## Updated at UTC 2026-10-02T05:56:36.126696

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-96658 9.9 0.00% 3 0 2026-10-02T04:18:09.757000 A flaw was found in Foreman. An authenticated attacker with low-level permission
CVE-2026-47593 7.8 0.18% 1 0 2026-10-02T04:18:08.737000 NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mod
CVE-2026-47592 7.8 0.19% 1 0 2026-10-02T04:18:08.560000 NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the
CVE-2026-14378 9.8 0.00% 2 2 2026-10-02T04:18:06.277000 The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leadi
CVE-2026-14157 0 0.00% 1 0 2026-10-02T04:18:06.140000 Use of an Externally Controlled Format String in the ASUS Router modules allow a
CVE-2026-104286 9.8 0.00% 21 1 2026-10-02T04:18:04.950000 An improper limitation of a pathname to a restricted directory ('path traversal'
CVE-2026-104480 0 0.00% 2 0 2026-10-02T02:17:02.007000 Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resu
CVE-2026-103098 7.5 0.00% 2 0 2026-10-02T01:16:43.193000 Transmission of a sensitive key in the URL over an unencrypted HTTP connection. 
CVE-2026-103097 7.5 0.00% 2 0 2026-10-02T01:16:43.070000 An API key is hardcoded and retrievable from the application package. Since Andr
CVE-2026-103096 7.5 0.00% 2 0 2026-10-02T01:16:42.930000 API key is hardcoded and retrievable from the application package. Since Android
CVE-2026-12540 8.2 0.00% 2 0 2026-10-02T00:32:33 A flaw was found in Foreman. A command injection vulnerability exists in the for
CVE-2026-86345 9.0 0.00% 4 0 2026-10-02T00:31:40 A flaw was found in 389-ds-base. The server does not discard plaintext bytes alr
CVE-2026-103765 9.4 0.00% 2 0 2026-10-02T00:31:39 Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in
CVE-2026-103764 9.8 0.00% 4 0 2026-10-02T00:31:39 Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference
CVE-2026-86344 7.5 0.00% 2 0 2026-10-02T00:31:39 A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a c
CVE-2026-103761 7.5 0.00% 2 0 2026-10-02T00:31:39 Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulne
CVE-2026-104051 8.2 0.00% 2 0 2026-10-02T00:31:33 PictShare before 3.7.1 contains an information disclosure vulnerability that all
CVE-2026-96659 9.1 0.00% 1 0 2026-10-02T00:17:04.627000 A flaw was found in Foreman. This vulnerability allows an authenticated user wit
CVE-2026-104018 8.8 0.00% 2 0 2026-10-01T21:33:58 An improper privilege management vulnerability (CWE-269) exists in the command s
CVE-2026-104057 7.5 0.00% 2 0 2026-10-01T21:33:02 Podgrab contains an unauthenticated denial-of-service vulnerability caused by un
CVE-2026-63292 7.5 0.00% 2 0 2026-10-01T21:17:23.610000 Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apa
CVE-2026-97662 8.2 0.00% 2 0 2026-10-01T20:36:52.220000 An argument injection issue in the diff scan operation in AWS security-agent-mcp
CVE-2026-12627 9.8 0.00% 2 0 2026-10-01T20:34:26.287000 Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer ove
CVE-2026-14316 8.1 0.00% 1 0 2026-10-01T20:34:26.287000 The revoked-key error path builds a human-readable failure reason using sprintf(
CVE-2026-95588 8.6 0.00% 1 0 2026-10-01T20:25:35.640000 Unauthenticated Arbitrary File Deletion in AcyMailing SMTP Newsletter <= 11.0.5
CVE-2026-97297 7.6 0.00% 1 0 2026-10-01T20:25:35.640000 Subscriber Broken Access Control in Gratisfaction <= 4.6.3 versions.
CVE-2026-55230 8.7 0.00% 2 0 2026-10-01T20:17:25.737000 Vvveb is a powerful and easy to use CMS with page builder to build websites, blo
CVE-2026-68496 7.5 0.00% 2 0 2026-10-01T19:17:24.467000 The Smile parser in FasterXML jackson-dataformats-binary never invokes StreamRea
CVE-2026-55232 7.6 0.00% 2 0 2026-10-01T19:17:23.117000 Vvveb is a powerful and easy to use CMS with page builder to build websites, blo
CVE-2026-104059 8.1 0.00% 2 0 2026-10-01T19:17:19.480000 Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability i
CVE-2026-103922 9.3 0.00% 4 0 2026-10-01T19:17:18.760000 Capacitor is a cross-platform native runtime for web applications. From 6.0.0 un
CVE-2026-13043 None 0.00% 1 0 2026-10-01T18:32:50 A missing authentication vulnerability in the Kernel Memory Access Driver (PSKMA
CVE-2026-79896 7.5 0.00% 1 0 2026-10-01T18:32:49 Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom T
CVE-2026-86950 8.8 1.24% 7 2 2026-10-01T18:17:28.430000 An out-of-bounds write issue was addressed with improved bounds checking. This i
CVE-2026-78210 0 0.00% 1 0 2026-10-01T16:17:59.517000 In affected versions of Octopus Server, users with certain scoped permission set
CVE-2026-101283 0 0.43% 1 0 2026-10-01T16:17:32.460000 iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rs
CVE-2026-79899 7.9 0.00% 1 0 2026-10-01T15:30:50 Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgeth
CVE-2026-79898 9.1 0.00% 1 0 2026-10-01T15:30:50 Fortra BoKS Manager contains a command injection vulnerability in crlserver. An
CVE-2026-97284 8.8 0.00% 1 0 2026-10-01T15:30:50 Contributor PHP Object Injection in Icegram <= 3.1.31 versions.
CVE-2026-79901 9.9 0.00% 1 0 2026-10-01T15:30:49 In deployments using BoKS keytab management, affected versions of boks_keytabmd
CVE-2026-97277 7.6 0.00% 1 0 2026-10-01T15:30:44 Subscriber Broken Access Control in Social Boost <= 3.6.2 versions.
CVE-2026-62059 7.6 0.00% 1 1 2026-10-01T15:30:41 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CVE-2026-92966 9.1 0.00% 1 1 2026-10-01T15:17:35.830000 The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordP
CVE-2024-58388 7.5 0.00% 3 0 2026-10-01T15:17:17.347000 Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthentica
CVE-2026-66246 8.8 0.00% 1 0 2026-10-01T15:07:27.747000 iControl is affected by a Broken Access Control vulnerability, which could allow
CVE-2026-102149 9.4 0.33% 1 0 2026-10-01T14:17:19.140000 Kiteworks Email Protection Gateway did not sufficiently restrict which account a
CVE-2026-102106 9.1 0.64% 1 0 2026-10-01T14:17:14.417000 Improper authentication in a Kiteworks Email Protection Gateway administrative s
CVE-2026-103655 None 0.00% 1 0 2026-10-01T09:30:42 MISP contains a vulnerability in its two-factor authentication (TOTP) verificati
CVE-2025-41753 9.8 0.00% 1 0 2026-10-01T09:30:33 The object name of a dynamically created BACnet File Object is interpreted as a
CVE-2026-47599 7.8 0.16% 1 0 2026-10-01T04:18:18.593000 NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source
CVE-2026-13313 None 0.00% 2 0 2026-10-01T03:31:14 An Active Debug Code vulnerability in certain ASUS router models allows a remote
CVE-2026-101276 None 0.43% 1 0 2026-09-30T21:32:15 iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free
CVE-2026-92870 7.5 0.32% 1 0 2026-09-30T20:17:37.253000 A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow
CVE-2026-62146 7.8 0.15% 1 1 2026-09-30T20:17:34.013000 A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influ
CVE-2026-102489 0 0.71% 3 0 2026-09-30T19:57:08.043000 Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability tha
CVE-2026-102490 0 0.32% 3 0 2026-09-30T19:57:08.043000 All versions of Zammad including the latest alpha enable the local zammad user t
CVE-2026-94545 0 0.80% 2 5 2026-09-30T19:57:08.043000 Satori is a library to convert HTML and CSS to SVG. Starting in version 0.0.27 a
CVE-2026-79625 8.1 0.40% 2 0 2026-09-30T19:57:08.043000 Affected products do not properly synchronize access to their monitoring functio
CVE-2026-76992 7.5 0.57% 2 0 2026-09-30T19:57:08.043000 The CODESYS Gateway Client allocates memory based on a size field in a gateway r
CVE-2026-47591 7.8 0.18% 1 0 2026-09-30T18:33:55 NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode
CVE-2026-47600 7.8 0.19% 1 0 2026-09-30T18:33:50 NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the
CVE-2026-47601 7.8 0.18% 1 0 2026-09-30T18:33:49 NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the
CVE-2026-76504 9.8 1.10% 20 1 2026-09-30T18:33:25 A vulnerability in the API session-based authentication management of Cisco Cata
CVE-2026-10764 8.7 0.24% 1 0 2026-09-30T17:32:07.107000 Information disclosure in BVMS 4.5 up to 12.3 including allows man-in-the-middle
CVE-2026-78902 6.1 0.30% 1 0 2026-09-30T17:23:08.953000 Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows an
CVE-2026-92867 8.8 0.34% 1 0 2026-09-30T17:16:51.120000 An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an au
CVE-2026-92871 7.5 0.29% 1 0 2026-09-30T16:47:57.730000 A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an
CVE-2026-76570 0 0.50% 1 1 2026-09-30T16:44:39.840000 Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and writ
CVE-2026-102458 9.8 0.43% 2 0 2026-09-30T16:30:42.327000 EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. U
CVE-2026-102455 9.8 0.51% 1 0 2026-09-30T16:30:42.327000 EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability.
CVE-2026-75098 7.5 0.90% 1 0 2026-09-30T16:18:58.363000 The Product Designer App plugin for WordPress is vulnerable to Directory Travers
CVE-2026-18782 9.8 0.58% 1 1 2026-09-30T16:18:57.403000 Improper neutralization of special elements used in an SQL command ('SQL injecti
CVE-2026-82307 9.8 0.47% 1 0 2026-09-30T16:18:57.403000 Improper neutralization of special elements used in an SQL command ('SQL injecti
CVE-2026-6806 7.5 0.27% 1 0 2026-09-30T16:18:39.783000 The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is
CVE-2026-102508 0 0.13% 1 0 2026-09-30T16:14:10.347000 Improper Verification of Cryptographic Signature and Improper Certificate Valida
CVE-2026-94002 7.5 0.43% 1 0 2026-09-30T16:13:13.493000 Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd
CVE-2026-93994 8.1 0.47% 1 0 2026-09-30T16:13:13.493000 Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH serv
CVE-2026-94052 9.1 0.55% 1 0 2026-09-30T16:13:13.493000 A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MI
CVE-2026-62097 7.6 0.38% 1 0 2026-09-30T15:31:44 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CVE-2026-18783 8.8 0.39% 1 1 2026-09-30T15:31:43 Missing authentication for critical function vulnerability in Trex Digital Smart
CVE-2026-97197 7.5 0.39% 1 0 2026-09-30T15:31:38 Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 v
CVE-2026-97241 7.5 0.42% 1 0 2026-09-30T15:31:38 Unauthenticated Sensitive Data Exposure in BackupEase <= 2.2.2 versions.
CVE-2026-97240 7.5 0.42% 1 0 2026-09-30T15:31:38 Unauthenticated Sensitive Data Exposure in StifLi Backup Tools <= 2.2.7 versions
CVE-2026-97248 9.8 0.56% 1 0 2026-09-30T15:31:38 Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions.
CVE-2026-97244 7.5 0.41% 1 0 2026-09-30T15:31:38 Contributor Path Traversal in Creator LMS <= 1.2.19 versions.
CVE-2026-97274 9.8 0.51% 1 0 2026-09-30T15:31:34 Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client
CVE-2026-97293 8.5 0.36% 1 0 2026-09-30T14:18:18.460000 Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions.
CVE-2026-97287 8.5 0.36% 1 0 2026-09-30T14:18:17.797000 Contributor SQL Injection in Event Tickets <= 5.29.5 versions.
CVE-2026-96837 8.8 0.73% 1 0 2026-09-30T14:18:12.963000 Contributor Remote Code Execution (RCE) in CartFlows <= 3.2.0 versions.
CVE-2026-94053 9.1 0.55% 1 0 2026-09-30T12:35:21 Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA S
CVE-2026-77185 9.1 0.51% 2 0 2026-09-30T12:35:16 Authentication bypass in sshd-core in Apache MINA SSHD versions 2.0.0 to 2.19.0
CVE-2026-89294 7.5 0.65% 1 0 2026-09-30T09:31:20 The Simply Schedule Appointments plugin for WordPress is vulnerable to Local Fil
CVE-2026-97196 9.1 0.30% 2 0 2026-09-30T09:31:11 Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web /
CVE-2026-103088 7.5 0.69% 1 0 2026-09-30T03:31:41 Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc
CVE-2026-86131 None 0.33% 3 0 2026-09-30T00:32:48 A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client
CVE-2026-96587 10.0 0.34% 1 0 2026-09-29T22:19:05.860000 The Viidure Android application embeds permanent, plaintext cloud storage creden
CVE-2026-94204 7.5 0.27% 1 0 2026-09-29T22:19:03.923000 The central cloud storage backend for the entire dashcam platform is misconfigur
CVE-2026-84782 8.2 0.39% 1 0 2026-09-29T21:27:41.130000 Issue summary: The DTLS retransmission logic does not correctly handle a handsha
CVE-2026-75804 5.3 0.35% 1 0 2026-09-29T18:31:49 Issue summary: OpenSSL QUIC stack does not enforce connection level flow control
CVE-2026-88771 9.8 1.06% 7 10 2026-09-29T04:18:01.603000 Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetSc
CVE-2026-15953 5.0 0.11% 2 0 2026-09-28T15:32:02 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') v
CVE-2026-15952 6.4 0.09% 2 0 2026-09-28T15:31:57 Incorrect Permission Assignment for Critical Resource vulnerability in ABB Prote
CVE-2026-88772 8.1 1.30% 8 7 2026-09-28T12:26:47.670000 Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue
CVE-2026-100382 None 0.95% 2 1 2026-09-26T00:32:22 Improper Neutralization of Special Elements used in an OS Command ('OS Command I
CVE-2026-67279 6.5 1.03% 1 3 2026-09-25T18:32:21 RouterOS SSH enters the connection protocol after a client-requested rekey even
CVE-2026-61851 0 0.47% 1 0 2026-09-24T21:25:27.050000 Chartbrew is an open-source web application that can connect directly to databas
CVE-2026-78806 5.5 0.11% 1 0 2026-09-24T14:18:17.497000 An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Proje
CVE-2026-18439 4.3 0.25% 1 0 2026-09-23T19:17:29.350000 The Tutor LMS – eLearning and online course solution plugin for WordPress is vul
CVE-2026-93616 9.8 19.65% 2 2 2026-09-23T16:38:38.987000 A directory traversal and file upload vulnerability allows an unauthenticated at
CVE-2026-85102 9.8 7.55% 2 0 2026-09-22T21:30:40 Improper certificate trust validation during VPN negotiation in Check Point Quan
CVE-2026-79079 7.8 0.19% 1 0 2026-09-22T20:00:03.713000 An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitra
CVE-2026-93556 0 0.30% 1 0 2026-09-22T19:41:38.447000 The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, w
CVE-2026-89420 0 0.47% 1 0 2026-09-22T19:09:32.273000 Improper Validation of Specified Quantity in Input in ZenHive mpp allows a clien
CVE-2026-89422 0 0.64% 1 0 2026-09-22T19:09:32.273000 Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allow
CVE-2026-74765 6.5 0.52% 1 0 2026-09-22T18:33:29 Net::IDN::Punycode versions before 2.590 for Perl allow an out-of-bounds read vi
CVE-2026-80521 7.8 0.17% 1 2 2026-09-21T14:17:20.193000 In the Linux kernel, the following vulnerability has been resolved: af_unix: Un
CVE-2026-85046 8.8 48.88% 1 8 2026-09-21T13:17:10.970000 Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote at
CVE-2026-63490 7.5 0.69% 1 0 2026-09-18T20:09:01.757000 Handlebars.java provides logic-less and semantic Mustache templates with Java. P
CVE-2026-86869 6.5 0.34% 1 0 2026-09-17T18:31:49 An out-of-bounds write issue was addressed with improved bounds checking. This i
CVE-2026-50610 None 0.13% 1 0 2026-09-17T09:33:03 A vulnerability has been identified in the Acer System Monitoring component incl
CVE-2026-76460 10.0 14.03% 1 1 2026-09-16T21:33:00 A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an
CVE-2026-76461 9.8 28.27% 1 4 2026-09-14T21:32:49 A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure
CVE-2026-81578 9.8 85.17% 1 2 2026-09-14T00:16:56.207000 An improper access control vulnerability exists in the web management interface
CVE-2026-85706 10.0 92.96% 1 14 template 2026-09-12T12:30:50 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7
CVE-2026-75650 10.0 3.95% 1 6 2026-09-09T05:18:07.237000 Adobe Commerce is affected by an Improper Neutralization of Special Elements Use
CVE-2026-81963 7.8 0.39% 1 0 2026-09-08T21:34:09 Improper link resolution before file access ('link following') in Windows Update
CVE-2026-86218 9.8 12.93% 1 3 template 2026-09-08T21:33:02 N-central is vulnerable to a pre-auth remote code execution This issue affects N
CVE-2026-65669 9.6 0.88% 1 0 2026-09-08T18:32:08 Improper neutralization of special elements in output used by a downstream compo
CVE-2026-60004 9.8 23.99% 1 11 2026-09-08T17:56:31 ### Summary Gitea's `diffpatch` endpoint can be abused to install and execute a
CVE-2026-83548 10.0 8.76% 1 3 2026-09-03T13:06:16.053000 A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Pla
CVE-2026-83549 7.8 10.76% 1 2 2026-09-02T18:32:06 Post-authentication Improper Neutralization of Special Elements used in an OS Co
CVE-2026-82078 9.1 61.39% 1 2 2026-08-31T21:31:56 An unsafe dynamic class loading vulnerability exists in the database connection
CVE-2026-73570 8.9 11.74% 3 10 2026-08-24T13:19:17.577000 A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) befor
CVE-2026-72018 7.8 0.18% 1 1 2026-08-17T06:34:07 In the Linux kernel, the following vulnerability has been resolved: dibs: loopb
CVE-2025-41738 7.5 0.39% 1 0 2026-06-17T09:23:03.883000 An unauthenticated remote attacker may cause the visualisation server of the COD
CVE-2025-41700 7.8 0.15% 1 0 2026-06-17T09:22:59.947000 An unauthenticated attacker can trick a local user into executing arbitrary code
CVE-2026-35273 9.8 9.44% 1 4 2026-06-12T18:31:50 Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleS
CVE-2025-41739 5.9 0.35% 1 0 2025-12-01T12:30:34 An unauthenticated remote attacker, who beats a race condition, can exploit a fl
CVE-2021-21975 7.5 78.29% 1 10 template 2025-10-22T00:32:06 Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975)
CVE-2026-86360 0 0.00% 2 0 N/A
CVE-2026-63692 0 0.00% 2 0 N/A
CVE-2026-63688 0 0.00% 2 0 N/A
CVE-2026-53953 0 0.00% 2 0 N/A
CVE-2026-104020 0 0.00% 2 0 N/A
CVE-2026-87902 0 19.76% 4 26 N/A
CVE-2026-56662 0 0.00% 2 0 N/A
CVE-2026-56661 0 0.00% 2 0 N/A
CVE-2026-56660 0 0.00% 2 0 N/A
CVE-2026-92543 0 0.00% 2 0 N/A
CVE-2026-55494 0 0.75% 1 1 N/A
CVE-2026-55083 0 0.00% 2 0 N/A
CVE-2026-68495 0 0.00% 2 0 N/A
CVE-2024-76504 0 0.00% 1 0 N/A
CVE-2026-102147 0 0.43% 1 0 N/A
CVE-2026-102105 0 0.53% 1 0 N/A
CVE-2026-91881 0 0.00% 1 0 N/A
CVE-2026-102115 0 0.53% 1 0 N/A
CVE-2026-43598 0 0.00% 1 0 N/A
CVE-2026-84411 0 0.00% 1 0 N/A

CVE-2026-96658
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-10-02T04:18:09.757000

3 posts

A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to improper handling of delegated methods, an attacker can append unauthorized functions to the allowed execution list, enabling them to run arbitrary commands on the hosting server.

DailyCyberSecurity at 2026-10-02T02:31:19.430Z ##

A 9.9 Foreman RCE flaw, CVE-2026-96658, lets low-privileged users run commands on Red Hat Satellite. A Viewer bug leaks root passwords.

securityonline.info/foreman-rc

##

DailyCyberSecurity@infosec.exchange at 2026-10-02T02:31:19.000Z ##

A 9.9 Foreman RCE flaw, CVE-2026-96658, lets low-privileged users run commands on Red Hat Satellite. A Viewer bug leaks root passwords.

#Foreman #RedHatSatellite #CVE202696658 #CVE202696659 #CVE202686345 #RCE #LDAP

securityonline.info/foreman-rc

##

thehackerwire@mastodon.social at 2026-10-01T17:19:31.000Z ##

🔴 CVE-2026-96658 - Critical (9.9)

A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to improper handling of delegated methods, an attacker ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47593
(7.8 HIGH)

EPSS: 0.18%

updated 2026-10-02T04:18:08.737000

1 posts

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an unprivileged user can cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, and denial of service.

thehackerwire@mastodon.social at 2026-09-30T17:02:07.000Z ##

🟠 CVE-2026-47593 - High (7.8)

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an unprivileged user can cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47592
(7.8 HIGH)

EPSS: 0.19%

updated 2026-10-02T04:18:08.560000

1 posts

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

thehackerwire@mastodon.social at 2026-09-30T17:01:57.000Z ##

🟠 CVE-2026-47592 - High (7.8)

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of serv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14378
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-02T04:18:06.277000

2 posts

The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled `original_user_id` cookie as the privileged identity: `verify_nonce_and_capability()` incorrectly checks the `manage_options` capability on the user identified by

2 repos

https://github.com/anoxhunterdump-ctrl/CVE-2026-14378-DevKit-Pro-Auth-Bypass

https://github.com/murrez/CVE-2026-14378

offseq at 2026-10-02T04:30:23.059Z ##

CVE-2026-14378 | CRITICAL vuln in dplugins DevKit Pro (<=2.3.0): Improper authentication lets unauth attackers gain admin access via crafted cookies & nonce. Immediate action: disable or restrict plugin. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-10-02T04:30:23.000Z ##

CVE-2026-14378 | CRITICAL vuln in dplugins DevKit Pro (<=2.3.0): Improper authentication lets unauth attackers gain admin access via crafted cookies & nonce. Immediate action: disable or restrict plugin. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #Infosec

##

CVE-2026-14157
(0 None)

EPSS: 0.00%

updated 2026-10-02T04:18:06.140000

1 posts

Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands via a crafted file uploaded through the web management interface.

offseq@infosec.exchange at 2026-10-01T03:00:27.000Z ##

ASUS Routers hit by CRITICAL vuln: CVE-2026-14157 (CVSS 9.4). Remote authenticated users can execute arbitrary commands via crafted file upload in web interface. Restrict access, monitor closely. radar.offseq.com/threat/cve-20 #OffSeq #CVE202614157 #ASUS #Vuln #BlueTeam

##

CVE-2026-104286
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-02T04:18:04.950000

21 posts

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

1 repos

https://github.com/ShadowForge-Cyber/CVE-2026-104286-POC

undercodenews@mastodon.social at 2026-10-02T05:36:10.000Z ##

FortiMail Zero-Day Under Attack: Critical 98 Vulnerability Lets Hackers Write Files Without Authentication + Video

Fortinet Issues Urgent Warning as Attackers Exploit FortiMail Appliances Fortinet has disclosed a critical FortiMail vulnerability that is already being exploited in the wild, putting organizations that expose the email-security platform’s management interface at immediate risk. Tracked as CVE-2026-104286, the vulnerability carries a CVSS score of 9.8 and…

undercodenews.com/fortimail-ze

##

cyberworldops at 2026-10-02T04:40:00.964Z ##

Fortinet FortiMail management interface is impacted by CVE-2026-104286 (CVSS 9.8), exploited in the wild as zero-day for unauthenticated system file writes and command execution. Internet-exposed instances face immediate full-compromise risk; isolate management and patch urgently.

cyberworldops.eu/en/fortimail-

##

undercodenews@mastodon.social at 2026-10-02T02:48:25.000Z ##

Fortinet FortiMail Zero-Day Crisis: Critical CVSS 98 Vulnerability Actively Exploited to Execute Unauthorized Code + Video

Introduction Fortinet has disclosed a critical security vulnerability affecting its FortiMail email security platform, warning that attackers are actively exploiting the flaw in real-world zero-day attacks. The vulnerability, tracked as CVE-2026-104286, carries a CVSS score of 9.8, placing it among the most severe classes of vulnerabilities because…

undercodenews.com/fortinet-for

##

Matchbook3469@mastodon.social at 2026-10-02T01:52:39.000Z ##

🔴 New security advisory:

CVE-2026-104286 affects multiple systems.

• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#InfoSec #VulnerabilityManagement #CyberSec

##

ninjaintelgroup@mastodon.social at 2026-10-02T01:16:23.000Z ##

🚨 NEW on CISA KEV — exploited in the wild

🛡 Fortinet FortiMail
Fortinet FortiMail Path Traversal Vulnerability
CVE: CVE-2026-104286 · patch by 2026-10-04

Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

🔗 ninjasignal.ninja/intel/cve/CV
#cybersecurity #KEV #CVE #infosec

##

undercodenews@mastodon.social at 2026-10-01T23:46:57.000Z ##

Critical Fortinet FortiMail Vulnerability Enters CISA KEV After Active Exploitation: Unauthenticated Attackers May Achieve File Write and Remote Code Execution + Video

Introduction A critical vulnerability affecting Fortinet FortiMail appliances has been added to the CISA Known Exploited Vulnerabilities (KEV) Catalog, indicating that attackers are actively exploiting the flaw in real-world environments. The vulnerability, tracked as CVE-2026-104286, combines a path…

undercodenews.com/critical-for

##

news@fawkes.rocks at 2026-10-01T23:18:13.000Z ##

FortiMail CVE-2026-104286 zero-day exploited in attacks

fawkes.rocks/2026/10/02/fortim

##

undercodenews@mastodon.social at 2026-10-01T23:03:55.000Z ##

Critical FortiMail Zero-Day Under Active Attack: Fortinet Urges Immediate Mitigation + Video

Fortinet is warning customers that a critical FortiMail vulnerability is being actively exploited as a zero-day, potentially allowing unauthenticated attackers to write arbitrary files to vulnerable appliances and ultimately execute unauthorized commands or code. The flaw, tracked as CVE-2026-104286 (FG-IR-26-175), carries a CVSS score of 9.8, placing it in the critical…

undercodenews.com/critical-for

##

oversecurity@mastodon.social at 2026-10-01T23:00:05.000Z ##

Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day...

🔗️ [Bleepingcomputer] link.is.it/QyRWj6

##

Analyst207@mastodon.social at 2026-10-01T22:51:01.000Z ##

Fortinet Warns of Zero-Day Attacks Exploiting Critical FortiMail Flaw

Fortinet has issued a critical warning about zero-day attacks exploiting a severe vulnerability in its FortiMail appliances, with a CVSS score of 9.8 that allows unauthenticated attackers to write arbitrary files on the system. This flaw, tracked as CVE-2026-104286, is under active exploitation, putting FortiMail users at risk.

osintsights.com/fortinet-warns

#ZeroDay #Fortimail #Cve2026104286 #PathTraversal #EmergingThreats

##

DailyCyberSecurity at 2026-10-01T22:10:04.550Z ##

Attackers exploit CVE-2026-104286, a 9.8 FortiMail vulnerability allowing unauthenticated file writes. CISA adds it to KEV. Apply the workaround.

securityonline.info/fortimail-

##

secdb at 2026-10-01T21:00:17.166Z ##

🚨 [CISA-2026:1001] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-104286 (secdb.nttzen.cloud/cve/detail/)
- Name: Fortinet FortiMail Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Fortinet
- Product: FortiMail
- Notes: fortiguard.fortinet.com/psirt/ ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-10-01T20:01:04.000Z ##

CVE ID: CVE-2026-104286
Vendor: Fortinet
Product: FortiMail
Date Added: 2026-10-01
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

ssvc at 2026-10-01T19:39:17.773Z ##

Happy FortiMail customers

CVE-2026-104286: An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

This has been reported to be exploited in the wild

fortiguard.fortinet.com/psirt/

##

cyberworldops@infosec.exchange at 2026-10-02T04:40:00.000Z ##

Fortinet FortiMail management interface is impacted by CVE-2026-104286 (CVSS 9.8), exploited in the wild as zero-day for unauthenticated system file writes and command execution. Internet-exposed instances face immediate full-compromise risk; isolate management and patch urgently. #Fortinet #ZeroDay #ThreatIntel

cyberworldops.eu/en/fortimail-

##

news@fawkes.rocks at 2026-10-01T23:18:13.000Z ##

FortiMail CVE-2026-104286 zero-day exploited in attacks

fawkes.rocks/2026/10/02/fortim

##

oversecurity@mastodon.social at 2026-10-01T23:00:05.000Z ##

Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day...

🔗️ [Bleepingcomputer] link.is.it/QyRWj6

##

DailyCyberSecurity@infosec.exchange at 2026-10-01T22:10:04.000Z ##

Attackers exploit CVE-2026-104286, a 9.8 FortiMail vulnerability allowing unauthenticated file writes. CISA adds it to KEV. Apply the workaround.

#Fortinet #FortiMail #CVE2026104286 #PathTraversal #CISAKEV #ActivelyExploited #ZeroDay

securityonline.info/fortimail-

##

secdb@infosec.exchange at 2026-10-01T21:00:17.000Z ##

🚨 [CISA-2026:1001] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-104286 (secdb.nttzen.cloud/cve/detail/)
- Name: Fortinet FortiMail Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Fortinet
- Product: FortiMail
- Notes: fortiguard.fortinet.com/psirt/ ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261001 #cisa20261001 #cve_2026_104286 #cve2026104286

##

cisakevtracker@mastodon.social at 2026-10-01T20:01:04.000Z ##

CVE ID: CVE-2026-104286
Vendor: Fortinet
Product: FortiMail
Date Added: 2026-10-01
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

ssvc@infosec.exchange at 2026-10-01T19:39:17.000Z ##

Happy #zeroday FortiMail customers

CVE-2026-104286: An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

This has been reported to be exploited in the wild

fortiguard.fortinet.com/psirt/

#fortinet #cve #vulnerability

##

CVE-2026-104480
(0 None)

EPSS: 0.00%

updated 2026-10-02T02:17:02.007000

2 posts

Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected clients to accept an unauthorized member into the end-to-end encrypted media sess

offseq at 2026-10-02T03:00:24.848Z ##

Discord libdave CRITICAL vuln (CVE-2026-104480, CVSS 9.4): Affected versions 1.1.0 – <1.2.0 let attackers inject unauthorized members into encrypted sessions. Patch status unconfirmed — check radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-10-02T03:00:24.000Z ##

Discord libdave CRITICAL vuln (CVE-2026-104480, CVSS 9.4): Affected versions 1.1.0 – <1.2.0 let attackers inject unauthorized members into encrypted sessions. Patch status unconfirmed — check radar.offseq.com/threat/cve-20 #OffSeq #Discord #CVE2026104480 #infosec

##

CVE-2026-103098
(7.5 HIGH)

EPSS: 0.00%

updated 2026-10-02T01:16:43.193000

2 posts

Transmission of a sensitive key in the URL over an unencrypted HTTP connection.  The request is sent over HTTP rather than HTTPS, meaning the key is transmitted in plaintext across the network. An attacker with the ability to monitor network traffic could intercept the request and obtain the key

thehackerwire@mastodon.social at 2026-10-02T02:47:22.000Z ##

🟠 CVE-2026-103098 - High (7.5)

Transmission of a sensitive key in the URL
over an unencrypted HTTP connection.  The
request is sent over HTTP rather than HTTPS, meaning the key is transmitted in
plaintext across the network. An attacker with the ability to monitor network
traf...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-02T02:47:22.000Z ##

🟠 CVE-2026-103098 - High (7.5)

Transmission of a sensitive key in the URL
over an unencrypted HTTP connection.  The
request is sent over HTTP rather than HTTPS, meaning the key is transmitted in
plaintext across the network. An attacker with the ability to monitor network
traf...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103097
(7.5 HIGH)

EPSS: 0.00%

updated 2026-10-02T01:16:43.070000

2 posts

An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.

thehackerwire@mastodon.social at 2026-10-02T02:47:13.000Z ##

🟠 CVE-2026-103097 - High (7.5)

An API key is
hardcoded and retrievable from the application package. Since Android
applications can be reverse engineered, embedding sensitive API credentials
directly in the client application may allow unauthorized users to extract and
misuse t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-02T02:47:13.000Z ##

🟠 CVE-2026-103097 - High (7.5)

An API key is
hardcoded and retrievable from the application package. Since Android
applications can be reverse engineered, embedding sensitive API credentials
directly in the client application may allow unauthorized users to extract and
misuse t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103096
(7.5 HIGH)

EPSS: 0.00%

updated 2026-10-02T01:16:42.930000

2 posts

API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.

thehackerwire@mastodon.social at 2026-10-02T02:47:32.000Z ##

🟠 CVE-2026-103096 - High (7.5)

API
key is hardcoded and retrievable from the application package. Since Android
applications can be reverse engineered, embedding sensitive API credentials
directly in the client application may allow unauthorized users to extract and
misuse the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-02T02:47:32.000Z ##

🟠 CVE-2026-103096 - High (7.5)

API
key is hardcoded and retrievable from the application package. Since Android
applications can be reverse engineered, embedding sensitive API credentials
directly in the client application may allow unauthorized users to extract and
misuse the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12540
(8.2 HIGH)

EPSS: 0.00%

updated 2026-10-02T00:32:33

2 posts

A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetch_log task. The request_id parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. While the task is intended to fetch specific log entries, an attacker with sudo permissions to execute this rake task can inject shell metacharacters (such as ;, ",

thehackerwire@mastodon.social at 2026-10-01T19:02:37.000Z ##

🟠 CVE-2026-12540 - High (8.2)

A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetch_log task. The request_id parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. While the t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-01T19:02:37.000Z ##

🟠 CVE-2026-12540 - High (8.2)

A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetch_log task. The request_id parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. While the t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86345
(9.0 None)

EPSS: 0.00%

updated 2026-10-02T00:31:40

4 posts

A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. This can cause a cl

offseq at 2026-10-02T01:30:27.635Z ##

Red Hat Directory Server 11: CVE-2026-86345 (CRITICAL, CVSS 9) allows on-path attackers to inject LDAP messages post-StartTLS, risking auth bypass. Restrict access, check Red Hat advisory radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-10-02T00:46:15.000Z ##

🔴 CVE-2026-86345 - Critical (9)

A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-02T01:30:27.000Z ##

Red Hat Directory Server 11: CVE-2026-86345 (CRITICAL, CVSS 9) allows on-path attackers to inject LDAP messages post-StartTLS, risking auth bypass. Restrict access, check Red Hat advisory radar.offseq.com/threat/cve-20 #OffSeq #CVE202686345 #RedHat #LDAP #infosec

##

thehackerwire@mastodon.social at 2026-10-02T00:46:15.000Z ##

🔴 CVE-2026-86345 - Critical (9)

A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103765
(9.4 CRITICAL)

EPSS: 0.00%

updated 2026-10-02T00:31:39

2 posts

Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer engine metadata keys. Attackers can poison segment descriptors such as tcp_data_port or re-create rpc_meta entries to redirect KV cache transfers to attacker-controlled listeners, or exhaust server

thehackerwire@mastodon.social at 2026-10-02T00:46:33.000Z ##

🔴 CVE-2026-103765 - Critical (9.4)

Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer engine metadata keys. Attackers can poison se...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-02T00:46:33.000Z ##

🔴 CVE-2026-103765 - Critical (9.4)

Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer engine metadata keys. Attackers can poison se...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103764
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-02T00:31:39

4 posts

Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with arbitrary addr and size values using READ or WRITE opcodes to disclose KV cache contents, prompts and secrets or corrupt memory

thehackerwire@mastodon.social at 2026-10-02T00:46:23.000Z ##

🔴 CVE-2026-103764 - Critical (9.8)

Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a cr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-10-02T00:00:35.435Z ##

CRITICAL CVE-2026-103764 in kvcache-ai Mooncake (<0.3.13): Untrusted pointer dereference lets unauthenticated attackers read/write arbitrary memory, risking data leak & code execution. Patch to 0.3.13+ now! radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-10-02T00:46:23.000Z ##

🔴 CVE-2026-103764 - Critical (9.8)

Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a cr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-02T00:00:35.000Z ##

CRITICAL CVE-2026-103764 in kvcache-ai Mooncake (<0.3.13): Untrusted pointer dereference lets unauthenticated attackers read/write arbitrary memory, risking data leak & code execution. Patch to 0.3.13+ now! radar.offseq.com/threat/cve-20 #OffSeq #CVE #Vuln #infosec

##

CVE-2026-86344
(7.5 HIGH)

EPSS: 0.00%

updated 2026-10-02T00:31:39

2 posts

A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage on the same connection, causing the server to hand that connection to a second worker thread before the first worker's result is flushed. The second worker blocks until nsslapd-ioblocktimeout while holding the connection mutex, preventing d

thehackerwire@mastodon.social at 2026-10-01T23:46:06.000Z ##

🟠 CVE-2026-86344 - High (7.5)

A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage on the same connection, causing the server to hand that connection to a second worker t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-01T23:46:06.000Z ##

🟠 CVE-2026-86344 - High (7.5)

A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage on the same connection, causing the server to hand that connection to a second worker t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103761
(7.5 HIGH)

EPSS: 0.00%

updated 2026-10-02T00:31:39

2 posts

Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenticated attackers to grow process memory without limit. Attackers can repeatedly send notify frames up to 1 MB to the handshake RPC port, filling the uncapped notifys vector until the out-of-memory killer terminates the engine.

thehackerwire@mastodon.social at 2026-10-01T23:45:57.000Z ##

🟠 CVE-2026-103761 - High (7.5)

Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenticated attackers to grow process memory without limit. Attackers can repeatedly send notify frames...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-01T23:45:57.000Z ##

🟠 CVE-2026-103761 - High (7.5)

Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenticated attackers to grow process memory without limit. Attackers can repeatedly send notify frames...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104051
(8.2 HIGH)

EPSS: 0.00%

updated 2026-10-02T00:31:33

2 posts

PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoint which returns the complete raw metadata object without a field whitelist. Attackers can use the publicly visible file hash to retrieve the delete_code via the info API and then invoke the delete API

thehackerwire@mastodon.social at 2026-10-01T23:47:04.000Z ##

🟠 CVE-2026-104051 - High (8.2)

PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoint which returns the complete raw metadata object...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-01T23:47:04.000Z ##

🟠 CVE-2026-104051 - High (8.2)

PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoint which returns the complete raw metadata object...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-96659
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-10-02T00:17:04.627000

1 posts

A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the user can access sensitive data, such as host root passwords. Furthermore, under insecure system configurations where Safemode protections are disabled, the flaw

thehackerwire@mastodon.social at 2026-10-01T17:19:22.000Z ##

🔴 CVE-2026-96659 - Critical (9.1)

A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the user ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104018
(8.8 HIGH)

EPSS: 0.00%

updated 2026-10-01T21:33:58

2 posts

An improper privilege management vulnerability (CWE-269) exists in the command shell of Wind River VxWorks 7 all versions up to 26.09. when configured to enforce per-user command privileges. Under certain shell operations, a command may be evaluated without the privilege check that is normally applied, allowing an authenticated user with limited privileges to execute commands they are not authoriz

thehackerwire@mastodon.social at 2026-10-01T19:02:18.000Z ##

🟠 CVE-2026-104018 - High (8.8)

An improper privilege management vulnerability (CWE-269) exists in the command shell of Wind River VxWorks 7 all versions up to 26.09. when configured to enforce per-user command privileges. Under certain shell operations, a command may be evaluat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-01T19:02:18.000Z ##

🟠 CVE-2026-104018 - High (8.8)

An improper privilege management vulnerability (CWE-269) exists in the command shell of Wind River VxWorks 7 all versions up to 26.09. when configured to enforce per-user command privileges. Under certain shell operations, a command may be evaluat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104057
(7.5 HIGH)

EPSS: 0.00%

updated 2026-10-01T21:33:02

2 posts

Podgrab contains an unauthenticated denial-of-service vulnerability caused by unsynchronized concurrent access to shared maps (activePlayers and allConnections) in its WebSocket handler, where Wshandler and HandleWebsocketMessages goroutines read and write these maps without a mutex. A remote attacker can open multiple WebSocket connections to the /ws endpoint and send messages in a loop to trigge

thehackerwire@mastodon.social at 2026-10-01T19:46:08.000Z ##

🟠 CVE-2026-104057 - High (7.5)

Podgrab contains an unauthenticated denial-of-service vulnerability caused by unsynchronized concurrent access to shared maps (activePlayers and allConnections) in its WebSocket handler, where Wshandler and HandleWebsocketMessages goroutines read ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-01T19:46:08.000Z ##

🟠 CVE-2026-104057 - High (7.5)

Podgrab contains an unauthenticated denial-of-service vulnerability caused by unsynchronized concurrent access to shared maps (activePlayers and allConnections) in its WebSocket handler, where Wshandler and HandleWebsocketMessages goroutines read ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63292
(7.5 HIGH)

EPSS: 0.00%

updated 2026-10-01T21:17:23.610000

2 posts

Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default. Users ar

CVE-2026-97662
(8.2 HIGH)

EPSS: 0.00%

updated 2026-10-01T20:36:52.220000

2 posts

An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat actors to create, overwrite, or truncate arbitrary files on the host outside the intended workspace directory via a crafted reference value supplied to the diff scan operation. To remediate this issue, users should upgrade to version 0.2.0.

thehackerwire@mastodon.social at 2026-10-01T19:01:14.000Z ##

🟠 CVE-2026-97662 - High (8.2)

An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat actors to create, overwrite, or truncate arbitrary files on the host outside the intended workspace d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-01T19:01:14.000Z ##

🟠 CVE-2026-97662 - High (8.2)

An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat actors to create, overwrite, or truncate arbitrary files on the host outside the intended workspace d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12627
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-01T20:34:26.287000

2 posts

Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing.

cR0w@infosec.exchange at 2026-10-01T18:42:59.000Z ##

fortra.com/security/advisories

No mention of it being EITW yet but if it is, I expect chicken-themed headlines and warez for BoKS.

sev:CRIT 9.8 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing.

nvd.nist.gov/vuln/detail/cve-2

##

thehackerwire@mastodon.social at 2026-10-01T16:18:28.000Z ##

🔴 CVE-2026-12627 - Critical (9.8)

Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14316
(8.1 HIGH)

EPSS: 0.00%

updated 2026-10-01T20:34:26.287000

1 posts

The revoked-key error path builds a human-readable failure reason using sprintf() into a heap buffer. The allocated buffer is too small for the final formatted message. When sprintf() writes the full message, it can write past the end of the heap allocation.

thehackerwire@mastodon.social at 2026-10-01T17:19:41.000Z ##

🟠 CVE-2026-14316 - High (8.1)

The revoked-key error path builds a human-readable failure reason using sprintf() into a heap buffer. The allocated buffer is too small for the final formatted message. When sprintf() writes the full message, it can write past the end of the heap ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-95588
(8.6 HIGH)

EPSS: 0.00%

updated 2026-10-01T20:25:35.640000

1 posts

Unauthenticated Arbitrary File Deletion in AcyMailing SMTP Newsletter <= 11.0.5 versions.

thehackerwire@mastodon.social at 2026-10-01T17:04:12.000Z ##

🟠 CVE-2026-95588 - High (8.6)

Unauthenticated Arbitrary File Deletion in AcyMailing SMTP Newsletter &lt;= 11.0.5 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97297
(7.6 HIGH)

EPSS: 0.00%

updated 2026-10-01T20:25:35.640000

1 posts

Subscriber Broken Access Control in Gratisfaction <= 4.6.3 versions.

thehackerwire@mastodon.social at 2026-10-01T16:32:34.000Z ##

🟠 CVE-2026-97297 - High (7.6)

Subscriber Broken Access Control in Gratisfaction &lt;= 4.6.3 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55230
(8.7 HIGH)

EPSS: 0.00%

updated 2026-10-01T20:17:25.737000

2 posts

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's HTML sanitizer fails to strip event-handler attributes when a tag carries a greater-than character inside a quoted attribute value. A low-privilege content author (default role author or contributor) can store a payload in post or product content that runs JavaS

thehackerwire@mastodon.social at 2026-10-01T19:31:24.000Z ##

🟠 CVE-2026-55230 - High (8.7)

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's HTML sanitizer fails to strip event-handler attributes when a tag carries a greater-than character inside a q...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-01T19:31:24.000Z ##

🟠 CVE-2026-55230 - High (8.7)

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's HTML sanitizer fails to strip event-handler attributes when a tag carries a greater-than character inside a q...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68496
(7.5 HIGH)

EPSS: 0.00%

updated 2026-10-01T19:17:24.467000

2 posts

The Smile parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. SmileParser._handleLongFieldName() grows its internal name buffer through an unconstrained _growArrayTo() call and performs no length validation. An attacker who can have a Smile docum

thehackerwire@mastodon.social at 2026-10-01T19:01:33.000Z ##

🟠 CVE-2026-68496 - High (7.5)

The Smile parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. SmileParser._handleLongFieldNam...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-01T19:01:33.000Z ##

🟠 CVE-2026-68496 - High (7.5)

The Smile parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. SmileParser._handleLongFieldNam...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55232
(7.6 HIGH)

EPSS: 0.00%

updated 2026-10-01T19:17:23.117000

2 posts

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's SSRF guard resolves a host with an IPv4-only function and never inspects IPv6, so any host that lacks an A record passes a private-range check. Editor oEmbed proxy fetches an attacker-supplied URL server side and reflects a response body, so an authenticated adm

thehackerwire@mastodon.social at 2026-10-01T19:31:34.000Z ##

🟠 CVE-2026-55232 - High (7.6)

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's SSRF guard resolves a host with an IPv4-only function and never inspects IPv6, so any host that lacks an A re...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-01T19:31:34.000Z ##

🟠 CVE-2026-55232 - High (7.6)

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's SSRF guard resolves a host with an IPv4-only function and never inspects IPv6, so any host that lacks an A re...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104059
(8.1 HIGH)

EPSS: 0.00%

updated 2026-10-01T19:17:19.480000

2 posts

Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that allows unauthenticated attackers to perform state-changing actions by sending cross-origin requests without CSRF tokens, Origin/Referer validation, CORS configuration, or Host allowlisting. Attackers can exploit the newattachment, deleterecord, build, clean, and publish endpoints from a m

thehackerwire@mastodon.social at 2026-10-01T19:46:18.000Z ##

🟠 CVE-2026-104059 - High (8.1)

Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that allows unauthenticated attackers to perform state-changing actions by sending cross-origin requests without CSRF tokens, Origin/Referer ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-01T19:46:18.000Z ##

🟠 CVE-2026-104059 - High (8.1)

Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that allows unauthenticated attackers to perform state-changing actions by sending cross-origin requests without CSRF tokens, Origin/Referer ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103922
(9.3 CRITICAL)

EPSS: 0.00%

updated 2026-10-01T19:17:18.760000

4 posts

Capacitor is a cross-platform native runtime for web applications. From 6.0.0 until 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1, the Android and iOS WebView navigation guard validates a target URL's host and scheme but not its path, allowing a victim who activates an untrusted link to navigate a frame to /_capacitor_http_interceptor_. The native proxy can fetch an attacker-selected URL and return the re

DailyCyberSecurity at 2026-10-02T03:49:34.784Z ##

Critical Capacitor vulnerability CVE-2026-103922 (CVSS 9.3) affects a package with 5.5M weekly downloads. Update to a patched release now.

securityonline.info/capacitor-

##

thehackerwire@mastodon.social at 2026-10-01T19:02:26.000Z ##

🔴 CVE-2026-103922 - Critical (9.3)

Capacitor is a cross-platform native runtime for web applications. From 6.0.0 until 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1, the Android and iOS WebView navigation guard validates a target URL's host and scheme but not its path, allowing a victim wh...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-10-02T03:49:34.000Z ##

Critical Capacitor vulnerability CVE-2026-103922 (CVSS 9.3) affects a package with 5.5M weekly downloads. Update to a patched release now.

#Capacitor #Ionic #CVE2026103922 #MobileSecurity #npm #Android #iOS

securityonline.info/capacitor-

##

thehackerwire@mastodon.social at 2026-10-01T19:02:26.000Z ##

🔴 CVE-2026-103922 - Critical (9.3)

Capacitor is a cross-platform native runtime for web applications. From 6.0.0 until 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1, the Android and iOS WebView navigation guard validates a target URL's host and scheme but not its path, allowing a victim wh...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13043(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-10-01T18:32:50

1 posts

A missing authentication vulnerability in the Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products allows a local, authenticated attacker to bypass the driver's access-control handshake and issue arbitrary privileged commands to the driver, resulting in disclosure of kernel and process memory.

cR0w@infosec.exchange at 2026-10-01T18:48:31.000Z ##

WatchGuard continuing the slow drip of sev:CRIT advisories.

psirt.watchguard.com/CVE-2026-

A missing authentication vulnerability in the Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products allows a local, authenticated attacker to bypass the driver's access-control handshake and issue arbitrary privileged commands to the driver, resulting in disclosure of kernel and process memory.

##

CVE-2026-79896
(7.5 HIGH)

EPSS: 0.00%

updated 2026-10-01T18:32:49

1 posts

Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is normally restarted automatically, repeated requests can sustain the service interruption.

thehackerwire@mastodon.social at 2026-10-01T16:32:24.000Z ##

🟠 CVE-2026-79896 - High (7.5)

Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is nor...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86950
(8.8 HIGH)

EPSS: 1.24%

updated 2026-10-01T18:17:28.430000

7 posts

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions o

2 repos

https://github.com/DeAurity/CVE-2026-86950-POC

https://github.com/msuiche/hotcell

lobsters@mastodon.social at 2026-10-01T18:45:14.000Z ##

CVE-2026-86950: The Great Glyph Grift - An in-the-wild iOS bug with a possible WhatsApp zero-click path lobste.rs/s/yfttkn #security
calif.io/research/the-great-gl

##

cyberworldops@infosec.exchange at 2026-10-01T10:30:00.000Z ##

Researchers published the first public PoC for CVE-2026-86950, an Apple CoreGraphics out-of-bounds write via crafted PDF font data. The PoC shows crash and controlled write only, but Apple reports targeted exploitation in the wild, raising immediate patching priority. #AppleSecurity #CoreGraphics #VulnManagement

cyberworldops.eu/en/public-cor

##

youranonnewsirc@nerdculture.de at 2026-09-30T22:26:25.000Z ##

Geopolitical: Iran warned UAE following Netanyahu's visit (Sept 30) amidst regional tensions, while Russia conducted a drone strike on Ukraine's National Academy of Sciences (Sept 29).

Technology: OpenAI launched "dots" agents and GPT-6.1 Sol (Sept 29), despite shelving a prior AI model (Astra) due to safety concerns. SpaceX's Starship successfully completed its first orbital flight (Sept 28-29).

Cybersecurity: Urgent advisories were issued for actively exploited Citrix NetScaler zero-days (Sept 30), mandating federal agency patching. Apple also patched a CoreGraphics zero-day (CVE-2026-86950) used in targeted attacks (Sept 29).

#AnonNews_irc #Cybersecurity #News

##

technews@eicker.news at 2026-09-30T21:47:01.000Z ##

#Apple released a #security update for #iOS 26, #iPadOS 26, and #macOS 26 to fix a #vulnerability in the #graphicsengine that could be exploited for sophisticated attacks. The bug, CVE-2026-86950, was discovered by Meta and could potentially allow hackers to steal personal data. A separate zero-click bug, CVE-2026-86869, was also fixed, preventing silent data theft via malicious iMessages. techcrunch.com/2026/09/29/stil

##

DailyCyberSecurity@infosec.exchange at 2026-09-30T20:20:10.000Z ##

Apple released the urgent iOS 26.7.1 update to patch a critical zero-day vulnerability (CVE-2026-86950) in CoreGraphics, preventing arbitrary code execution.

#AppleSecurity #iOSUpdate #ZeroDay #CyberSecurity #TechNews

dailytechnow.com/apple-patches

##

beyondmachines1@infosec.exchange at 2026-09-30T11:01:12.000Z ##

Apple Patches Actively Exploited Zero-Day in iOS 26, iPadOS 26 and macOS

Apple patched a zero-click vulnerability (CVE-2026-86950) in iOS 26 and macOS 26 that allow remote code execution and data theft, and has been exploited

**If you use an iPhone, iPad or Mac, update it right now to iOS/iPadOS 26.7.1, macOS Tahoe 26.7.1 or macOS Sequoia 15.8.1. Alterantively, where possible, move to iOS 27. Attackers are already using this flaw to take over devices and steal personal data. If you're a likely target, such as a journalist, activist or executive, consider turning on Lockdown Mode for extra protection.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

benzogaga33@mamot.fr at 2026-09-30T09:40:04.000Z ##

Apple a corrigé une faille CoreGraphics exploitée pour cibler des utilisateurs d’iPhone (CVE-2026-86950) it-connect.fr/apple-cve-2026-8 #ActuCybersécurité #Cybersécurité #Vulnérabilité #Apple

##

CVE-2026-78210
(0 None)

EPSS: 0.00%

updated 2026-10-01T16:17:59.517000

1 posts

In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts in an environment without possessing the required authorization.

offseq@infosec.exchange at 2026-10-01T12:00:24.000Z ##

CVE-2026-78210: HIGH severity in Octopus Server (CVSS 7.1) lets users with scoped permissions execute unauthorized scripts in certain environments. Patch status unknown — minimize permissions and monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #OctopusDeploy #Vuln #CVE202678210

##

CVE-2026-101283
(0 None)

EPSS: 0.43%

updated 2026-10-01T16:17:32.460000

1 posts

iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client overflows the heap via an oversized authtoken; fixed in 3.22

offseq@infosec.exchange at 2026-10-01T00:00:37.000Z ##

CVE-2026-101283: CRITICAL heap buffer overflow in esnet iperf3 (v3.20 & v3.21). Unauthenticated attackers can trigger memory corruption via decrypt_rsa_message(). Upgrade to 3.22 ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026101283 #infosec #vulnerability

##

CVE-2026-79899
(7.9 HIGH)

EPSS: 0.00%

updated 2026-10-01T15:30:50

1 posts

Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to obtain CA secret or host private-key material while the utility runs, or obtain CA secret material left behind after successful certificate

thehackerwire@mastodon.social at 2026-10-01T17:04:30.000Z ##

🟠 CVE-2026-79899 - High (7.9)

Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp m...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79898
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-10-01T15:30:50

1 posts

Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs through BCC, the WSI REST or SOAP API, or the cacrl command-line interface could cause shell command substitution to be processed by crlserver as root on the BoKS Master. BCC and WSI provide network-accessible administration paths and do not require a local sudo or suexec r

thehackerwire@mastodon.social at 2026-10-01T17:04:21.000Z ##

🔴 CVE-2026-79898 - Critical (9.1)

Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs through BCC, the WSI REST or SOAP API, or the cacrl command-line interface could cause shell command substitution to be p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97284
(8.8 HIGH)

EPSS: 0.00%

updated 2026-10-01T15:30:50

1 posts

Contributor PHP Object Injection in Icegram <= 3.1.31 versions.

CVE-2026-79901
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-10-01T15:30:49

1 posts

In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.

thehackerwire@mastodon.social at 2026-10-01T15:03:49.000Z ##

🔴 CVE-2026-79901 - Critical (9.9)

In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97277
(7.6 HIGH)

EPSS: 0.00%

updated 2026-10-01T15:30:44

1 posts

Subscriber Broken Access Control in Social Boost <= 3.6.2 versions.

thehackerwire@mastodon.social at 2026-10-01T16:18:38.000Z ##

🟠 CVE-2026-97277 - High (7.6)

Subscriber Broken Access Control in Social Boost &lt;= 3.6.2 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62059
(7.6 HIGH)

EPSS: 0.00%

updated 2026-10-01T15:30:41

1 posts

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Blind SQL Injection.This issue affects Ultimate Member: from n/a through 2.13.1.

1 repos

https://github.com/Hassham1/CVE-2026-62059-ultimate-member-sqli-poc

thehackerwire@mastodon.social at 2026-10-01T15:04:07.000Z ##

🟠 CVE-2026-62059 - High (7.6)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Blind SQL Injection.This issue affects Ultimate Member: from n/a through 2.13.1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92966
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-10-01T15:17:35.830000

1 posts

The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbit

1 repos

https://github.com/murrez/CVE-2026-92966

offseq@infosec.exchange at 2026-10-01T06:00:25.000Z ##

CVE-2026-92966: CRITICAL code injection in LatePoint Appointment Booking Plugin (<=5.7.0) for WordPress. Unauthenticated attackers can inject & execute shortcodes, risking full site compromise. Disable plugin or restrict access until patched. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202692966

##

CVE-2024-58388
(7.5 HIGH)

EPSS: 0.00%

updated 2026-10-01T15:17:17.347000

3 posts

Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply directory traversal sequences such as path=/manual/../../../<path> to access files outside the intended manual directory, inclu

DailyCyberSecurity at 2026-10-02T03:19:39.563Z ##

Sharp printer vulnerability CVE-2024-58388 lets attackers read files without login. PoC is public and attacks seen in the wild. Patch now.

securityonline.info/sharp-prin

##

DailyCyberSecurity@infosec.exchange at 2026-10-02T03:19:39.000Z ##

Sharp printer vulnerability CVE-2024-58388 lets attackers read files without login. PoC is public and attacks seen in the wild. Patch now.

#Sharp #ToshibaTec #CVE202458388 #PrinterSecurity #LFI #PoC #ExploitedInTheWild

securityonline.info/sharp-prin

##

cR0w@infosec.exchange at 2026-10-01T14:52:02.000Z ##

Fuck this bullshit. This 2024 CVE was just published today. Which, fine, whatever. It happens. Except it specifically says it was observed EITW in July 2024.

cve.org/CVERecord?id=CVE-2024-

Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30.

Witholding a CVE for something known to be EITW for over two years is fucking bullshit. Especially when the PoC was published in June 2024:

pierrekim.github.io/blog/2024-

But at least there's a Nuclei template:

github.com/projectdiscovery/nu

##

CVE-2026-66246
(8.8 HIGH)

EPSS: 0.00%

updated 2026-10-01T15:07:27.747000

1 posts

iControl is affected by a Broken Access Control vulnerability, which could allow an attacker to exploit missing authentication checks or insecure direct object references (IDOR), enabling privilege escalation and the unauthorized modification or deletion of sensitive application data.

thehackerwire@mastodon.social at 2026-10-01T15:03:58.000Z ##

🟠 CVE-2026-66246 - High (8.8)

iControl is affected by a Broken Access Control vulnerability, which could allow an attacker to exploit missing authentication checks or insecure direct object references (IDOR), enabling privilege escalation and the unauthorized modification or d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-102149
(9.4 CRITICAL)

EPSS: 0.33%

updated 2026-10-01T14:17:19.140000

1 posts

Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to. This could allow an attacker to associate a certificate with another user's account, affecting the confidentiality and integrity of that account's encrypted mail and, where certificate-based login is enabled, potentially permitting unauthorized access to the account.

offseq@infosec.exchange at 2026-10-01T09:00:24.000Z ##

Kiteworks Email Protection Gateway <9.5.1 has a CRITICAL vuln (CVE-2026-102149, CVSS 9.4): attackers can assign certificates to other user accounts, risking encrypted email exposure & unauthorized access. Await patch, consider disabling cert login. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026102149 #infosec

##

CVE-2026-102106
(9.1 CRITICAL)

EPSS: 0.64%

updated 2026-10-01T14:17:14.417000

1 posts

Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email Protection Gateway did not consistently enforce administrator authentication, so the required password check could be bypassed. An attacker who referenced a valid administrator account could potentially create, modify, or delete internal users and managed domains and

offseq@infosec.exchange at 2026-10-01T07:30:24.000Z ##

CVE-2026-102106 (CRITICAL, CVSS 9.1): Kiteworks Email Protection Gateway (<9.5.0) suffers improper admin authentication — attackers can bypass password checks & gain full admin access. Restrict admin service access & monitor for patches. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Infosec

##

CVE-2026-103655(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-10-01T09:30:42

1 posts

MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its time-based validity window. The issue exists in the user login flow where a TOTP code is verified as a second authentication factor. Because the system did not record whether a given TOTP period had already been consumed, the same c

cR0w@infosec.exchange at 2026-10-01T12:52:40.000Z ##

This is an interesting vuln and one that can be a great example of why a sev:CRIT may not be high priority.

sev:CRIT 9.3 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its time-based validity window. The issue exists in the user login flow where a TOTP code is verified as a second authentication factor. Because the system did not record whether a given TOTP period had already been consumed, the same code remained valid for its entire time window (typically 30 seconds). An attacker who captures a legitimate code during a user's login could replay it to authenticate a second session as that user. Preconditions: - The target user has TOTP-based two-factor authentication enabled. - The attacker is in a position to observe or intercept the TOTP code during a legitimate login (e.g., network-level interception, shoulder surfing, or a compromised client). - The replay must occur within the TOTP validity period. Security impact: - Unauthorized account access by replaying a captured one-time code. - Potential compromise of threat-intelligence data and administrative functions accessible to the targeted user. Affected versions: <v2.5.48.

nvd.nist.gov/vuln/detail/cve-2

##

CVE-2025-41753
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-01T09:30:33

1 posts

The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise.

certvde@infosec.exchange at 2026-10-01T06:41:41.000Z ##

🔒 New CSAF advisory published

VDE-2025-102
WAGO: Multiple Devices are affected by a Vulnerability in BACnet IP Stack
CVE-2025-41753

Multiple WAGO devices are affected by a vulnerability in the dynamic creation of BACnet File Objects. The object name is used as a file path without sufficient validation and is not restricted to the intend…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: wago.csaf-tp.certvde.com/.well

#OT #Advisory

##

CVE-2026-47599
(7.8 HIGH)

EPSS: 0.16%

updated 2026-10-01T04:18:18.593000

1 posts

NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source kernel module where an unprivileged local user could cause improper preservation of memory access permissions during DMA mapping. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.

thehackerwire@mastodon.social at 2026-09-30T16:31:54.000Z ##

🟠 CVE-2026-47599 - High (7.8)

NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source kernel module where an unprivileged local user could cause improper preservation of memory access permissions during DMA mapping. A successful exploit of this vulnerab...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13313(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-10-01T03:31:14

2 posts

An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, to bypass security mechanisms and enable the Telnet service, thereby executing arbitrary commands with root privileges and potentially affecting other devices connected to the router. Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security

offseq@infosec.exchange at 2026-10-01T13:30:28.000Z ##

CVE-2026-13313 (HIGH, CVSS 8.9) in ASUS routers: Authenticated attackers can enable Telnet via debug code, gaining root command execution. Restrict management access & monitor Telnet until patch info is released. radar.offseq.com/threat/cve-20 #OffSeq #ASUS #Infosec #Vuln

##

DailyCyberSecurity@infosec.exchange at 2026-10-01T03:40:21.000Z ##

Learn how to patch critical ASUS security vulnerabilities like CVE-2026-13313 to protect your routers and motherboards from severe network exploits.

#ASUS #Cybersecurity #Vulnerability #Router #Hardware

securityonline.info/asus-secur

##

CVE-2026-101276(CVSS UNKNOWN)

EPSS: 0.43%

updated 2026-09-30T21:32:15

1 posts

iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker dereferences a freed iperf_stream; fixed in 3.22.

offseq@infosec.exchange at 2026-10-01T01:30:23.000Z ##

CVE-2026-101276: esnet iperf3 3.21 suffers a CRITICAL remote use-after-free (CVSS 9.2). Unauthenticated attackers can trigger memory corruption or RCE. Upgrade to 3.22+ now. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE2026101276 #iperf3 #infosec

##

CVE-2026-92870
(7.5 HIGH)

EPSS: 0.32%

updated 2026-09-30T20:17:37.253000

1 posts

A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termination.

thehackerwire@mastodon.social at 2026-09-30T11:47:52.000Z ##

🟠 CVE-2026-92870 - High (7.5)

A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termination.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62146
(7.8 HIGH)

EPSS: 0.15%

updated 2026-09-30T20:17:34.013000

1 posts

A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influenced pod metadata to overwrite CRI-O's own reserved sandbox bookkeeping; once reloaded as trusted after a restart, a later container recreate in that sandbox can expose a host-side runtime-management resource inside the container, enabling container escape.

1 repos

https://github.com/TeamN4C/SG-2026-0026

thehackerwire@mastodon.social at 2026-09-30T12:46:01.000Z ##

🟠 CVE-2026-62146 - High (7.8)

A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influenced pod metadata to overwrite CRI-O's own reserved sandbox bookkeeping; once reloaded as trusted after a restart, a later container recreate in that sandbox can expo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-102489
(0 None)

EPSS: 0.71%

updated 2026-09-30T19:57:08.043000

3 posts

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.

DailyCyberSecurity at 2026-10-02T03:54:26.328Z ##

Attackers exploited Zammad zero-day flaws CVE-2026-102489 and CVE-2026-102490 to gain root at DIVD. Upgrade to Zammad 7 or go offline.

securityonline.info/zammad-zer

##

DailyCyberSecurity@infosec.exchange at 2026-10-02T03:54:26.000Z ##

Attackers exploited Zammad zero-day flaws CVE-2026-102489 and CVE-2026-102490 to gain root at DIVD. Upgrade to Zammad 7 or go offline.

#Zammad #ZeroDay #CVE2026102489 #CVE2026102490 #DIVD #AIAgent #ExploitedInTheWild

securityonline.info/zammad-zer

##

security_crawler_carl@infosec.exchange at 2026-09-30T20:28:42.000Z ##

🏆 New Achievement! Root in the Wild!

Observe the Zammad ticketing system in its natural habitat — quietly managing support queues, utterly unaware it carries two zero-days, CVE-2026-102489 and CVE-2026-102490, like a doomed species bearing a genetic flaw it cannot name. An autonomous AI agent, patient and efficient as a nature film's apex predator, chained the pair together: session hijack, remote code execution, root escalation — all in mere seconds. The herd had no warning. (1/2)

##

CVE-2026-102490
(0 None)

EPSS: 0.32%

updated 2026-09-30T19:57:08.043000

3 posts

All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

DailyCyberSecurity at 2026-10-02T03:54:26.328Z ##

Attackers exploited Zammad zero-day flaws CVE-2026-102489 and CVE-2026-102490 to gain root at DIVD. Upgrade to Zammad 7 or go offline.

securityonline.info/zammad-zer

##

DailyCyberSecurity@infosec.exchange at 2026-10-02T03:54:26.000Z ##

Attackers exploited Zammad zero-day flaws CVE-2026-102489 and CVE-2026-102490 to gain root at DIVD. Upgrade to Zammad 7 or go offline.

#Zammad #ZeroDay #CVE2026102489 #CVE2026102490 #DIVD #AIAgent #ExploitedInTheWild

securityonline.info/zammad-zer

##

security_crawler_carl@infosec.exchange at 2026-09-30T20:28:42.000Z ##

🏆 New Achievement! Root in the Wild!

Observe the Zammad ticketing system in its natural habitat — quietly managing support queues, utterly unaware it carries two zero-days, CVE-2026-102489 and CVE-2026-102490, like a doomed species bearing a genetic flaw it cannot name. An autonomous AI agent, patient and efficient as a nature film's apex predator, chained the pair together: session hijack, remote code execution, root escalation — all in mere seconds. The herd had no warning. (1/2)

##

CVE-2026-94545
(0 None)

EPSS: 0.80%

updated 2026-09-30T19:57:08.043000

2 posts

Satori is a library to convert HTML and CSS to SVG. Starting in version 0.0.27 and prior to version 0.33.5, Satori does not properly escape certain values before including them in generated SVG output. This can allow crafted values to be interpreted as SVG markup. The impact depends on how the generated SVG is consumed. Version 0.33.5 contains a patch. No complete workaround exists besides upgradi

5 repos

https://github.com/Hassham1/CVE-2026-94545-nextjs-og-poc

https://github.com/EQSTLab/CVE-2026-94545

https://github.com/HORKimhab/CVE-2026-94545

https://github.com/mhtsec/CVE-2026-94545

https://github.com/MRdark-ops/CVE-2026-94545-

CVE-2026-79625
(8.1 HIGH)

EPSS: 0.40%

updated 2026-09-30T19:57:08.043000

2 posts

Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authenticated remote attacker with monitoring access can exploit this issue to cause incorrect data processing or a denial-of-service condition.

thehackerwire@mastodon.social at 2026-09-30T11:32:19.000Z ##

🟠 CVE-2026-79625 - High (8.1)

Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authenticated re...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

certvde@infosec.exchange at 2026-09-30T09:22:53.000Z ##

🔒 New CSAF advisory published

VDE-2026-097
CODESYS Control Runtime - Improper Synchronization in Monitoring
CVE-2026-79625

The monitoring functionality of affected CODESYS Control runtime systems processes read and write requests to PLC application data sent by the CODESYS Development System and other clients suc…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: codesys.csaf-tp.certvde.com/.w

#OT #Advisory

##

CVE-2026-76992
(7.5 HIGH)

EPSS: 0.57%

updated 2026-09-30T19:57:08.043000

2 posts

The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus leading to a total loss of availablity.

thehackerwire@mastodon.social at 2026-09-30T11:32:09.000Z ##

🟠 CVE-2026-76992 - High (7.5)

The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

certvde@infosec.exchange at 2026-09-30T11:04:07.000Z ##

🔒 New CSAF advisory published

VDE-2026-094
CODESYS Gateway Client - Uncontrolled Memory Allocation
CVE-2026-76992

The CODESYS Gateway Client (CmpGatewayClient) is used by various CODESYS products to establish PLC communication via the CODESYS Gateway.

Due to missing limits on memory allocations derived from a si…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: codesys.csaf-tp.certvde.com/.w

#OT #Advisory

##

CVE-2026-47591
(7.8 HIGH)

EPSS: 0.18%

updated 2026-09-30T18:33:55

1 posts

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could bypass read-only memory protection due to incorrect authorization, enabling write access to memory marked read-only. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

thehackerwire@mastodon.social at 2026-09-30T17:01:48.000Z ##

🟠 CVE-2026-47591 - High (7.8)

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could bypass read-only memory protection due to incorrect authorization, enabling write access to memory marked read-only. A successfu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47600
(7.8 HIGH)

EPSS: 0.19%

updated 2026-09-30T18:33:50

1 posts

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an error-handling path could operate on an improperly initialized resource. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.

thehackerwire@mastodon.social at 2026-09-30T16:32:03.000Z ##

🟠 CVE-2026-47600 - High (7.8)

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an error-handling path could operate on an improperly initialized resource. A successful exploit of this vulnerability might lead to code execu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47601
(7.8 HIGH)

EPSS: 0.18%

updated 2026-09-30T18:33:49

1 posts

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel module DMA-BUF import path where an unprivileged local user could cause improper preservation of memory access permissions when importing a read-only buffer from another device's DMA-BUF exporter. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denia

thehackerwire@mastodon.social at 2026-09-30T16:32:12.000Z ##

🟠 CVE-2026-47601 - High (7.8)

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel module DMA-BUF import path where an unprivileged local user could cause improper preservation of memory access permissions when importing a read-onl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76504
(9.8 CRITICAL)

EPSS: 1.10%

updated 2026-09-30T18:33:25

20 posts

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a speci

1 repos

https://github.com/ShadowForge-Cyber/CVE-2026-76504-Proof-of-concept

youranonnewsirc@nerdculture.de at 2026-10-01T22:26:13.000Z ##

Recent geopolitical news indicates Russia initiated a winter strike campaign targeting Ukraine's energy infrastructure on September 30. In cybersecurity, CISA added a critical Cisco Catalyst SD-WAN Manager authentication bypass flaw (CVE-2026-76504) to its Known Exploited Vulnerabilities catalog on September 30. On the technology front, Chinese hackers were reported to be impersonating AI experts to target US policy minds on October 1. Additionally, the NSA announced new post-quantum cryptography measures to safeguard national security systems on October 1.

#AnonNews_irc #Cybersecurity #News

##

catc0n at 2026-10-01T21:13:13.805Z ##

Cisco SD-WAN CVE-2026-76504 analysis and exploit walk-through available c/o Landon Rice on the @vulncheck team ㊙️

vulncheck.com/blog/revenge-of-

##

Matchbook3469@mastodon.social at 2026-10-01T20:52:17.000Z ##

🔵 THREAT INTELLIGENCE

CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

Vulnerability | CRITICAL
CVEs: CVE-2026-76504

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst...

Full analysis:
yazoul.net/news/article/cisa-a

by Yazoul AI

#ThreatIntel #SecurityNews #CyberNews

##

youranonnewsirc@nerdculture.de at 2026-10-01T22:26:13.000Z ##

Recent geopolitical news indicates Russia initiated a winter strike campaign targeting Ukraine's energy infrastructure on September 30. In cybersecurity, CISA added a critical Cisco Catalyst SD-WAN Manager authentication bypass flaw (CVE-2026-76504) to its Known Exploited Vulnerabilities catalog on September 30. On the technology front, Chinese hackers were reported to be impersonating AI experts to target US policy minds on October 1. Additionally, the NSA announced new post-quantum cryptography measures to safeguard national security systems on October 1.

#AnonNews_irc #Cybersecurity #News

##

catc0n@infosec.exchange at 2026-10-01T21:13:13.000Z ##

Cisco SD-WAN CVE-2026-76504 analysis and exploit walk-through available c/o Landon Rice on the @vulncheck team ㊙️

vulncheck.com/blog/revenge-of-

##

thecybermind@infosec.exchange at 2026-10-01T12:27:31.000Z ##

Critical Threat Advisory: Cisco Catalyst SD-WAN Manager (CVE-2026-76504)

CISA’s active exploitation verification of CVE-2026-76504 demands an immediate, high-priority posture adjustment across all Cisco Catalyst SD-WAN Manager…...

thecybermind.co/2026/10/01/cve

##

thecybermind@infosec.exchange at 2026-10-01T11:16:17.000Z ##

Critical Threat Advisory: Cisco Catalyst SD-WAN Manager (CVE-2026-76504)

CISA’s active exploitation verification of CVE-2026-76504 demands an immediate, high-priority posture adjustment across all Cisco Catalyst SD-WAN Manager…...

thecybermind.co/2026/10/01/cve

##

thecybermind@infosec.exchange at 2026-10-01T11:05:43.000Z ##

Critical Threat Advisory: Cisco Catalyst SD-WAN Manager (CVE-2026-76504)

Strategic Threat Advisory: CVE-2026-76504 Affected Vendor & Product: Cisco - Catalyst SD-WAN Manager Vulnerability Class (CWE):...

thecybermind.co/2026/10/01/cve

##

thecybermind@infosec.exchange at 2026-10-01T11:02:05.000Z ##

Critical Threat Advisory: Cisco Catalyst SD-WAN Manager (CVE-2026-76504)

Threat Advisory: CVE-2026-76504 Affected Vendor/Product: Cisco - Catalyst SD-WAN Manager Vulnerability Type (CWE): N/A Operational Threat Level:...

thecybermind.co/2026/10/01/cve

##

beyondmachines1@infosec.exchange at 2026-10-01T08:01:13.000Z ##

Cisco Patches Actively Exploited Zero-Day in Catalyst SD-WAN Manager

Cisco released security updates for a zero-day vulnerability (CVE-2026-76504) in Catalyst SD-WAN Manager that attackers are actively exploiting to gain admin privileges. The flaw allows unauthenticated remote access to the management API through URI encoding bypasses.

**If you run Cisco Catalyst SD-WAN Manager, make sure it is isolated from the internet and reachable from trusted networks only, then patch it ASAP to the fixed version for your release (or migrate if you're on anything older than 20.9). Before patching, save an admin-tech file and check the logs for suspicious j_security_check requests or activity from viptela-reserved- accounts. If you find any, assume your whole SD-WAN network is compromised and call in incident response.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

secdb@infosec.exchange at 2026-09-30T19:00:11.000Z ##

🚨 [CISA-2026:0930] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-76504 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Catalyst SD-WAN Manager
- Notes: sec.cloudapps.cisco.com/securi ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260930 #cisa20260930 #cve_2026_76504 #cve202676504

##

cyberworldops@infosec.exchange at 2026-09-30T18:50:00.000Z ##

Cisco confirmed active exploitation of CVE-2026-76504, an authentication bypass in Catalyst SD-WAN Manager API session handling. It allows unauthenticated remote admin access, enabling full control of SD-WAN fabrics. Prioritize patching and review management-plane logs for abuse. #CiscoSecurity #SdWan #AuthBypass

cyberworldops.eu/en/cisco-sd-w

##

DarkWebInformer@infosec.exchange at 2026-09-30T18:34:31.000Z ##

🚨 Cisco warns critical SD-WAN Manager zero-day is actively exploited

CVE-2026-76504 is a critical authentication bypass affecting Cisco Catalyst SD-WAN Manager.

The flaw allows an unauthenticated remote attacker to send a crafted HTTP request that bypasses an API authentication rule and grants access with admin privileges.
⠀
The vulnerability carries a CVSS score of 9.8 and affects the product regardless of its configuration.

Cisco became aware of active exploitation in September after investigating a support case.
⠀
There are no workarounds. Administrators should install a fixed release immediately and investigate internet-facing systems for signs of compromise.

Source: bleepingcomputer.com/news/secu

##

ifin@infosec.exchange at 2026-09-30T18:29:01.000Z ##

Well would you look at that; it's Cisco 0-day o'clock again.

ifin.network/t/cve-2026-76504-

#ThreatIntel #ThreatIntelligence #IFIN

##

cisakevtracker@mastodon.social at 2026-09-30T18:01:01.000Z ##

CVE ID: CVE-2026-76504
Vendor: Cisco
Product: Catalyst SD-WAN Manager
Date Added: 2026-09-30
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

news@fawkes.rocks at 2026-09-30T17:22:28.000Z ##

Cisco SD-WAN Manager zero-day CVE-2026-76504 exploited

fawkes.rocks/2026/09/30/cisco-

##

security_crawler_carl@infosec.exchange at 2026-09-30T16:54:42.000Z ##

🏆 New Achievement! Unauthenticated and Loving It!

Welcome to Module 7: API Authentication and Why Your Vendor Forgot To Include It. Today's learning objective is CVE-2026-76504, a critical zero-day in Cisco Catalyst SD-WAN Manager. Attackers are actively exploiting a flaw in the API authentication mechanism to gain full administrator privileges on your systems. Without a username. Without a password. Without so much as a polite knock. (1/3)

##

AAKL@infosec.exchange at 2026-09-30T16:09:42.000Z ##

New advisory, new flaw.

Cisco: CRITICAL CVE-2026-76504: Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco

More on that Cisco vulnerability:

Rapid7: Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504) rapid7.com/blog/post/etr-criti @Rapid7Official

Also:

Broadcom has several advisories today, three of them addressing critical vulnerabilities support.broadcom.com/web/ecx/s #Broadcom #infosec #vulnerability

##

oversecurity@mastodon.social at 2026-09-30T15:50:31.000Z ##

Cisco warns of new SD-WAN zero-day exploited in attacks

Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are...

🔗️ [Bleepingcomputer] link.is.it/cZgOkH

##

DailyCyberSecurity@infosec.exchange at 2026-09-30T15:16:24.000Z ##

Attackers exploit CVE-2026-76504, a 9.8 authentication bypass in Cisco SD-WAN Manager that grants admin API access. Patch now.

#Cisco #SDWAN #CVE202676504 #AuthenticationBypass #ActivelyExploited #CyberSecurity

securityonline.info/cisco-sd-w

##

CVE-2026-10764
(8.7 HIGH)

EPSS: 0.24%

updated 2026-09-30T17:32:07.107000

1 posts

Information disclosure in BVMS 4.5 up to 12.3 including allows man-in-the-middle attackers to gain unauthorized access to sensitive data.

thehackerwire@mastodon.social at 2026-09-30T11:33:20.000Z ##

🟠 CVE-2026-10764 - High (8.7)

Information disclosure in BVMS 4.5 up to 12.3 including allows man-in-the-middle attackers to gain unauthorized access to sensitive data.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78902
(6.1 MEDIUM)

EPSS: 0.30%

updated 2026-09-30T17:23:08.953000

1 posts

Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows an attacker to execute arbitrary code via the pfBlockerNG package

christopherkunz@chaos.social at 2026-10-01T15:14:28.000Z ##

@hlux @bkastl Im Prinzip stimmt das mit meiner Wahrnehmung überein, vor allem im Vergleich mit Citrix, Ivanti, Fortinet, Cisco. Aber auch hier gab's neulich was Spannendes: netspi.com/blog/technical-blog

##

CVE-2026-92867
(8.8 HIGH)

EPSS: 0.34%

updated 2026-09-30T17:16:51.120000

1 posts

An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker to cause abnormal process termination or arbitrary code execution.

thehackerwire@mastodon.social at 2026-09-30T12:02:23.000Z ##

🟠 CVE-2026-92867 - High (8.8)

An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker to cause abnormal process termination or arbitrary code execution.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92871
(7.5 HIGH)

EPSS: 0.29%

updated 2026-09-30T16:47:57.730000

1 posts

A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process.

thehackerwire@mastodon.social at 2026-09-30T12:02:04.000Z ##

🟠 CVE-2026-92871 - High (7.5)

A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76570
(0 None)

EPSS: 0.50%

updated 2026-09-30T16:44:39.840000

1 posts

Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The front-end CRUD API controller performs no Joomla token validation and no authentication check on any task. Table names, column names, and values are taken directly from request parameters and concatenated into SQL queries, allowing SQLi for reading and writing queries.

1 repos

https://github.com/murrez/CVE-2026-76570

AAKL@infosec.exchange at 2026-09-30T16:21:59.000Z ##

New. This relates to CVE-2026-76570.

VulnCheck: JCTables for Joomla: When "Already Escaped" Means Injectable vulncheck.com/blog/jctables-un @vulncheck #infoec #vulnerability #SQL

##

CVE-2026-102458
(9.8 CRITICAL)

EPSS: 0.43%

updated 2026-09-30T16:30:42.327000

2 posts

EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain other users' plaintext passwords through a specific API.

thehackerwire@mastodon.social at 2026-09-30T11:47:43.000Z ##

🔴 CVE-2026-102458 - Critical (9.8)

EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain other users' plaintext passwords through a specific API.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-30T09:00:25.000Z ##

CRITICAL vuln in DigiWin EasyFlow .NET (CVE-2026-102458, CVSS 9.3): Missing authentication allows remote attackers to obtain plaintext passwords via API. Affects 6.6 – 6.6.19, 8.1 – 8.1.5. Patch ASAP! radar.offseq.com/threat/cve-20 #OffSeq #CVE2026_102458 #infosec #appsec

##

CVE-2026-102455
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-09-30T16:30:42.327000

1 posts

EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.

thehackerwire@mastodon.social at 2026-09-30T11:47:32.000Z ##

🔴 CVE-2026-102455 - Critical (9.8)

EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75098
(7.5 HIGH)

EPSS: 0.90%

updated 2026-09-30T16:18:58.363000

1 posts

The Product Designer App plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.3 via the 'svg' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The endpoint's only authentication gate relies on a nonce and token that are both publicl

thehackerwire@mastodon.social at 2026-09-30T11:33:29.000Z ##

🟠 CVE-2026-75098 - High (7.5)

The Product Designer App plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.3 via the 'svg' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18782
(9.8 CRITICAL)

EPSS: 0.58%

updated 2026-09-30T16:18:57.403000

1 posts

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection. This issue affects Trex MES: through 2026-09-29.

1 repos

https://github.com/Hasanuyarrr/CVE-2026-18782-TREX-MES-Uygulamalarinda-SQL-Zafiyeti

thehackerwire@mastodon.social at 2026-09-30T15:47:46.000Z ##

🔴 CVE-2026-18782 - Critical (9.8)

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection.

This issue affects Trex MES: through...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82307
(9.8 CRITICAL)

EPSS: 0.47%

updated 2026-09-30T16:18:57.403000

1 posts

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection. This issue affects SOPLOG: before Soplog 2026.9.4.1.

thehackerwire@mastodon.social at 2026-09-30T14:32:08.000Z ##

🔴 CVE-2026-82307 - Critical (9.8)

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection.

This issue affects SOPLOG: before Soplog 2026.9.4.1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-6806
(7.5 HIGH)

EPSS: 0.27%

updated 2026-09-30T16:18:39.783000

1 posts

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'stm_lat/stm_lng' parameter in all versions up to, and including, 1.4.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additio

thehackerwire@mastodon.social at 2026-09-30T12:02:13.000Z ##

🟠 CVE-2026-6806 - High (7.5)

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'stm_lat/stm_lng' parameter in all versions up to, and including, 1.4.109 due to insufficient escaping on the u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-102508
(0 None)

EPSS: 0.13%

updated 2026-09-30T16:14:10.347000

1 posts

Improper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of Apache PLC4X (PLC4J) allows an attacker in a network position between client and server to impersonate the OPC UA server and to read, forge or modify secure-channel traffic, including user credential ssent by the client. The defect manifests differently depending on the version: - In 0.9.0

CVE-2026-94002
(7.5 HIGH)

EPSS: 0.43%

updated 2026-09-30T16:13:13.493000

1 posts

Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. The sshd-sftp component provides support for SFTP. The SFTP client implementation, when receiving a reply, did not check that this reply corresponded to a request

thehackerwire@mastodon.social at 2026-09-30T11:33:10.000Z ##

🟠 CVE-2026-94002 - High (7.5)

Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5.

Apache
MINA SSHD is a Java library for client-side and server-side SSH. The sshd-sftp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93994
(8.1 HIGH)

EPSS: 0.47%

updated 2026-09-30T16:13:13.493000

1 posts

Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH servers can be configured to require multi-authentication schemes, for instance two different public keys, not just one. In OpenSSH, this would be done by setting in sshd_config AuthenticationMethods "publickey,publickey". Apache MINA SSHD provides an equivalent configuration mechanism. In Apache MINA SSHD versions up

thehackerwire@mastodon.social at 2026-09-30T11:32:29.000Z ##

🟠 CVE-2026-93994 - High (8.1)

Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH servers can be configured to require multi-authentication schemes, for instance two different public keys, not just one. In OpenSSH, this would be done by setting in sshd_...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94052
(9.1 CRITICAL)

EPSS: 0.55%

updated 2026-09-30T16:13:13.493000

1 posts

A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks. Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the server side with an LDAP server. sshd-ld

thehackerwire@mastodon.social at 2026-09-30T11:01:32.000Z ##

🔴 CVE-2026-94052 - Critical (9.1)

A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks.

Apache MINA SSHD is a Java library for client-side and server-side SSH. T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62097
(7.6 HIGH)

EPSS: 0.38%

updated 2026-09-30T15:31:44

1 posts

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPTasty Business Directory business-directory-plugin allows Blind SQL Injection.This issue affects Business Directory: from n/a through 6.4.27.

thehackerwire@mastodon.social at 2026-09-30T15:47:37.000Z ##

🟠 CVE-2026-62097 - High (7.6)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPTasty Business Directory business-directory-plugin allows Blind SQL Injection.This issue affects Business Directory: from n/a through 6.4.27.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18783
(8.8 HIGH)

EPSS: 0.39%

updated 2026-09-30T15:31:43

1 posts

Missing authentication for critical function vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Authentication Bypass. This issue affects Trex MES: through 2026-09-29.

1 repos

https://github.com/Hasanuyarrr/CVE-2026-18783-TREX-MES-Uygulamalarinda-Yetkisiz-Nesne-Erisimi

thehackerwire@mastodon.social at 2026-09-30T15:47:56.000Z ##

🟠 CVE-2026-18783 - High (8.8)

Missing authentication for critical function vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Authentication Bypass.

This issue affects Trex MES: through 2026-09-29.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97197
(7.5 HIGH)

EPSS: 0.39%

updated 2026-09-30T15:31:38

1 posts

Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions.

thehackerwire@mastodon.social at 2026-09-30T14:49:01.000Z ##

🟠 CVE-2026-97197 - High (7.5)

Unauthenticated Broken Access Control in WordPress Backup & Migration &lt;= 1.6.0 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97241
(7.5 HIGH)

EPSS: 0.42%

updated 2026-09-30T15:31:38

1 posts

Unauthenticated Sensitive Data Exposure in BackupEase <= 2.2.2 versions.

thehackerwire@mastodon.social at 2026-09-30T14:48:52.000Z ##

🟠 CVE-2026-97241 - High (7.5)

Unauthenticated Sensitive Data Exposure in BackupEase &lt;= 2.2.2 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97240
(7.5 HIGH)

EPSS: 0.42%

updated 2026-09-30T15:31:38

1 posts

Unauthenticated Sensitive Data Exposure in StifLi Backup Tools <= 2.2.7 versions.

thehackerwire@mastodon.social at 2026-09-30T14:19:05.000Z ##

🟠 CVE-2026-97240 - High (7.5)

Unauthenticated Sensitive Data Exposure in StifLi Backup Tools &lt;= 2.2.7 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97248
(9.8 CRITICAL)

EPSS: 0.56%

updated 2026-09-30T15:31:38

1 posts

Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions.

thehackerwire@mastodon.social at 2026-09-30T14:18:54.000Z ##

🔴 CVE-2026-97248 - Critical (9.8)

Unauthenticated PHP Object Injection in Booking Activities &lt;= 1.18.7.1 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97244
(7.5 HIGH)

EPSS: 0.41%

updated 2026-09-30T15:31:38

1 posts

Contributor Path Traversal in Creator LMS <= 1.2.19 versions.

CVE-2026-97274
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-09-30T15:31:34

1 posts

Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions.

thehackerwire@mastodon.social at 2026-09-30T13:31:56.000Z ##

🔴 CVE-2026-97274 - Critical (9.8)

Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) &lt;= 7.1.2 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97293
(8.5 HIGH)

EPSS: 0.36%

updated 2026-09-30T14:18:18.460000

1 posts

Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions.

thehackerwire@mastodon.social at 2026-09-30T13:31:47.000Z ##

🟠 CVE-2026-97293 - High (8.5)

Contributor SQL Injection in Media LIbrary Assistant &lt;= 3.41 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97287
(8.5 HIGH)

EPSS: 0.36%

updated 2026-09-30T14:18:17.797000

1 posts

Contributor SQL Injection in Event Tickets <= 5.29.5 versions.

CVE-2026-96837
(8.8 HIGH)

EPSS: 0.73%

updated 2026-09-30T14:18:12.963000

1 posts

Contributor Remote Code Execution (RCE) in CartFlows <= 3.2.0 versions.

thehackerwire@mastodon.social at 2026-09-30T14:49:10.000Z ##

🟠 CVE-2026-96837 - High (8.8)

Contributor Remote Code Execution (RCE) in CartFlows &lt;= 3.2.0 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94053
(9.1 CRITICAL)

EPSS: 0.55%

updated 2026-09-30T12:35:21

1 posts

Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the server side with an LDAP server. sshd-ldap is an optional component. SS

thehackerwire@mastodon.social at 2026-09-30T11:01:42.000Z ##

🔴 CVE-2026-94053 - Critical (9.1)

Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5.

Apache MINA SSHD is a Java library for client-side and server-side SSH.
The optional sshd-ldap component p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77185
(9.1 CRITICAL)

EPSS: 0.51%

updated 2026-09-30T12:35:16

2 posts

Authentication bypass in sshd-core in Apache MINA SSHD versions 2.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 for a certain (presumed rare) way to implement an SSH server. Apache MINA SSHD is a Java library for client- and server-side SSH. In the server part of the library, a mechanism to perform "asynchronous authentication" exists. A server implemented with Apache MINA SSHD must contain explicit

thehackerwire@mastodon.social at 2026-09-30T11:01:52.000Z ##

🔴 CVE-2026-77185 - Critical (9.1)

Authentication bypass in sshd-core in Apache MINA SSHD versions 2.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 for a certain (presumed rare) way to implement an SSH server.

Apache MINA SSHD is a Java library for client- and server-side SSH. In the s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-30T10:30:28.000Z ##

Apache MINA SSHD auth bypass (CVE-2026-77185, CRITICAL, CVSS 9.1): Async public-key/hostbased auth can be skipped, risking full SSH compromise. Affected: 2.0.0 – 2.19.x, 3.0.0-M1 – M5. Patch to 2.20.0/3.0.0-M6. radar.offseq.com/threat/cve-20 #OffSeq #Apache #Infosec

##

CVE-2026-89294
(7.5 HIGH)

EPSS: 0.65%

updated 2026-09-30T09:31:20

1 posts

The Simply Schedule Appointments plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.12.27 via the 'ssa_locale' parameter parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be

thehackerwire@mastodon.social at 2026-09-30T13:17:29.000Z ##

🟠 CVE-2026-89294 - High (7.5)

The Simply Schedule Appointments plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.12.27 via the 'ssa_locale' parameter parameter. This makes it possible for authenticated attackers, with subscrib...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97196
(9.1 CRITICAL)

EPSS: 0.30%

updated 2026-09-30T09:31:11

2 posts

Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass. This issue affects GiveWP: from n/a through 4.16.9.

thehackerwire@mastodon.social at 2026-09-30T13:17:20.000Z ##

🔴 CVE-2026-97196 - Critical (9.1)

Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass.

This issue affects GiveWP: from n/a through 4.16.9.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-30T07:30:27.000Z ##

GiveWP (Liquid Web/StellarWP) CRITICAL vuln (CVE-2026-97196): Improper input validation leads to auth bypass (CVSS 9.1). Affects up to 4.16.9. Patch when available. Details: radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #WordPress

##

CVE-2026-103088
(7.5 HIGH)

EPSS: 0.69%

updated 2026-09-30T03:31:41

1 posts

Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the template file is opened through a URL handler that percent-decodes the path. In a Spring MVC application with a file: template prefix and a request-derived view name, a percent-encoded

thehackerwire@mastodon.social at 2026-09-30T13:17:38.000Z ##

🟠 CVE-2026-103088 - High (7.5)

Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the template file is opened through ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86131(CVSS UNKNOWN)

EPSS: 0.33%

updated 2026-09-30T00:32:48

3 posts

A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.

beyondmachines1@infosec.exchange at 2026-10-01T10:01:13.000Z ##

WatchGuard Patches Multiple Flaws, One Critical in Fireware OS

WatchGuard patched 15 Fireware OS vulnerabilities, the worst a critical code injection flaw (CVE-2026-86131) that lets a malicious remote BOVPN-over-TLS server run root commands on a connecting Firebox, along several pre-authentication remote code execution and DoS bugs in services such as fingerd, spamd, iked and samld.

**If you run WatchGuard Firebox appliances, upgrade Fireware OS to a fixed version ASAP (2026.3.2, 2026.2.3, 12.12.3, or 12.5.21 on T15/T35). There are 15 flaws, including a critical one with no workaround, so prioritize devices that use Branch Office VPN over TLS. Until you patch, make sure the firewall's management interface is reachable only from trusted admin networks, and only connect VPN tunnels to servers you fully control.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

cyberworldops@infosec.exchange at 2026-09-30T22:40:00.000Z ##

WatchGuard patched CVE-2026-86131 (CVSS 9.2) in Fireware OS, allowing a malicious VPN server to achieve root RCE on connecting Firebox appliances. Unpatched edge devices risk full takeover and network compromise, so prioritize updates and review VPN peers. #WatchGuard #FirewareOS #VulnManagement

cyberworldops.eu/en/malicious-

##

offseq@infosec.exchange at 2026-09-30T13:30:30.000Z ##

CRITICAL RCE (CVE-2026-86131) in WatchGuard Fireware OS enables root code execution via BOVPN over TLS. Multiple high-severity flaws also patched. No known in-the-wild attacks, but update ASAP. radar.offseq.com/threat/watchg #OffSeq #Vuln #WatchGuard #PatchTuesday #InfoSec

##

CVE-2026-96587
(10.0 CRITICAL)

EPSS: 0.34%

updated 2026-09-29T22:19:05.860000

1 posts

The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries.

CVE-2026-94204
(7.5 HIGH)

EPSS: 0.27%

updated 2026-09-29T22:19:03.923000

1 posts

The central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored objects. Because this bucket serves as shared storage for the platform, sensitive user records, live dashcam footage, application packages, and firmware files are exposed to anyone on the internet.

CVE-2026-84782
(8.2 HIGH)

EPSS: 0.39%

updated 2026-09-29T21:27:41.130000

1 posts

Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly. Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake

cyberworldops@infosec.exchange at 2026-09-30T11:10:00.000Z ##

OpenSSL disclosed CVE-2026-84782, a high-severity bug in DTLS handshake retransmission that can leak unencrypted heap data to peers or crash the process. Ubuntu describes the impact as incorrect handshake behavior or denial of service. Patch affected builds and audit DTLS-exposed services. #OpenSSL #Dtls #VulnManagement

cyberworldops.eu/en/openssl-dt

##

CVE-2026-75804
(5.3 MEDIUM)

EPSS: 0.35%

updated 2026-09-29T18:31:49

1 posts

Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size). CWE: CWE-

moltenbit@infosec.exchange at 2026-10-01T17:47:53.000Z ##

found a vuln in openssl's QUIC stack, now CVE-2026-75804.

a remote peer can make an openssl QUIC endpoint hold ~100 MB of heap per connection. the flow control window is supposed to cap that at 768 KiB. ten connections --> a gigabyte.

cause: connection-level flow control wasn't enforced, only the per-stream limit.

rated low. affects 3.4 through 4.0, fixed in 4.0.3, 3.6.5, 3.5.9 and 3.4.8.

openssl-library.org/news/vulne

#OpenSSL #QUIC #CVE #InfoSec #Security #Cybersecurity #vulnerability

##

CVE-2026-88771
(9.8 CRITICAL)

EPSS: 1.06%

updated 2026-09-29T04:18:01.603000

7 posts

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

10 repos

https://github.com/bkchaudhari/NetScaler-CTX697096-Assessment-Script

https://github.com/craigsblackie/cve-2026-88771-netscaler

https://github.com/securekomodo/citrixInspector

https://github.com/techupdate24/citrix-netscaler-cve-2026-88771-rce

https://github.com/emilstahl/pitscaler

https://github.com/technion/netscaler_scanner

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

https://github.com/SwiftSecur/CVE-2026-88771-HuntScript

https://github.com/EXEcution-py/CVE-2026-88771-POC

https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88771

sayzard@mastodon.sayzard.org at 2026-10-02T03:41:25.000Z ##

Mass exploitation of Citrix NetScaler: What we currently know

Citrix NetScaler ADC/Gateway의 치명적 취약점 CVE-2026-88771과 CVE-2026-88772(CVSS 9.5)이 실제 대규모 공격에 악용되고 있다. 인증 없이 원격 명령 실행이 가능한 취약점을 포함하며, 최소 78개 조직과 유럽·북미의 정부·핵심 인프라·금융·의료 기관이 영향을 받은 것으로 조사됐다. 공격자는 PHP 웹셸 Whipshot과 Python 터널러 Slapshot을 사용해 C2 통신 은닉, 정찰, 자격 증명 탈취를 수행한 정황이 있다. NetScaler를 VPN·원격 접...

cybersecuritydive.com/news/exp

##

CyReVolt@mastodon.social at 2026-10-01T17:55:45.000Z ##

oh wow that grep|sed|awk pipeline...

I keep saying this:
Parsing strings all over the place is a funny idea that #Unix had, but inherently prone to error and, frankly, horribly insecure.

labs.watchtowr.com/oh-look-the

##

cyberworldops@infosec.exchange at 2026-10-01T07:00:01.000Z ##

LevelBlue THOR observed active exploitation of CVE-2026-88771 in Citrix NetScaler ADC and Gateway for unauthenticated command execution. Payloads establish reverse shells, create persistent superuser accounts, and hide web shells as CSS URLs while staging configs. This enables long-term persistence and credential access on edge devices. #NetScaler #Citrix #ThreatIntel

cyberworldops.eu/en/netscaler-

##

cyberworldops@infosec.exchange at 2026-10-01T00:30:00.000Z ##

Mandiant and GTIG confirm active exploitation of NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 on ADC and Gateway appliances. Edge compromise can escalate to root-level network access, bypassing perimeter controls. Immediate patching and compromise hunting are required. #NetScaler #ZeroDay #ThreatIntel

cyberworldops.eu/en/netscaler-

##

GossiTheDog@cyberplace.social at 2026-10-01T00:12:49.000Z ##

Great IOCs on the follow up spray and pray activity on #PitScaler so far.

For context this activity definitely is not related to the inital threat actor activity in early September. This is new stuff.

github.com/rtkwlf/wolf-tools/t

##

ssvc@infosec.exchange at 2026-09-30T15:53:50.000Z ##

CERT-EU shares their insights on CVE-2026-88771 exploitation and provides threat hunting tips in different logs.

cert.europa.eu/blog/taking-exe

#threatintel #threathunting #citrix #netscaler

##

guru@thecybersecguru.com at 2026-09-30T09:10:53.000Z ##

Critical Citrix NetScaler RCE (CVE-2026-88772) exploited in the wild: a deep dive into the DTLS buffer overflow

Citrix NetScaler vulnerability, NetScaler RCE, Citrix zero-day, DTLS buffer overflow, CVE-2026-88771, NetScaler Gateway exploit, Citrix security advisory

thecybersecguru.com/news/citri

##

CVE-2026-15953
(5.0 MEDIUM)

EPSS: 0.11%

updated 2026-09-28T15:32:02

2 posts

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Protection and control IED manager (PCM600). This issue affects Protection and control IED manager (PCM600): through 2.14.

cyberworldops at 2026-10-01T21:00:00.849Z ##

CISA advisory ICSA-26-274-03 documents CVE-2026-15952 and CVE-2026-15953 in ABB PCM600 up to version 2.14. Exploitation risks Windows privilege escalation and integrity of IED project files, with direct impact on substation protection engineering. Patch and restrict engineering workstation access.

cyberworldops.eu/en/two-abb-pc

##

cyberworldops@infosec.exchange at 2026-10-01T21:00:00.000Z ##

CISA advisory ICSA-26-274-03 documents CVE-2026-15952 and CVE-2026-15953 in ABB PCM600 up to version 2.14. Exploitation risks Windows privilege escalation and integrity of IED project files, with direct impact on substation protection engineering. Patch and restrict engineering workstation access. #AbbPcm600 #IcsSecurity #SubstationSecurity

cyberworldops.eu/en/two-abb-pc

##

CVE-2026-15952
(6.4 MEDIUM)

EPSS: 0.09%

updated 2026-09-28T15:31:57

2 posts

Incorrect Permission Assignment for Critical Resource vulnerability in ABB Protection and control IED manager (PCM600). This issue affects Protection and control IED manager (PCM600): through 2.14.

cyberworldops at 2026-10-01T21:00:00.849Z ##

CISA advisory ICSA-26-274-03 documents CVE-2026-15952 and CVE-2026-15953 in ABB PCM600 up to version 2.14. Exploitation risks Windows privilege escalation and integrity of IED project files, with direct impact on substation protection engineering. Patch and restrict engineering workstation access.

cyberworldops.eu/en/two-abb-pc

##

cyberworldops@infosec.exchange at 2026-10-01T21:00:00.000Z ##

CISA advisory ICSA-26-274-03 documents CVE-2026-15952 and CVE-2026-15953 in ABB PCM600 up to version 2.14. Exploitation risks Windows privilege escalation and integrity of IED project files, with direct impact on substation protection engineering. Patch and restrict engineering workstation access. #AbbPcm600 #IcsSecurity #SubstationSecurity

cyberworldops.eu/en/two-abb-pc

##

CVE-2026-88772
(8.1 HIGH)

EPSS: 1.30%

updated 2026-09-28T12:26:47.670000

8 posts

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

7 repos

https://github.com/securekomodo/citrixInspector

https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772

https://github.com/murrez/CVE-2026-88772

https://github.com/emilstahl/pitscaler

https://github.com/technion/netscaler_scanner

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

https://github.com/FollowerSeize/CVE-2026-88772-POC

sayzard@mastodon.sayzard.org at 2026-10-02T03:41:25.000Z ##

Mass exploitation of Citrix NetScaler: What we currently know

Citrix NetScaler ADC/Gateway의 치명적 취약점 CVE-2026-88771과 CVE-2026-88772(CVSS 9.5)이 실제 대규모 공격에 악용되고 있다. 인증 없이 원격 명령 실행이 가능한 취약점을 포함하며, 최소 78개 조직과 유럽·북미의 정부·핵심 인프라·금융·의료 기관이 영향을 받은 것으로 조사됐다. 공격자는 PHP 웹셸 Whipshot과 Python 터널러 Slapshot을 사용해 C2 통신 은닉, 정찰, 자격 증명 탈취를 수행한 정황이 있다. NetScaler를 VPN·원격 접...

cybersecuritydive.com/news/exp

##

DailyCyberSecurity@infosec.exchange at 2026-10-01T08:15:04.000Z ##

Attackers exploit Citrix NetScaler zero-day CVE-2026-88772 for root access, then hide WHIPSHOT web shells and a SLAPSHOT tunneler. Patch now.

#CitrixNetScaler #ZeroDay #CVE202688772 #CVE202688771 #WHIPSHOT #SLAPSHOT #Mandiant #CyberSecurity

securityonline.info/citrix-net

##

cyberworldops@infosec.exchange at 2026-10-01T00:30:00.000Z ##

Mandiant and GTIG confirm active exploitation of NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 on ADC and Gateway appliances. Edge compromise can escalate to root-level network access, bypassing perimeter controls. Immediate patching and compromise hunting are required. #NetScaler #ZeroDay #ThreatIntel

cyberworldops.eu/en/netscaler-

##

DailyCyberSecurity@infosec.exchange at 2026-10-01T00:29:03.000Z ##

CVE-2026-88772, a Citrix NetScaler DTLS memory overflow, is exploited in the wild. A watchTowr PoC and full details are now public. Patch NetScaler now.

#Citrix #NetScaler #CVE202688772 #DTLS #watchTowr #KEV #ZeroDay #RCE

securityonline.info/citrix-net

##

reput_io@infosec.exchange at 2026-09-30T15:27:50.000Z ##

Two Citrix NetScaler zero-days (CVE-2026-88772/88771) gave attackers pre-auth root on the box that fronts your whole network. GTIG traced exploitation to early September, weeks before the patch existed.

Once inside, their C2 leaves from your own public IP. No strange domain, no foreign address to block. The call is coming from inside the house.

Reputation Radar #13:
reput.io/blog/reputation-radar

#ThreatIntel #NetScaler #SOC

##

news@fawkes.rocks at 2026-09-30T13:22:34.000Z ##

NetScaler CVE-2026-88772 zero-day tied to state hackers

fawkes.rocks/2026/09/30/netsca

##

pwr2@infosec.exchange at 2026-09-30T13:09:38.000Z ##

Nice blog post on Citrix CVE-2026-88772 exploit:

cloud.google.com/blog/topics/t

#citrix #cve_2026_88772 #pitscaler

##

guru@thecybersecguru.com at 2026-09-30T09:10:53.000Z ##

Critical Citrix NetScaler RCE (CVE-2026-88772) exploited in the wild: a deep dive into the DTLS buffer overflow

Citrix NetScaler vulnerability, NetScaler RCE, Citrix zero-day, DTLS buffer overflow, CVE-2026-88771, NetScaler Gateway exploit, Citrix security advisory

thecybersecguru.com/news/citri

##

CVE-2026-100382(CVSS UNKNOWN)

EPSS: 0.95%

updated 2026-09-26T00:32:22

2 posts

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Foundation Mediawiki - ExternalData Extension allows OS Command Injection. This issue affects Mediawiki - ExternalData Extension: from * before 3.7.

1 repos

https://github.com/nth347/mediawiki-CVE-2026-100382

DailyCyberSecurity@infosec.exchange at 2026-10-01T03:30:34.000Z ##

Attackers exploit CVE-2026-100382, a CVSS 10 unauthenticated MediaWiki RCE in External Data. PoC is public. Upgrade to 3.7 now.

#MediaWiki #ExternalData #CVE2026100382 #RCE #CommandInjection #ExploitedInTheWild #PoC

securityonline.info/mediawiki-

##

maxlath@piaille.fr at 2026-09-30T08:59:15.000Z ##

[🚨 #MediaWiki vulnerable extension]

If you are running a MediaWiki instance with Extension:External_Data < v3.7, your instance is vulnerable to arbitrary file loading and #RemoteCodeExecution.

The vulnerability was apparently publicly known since August, but due to the lack of communication, instance admins learned about it due to that vulnerability being exploited en masse.

If you know and like a MediaWiki instance, you can check their Special:Version page to see if they are using the External_Data extension to warn them.

More info:
- lists.wikimedia.org/hyperkitty
- cve.org/CVERecord?id=CVE-2026-

#infosec #wikipedia #wikidata #adminsys #CVE #pwned cc @mediawiki

##

CVE-2026-67279
(6.5 MEDIUM)

EPSS: 1.03%

updated 2026-09-25T18:32:21

1 posts

RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support

3 repos

https://github.com/tc4dy/CVE-2026-67279-86060-Toolkit

https://github.com/HackSpeak/CVE-2026-67279

https://github.com/gagaltotal/CVE-2026-mikrotik-poc

thecybermind@infosec.exchange at 2026-10-01T17:58:12.000Z ##

Critical Threat Advisory: CVE-2026-67279 MikroTik RouterOS

Immediate CISA KEV threat advisory for CVE-2026-67279 affecting MikroTik RouterOS. Includes behavioral workflow analysis, BOD 26-04 patch compliance guidance, and multi-vendor SOC detection queries....

thecybermind.co/9t9e

##

CVE-2026-61851
(0 None)

EPSS: 0.47%

updated 2026-09-24T21:25:27.050000

1 posts

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's runQuery() implementation in server/modules/ai/orchestrator/tools/runQuery.js attempts to enforce read-only database access with a blocklist containing only seven SQL keywords. An authenticated user with AI feature access can submit dangerous st

hugovalters@mastodon.social at 2026-10-02T05:10:19.000Z ##

CVE-2026-61851: SQL injection in Chartbrew's runQuery() - incomplete keyword blocklist lets authenticated users execute dangerous SQL. CVSS 8.8. Patch under review, no fix yet. Track it: valtersit.com/cve/CVE-2026-618 #CVE #infosec

##

CVE-2026-78806
(5.5 MEDIUM)

EPSS: 0.11%

updated 2026-09-24T14:18:17.497000

1 posts

An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker to obtain sensitive information via the PerformCommissioningStep function in the ChipDeviceController.cpp component

hugovalters@mastodon.social at 2026-10-01T19:50:01.000Z ##

CVE-2026-78806 in Matter Project Chip V1.5.1: local attacker can leak sensitive data via PerformCommissioningStep in ChipDeviceController.cpp. CVSS 5.5, no known patch yet. Restrict local access and watch for updates. valtersit.com/cve/CVE-2026-788 #CVE #infosec #IoT

##

CVE-2026-18439
(4.3 MEDIUM)

EPSS: 0.25%

updated 2026-09-23T19:17:29.350000

1 posts

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.0.7 via the tutor_quiz_builder_save AJAX action due to missing validation that nested question_id, answer_id, deleted_question_ids[], and deleted_answer_ids[] values in the submitted payload belong to a quiz/topic/course the requester is au

hugovalters@mastodon.social at 2026-10-02T02:20:39.000Z ##

CVE-2026-18439 Tutor LMS IDOR (CVSS 4.3): tutor_quiz_builder_save AJAX lets low-priv users tamper with quiz questions they shouldn't manage. Patch under review - apply when released. valtersit.com/cve/CVE-2026-184 #CVE #infosec #WordPress

##

CVE-2026-93616
(9.8 CRITICAL)

EPSS: 19.65%

updated 2026-09-23T16:38:38.987000

2 posts

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

2 repos

https://github.com/WadesWeaponShed/CVE-2026-93616_Checks

https://github.com/BishopFox/CVE-2026-93616-check

daniel1820815@infosec.exchange at 2026-10-01T15:24:02.000Z ##

From Check Point Research: Exploitation of CVE-2026-85102 and CVE-2026-93616

Check Point has observed active exploitation of two critical pre-authentication vulnerabilities with CVSS scores of 9.8 - CVE-2026-85102 and CVE-2026-93616. The flaws affect Security Gateway and Security Management products and can enable remote code execution. Fixes for both vulnerabilities are available.

blog.checkpoint.com/security/s

#CheckPoint #CheckPointSoftwareTechnologies #CVE #CVE202685102 #CVE202693616

##

secdb@infosec.exchange at 2026-10-01T00:02:39.000Z ##

📈 CVE Published in last 30 days (2026-09-01 - 2026-09-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1417
- High: 5956
- Medium: 4625
- Low: 927
- None: 1743

Status:
- : 93
- Analyzed: 3418
- Awaiting Analysis: 2780
- Deferred: 5097
- Modified: 128
- Received: 2835
- Rejected: 130
- Undergoing Analysis: 187

CISA KEVs:
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 2117
- VulnCheck: 1638
- GitHub, Inc.: 1424
- Microsoft Corporation: 1000
- VulDB: 900
- Oracle: 634
- WPScan: 552
- MITRE: 497
- Chrome: 467
- Wordfence: 408

Top Affected Products:
- UNKNOWN: 11109
- Microsoft Windows Server 2025: 648
- Microsoft Windows Server 2022: 611
- Microsoft Windows 11 24h2: 600
- Microsoft Windows 11 26h1: 600
- Microsoft Windows 11 25h2: 599
- Microsoft Windows Server 2019: 586
- Microsoft Windows 10 1809: 582
- Microsoft Windows 11 23h2: 574
- Microsoft Windows 10 21h2: 541

Top EPSS Score:
- CVE-2026-85706 - 91.43 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85046 - 48.88 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76461 - 28.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 19.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76460 - 14.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-86218 - 12.93 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83549 - 10.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83548 - 8.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85102 - 7.55 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-85102
(9.8 CRITICAL)

EPSS: 7.55%

updated 2026-09-22T21:30:40

2 posts

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

daniel1820815@infosec.exchange at 2026-10-01T15:24:02.000Z ##

From Check Point Research: Exploitation of CVE-2026-85102 and CVE-2026-93616

Check Point has observed active exploitation of two critical pre-authentication vulnerabilities with CVSS scores of 9.8 - CVE-2026-85102 and CVE-2026-93616. The flaws affect Security Gateway and Security Management products and can enable remote code execution. Fixes for both vulnerabilities are available.

blog.checkpoint.com/security/s

#CheckPoint #CheckPointSoftwareTechnologies #CVE #CVE202685102 #CVE202693616

##

secdb@infosec.exchange at 2026-10-01T00:02:39.000Z ##

📈 CVE Published in last 30 days (2026-09-01 - 2026-09-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1417
- High: 5956
- Medium: 4625
- Low: 927
- None: 1743

Status:
- : 93
- Analyzed: 3418
- Awaiting Analysis: 2780
- Deferred: 5097
- Modified: 128
- Received: 2835
- Rejected: 130
- Undergoing Analysis: 187

CISA KEVs:
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 2117
- VulnCheck: 1638
- GitHub, Inc.: 1424
- Microsoft Corporation: 1000
- VulDB: 900
- Oracle: 634
- WPScan: 552
- MITRE: 497
- Chrome: 467
- Wordfence: 408

Top Affected Products:
- UNKNOWN: 11109
- Microsoft Windows Server 2025: 648
- Microsoft Windows Server 2022: 611
- Microsoft Windows 11 24h2: 600
- Microsoft Windows 11 26h1: 600
- Microsoft Windows 11 25h2: 599
- Microsoft Windows Server 2019: 586
- Microsoft Windows 10 1809: 582
- Microsoft Windows 11 23h2: 574
- Microsoft Windows 10 21h2: 541

Top EPSS Score:
- CVE-2026-85706 - 91.43 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85046 - 48.88 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76461 - 28.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 19.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76460 - 14.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-86218 - 12.93 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83549 - 10.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83548 - 8.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85102 - 7.55 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-79079
(7.8 HIGH)

EPSS: 0.19%

updated 2026-09-22T20:00:03.713000

1 posts

An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components

hugovalters@mastodon.social at 2026-10-02T04:31:09.000Z ##

CVE-2026-79079 CrossWire Xiphos 4.3.2 and below: local attacker can execute arbitrary code via url.cc and menu_popup.c. CVSS 7.8. No patch yet - isolate or update when fixed. valtersit.com/cve/CVE-2026-790 #CVE #infosec #cybersecurity

##

CVE-2026-93556
(0 None)

EPSS: 0.30%

updated 2026-09-22T19:41:38.447000

1 posts

The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose password is to be changed. The JWT token for the recovery process is not validated against the user specified in that parameter. An unauthenticated attacker could manipulate the identifier and reset the password for any account, including administrative accounts, which could allow them

hugovalters@mastodon.social at 2026-10-01T13:30:02.000Z ##

CVE-2026-93556: CVSS 9.8. Broken JWT validation in /password/guardarClau/recover lets unauthenticated attackers reset any password, including admin. Patch status unknown. Assume exposed and mitigate now. valtersit.com/cve/CVE-2026-935 #CVE #infosec #cybersecurity

##

CVE-2026-89420
(0 None)

EPSS: 0.47%

updated 2026-09-22T19:09:32.273000

1 posts

Improper Validation of Specified Quantity in Input in ZenHive mpp allows a client holding an open payment channel to obtain paid resources without being charged. MPP.Session.Actions.accept_voucher/3 in lib/mpp/session/actions.ex treats a voucher whose cumulativeAmount equals the channel's already-accepted cumulative amount as an idempotent success, returning the channel unchanged without calling

hugovalters@mastodon.social at 2026-10-02T03:40:39.000Z ##

CVE-2026-89420 ZenHive mpp CVSS 4.3: improper validation lets a client with an open payment channel obtain paid resources without being charged. Patch under review. Monitor and patch when released. valtersit.com/cve/CVE-2026-894 #CVE #infosec #cybersecurity

##

CVE-2026-89422
(0 None)

EPSS: 0.64%

updated 2026-09-22T19:09:32.273000

1 posts

Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A pre_shared_key extension in the ServerHello that the client never offered causes the client to complete the handshake without validating the server's certificate, so ssl:connect returns {ok, Socket} against a peer holding no certifi

hugovalters@mastodon.social at 2026-10-02T02:40:44.000Z ##

CVE-2026-89422: Erlang/OTP ssl TLS 1.3 client auth bypass. Malicious server impersonates any host, no cert required. CVSS 10. Patch under review. Audit your ssl:connect now. valtersit.com/cve/CVE-2026-894 #CVE #infosec #Erlang

##

CVE-2026-74765
(6.5 MEDIUM)

EPSS: 0.52%

updated 2026-09-22T18:33:29

1 posts

Net::IDN::Punycode versions before 2.590 for Perl allow an out-of-bounds read via integer overflow of the delta accumulator in encode_punycode. The XS backend keeps the punycode delta, and the digit index derived from it, in a signed int. The accumulation `delta += (m-n) * (h+1)` has no overflow check, so a large enough code point wraps the delta and the digit index leaves the range of the 36-ent

hugovalters@mastodon.social at 2026-10-01T21:20:05.000Z ##

CVE-2026-74765 Net::IDN::Punycode for Perl: out-of-bounds read via integer overflow in encode_punycode lets the digit index escape the 36-entry table. CVSS 6.5. Patch under review - check your deps. valtersit.com/cve/CVE-2026-747 #CVE #infosec #Perl

##

CVE-2026-80521
(7.8 HIGH)

EPSS: 0.17%

updated 2026-09-21T14:17:20.193000

1 posts

In the Linux kernel, the following vulnerability has been resolved: af_unix: Unlink scc_entry in unix_del_edge(). Kyle Zeng reported that GC could free a dead SCC partially. The scenario is as follows: 1) Create two SCCs: X -. A <-> B ^--' 2) Run the following concurrently: 2-1) send() sk-B to sk-B from sk-X 2-2) close() both A and B At 2-1), there is a sm

2 repos

https://github.com/rifkyards/Container_escape-CVE-2026-80521-CVE-2026-52910

https://github.com/Markakd/Container_escape

sigint@fosstodon.org at 2026-09-30T23:45:07.000Z ##

🐧 SIGINT // Ubuntu Watch — 2026-10-01

Public exploit for container-to-host root escape, CVE-2026-80521, patched upstream but not yet shipped in Ubuntu 22.04/24.04/26.04 LTS. If you run containers on Ubuntu hosts, treat this as urgent and watch for the USN, or mitigate with stricter namespace/seccomp policies now.

🔗 thehackernews.com/2026/09/expl

#Ubuntu #Linux #infosec

##

secdb@infosec.exchange at 2026-10-01T00:02:39.000Z ##

📈 CVE Published in last 30 days (2026-09-01 - 2026-09-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1417
- High: 5956
- Medium: 4625
- Low: 927
- None: 1743

Status:
- : 93
- Analyzed: 3418
- Awaiting Analysis: 2780
- Deferred: 5097
- Modified: 128
- Received: 2835
- Rejected: 130
- Undergoing Analysis: 187

CISA KEVs:
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 2117
- VulnCheck: 1638
- GitHub, Inc.: 1424
- Microsoft Corporation: 1000
- VulDB: 900
- Oracle: 634
- WPScan: 552
- MITRE: 497
- Chrome: 467
- Wordfence: 408

Top Affected Products:
- UNKNOWN: 11109
- Microsoft Windows Server 2025: 648
- Microsoft Windows Server 2022: 611
- Microsoft Windows 11 24h2: 600
- Microsoft Windows 11 26h1: 600
- Microsoft Windows 11 25h2: 599
- Microsoft Windows Server 2019: 586
- Microsoft Windows 10 1809: 582
- Microsoft Windows 11 23h2: 574
- Microsoft Windows 10 21h2: 541

Top EPSS Score:
- CVE-2026-85706 - 91.43 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85046 - 48.88 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76461 - 28.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 19.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76460 - 14.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-86218 - 12.93 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83549 - 10.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83548 - 8.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85102 - 7.55 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-63490
(7.5 HIGH)

EPSS: 0.69%

updated 2026-09-18T20:09:01.757000

1 posts

Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateLoader resolves attacker-influenced Spring MVC view names through Spring ResourceLoader without the path-containment validation used by other URL-based loaders. In handlebars-springmvc/src/main/java/com/github/jknack/handlebars/springmvc/SpringTemplate

thehackerwire@mastodon.social at 2026-09-30T13:17:38.000Z ##

🟠 CVE-2026-103088 - High (7.5)

Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the template file is opened through ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86869
(6.5 MEDIUM)

EPSS: 0.34%

updated 2026-09-17T18:31:49

1 posts

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, macOS Golden Gate 27. Processing a maliciously crafted image may lead to unexpected app termination.

technews@eicker.news at 2026-09-30T21:47:01.000Z ##

#Apple released a #security update for #iOS 26, #iPadOS 26, and #macOS 26 to fix a #vulnerability in the #graphicsengine that could be exploited for sophisticated attacks. The bug, CVE-2026-86950, was discovered by Meta and could potentially allow hackers to steal personal data. A separate zero-click bug, CVE-2026-86869, was also fixed, preventing silent data theft via malicious iMessages. techcrunch.com/2026/09/29/stil

##

CVE-2026-50610(CVSS UNKNOWN)

EPSS: 0.13%

updated 2026-09-17T09:33:03

1 posts

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense due to insufficient access controls in a privileged service. An authenticated local user may be able to access the service and perform unauthorized registry modifications, potentially resulting in local privilege escalation.

CVE-2026-76460
(10.0 CRITICAL)

EPSS: 14.03%

updated 2026-09-16T21:33:00

1 posts

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized acce

1 repos

https://github.com/S3v3n-JG/CVE-2026-76460

secdb@infosec.exchange at 2026-10-01T00:02:39.000Z ##

📈 CVE Published in last 30 days (2026-09-01 - 2026-09-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1417
- High: 5956
- Medium: 4625
- Low: 927
- None: 1743

Status:
- : 93
- Analyzed: 3418
- Awaiting Analysis: 2780
- Deferred: 5097
- Modified: 128
- Received: 2835
- Rejected: 130
- Undergoing Analysis: 187

CISA KEVs:
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 2117
- VulnCheck: 1638
- GitHub, Inc.: 1424
- Microsoft Corporation: 1000
- VulDB: 900
- Oracle: 634
- WPScan: 552
- MITRE: 497
- Chrome: 467
- Wordfence: 408

Top Affected Products:
- UNKNOWN: 11109
- Microsoft Windows Server 2025: 648
- Microsoft Windows Server 2022: 611
- Microsoft Windows 11 24h2: 600
- Microsoft Windows 11 26h1: 600
- Microsoft Windows 11 25h2: 599
- Microsoft Windows Server 2019: 586
- Microsoft Windows 10 1809: 582
- Microsoft Windows 11 23h2: 574
- Microsoft Windows 10 21h2: 541

Top EPSS Score:
- CVE-2026-85706 - 91.43 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85046 - 48.88 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76461 - 28.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 19.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76460 - 14.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-86218 - 12.93 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83549 - 10.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83548 - 8.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85102 - 7.55 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-76461
(9.8 CRITICAL)

EPSS: 28.27%

updated 2026-09-14T21:32:49

1 posts

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that cont

4 repos

https://github.com/S3v3n-JG/CVE-2026-76461

https://github.com/HORKimhab/CVE-2026-76461

https://github.com/0xBlackash/CVE-2026-76461

https://github.com/fevar54/CVE-2026-76461-Detection-Kit-

secdb@infosec.exchange at 2026-10-01T00:02:39.000Z ##

📈 CVE Published in last 30 days (2026-09-01 - 2026-09-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1417
- High: 5956
- Medium: 4625
- Low: 927
- None: 1743

Status:
- : 93
- Analyzed: 3418
- Awaiting Analysis: 2780
- Deferred: 5097
- Modified: 128
- Received: 2835
- Rejected: 130
- Undergoing Analysis: 187

CISA KEVs:
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 2117
- VulnCheck: 1638
- GitHub, Inc.: 1424
- Microsoft Corporation: 1000
- VulDB: 900
- Oracle: 634
- WPScan: 552
- MITRE: 497
- Chrome: 467
- Wordfence: 408

Top Affected Products:
- UNKNOWN: 11109
- Microsoft Windows Server 2025: 648
- Microsoft Windows Server 2022: 611
- Microsoft Windows 11 24h2: 600
- Microsoft Windows 11 26h1: 600
- Microsoft Windows 11 25h2: 599
- Microsoft Windows Server 2019: 586
- Microsoft Windows 10 1809: 582
- Microsoft Windows 11 23h2: 574
- Microsoft Windows 10 21h2: 541

Top EPSS Score:
- CVE-2026-85706 - 91.43 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85046 - 48.88 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76461 - 28.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 19.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76460 - 14.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-86218 - 12.93 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83549 - 10.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83548 - 8.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85102 - 7.55 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-81578
(9.8 CRITICAL)

EPSS: 85.17%

updated 2026-09-14T00:16:56.207000

1 posts

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

2 repos

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

https://github.com/virologi-info/papercut-toolkit

VirusBulletin@infosec.exchange at 2026-09-30T12:35:26.000Z ##

eSentire's TRU team shows how a threat actor exploited an internet-facing PaperCut MF server to deploy a Java loader & a web shell. Threat actors subsequently used the web shell to deploy a trojanized Microsoft Copilot binary carrying an AdaptixC2 implant. esentire.com/blog/papercut-mf-

##

secdb@infosec.exchange at 2026-10-01T00:02:39.000Z ##

📈 CVE Published in last 30 days (2026-09-01 - 2026-09-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1417
- High: 5956
- Medium: 4625
- Low: 927
- None: 1743

Status:
- : 93
- Analyzed: 3418
- Awaiting Analysis: 2780
- Deferred: 5097
- Modified: 128
- Received: 2835
- Rejected: 130
- Undergoing Analysis: 187

CISA KEVs:
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 2117
- VulnCheck: 1638
- GitHub, Inc.: 1424
- Microsoft Corporation: 1000
- VulDB: 900
- Oracle: 634
- WPScan: 552
- MITRE: 497
- Chrome: 467
- Wordfence: 408

Top Affected Products:
- UNKNOWN: 11109
- Microsoft Windows Server 2025: 648
- Microsoft Windows Server 2022: 611
- Microsoft Windows 11 24h2: 600
- Microsoft Windows 11 26h1: 600
- Microsoft Windows 11 25h2: 599
- Microsoft Windows Server 2019: 586
- Microsoft Windows 10 1809: 582
- Microsoft Windows 11 23h2: 574
- Microsoft Windows 10 21h2: 541

Top EPSS Score:
- CVE-2026-85706 - 91.43 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85046 - 48.88 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76461 - 28.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 19.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76460 - 14.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-86218 - 12.93 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83549 - 10.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83548 - 8.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85102 - 7.55 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-75650
(10.0 CRITICAL)

EPSS: 3.95%

updated 2026-09-09T05:18:07.237000

1 posts

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

6 repos

https://github.com/dinosn/cve-2026-75650-magento-validation-lab

https://github.com/fortbridge/stylesmuggler

https://github.com/disrex-group/stylesmuggler-adobe-patches

https://github.com/jithinkrishnanrs/stylesmuggler-ioc-toolkit

https://github.com/abraxas/CVE-2026-75650

https://github.com/disrex-group/stylesmuggler-adobe-patches-mageos

CVE-2026-81963
(7.8 HIGH)

EPSS: 0.39%

updated 2026-09-08T21:34:09

1 posts

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

CVE-2026-86218
(9.8 CRITICAL)

EPSS: 12.93%

updated 2026-09-08T21:33:02

1 posts

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

Nuclei template

3 repos

https://github.com/Udyz/CVE-2026-86218

https://github.com/HORKimhab/CVE-2026-86218

https://github.com/super-meuw/CVE-2026-86218

secdb@infosec.exchange at 2026-10-01T00:02:39.000Z ##

📈 CVE Published in last 30 days (2026-09-01 - 2026-09-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1417
- High: 5956
- Medium: 4625
- Low: 927
- None: 1743

Status:
- : 93
- Analyzed: 3418
- Awaiting Analysis: 2780
- Deferred: 5097
- Modified: 128
- Received: 2835
- Rejected: 130
- Undergoing Analysis: 187

CISA KEVs:
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 2117
- VulnCheck: 1638
- GitHub, Inc.: 1424
- Microsoft Corporation: 1000
- VulDB: 900
- Oracle: 634
- WPScan: 552
- MITRE: 497
- Chrome: 467
- Wordfence: 408

Top Affected Products:
- UNKNOWN: 11109
- Microsoft Windows Server 2025: 648
- Microsoft Windows Server 2022: 611
- Microsoft Windows 11 24h2: 600
- Microsoft Windows 11 26h1: 600
- Microsoft Windows 11 25h2: 599
- Microsoft Windows Server 2019: 586
- Microsoft Windows 10 1809: 582
- Microsoft Windows 11 23h2: 574
- Microsoft Windows 10 21h2: 541

Top EPSS Score:
- CVE-2026-85706 - 91.43 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85046 - 48.88 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76461 - 28.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 19.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76460 - 14.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-86218 - 12.93 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83549 - 10.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83548 - 8.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85102 - 7.55 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-65669
(9.6 CRITICAL)

EPSS: 0.88%

updated 2026-09-08T18:32:08

1 posts

Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.

sayzard@mastodon.sayzard.org at 2026-10-01T23:44:44.000Z ##

From Select to Sysadmin: Hijacking Microsoft SQL Copilot (CVE-2026-65669)

Microsoft SQL Server Management Studio(SSMS)의 SQL Copilot에서 CVE-2026-65669가 발견됐다. Copilot의 ‘읽기 전용’ 제어가 별도 권한 분리 없이 정규식 기반 차단 목록과 시스템 프롬프트에 의존해, 동적 SQL과 저장 프로시저 호출로 우회되어 임의 T-SQL 실행이 가능했다. 공격자는 데이터베이스 콘텐츠·T-SQL 파일·확장 속성의 AGENTS.md/CONSTITUTION.md에 간접 프롬프트 인젝션을 심어, 나중에 더 높은 권...

embracethered.com/blog/posts/2

##

CVE-2026-60004
(9.8 CRITICAL)

EPSS: 23.99%

updated 2026-09-08T17:56:31

1 posts

### Summary Gitea's `diffpatch` endpoint can be abused to install and execute a Git hook from repository-controlled content. An attacker with ordinary write access to a repository can execute arbitrary shell commands as the Gitea OS user. With default open registration, an unauthenticated visitor can obtain the required write access by registering an account and creating a repository. ### Detai

11 repos

https://github.com/yym8538/CVE-2026-60004

https://github.com/EQSTLab/CVE-2026-60004

https://github.com/imbas007/CVE-2026-60004-POC

https://github.com/HORKimhab/CVE-2026-60004

https://github.com/erberkan/CVE-2026-60004-PoC

https://github.com/shinthink/CVE-2026-60004

https://github.com/HackSpeak/CVE-2026-60004

https://github.com/0xBlackash/CVE-2026-60004

https://github.com/gagaltotal/CVE-2026-60004-poc-gitea

https://github.com/fevar54/cve-2026-60004

https://github.com/Sachinart/CVE-2026-60004-gitea-0day

egeltje@infosec.exchange at 2026-10-01T08:18:29.000Z ##

When you find your private Gitea server infected with #XMrigMalware cryptominer through CVE-2026-60004...
Enormous gratitude to foresh.com/posts/2026-09-15-ai for writing a very concise analysis and recovery!

##

CVE-2026-83548
(10.0 CRITICAL)

EPSS: 8.76%

updated 2026-09-03T13:06:16.053000

1 posts

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

3 repos

https://github.com/xoessie/CVE-2026-83548-SonicWall-SMA1000-Analysis

https://github.com/xcoy0te/CVE-2026-83548-checker

https://github.com/HORKimhab/CVE-2026-83548-CVE-2026-83549

secdb@infosec.exchange at 2026-10-01T00:02:39.000Z ##

📈 CVE Published in last 30 days (2026-09-01 - 2026-09-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1417
- High: 5956
- Medium: 4625
- Low: 927
- None: 1743

Status:
- : 93
- Analyzed: 3418
- Awaiting Analysis: 2780
- Deferred: 5097
- Modified: 128
- Received: 2835
- Rejected: 130
- Undergoing Analysis: 187

CISA KEVs:
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 2117
- VulnCheck: 1638
- GitHub, Inc.: 1424
- Microsoft Corporation: 1000
- VulDB: 900
- Oracle: 634
- WPScan: 552
- MITRE: 497
- Chrome: 467
- Wordfence: 408

Top Affected Products:
- UNKNOWN: 11109
- Microsoft Windows Server 2025: 648
- Microsoft Windows Server 2022: 611
- Microsoft Windows 11 24h2: 600
- Microsoft Windows 11 26h1: 600
- Microsoft Windows 11 25h2: 599
- Microsoft Windows Server 2019: 586
- Microsoft Windows 10 1809: 582
- Microsoft Windows 11 23h2: 574
- Microsoft Windows 10 21h2: 541

Top EPSS Score:
- CVE-2026-85706 - 91.43 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85046 - 48.88 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76461 - 28.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 19.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76460 - 14.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-86218 - 12.93 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83549 - 10.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83548 - 8.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85102 - 7.55 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-83549
(7.8 HIGH)

EPSS: 10.76%

updated 2026-09-02T18:32:06

1 posts

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

2 repos

https://github.com/xcoy0te/CVE-2026-83548-checker

https://github.com/HORKimhab/CVE-2026-83548-CVE-2026-83549

secdb@infosec.exchange at 2026-10-01T00:02:39.000Z ##

📈 CVE Published in last 30 days (2026-09-01 - 2026-09-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1417
- High: 5956
- Medium: 4625
- Low: 927
- None: 1743

Status:
- : 93
- Analyzed: 3418
- Awaiting Analysis: 2780
- Deferred: 5097
- Modified: 128
- Received: 2835
- Rejected: 130
- Undergoing Analysis: 187

CISA KEVs:
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 2117
- VulnCheck: 1638
- GitHub, Inc.: 1424
- Microsoft Corporation: 1000
- VulDB: 900
- Oracle: 634
- WPScan: 552
- MITRE: 497
- Chrome: 467
- Wordfence: 408

Top Affected Products:
- UNKNOWN: 11109
- Microsoft Windows Server 2025: 648
- Microsoft Windows Server 2022: 611
- Microsoft Windows 11 24h2: 600
- Microsoft Windows 11 26h1: 600
- Microsoft Windows 11 25h2: 599
- Microsoft Windows Server 2019: 586
- Microsoft Windows 10 1809: 582
- Microsoft Windows 11 23h2: 574
- Microsoft Windows 10 21h2: 541

Top EPSS Score:
- CVE-2026-85706 - 91.43 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85046 - 48.88 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76461 - 28.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 19.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76460 - 14.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-86218 - 12.93 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83549 - 10.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83548 - 8.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85102 - 7.55 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-82078
(9.1 CRITICAL)

EPSS: 61.39%

updated 2026-08-31T21:31:56

1 posts

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on

2 repos

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

https://github.com/virologi-info/papercut-toolkit

VirusBulletin@infosec.exchange at 2026-09-30T12:35:26.000Z ##

eSentire's TRU team shows how a threat actor exploited an internet-facing PaperCut MF server to deploy a Java loader & a web shell. Threat actors subsequently used the web shell to deploy a trojanized Microsoft Copilot binary carrying an AdaptixC2 implant. esentire.com/blog/papercut-mf-

##

CVE-2026-73570
(8.9 HIGH)

EPSS: 11.74%

updated 2026-08-24T13:19:17.577000

3 posts

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands a

10 repos

https://github.com/dahnutz/zimbra-cve-2026-73570-ir

https://github.com/HORKimhab/CVE-2026-73570

https://github.com/juanpoch/CVE-2026-73570

https://github.com/BiuTrap/CVE-2026-73570

https://github.com/INFOKOM-KI/Zimbra-CVE-2026-73570-Rules

https://github.com/gabrielunknown/CVE-2026-73570

https://github.com/0xBlackash/CVE-2026-73570

https://github.com/jishino567/CVE-2026-73570

https://github.com/hainhc/CVE-2026-73570

https://github.com/alsyundawy/eradicate-zimbra-malware

CVE-2026-72018
(7.8 HIGH)

EPSS: 0.18%

updated 2026-08-17T06:34:07

1 posts

In the Linux kernel, the following vulnerability has been resolved: dibs: loopback: validate offset and size in move_data() The loopback move_data() performs a memcpy into the registered DMB without checking whether offset + size exceeds the DMB length. Unlike real ISM hardware, which enforces memory region bounds natively, the software loopback has no such protection. A peer-supplied out-of-b

1 repos

https://github.com/0xBlackash/CVE-2026-72018

_r_netsec@infosec.exchange at 2026-09-30T07:03:21.000Z ##

No Time to Pwn – Can AI Find and Exploit the Linux Kernel? xbow.com/blog/no-time-to-pwn-c

##

CVE-2025-41738
(7.5 HIGH)

EPSS: 0.39%

updated 2026-06-17T09:23:03.883000

1 posts

An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.

certvde@infosec.exchange at 2026-10-01T06:41:04.000Z ##

🔒 New CSAF advisory published

VDE-2025-081
WAGO: Multiple PLCs and Communication Components are Affected by multiple Vulnerabilities leading to RCE
CVE-2025-41700, CVE-2025-41738, CVE-2025-41739

Multiple WAGO devices are affected by CODESYS Control vulnerabilities. The affected WAGO firmware versions are <4.10.0 (FW32) and <4.10.0 (70).

HTML: certvde.com/en/advisories/vde-
CSAF JSON: wago.csaf-tp.certvde.com/.well

#OT #Advisory

##

CVE-2025-41700
(7.8 HIGH)

EPSS: 0.15%

updated 2026-06-17T09:22:59.947000

1 posts

An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CODESYS development system. This arbitrary code is executed in the user context.

certvde@infosec.exchange at 2026-10-01T06:41:04.000Z ##

🔒 New CSAF advisory published

VDE-2025-081
WAGO: Multiple PLCs and Communication Components are Affected by multiple Vulnerabilities leading to RCE
CVE-2025-41700, CVE-2025-41738, CVE-2025-41739

Multiple WAGO devices are affected by CODESYS Control vulnerabilities. The affected WAGO firmware versions are <4.10.0 (FW32) and <4.10.0 (70).

HTML: certvde.com/en/advisories/vde-
CSAF JSON: wago.csaf-tp.certvde.com/.well

#OT #Advisory

##

CVE-2026-35273
(9.8 CRITICAL)

EPSS: 9.44%

updated 2026-06-12T18:31:50

1 posts

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of Peopl

4 repos

https://github.com/HORKimhab/CVE-2026-35273

https://github.com/0xBlackash/CVE-2026-35273

https://github.com/12hrformat/CVE-2026-35273-POC

https://github.com/ekomsSavior/POC_cve_2026_35273

linuxmint_hun@mastodon.social at 2026-10-01T07:06:30.000Z ##

A ShinyHunters ismét kihasználja a CVE-2026-35273 hibát, web shellt és rendszerszintű hozzáférést szerezve több tucat PeopleSoft-rendszerben. Vannak érintett felsőoktatási, egészségügyi és kormányzati szervek — téged is érinthet, ha nem telepítettétek a javítást? Olvasd el, milyen jeleket keressenek az adminok és miért sürgős a frissítés.

linuxmint.hu/hir/2026/09/tobb-

#ShinyHunters #PeopleSoft #CVE2026-35273 #Oracle #Mandiant #cybersecurity #adatbiztonság #webshell #incidentresponse #ITbiztonság

##

CVE-2025-41739
(5.9 MEDIUM)

EPSS: 0.35%

updated 2025-12-01T12:30:34

1 posts

An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the CODESYS Control runtime system on Linux and QNX to trigger an out-of-bounds read via crafted socket communication, potentially causing a denial of service.

certvde@infosec.exchange at 2026-10-01T06:41:04.000Z ##

🔒 New CSAF advisory published

VDE-2025-081
WAGO: Multiple PLCs and Communication Components are Affected by multiple Vulnerabilities leading to RCE
CVE-2025-41700, CVE-2025-41738, CVE-2025-41739

Multiple WAGO devices are affected by CODESYS Control vulnerabilities. The affected WAGO firmware versions are <4.10.0 (FW32) and <4.10.0 (70).

HTML: certvde.com/en/advisories/vde-
CSAF JSON: wago.csaf-tp.certvde.com/.well

#OT #Advisory

##

CVE-2021-21975
(7.5 HIGH)

EPSS: 78.29%

updated 2025-10-22T00:32:06

1 posts

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.

Nuclei template

10 repos

https://github.com/rabidwh0re/REALITY_SMASHER

https://github.com/dorkerdevil/CVE-2021-21975

https://github.com/GuayoyoCyber/CVE-2021-21975

https://github.com/Henry4E36/VMWare-vRealize-SSRF

https://github.com/zhzyker/vulmap

https://github.com/DarkFunct/exp_hub

https://github.com/Al1ex/CVE-2021-21975

https://github.com/Vulnmachines/VMWare-CVE-2021-21975

https://github.com/murataydemir/CVE-2021-21983

https://github.com/murataydemir/CVE-2021-21975

EUVD_Bot@mastodon.social at 2026-10-01T21:03:08.000Z ##

🚨 EUVD-2021-9146

📊 Score: 9.8/10 (CVSS v3.1)
📦 Product: VMware vRealize Operations
📅 Published: 2021-03-31 | Updated: 2026-10-01

📝 Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to ste...

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2026-86360
(0 None)

EPSS: 0.00%

2 posts

N/A

CVE-2026-63692
(0 None)

EPSS: 0.00%

2 posts

N/A

CVE-2026-63688
(0 None)

EPSS: 0.00%

2 posts

N/A

CVE-2026-53953
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-10-01T23:47:23.000Z ##

🔴 CVE-2026-53953 - Critical (9.1)

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3.22, the password reset endpoint can be accessed without authentication. When a reset request is submitted for an existing...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-01T23:47:23.000Z ##

🔴 CVE-2026-53953 - Critical (9.1)

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3.22, the password reset endpoint can be accessed without authentication. When a reset request is submitted for an existing...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104020
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-10-01T23:47:14.000Z ##

🟠 CVE-2026-104020 - High (7.5)

Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote unauthenticated actor to crash the application using the library, resulting in a denial of service, via a crafted, deeply nested Ion value.

To reme...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-01T23:47:14.000Z ##

🟠 CVE-2026-104020 - High (7.5)

Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote unauthenticated actor to crash the application using the library, resulting in a denial of service, via a crafted, deeply nested Ion value.

To reme...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

undercodenews@mastodon.social at 2026-10-01T21:56:46.000Z ##

WordPress Vulnerability Could Let Attackers Execute Code on Vulnerable Websites + Video

WordPress Vulnerability Could Let Attackers Execute Code on Vulnerable Websites A Serious WordPress Security Flaw Is Now Being Exploited A newly disclosed vulnerability in WordPress could allow unauthenticated attackers to execute arbitrary PHP code on vulnerable web servers under certain conditions. The issue, tracked as CVE-2026-87902, affects WordPress versions before 7.1.2 and…

undercodenews.com/wordpress-vu

##

thecybermind@infosec.exchange at 2026-10-01T10:07:22.000Z ##

(CISA TS+SOC) CVE-2026-87902 WORDPRESS CODE REMOTE FILE INCLUSION

Active exploitation of CVE-2026-87902 WordPress requires immediate patch deployment and forensic triage. Review integrated TSUITE + SOC intelligence assets....

thecybermind.co/go2d

##

wpguyuk@infosec.exchange at 2026-10-01T07:04:45.000Z ##

CVE-2026-87902 scored 9.2 out of 10, affected every WordPress version since 2016, and was actively exploited within 24 hours of disclosure — no login required. Most site owners never heard a word about it. That silence is the real vulnerability. Knowing your site runs WordPress is not the same as knowing what is happening to it.

#WordPress #WordPressSecurity #CyberSecurity #SecurityHardening

wpguy.uk/blog/cve-2026-87902-t

##

secdb@infosec.exchange at 2026-10-01T00:02:39.000Z ##

📈 CVE Published in last 30 days (2026-09-01 - 2026-09-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1417
- High: 5956
- Medium: 4625
- Low: 927
- None: 1743

Status:
- : 93
- Analyzed: 3418
- Awaiting Analysis: 2780
- Deferred: 5097
- Modified: 128
- Received: 2835
- Rejected: 130
- Undergoing Analysis: 187

CISA KEVs:
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 2117
- VulnCheck: 1638
- GitHub, Inc.: 1424
- Microsoft Corporation: 1000
- VulDB: 900
- Oracle: 634
- WPScan: 552
- MITRE: 497
- Chrome: 467
- Wordfence: 408

Top Affected Products:
- UNKNOWN: 11109
- Microsoft Windows Server 2025: 648
- Microsoft Windows Server 2022: 611
- Microsoft Windows 11 24h2: 600
- Microsoft Windows 11 26h1: 600
- Microsoft Windows 11 25h2: 599
- Microsoft Windows Server 2019: 586
- Microsoft Windows 10 1809: 582
- Microsoft Windows 11 23h2: 574
- Microsoft Windows 10 21h2: 541

Top EPSS Score:
- CVE-2026-85706 - 91.43 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85046 - 48.88 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76461 - 28.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 19.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76460 - 14.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-86218 - 12.93 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83549 - 10.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83548 - 8.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85102 - 7.55 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-56662
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-10-01T20:46:21.000Z ##

🔴 CVE-2026-56662 - Critical (9.6)

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the UpdateCE update form contained no anti-CSRF token, and the POST handler performed no token or request-origin v...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-01T20:46:21.000Z ##

🔴 CVE-2026-56662 - Critical (9.6)

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the UpdateCE update form contained no anti-CSRF token, and the POST handler performed no token or request-origin v...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56661
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-10-01T20:46:12.000Z ##

🟠 CVE-2026-56661 - High (7.5)

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler fetches a user-supplied URL with file_get_contents() after only format validation (FILTER_VALID...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-01T20:46:12.000Z ##

🟠 CVE-2026-56661 - High (7.5)

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler fetches a user-supplied URL with file_get_contents() after only format validation (FILTER_VALID...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56660
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-10-01T20:46:02.000Z ##

🔴 CVE-2026-56660 - Critical (9.1)

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler in UpdateCE.php downloads a ZIP archive and extracts its contents into the web root without val...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-01T20:46:02.000Z ##

🔴 CVE-2026-56660 - Critical (9.1)

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler in UpdateCE.php downloads a ZIP archive and extracts its contents into the web root without val...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92543
(0 None)

EPSS: 0.00%

2 posts

N/A

bmitch@fosstodon.org at 2026-10-01T20:29:30.000Z ##

RE: mastodon.com.pl/@grono/1173619

Digging a bit into CVE-2026-92543, this one looks bad. A MITM can trivially get #docker to ignore TLS certificate issues when pulling content from a registry, allowing an attacker with control of the network to inject malicious container images to run on the target. Digest pinning and signature verification would prevent this attack.

##

bmitch@fosstodon.org at 2026-10-01T20:29:30.000Z ##

RE: mastodon.com.pl/@grono/1173619

Digging a bit into CVE-2026-92543, this one looks bad. A MITM can trivially get #docker to ignore TLS certificate issues when pulling content from a registry, allowing an attacker with control of the network to inject malicious container images to run on the target. Digest pinning and signature verification would prevent this attack.

##

Matchbook3469@mastodon.social at 2026-10-01T19:47:02.000Z ##

🔴 New security advisory:

CVE-2026-55494 affects multiple systems.

• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#Cybersecurity #PatchNow #InfoSecCommunity

##

CVE-2026-55083
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-10-01T19:31:14.000Z ##

🔴 CVE-2026-55083 - Critical (9.1)

DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. From versions 2.42.0 to before 2.42.5.1, and from versions 2.43.0 to before 2.43.0.1, DHIS2 is vulnerable to remote code execution (RCE) ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-01T19:31:14.000Z ##

🔴 CVE-2026-55083 - Critical (9.1)

DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. From versions 2.42.0 to before 2.42.5.1, and from versions 2.43.0 to before 2.43.0.1, DHIS2 is vulnerable to remote code execution (RCE) ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68495
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-10-01T19:01:23.000Z ##

🟠 CVE-2026-68495 - High (7.5)

The CBOR parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. CBORParser._decodeLongerName() d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-01T19:01:23.000Z ##

🟠 CVE-2026-68495 - High (7.5)

The CBOR parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. CBORParser._decodeLongerName() d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2024-76504
(0 None)

EPSS: 0.00%

1 posts

N/A

security_crawler_carl@infosec.exchange at 2026-10-01T18:22:35.000Z ##

CVE-2024-76504 is already being exploited in the wild, so you have entered the failure state before the tutorial even finished loading.

To exit this debuff, upgrade your Cisco Catalyst SD-WAN Manager to a fixed software release immediately — Cisco says so, and frankly the dungeon agrees.

Reward: You've received the Cursed Debuff: Open Admin Panel. It cannot be unequipped until you patch. (2/3)

##

CVE-2026-102147
(0 None)

EPSS: 0.43%

1 posts

N/A

offseq@infosec.exchange at 2026-10-01T10:30:27.000Z ##

CVE-2026-102147: Stored XSS in Kiteworks Core (<9.5.1) rated CRITICAL (CVSS 9.3). Unauth attacker can hijack admin sessions via injected JS — admin takeover risk. No patch yet; restrict access & monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026102147 #AppSec ⚡️

##

CVE-2026-102105
(0 None)

EPSS: 0.53%

1 posts

N/A

offseq@infosec.exchange at 2026-10-01T04:30:23.000Z ##

CVE-2026-102105: Kiteworks Email Protection Gateway <9.5.0 has a CRITICAL SSRF (CVSS 9.1) letting remote attackers access internal resources. No confirmed patch — review vendor guidance & restrict network access. radar.offseq.com/threat/cve-20 #OffSeq #SSRF #Infosec #Vuln

##

CVE-2026-91881
(0 None)

EPSS: 0.00%

1 posts

N/A

DailyCyberSecurity@infosec.exchange at 2026-10-01T02:32:57.000Z ##

Dell patched critical Dell Terraform Provider vulnerabilities. CVE-2026-91881 exposes BMC traffic to attackers. Upgrade your providers to stay safe.

#Dell #Terraform #CVE202691881 #Cybersecurity #InfoSec

securityonline.info/dell-terra

##

CVE-2026-102115
(0 None)

EPSS: 0.53%

1 posts

N/A

CVE-2026-43598
(0 None)

EPSS: 0.00%

1 posts

N/A

AAKL@infosec.exchange at 2026-09-30T17:06:18.000Z ##

New.

Nvidia security advisories today:

This impacts multiple CVEs: NVIDIA GPU Display Driver - September 2026 nvidia.custhelp.com/app/answer

There's more, posted yesterday nvidia.com/en-us/product-secur

AMD security bulletin: CVE-2026-43598: RCCL Vulnerability amd.com/en/resources/product-s #AMD #infosec #vulnerability #Nvidia

##

CVE-2026-84411
(0 None)

EPSS: 0.00%

1 posts

N/A

Visit counter For Websites