##
Updated at UTC 2026-08-06T14:54:06.803226
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-71315 | 8.2 | 0.00% | 1 | 0 | 2026-08-06T14:16:43.987000 | Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3 | |
| CVE-2026-18649 | 7.5 | 0.00% | 1 | 0 | 2026-08-06T14:16:32.430000 | A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and | |
| CVE-2026-66733 | 7.5 | 0.00% | 2 | 0 | 2026-08-06T13:18:21.947000 | Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vul | |
| CVE-2026-5430 | 10.0 | 0.00% | 2 | 0 | 2026-08-06T13:18:21.283000 | The JWT authentication mechanism accepts tokens signed with algorithms other tha | |
| CVE-2026-1728 | 9.8 | 0.00% | 2 | 0 | 2026-08-06T13:17:28.180000 | Tokens issued to a low-privileged user are not sufficiently restricted, allowing | |
| CVE-2026-15459 | 8.1 | 0.00% | 2 | 0 | 2026-08-06T06:31:41 | The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypa | |
| CVE-2026-8478 | 8.8 | 0.00% | 1 | 0 | 2026-08-06T05:17:11.987000 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject ar | |
| CVE-2026-70482 | 8.1 | 0.34% | 1 | 0 | 2026-08-06T05:17:07.240000 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI plat | |
| CVE-2026-70431 | 8.8 | 0.00% | 2 | 0 | 2026-08-06T05:17:06.537000 | Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scriptin | |
| CVE-2026-70426 | 9.0 | 0.00% | 5 | 0 | 2026-08-06T05:17:05.850000 | In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, incl | |
| CVE-2026-63077 | 9.8 | 0.65% | 9 | 1 | 2026-08-06T05:17:05.170000 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe | |
| CVE-2026-44945 | 9.1 | 0.74% | 1 | 0 | 2026-08-06T05:17:03.793000 | A privilege escalation vulnerability exists in Rancher's impersonation middlewar | |
| CVE-2026-20312 | 8.8 | 0.00% | 1 | 0 | 2026-08-06T05:17:02.450000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-20304 | 9.9 | 0.00% | 1 | 0 | 2026-08-06T05:16:59.827000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-20267 | 9.0 | 0.00% | 1 | 0 | 2026-08-06T05:16:43.583000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-17633 | 8.5 | 0.00% | 2 | 0 | 2026-08-06T05:16:40.457000 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacke | |
| CVE-2026-18973 | 7.3 | 0.00% | 1 | 0 | 2026-08-06T01:16:29.410000 | A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The | |
| CVE-2026-67869 | 7.5 | 0.00% | 2 | 0 | 2026-08-06T00:31:38 | Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to ca | |
| CVE-2026-67863 | 7.5 | 0.00% | 2 | 0 | 2026-08-06T00:31:29 | In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredIt | |
| CVE-2026-67531 | 0 | 0.00% | 2 | 0 | 2026-08-06T00:16:53.733000 | FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). P | |
| CVE-2026-18970 | 7.3 | 0.00% | 1 | 0 | 2026-08-06T00:16:53.060000 | A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Plat | |
| CVE-2026-71321 | 7.5 | 0.00% | 2 | 0 | 2026-08-05T21:43:07 | ### Impact The internal island renderer endpoint (`/__nuxt_island/...`) decodes | |
| CVE-2026-70432 | 8.8 | 0.00% | 2 | 0 | 2026-08-05T21:32:44 | A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669 | |
| CVE-2026-60007 | 7.4 | 0.45% | 1 | 0 | 2026-08-05T21:32:37 | In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns | |
| CVE-2026-70615 | 9.9 | 0.00% | 1 | 0 | 2026-08-05T21:31:48 | boringproxy through 0.10.0 contains a newline injection vulnerability that allow | |
| CVE-2026-34966 | 7.6 | 0.00% | 1 | 0 | 2026-08-05T21:31:47 | Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that | |
| CVE-2026-17624 | 8.5 | 0.00% | 2 | 0 | 2026-08-05T21:31:46 | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10. | |
| CVE-2026-17632 | 8.8 | 0.00% | 2 | 0 | 2026-08-05T21:31:46 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacke | |
| CVE-2026-18485 | 7.8 | 0.00% | 2 | 0 | 2026-08-05T21:31:46 | There is a local privilege escalation vulnerability recently discovered in the N | |
| CVE-2026-18411 | 8.1 | 0.00% | 2 | 0 | 2026-08-05T21:31:46 | The KARR Security System and SWDS dealer-installed automotive anti-theft systems | |
| CVE-2026-17583 | 8.4 | 0.00% | 2 | 1 | 2026-08-05T21:31:46 | The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable | |
| CVE-2026-69111 | 7.5 | 0.00% | 1 | 0 | 2026-08-05T21:31:46 | Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vu | |
| CVE-2026-8183 | 7.7 | 0.00% | 1 | 0 | 2026-08-05T21:31:39 | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10. | |
| CVE-2026-8182 | 8.8 | 0.00% | 1 | 0 | 2026-08-05T21:31:39 | IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet | |
| CVE-2026-9201 | 8.8 | 0.00% | 1 | 0 | 2026-08-05T21:31:39 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to e | |
| CVE-2026-9196 | 8.1 | 0.00% | 1 | 0 | 2026-08-05T21:31:39 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to e | |
| CVE-2026-71320 | 8.1 | 0.00% | 2 | 0 | 2026-08-05T21:29:56 | ## Impact Nuxt server islands accept props via the `/__nuxt_island/` endpoint. | |
| CVE-2026-71319 | 9.6 | 0.00% | 4 | 0 | 2026-08-05T21:27:39 | ### Impact Nuxt DevTools (development mode only) exposes a bidirectional RPC ch | |
| CVE-2026-71316 | 7.5 | 0.00% | 2 | 0 | 2026-08-05T21:14:34 | ### Impact When a page is covered by `routeRules` `cache` / `swr` / `isr`, Nuxt | |
| CVE-2026-71314 | 7.5 | 0.00% | 1 | 0 | 2026-08-05T20:59:08 | ### Impact An unauthenticated attacker can crash a Nuxt server that renders any | |
| CVE-2026-71312 | 8.0 | 0.00% | 1 | 0 | 2026-08-05T20:38:00 | ## 1. Summary rclone interpolates remote SFTP paths into PowerShell hash comman | |
| CVE-2026-70617 | 8.1 | 0.00% | 1 | 0 | 2026-08-05T20:17:17.770000 | Spacebar Server before commit dcfd910 contains a missing authorization vulnerabi | |
| CVE-2026-15573 | 8.1 | 0.00% | 1 | 0 | 2026-08-05T20:17:05.243000 | A flaw was found in Keycloak's Authorization Services. The component responsible | |
| CVE-2026-17566 | 9.9 | 0.43% | 1 | 1 | 2026-08-05T20:00:10.473000 | pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by in | |
| CVE-2026-9077 | 8.5 | 0.00% | 1 | 0 | 2026-08-05T19:17:45.807000 | IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attac | |
| CVE-2026-20310 | 9.1 | 0.00% | 2 | 0 | 2026-08-05T18:31:49 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-20313 | 7.7 | 0.00% | 2 | 0 | 2026-08-05T18:31:49 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-20303 | 9.9 | 0.00% | 1 | 0 | 2026-08-05T18:31:48 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-20272 | 9.8 | 0.00% | 1 | 0 | 2026-08-05T18:31:45 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-45537 | 9.1 | 0.36% | 1 | 0 | 2026-08-05T18:17:11.353000 | OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versio | |
| CVE-2026-20301 | 8.6 | 0.00% | 2 | 0 | 2026-08-05T18:17:07.557000 | A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referre | |
| CVE-2026-18898 | 8.8 | 0.47% | 1 | 0 | 2026-08-05T17:16:45.797000 | A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. Thi | |
| CVE-2026-71289 | 9.8 | 0.00% | 1 | 0 | 2026-08-05T16:17:08.400000 | The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implement | |
| CVE-2026-71287 | 8.8 | 0.00% | 1 | 0 | 2026-08-05T16:17:08.190000 | Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER | |
| CVE-2026-71285 | 8.1 | 0.00% | 1 | 0 | 2026-08-05T16:17:07.967000 | Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js | |
| CVE-2026-67861 | 7.5 | 0.42% | 1 | 0 | 2026-08-05T16:17:00.200000 | An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a den | |
| CVE-2026-67859 | 7.5 | 0.47% | 1 | 0 | 2026-08-05T16:17:00.067000 | Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to ca | |
| CVE-2026-59913 | 7.8 | 0.11% | 1 | 0 | 2026-08-05T15:44:27.057000 | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, co | |
| CVE-2026-34486 | 9.8 | 81.16% | 5 | 6 | 2026-08-05T15:33:26.557000 | Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the f | |
| CVE-2026-71294 | 7.6 | 0.00% | 1 | 0 | 2026-08-05T15:32:29 | Cotonti CMS's Comments plugin deserializes user-supplied data without restrictin | |
| CVE-2026-67857 | 7.5 | 0.35% | 1 | 0 | 2026-08-05T15:32:14 | open62541 1.5.5 contains an out-of-bounds read in the client-side function respo | |
| CVE-2026-9273 | 9.3 | 0.28% | 1 | 0 | 2026-08-05T15:17:19.770000 | The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restr | |
| CVE-2026-70554 | 9.8 | 0.85% | 1 | 0 | 2026-08-05T15:17:13.783000 | MaxSite CMS contains a PHP object injection vulnerability that allows unauthenti | |
| CVE-2026-70486 | 8.2 | 0.37% | 1 | 0 | 2026-08-05T15:17:10.497000 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI plat | |
| CVE-2026-67858 | 7.5 | 0.49% | 1 | 0 | 2026-08-05T15:17:06.617000 | Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery | |
| CVE-2026-18895 | 8.8 | 0.57% | 1 | 0 | 2026-08-05T15:16:45.587000 | A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacte | |
| CVE-2026-68981 | 7.5 | 0.32% | 1 | 0 | 2026-08-05T14:59:30.577000 | Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the appl | |
| CVE-2026-68979 | 9.8 | 0.35% | 1 | 0 | 2026-08-05T14:59:03.460000 | Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API me | |
| CVE-2026-48449 | 10.0 | 0.54% | 1 | 0 | 2026-08-05T14:54:01.933000 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi | |
| CVE-2026-71214 | 9.8 | 0.34% | 1 | 0 | 2026-08-05T14:17:14.103000 | The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-serve | |
| CVE-2026-71254 | 9.8 | 0.00% | 1 | 0 | 2026-08-05T13:24:49.680000 | nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server- | |
| CVE-2026-66747 | 9.8 | 0.00% | 1 | 0 | 2026-08-05T12:31:36 | Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, | |
| CVE-2026-4431 | 9.1 | 0.33% | 1 | 0 | 2026-08-05T09:31:26 | The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modi | |
| CVE-2026-9198 | 9.8 | 17.05% | 4 | 4 | 2026-08-05T05:17:15.823000 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain | |
| CVE-2026-6837 | 7.2 | 0.95% | 1 | 0 | 2026-08-05T05:17:14.873000 | A post-authentication command injection vulnerability in the "export-cgi" CGI pr | |
| CVE-2026-66318 | 8.1 | 0.37% | 1 | 0 | 2026-08-05T05:17:07.877000 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorize | |
| CVE-2026-58073 | 0 | 0.22% | 3 | 0 | 2026-08-05T05:17:02.413000 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated at | |
| CVE-2026-58072 | 0 | 0.38% | 2 | 0 | 2026-08-05T05:17:01.967000 | A vulnerability in Veeam Service Provider Console allowing arbitrary file write | |
| CVE-2026-15307 | 8.8 | 0.54% | 1 | 0 | 2026-08-05T05:16:46.480000 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDja | |
| CVE-2026-18897 | 8.8 | 0.57% | 1 | 0 | 2026-08-05T03:30:28 | A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. T | |
| CVE-2026-70619 | 8.8 | 0.36% | 1 | 0 | 2026-08-05T00:30:46 | Odysseus before commit bf325f6 contains a missing authorization vulnerability th | |
| CVE-2026-70553 | 9.8 | 0.88% | 2 | 1 | 2026-08-04T21:30:37 | MaxSite CMS contains a remote code execution vulnerability that allows unauthent | |
| CVE-2026-69703 | 9.8 | 0.46% | 1 | 0 | 2026-08-04T21:30:29 | Atlas-Livre contains an improper access control vulnerability in the admin contr | |
| CVE-2026-49435 | 9.8 | 0.77% | 1 | 0 | 2026-08-04T21:30:28 | Keysight IxChariot Endpoint and associated products contain a stack-based buffer | |
| CVE-2026-18556 | 7.4 | 0.49% | 4 | 1 | 2026-08-04T21:30:26 | Authentication bypass using an alternate path or channel vulnerability in N-able | |
| CVE-2026-15969 | 9.8 | 0.98% | 1 | 0 | 2026-08-04T20:43:06.967000 | SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via by | |
| CVE-2026-70478 | None | 0.38% | 1 | 0 | 2026-08-04T19:37:38 | ### Summary The OAuth2 token refresh endpoint (`POST /api/v1/oauth2-credential/ | |
| CVE-2026-70477 | None | 0.44% | 1 | 0 | 2026-08-04T19:29:28 | -- ABSTRACT ------------------------------------- Trend Micro's Zero Day Initia | |
| CVE-2026-18830 | 8.1 | 0.29% | 1 | 0 | 2026-08-04T19:16:45.433000 | Insufficient input validation in Amazon Bedrock AgentCore harness might allow an | |
| CVE-2026-24254 | 9.8 | 0.45% | 1 | 0 | 2026-08-04T18:31:37 | NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topol | |
| CVE-2026-64633 | None | 0.34% | 1 | 1 | 2026-08-04T18:31:36 | A vulnerability allowing remote unauthenticated code execution on the agent host | |
| CVE-2026-15920 | 6.1 | 0.30% | 1 | 0 | 2026-08-04T18:31:31 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `djang | |
| CVE-2026-24083 | 7.8 | 0.11% | 1 | 0 | 2026-08-04T18:31:31 | Memory Corruption while processing IOCTL device driver requests with invalid arg | |
| CVE-2026-25292 | 7.6 | 0.16% | 1 | 0 | 2026-08-04T18:31:31 | Memory Corruption when processing untrusted user input in the fastboot command h | |
| CVE-2026-69100 | 8.8 | 0.55% | 1 | 0 | 2026-08-04T18:31:31 | LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains | |
| CVE-2026-69098 | 9.8 | 0.51% | 1 | 1 | 2026-08-04T18:31:31 | kotaemon through 0.12.0 contains an insecure deserialization vulnerability in th | |
| CVE-2026-15958 | 9.3 | 0.20% | 1 | 0 | 2026-08-04T18:16:45.220000 | The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform | |
| CVE-2026-69110 | 9.1 | 0.55% | 1 | 0 | 2026-08-04T17:16:59.733000 | OpenCode Studio before 2.4.4 contains a missing authentication vulnerability tha | |
| CVE-2026-48323 | 10.0 | 0.62% | 2 | 0 | 2026-08-04T17:16:55.413000 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia | |
| CVE-2026-24084 | 7.5 | 0.23% | 1 | 0 | 2026-08-04T17:16:52.453000 | Weak configuration when UE does not verify the consistency of its additional sec | |
| CVE-2026-48326 | 9.9 | 0.48% | 1 | 0 | 2026-08-04T16:16:25.497000 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia | |
| CVE-2026-18686 | 9.8 | 2.61% | 1 | 0 | 2026-08-04T16:16:21.593000 | A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected elem | |
| CVE-2026-18577 | 8.1 | 4.10% | 11 | 2 | 2026-08-04T15:33:20 | An incomplete patch for CVE-2026-18556 allows for authentication bypass and acco | |
| CVE-2026-69240 | 9.8 | 0.32% | 1 | 0 | 2026-08-04T15:16:42.087000 | Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with | |
| CVE-2026-59639 | 0 | 0.17% | 1 | 0 | 2026-08-04T14:50:12.360000 | In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for Sig | |
| CVE-2026-12816 | 0 | 0.16% | 1 | 0 | 2026-08-04T14:50:12.360000 | In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via len | |
| CVE-2026-15721 | 9.8 | 0.23% | 1 | 0 | 2026-08-04T14:16:30.620000 | Cleartext storage of sensitive information vulnerability in Bilin Software and I | |
| CVE-2026-14175 | 9.8 | 0.40% | 2 | 0 | 2026-08-04T12:34:56 | Unrestricted upload of file with dangerous type vulnerability in Bilin Software | |
| CVE-2026-14804 | 9.1 | 0.30% | 2 | 0 | 2026-08-04T12:34:56 | Use of hard-coded cryptographic key vulnerability in Bilin Software and Informat | |
| CVE-2026-18754 | 9.1 | 0.31% | 1 | 0 | 2026-08-04T09:31:41 | The product firmware contains an embedded, static RSA private key utilized by th | |
| CVE-2026-9044 | 0 | 0.97% | 1 | 0 | 2026-08-04T05:16:40.213000 | An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 | |
| CVE-2026-62354 | None | 0.26% | 1 | 0 | 2026-08-04T00:35:57 | Authorization handling for Parameter Context validation requests in Apache NiFi | |
| CVE-2026-48333 | 9.8 | 0.47% | 1 | 0 | 2026-08-04T00:35:01 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi | |
| CVE-2026-18684 | 9.8 | 2.03% | 1 | 0 | 2026-08-04T00:35:01 | A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affe | |
| CVE-2026-48331 | 10.0 | 0.47% | 1 | 0 | 2026-08-04T00:35:01 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) | |
| CVE-2026-66310 | 7.7 | 0.40% | 1 | 0 | 2026-08-04T00:35:01 | External control of file name or path in Microsoft Edge for Android allows an un | |
| CVE-2026-18685 | 9.8 | 1.99% | 1 | 0 | 2026-08-04T00:35:01 | A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Imp | |
| CVE-2026-48330 | 10.0 | 0.68% | 1 | 0 | 2026-08-04T00:35:01 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia | |
| CVE-2026-66315 | 7.5 | 0.62% | 1 | 0 | 2026-08-04T00:34:55 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacke | |
| CVE-2026-59912 | 7.8 | 0.10% | 1 | 0 | 2026-08-03T21:31:36 | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, co | |
| CVE-2026-18108 | 9.8 | 0.22% | 1 | 0 | 2026-08-03T20:17:14.513000 | Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _ve | |
| CVE-2026-18614 | 9.8 | 2.01% | 1 | 0 | 2026-08-03T19:16:45.200000 | A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the func | |
| CVE-2026-18574 | None | 0.99% | 1 | 0 | 2026-08-03T15:32:49 | An authentication bypass vulnerability in Check Point Security Management Server | |
| CVE-2026-33591 | None | 0.52% | 1 | 0 | 2026-08-03T12:32:43 | A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unaut | |
| CVE-2026-5674 | 8.8 | 0.13% | 1 | 0 | 2026-08-03T09:33:40 | A flaw was found in PipeWire, a multimedia server. This vulnerability allows an | |
| CVE-2026-8763 | None | 0.33% | 1 | 1 | 2026-08-03T09:32:36 | In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot | |
| CVE-2026-12803 | None | 0.17% | 1 | 0 | 2026-08-03T09:32:36 | In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce w | |
| CVE-2026-58062 | None | 0.20% | 1 | 1 | 2026-08-03T09:32:36 | In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without bi | |
| CVE-2026-58061 | None | 0.21% | 1 | 0 | 2026-08-03T09:32:36 | In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to calle | |
| CVE-2026-12569 | 9.8 | 30.20% | 4 | 1 | 2026-08-01T05:16:55.023000 | A critical remote code execution (RCE) vulnerability has been reported in PTC Wi | |
| CVE-2026-58048 | None | 0.50% | 1 | 2 | 2026-07-31T18:32:25 | Improper preservation of SQL mode when renaming databases in cPanel allows exec | |
| CVE-2026-12943 | 9.8 | 0.92% | 1 | 0 | 2026-07-30T21:31:50 | IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1 | |
| CVE-2026-51291 | 9.8 | 0.00% | 1 | 0 | 2026-07-30T21:31:47 | sqlite 3.41 is vulnerable to use after free in the json.c jsonCacheInsert functi | |
| CVE-2026-67192 | 8.1 | 0.62% | 1 | 0 | 2026-07-30T20:04:51.110000 | Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overfl | |
| CVE-2026-41709 | 2.7 | 0.38% | 1 | 0 | 2026-07-30T19:07:59.843000 | VMware ESX contains an insufficient logging vulnerability. A malicious administr | |
| CVE-2026-66066 | None | 1.70% | 3 | 7 | 2026-07-30T18:23:34 | ### Impact In its default configuration, a Rails application that displays image | |
| CVE-2026-47876 | 9.3 | 0.28% | 1 | 0 | 2026-07-30T15:31:54 | VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual | |
| CVE-2026-59309 | 9.8 | 0.74% | 1 | 0 | 2026-07-30T15:31:54 | VMware vCenter contains an authentication bypass vulnerability in the VMware Dir | |
| CVE-2026-59310 | 9.8 | 1.14% | 1 | 0 | 2026-07-30T15:31:51 | VMware vCenter contains a directory traversal vulnerability in the Syslog server | |
| CVE-2026-41703 | 7.6 | 0.56% | 1 | 0 | 2026-07-30T15:31:50 | VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. | |
| CVE-2026-16498 | 10.0 | 0.33% | 1 | 0 | 2026-07-30T14:08:23.057000 | The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant cr | |
| CVE-2026-20316 | 5.3 | 0.79% | 1 | 0 | 2026-07-29T21:31:00 | A vulnerability in the web interface of Cisco Secure Firewall Management Center | |
| CVE-2026-53264 | 7.8 | 0.21% | 1 | 1 | 2026-07-29T21:30:47 | In the Linux kernel, the following vulnerability has been resolved: net/sched: | |
| CVE-2026-31431 | 7.8 | 94.55% | 1 | 100 | 2026-07-28T14:54:01.770000 | In the Linux kernel, the following vulnerability has been resolved: crypto: alg | |
| CVE-2026-12495 | 0 | 0.16% | 1 | 0 | 2026-07-28T08:17:14.187000 | Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http | |
| CVE-2026-39868 | 9.1 | 0.94% | 2 | 0 | 2026-07-27T21:16:51.020000 | This issue was addressed with improved input validation. This issue is fixed in | |
| CVE-2026-50522 | 9.8 | 75.76% | 1 | 5 | 2026-07-23T15:44:10.873000 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut | |
| CVE-2026-46300 | 7.8 | 7.01% | 1 | 15 | 2026-07-23T11:10:00.120000 | In the Linux kernel, the following vulnerability has been resolved: net: skbuff | |
| CVE-2026-50343 | 7.8 | 3.50% | 1 | 1 | 2026-07-22T16:17:42.747000 | Improper privilege management in Microsoft Install Service allows an authorized | |
| CVE-2026-15410 | 7.2 | 76.35% | 2 | 3 | 2026-07-16T05:16:18.470000 | Post-authentication improper control of generation of code ('Code Injection') vu | |
| CVE-2026-15409 | 10.0 | 78.44% | 2 | 6 | 2026-07-16T05:16:18.293000 | A Server-side request forgery (SSRF) vulnerability has been identified in the SM | |
| CVE-2026-54121 | 8.8 | 1.05% | 1 | 12 | 2026-07-14T18:32:37 | Improper authorization in Active Directory Certificate Services (AD CS) allows a | |
| CVE-2026-43284 | 7.8 | 93.23% | 1 | 44 | 2026-07-14T15:31:59 | In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: | |
| CVE-2026-59726 | 10.0 | 0.48% | 2 | 1 | 2026-07-10T19:15:15.780000 | Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo | |
| CVE-2026-46113 | 8.8 | 0.15% | 1 | 0 | 2026-06-24T18:32:31 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: F | |
| CVE-2026-50645 | 7.5 | 0.48% | 1 | 0 | 2026-06-17T10:57:46.017000 | There is no restriction on the amount of attachment headers that a message can c | |
| CVE-2026-41679 | 10.0 | 1.97% | 2 | 1 | 2026-06-17T10:46:59.450000 | Paperclip is a Node.js server and React UI that orchestrates a team of AI agents | |
| CVE-2025-58487 | 4.0 | 0.15% | 2 | 0 | 2026-06-17T09:44:33.170000 | Improper authorization in Samsung Account prior to version 15.5.01.1 allows loca | |
| CVE-2025-58486 | 4.0 | 0.16% | 4 | 0 | 2026-06-17T09:44:33.060000 | Improper input validation in Samsung Account prior to version 15.5.01.1 allows l | |
| CVE-2025-26399 | 9.8 | 88.33% | 1 | 1 | 2026-06-17T09:01:42.407000 | SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxP | |
| CVE-2025-21079 | 7.1 | 0.41% | 4 | 0 | 2026-06-17T08:42:34.123000 | Improper input validation in Samsung Members prior to version 5.5.01.3 allows re | |
| CVE-2023-32233 | 7.8 | 12.97% | 1 | 7 | 2026-06-17T05:58:22.273000 | In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when | |
| CVE-2026-42897 | 8.1 | 70.31% | 2 | 1 | 2026-05-15T18:30:32 | Improper neutralization of input during web page generation ('cross-site scripti | |
| CVE-2026-20079 | 10.0 | 37.67% | 3 | 1 | 2026-03-04T18:32:03 | A vulnerability in the web interface of Cisco Secure Firewall Management Center | |
| CVE-2013-4786 | 7.5 | 78.57% | 2 | 1 | 2025-04-11T04:12:49 | The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (R | |
| CVE-2026-59774 | 0 | 0.00% | 3 | 1 | N/A | ||
| CVE-2026-15991 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-48168 | 0 | 0.00% | 3 | 0 | N/A | ||
| CVE-2026-18953 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-55524 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-55522 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-8446 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-53921 | 0 | 0.00% | 1 | 2 | N/A |
updated 2026-08-06T14:16:43.987000
1 posts
🟠 CVE-2026-71315 - High (8.2)
Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules keys can fail to match case-folded lookups when router.options.sensitive is false and drop appMiddleware authorization gates. T...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71315/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T14:16:32.430000
1 posts
CVE-2026-18649 - DoS in GStreamer via RTP depayloaders. Unbounded buffer growth from fragmented packets crashes process. CVSS 7.5. Unpatched - update or block RTP. #CVE #GStreamer #infosec
##updated 2026-08-06T13:18:21.947000
2 posts
CVE-2026-66733: HIGH severity vuln in Eukaryot sonic3air ≤26.03.28.0. Crafted UDP packets can force unbounded memory allocation, crashing the server (DoS, no RCE). Patch unconfirmed — check vendor. https://radar.offseq.com/threat/cve-2026-66733-memory-allocation-with-excessive-size-value-in-eukaryot-sonic3air-4d6f914f9dea29a1 #OffSeq #Vuln #DoS #sonic3air
##CVE-2026-66733: HIGH severity vuln in Eukaryot sonic3air ≤26.03.28.0. Crafted UDP packets can force unbounded memory allocation, crashing the server (DoS, no RCE). Patch unconfirmed — check vendor. https://radar.offseq.com/threat/cve-2026-66733-memory-allocation-with-excessive-size-value-in-eukaryot-sonic3air-4d6f914f9dea29a1 #OffSeq #Vuln #DoS #sonic3air
##updated 2026-08-06T13:18:21.283000
2 posts
WSO2 Universal Gateway v4.5.0 & 4.6.0 affected by CRITICAL CVE-2026-5430 (CVSS 10.0). Improper JWT validation enables account takeover. No patch yet — apply compensating controls. https://radar.offseq.com/threat/cve-2026-5430-cwe-347-improper-validation-of-certificate-with-host-mismatch-in-wso2-wso2-universal-f913080655427dd8 #OffSeq #WSO2 #JWT #Vulnerability
##WSO2 Universal Gateway v4.5.0 & 4.6.0 affected by CRITICAL CVE-2026-5430 (CVSS 10.0). Improper JWT validation enables account takeover. No patch yet — apply compensating controls. https://radar.offseq.com/threat/cve-2026-5430-cwe-347-improper-validation-of-certificate-with-host-mismatch-in-wso2-wso2-universal-f913080655427dd8 #OffSeq #WSO2 #JWT #Vulnerability
##updated 2026-08-06T13:17:28.180000
2 posts
CVE-2026-1728 | CRITICAL: WSO2 API Manager (v4.0.0 – 4.6.0) has an improper privilege management flaw. Low-privileged user tokens can access admin REST APIs — possible admin account takeover. Patch status unknown. Restrict access & monitor. https://radar.offseq.com/threat/cve-2026-1728-cwe-269-improper-privilege-management-in-wso2-wso2-api-manager-fea4a27d18a06e70 #OffSeq #WSO2 #Vuln
##CVE-2026-1728 | CRITICAL: WSO2 API Manager (v4.0.0 – 4.6.0) has an improper privilege management flaw. Low-privileged user tokens can access admin REST APIs — possible admin account takeover. Patch status unknown. Restrict access & monitor. https://radar.offseq.com/threat/cve-2026-1728-cwe-269-improper-privilege-management-in-wso2-wso2-api-manager-fea4a27d18a06e70 #OffSeq #WSO2 #Vuln
##updated 2026-08-06T06:31:41
2 posts
🟠 CVE-2026-15459 - High (8.1)
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet connected to the WPMU DEV Hub — the default state after installation — the site API key that keys ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15459/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-15459 - High (8.1)
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet connected to the WPMU DEV Hub — the default state after installation — the site API key that keys ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15459/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T05:17:11.987000
1 posts
🟠 CVE-2026-8478 - High (8.8)
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8478/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T05:17:07.240000
1 posts
🟠 CVE-2026-70482 - High (8.1)
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchange accepts a raw provider access token and validates it by calling ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70482/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T05:17:06.537000
2 posts
🟠 CVE-2026-70431 - High (8.8)
Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugin, allowing attackers with Item/Create or Item/Configure permission to execute arbitrary code in the context...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70431/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-70431 - High (8.8)
Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugin, allowing attackers with Item/Create or Item/Configure permission to execute arbitrary code in the context...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70431/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T05:17:05.850000
5 posts
Critical Jenkins Vulnerability Exposes Build Controllers: CVE-2026-70426 Could Turn Trusted Automation Into an Attacker’s Gateway + Video
Introduction: The Hidden Risk Behind Modern Software Automation Jenkins has become one of the most important automation platforms in the software industry, powering continuous integration and continuous delivery (CI/CD) pipelines for organizations worldwide. From compiling applications to deploying cloud infrastructure, Jenkins…
##🔴 CVE-2026-70426 - Critical (9)
In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserializa...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70426/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Critical Jenkins vulnerability CVE-2026-70426 lets attackers bypass the JEP-200 filter and run code on the controller. Patch now.
#Jenkins #CVE202670426 #RCE #DevSecOps #Deserialization #CyberSecurity
🔴 CVE-2026-70426 - Critical (9)
In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserializa...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70426/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Critical Jenkins vulnerability CVE-2026-70426 lets attackers bypass the JEP-200 filter and run code on the controller. Patch now.
#Jenkins #CVE202670426 #RCE #DevSecOps #Deserialization #CyberSecurity
updated 2026-08-06T05:17:05.170000
9 posts
1 repos
https://github.com/unveiledhistory49/teamcity-cve-2026-63077-remediation
🚨 CSUITE THREAT ADVISORY: CISA confirms active exploitation of CVE-2026-63077 in JetBrains TeamCity. Unauthenticated RCE threatens core build pipelines & supply chain integrity. Get the executive governance, risk management, and compliance brief now: https://thecybermind.co/jvee
##CISA Warns of Active TeamCity Exploit
Warning: a critical vulnerability in JetBrains TeamCity (CVE-2026-63077) is being actively exploited in the wild, allowing unauthenticated attackers to execute malicious code remotely. This severe flaw has a CVSS score of 9.8, highlighting the urgent need for immediate action.
https://osintsights.com/cisa-warns-of-active-teamcity-exploit?utm_source=mastodon&utm_medium=social
#Teamcity #Cve202663077 #DeserializationVulnerability #RemoteCodeExecution #Cisa
##CVE-2026-63077: CISA warnt vor aktiver Ausnutzung einer TeamCity-Sicherheitslücke
Angreifer können ohne Authentifizierung Schadcode auf dem Server ausführen.
##TeamCity vulnerability CVE-2026-63077 enables unauthenticated remote code execution. CISA added it to the KEV catalog amid active exploitation.
##🚨 CSUITE THREAT ADVISORY: CISA confirms active exploitation of CVE-2026-63077 in JetBrains TeamCity. Unauthenticated RCE threatens core build pipelines & supply chain integrity. Get the executive governance, risk management, and compliance brief now: https://thecybermind.co/jvee
##TeamCity vulnerability CVE-2026-63077 enables unauthenticated remote code execution. CISA added it to the KEV catalog amid active exploitation.
##🚨 CISA KEV ALERT: CVE-2026-63077 exposes JetBrains TeamCity servers to unauthenticated RCE via untrusted deserialization. Active exploitation confirmed. Get the forensic breakdown, CrowdStrike CQL detection logic, and CI/CD hardening steps: https://thecybermind.co/oapr
##🚨 [CISA-2026:0805] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-63077 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63077)
- Name: JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JetBrains
- Product: TeamCity
- Notes: https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/; https://www.jetbrains.com/privacy-security/issues-fixed/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-63077
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260805 #cisa20260805 #cve_2026_63077 #cve202663077
##CVE ID: CVE-2026-63077
Vendor: JetBrains
Product: TeamCity
Date Added: 2026-08-05
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-63077
updated 2026-08-06T05:17:03.793000
1 posts
SUSE Rancher CVE-2026-44945 (CRITICAL, CVSS 9.1): Privilege escalation flaw lets authenticated users with default global role gain full admin on Rancher & clusters. Restrict access & monitor pending patch. https://radar.offseq.com/threat/cve-2026-44945-cwe-441-unintended-proxy-or-intermediary-confused-deputy-in-suse-rancher-9a7358d4ec1c0d9c #OffSeq #infosec #CVE202644945 #Kubernetes
##updated 2026-08-06T05:17:02.450000
1 posts
🟠 CVE-2026-20312 - High (8.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address mu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20312/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T05:16:59.827000
1 posts
Cisco SD-WAN vulnerability CVE-2026-20303 and CVE-2026-20304 reach CVSS 9.9. Cisco urges Catalyst SD-WAN customers to patch now.
#Cisco #SDWAN #CVE202620303 #CVE202620304 #CyberSecurity #NetworkSecurity
updated 2026-08-06T05:16:43.583000
1 posts
Cisco IOS XE vulnerability CVE-2026-20272 hits CVSS 9.8 and CVE-2026-20267 scores 9.0. Cisco urges customers to patch now.
#Cisco #IOSXE #CVE202620272 #CVE202620267 #CyberSecurity #NetworkSecurity
##updated 2026-08-06T05:16:40.457000
2 posts
🟠 CVE-2026-17633 - High (8.5)
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17633/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-17633 - High (8.5)
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17633/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T01:16:29.410000
1 posts
CVE-2026-18973 - SSRF in heshengtao super-agent-party ≤0.4.1. Unpatched, exploit public. CVSS 7.3. Update/block immediately. #CVE #infosec #cybersecurity
##updated 2026-08-06T00:31:38
2 posts
🟠 CVE-2026-67869 - High (7.5)
Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67869/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67869 - High (7.5)
Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67869/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T00:31:29
2 posts
🟠 CVE-2026-67863 - High (7.5)
In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish continues to use the current UA_Notification after a callback invokes UA_Server_deleteMonitoredIte...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67863/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67863 - High (7.5)
In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish continues to use the current UA_Notification after a callback invokes UA_Server_deleteMonitoredIte...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67863/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T00:16:53.733000
2 posts
CVE-2026-67531 (CRITICAL): agentfront frontmcp <1.5.7 suffers a code injection flaw enabling remote code execution and theft of secrets. Upgrade to v1.5.7+ ASAP. https://radar.offseq.com/threat/cve-2026-67531-cwe-94-improper-control-of-generation-of-code-code-injection-in-agentfront-frontmcp-2c28d3d3312eb9f5 #OffSeq #Vulnerability #RCE #InfoSec #CVE2026
##CVE-2026-67531 (CRITICAL): agentfront frontmcp <1.5.7 suffers a code injection flaw enabling remote code execution and theft of secrets. Upgrade to v1.5.7+ ASAP. https://radar.offseq.com/threat/cve-2026-67531-cwe-94-improper-control-of-generation-of-code-code-injection-in-agentfront-frontmcp-2c28d3d3312eb9f5 #OffSeq #Vulnerability #RCE #InfoSec #CVE2026
##updated 2026-08-06T00:16:53.060000
1 posts
CVE-2026-18970 - SQLi in Command Dispatch Platform. Remote exploit via /dm/dispatch/user/findAll, CVSS 7.3. Unpatched, vendor unresponsive. Mitigate now. #CVE #infosec #cybersecurity
##updated 2026-08-05T21:43:07
2 posts
🟠 CVE-2026-71321 - High (7.5)
Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island renderer endpoint `/__nuxt_island/...` decodes and hashes attacker-controlled JSON body input with destr and ohash before validati...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71321/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-71321 - High (7.5)
Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island renderer endpoint `/__nuxt_island/...` decodes and hashes attacker-controlled JSON body input with destr and ohash before validati...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71321/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T21:32:44
2 posts
🟠 CVE-2026-70432 - High (8.8)
A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute arbitrary code in the context of the Jenkins controller JVM.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70432/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-70432 - High (8.8)
A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute arbitrary code in the context of the Jenkins controller JVM.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70432/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T21:32:37
1 posts
Eclipse Milo (0.6.0 – 1.1.4) faces a CRITICAL flaw (CVE-2026-60007): error messages in username-token RSA PKCS#1 v1.5 handling enable padding oracle attacks, risking password compromise. Patch status unclear. https://radar.offseq.com/threat/cve-2026-60007-cwe-204-in-eclipse-foundation-eclipse-milo-bf23a775f0392e71 #OffSeq #EclipseMilo #Vuln #Infosec
##updated 2026-08-05T21:31:48
1 posts
🔴 CVE-2026-70615 - Critical (9.9)
boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH authorized_keys file by supplying a percen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70615/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T21:31:47
1 posts
🟠 CVE-2026-34966 - High (7.6)
Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get w...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-34966/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T21:31:46
2 posts
🟠 CVE-2026-17624 - High (8.5)
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17624/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-17624 - High (8.5)
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17624/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T21:31:46
2 posts
🟠 CVE-2026-17632 - High (8.8)
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based security scanning.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17632/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-17632 - High (8.8)
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based security scanning.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17632/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T21:31:46
2 posts
🟠 CVE-2026-18485 - High (7.8)
There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver. This may allow a local, authenticated user to escalate privileges and execute arbitrary code. This vulnerability affects NI-PAL 26.3.1 and p...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18485/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18485 - High (7.8)
There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver. This may allow a local, authenticated user to escalate privileges and execute arbitrary code. This vulnerability affects NI-PAL 26.3.1 and p...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18485/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T21:31:46
2 posts
🟠 CVE-2026-18411 - High (8.1)
The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. An attacker within Bluetooth range can leverage this weakness to issue unauthorized commands to the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18411/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18411 - High (8.1)
The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. An attacker within Bluetooth range can leverage this weakness to issue unauthorized commands to the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18411/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T21:31:46
2 posts
1 repos
🟠 CVE-2026-17583 - High (8.4)
The affected
Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17583/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-17583 - High (8.4)
The affected
Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17583/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T21:31:46
1 posts
🟠 CVE-2026-69111 - High (7.5)
Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service components by sending a crafted HTTP GET request to the management server on port 9091. Attackers can exp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69111/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T21:31:39
1 posts
🟠 CVE-2026-8183 - High (7.7)
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote attacker to traverse directories on the system. An attacker could send a s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8183/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T21:31:39
1 posts
🟠 CVE-2026-8182 - High (8.8)
IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via 2 HTTP requests.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8182/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T21:31:39
1 posts
🟠 CVE-2026-9201 - High (8.8)
IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom component validation mechanism. When the optional hardening mode that restricts execution to truste...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9201/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T21:31:39
1 posts
🟠 CVE-2026-9196 - High (8.1)
IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLM‑generated components. The application executes model‑generated Python co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9196/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T21:29:56
2 posts
🟠 CVE-2026-71320 - High (8.1)
Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a template key through /__nuxt_island/ props into a dynamic component when `vue.runtimeCompiler: true` is enabled, causing temp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71320/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-71320 - High (8.1)
Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a template key through /__nuxt_island/ props into a dynamic component when `vue.runtimeCompiler: true` is enabled, causing temp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71320/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T21:27:39
4 posts
Nuxt DevTools <3.3.1 is affected by CVE-2026-71319 (CRITICAL). Unauthenticated Vite HMR WebSocket RPC lets attackers execute arbitrary code via updateOptions() & openInEditor(). Patch to 3.3.1 ASAP. https://radar.offseq.com/threat/cve-2026-71319-cwe-94-improper-control-of-generation-of-code-code-injection-in-nuxt-devtools-d2e93c140a0d8a9f #OffSeq #NuxtJS #CVE202671319 #infosec
##🔴 CVE-2026-71319 - Critical (9.6)
Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin. On affected versions the channel h...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71319/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Nuxt DevTools <3.3.1 is affected by CVE-2026-71319 (CRITICAL). Unauthenticated Vite HMR WebSocket RPC lets attackers execute arbitrary code via updateOptions() & openInEditor(). Patch to 3.3.1 ASAP. https://radar.offseq.com/threat/cve-2026-71319-cwe-94-improper-control-of-generation-of-code-code-injection-in-nuxt-devtools-d2e93c140a0d8a9f #OffSeq #NuxtJS #CVE202671319 #infosec
##🔴 CVE-2026-71319 - Critical (9.6)
Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin. On affected versions the channel h...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71319/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T21:14:34
2 posts
🟠 CVE-2026-71316 - High (7.5)
Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries for //_payload.json can be returned before route middleware and page guards because import.meta.prerender is not enforced, disc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71316/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-71316 - High (7.5)
Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries for //_payload.json can be returned before route middleware and page guards because import.meta.prerender is not enforced, disc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71316/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T20:59:08
1 posts
🟠 CVE-2026-71314 - High (7.5)
Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated attacker can use a server island v-for prop, including vforToArray and , to trigger unbounded SSR memory allocation until MAX_VFOR_...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71314/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T20:38:00
1 posts
🟠 CVE-2026-71312 - High (8)
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and quoteOrEscapeShellPath...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71312/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T20:17:17.770000
1 posts
🟠 CVE-2026-70617 - High (8.1)
Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group DM channels by sending a PUT request to the channels recipient endpoint without member...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70617/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T20:17:05.243000
1 posts
CVE-2026-15573 - High severity auth bypass in Red Hat Keycloak. URI normalization flaw lets authenticated users bypass policies to access restricted areas. CVSS 8.1. Unpatched - update when available. #CVE #Keycloak #infosec
##updated 2026-08-05T20:00:10.473000
1 posts
1 repos
pgAdmin 4 RCE Flaw Leads Three Critical Fixes in Version 9.17
##updated 2026-08-05T19:17:45.807000
1 posts
🟠 CVE-2026-9077 - High (8.5)
IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files on the host system.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9077/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T18:31:49
2 posts
🔴 CVE-2026-20310 - Critical (9.1)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address mu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20310/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-20310 - Critical (9.1)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address mu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20310/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T18:31:49
2 posts
🟠 CVE-2026-20313 - High (7.7)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address mu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20313/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-20313 - High (7.7)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address mu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20313/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T18:31:48
1 posts
Cisco SD-WAN vulnerability CVE-2026-20303 and CVE-2026-20304 reach CVSS 9.9. Cisco urges Catalyst SD-WAN customers to patch now.
#Cisco #SDWAN #CVE202620303 #CVE202620304 #CyberSecurity #NetworkSecurity
updated 2026-08-05T18:31:45
1 posts
Cisco IOS XE vulnerability CVE-2026-20272 hits CVSS 9.8 and CVE-2026-20267 scores 9.0. Cisco urges customers to patch now.
#Cisco #IOSXE #CVE202620272 #CVE202620267 #CyberSecurity #NetworkSecurity
##updated 2026-08-05T18:17:11.353000
1 posts
🔴 CVE-2026-45537 - Critical (9.1)
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the construct_uri() function concatenates multiple URI components (protocol, username, domain, port, params) into a fixed 1024-byte gl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45537/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T18:17:07.557000
2 posts
🟠 CVE-2026-20301 - High (8.6)
A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20301/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-20301 - High (8.6)
A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20301/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T17:16:45.797000
1 posts
🟠 CVE-2026-18898 - High (8.8)
A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the function strcpy of the file /goform/ConfigAdvideo. The manipulation of the argument timestart results in stack-based buffer overflow. The attack can be l...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18898/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T16:17:08.400000
1 posts
CVE-2026-71289 (CRITICAL, CVSS 9.8): NASA-AMMOS ANMS exposes amp-manager REST API w/ no auth. Remote attackers can control system & disrupt ops. Restrict access, avoid default configs, check vendor for patches. https://radar.offseq.com/threat/cve-2026-71289-cwe-306-in-nasa-ammos-anms-e9bcfd162464d056 #OffSeq #CVE #NASA #Infosec
##updated 2026-08-05T16:17:08.190000
1 posts
🟠 CVE-2026-71287 - High (8.8)
Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex `preg_replace('/[^a-zA-Z0-9_().]/', '', $column)`. Because this allowlist retains letters, digits, underscore, parentheses, and dot (in...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71287/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T16:17:07.967000
1 posts
🟠 CVE-2026-71285 - High (8.1)
Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo `siteId` value as a bare, unquoted JavaScript expression inside a block rendered on every public status page: `_paq.push(['set...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71285/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T16:17:00.200000
1 posts
🟠 CVE-2026-67861 - High (7.5)
An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67861/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T16:17:00.067000
1 posts
🟠 CVE-2026-67859 - High (7.5)
Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67859/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T15:44:27.057000
1 posts
🟠 CVE-2026-59913 - High (7.8)
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59913/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T15:33:26.557000
5 posts
6 repos
https://github.com/razureink/cve-2026-34486-tomcat_encrypt_bypass_reproduction
https://github.com/404-src/CVE-2026-34486
https://github.com/punitdarji/tomcat-cve-2026-34486
https://github.com/AirSkye/CVE-2026-34486-poc
CISA Reports Active Exploitation of Apache Tomcat RCE Vulnerability
CISA reports active exploitation of an Apache Tomcat vulnerability (CVE-2026-34486) to its KEV catalog after Chinese threat actors exploited a fail-open logic error in the EncryptInterceptor to achieve remote code execution.
**If you run Apache Tomcat with clustering enabled, upgrade ASAP to 9.0.117, 10.1.54, or 11.0.21 This flaw is being actively exploited and can give attackers full remote code execution on every node in the cluster. If you can't patch, make sure your cluster traffic ports are not reachable from the internet, check `server.xml` and `context.xml` to confirm EncryptInterceptor is active with no custom interceptors overriding it, and turn off plain HTTP in favour of HTTPS only.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/cisa-reports-active-exploitation-of-apache-tomcat-rce-vulnerability-t-a-b-r-8/gD2P6Ple2L
CISA Reports Active Exploitation of Apache Tomcat RCE Vulnerability
CISA reports active exploitation of an Apache Tomcat vulnerability (CVE-2026-34486) to its KEV catalog after Chinese threat actors exploited a fail-open logic error in the EncryptInterceptor to achieve remote code execution.
**If you run Apache Tomcat with clustering enabled, upgrade ASAP to 9.0.117, 10.1.54, or 11.0.21 This flaw is being actively exploited and can give attackers full remote code execution on every node in the cluster. If you can't patch, make sure your cluster traffic ports are not reachable from the internet, check `server.xml` and `context.xml` to confirm EncryptInterceptor is active with no custom interceptors overriding it, and turn off plain HTTP in favour of HTTPS only.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/cisa-reports-active-exploitation-of-apache-tomcat-rce-vulnerability-t-a-b-r-8/gD2P6Ple2L
🚨 CISA KEV ALERT: CVE-2026-34486 exposes Apache Tomcat installations to EncryptInterceptor bypasses and data interception. Active exploitation confirmed. Get the forensic breakdown, Splunk/KQL/Chronicle detection queries, and hardening steps: https://thecybermind.co/it1p
Top-of-the-Line LinkedIn Post
##🚨 [CISA-2026:0804] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-18556 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18556)
- Name: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: https://uptime.n-able.com/ ; https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-18556
⚠️ CVE-2026-34486 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-34486)
- Name: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Tomcat
- Notes: https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-34486
⚠️ CVE-2026-9198 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9198)
- Name: IBM Langflow Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: IBM
- Product: Langflow
- Notes: https://www.ibm.com/support/pages/node/7278927 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-9198
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260804 #cisa20260804 #cve_2026_18556 #cve_2026_34486 #cve_2026_9198 #cve202618556 #cve202634486 #cve20269198
##CVE ID: CVE-2026-34486
Vendor: Apache
Product: Tomcat
Date Added: 2026-08-04
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-34486
updated 2026-08-05T15:32:29
1 posts
🟠 CVE-2026-71294 - High (7.6)
Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controllers/actions/CreateAction.php, a `ci` POST parameter obtained via `cot_import('ci', 'P', 'TXT')` (tr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71294/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T15:32:14
1 posts
🟠 CVE-2026-67857 - High (7.5)
open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67857/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T15:17:19.770000
1 posts
Kadence Memberships (stellarwp) ≤4.0.0 suffers CRITICAL vuln (CVE-2026-9273, CVSS 9.3): attackers can hijack any account by poisoning password reset links. Restrict reset features & monitor for patches. https://radar.offseq.com/threat/cve-2026-9273-cwe-640-weak-password-recovery-mechanism-for-forgotten-password-in-stellarwp-membership-10c6cffc948a3c97 #OffSeq #WordPress #Vuln #Security
##updated 2026-08-05T15:17:13.783000
1 posts
MaxSite CMS 0.78 is vulnerable (CVE-2026-70554, CRITICAL): PHP object injection via maxsite_comuser cookie enables unauthenticated RCE. No patch available. Restrict access, deploy WAF, and monitor activity. https://radar.offseq.com/threat/cve-2026-70554-deserialization-of-untrusted-data-in-maxsite-maxsite-cms-e8db7f34d62a5e30 #OffSeq #Vuln #CMS #PHP #RCE
##updated 2026-08-05T15:17:10.497000
1 posts
🟠 CVE-2026-70486 - High (8.2)
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together with allow-scripts for HTML files served from...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70486/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T15:17:06.617000
1 posts
🟠 CVE-2026-67858 - High (7.5)
Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. An unauthenticated remote attacker can send a RegisterServer or RegisterServer2 requ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67858/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T15:16:45.587000
1 posts
🟠 CVE-2026-18895 - High (8.8)
A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulation of the argument cipher results in stack-based buffer overflow. It is possible to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18895/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T14:59:30.577000
1 posts
Apache NiFi vulnerabilities, including CVE-2026-68979, CVE-2026-62354, and CVE-2026-68981, expose users to code execution and resource consumption.
##updated 2026-08-05T14:59:03.460000
1 posts
Apache NiFi vulnerabilities, including CVE-2026-68979, CVE-2026-62354, and CVE-2026-68981, expose users to code execution and resource consumption.
##updated 2026-08-05T14:54:01.933000
1 posts
Adobe fixes a CVSS 10 RCE in Campaign Classic (CVE-2026-48449) and eight critical flaws in Bridge. Update to build 9398 and Bridge 15.1.7 or 16.0.6 now.
#AdobeCampaign #CVE202648449 #AdobeBridge #CriticalPatch #RCE
##updated 2026-08-05T14:17:14.103000
1 posts
CVE-2026-71214: NASA-AMMOS plandev sequencing-server has a CRITICAL vuln (CVSS 9.8) — unauthenticated users can inject commands by spoofing session roles or using whitelisted endpoints. Patch urgently. More: https://radar.offseq.com/threat/cve-2026-71214-cwe-306-missing-authentication-for-critical-function-in-nasa-ammos-plandev-sequencing-a69c1ea44211854b #OffSeq #Vuln #NASA #CyberSec #CVSS
##updated 2026-08-05T13:24:49.680000
1 posts
CVE-2026-71254: CRITICAL out-of-bounds write in debevv nanoMODBUS (≤v1.23.0). Unauthenticated FC 0x14 requests can cause memory corruption, leading to DoS or RCE — especially on embedded targets. Patch/mitigate now. https://radar.offseq.com/threat/cve-2026-71254-cwe-787-in-debevv-nanomodbus-649361bc8788d305 #OffSeq #CVE #ICS #infosec
##updated 2026-08-05T12:31:36
1 posts
Today, VulnCheck is disclosing #ENDLESSDOORS, a phone-home implant CTO @albinolobster discovered in Zbtlink routers. ENDLESSDOORS starts automatically, runs with root privileges, and attempts to connect to command-and-control infrastructure roughly every 35 seconds. The backdoor ships by default across 20+ Zbtlink router models, which are white-labeled and sold on popular retail sites including Amazon, AliExpress, and Alibaba.
The implant and server implement no encryption or verification, meaning anyone along the network path can hijack the client-server communication and obtain a root shell on the device, regardless of the router's network position.
The VulnCheck CNA has assigned CVE-2026-66747 to track backdoored firmware versions; our blog also has guidance for defenders, including affected firmware images, hashes, network indicators, a YARA rule, and network signatures (Suricata / Snort).
##updated 2026-08-05T09:31:26
1 posts
CVE-2026-4431: CRITICAL vuln in Easy Post Submission ≤2.3.0 for WordPress. Missing auth lets unauthenticated attackers modify or unpublish any post via AJAX. No patch yet — disable plugin if possible. https://radar.offseq.com/threat/cve-2026-4431-cwe-862-missing-authorization-in-themeruby-easy-post-submission-frontend-posting-guest-a356c334d549556e #OffSeq #WordPress #Vuln #CVE20264431
##updated 2026-08-05T05:17:15.823000
4 posts
4 repos
https://github.com/0xdak/CVE-2026-9198_exploit
https://github.com/rmhowe425/PoC-CVE-2026-9198
Actively Exploited IBM Langflow Vulnerability Allows Unauthenticated Remote Code Execution
IBM Langflow OSS injection vulnerability (CVE-2026-9198)is actively exploited. CISA has added the flaw to its Known Exploited Vulnerabilities catalog and requires immediate patching/
**If you run IBM Langflow OSS (versions 1.0.0 through 1.10.0), update to version 1.10.1 or later immediately. Attackers are already using this flaw to take over servers. If you can't update immediately, take the Langflow instance off the internet, and check your logs for unexpected superuser tokens or odd Python code being run.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/actively-exploited-ibm-langflow-vulnerability-allows-unauthenticated-remote-code-execution-1-k-n-g-e/gD2P6Ple2L
🚨 CISA KEV ALERT: CVE-2026-9198 identifies a critical unauthenticated code injection flaw in IBM Langflow allowing full RCE on default deployments. Active exploitation confirmed. Get the execution mechanics, CrowdStrike CQL detection, and compensating controls now: https://thecybermind.co/fi0v
##🚨 [CISA-2026:0804] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-18556 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18556)
- Name: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: https://uptime.n-able.com/ ; https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-18556
⚠️ CVE-2026-34486 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-34486)
- Name: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Tomcat
- Notes: https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-34486
⚠️ CVE-2026-9198 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9198)
- Name: IBM Langflow Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: IBM
- Product: Langflow
- Notes: https://www.ibm.com/support/pages/node/7278927 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-9198
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260804 #cisa20260804 #cve_2026_18556 #cve_2026_34486 #cve_2026_9198 #cve202618556 #cve202634486 #cve20269198
##CVE ID: CVE-2026-9198
Vendor: IBM
Product: Langflow
Date Added: 2026-08-04
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9198
updated 2026-08-05T05:17:14.873000
1 posts
CVE-2026-6837 - Post-auth command injection in Zyxel WAX650S export-cgi. Admin RCE. CVSS 7.2. Unpatched - restrict admin access now. #CVE #Zyxel #infosec
##updated 2026-08-05T05:17:07.877000
1 posts
🟠 CVE-2026-66318 - High (8.1)
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66318/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T05:17:02.413000
3 posts
Veeam Patches Critical Credential Theft and RCE Flaws in Service Provider Console
Veeam patched four vulnerabilities in its Service Provider Console, including critical flaws (CVE-2026-58073 and CVE-2026-58072) that allow unauthenticated credential theft and remote code execution.
**If you run Veeam Service Provider Console version 9.2.1.33875 or any earlier version 9 build, upgrade to version 9.3.0.35057 ASAP. These flaws let attackers take over the console that controls all of your customers' backups. Make sure to lock down the management portal so it's only reachable from a small list of trusted IP addresses, not the open internet.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/veeam-patches-critical-credential-theft-and-rce-flaws-in-service-provider-console-y-k-8-e-6/gD2P6Ple2L
Veeam Patches Critical Credential Theft and RCE Flaws in Service Provider Console
Veeam patched four vulnerabilities in its Service Provider Console, including critical flaws (CVE-2026-58073 and CVE-2026-58072) that allow unauthenticated credential theft and remote code execution.
**If you run Veeam Service Provider Console version 9.2.1.33875 or any earlier version 9 build, upgrade to version 9.3.0.35057 ASAP. These flaws let attackers take over the console that controls all of your customers' backups. Make sure to lock down the management portal so it's only reachable from a small list of trusted IP addresses, not the open internet.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/veeam-patches-critical-credential-theft-and-rce-flaws-in-service-provider-console-y-k-8-e-6/gD2P6Ple2L
A critical Veeam Service Provider Console flaw lets attackers steal agent credentials, while a second enables remote code execution. Update to 9.3 now.
#Veeam #VSPC #ServiceProviderConsole #CVE202658073 #RCE #RemoteCodeExecution #Vulnerability #MSP #CyberSecurity #InfoSec
https://securityonline.info/veeam-vspc-cve-2026-58073/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-08-05T05:17:01.967000
2 posts
Veeam Patches Critical Credential Theft and RCE Flaws in Service Provider Console
Veeam patched four vulnerabilities in its Service Provider Console, including critical flaws (CVE-2026-58073 and CVE-2026-58072) that allow unauthenticated credential theft and remote code execution.
**If you run Veeam Service Provider Console version 9.2.1.33875 or any earlier version 9 build, upgrade to version 9.3.0.35057 ASAP. These flaws let attackers take over the console that controls all of your customers' backups. Make sure to lock down the management portal so it's only reachable from a small list of trusted IP addresses, not the open internet.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/veeam-patches-critical-credential-theft-and-rce-flaws-in-service-provider-console-y-k-8-e-6/gD2P6Ple2L
Veeam Patches Critical Credential Theft and RCE Flaws in Service Provider Console
Veeam patched four vulnerabilities in its Service Provider Console, including critical flaws (CVE-2026-58073 and CVE-2026-58072) that allow unauthenticated credential theft and remote code execution.
**If you run Veeam Service Provider Console version 9.2.1.33875 or any earlier version 9 build, upgrade to version 9.3.0.35057 ASAP. These flaws let attackers take over the console that controls all of your customers' backups. Make sure to lock down the management portal so it's only reachable from a small list of trusted IP addresses, not the open internet.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/veeam-patches-critical-credential-theft-and-rce-flaws-in-service-provider-console-y-k-8-e-6/gD2P6Ple2L
updated 2026-08-05T05:16:46.480000
1 posts
A high-severity Django vulnerability, CVE-2026-15307, can enable remote code execution through spatial lookups. Update to Django 6.0.8 or 5.2.17 now.
#Django #DjangoSecurity #CVE202615307 #RCE #RemoteCodeExecution #Vulnerability #Python #WebSecurity #InfoSec #CyberSecurity
##updated 2026-08-05T03:30:28
1 posts
🟠 CVE-2026-18897 - High (8.8)
A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempEntry. The manipulation of the argument tempName leads to stack-based buffer overflow. T...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18897/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T00:30:46
1 posts
🟠 CVE-2026-70619 - High (8.8)
Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend configuration by invoking endpoint management routes that verify session authentication...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70619/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T21:30:37
2 posts
1 repos
CVE-2026-70553: CRITICAL RCE in MaxSite CMS 105.2 (CVSS 9.3). Attackers can inject PHP via POST to the install endpoint, gaining persistent code exec as www-data. Restrict endpoint & monitor traffic until patched. Details: https://radar.offseq.com/threat/cve-2026-70553-improper-control-of-generation-of-code-code-injection-in-maxsite-maxsite-cms-5161bdfb2e6804e9 #OffSeq #CVE #websecurity #RCE
##🔴 CVE-2026-70553 - Critical (9.8)
MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install endpoint after installation is...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70553/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T21:30:29
1 posts
🔴 CVE-2026-69703 - Critical (9.8)
Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that ignore redi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69703/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T21:30:28
1 posts
🔴 CVE-2026-49435 - Critical (9.8)
Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with administrative privileges.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49435/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T21:30:26
4 posts
1 repos
https://github.com/CreamyG31337/ncentral-compromise-ioc-triage
🚨 CISA KEV ALERT: CVE-2026-18556 exposes N-able N-central installations to authentication bypass via alternate channel paths. Active exploitation confirmed. Get the forensic breakdown, Splunk/KQL/Chronicle detection logic, and hardening guidance now: https://thecybermind.co/radr
##🚨 [CISA-2026:0804] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-18556 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18556)
- Name: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: https://uptime.n-able.com/ ; https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-18556
⚠️ CVE-2026-34486 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-34486)
- Name: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Tomcat
- Notes: https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-34486
⚠️ CVE-2026-9198 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9198)
- Name: IBM Langflow Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: IBM
- Product: Langflow
- Notes: https://www.ibm.com/support/pages/node/7278927 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-9198
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260804 #cisa20260804 #cve_2026_18556 #cve_2026_34486 #cve_2026_9198 #cve202618556 #cve202634486 #cve20269198
##CVE ID: CVE-2026-18556
Vendor: N-able
Product: N-central
Date Added: 2026-08-04
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18556
CISA added this vulnerability to the catalogue yesterday, if you missed it:
CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-18577
Arctic Wolf: CVE-2026-18556 / CVE-2026-18577: N-able N-central Authentication Bypass Vulnerabilities Require Immediate Patching https://arcticwolf.com/resources/blog/cve-2026-18556-cve-2026-18577/ #infosec #vulnerability #CISA
##updated 2026-08-04T20:43:06.967000
1 posts
Six SGLang vulnerabilities include unauthenticated RCE via CVE-2026-15969, plus data and model-weight theft. No patch exists yet.
#SGLang #RCE #LLMSecurity #CVE202615969 #InfoSec
https://securityonline.info/sglang-vulnerabilities/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-08-04T19:37:38
1 posts
FlowiseAI Flowise (<3.1.3) has a CRITICAL vuln (CVE-2026-70478): unauthenticated POST endpoint leaks refreshed OAuth tokens if credential ID is known. Upgrade to 3.1.3+ ASAP. https://radar.offseq.com/threat/cve-2026-70478-cwe-200-exposure-of-sensitive-information-to-an-unauthorized-actor-in-flowiseai-flowise-2c912baff770743c #OffSeq #CVE202670478 #OAuth #infosec
##updated 2026-08-04T19:29:28
1 posts
FlowiseAI Flowise <3.1.3 is affected by CRITICAL CVE-2026-70477 (code injection, CVSS 9.5). Exploitation via CSV Agent node allows arbitrary Python execution. Patch to 3.1.3+ ASAP. https://radar.offseq.com/threat/cve-2026-70477-cwe-94-improper-control-of-generation-of-code-code-injection-in-flowiseai-flowise-52ff32a90a84fd22 #OffSeq #Infosec #CVE #AppSec
##updated 2026-08-04T19:16:45.433000
1 posts
CVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation
Bulletin ID: 2026-073-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/04/2026 10:00 AM PDT
Description:
We have identified CVE-2026-18830 in the Amazon Bedrock AgentCore harness InvokeHarness API...
https://aws.amazon.com/security/security-bulletins/rss/2026-073-aws/
##updated 2026-08-04T18:31:37
1 posts
NVIDIA Dynamo Code Execution Flaw CVE-2026-24254 CVSS 9.8
##updated 2026-08-04T18:31:36
1 posts
1 repos
A critical Veeam ONE vulnerability, CVE-2026-64633, allows remote unauthenticated code execution at CVSS 10.0. Update to build 13.1.0.7034 now.
#Veeam #VeeamONE #CVE202664633 #RCE #RemoteCodeExecution #Vulnerability #CVSS10 #PatchNow #CyberSecurity #InfoSec
##updated 2026-08-04T18:31:31
1 posts
Stored XSS in Django's admin via an unvalidated URLField display path (CVE-2026-15920) https://syntetisk.tech/blog/posts/stored-xss-in-djangos-admin-via-an-unvalidated-urlfield-display-path-cve-2026-15920/
##updated 2026-08-04T18:31:31
1 posts
🟠 CVE-2026-24083 - High (7.8)
Memory Corruption while processing IOCTL device driver requests with invalid arguments.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-24083/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T18:31:31
1 posts
🟠 CVE-2026-25292 - High (7.6)
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-25292/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T18:31:31
1 posts
🟠 CVE-2026-69100 - High (8.8)
LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitel...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69100/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T18:31:31
1 posts
1 repos
🔴 CVE-2026-69098 - Critical (9.8)
kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. A...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69098/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T18:16:45.220000
1 posts
CVE-2026-15958 (CRITICAL): Easy Integration for Dropbox <2.2.0 suffers from missing authorization, letting unauthenticated users manage Dropbox files and access account emails. Patch or disable plugin. https://radar.offseq.com/threat/cve-2026-15958-cwe-862-missing-authorization-in-easy-integration-for-dropbox-50b9554583db42aa #OffSeq #WordPress #CVE #Security
##updated 2026-08-04T17:16:59.733000
1 posts
🔴 CVE-2026-69110 - Critical (9.1)
OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69110/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T17:16:55.413000
2 posts
Adobe Campaign Classic is impacted by CVE-2026-48323 (CRITICAL, CVSS 10). Improper neutralization in the template engine allows remote code execution — no user interaction needed. No patch yet. Monitor advisories: https://radar.offseq.com/threat/cve-2026-48323-improper-neutralization-of-special-elements-used-in-a-template-engine-cwe-1336-in-adobe-9070fce8af299a9b #OffSeq #Adobe #Vuln #CVE202648323
##🔴 CVE-2026-48323 - Critical (10)
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vul...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48323/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T17:16:52.453000
1 posts
🟠 CVE-2026-24084 - High (7.5)
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-24084/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T16:16:25.497000
1 posts
🔴 CVE-2026-48326 - Critical (9.9)
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged at...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48326/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T16:16:21.593000
1 posts
CVE-2026-18686: CRITICAL command injection in GL.iNet GL-MT3000 (4.4.0 – 4.4.5). Remote, unauthenticated code execution possible — no patch yet. Limit admin interface exposure & monitor for abuse. https://radar.offseq.com/threat/cve-2026-18686-command-injection-in-glinet-gl-mt3000-14534eb705079787 #OffSeq #CVE #RouterSecurity
##updated 2026-08-04T15:33:20
11 posts
2 repos
https://github.com/CreamyG31337/ncentral-compromise-ioc-triage
🚨 [CISA-2026:0804] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-18556 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18556)
- Name: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: https://uptime.n-able.com/ ; https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-18556
⚠️ CVE-2026-34486 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-34486)
- Name: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Tomcat
- Notes: https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-34486
⚠️ CVE-2026-9198 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9198)
- Name: IBM Langflow Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: IBM
- Product: Langflow
- Notes: https://www.ibm.com/support/pages/node/7278927 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-9198
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260804 #cisa20260804 #cve_2026_18556 #cve_2026_34486 #cve_2026_9198 #cve202618556 #cve202634486 #cve20269198
##New.
Rapid7: CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-18577-n-able-n-central-authentication-bypass-exploited-in-the-wild/ @Rapid7Official #infosec #vulnerabiity
##CISA added this vulnerability to the catalogue yesterday, if you missed it:
CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-18577
Arctic Wolf: CVE-2026-18556 / CVE-2026-18577: N-able N-central Authentication Bypass Vulnerabilities Require Immediate Patching https://arcticwolf.com/resources/blog/cve-2026-18556-cve-2026-18577/ #infosec #vulnerability #CISA
##Geopolitical: Trump indicates ongoing talks with Iran for Strait of Hormuz reopening (Aug 3-4), though Tehran denies. Gaza operations persist.
Technology: SK hynix & Sandisk unveil HBF standard for AI memory (Aug 4). White House schedules AI safety talks (Aug 4).
Cybersecurity: CISA alerts to active exploitation of N-able N-central flaw (CVE-2026-18577) (Aug 3). Interpol: AI fuels over 55% of African cybercrime (Aug 3).
#AnonNews_irc #Cybersecurity #News
URGENT C-SUITE BRIEF: Active exploitation verified on CISA KEV for CVE-2026-18577 (N-able N-central). Executive leadership must oversee immediate patch deployment, supply chain auditing, and trust model revalidation to safeguard organizational assets. Full strategic analysis: https://thecybermind.co/0156
##N-able warns of N-central auth bypass flaw exploited in attacks
N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-...
🔗️ [Bleepingcomputer] https://link.is.it/tS9UYV
##N-able warns of N-central auth bypass flaw exploited in attacks
N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-...
🔗️ [Bleepingcomputer] https://www.bleepingcomputer.com/news/security/n-able-warns-of-n-central-auth-bypass-flaw-exploited-in-attacks/
##ALERT: Active exploitation verified for CVE-2026-18577 in N-able N-central. Unauthenticated attackers can execute account takeovers via alternate path manipulation. Access our complete threat breakdown, SPL/KQL detection logic, and hardening guidance here: https://thecybermind.co/jily
##🚨 [CISA-2026:0803] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-18577 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18577)
- Name: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF1_Release_Notes.htm ; https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-18577
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260803 #cisa20260803 #cve_2026_18577 #cve202618577
##CVE ID: CVE-2026-18577
Vendor: N-able
Product: N-central
Date Added: 2026-08-03
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18577
CVE-2026-18577 is being exploited in the wild for N-central account takeover. An incomplete patch let attackers gain admin access. Update to 2026.3.1.7.
#Nable #Ncentral #CVE202618577 #AccountTakeover #RMM #CyberSecurity
##updated 2026-08-04T15:16:42.087000
1 posts
🔴 CVE-2026-69240 - Critical (9.8)
Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function defined in sql-string.js does not escape quotes if the value starts with TO_TIMESTAMP or TO_DATE. In the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69240/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T14:50:12.360000
1 posts
Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:
- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.
https://www.bouncycastle.org/resources/new-release-bouncy-castle-java-1-85/
##updated 2026-08-04T14:50:12.360000
1 posts
Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:
- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.
https://www.bouncycastle.org/resources/new-release-bouncy-castle-java-1-85/
##updated 2026-08-04T14:16:30.620000
1 posts
🔴 CVE-2026-15721 - Critical (9.8)
Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection.
This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15721/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T12:34:56
2 posts
🔴 CVE-2026-14175 - Critical (9.8)
Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server.
This issue affects HUMANIST Digital Human Resources: from...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14175/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-14175 (CRITICAL, CVSS 9.8): HUMANIST Digital HR v26.0 has an unrestricted file upload flaw — attackers can deploy web shells for full compromise. No patch yet. Restrict uploads, monitor, and apply network controls. https://radar.offseq.com/threat/cve-2026-14175-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-bilin-software-and-caf423644ef42f8e #OffSeq #Vuln #AppSec
##updated 2026-08-04T12:34:56
2 posts
🔴 CVE-2026-14804 - Critical (9.1)
Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable.
This issue affects HUMANIST Digital Human Resources: from ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14804/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-14804: CRITICAL (CVSS 9.1) in HUMANIST Digital HR v26.0 🛡️ Hard-coded cryptographic key (CWE-321) allows data exposure & integrity loss. No official fix — limit access & track vendor updates. https://radar.offseq.com/threat/cve-2026-14804-cwe-321-use-of-hard-coded-cryptographic-key-in-bilin-software-and-informatics-7feb29c78f0c5d49 #OffSeq #Vulnerability #CVE202614804
##updated 2026-08-04T09:31:41
1 posts
CVE-2026-18754: GeoVision GV-AS1620 (GV-Cloud) v1.16 has a CRITICAL bug — static RSA key in firmware lets attackers decrypt HTTPS & spoof server. No fix yet; restrict access & watch for vendor updates. https://radar.offseq.com/threat/cve-2026-18754-cwe-321-use-of-hard-coded-cryptographic-key-in-geovision-inc-gv-as1620-gv-cloud-c051119ceee7e889 #OffSeq #Vuln #Cybersecurity #TLS
##updated 2026-08-04T05:16:40.213000
1 posts
CVE-2026-9044 is a command injection flaw in TP-Link Archer AXE75 OpenVPN, CVSS 8.5. Update to firmware 1.5.6 Build 20260623 now.
#TPLink #CVE20269044 #CommandInjection #OpenVPN #RouterSecurity #CyberSecurity
##updated 2026-08-04T00:35:57
1 posts
Apache NiFi vulnerabilities, including CVE-2026-68979, CVE-2026-62354, and CVE-2026-68981, expose users to code execution and resource consumption.
##updated 2026-08-04T00:35:01
1 posts
CVE-2026-48333 (CRITICAL, CVSS 9.8): Incorrect Authorization in Adobe Campaign Classic enables attackers to escalate privileges without user interaction. No patch info yet — monitor vendor updates. https://radar.offseq.com/threat/cve-2026-48333-incorrect-authorization-cwe-863-in-adobe-adobe-campaign-classic-c17f18d3ff17c03b #OffSeq #Adobe #Security #CVE202648333
##updated 2026-08-04T00:35:01
1 posts
CVE-2026-18684 | CRITICAL command injection in GL.iNet GL-MT3000 (fw 4.4.0 – 4.4.5) 🛡️ Remote attackers can execute commands — no patch yet. Restrict access and watch for vendor updates. Info: https://radar.offseq.com/threat/cve-2026-18684-command-injection-in-glinet-gl-mt3000-4a4de87391e0f428 #OffSeq #CVE202618684 #IoTSecurity
##updated 2026-08-04T00:35:01
1 posts
Adobe patched critical Adobe Campaign Classic flaws. CVE-2026-48331 scores CVSS 10.0 and enables arbitrary code execution. Update to build 9399 now.
#Adobe #AdobeCampaignClassic #CVE202648331 #ArbitraryCodeExecution #Vulnerability #SSRF #SQLInjection #InfoSec #CyberSecurity
##updated 2026-08-04T00:35:01
1 posts
🟠 CVE-2026-66310 - High (7.7)
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66310/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T00:35:01
1 posts
CVE-2026-18685: CRITICAL command injection in GL.iNet GL-MT3000 (4.4.0 – 4.4.5). Remote, unauthenticated RCE possible. No patch yet — restrict access & monitor for abuse. Details: https://radar.offseq.com/threat/cve-2026-18685-command-injection-in-glinet-gl-mt3000-32060ee21fb81c76 #OffSeq #vuln #IoT #infosec
##updated 2026-08-04T00:35:01
1 posts
🔴 CVE-2026-48330 - Critical (10)
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could e...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48330/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T00:34:55
1 posts
🟠 CVE-2026-66315 - High (7.5)
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66315/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T21:31:36
1 posts
🟠 CVE-2026-59912 - High (7.8)
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59912/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T20:17:14.513000
1 posts
CVE-2026-18108 - Critical auth bypass in Perl Net::SAML2. Encrypted assertions without signatures accepted. CVSS 9.8. Upgrade to >=0.86 now. #CVE #Perl #infosec
##updated 2026-08-03T19:16:45.200000
1 posts
🔴 CVE-2026-18614 - Critical (9.8)
A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command injection...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18614/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T15:32:49
1 posts
CVE-2026-18574 is a Check Point authentication bypass rated CVSS 9.3, letting attackers run commands as admin. Patch via the latest Jumbo Hotfix.
#CheckPoint #CVE202618574 #AuthenticationBypass #SecurityManagement #CyberSecurity #Firewall
##updated 2026-08-03T12:32:43
1 posts
WAPT Server (CVE-2026-33591) : une faille permet de contourner l’authentification https://www.it-connect.fr/wapt-server-cve-2026-33591/ #ActuCybersécurité #Cybersécurité #Vulnérabilité
##updated 2026-08-03T09:33:40
1 posts
Simple Flatpak sandbox escape through pipewire:
1. Missing auth 2. Insecure default module loader
Vulns like these do not exist because devs lack the capability to look for them, but they lack the capacity.
I predict this class of issue will soon™️ cease to exist. LLM harnesses like the one used by Johann are getting productized at scale currently. The question is just how cheap can we make them and how quickly can we get them into CI pipelines.
https://embracethered.com/blog/posts/2026/pipewire-flatpak-linux-sandbox-escape-cve-2026-5674/
updated 2026-08-03T09:32:36
1 posts
1 repos
Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:
- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.
https://www.bouncycastle.org/resources/new-release-bouncy-castle-java-1-85/
##updated 2026-08-03T09:32:36
1 posts
Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:
- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.
https://www.bouncycastle.org/resources/new-release-bouncy-castle-java-1-85/
##updated 2026-08-03T09:32:36
1 posts
1 repos
Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:
- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.
https://www.bouncycastle.org/resources/new-release-bouncy-castle-java-1-85/
##updated 2026-08-03T09:32:36
1 posts
Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:
- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.
https://www.bouncycastle.org/resources/new-release-bouncy-castle-java-1-85/
##updated 2026-08-01T05:16:55.023000
4 posts
1 repos
Dark Web Ransomware Watch: Clop Claims Attack on Engineering Target Using CVE-2026-12569 to Steal Sensitive Data + Video
Introduction: A New Chapter in the Ransomware War Ransomware groups continue to evolve beyond simple file encryption, increasingly focusing on data theft, intellectual property harvesting, and exploitation of newly discovered vulnerabilities. A recent claim attributed to the notorious Clop ransomware operation suggests another targeted attack…
##Clop Ransomware Strikes Again: New Attack Exploits CVE-2026-12569 to Steal Database and Project Data + Video
A New Wave of Cyber Extortion Targets Critical Business Data The ransomware landscape continues to evolve as threat actors increasingly combine advanced exploitation techniques with aggressive data theft operations. A new incident linked to the Clop ransomware group highlights this growing danger, with reports indicating that attackers compromised a targeted…
##Clop Ransomware Exploits New Vulnerability to Target Enterprise Data, Raising Fresh Concerns Over Supply Chain Security + Video
A New Cybersecurity Threat Emerges Through CVE-2026-12569 The cybersecurity landscape continues to face a growing wave of sophisticated attacks as threat groups adapt their strategies around newly discovered vulnerabilities. The Clop ransomware operation has reportedly targeted an organization through CVE-2026-12569, claiming that it…
##Clop Ransomware Strikes Again: New Attack Exploits CVE-2026-12569 to Steal Sensitive Project and Software Data + Video
Introduction: A New Warning Sign in the Growing Ransomware War The ransomware landscape continues to evolve as cybercriminal groups become more aggressive, technically advanced, and focused on exploiting newly discovered vulnerabilities before organizations can fully defend their systems. A recent cybersecurity alert highlights another dangerous…
##updated 2026-07-31T18:32:25
1 posts
2 repos
CVE-2026-58048: cPanel Root SQL Execution Flaw Patched
##updated 2026-07-30T21:31:50
1 posts
IBM critical vulnerabilities hit App Connect, Power HMC, and webMethods. CVE-2026-12943 lets attackers execute arbitrary commands at CVSS 9.8.
##updated 2026-07-30T21:31:47
1 posts
Ok, the first one is absolutely it:
##Furthermore, we deploy MLG-UAF to conduct large-scale security auditing on mainstream open-source software such as libtiff, LibRaw, SQLite, ImageMagick and Zephyr RTOS. In real-world industrial source code scanning, our framework successfully discovered 17 unique confirmed UAF vulnerabilities assigned with independent Common Vulnerabilities and Exposures (CVE) IDs (CVE-2026 series, RESERVED and not yet publicized), covering cross-functional kernel UAF, intra-procedural cache UAF, race-condition UAF and multimedia parsing UAF scenarios.Real CVE case studies on CVE-2026-51291 (SQLite JSON cache flaw) and CVE-2023-32233 (Linux netfilter kernel vulnerability) demonstrate that MLG-UAF can precisely capture the fixed free-then-use spatial topological fingerprint of UAF defects and accurately resolve ambiguous multi-level pointer aliasing, even under heavy control-flow obfuscation.
updated 2026-07-30T20:04:51.110000
1 posts
Pre-Auth Stack Buffer Overflow Hits Xlight FTP Server (CVE-2026-67192)
https://securityonline.info/xlight-ftp-cve-2026-67192/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-07-30T19:07:59.843000
1 posts
New;
Broadcom has released advisories relating to several high and medium-severity vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Nvidia:
CRITICAL: NVIDIA Dynamo - July 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5842
NVIDIA Triton Inference Server - June 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5860 #Nvidia
Dell:
Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000450699/dsa-2026-060-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities #Dell #Apache
Google:
This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 #google #infosec #vulnerability
##updated 2026-07-30T18:23:34
3 posts
7 repos
https://github.com/paveg/rails-activestorage-vips-audit
https://github.com/Zer0SumGam3/CVE-2026-66066-POC
https://github.com/0xsha/KindaRails2Shell
https://github.com/0xBlackash/CVE-2026-66066
https://github.com/shinthink/CVE-2026-66066
🏆 New Achievement! Upload In Peace, Active Storage!
We are gathered here today to mourn Active Storage, the earnest, overly-trusting file-handling component of Ruby on Rails, taken from us by CVE-2026-66066, nicknamed "KindaRails2Shell." It lived as it worked: accepting everything without question, like a golden retriever at a buffet. (1/3)
##🏆 New Achievement! Upload In Peace, Active Storage!
We are gathered here today to mourn Active Storage, the earnest, overly-trusting file-handling component of Ruby on Rails, taken from us by CVE-2026-66066, nicknamed "KindaRails2Shell." It lived as it worked: accepting everything without question, like a golden retriever at a buffet. (1/3)
##A critical KindaRails2Shell Rails RCE flaw (CVE-2026-66066) in Active Storage exposes servers to secret theft and remote code execution via image uploads.
#RubyOnRails #KindaRails2Shell #CVE202666066 #Cybersecurity #WebSecurity
##updated 2026-07-30T15:31:54
1 posts
New;
Broadcom has released advisories relating to several high and medium-severity vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Nvidia:
CRITICAL: NVIDIA Dynamo - July 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5842
NVIDIA Triton Inference Server - June 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5860 #Nvidia
Dell:
Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000450699/dsa-2026-060-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities #Dell #Apache
Google:
This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 #google #infosec #vulnerability
##updated 2026-07-30T15:31:54
1 posts
New;
Broadcom has released advisories relating to several high and medium-severity vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Nvidia:
CRITICAL: NVIDIA Dynamo - July 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5842
NVIDIA Triton Inference Server - June 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5860 #Nvidia
Dell:
Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000450699/dsa-2026-060-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities #Dell #Apache
Google:
This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 #google #infosec #vulnerability
##updated 2026-07-30T15:31:51
1 posts
New;
Broadcom has released advisories relating to several high and medium-severity vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Nvidia:
CRITICAL: NVIDIA Dynamo - July 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5842
NVIDIA Triton Inference Server - June 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5860 #Nvidia
Dell:
Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000450699/dsa-2026-060-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities #Dell #Apache
Google:
This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 #google #infosec #vulnerability
##updated 2026-07-30T15:31:50
1 posts
New;
Broadcom has released advisories relating to several high and medium-severity vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Nvidia:
CRITICAL: NVIDIA Dynamo - July 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5842
NVIDIA Triton Inference Server - June 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5860 #Nvidia
Dell:
Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000450699/dsa-2026-060-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities #Dell #Apache
Google:
This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 #google #infosec #vulnerability
##updated 2026-07-30T14:08:23.057000
1 posts
Terraform MCP Server Flaw CVE-2026-16498 Scores CVSS 10.0
##updated 2026-07-29T21:31:00
1 posts
Broadcom has addressed several vulnerabilities published yesterday, all of them ranked high-severity https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Cisco has a new advisory for a critical vulnerability that was published yesterday:
CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
This addresses a vulnerability that was first published on July 29:
High: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh @TalosSecurity #Cisco #infosec #vulnerability
##updated 2026-07-29T21:30:47
1 posts
1 repos
A Linux kernel vulnerability, CVE-2026-53264, lets a local user run arbitrary code via a net/sched use-after-free. A public PoC is now available.
#CVE202653264 #LinuxKernel #UseAfterFree #PrivilegeEscalation #InfoSec
##updated 2026-07-28T14:54:01.770000
1 posts
100 repos
https://github.com/erlangparasu/mitigate_cve_2026_31431-sh
https://github.com/ben-slates/CVE-2026-31431-Exploit
https://github.com/M4xSec/CVE-2026-31431-RCE-Exploit
https://github.com/mym0us3r/COPY-FAIL-Detection-with-Wazuh-4.14.4
https://github.com/Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431
https://github.com/cyber-joker/copy-fail-python
https://github.com/Smarttfoxx/copyfail
https://github.com/bootsareme/copyfail-deconstructed
https://github.com/rootsecdev/cve_2026_31431
https://github.com/0xBlackash/CVE-2026-31431
https://github.com/Alfredooe/CVE-2026-31431
https://github.com/povzayd/CVE-2026-31431
https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC
https://github.com/bigwario/copy-fail-CVE-2026-31431-C
https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit
https://github.com/AdityaBhatt3010/CVE-2026-31431
https://github.com/lonelyor/CVE-2026-31431-exp
https://github.com/TheMalwareGuardian/CVE-2026-31431
https://github.com/MrAriaNet/cPanel-Fix
https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag
https://github.com/desultory/CVE-2026-31431
https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe
https://github.com/insomnisec/Detections-CVE-2026-31431
https://github.com/Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail
https://github.com/rvzsec/CVE-2026-31431
https://github.com/yxdm02/CVE-2026-31431
https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit
https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431
https://github.com/cozystack/copy-fail-blocker
https://github.com/ncmprbll/copy-fail-rs
https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail
https://github.com/jbnetwork-git/copy-fail-check
https://github.com/luotian2/CVE-2026-31431
https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE
https://github.com/ExploitEoom/CVE-2026-31431
https://github.com/sec17br/CVE-2026-31431-Copy-Fail
https://github.com/kvakirsanov/CVE-2026-31431-live-process-code-injection
https://github.com/painoob/Copy-Fail-Exploit-CVE-2026-31431
https://github.com/mrunalp/block-copyfail
https://github.com/g1nt0n1x/copy-fail-CVE-2026-31431-shell
https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431
https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs
https://github.com/Juguitos/copy-fail
https://github.com/samanzamani/copy-fail-checker
https://github.com/kinryulabs/rootpacket-cve-2026-31431
https://github.com/Dabbleam/CVE-2026-31431-mitigation
https://github.com/SeanRickerd/cve-2026-31431
https://github.com/ZephrFish/CopyFail-CVE-2026-31431
https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script
https://github.com/1neptune/CopyFail
https://github.com/diemoeve/copyfail-rs
https://github.com/ErdemOzgen/copy-fail-cve-2026-31431
https://github.com/Boos4721/copyfail-rs
https://github.com/malwarekid/CVE-2026-31431
https://github.com/haydenjames/CVE-2026-31431-check
https://github.com/guiimoraes/CVE-2026-31431
https://github.com/adysec/cve-2026-31431
https://github.com/wgnet/wg.copyfail.patch
https://github.com/AliHzSec/CVE-2026-31431
https://github.com/KaraZajac/DIRTYFAIL
https://github.com/professional-slacker/alg_check
https://github.com/sgkdev/page_inject
https://github.com/kadir/copy-fail-CVE-2026-31431-IOC
https://github.com/mahdi13830510/CVE-2026-31431-mitigation-suite
https://github.com/yandex-cloud-examples/yc-mk8s-copy-fail-mitigation
https://github.com/pascal-gujer/CVE-2026-31431
https://github.com/H1d3r/copy-fail_LPE_Interactive
https://github.com/JuanBindez/CVE-2026-31431
https://github.com/0xShe/CVE-2026-31431
https://github.com/qi4L/CVE-2026-31431-Container-Escape
https://github.com/philfry/cve-2026-31431-ftrace
https://github.com/abdullaabdullazade/CVE-2026-31431
https://github.com/wuwu001/CVE-2026-31431-exploit
https://github.com/atgreen/block-copyfail
https://github.com/Shotafry/CopyFail-Exploits-CVE-2026-31431
https://github.com/novysodope/copy-fail-CVE-2026-31431-C
https://github.com/Sl4cK0TH/CVE-2026-31431-PoC
https://github.com/4xura/CVE-2026-31431-Copy-Fail
https://github.com/sgkdev/ptrace_may_dream
https://github.com/yuspring/cve-2026-31431-poc
https://github.com/MartinPham/copy-fail-CVE-2026-31431-php
https://github.com/pedromizz/copy-fail
https://github.com/XsanFlip/CVE-2026-31431-Patch
https://github.com/JnamerZ/CopyFail-CVE-2026-31431
https://github.com/xeloxa/copyfail-exploit
https://github.com/Iamliuxiaozhen/copy_fail
https://github.com/st4rburn/public-passwd
https://github.com/scriptzteam/Paranoid-Copy-Fail-CVE-2026-31431
https://github.com/b5null/CVE-2026-31431-C
https://github.com/cs8425/copy-fail-go
https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized
https://github.com/sammwyy/copyfail-rs
https://github.com/aestechno/cve-2026-31431-ansible
https://github.com/Xerxes-2/CVE-2026-31431-rs
https://github.com/wesmar/CVE-2026-31431
https://github.com/badsectorlabs/copyfail-go
https://github.com/tgies/copy-fail-c
https://github.com/theori-io/copy-fail-CVE-2026-31431
https://github.com/Huchangzhi/autorootlinux
https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC
#OT #Advisory VDE-2026-072
Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI
The Linux kernel used in the IndustrialPI, 'linux-image-revpi-v8', prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.
#CVE CVE-2026-43284, CVE-2026-46300, CVE-2026-31431
https://certvde.com/en/advisories/vde-2026-072/
#CSAF https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2026/ppsa-2026-003.json
##updated 2026-07-28T08:17:14.187000
1 posts
Hardware Hacking: From zero to a Pre-Auth Stack Buffer Overflow on Amazon's best-selling router https://rotcee.github.io/posts/analyzing-the-mersusys-mb115-4g-router/#cve-2026-12495-finding-a-pre-auth-stack-buffer-overflow-in-the-mercusys-mb115-4g
##updated 2026-07-27T21:16:51.020000
2 posts
CVE-2026-39868: Public PoC Discloses a macOS and iOS Kernel Memory Corruption Flaw
##CVE-2026-39868: Public PoC Discloses a macOS and iOS Kernel Memory Corruption Flaw
##updated 2026-07-23T15:44:10.873000
1 posts
5 repos
https://github.com/webshellseo8/CVE-2026-50522-Proof-of-Concept
https://github.com/HORKimhab/CVE-2026-50522
https://github.com/darses/CVE-2026-50522
(CISA TS-SOC) CVE-2026-50522 – Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Severity: CRITICAL Impact Summary: An unauthorized attacker could exploit a deserialization vulnerability in Microsoft SharePoint to execute arbitrary code over a network....
##updated 2026-07-23T11:10:00.120000
1 posts
15 repos
https://github.com/AzDevops143/FRAGNESIA-Charan-cve-2026-46300
https://github.com/ExploitEoom/CVE-2026-46300
https://github.com/0xBlackash/CVE-2026-46300
https://github.com/MadExploits/CVE-2026-46300
https://github.com/azilRababe/CVE-2026-46300
https://github.com/Sentebale/CVE-2026-46300
https://github.com/1neptune/Fragnesia
https://github.com/BenedictEjepu/CVE-2026-46300-Fragnesia---TryHackMe-Lab-Project
https://github.com/BenedictEjepu/CVE-2026-46300-Fragnesia---TryHackMe-Lab-Walkthrough
https://github.com/cumakurt/linuxpi
https://github.com/nonameuserosint-hue/Fragnesia-go
https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag
https://github.com/HORKimhab/CVE-2026-46300
#OT #Advisory VDE-2026-072
Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI
The Linux kernel used in the IndustrialPI, 'linux-image-revpi-v8', prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.
#CVE CVE-2026-43284, CVE-2026-46300, CVE-2026-31431
https://certvde.com/en/advisories/vde-2026-072/
#CSAF https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2026/ppsa-2026-003.json
##updated 2026-07-22T16:17:42.747000
1 posts
1 repos
Details and proof-of-concept exploit code for CVE-2026-50343 are now public. The Windows privilege escalation flaw hands standard users SYSTEM privileges.
##updated 2026-07-16T05:16:18.470000
2 posts
3 repos
https://github.com/tc4dy/CVE-2026-15409-15410-Framework
https://github.com/HORKimhab/CVE-2026-15410
https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check
🚨 INC Ransomware chains SonicWall zero-days for ransomware
The group exploited CVE-2026-15409 and CVE-2026-15410 to steal data and deploy ransomware.
🔗 read more: cyberscoop.com/inc-r...
#ransomNews #cybersecurity
Prolific ransomware group behi...
CVE-2026-15410 - Changed to Known Ransomware Status
SonicWall SMA1000 Appliances Code Injection VulnerabilityVendor: SonicWallProduct: SMA1000 AppliancesSonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: https://nvd.nist.gov/vuln/detail/CVE-2026-15410
##updated 2026-07-16T05:16:18.293000
2 posts
6 repos
https://github.com/HORKimhab/CVE-2026-15409
https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check
https://github.com/Ch4120N/CVE-2026-15409
https://github.com/0xBlackash/CVE-2026-15409
🚨 INC Ransomware chains SonicWall zero-days for ransomware
The group exploited CVE-2026-15409 and CVE-2026-15410 to steal data and deploy ransomware.
🔗 read more: cyberscoop.com/inc-r...
#ransomNews #cybersecurity
Prolific ransomware group behi...
CVE-2026-15409 - Changed to Known Ransomware Status
SonicWall SMA1000 Appliances Server-Side Request Forgery VulnerabilityVendor: SonicWallProduct: SMA1000 AppliancesSonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.Status changed from Unknown to Known for ransomware campaign usage.Flip https://nvd.nist.gov/vuln/detail/CVE-2026-15409
##updated 2026-07-14T18:32:37
1 posts
12 repos
https://github.com/KrakenEU/CVE-2026-54121-CertiGhost
https://github.com/tc4dy/CVE-2026-54121-PoC-Exploit
https://github.com/AtlasVector/Certighost-CVE-2026-54121
https://github.com/ChPratik/CVE-2026-54121
https://github.com/marcgoam/CVE-2026-54121-CertiGhost
https://github.com/nafiez/Metasploit-CVE-2026-54121-Certighost
https://github.com/sam00/POC-CVE-2026-54121-Certighost
https://github.com/0xBlackash/CVE-2026-54121
https://github.com/aniqfakhrul/CVE-2026-54121
https://github.com/HORKimhab/CVE-2026-54121
https://github.com/mwnickerson/certighost-bof
https://github.com/GlendonNotGlen/certighost-cve-2026-54121-slides
A Microsoft acaba de corrigir a falha Certighost, que permitia a um utilizador com acessos básicos manipular o sistema de cadastro e obter um certificado válido em nome de um Controlador de Domínio, assumindo a gestão absoluta de uma rede Windows. A falha, classificada como de gravidade alta, foi corrigida com a CVE-2026-54121. 🛡️
##updated 2026-07-14T15:31:59
1 posts
44 repos
https://github.com/Aiyakami/rust_dirtyfrag
https://github.com/haydenjames/dirty-frag-check
https://github.com/RevyHub/CVE-2026-43284---DirtyFrag-Analysis-THM-
https://github.com/AK777177/Dirty-Frag-Analysis
https://github.com/lukeslp/redtail-ioc
https://github.com/0xlane/pagecache-guard
https://github.com/jayhutajulu1/CVE-2026-43284-DirtyFrag-PoC
https://github.com/millikanjohnl-blip/dirtyfrag-detection-rules
https://github.com/cumakurt/linuxpi
https://github.com/liamromanis101/DirtyFrag-Detector
https://github.com/krisiasty/vcheck
https://github.com/dixyes/dirtypatch
https://github.com/nonameuserosint-hue/DirtyFrag-go
https://github.com/DylanClaudio/Reporte-de-Escalada-de-Privilegios-Local-Dirty-Frag
https://github.com/aettern/copyfrag-fuse
https://github.com/LucasPDiniz/CVE-2026-43284
https://github.com/MadExploits/CVE-2026-46300
https://github.com/KaraZajac/DIRTYFAIL
https://github.com/XRSecCD/202605_dirty_frag
https://github.com/scriptzteam/Paranoid-Dirty-Frag-CVE-2026-43284
https://github.com/6abc/Copy-Fail-CVE-2026-31431-dirty-frag-CVE-2026-43284
https://github.com/metalx1993/dirtyfrag-patches
https://github.com/kuniyal08/Dirty-Frag-CVE-2026-43284
https://github.com/gagaltotal/CVE-2026-43284-CVE-2026-43500-scan
https://github.com/suominen/CVE-2026-43284
https://github.com/linnemanlabs/dirtyfrag-arm64
https://github.com/AtlasVector/Dirty-Frag-CVE-2026-43284
https://github.com/Percivalll/Dirty-Frag-Kubernetes-PoC
https://github.com/ChernStepanov/DirtyFrag-for-dummies
https://github.com/xd20111/CVE-2026-43284
https://github.com/ryan2929/CVE-2026-43284-
https://github.com/1neptune/DirtyFrag
https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag
https://github.com/grabesec/XCP_ng_CVE-2026-43284_tester
https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe
https://github.com/0xBlackash/CVE-2026-43284
https://github.com/nabhan-mohy/Dirty-Frag-Research-CVE-2026-43284-
https://github.com/g0thamRabb1t/CVE-2026-43284-dirtyfrag-detection
https://github.com/armircetaj/tetragon-dirtyfrag
https://github.com/t1ckprivate/CVE-2026-43284-Dirty-Frag
https://github.com/FrosterDL/CVE-2026-43284
https://github.com/mym0us3r/DIRTY-FRAG-Detection-with-Wazuh-4.14.4
#OT #Advisory VDE-2026-072
Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI
The Linux kernel used in the IndustrialPI, 'linux-image-revpi-v8', prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.
#CVE CVE-2026-43284, CVE-2026-46300, CVE-2026-31431
https://certvde.com/en/advisories/vde-2026-072/
#CSAF https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2026/ppsa-2026-003.json
##updated 2026-07-10T19:15:15.780000
2 posts
1 repos
RufRoot CVE-2026-59726: Unauthenticated RCE in Ruflo MCP Bridge Exposes AI Agent Keys
##🏆 New Achievement! RufRoot Has Entered The Arena!
PHASE ONE BEGINS. The challenger: CVE-2026-59726, alias RufRoot, a CVSS 10.0 critical flaw in the open-source AI agent platform Ruflo. Its special move — exploiting an exposed Model Context Protocol bridge to hand unauthenticated attackers full control of enterprise AI environments. No credentials required. No mercy shown. Noma Security surfaced this beast hiding in every Ruflo version before 3.16.3.
This is not a warm-up encounter. (1/2)
##updated 2026-06-24T18:32:31
1 posts
🐧 SIGINT // Ubuntu Watch — 2026-08-06
A recurring KVM shadow paging bug enabling guest-to-host escape is a nightmare for anyone running multi-tenant VMs at home. Note it ships bundled with CVE-2026-46113, so patch both together or you are still exposed.
🔗 https://tuxcare.com/blog/januscape-exposes-the-kvm-shadow-paging-bug-that-kept-coming-back/
##updated 2026-06-17T10:57:46.017000
1 posts
🚨 EUVD-2026-53853
📊 Score: n/a
📦 Product: Apache CXF, Apache CXF, Apache CXF
🏢 Vendor: Apache Software Foundation
📅 Updated: 2026-08-06
📝 An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment headers. Users are recommended to upgrade to versions 4.2.3 or 4...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53853
##updated 2026-06-17T10:46:59.450000
2 posts
1 repos
CVE-2026-41679 | Paperclip AI platform CRITICAL vuln: auth bypass let attackers register, obtain API tokens, & run code as server. DNS rebinding risk in dev mode. Patch now. https://radar.offseq.com/threat/critical-paperclip-flaw-allowed-admin-access-code-execution-09ee35c54d49b29b #OffSeq #CVE #Paperclip #vuln
##CVE-2026-41679 | Paperclip AI platform CRITICAL vuln: auth bypass let attackers register, obtain API tokens, & run code as server. DNS rebinding risk in dev mode. Patch now. https://radar.offseq.com/threat/critical-paperclip-flaw-allowed-admin-access-code-execution-09ee35c54d49b29b #OffSeq #CVE #Paperclip #vuln
##updated 2026-06-17T09:44:33.170000
2 posts
⚠️ CRITICAL: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones
A three-stage exploit chain (CVE-2025-21079, CVE-2025-58486, CVE-2025-58487) chaining Samsung Members, Samsung Account, and Bixby achieves RCE and system-level access on Galaxy phones. Samsung patched in November/December 2025, but unpatched devices and those missing any of the three apps remain ex…
🤖 AI generated summary
##⚠️ CRITICAL: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones
A three-stage exploit chain (CVE-2025-21079, CVE-2025-58486, CVE-2025-58487) chaining Samsung Members, Samsung Account, and Bixby achieves RCE and system-level access on Galaxy phones. Samsung patched in November/December 2025, but unpatched devices and those missing any of the three apps remain ex…
🤖 AI generated summary
##updated 2026-06-17T09:44:33.060000
4 posts
⚠️ CRITICAL: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones
A three-stage exploit chain (CVE-2025-21079, CVE-2025-58486, CVE-2025-58487) chaining Samsung Members, Samsung Account, and Bixby achieves RCE and system-level access on Galaxy phones. Samsung patched in November/December 2025, but unpatched devices and those missing any of the three apps remain ex…
🤖 AI generated summary
##CRITICAL exploit chain affects Samsung Galaxy S25, S24, Flip 7: chained flaws in Samsung Members (CVE-2025-21079), Samsung Account (CVE-2025-58486/58487), and Bixby allow full remote system access. Patch now. https://radar.offseq.com/threat/how-a-50000-exploit-chain-turned-bixby-against-samsung-phones-87a925ed8f0dd685 #OffSeq #Samsung #Infosec #Vuln
##⚠️ CRITICAL: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones
A three-stage exploit chain (CVE-2025-21079, CVE-2025-58486, CVE-2025-58487) chaining Samsung Members, Samsung Account, and Bixby achieves RCE and system-level access on Galaxy phones. Samsung patched in November/December 2025, but unpatched devices and those missing any of the three apps remain ex…
🤖 AI generated summary
##CRITICAL exploit chain affects Samsung Galaxy S25, S24, Flip 7: chained flaws in Samsung Members (CVE-2025-21079), Samsung Account (CVE-2025-58486/58487), and Bixby allow full remote system access. Patch now. https://radar.offseq.com/threat/how-a-50000-exploit-chain-turned-bixby-against-samsung-phones-87a925ed8f0dd685 #OffSeq #Samsung #Infosec #Vuln
##updated 2026-06-17T09:01:42.407000
1 posts
1 repos
CVE-2025-26399 - Changed to Known Ransomware Status
SolarWinds Web Help Desk Deserialization of Untrusted Data VulnerabilityVendor: SolarWindsProduct: Web Help DeskSolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 04, 2026 at 18:08:17 UTCDate https://nvd.nist.gov/vuln/detail/CVE-2025-26399
##updated 2026-06-17T08:42:34.123000
4 posts
⚠️ CRITICAL: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones
A three-stage exploit chain (CVE-2025-21079, CVE-2025-58486, CVE-2025-58487) chaining Samsung Members, Samsung Account, and Bixby achieves RCE and system-level access on Galaxy phones. Samsung patched in November/December 2025, but unpatched devices and those missing any of the three apps remain ex…
🤖 AI generated summary
##CRITICAL exploit chain affects Samsung Galaxy S25, S24, Flip 7: chained flaws in Samsung Members (CVE-2025-21079), Samsung Account (CVE-2025-58486/58487), and Bixby allow full remote system access. Patch now. https://radar.offseq.com/threat/how-a-50000-exploit-chain-turned-bixby-against-samsung-phones-87a925ed8f0dd685 #OffSeq #Samsung #Infosec #Vuln
##⚠️ CRITICAL: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones
A three-stage exploit chain (CVE-2025-21079, CVE-2025-58486, CVE-2025-58487) chaining Samsung Members, Samsung Account, and Bixby achieves RCE and system-level access on Galaxy phones. Samsung patched in November/December 2025, but unpatched devices and those missing any of the three apps remain ex…
🤖 AI generated summary
##CRITICAL exploit chain affects Samsung Galaxy S25, S24, Flip 7: chained flaws in Samsung Members (CVE-2025-21079), Samsung Account (CVE-2025-58486/58487), and Bixby allow full remote system access. Patch now. https://radar.offseq.com/threat/how-a-50000-exploit-chain-turned-bixby-against-samsung-phones-87a925ed8f0dd685 #OffSeq #Samsung #Infosec #Vuln
##updated 2026-06-17T05:58:22.273000
1 posts
7 repos
https://github.com/RogelioPumajulca/TEST-CVE-2023-32233
https://github.com/Destawell/gemini-2.5-pro-nf-tables-red-teamin
https://github.com/void0red/CVE-2023-32233
https://github.com/oferchen/POC-CVE-2023-32233
https://github.com/Destawell/gemini-2.5-pro-nf-tables-red-teaming
Ok, the first one is absolutely it:
##Furthermore, we deploy MLG-UAF to conduct large-scale security auditing on mainstream open-source software such as libtiff, LibRaw, SQLite, ImageMagick and Zephyr RTOS. In real-world industrial source code scanning, our framework successfully discovered 17 unique confirmed UAF vulnerabilities assigned with independent Common Vulnerabilities and Exposures (CVE) IDs (CVE-2026 series, RESERVED and not yet publicized), covering cross-functional kernel UAF, intra-procedural cache UAF, race-condition UAF and multimedia parsing UAF scenarios.Real CVE case studies on CVE-2026-51291 (SQLite JSON cache flaw) and CVE-2023-32233 (Linux netfilter kernel vulnerability) demonstrate that MLG-UAF can precisely capture the fixed free-then-use spatial topological fingerprint of UAF defects and accurately resolve ambiguous multi-level pointer aliasing, even under heavy control-flow obfuscation.
updated 2026-05-15T18:30:32
2 posts
1 repos
Falla in Outlook: apri un’e-mail e ti infettano, non servono più link o allegati
Il gruppo criminale filorusso TA488 sfrutta la CVE-2026-42897, falla XSS in Outlook Web Access, con un exploit half-click: basta aprire l'email per...
🔗️ [Cybersecurity360] https://link.is.it/ssYZlG
##Falla in Outlook: apri un’e-mail e ti infettano, non servono più link o allegati
Il gruppo criminale filorusso TA488 sfrutta la CVE-2026-42897, falla XSS in Outlook Web Access, con un exploit half-click: basta aprire l'email per...
🔗️ [Cybersecurity360] https://link.is.it/ssYZlG
##updated 2026-03-04T18:32:03
3 posts
1 repos
CRITICAL vulnerabilities patched in Cisco SD-WAN, IOS XE, FMC, and IMC. FMC flaw (CVE-2026-20079, CVSS 10.0) allows remote root access; IMC PoC public. No active exploitation. Patch now: https://radar.offseq.com/threat/cisco-patches-critical-sd-wan-ios-xe-fmc-vulnerabilities-d0d83f67659b4d15 #OffSeq #Cisco #Vulnerability #PatchTuesday
##CRITICAL vulnerabilities patched in Cisco SD-WAN, IOS XE, FMC, and IMC. FMC flaw (CVE-2026-20079, CVSS 10.0) allows remote root access; IMC PoC public. No active exploitation. Patch now: https://radar.offseq.com/threat/cisco-patches-critical-sd-wan-ios-xe-fmc-vulnerabilities-d0d83f67659b4d15 #OffSeq #Cisco #Vulnerability #PatchTuesday
##Broadcom has addressed several vulnerabilities published yesterday, all of them ranked high-severity https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Cisco has a new advisory for a critical vulnerability that was published yesterday:
CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
This addresses a vulnerability that was first published on July 29:
High: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh @TalosSecurity #Cisco #infosec #vulnerability
##updated 2025-04-11T04:12:49
2 posts
1 repos
⚠️ CRITICAL: Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks
CVE-2013-4786 in IPMI 2.0 allows unauthenticated attackers to harvest password hashes from Baseboard Management Controllers via UDP 623, then crack them offline. Over 24,000 internet-exposed BMCs are vulnerable, and many run weak or predictable default credentials. Compromised BMCs give attackers d…
🤖 AI generated summary
##LAVA found 36,872 exposed BMCs leaking IPMI password hashes via CVE-2013-4786. Some are already exploited in the wild. Here is how to lock them down.
#BMC #IPMI #CVE20134786 #DataCenter #Supermicro #CyberSecurity
##🏆 New Achievement! Open Source, Open Season!
The court finds Gitea guilty of harboring CVE-2026-59774. The charges: permitting unauthenticated attackers to submit specially crafted Org-mode markup to a public repository and read arbitrary files from the server — with sentencing escalating, in certain configurations, to full remote code execution as the Gitea operating system user. No login required. No accomplices named. (1/2)
##🏆 New Achievement! Open Source, Open Season!
The court finds Gitea guilty of harboring CVE-2026-59774. The charges: permitting unauthenticated attackers to submit specially crafted Org-mode markup to a public repository and read arbitrary files from the server — with sentencing escalating, in certain configurations, to full remote code execution as the Gitea operating system user. No login required. No accomplices named. (1/2)
##Gitea Vulnerability CVE-2026-59774 Enables Unauthenticated Remote Code Execution
##🟠 CVE-2026-15991 - High (8.8)
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-l...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15991/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-15991 - High (8.8)
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-l...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15991/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##PraisonAI <4.6.40 is affected by CVE-2026-48168 (CRITICAL, CVSS 10): Missing authorization lets attackers exploit GitHub Actions, execute arbitrary shell commands, and compromise repos. Patch to 4.6.40! https://radar.offseq.com/threat/cve-2026-48168-cwe-862-missing-authorization-in-mervinpraison-praisonai-b6d133d881efd541 #OffSeq #CVE202648168 #SecDevOps
##PraisonAI <4.6.40 is affected by CVE-2026-48168 (CRITICAL, CVSS 10): Missing authorization lets attackers exploit GitHub Actions, execute arbitrary shell commands, and compromise repos. Patch to 4.6.40! https://radar.offseq.com/threat/cve-2026-48168-cwe-862-missing-authorization-in-mervinpraison-praisonai-b6d133d881efd541 #OffSeq #CVE202648168 #SecDevOps
##🔴 CVE-2026-48168 - Critical (10)
PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection because it embeds an attacker-controlled pull request branch name into a Bash run: block without qu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48168/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18953 - High (8.6)
Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow a context-dependent actor to write arbitrary files outside the intended working directo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18953/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18953 - High (8.6)
Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow a context-dependent actor to write arbitrary files outside the intended working directo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18953/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-55524 - High (7.5)
PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the initially supplied URL, allowing the protection to be bypassed so the tool connects to attacker-chosen internal destinatio...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55524/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-55524 - High (7.5)
PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the initially supplied URL, allowing the protection to be bypassed so the tool connects to attacker-chosen internal destinatio...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55524/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-55522 - High (7.8)
PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerable to code execution. Workflow._execute_include() implicitly imports...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55522/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-55522 - High (7.8)
PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerable to code execution. Workflow._execute_include() implicitly imports...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55522/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-8446 - High (7.5)
IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_composer_enabled=true (default) and projects are configured with auth_type=oauth .
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8446/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##1 posts
2 repos
⚪️ OpenWrt Fixes Critical Vulnerability in DHCPv6 Server
🗨️ OpenWrt developers have released updates that fix a critical vulnerability in the DHCPv6 server. The flaw allowed an unauthenticated attacker to execute arbitrary code with root privileges and potentially fully compromise a vulnerable router. The issue, tracked as CVE-2026-53921 (CVSS…
##