

A vulnerability in the Gemini CLI and associated GitHub Action allowed an unprivileged attackerย to achieve an arbitrary code execution in Gemini CLI via untrusted local .env files overriding GEMINI_CLI_HOME.

offseq at 2026-09-10T09:00:26.166Z ##

CVE-2026-13745: CRITICAL vuln (CVSS 9.2) in Google Cloud Gemini CLI allows arbitrary code execution via untrusted .env files overriding GEMINI_CLI_HOME. Review .env file usage & restrict access. More info: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-10T09:00:26.000Z ##

CVE-2026-13745: CRITICAL vuln (CVSS 9.2) in Google Cloud Gemini CLI allows arbitrary code execution via untrusted .env files overriding GEMINI_CLI_HOME. Review .env file usage & restrict access. More info: radar.offseq.com/threat/cve-20 #OffSeq #GoogleCloud #Vulnerability #InfoSec

##

CVE-2026-87931
(9.6 CRITICAL)

EPSS: 0.45%

updated 2026-09-10T06:32:50

2 posts

A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation leads to buffer overflow. The attack must be carried out from within the local network. The vendor was contacted early about this disclosure but did not respond in any

offseq at 2026-09-10T00:00:52.552Z ##

CVE-2026-87931 | CRITICAL buffer overflow in Pavlok Behavioral Conditioning Wearable (Apple Notification Center Service Event Handler). Exploitable locally, no patch or vendor response. Limit device network access. Details: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-10T00:00:52.000Z ##

CVE-2026-87931 | CRITICAL buffer overflow in Pavlok Behavioral Conditioning Wearable (Apple Notification Center Service Event Handler). Exploitable locally, no patch or vendor response. Limit device network access. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE202687931 #IoTSecurity

##

CVE-2026-0310(CVSS UNKNOWN)

EPSS: 0.34%

updated 2026-09-10T06:31:55

6 posts

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OSยฎ software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls. The security risk posed by this issue is minimiz

threatcodex at 2026-09-10T18:39:08.028Z ##

CVE-2026-0310: PAN-OS Buffer Overflow Can Enable Root RCE on PA-Series Firewalls

socprime.com/blog/cve-2026-031

##

threatcodex@infosec.exchange at 2026-09-10T18:39:08.000Z ##

CVE-2026-0310: PAN-OS Buffer Overflow Can Enable Root RCE on PA-Series Firewalls
#CVE_2026_0310
socprime.com/blog/cve-2026-031

##

cR0w@infosec.exchange at 2026-09-09T17:10:22.000Z ##

RE: infosec.exchange/@cR0w/1172419

Seriously, maybe take a good look at CVE-2026-0310.

CVSS-BT: 7.2 / **CVSS-B: 9.2** (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Red)

##

DailyCyberSecurity@infosec.exchange at 2026-09-09T17:06:44.000Z ##

A new PAN-OS buffer overflow flaw, tracked as CVE-2026-0310, exposes firewalls to remote code execution. Patch your network devices immediately.

#PANOS #BufferOverflow #CVE20260310 #Cybersecurity #PaloAltoNetworks

securityonline.info/pan-os-buf

##

cR0w@infosec.exchange at 2026-09-09T16:12:33.000Z ##

RE: infosec.exchange/@cR0w/1172369

lol. lmao even.

security.paloaltonetworks.com/

security.paloaltonetworks.com/

##

AAKL@infosec.exchange at 2026-09-09T16:10:40.000Z ##

Broadcom has a long list of advisories today for high and medium-severity vulnerabilities support.broadcom.com/web/ecx/s #Broadcom #Linux

Palo Alto:

Palo Alto has several advisories, one of them critical:

CRITICAL: CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing security.paloaltonetworks.com/

More: security.paloaltonetworks.com/

Cisco:

CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco

Dell:

A Dell release that impacts multiple CVEs: Security Update for Dell PowerScale OneFS Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell

Posted yesterday:

Apple:

Several releases were posted yesterday support.apple.com/en-us/100100 #Apple #iOS

AMD:

AMD: Linux GPU Driver NULL Pointer Dereference amd.com/en/resources/product-s #AMD

Adobe:

Adobe has a long list of updates here helpx.adobe.com/security/secur #Adobe #infosec #vulnerability

@cR0w

##

CVE-2026-14873
(8.0 HIGH)

EPSS: 0.24%

updated 2026-09-10T06:31:42

2 posts

The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating a user's identity prior to updating their details like arbitrary user passwords, including administrator passwords, to a known plugin-configured custom value, enabling full account takeover of the site

thehackerwire@mastodon.social at 2026-09-10T06:00:48.000Z ##

๐ŸŸ  CVE-2026-14873 - High (8)

The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating a user's identity prior to updating their detail...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T06:00:48.000Z ##

๐ŸŸ  CVE-2026-14873 - High (8)

The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating a user's identity prior to updating their detail...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87628
(8.3 HIGH)

EPSS: 0.17%

updated 2026-09-10T04:18:29.850000

1 posts

Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical)

offseq@infosec.exchange at 2026-09-09T01:30:26.000Z ##

CVE-2026-87628: CRITICAL use-after-free in Chrome's Cast (<153.0.8010.36) enables adjacent code execution outside the sandbox. Patch status unconfirmed. Check the vendor advisory: radar.offseq.com/threat/cve-20 #OffSeq #Chrome #Vuln #CVE202687628

##

CVE-2026-69730
(9.8 CRITICAL)

EPSS: 1.05%

updated 2026-09-10T04:18:14.773000

4 posts

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

lrosa@mastodon.uno at 2026-09-10T03:46:13.000Z ##

Esecuzione remota di programmi (RCE) da remoto senza autenticazione sui server DNS di Microsoft.

Problema risolto con gli ultimi aggiornamenti.

Quasi tutti i Domain Controller hanno un server DNS a bordo e la vulnerabilitร  รจ sfruttabile con richieste DNS, quindi non bloccabili da un normale firewall.

msrc.microsoft.com/update-guid

##

i0null at 2026-09-09T22:38:29.832Z ##

@pkprotoplasm the infamous phrase is used on the FAQ of the MSRC advisory. the NIST description is even more generic.

msrc.microsoft.com/update-guid

##

i0null@infosec.exchange at 2026-09-09T22:38:29.000Z ##

@pkprotoplasm the infamous phrase is used on the FAQ of the MSRC advisory. the NIST description is even more generic.

msrc.microsoft.com/update-guid

##

security_crawler_carl@infosec.exchange at 2026-09-09T00:46:57.000Z ##

Meanwhile CVE-2026-69829 is a CVSS 9.8 heap overflow in Windows Shell letting unauthenticated attackers run code over a network. I called the mechanics. I drew the diagram. I made a spreadsheet.

Patch CVE-2026-81963, CVE-2026-85880, CVE-2026-69730, and CVE-2026-69829 immediately โ€” yes, right now, before you ask if it can wait until Friday.

Reward: You've received the Tunnel Vision Debuff. It cannot be cleansed.

#ZeroDay #Microsoft #WindowsUpdate #PrivilegeEscalation #CyberSecurity (2/2)

##

CVE-2016-7255
(7.8 HIGH)

EPSS: 80.97%

updated 2026-09-10T04:17:32.400000

2 posts

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."

5 repos

https://github.com/yuvatia/page-table-exploitation

https://github.com/bbolmin/cve-2016-7255_x86_x64

https://github.com/FSecureLABS/CVE-2016-7255

https://github.com/homjxi0e/CVE-2016-7255

https://github.com/heh3/CVE-2016-7255

kev_Stalker at 2026-09-10T11:30:23.497Z ##

CVE-2016-7255 - Changed to Known Ransomware Status

Microsoft Win32k Privilege Escalation VulnerabilityVendor: MicrosoftProduct: Win32kMicrosoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 09, 2026 at 14:08:17 UTCDate nvd.nist.gov/vuln/detail/CVE-2

##

kev_Stalker@infosec.exchange at 2026-09-10T11:30:23.000Z ##

CVE-2016-7255 - Changed to Known Ransomware Status

Microsoft Win32k Privilege Escalation VulnerabilityVendor: MicrosoftProduct: Win32kMicrosoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 09, 2026 at 14:08:17 UTCDate nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-19584
(7.7 HIGH)

EPSS: 0.19%

updated 2026-09-10T03:30:27

2 posts

Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user with NOTEBOOK_EDITOR permission to plant a VQL query which will be evaluated at elevated permissions if the notebook's backup is subsequently restored.

thehackerwire@mastodon.social at 2026-09-10T06:01:16.000Z ##

๐ŸŸ  CVE-2026-19584 - High (7.7)

Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T06:01:16.000Z ##

๐ŸŸ  CVE-2026-19584 - High (7.7)

Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18351
(9.8 CRITICAL)

EPSS: 0.77%

updated 2026-09-10T03:30:27

2 posts

The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type validation in the is_file_type_valid() function, which uses the attacker-controlled 'type' parameter as regex keys in the MIME allowlist, allowing blacklist bypass via

offseq at 2026-09-10T03:00:31.108Z ##

CVE-2026-18351 (CRITICAL): addonsorg Drag and Drop File Upload for Elementor Forms <=1.6.0 lets unauthenticated attackers upload arbitrary files โ€” enabling RCE. Restrict or disable plugin use until remediation. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-10T03:00:31.000Z ##

CVE-2026-18351 (CRITICAL): addonsorg Drag and Drop File Upload for Elementor Forms <=1.6.0 lets unauthenticated attackers upload arbitrary files โ€” enabling RCE. Restrict or disable plugin use until remediation. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #RCE

##

CVE-2026-19583
(9.9 CRITICAL)

EPSS: 0.60%

updated 2026-09-10T03:30:26

2 posts

Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for client monitoring artifacts. Additionally there was no requirement that client monitoring artifacts carry the CLIENT_EVENTS

offseq at 2026-09-10T04:30:24.651Z ##

CVE-2026-19583: CRITICAL vuln in Rapid7 Velociraptor (<0.77.2) allows users w/ artifact scheduling rights to execute privileged artifacts like Linux.Sys.BashShell โ€” risking full compromise. Restrict permissions, monitor activity. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-10T04:30:24.000Z ##

CVE-2026-19583: CRITICAL vuln in Rapid7 Velociraptor (<0.77.2) allows users w/ artifact scheduling rights to execute privileged artifacts like Linux.Sys.BashShell โ€” risking full compromise. Restrict permissions, monitor activity. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Infosec

##

CVE-2026-88069(CVSS UNKNOWN)

EPSS: 0.33%

updated 2026-09-10T00:30:34

2 posts

Pandora contains a path traversal vulnerability in its archive extraction worker. When processing a specially crafted archive or disk image, attacker-controlled file paths could be used without ensuring that the resulting destination remained within the intended extraction directory. An attacker able to submit a malicious file for analysis could use path traversal sequences or crafted paths to ca

offseq at 2026-09-10T01:30:24.171Z ##

CVE-2026-88069: Path traversal in pandora-analysis pandora (<=1.12.7) allows attackers to overwrite system/app files via crafted archives. Severity: CRITICAL (CVSS 9.3). No patch confirmed โ€” monitor vendor updates. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-10T01:30:24.000Z ##

CVE-2026-88069: Path traversal in pandora-analysis pandora (<=1.12.7) allows attackers to overwrite system/app files via crafted archives. Severity: CRITICAL (CVSS 9.3). No patch confirmed โ€” monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE202688069 #vuln #infosec

##

CVE-2026-79324
(7.5 HIGH)

EPSS: 0.32%

updated 2026-09-09T21:32:03

1 posts

Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through 4.2.9 allows remote unauthenticated attackers to delete any customer's saved address, and to erase all stored addresses by iterating the address id, via a GET request to /customer/address/delete/id/{id}. The controller extends the legacy Action class instead of AbstractAccount, so

thehackerwire@mastodon.social at 2026-09-09T21:01:00.000Z ##

๐ŸŸ  CVE-2026-79324 - High (7.5)

Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through 4.2.9 allows remote unauthenticated attackers to delete any customer's saved address, and to erase all stored addresses by itera...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79322
(8.6 HIGH)

EPSS: 0.28%

updated 2026-09-09T21:31:56

2 posts

SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-extension) through 4.3.2 allows remote unauthenticated attackers to execute arbitrary SQL commands and read arbitrary database contents via the id parameter to /mpblog/post/view.

thehackerwire@mastodon.social at 2026-09-09T21:04:44.000Z ##

๐ŸŸ  CVE-2026-79322 - High (8.6)

SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-extension) through 4.3.2 allows remote unauthenticated attackers to execute arbitrary SQL commands and read arbitrary database contents via the id ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-09T21:04:44.000Z ##

๐ŸŸ  CVE-2026-79322 - High (8.6)

SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-extension) through 4.3.2 allows remote unauthenticated attackers to execute arbitrary SQL commands and read arbitrary database contents via the id ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20079
(10.0 CRITICAL)

EPSS: 74.70%

updated 2026-09-09T21:31:33

21 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerab

2 repos

https://github.com/CyberAuth/CVE-2026-20079

https://github.com/0xBlackash/CVE-2026-20079

cyberworldops at 2026-09-10T17:00:00.702Z ##

Cisco Talos reports active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center by Qilin ransomware, credential-theft actors, and Sandworm-linked groups. The auth bypass provides root command execution and the static credential exposure broadens initial access.

cyberworldops.eu/en/cisco-fmc-

##

undercodenews@mastodon.social at 2026-09-10T16:48:33.000Z ##

Cisco FMC Under Attack as Sandworm and Qilin Exploit Critical Vulnerabilities to Reach Protected Networks + Video

A New Warning for Enterprise Defenders Cisco Secure Firewall Management Center is facing a serious security crisis after Cisco Talos confirmed active exploitation of two vulnerabilities that can give attackers a foothold inside vulnerable environments. The flaws, tracked as CVE-2026-20079 and CVE-2026-20316, are being abused in real-world attacks involvingโ€ฆ

undercodenews.com/cisco-fmc-un

##

cyberveille@mastobot.ping.moi at 2026-09-10T15:00:05.000Z ##

๐Ÿ“ข Cisco confirme l'exploitation active de CVE-2026-20079, faille critique dans Secure FMC

BleepingComputer, publiรฉ le 9 septembre 2026. Cisco a officiellement confirmรฉ l'exploitation active de CVE-2026-20079, une vulnรฉrabilitรฉ d'authentification bypass de sรฉvรฉritรฉ maximale (CVSS 10.0) affectant son logiciel Cisco Secure Firewall Management Centerโ€ฆ

๐Ÿ“– cyberveille : cyberveille.ch/posts/2026-09-1
๐ŸŒ source : bleepingcomputer.com/news/secu
๐ŸŸข vรฉrification factuelle haute
#CISAKEV #CiscoSecureFMC #Cyberveille

##

jbhall56 at 2026-09-10T12:53:19.814Z ##

The vulnerability has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts and commands as root on vulnerable devices. bleepingcomputer.com/news/secu

##

beyondmachines1 at 2026-09-10T10:01:13.581Z ##

Cisco Secure Firewall Management Center Under Active Attack

Cisco Talos warns of active exploitation of two vulnerabilities (CVE-2026-20079 and CVE-2026-20316) in Secure Firewall Management Center, allowing attackers to gain root access and deploy malware like Cyclops Blink and Qilin ransomware.

**If you run Cisco Secure Firewall Management Center (versions 7.0.x, 7.1.x, or 7.2โ€“7.7), apply Cisco's emergency patches for CVE-2026-20079 and CVE-2026-20316 right away. Make sure the management interface is reachable only from trusted internal networks, never the internet. Because these flaws are already being exploited, also check for unexpected files in /var/sf/bin/ and the Tomcat webroot. Then plan to install Cisco's hardening update due to be released in the week of September 14.**

beyondmachines.net/event_detai

##

cyberworldops at 2026-09-10T00:50:00.849Z ##

Cisco confirmed active exploitation of CVE-2026-20079, a CVSS 10.0 authentication bypass in Secure FMC. Unauthenticated remote attackers can execute commands as root via crafted HTTP requests, compromising firewall management. Immediate patching and exposure review are critical.

cyberworldops.eu/en/cisco-secu

##

bleepingcomputer.com@web.brid.gy at 2026-09-09T21:40:44.000Z ##

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

fed.brid.gy/r/https://www.blee

##

undercodenews@mastodon.social at 2026-09-09T22:17:51.000Z ##

Cisco Secure Firewall Crisis Deepens as CVE-2026-20079 Becomes an Actively Exploited Root-Level Threat + Video

A Maximum-Severity Flaw Has Crossed the Line A critical warning is now hanging over organizations that rely on Cisco Secure Firewall Management Center (FMC): a vulnerability once described as having no evidence of exploitation has now been confirmed as actively abused in real-world attacks. Tracked as CVE-2026-20079, the flaw carries the maximum possible CVSSโ€ฆ

undercodenews.com/cisco-secure

##

patrickcmiller at 2026-09-09T22:12:01.834Z ##

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks bleepingcomputer.com/news/secu

##

oversecurity@mastodon.social at 2026-09-09T22:01:24.000Z ##

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center...

๐Ÿ”—๏ธ [Bleepingcomputer] link.is.it/y6fb5Q

##

cyberworldops@infosec.exchange at 2026-09-10T17:00:00.000Z ##

Cisco Talos reports active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center by Qilin ransomware, credential-theft actors, and Sandworm-linked groups. The auth bypass provides root command execution and the static credential exposure broadens initial access.

#CiscoFMC #ThreatIntelligence #VulnerabilityManagement #Qilin

cyberworldops.eu/en/cisco-fmc-

##

jbhall56@infosec.exchange at 2026-09-10T12:53:19.000Z ##

The vulnerability has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts and commands as root on vulnerable devices. bleepingcomputer.com/news/secu

##

beyondmachines1@infosec.exchange at 2026-09-10T10:01:13.000Z ##

Cisco Secure Firewall Management Center Under Active Attack

Cisco Talos warns of active exploitation of two vulnerabilities (CVE-2026-20079 and CVE-2026-20316) in Secure Firewall Management Center, allowing attackers to gain root access and deploy malware like Cyclops Blink and Qilin ransomware.

**If you run Cisco Secure Firewall Management Center (versions 7.0.x, 7.1.x, or 7.2โ€“7.7), apply Cisco's emergency patches for CVE-2026-20079 and CVE-2026-20316 right away. Make sure the management interface is reachable only from trusted internal networks, never the internet. Because these flaws are already being exploited, also check for unexpected files in /var/sf/bin/ and the Tomcat webroot. Then plan to install Cisco's hardening update due to be released in the week of September 14.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

cyberworldops@infosec.exchange at 2026-09-10T00:50:00.000Z ##

Cisco confirmed active exploitation of CVE-2026-20079, a CVSS 10.0 authentication bypass in Secure FMC. Unauthenticated remote attackers can execute commands as root via crafted HTTP requests, compromising firewall management. Immediate patching and exposure review are critical. #CiscoFmc #AuthBypass #CriticalVulnerability

cyberworldops.eu/en/cisco-secu

##

patrickcmiller@infosec.exchange at 2026-09-09T22:12:01.000Z ##

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks bleepingcomputer.com/news/secu

##

oversecurity@mastodon.social at 2026-09-09T22:01:24.000Z ##

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center...

๐Ÿ”—๏ธ [Bleepingcomputer] link.is.it/y6fb5Q

##

ssvc@infosec.exchange at 2026-09-09T21:01:44.000Z ##

Cisco Talos is actively tracking the exploitation of two vulnerabilities in Ciscoโ€™s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Ciscoโ€™s Secure FMC Software, which allows an unauthenticated, remote attacker to bypass authentications and execute scripts on impacted devices to obtain root access to the underlying operating system. Second, CVE-2026-20316 is a vulnerability that allows a remote attacker to log in using a low-privileged account.

blog.talosintelligence.com/fmc

#threatintel #ransomware #Qilin #KEV #CVE

##

secdb@infosec.exchange at 2026-09-09T21:00:26.000Z ##

๐Ÿšจ [CISA-2026:0909] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

โš ๏ธ CVE-2025-25249 (secdb.nttzen.cloud/cve/detail/)
- Name: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Fortinet
- Product: Multiple Products
- Notes: fortiguard.fortinet.com/psirt/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-19490 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: support.citrix.com/external/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-20079 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-87491 (secdb.nttzen.cloud/cve/detail/)
- Name: Google Chromium V8 Out of Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Chromium V8
- Notes: chromereleases.googleblog.com/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260909 #cisa20260909 #cve_2025_25249 #cve_2026_19490 #cve_2026_20079 #cve_2026_87491 #cve202525249 #cve202619490 #cve202620079 #cve202687491

##

cisakevtracker@mastodon.social at 2026-09-09T20:01:41.000Z ##

CVE ID: CVE-2026-20079
Vendor: Cisco
Product: Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
Date Added: 2026-09-09
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

DailyCyberSecurity@infosec.exchange at 2026-09-09T16:28:31.000Z ##

Cisco Talos warns of Cisco FMC vulnerabilities actively exploited in the wild. Attackers chain CVE-2026-20079 and CVE-2026-20316 to deploy ransomware.

#CiscoFMC #Cybersecurity #CVE202620079 #Ransomware #InfoSec

securityonline.info/cisco-fmc-

##

AAKL@infosec.exchange at 2026-09-09T16:10:40.000Z ##

Broadcom has a long list of advisories today for high and medium-severity vulnerabilities support.broadcom.com/web/ecx/s #Broadcom #Linux

Palo Alto:

Palo Alto has several advisories, one of them critical:

CRITICAL: CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing security.paloaltonetworks.com/

More: security.paloaltonetworks.com/

Cisco:

CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco

Dell:

A Dell release that impacts multiple CVEs: Security Update for Dell PowerScale OneFS Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell

Posted yesterday:

Apple:

Several releases were posted yesterday support.apple.com/en-us/100100 #Apple #iOS

AMD:

AMD: Linux GPU Driver NULL Pointer Dereference amd.com/en/resources/product-s #AMD

Adobe:

Adobe has a long list of updates here helpx.adobe.com/security/secur #Adobe #infosec #vulnerability

@cR0w

##

CVE-2026-12855
(8.2 HIGH)

EPSS: 0.12%

updated 2026-09-09T21:17:01.313000

1 posts

Unvalidated memory boundary could result in arbitrary code execution. The vulnerability exists in the code developed specifically for HP projects.

offseq@infosec.exchange at 2026-09-09T04:30:23.000Z ##

CVE-2026-12855: HIGH-severity vuln in InsydeH2O firmware (HP). Local attackers with high privileges may execute arbitrary code due to improper input validation. No patch yet โ€” restrict local admin access. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Firmware #Infosec

##

CVE-2026-85061
(10.0 CRITICAL)

EPSS: 0.31%

updated 2026-09-09T21:09:13.080000

1 posts

MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap while removeAttributes() removes attributes from the same collection, shifting indexes and skipping an adjacent dangerous attribute. An attacker who controls untrusted third-party style attribution strings or user-supplied cust

DailyCyberSecurity@infosec.exchange at 2026-09-09T02:25:56.000Z ##

A critical MapLibre XSS vulnerability allows zero-click code execution in 2.7M weekly downloads. Discover how CVE-2026-85061 works and how to patch now.

#MapLibre #XSS #CVE202685061 #WebSecurity #InfoSec #CyberSecurity #OpenSource

securityonline.info/maplibre-x

##

CVE-2026-87874
(8.1 HIGH)

EPSS: 0.43%

updated 2026-09-09T20:13:26.720000

1 posts

A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and unpickles them on read. Because memcached is unauthenticated and cache keys are predictable, an attacker able to reach a n

thehackerwire@mastodon.social at 2026-09-09T20:00:36.000Z ##

๐ŸŸ  CVE-2026-87874 - High (8.1)

A flaw was found in the memcached cache plugin of the community.general Ansible
collection. Although its documentation states that records are stored in JSON
format, the plugin performs no explicit serialization and relies on
python-memcached, whi...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17469
(5.3 MEDIUM)

EPSS: 0.21%

updated 2026-09-09T18:32:16

2 posts

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser.

hugovalters@mastodon.social at 2026-09-10T20:40:01.000Z ##

CVE-2026-17469: IBM i (7.3-7.6) DoS via off-by-one write in LPD queue parser. Local authenticated attacker can crash the service. CVSS 5.3. No patch yet. Lock down LPD access & monitor. Details: valtersit.com/cve/CVE-2026-174 #CVE #IBM #infosec

##

hugovalters@mastodon.social at 2026-09-10T20:40:01.000Z ##

CVE-2026-17469: IBM i (7.3-7.6) DoS via off-by-one write in LPD queue parser. Local authenticated attacker can crash the service. CVSS 5.3. No patch yet. Lock down LPD access & monitor. Details: valtersit.com/cve/CVE-2026-174 #CVE #IBM #infosec

##

CVE-2026-87929
(9.8 CRITICAL)

EPSS: 0.29%

updated 2026-09-09T18:32:12

2 posts

MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. Attackers can mint a malicious ci_session cookie with administrator privileges by computing an HMAC-SHA1 using the publicly known encryption key, bypassing authentication checks

thehackerwire@mastodon.social at 2026-09-10T00:04:45.000Z ##

๐Ÿ”ด CVE-2026-87929 - Critical (9.8)

MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. Attackers can mint a mal...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T00:04:45.000Z ##

๐Ÿ”ด CVE-2026-87929 - Critical (9.8)

MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. Attackers can mint a mal...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87927
(8.2 HIGH)

EPSS: 0.34%

updated 2026-09-09T18:32:12

1 posts

MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequences. Attackers can bypass path validation checks and execute admin-gated handler actions without authentication to access sensitive functionality.

thehackerwire@mastodon.social at 2026-09-09T20:00:47.000Z ##

๐ŸŸ  CVE-2026-87927 - High (8.2)

MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequences. Att...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67401
(9.9 CRITICAL)

EPSS: 0.96%

updated 2026-09-09T18:32:06

3 posts

A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component

3 repos

https://github.com/axedos/CVE-2026-67401

https://github.com/jithinkrishnanrs/CVE-2026-67401-cPanel-EmailTrack-SQLi

https://github.com/HORKimhab/CVE-2026-67401

cR0w@infosec.exchange at 2026-09-09T18:43:49.000Z ##

I can't imagine trying to manage cPanel on the public Internet in 2026, especially on shared systems.

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.9 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component

##

guru@thecybersecguru.com at 2026-09-09T13:15:19.000Z ##

Critical cPanel Vulnerability (CVE-2026-67401): How an EmailTrack SQL Injection Grants Root Access

A critical cPanel EmailTrack SQL injection vulnerability, CVE-2026-67401, can allow authenticated attackers to escalate to root and take over an entire hosting server

thecybersecguru.com/news/cve-2

##

DailyCyberSecurity@infosec.exchange at 2026-09-09T01:47:41.000Z ##

A critical CVE-2026-67401 cPanel SQL injection flaw in EmailTrack allows authenticated users to gain full control of the server. Patch your system today.

#cPanel #SQLInjection #CVE202667401 #Cybersecurity #Vulnerability

securityonline.info/cve-2026-6

##

CVE-2026-83970
(7.8 HIGH)

EPSS: 0.31%

updated 2026-09-09T17:17:48.473000

1 posts

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

nyanbinary@infosec.exchange at 2026-09-08T18:36:25.000Z ##

I'm also quickly going to mention this, explicitly not as a complaint but as a good case study of a well chosen "SHOULD" & why should is better than must here:

cve.org/ResourcesSupport/AllRe

5.1.1 SHOULD contain sufficient information to uniquely identify the Vulnerability and distinguish it from similar Vulnerabilities.

This, uh, will be a bit of an issue with msrc.microsoft.com/update-guid & msrc.microsoft.com/update-guid . You it actually doesn't matter. The fix is the same, fucking update. And it doesn't matter if you got owned through -83972 or -83970, given the current firehose. It's actually one of those cases where I'd be happy to relax the "one record per vuln" rule, in no world does the differentiation of these two matter to anyone.

##

CVE-2026-85103
(9.8 CRITICAL)

EPSS: 0.36%

updated 2026-09-09T15:35:15

7 posts

A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.

cyberworldops at 2026-09-10T15:00:00.734Z ##

Check Point patched two critical VPN certificate handling flaws, CVE-2026-85102 and CVE-2026-85103, both rated 9.8. They allow unauthenticated remote code execution, making internet-facing VPN gateways an immediate target. Review exposure, apply patches, and investigate for signs of compromise.

cyberworldops.eu/en/check-poin

##

undercodenews@mastodon.social at 2026-09-10T12:39:01.000Z ##

Check Point Rushes to Patch Two Critical VPN Vulnerabilities With 98 CVSS Scores + Video

A Serious Warning for Security Gateway Operators Check Point has moved quickly to patch two critical vulnerabilities affecting its VPN certificate-processing technology, closing a potentially dangerous path that could allow an unauthenticated remote attacker to execute code on vulnerable security infrastructure. The flaws, tracked as CVE-2026-85102 and CVE-2026-85103, wereโ€ฆ

undercodenews.com/check-point-

##

cyberworldops@infosec.exchange at 2026-09-10T15:00:00.000Z ##

Check Point patched two critical VPN certificate handling flaws, CVE-2026-85102 and CVE-2026-85103, both rated 9.8. They allow unauthenticated remote code execution, making internet-facing VPN gateways an immediate target. Review exposure, apply patches, and investigate for signs of compromise. #CyberSecurity #CheckPoint #VPN #RCE

cyberworldops.eu/en/check-poin

##

daniel1820815@infosec.exchange at 2026-09-09T20:10:44.000Z ##

[Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510

Check Point research team has identified and remediated two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, which could potentially allow unauthenticated remote code execution under specific conditions. These issues were discovered internally, and we have no indication of active exploitation.

community.checkpoint.com/t5/Ge

#CheckPoint #CheckPointSoftwareTechnologies #VPN #vulnerability

##

cR0w@infosec.exchange at 2026-09-09T15:52:09.000Z ##

It has been :zero_percent: days since an ASN.1 decoding vuln.

It has been :zero_percent: days since an overflow vuln in a corp VPN.

It has been :zero_percent: days since a vuln with "Quantum" in the system name.

They are all the same vuln.

nvd.nist.gov/vuln/detail/cve-2

A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.

##

DailyCyberSecurity@infosec.exchange at 2026-09-09T14:36:57.000Z ##

Check Point fixed critical Check Point VPN vulnerabilities. Update gateways to prevent remote code execution under CVE-2026-85102 and CVE-2026-85103.

#CheckPoint #VPN #Cybersecurity #CVE202685102 #CVE202685103

securityonline.info/checkpoint

##

offseq@infosec.exchange at 2026-09-09T13:30:24.000Z ##

CRITICAL CVE-2026-85103 in Check Point Quantum Security Gateway: Heap-based buffer overflow in VPN certificate ASN.1 decoding allows unauthenticated RCE. Patch pending โ€” monitor vendor. radar.offseq.com/threat/cve-20 #OffSeq #CheckPoint #infosec #Vuln

##

CVE-2026-85102
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-09-09T15:35:15

5 posts

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

cyberworldops at 2026-09-10T15:00:00.734Z ##

Check Point patched two critical VPN certificate handling flaws, CVE-2026-85102 and CVE-2026-85103, both rated 9.8. They allow unauthenticated remote code execution, making internet-facing VPN gateways an immediate target. Review exposure, apply patches, and investigate for signs of compromise.

cyberworldops.eu/en/check-poin

##

undercodenews@mastodon.social at 2026-09-10T12:39:01.000Z ##

Check Point Rushes to Patch Two Critical VPN Vulnerabilities With 98 CVSS Scores + Video

A Serious Warning for Security Gateway Operators Check Point has moved quickly to patch two critical vulnerabilities affecting its VPN certificate-processing technology, closing a potentially dangerous path that could allow an unauthenticated remote attacker to execute code on vulnerable security infrastructure. The flaws, tracked as CVE-2026-85102 and CVE-2026-85103, wereโ€ฆ

undercodenews.com/check-point-

##

cyberworldops@infosec.exchange at 2026-09-10T15:00:00.000Z ##

Check Point patched two critical VPN certificate handling flaws, CVE-2026-85102 and CVE-2026-85103, both rated 9.8. They allow unauthenticated remote code execution, making internet-facing VPN gateways an immediate target. Review exposure, apply patches, and investigate for signs of compromise. #CyberSecurity #CheckPoint #VPN #RCE

cyberworldops.eu/en/check-poin

##

daniel1820815@infosec.exchange at 2026-09-09T20:10:44.000Z ##

[Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510

Check Point research team has identified and remediated two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, which could potentially allow unauthenticated remote code execution under specific conditions. These issues were discovered internally, and we have no indication of active exploitation.

community.checkpoint.com/t5/Ge

#CheckPoint #CheckPointSoftwareTechnologies #VPN #vulnerability

##

DailyCyberSecurity@infosec.exchange at 2026-09-09T14:36:57.000Z ##

Check Point fixed critical Check Point VPN vulnerabilities. Update gateways to prevent remote code execution under CVE-2026-85102 and CVE-2026-85103.

#CheckPoint #VPN #Cybersecurity #CVE202685102 #CVE202685103

securityonline.info/checkpoint

##

CVE-2026-81953
(7.8 HIGH)

EPSS: 0.43%

updated 2026-09-09T15:03:00.630000

1 posts

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

nyanbinary@infosec.exchange at 2026-09-08T18:13:22.000Z ##

db.gcve.eu/vuln/cve-2026-81953

Microsoft Excel Remote Code Execution Vulnerability

looks inside

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

##

CVE-2026-80172
(9.8 CRITICAL)

EPSS: 0.27%

updated 2026-09-09T12:32:22

1 posts

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Verification of Data Authenticity vulnerability. An unauthenticated attacker with remote access could exploit this, leading to unauthorized access. This vulnerability is considered critical as an unauthenticated attacker can repeatedly reuse a captured request to

offseq@infosec.exchange at 2026-09-09T12:00:25.000Z ##

Dell SCG 5.0 (pre-5.36.00.00) hit by CRITICAL vuln (CVE-2026-80172, CVSS 9.8): unauthenticated attackers can reuse requests to gain admin access. Upgrade required to patch. radar.offseq.com/threat/cve-20 #OffSeq #CVE202680172 #Dell #Infosec

##

CVE-2026-79641
(7.5 HIGH)

EPSS: 0.67%

updated 2026-09-09T12:32:21

1 posts

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges.

thehackerwire@mastodon.social at 2026-09-09T12:00:14.000Z ##

๐ŸŸ  CVE-2026-79641 - High (7.5)

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged a...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87795
(8.2 HIGH)

EPSS: 0.34%

updated 2026-09-09T12:32:12

1 posts

zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.

thehackerwire@mastodon.social at 2026-09-09T12:00:35.000Z ##

๐ŸŸ  CVE-2026-87795 - High (8.2)

zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the co...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79696(CVSS UNKNOWN)

EPSS: 0.44%

updated 2026-09-09T09:33:06

1 posts

A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote attacker to execute arbitrary code using a crafted test session replay.

offseq@infosec.exchange at 2026-09-09T10:30:26.000Z ##

CVE-2026-79696: Critical code injection (CVSS 10.0) in Google Cloud ADK for Python (2.0.0 โ€“ 2.6.0). Unauth RCE possible via crafted session replay in pytest-enabled Cloud Run & GKE. Patch or update now. radar.offseq.com/threat/cve-20 #OffSeq #CVE #CloudSecurity #Python

##

CVE-2026-16272
(9.1 CRITICAL)

EPSS: 0.14%

updated 2026-09-09T09:33:00

1 posts

Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Exploitation of Trusted Identifiers. This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.

offseq@infosec.exchange at 2026-09-09T09:00:24.000Z ##

CVE-2026-16272 (CVSS 9.1, CRITICAL) in PayTR Virtual Pos iFrame API (v9x) WHMCS Module v9.0.0: Use of less trusted source can compromise confidentiality and integrity. No patch yet โ€” restrict access and monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026_16272 #infosec

##

CVE-2026-76009
(8.1 HIGH)

EPSS: 0.52%

updated 2026-09-09T06:31:48

2 posts

The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.9.8 via the `NCWM_Kitconnect::run()` function. This is due to the plugin registering the `/wp-json/next_cart/v1/migration` REST route with `permission_callback` set to `__return_true` and relying on a hardcoded fallback value of `__token__` in `get_option

thehackerwire@mastodon.social at 2026-09-09T09:01:38.000Z ##

๐ŸŸ  CVE-2026-76009 - High (8.1)

The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.9.8 via the `NCWM_Kitconnect::run()` function. This is due to the plugin registering the `/wp-json/nex...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-09T06:00:25.000Z ##

CVE-2026-76009 (HIGH): Next-Cart Store to WooCommerce Migration โ‰ค3.9.8 exposes an auth bypass via REST API. Attackers can execute arbitrary SQL & delete files โ€” full site compromise possible. Patch status unknown. Details: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #Infosec

##

CVE-2026-87734
(7.5 HIGH)

EPSS: 0.29%

updated 2026-09-09T06:31:40

1 posts

An issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-order segment reassembly allows remote denial of service.

thehackerwire@mastodon.social at 2026-09-09T09:01:48.000Z ##

๐ŸŸ  CVE-2026-87734 - High (7.5)

An issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-order segment reassembly allows remote denial of service.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15667
(7.5 HIGH)

EPSS: 0.56%

updated 2026-09-09T03:30:51

1 posts

The Eventin โ€“ Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execut

offseq@infosec.exchange at 2026-09-09T03:00:25.000Z ##

CVE-2026-15667: HIGH-severity LFI in Eventin WordPress plugin (โ‰ค4.1.22). Contributors can include arbitrary PHP via 'event_layout', risking code execution. Restrict privileges & await patch. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #LFI

##

CVE-2026-81994
(8.2 HIGH)

EPSS: 0.30%

updated 2026-09-08T21:34:41

1 posts

Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious fi

thehackerwire@mastodon.social at 2026-09-09T03:00:30.000Z ##

๐ŸŸ  CVE-2026-81994 - High (8.2)

Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitiv...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84869
(9.9 CRITICAL)

EPSS: 0.38%

updated 2026-09-08T21:34:37

3 posts

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

ssvc@infosec.exchange at 2026-09-09T20:37:11.000Z ##

ConnectWise ScreenConnect #zeroday CVE-2026-84869

Huntress article: huntress.com/blog/rogue-screen

Canadian Centre for Cyber Security: cyber.gc.ca/en/alerts-advisori

Open-source reporting indicates that CVE-2026-84869 is being exploited in the wild.

ConnectWise is silent on exploitation status: connectwise.com/company/trust/

#connectwise #screenconnect #cve

##

cR0w@infosec.exchange at 2026-09-08T21:38:08.000Z ##

WTF

github.com/ConnectWise-Advisor

Earlier versions of ScreenConnect Client Support and Access sessions contained a client-side file-transfer handling condition in which file-transfer actions could be processed through an active remote session without proper authorization or Host confirmation. Under certain circumstances, this could allow files to be transferred to and executed on the Host client system, including through elevated execution actions. ScreenConnect servers are not impacted. Disabling file-transfer permissions for affected sessions may reduce exposure until the update is applied.

##

thehackerwire@mastodon.social at 2026-09-08T21:00:02.000Z ##

๐Ÿ”ด CVE-2026-84869 - Critical (9.9)

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84942
(8.7 HIGH)

EPSS: 0.33%

updated 2026-09-08T21:34:37

1 posts

Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty validation routine failed to recurse into arrays of objects, allowing a function pro

thehackerwire@mastodon.social at 2026-09-08T21:00:13.000Z ##

๐ŸŸ  CVE-2026-84942 - High (8.7)

Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82007
(7.8 HIGH)

EPSS: 0.23%

updated 2026-09-08T21:34:36

1 posts

Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

thehackerwire@mastodon.social at 2026-09-08T21:00:23.000Z ##

๐ŸŸ  CVE-2026-82007 - High (7.8)

Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a ma...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85880
(7.8 HIGH)

EPSS: 0.57%

updated 2026-09-08T21:34:12

9 posts

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

AAKL@infosec.exchange at 2026-09-09T16:27:09.000Z ##

New.

Press release:

CISA Releases Updated Insider Threat Guide With New Insights to Mitigate Physical and Cyber Threats cisa.gov/news-events/news/cisa

The guide: cisa.gov/resources-tools/resou

Updates to the Kev catalogue:

- CVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerability cve.org/CVERecord?id=CVE-2026- #Microsoft #Windows

- CVE-2026-86218: N-able N-central Static Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-81963: Microsoft Windows Link Following Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-75650: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability cve.org/CVERecord?id=CVE-2026- #Adobe

Yesterday:

Joint advisory: China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies cisa.gov/news-events/cybersecu #CISA #infosec #vulnerability

##

youranonnewsirc@nerdculture.de at 2026-09-09T16:26:23.000Z ##

**Latest Global Briefing: September 9, 2026**

**Cybersecurity:** Microsoft's September Patch Tuesday revealed nearly 1000 vulnerabilities, with CISA flagging two exploited zero-days (CVE-2026-81963, CVE-2026-85880) requiring urgent patching by federal agencies. The FBI also announced a new strategy to enhance cyberattack disruptions.

**Technology:** Dell Technologies reported surging Q2 FY 2027 earnings driven by high AI server demand, with OpenAI exploring AI infrastructure-as-a-service.

**Geopolitics:** Tensions heightened in the Middle East as US forces destroyed five Iranian oil tankers following IRGC attacks on a US Navy warship. Separately, 12 nations implemented trade bans on goods from Israeli settlements.

#Cybersecurity #TechNews #Geopolitics

##

secdb@infosec.exchange at 2026-09-09T11:00:11.000Z ##

๐Ÿšจ [CISA-2026:0908] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

โš ๏ธ CVE-2026-75650 (secdb.nttzen.cloud/cve/detail/)
- Name: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Adobe
- Product: Commerce and Magento
- Notes: helpx.adobe.com/security/produ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-81963 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Link Following Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-85880 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Heap-Based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-86218 (secdb.nttzen.cloud/cve/detail/)
- Name: N-able N-central Static Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: status.n-able.com/2026/09/06/n ; me.n-able.com/s/security-advis ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260908 #cisa20260908 #cve_2026_75650 #cve_2026_81963 #cve_2026_85880 #cve_2026_86218 #cve202675650 #cve202681963 #cve202685880 #cve202686218

##

beyondmachines1@infosec.exchange at 2026-09-09T09:01:13.000Z ##

Microsoft Patches 966 Vulnerabilities in September 2026 Update Including Two Actively Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixed 966 flaws, its largest ever. The patch package includes 105 critical bugs and two actively exploited zero-days (CVE-2026-81963 and CVE-2026-85880). The critical flaws cluster in Windows network services (DNS, DHCP, RRAS, Netlogon), Office file parsing, imaging/graphics components, and Azure/Entra cloud services. Microsoft is attributing the surge in volume to AI-assisted vulnerability discovery.

**Patch the Windows OS first for the two zero-days, CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in ALPC, both already exploited in attacks to gain SYSTEM privileges. Next, patch internet-reachable and domain-joined Windows servers: DNS, DHCP, RRAS, Netlogon, Kerberos and the Key Distribution Center, Services for NFS, Deployment Services, Failover Cluster and SSTP all carry critical remote code execution flaws. Then move through Outlook, Word, Excel, and Office, followed by SQL Server, SharePoint Server, and Exchange. Windows Hello, Secure Kernel Mode, Credential Guard, and VBS should follow for anything holding credentials or running as a security boundary. Everything else can follow in the normal cycle, but plan for it to take longer than usual: almost no organization can test and deploy this volume in a single window.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

security_crawler_carl@infosec.exchange at 2026-09-09T00:46:57.000Z ##

Meanwhile CVE-2026-69829 is a CVSS 9.8 heap overflow in Windows Shell letting unauthenticated attackers run code over a network. I called the mechanics. I drew the diagram. I made a spreadsheet.

Patch CVE-2026-81963, CVE-2026-85880, CVE-2026-69730, and CVE-2026-69829 immediately โ€” yes, right now, before you ask if it can wait until Friday.

Reward: You've received the Tunnel Vision Debuff. It cannot be cleansed.

#ZeroDay #Microsoft #WindowsUpdate #PrivilegeEscalation #CyberSecurity (2/2)

##

security_crawler_carl@infosec.exchange at 2026-09-09T00:46:57.000Z ##

๐Ÿ† New Achievement! Stand In The Fire One More Time, I Dare You!

NINE HUNDRED AND SEVENTY-FOUR vulnerabilities. Microsoft dropped 974 patches this Patch Tuesday and you are STILL standing in the bad stuff. CVE-2026-81963 and CVE-2026-85880, both CVSS 7.8, are being actively exploited RIGHT NOW against the Windows Update Stack and Windows Advanced Local Procedure Call โ€” privilege escalation, in the wild, before disclosure. (1/2)

##

cisakevtracker@mastodon.social at 2026-09-08T19:01:33.000Z ##

CVE ID: CVE-2026-85880
Vendor: Microsoft
Product: Windows
Date Added: 2026-09-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

DailyCyberSecurity@infosec.exchange at 2026-09-08T18:09:23.000Z ##

Microsoft's September 2026 Patch Tuesday fixes two zero-day flaws, CVE-2026-81963 and CVE-2026-85880, both exploited in the wild.

#PatchTuesday #ZeroDay #Microsoft #Windows #CyberSecurity #CVE #Infosec #VulnerabilityManagement

securityonline.info/patch-tues

##

cR0w@infosec.exchange at 2026-09-08T17:25:21.000Z ##

Only two 0days this month for MS? Bummer.

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

##

CVE-2026-81963
(7.8 HIGH)

EPSS: 0.63%

updated 2026-09-08T21:34:09

9 posts

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

AAKL@infosec.exchange at 2026-09-09T16:27:09.000Z ##

New.

Press release:

CISA Releases Updated Insider Threat Guide With New Insights to Mitigate Physical and Cyber Threats cisa.gov/news-events/news/cisa

The guide: cisa.gov/resources-tools/resou

Updates to the Kev catalogue:

- CVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerability cve.org/CVERecord?id=CVE-2026- #Microsoft #Windows

- CVE-2026-86218: N-able N-central Static Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-81963: Microsoft Windows Link Following Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-75650: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability cve.org/CVERecord?id=CVE-2026- #Adobe

Yesterday:

Joint advisory: China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies cisa.gov/news-events/cybersecu #CISA #infosec #vulnerability

##

youranonnewsirc@nerdculture.de at 2026-09-09T16:26:23.000Z ##

**Latest Global Briefing: September 9, 2026**

**Cybersecurity:** Microsoft's September Patch Tuesday revealed nearly 1000 vulnerabilities, with CISA flagging two exploited zero-days (CVE-2026-81963, CVE-2026-85880) requiring urgent patching by federal agencies. The FBI also announced a new strategy to enhance cyberattack disruptions.

**Technology:** Dell Technologies reported surging Q2 FY 2027 earnings driven by high AI server demand, with OpenAI exploring AI infrastructure-as-a-service.

**Geopolitics:** Tensions heightened in the Middle East as US forces destroyed five Iranian oil tankers following IRGC attacks on a US Navy warship. Separately, 12 nations implemented trade bans on goods from Israeli settlements.

#Cybersecurity #TechNews #Geopolitics

##

secdb@infosec.exchange at 2026-09-09T11:00:11.000Z ##

๐Ÿšจ [CISA-2026:0908] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

โš ๏ธ CVE-2026-75650 (secdb.nttzen.cloud/cve/detail/)
- Name: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Adobe
- Product: Commerce and Magento
- Notes: helpx.adobe.com/security/produ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-81963 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Link Following Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-85880 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Heap-Based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-86218 (secdb.nttzen.cloud/cve/detail/)
- Name: N-able N-central Static Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: status.n-able.com/2026/09/06/n ; me.n-able.com/s/security-advis ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260908 #cisa20260908 #cve_2026_75650 #cve_2026_81963 #cve_2026_85880 #cve_2026_86218 #cve202675650 #cve202681963 #cve202685880 #cve202686218

##

beyondmachines1@infosec.exchange at 2026-09-09T09:01:13.000Z ##

Microsoft Patches 966 Vulnerabilities in September 2026 Update Including Two Actively Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixed 966 flaws, its largest ever. The patch package includes 105 critical bugs and two actively exploited zero-days (CVE-2026-81963 and CVE-2026-85880). The critical flaws cluster in Windows network services (DNS, DHCP, RRAS, Netlogon), Office file parsing, imaging/graphics components, and Azure/Entra cloud services. Microsoft is attributing the surge in volume to AI-assisted vulnerability discovery.

**Patch the Windows OS first for the two zero-days, CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in ALPC, both already exploited in attacks to gain SYSTEM privileges. Next, patch internet-reachable and domain-joined Windows servers: DNS, DHCP, RRAS, Netlogon, Kerberos and the Key Distribution Center, Services for NFS, Deployment Services, Failover Cluster and SSTP all carry critical remote code execution flaws. Then move through Outlook, Word, Excel, and Office, followed by SQL Server, SharePoint Server, and Exchange. Windows Hello, Secure Kernel Mode, Credential Guard, and VBS should follow for anything holding credentials or running as a security boundary. Everything else can follow in the normal cycle, but plan for it to take longer than usual: almost no organization can test and deploy this volume in a single window.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

security_crawler_carl@infosec.exchange at 2026-09-09T00:46:57.000Z ##

Meanwhile CVE-2026-69829 is a CVSS 9.8 heap overflow in Windows Shell letting unauthenticated attackers run code over a network. I called the mechanics. I drew the diagram. I made a spreadsheet.

Patch CVE-2026-81963, CVE-2026-85880, CVE-2026-69730, and CVE-2026-69829 immediately โ€” yes, right now, before you ask if it can wait until Friday.

Reward: You've received the Tunnel Vision Debuff. It cannot be cleansed.

#ZeroDay #Microsoft #WindowsUpdate #PrivilegeEscalation #CyberSecurity (2/2)

##

security_crawler_carl@infosec.exchange at 2026-09-09T00:46:57.000Z ##

๐Ÿ† New Achievement! Stand In The Fire One More Time, I Dare You!

NINE HUNDRED AND SEVENTY-FOUR vulnerabilities. Microsoft dropped 974 patches this Patch Tuesday and you are STILL standing in the bad stuff. CVE-2026-81963 and CVE-2026-85880, both CVSS 7.8, are being actively exploited RIGHT NOW against the Windows Update Stack and Windows Advanced Local Procedure Call โ€” privilege escalation, in the wild, before disclosure. (1/2)

##

cisakevtracker@mastodon.social at 2026-09-08T19:01:01.000Z ##

CVE ID: CVE-2026-81963
Vendor: Microsoft
Product: Windows
Date Added: 2026-09-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

DailyCyberSecurity@infosec.exchange at 2026-09-08T18:09:23.000Z ##

Microsoft's September 2026 Patch Tuesday fixes two zero-day flaws, CVE-2026-81963 and CVE-2026-85880, both exploited in the wild.

#PatchTuesday #ZeroDay #Microsoft #Windows #CyberSecurity #CVE #Infosec #VulnerabilityManagement

securityonline.info/patch-tues

##

cR0w@infosec.exchange at 2026-09-08T17:25:21.000Z ##

Only two 0days this month for MS? Bummer.

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

##

CVE-2026-75650
(10.0 CRITICAL)

EPSS: 2.15%

updated 2026-09-08T21:33:09

11 posts

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

4 repos

https://github.com/jithinkrishnanrs/stylesmuggler-ioc-toolkit

https://github.com/dinosn/cve-2026-75650-magento-validation-lab

https://github.com/disrex-group/stylesmuggler-adobe-patches

https://github.com/disrex-group/stylesmuggler-adobe-patches-mageos

shochdoerfer@phpc.social at 2026-09-10T16:51:52.000Z ##

If you want to learn more about the latest zero-day #Magento exploit (StyleSmuggler), this a great read: graycore.io/case-studies/CVE-2

##

thecybermind at 2026-09-10T09:42:55.630Z ##

Executive alert: CVE-2026-75650 actively threatens Adobe Commerce and Magento infrastructure. Review board-ready risk evaluation protocols, asset integrity measures, and strategic remediation steps to protect your enterprise value today.

thecybermind.co/hip4

##

thecybermind at 2026-09-10T00:59:17.540Z ##

Critical CVE-2026-75650 alert for Adobe Commerce and Magento. Active CISA KEV exploitation requires immediate template parsing audits and endpoint hardening. Access our technical forensic brief to secure your enterprise perimeter today.

thecybermind.co/8in9

##

shochdoerfer@phpc.social at 2026-09-10T16:51:52.000Z ##

If you want to learn more about the latest zero-day #Magento exploit (StyleSmuggler), this a great read: graycore.io/case-studies/CVE-2

##

thecybermind@infosec.exchange at 2026-09-10T09:42:55.000Z ##

Executive alert: CVE-2026-75650 actively threatens Adobe Commerce and Magento infrastructure. Review board-ready risk evaluation protocols, asset integrity measures, and strategic remediation steps to protect your enterprise value today.

thecybermind.co/hip4

##

thecybermind@infosec.exchange at 2026-09-10T00:59:17.000Z ##

Critical CVE-2026-75650 alert for Adobe Commerce and Magento. Active CISA KEV exploitation requires immediate template parsing audits and endpoint hardening. Access our technical forensic brief to secure your enterprise perimeter today.

thecybermind.co/8in9

##

AAKL@infosec.exchange at 2026-09-09T16:27:09.000Z ##

New.

Press release:

CISA Releases Updated Insider Threat Guide With New Insights to Mitigate Physical and Cyber Threats cisa.gov/news-events/news/cisa

The guide: cisa.gov/resources-tools/resou

Updates to the Kev catalogue:

- CVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerability cve.org/CVERecord?id=CVE-2026- #Microsoft #Windows

- CVE-2026-86218: N-able N-central Static Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-81963: Microsoft Windows Link Following Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-75650: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability cve.org/CVERecord?id=CVE-2026- #Adobe

Yesterday:

Joint advisory: China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies cisa.gov/news-events/cybersecu #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-09T11:00:11.000Z ##

๐Ÿšจ [CISA-2026:0908] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

โš ๏ธ CVE-2026-75650 (secdb.nttzen.cloud/cve/detail/)
- Name: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Adobe
- Product: Commerce and Magento
- Notes: helpx.adobe.com/security/produ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-81963 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Link Following Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-85880 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Heap-Based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-86218 (secdb.nttzen.cloud/cve/detail/)
- Name: N-able N-central Static Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: status.n-able.com/2026/09/06/n ; me.n-able.com/s/security-advis ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260908 #cisa20260908 #cve_2026_75650 #cve_2026_81963 #cve_2026_85880 #cve_2026_86218 #cve202675650 #cve202681963 #cve202685880 #cve202686218

##

benzogaga33@mamot.fr at 2026-09-09T09:40:05.000Z ##

Magento : la faille zero-day StyleSmuggler est corrigรฉe, mais des boutiques sont dรฉjร  piratรฉes it-connect.fr/magento-adobe-co #ActuCybersรฉcuritรฉ #Cybersรฉcuritรฉ #Vulnรฉrabilitรฉ #Adobe

##

beyondmachines1@infosec.exchange at 2026-09-08T20:01:13.000Z ##

Adobe releases September 2026 patches for multiple products

Adobe's September 2026 security updates patch vulnerabilities across eight product families: Commerce/Magento, ColdFusion, Campaign Classic, Acrobat/Reader, Experience Manager, Photoshop, Illustrator, and Animate. The flaws could allow arbitrary code execution, privilege escalation, security feature bypass, file system read/write, memory exposure, and denial-of-service. The most urgent is CVE-2026-75650 (CVSS 10.0) in Adobe Commerce and Magento Open Source, an unauthenticated template-engine flaw already exploited in the wild and fixed by a separate out-of-band hotfix on September 7 that must be applied in addition to the September update.

**If you run Adobe Commerce or Magento Open Source, apply the out-of-band hotfix for CVE-2026-75650 immediately! Adobe is aware of this flaw being exploited in the wild, it carries a CVSS score of 10.0, and it can be triggered without authentication. Next, update ColdFusion and Adobe Campaign Classic, both of which received Adobe's highest priority rating and contain critical flaws that could lead to arbitrary code execution. Then apply the September Adobe Commerce security update, which is separate from the hotfix and must be installed in addition to it. After that, update Adobe Experience Manager and Acrobat and Reader. Finally, update Photoshop, Illustrator, and Animate. If you can't update right away, restrict network access to Commerce, ColdFusion, Campaign Classic, and Experience Manager servers, and avoid opening untrusted PDFs and untrusted image or project files in Acrobat, Reader, Photoshop, Illustrator, and Animate until patches are applied.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

cisakevtracker@mastodon.social at 2026-09-08T19:00:46.000Z ##

CVE ID: CVE-2026-75650
Vendor: Adobe
Product: Commerce and Magento
Date Added: 2026-09-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-86218
(9.8 CRITICAL)

EPSS: 0.74%

updated 2026-09-08T21:33:02

12 posts

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

1 repos

https://github.com/HORKimhab/CVE-2026-86218

DailyCyberSecurity at 2026-09-10T14:04:30.724Z ##

Discover the severe N-central CVE-2026-86218 vulnerability allowing unauthenticated RCE. Learn about N-able HF4 patches, CISA mandates, and threat actors.

meterpreter.org/n-central-cve-

##

beyondmachines1 at 2026-09-10T11:01:14.357Z ##

N-Able Patches N-Central Zero-Day Exploited in the Wild

N-Able released an emergency hotfix for a remote code execution vulnerability (CVE-2026-86218) in N-Central that attackers are actively exploiting to gain full administrative control over RMM servers and downstream client endpoints.

**If you run on-premises N-able N-central, upgrade immediately to version 2026.3.1.14 (2026.3 Hotfix 4). Make sure to keep the management console off the open internet behind a VPN or firewall allowlist limited to trusted admin networks. Since attackers may have already gained access, check for unfamiliar administrator accounts, unknown scripts or scheduled jobs and strange outbound connections, and change all passwords and keys used by or stored on the N-central server.**

beyondmachines.net/event_detai

##

threatnoir at 2026-09-10T00:06:02.183Z ##

โš ๏ธ CRITICAL: N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

CVE-2026-86218 is a critical pre-auth RCE in N-able N-central being actively exploited in the wild. Any organization running N-central is vulnerable to unauthenticated remote code execution. Federal agencies are mandated to patch by September 11, 2026.

threatnoir.com/focus

๐Ÿค– AI generated summary

##

DailyCyberSecurity@infosec.exchange at 2026-09-10T14:04:30.000Z ##

Discover the severe N-central CVE-2026-86218 vulnerability allowing unauthenticated RCE. Learn about N-able HF4 patches, CISA mandates, and threat actors.

#Ncentral #CVE202686218 #CyberSecurity #ZeroDay #Vulnerability

meterpreter.org/n-central-cve-

##

beyondmachines1@infosec.exchange at 2026-09-10T11:01:14.000Z ##

N-Able Patches N-Central Zero-Day Exploited in the Wild

N-Able released an emergency hotfix for a remote code execution vulnerability (CVE-2026-86218) in N-Central that attackers are actively exploiting to gain full administrative control over RMM servers and downstream client endpoints.

**If you run on-premises N-able N-central, upgrade immediately to version 2026.3.1.14 (2026.3 Hotfix 4). Make sure to keep the management console off the open internet behind a VPN or firewall allowlist limited to trusted admin networks. Since attackers may have already gained access, check for unfamiliar administrator accounts, unknown scripts or scheduled jobs and strange outbound connections, and change all passwords and keys used by or stored on the N-central server.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

threatnoir@infosec.exchange at 2026-09-10T00:06:02.000Z ##

โš ๏ธ CRITICAL: N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

CVE-2026-86218 is a critical pre-auth RCE in N-able N-central being actively exploited in the wild. Any organization running N-central is vulnerable to unauthenticated remote code execution. Federal agencies are mandated to patch by September 11, 2026.

threatnoir.com/focus

#infosec #cybersecurity

๐Ÿค– AI generated summary

##

AAKL@infosec.exchange at 2026-09-09T16:27:09.000Z ##

New.

Press release:

CISA Releases Updated Insider Threat Guide With New Insights to Mitigate Physical and Cyber Threats cisa.gov/news-events/news/cisa

The guide: cisa.gov/resources-tools/resou

Updates to the Kev catalogue:

- CVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerability cve.org/CVERecord?id=CVE-2026- #Microsoft #Windows

- CVE-2026-86218: N-able N-central Static Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-81963: Microsoft Windows Link Following Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-75650: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability cve.org/CVERecord?id=CVE-2026- #Adobe

Yesterday:

Joint advisory: China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies cisa.gov/news-events/cybersecu #CISA #infosec #vulnerability

##

cyberworldops@infosec.exchange at 2026-09-09T15:00:01.000Z ##

N-able released Hotfix 4 for CVE-2026-86218, a pre-auth RCE in on-prem N-central with CVSS 4.0 10.0. All builds before 2026.3.1.14 are vulnerable, including Hotfix 3. RMM pre-auth RCE is high-value for initial access, prioritize patching and internet exposure review. #NAble #NCentral #RemoteCodeExecution

cyberworldops.eu/en/n-able-fix

##

secdb@infosec.exchange at 2026-09-09T11:00:11.000Z ##

๐Ÿšจ [CISA-2026:0908] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

โš ๏ธ CVE-2026-75650 (secdb.nttzen.cloud/cve/detail/)
- Name: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Adobe
- Product: Commerce and Magento
- Notes: helpx.adobe.com/security/produ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-81963 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Link Following Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-85880 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Heap-Based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-86218 (secdb.nttzen.cloud/cve/detail/)
- Name: N-able N-central Static Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: status.n-able.com/2026/09/06/n ; me.n-able.com/s/security-advis ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260908 #cisa20260908 #cve_2026_75650 #cve_2026_81963 #cve_2026_85880 #cve_2026_86218 #cve202675650 #cve202681963 #cve202685880 #cve202686218

##

cyberworldops@infosec.exchange at 2026-09-09T07:10:01.000Z ##

CISA added CVE-2026-86218 to KEV after confirmed active exploitation. The N-able N-central static code injection allows pre-auth RCE with CVSS 9.8, exposing centralized management infrastructure. Patch and hunt for pre-patch compromise. #Nable #NCentral #RemoteCodeExecution

cyberworldops.eu/en/actively-e

##

ssvc@infosec.exchange at 2026-09-09T01:37:53.000Z ##

N-able didn't beat around the bush:

Since our post 9/5/2026, 08:11:00 UTC a third independent researcher disclosed to N-able a new vulnerabilityโ€” one that has been exploited in the wild and is unrelated to the previously disclosed CVEs.

This critical zero-day vulnerability, CVE-2026-86218, could allow pre-authenticated access to the N-central server if exploited.

#nable #zeroday #KEV #CVE

##

cisakevtracker@mastodon.social at 2026-09-08T19:01:17.000Z ##

CVE ID: CVE-2026-86218
Vendor: N-able
Product: N-central
Date Added: 2026-09-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-57162
(0 None)

EPSS: 0.35%

updated 2026-09-08T21:14:35.567000

1 posts

PJSIP is a free and open source multimedia communication library written in C. Prior to commit a1b707c, a stack buffer overflow exists in the SRTP/SDES media transport when processing a=crypto attributes during SDP offer/answer (sdes_encode_sdp() in transport_srtp_sdes.c). This affects applications with SRTP enabled (use_srtp optional or mandatory, using SDES keying). During media negotiation, the

hugovalters@mastodon.social at 2026-09-10T16:00:22.000Z ##

CVE-2026-57162: Stack buffer overflow in PJSIP SRTP/SDES when processing crafted crypto attributes during SDP negotiation. CVSS: N/A, unpatched. If you use SRTP with SDES keying, you are exposed. Patch immediately. Details: valtersit.com/cve/CVE-2026-571 #CVE #info

##

CVE-2026-84372
(9.8 CRITICAL)

EPSS: 0.41%

updated 2026-09-08T20:57:52

1 posts

### Summary An improper CRLF neutralization flaw in Predis' pipeline handling on aggregate connections lets an unauthenticated attacker who can influence any pipelined argument โ€” a value **or** a key, e.g. a URL slug used as a cache key โ€” smuggle arbitrary Redis commands into the connection. - On **cluster** connections (`cluster` option, incl. client-side sharding) this is remote command inje

CVE-2026-86721
(7.5 HIGH)

EPSS: 0.29%

updated 2026-09-08T19:53:13.400000

1 posts

AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cookie named 'key' with value 'value' overrides the $_REQUEST['key'] parameter in saveLive.php and related endpoints. Attackers can publish to any user's RTMP stream without authentication by using the known constant stream key value to hijack live broadcasts.

thehackerwire@mastodon.social at 2026-09-08T17:02:29.000Z ##

๐ŸŸ  CVE-2026-86721 - High (7.5)

AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cookie named 'key' with value 'value' overrides the $_REQUEST['key'] parameter in saveLive.php and related endpoints. Attackers can publish to any user...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86730
(8.8 HIGH)

EPSS: 0.39%

updated 2026-09-08T19:53:13.400000

1 posts

Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout elements, allowing authenticated control-panel users to inject Yii2 behavior attachments and event handlers. Attackers can post field-layout tab elements as JSON strings to bypass cleanse validation, then trigger arbitrary object instantiation and code execution through Craft::createObject().

thehackerwire@mastodon.social at 2026-09-08T17:01:16.000Z ##

๐ŸŸ  CVE-2026-86730 - High (8.8)

Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout elements, allowing authenticated control-panel users to inject Yii2 behavior attachments and event handlers. Attackers can post field-layout tab elements as JSON ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44756
(10.0 CRITICAL)

EPSS: 0.32%

updated 2026-09-08T19:12:59.557000

5 posts

A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availabil

DailyCyberSecurity at 2026-09-10T14:37:16.736Z ##

The SAP OVERPASS vulnerability (CVE-2026-44756) scores a perfect CVSS 10.0, letting attackers seize SAP servers before login. Patch Note 3747649 now.

securityexpress.info/sap-overp

##

DailyCyberSecurity@infosec.exchange at 2026-09-10T14:37:16.000Z ##

The SAP OVERPASS vulnerability (CVE-2026-44756) scores a perfect CVSS 10.0, letting attackers seize SAP servers before login. Patch Note 3747649 now.

#SAP #OVERPASS #CVE202644756 #CyberSecurity #RCE #Onapsis #InfoSec

securityexpress.info/sap-overp

##

guru@thecybersecguru.com at 2026-09-09T12:33:27.000Z ##

SAP OVERPASS CVE-2026-44756: CVSS 10.0 Kernel RCE Explained

SAP OVERPASS CVE-2026-44756 is a CVSS 10.0 kernel flaw enabling unauthenticated RCE. Learn the attack path, S4GET risks and patching steps

thecybersecguru.com/news/sap-o

##

jbhall56@infosec.exchange at 2026-09-09T12:29:39.000Z ##

The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP security company Onapsis, it has been codenamed OVERPASS. thehackernews.com/2026/09/sap-

##

security_crawler_carl@infosec.exchange at 2026-09-09T03:04:18.000Z ##

๐Ÿ† New Achievement! OVERPASS: The SAP Kernel Speedrun!

Patch compliance policy activated. Scanning enterprise environment. Detecting CVE-2026-44756, a CVSS 10/10 memory corruption flaw in SAP Extended Passport Processing, dubbed OVERPASS. Policy requires acknowledgment of impact: unauthenticated remote attackers may execute arbitrary system commands, drain database credentials and password hashes, hijack live user sessions, and rewrite configurations and SAP binaries. (1/2)

##

CVE-2026-83972
(7.8 HIGH)

EPSS: 0.31%

updated 2026-09-08T18:34:21

1 posts

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

nyanbinary@infosec.exchange at 2026-09-08T18:36:25.000Z ##

I'm also quickly going to mention this, explicitly not as a complaint but as a good case study of a well chosen "SHOULD" & why should is better than must here:

cve.org/ResourcesSupport/AllRe

5.1.1 SHOULD contain sufficient information to uniquely identify the Vulnerability and distinguish it from similar Vulnerabilities.

This, uh, will be a bit of an issue with msrc.microsoft.com/update-guid & msrc.microsoft.com/update-guid . You it actually doesn't matter. The fix is the same, fucking update. And it doesn't matter if you got owned through -83972 or -83970, given the current firehose. It's actually one of those cases where I'd be happy to relax the "one record per vuln" rule, in no world does the differentiation of these two matter to anyone.

##

CVE-2026-81954
(7.8 HIGH)

EPSS: 0.32%

updated 2026-09-08T18:34:18

1 posts

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

nyanbinary@infosec.exchange at 2026-09-08T18:26:10.000Z ##

I explicitly don't want to complain about MSRC here, this is a bigger topic, but I am a bit confused here:

Compare these two:

msrc.microsoft.com/update-guid - AV:L,UI:R

Q: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
A: An attacker must send a user a malicious Office file and convince them to open it.

msrc.microsoft.com/update-guid - AV:N,UI:R

Q: How could an attacker exploit this vulnerability?
A: An attacker could send a specially crafted PowerPoint presentation containing malicious linked media to a target user. The user would need to open the presentation, start the slideshow, and allow the linked content. Successful exploitation could allow the attacker to execute code on the user's system. Authentication is not required.

To me the attack flow looks equivalent wrt to attacker location. We can argue about #2 being actually harder to execute, having more social engineering prerequisites... which is why it totally makes sense for #2 to scored higher on CVSS as it's apparently network & the other one local.

##

CVE-2026-83991
(5.5 MEDIUM)

EPSS: 0.34%

updated 2026-09-08T18:34:14

1 posts

Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.

2 repos

https://github.com/ZeroDayVPN/CVE-2026-83991-WriteUP-and-PoC

https://github.com/karollooool/CVE-2026-83991-writeup-and-poc

CVE-2026-80081
(8.8 HIGH)

EPSS: 0.47%

updated 2026-09-08T18:34:00

1 posts

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.

nyanbinary@infosec.exchange at 2026-09-08T18:26:10.000Z ##

I explicitly don't want to complain about MSRC here, this is a bigger topic, but I am a bit confused here:

Compare these two:

msrc.microsoft.com/update-guid - AV:L,UI:R

Q: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
A: An attacker must send a user a malicious Office file and convince them to open it.

msrc.microsoft.com/update-guid - AV:N,UI:R

Q: How could an attacker exploit this vulnerability?
A: An attacker could send a specially crafted PowerPoint presentation containing malicious linked media to a target user. The user would need to open the presentation, start the slideshow, and allow the linked content. Successful exploitation could allow the attacker to execute code on the user's system. Authentication is not required.

To me the attack flow looks equivalent wrt to attacker location. We can argue about #2 being actually harder to execute, having more social engineering prerequisites... which is why it totally makes sense for #2 to scored higher on CVSS as it's apparently network & the other one local.

##

CVE-2026-69829
(9.8 CRITICAL)

EPSS: 1.05%

updated 2026-09-08T18:33:17

1 posts

Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.

security_crawler_carl@infosec.exchange at 2026-09-09T00:46:57.000Z ##

Meanwhile CVE-2026-69829 is a CVSS 9.8 heap overflow in Windows Shell letting unauthenticated attackers run code over a network. I called the mechanics. I drew the diagram. I made a spreadsheet.

Patch CVE-2026-81963, CVE-2026-85880, CVE-2026-69730, and CVE-2026-69829 immediately โ€” yes, right now, before you ask if it can wait until Friday.

Reward: You've received the Tunnel Vision Debuff. It cannot be cleansed.

#ZeroDay #Microsoft #WindowsUpdate #PrivilegeEscalation #CyberSecurity (2/2)

##

CVE-2026-20293
(7.1 HIGH)

EPSS: 0.13%

updated 2026-09-08T18:32:05

2 posts

A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin&nbsp;or an unauthenticated attacker with physical access to an affected device to bypass UEFI Secure Boot validation checks and execute unauthorized softw

ssvc@infosec.exchange at 2026-09-09T01:33:59.000Z ##

#Cisco only had one for #PatchTuesday? CVE-2026-20293 Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability

The Cisco PSIRT is aware that proof-of-concept exploit code is available for the vulnerability described in this advisory.

It appears to be related to Eclypsium research into UEFI shell vulnerabilities from 2025:

#poc #UEFI

##

AAKL@infosec.exchange at 2026-09-08T16:42:45.000Z ##

New advisories from Cisco addressing two high and medium-severity vulnerabilities.

New: CVE-2026-20293: Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability sec.cloudapps.cisco.com/securi

Known: CVE-2026-20354 and CVE-2026-20355: Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities @TalosSecurity #infosec #vulnerability #Cisco

##

CVE-2026-82067
(8.1 HIGH)

EPSS: 0.28%

updated 2026-09-08T18:32:04

2 posts

Improper handling of case sensitivity in the configuration validation component of MongoDB Server may cause the authorization subsystem to remain in a default disabled state during server startup. An unauthenticated user with network access to a deployment where this condition occurs can perform arbitrary administrative operations, resulting in full impact of data confidentiality, integrity, and a

CVE-2026-86738
(8.7 HIGH)

EPSS: 0.27%

updated 2026-09-08T18:32:01

1 posts

Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters. Superusers can plant malicious CSS payloads using @import and url() references to exfiltrate CSRF tokens from other superusers via attribute-selector rules, enabling account takeover.

thehackerwire@mastodon.social at 2026-09-08T17:00:56.000Z ##

๐ŸŸ  CVE-2026-86738 - High (8.7)

Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters. Superusers can plant malicious CSS payloads using ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86728
(7.5 HIGH)

EPSS: 0.32%

updated 2026-09-08T18:32:00

1 posts

AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG schedules to unauthenticated users. Attackers can request the endpoint with sequential user or playlist IDs to retrieve sensitive credentials, server identifiers, and complete programme schedules without authentication.

thehackerwire@mastodon.social at 2026-09-08T17:02:18.000Z ##

๐ŸŸ  CVE-2026-86728 - High (7.5)

AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG schedules to unauthenticated users. Attackers can request the endpoint with sequential user or playl...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86727
(7.5 HIGH)

EPSS: 0.31%

updated 2026-09-08T18:31:59

1 posts

AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php that allows unauthenticated attackers to retrieve stream keys and m3u8 URLs by accessing the endpoint without authentication. Attackers can enumerate private, unlisted, and group-restricted live streams by parsing the hidden_applications array in the JSON response to obtain sensitive streaming creden

thehackerwire@mastodon.social at 2026-09-08T17:02:07.000Z ##

๐ŸŸ  CVE-2026-86727 - High (7.5)

AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php that allows unauthenticated attackers to retrieve stream keys and m3u8 URLs by accessing the endpoint without authentication. Attackers can enumerat...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86732
(8.8 HIGH)

EPSS: 0.51%

updated 2026-09-08T18:31:59

1 posts

Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated content editors to instantiate arbitrary classes through the criteria parameter. Attackers can inject a malicious class via criteria[withTransforms][0][class] that reaches ImageTransforms::normalizeTransform(), then use a PHP gadget chain with yii\rbac\PhpManager

thehackerwire@mastodon.social at 2026-09-08T17:01:06.000Z ##

๐ŸŸ  CVE-2026-86732 - High (8.8)

Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated content editors to instantiate arbitrary classes through the criteria parameter. Attackers can inject a malicio...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-26084
(9.9 CRITICAL)

EPSS: 0.24%

updated 2026-09-08T18:31:56

1 posts

A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.

CVE-2025-20701
(8.8 HIGH)

EPSS: 7.77%

updated 2026-09-08T18:31:36

1 posts

In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

2 repos

https://github.com/x0jac0b0x/skullcandy-dime3-cve-2025-20701

https://github.com/SpiritualMachines/buds-audit

cyberveille@mastobot.ping.moi at 2026-09-10T14:30:05.000Z ##

๐Ÿ“ข CVE-2025-20701 : Les รฉcouteurs Skullcandy Dime 3 vulnรฉrables au dรฉtournement Bluetooth

Le 9 septembre 2026, BleepingComputer relaie un avis du CERT/CC de l'Universitรฉ Carnegie Mellon concernant une vulnรฉrabilitรฉ affectant les รฉcouteurs sans fil Skullcandy Dime 3 (modรจle S2DCW). La faille, identifiรฉe sous CVE-2025-20701, est prรฉsente dans leโ€ฆ

๐Ÿ“– cyberveille : cyberveille.ch/posts/2026-09-1
๐ŸŒ source : bleepingcomputer.com/news/secu
๐ŸŸก vรฉrification factuelle moyenne
#Bluetooth #SkullcandyDime3 #Cyberveille

##

CVE-2026-33197
(0 None)

EPSS: 0.12%

updated 2026-09-08T16:18:08.077000

2 posts

AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause the โ€œIncomplete List of Disallowedย Inputsโ€ by local access. Successful exploitation of this vulnerability may lead to arbitrary code execution and impactย system Confidentiality, Integrity, and Availability.

DailyCyberSecurity at 2026-09-10T01:14:10.106Z ##

A critical Secure Boot bypass vulnerability via a UEFI Shell flaw exposes servers to code execution. Discover how CVE-2026-33197 impacts devices.

securityonline.info/secure-boo

##

DailyCyberSecurity@infosec.exchange at 2026-09-10T01:14:10.000Z ##

A critical Secure Boot bypass vulnerability via a UEFI Shell flaw exposes servers to code execution. Discover how CVE-2026-33197 impacts devices.

#SecureBoot #UEFI #Vulnerability #Cybersecurity #CVE202633197

securityonline.info/secure-boo

##

CVE-2026-31431
(7.8 HIGH)

EPSS: 99.91%

updated 2026-09-08T15:13:07.273000

1 posts

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just

100 repos

https://github.com/MrAriaNet/cPanel-Fix

https://github.com/yandex-cloud-examples/yc-mk8s-copy-fail-mitigation

https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized

https://github.com/Juguitos/copy-fail

https://github.com/rootsecdev/cve_2026_31431

https://github.com/Boos4721/copyfail-rs

https://github.com/atgreen/block-copyfail

https://github.com/badsectorlabs/copyfail-go

https://github.com/Xerxes-2/CVE-2026-31431-rs

https://github.com/sec17br/CVE-2026-31431-Copy-Fail

https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag

https://github.com/SeanRickerd/cve-2026-31431

https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE

https://github.com/Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail

https://github.com/bigwario/copy-fail-CVE-2026-31431-C

https://github.com/ben-slates/CVE-2026-31431-Exploit

https://github.com/ZephrFish/CopyFail-CVE-2026-31431

https://github.com/TheMalwareGuardian/CVE-2026-31431

https://github.com/mym0us3r/COPY-FAIL-Detection-with-Wazuh-4.14.4

https://github.com/erlangparasu/mitigate_cve_2026_31431-sh

https://github.com/Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431

https://github.com/g1nt0n1x/copy-fail-CVE-2026-31431-shell

https://github.com/Sl4cK0TH/CVE-2026-31431-PoC

https://github.com/KaraZajac/DIRTYFAIL

https://github.com/mahdi13830510/CVE-2026-31431-mitigation-suite

https://github.com/mrunalp/block-copyfail

https://github.com/JuanBindez/CVE-2026-31431

https://github.com/Smarttfoxx/copyfail

https://github.com/JnamerZ/CopyFail-CVE-2026-31431

https://github.com/rvzsec/CVE-2026-31431

https://github.com/Iamliuxiaozhen/copy_fail

https://github.com/ErdemOzgen/copy-fail-cve-2026-31431

https://github.com/nisec-eric/cve-2026-31431

https://github.com/Dabbleam/CVE-2026-31431-mitigation

https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit

https://github.com/xeloxa/copyfail-exploit

https://github.com/povzayd/CVE-2026-31431

https://github.com/abdelkabirouadoukou/CVE-2026-31431-Analysis-and-Fix

https://github.com/pedromizz/copy-fail

https://github.com/cyber-joker/copy-fail-python

https://github.com/adampielak/CVE-2026-31431_SCA_WAZUH

https://github.com/ExploitEoom/CVE-2026-31431

https://github.com/scriptzteam/Paranoid-Copy-Fail-CVE-2026-31431

https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail

https://github.com/cs8425/copy-fail-go

https://github.com/kinryulabs/rootpacket-cve-2026-31431

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC

https://github.com/pyroceper/copy-fail-CVE-2026-31431

https://github.com/wgnet/wg.copyfail.patch

https://github.com/samanzamani/copy-fail-checker

https://github.com/diemoeve/copyfail-rs

https://github.com/tgies/copy-fail-c

https://github.com/painoob/Copy-Fail-Exploit-CVE-2026-31431

https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script

https://github.com/0xBlackash/CVE-2026-31431

https://github.com/Shotafry/CopyFail-Exploits-CVE-2026-31431

https://github.com/desultory/CVE-2026-31431

https://github.com/XsanFlip/CVE-2026-31431-Patch

https://github.com/sgkdev/page_inject

https://github.com/0xShe/CVE-2026-31431

https://github.com/b5null/CVE-2026-31431-C

https://github.com/luotian2/CVE-2026-31431

https://github.com/insomnisec/Detections-CVE-2026-31431

https://github.com/yuspring/cve-2026-31431-poc

https://github.com/malwarekid/CVE-2026-31431

https://github.com/aestechno/cve-2026-31431-ansible

https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431

https://github.com/4xura/CVE-2026-31431-Copy-Fail

https://github.com/qi4L/CVE-2026-31431-Container-Escape

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC

https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431

https://github.com/Qengineering/RK35xx-CopyFail-Hotfix

https://github.com/AdityaBhatt3010/CVE-2026-31431

https://github.com/Huchangzhi/autorootlinux

https://github.com/M4xSec/CVE-2026-31431-RCE-Exploit

https://github.com/guiimoraes/CVE-2026-31431

https://github.com/theori-io/copy-fail-CVE-2026-31431

https://github.com/philfry/cve-2026-31431-ftrace

https://github.com/AliHzSec/CVE-2026-31431

https://github.com/sammwyy/copyfail-rs

https://github.com/kadir/copy-fail-CVE-2026-31431-IOC

https://github.com/wuwu001/CVE-2026-31431-exploit

https://github.com/sgkdev/ptrace_may_dream

https://github.com/sudoytang/copyfail-arm64

https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe

https://github.com/kvakirsanov/CVE-2026-31431-live-process-code-injection

https://github.com/jbnetwork-git/copy-fail-check

https://github.com/wesmar/CVE-2026-31431

https://github.com/gagaltotal/cve-2026-31431-copy-fail

https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs

https://github.com/cozystack/copy-fail-blocker

https://github.com/novysodope/copy-fail-CVE-2026-31431-C

https://github.com/haydenjames/CVE-2026-31431-check

https://github.com/Alfredooe/CVE-2026-31431

https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit

https://github.com/pascal-gujer/CVE-2026-31431

https://github.com/MartinPham/copy-fail-CVE-2026-31431-php

https://github.com/hans362/CVE-2026-31431-Copy-Fail-Container-Escape

https://github.com/lonelyor/CVE-2026-31431-exp

https://github.com/bootsareme/copyfail-deconstructed

kubesploit@learnk8s.news at 2026-09-09T18:36:03.000Z ##

This article examines why Copy Fail (CVE-2026-31431) breaks container assumptions and provides a small, safe Python check to determine whether your nodes can reach the vulnerable kernel path

โžœ ku.bz/CTv-Yf60c

##

CVE-2026-85012
(8.0 HIGH)

EPSS: 1.06%

updated 2026-09-08T14:00:33.017000

2 posts

Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository in the project to execute arbitrary commands in the blueprint resynthesis environment via shell metacharacters in the owner field of a [local] merge strategy entry

awssecurityfeed at 2026-09-09T21:45:02.293Z ##

CVE-2026-85012 - OS command injection in the Amazon CodeCatalyst blueprints SDK

Bulletin ID: 2026-095-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/03/2026 10:00 AM PDT
Description:
Amazon CodeCatalyst blueprints are reusable project templates that generate a software proj...

aws.amazon.com/security/securi

##

awssecurityfeed@infosec.exchange at 2026-09-09T21:45:02.000Z ##

CVE-2026-85012 - OS command injection in the Amazon CodeCatalyst blueprints SDK

Bulletin ID: 2026-095-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/03/2026 10:00 AM PDT
Description:
Amazon CodeCatalyst blueprints are reusable project templates that generate a software proj...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-78234
(9.9 CRITICAL)

EPSS: 0.21%

updated 2026-09-08T12:31:35

1 posts

A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a namespaced Hawtio custom resource. Because the operator ships a ClusterRole that aggregates Hawtio CR permissions into the edit and admin roles, any user with

DailyCyberSecurity@infosec.exchange at 2026-09-09T00:32:06.000Z ##

A critical Hawtio Operator vulnerability, tracked as CVE-2026-78234, allows in-cluster service impersonation. Discover the impact and mitigation steps.

#HawtioOperator #CVE202678234 #Kubernetes #OpenShift #Vulnerability

securityonline.info/hawtio-ope

##

CVE-2026-50093
(9.0 None)

EPSS: 0.19%

updated 2026-09-08T09:35:45

1 posts

A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Control V3.0 (All versions < V3.0.22.2177), Siveillance Control V4.0 (All versions < V4.0.11.2177). A vulnerability in the OIS web module allows an attacker to upload arbitrary files to the server. Successful exploitation of this

CVE-2026-86206(CVSS UNKNOWN)

EPSS: 0.68%

updated 2026-09-05T21:31:26

2 posts

A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4

ssvc@infosec.exchange at 2026-09-09T01:37:53.000Z ##

N-able didn't beat around the bush:

Since our post 9/5/2026, 08:11:00 UTC a third independent researcher disclosed to N-able a new vulnerabilityโ€” one that has been exploited in the wild and is unrelated to the previously disclosed CVEs.

This critical zero-day vulnerability, CVE-2026-86218, could allow pre-authenticated access to the N-central server if exploited.

#nable #zeroday #KEV #CVE

##

AAKL@infosec.exchange at 2026-09-08T16:56:24.000Z ##

New.

Rapid7: CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED) rapid7.com/blog/post/ve-cve-20 @Rapid7Official #infosec #vulnerability #threatresearch

##

CVE-2026-67276(CVSS UNKNOWN)

EPSS: 0.24%

updated 2026-09-05T21:31:20

1 posts

RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target

4 repos

https://github.com/dinosn/mikrotrick-poc

https://github.com/BlackHatExploitation/exploit-mikrotik-2026

https://github.com/HORKimhab/CVE-2026-67276

https://github.com/4rt-Net/Mikrotrick_POC

CVE-2026-86207(CVSS UNKNOWN)

EPSS: 0.73%

updated 2026-09-05T21:31:20

2 posts

An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs

ssvc@infosec.exchange at 2026-09-09T01:37:53.000Z ##

N-able didn't beat around the bush:

Since our post 9/5/2026, 08:11:00 UTC a third independent researcher disclosed to N-able a new vulnerabilityโ€” one that has been exploited in the wild and is unrelated to the previously disclosed CVEs.

This critical zero-day vulnerability, CVE-2026-86218, could allow pre-authenticated access to the N-central server if exploited.

#nable #zeroday #KEV #CVE

##

AAKL@infosec.exchange at 2026-09-08T16:56:24.000Z ##

New.

Rapid7: CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED) rapid7.com/blog/post/ve-cve-20 @Rapid7Official #infosec #vulnerability #threatresearch

##

CVE-2026-86090
(7.1 HIGH)

EPSS: 0.25%

updated 2026-09-05T00:31:10

1 posts

ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured notification endpoints and recipients, silencing all alerts.

hugovalters@mastodon.social at 2026-09-10T03:30:03.000Z ##

CVE-2026-86090: ntopng auth bypass lets non-admin users delete all alert endpoints, silencing critical notifications. CVSS 7.1. No patch yet. Audit your instance now. Details: valtersit.com/cve/CVE-2026-860 #CVE #infosec #ntopng

##

CVE-2026-80119
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-04T21:31:59

1 posts

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to dump complete physical memory contents by supplying a caller-controlled file path to an exposed IOCTL. Attackers can issue a single IOCTL call to trigger the driver

hugovalters@mastodon.social at 2026-09-10T04:20:44.000Z ##

CVE-2026-80119: Info disclosure in Directio64.sys lets unauthenticated local attackers dump physical memory via crafted IOCTL. CVSS 7.8. Unpatched. Update PassMark tools or restrict driver access. Details: valtersit.com/cve/CVE-2026-801 #CVE #infosec #cybersecurity

##

CVE-2026-80905(CVSS UNKNOWN)

EPSS: 0.15%

updated 2026-09-04T18:31:46

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: tap: fix wrong transport_header when sending VLAN-tagged frame In tap_get_user_xdp(), when processing a VLAN-tagged frame (e.g. ETH_P_8021Q), skb_set_network_header() is called first to advance network_header past the VLAN tag to the inner protocol header. skb_probe_transport_header() is then called with skb->protocol still

hugovalters@mastodon.social at 2026-09-10T08:10:03.000Z ##

CVE-2026-80905: Linux kernel net: tap bug mishandles VLAN-tagged frames, corrupting transport_header. Potential for network disruption or security bypass. Unpatchedโ€”act now. CVSS N/A. Details: valtersit.com/cve/CVE-2026-809 Update kernel immediately. #CVE #Linux #i

##

CVE-2026-9317
(8.1 HIGH)

EPSS: 0.68%

updated 2026-09-04T18:31:46

1 posts

Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by invoking the exposed start procedure without credentials. Attackers with network access to the runner port can send requests to the unauthenticated start procedure, bypassing the unenforced RUNNER_SECRET_KEY environment variable

hugovalters@mastodon.social at 2026-09-09T21:10:04.000Z ##

CVE-2026-9317: Nango <0.71.6 has a missing auth flaw in its runner tRPC server. Attackers can send requests to the unpatched start procedure, bypassing RUNNER_SECRET_KEY to trigger RCE. CVSS 8.1. Patch or isolate the runner port immediately. valtersit.com/cve/CVE-2026

##

CVE-2026-80874(CVSS UNKNOWN)

EPSS: 0.14%

updated 2026-09-04T18:31:40

1 posts

In the Linux kernel, the following vulnerability has been resolved: arm64: dts: renesas: ironhide: Describe inline ECC carveouts The DBSC5 DRAM controller protects DRAM content using inline ECC. The inline ECC utilizes areas of DRAM for its operation, which are in the DRAM address range, but must not be accessed or modified. Describe the inline ECC carveout areas used by the DBSC5 controller on

hugovalters@mastodon.social at 2026-09-10T19:10:04.000Z ##

CVE-2026-80874: Linux kernel arm64 Renesas flawโ€”inline ECC carveouts not reserved, risking DRAM corruption via memory access. Unpatched. If you run affected kernels, isolate or patch ASAP. Details: valtersit.com/cve/CVE-2026-808 #CVE #Linux #infosec

##

CVE-2026-17255
(4.3 MEDIUM)

EPSS: 0.40%

updated 2026-09-04T18:31:40

1 posts

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of the prefix length in ICMPv6 Router Advertisements.

hugovalters@mastodon.social at 2026-09-10T17:30:01.000Z ##

CVE-2026-17255: DoS in IBM i (7.3-7.6) via malformed ICMPv6 Router Advertisements. Remote crash risk, CVSS 4.3. No patch confirmed. Review firewall rules & disable IPv6 if unused. Details: valtersit.com/cve/CVE-2026-172 #CVE #IBM #infosec

##

CVE-2026-80872(CVSS UNKNOWN)

EPSS: 0.15%

updated 2026-09-04T18:31:40

1 posts

In the Linux kernel, the following vulnerability has been resolved: ALSA: hda/tas2781: Cancel async firmware request at unbind TAS2781 HDA I2C and SPI queue RCA firmware loading from component bind with request_firmware_nowait(). The firmware loader keeps the callback module pinned and holds a device reference, but the callback still uses driver-private HDA state. Component unbind removes contr

hugovalters@mastodon.social at 2026-09-10T14:30:03.000Z ##

CVE-2026-80872: Linux kernel ALSA tas2781 driver risks use-after-free during unbindโ€”async firmware callback can outlive private HDA state. Local impact, no CVSS yet. Patch status unknown, so audit & update when fix lands. Full details: valtersit.com/cve/CVE-2026-808

##

CVE-2026-17440
(5.5 MEDIUM)

EPSS: 0.10%

updated 2026-09-04T18:31:40

1 posts

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to cause a denial of service due to uncontrolled recursion.

hugovalters@mastodon.social at 2026-09-10T09:40:01.000Z ##

CVE-2026-17440: IBM App Connect Enterprise & Integration Bus for z/OS affected by DoS via uncontrolled recursion. CVSS 5.5. Local attacker can crash services. No patch yetโ€”monitor and limit local access. Details: valtersit.com/cve/CVE-2026-174 #CVE #IBM #cybersecur

##

CVE-2026-17057
(6.5 MEDIUM)

EPSS: 0.38%

updated 2026-09-04T18:31:40

1 posts

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions.

hugovalters@mastodon.social at 2026-09-10T06:40:01.000Z ##

CVE-2026-17057: IBM i (7.3-7.6) missing auth for critical functions. Remote DoS + data integrity risk. CVSS 6.5. No patch availableโ€”assume exposed. Lock down network access & monitor logs now. valtersit.com/cve/CVE-2026-170 #CVE #IBM #cybersecurity

##

CVE-2026-16660
(5.3 MEDIUM)

EPSS: 0.36%

updated 2026-09-04T18:31:39

1 posts

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.

hugovalters@mastodon.social at 2026-09-10T11:20:02.000Z ##

CVE-2026-16660: IBM Db2 Mirror for i (7.4-7.6) has an out-of-bounds read flaw. Remote attackers can trigger a DoS. CVSS 5.3. No patch yet. Details: valtersit.com/cve/CVE-2026-166 Monitor and harden access now. #CVE #IBM #infosec

##

CVE-2026-75754(CVSS UNKNOWN)

EPSS: 0.21%

updated 2026-09-04T03:31:07

1 posts

Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Centerย allow an unauthorized user to obtain the encryption key via an HTTP request, causing a local service to enable SSH on port 2222. The attacker can then log in with the hardcode credentialsย to obtain a root shell, enabling direct reading, writing, and deletion of

sekurakbot@mastodon.com.pl at 2026-09-09T10:26:00.000Z ##

RCE z uprawnieniami roota. Krytyczna podatnoล›ฤ‡ (CVSS 10.0) w ASUS Control Center Enterprise

Firma ASUS w najnowszym biuletynie bezpieczeล„stwa poinformowaล‚a o wykryciu krytycznej luki w popularnym oprogramowaniu ASUS Control Center Enterprise (ACC). Podatnoล›ฤ‡ oznaczona identyfikatorem CVE-2026-75754 otrzymaล‚a maksymalnฤ… ocenฤ™ 10.0 w skali CVSS 4.0. TLDR: ลšwiadczy to o tym, ลผe potencjalny atakujฤ…cy moลผe w ล‚atwy sposรณb, caล‚kowicie zdalnie oraz bez koniecznoล›ci jakiejkolwiek interakcji...

#WBiegu #Asus #ControlCenter #Cve #Rce

sekurak.pl/rce-z-uprawnieniami

##

CVE-2026-20355
(5.9 MEDIUM)

EPSS: 0.15%

updated 2026-09-02T19:23:13.660000

1 posts

Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle tec

AAKL@infosec.exchange at 2026-09-08T16:42:45.000Z ##

New advisories from Cisco addressing two high and medium-severity vulnerabilities.

New: CVE-2026-20293: Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability sec.cloudapps.cisco.com/securi

Known: CVE-2026-20354 and CVE-2026-20355: Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities @TalosSecurity #infosec #vulnerability #Cisco

##

CVE-2026-20354
(5.9 MEDIUM)

EPSS: 0.15%

updated 2026-09-02T18:32:31

1 posts

Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle techn

AAKL@infosec.exchange at 2026-09-08T16:42:45.000Z ##

New advisories from Cisco addressing two high and medium-severity vulnerabilities.

New: CVE-2026-20293: Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability sec.cloudapps.cisco.com/securi

Known: CVE-2026-20354 and CVE-2026-20355: Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities @TalosSecurity #infosec #vulnerability #Cisco

##

CVE-2026-20212
(9.8 CRITICAL)

EPSS: 0.53%

updated 2026-09-02T18:32:26

1 posts

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with&nbsp;root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and

1 repos

https://github.com/HORKimhab/CVE-2026-20212

sekurakbot@mastodon.com.pl at 2026-09-09T10:26:00.000Z ##

Krytyczna luka w przeล‚ฤ…cznikach Cisco Nexus 9000 [CVE-2026-20212]. RCE bez uwierzytelnienia i dostฤ™p do roota

Firma Cisco opublikowaล‚a biuletyn bezpieczeล„stwa opisujฤ…cy krytycznฤ… lukฤ™ w przeล‚ฤ…cznikach Nexus serii 9000 opartych na ukล‚adach Silicon One. Podatnoล›ฤ‡ zostaล‚a oznaczona jako CVE-2026-20212 i oceniona na 9.8 (Critical) w skali CVSS v3.1. Umoลผliwia nieuwierzytelnionemu uลผytkownikowi zdalne wykonanie kodu z uprawnieniami roota. Poprawki bezpieczeล„stwa sฤ… juลผ dostฤ™pne, zalecamy niezwล‚ocznฤ… aktualizacjฤ™ oprogramowania. ...

#WBiegu #Cisco #Cve #Nexus #Rce #Switch

sekurak.pl/krytyczna-luka-w-pr

##

CVE-2026-83548
(10.0 CRITICAL)

EPSS: 4.67%

updated 2026-09-02T18:32:06

1 posts

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

3 repos

https://github.com/HORKimhab/CVE-2026-83548-CVE-2026-83549

https://github.com/xcoy0te/CVE-2026-83548-checker

https://github.com/xoessie/CVE-2026-83548-SonicWall-SMA1000-Analysis

PC_Fluesterer@social.tchncs.de at 2026-09-10T11:55:45.000Z ##

SonicWall VPN-Router (Closed-Source) wird aktiv angegriffen

Appliances der SMA1000 Serie des amerikanischen Herstellers SonicWall stehen gerade unter Beschuss. Die Boxen sollen eigentlich fรผr einen sicheren Fernzugang per VPN ins Intranet sorgen. Ja, es hรคtte so schรถn sein kรถnnen. Die Angreifer verketten zwei unterschiedliche "Sicherheitslรผcken", um sich unbefugten Zugang in das Unternehmensnetzwerk dahinter zu verschaffen. Weshalb habe ich "Sicherheitslรผcken" in Anfรผhrungszeichen geschrieben? Weil es hier wieder mal streng riecht - nach Hintertรผr. Die erste Zero-day Schwachstelle CVE-2026-83548 (10 von 10) entsteht durch ... Weiterlesen:

pc-fluesterer.info/wordpress/2

#0day #backdoor #cybercrime #exploits #firewall #hersteller #router #UnplugTrump #vorbeugen #wissen #zeroday

##

CVE-2026-81578
(9.8 CRITICAL)

EPSS: 1.62%

updated 2026-09-01T04:18:01.990000

4 posts

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specificย conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

2 repos

https://github.com/virologi-info/papercut-toolkit

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

cyberveille@mastobot.ping.moi at 2026-09-10T14:00:06.000Z ##

๐Ÿ“ข Exploitation IA ร  grande รฉchelle de PaperCut via CVE-2026-81578 et CVE-2026-82078

Cet article prรฉsente l'analyse technique d'une campagne d'exploitation active de serveurs PaperCut exposรฉs sur Internet, utilisant les vulnรฉrabilitรฉs CVE-2026-81578 et CVE-2026-82078.

๐Ÿ“– cyberveille : cyberveille.ch/posts/2026-09-1
๐ŸŒ source : blackpointcyber.com/blog/death
๐ŸŸข vรฉrification factuelle haute
#PaperCut #AIAssistedExploitation #Cyberveille

##

AAKL@infosec.exchange at 2026-09-09T16:37:11.000Z ##

Which is to say, a real person directed this nonsense.

"On 31 August 2026, a likely Russian-speaking malicious cyber actor (MCA) used 45.142.193.132 and artificial intelligence (AI) to develop, test, and use exploits for PaperCut NG/MF (CVE-2026-81578 and CVE-2026-82078)."

GreyNoise: Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF greynoise.io/blog/ai-orchestra @greynoise #infosec #cyberattack #bot

##

guru@thecybersecguru.com at 2026-09-09T15:35:45.000Z ##

The AI swarm that breached 440 PaperCut servers worldwide

GreyNoise uncovered an AI-driven PaperCut attack that compromised 440 servers across 395 organizations in 48 countries using CVE-2026-81578 and CVE-2026-82078

thecybersecguru.com/news/ai-sw

##

ssvc@infosec.exchange at 2026-09-09T13:54:30.000Z ##

GreyNoise: Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF

On 31 August 2026, a likely Russian-speaking malicious cyber actor (MCA) used 45.142.193.132 and artificial intelligence (AI) to develop, test, and use exploits for PaperCut NG/MF (CVE-2026-81578 and CVE-2026-82078).
greynoise.io/blog/ai-orchestra

#papercut #CVE #threatintel #IOC

##

CVE-2026-82078
(9.1 CRITICAL)

EPSS: 1.69%

updated 2026-08-31T21:31:56

4 posts

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on

2 repos

https://github.com/virologi-info/papercut-toolkit

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

cyberveille@mastobot.ping.moi at 2026-09-10T14:00:06.000Z ##

๐Ÿ“ข Exploitation IA ร  grande รฉchelle de PaperCut via CVE-2026-81578 et CVE-2026-82078

Cet article prรฉsente l'analyse technique d'une campagne d'exploitation active de serveurs PaperCut exposรฉs sur Internet, utilisant les vulnรฉrabilitรฉs CVE-2026-81578 et CVE-2026-82078.

๐Ÿ“– cyberveille : cyberveille.ch/posts/2026-09-1
๐ŸŒ source : blackpointcyber.com/blog/death
๐ŸŸข vรฉrification factuelle haute
#PaperCut #AIAssistedExploitation #Cyberveille

##

AAKL@infosec.exchange at 2026-09-09T16:37:11.000Z ##

Which is to say, a real person directed this nonsense.

"On 31 August 2026, a likely Russian-speaking malicious cyber actor (MCA) used 45.142.193.132 and artificial intelligence (AI) to develop, test, and use exploits for PaperCut NG/MF (CVE-2026-81578 and CVE-2026-82078)."

GreyNoise: Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF greynoise.io/blog/ai-orchestra @greynoise #infosec #cyberattack #bot

##

guru@thecybersecguru.com at 2026-09-09T15:35:45.000Z ##

The AI swarm that breached 440 PaperCut servers worldwide

GreyNoise uncovered an AI-driven PaperCut attack that compromised 440 servers across 395 organizations in 48 countries using CVE-2026-81578 and CVE-2026-82078

thecybersecguru.com/news/ai-sw

##

ssvc@infosec.exchange at 2026-09-09T13:54:30.000Z ##

GreyNoise: Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF

On 31 August 2026, a likely Russian-speaking malicious cyber actor (MCA) used 45.142.193.132 and artificial intelligence (AI) to develop, test, and use exploits for PaperCut NG/MF (CVE-2026-81578 and CVE-2026-82078).
greynoise.io/blog/ai-orchestra

#papercut #CVE #threatintel #IOC

##

CVE-2026-77237
(6.5 MEDIUM)

EPSS: 0.13%

updated 2026-08-25T16:44:12.343000

2 posts

Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports with configUSE_QUEUE_SETS=1 to read privileged kernel memory.ย To remediate this issue, users should upgrade to versionย 11.3.1 or later.

awssecurityfeed at 2026-09-09T21:45:01.951Z ##

Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237

Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT
Description:
FreeRTOS-Kernel is a real-time operating system kernel for microcontrollers and small micro...

aws.amazon.com/security/securi

##

awssecurityfeed@infosec.exchange at 2026-09-09T21:45:01.000Z ##

Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237

Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT
Description:
FreeRTOS-Kernel is a real-time operating system kernel for microcontrollers and small micro...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-69836
(10.0 CRITICAL)

EPSS: 1.55%

updated 2026-08-25T16:08:43.290000

1 posts

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

2 repos

https://github.com/HORKimhab/CVE-2026-69836

https://github.com/sentinel-aidefense/CVE-2026-69836-EXP

adulau@infosec.exchange at 2026-09-09T14:43:49.000Z ##

The @gcve BCP-07 KEV format has been updated to allow the Withdrawn and Reasserted KEV Assertions.

This allows to support case like CVE-2026-69836 .

๐Ÿ”— gcve.eu/bcp/gcve-bcp-07/#withd

#cve #gcve #kev #cybersecurity #vulnerabilitymanagement #vulnerability

##

CVE-2026-69414
(7.8 HIGH)

EPSS: 0.56%

updated 2026-08-19T18:32:28

6 posts

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;ShieldBreak &quot;. We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.

2 repos

https://github.com/1neptune/ShieldBreak

https://github.com/HORKimhab/CVE-2026-50656

cyberworldops at 2026-09-10T18:50:00.635Z ##

Researcher Nightmare-Eclipse has released ShieldCrash, a PoC claiming to bypass Microsoft's fix for CVE-2026-69414, a privilege escalation flaw in Defender's Malware Protection Engine. Public exploit code may increase abuse; verify the patch blocks the technique and monitor for exploitation.

cyberworldops.eu/en/shieldcras

##

offseq at 2026-09-10T07:30:25.020Z ##

CRITICAL: ShieldCrash zero-day (CVE-2026-69414) exploits Microsoft Defender on patched Windows (Sept 2026), enabling privilege escalation to System and SAM dumping. No patch yet. Monitor for Defender anomalies. radar.offseq.com/threat/new-sh

##

cyberworldops@infosec.exchange at 2026-09-10T18:50:00.000Z ##

Researcher Nightmare-Eclipse has released ShieldCrash, a PoC claiming to bypass Microsoft's fix for CVE-2026-69414, a privilege escalation flaw in Defender's Malware Protection Engine. Public exploit code may increase abuse; verify the patch blocks the technique and monitor for exploitation. #CyberSecurity #Vulnerability #ThreatIntel #MicrosoftDefender

cyberworldops.eu/en/shieldcras

##

offseq@infosec.exchange at 2026-09-10T07:30:25.000Z ##

CRITICAL: ShieldCrash zero-day (CVE-2026-69414) exploits Microsoft Defender on patched Windows (Sept 2026), enabling privilege escalation to System and SAM dumping. No patch yet. Monitor for Defender anomalies. radar.offseq.com/threat/new-sh #OffSeq #ZeroDay #MicrosoftDefender #Infosec

##

cyberworldops@infosec.exchange at 2026-09-09T12:50:00.000Z ##

Chaotic Eclipse released ShieldCrash PoC, described as a patch bypass for CVE-2026-69414 ShieldBreak in Microsoft Malware Protection Engine. If valid, Defender privilege escalation remains exploitable despite the official fix, requiring re-validation of mitigations. #ShieldBreak #MicrosoftDefender #PatchBypass

cyberworldops.eu/en/microsoft-

##

DailyCyberSecurity@infosec.exchange at 2026-09-09T00:35:56.000Z ##

A Windows Defender 0day has public PoC exploit code. ShieldCrash reads files as SYSTEM on all supported Windows versions.

#WindowsDefender #0day #CVE #ShieldCrash #CyberSecurity #Windows #PoC #Infosec

securityonline.info/windows-de

##

CVE-2026-68820
(7.0 HIGH)

EPSS: 6.18%

updated 2026-08-16T19:17:24.183000

1 posts

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

4 repos

https://github.com/ubitquity/Windows-WinSock-UAF-Mitigation

https://github.com/fevar54/CVE-2026-68820-Mitigation-PoC-

https://github.com/maxprog-svg/CVE-2026-68820_Mass_Exploit

https://github.com/HORKimhab/CVE-2026-68820

cyberworldops@infosec.exchange at 2026-09-09T10:30:00.000Z ##

Microsoft patched 398 vulnerabilities, 42 rated Critical. CVE-2026-68820 in afd.sys is actively exploited and added to CISA KEV, enabling local privilege escalation to SYSTEM. Prioritize Kernel and RCE flaws in this cycle. #PatchTuesday #WindowsSecurity #CisaKev

cyberworldops.eu/en/microsoft-

##

CVE-2026-19311
(8.1 HIGH)

EPSS: 0.41%

updated 2026-08-12T21:31:44

2 posts

Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.

awssecurityfeed at 2026-09-09T21:45:02.820Z ##

CVE-2026-19311- Missing Authorization in OpenSearch Alerting Plugin

Bulletin ID: 2026-078-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/12/2026 11:30 AM PDT
Description:
OpenSearch is a community-driven, open-source search and analytics suite. We identified CVE...

aws.amazon.com/security/securi

##

awssecurityfeed@infosec.exchange at 2026-09-09T21:45:02.000Z ##

CVE-2026-19311- Missing Authorization in OpenSearch Alerting Plugin

Bulletin ID: 2026-078-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/12/2026 11:30 AM PDT
Description:
OpenSearch is a community-driven, open-source search and analytics suite. We identified CVE...

aws.amazon.com/security/securi

#aws #security

##

CVE-2025-14733
(9.8 CRITICAL)

EPSS: 26.51%

updated 2026-08-10T21:33:00

9 posts

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.This vulnerability affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.11.5 and

1 repos

https://github.com/machevalia/CVE-2025-14733

security_crawler_carl at 2026-09-10T20:28:41.199Z ##

๐Ÿ† New Achievement! WatchGuard Out, Ransomware In!

Patch Notes v0.0.0 (Unplanned Release): REMOVED โ€” the assumption that your perimeter firewall was keeping anyone out. ADDED โ€” unauthenticated remote code execution via CVE-2025-14733, a critical out-of-bounds write in the Fireware OS iked process affecting versions 11.x, 12.x, and 2025.1 through 2025.1.3. KNOWN ISSUE โ€” ransomware gangs are already shipping this feature to your network. (1/2)

##

undercodenews@mastodon.social at 2026-09-10T13:08:36.000Z ##

CISA Warns WatchGuard Firebox RCE Is Being Exploited by Ransomware Attackers + Video

A Critical Firewall Vulnerability Has Become a Real-World Threat A serious warning is emerging for organizations that rely on WatchGuard Firebox appliances to protect their networks. The vulnerability tracked as CVE-2025-14733 is a critical out-of-bounds write flaw in the Fireware OS iked process that can allow an unauthenticated remote attacker to execute arbitrary code. WatchGuardโ€ฆ

undercodenews.com/cisa-warns-w

##

offseq at 2026-09-10T12:00:25.712Z ##

CVE-2025-14733: CRITICAL RCE in WatchGuard Firebox (Fireware OS 11.x+, 12.x+, 2025.1 โ€“ 2025.1.3) exploited by ransomware. Patch ASAP! Review VPN configs, monitor for IOCs. Details: radar.offseq.com/threat/cisa-w

##

cyberworldops at 2026-09-10T10:50:00.694Z ##

CISA confirmed CVE-2025-14733, a critical WatchGuard Firebox RCE, is being exploited in ransomware attacks. Edge firewalls are high-value targets because compromise enables network-wide access. Patch immediately and audit exposed interfaces for post-exploitation activity.

cyberworldops.eu/en/cisa-confi

##

Analyst207@mastodon.social at 2026-09-10T09:37:59.000Z ##

Ransomware gangs exploit WatchGuard firewall flaw

Ransomware gangs are exploiting a critical vulnerability in WatchGuard Firebox firewalls, allowing them to execute malicious code remotely with ease. This flaw, known as CVE-2025-14733, affects various Fireware OS versions and could leave your network exposed to low-complexity attacks.

osintsights.com/ransomware-gan

#Ransomware #Watchguard #Cve202514733 #FirewareOs #Ikev2Vpn

##

security_crawler_carl@infosec.exchange at 2026-09-10T20:28:41.000Z ##

๐Ÿ† New Achievement! WatchGuard Out, Ransomware In!

Patch Notes v0.0.0 (Unplanned Release): REMOVED โ€” the assumption that your perimeter firewall was keeping anyone out. ADDED โ€” unauthenticated remote code execution via CVE-2025-14733, a critical out-of-bounds write in the Fireware OS iked process affecting versions 11.x, 12.x, and 2025.1 through 2025.1.3. KNOWN ISSUE โ€” ransomware gangs are already shipping this feature to your network. (1/2)

##

offseq@infosec.exchange at 2026-09-10T12:00:25.000Z ##

CVE-2025-14733: CRITICAL RCE in WatchGuard Firebox (Fireware OS 11.x+, 12.x+, 2025.1 โ€“ 2025.1.3) exploited by ransomware. Patch ASAP! Review VPN configs, monitor for IOCs. Details: radar.offseq.com/threat/cisa-w #OffSeq #WatchGuard #Ransomware #Infosec

##

cyberworldops@infosec.exchange at 2026-09-10T10:50:00.000Z ##

CISA confirmed CVE-2025-14733, a critical WatchGuard Firebox RCE, is being exploited in ransomware attacks. Edge firewalls are high-value targets because compromise enables network-wide access. Patch immediately and audit exposed interfaces for post-exploitation activity. #WatchGuard #Ransomware #CisaKev

cyberworldops.eu/en/cisa-confi

##

kev_Stalker@infosec.exchange at 2026-09-09T11:19:35.000Z ##

CVE-2025-14733 - Changed to Known Ransomware Status

WatchGuard Firebox Out of Bounds Write VulnerabilityVendor: WatchGuardProduct: FireboxWatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code and affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-20316
(5.3 MEDIUM)

EPSS: 11.15%

updated 2026-08-01T05:16:55.973000

7 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged&nbsp;account. An attacker could exploit this vu

cyberworldops at 2026-09-10T17:00:00.702Z ##

Cisco Talos reports active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center by Qilin ransomware, credential-theft actors, and Sandworm-linked groups. The auth bypass provides root command execution and the static credential exposure broadens initial access.

cyberworldops.eu/en/cisco-fmc-

##

undercodenews@mastodon.social at 2026-09-10T16:48:33.000Z ##

Cisco FMC Under Attack as Sandworm and Qilin Exploit Critical Vulnerabilities to Reach Protected Networks + Video

A New Warning for Enterprise Defenders Cisco Secure Firewall Management Center is facing a serious security crisis after Cisco Talos confirmed active exploitation of two vulnerabilities that can give attackers a foothold inside vulnerable environments. The flaws, tracked as CVE-2026-20079 and CVE-2026-20316, are being abused in real-world attacks involvingโ€ฆ

undercodenews.com/cisco-fmc-un

##

beyondmachines1 at 2026-09-10T10:01:13.581Z ##

Cisco Secure Firewall Management Center Under Active Attack

Cisco Talos warns of active exploitation of two vulnerabilities (CVE-2026-20079 and CVE-2026-20316) in Secure Firewall Management Center, allowing attackers to gain root access and deploy malware like Cyclops Blink and Qilin ransomware.

**If you run Cisco Secure Firewall Management Center (versions 7.0.x, 7.1.x, or 7.2โ€“7.7), apply Cisco's emergency patches for CVE-2026-20079 and CVE-2026-20316 right away. Make sure the management interface is reachable only from trusted internal networks, never the internet. Because these flaws are already being exploited, also check for unexpected files in /var/sf/bin/ and the Tomcat webroot. Then plan to install Cisco's hardening update due to be released in the week of September 14.**

beyondmachines.net/event_detai

##

cyberworldops@infosec.exchange at 2026-09-10T17:00:00.000Z ##

Cisco Talos reports active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center by Qilin ransomware, credential-theft actors, and Sandworm-linked groups. The auth bypass provides root command execution and the static credential exposure broadens initial access.

#CiscoFMC #ThreatIntelligence #VulnerabilityManagement #Qilin

cyberworldops.eu/en/cisco-fmc-

##

beyondmachines1@infosec.exchange at 2026-09-10T10:01:13.000Z ##

Cisco Secure Firewall Management Center Under Active Attack

Cisco Talos warns of active exploitation of two vulnerabilities (CVE-2026-20079 and CVE-2026-20316) in Secure Firewall Management Center, allowing attackers to gain root access and deploy malware like Cyclops Blink and Qilin ransomware.

**If you run Cisco Secure Firewall Management Center (versions 7.0.x, 7.1.x, or 7.2โ€“7.7), apply Cisco's emergency patches for CVE-2026-20079 and CVE-2026-20316 right away. Make sure the management interface is reachable only from trusted internal networks, never the internet. Because these flaws are already being exploited, also check for unexpected files in /var/sf/bin/ and the Tomcat webroot. Then plan to install Cisco's hardening update due to be released in the week of September 14.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

ssvc@infosec.exchange at 2026-09-09T21:01:44.000Z ##

Cisco Talos is actively tracking the exploitation of two vulnerabilities in Ciscoโ€™s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Ciscoโ€™s Secure FMC Software, which allows an unauthenticated, remote attacker to bypass authentications and execute scripts on impacted devices to obtain root access to the underlying operating system. Second, CVE-2026-20316 is a vulnerability that allows a remote attacker to log in using a low-privileged account.

blog.talosintelligence.com/fmc

#threatintel #ransomware #Qilin #KEV #CVE

##

DailyCyberSecurity@infosec.exchange at 2026-09-09T16:28:31.000Z ##

Cisco Talos warns of Cisco FMC vulnerabilities actively exploited in the wild. Attackers chain CVE-2026-20079 and CVE-2026-20316 to deploy ransomware.

#CiscoFMC #Cybersecurity #CVE202620079 #Ransomware #InfoSec

securityonline.info/cisco-fmc-

##

CVE-2026-15409
(10.0 CRITICAL)

EPSS: 83.66%

updated 2026-07-14T21:32:22

2 posts

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

6 repos

https://github.com/Ch4120N/CVE-2026-15409

https://github.com/tc4dy/CVE-2026-15409-15410-Framework

https://github.com/HORKimhab/CVE-2026-15409

https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check

https://github.com/remmons-r7/rapid7-CVE-2026-15409

https://github.com/0xBlackash/CVE-2026-15409

_r_netsec at 2026-09-10T17:58:04.748Z ##

๐Ÿ•ต๏ธโ€โ™‚๏ธ SonicWall SMA1000 (CVE-2026-15409): SSRF to Erlang RCE chained into automated DCSync from the appliance hunt.io/blog/sonicwall-sma1000

##

_r_netsec@infosec.exchange at 2026-09-10T17:58:04.000Z ##

๐Ÿ•ต๏ธโ€โ™‚๏ธ SonicWall SMA1000 (CVE-2026-15409): SSRF to Erlang RCE chained into automated DCSync from the appliance hunt.io/blog/sonicwall-sma1000

##

CVE-2026-52774
(6.1 MEDIUM)

EPSS: 0.51%

updated 2026-07-09T21:01:12

1 posts

### Summary YesWiki's Bazar widget handler reflects the `id` `GET` parameter into HTML attributes using `strip_tags()` only. Because `strip_tags()` does not escape double quotes, an attacker can break out of the attribute value, inject an event handler such as `onmouseover`, and execute arbitrary JavaScript in the victim's browser. This issue is reachable without authentication. During validation

1 repos

https://github.com/0xTerror/CVE-2026-52774-YESWIKI-XSS

hugovalters@mastodon.social at 2026-09-10T05:00:36.000Z ##

CVE-2026-52774: YesWiki < 4.6.6 has a stored XSS via the Bazar widget's id parameter, exploitable without auth. CVSS 6.1. No patch confirmed. Update immediately or restrict access. Details: valtersit.com/cve/CVE-2026-527 #CVE #infosec #YesWiki

##

CVE-2026-11387
(9.8 CRITICAL)

EPSS: 2.21%

updated 2026-07-01T09:30:33

2 posts

The SMS Alert โ€“ SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.9.5. This is due to the plugin not properly validating a user's identity prior to updating their details like reset the password of any user account, including administrators, and gain full a

2 repos

https://github.com/1beelze/CVE-2026-11387

https://github.com/abraxas/CVE-2026-11387-WooCommerce-SMS-OTP

DarkWebInformer at 2026-09-10T20:20:41.274Z ##

โ€ผ๏ธ CVE-2026-11387: A critical improper-authentication flaw in the WordPress plugin SMS Alert โ€“ SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery.

GitHub: github.com/abraxas/CVE-2026-11

##

DarkWebInformer@infosec.exchange at 2026-09-10T20:20:41.000Z ##

โ€ผ๏ธ CVE-2026-11387: A critical improper-authentication flaw in the WordPress plugin SMS Alert โ€“ SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery.

GitHub: github.com/abraxas/CVE-2026-11

##

CVE-2026-43502
(7.8 HIGH)

EPSS: 0.12%

updated 2026-06-01T18:31:32

2 posts

In the Linux kernel, the following vulnerability has been resolved: net/rds: handle zerocopy send cleanup before the message is queued A zerocopy send can fail after user pages have been pinned but before the message is attached to the sending socket. The purge path currently infers zerocopy state from rm->m_rs, so an unqueued message can be cleaned up as if it owned normal payload pages. Howev

1 repos

https://github.com/suominen/pintheft

bearstech@mamot.fr at 2026-09-10T09:14:32.000Z ##

ZcopyReaper (CVE-2026-43502) nous avons dรฉployรฉ cette nuit les mesures de contournement.

Toutes nos VM ont รฉtรฉ redรฉmarrรฉes en moins dโ€™une heure.

๐Ÿ‘‰ En savoir plus sur nos offres d'infogรฉrance : bearstech.com/contact

Merci ร  @Octopuce et @evolix pour votre collaboration sur ce sujet.

##

bearstech@mamot.fr at 2026-09-10T09:14:32.000Z ##

ZcopyReaper (CVE-2026-43502) nous avons dรฉployรฉ cette nuit les mesures de contournement.

Toutes nos VM ont รฉtรฉ redรฉmarrรฉes en moins dโ€™une heure.

๐Ÿ‘‰ En savoir plus sur nos offres d'infogรฉrance : bearstech.com/contact

Merci ร  @Octopuce et @evolix pour votre collaboration sur ce sujet.

##

CVE-2026-8510
(7.5 HIGH)

EPSS: 0.21%

updated 2026-05-15T00:31:36

1 posts

Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

daniel1820815@infosec.exchange at 2026-09-09T20:10:44.000Z ##

[Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510

Check Point research team has identified and remediated two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, which could potentially allow unauthenticated remote code execution under specific conditions. These issues were discovered internally, and we have no indication of active exploitation.

community.checkpoint.com/t5/Ge

#CheckPoint #CheckPointSoftwareTechnologies #VPN #vulnerability

##

CVE-2026-33671
(7.5 HIGH)

EPSS: 0.40%

updated 2026-03-27T21:36:14

2 posts

### Impact `picomatch` is vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob quantifiers such as `+()` and `*()`, especially when combined with overlapping alternatives or nested extglobs, are compiled into regular expressions that can exhibit catastrophic backtracking on non-matching input. Examples of problematic p

1 repos

https://github.com/BeLazy167/next-picomatch-cve-repro

certvde at 2026-09-10T07:33:05.830Z ##

๐Ÿ”„ CSAF advisory updated (version 2.0.0)

VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)

Changes: corrected version

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

##

certvde@infosec.exchange at 2026-09-10T07:33:05.000Z ##

๐Ÿ”„ CSAF advisory updated (version 2.0.0)

VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)

Changes: corrected version

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

#OT #Advisory

##

CVE-2026-33186
(9.1 CRITICAL)

EPSS: 1.56%

updated 2026-03-25T18:12:09

2 posts

### Impact _What kind of vulnerability is it? Who is impacted?_ It is an **Authorization Bypass** resulting from **Improper Input Validation** of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server successfully rou

1 repos

https://github.com/JohannesLks/CVE-2026-33186

certvde at 2026-09-10T07:33:05.830Z ##

๐Ÿ”„ CSAF advisory updated (version 2.0.0)

VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)

Changes: corrected version

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

##

certvde@infosec.exchange at 2026-09-10T07:33:05.000Z ##

๐Ÿ”„ CSAF advisory updated (version 2.0.0)

VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)

Changes: corrected version

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

#OT #Advisory

##

CVE-2026-0915
(7.5 HIGH)

EPSS: 0.59%

updated 2026-01-20T18:31:56

2 posts

Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.

1 repos

https://github.com/Terra-Nova83/CVE-2026-0915-json-Patch.-V2.0

certvde at 2026-09-10T07:33:05.830Z ##

๐Ÿ”„ CSAF advisory updated (version 2.0.0)

VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)

Changes: corrected version

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

##

certvde@infosec.exchange at 2026-09-10T07:33:05.000Z ##

๐Ÿ”„ CSAF advisory updated (version 2.0.0)

VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)

Changes: corrected version

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

#OT #Advisory

##

CVE-2019-0859
(7.8 HIGH)

EPSS: 4.15%

updated 2025-10-22T00:32:43

2 posts

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0803.

1 repos

https://github.com/Sheisback/CVE-2019-0859-1day-Exploit

kev_Stalker at 2026-09-10T11:20:16.857Z ##

CVE-2019-0859 - Changed to Known Ransomware Status

Microsoft Win32k Privilege Escalation VulnerabilityVendor: MicrosoftProduct: Win32kMicrosoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 09, 2026 at 14:08:17 UTCDate Added to KEV: 2021-11-03View nvd.nist.gov/vuln/detail/CVE-2

##

kev_Stalker@infosec.exchange at 2026-09-10T11:20:16.000Z ##

CVE-2019-0859 - Changed to Known Ransomware Status

Microsoft Win32k Privilege Escalation VulnerabilityVendor: MicrosoftProduct: Win32kMicrosoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 09, 2026 at 14:08:17 UTCDate Added to KEV: 2021-11-03View nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2022-41352
(9.8 CRITICAL)

EPSS: 95.48%

updated 2025-10-22T00:32:37

2 posts

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavisd via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red H

4 repos

https://github.com/dafrax/cve-2022-41352-zimbra-rce

https://github.com/segfault-it/cve-2022-41352

https://github.com/rxerium/CVE-2022-41352

https://github.com/Cr4ckC4t/cve-2022-41352-zimbra-rce

kev_Stalker at 2026-09-10T11:25:19.656Z ##

CVE-2022-41352 - Changed to Known Ransomware Status

Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload VulnerabilityVendor: SynacorProduct: Zimbra Collaboration Suite (ZCS)Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to upload arbitrary files using cpio package to gain incorrect access to any other user accounts.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 09, 2026 nvd.nist.gov/vuln/detail/CVE-2

##

kev_Stalker@infosec.exchange at 2026-09-10T11:25:19.000Z ##

CVE-2022-41352 - Changed to Known Ransomware Status

Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload VulnerabilityVendor: SynacorProduct: Zimbra Collaboration Suite (ZCS)Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to upload arbitrary files using cpio package to gain incorrect access to any other user accounts.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 09, 2026 nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2025-2524
(4.8 MEDIUM)

EPSS: 0.30%

updated 2025-06-17T21:31:59

1 posts

The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2026-89049
(0 None)

EPSS: 0.00%

4 posts

N/A

thehackerwire@mastodon.social at 2026-09-10T21:00:17.000Z ##

๐Ÿ”ด CVE-2026-89049 - Critical (9.9)

A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allo...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

awssecurityfeed at 2026-09-10T19:00:01.199Z ##

CVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent

Bulletin ID: 2026-107-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 11:30 AM PDT
Description:
AWS Systems Manager Agent (SSM Agent) is software that runs on managed nodes (EC2 instances...

aws.amazon.com/security/securi

##

thehackerwire@mastodon.social at 2026-09-10T21:00:17.000Z ##

๐Ÿ”ด CVE-2026-89049 - Critical (9.9)

A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allo...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

awssecurityfeed@infosec.exchange at 2026-09-10T19:00:01.000Z ##

CVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent

Bulletin ID: 2026-107-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 11:30 AM PDT
Description:
AWS Systems Manager Agent (SSM Agent) is software that runs on managed nodes (EC2 instances...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-88052
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-10T19:00:53.000Z ##

๐ŸŸ  CVE-2026-88052 - High (7.8)

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, UNICHARSET::load_via_fgets in src/ccutil/unicharset.cpp trusts the declared unichar count as a loop bound and uses id as an unchecked index into the unichars vector. unichar_ins...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T19:00:53.000Z ##

๐ŸŸ  CVE-2026-88052 - High (7.8)

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, UNICHARSET::load_via_fgets in src/ccutil/unicharset.cpp trusts the declared unichar count as a loop bound and uses id as an unchecked index into the unichars vector. unichar_ins...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cert_fr@social.numerique.gouv.fr at 2026-09-10T16:04:24.000Z ##

โš ๏ธAlerte CERT-FRโš ๏ธ

Le CERT-FR a connaissance de nombreuses compromissions de Metabase vulnรฉrables ร  l'injection SQL CVE-2026-72898.

cert.ssi.gouv.fr/alerte/CERTFR

##

cert_fr@social.numerique.gouv.fr at 2026-09-10T16:04:24.000Z ##

โš ๏ธAlerte CERT-FRโš ๏ธ

Le CERT-FR a connaissance de nombreuses compromissions de Metabase vulnรฉrables ร  l'injection SQL CVE-2026-72898.

cert.ssi.gouv.fr/alerte/CERTFR

##

CVE-2026-73453
(0 None)

EPSS: 0.00%

1 posts

N/A

sayzard@mastodon.sayzard.org at 2026-09-10T11:42:38.000Z ##

Arista Networks Arbitrary RCE Vulnerability

Arista EOS์—์„œ P4Runtime๊ฐ€ ํ™œ์„ฑํ™”๋œ ํŠน์ • ๊ตฌ์„ฑ์— ๋Œ€ํ•ด ์ธ์ฆ ์—†์ด ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰์ด ๊ฐ€๋Šฅํ•œ CVE-2026-73453์ด ๊ณต๊ฐœ๋๋‹ค. ๊ณต๊ฒฉ์ž๋Š” P4Runtime ์„ธ์…˜ ์ดˆ๊ธฐํ™” ๊ณผ์ •์˜ ์•…์„ฑ ํŒจํ‚ท์œผ๋กœ ์Šค์œ„์น˜์˜ ์™„์ „ํ•œ ๊ด€๋ฆฌ์ž ๊ถŒํ•œ์„ ํš๋“ํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, CVSS v3.1 ์ ์ˆ˜๋Š” 10.0์ด๋‹ค. ๋‹ค๋งŒ P4Runtime๋Š” ๊ธฐ๋ณธ์ ์œผ๋กœ ๋น„ํ™œ์„ฑํ™”๋˜์–ด ์žˆ์œผ๋ฏ€๋กœ, ์šด์˜์ž๋Š” `show p4-runtime`์œผ๋กœ ๋…ธ์ถœ ์—ฌ๋ถ€๋ฅผ ์šฐ์„  ์ ๊ฒ€ํ•ด์•ผ ํ•œ๋‹ค. ์˜ํ–ฅ๋ฐ›๋Š” ํ™˜๊ฒฝ์€ mTLS์™€ gNSI Authz๋ฅผ ์ ์šฉํ•˜๊ณ , EOS 4.36.2Fยท4.35.6Mยท4...

arista.com/en/support/advisori

##

CVE-2026-84388
(0 None)

EPSS: 0.00%

2 posts

N/A

beyondmachines1 at 2026-09-10T09:01:13.421Z ##

Fortinet Patches Critical Authentication Bypass and Proxy Flaws Across Product Line

Fortinet patched 10 vulnerabilities, including two critical flaws (CVE-2026-84390 and CVE-2026-84388) that allow unauthenticated attackers to bypass authentication in FortiMonitorOnSight and proxy browser traffic via a Chrome extension.

**If you use Fortinet products, patch ASAP. Prioritise FortiMonitorOnSight and the Privileged Access Agent Chrome extension, then review everything else and update to the latest stable versions such as FortiOS and FortiProxy 7.6.7. After patching, check your logs for reused or forged JWTs and any unusual traffic from admin machines.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-09-10T09:01:13.000Z ##

Fortinet Patches Critical Authentication Bypass and Proxy Flaws Across Product Line

Fortinet patched 10 vulnerabilities, including two critical flaws (CVE-2026-84390 and CVE-2026-84388) that allow unauthenticated attackers to bypass authentication in FortiMonitorOnSight and proxy browser traffic via a Chrome extension.

**If you use Fortinet products, patch ASAP. Prioritise FortiMonitorOnSight and the Privileged Access Agent Chrome extension, then review everything else and update to the latest stable versions such as FortiOS and FortiProxy 7.6.7. After patching, check your logs for reused or forged JWTs and any unusual traffic from admin machines.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-84390
(0 None)

EPSS: 0.00%

3 posts

N/A

beyondmachines1 at 2026-09-10T09:01:13.421Z ##

Fortinet Patches Critical Authentication Bypass and Proxy Flaws Across Product Line

Fortinet patched 10 vulnerabilities, including two critical flaws (CVE-2026-84390 and CVE-2026-84388) that allow unauthenticated attackers to bypass authentication in FortiMonitorOnSight and proxy browser traffic via a Chrome extension.

**If you use Fortinet products, patch ASAP. Prioritise FortiMonitorOnSight and the Privileged Access Agent Chrome extension, then review everything else and update to the latest stable versions such as FortiOS and FortiProxy 7.6.7. After patching, check your logs for reused or forged JWTs and any unusual traffic from admin machines.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-09-10T09:01:13.000Z ##

Fortinet Patches Critical Authentication Bypass and Proxy Flaws Across Product Line

Fortinet patched 10 vulnerabilities, including two critical flaws (CVE-2026-84390 and CVE-2026-84388) that allow unauthenticated attackers to bypass authentication in FortiMonitorOnSight and proxy browser traffic via a Chrome extension.

**If you use Fortinet products, patch ASAP. Prioritise FortiMonitorOnSight and the Privileged Access Agent Chrome extension, then review everything else and update to the latest stable versions such as FortiOS and FortiProxy 7.6.7. After patching, check your logs for reused or forged JWTs and any unusual traffic from admin machines.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

DailyCyberSecurity@infosec.exchange at 2026-09-08T17:27:14.000Z ##

Fortinet fixed three critical Fortinet vulnerabilities. Attackers can exploit CVE-2026-84390 and CVE-2026-26084 to access corporate data.

#Fortinet #Vulnerabilities #Cybersecurity #InfoSec #PatchManagement

securityonline.info/fortinet-v

##

CVE-2026-87911
(0 None)

EPSS: 0.99%

3 posts

N/A

offseq at 2026-09-10T06:00:25.092Z ##

CVE-2026-87911 (CVSS 9.6): CRITICAL OS command injection in AWS Labs postgres MCP Server (<1.1.7). Unauthenticated attackers can execute OS commands via crafted SQL. Upgrade to 1.1.7+ ASAP. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-10T06:00:25.000Z ##

CVE-2026-87911 (CVSS 9.6): CRITICAL OS command injection in AWS Labs postgres MCP Server (<1.1.7). Unauthenticated attackers can execute OS commands via crafted SQL. Upgrade to 1.1.7+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #AWS #PostgreSQL #Vuln

##

thehackerwire@mastodon.social at 2026-09-09T21:00:50.000Z ##

๐Ÿ”ด CVE-2026-87911 - Critical (9.6)

An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-manage...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85786
(0 None)

EPSS: 0.33%

1 posts

N/A

hugovalters@mastodon.social at 2026-09-10T02:40:38.000Z ##

CVE-2026-85786: DoS via crafted compressed Ion data in Amazon ion-java <1.12.1. Expansion bomb bypasses GZIP opt-out (CVE-2026-75936). CVSS 7.5. Update to 1.12.1 now. valtersit.com/cve/CVE-2026-857 #CVE #infosec #AWS

##

CVE-2026-75936
(0 None)

EPSS: 0.44%

1 posts

N/A

hugovalters@mastodon.social at 2026-09-10T02:40:38.000Z ##

CVE-2026-85786: DoS via crafted compressed Ion data in Amazon ion-java <1.12.1. Expansion bomb bypasses GZIP opt-out (CVE-2026-75936). CVSS 7.5. Update to 1.12.1 now. valtersit.com/cve/CVE-2026-857 #CVE #infosec #AWS

##

CVE-2026-77234
(0 None)

EPSS: 0.12%

2 posts

N/A

awssecurityfeed at 2026-09-09T21:45:01.951Z ##

Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237

Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT
Description:
FreeRTOS-Kernel is a real-time operating system kernel for microcontrollers and small micro...

aws.amazon.com/security/securi

##

awssecurityfeed@infosec.exchange at 2026-09-09T21:45:01.000Z ##

Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237

Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT
Description:
FreeRTOS-Kernel is a real-time operating system kernel for microcontrollers and small micro...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-77236
(0 None)

EPSS: 0.11%

2 posts

N/A

awssecurityfeed at 2026-09-09T21:45:01.951Z ##

Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237

Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT
Description:
FreeRTOS-Kernel is a real-time operating system kernel for microcontrollers and small micro...

aws.amazon.com/security/securi

##

awssecurityfeed@infosec.exchange at 2026-09-09T21:45:01.000Z ##

Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237

Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT
Description:
FreeRTOS-Kernel is a real-time operating system kernel for microcontrollers and small micro...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-77235
(0 None)

EPSS: 0.11%

2 posts

N/A

awssecurityfeed at 2026-09-09T21:45:01.951Z ##

Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237

Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT
Description:
FreeRTOS-Kernel is a real-time operating system kernel for microcontrollers and small micro...

aws.amazon.com/security/securi

##

awssecurityfeed@infosec.exchange at 2026-09-09T21:45:01.000Z ##

Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237

Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT
Description:
FreeRTOS-Kernel is a real-time operating system kernel for microcontrollers and small micro...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-54694
(0 None)

EPSS: 0.28%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-09T20:00:26.000Z ##

๐Ÿ”ด CVE-2026-54694 - Critical (9.6)

SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combine into a single exploitable attack chain, with three distinct exploitation paths of escalating impact. `StringHighlighter.js` builds an H...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85982
(0 None)

EPSS: 0.22%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-09T03:00:08.000Z ##

๐Ÿ”ด CVE-2026-85982 - Critical (9)

The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user with privileges to modify dir...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85083
(0 None)

EPSS: 0.00%

1 posts

N/A

cyberworldops@infosec.exchange at 2026-09-09T01:30:00.000Z ##

CISA advisory ICSA-26-251-01 documents CVE-2026-85083 in CareCam Pro ANJIA AJL33PC0801: hard-coded bootloader credential allows privileged access with physical presence. It enables firmware modification and persistent compromise, undermining trust in affected deployments. #HardcodedCredentials #IotSecurity #FirmwareSecurity

cyberworldops.eu/en/hard-coded

##

CVE-2026-53938
(0 None)

EPSS: 0.24%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-09T01:00:08.000Z ##

๐ŸŸ  CVE-2026-53938 - High (8.2)

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior to version 0.6.2.5, cjose's JWE decryption path for the AES Key Wrap key-management algorithms (`alg` = `A128KW`, `A192KW`, `A256KW`) does not val...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53581
(0 None)

EPSS: 0.33%

2 posts

N/A

offseq@infosec.exchange at 2026-09-09T00:00:35.000Z ##

CVE-2026-53581 (CRITICAL, CVSS 9.0): OPNsense core <26.1.9 NTP module path traversal lets privileged users overwrite files as root. Upgrade to 26.1.9+ & backend 26.4_20+ now. radar.offseq.com/threat/cve-20 #OffSeq #OPNsense #Vuln #PathTraversal

##

thehackerwire@mastodon.social at 2026-09-09T00:00:16.000Z ##

๐Ÿ”ด CVE-2026-53581 - Critical (9)

OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attacker to overwrite arbitrary f...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites