## Updated at UTC 2026-09-25T00:51:40.542367

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-86858 None 0.00% 2 0 2026-09-24T21:32:59 ServiceNow has remediated an improper access control security issue that was ide
CVE-2026-93289 7.5 0.00% 2 0 2026-09-24T21:32:59 The affected products are vulnerable to command injection attack that could allo
CVE-2026-86857 None 0.00% 2 0 2026-09-24T21:32:58 ServiceNow has remediated an authorization bypass security issue that was identi
CVE-2026-93354 8.1 0.00% 2 0 2026-09-24T21:32:58 Taskview Community before 1.56.0 contains a missing authentication vulnerability
CVE-2026-93291 9.4 0.00% 2 0 2026-09-24T21:32:58 Omni C20 lacks proper certificate validation which could allow an attacker to pe
CVE-2026-86859 None 0.00% 2 0 2026-09-24T21:32:57 ServiceNow has remediated an authorization bypass security issue that was identi
CVE-2026-71362 9.1 2.33% 3 1 2026-09-24T21:32:31 Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul
CVE-2026-5430 10.0 0.37% 3 1 2026-09-24T21:32:26 The JWT authentication mechanism accepts tokens signed with algorithms other tha
CVE-2026-81630 8.1 0.00% 4 0 2026-09-24T21:25:27.050000 The Botslab G980H dash camera firmware does not adequately verify the authentici
CVE-2026-85496 8.8 0.00% 2 0 2026-09-24T21:25:27.050000 The Botslab G980H dash camera firmware generates session identifiers using a sma
CVE-2026-84399 8.8 0.00% 2 0 2026-09-24T21:25:27.050000 The Botslab G980H dash camera firmware contains an authorization vulnerability i
CVE-2026-82566 8.8 0.00% 2 0 2026-09-24T21:25:27.050000 The Botslab G980H dash camera firmware contains a session management vulnerabili
CVE-2026-95699 9.6 0.00% 2 0 2026-09-24T21:25:27.050000 Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant auth
CVE-2026-88419 8.8 0.48% 1 0 2026-09-24T21:25:27.050000 An unrestricted upload of files with a dangerous type in the thumbnail-upload en
CVE-2026-93345 7.5 0.49% 1 0 2026-09-24T21:18:58.180000 MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnera
CVE-2026-61674 0 0.85% 1 0 2026-09-24T21:16:28.120000 Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Lin
CVE-2026-97359 10.0 0.00% 2 0 2026-09-24T21:08:55.030000 HFS2 version 2.4.0 and earlier contains a template injection vulnerability in th
CVE-2026-97055 8.1 0.41% 1 0 2026-09-24T21:08:55.030000 SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (to
CVE-2026-86860 0 0.00% 2 0 2026-09-24T21:00:46.893000 ServiceNow has remediated a missing authorization vulnerability that was identif
CVE-2026-13016 0 0.00% 2 0 2026-09-24T21:00:46.893000 ServiceNow has remediated a SQL injection vulnerability that was identified in t
CVE-2026-95519 7.8 0.00% 1 0 2026-09-24T21:00:46.893000 A flaw was found in rpm. An attacker can supply a crafted manifest file that, wh
CVE-2026-97059 8.2 0.00% 1 0 2026-09-24T21:00:46.893000 DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoad
CVE-2026-81549 9.6 0.00% 1 0 2026-09-24T19:41:16.513000 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a
CVE-2026-81545 8.8 0.00% 1 0 2026-09-24T19:41:16.513000 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a
CVE-2026-81552 8.8 0.00% 1 0 2026-09-24T19:41:16.513000 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a
CVE-2026-78308 9.8 0.35% 2 0 2026-09-24T19:39:45.600000 Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass
CVE-2026-57590 8.1 0.18% 1 0 2026-09-24T19:36:39.327000 A missing authorization vulnerability exists in the Task Group APIs of Apache Do
CVE-2026-56737 8.1 0.00% 1 0 2026-09-24T19:29:30 ### Summary The public two-factor verification endpoint `POST /check` logs a use
CVE-2026-93425 9.9 0.00% 1 0 2026-09-24T18:19:07.280000 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13,
CVE-2026-6928 9.8 0.45% 1 0 2026-09-24T16:17:10.010000 IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been
CVE-2026-81548 8.8 0.00% 1 0 2026-09-24T15:31:42 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a
CVE-2026-81547 8.8 0.00% 1 0 2026-09-24T15:31:42 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a
CVE-2026-82093 8.8 0.00% 1 0 2026-09-24T15:31:42 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a
CVE-2026-90959 8.1 0.00% 1 0 2026-09-24T15:31:42 A path traversal vulnerability was found in pulpcore. The content upload API acc
CVE-2026-97362 7.5 0.00% 1 0 2026-09-24T15:31:42 HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that a
CVE-2026-58008 8.1 0.00% 1 0 2026-09-24T15:31:41 Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allo
CVE-2026-58007 8.1 0.00% 1 0 2026-09-24T15:31:41 Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS al
CVE-2026-77874 8.6 0.00% 1 0 2026-09-24T15:31:41 IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.
CVE-2026-81539 8.8 0.00% 1 0 2026-09-24T15:31:41 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a
CVE-2026-97057 7.5 0.00% 1 0 2026-09-24T15:31:40 redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP
CVE-2026-97360 10.0 0.00% 1 0 2026-09-24T15:31:40 HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access
CVE-2026-95521 7.8 0.00% 1 0 2026-09-24T15:31:35 A command injection flaw was found in rpm. Installing or rebuilding a source RPM
CVE-2026-19072 9.9 0.00% 2 0 2026-09-24T15:31:29 Velociraptor stores the compiled VQL in the hunt object internally to avoid havi
CVE-2026-85682 8.8 0.14% 1 0 2026-09-24T15:17:46.703000 The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in al
CVE-2026-89078 9.9 0.36% 1 0 2026-09-24T15:03:53.487000 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2
CVE-2026-93577 9.9 0.43% 1 0 2026-09-24T15:03:53.487000 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2
CVE-2026-81537 8.8 0.98% 1 0 2026-09-24T14:51:56.593000 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a
CVE-2026-81208 7.7 0.23% 1 0 2026-09-24T14:51:56.593000 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to
CVE-2026-12227 9.8 0.77% 2 2 2026-09-24T12:31:29 The Visual Composer Website Builder plugin for WordPress is vulnerable to Local
CVE-2026-80513 7.5 0.20% 1 0 2026-09-24T12:31:23 The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes m
CVE-2026-77193 7.5 0.36% 1 0 2026-09-24T09:32:00 The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Pa
CVE-2026-97185 7.8 0.13% 1 0 2026-09-24T09:32:00 A flaw was found in GIMP. When processing a specially crafted GIMPressionist pre
CVE-2026-78312 9.1 0.34% 1 0 2026-09-24T09:32:00 Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022
CVE-2026-78311 8.8 0.24% 1 0 2026-09-24T09:32:00 SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: befor
CVE-2026-78309 8.8 0.24% 1 0 2026-09-24T09:32:00 SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: befor
CVE-2026-18467 9.8 0.39% 2 0 2026-09-24T03:30:34 The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable
CVE-2026-96891 9.8 0.65% 1 0 2026-09-24T03:30:34 A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the functi
CVE-2026-70125 8.8 0.44% 1 0 2026-09-24T00:30:34 Microsoft Outlook Remote Code Execution Vulnerability
CVE-2026-19125 8.1 0.64% 1 1 2026-09-24T00:30:29 The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication B
CVE-2026-93352 9.8 0.62% 2 0 2026-09-24T00:30:29 Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49
CVE-2026-81536 7.7 0.28% 1 0 2026-09-24T00:30:29 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a
CVE-2026-80423 8.8 0.33% 1 0 2026-09-24T00:30:29 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a
CVE-2026-86583 8.8 0.33% 1 0 2026-09-24T00:30:29 The Import and export users and customers plugin for WordPress is vulnerable to
CVE-2026-75887 7.5 0.36% 1 0 2026-09-24T00:30:26 A flaw was found in the OpenShift console. An unauthenticated attacker can explo
CVE-2026-6730 9.8 0.44% 1 0 2026-09-23T21:31:08 IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by im
CVE-2026-87899 None 0.53% 1 0 2026-09-23T21:31:03 Execution with unnecessary privileges in cPanel allows remote authenticated user
CVE-2026-18162 9.8 0.48% 1 0 2026-09-23T19:17:28.687000 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remot
CVE-2026-18169 9.9 0.53% 1 0 2026-09-23T18:17:07.270000 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remot
CVE-2026-91818 7.8 0.12% 1 0 2026-09-23T17:58:26.570000 A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s JavaScript ha
CVE-2026-19599 9.9 2.86% 2 0 2026-09-23T15:30:51 ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable
CVE-2026-91811 7.8 0.12% 1 0 2026-09-23T09:30:37 A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader
CVE-2026-91809 7.8 0.12% 1 0 2026-09-23T09:30:30 A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of m
CVE-2026-74849 9.8 4.61% 1 0 2026-09-23T04:17:44.340000 Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerab
CVE-2026-96257 10.0 0.58% 1 0 2026-09-23T03:30:35 A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this i
CVE-2026-18163 9.8 0.51% 1 0 2026-09-23T00:31:21 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remot
CVE-2026-19202 None 0.25% 1 0 2026-09-23T00:31:15 A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK cau
CVE-2026-81642 9.8 0.80% 1 1 2026-09-22T21:31:54 In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in t
CVE-2026-77987 None 0.89% 1 0 2026-09-22T21:31:40 A server-side request forgery (SSRF) vulnerability was identified in the noteboo
CVE-2026-88020 6.1 0.27% 1 0 2026-09-22T21:31:39 Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input d
CVE-2026-28324 9.8 0.65% 3 0 2026-09-22T21:31:34 SolarWinds Observability Self-Hosted was found to be affected by an unauthentica
CVE-2026-87121 9.8 0.53% 2 0 2026-09-22T21:31:34 lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow
CVE-2026-94127 9.8 1.29% 16 2 2026-09-22T21:31:17 When a BIG-IP APM access policy and an OAuth profile is configured on a virtual
CVE-2026-93616 9.8 2.42% 12 2 2026-09-22T21:31:15 A directory traversal and file upload vulnerability allows an unauthenticated at
CVE-2026-93952 10.0 0.90% 8 0 2026-09-22T21:31:14 VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may a
CVE-2026-85102 9.8 0.99% 11 0 2026-09-22T21:30:40 Improper certificate trust validation during VPN negotiation in Check Point Quan
CVE-2026-77322 7.5 0.52% 1 0 2026-09-22T20:34:31 ### Summary The WebSocket transport allocates a buffer from the frame payload l
CVE-2026-84388 9.6 0.38% 1 1 2026-09-22T19:09:58.680000 A improper restriction of rendered ui layers or frames vulnerability in Fortinet
CVE-2026-89275 10.0 1.25% 1 0 2026-09-22T18:33:43 Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of
CVE-2026-95675 9.8 3.91% 1 1 2026-09-22T15:32:43 D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated re
CVE-2026-65113 9.8 0.61% 1 0 2026-09-22T15:32:43 NVIDIA Infrastructure Controller for Linux contains a vulnerability where an att
CVE-2026-7273 8.8 1.29% 2 0 2026-09-22T12:10:51.067000 A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-4
CVE-2026-12249 9.0 0.14% 1 0 2026-09-21T22:27:11 An issue was discovered in Canonical ADSys upstream versions through v0.16.2. Du
CVE-2026-80521 7.8 0.17% 1 1 2026-09-21T14:17:20.193000 In the Linux kernel, the following vulnerability has been resolved: af_unix: Un
CVE-2026-93958 9.1 2.70% 1 1 2026-09-20T03:30:31 A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affec
CVE-2026-82892 8.1 0.62% 1 0 2026-09-18T21:32:35 IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbit
CVE-2026-93485 7.1 0.28% 1 2 2026-09-18T06:32:17 Improper neutralization of input during web page generation ('cross-site scripti
CVE-2026-76460 10.0 14.03% 1 1 2026-09-16T21:33:00 A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an
CVE-2026-43783 7.8 0.13% 1 1 2026-09-15T00:31:13 A race condition was addressed with improved locking. This issue is fixed in mac
CVE-2026-9176 6.7 0.16% 2 0 2026-09-10T21:31:46 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass
CVE-2026-85103 9.8 3.65% 1 0 2026-09-10T04:18:18.390000 A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unau
CVE-2026-50093 9.0 0.32% 1 0 2026-09-08T09:35:45 A vulnerability has been identified in Siveillance Control Pro V3.0 (All version
CVE-2026-43499 7.8 0.28% 1 100 2026-09-08T09:35:29 In the Linux kernel, the following vulnerability has been resolved: rtmutex: Us
CVE-2026-86296 10.0 1.44% 4 0 2026-09-07T12:30:36 A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affe
CVE-2026-78306 None 0.23% 1 2 2026-08-24T09:33:52 DJI drones expose an unauthenticated DUML command interface over Bluetooth that
CVE-2026-59310 9.8 2.56% 1 2 2026-08-19T04:17:24.940000 VMware vCenter contains a directory traversal vulnerability in the Syslog server
CVE-2026-55040 9.1 17.54% 1 5 template 2026-08-19T04:17:23.540000 Weak authentication in Microsoft Office SharePoint allows an unauthorized attack
CVE-2026-33824 9.8 1.62% 1 2 2026-08-18T18:31:46 Double free in Windows IKE Extension allows an unauthorized attacker to execute
CVE-2026-46345 8.4 0.20% 1 0 2026-08-17T17:54:44 **Relevant Products/Components:** * `trestle/core/commands/author/jinja.py` * `
CVE-2026-68820 7.0 0.33% 1 4 2026-08-16T19:17:24.183000 Use after free in Windows Ancillary Function Driver for WinSock allows an author
CVE-2026-65660 6.5 1.19% 4 0 2026-08-11T18:31:43 Improper control of generation of code ('code injection') in Microsoft Office Sh
CVE-2026-63077 9.8 9.76% 3 6 2026-08-05T18:32:31 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe
CVE-2026-15830 5.3 0.76% 1 0 2026-08-04T18:31:31 An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDja
CVE-2026-59309 9.8 0.61% 1 0 2026-07-30T15:31:54 VMware vCenter contains an authentication bypass vulnerability in the VMware Dir
CVE-2025-68686 5.9 29.60% 1 0 2026-07-27T18:31:25 An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE
CVE-2026-48842 8.1 0.89% 1 0 2026-07-24T10:10:00.197000 Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authenticat
CVE-2026-50522 9.8 3.04% 1 5 2026-07-23T15:44:10.873000 Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CVE-2026-49972 8.8 1.08% 1 0 2026-07-15T19:17:24.827000 Laravel-Mediable before 7.0.0 contains a file upload vulnerability that allows u
CVE-2025-68788 0 0.21% 1 0 2026-07-14T13:18:00.363000 In the Linux kernel, the following vulnerability has been resolved: fsnotify: d
CVE-2026-45659 8.8 2.70% 1 2 2026-07-01T21:35:53 Deserialization of untrusted data in Microsoft Office SharePoint allows an autho
CVE-2026-23239 7.8 0.10% 2 0 2026-06-17T10:21:09.960000 In the Linux kernel, the following vulnerability has been resolved: espintcp: F
CVE-2024-0244 9.8 1.38% 1 0 2026-06-17T06:53:04.567000 Buffer overflow in CPCA PCFAX number process of Office Multifunction Printers an
CVE-2020-4428 9.1 61.69% 1 0 2026-06-17T03:19:58.553000 IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authen
CVE-2026-46439 7.8 0.27% 1 0 2026-05-28T19:01:39 A High severity Server-Side Template Injection (SSTI) vulnerability exists in th
CVE-2026-41091 7.8 0.44% 1 4 2026-05-20T18:31:35 Improper link resolution before file access ('link following') in Microsoft Defe
CVE-2026-21513 8.8 15.64% 1 0 2026-03-27T21:32:39 Protection mechanism failure in MSHTML Framework allows an unauthorized attacker
CVE-2026-21525 6.2 4.80% 1 0 2026-03-27T21:31:32 Null pointer dereference in Windows Remote Access Connection Manager allows an u
CVE-2026-21519 7.8 2.46% 1 0 2026-02-10T21:31:29 Access of resource using incompatible type ('type confusion') in Desktop Window
CVE-2026-20805 5.5 7.20% 1 6 2026-01-13T21:31:44 Exposure of sensitive information to an unauthorized actor in Desktop Windows Ma
CVE-2020-4427 9.8 70.03% 1 0 template 2025-11-04T00:30:30 IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a
CVE-2025-4632 9.8 24.30% 1 2 2025-10-22T00:34:22 Improper limitation of a pathname to a restricted directory vulnerability in Sam
CVE-2023-48788 9.8 98.45% 1 1 template 2025-10-22T00:34:05 A improper neutralization of special elements used in an sql command ('sql injec
CVE-2023-20118 7.2 54.11% 2 0 2025-10-22T00:33:50 A vulnerability in the web-based management interface of Cisco Small Business Ro
CVE-2022-42475 9.8 99.47% 1 9 template 2025-10-22T00:32:38 A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 th
CVE-2021-44168 7.8 0.87% 1 1 2025-10-22T00:32:27 A download of code without integrity check vulnerability in the "execute restore
CVE-2024-20260 8.6 0.59% 1 0 2024-10-23T18:33:16 A vulnerability in the VPN and management web servers of the Cisco Adaptive Secu
CVE-2026-61821 0 0.38% 1 0 N/A
CVE-2026-96883 0 0.00% 2 0 N/A
CVE-2026-91766 0 0.00% 2 0 N/A
CVE-2026-87902 0 2.88% 12 14 N/A
CVE-2026-63203 0 0.00% 1 0 N/A
CVE-2026-77581 0 0.00% 1 0 N/A
CVE-2026-94545 0 0.00% 2 2 N/A
CVE-2026-84739 0 0.00% 1 0 N/A
CVE-2026-96419 0 0.00% 1 0 N/A
CVE-2026-78902 0 0.00% 1 0 N/A
CVE-2026-67231 0 0.25% 1 0 N/A
CVE-2026-88804 0 0.00% 1 0 N/A
CVE-2026-69184 0 0.68% 1 0 N/A
CVE-2024-85880 0 0.00% 1 0 N/A
CVE-2024-85046 0 0.00% 1 0 N/A
CVE-2024-87491 0 0.00% 1 0 N/A
CVE-2026-89090 0 0.52% 1 0 N/A
CVE-2026-85279 0 0.21% 1 0 N/A

CVE-2026-86858(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-09-24T21:32:59

2 posts

ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. This security issue could enable an unauthenticated user, in certain circumstances, to create, modify, or delete instance data beyond what was intended. In August 2026, ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partner

cR0w at 2026-09-24T21:41:51.803Z ##

Hack and patch more ServiceNow shit.

support.servicenow.com/kb?id=k

On September 24, 2026, ServiceNow issued CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, and CVE-2026-86860.
Each of these security issues was identified through internal security testing, customer security assessments, or reports submitted through ServiceNow's responsible disclosure and bug bounty programs and was remediated independently. For security issues identified through responsible disclosure, researchers may choose to publish their findings.
ServiceNow did not identify evidence of malicious exploitation related to these issues.

##

cR0w@infosec.exchange at 2026-09-24T21:41:51.000Z ##

Hack and patch more ServiceNow shit.

support.servicenow.com/kb?id=k

On September 24, 2026, ServiceNow issued CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, and CVE-2026-86860.
Each of these security issues was identified through internal security testing, customer security assessments, or reports submitted through ServiceNow's responsible disclosure and bug bounty programs and was remediated independently. For security issues identified through responsible disclosure, researchers may choose to publish their findings.
ServiceNow did not identify evidence of malicious exploitation related to these issues.

##

CVE-2026-93289
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-24T21:32:59

2 posts

The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process.

thehackerwire@mastodon.social at 2026-09-24T20:31:01.000Z ##

🟠 CVE-2026-93289 - High (7.5)

The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-24T20:31:01.000Z ##

🟠 CVE-2026-93289 - High (7.5)

The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86857(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-09-24T21:32:58

2 posts

ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an authenticated user to access data within the ServiceNow AI Platform that the user otherwise would not be entitled to access, potentially enabling further unintended access. ServiceNow deployed an update to hosted instances, and

cR0w at 2026-09-24T21:41:51.803Z ##

Hack and patch more ServiceNow shit.

support.servicenow.com/kb?id=k

On September 24, 2026, ServiceNow issued CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, and CVE-2026-86860.
Each of these security issues was identified through internal security testing, customer security assessments, or reports submitted through ServiceNow's responsible disclosure and bug bounty programs and was remediated independently. For security issues identified through responsible disclosure, researchers may choose to publish their findings.
ServiceNow did not identify evidence of malicious exploitation related to these issues.

##

cR0w@infosec.exchange at 2026-09-24T21:41:51.000Z ##

Hack and patch more ServiceNow shit.

support.servicenow.com/kb?id=k

On September 24, 2026, ServiceNow issued CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, and CVE-2026-86860.
Each of these security issues was identified through internal security testing, customer security assessments, or reports submitted through ServiceNow's responsible disclosure and bug bounty programs and was remediated independently. For security issues identified through responsible disclosure, researchers may choose to publish their findings.
ServiceNow did not identify evidence of malicious exploitation related to these issues.

##

CVE-2026-93354
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-24T21:32:58

2 posts

Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over user accounts by exploiting the OAuth 2.0 Dynamic Client Registration endpoint, which is enabled by default and requires no authentication. Attackers can send a POST request to the registration endpoint to obtain a client_id and cl

thehackerwire@mastodon.social at 2026-09-24T21:01:24.000Z ##

🟠 CVE-2026-93354 - High (8.1)

Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over user accounts by exploiting the OAuth 2.0 Dynamic Client Registration endpoint...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-24T21:01:24.000Z ##

🟠 CVE-2026-93354 - High (8.1)

Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over user accounts by exploiting the OAuth 2.0 Dynamic Client Registration endpoint...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93291
(9.4 CRITICAL)

EPSS: 0.00%

updated 2026-09-24T21:32:58

2 posts

Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.

thehackerwire@mastodon.social at 2026-09-24T20:31:10.000Z ##

🔴 CVE-2026-93291 - Critical (9.4)

Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-24T20:31:10.000Z ##

🔴 CVE-2026-93291 - Critical (9.4)

Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86859(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-09-24T21:32:57

2 posts

ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an unauthenticated user to access data within the ServiceNow AI Platform that the user otherwise would not be entitled to access, potentially enabling further unintended access. ServiceNow deployed a security update to hosted insta

cR0w at 2026-09-24T21:41:51.803Z ##

Hack and patch more ServiceNow shit.

support.servicenow.com/kb?id=k

On September 24, 2026, ServiceNow issued CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, and CVE-2026-86860.
Each of these security issues was identified through internal security testing, customer security assessments, or reports submitted through ServiceNow's responsible disclosure and bug bounty programs and was remediated independently. For security issues identified through responsible disclosure, researchers may choose to publish their findings.
ServiceNow did not identify evidence of malicious exploitation related to these issues.

##

cR0w@infosec.exchange at 2026-09-24T21:41:51.000Z ##

Hack and patch more ServiceNow shit.

support.servicenow.com/kb?id=k

On September 24, 2026, ServiceNow issued CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, and CVE-2026-86860.
Each of these security issues was identified through internal security testing, customer security assessments, or reports submitted through ServiceNow's responsible disclosure and bug bounty programs and was remediated independently. For security issues identified through responsible disclosure, researchers may choose to publish their findings.
ServiceNow did not identify evidence of malicious exploitation related to these issues.

##

CVE-2026-71362
(9.1 CRITICAL)

EPSS: 2.33%

updated 2026-09-24T21:32:31

3 posts

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

1 repos

https://github.com/dinosn/cve-2026-71362-magento-lab

secdb at 2026-09-24T21:00:17.853Z ##

🚨 [CISA-2026:0924] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-5430 (secdb.nttzen.cloud/cve/detail/)
- Name: WSO2 Multiple Products Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: WSO2
- Product: Multiple Products
- Notes: security.docs.wso2.com/en/late ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-71362 (secdb.nttzen.cloud/cve/detail/)
- Name: Adobe Commerce and Magento Incorrect Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Adobe
- Product: Commerce and Magento
- Notes: helpx.adobe.com/security/produ ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-09-24T21:00:17.000Z ##

🚨 [CISA-2026:0924] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-5430 (secdb.nttzen.cloud/cve/detail/)
- Name: WSO2 Multiple Products Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: WSO2
- Product: Multiple Products
- Notes: security.docs.wso2.com/en/late ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-71362 (secdb.nttzen.cloud/cve/detail/)
- Name: Adobe Commerce and Magento Incorrect Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Adobe
- Product: Commerce and Magento
- Notes: helpx.adobe.com/security/produ ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260924 #cisa20260924 #cve_2026_5430 #cve_2026_71362 #cve20265430 #cve202671362

##

cisakevtracker@mastodon.social at 2026-09-24T20:00:59.000Z ##

CVE ID: CVE-2026-71362
Vendor: Adobe
Product: Commerce and Magento
Date Added: 2026-09-24
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-5430
(10.0 CRITICAL)

EPSS: 0.37%

updated 2026-09-24T21:32:26

3 posts

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of adm

1 repos

https://github.com/HORKimhab/CVE-2026-5430

secdb at 2026-09-24T21:00:17.853Z ##

🚨 [CISA-2026:0924] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-5430 (secdb.nttzen.cloud/cve/detail/)
- Name: WSO2 Multiple Products Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: WSO2
- Product: Multiple Products
- Notes: security.docs.wso2.com/en/late ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-71362 (secdb.nttzen.cloud/cve/detail/)
- Name: Adobe Commerce and Magento Incorrect Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Adobe
- Product: Commerce and Magento
- Notes: helpx.adobe.com/security/produ ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-09-24T21:00:17.000Z ##

🚨 [CISA-2026:0924] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-5430 (secdb.nttzen.cloud/cve/detail/)
- Name: WSO2 Multiple Products Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: WSO2
- Product: Multiple Products
- Notes: security.docs.wso2.com/en/late ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-71362 (secdb.nttzen.cloud/cve/detail/)
- Name: Adobe Commerce and Magento Incorrect Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Adobe
- Product: Commerce and Magento
- Notes: helpx.adobe.com/security/produ ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260924 #cisa20260924 #cve_2026_5430 #cve_2026_71362 #cve20265430 #cve202671362

##

cisakevtracker@mastodon.social at 2026-09-24T20:00:44.000Z ##

CVE ID: CVE-2026-5430
Vendor: WSO2
Product: Multiple Products
Date Added: 2026-09-24
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-81630
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-24T21:25:27.050000

4 posts

The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integrity value supplied with the firmware instead of a trusted cryptographic signature. A suitably positioned attacker who intercepts a firmware download, or an authenticated attacker who submits a crafted

offseq at 2026-09-25T00:00:38.200Z ##

Botslab G980H dash cams are affected by CVE-2026-81630 (CRITICAL, CVSS 9.2): Firmware authenticity is not cryptographically verified, enabling remote code execution if updates are intercepted. Avoid untrusted networks until a patch is released. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-24T23:45:30.000Z ##

🟠 CVE-2026-81630 - High (8.1)

The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integrity value supplied with the firmware instead of ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-25T00:00:38.000Z ##

Botslab G980H dash cams are affected by CVE-2026-81630 (CRITICAL, CVSS 9.2): Firmware authenticity is not cryptographically verified, enabling remote code execution if updates are intercepted. Avoid untrusted networks until a patch is released. radar.offseq.com/threat/cve-20 #OffSeq #CVE202681630 #IoTSecurity

##

thehackerwire@mastodon.social at 2026-09-24T23:45:30.000Z ##

🟠 CVE-2026-81630 - High (8.1)

The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integrity value supplied with the firmware instead of ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85496
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-24T21:25:27.050000

2 posts

The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated attacker with adjacent network access and knowledge that an active session exists could potentially determine a valid session identifier and use it to bypass intended authorization controls.

thehackerwire@mastodon.social at 2026-09-24T23:46:38.000Z ##

🟠 CVE-2026-85496 - High (8.8)

The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated attacker with adjacent network access and knowledge that an active session ex...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-24T23:46:38.000Z ##

🟠 CVE-2026-85496 - High (8.8)

The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated attacker with adjacent network access and knowledge that an active session ex...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84399
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-24T21:25:27.050000

2 posts

The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an authenticated session with the client connection that established it, and subsequent privileged operations rely on possession of a valid session identifier without adequately validating the requesting client's authenticated contex

thehackerwire@mastodon.social at 2026-09-24T23:46:30.000Z ##

🟠 CVE-2026-84399 - High (8.8)

The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an authenticated session with the client connection that established it, and sub...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-24T23:46:30.000Z ##

🟠 CVE-2026-84399 - High (8.8)

The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an authenticated session with the client connection that established it, and sub...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82566
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-24T21:25:27.050000

2 posts

The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced. Under certain connection conditions, a newly established connection can displace an existing client while previously established session state remains active until a separate expiration mechanism in

thehackerwire@mastodon.social at 2026-09-24T23:46:21.000Z ##

🟠 CVE-2026-82566 - High (8.8)

The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced. Under certain connection conditions, a newly ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-24T23:46:21.000Z ##

🟠 CVE-2026-82566 - High (8.8)

The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced. Under certain connection conditions, a newly ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-95699
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-09-24T21:25:27.050000

2 posts

Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' devices. This risked exposing user profile information and potential scalding due to unintended device activation.

thehackerwire@mastodon.social at 2026-09-24T23:45:22.000Z ##

🔴 CVE-2026-95699 - Critical (9.6)

Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' devices. This...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-24T23:45:22.000Z ##

🔴 CVE-2026-95699 - Critical (9.6)

Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' devices. This...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88419
(8.8 HIGH)

EPSS: 0.48%

updated 2026-09-24T21:25:27.050000

1 posts

An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index.php?m=member&f=article&v=thumbUpload) of WuzhiCMS 5.0.0 allows an authenticated low-privileged member to upload a crafted .php file and execute arbitrary PHP code on the server, because the stored file extension is taken verbatim from the client-supplied filename with no extension allowlist or content va

thehackerwire@mastodon.social at 2026-09-22T21:01:48.000Z ##

🟠 CVE-2026-88419 - High (8.8)

An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index.php?m=member&f=article&v=thumbUpload) of WuzhiCMS 5.0.0 allows an authenticated low-privileged member to upload a crafted .php file and execute arbitrar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93345
(7.5 HIGH)

EPSS: 0.49%

updated 2026-09-24T21:18:58.180000

1 posts

MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI iterators of the routing service that allows an unauthenticated on-path attacker to crash the BGP service by sending a malformed MP_REACH_NLRI UPDATE message with a prefix-length value below the minimum valid for a labelled-VPN NLRI, which passes validation while describing a route with

thehackerwire@mastodon.social at 2026-09-22T19:04:08.000Z ##

🟠 CVE-2026-93345 - High (7.5)

MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI iterators of the routing service that allows an unauthenticated on-path attacker to crash the BGP service by sending a malformed MP_REA...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61674
(0 None)

EPSS: 0.85%

updated 2026-09-24T21:16:28.120000

1 posts

Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows. From 0.11.0 until 5.0.8, plugins/out_forward/forward.c secure_forward_pong copies the server-controlled PONG[2] reason into the 32-byte stack buffer msg with memcpy without checking its MessagePack type or length. An attacker who controls or can impersonate an out_forward Secure Forward des

DailyCyberSecurity@infosec.exchange at 2026-09-24T01:09:00.000Z ##

Technical details and a PoC for a critical Fluent Bit vulnerability (CVE-2026-61674) are public. Patch this Fluent Bit vulnerability to prevent RCE attacks.

#FluentBit #CVE202661674 #BufferOverflow #RCE #Cybersecurity #InfoSec

securityonline.info/fluent-bit

##

CVE-2026-97359
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-24T21:08:55.030000

2 posts

HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename. Attackers can craft a filename containing a closing template quoting sequence followed by an exec macro, which bypasses the authorization check in the dispatcher to exe

hugovalters@mastodon.social at 2026-09-24T23:07:17.000Z ##

CVE-2026-97359 - Critical unauthenticated RCE in HFS2 (<= 2.4.0) via template injection in multipart uploads. CVSS 10.0. Mitigate immediately. #CVE #infosec #cybersecurity

valtersit.com/cve/CVE-2026-973

##

thehackerwire@mastodon.social at 2026-09-24T14:20:28.000Z ##

🔴 CVE-2026-97359 - Critical (10)

HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename. Attackers can c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97055
(8.1 HIGH)

EPSS: 0.41%

updated 2026-09-24T21:08:55.030000

1 posts

SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOKENIZER_JWT_SECRET or the deprecated SIGNOZ_JWT_SECRET) to an empty string, and Config.Validate() does not reject the empty value, so a deployment that does not configure a secret starts up and both signs and verifies session tokens with an empty HMAC key. Because the JWT tokenize

thehackerwire@mastodon.social at 2026-09-24T07:47:51.000Z ##

🟠 CVE-2026-97055 - High (8.1)

SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOKENIZER_JWT_SECRET or the deprecated SIGNOZ_JWT_SECRET) to an empty string, and Config.Validate() does not reject the empty valu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86860
(0 None)

EPSS: 0.00%

updated 2026-09-24T21:00:46.893000

2 posts

ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to extract instance data beyond what was intended, resulting in privilege escalation. ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners an

cR0w at 2026-09-24T21:41:51.803Z ##

Hack and patch more ServiceNow shit.

support.servicenow.com/kb?id=k

On September 24, 2026, ServiceNow issued CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, and CVE-2026-86860.
Each of these security issues was identified through internal security testing, customer security assessments, or reports submitted through ServiceNow's responsible disclosure and bug bounty programs and was remediated independently. For security issues identified through responsible disclosure, researchers may choose to publish their findings.
ServiceNow did not identify evidence of malicious exploitation related to these issues.

##

cR0w@infosec.exchange at 2026-09-24T21:41:51.000Z ##

Hack and patch more ServiceNow shit.

support.servicenow.com/kb?id=k

On September 24, 2026, ServiceNow issued CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, and CVE-2026-86860.
Each of these security issues was identified through internal security testing, customer security assessments, or reports submitted through ServiceNow's responsible disclosure and bug bounty programs and was remediated independently. For security issues identified through responsible disclosure, researchers may choose to publish their findings.
ServiceNow did not identify evidence of malicious exploitation related to these issues.

##

CVE-2026-13016
(0 None)

EPSS: 0.00%

updated 2026-09-24T21:00:46.893000

2 posts

ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and gain access to, or modify, instance data beyond what was intended.  ServiceNow deployed a security update to hosted instan

cR0w at 2026-09-24T21:41:51.803Z ##

Hack and patch more ServiceNow shit.

support.servicenow.com/kb?id=k

On September 24, 2026, ServiceNow issued CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, and CVE-2026-86860.
Each of these security issues was identified through internal security testing, customer security assessments, or reports submitted through ServiceNow's responsible disclosure and bug bounty programs and was remediated independently. For security issues identified through responsible disclosure, researchers may choose to publish their findings.
ServiceNow did not identify evidence of malicious exploitation related to these issues.

##

cR0w@infosec.exchange at 2026-09-24T21:41:51.000Z ##

Hack and patch more ServiceNow shit.

support.servicenow.com/kb?id=k

On September 24, 2026, ServiceNow issued CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, and CVE-2026-86860.
Each of these security issues was identified through internal security testing, customer security assessments, or reports submitted through ServiceNow's responsible disclosure and bug bounty programs and was remediated independently. For security issues identified through responsible disclosure, researchers may choose to publish their findings.
ServiceNow did not identify evidence of malicious exploitation related to these issues.

##

CVE-2026-95519
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-24T21:00:46.893000

1 posts

A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because manifest entries are unexpectedly macro-expanded before being opened, allowing embedded shell commands to run with the privileges of the `rpm` process. Successful exploitat

thehackerwire@mastodon.social at 2026-09-24T14:33:27.000Z ##

🟠 CVE-2026-95519 - High (7.8)

A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because manifest entries ar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97059
(8.2 HIGH)

EPSS: 0.00%

updated 2026-09-24T21:00:46.893000

1 posts

DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without validating the PixelData buffer length against the declared NumberOfFrames. Attackers can craft malicious DICOM instances declaring more frames than the buffer contains to trigger heap over-reads that crash the application or leak adjacent heap memory.

thehackerwire@mastodon.social at 2026-09-24T14:33:18.000Z ##

🟠 CVE-2026-97059 - High (8.2)

DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without validating the PixelData buffer length against the declared NumberOfFrames. Attackers can craft malicious DICOM instances decl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81549
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-09-24T19:41:16.513000

1 posts

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of the X-Forwarded-Proto header.

thehackerwire@mastodon.social at 2026-09-24T15:37:04.000Z ##

🔴 CVE-2026-81549 - Critical (9.6)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of the X-Forwarded-Proto header.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81545
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-24T19:41:16.513000

1 posts

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

thehackerwire@mastodon.social at 2026-09-24T15:35:38.000Z ##

🟠 CVE-2026-81545 - High (8.8)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81552
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-24T19:41:16.513000

1 posts

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of environment variables.

thehackerwire@mastodon.social at 2026-09-24T15:19:03.000Z ##

🟠 CVE-2026-81552 - High (8.8)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of environment variables.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78308
(9.8 CRITICAL)

EPSS: 0.35%

updated 2026-09-24T19:39:45.600000

2 posts

Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022.

thehackerwire@mastodon.social at 2026-09-24T12:21:34.000Z ##

🔴 CVE-2026-78308 - Critical (9.8)

Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass.

This issue affects DIAEnergie: before 1.11.00.022.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-24T09:00:25.000Z ##

CVE-2026-78308 | CRITICAL | DIAEnergie (<1.11.00.022): Improper Authentication lets attackers bypass auth controls. Patch urgently when available. radar.offseq.com/threat/cve-20 #OffSeq #ICS #Vulnerability #Cybersecurity

##

CVE-2026-57590
(8.1 HIGH)

EPSS: 0.18%

updated 2026-09-24T19:36:39.327000

1 posts

A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has permission to access the project associated with the target Task Group. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.

thehackerwire@mastodon.social at 2026-09-24T13:34:33.000Z ##

🟠 CVE-2026-57590 - High (8.1)

A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has permission to access the project associated with the target Task Group.

...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56737
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-24T19:29:30

1 posts

### Summary The public two-factor verification endpoint `POST /check` logs a user in based **solely** on a valid 6-digit TOTP token and a chosen `user-id`. It does **not** require — and is not bound to — a prior successful password authentication. For any account that has 2FA enabled, an unauthenticated attacker can authenticate **without knowing the password**, reducing the account to a single fa

thehackerwire@mastodon.social at 2026-09-24T16:48:58.000Z ##

🟠 CVE-2026-56737 - High (8.1)

phpMyFAQ is an open source FAQ web application. Versions 3.2.0 through 4.1.5 contain an authentication bypass in its public two-factor authentication verification flow: an unauthenticated attacker can submit an account’s numeric user ID and a va...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93425
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-24T18:19:07.280000

1 posts

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath value from apps/dokploy/server/api/routers/patch.ts into a shell command in packages/server/src/services/patch-repo.ts without safe argument quoting. An authenticated organization member with service:read permission can inject shell metac

thehackerwire@mastodon.social at 2026-09-24T16:19:14.000Z ##

🔴 CVE-2026-93425 - Critical (9.9)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath value from apps/dokploy/server/api/routers/patch.ts into a shell command in packages/...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-6928
(9.8 CRITICAL)

EPSS: 0.45%

updated 2026-09-24T16:17:10.010000

1 posts

IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can influence program execution or input may exploit this condition to corrupt memory, cause application crashes, or execute arbitrary code.

offseq@infosec.exchange at 2026-09-24T01:30:25.000Z ##

IBM Concert v1.0.0 – 3.0.0 hit by CRITICAL use-after-free bug (CVE-2026-6928, CVSS 9.8). Remote code execution & full compromise possible; no patch confirmed. Monitor IBM advisories. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IBM #CVE20266928 #Infosec

##

CVE-2026-81548
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-24T15:31:42

1 posts

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

thehackerwire@mastodon.social at 2026-09-24T15:36:56.000Z ##

🟠 CVE-2026-81548 - High (8.8)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81547
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-24T15:31:42

1 posts

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to path traversal.

thehackerwire@mastodon.social at 2026-09-24T15:36:46.000Z ##

🟠 CVE-2026-81547 - High (8.8)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to path traversal.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82093
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-24T15:31:42

1 posts

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to unsafe deserialization of untrusted data.

thehackerwire@mastodon.social at 2026-09-24T15:35:20.000Z ##

🟠 CVE-2026-82093 - High (8.8)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to unsafe deserialization of untrusted data.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90959
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-24T15:31:42

1 posts

A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file repository privileges to specify a local file URL for Pulp to download and store. A URL scheme validation check uses a string prefix comparison that only rejects URLs beginning with 'file://', but Python's URL parser recognizes the 'file:' scheme without double sl

thehackerwire@mastodon.social at 2026-09-24T15:18:54.000Z ##

🟠 CVE-2026-90959 - High (8.1)

A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file repository privileges to specify a local file URL for Pulp to download and store. A URL scheme validation check...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97362
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-24T15:31:42

1 posts

HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by sending a single crafted request. Attackers can trigger a hung serving thread that enters a busy loop, rendering the entire file server unresponsive to all clients without self-recovery until an operator manually restarts the ser

thehackerwire@mastodon.social at 2026-09-24T15:18:45.000Z ##

🟠 CVE-2026-97362 - High (7.5)

HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by sending a single crafted request. Attackers can trigger a hung serving threa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58008
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-24T15:31:41

1 posts

Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0.

thehackerwire@mastodon.social at 2026-09-24T15:48:52.000Z ##

🟠 CVE-2026-58008 - High (8.1)

Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections.

This issue affects Trusted Firmware: through socfpga_v2.14.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58007
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-24T15:31:41

1 posts

Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0.

thehackerwire@mastodon.social at 2026-09-24T15:48:43.000Z ##

🟠 CVE-2026-58007 - High (8.1)

Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections.

This issue affects Trusted Firmware: through socfpga_v2.14.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77874
(8.6 HIGH)

EPSS: 0.00%

updated 2026-09-24T15:31:41

1 posts

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

thehackerwire@mastodon.social at 2026-09-24T15:48:32.000Z ##

🟠 CVE-2026-77874 - High (8.6)

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, mo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81539
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-24T15:31:41

1 posts

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

thehackerwire@mastodon.social at 2026-09-24T15:35:29.000Z ##

🟠 CVE-2026-81539 - High (8.8)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97057
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-24T15:31:40

1 posts

redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supplying an excessively large declared length. A malicious or compromised Redis endpoint can deliver a crafted RESP header with a length above 2^32-1 to crash the Node.js client process.

thehackerwire@mastodon.social at 2026-09-24T14:20:46.000Z ##

🟠 CVE-2026-97057 - High (7.5)

redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supplying an excessively large declared length. A malicious or compromised Redis endpoint ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97360
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-24T15:31:40

1 posts

HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside the shared folder. Attackers can exploit the macro dispatcher's lack of authorization model combined with the path resolver's failure to confine absolute paths to

thehackerwire@mastodon.social at 2026-09-24T14:20:37.000Z ##

🔴 CVE-2026-97360 - Critical (10)

HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside the shared...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-95521
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-24T15:31:35

1 posts

A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating the source file list. This allows arbitrary command execution as the invoking (typically non-root) user, simply by installing, rebuilding, or otherwise processing an

thehackerwire@mastodon.social at 2026-09-24T14:33:36.000Z ##

🟠 CVE-2026-95521 - High (7.8)

A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating the source f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19072
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-24T15:31:29

2 posts

Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt. Although the field "compiled_collector_args" is an internal field, Velociraptor allowed the field to be set from a user API call. This allows another user who can schedule a hunt (minimal role of "investigator" ) to set the compiled VQL statements for the hun

thehackerwire@mastodon.social at 2026-09-24T13:34:23.000Z ##

🔴 CVE-2026-19072 - Critical (9.9)

Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt. Although the field "compiled_collector_args" is an internal field, Velociraptor allowed the field to be se...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-24T13:30:25.000Z ##

CVE-2026-19072 (CRITICAL, CVSS 9.9) impacts Rapid7 Velociraptor <0.77.2. 'Investigator' role can escalate to admin by injecting arbitrary VQL via API. Patch by upgrading to 0.77.2+. Details: radar.offseq.com/threat/cve-20 #OffSeq #Velociraptor #CVE #Infosec

##

CVE-2026-85682
(8.8 HIGH)

EPSS: 0.14%

updated 2026-09-24T15:17:46.703000

1 posts

The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10. This is due to the plugin transmitting a wp_rest nonce to window.opener via postMessage() with a wildcard targetOrigin. This makes it possible for unauthenticated attackers to steal a REST nonce scoped to a logged-in Administrator and use it to change the Administrator's email a

thehackerwire@mastodon.social at 2026-09-24T13:35:45.000Z ##

🟠 CVE-2026-85682 - High (8.8)

The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10. This is due to the plugin transmitting a wp_rest nonce to window.opener via postMessage() with a wildcard targetOrigin. This m...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89078
(9.9 CRITICAL)

EPSS: 0.36%

updated 2026-09-24T15:03:53.487000

1 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to a double free issue when parsing a specially crafted regular expression in a CI/CD configuration.

thehackerwire@mastodon.social at 2026-09-24T13:48:00.000Z ##

🔴 CVE-2026-89078 - Critical (9.9)

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93577
(9.9 CRITICAL)

EPSS: 0.43%

updated 2026-09-24T15:03:53.487000

1 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to an integer overflow issue when compiling a specially crafted regular expression in a CI/CD configuration.

bearstech@mamot.fr at 2026-09-24T09:45:00.000Z ##

Toutes nos instances GitLab sont à jour en version 19.4.1 depuis hier soir à 22h.

Il faut mettre à jour rapidement : cette nouvelle version corrige 2 CVE évaluées à 9,9 (CVE-2026-93577 et CVE-2026-84739).

En savoir plus sur nos offres 👇
gitlab-saas.bearstech.com/

##

CVE-2026-81537
(8.8 HIGH)

EPSS: 0.98%

updated 2026-09-24T14:51:56.593000

1 posts

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to OS command injection.

thehackerwire@mastodon.social at 2026-09-24T00:16:19.000Z ##

🟠 CVE-2026-81537 - High (8.8)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to OS command injection.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81208
(7.7 HIGH)

EPSS: 0.23%

updated 2026-09-24T14:51:56.593000

1 posts

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to improper handling of encrypted credentials. An attacker could exploit this vulnerability to obtain credentials intended for other users or environments.

thehackerwire@mastodon.social at 2026-09-23T23:04:12.000Z ##

🟠 CVE-2026-81208 - High (7.7)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to improper handling of encrypted credentials. An attacker could exploit this vulnerability to obtain credentials intended for other ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12227
(9.8 CRITICAL)

EPSS: 0.77%

updated 2026-09-24T12:31:29

2 posts

The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0 via the `vcv-template` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive da

2 repos

https://github.com/Hassham1/CVE-2026-12227-visualcomposer-lfi-poc

https://github.com/murrez/CVE-2026-12227

thehackerwire@mastodon.social at 2026-09-24T12:21:25.000Z ##

🔴 CVE-2026-12227 - Critical (9.8)

The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0 via the `vcv-template` parameter. This makes it possible for unauthenticated attackers to include and exec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-24T10:30:27.000Z ##

Visual Composer Website Builder plugin ≤45.16.0 hit by CRITICAL LFI (CVE-2026-12227). Unauthenticated attackers can execute arbitrary PHP files via 'vcv-template'. Patch unconfirmed. Mitigate & monitor now: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #LFI

##

CVE-2026-80513
(7.5 HIGH)

EPSS: 0.20%

updated 2026-09-24T12:31:23

1 posts

The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes a user-supplied profile field value, allowing authenticated users with Subscriber-level access and above to inject a PHP Object. No POP chain is present in the wpForo Forum WordPress plugin before 3.1.6 itself; if one is present via another installed wpForo Forum WordPress plugin

thehackerwire@mastodon.social at 2026-09-24T13:47:51.000Z ##

🟠 CVE-2026-80513 - High (7.5)

The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes a user-supplied profile field value, allowing authenticated users with Subscriber-level access and above to inject a PHP Object...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77193
(7.5 HIGH)

EPSS: 0.36%

updated 2026-09-24T09:32:00

1 posts

The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.3 via the `id2wp_path` parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

thehackerwire@mastodon.social at 2026-09-24T13:47:42.000Z ##

🟠 CVE-2026-77193 - High (7.5)

The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.3 via the `id2wp_path` parameter. This makes it possible for unauthenticated attackers to read the contents of...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97185
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-24T09:32:00

1 posts

A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to load a malicious preset file, potentially causing a crash or enabling arbitrary code execution.

thehackerwire@mastodon.social at 2026-09-24T13:35:54.000Z ##

🟠 CVE-2026-97185 - High (7.8)

A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting memory. An a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78312
(9.1 CRITICAL)

EPSS: 0.34%

updated 2026-09-24T09:32:00

1 posts

Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

thehackerwire@mastodon.social at 2026-09-24T13:35:36.000Z ##

🔴 CVE-2026-78312 - Critical (9.1)

Path Traversal in DIAEnergie.

This issue affects DIAEnergie: before 1.11.00.022.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78311
(8.8 HIGH)

EPSS: 0.24%

updated 2026-09-24T09:32:00

1 posts

SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

thehackerwire@mastodon.social at 2026-09-24T13:34:43.000Z ##

🟠 CVE-2026-78311 - High (8.8)

SQL Injection vulnerability in DIAEnergie.

This issue affects DIAEnergie: before 1.11.00.022.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78309
(8.8 HIGH)

EPSS: 0.24%

updated 2026-09-24T09:32:00

1 posts

SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

thehackerwire@mastodon.social at 2026-09-24T12:21:44.000Z ##

🟠 CVE-2026-78309 - High (8.8)

SQL Injection vulnerability in DIAEnergie.

This issue affects DIAEnergie: before 1.11.00.022.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18467
(9.8 CRITICAL)

EPSS: 0.39%

updated 2026-09-24T03:30:34

2 posts

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.3. The 5.0.3 patch introduced a wp_hash()/hash_equals() signature gate on the pt-paytium-user-data field, but left a second filter — pt_cf_checkout_meta(), registered on the pt_meta_values hook after the signed builder — that copies every $_POST['pt_for

thehackerwire@mastodon.social at 2026-09-24T07:47:59.000Z ##

🔴 CVE-2026-18467 - Critical (9.8)

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.3. The 5.0.3 patch introduced a wp_hash()/hash_equals() signature gate on the pt-paytium-user-data f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-24T03:00:25.000Z ##

CVE-2026-18467: CRITICAL privilege escalation in Paytium: Mollie payment forms (≤5.0.3). Unauthenticated users can create admin accounts via exploited payment forms. Restrict forms or disable plugin until full fix. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202618467 #Security

##

CVE-2026-96891
(9.8 CRITICAL)

EPSS: 0.65%

updated 2026-09-24T03:30:34

1 posts

A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the argument peer_hostname  leads to out-of-bounds write. The attack may be initiated remotely.

thehackerwire@mastodon.social at 2026-09-24T07:47:42.000Z ##

🔴 CVE-2026-96891 - Critical (9.8)

A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the argument peer_hostname  leads to out-of-bounds write. The attack may be in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70125
(8.8 HIGH)

EPSS: 0.44%

updated 2026-09-24T00:30:34

1 posts

Microsoft Outlook Remote Code Execution Vulnerability

CVE-2026-19125
(8.1 HIGH)

EPSS: 0.64%

updated 2026-09-24T00:30:29

1 posts

The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.5. This is due to the verify_login() function in app/Login.php containing a missing return statement in the signature verification failure branch — when Signature::verify2() reports a mismatch, the function only assigns a WP_Error to a local variable and continues executi

1 repos

https://github.com/Polosss/By-Poloss..-..CVE-2026-19125

thehackerwire@mastodon.social at 2026-09-24T00:16:28.000Z ##

🟠 CVE-2026-19125 - High (8.1)

The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.5. This is due to the verify_login() function in app/Login.php containing a missing return statement in the signature...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93352
(9.8 CRITICAL)

EPSS: 0.62%

updated 2026-09-24T00:30:29

2 posts

Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist introduced to address CVE-2026-49972 includes phpt but omits pht, which Apache executes as PHP via the default FilesMatch directive on Debian and Ubuntu systems. An attacker can upload a .pht file tha

offseq@infosec.exchange at 2026-09-24T00:00:35.000Z ##

plank laravel-mediable <7.0.2 has a CRITICAL vuln (CVE-2026-93352): .pht files not blocked, allowing unauthenticated RCE. Upgrade to 7.0.2+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE202693352 #RCE #Laravel #Infosec

##

thehackerwire@mastodon.social at 2026-09-23T23:02:06.000Z ##

🔴 CVE-2026-93352 - Critical (9.8)

Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist introduced to address CVE-2026-49972 includes p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81536
(7.7 HIGH)

EPSS: 0.28%

updated 2026-09-24T00:30:29

1 posts

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.

thehackerwire@mastodon.social at 2026-09-23T23:04:21.000Z ##

🟠 CVE-2026-81536 - High (7.7)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80423
(8.8 HIGH)

EPSS: 0.33%

updated 2026-09-24T00:30:29

1 posts

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to the exposure of namespace-wide secrets via accessible file mounts.

thehackerwire@mastodon.social at 2026-09-23T23:04:02.000Z ##

🟠 CVE-2026-80423 - High (8.8)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to the exposure of namespace-wide secrets via accessible file mounts.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86583
(8.8 HIGH)

EPSS: 0.33%

updated 2026-09-24T00:30:29

1 posts

The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the plugin's own export and re-import workflow. The vulnerability exists because the exporter writes CSV cells using fputcsv() with a NUL byte (\0) as the escape character, while the importer parses the same file using SplFileObject::fgetcsv() with o

thehackerwire@mastodon.social at 2026-09-23T23:01:57.000Z ##

🟠 CVE-2026-86583 - High (8.8)

The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the plugin's own export and re-import workflow. The vulnerability exists because the exporter wri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75887
(7.5 HIGH)

EPSS: 0.36%

updated 2026-09-24T00:30:26

1 posts

A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows the attacker to read sensitive `*.json` files from the pod filesystem, including plugin manifests and configuration files. Furthermore, this flaw can enable path traversal against

thehackerwire@mastodon.social at 2026-09-23T23:02:15.000Z ##

🟠 CVE-2026-75887 - High (7.5)

A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows the attacker to read sensit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-6730
(9.8 CRITICAL)

EPSS: 0.44%

updated 2026-09-23T21:31:08

1 posts

IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.

offseq@infosec.exchange at 2026-09-24T06:00:23.000Z ##

Buffer overflow (CVE-2026-6730) in IBM Concert 1.0.0-3.0.0 (CVSS 9.8, CRITICAL) lets local users execute arbitrary code. No patch yet — restrict local access, check vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #IBM #Vuln #CyberSecurity

##

CVE-2026-87899(CVSS UNKNOWN)

EPSS: 0.53%

updated 2026-09-23T21:31:03

1 posts

Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.

CVE-2026-18162
(9.8 CRITICAL)

EPSS: 0.48%

updated 2026-09-23T19:17:28.687000

1 posts

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper neutralization of user-controlled input within the new Function constructor.

offseq@infosec.exchange at 2026-09-23T03:00:24.000Z ##

CVE-2026-18162: IBM FTM for RedHat OpenShift v4.0.6.0 has a CRITICAL code injection flaw (CVSS 9.8). Remote attackers can execute arbitrary code via improper input neutralization. No patch yet — monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE202618162 #IBM #RCE

##

CVE-2026-18169
(9.9 CRITICAL)

EPSS: 0.53%

updated 2026-09-23T18:17:07.270000

1 posts

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.

offseq@infosec.exchange at 2026-09-23T00:00:43.000Z ##

CVE-2026-18169: CRITICAL path traversal in IBM FTM for RedHat OpenShift 4.0.6.0 (CVSS 9.9) 🕵️‍♂️. Authenticated attackers can access sensitive info via symlink abuse. Restrict access & monitor logs. Patch status unknown. radar.offseq.com/threat/cve-20 #OffSeq #IBM #CVE202618169 #Infosec

##

CVE-2026-91818
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-23T17:58:26.570000

1 posts

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s JavaScript handling of PDF annotations. Reentrant page-event processing during annotation enumeration may release the associated page object, which is subsequently accessed, resulting in an application crash.

thehackerwire@mastodon.social at 2026-09-23T09:02:58.000Z ##

🟠 CVE-2026-91818 - High (7.8)

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s JavaScript handling of PDF annotations. Reentrant page-event processing during annotation enumeration may release the associated page object, which is subsequently accessed, resu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19599
(9.9 CRITICAL)

EPSS: 2.86%

updated 2026-09-23T15:30:51

2 posts

ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability in the Notification Profile module.

DailyCyberSecurity@infosec.exchange at 2026-09-23T14:35:09.000Z ##

ManageEngine security vulnerabilities expose servers to remote code execution. Patch these OpManager vulnerabilities and CVE-2026-19599 to secure your network.

#ManageEngine #Cybersecurity #CVE202619599 #OpManager #Infosec #Vulnerability

securityonline.info/manageengi

##

offseq@infosec.exchange at 2026-09-23T13:30:24.000Z ##

CVE-2026-19599: CRITICAL RCE in ManageEngine OpManager MSP (<12.8.711). Improper OS command neutralization enables remote command execution (CVSS 9.9). Upgrade to 12.8.711+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #InfoSec #RCE

##

CVE-2026-91811
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-23T09:30:37

1 posts

A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s PRC parser due to insufficient validation of vertex indices in triangular fan texture meshes. Successful exploitation could result in memory corruption and an application crash.

thehackerwire@mastodon.social at 2026-09-23T09:03:17.000Z ##

🟠 CVE-2026-91811 - High (7.8)

A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s PRC parser due to insufficient validation of vertex indices in triangular fan texture meshes. Successful exploitation could result in memory corruption and an app...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91809
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-23T09:30:30

1 posts

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF form fields. Improper validation during field-name traversal may cause the application to access a released object, resulting in an application crash.

thehackerwire@mastodon.social at 2026-09-23T09:03:07.000Z ##

🟠 CVE-2026-91809 - High (7.8)

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF form fields. Improper validation during field-name traversal may cause the application to access a released object, resulting in an application crash.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74849
(9.8 CRITICAL)

EPSS: 4.61%

updated 2026-09-23T04:17:44.340000

1 posts

Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client.

CVE-2026-96257
(10.0 CRITICAL)

EPSS: 0.58%

updated 2026-09-23T03:30:35

1 posts

A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this issue is the function copy_msg_element of the component Device Discovery Service. Executing a manipulation can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

offseq@infosec.exchange at 2026-09-23T04:30:24.000Z ##

Fast FAC1203R Gigabit Edition v2.0.4 hit by CRITICAL stack-based buffer overflow (CVE-2026-96257). Remote, unauthenticated RCE possible. Exploit is public, no patch exists — restrict access to Device Discovery Service now. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Infosec

##

CVE-2026-18163
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-09-23T00:31:21

1 posts

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data.

offseq@infosec.exchange at 2026-09-23T01:30:24.000Z ##

CVE-2026-18163 (CRITICAL, CVSS 9.8): IBM FTM for RedHat OpenShift v4.0.6.0 has a deserialization vulnerability enabling remote code execution without auth. Restrict access & monitor activity. Patch status unconfirmed. radar.offseq.com/threat/cve-20 #OffSeq #CVE202618163 #IBM #InfoSec 🛡️

##

CVE-2026-19202(CVSS UNKNOWN)

EPSS: 0.25%

updated 2026-09-23T00:31:15

1 posts

A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK causes the same Google ID token to be cached and reused across different audiences. If an application uses the SDK to authenticate to two or more different audiences within the same process, the module-level token cache fails to key its cached tokens by the requested audience. Consequently, a valid, unexpired token minted

offseq@infosec.exchange at 2026-09-23T06:00:25.000Z ##

CVE-2026-19202: CRITICAL vuln in Google mcp-toolbox-sdk-python (v0 – 1.1.0). Shared cache flaw lets Google ID tokens be reused across audiences — risk of token replay & impersonation. Patch pending. Details: radar.offseq.com/threat/cve-20 #OffSeq #infosec #CVE202619202 #Python

##

CVE-2026-81642
(9.8 CRITICAL)

EPSS: 0.80%

updated 2026-09-22T21:31:54

1 posts

In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression pointer to its own RDATA can overflow the digest buffer. Remote code execution is possible through attacker controlled data. An adversary can exploit the vulnerabili

1 repos

https://github.com/suominen/CVE-2026-81642

CVE-2026-77987(CVSS UNKNOWN)

EPSS: 0.89%

updated 2026-09-22T21:31:40

1 posts

A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated the scheme and host of a user-supplied URL but did not validate the port, allowing requests to be directed to internal services listening on other ports of the same appliance. Response bodies were not returned to the requester, but response timing acte

cR0w@infosec.exchange at 2026-09-22T21:36:48.000Z ##

Go hack more GitHub shit.

nvd.nist.gov/vuln/detail/cve-2

A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated the scheme and host of a user-supplied URL but did not validate the port, allowing requests to be directed to internal services listening on other ports of the same appliance. Response bodies were not returned to the requester, but response timing acted as an oracle that allowed instance secrets to be extracted character by character. An extracted secret could then be used in a separate interaction with an internal service to obtain remote code execution on the appliance. Exploitation required network access to the instance and was unauthenticated when private mode was disabled, or required any authenticated user when private mode was enabled. This vulnerability affected GitHub Enterprise Server versions 3.17 through 3.22 and was fixed in versions 3.22.1, 3.21.6, 3.20.8, 3.19.12, 3.18.15, and 3.17.21. This vulnerability was reported through the GitHub Bug Bounty program.

sev:CRIT 9.3 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

##

CVE-2026-88020
(6.1 MEDIUM)

EPSS: 0.27%

updated 2026-09-22T21:31:39

1 posts

Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter with no encoding.

cyberworldops@infosec.exchange at 2026-09-23T11:00:01.000Z ##

CISA reports CVE-2026-88020, XSS in OpenPLC Runtime v3 6.1. Theft of an operator session cookie can enable state-changing requests and PLC-level control. Exposure of OT web interfaces significantly raises impact. #IcsSecurity #OtSecurity #Xss

cyberworldops.eu/en/openplc-we

##

CVE-2026-28324
(9.8 CRITICAL)

EPSS: 0.65%

updated 2026-09-22T21:31:34

3 posts

SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected.

cyberworldops@infosec.exchange at 2026-09-24T13:00:00.000Z ##

SolarWinds patched three RCE flaws in Observability Self-Hosted, including CVE-2026-28324 (CVSS 9.8) exploitable without authentication. Monitoring hosts hold broad access, so RCE risks full environment compromise and persistence. Patch and restrict exposure now. #SolarWinds #RemoteCodeExecution #PatchManagement

cyberworldops.eu/en/three-sola

##

DailyCyberSecurity@infosec.exchange at 2026-09-23T01:02:41.000Z ##

SolarWinds Observability vulnerabilities allow RCE via CVE-2026-28324. Update to version 2026.2.3 to secure your monitoring infrastructure today.

#SolarWinds #Cybersecurity #CVE202628324 #CVE202628325 #RCE #Infosec

securityonline.info/solarwinds

##

cR0w@infosec.exchange at 2026-09-22T21:34:44.000Z ##

solarwinds.com/trust-center/se

SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected.

sev:CRIT 9.8 - AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

##

CVE-2026-87121
(9.8 CRITICAL)

EPSS: 0.53%

updated 2026-09-22T21:31:34

2 posts

lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.

cR0w@infosec.exchange at 2026-09-22T21:35:40.000Z ##

Go hack more MQTT shit.

nvd.nist.gov/vuln/detail/cve-2

##

thehackerwire@mastodon.social at 2026-09-22T21:01:57.000Z ##

🔴 CVE-2026-87121 - Critical (9.8)

lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94127
(9.8 CRITICAL)

EPSS: 1.29%

updated 2026-09-22T21:31:17

16 posts

When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software version

2 repos

https://github.com/watchtowrlabs/watchTowr-vs-f5-bigip-PreAuth-RCE-CVE-2026-94127

https://github.com/FurkanKAYAPINAR/CVE-2026-94127

DarkWebInformer@infosec.exchange at 2026-09-24T19:41:58.000Z ##

‼️[POC] CVE-2026-94127: When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE)

GitHub: github.com/watchtowrlabs/watch

##

AAKL@infosec.exchange at 2026-09-24T16:38:20.000Z ##

WatchTower posted this yesterday:

WatchTower: Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127) labs.watchtowr.com/is-this-a-j #infosec #vulnerability

##

AAKL@infosec.exchange at 2026-09-24T16:26:29.000Z ##

New.

Picus: CVE-2026-94127 Explained: F5 BIG-IP APM Heap Overflow Attack picussecurity.com/resource/blo #infosec #threatresearch

##

threatcodex@infosec.exchange at 2026-09-24T13:48:35.000Z ##

Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)
#CVE_2026_94127
labs.watchtowr.com/is-this-a-j

##

raptor@infosec.exchange at 2026-09-24T05:01:11.000Z ##

Is This A Joke? In The Auth Header? (#F5 BIG-IP UnAuth Heap-Overflow to #RCE CVE-2026-94127)

labs.watchtowr.com/is-this-a-j

##

_r_netsec@infosec.exchange at 2026-09-23T23:28:04.000Z ##

Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127) - watchTowr Labs labs.watchtowr.com/is-this-a-j

##

security_crawler_carl@infosec.exchange at 2026-09-23T11:14:37.000Z ##

🏆 New Achievement! Terms and Conditions of Your Own Destruction!

LOOTBOX DISCLAIMER: By operating F5 BIG-IP APM versions 21.1.0, 17.5.0–17.5.1, or 17.1.0–17.1.3, you have automatically entered our Unauthenticated Remote Code Execution Sweepstakes. Prizes are awarded via CVE-2026-94127, targeting the OAuth Authorization Server component. Odds of receiving a prize are classified as "active exploitation." The System does not guarantee prize desirability. (1/3)

##

offseq@infosec.exchange at 2026-09-23T10:30:25.000Z ##

F5 BIG-IP APM (OAuth Authorization Server) is facing a CRITICAL RCE zero-day, CVE-2026-94127, with active exploitation. Versions 21.1.0, 17.5.0 – 17.5.1, 17.1.0 – 17.1.3 affected. Apply hotfixes now. Details: radar.offseq.com/threat/critic #OffSeq #F5 #ZeroDay #Infosec

##

cyberworldops@infosec.exchange at 2026-09-23T08:20:00.000Z ##

F5 patched CVE-2026-94127, a heap-based buffer overflow in BIG-IP APM when operating as OAuth Authorization Server, enabling remote code execution. Active zero-day exploitation poses high risk of full appliance compromise. Patch immediately and review for crafted malicious traffic. #F5BigIp #ZeroDay #RemoteCodeExecution

cyberworldops.eu/en/actively-e

##

bsi@social.bund.de at 2026-09-23T08:09:54.000Z ##

Der Hersteller F5 veröffentlichte ein Advisory zu einer ausgenutzten Zero-Day Schwachstelle in seinem Produkt BIG-IP Access Policy Manager (APM) zur sicheren Zugriffsteuerung und Anwendungszugriff: CVE-2026-94127, CVSS-Score 9.8/10 ("kritisch")

F5 gibt an, dass die Schwachstelle bereits aktiv ausgenutzt wird. IT-Sicherheitsverantwortliche sollten unverzüglich die Patchstände prüfen und, sofern erforderlich, die verfügbaren Engineering Hotfixes einspielen.

👉️ bsi.bund.de/dok/1209384

##

offseq@infosec.exchange at 2026-09-23T07:30:23.000Z ##

CVE-2026-94127: Critical zero-day in F5 BIG-IP APM exploited for RCE on OAuth Authorization Servers. Patch urgently or use F5's iRule mitigation. Monitor for OAuth auth failures and TMM SIGABRTs. radar.offseq.com/threat/f5-pat #OffSeq #F5 #ZeroDay #RCE #Vuln

##

secdb@infosec.exchange at 2026-09-22T22:00:21.000Z ##

🚨 [CISA-2026:0922] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-85102 (secdb.nttzen.cloud/cve/detail/)
- Name: Check Point Multiple Products Improper Certificate Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Check Point
- Product: Multiple Products
- Notes: support.checkpoint.com/results ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-93616 (secdb.nttzen.cloud/cve/detail/)
- Name: Check Point Multiple Products Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Check Point
- Product: Multiple Products
- Notes: support.checkpoint.com/results ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-93952 (secdb.nttzen.cloud/cve/detail/)
- Name: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Arista
- Product: VeloCloud Orchestrator
- Notes: arista.com/en/support/advisori ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-94127 (secdb.nttzen.cloud/cve/detail/)
- Name: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: F5
- Product: BIG-IP APM
- Notes: For temporary mitigation to allow for proactive forensic triage, apply the vendor-provided iRule. Once completed, install the final vendor patch as soon as possible. For more information please see: my.f5.com/manage/s/article/K00 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260922 #cisa20260922 #cve_2026_85102 #cve_2026_93616 #cve_2026_93952 #cve_2026_94127 #cve202685102 #cve202693616 #cve202693952 #cve202694127

##

ifin@infosec.exchange at 2026-09-22T20:51:00.000Z ##

When it rains, it pours. F5 BIG-IP APM also has an exploited CVE!

ifin.network/t/f5-big-ip-cve-2

#ThreatIntel #ThreatIntelligence #IFIN

##

cisakevtracker@mastodon.social at 2026-09-22T20:01:07.000Z ##

CVE ID: CVE-2026-94127
Vendor: F5
Product: BIG-IP APM
Date Added: 2026-09-22
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

DailyCyberSecurity@infosec.exchange at 2026-09-22T16:27:39.000Z ##

An exploited BIG-IP APM vulnerability tracked as CVE-2026-94127 allows RCE attacks. Secure your BIG-IP APM vulnerability deployments with new F5 hotfixes.

#F5 #BIGIP #CVE202694127 #Cybersecurity #InfoSec #RCE #Vulnerability

securityonline.info/big-ip-apm

##

cR0w@infosec.exchange at 2026-09-22T15:03:32.000Z ##

EITW 0day in F5 APM.

my.f5.com/manage/s/article/K00

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). (CVE-2026-94127)

This vulnerability allows an unauthenticated attacker to perform RCE. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure.

##

CVE-2026-93616
(9.8 CRITICAL)

EPSS: 2.42%

updated 2026-09-22T21:31:15

12 posts

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

2 repos

https://github.com/Nebula-Consulting-Limited/CVE-2026-93616-PoC

https://github.com/WadesWeaponShed/CVE-2026-93616_Checks

beyondmachines1@infosec.exchange at 2026-09-24T08:01:13.000Z ##

Check Point VPN Gateways and Management Server Flaws Actively Exploited

Check Point confirmed active exploitation of three critical vulnerabilities (CVE-2026-85102, CVE-2026-85103, and CVE-2026-93616) affecting VPN gateways and management servers, prompting a 72-hour US federal remediation deadline.

**If you run Check Point Security Gateways, Spark Firewalls or Security Management Servers, patch immediately to LivePatch Take 26 or the latest Jumbo Hotfix. Older unsupported versions R80 through R81.10 must be upgraded first. Make sure the management server's web interface is reachable only from trusted internal networks. Patching isn't enough, since attackers have been active since September 12: check your VPN logs for unknown sessions and internal LDAP scanning, and if you find anything suspicious, treat the device as compromised and escalate to your incident response team.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

tugatech@masto.pt at 2026-09-24T07:07:21.000Z ##

Até 30 de junho, a Check Point confirma ataques ativos a falhas críticas em seus produtos, recomendando atualização urgente. Piratas informáticos exploram vulnerabilidades nos certificados de VPN do Security Gateway (CVE-2026-85102) e no serviço web de Management (CVE-2026-93616), permitindo a execução remota de código sem autenticação prévia. 🚨

🔗 tugatech.com.pt/t91581-check-p

#urgente 

##

cyberworldops@infosec.exchange at 2026-09-23T20:50:00.000Z ##

Check Point confirms active exploitation of CVE-2026-85102, unauthenticated RCE in Security Gateway VPN negotiation, and CVE-2026-93616, path traversal leading to script execution on management systems. Internet-exposed gateways and management planes should be patched and reviewed for compromise immediately. #CheckPoint #ThreatIntel #VpnSecurity

cyberworldops.eu/en/active-att

##

uztq@infosec.exchange at 2026-09-23T19:49:09.000Z ##

Checkpoint / CVE-2026-93616: support.checkpoint.com/results

Soooo, it is always fun to translate a vendor advisory into real facts. Here, checkpoint says "Directory Traversal and File upload allows execution of arbitrary script", and provide, as an example:

login(loginRequest=LoginRequest{authenticationInfo=AuthenticationInfoBase{username='abcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdababcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcd'}

And: "if a core dump file was generated at the same time as the login attempt [...]"

Sorry guys, but you are totally misleading whoever is trying to qualify/understand your adivsory. Security vendors should really be accountable of whatever they deliver. I am not even mentioning 1. the triviality of the findings, 2. everything is running as root.

They also discovered that ASN.1 parsing requires extensive fuzzing (support.checkpoint.com/results).

I was expected more from checkpoint, but at least they provide a bit more info than the other "similar" vendors.

##

secdb@infosec.exchange at 2026-09-22T22:00:21.000Z ##

🚨 [CISA-2026:0922] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-85102 (secdb.nttzen.cloud/cve/detail/)
- Name: Check Point Multiple Products Improper Certificate Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Check Point
- Product: Multiple Products
- Notes: support.checkpoint.com/results ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-93616 (secdb.nttzen.cloud/cve/detail/)
- Name: Check Point Multiple Products Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Check Point
- Product: Multiple Products
- Notes: support.checkpoint.com/results ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-93952 (secdb.nttzen.cloud/cve/detail/)
- Name: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Arista
- Product: VeloCloud Orchestrator
- Notes: arista.com/en/support/advisori ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-94127 (secdb.nttzen.cloud/cve/detail/)
- Name: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: F5
- Product: BIG-IP APM
- Notes: For temporary mitigation to allow for proactive forensic triage, apply the vendor-provided iRule. Once completed, install the final vendor patch as soon as possible. For more information please see: my.f5.com/manage/s/article/K00 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260922 #cisa20260922 #cve_2026_85102 #cve_2026_93616 #cve_2026_93952 #cve_2026_94127 #cve202685102 #cve202693616 #cve202693952 #cve202694127

##

security_crawler_carl@infosec.exchange at 2026-09-22T21:31:08.000Z ##

blog.checkpoint.com/security/s

#CyberSecurity #ZeroDay #CheckPoint #Vulnerability #ActiveExploitation #PatchedOrPerish (3/3)

##

security_crawler_carl@infosec.exchange at 2026-09-22T21:31:07.000Z ##

Meanwhile a second zero-day, CVE-2026-93616, materialized in Security Management with its own handful of pinpointed hits.

Policy dictates we inform you patches now exist for both CVE-2026-85102 and CVE-2026-93616. Policy does not require we feel bad about what happens next if you ignore them. Install both immediately.

Reward: Compliance logged. Outcome: your problem. (2/3)

##

campuscodi@mastodon.social at 2026-09-22T20:02:50.000Z ##

Check Point has disclosed a zero-day (in Security Management Server) and marked an older bug also as exploited in the wild (in Site-to-Site VPN)

blog.checkpoint.com/security/s

##

cisakevtracker@mastodon.social at 2026-09-22T20:01:22.000Z ##

CVE ID: CVE-2026-93616
Vendor: Check Point
Product: Multiple Products
Date Added: 2026-09-22
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

DarkWebInformer@infosec.exchange at 2026-09-22T18:46:03.000Z ##

🚨 Check Point patches Management Server zero-day exploited in attacks
⠀
Check Point has released fixes for CVE-2026-93616, a vulnerability that allows unauthenticated attackers to upload and execute arbitrary scripts on affected management servers.
⠀
The company says a small number of customers have already been attacked.
⠀
Affected products include:

• Security Management Server
• Multi-Domain Security Management Server
• Log Server
• Multi-Domain Log Server
• SmartEvent
⠀
The vulnerability carries a CVSS score of 9.8.
⠀
Check Point advises installing the applicable fixes, restricting management access to trusted IP addresses, and checking for signs of exploitation.
⠀
LivePatch Take 28/29 does not fix this vulnerability.

Source: bleepingcomputer.com/news/secu

##

DailyCyberSecurity@infosec.exchange at 2026-09-22T13:58:15.000Z ##

A critical exploited Check Point Management vulnerability (CVE-2026-93616) allows attackers to execute arbitrary scripts. Secure your servers now.

#CheckPoint #CVE202693616 #Cybersecurity #InfoSec #Vulnerability #RCE

securityonline.info/exploited-

##

offseq@infosec.exchange at 2026-09-22T13:30:26.000Z ##

Check Point Quantum Security Management is affected by CVE-2026-93616 (CRITICAL, CVSS 9.8): unauthenticated attackers can upload & execute scripts via path traversal. Restrict access & monitor activity until patch info is released. radar.offseq.com/threat/cve-20 #OffSeq #CheckPoint #CyberAlert

##

CVE-2026-93952
(10.0 CRITICAL)

EPSS: 0.90%

updated 2026-09-22T21:31:14

8 posts

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been

beyondmachines1@infosec.exchange at 2026-09-24T11:01:12.000Z ##

Arista Networks Patches Critical VeloCloud Orchestrator Zero-Day Exploited in the Wild

Arista Networks disclosed a critical CVSS 10.0 vulnerability (CVE-2026-93952) in VeloCloud Orchestrator On-Prem that is being actively exploited to gain unauthenticated remote access to orchestrator hosts and managed edge devices.

**If you run VeloCloud Orchestrator On-Prem, this is urgent. Make sure its web interface is not reachable from the internet and is accessible only from trusted admin networks, then update right away to a fixed version (5.2.3.16, 6.4.2.8 or later). Attackers are already using this flaw to take full control without any password. After patching, look for the hidden file /usr/local/sbin/.vcnode.js or the x-vc-opt header in your web logs, and if you find either, treat the orchestrator and every connected Edge device as compromised.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

offseq@infosec.exchange at 2026-09-23T09:00:25.000Z ##

CVE-2026-93952: CRITICAL zero-day in Arista VeloCloud Orchestrator (on-prem <5.2.3.16, <6.4.2.8) is actively exploited. Remote attackers can access privileged functions w/o creds. Patch now — review logs for signs of compromise. radar.offseq.com/threat/arista #OffSeq #Arista #ZeroDay #Infosec

##

DailyCyberSecurity@infosec.exchange at 2026-09-23T08:40:23.000Z ##

Arista confirmed active exploitation of a CVSS 10 VeloCloud Orchestrator vulnerability (CVE-2026-93952) affecting certificate-based SD-WAN setups. Patch now.

#VeloCloud #Arista #CVE202693952 #SDWAN #Vulnerability #CyberSecurity

meterpreter.org/arista-veloclo

##

ifin@infosec.exchange at 2026-09-22T22:28:10.000Z ##

Completing our tour of new known-exploited vulns today, here is Arista's perfect-10.

ifin.network/t/arista-cve-2026

#ThreatIntel #ThreatIntelligence #IFIN

##

secdb@infosec.exchange at 2026-09-22T22:00:21.000Z ##

🚨 [CISA-2026:0922] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-85102 (secdb.nttzen.cloud/cve/detail/)
- Name: Check Point Multiple Products Improper Certificate Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Check Point
- Product: Multiple Products
- Notes: support.checkpoint.com/results ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-93616 (secdb.nttzen.cloud/cve/detail/)
- Name: Check Point Multiple Products Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Check Point
- Product: Multiple Products
- Notes: support.checkpoint.com/results ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-93952 (secdb.nttzen.cloud/cve/detail/)
- Name: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Arista
- Product: VeloCloud Orchestrator
- Notes: arista.com/en/support/advisori ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-94127 (secdb.nttzen.cloud/cve/detail/)
- Name: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: F5
- Product: BIG-IP APM
- Notes: For temporary mitigation to allow for proactive forensic triage, apply the vendor-provided iRule. Once completed, install the final vendor patch as soon as possible. For more information please see: my.f5.com/manage/s/article/K00 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260922 #cisa20260922 #cve_2026_85102 #cve_2026_93616 #cve_2026_93952 #cve_2026_94127 #cve202685102 #cve202693616 #cve202693952 #cve202694127

##

cisakevtracker@mastodon.social at 2026-09-22T20:00:51.000Z ##

CVE ID: CVE-2026-93952
Vendor: Arista
Product: VeloCloud Orchestrator
Date Added: 2026-09-22
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cyberworldops@infosec.exchange at 2026-09-22T14:40:00.000Z ##

Arista disclosed active exploitation of CVE-2026-93952, a CVSS 10.0 unauthenticated flaw in on-prem VeloCloud Orchestrator with certificate authentication enabled. Compromise of the management plane risks full SD-WAN Edge control and lateral movement. Isolate exposed instances and hunt for abuse. #VeloCloud #ThreatIntel #InfoSec

cyberworldops.eu/en/active-att

##

security_crawler_carl@infosec.exchange at 2026-09-22T14:39:04.000Z ##

🏆 New Achievement! Exceeds Expectations (Except Security)!

Thank you for joining us for your annual review, Arista VeloCloud Orchestrator team. Uptime? Stellar. Throughput? Impressive. Unauthorized remote access granted to unauthenticated strangers due to CVE-2026-93952, a CVSS 10.0 critical improper-input-validation flaw currently being actively exploited in the wild? That's a "needs improvement," and frankly it drags down the whole scorecard.

Full system compromise is on the table. (1/2)

##

CVE-2026-85102
(9.8 CRITICAL)

EPSS: 0.99%

updated 2026-09-22T21:30:40

11 posts

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

beyondmachines1@infosec.exchange at 2026-09-24T08:01:13.000Z ##

Check Point VPN Gateways and Management Server Flaws Actively Exploited

Check Point confirmed active exploitation of three critical vulnerabilities (CVE-2026-85102, CVE-2026-85103, and CVE-2026-93616) affecting VPN gateways and management servers, prompting a 72-hour US federal remediation deadline.

**If you run Check Point Security Gateways, Spark Firewalls or Security Management Servers, patch immediately to LivePatch Take 26 or the latest Jumbo Hotfix. Older unsupported versions R80 through R81.10 must be upgraded first. Make sure the management server's web interface is reachable only from trusted internal networks. Patching isn't enough, since attackers have been active since September 12: check your VPN logs for unknown sessions and internal LDAP scanning, and if you find anything suspicious, treat the device as compromised and escalate to your incident response team.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

tugatech@masto.pt at 2026-09-24T07:07:21.000Z ##

Até 30 de junho, a Check Point confirma ataques ativos a falhas críticas em seus produtos, recomendando atualização urgente. Piratas informáticos exploram vulnerabilidades nos certificados de VPN do Security Gateway (CVE-2026-85102) e no serviço web de Management (CVE-2026-93616), permitindo a execução remota de código sem autenticação prévia. 🚨

🔗 tugatech.com.pt/t91581-check-p

#urgente 

##

cyberworldops@infosec.exchange at 2026-09-23T20:50:00.000Z ##

Check Point confirms active exploitation of CVE-2026-85102, unauthenticated RCE in Security Gateway VPN negotiation, and CVE-2026-93616, path traversal leading to script execution on management systems. Internet-exposed gateways and management planes should be patched and reviewed for compromise immediately. #CheckPoint #ThreatIntel #VpnSecurity

cyberworldops.eu/en/active-att

##

oversecurity@mastodon.social at 2026-09-23T20:10:05.000Z ##

Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE)...

🔗️ [Bleepingcomputer] link.is.it/iSJtsD

##

secdb@infosec.exchange at 2026-09-22T22:00:21.000Z ##

🚨 [CISA-2026:0922] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-85102 (secdb.nttzen.cloud/cve/detail/)
- Name: Check Point Multiple Products Improper Certificate Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Check Point
- Product: Multiple Products
- Notes: support.checkpoint.com/results ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-93616 (secdb.nttzen.cloud/cve/detail/)
- Name: Check Point Multiple Products Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Check Point
- Product: Multiple Products
- Notes: support.checkpoint.com/results ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-93952 (secdb.nttzen.cloud/cve/detail/)
- Name: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Arista
- Product: VeloCloud Orchestrator
- Notes: arista.com/en/support/advisori ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-94127 (secdb.nttzen.cloud/cve/detail/)
- Name: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: F5
- Product: BIG-IP APM
- Notes: For temporary mitigation to allow for proactive forensic triage, apply the vendor-provided iRule. Once completed, install the final vendor patch as soon as possible. For more information please see: my.f5.com/manage/s/article/K00 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260922 #cisa20260922 #cve_2026_85102 #cve_2026_93616 #cve_2026_93952 #cve_2026_94127 #cve202685102 #cve202693616 #cve202693952 #cve202694127

##

security_crawler_carl@infosec.exchange at 2026-09-22T21:31:08.000Z ##

blog.checkpoint.com/security/s

#CyberSecurity #ZeroDay #CheckPoint #Vulnerability #ActiveExploitation #PatchedOrPerish (3/3)

##

security_crawler_carl@infosec.exchange at 2026-09-22T21:31:07.000Z ##

Meanwhile a second zero-day, CVE-2026-93616, materialized in Security Management with its own handful of pinpointed hits.

Policy dictates we inform you patches now exist for both CVE-2026-85102 and CVE-2026-93616. Policy does not require we feel bad about what happens next if you ignore them. Install both immediately.

Reward: Compliance logged. Outcome: your problem. (2/3)

##

campuscodi@mastodon.social at 2026-09-22T20:02:50.000Z ##

Check Point has disclosed a zero-day (in Security Management Server) and marked an older bug also as exploited in the wild (in Site-to-Site VPN)

blog.checkpoint.com/security/s

##

cisakevtracker@mastodon.social at 2026-09-22T20:01:37.000Z ##

CVE ID: CVE-2026-85102
Vendor: Check Point
Product: Multiple Products
Date Added: 2026-09-22
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

ifin@infosec.exchange at 2026-09-22T19:56:52.000Z ##

Two Check Point critical vulnerabilities are now listed as exploited in the wild.

ifin.network/t/cve-2026-85102-

#ThreatIntel #ThreatIntelligence #IFIN

##

DailyCyberSecurity@infosec.exchange at 2026-09-22T16:11:01.000Z ##

An exploited Check Point VPN vulnerability allows remote code execution. Patch this Check Point VPN vulnerability now to block active in-the-wild attacks.

#CheckPoint #CVE202685102 #VPN #Cybersecurity #Infosec #ZeroDay

securityonline.info/checkpoint

##

CVE-2026-77322
(7.5 HIGH)

EPSS: 0.52%

updated 2026-09-22T20:34:31

1 posts

### Summary The WebSocket transport allocates a buffer from the frame payload length before validating its size, which can lead to an unauthenticated DoS. ### Details `WSConnection.Read` allocates a buffer from the declared WebSocket frame length before reading the payload (https://github.com/emiago/sipgo/blob/v1.4.0/sip/transport_ws.go#L400): ```go data := make([]byte, header.Length) // hea

thehackerwire@mastodon.social at 2026-09-22T21:02:07.000Z ##

🟠 CVE-2026-77322 - High (7.5)

SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.3, WSConnection.Read in sip/transport_ws.go creates a wsutil.Reader without setting MaxFrameSize, allowing NextFrame to accept a client-controlled header.Length before Pa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84388
(9.6 CRITICAL)

EPSS: 0.38%

updated 2026-09-22T19:09:58.680000

1 posts

A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack

1 repos

https://github.com/ShadowForge-Cyber/CVE-2026-84388-POC

CVE-2026-89275
(10.0 CRITICAL)

EPSS: 1.25%

updated 2026-09-22T18:33:43

1 posts

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

thehackerwire@mastodon.social at 2026-09-22T19:04:18.000Z ##

🔴 CVE-2026-89275 - Critical (10)

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-95675
(9.8 CRITICAL)

EPSS: 3.91%

updated 2026-09-22T15:32:43

1 posts

D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web management interface without valid credentials. Attackers can fully compromise the device to persistently modify its configuration and use it as a pivot point into the loc

1 repos

https://github.com/d6fault/CVE-2026-95675

DailyCyberSecurity@infosec.exchange at 2026-09-23T00:38:45.000Z ##

Technical details and a PoC for the D-Link DAP-1360 vulnerability (CVE-2026-95675) are public. Learn how this unauthenticated flaw impacts legacy routers.

#DLink #DAP1360 #CVE202695675 #RCE #RouterSecurity #Cybersecurity

securityonline.info/d-link-dap

##

CVE-2026-65113
(9.8 CRITICAL)

EPSS: 0.61%

updated 2026-09-22T15:32:43

1 posts

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, and information disclosure.

CVE-2026-7273
(8.8 HIGH)

EPSS: 1.29%

updated 2026-09-22T12:10:51.067000

2 posts

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

beyondmachines1@infosec.exchange at 2026-09-23T10:01:13.000Z ##

Zyxel GS1900 Switches Targeted by Chinese Threat Actor in Data Theft Campaign

Zyxel GS1900 series switches are under active exploitation by a Chinese threat actor using a high-severity buffer overflow (CVE-2026-7273) to steal sensitive data from nearly 1,000 devices worldwide. The campaign has compromised government records and relies on unpatched firmware and default credentials to gain system control.

**If you have Zyxel GS1900 series switches, make sure their management interface is isolated from the internet, accessible from trusted networks only and all default passwords are changed. Then update the firmware to version 2.90(xxxx.2)C0 or later ASAP and check the switches for signs of breach. Attackers are actively exploiting this flaw.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

jbhall56@infosec.exchange at 2026-09-22T11:48:40.000Z ##

The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow vulnerability that could result in arbitrary operating system (OS) command execution. thehackernews.com/2026/09/zyxe

##

CVE-2026-12249
(9.0 None)

EPSS: 0.14%

updated 2026-09-21T22:27:11

1 posts

An issue was discovered in Canonical ADSys upstream versions through v0.16.2. During Active Directory Certificate Services (AD CS) certificate auto-enrollment via the vendored Samba client script (internal/policies/certificate/python/vendor_samba/gp/gp_cert_auto_enroll_ext.py), ADSys utilizes a plaintext HTTP connection (http://) instead of a secure HTTPS connection (https://) to request the CA ce

beyondmachines1@infosec.exchange at 2026-09-23T09:01:13.000Z ##

Canonical Patches Critical Trust Store Poisoning Flaw in ADSys

Canonical patched a critical vulnerability (CVE-2026-12249) in ADSys that allows attackers to poison the Ubuntu system trust store by intercepting unencrypted certificate enrollment requests. This flaw enables persistent decryption of TLS traffic and full compromise of encrypted communications on affected hosts.

**If you manage Ubuntu machines connected to Active Directory through ADSys, update ADSys to version 0.16.3 or later on all of them. Oder versions fetch certificates over unencrypted HTTP and let an attacker plant a fake root certificate that exposes all encrypted traffic on the machine. After updating, check each machine's trusted certificates for any unfamiliar root certificates and remove them, since a machine that was already compromised stays exposed even after the patch.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-80521
(7.8 HIGH)

EPSS: 0.17%

updated 2026-09-21T14:17:20.193000

1 posts

In the Linux kernel, the following vulnerability has been resolved: af_unix: Unlink scc_entry in unix_del_edge(). Kyle Zeng reported that GC could free a dead SCC partially. The scenario is as follows: 1) Create two SCCs: X -. A <-> B ^--' 2) Run the following concurrently: 2-1) send() sk-B to sk-B from sk-X 2-2) close() both A and B At 2-1), there is a sm

1 repos

https://github.com/Markakd/Container_escape

guru@thecybersecguru.com at 2026-09-23T12:54:00.000Z ##

Exploit released for unpatched Ubuntu kernel flaw that lets containers root the host (CVE-2026-80521)

CVE-2026-80521 is a Linux kernel AF_UNIX use-after-free that enables container escape to host root. Ubuntu 22.04, 24.04 and 26.04 remain vulnerable

thecybersecguru.com/news/cve-2

##

CVE-2026-93958
(9.1 CRITICAL)

EPSS: 2.70%

updated 2026-09-20T03:30:31

1 posts

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.

1 repos

https://github.com/HackSpeak/CVE-2026-93958

CVE-2026-82892
(8.1 HIGH)

EPSS: 0.62%

updated 2026-09-18T21:32:35

1 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

hugovalters@mastodon.social at 2026-09-24T20:10:07.000Z ##

CVE-2026-82892: IBM Guardium Data Protection 12.2 OS command injection allows remote arbitrary command execution. CVSS 8.1, no patch yet. Isolate exposed instances now. valtersit.com/cve/CVE-2026-828 #CVE #infosec #IBM

##

CVE-2026-93485
(7.1 HIGH)

EPSS: 0.28%

updated 2026-09-18T06:32:17

1 posts

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through 6.5.10; 6.4 through 6.4.10; 6.3 through 6.3.10; 6.2 through 6.2.11; 6.1 through 6.1.1

2 repos

https://github.com/0xBlackash/CVE-2026-93485

https://github.com/HORKimhab/CVE-2026-93485

DailyCyberSecurity@infosec.exchange at 2026-09-23T12:59:52.000Z ##

Details and PoC exploit code for a critical WordPress stored XSS are public. Learn how CVE-2026-93485 enables RCE and patch WordPress today.

#WordPress #CVE202693485 #StoredXSS #RCE #Cybersecurity #Infosec

securityonline.info/wordpress-

##

CVE-2026-76460
(10.0 CRITICAL)

EPSS: 14.03%

updated 2026-09-16T21:33:00

1 posts

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized acce

1 repos

https://github.com/S3v3n-JG/CVE-2026-76460

thecybermind@infosec.exchange at 2026-09-24T09:40:51.000Z ##

(CISA TS-MAN) The Cyber Mind TSUITE Brief: CVE-2026-76460 – Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

Analyze the technical mechanics of CVE-2026-76460 with our Cisco TSUITE brief, covering Cisco ISE authentication bypass, path traversal vectors, and endpoint hardening....

thecybermind.co/9ysa

##

CVE-2026-43783
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-15T00:31:13

1 posts

A race condition was addressed with improved locking. This issue is fixed in macOS Tahoe 26.6. A malicious app may be able to gain root privileges.

1 repos

https://github.com/andrd3v/CVE-2026-43783

CVE-2026-9176
(6.7 MEDIUM)

EPSS: 0.16%

updated 2026-09-10T21:31:46

2 posts

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized access to protected resources.

_r_netsec at 2026-09-24T20:28:05.171Z ##

CVE-2026-91766: PHP had the redirect credential leak curl fixed in 2018 daubois.dev/blog/cve-2026-9176

##

_r_netsec@infosec.exchange at 2026-09-24T20:28:05.000Z ##

CVE-2026-91766: PHP had the redirect credential leak curl fixed in 2018 daubois.dev/blog/cve-2026-9176

##

CVE-2026-85103
(9.8 CRITICAL)

EPSS: 3.65%

updated 2026-09-10T04:18:18.390000

1 posts

A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.

beyondmachines1@infosec.exchange at 2026-09-24T08:01:13.000Z ##

Check Point VPN Gateways and Management Server Flaws Actively Exploited

Check Point confirmed active exploitation of three critical vulnerabilities (CVE-2026-85102, CVE-2026-85103, and CVE-2026-93616) affecting VPN gateways and management servers, prompting a 72-hour US federal remediation deadline.

**If you run Check Point Security Gateways, Spark Firewalls or Security Management Servers, patch immediately to LivePatch Take 26 or the latest Jumbo Hotfix. Older unsupported versions R80 through R81.10 must be upgraded first. Make sure the management server's web interface is reachable only from trusted internal networks. Patching isn't enough, since attackers have been active since September 12: check your VPN logs for unknown sessions and internal LDAP scanning, and if you find anything suspicious, treat the device as compromised and escalate to your incident response team.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2026-50093
(9.0 None)

EPSS: 0.32%

updated 2026-09-08T09:35:45

1 posts

A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Control V3.0 (All versions < V3.0.22.2177), Siveillance Control V4.0 (All versions < V4.0.11.2177). A vulnerability in the OIS web module allows an attacker to upload arbitrary files to the server. Successful exploitation of this

beyondmachines1@infosec.exchange at 2026-09-23T08:01:13.000Z ##

Siemens Patches Root-Level File Upload Flaw in Siveillance Control OIS Module

Siemens patched a critical root-level file upload vulnerability (CVE-2026-50093) in the Siveillance Control OIS web module that affects physical security management systems worldwide.

**If you use Siemens Siveillance Control or Control Pro, make sure all these systems are isolated from the internet and the OIS web module is reachable only from trusted internal networks. Then update right away to the fixed version for your edition.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-43499
(7.8 HIGH)

EPSS: 0.28%

updated 2026-09-08T09:35:29

1 posts

In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_requeue(). In the latter case waiter::task is not current, but remove_waiter() operates on current for the dequeue oper

100 repos

https://github.com/ankitrawatgit/iQOO-Z9_5G-vivo-T3_5G-Root-GhostLock

https://github.com/veygax/HORiZonstack

https://github.com/fusiondrive/CVE-2026-43499-ZFOLD4

https://github.com/mobilehackinglab/ghostlock-a17

https://github.com/soralis0912/CVE-2026-43499-aristotle-apk

https://github.com/Bugel/cve-2026-43499-m3q-azf1

https://github.com/oopnv70-lab/ghostlock-aak-apk

https://github.com/cuteaplane/GhostLock-for-OnePlus15T

https://github.com/1ndevelopment/ghostlock-s26

https://github.com/yijiacloud/ghostlock-cve-2026-43499-4.19-k40

https://github.com/fusiondrive/CVE-2026-43499-S24U

https://github.com/accessmodifier364/cve-2026-43499-firetv-sheldonp-writeup

https://github.com/233laoliu/mt6985-CVE-2026-43499

https://github.com/Wtrwx/smt878u-ionstack-poc

https://github.com/pimpamebanihah/cve-2026-43499-app.so

https://github.com/HORKimhab/CVE-2026-43499

https://github.com/XiaoBaiLovesStirring/ghostlock-k419-adapter

https://github.com/ccp-p/ghostlock-cve-2026-43499-4.19-k40

https://github.com/yijiacloud/GhostLock-OPPO-PCKM00

https://github.com/Petalrain224/CVE-2026-43499-Redmi-Turbo5

https://github.com/zzzxxxxxxxxxx/GhostLock-GOT-W29

https://github.com/snothin/ghostlock-s26

https://github.com/Linuxoid-cn/Mi8E5-Unlocker-by-CVE-2026-43499

https://github.com/NanoTurtle1145/root-my-s24

https://github.com/2932796375github/CVE-2026-43499_OPPO-MT6835

https://github.com/dnlid/CVE-2026-43499

https://github.com/XingChenRS/CyberMeowfiaNS

https://github.com/ctn-Qvo/CVE-2026-43499-so-build

https://github.com/xianwan1314/CVE-2026-43499-Poc-Analysis

https://github.com/Bobikl/CVE-2026-43499-T807D

https://github.com/ctn-Qvo/auto_extract_offsets

https://github.com/TheAndersMadsen/humane-aipin-ghostlock

https://github.com/SammyEnigma/CVE-2026-43499-S26

https://github.com/caspy123/CVE-2026-43499

https://github.com/JoinChang/ghostlock-oneplus

https://github.com/YuKongA/ghostlock-app

https://github.com/Colorful-glassblock/duchamp-root

https://github.com/PeronGH/ghostlock-selinux-disabler

https://github.com/joehquak/Mi8E5-Unlocker-by-CVE-2026-43499

https://github.com/yakidango-official/GhostLock-H80GT

https://github.com/0xBlackash/CVE-2026-43499

https://github.com/k-o-n-t-o-r/ghostlock-sabrina

https://github.com/hackyangwen-lgtm/rmg-s9180-fzg1

https://github.com/x-spy/CVE-2026-43499-popsicle

https://github.com/MiaPatsune/cve-2026-43499

https://github.com/oopnv70-lab/ghostlock-honor-aak

https://github.com/ReBiliBin/ghostlock-oppo-watch3pro

https://github.com/hui191/cve-2026-43499-aak-an00

https://github.com/NothingFumo/ghostlock-aresin

https://github.com/pubglite55/oppo-ghostlock

https://github.com/CatXiaoShi/cve-2026-43499

https://github.com/soralis0912/CVE-2026-43499-warhol-root

https://github.com/zenyxx-xd/RootMyVivo

https://github.com/p2p3p/GhostLock-for-OnePlus

https://github.com/knowlily/cve-2026-43499-honor

https://github.com/mumaosong/cve-2026-43499-CyberMeowfia

https://github.com/HYCQAQ/Logitech-G-Cloud-GhostLock-CVE-2026-43499

https://github.com/wxxsfxyzm/GhostLock-Galaxy

https://github.com/Thiasap/oppo-pgem10-ghostlock

https://github.com/dmcdtc/openvz-cve-patch-2026

https://github.com/tc3650/CVE-2026-43499-armv7

https://github.com/inforcqb/CVE-2026-43499-pja110

https://github.com/Linuxoid-cn/CVE-2026-43499-Poc-Analysis

https://github.com/boxiaolanya2008/CVE-2026-43499-Neo11Plus

https://github.com/hybLOVE/iqoo-temp-root

https://github.com/huaguiqi/asus-i005-cve-2026-43499

https://github.com/BuSung-dev/Root-My-Galaxy

https://github.com/onesmiledx/CVE-2026-43499

https://github.com/dorlow/hazel-cve-2026-43499

https://github.com/woshimaniubi8/CVE-2026-43499-root-KernelSU

https://github.com/No-22-Github/UnPlus

https://github.com/gitchw/ghostlock-cve-2026-43499

https://github.com/justsoman/CVE-2026-43499-jinghu

https://github.com/zhubaohe123/ghostlock-kit

https://github.com/oopnv70-lab/ghostlock-apk

https://github.com/gagaltotal/CVE-2026-43499-PoC-Scanner

https://github.com/Bartixxx32/CVE-2026-43499-OnePlus15

https://github.com/MobiusM/CVE-2026-43499

https://github.com/R0rt1z2/GhostLock

https://github.com/Cxyofficial/x200-cve-2026-43499

https://github.com/fusiondrive/CVE-2026-43499-A36

https://github.com/fancyzll/CVE-2026-43499_OPPO-MT6835

https://github.com/jason5545/ghostlock-myron-tw

https://github.com/xiaohj233/ghostlock-x200-root

https://github.com/eroorvbsyes-hotmail/CVE-2026-43499_x86_Exploit

https://github.com/sarabpal-dev/IonStack-S22U

https://github.com/sorrow404Null/CVE-2026-43499-RMX5200

https://github.com/WitAqua-tools/Root-My-Device

https://github.com/Meowkis/tcp-zerocopy-sm

https://github.com/CakesTwix/Android-CVE-2026-43499

https://github.com/Bailan766/rmx3888-cve-2026-43499-config

https://github.com/xrzcc/s26-m1q-ghostlock-selinux

https://github.com/datfooldive/ghostlock-emerald

https://github.com/lkeld/CVE-2026-43499-poc

https://github.com/alex193a/Root-My-Pixel

https://github.com/slapah/ghostlock-h8q

https://github.com/soralis0912/CVE-2026-43499-pmg110-root

https://github.com/wzhdgithub/GhostLock

https://github.com/BuSung-dev/CVE-2026-43499-S25U

https://github.com/soralis0912/CVE-2026-43499-aristotle

CVE-2026-86296
(10.0 CRITICAL)

EPSS: 1.44%

updated 2026-09-07T12:30:36

4 posts

A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

hackmag@infosec.exchange at 2026-09-24T15:30:26.000Z ##

⚪️ D-Link Warns of Unpatched Zero-Day Flaw in DIR-822A Routers

🗨️ D-Link has warned of a critical zero-day vulnerability (CVE-2026-86296) affecting end-of-life DIR-822A dual-band routers. The issue allows an unauthenticated local attacker to cause a denial of service in the DHCP service or achieve remote code execution. No patch is currently…

🔗 hackmag.com/news/d-link-0days?

#news

##

DailyCyberSecurity@infosec.exchange at 2026-09-23T13:31:12.000Z ##

Discover the critical CVE-2026-86296 vulnerability in D-Link DIR-822A routers. Learn how this DHCP flaw allows attackers to execute arbitrary code locally.

#DLink #RouterSecurity #CVE #CyberSecurity #TechNews

meterpreter.org/dlink-dir-822a

##

campuscodi@mastodon.social at 2026-09-22T13:25:37.000Z ##

D-Link warns of two major bugs with public POCs

CVE-2026-86296: supportannouncement.us.dlink.c

POC: tzh00203.notion.site/D-Link-DI

CVE-2026-93958: supportannouncement.us.dlink.c

POC: github.com/FoundTL/D-Link-R95-

##

oversecurity@mastodon.social at 2026-09-22T13:20:34.000Z ##

D-Link warns of max severity zero-day bug in DIR-822A routers

D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch,...

🔗️ [Bleepingcomputer] link.is.it/hXngI9

##

CVE-2026-78306(CVSS UNKNOWN)

EPSS: 0.23%

updated 2026-08-24T09:33:52

1 posts

DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, including the SSID, PSK, MAC address, regulatory country code, and wireless channel. An attacker can overwrite the Wi-Fi PSK with a known value and connect to the drone's internal Wi-Fi network, potentially gaining access to the flight

2 repos

https://github.com/FEEDBEEF/Dji_ble_vuln

https://github.com/Wh02m1/CVE-2026-78306

DailyCyberSecurity@infosec.exchange at 2026-09-23T14:45:15.000Z ##

The DJI Bluetooth vulnerability CVE-2026-78306 lets a nearby attacker send unauthenticated DUML commands to 16 drone models. Update firmware now.

#DJI #CVE202678306 #Bluetooth #DroneSecurity #DUML #CyberSecurity

meterpreter.org/dji-bluetooth-

##

CVE-2026-59310
(9.8 CRITICAL)

EPSS: 2.56%

updated 2026-08-19T04:17:24.940000

1 posts

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

2 repos

https://github.com/HORKimhab/CVE-2026-59310

https://github.com/BiuTrap/CVE-2026-59310

christopherkunz@chaos.social at 2026-09-23T13:06:38.000Z ##

@nyanbinary @cR0w here's one
(from the writeup to CVE-2026-59310 from July/August).
Point at the variables in the picture that traversed your path inappropriately...
mobeta.fr/blog/vcenter-cve-202

##

CVE-2026-55040
(9.1 CRITICAL)

EPSS: 17.54%

updated 2026-08-19T04:17:23.540000

1 posts

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

Nuclei template

5 repos

https://github.com/virologi-info/mssharepoint-scanner

https://github.com/l0ggg/CVE-2026-55040

https://github.com/maxprog-svg/CVE-2026-55040-Mass-Exploit

https://github.com/sfewer-r7/CVE-2026-55040

https://github.com/zenzue/CVE-2026-55040

CVE-2026-33824
(9.8 CRITICAL)

EPSS: 1.62%

updated 2026-08-18T18:31:46

1 posts

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

2 repos

https://github.com/kaleth4/CVE-2026-33824

https://github.com/EpSiLoNPoInTOrI/IKEV2-POC

CVE-2026-46345
(8.4 HIGH)

EPSS: 0.20%

updated 2026-08-17T17:54:44

1 posts

**Relevant Products/Components:** * `trestle/core/commands/author/jinja.py` * `trestle author jinja` --- ## Detailed Description: The `-o/--output` argument in `trestle author jinja` allows writing files outside the intended workspace. The application does not properly validate: * `../` * `..\` * absolute paths This allows arbitrary file write to attacker-controlled locations. Vulnerable c

EUVD_Bot@mastodon.social at 2026-09-24T21:03:06.000Z ##

🚨 EUVD-2026-66225

📊 Score: 7.7/10 (CVSS v3.1)
📦 Product: compliance-trestle, compliance-trestle
🏢 Vendor: oscal-compass
📅 Updated: 2026-09-24

📝 Trestle is vulnerable to arbitrary file write via path traversal in author generate commands (Incomplete fix of CVE-2026-46345)

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2026-68820
(7.0 HIGH)

EPSS: 0.33%

updated 2026-08-16T19:17:24.183000

1 posts

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

4 repos

https://github.com/maxprog-svg/CVE-2026-68820_Mass_Exploit

https://github.com/fevar54/CVE-2026-68820-Mitigation-PoC-

https://github.com/ubitquity/Windows-WinSock-UAF-Mitigation

https://github.com/HORKimhab/CVE-2026-68820

CVE-2026-65660
(6.5 MEDIUM)

EPSS: 1.19%

updated 2026-08-11T18:31:43

4 posts

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

oversecurity@mastodon.social at 2026-09-23T10:20:31.000Z ##

Microsoft Upgrades SharePoint Flaw From Spoofing to 8.8 RCE

A SharePoint Server vulnerability tracked as CVE-2026-65660 turned out to be far more serious than Microsoft first indicated. The company

🔗️ [Thecyberexpress] link.is.it/qUvtLM

##

obivan@infosec.exchange at 2026-09-23T08:53:09.000Z ##

SharePoint CVE-2026-65660: From Anonymous Access to Pre-Auth RCE via EditingPageParser Type-Check Bypass blog.viettelcybersecurity.com/

##

guru@thecybersecguru.com at 2026-09-22T14:06:40.000Z ##

Microsoft Called CVE-2026-65660 a Spoofing Bug. It’s an Authenticated SharePoint RCE

CVE-2026-65660 is an authenticated SharePoint RCE, not just spoofing. Learn about the ToolPane flaw, XAML exploit chain, affected versions, and fixes

thecybersecguru.com/news/cve-2

##

cyberworldops@infosec.exchange at 2026-09-22T12:50:01.000Z ##

CVE-2026-65660 reportedly enables authenticated, low-privilege attackers to execute arbitrary code remotely on SharePoint Server. Its initial spoofing classification makes accurate advisory tracking and impact reassessment especially important. #SharePointSecurity #VulnerabilityManagement #ThreatIntelligence

cyberworldops.eu/en/sharepoint

##

cyberworldops@infosec.exchange at 2026-09-24T19:00:01.000Z ##

CISA added CVE-2026-63077 to the KEV catalog after confirming active exploitation in ransomware operations. The flaw allows unauthenticated RCE on JetBrains TeamCity via the agent-polling protocol, putting internet-exposed build infrastructure at direct risk. #TeamCity #Ransomware #InfoSec

cyberworldops.eu/en/exploited-

##

offseq@infosec.exchange at 2026-09-24T12:00:26.000Z ##

CVE-2026-63077 (CRITICAL): JetBrains TeamCity auth bypass lets unauthenticated attackers run OS commands. Ransomware gangs are actively exploiting this flaw. Patch to 2025.11.7/2026.1.3 or restrict access ASAP. Details: radar.offseq.com/threat/cisa-r #OffSeq #TeamCity #CVE202663077 #Infosec

##

kev_Stalker@infosec.exchange at 2026-09-23T19:19:31.000Z ##

CVE-2026-63077 - Changed to Known Ransomware Status

JetBrains TeamCity Deserialization of Untrusted Data VulnerabilityVendor: JetBrainsProduct: TeamCityJetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 23, 2026 at 14:08:17 UTCDate Added nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-15830
(5.3 MEDIUM)

EPSS: 0.76%

updated 2026-08-04T18:31:31

1 posts

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spa

djangonews@mastodon.social at 2026-09-23T23:00:08.000Z ##

Django Fellow Report - Jacob

Jacob reviewed six Django pull requests and authored changes covering GEOS 3.10 support removal and expanded WKT depth-check coverage related to CVE-2026-15830. He also worked on security reports and Django coordination...

forum.djangoproject.com/t/djan

##

CVE-2026-59309
(9.8 CRITICAL)

EPSS: 0.61%

updated 2026-07-30T15:31:54

1 posts

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

christopherkunz@chaos.social at 2026-09-23T13:06:38.000Z ##

@nyanbinary @cR0w here's one
(from the writeup to CVE-2026-59310 from July/August).
Point at the variables in the picture that traversed your path inappropriately...
mobeta.fr/blog/vcenter-cve-202

##

CVE-2025-68686
(5.9 MEDIUM)

EPSS: 29.60%

updated 2026-07-27T18:31:25

1 posts

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases

CVE-2026-48842
(8.1 HIGH)

EPSS: 0.89%

updated 2026-07-24T10:10:00.197000

1 posts

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

CVE-2026-50522
(9.8 CRITICAL)

EPSS: 3.04%

updated 2026-07-23T15:44:10.873000

1 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

5 repos

https://github.com/4minx/CVE-2026-50522

https://github.com/ChPratik/CVE-2026-50522

https://github.com/darses/CVE-2026-50522

https://github.com/WismanSec/sharepoint-2026-poc

https://github.com/HORKimhab/CVE-2026-50522

CVE-2026-49972
(8.8 HIGH)

EPSS: 1.08%

updated 2026-07-15T19:17:24.827000

1 posts

Laravel-Mediable before 7.0.0 contains a file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading a file with an embedded PHP extension disguised within a double extension such as shell.php.jpg. The PATHINFO_FILENAME extraction preserves the inner .php extension in the base name, and on misconfigured Apache or nginx servers that execute any file

thehackerwire@mastodon.social at 2026-09-23T23:02:06.000Z ##

🔴 CVE-2026-93352 - Critical (9.8)

Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist introduced to address CVE-2026-49972 includes p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-68788
(0 None)

EPSS: 0.21%

updated 2026-07-14T13:18:00.363000

1 posts

In the Linux kernel, the following vulnerability has been resolved: fsnotify: do not generate ACCESS/MODIFY events on child for special files inotify/fanotify do not allow users with no read access to a file to subscribe to events (e.g. IN_ACCESS/IN_MODIFY), but they do allow the same user to subscribe for watching events on children when the user has access to the parent directory (e.g. /dev).

sayzard@mastodon.sayzard.org at 2026-09-24T23:38:34.000Z ##

Decades-old file security flaws found in Android, Linux, macOS, and Windows

TU Graz 연구진이 Linux, Android, Windows, macOS의 파일 변경 알림 서브시스템에서 수십 년간 존재한 사이드채널 정보 유출을 발견했다. 공격자는 파일 내용이나 직접 읽기 권한 없이도 이벤트의 파일명·경로·타이밍을 관찰해 키 입력, 방문 웹사이트, 인증 프롬프트 등의 활동을 추론할 수 있다. Linux inotify 관련 CVE-2025-68788은 일부 커널 버전에서 /dev 특수 파일의 a...

theregister.com/security/2026/

##

CVE-2026-45659
(8.8 HIGH)

EPSS: 2.70%

updated 2026-07-01T21:35:53

1 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

2 repos

https://github.com/WismanSec/sharepoint-2026-poc

https://github.com/HORKimhab/CVE-2026-45659

CVE-2026-23239
(7.8 HIGH)

EPSS: 0.10%

updated 2026-06-17T10:21:09.960000

2 posts

In the Linux kernel, the following vulnerability has been resolved: espintcp: Fix race condition in espintcp_close() This issue was discovered during a code audit. After cancel_work_sync() is called from espintcp_close(), espintcp_tx_work() can still be scheduled from paths such as the Delayed ACK handler or ksoftirqd. As a result, the espintcp_tx_work() worker may dereference a freed espintcp

DailyCyberSecurity at 2026-09-25T00:20:58.573Z ##

RustyTux is a public PoC for a Linux kernel privilege escalation via an ESP-in-TCP use-after-free (CVE-2026-23239). Details and exploit code are now public.

securityonline.info/rustytux-l

##

DailyCyberSecurity@infosec.exchange at 2026-09-25T00:20:58.000Z ##

RustyTux is a public PoC for a Linux kernel privilege escalation via an ESP-in-TCP use-after-free (CVE-2026-23239). Details and exploit code are now public.

#RustyTux #LinuxKernel #PrivilegeEscalation #UseAfterFree #espintcp #LPE #PoC #CVE202623239

securityonline.info/rustytux-l

##

CVE-2024-0244
(9.8 CRITICAL)

EPSS: 1.38%

updated 2026-06-17T06:53:04.567000

1 posts

Buffer overflow in CPCA PCFAX number process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS MF750C Series/Color imageCLASS X MF1333C firmware v03.07 and earlier sold in US. i-SEN

thezdi@infosec.exchange at 2026-09-23T19:09:09.000Z ##

CVE-2024-0244: Connor Ford details how he exploited the #Canon MF753Cdw printer back when he was a #Pwn2Own contestant. Now he's on the judging side as a ZDI analyst, but Doom is still on the table. zerodayinitiative.com/blog/202

##

CVE-2020-4428
(9.1 CRITICAL)

EPSS: 61.69%

updated 2026-06-17T03:19:58.553000

1 posts

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Force ID: 180533.

CVE-2026-46439
(7.8 HIGH)

EPSS: 0.27%

updated 2026-05-28T19:01:39

1 posts

A High severity Server-Side Template Injection (SSTI) vulnerability exists in the `trestle author jinja` command. The command recursively evaluates rendered templates, allowing an attacker to achieve arbitrary command execution with privileges of the running process by injecting malicious payloads into data fields (such as SSP documents or Lookup Tables). **The vulnerability does not require atta

EUVD_Bot@mastodon.social at 2026-09-24T21:03:07.000Z ##

🚨 EUVD-2026-66211

📊 Score: 7.8/10 (CVSS v3.1)
📦 Product: compliance-trestle, compliance-trestle
🏢 Vendor: oscal-compass
📅 Updated: 2026-09-24

📝 Trestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439)

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2026-41091
(7.8 HIGH)

EPSS: 0.44%

updated 2026-05-20T18:31:35

1 posts

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

4 repos

https://github.com/tc4dy/CVE-2026-41091-PoC-Exploit

https://github.com/s4m98/RedSun-

https://github.com/ridhinva/defender-privilege-escalation-scanner

https://github.com/0xBlackash/CVE-2026-41091

CVE-2026-21513
(8.8 HIGH)

EPSS: 15.64%

updated 2026-03-27T21:32:39

1 posts

Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-21525
(6.2 MEDIUM)

EPSS: 4.80%

updated 2026-03-27T21:31:32

1 posts

Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.

CVE-2026-21519
(7.8 HIGH)

EPSS: 2.46%

updated 2026-02-10T21:31:29

1 posts

Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

CVE-2020-4427
(9.8 CRITICAL)

EPSS: 70.03%

updated 2025-11-04T00:30:30

1 posts

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. IBM X-Force ID: 180532.

Nuclei template

CVE-2025-4632
(9.8 CRITICAL)

EPSS: 24.30%

updated 2025-10-22T00:34:22

1 posts

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.

2 repos

https://github.com/MantisToboggan-git/CVE-2025-4632-POC

https://github.com/digitalsurgn/CVE-2025-4632_POC

undercodenews@mastodon.social at 2026-09-24T21:37:50.000Z ##

Samsung MagicINFO Flaw Leads to a “Silent” Monero Miner — Attackers Turn a Compromised Endpoint Into Their Own Mining Rig

A previously disclosed Samsung MagicINFO vulnerability has been used in a real-world intrusion that went far beyond simple unauthorized access. Huntress researchers found attackers exploiting CVE-2025-4632, installing AnyDesk for remote access, creating a local administrator account, weakening Microsoft Defender protections, and ultimately compiling…

undercodenews.com/samsung-magi

##

CVE-2023-48788
(9.8 CRITICAL)

EPSS: 98.45%

updated 2025-10-22T00:34:05

1 posts

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.

Nuclei template

1 repos

https://github.com/horizon3ai/CVE-2023-48788

CVE-2023-20118
(7.2 HIGH)

EPSS: 54.11%

updated 2025-10-22T00:33:50

2 posts

A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to improper validation of user input within incoming HTTP packets. An attacker could exploit this vulnerability by sending a crafted

oversecurity@mastodon.social at 2026-09-23T10:39:29.000Z ##

PolarEdge: Unveiling an uncovered ORB network

Discover PolarEdge, a newly identified botnet targeting edge devices via CVE-2023-20118, using a stealthy TLS backdoor.

🔗️ [Sekoia] link.is.it/PmRTZ9

##

oversecurity@mastodon.social at 2026-09-23T10:38:41.000Z ##

PolarEdge: Unveiling an uncovered ORB network

Discover PolarEdge, a newly identified botnet targeting edge devices via CVE-2023-20118, using a stealthy TLS backdoor.

🔗️ [Sekoia] link.is.it/PmRTZ9

##

CVE-2022-42475
(9.8 CRITICAL)

EPSS: 99.47%

updated 2025-10-22T00:32:38

1 posts

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

Nuclei template

9 repos

https://github.com/uLl0a/cve-2022-42475-poc

https://github.com/scrt/cve-2022-42475

https://github.com/Mustafa1986/cve-2022-42475-Fortinet

https://github.com/Amir-hy/cve-2022-42475

https://github.com/0xhaggis/CVE-2022-42475

https://github.com/P4x1s/CVE-2022-42475-RCE-POC

https://github.com/bryanster/ioc-cve-2022-42475

https://github.com/ArthurHendrich/CVE-2022-42475-POC

https://github.com/natceil/cve-2022-42475

CVE-2021-44168
(7.8 HIGH)

EPSS: 0.87%

updated 2025-10-22T00:32:27

1 posts

A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially crafted update packages.

1 repos

https://github.com/0xhaggis/CVE-2021-44168

CVE-2024-20260
(8.6 HIGH)

EPSS: 0.59%

updated 2024-10-23T18:33:16

1 posts

A vulnerability in the VPN and management web servers of the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv), formerly Cisco Firepower Threat Defense Virtual, platforms could allow an unauthenticated, remote attacker to cause the virtual devices to run out of system memory, which could cause SSL VPN connection processing to slow down and eve

AAKL@infosec.exchange at 2026-09-23T15:33:07.000Z ##

Broadcom has a long list of advisories addressing some critical vulnerabilities, among others support.broadcom.com/web/ecx/s #Broadcom

Cisco:

This addresses high-severity CVE-2024-20260, first published in October.

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

CVE-2026-61821
(0 None)

EPSS: 0.38%

1 posts

N/A

hugovalters@mastodon.social at 2026-09-24T21:40:03.000Z ##

CVE-2026-61821 pg_partman: drop_partition_id/time allow privilege escalation to superuser via retention_schema. CVSS 8.5, unpatched. patch to 5.5.0 now valtersit.com/cve/CVE-2026-618 #CVE #infosec #PostgreSQL

##

CVE-2026-96883
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-24T20:30:51.000Z ##

🟠 CVE-2026-96883 - High (8.8)

pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to execute arbitrary code as the postgres operating system user via crafted SQL stateme...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-24T20:30:51.000Z ##

🟠 CVE-2026-96883 - High (8.8)

pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to execute arbitrary code as the postgres operating system user via crafted SQL stateme...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91766
(0 None)

EPSS: 0.00%

2 posts

N/A

_r_netsec at 2026-09-24T20:28:05.171Z ##

CVE-2026-91766: PHP had the redirect credential leak curl fixed in 2018 daubois.dev/blog/cve-2026-9176

##

_r_netsec@infosec.exchange at 2026-09-24T20:28:05.000Z ##

CVE-2026-91766: PHP had the redirect credential leak curl fixed in 2018 daubois.dev/blog/cve-2026-9176

##

threatcodex@infosec.exchange at 2026-09-24T17:18:06.000Z ##

CVE-2026-87902: Attackers Started Probing WordPress Sites Hours After the Patch
#CVE_2026_87902
patchstack.com/articles/cve-20

##

security_crawler_carl@infosec.exchange at 2026-09-24T14:29:50.000Z ##

🏆 New Achievement! The Court Finds Your Server Guilty!

This tribunal has reviewed the evidence. CVE-2026-87902 — an unauthenticated path traversal flaw scoring 9.2 out of 10 — was discovered by researcher Robert Ressl and patched in WordPress 7.1.2. Attackers began probing within five hours of that patch dropping. Exhibit A: Patchstack logged the first malicious requests at 17:44 UTC on September 22. (1/3)

##

youranonnewsirc@nerdculture.de at 2026-09-24T10:26:17.000Z ##

Cybersecurity faces immediate threats as a critical WordPress vulnerability (CVE-2026-87902) was exploited post-disclosure (Sept 24). Ransomware attacks reached a record high in August 2026, marking a significant surge. On the technology front, Meta Connect 2026 showcased key advancements in AI and virtual reality. Geopolitically, the Ukraine war persists, with President Zelensky expressing hope for peace before winter amidst ongoing US-Iran tensions.

#Cybersecurity #TechNews #Geopolitics

##

cyberworldops@infosec.exchange at 2026-09-24T08:30:00.000Z ##

Unauthenticated LFI in WordPress page-template resolution (CVE-2026-87902, CVSS 9.2) is being exploited in the wild. Under specific server and theme conditions it escalates to RCE, enabling full site compromise. Patch and review exposure immediately. #WordPress #InfoSec #RemoteCodeExecution

cyberworldops.eu/en/attackers-

##

oversecurity@mastodon.social at 2026-09-23T19:00:44.000Z ##

Hackers start exploiting critical WordPress flaw for code execution

Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell...

🔗️ [Bleepingcomputer] link.is.it/xdsXDB

##

DarkWebInformer@infosec.exchange at 2026-09-23T18:52:55.000Z ##

🚨[POC] CVE-2026-87902: WordPress Core versions up to and including 7.1.1 are affected by a Local File Inclusion vulnerability in the locate_template() function.

GitHub: github.com/abraxas/CVE-2026-87

Credit: @abraxas_null (X)

##

DailyCyberSecurity@infosec.exchange at 2026-09-23T15:02:03.000Z ##

An exploited WordPress RCE vulnerability (CVE-2026-87902) is under attack. Details and PoC exploit code are public. Patch your sites now.

#WordPress #CVE202687902 #RCE #Cybersecurity #Infosec #ZeroDay

securityonline.info/exploited-

##

obivan@infosec.exchange at 2026-09-23T08:47:19.000Z ##

WordPress unauthenticated LFI to RCE PoC github.com/dinosn/cve-2026-879

##

appinn@m.cmx.im at 2026-09-23T04:13:48.000Z ##

新内容:《WordPress 爆出 9.2 分严重安全漏洞|CVE-2026-87902》
appinn.com/wordpress-cve-2026-
2026年9月23日,WordPress 爆出 9.2 分的严重安全漏洞,攻击者无需登录即可在服务器上运行代码。漏洞编号 CVE-2026-87902,请务必升级至最新版本 7.1.2。@appinn 根据 W3Techs 2026 年 9 月 22 日的最新统计,全球约 40.2% 的网站都在使用

##

technotenshi@infosec.exchange at 2026-09-22T21:07:41.000Z ##

WordPress patched a critical unauthenticated path traversal vulnerability (CVE-2026-87902, GHSA-7hp8-65ch-5whp, CVSS 9.2) in its page-template resolution function get_page_template(), discovered and responsibly disclosed by Robert Ressl. Under specific preconditions, such as an active theme with a top level directory starting with "page-" and a readable local PHP file usable for the pearcmd.php PEAR RCE chain, an attacker could achieve remote code execution with no authentication. WordPress 7.1.2 fixes the issue, and the patch has been backported to every supported branch back to 4.7.37, so all sites should update immediately.

github.com/WordPress/wordpress

#InfoSec #WordPress #Vulnerability #CVE

##

DailyCyberSecurity@infosec.exchange at 2026-09-22T15:47:49.000Z ##

WordPress 7.1.2 patches a critical WordPress RCE vulnerability (CVE-2026-87902). Update your site to prevent conditional remote code execution.

#WordPress #CVE202687902 #RCE #Cybersecurity #Infosec #WordPressSecurity

securityonline.info/wordpress-

##

cyberia@mast.eu.org at 2026-09-22T15:30:11.000Z ##

Service notice: all hosted/maintained WP websites have been updated to the latest minor version of your current major branch (security release, CVE-2026-87902). No action needed from you!

I don't host or maintain your website? Be sure to update your WordPress ASAP. This one is critical.

Release notes → wordpress.org/news/2026/09/wor

#WordPress #Security #Critical #Cyberia

##

CVE-2026-63203
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-24T16:48:49.000Z ##

🟠 CVE-2026-63203 - High (7.6)

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.31.0 until 1.42.0, the Account API handlers in packages/core/src/routes/account/third-party-tokens.ts allow a caller holding a same-user access token with only the o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77581
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-24T16:48:39.000Z ##

🟠 CVE-2026-77581 - High (8.6)

BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, the certificate and timestamp CORS proxy in cloudflare/cors-proxy-worker.js uses isPrivateOrReservedHost() to validate a supplied hostname separately from the DNS r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

beyondmachines1@infosec.exchange at 2026-09-24T10:01:13.000Z ##

Vercel Patches Critical Remote Code Execution Vulnerability in Next.js Image Generation Feature

Vercel patched a critical vulnerability (CVE-2026-94545) in Next.js that allows remote code execution through the ImageResponse feature. The flaw involves improper input escaping in the Satori library when processing SVG content on the Node.js runtime.

**If your web apps run Next.js 16 (versions 16.2.0 to 16.3.5), update to 16.3.6 ASAP. Don't rely on dependency scanners to flag this one, because they may miss it. If you can't update right away, make sure your developers sanitize up all user input before it reaches the social preview image feature (ImageResponse).**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

DailyCyberSecurity@infosec.exchange at 2026-09-23T07:55:06.000Z ##

Vercel fixed a critical Next.js RCE vulnerability in image generation. Update to patch this Next.js RCE vulnerability and secure your apps.

#Nextjs #CVE202694545 #RCE #Cybersecurity #WebSecurity #Vulnerability

securityonline.info/nextjs-rce

##

CVE-2026-84739
(0 None)

EPSS: 0.00%

1 posts

N/A

bearstech@mamot.fr at 2026-09-24T09:45:00.000Z ##

Toutes nos instances GitLab sont à jour en version 19.4.1 depuis hier soir à 22h.

Il faut mettre à jour rapidement : cette nouvelle version corrige 2 CVE évaluées à 9,9 (CVE-2026-93577 et CVE-2026-84739).

En savoir plus sur nos offres 👇
gitlab-saas.bearstech.com/

##

CVE-2026-96419
(0 None)

EPSS: 0.00%

1 posts

N/A

linuxmint_hun@mastodon.social at 2026-09-24T06:46:10.000Z ##

Megjelent a Wireshark 4.6.9, amely 19 sebezhetőséget és több kritikus összeomlást, végtelen ciklust és memóriaszivárgást javít. Aggódsz, hogy a profilimportálás (CVE-2026-96419) akár kódfuttatást is lehetővé tehetett — frissítettél már? Nézd meg a részleteket és a javítások listáját!

linuxmint.hu/hir/2026/09/a-wir

#Wireshark #CVE2026-96419 #Sharkd #ZigBee #IEEE80211 #LoRaWAN #QUIC #SMB #pcapng #hálózat #sebezhetőség #biztonság

##

CVE-2026-78902
(0 None)

EPSS: 0.00%

1 posts

N/A

CVE-2026-67231
(0 None)

EPSS: 0.25%

1 posts

N/A

offseq@infosec.exchange at 2026-09-24T04:30:23.000Z ##

CVE-2026-67231: Critical flaw in rabbitmq-server trust-store plugin (CVSS 9.1) lets attackers bypass TLS client auth with forged certs if they know whitelisted issuer/serial. Patch or disable plugin ASAP. radar.offseq.com/threat/cve-20 #OffSeq #RabbitMQ #Vuln #TLS #InfoSec

##

CVE-2026-88804
(0 None)

EPSS: 0.00%

1 posts

N/A

DailyCyberSecurity@infosec.exchange at 2026-09-24T02:50:37.000Z ##

A critical Rancher XSS vulnerability tracked as CVE-2026-88804 exposes admin sessions. Update your clusters immediately to prevent system compromise.

#Rancher #Kubernetes #CVE202688804 #XSS #Cybersecurity #Infosec

securityonline.info/rancher-xs

##

CVE-2026-69184
(0 None)

EPSS: 0.68%

1 posts

N/A

hugovalters@mastodon.social at 2026-09-23T20:40:13.000Z ##

CVE-2026-69184 c-ares memory corruption, CVSS 7.5. Malicious DNS server can stall any app using the resolver via crafted compression pointers. Patch to 1.34.7 now. valtersit.com/cve/CVE-2026-691 #CVE #infosec #cybersecurity

##

CVE-2024-85880
(0 None)

EPSS: 0.00%

1 posts

N/A

security_crawler_carl@infosec.exchange at 2026-09-23T04:54:36.000Z ##

🏆 New Achievement! Triple Threat, Zero Regrets!

PATCH NOTES v0.0.0 — KNOWN ISSUES: A China-aligned threat group has successfully shipped a three-zero-day exploit chain targeting Google Chrome and Microsoft Windows. ADDED: coordinated weaponization across CVE-2024-85046, CVE-2024-87491, and CVE-2024-85880. FIXED: nothing on your end, apparently. DEPRECATED: the assumption that one vendor's unpatched flaw is somebody else's problem. (1/2)

##

CVE-2024-85046
(0 None)

EPSS: 0.00%

1 posts

N/A

security_crawler_carl@infosec.exchange at 2026-09-23T04:54:36.000Z ##

🏆 New Achievement! Triple Threat, Zero Regrets!

PATCH NOTES v0.0.0 — KNOWN ISSUES: A China-aligned threat group has successfully shipped a three-zero-day exploit chain targeting Google Chrome and Microsoft Windows. ADDED: coordinated weaponization across CVE-2024-85046, CVE-2024-87491, and CVE-2024-85880. FIXED: nothing on your end, apparently. DEPRECATED: the assumption that one vendor's unpatched flaw is somebody else's problem. (1/2)

##

CVE-2024-87491
(0 None)

EPSS: 0.00%

1 posts

N/A

security_crawler_carl@infosec.exchange at 2026-09-23T04:54:36.000Z ##

🏆 New Achievement! Triple Threat, Zero Regrets!

PATCH NOTES v0.0.0 — KNOWN ISSUES: A China-aligned threat group has successfully shipped a three-zero-day exploit chain targeting Google Chrome and Microsoft Windows. ADDED: coordinated weaponization across CVE-2024-85046, CVE-2024-87491, and CVE-2024-85880. FIXED: nothing on your end, apparently. DEPRECATED: the assumption that one vendor's unpatched flaw is somebody else's problem. (1/2)

##

CVE-2026-89090
(0 None)

EPSS: 0.52%

1 posts

N/A

awssecurityfeed@infosec.exchange at 2026-09-22T20:00:01.000Z ##

CVE-2026-89090 - Denial of service in the event stream header decoder in AWS SDK for Go v2

Bulletin ID: 2026-110-AWS

Scope: AWS

Content Type: Important (requires attention)

Publication Date: 09/11/2026 10:00 AM PDT
Description:
An issue exists in the the EventStream header decoder in AWS SDK for Go v2 in versio...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-85279
(0 None)

EPSS: 0.21%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-22T19:04:28.000Z ##

🟠 CVE-2026-85279 - High (8.6)

Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ contains a stack buffer overflow in PluginsManager::loadPluginFromPath in PowerEditor/src/MISC/PluginsManager/PluginsManager.cpp because the plugin-supplied GetLexer...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites