## Updated at UTC 2026-09-18T05:14:06.871053

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-20341 9.1 0.00% 1 0 2026-09-18T04:17:47.180000 A vulnerability in the sftunnel inter-device communication protocol of Cisco Sec
CVE-2026-93456 8.2 0.00% 2 0 2026-09-18T02:17:09.113000 django-page-cms through 2.0.13 exempts five admin mutation views from CSRF prote
CVE-2026-85889 10.0 0.00% 2 0 2026-09-18T00:31:16 Missing authentication for critical function in Azure AI Foundry allows an unaut
CVE-2026-87886 7.8 0.00% 8 0 2026-09-18T00:31:15 Local privilege escalation due to insecure file permissions. The following produ
CVE-2026-93452 7.5 0.00% 2 0 2026-09-18T00:17:49.540000 snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.
CVE-2026-93450 7.5 0.00% 2 0 2026-09-18T00:17:49.230000 go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability
CVE-2026-54734 10.0 0.00% 2 0 2026-09-17T22:17:03.317000 Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certai
CVE-2026-70469 7.5 0.00% 1 0 2026-09-17T21:32:42 Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the appli
CVE-2026-84858 8.8 0.00% 1 0 2026-09-17T21:32:41 ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote
CVE-2026-79752 None 0.00% 2 0 2026-09-17T20:28:17 ### Impact The `FunctionsBuilder::cast($field, $dataType)`, `extract($part, $exp
CVE-2026-92956 10.0 0.00% 2 0 2026-09-17T20:18:59.730000 vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a def
CVE-2026-92935 9.0 0.00% 2 0 2026-09-17T20:18:59.093000 vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and <
CVE-2026-91989 7.5 1.26% 1 0 2026-09-17T20:18:54.893000 atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the
CVE-2026-54627 9.8 0.00% 2 0 2026-09-17T20:16:52.117000 SAIL is a cross-platform library for loading and saving images with support for
CVE-2026-87286 8.1 0.24% 1 0 2026-09-17T18:34:49 Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compil
CVE-2026-12793 9.8 0.39% 1 3 2026-09-17T18:16:36.517000 The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnera
CVE-2026-86863 9.8 0.00% 2 0 2026-09-17T17:16:51.633000 pgAdmin 4's Webserver authentication source is intended to accept an identity as
CVE-2026-92941 10.0 0.00% 2 0 2026-09-17T16:18:34.520000 vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sand
CVE-2026-86865 7.2 0.00% 1 0 2026-09-17T16:18:18.163000 Tanium addressed a SQL injection vulnerability in Asset.
CVE-2026-86320 7.8 0.00% 2 0 2026-09-17T16:18:17.403000 A flaw was found in flatpak-builder where Git hooks are not disabled when applyi
CVE-2026-92938 9.9 0.00% 2 0 2026-09-17T15:32:28 vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to c
CVE-2026-92939 9.9 0.00% 2 0 2026-09-17T15:32:28 vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM san
CVE-2026-92954 8.6 0.00% 2 0 2026-09-17T15:32:28 vm2 is a sandbox library for running untrusted JavaScript in Node.js. In version
CVE-2026-92940 10.0 0.00% 2 0 2026-09-17T15:32:27 vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAg
CVE-2026-92960 10.0 0.00% 2 0 2026-09-17T15:32:27 vm2 before 3.11.6 fails to restrict access to os and dns builtins under the buil
CVE-2026-92951 9.9 0.00% 2 0 2026-09-17T15:32:26 vm2 before 3.11.7 contains an incorrect authorization vulnerability in the exter
CVE-2026-92944 9.8 0.00% 2 0 2026-09-17T15:32:26 vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Nod
CVE-2026-92957 9.9 0.00% 2 0 2026-09-17T15:32:26 vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when e
CVE-2026-92918 8.8 0.00% 2 0 2026-09-17T15:32:24 admin3 through 3.0.0 persists user session tokens in the audit log event body wh
CVE-2026-92937 10.0 0.00% 2 0 2026-09-17T15:32:23 vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in
CVE-2026-92919 8.1 0.00% 2 0 2026-09-17T15:32:23 admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload h
CVE-2026-92946 10.0 0.00% 2 0 2026-09-17T15:32:22 vm2 before 3.11.7 contains a remote code execution vulnerability when require.ex
CVE-2026-92953 10.0 0.00% 2 0 2026-09-17T15:32:22 vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and Array
CVE-2026-92947 10.0 0.00% 2 0 2026-09-17T15:32:21 vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing
CVE-2026-81481 7.5 0.00% 2 0 2026-09-17T15:32:18 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Im
CVE-2026-92955 10.0 0.00% 2 0 2026-09-17T15:32:17 vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows
CVE-2026-92950 8.6 0.00% 2 0 2026-09-17T15:17:00.910000 vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that a
CVE-2026-92934 9.0 0.00% 2 0 2026-09-17T15:17:00.520000 vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that a
CVE-2026-92948 9.9 0.00% 2 0 2026-09-17T14:18:00.420000 vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist b
CVE-2026-92838 7.8 0.00% 2 0 2026-09-17T14:17:56.873000 A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop ap
CVE-2026-15688 0 0.00% 2 0 2026-09-17T13:16:42.530000 Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi
CVE-2026-76460 10.0 0.00% 30 1 2026-09-17T12:46:31.670000 A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an
CVE-2026-92913 7.4 0.00% 2 0 2026-09-17T12:18:30.290000 AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptograp
CVE-2026-91843 9.8 0.00% 6 1 2026-09-17T12:18:29.687000 A stack overflow during the unauthenticated login process may allow an attacker
CVE-2026-20307 9.9 0.00% 1 0 2026-09-17T12:17:25.977000 A vulnerability in the web-based management interface of Cisco ISE could allow a
CVE-2026-87796 9.8 0.00% 2 1 2026-09-17T06:30:45 The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbit
CVE-2026-73453 10.0 0.75% 1 0 2026-09-17T04:17:59.823000 An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors
CVE-2026-69486 8.8 0.66% 1 0 2026-09-17T04:17:55.620000 Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthor
CVE-2026-92578 8.1 0.00% 1 0 2026-09-17T00:31:30 WWBN AVideo through 29.0 contains an authentication bypass vulnerability where t
CVE-2026-92576 8.6 0.00% 1 0 2026-09-17T00:31:25 HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability
CVE-2026-20332 9.9 0.00% 2 0 2026-09-16T21:32:55 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-89082 None 0.00% 2 0 2026-09-16T21:32:55 HP has identified potential security vulnerabilities in the HP Advance software
CVE-2026-20324 9.9 0.00% 1 0 2026-09-16T21:32:50 A vulnerability in the sftunnel inter-device communication protocol of Cisco Sec
CVE-2026-20192 10.0 0.00% 2 0 2026-09-16T21:32:50 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20211 9.1 0.00% 1 0 2026-09-16T21:32:50 A vulnerability in Cisco ISE could allow an authenticated, remote attacker to ex
CVE-2026-20176 9.1 0.00% 1 0 2026-09-16T21:32:50 A vulnerability in Cisco ISE could allow an authenticated, remote attacker to ex
CVE-2026-87976 None 0.00% 1 0 2026-09-16T21:32:48 Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when
CVE-2026-87024 7.2 0.00% 1 0 2026-09-16T21:32:47 Tanium addressed a SQL injection vulnerability in Asset.
CVE-2026-88975 7.5 0.62% 1 0 2026-09-16T20:39:16.610000 Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, E
CVE-2026-77179 0 0.16% 2 1 2026-09-16T20:38:33.883000 On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows
CVE-2026-70416 10.0 0.00% 1 0 2026-09-16T20:37:16.870000 Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untru
CVE-2026-63696 9.1 0.32% 1 0 2026-09-16T20:37:16.870000 Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download
CVE-2026-92176 7.8 0.17% 1 0 2026-09-16T20:26:50.280000 pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulne
CVE-2026-92177 7.8 0.17% 1 0 2026-09-16T20:26:50.280000 pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Executio
CVE-2026-15638 0 0.20% 1 0 2026-09-16T20:17:20.950000 An unauthenticated user with access to Secret Server could leverage a padding or
CVE-2026-87289 7.5 0.46% 1 0 2026-09-16T19:42:12.090000 Vulnerability in the Helidon product of Oracle Fusion Middleware (component: hel
CVE-2026-80217 8.8 0.28% 1 0 2026-09-16T19:27:25.623000 Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allo
CVE-2026-76670 9.9 0.45% 1 0 2026-09-16T19:20:52.817000 Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConn
CVE-2026-27564 7.2 2.02% 3 0 2026-09-16T19:17:13.860000 A high-privileged remote attacker can exploit a command injection vulnerability
CVE-2026-27561 7.2 2.23% 3 0 2026-09-16T19:17:13.633000 A high-privileged remote attacker can exploit a command injection vulnerability
CVE-2026-40854 0 0.00% 1 0 2026-09-16T19:14:25.980000 WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability i
CVE-2026-87288 8.1 0.24% 1 0 2026-09-16T18:32:58 Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compil
CVE-2026-20331 9.6 0.00% 1 0 2026-09-16T18:32:09 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-92397 9.1 0.00% 1 0 2026-09-16T18:32:09 A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected
CVE-2026-89775 9.3 0.18% 1 0 2026-09-16T18:31:58 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64:
CVE-2026-87287 8.1 0.24% 1 0 2026-09-16T18:31:53 Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compil
CVE-2026-90999 0 0.00% 2 0 2026-09-16T17:18:18.923000 Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows
CVE-2026-61595 7.7 0.00% 1 0 2026-09-16T15:32:15 ### Impact `djust.tenants` isolation was enforced only on the HTTP path. The cur
CVE-2026-73172 None 0.00% 1 0 2026-09-16T15:31:13 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele
CVE-2026-58704 8.0 0.11% 23 0 2026-09-16T15:30:57 In Cellular Modem, there is a possible permission bypass due to a logic error in
CVE-2026-88065 7.5 0.37% 1 0 2026-09-16T14:17:12.413000 `tts-be` is a backend for a timetable selector that aims to help students better
CVE-2026-27565 9.8 0.94% 4 0 2026-09-16T09:30:35 An unauthenticated remote attacker can upload a malicious IODD file that places
CVE-2026-27563 7.2 2.02% 3 0 2026-09-16T09:30:35 A high-privileged remote attacker can exploit a command injection vulnerability
CVE-2026-27562 7.2 2.23% 3 0 2026-09-16T09:30:34 A high-privileged remote attacker can exploit a command injection vulnerability
CVE-2026-81642 None 0.52% 5 1 2026-09-16T09:30:28 In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in t
CVE-2026-14349 9.8 0.42% 1 0 2026-09-16T06:31:34 The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress i
CVE-2026-79994 None 0.11% 1 0 2026-09-16T00:32:32 The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a
CVE-2026-85893 8.8 0.68% 1 0 2026-09-16T00:31:42 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacke
CVE-2026-15640 None 0.28% 2 0 2026-09-16T00:31:41 Under certain conditions a valid SAML IdP response may be used to impersonate an
CVE-2026-92248 7.8 0.18% 1 0 2026-09-16T00:31:36 A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail pre
CVE-2026-73807 9.8 0.65% 2 0 2026-09-16T00:31:35 The mySCADA myPRO Manager command API does not properly enforce authentication f
CVE-2026-15639 None 0.39% 2 0 2026-09-16T00:31:33 An attacker can craft a malicious link that, if used by a legitimate user, may c
CVE-2026-91939 9.8 0.59% 1 0 2026-09-15T21:33:15 Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() witho
CVE-2026-92000 7.5 0.39% 1 0 2026-09-15T21:33:15 adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output li
CVE-2026-68070 8.8 0.27% 1 0 2026-09-15T21:33:13 The affected products are missing authentication for a critical function, which
CVE-2026-66890 9.6 0.20% 1 0 2026-09-15T21:33:13 The affected products use hard-coded credentials, which could allow remote acces
CVE-2026-89040 9.8 0.93% 1 0 2026-09-15T21:33:13 Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated a
CVE-2026-92179 7.8 0.17% 1 0 2026-09-15T21:31:29 pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Executio
CVE-2026-92178 7.8 0.17% 1 0 2026-09-15T21:31:28 pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution
CVE-2026-92180 7.8 0.14% 1 0 2026-09-15T21:31:25 pdfforge PDF Architect activation-service Update Service Uncontrolled Search Pat
CVE-2026-69213 7.5 0.36% 1 0 2026-09-15T20:00:36 Ember's HTTP/2 connection serializes all outgoing frames through a single unboun
CVE-2026-20274 9.8 0.73% 1 0 2026-09-15T18:33:13 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-89026 9.8 0.52% 3 1 2026-09-15T18:32:43 The Issabel Framework, the web framework supporting Issabel PBX software, before
CVE-2026-91985 7.5 0.38% 1 0 2026-09-15T18:32:43 Vikunja before 2.6.0 fails to properly restrict access to the link-share hash fi
CVE-2026-91990 7.5 0.41% 1 0 2026-09-15T18:32:43 Tornado before 6.5.8 contains a memory amplification vulnerability in parse_mult
CVE-2026-20276 8.6 0.27% 1 0 2026-09-15T18:32:13 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-63443 8.3 0.42% 1 0 2026-09-15T18:17:29.010000 Coder allows organizations to provision remote development environments via Terr
CVE-2026-20275 8.8 0.19% 1 0 2026-09-15T18:17:18.413000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-63695 9.8 0.53% 1 0 2026-09-15T15:32:20 Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session F
CVE-2026-89025 7.5 0.42% 1 0 2026-09-15T15:32:20 Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerabilit
CVE-2026-39919 9.8 0.49% 1 0 2026-09-15T15:17:14.723000 Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability i
CVE-2026-81915 0 0.37% 1 0 2026-09-15T14:40:24.370000 Concrete CMS below 9.5.3 does not perform an object-level authorization check wh
CVE-2026-89308 0 2.97% 1 0 2026-09-15T13:16:45.543000 An unauthenticated OS command injection vulnerability exists in the ping.php end
CVE-2026-76461 9.8 2.01% 12 4 2026-09-15T12:47:32.497000 A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure
CVE-2026-91995 9.1 0.61% 1 0 2026-09-15T12:31:54 pig before 4.1.0 contains an authentication bypass vulnerability in the /registe
CVE-2026-77853 8.8 1.03% 1 0 2026-09-15T09:30:39 Improper neutralization of special elements used in an OS command ('OS Command I
CVE-2026-91001 9.9 0.48% 1 0 2026-09-15T06:30:39 A security flaw has been discovered in D-Link DI-8400 16.07. This affects the fu
CVE-2026-12944 9.6 0.25% 1 2 2026-09-15T00:31:21 IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary P
CVE-2026-65352 4.3 0.25% 1 0 2026-09-15T00:31:13 An information disclosure issue was addressed with improved state management. Th
CVE-2026-82232 9.8 0.56% 1 0 2026-09-14T21:32:45 Improper neutralization of special elements used in an SQL command ('SQL injecti
CVE-2026-78159 9.8 0.76% 1 0 2026-09-14T17:17:51.410000 The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execut
CVE-2026-81005 None 0.18% 3 0 2026-09-14T15:33:28 In the Linux kernel, the following vulnerability has been resolved: ipmi: si: F
CVE-2026-81000 7.8 0.16% 1 0 2026-09-14T15:33:28 In the Linux kernel, the following vulnerability has been resolved: net: tun: b
CVE-2026-80967 8.4 0.18% 1 0 2026-09-14T15:33:27 In the Linux kernel, the following vulnerability has been resolved: ALSA: pcxhr
CVE-2026-80952 7.8 0.12% 1 0 2026-09-14T15:33:27 In the Linux kernel, the following vulnerability has been resolved: i3c: master
CVE-2026-89483 7.5 0.56% 1 0 2026-09-14T15:32:26 In the Linux kernel, the following vulnerability has been resolved: nvme: zero
CVE-2026-80982 7.8 0.16% 1 0 2026-09-14T15:32:22 In the Linux kernel, the following vulnerability has been resolved: net/smc: fi
CVE-2026-80938 None 0.17% 1 0 2026-09-14T15:32:20 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76:
CVE-2026-85706 10.0 11.96% 5 13 2026-09-14T14:22:15.323000 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7
CVE-2026-89491 0 0.21% 1 0 2026-09-14T13:19:06.090000 In the Linux kernel, the following vulnerability has been resolved: ocfs2: clus
CVE-2026-89474 0 0.17% 1 0 2026-09-14T13:19:03.733000 In the Linux kernel, the following vulnerability has been resolved: power: supp
CVE-2026-89442 7.8 0.16% 1 0 2026-09-14T13:19:01.410000 In the Linux kernel, the following vulnerability has been resolved: platform/x8
CVE-2026-80983 0 0.17% 1 0 2026-09-14T13:18:53.090000 In the Linux kernel, the following vulnerability has been resolved: net/smc: fi
CVE-2026-80939 0 0.17% 1 0 2026-09-14T13:18:50.037000 In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89
CVE-2026-90894 7.8 0.15% 2 0 2026-09-14T12:31:44 Parallels Desktop runs prl_disp_service as root. Local clients reach it on the w
CVE-2026-12518 None 0.11% 1 0 2026-09-14T09:31:09 A local privilege escalation vulnerability in the Logitech Logi Options+ updater
CVE-2026-80955 7.8 0.16% 1 0 2026-09-13T07:17:02.700000 In the Linux kernel, the following vulnerability has been resolved: dm-pcache:
CVE-2026-78006 9.8 0.78% 1 2 2026-09-12T09:33:41 The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execut
CVE-2026-89529 None 0.19% 1 0 2026-09-11T21:31:37 In the Linux kernel, the following vulnerability has been resolved: svcrdma: Re
CVE-2026-89514 None 0.17% 1 0 2026-09-11T21:31:37 In the Linux kernel, the following vulnerability has been resolved: scsi: fnic:
CVE-2026-84869 9.9 0.69% 2 0 2026-09-11T21:31:17 A condition in the ScreenConnect client may allow files to be transferred and ex
CVE-2026-42016 8.1 0.89% 1 0 2026-09-11T21:31:06 JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a pri
CVE-2026-59971 10.0 0.39% 1 0 2026-09-11T20:36:20 ## Summary In SSE/HTTP transport mode, `mysql_mcp_server` constructs `SseServer
CVE-2026-81861 None 0.38% 1 1 2026-09-11T18:31:25 CWE-522: Insufficiently Protected Credentials vulnerability that could result in
CVE-2026-82079 8.4 0.16% 1 0 2026-09-11T03:31:25 A stack-based buffer overflow vulnerability in the Nintendo Switch local wireles
CVE-2026-59160 8.8 0.41% 1 0 2026-09-09T23:47:56 ## Unauthenticated Network-Exposed Turborepo Task Execution via /api/run ### Su
CVE-2026-20079 10.0 75.75% 1 3 2026-09-09T21:31:33 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2026-15534 5.7 0.17% 1 0 2026-09-08T22:17:38.113000 Perl versions through 5.45.1 have out-of-bounds heap reads and writes during reg
CVE-2026-75650 10.0 2.15% 1 5 2026-09-08T21:33:09 Adobe Commerce is affected by an Improper Neutralization of Special Elements Use
CVE-2026-31431 7.8 99.91% 1 100 2026-09-08T09:36:36 In the Linux kernel, the following vulnerability has been resolved: crypto: alg
CVE-2026-58113 6.1 0.22% 1 0 2026-09-08T09:35:45 A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.00
CVE-2026-15315 8.8 0.30% 4 1 2026-09-04T18:32:18 Tapo C200 v5 contains an improper authentication vulnerability within the login
CVE-2026-15316 6.5 0.23% 4 1 2026-09-04T18:31:13 An improper input validation vulnerability in the configuration service for proc
CVE-2026-81573 8.6 0.46% 1 0 2026-09-01T20:56:59.203000 If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configu
CVE-2026-56211 7.1 0.48% 1 0 2026-09-01T13:19:51.053000 A remote code execution vulnerability was found in libaom, the reference AV1 cod
CVE-2026-39113 4.0 0.21% 1 1 2026-08-31T18:31:16 Buffer Overflow vulnerability in SQLite affected version source snapshots/builds
CVE-2026-56210 7.1 0.31% 1 0 2026-08-31T15:35:36 A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1
CVE-2026-56208 7.6 0.42% 1 0 2026-08-31T15:34:31 A heap buffer overflow vulnerability was found in libaom, the reference AV1 code
CVE-2026-56209 7.1 0.35% 1 0 2026-08-31T15:34:31 An arbitrary address write vulnerability was found in libaom, the reference AV1
CVE-2026-81572 7.8 0.17% 1 0 2026-08-27T12:30:27 cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-S
CVE-2026-81576 7.7 0.33% 1 0 2026-08-27T12:30:27 If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issu
CVE-2026-81574 8.2 0.41% 1 0 2026-08-27T12:30:27 In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitiz
CVE-2026-81575 7.5 0.44% 1 0 2026-08-27T12:30:26 If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 acce
CVE-2026-60004 9.8 86.78% 2 10 2026-08-27T11:41:19.230000 Gitea before 1.27.1 allows remote code execution via the diffpatch API through G
CVE-2026-56389 8.6 0.16% 2 0 2026-08-24T18:32:30 GNU Bison allows for an execution of an arbitrary program during HTML report gen
CVE-2026-59310 9.8 45.88% 2 2 2026-08-19T04:17:24.940000 VMware vCenter contains a directory traversal vulnerability in the Syslog server
CVE-2026-19487 5.3 0.42% 1 0 2026-08-13T21:37:11 Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression matc
CVE-2026-5430 10.0 0.32% 4 1 2026-08-06T09:30:40 The JWT authentication mechanism accepts tokens signed with algorithms other tha
CVE-2026-15830 5.3 1.26% 1 0 2026-08-04T18:31:31 An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDja
CVE-2026-13584 None 0.13% 2 0 2026-08-04T06:32:37 Improper Enforcement of Message Integrity During Transmission in a Communication
CVE-2026-45659 8.8 76.08% 1 2 2026-07-01T21:35:53 Deserialization of untrusted data in Microsoft Office SharePoint allows an autho
CVE-2026-47203 None 0.45% 1 0 2026-06-26T21:32:44 ### Impact **CVSSv4 Baseline Score:** Moderate 6.3 **CVSSv4 Weighted Score:**
CVE-2026-45051 None 0.51% 1 0 2026-06-24T17:25:29 ## Summary **Description** A deserialization of untrusted data vulnerability (
CVE-2026-8024 9.8 0.55% 2 0 2026-06-18T15:32:09 A remote, unauthenticated attacker may exploit a deserialization of untrusted da
CVE-2026-39987 9.8 98.95% 1 25 template 2026-06-17T10:42:51.460000 marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE
CVE-2025-48595 8.4 1.71% 1 3 2026-06-02T21:30:39 In multiple locations, there is a possible way to achieve code execution due to
CVE-2026-32746 9.8 23.67% 7 8 2026-03-23T15:31:40 telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMO
CVE-2026-27540 9.0 2.32% 2 2 2026-03-19T06:30:33 Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co P
CVE-2023-38198 9.8 1.08% 1 0 2024-10-30T21:30:36 acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as e
CVE-2024-20260 8.6 0.62% 1 0 2024-10-23T18:33:16 A vulnerability in the VPN and management web servers of the Cisco Adaptive Secu
CVE-2026-54520 0 0.00% 2 1 N/A
CVE-2026-54670 0 0.00% 2 0 N/A
CVE-2026-54767 0 0.00% 2 0 N/A
CVE-2026-54671 0 0.00% 2 0 N/A
CVE-2026-93426 0 0.00% 2 0 N/A
CVE-2026-54752 0 0.00% 2 0 N/A
CVE-2026-54716 0 0.00% 2 0 N/A
CVE-2026-54692 0 0.00% 2 0 N/A
CVE-2026-92943 0 0.00% 2 0 N/A
CVE-2026-93337 0 0.00% 2 0 N/A
CVE-2026-85500 0 0.00% 2 0 N/A
CVE-2026-59347 0 0.00% 2 0 N/A
CVE-2026-59346 0 0.00% 2 1 N/A
CVE-2026-78428 0 0.00% 2 0 N/A
CVE-2026-90711 0 0.19% 1 0 N/A
CVE-2026-61642 0 0.00% 1 0 N/A
CVE-2026-85498 0 0.00% 1 0 N/A
CVE-2026-57586 0 0.15% 1 0 N/A

CVE-2026-20341
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-18T04:17:47.180000

1 posts

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software could allow an authenticated, remote attacker to obtain&nbsp;root privileges. This vulnerability is due to unsecured deserialization of untrusted data over the sftunnel management connection. An attacker could exploit this vulnerability by sending crafted sftunnel remote procedure calls (RPCs). A su

offseq@infosec.exchange at 2026-09-17T03:00:25.000Z ##

CVE-2026-20341: CRITICAL flaw in Cisco Secure FMC Software sftunnel protocol. Admin remote attackers can gain root via insecure deserialization. Limit admin access, monitor for abuse, and check for patch updates. radar.offseq.com/threat/a-vuln #OffSeq #Cisco #Infosec #Vulnerability

##

CVE-2026-93456
(8.2 HIGH)

EPSS: 0.00%

updated 2026-09-18T02:17:09.113000

2 posts

django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify page content. Signed-in editors visiting a malicious page can be tricked into storing unescaped content that renders to all visitors, enabling stored cross-site scripting attacks.

thehackerwire@mastodon.social at 2026-09-18T03:03:10.000Z ##

🟠 CVE-2026-93456 - High (8.2)

django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify page content. Signed-in editors visiting a malicious page can be tricked into storing u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T03:03:10.000Z ##

🟠 CVE-2026-93456 - High (8.2)

django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify page content. Signed-in editors visiting a malicious page can be tricked into storing u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85889
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-18T00:31:16

2 posts

Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

offseq at 2026-09-18T00:00:34.707Z ##

CVE-2026-85889 | CRITICAL flaw in Azure AI Foundry: missing authentication for a critical function (CVSS 10) allows remote privilege escalation. Microsoft patched this cloud vulnerability — verify your environment per MSRC: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-18T00:00:34.000Z ##

CVE-2026-85889 | CRITICAL flaw in Azure AI Foundry: missing authentication for a critical function (CVSS 10) allows remote privilege escalation. Microsoft patched this cloud vulnerability — verify your environment per MSRC: radar.offseq.com/threat/cve-20 #OffSeq #Azure #Infosec #CVE202685889

##

CVE-2026-87886
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-18T00:31:15

8 posts

Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.

Matchbook3469@mastodon.social at 2026-09-18T00:48:28.000Z ##

🟠 New security advisory:

CVE-2026-87886 affects multiple systems.

• Impact: Significant security breach potential
• Risk: Unauthorized access or data exposure
• Mitigation: Apply patches within 24-48 hours

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#CVE #ZeroDay #ThreatIntel

##

netsecio@mastodon.social at 2026-09-17T15:31:25.000Z ##

📰 CISA Adds Actively Exploited Cisco and Acronis Flaws to KEV Catalog

CISA adds two actively exploited vulnerabilities to its KEV catalog: a critical Cisco ISE auth bypass (CVE-2026-76460) and an Acronis Backup flaw (CVE-2026-87886). Federal agencies must patch urgently. #CISA #KEV #PatchNow

🔗 cyber.netsecops.io/articles/ci

##

thecybermind at 2026-09-17T10:11:07.444Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-87886 – Acronis Backup Incorrect Default Permissions Vulnerability

A strategic executive briefing detailing permission hardening, risk deliberation, and incident response frameworks for CVE-2026-87886 in Acronis Backup environments....

thecybermind.co/enr6

##

beyondmachines1 at 2026-09-17T10:01:14.037Z ##

Acronis Patches Actively Exploited Privilege Escalation Flaw in Hosting Plugins

Acronis patched a high-severity privilege escalation vulnerability (CVE-2026-87886) in its cPanel and Plesk backup plugins that attackers are actively exploiting in the wild. The flaw allows local users to gain root access by taking advantage of insecure file permissions.

**Check your Linux hosting servers for the Acronis backup plugin and update it to the latest version right now. Attackers are already using this flaw to gain root access, so do not wait for your next scheduled maintenance window.**

beyondmachines.net/event_detai

##

thecybermind@infosec.exchange at 2026-09-17T10:11:07.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-87886 – Acronis Backup Incorrect Default Permissions Vulnerability

A strategic executive briefing detailing permission hardening, risk deliberation, and incident response frameworks for CVE-2026-87886 in Acronis Backup environments....

thecybermind.co/enr6

##

beyondmachines1@infosec.exchange at 2026-09-17T10:01:14.000Z ##

Acronis Patches Actively Exploited Privilege Escalation Flaw in Hosting Plugins

Acronis patched a high-severity privilege escalation vulnerability (CVE-2026-87886) in its cPanel and Plesk backup plugins that attackers are actively exploiting in the wild. The flaw allows local users to gain root access by taking advantage of insecure file permissions.

**Check your Linux hosting servers for the Acronis backup plugin and update it to the latest version right now. Attackers are already using this flaw to gain root access, so do not wait for your next scheduled maintenance window.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

cisakevtracker@mastodon.social at 2026-09-16T20:00:47.000Z ##

CVE ID: CVE-2026-87886
Vendor: Acronis
Product: Backup
Date Added: 2026-09-16
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cyberworldops@infosec.exchange at 2026-09-16T01:00:01.000Z ##

Acronis confirmed active exploitation of CVE-2026-87886, a CVSS 7.8 local privilege escalation in its backup plugin for cPanel and WHM and Plesk. Any local user on shared hosting could escalate to root and compromise all tenants, making immediate patching and audit critical. #LinuxSecurity #PrivilegeEscalation #CpanelSecurity

cyberworldops.eu/en/acronis-wa

##

CVE-2026-93452
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-18T00:17:49.540000

2 posts

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination buffer's remaining capacity, corrupting off-heap memory and causing JVM termination.

thehackerwire@mastodon.social at 2026-09-18T03:03:29.000Z ##

🟠 CVE-2026-93452 - High (7.5)

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination buffer's rem...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T03:03:29.000Z ##

🟠 CVE-2026-93452 - High (7.5)

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination buffer's rem...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93450
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-18T00:17:49.230000

2 posts

go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attackers can submit deeply nested JSON documents to services accepting OpenAPI specifications, causing fatal stack overflow that terminates the process and all in-flight requests.

thehackerwire@mastodon.social at 2026-09-18T03:03:20.000Z ##

🟠 CVE-2026-93450 - High (7.5)

go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attackers can submit deeply nested JSON documents to s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T03:03:20.000Z ##

🟠 CVE-2026-93450 - High (7.5)

go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attackers can submit deeply nested JSON documents to s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54734
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-17T22:17:03.317000

2 posts

Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the resulting domain or path segment. A malicious actor who can supply bid-request parameters can cause the server to send HTTP requests to unintended destinations, potentially reaching internal network

thehackerwire@mastodon.social at 2026-09-17T23:00:45.000Z ##

🔴 CVE-2026-54734 - Critical (10)

Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the resulting domain or path segment. A malicious ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T23:00:45.000Z ##

🔴 CVE-2026-54734 - Critical (10)

Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the resulting domain or path segment. A malicious ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70469
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-17T21:32:42

1 posts

Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests that included the standard Content-Encoding header indicating gzip encoding. The framework enforcement filter did not check multiple instances of the Content-Encoding header and did not reject non-standard identifiers for gzip encoding, allowing a malicious client to send crafted r

DailyCyberSecurity@infosec.exchange at 2026-09-17T03:08:21.000Z ##

Learn about recent Apache NiFi vulnerabilities (CVE-2026-87976, CVE-2026-70469) and Apache MyFaces flaws. Apply Apache security updates to prevent DoS attacks.

#ApacheNiFi #ApacheMyFaces #Vulnerability #CVE202687976 #Cybersecurity

securityonline.info/apache-nif

##

CVE-2026-84858
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-17T21:32:41

1 posts

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Bypass The DWR "DataSourceEditDwr" class exposes the "validateScript" method that compiles and executes attacker-supplied JavaScript via the Rhino scripting engine. There are no authorization checks on this method and so it is possible for an attacker with access to a low privile

AAKL@infosec.exchange at 2026-09-16T17:17:37.000Z ##

New.

Cisco has advisories to address 13 critical vulnerabilities, among other lower-ranking flaws sec.cloudapps.cisco.com/securi

This one is new, but there are others:

CRITICAL: CVE-2026-20176, CVE-2026-20211, and CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerabilities sec.cloudapps.cisco.com/securi

Broadcom:

Broadcom has a long list of advisories addressing at least two critical vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

Tenable:

Tenable Research Advisories: CVE-2026-84858: ScadaLTS Multiple Vulnerabilities tenable.com/security/research/

And if you missed this, Microsoft posted two advisories for Edge yesterday: msrc.microsoft.com/update-guide #Microsoft #infosec #Cisco #vulnerability

##

CVE-2026-79752(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-09-17T20:28:17

2 posts

### Impact The `FunctionsBuilder::cast($field, $dataType)`, `extract($part, $expr)`, `datePart($part, $expr)`, `dateAdd($expr, $value, $unit)` methods are vulnerable to SQL injection if user controlled data is supplied to the ($dataType / $part / $unit) parameters. ### Patches 5.3.7, 5.2.14, 5.1.9, 4.6.5, 4.5.12 contain fixes ### Workarounds Don't provide user controlled data to these functions

offseq at 2026-09-18T01:30:23.307Z ##

CVE-2026-79752: CakePHP <4.5.12, 4.6.0-4.6.4, 5.0.0-5.1.8, 5.2.0-5.2.13, 5.3.0-5.3.6 FunctionsBuilder SQL injection risk! CRITICAL severity — patch ASAP or avoid user input in $dataType, $part, $unit. radar.offseq.com/threat/databa

##

offseq@infosec.exchange at 2026-09-18T01:30:23.000Z ##

CVE-2026-79752: CakePHP <4.5.12, 4.6.0-4.6.4, 5.0.0-5.1.8, 5.2.0-5.2.13, 5.3.0-5.3.6 FunctionsBuilder SQL injection risk! CRITICAL severity — patch ASAP or avoid user input in $dataType, $part, $unit. radar.offseq.com/threat/databa #OffSeq #CakePHP #SQLi #Infosec

##

CVE-2026-92956
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-17T20:18:59.730000

2 posts

vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on Node.js 26. WebAssembly.compileStreaming and WebAssembly.instantiateStreaming can produce a raw host-realm Promise that rejects with a host-realm error object; by controlling Symbol.species via Promise.prototype.finally, sandbox code receives that raw host error, walks from the h

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92935
(9.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-17T20:18:59.093000

2 posts

vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and <= 3.11.6, the NodeVM constructor computes `hasRealRequireConfig` with `typeof requireOpts === 'object' && requireOpts !== null`, so an array-shaped `require` value (for example `require: []`) satisfies the guard that is meant to reject nesting without an explicit require configuration. `makeResolverFromLegacyOptions()`

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-91989
(7.5 HIGH)

EPSS: 1.26%

updated 2026-09-17T20:18:54.893000

1 posts

atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths. Attackers can bypass path containment checks by including '../' segments in requests to the DashboardHandler.do_GET endpoint to access files outside the intended agents_root directory.

thehackerwire@mastodon.social at 2026-09-15T16:59:53.000Z ##

🟠 CVE-2026-91989 - High (7.5)

atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths. Attackers can bypass path conta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54627
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-17T20:16:52.117000

2 posts

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_private_sail_pixel_format() in src/sail-codecs/psd/helpers.c resolves a one-channel PSD in Bitmap color mode to SAIL_PIXEL_FORMAT_BPP1_INDEXED without requiring the file depth to be one, so the pixel buffer uses one-bit rows while sail_codec_load_frame_v

thehackerwire@mastodon.social at 2026-09-17T21:00:40.000Z ##

🔴 CVE-2026-54627 - Critical (9.8)

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_private_sail_pixel_format() in src/sail-codecs/psd/helpers.c resolves a one-channel PSD in Bitmap col...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T21:00:40.000Z ##

🔴 CVE-2026-54627 - Critical (9.8)

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_private_sail_pixel_format() in src/sail-codecs/psd/helpers.c resolves a one-channel PSD in Bitmap col...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87286
(8.1 HIGH)

EPSS: 0.24%

updated 2026-09-17T18:34:49

1 posts

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidenti

thehackerwire@mastodon.social at 2026-09-15T21:00:53.000Z ##

🟠 CVE-2026-87286 - High (8.1)

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via H...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12793
(9.8 CRITICAL)

EPSS: 0.39%

updated 2026-09-17T18:16:36.517000

1 posts

The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is due to the plugin not validating that a submitted form ID belongs to a JetFormBuilder form before parsing the referenced post's content as form schema and executing an Advanced Validation server-side callback. This makes it possible for un

3 repos

https://github.com/abraxas/CVE-2026-12793

https://github.com/rootxn/CVE-2026-12793

https://github.com/murrez/CVE-2026-12793

offseq@infosec.exchange at 2026-09-16T04:30:24.000Z ##

CVE-2026-12793: CRITICAL privilege escalation in JetFormBuilder Dynamic Blocks Form Builder (<=3.6.2). Unauthenticated attackers can create admin accounts. Restrict access & monitor until patch. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202612793 #Infosec

##

CVE-2026-86863
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-17T17:16:51.633000

2 posts

pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI environment. WebserverAuthentication.get_user() read config.WEBSERVER_REMOTE_USER from request.environ and, when that returned nothing, fell back to reading the same name directly from the inbound HTTP request headers via requ

DailyCyberSecurity at 2026-09-18T02:58:24.972Z ##

A critical pgAdmin 4 authentication bypass (CVE-2026-86863) allows remote admin takeover. Patch this pgAdmin 4 authentication bypass vulnerability now.

securityonline.info/pgadmin-4-

##

DailyCyberSecurity@infosec.exchange at 2026-09-18T02:58:24.000Z ##

A critical pgAdmin 4 authentication bypass (CVE-2026-86863) allows remote admin takeover. Patch this pgAdmin 4 authentication bypass vulnerability now.

#pgAdmin #PostgreSQL #CVE202686863 #AuthenticationBypass #Cybersecurity

securityonline.info/pgadmin-4-

##

CVE-2026-92941
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-17T16:18:34.520000

2 posts

vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls and url builtins can use URLSearchParams to create host-realm arrays and manipulate the TLS trust store, enabling subsequent host HTTPS clients to accept attacker-co

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-86865
(7.2 HIGH)

EPSS: 0.00%

updated 2026-09-17T16:18:18.163000

1 posts

Tanium addressed a SQL injection vulnerability in Asset.

CVE-2026-86320
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-17T16:18:17.403000

2 posts

A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch hook can cause the hook to execute on the host during the build process, resulting in arbitrary code execution with the privileges of the user running flatpak-builder.

thehackerwire@mastodon.social at 2026-09-17T11:00:52.000Z ##

🟠 CVE-2026-86320 - High (7.8)

A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch hook can cause the hook to execute on the host ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T11:00:52.000Z ##

🟠 CVE-2026-86320 - High (7.8)

A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch hook can cause the hook to execute on the host ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92938
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-17T15:32:28

2 posts

vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or through builtin: ['*']. The module is wrapped with vm.readonly(), which prevents property assignment but leaves host-authority callables reachable; in addition, the resolver treats any request starting with 'node:' as a core-module request and t

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92939
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-17T15:32:28

2 posts

vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed. The module is presented via a recursive read-only proxy, but its callable exports still execute with host-process authority. Sandboxed JavaScript can therefore call crypto.setEngine() with a filesystem path to an attacker-supplied native library (for example, one bundled in an u

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92954
(8.6 HIGH)

EPSS: 0.00%

updated 2026-09-17T15:32:28

2 posts

vm2 is a sandbox library for running untrusted JavaScript in Node.js. In versions >= 3.10.0 and <= 3.11.7, Promises returned from the host realm into the sandbox are not marked as handled at the bridge boundary; only Promises created inside the sandbox are wrapped with a rejection-swallowing handler (lib/setup-sandbox.js), and the bridge only installs host-side rejection sanitizers when sandbox co

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92940
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-17T15:32:27

2 posts

vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is explicitly configured to allow require('https'). The builtin loader wraps host modules in a read-only proxy, but method calls such as Agent.prototype.on() are forwarded to the underlying host object, so sandbox code can register a listener for the agent's 'free' event. When an unr

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92960
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-17T15:32:27

2 posts

vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox code to read host process identity and network topology. Attackers can invoke dns.setServers() to hijack the host process DNS resolver globally, redirecting all subsequent host DNS queries through an attacker-controlled resolver.

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92951
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-17T15:32:26

2 posts

vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses non-exact substring matching instead of full package-name boundary validation. Attackers can bypass the allowlist by requiring a colliding package name that contains an allowlisted package substring, causing vm2 to load and execute unauthorized host packages in the host context.

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92944
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-17T15:32:26

2 posts

vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally() bypasses vm2's wrapper protections due to a stale PromiseThenLookupChain protector in V8 14.6. Attackers can exploit this by creating an async function that returns a Promise with an attacker-controlled constructor Symbol.species, allowing them to reach the host Function constr

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92957
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-17T15:32:26

2 posts

vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) entries in a NodeVM wildcard require policy. Although NodeVM strips the `node:` prefix during require() resolution, negative wildcard entries are matched by exact string comparison against the canonical builtin names, so a policy such as `new NodeVM({ require: { builtin: ['*', '-

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92918
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-17T15:32:24

2 posts

admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /logs endpoint to harvest session tokens and replay them as bearer credentials for full user access.

thehackerwire@mastodon.social at 2026-09-17T14:02:24.000Z ##

🟠 CVE-2026-92918 - High (8.8)

admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /logs endpoint to harvest session tokens and repla...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T14:02:24.000Z ##

🟠 CVE-2026-92918 - High (8.8)

admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /logs endpoint to harvest session tokens and repla...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92937
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-17T15:32:23

2 posts

vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for GHSA-m283-3h24-438v is incomplete: the bridge gate at lib/bridge.js:1624 identity-checks only the direct call target when deciding whether to rebuild/sanitise a rejected host Promise value. Registering the rejection handler through Function.prototype.call or .apply indirection (e.

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92919
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-17T15:32:23

2 posts

admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. Attackers can use dot-dot path segments in filenames to escape the configured storage directory and overwrite arbitrary files accessible to the server process.

thehackerwire@mastodon.social at 2026-09-17T14:02:33.000Z ##

🟠 CVE-2026-92919 - High (8.1)

admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. Attackers can use dot-dot path segments in filenames to escape the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T14:02:33.000Z ##

🟠 CVE-2026-92919 - High (8.1)

admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. Attackers can use dot-dot path segments in filenames to escape the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92946
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-17T15:32:22

2 posts

vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit require.root that excludes node_modules. Sandboxed code can require vm2's own package, instantiate an unrestricted NodeVM instance, and execute arbitrary host OS commands via child_process.

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92953
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-17T15:32:22

2 posts

vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation. Attackers can use prototype-walking primitives to reach and modify host Uint8Array.prototype, %TypedArray%.prototype, and ArrayBuffer.prototype, causing host-created typed arrays to observe attacker-controlled properties after VM.run() returns.

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92947
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-17T15:32:21

2 posts

vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations. Sandboxed code can read and write to host-realm buffers by acquiring ArrayBuffers from small allocations, leading to sensitive data exposure and potential denial-of-service.

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-81481
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-17T15:32:18

2 posts

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker.

thehackerwire@mastodon.social at 2026-09-17T14:02:43.000Z ##

🟠 CVE-2026-81481 - High (7.5)

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T14:02:43.000Z ##

🟠 CVE-2026-81481 - High (7.5)

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92955
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-17T15:32:17

2 posts

vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ getter/setter through console._stdout and console._stderr. Attackers can overwrite EventEmitter.prototype.emit and trigger process events to execute code with process context, bypassing code generation restrictions.

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92950
(8.6 HIGH)

EPSS: 0.00%

updated 2026-09-17T15:17:00.910000

2 posts

vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that allows attackers to execute arbitrary code in the host Node.js process. Attackers can supply a malicious script file to the vm2 CLI that uses require(__filename) to re-execute itself in the host realm, bypassing sandbox isolation and accessing host modules like fs and child_process.

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92934
(9.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-17T15:17:00.520000

2 posts

vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host-wrapped AggregateError objects are caught within a single exception handler traversal. Attackers can exploit cycle detection bypass in handleException to access unsanitized host proxies embedded in the errors array, enabling full remote code execution and process information dis

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92948
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-17T14:18:00.420000

2 posts

vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox escape on Node.js 24 and newer when the embedder explicitly allows the node:test builtin (e.g. require: { builtin: ['node:test'] }). On Node.js 24+, module.builtinModules exposes the scheme-only key node:test, which is not covered by vm2's family-based DANGEROUS_BUILTINS protection, so it i

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92838
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-17T14:17:56.873000

2 posts

A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location. If successfully exploited, an attacker with local write access to the affected directory could achieve

offseq at 2026-09-17T04:30:24.676Z ##

CVE-2026-92838: HIGH severity DLL hijack in GeoVision GV-Remote E-map 18.3.1 🖥️. Local attackers can execute arbitrary code via unsafe DLL load paths. Restrict directory write access; check vendor guidance. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-17T04:30:24.000Z ##

CVE-2026-92838: HIGH severity DLL hijack in GeoVision GV-Remote E-map 18.3.1 🖥️. Local attackers can execute arbitrary code via unsafe DLL load paths. Restrict directory write access; check vendor guidance. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #InfoSec #Windows

##

CVE-2026-15688
(0 None)

EPSS: 0.00%

updated 2026-09-17T13:16:42.530000

2 posts

Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi Electric GX Works3 and Motion Control Setting allows a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modifying part of the executable module in memory, and thereby may be able to view, tamper with, destroy, or delete control programs.

offseq at 2026-09-17T09:00:28.138Z ##

CVE-2026-15688 | Mitsubishi Electric GX Works3 (CVSS 9.2, CRITICAL): Local attackers can bypass authentication by modifying memory, risking control program compromise. No fix yet — restrict local access. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-17T09:00:28.000Z ##

CVE-2026-15688 | Mitsubishi Electric GX Works3 (CVSS 9.2, CRITICAL): Local attackers can bypass authentication by modifying memory, risking control program compromise. No fix yet — restrict local access. #OffSeq #ICS #CVE202615688 radar.offseq.com/threat/cve-20

##

CVE-2026-76460
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-17T12:46:31.670000

30 posts

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized ac

1 repos

https://github.com/S3v3n-JG/CVE-2026-76460

youranonnewsirc@nerdculture.de at 2026-09-18T04:26:20.000Z ##

Critical cybersecurity alerts issued as Check Point (CVE-2026-91843) and Cisco (CVE-2026-76460) disclose severe vulnerabilities, with Cisco's already exploited. Geopolitically, USCG/FBI investigate suspected foreign cyberattacks on two oil tankers; Iran reportedly targeted another in the Strait of Hormuz. Tech advances with OpenAI's 'Astra for Law' for legal AI workflows.

#Cybersecurity #TechNews #Geopolitics

##

threatnoir at 2026-09-18T03:05:51.971Z ##

⚠️ CRITICAL: Cisco alerts customers to second actively exploited zero-day in as many days

Cisco ISE zero-day CVE-2026-76460 is actively exploited in the wild. Remote attackers can bypass authentication, take full device control, modify network policies, and steal credentials. If you run ISE, this is a direct threat to your network perimeter and access controls.

threatnoir.com/focus

🤖 AI generated summary

##

undercodenews@mastodon.social at 2026-09-18T02:16:37.000Z ##

Cisco ISE Faces a Critical Zero-Day Threat as CISA Adds CVE-2026-76460 to the KEV Catalog + Video

A Critical Warning for Cisco ISE Administrators A new Cisco security vulnerability has moved rapidly from a newly disclosed flaw to an active-exploitation concern. On September 16, 2026, Cisco disclosed CVE-2026-76460, a critical authentication-bypass vulnerability affecting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). Cisco…

undercodenews.com/cisco-ise-fa

##

Matchbook3469@mastodon.social at 2026-09-17T19:36:05.000Z ##

🔵 THREAT INTELLIGENCE

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Vulnerability | CRITICAL
CVEs: CVE-2026-76460

Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in...

Full analysis:
yazoul.net/news/article/cisco-

by Yazoul AI

#InfoSec #Ransomware #IncidentResponse

##

netsecio@mastodon.social at 2026-09-17T15:31:25.000Z ##

📰 CISA Adds Actively Exploited Cisco and Acronis Flaws to KEV Catalog

CISA adds two actively exploited vulnerabilities to its KEV catalog: a critical Cisco ISE auth bypass (CVE-2026-76460) and an Acronis Backup flaw (CVE-2026-87886). Federal agencies must patch urgently. #CISA #KEV #PatchNow

🔗 cyber.netsecops.io/articles/ci

##

netsecio@mastodon.social at 2026-09-17T15:31:22.000Z ##

📰 Cisco ISE Zero-Day (CVSS 10.0) Under Active Attack, Bypasses Auth

Cisco warns of a critical (CVSS 10.0) zero-day in Identity Services Engine (ISE) actively exploited in the wild. The flaw, CVE-2026-76460, allows full authentication bypass. CISA added to KEV catalog. Patch immediately! #Cisco #ZeroDay #CyberSecurity

🔗 cyber.netsecops.io/articles/ci

##

Analyst207@mastodon.social at 2026-09-17T14:10:01.000Z ##

Cisco Discloses Zero-Day ISE Auth Bypass Under Active Exploitation

Cisco has uncovered a critical zero-day vulnerability, CVE-2026-76460, that lets hackers bypass authentication on its Identity Services Engine and Passive Identity Connector, and it's already being exploited by attackers. This flaw allows unauthorized access to affected devices with just a crafted request.

osintsights.com/cisco-disclose

#ZeroDay #Cve202676460 #IdentityServicesEngine #Ise #Cisco

##

beyondmachines1 at 2026-09-17T14:01:13.778Z ##

Cisco Patches 21 Flaws in ISE Identity Infrastructure Including Actively Exploited Zero-Days

Cisco released a set of security updates for Identity Services Engine (ISE) addressing 21 vulnerabilities, including two critical authentication bypasses (CVE-2026-20192 and CVE-2026-76460) currently exploited by attackers to gain root access.

**Treat this as a top-priority emergency attackers are already using some of these flaws to take over identity servers. If you run Cisco ISE or ISE-PIC, first make sure the management interface is never reachable from the internet. Then patch ASAP to 3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7 or 3.5 P4. Check your access logs for strange accounts like "dummyuser". Assume a breach if you find anything weird.**

beyondmachines.net/event_detai

##

Matchbook3469@mastodon.social at 2026-09-17T12:28:07.000Z ##

🔴 New security advisory:

CVE-2026-76460 affects multiple systems.

• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#InfoSec #SecurityPatching #HackerNews

##

undercodenews@mastodon.social at 2026-09-17T12:21:13.000Z ##

Cisco ISE Under Attack: Critical CVE-2026-76460 Gives Attackers a Path to Root Access + Video

A Maximum-Severity Warning for Network Defenders Cisco has issued an urgent warning over active exploitation of a maximum-severity vulnerability in Cisco Identity Services Engine (ISE), a platform used by organizations to control and enforce access to corporate networks. The vulnerability, tracked as CVE-2026-76460, carries the highest possible CVSS score of 10.0 and has now…

undercodenews.com/cisco-ise-un

##

Analyst207@mastodon.social at 2026-09-17T12:03:14.000Z ##

Cisco Discloses Active Exploitation of ISE Flaw

Cisco warns that a critical API vulnerability, CVE-2026-76460, is under active exploitation, allowing attackers to bypass security and gain unauthorized access to devices with a simple crafted request. This maximum-severity flaw scores a perfect 10.0 on the CVSS scale, making it a high-risk threat that demands immediate attention.

osintsights.com/cisco-disclose

#Cve202676460 #ApiVulnerability #ActiveExploitation #Cisco #IseFlaw

##

thecybermind at 2026-09-17T10:58:07.875Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-76460 – Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

A strategic executive briefing detailing privileged API mitigation, network segmentation, and zero-trust verification frameworks for CVE-2026-76460 in Cisco ISE....

thecybermind.co/78ny

##

offseq at 2026-09-17T10:30:26.279Z ##

CVE-2026-76460: CRITICAL auth bypass in Cisco ISE & ISE-PIC is actively exploited. Remote attackers can gain admin access via crafted API requests. Patch ISE 3.1 – 3.5 now — no workarounds. More: radar.offseq.com/threat/cisco-

##

guru@thecybersecguru.com at 2026-09-17T08:44:54.000Z ##

Cisco ISE Zero-Day: CVE-2026-76460 Bypasses Authentication With a Perfect CVSS 10.0

Cisco ISE CVE-2026-76460 is a critical CVSS 10 authentication bypass. Learn how the flaw enables admin and root access, IOCs, hunting and fixes

thecybersecguru.com/news/cisco

##

undercodenews@mastodon.social at 2026-09-17T08:00:33.000Z ##

Cisco ISE Zero-Day Under Active Attack: Critical Authentication Bypass Puts Network Identity Systems at Risk

A Dangerous New Attack on the Network’s Identity Gatekeeper Cisco has released emergency security updates for a maximum-severity vulnerability in Cisco Identity Services Engine (ISE) after confirming that attackers are already exploiting the flaw in real-world attacks. Tracked as CVE-2026-76460, the vulnerability carries a CVSS score of 10.0 and allows an…

undercodenews.com/cisco-ise-ze

##

ottoto2017@prattohome.com at 2026-09-17T07:49:31.000Z ##

「Ciscoは、ISEのゼロデイ脆弱性が攻撃に悪用され、深刻な被害を受ける可能性があると警告している。 」: #BLEEPINGCOMPUTER

「シスコは、攻撃者が実際に悪用している、深刻度が最大レベルのアイデンティティサービスエンジンの脆弱性に対処するためのセキュリティアップデートをリリースしました。

Cisco ISEは、IT管理者がエンドポイント、ユーザー、およびデバイスのネットワークリソースへのアクセスを管理するために使用する集中型ポリシープラットフォームであり、多くの場合、ゼロトラストセキュリティモデルを適用しながら使用されます。

このセキュリティ上の欠陥( CVE-2026-76460 として追跡)により、リモートの攻撃者は、Cisco Identity Services Engine(ISE)およびCisco ISE Passive Identity Connector(ISE-PIC)のAPIの脆弱性を悪用することで、設定に関係なく認証を回避できます。 」

bleepingcomputer.com/news/secu

#prattohome

##

offseq at 2026-09-17T07:30:37.396Z ##

CRITICAL auth bypass (CVE-2026-76460) in Cisco ISE & ISE-PIC is being actively exploited. Remote attackers gain root on management interface via crafted API calls. Patch ASAP — no workarounds except ACLs. Details: radar.offseq.com/threat/active

##

undercodenews@mastodon.social at 2026-09-17T07:08:04.000Z ##

Cisco’s Critical ISE Zero-Day Is Being Exploited: CVE-2026-76460 Gives Remote Attackers a Path to Root Access + Video

A New Cisco Emergency for Security Teams A serious new vulnerability in Cisco Identity Services Engine has moved rapidly from disclosure to active exploitation, creating an immediate security concern for organizations that rely on ISE to control identity, authentication, and network access. Cisco has assigned the flaw CVE-2026-76460, giving it the…

undercodenews.com/ciscos-criti

##

cyberworldops at 2026-09-17T07:00:01.220Z ##

Cisco confirmed active exploitation of CVE-2026-76460, an authentication bypass in an ISE API endpoint. Unauthenticated remote access can lead to root compromise of ISE and ISE-PIC, now listed in CISA KEV. Patching and log review are urgent.

cyberworldops.eu/en/cisco-ise-

##

youranonnewsirc@nerdculture.de at 2026-09-18T04:26:20.000Z ##

Critical cybersecurity alerts issued as Check Point (CVE-2026-91843) and Cisco (CVE-2026-76460) disclose severe vulnerabilities, with Cisco's already exploited. Geopolitically, USCG/FBI investigate suspected foreign cyberattacks on two oil tankers; Iran reportedly targeted another in the Strait of Hormuz. Tech advances with OpenAI's 'Astra for Law' for legal AI workflows.

#Cybersecurity #TechNews #Geopolitics

##

threatnoir@infosec.exchange at 2026-09-18T03:05:51.000Z ##

⚠️ CRITICAL: Cisco alerts customers to second actively exploited zero-day in as many days

Cisco ISE zero-day CVE-2026-76460 is actively exploited in the wild. Remote attackers can bypass authentication, take full device control, modify network policies, and steal credentials. If you run ISE, this is a direct threat to your network perimeter and access controls.

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

beyondmachines1@infosec.exchange at 2026-09-17T14:01:13.000Z ##

Cisco Patches 21 Flaws in ISE Identity Infrastructure Including Actively Exploited Zero-Days

Cisco released a set of security updates for Identity Services Engine (ISE) addressing 21 vulnerabilities, including two critical authentication bypasses (CVE-2026-20192 and CVE-2026-76460) currently exploited by attackers to gain root access.

**Treat this as a top-priority emergency attackers are already using some of these flaws to take over identity servers. If you run Cisco ISE or ISE-PIC, first make sure the management interface is never reachable from the internet. Then patch ASAP to 3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7 or 3.5 P4. Check your access logs for strange accounts like "dummyuser". Assume a breach if you find anything weird.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

thecybermind@infosec.exchange at 2026-09-17T10:58:07.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-76460 – Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

A strategic executive briefing detailing privileged API mitigation, network segmentation, and zero-trust verification frameworks for CVE-2026-76460 in Cisco ISE....

thecybermind.co/78ny

##

offseq@infosec.exchange at 2026-09-17T10:30:26.000Z ##

CVE-2026-76460: CRITICAL auth bypass in Cisco ISE & ISE-PIC is actively exploited. Remote attackers can gain admin access via crafted API requests. Patch ISE 3.1 – 3.5 now — no workarounds. More: radar.offseq.com/threat/cisco- #OffSeq #Cisco #ZeroDay #Vuln #Cybersecurity

##

guru@thecybersecguru.com at 2026-09-17T08:44:54.000Z ##

Cisco ISE Zero-Day: CVE-2026-76460 Bypasses Authentication With a Perfect CVSS 10.0

Cisco ISE CVE-2026-76460 is a critical CVSS 10 authentication bypass. Learn how the flaw enables admin and root access, IOCs, hunting and fixes

thecybersecguru.com/news/cisco

##

ottoto2017@prattohome.com at 2026-09-17T07:49:31.000Z ##

「Ciscoは、ISEのゼロデイ脆弱性が攻撃に悪用され、深刻な被害を受ける可能性があると警告している。 」: #BLEEPINGCOMPUTER

「シスコは、攻撃者が実際に悪用している、深刻度が最大レベルのアイデンティティサービスエンジンの脆弱性に対処するためのセキュリティアップデートをリリースしました。

Cisco ISEは、IT管理者がエンドポイント、ユーザー、およびデバイスのネットワークリソースへのアクセスを管理するために使用する集中型ポリシープラットフォームであり、多くの場合、ゼロトラストセキュリティモデルを適用しながら使用されます。

このセキュリティ上の欠陥( CVE-2026-76460 として追跡)により、リモートの攻撃者は、Cisco Identity Services Engine(ISE)およびCisco ISE Passive Identity Connector(ISE-PIC)のAPIの脆弱性を悪用することで、設定に関係なく認証を回避できます。 」

bleepingcomputer.com/news/secu

#prattohome

##

offseq@infosec.exchange at 2026-09-17T07:30:37.000Z ##

CRITICAL auth bypass (CVE-2026-76460) in Cisco ISE & ISE-PIC is being actively exploited. Remote attackers gain root on management interface via crafted API calls. Patch ASAP — no workarounds except ACLs. Details: radar.offseq.com/threat/active #OffSeq #Cisco #ZeroDay

##

cyberworldops@infosec.exchange at 2026-09-17T07:00:01.000Z ##

Cisco confirmed active exploitation of CVE-2026-76460, an authentication bypass in an ISE API endpoint. Unauthenticated remote access can lead to root compromise of ISE and ISE-PIC, now listed in CISA KEV. Patching and log review are urgent. #CiscoIse #AuthBypass #CisaKev

cyberworldops.eu/en/cisco-ise-

##

cR0w@infosec.exchange at 2026-09-16T17:54:16.000Z ##

Patch your Cisco ISE. CVE-2026-76460 a perfect 10 and is EITW. 🥳

sec.cloudapps.cisco.com/securi

The Cisco PSIRT is aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.

##

DailyCyberSecurity@infosec.exchange at 2026-09-16T17:27:21.000Z ##

An exploited Cisco ISE vulnerability (CVE-2026-76460) allows remote root access. Patch this critical Cisco ISE vulnerability to secure networks.

#Cisco #CiscoISE #CVE202676460 #Cybersecurity #InfoSec

securityonline.info/cisco-ise-

##

CVE-2026-92913
(7.4 HIGH)

EPSS: 0.00%

updated 2026-09-17T12:18:30.290000

2 posts

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptographically weak pseudo-random number generator when creating account activation / login pairing codes. getRandomCode() in objects/functions.php derives the code entirely from uniqid() (sprintf('%08x%05x', seconds, microseconds)) with a single non-CSPRNG rand() character used only as padding, reducing the code space to rou

offseq at 2026-09-17T12:00:25.402Z ##

CVE-2026-92913 | WWBN AVideo (CRITICAL, CVSS 9.1): Weak random pairing codes + exposed microtime API = unauthenticated account takeover risk. No patch yet — restrict API access if possible. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-17T12:00:25.000Z ##

CVE-2026-92913 | WWBN AVideo (CRITICAL, CVSS 9.1): Weak random pairing codes + exposed microtime API = unauthenticated account takeover risk. No patch yet — restrict API access if possible. radar.offseq.com/threat/cve-20 #OffSeq #AVideo #CVE202692913 #AccountSecurity

##

CVE-2026-91843
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-17T12:18:29.687000

6 posts

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

1 repos

https://github.com/HORKimhab/CVE-2026-91843

youranonnewsirc@nerdculture.de at 2026-09-18T04:26:20.000Z ##

Critical cybersecurity alerts issued as Check Point (CVE-2026-91843) and Cisco (CVE-2026-76460) disclose severe vulnerabilities, with Cisco's already exploited. Geopolitically, USCG/FBI investigate suspected foreign cyberattacks on two oil tankers; Iran reportedly targeted another in the Strait of Hormuz. Tech advances with OpenAI's 'Astra for Law' for legal AI workflows.

#Cybersecurity #TechNews #Geopolitics

##

undercodenews@mastodon.social at 2026-09-17T05:55:54.000Z ##

Critical Check Point Security Flaw Exposes Management Servers to Root-Level Remote Code Execution + Video

A Dangerous Vulnerability in the Security Control Plane A newly disclosed vulnerability in Check Point management infrastructure has created an urgent patching situation for organizations relying on the company’s security platforms. Tracked as CVE-2026-91843, the flaw is rated CVSS 9.8, Critical, and could allow an unauthenticated remote attacker to execute…

undercodenews.com/critical-che

##

youranonnewsirc@nerdculture.de at 2026-09-18T04:26:20.000Z ##

Critical cybersecurity alerts issued as Check Point (CVE-2026-91843) and Cisco (CVE-2026-76460) disclose severe vulnerabilities, with Cisco's already exploited. Geopolitically, USCG/FBI investigate suspected foreign cyberattacks on two oil tankers; Iran reportedly targeted another in the Strait of Hormuz. Tech advances with OpenAI's 'Astra for Law' for legal AI workflows.

#Cybersecurity #TechNews #Geopolitics

##

censys@infosec.exchange at 2026-09-16T22:29:53.000Z ##

🚨New Censys Advisory: CVE-2026-91843

A critical (CVSS 9.8) unauthenticated RCE affects Check Point Quantum Security Management and Log Servers.

Censys observes 3,836 hosts globally exposing the management/log server role. This is total product presence, not a confirmed-vulnerable count.

No public PoC or confirmed exploitation has been reported as of publication. Check Point has released patches for supported versions via LivePatch.

Read the analysis and remediation details: censys.com/advisory/cve-2026-9

#Cybersecurity #CVE #Vulnerability #CensysARC

##

daniel1820815@infosec.exchange at 2026-09-16T19:23:20.000Z ##

🚨 Please read this important update from Check Point:

CVE-2026-91843 - Stack overflow in login process to the Security Management and Log Servers

support.checkpoint.com/results

#CheckPoint #CheckPointsoftwareTechnologies #CVE #CVE202691843

##

DailyCyberSecurity@infosec.exchange at 2026-09-16T16:08:43.000Z ##

Check Point fixed a critical Check Point login flaw (CVE-2026-91843). Patch this Check Point login flaw now to block unauthenticated remote root takeovers.

#CheckPoint #Cybersecurity #CVE202691843 #InfoSec #Vulnerability

securityonline.info/check-poin

##

CVE-2026-20307
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-17T12:17:25.977000

1 posts

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least low-privileged administrative credentials. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream.

AAKL@infosec.exchange at 2026-09-16T17:17:37.000Z ##

New.

Cisco has advisories to address 13 critical vulnerabilities, among other lower-ranking flaws sec.cloudapps.cisco.com/securi

This one is new, but there are others:

CRITICAL: CVE-2026-20176, CVE-2026-20211, and CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerabilities sec.cloudapps.cisco.com/securi

Broadcom:

Broadcom has a long list of advisories addressing at least two critical vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

Tenable:

Tenable Research Advisories: CVE-2026-84858: ScadaLTS Multiple Vulnerabilities tenable.com/security/research/

And if you missed this, Microsoft posted two advisories for Edge yesterday: msrc.microsoft.com/update-guide #Microsoft #infosec #Cisco #vulnerability

##

CVE-2026-87796
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-17T06:30:45

2 posts

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution poss

1 repos

https://github.com/abraxas/CVE-2026-87796

offseq at 2026-09-17T06:00:25.041Z ##

CVE-2026-87796 (CRITICAL, CVSS 9.8): sh1zen Multi Uploader for Gravity Forms ≤1.1.9 lets unauthenticated attackers upload arbitrary files, risking remote code execution. No patch yet — disable the plugin or restrict uploads. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-17T06:00:25.000Z ##

CVE-2026-87796 (CRITICAL, CVSS 9.8): sh1zen Multi Uploader for Gravity Forms ≤1.1.9 lets unauthenticated attackers upload arbitrary files, risking remote code execution. No patch yet — disable the plugin or restrict uploads. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE #RCE

##

CVE-2026-73453
(10.0 CRITICAL)

EPSS: 0.75%

updated 2026-09-17T04:17:59.823000

1 posts

An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS configured with P4Runtime. P4Runtime is disabled by default in Arista EOS. By crafting a malicious packet during the initiation of a P4Runtime session, an attacker can obtain complete administrative c

offseq@infosec.exchange at 2026-09-16T10:30:23.000Z ##

CVE-2026-73453: CRITICAL code injection in Arista EOS (4.29.2F – 4.36.1F) via P4Runtime. Allows unauthenticated code execution & admin control if enabled. Disable P4Runtime if not needed. No active exploits yet. radar.offseq.com/threat/cve-20 #OffSeq #CVE202673453 #NetworkSecurity

##

CVE-2026-69486
(8.8 HIGH)

EPSS: 0.66%

updated 2026-09-17T04:17:55.620000

1 posts

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-09-16T00:00:09.000Z ##

🟠 CVE-2026-69486 - High (8.8)

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92578
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-17T00:31:30

1 posts

WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify(). Attackers who obtain the stored users.password hash value can authenticate as any user by submitting the hash directly to login endpoints, completely bypassing password v

offseq@infosec.exchange at 2026-09-17T00:00:35.000Z ##

CVE-2026-92578: CRITICAL auth bypass in WWBN AVideo (≤29.0) allows attackers with stolen password hashes to log in as any user — no password needed. Patch pending — restrict hash access, monitor for abuse. radar.offseq.com/threat/cve-20 #OffSeq #CVE202692578 #authentication #infosec

##

CVE-2026-92576
(8.6 HIGH)

EPSS: 0.00%

updated 2026-09-17T00:31:25

1 posts

HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instructing the bot to fetch cloud metadata endpoints, localhost services, and RFC 1918 addresses to extract IAM credentials and internal service data.

offseq@infosec.exchange at 2026-09-17T01:30:25.000Z ##

CRITICAL SSRF vuln (CVE-2026-92576) in HKUDS nanobot <0.3.0: Inadequate URL validation lets attackers access internal cloud metadata & services. Restrict WebFetchTool, monitor for suspicious requests. Patch status: unconfirmed. radar.offseq.com/threat/cve-20 #OffSeq #infosec #CVE202692576

##

CVE-2026-20332
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-16T21:32:55

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally disc

beyondmachines1 at 2026-09-17T17:01:13.925Z ##

Cisco Patches 18 Critical and High-Severity Firewall Vulnerabilities, One Actively Exploited

Cisco released a massive security hardening update fixing 18 vulnerabilities in its Secure Firewall suite, including an actively exploited authentication bypass (CVE-2026-20332) and multiple critical remote code execution flaws.

**If you use Cisco Secure Firewall (ASA, FTD, or FMC), this is urgent. Patch now to the fixed versions Cisco lists. At least one flaw is already being exploited by attackers. Make sure the management interfaces are reachable only from your trusted internal network and never from the internet.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-09-17T17:01:13.000Z ##

Cisco Patches 18 Critical and High-Severity Firewall Vulnerabilities, One Actively Exploited

Cisco released a massive security hardening update fixing 18 vulnerabilities in its Secure Firewall suite, including an actively exploited authentication bypass (CVE-2026-20332) and multiple critical remote code execution flaws.

**If you use Cisco Secure Firewall (ASA, FTD, or FMC), this is urgent. Patch now to the fixed versions Cisco lists. At least one flaw is already being exploited by attackers. Make sure the management interfaces are reachable only from your trusted internal network and never from the internet.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2026-89082(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-09-16T21:32:55

2 posts

HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software.

DailyCyberSecurity at 2026-09-17T14:52:01.266Z ##

HP released updates to fix critical HP Advance vulnerabilities (CVE-2026-89082). Patch these HP Advance vulnerabilities to stop remote code execution.

securityonline.info/hp-advance

##

DailyCyberSecurity@infosec.exchange at 2026-09-17T14:52:01.000Z ##

HP released updates to fix critical HP Advance vulnerabilities (CVE-2026-89082). Patch these HP Advance vulnerabilities to stop remote code execution.

#HP #HPAdvance #CVE202689082 #Cybersecurity #Vulnerability

securityonline.info/hp-advance

##

CVE-2026-20324
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-16T21:32:50

1 posts

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands as root. This vulnerability exists because a registered sftunnel peer has incorrect permissions to write an arbitrary file to any location on the device. An attacker could exploit this vulnerabilit

undercodenews@mastodon.social at 2026-09-17T18:38:51.000Z ##

Cisco Secure Firewall Management Center Hit by Critical CVE-2026-20324 Root RCE Vulnerability + Video

A Critical Warning for Cisco Firewall Administrators A critical vulnerability in Cisco Secure Firewall Management Center (FMC) has raised concerns for organizations relying on Cisco infrastructure to manage and protect their networks. Tracked as CVE-2026-20324, the flaw carries a CVSS score of 9.9 and can allow an authenticated remote attacker to execute arbitrary…

undercodenews.com/cisco-secure

##

CVE-2026-20192
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-16T21:32:50

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-

beyondmachines1 at 2026-09-17T14:01:13.778Z ##

Cisco Patches 21 Flaws in ISE Identity Infrastructure Including Actively Exploited Zero-Days

Cisco released a set of security updates for Identity Services Engine (ISE) addressing 21 vulnerabilities, including two critical authentication bypasses (CVE-2026-20192 and CVE-2026-76460) currently exploited by attackers to gain root access.

**Treat this as a top-priority emergency attackers are already using some of these flaws to take over identity servers. If you run Cisco ISE or ISE-PIC, first make sure the management interface is never reachable from the internet. Then patch ASAP to 3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7 or 3.5 P4. Check your access logs for strange accounts like "dummyuser". Assume a breach if you find anything weird.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-09-17T14:01:13.000Z ##

Cisco Patches 21 Flaws in ISE Identity Infrastructure Including Actively Exploited Zero-Days

Cisco released a set of security updates for Identity Services Engine (ISE) addressing 21 vulnerabilities, including two critical authentication bypasses (CVE-2026-20192 and CVE-2026-76460) currently exploited by attackers to gain root access.

**Treat this as a top-priority emergency attackers are already using some of these flaws to take over identity servers. If you run Cisco ISE or ISE-PIC, first make sure the management interface is never reachable from the internet. Then patch ASAP to 3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7 or 3.5 P4. Check your access logs for strange accounts like "dummyuser". Assume a breach if you find anything weird.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-20211
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-16T21:32:50

1 posts

A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privileged administrative credentials. This vulnerability is due to insecure deserialization of Java objects by the affected software. An attacker could exploit this vulne

AAKL@infosec.exchange at 2026-09-16T17:17:37.000Z ##

New.

Cisco has advisories to address 13 critical vulnerabilities, among other lower-ranking flaws sec.cloudapps.cisco.com/securi

This one is new, but there are others:

CRITICAL: CVE-2026-20176, CVE-2026-20211, and CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerabilities sec.cloudapps.cisco.com/securi

Broadcom:

Broadcom has a long list of advisories addressing at least two critical vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

Tenable:

Tenable Research Advisories: CVE-2026-84858: ScadaLTS Multiple Vulnerabilities tenable.com/security/research/

And if you missed this, Microsoft posted two advisories for Edge yesterday: msrc.microsoft.com/update-guide #Microsoft #infosec #Cisco #vulnerability

##

CVE-2026-20176
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-16T21:32:50

1 posts

A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privileged administrative credentials. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending

AAKL@infosec.exchange at 2026-09-16T17:17:37.000Z ##

New.

Cisco has advisories to address 13 critical vulnerabilities, among other lower-ranking flaws sec.cloudapps.cisco.com/securi

This one is new, but there are others:

CRITICAL: CVE-2026-20176, CVE-2026-20211, and CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerabilities sec.cloudapps.cisco.com/securi

Broadcom:

Broadcom has a long list of advisories addressing at least two critical vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

Tenable:

Tenable Research Advisories: CVE-2026-84858: ScadaLTS Multiple Vulnerabilities tenable.com/security/research/

And if you missed this, Microsoft posted two advisories for Edge yesterday: msrc.microsoft.com/update-guide #Microsoft #infosec #Cisco #vulnerability

##

CVE-2026-87976(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-09-16T21:32:48

1 posts

Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests. The default file persistence provider used coordinates as filesystem path components without rejected parent-directory names, and the path-containment check compared an unnormalized resolved path. An authenticat

DailyCyberSecurity@infosec.exchange at 2026-09-17T03:08:21.000Z ##

Learn about recent Apache NiFi vulnerabilities (CVE-2026-87976, CVE-2026-70469) and Apache MyFaces flaws. Apply Apache security updates to prevent DoS attacks.

#ApacheNiFi #ApacheMyFaces #Vulnerability #CVE202687976 #Cybersecurity

securityonline.info/apache-nif

##

CVE-2026-87024
(7.2 HIGH)

EPSS: 0.00%

updated 2026-09-16T21:32:47

1 posts

Tanium addressed a SQL injection vulnerability in Asset.

CVE-2026-88975
(7.5 HIGH)

EPSS: 0.62%

updated 2026-09-16T20:39:16.610000

1 posts

Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, Ember’s HTTP/2 read loop parses a frame’s 24-bit declared length but waits to buffer the entire payload before comparing it with SETTINGS_MAX_FRAME_SIZE. An unauthenticated peer can declare a payload near 16 MiB on a connection where Ember advertised 16 KiB and either complete or slowly stream it, causing up to 1024-fol

thehackerwire@mastodon.social at 2026-09-15T21:00:43.000Z ##

🟠 CVE-2026-88975 - High (7.5)

Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, Ember’s HTTP/2 read loop parses a frame’s 24-bit declared length but waits to buffer the entire payload before comparing it with SETTINGS_MAX_FRAME_SIZE. An unauthe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77179
(0 None)

EPSS: 0.16%

updated 2026-09-16T20:38:33.883000

2 posts

On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution.

1 repos

https://github.com/HORKimhab/CVE-2026-77179

Analyst207@mastodon.social at 2026-09-18T04:04:42.000Z ##

Docker Flaw Lets Guest Code Read, Modify macOS Host Files

A newly discovered Docker flaw on macOS could allow malicious code in a virtual machine to break free from its sandbox and read or modify sensitive host files, potentially leading to code execution on the host. This vulnerability, tracked as CVE-2026-77179, leverages a weakness in the virtio-fs host server to gain unauthorized access.

osintsights.com/docker-flaw-le

#DockerFlaw #Macos #Cve202677179 #Containerization #VirtualMachine

##

DailyCyberSecurity@infosec.exchange at 2026-09-17T02:33:27.000Z ##

Docker released an update for critical Docker Sandboxes vulnerabilities (CVE-2026-77179, CVE-2026-79994). Patch these Docker Sandboxes vulnerabilities today.

#Docker #DockerSandboxes #CVE202677179 #CVE202679994 #Cybersecurity

securityonline.info/docker-san

##

CVE-2026-70416
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-16T20:37:16.870000

1 posts

Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

thehackerwire@mastodon.social at 2026-09-16T17:02:58.000Z ##

🔴 CVE-2026-70416 - Critical (10)

Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63696
(9.1 CRITICAL)

EPSS: 0.32%

updated 2026-09-16T20:37:16.870000

1 posts

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.

thehackerwire@mastodon.social at 2026-09-15T16:01:34.000Z ##

🔴 CVE-2026-63696 - Critical (9.1)

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92176
(7.8 HIGH)

EPSS: 0.17%

updated 2026-09-16T20:26:50.280000

1 posts

pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of App obj

thehackerwire@mastodon.social at 2026-09-15T20:02:50.000Z ##

🟠 CVE-2026-92176 - High (7.8)

pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92177
(7.8 HIGH)

EPSS: 0.17%

updated 2026-09-16T20:26:50.280000

1 posts

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of P

thehackerwire@mastodon.social at 2026-09-15T19:59:48.000Z ##

🟠 CVE-2026-92177 - High (7.8)

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15638
(0 None)

EPSS: 0.20%

updated 2026-09-16T20:17:20.950000

1 posts

An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not exposed.

cR0w@infosec.exchange at 2026-09-16T14:17:30.000Z ##

Go hack more Secret Server shit.

delinea.com/security-advisories

Authentication Bypass via SAML Response Manipulation - CVE-2026-15640

Reflected Cross-Site Scripting - CVE-2026-15639

Cryptographic Padding Oracle - CVE-2026-15638

##

CVE-2026-87289
(7.5 HIGH)

EPSS: 0.46%

updated 2026-09-16T19:42:12.090000

1 posts

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-static-content). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatabl

thehackerwire@mastodon.social at 2026-09-15T21:03:11.000Z ##

🟠 CVE-2026-87289 - High (7.5)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-static-content). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network ac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80217
(8.8 HIGH)

EPSS: 0.28%

updated 2026-09-16T19:27:25.623000

1 posts

Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode on the product to execute arbitrary OS commands.

thehackerwire@mastodon.social at 2026-09-15T10:04:02.000Z ##

🟠 CVE-2026-80217 - High (8.8)

Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode on the product to execute arbitrary OS commands.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76670
(9.9 CRITICAL)

EPSS: 0.45%

updated 2026-09-16T19:20:52.817000

1 posts

Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system compromise.

DailyCyberSecurity@infosec.exchange at 2026-09-16T02:03:44.000Z ##

A critical HPE EdgeConnect authorization bypass (CVE-2026-76670) enables full system compromise. Patch this HPE EdgeConnect authorization bypass now.

#HPE #EdgeConnect #AuthorizationBypass #CVE202676670 #Cybersecurity

securityonline.info/hpe-edgeco

##

CVE-2026-27564
(7.2 HIGH)

EPSS: 2.02%

updated 2026-09-16T19:17:13.860000

3 posts

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a PUT request with admin credentials allowing execution of commands with root privileges on the device.

certvde@infosec.exchange at 2026-09-16T07:58:13.000Z ##

🔒 New CSAF advisory published

VDE-2026-028
Carlo Gavazzi Automation: YL212* and YN115* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: gavazziautomation.csaf-tp.cert

#OT #Advisory

##

certvde@infosec.exchange at 2026-09-16T07:57:36.000Z ##

🔒 New CSAF advisory published

VDE-2026-027
Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices is affected by security vulnerab…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: phoenixcontact.csaf-tp.certvde

#OT #Advisory

##

certvde@infosec.exchange at 2026-09-16T07:56:58.000Z ##

🔒 New CSAF advisory published

VDE-2026-014
Pepperl+Fuchs: ICE2-* and ICE3-* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be execute…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: pepperl-fuchs.csaf-tp.certvde.

#OT #Advisory

##

CVE-2026-27561
(7.2 HIGH)

EPSS: 2.23%

updated 2026-09-16T19:17:13.633000

3 posts

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.

certvde@infosec.exchange at 2026-09-16T07:58:13.000Z ##

🔒 New CSAF advisory published

VDE-2026-028
Carlo Gavazzi Automation: YL212* and YN115* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: gavazziautomation.csaf-tp.cert

#OT #Advisory

##

certvde@infosec.exchange at 2026-09-16T07:57:36.000Z ##

🔒 New CSAF advisory published

VDE-2026-027
Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices is affected by security vulnerab…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: phoenixcontact.csaf-tp.certvde

#OT #Advisory

##

certvde@infosec.exchange at 2026-09-16T07:56:58.000Z ##

🔒 New CSAF advisory published

VDE-2026-014
Pepperl+Fuchs: ICE2-* and ICE3-* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be execute…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: pepperl-fuchs.csaf-tp.certvde.

#OT #Advisory

##

CVE-2026-40854
(0 None)

EPSS: 0.00%

updated 2026-09-16T19:14:25.980000

1 posts

WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session verification mechanism improperly validates the sessionid cookie by checking for the existence of a corresponding file in /tmp/login_user. An attacker can bypass authentication by using directory entries such as "." or ".." in the cookie, allowing unauthorized access to the admin

cR0w@infosec.exchange at 2026-09-16T14:35:20.000Z ##

Vulnerabilities in a 5g router from T-Mobile, the company known for its security?! I'm shocked. Shocked! Well, not that shocked.

cert.pl/posts/2026/09/CVE-2026

#internetOfShit #miraiWillNeverDie
#jobSecurityForSomeone

##

CVE-2026-87288
(8.1 HIGH)

EPSS: 0.24%

updated 2026-09-16T18:32:58

1 posts

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidenti

thehackerwire@mastodon.social at 2026-09-15T21:03:00.000Z ##

🟠 CVE-2026-87288 - High (8.1)

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via H...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20331
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-09-16T18:32:09

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally disc

nyanbinary@infosec.exchange at 2026-09-16T18:08:42.000Z ##

@cR0w was just looking at those, lol. Don't sleep on this great advertisment of a CVE though: db.gcve.eu/vuln/cve-2026-20331

##

CVE-2026-92397
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-16T18:32:09

1 posts

A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. Such manipulation of the argument data.url leads to os command injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

thehackerwire@mastodon.social at 2026-09-16T17:02:40.000Z ##

🔴 CVE-2026-92397 - Critical (9.1)

A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. Such manipulation of the argument data.url leads to os comma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89775
(9.3 CRITICAL)

EPSS: 0.18%

updated 2026-09-16T18:31:58

1 posts

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation Computing the effects of a TLB invalidation involves looking at the size of the mapping cached by the TLB. For S1 mappings such as VNCR, this is deducted from the combination of the base granule size and the mapping level. However, this implies that the S1 M

DailyCyberSecurity@infosec.exchange at 2026-09-17T02:40:47.000Z ##

A critical KVM guest escape (CVE-2026-89775) enables an LPE to gain root on Linux hosts. Patch this KVM guest escape vulnerability now.

#KVM #LinuxKernel #CVE202689775 #Cybersecurity #InfoSec

securityonline.info/kvm-guest-

##

CVE-2026-87287
(8.1 HIGH)

EPSS: 0.24%

updated 2026-09-16T18:31:53

1 posts

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidenti

thehackerwire@mastodon.social at 2026-09-15T21:02:51.000Z ##

🟠 CVE-2026-87287 - High (8.1)

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via H...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90999
(0 None)

EPSS: 0.00%

updated 2026-09-16T17:18:18.923000

2 posts

Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment. An external attacker can submit fabricated Sentry events without having access to the victim’s Sentry account, source repository, or infrastructure.

_r_netsec at 2026-09-17T14:13:04.850Z ##

CVE-2026-90999: A fabricated Sentry bug report can make Seer's coding agent run attacker code agyn.io/blog/sentry-seer-autof

##

_r_netsec@infosec.exchange at 2026-09-17T14:13:04.000Z ##

CVE-2026-90999: A fabricated Sentry bug report can make Seer's coding agent run attacker code agyn.io/blog/sentry-seer-autof

##

CVE-2026-61595
(7.7 HIGH)

EPSS: 0.00%

updated 2026-09-16T15:32:15

1 posts

### Impact `djust.tenants` isolation was enforced only on the HTTP path. The current tenant was stored in `threading.local()` and set exclusively by the HTTP-only `TenantMiddleware`, so on the live (WebSocket/SSE) path `get_current_tenant()` was always `None` during mount and every event handler — and the tenant-aware `QuerySet` manager failed **OPEN** (returned the unfiltered queryset, ignoring `

thehackerwire@mastodon.social at 2026-09-16T17:02:47.000Z ##

🟠 CVE-2026-61595 - High (7.7)

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.tenants` isolation was enforced only on the HTTP path. The current tenant was stored in `threading.local(...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73172(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-09-16T15:31:13

1 posts

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the edgserver management service of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to execute arbitrary OS commands as root via crafted requests to TCP port 5058.

offseq@infosec.exchange at 2026-09-16T13:30:26.000Z ##

Advantech EKI-1242IEIMS (fw ≤1.06.01) suffers CRITICAL CVE-2026-73172: unauthenticated OS command injection via TCP 5058 enables remote root access. No patch yet — restrict device exposure & monitor traffic. Details: radar.offseq.com/threat/cve-20 #OffSeq #ICS #CVE202673172 #infosec

##

CVE-2026-58704
(8.0 HIGH)

EPSS: 0.11%

updated 2026-09-16T15:30:57

23 posts

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

undercodenews@mastodon.social at 2026-09-17T19:33:26.000Z ##

Google Pixel Zero-Day Warning: CVE-2026-58704 Exploited in Targeted Attacks + Video

Google Pixel Zero-Day Warning: CVE-2026-58704 Exploited in Targeted Attacks A Silent Pixel Attack Has Triggered a New Security Warning Google Pixel users are facing a serious security warning after Google disclosed that a high-severity vulnerability in the cellular modem may have already been exploited in limited, targeted attacks. Tracked as CVE-2026-58704, the flaw involves a…

undercodenews.com/google-pixel

##

DarkWebInformer at 2026-09-17T17:33:47.483Z ##

🚨 Google confirms Pixel phones targeted in zero-click zero-day attacks

Google has patched CVE-2026-58704, a high-severity vulnerability in Pixel phones' cellular modem that the company says was already under "limited, targeted exploitation."

The flaw is caused by a logic error that can allow an attacker to bypass permission checks and escalate privileges beyond the modem's isolated environment.

Most importantly, exploitation requires no interaction from the victim.

No malicious link needs to be clicked and no file needs to be opened, making it a zero-click attack.

Google has not disclosed:

• Who carried out the attacks
• How many Pixel owners were targeted
• How the victims were selected
• What tools or spyware may have been deployed

CISA has added CVE-2026-58704 to its Known Exploited Vulnerabilities catalog and set a September 19 remediation deadline for affected federal systems.

Google says Pixel devices with the September 5, 2026 security patch level or later are protected.

Pixel owners should update their devices immediately.

Source: techcrunch.com/2026/09/16/goog

##

sayzard@mastodon.sayzard.org at 2026-09-17T16:42:17.000Z ##

Google Pixel phones pwned in zero-click attacks

Google Pixel 휴대폰의 셀룰러 모뎀에서 권한 검증을 우회하고 권한 상승을 가능하게 하는 제로데이 취약점 CVE-2026-58704가 제한적 표적 공격에 악용된 정황이 공개됐다. 사용자 상호작용이 필요 없는 zero-click 공격이 가능하며, 이런 유형은 상용 스파이웨어 기반 표적 감시에 자주 활용된다. Google은 패치를 배포했고, CISA는 이 취약점을 KEV 카탈로그에 추가하며 미국 연방기관에 9월 19일까지 패치하도록 지시했다. AI 개발 자체와 직접 관련되지는 않지만, Android 기기를...

theregister.com/security/2026/

##

beyondmachines1 at 2026-09-17T13:01:13.438Z ##

Google Patches Pixel Modem Zero-Day Exploited in Targeted Attacks

Google's September 2026 update for Pixel devices fixes 110 vulnerabilities, including a high-severity modem flaw (CVE-2026-58704) that attackers are actively exploiting to escalate privileges without user interaction.

**Update your Pixel devices to the September 2026 patch level ASAP to block an active modem exploit and patch a huge set of issues.**

beyondmachines.net/event_detai

##

ottoto2017@prattohome.com at 2026-09-17T04:56:11.000Z ##

「Google Pixel端末がゼロクリック攻撃でハッキングされる
/CISAは連邦政府機関に対し、パッチ適用にわずか3日間しか猶予を与えていない。 」: #TheRegister

「Googleと米国政府は、Pixelスマートフォンの携帯モデムに存在するゼロデイ脆弱性を悪用した攻撃者が、権限チェックを回避し、ユーザーの操作なしに権限を昇格できると警告した。この脆弱性は、アップデートを行うことで既に修正されている。

Googleは 火曜日に、 CVE-2026-58704 として追跡されているこの重大な脆弱性 を公表し 、その際、このセキュリティホールが「限定的かつ標的を絞った悪用を受けている可能性がある」と警告した。つまり、Googleが問題を修正する前に、悪意のある人物がこのバグを発見し、悪用していたということだ。」

theregister.com/security/2026/

#prattohome

##

ottoto2017@prattohome.com at 2026-09-17T04:40:19.000Z ##

「Google、限定的な標的型攻撃の兆候が見られる中、Pixelモデムの脆弱性を修正 」: #TheHackerNews

「Googleは、 明らかにした。 同社のPixel Cellular Modemに存在する深刻なセキュリティ上の欠陥が、実際に悪用されていることを

(CVSSスコア:8.0)として追跡されているこの脆弱性は CVE-2026-58704 、権限昇格の欠陥です。

によると、「セルラーモデムには、コードの論理エラーにより権限がバイパスされる可能性がある」とのことです NIST(米国国立標準技術研究所)の国家脆弱性データベース(NVD)に掲載されているバグの説明 。「これにより、追加の実行権限を必要とせずに、リモート(近接/隣接)での権限昇格が可能になる可能性がある。悪用にはユーザーの操作は不要である。」 」

thehackernews.com/2026/09/goog

#prattohome

##

DarkWebInformer@infosec.exchange at 2026-09-17T17:33:47.000Z ##

🚨 Google confirms Pixel phones targeted in zero-click zero-day attacks

Google has patched CVE-2026-58704, a high-severity vulnerability in Pixel phones' cellular modem that the company says was already under "limited, targeted exploitation."

The flaw is caused by a logic error that can allow an attacker to bypass permission checks and escalate privileges beyond the modem's isolated environment.

Most importantly, exploitation requires no interaction from the victim.

No malicious link needs to be clicked and no file needs to be opened, making it a zero-click attack.

Google has not disclosed:

• Who carried out the attacks
• How many Pixel owners were targeted
• How the victims were selected
• What tools or spyware may have been deployed

CISA has added CVE-2026-58704 to its Known Exploited Vulnerabilities catalog and set a September 19 remediation deadline for affected federal systems.

Google says Pixel devices with the September 5, 2026 security patch level or later are protected.

Pixel owners should update their devices immediately.

Source: techcrunch.com/2026/09/16/goog

##

beyondmachines1@infosec.exchange at 2026-09-17T13:01:13.000Z ##

Google Patches Pixel Modem Zero-Day Exploited in Targeted Attacks

Google's September 2026 update for Pixel devices fixes 110 vulnerabilities, including a high-severity modem flaw (CVE-2026-58704) that attackers are actively exploiting to escalate privileges without user interaction.

**Update your Pixel devices to the September 2026 patch level ASAP to block an active modem exploit and patch a huge set of issues.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

ottoto2017@prattohome.com at 2026-09-17T04:56:11.000Z ##

「Google Pixel端末がゼロクリック攻撃でハッキングされる
/CISAは連邦政府機関に対し、パッチ適用にわずか3日間しか猶予を与えていない。 」: #TheRegister

「Googleと米国政府は、Pixelスマートフォンの携帯モデムに存在するゼロデイ脆弱性を悪用した攻撃者が、権限チェックを回避し、ユーザーの操作なしに権限を昇格できると警告した。この脆弱性は、アップデートを行うことで既に修正されている。

Googleは 火曜日に、 CVE-2026-58704 として追跡されているこの重大な脆弱性 を公表し 、その際、このセキュリティホールが「限定的かつ標的を絞った悪用を受けている可能性がある」と警告した。つまり、Googleが問題を修正する前に、悪意のある人物がこのバグを発見し、悪用していたということだ。」

theregister.com/security/2026/

#prattohome

##

ottoto2017@prattohome.com at 2026-09-17T04:40:19.000Z ##

「Google、限定的な標的型攻撃の兆候が見られる中、Pixelモデムの脆弱性を修正 」: #TheHackerNews

「Googleは、 明らかにした。 同社のPixel Cellular Modemに存在する深刻なセキュリティ上の欠陥が、実際に悪用されていることを

(CVSSスコア:8.0)として追跡されているこの脆弱性は CVE-2026-58704 、権限昇格の欠陥です。

によると、「セルラーモデムには、コードの論理エラーにより権限がバイパスされる可能性がある」とのことです NIST(米国国立標準技術研究所)の国家脆弱性データベース(NVD)に掲載されているバグの説明 。「これにより、追加の実行権限を必要とせずに、リモート(近接/隣接)での権限昇格が可能になる可能性がある。悪用にはユーザーの操作は不要である。」 」

thehackernews.com/2026/09/goog

#prattohome

##

DailyCyberSecurity@infosec.exchange at 2026-09-17T04:07:33.000Z ##

Google confirmed a Pixel modem zero-day (CVE-2026-58704) exploited in a zero-click spyware attack to escape the modem sandbox. Update now.

#Pixel #ZeroDay #CVE202658704 #Google #Spyware #ZeroClick #CyberSecurity

securityexpress.info/pixel-mod

##

thecybermind@infosec.exchange at 2026-09-16T21:31:34.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-58704 – Google Pixel Improper Authorization Vulnerability

A strategic executive briefing detailing governance, risk mitigation, and compliance frameworks for CVE-2026-58704 on Google Pixel mobile devices....

thecybermind.co/h86g

##

simonzerafa@infosec.exchange at 2026-09-16T21:27:45.000Z ##

Google and CISA warned that an actively exploited zero-day vulnerability (CVE-2026-58704) affecting Pixel cellular modems.

This allows attackers to silently bypass permission checks and escalate privileges with no user interaction!

It was quickly added to CISA's Known Exploited Vulnerabilities (KEV) catalog [1.2.1, 1.5.1].

Would be an excellent idea for Pixel owners to ownload and apply the September Android OS patches ASAP!

#Google #PixelPhone #ZeroDay #Exploit

##

thecybermind@infosec.exchange at 2026-09-16T20:58:59.000Z ##

(CISA TS-MAN) The Cyber Mind TSUITE Brief: CVE-2026-58704 – Google Pixel Improper Authorization Vulnerability

Actionable threat intelligence and end-to-end hardening strategies for CVE-2026-58704, addressing improper authorization flaws in Google Pixel cellular modems....

thecybermind.co/iuw6

##

cyberworldops@infosec.exchange at 2026-09-16T16:50:00.000Z ##

Google patched CVE-2026-58704, a high-severity Pixel Cellular Modem privilege-escalation flaw reportedly exploited in limited, targeted attacks. Its addition to CISA’s KEV Catalog underscores the need to prioritize affected device updates. #ZeroDay #MobileSecurity #ThreatIntelligence

cyberworldops.eu/en/google-pat

##

AAKL@infosec.exchange at 2026-09-16T16:26:50.000Z ##

New.

Press release: New CISA Guidance Helps Critical Infrastructure Detect, Observe and Impede Malicious Cyber Activity cisa.gov/news-events/news/new-

The guide: Using Cyber Decoys to Strengthen Detection and Response cisa.gov/resources-tools/resou

CISA has also added one vulnerability to the catalogue.

CVE-2026-58704: Google Pixel Improper Authorization Vulnerability cve.org/CVERecord?id=CVE-2026- #Google #infosec #vulnerability #CISA

##

security_crawler_carl@infosec.exchange at 2026-09-16T16:14:16.000Z ##

🏆 New Achievement! Tutorial: Learning to Live With Being Actively Exploited!

Welcome to the Mandatory Pixel Debuff Sequence. Before you proceed, please note that CVE-2026-58704 has been equipped to your device without your consent. This is a zero-day — that means the tutorial boss was already in your pocket before the level loaded. (1/3)

##

secdb@infosec.exchange at 2026-09-16T15:01:11.000Z ##

🚨 [CISA-2026:0916] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-58704 (secdb.nttzen.cloud/cve/detail/)
- Name: Google Pixel Improper Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Pixel
- Notes: source.android.com/docs/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260916 #cisa20260916 #cve_2026_58704 #cve202658704

##

rogeragrimes@infosec.exchange at 2026-09-16T14:56:00.000Z ##

If you've got a Google Pixel cell phone, do a system patch immediately. There is an active vulnerability that allows the hacker to take control of your device with no user interaction. It is being actively used in the wild.

cve.org/CVERecord?id=CVE-2026-

##

tugatech@masto.pt at 2026-09-16T14:31:09.000Z ##

Google corrige falha zero-day em telemóveis Pixel com atualização que resolve 110 vulnerabilidades. A falha, identificada como CVE-2026-58704, está a ser explorada em ataques direcionados de alcance limitado. 📱

🔗 tugatech.com.pt/t91149-google-

#falha #google #pixel 

##

cisakevtracker@mastodon.social at 2026-09-16T14:01:08.000Z ##

CVE ID: CVE-2026-58704
Vendor: Google
Product: Pixel
Date Added: 2026-09-16
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

GrapheneOS@grapheneos.social at 2026-09-16T12:36:14.000Z ##

@skyblitz CVE-2026-58704 is a modem firmware vulnerability with a patch released today and it will be included in our upcoming release.

##

skyblitz@ieji.de at 2026-09-16T12:00:11.000Z ##

@GrapheneOS funny to see google fixing : CVE-2025-48595 that was fixed looooooong ago in your.

i don't see CVE-2026-58704, is it already fixed ?

bleepingcomputer.com/news/secu

##

CVE-2026-88065
(7.5 HIGH)

EPSS: 0.37%

updated 2026-09-16T14:17:12.413000

1 posts

`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions prior to 2.1.0 have a Broken Access Control vulnerability across several API endpoints (such as `/api/student/{id}/photo` and `/api/course_unit/{id}/exchange/metadata`). By chaining these unauthenticated endpoints, a remote attacker can use the backend as an open proxy to bypass

thehackerwire@mastodon.social at 2026-09-15T22:00:50.000Z ##

🟠 CVE-2026-88065 - High (7.5)

`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions prior to 2.1.0 have a Broken Access Control vulnerability across several API endpoints (such as `/api/student/{id}/photo` and `...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-27565
(9.8 CRITICAL)

EPSS: 0.94%

updated 2026-09-16T09:30:35

4 posts

An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot.

DailyCyberSecurity@infosec.exchange at 2026-09-16T09:48:49.000Z ##

Patch critical industrial firmware vulnerabilities and authentication bypass flaws like CVE-2026-27565 in Pepperl+Fuchs, Phoenix Contact & Carlo Gavazzi.

#IndustrialSecurity #FirmwareFlaws #Cybersecurity #CVE202627565 #InfoSec

securityonline.info/industrial

##

certvde@infosec.exchange at 2026-09-16T07:58:13.000Z ##

🔒 New CSAF advisory published

VDE-2026-028
Carlo Gavazzi Automation: YL212* and YN115* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: gavazziautomation.csaf-tp.cert

#OT #Advisory

##

certvde@infosec.exchange at 2026-09-16T07:57:36.000Z ##

🔒 New CSAF advisory published

VDE-2026-027
Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices is affected by security vulnerab…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: phoenixcontact.csaf-tp.certvde

#OT #Advisory

##

certvde@infosec.exchange at 2026-09-16T07:56:58.000Z ##

🔒 New CSAF advisory published

VDE-2026-014
Pepperl+Fuchs: ICE2-* and ICE3-* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be execute…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: pepperl-fuchs.csaf-tp.certvde.

#OT #Advisory

##

CVE-2026-27563
(7.2 HIGH)

EPSS: 2.02%

updated 2026-09-16T09:30:35

3 posts

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.

certvde@infosec.exchange at 2026-09-16T07:58:13.000Z ##

🔒 New CSAF advisory published

VDE-2026-028
Carlo Gavazzi Automation: YL212* and YN115* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: gavazziautomation.csaf-tp.cert

#OT #Advisory

##

certvde@infosec.exchange at 2026-09-16T07:57:36.000Z ##

🔒 New CSAF advisory published

VDE-2026-027
Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices is affected by security vulnerab…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: phoenixcontact.csaf-tp.certvde

#OT #Advisory

##

certvde@infosec.exchange at 2026-09-16T07:56:58.000Z ##

🔒 New CSAF advisory published

VDE-2026-014
Pepperl+Fuchs: ICE2-* and ICE3-* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be execute…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: pepperl-fuchs.csaf-tp.certvde.

#OT #Advisory

##

CVE-2026-27562
(7.2 HIGH)

EPSS: 2.23%

updated 2026-09-16T09:30:34

3 posts

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution of commands with root privileges on the device.

certvde@infosec.exchange at 2026-09-16T07:58:13.000Z ##

🔒 New CSAF advisory published

VDE-2026-028
Carlo Gavazzi Automation: YL212* and YN115* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: gavazziautomation.csaf-tp.cert

#OT #Advisory

##

certvde@infosec.exchange at 2026-09-16T07:57:36.000Z ##

🔒 New CSAF advisory published

VDE-2026-027
Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices is affected by security vulnerab…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: phoenixcontact.csaf-tp.certvde

#OT #Advisory

##

certvde@infosec.exchange at 2026-09-16T07:56:58.000Z ##

🔒 New CSAF advisory published

VDE-2026-014
Pepperl+Fuchs: ICE2-* and ICE3-* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be execute…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: pepperl-fuchs.csaf-tp.certvde.

#OT #Advisory

##

CVE-2026-81642(CVSS UNKNOWN)

EPSS: 0.52%

updated 2026-09-16T09:30:28

5 posts

In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression pointer to its own RDATA can overflow the digest buffer. Remote code execution is possible through attacker controlled data. An adversary can exploit the vulnerabili

1 repos

https://github.com/suominen/CVE-2026-81642

undercodenews@mastodon.social at 2026-09-18T00:02:32.000Z ##

Critical Unbound DNSSEC Flaw Opens a Dangerous Path to Remote Code Execution + Video

Critical Unbound DNSSEC Flaw Could Turn a Malicious DNS Zone Into a Remote Code Execution Gateway A Critical Weakness Hidden Inside DNS Validation A critical security flaw in the Unbound DNS resolver has placed organizations running older versions under serious patching pressure. Tracked as CVE-2026-81642, the vulnerability is a heap buffer overflow in Unbound's DNSSEC validation…

undercodenews.com/critical-unb

##

cyberworldops at 2026-09-17T20:30:00.629Z ##

NLnet Labs Unbound before 1.26.1 contains heap overflow CVE-2026-81642 in the DNSSEC validator via crafted DNSKEY with compression pointer into RDATA. Any resolver induced to query a malicious zone risks crash or potential RCE, exposing core DNS infrastructure.

cyberworldops.eu/en/unbound-dn

##

Analyst207@mastodon.social at 2026-09-17T14:03:25.000Z ##

Unbound DNSSEC Validator Flaw Enables Remote Code Execution

A critical flaw in the Unbound DNSSEC Validator, known as CVE-2026-81642, allows attackers to trigger a heap overflow, potentially enabling remote code execution on vulnerable systems. This vulnerability affects all Unbound DNS resolver releases before 1.26.1, putting countless systems at risk.

osintsights.com/unbound-dnssec

#DnssecValidatorFlaw #RemoteCodeExecution #Cve202681642 #Unbound #HeapOverflow

##

cyberworldops@infosec.exchange at 2026-09-17T20:30:00.000Z ##

NLnet Labs Unbound before 1.26.1 contains heap overflow CVE-2026-81642 in the DNSSEC validator via crafted DNSKEY with compression pointer into RDATA. Any resolver induced to query a malicious zone risks crash or potential RCE, exposing core DNS infrastructure. #Unbound #DnsSec #HeapOverflow

cyberworldops.eu/en/unbound-dn

##

offseq@infosec.exchange at 2026-09-16T09:00:26.000Z ##

CVE-2026-81642: CRITICAL heap buffer overflow in NLnet Labs Unbound ≤1.26.0. Exploitable via DNSKEY with owner compression pointer — possible DoS & RCE. Patch ASAP. radar.offseq.com/threat/cve-20 #OffSeq #DNS #Unbound #Vuln #RCE

##

CVE-2026-14349
(9.8 CRITICAL)

EPSS: 0.42%

updated 2026-09-16T06:31:34

1 posts

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the email address of arbitrary user accounts, including administrators, which

offseq@infosec.exchange at 2026-09-16T06:00:25.000Z ##

TrueBooker (<=1.2.3) WordPress plugin hit by CVE-2026-14349 (CRITICAL, CVSS 9.8): missing auth lets unauthenticated attackers change user emails & reset passwords. No patch yet — restrict access & monitor! radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202614349 #AppSec

##

CVE-2026-79994(CVSS UNKNOWN)

EPSS: 0.11%

updated 2026-09-16T00:32:32

1 posts

The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname. A malicious guest can replace an intermediate directory with a symlink between validation and connection, causing the host to connect to an arbitrary AF_UNIX socket outside the shared workspace. This can expose data or host-side cap

DailyCyberSecurity@infosec.exchange at 2026-09-17T02:33:27.000Z ##

Docker released an update for critical Docker Sandboxes vulnerabilities (CVE-2026-77179, CVE-2026-79994). Patch these Docker Sandboxes vulnerabilities today.

#Docker #DockerSandboxes #CVE202677179 #CVE202679994 #Cybersecurity

securityonline.info/docker-san

##

CVE-2026-85893
(8.8 HIGH)

EPSS: 0.68%

updated 2026-09-16T00:31:42

1 posts

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

thehackerwire@mastodon.social at 2026-09-16T00:00:00.000Z ##

🟠 CVE-2026-85893 - High (8.8)

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15640(CVSS UNKNOWN)

EPSS: 0.28%

updated 2026-09-16T00:31:41

2 posts

Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.

cR0w@infosec.exchange at 2026-09-16T14:17:30.000Z ##

Go hack more Secret Server shit.

delinea.com/security-advisories

Authentication Bypass via SAML Response Manipulation - CVE-2026-15640

Reflected Cross-Site Scripting - CVE-2026-15639

Cryptographic Padding Oracle - CVE-2026-15638

##

offseq@infosec.exchange at 2026-09-16T01:30:23.000Z ##

Delinea Secret Server (On-Prem, v10.5.0 – 12.1.3) hit by CRITICAL auth bypass (CVE-2026-15640). SAML spoofing may allow attacker impersonation. Patch info not yet available. Details: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Delinea #CVE202615640

##

CVE-2026-92248
(7.8 HIGH)

EPSS: 0.18%

updated 2026-09-16T00:31:36

1 posts

A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header. This leads to an undersized heap allocation, resulting in a heap-based buffer overflow when the image data is decoded. This buffer overflow corrupts adjacent hea

thehackerwire@mastodon.social at 2026-09-16T00:00:19.000Z ##

🟠 CVE-2026-92248 - High (7.8)

A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header. This lea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73807
(9.8 CRITICAL)

EPSS: 0.65%

updated 2026-09-16T00:31:35

2 posts

The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions.

DailyCyberSecurity@infosec.exchange at 2026-09-16T02:09:47.000Z ##

Discover the latest mySCADA myPRO Manager vulnerabilities, including CVE-2026-73807, and learn how to patch your systems to prevent remote attacks.

#mySCADA #CVE202673807 #Cybersecurity #Vulnerability

securityonline.info/myscada-my

##

offseq@infosec.exchange at 2026-09-16T00:00:36.000Z ##

CVE-2026-73807 | CRITICAL: mySCADA myPRO (v0 – 2.1) API flaw allows unauthenticated access to privileged functions. No patch yet — restrict API network access & monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #ICS #SCADA #Vulnerability

##

CVE-2026-15639(CVSS UNKNOWN)

EPSS: 0.39%

updated 2026-09-16T00:31:33

2 posts

An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker.

cR0w@infosec.exchange at 2026-09-16T14:17:30.000Z ##

Go hack more Secret Server shit.

delinea.com/security-advisories

Authentication Bypass via SAML Response Manipulation - CVE-2026-15640

Reflected Cross-Site Scripting - CVE-2026-15639

Cryptographic Padding Oracle - CVE-2026-15638

##

offseq@infosec.exchange at 2026-09-16T03:00:24.000Z ##

CVE-2026-15639: CRITICAL XSS in Delinea Secret Server (On-Prem, 10.2.19 – 11.9.48). Exploitation allows remote attackers to run JS in user sessions. Patch status unknown — check vendor advisories. radar.offseq.com/threat/cve-20 #OffSeq #XSS #Vuln #Delinea #Cybersecurity

##

CVE-2026-91939
(9.8 CRITICAL)

EPSS: 0.59%

updated 2026-09-15T21:33:15

1 posts

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted serialized payloads to trigger gadget chains and achieve database manipulation or code execution.

thehackerwire@mastodon.social at 2026-09-15T22:00:14.000Z ##

🔴 CVE-2026-91939 - Critical (9.8)

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92000
(7.5 HIGH)

EPSS: 0.39%

updated 2026-09-15T21:33:15

1 posts

adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory and cause denial of service.

thehackerwire@mastodon.social at 2026-09-15T22:00:04.000Z ##

🟠 CVE-2026-92000 - High (7.5)

adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68070
(8.8 HIGH)

EPSS: 0.27%

updated 2026-09-15T21:33:13

1 posts

The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command.

thehackerwire@mastodon.social at 2026-09-15T22:01:10.000Z ##

🟠 CVE-2026-68070 - High (8.8)

The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66890
(9.6 CRITICAL)

EPSS: 0.20%

updated 2026-09-15T21:33:13

1 posts

The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.

thehackerwire@mastodon.social at 2026-09-15T22:00:59.000Z ##

🔴 CVE-2026-66890 - Critical (9.6)

The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89040
(9.8 CRITICAL)

EPSS: 0.93%

updated 2026-09-15T21:33:13

1 posts

Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code as root.

thehackerwire@mastodon.social at 2026-09-15T21:00:33.000Z ##

🔴 CVE-2026-89040 - Critical (9.8)

Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code as root.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92179
(7.8 HIGH)

EPSS: 0.17%

updated 2026-09-15T21:31:29

1 posts

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of P

thehackerwire@mastodon.social at 2026-09-15T20:00:10.000Z ##

🟠 CVE-2026-92179 - High (7.8)

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92178
(7.8 HIGH)

EPSS: 0.17%

updated 2026-09-15T21:31:28

1 posts

pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF

thehackerwire@mastodon.social at 2026-09-15T19:59:59.000Z ##

🟠 CVE-2026-92178 - High (7.8)

pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92180
(7.8 HIGH)

EPSS: 0.14%

updated 2026-09-15T21:31:25

1 posts

pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architect. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific fl

thehackerwire@mastodon.social at 2026-09-15T20:02:40.000Z ##

🟠 CVE-2026-92180 - High (7.8)

pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-69213
(7.5 HIGH)

EPSS: 0.36%

updated 2026-09-15T20:00:36

1 posts

Ember's HTTP/2 connection serializes all outgoing frames through a single unbounded queue drained by one writer fiber (`writeLoop`). When the write side stalls, any frames the connection keeps producing accumulate in that queue without limit. The peer can drive this cheaply because the connection emits a control frame in response to inbound frames it does not flow-control: one `PING` ACK per `PI

thehackerwire@mastodon.social at 2026-09-15T20:03:00.000Z ##

🟠 CVE-2026-69213 - High (7.5)

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/2 serializes outbound frames through one unbounded queue consumed by writeLoop. When the peer stops reading, an unauthenticated HTTP/2 client can continue se...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20274
(9.8 CRITICAL)

EPSS: 0.73%

updated 2026-09-15T18:33:13

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20274 are related to improper resource control issues that are g

AAKL@infosec.exchange at 2026-09-15T15:50:22.000Z ##

Cisco has addressed a critical September 2 vulnerability.

CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi @TalosSecurity

More related to Cisco:

Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official #threatresearch #infosec #Cisco #vulnerability

##

CVE-2026-89026
(9.8 CRITICAL)

EPSS: 0.52%

updated 2026-09-15T18:32:43

3 posts

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System application parameter, c

1 repos

https://github.com/cflowsec/CVE-2026-89026

cyberworldops@infosec.exchange at 2026-09-17T04:30:00.000Z ##

Unauthenticated RCE in Issabel Framework (CVE-2026-89026) is being exploited in the wild. A hardcoded JWT secret in pbxapi/index.php allows token forgery and OS command execution as the Asterisk user, risking full PBX takeover. #Issabel #RemoteCodeExecution #InfoSec

cyberworldops.eu/en/one-shared

##

rxerium@infosec.exchange at 2026-09-15T18:03:42.000Z ##

Thank you to @vulncheck for the smooth collaboration throughout the CNA process.

More details:
cve.org/CVERecord?id=CVE-2026-

##

thehackerwire@mastodon.social at 2026-09-15T18:01:18.000Z ##

🔴 CVE-2026-89026 - Critical (9.8)

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91985
(7.5 HIGH)

EPSS: 0.38%

updated 2026-09-15T18:32:43

1 posts

Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the disclosed hash for a link-share JWT at the share's permission level to escalate privileges and perform unauthorized writes or administrative actions.

thehackerwire@mastodon.social at 2026-09-15T17:00:15.000Z ##

🟠 CVE-2026-91985 - High (7.5)

Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the disclosed hash for a link-share JWT ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91990
(7.5 HIGH)

EPSS: 0.41%

updated 2026-09-15T18:32:43

1 posts

Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create large transient lists, exhausting server memory and causing denial of service.

thehackerwire@mastodon.social at 2026-09-15T17:00:03.000Z ##

🟠 CVE-2026-91990 - High (7.5)

Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create large transie...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20276
(8.6 HIGH)

EPSS: 0.27%

updated 2026-09-15T18:32:13

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20276 are related to insufficient control flow management issues

AAKL@infosec.exchange at 2026-09-15T15:50:22.000Z ##

Cisco has addressed a critical September 2 vulnerability.

CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi @TalosSecurity

More related to Cisco:

Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official #threatresearch #infosec #Cisco #vulnerability

##

CVE-2026-63443
(8.3 HIGH)

EPSS: 0.42%

updated 2026-09-15T18:17:29.010000

1 posts

Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected request URL when the port is the workspace agent HTTP API port 4. An authenticated user who controls a modified workspace agent and knows another online agent's U

thehackerwire@mastodon.social at 2026-09-15T18:01:40.000Z ##

🟠 CVE-2026-63443 - High (8.3)

Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected request U...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20275
(8.8 HIGH)

EPSS: 0.19%

updated 2026-09-15T18:17:18.413000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20275 are related to incorrect calculation issues that are gro

AAKL@infosec.exchange at 2026-09-15T15:50:22.000Z ##

Cisco has addressed a critical September 2 vulnerability.

CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi @TalosSecurity

More related to Cisco:

Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official #threatresearch #infosec #Cisco #vulnerability

##

CVE-2026-63695
(9.8 CRITICAL)

EPSS: 0.53%

updated 2026-09-15T15:32:20

1 posts

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft.

thehackerwire@mastodon.social at 2026-09-15T16:01:02.000Z ##

🔴 CVE-2026-63695 - Critical (9.8)

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89025
(7.5 HIGH)

EPSS: 0.42%

updated 2026-09-15T15:32:20

1 posts

Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint that is processed incorrectly, causing the device to perform an unintended reboot and resulting in a temporary denial-of-service condition. T

thehackerwire@mastodon.social at 2026-09-15T16:00:52.000Z ##

🟠 CVE-2026-89025 - High (7.5)

Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specif...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-39919
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-09-15T15:17:14.723000

1 posts

Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 image with mismatched component subsampling factors. When image components declare different subsampling values, the non-samescale sub-byte-depth output path allocates

DailyCyberSecurity@infosec.exchange at 2026-09-17T02:20:05.000Z ##

A Ghostscript buffer overflow enables unauthenticated remote code execution. Patch this Ghostscript buffer overflow flaw (CVE-2026-39919) immediately.

#Ghostscript #CVE202639919 #RemoteCodeExecution #Cybersecurity #InfoSec

securityonline.info/ghostscrip

##

CVE-2026-81915
(0 None)

EPSS: 0.37%

updated 2026-09-15T14:40:24.370000

1 posts

Concrete CMS below 9.5.3 does not perform an object-level authorization check when a Page Type was updated. The Types::submit() dashboard controller loaded and saved the Page Type identified by a user-supplied ptID without calling canEditPageType(), so a signed-in dashboard user permitted to edit one Page Type could modify the configuration of Page Types outside their assigned authorization bounda

hugovalters@mastodon.social at 2026-09-17T21:10:08.000Z ##

CVE-2026-81915 Concrete CMS below 9.5.3: broken object-level authz lets any dashboard user edit Page Types outside their scope. CVSS N/A, patch status unknown. Update immediately. valtersit.com/cve/CVE-2026-819 #CVE #infosec #ConcreteCMS

##

CVE-2026-89308
(0 None)

EPSS: 2.97%

updated 2026-09-15T13:16:45.543000

1 posts

An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to execute arbitrary commands on the underlying operating system and achieve remote code execution.

offseq@infosec.exchange at 2026-09-15T12:00:26.000Z ##

CVE-2026-89308 in TREXOM TrxTimeATTENDANCE (v1.0.5 – 1.9.5): CRITICAL OS command injection in ping.php allows unauthenticated RCE. Remediate ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE202689308 #infosec #vuln #remediation

##

CVE-2026-76461
(9.8 CRITICAL)

EPSS: 2.01%

updated 2026-09-15T12:47:32.497000

12 posts

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that co

4 repos

https://github.com/S3v3n-JG/CVE-2026-76461

https://github.com/HORKimhab/CVE-2026-76461

https://github.com/0xBlackash/CVE-2026-76461

https://github.com/fevar54/CVE-2026-76461-Detection-Kit-

PC_Fluesterer@social.tchncs.de at 2026-09-17T13:30:04.000Z ##

Cisco Zero-Day wird aktiv angegriffen

Mal was neues - ach nein, Hintertüren bei Cisco sind ja gar nicht neu, sondern schon fast Gewohnheit. Am Montag hat die Firma ihre Kunden informiert, dass im Secure Email Gateway (SEG) eine Sicherheitslücke steckt, die bereits aktiv angegriffen wird. Dabei ist gleichgültig, ob das SEG auf eigener Hardware (Appliance) läuft oder als virtuelle Maschine oder Cloud-Dienst. Auch die Konfiguration des SEG macht keinen Unterschied. Das muss man sich mal auf der Zunge zergehen lassen: Das SEG, das vor schädlichen E-Mails schützen soll, kann durch genau solche angegriffen werden! Die Sicherheitslücke CVE-2026-76461 ... Weiterlesen:

pc-fluesterer.info/wordpress/2

#0day #backdoor #closedsource #email #exploits #hersteller #sicherheit #UnplugTrump #zeroday #cisco

##

security_crawler_carl@infosec.exchange at 2026-09-16T23:37:29.000Z ##

🏆 New Achievement! Root Access? We'll Get That Escalated for You!

Your ticket has been received. We see you're experiencing an issue where an unauthenticated attacker is executing arbitrary commands with root privileges on your Cisco Secure Email Gateway via CVE-2026-76461. Great news: we've reproduced the bug! It's the email parsing in Cisco AsyncOS — sending a specially crafted email with malicious SQL statements is all it takes. (1/3)

##

youranonnewsirc@nerdculture.de at 2026-09-16T16:26:20.000Z ##

Recent developments include Cisco patching a critical zero-day (CVE-2026-76461) in its Secure Email Gateway, which was actively exploited for root command execution. Geopolitically, China warned against weaponizing space after the US confirmed orbital weapon deployments. In technology, debates continue on AI safety versus national competitive advantage, with US Speaker Johnson rejecting development pauses.

#Cybersecurity #Geopolitics #AnonNews_irc

##

youranonnewsirc@nerdculture.de at 2026-09-16T10:26:27.000Z ##

Global cybersecurity agencies, including CISA & NSA, issued guidance to mitigate 17 Active Directory compromise techniques (Sept 16). Cisco patched an actively exploited email gateway zero-day (CVE-2026-76461). Geopolitically, the US confirmed deploying space weapons, drawing warnings from China about an arms race (Sept 15). AI is now the leading driver for new cybersecurity spending.

#Cybersecurity #Geopolitics #TechNews

##

DailyCyberSecurity@infosec.exchange at 2026-09-16T06:17:38.000Z ##

A critical Cisco Secure Email Gateway vulnerability allows unauthenticated attackers to gain root access via a single email. Learn about CVE-2026-76461.

#Cisco #EmailGateway #CyberSecurity #ZeroDay #Vulnerability

meterpreter.org/cisco-secure-e

##

threatnoir@infosec.exchange at 2026-09-16T02:05:58.000Z ##

⚠️ CRITICAL: Cisco warns customers of actively exploited zero-day in email gateways

Cisco Secure Email Gateway contains a critical unauthenticated root privilege escalation vulnerability (CVE-2026-76461) that was actively exploited in the wild before patches were available. Multiple customers are likely already compromised. This is now tracked in CISA's Known Exploited Vulnerabili…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

threatnoir@infosec.exchange at 2026-09-16T02:05:54.000Z ##

⚠️ CRITICAL: Cisco patches Secure Email Gateway zero-day exploited in attacks

Cisco Secure Email Gateway has a critical zero-day (CVE-2026-76461) that allows unauthenticated attackers to execute arbitrary commands as root via malicious SQL in crafted emails. This is actively exploited in the wild. Any organization running SEG is at immediate risk of full compromise.

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

youranonnewsirc@nerdculture.de at 2026-09-15T16:26:27.000Z ##

Geopolitical tensions: A Russian drone struck a Kyiv-Warsaw train near the Polish border (Sept 13), and Houthi forces secured Yemen's Red Sea coast (Sept 11), affecting maritime routes. Tech news: Apple's Siri AI, powered by Apple Intelligence, began its beta rollout (Sept 14). Cybersecurity: Cisco warned of active exploitation of a critical Secure Email Gateway flaw (CVE-2026-76461) (Sept 15), and Anthropic reported Russia-linked spies used its AI Claude for hacking campaigns.

#Cybersecurity #Geopolitics #TechNews

##

thecybermind@infosec.exchange at 2026-09-15T16:25:35.000Z ##

Actionable C-Suite threat intelligence and mitigation strategies for CVE-2026-76461, addressing active SQL injection exploitation vectors within enterprise Cisco Secure Email Gateway infrastructures. thecybermind.co/r5ry

##

AAKL@infosec.exchange at 2026-09-15T15:50:22.000Z ##

Cisco has addressed a critical September 2 vulnerability.

CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi @TalosSecurity

More related to Cisco:

Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official #threatresearch #infosec #Cisco #vulnerability

##

cyberveille@mastobot.ping.moi at 2026-09-15T09:00:06.000Z ##

📢 [VULN] ⚠️Injection SQL exploitée dans Cisco Secure Email Gateway - CVE-2026-76461

Le 14 septembre 2026 à 16 h 00 UTC, Cisco a publié deux avis de sécurité sur sa passerelle de messagerie.

🔗 blog.marcfredericgomez.fr/inje
💬 discussion : infosec.pub/post/52317366
#CVE #Cyberveille

##

ottoto2017@prattohome.com at 2026-09-15T08:14:44.000Z ##

「Ciscoのセキュアメールゲートウェイの脆弱性が実際に悪用され、ルート権限でのコマンド実行が可能になる 」: #TheHackerNews

「スコは、Cisco Secure Email Gateway向けAsyncOSソフトウェアに影響を与える新たな重大な脆弱性が、実際に悪用されていると警告した。

CVE-2026-76461 として追跡されているこの脆弱性は 、CVSSスコアが10.0点満点中9.8点です。これは、メール解析ロジックにおける検証の不備が原因で、認証されていないリモート攻撃者が、基盤となるオペレーティングシステム上でroot権限で任意のコマンドを実行できる可能性があるとされています。

シスコは月曜日の勧告で、「攻撃者は、悪意のあるSQL文を含む細工された電子メールメッセージを影響を受けるデバイスに送信することで、この脆弱性を悪用する可能性がある」 と述べた 。」

thehackernews.com/2026/09/cisc

#prattohome

##

CVE-2026-91995
(9.1 CRITICAL)

EPSS: 0.61%

updated 2026-09-15T12:31:54

1 posts

pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password. Remote attackers can submit a username with an incorrect current password to overwrite any account credential including the admin account and gain full administrative control.

offseq@infosec.exchange at 2026-09-15T13:30:26.000Z ##

pig-mesh pig <4.1.0 hit by CRITICAL vuln (CVE-2026-91995, CVSS 9.3): remote attackers can reset any account password — admin included — via /register/password auth bypass. Restrict access & monitor logs while awaiting patch. radar.offseq.com/threat/cve-20 #OffSeq #vulnerability #CVE #infosec

##

CVE-2026-77853
(8.8 HIGH)

EPSS: 1.03%

updated 2026-09-15T09:30:39

1 posts

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands.

thehackerwire@mastodon.social at 2026-09-15T10:03:52.000Z ##

🟠 CVE-2026-77853 - High (8.8)

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91001
(9.9 CRITICAL)

EPSS: 0.48%

updated 2026-09-15T06:30:39

1 posts

A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

thehackerwire@mastodon.social at 2026-09-15T10:04:12.000Z ##

🔴 CVE-2026-91001 - Critical (9.9)

A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip results in stac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12944
(9.6 CRITICAL)

EPSS: 0.25%

updated 2026-09-15T00:31:21

1 posts

IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via IMDSv1 SSRF with full IAM role permissions, (2) arbitrary file exfiltration from the container filesystem, and (3) lateral movement to internal services

2 repos

https://github.com/ShadowForge-Cyber/CVE-2026-12944

https://github.com/cflowsec/CVE-2026-12944

DailyCyberSecurity@infosec.exchange at 2026-09-16T01:03:01.000Z ##

A critical Langflow SSRF flaw (CVE-2026-12944) exposes cloud credentials and internal networks. Patch your Langflow OSS servers immediately.

#Langflow #SSRF #CVE202612944 #CVE202617628 #Cybersecurity

securityonline.info/langflow-s

##

CVE-2026-65352
(4.3 MEDIUM)

EPSS: 0.25%

updated 2026-09-15T00:31:13

1 posts

An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 26.6.1. A website may be able to determine a user's IP address with Private Relay turned on.

mysk@mastodon.social at 2026-09-15T14:41:27.000Z ##

Apple acknowledges fixing the Private Relay bug leaking the IP in the secure release notes of iOS 26.6.1 and macOS 26.6.2.
CVE-2026-65352 was assigned to it

##

CVE-2026-82232
(9.8 CRITICAL)

EPSS: 0.56%

updated 2026-09-14T21:32:45

1 posts

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort clauses for Task search. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2

DailyCyberSecurity@infosec.exchange at 2026-09-16T01:52:03.000Z ##

Six Apache Syncope vulnerabilities, including CVE-2026-82232, expose severe identity management flaws. Patch your Apache Syncope servers immediately.

#ApacheSyncope #IdentityManagement #CVE202682232 #Cybersecurity #Vulnerability

securityonline.info/apache-syn

##

CVE-2026-78159
(9.8 CRITICAL)

EPSS: 0.76%

updated 2026-09-14T17:17:51.410000

1 posts

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and reach the callable-invocation sink in Element_Classes::parse_array(). This makes it p

offseq@infosec.exchange at 2026-09-16T12:00:26.000Z ##

CRITICAL: The Events Calendar WP plugin (<6.17.4.1) has two unauthenticated RCEs — CVE-2026-78159 (code injection) & CVE-2026-78006 (object injection, comments enabled). 240K+ sites at risk. Update now: radar.offseq.com/threat/unauth #OffSeq #WordPress #RCE #Vuln

##

CVE-2026-81005(CVSS UNKNOWN)

EPSS: 0.18%

updated 2026-09-14T15:33:28

3 posts

In the Linux kernel, the following vulnerability has been resolved: ipmi: si: Fix NULL pointer dereference after failed registration try_smi_init() allocates new_smi->si_sm and later calls ipmi_register_smi_mod(), which maps to ipmi_add_smi(). During ipmi_add_smi(), the upper IPMI message handler obtains the initial BMC device information through __bmc_get_device_id(). This can fail if the BMC

hugovalters@mastodon.social at 2026-09-17T08:40:00.000Z ##

CVE-2026-81005 Linux kernel NULL pointer dereference in ipmi_si after failed SMI registration. CVSS N/A. Unpatched. A BMC that fails Get Device ID can crash the kernel. Patch now. valtersit.com/cve/CVE-2026-810 #CVE #Linux #infosec

##

NyxKai@ieji.de at 2026-09-17T08:48:16.000Z ##

@hugovalters Thanks for flagging CVE-2026-81005. This NULL pointer dereference in ipmi_si is nasty — BMC failure during Get Device ID shouldn't crash the kernel. Mitigation: disable ipmi_si module if BMC is unresponsive (modprobe -r ipmi_si) or ensure ipmi_si.force_kipmi=0 to avoid kernel thread hang. Patch backports likely in stable kernel queue. #infosec #Linux #CVE

##

hugovalters@mastodon.social at 2026-09-17T08:40:00.000Z ##

CVE-2026-81005 Linux kernel NULL pointer dereference in ipmi_si after failed SMI registration. CVSS N/A. Unpatched. A BMC that fails Get Device ID can crash the kernel. Patch now. valtersit.com/cve/CVE-2026-810 #CVE #Linux #infosec

##

CVE-2026-81000
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-14T15:33:28

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: tun: bound receive headroom tun_get_user() uses tun->align both as skb headroom and when choosing how much packet data to keep linear. OVS can propagate an oversized headroom request from another port to TUN or TAP. When align is larger than the usable space in a one-page skb head, SKB_MAX_HEAD(align) underflows and the re

hugovalters@mastodon.social at 2026-09-17T05:30:20.000Z ##

CVE-2026-81000 Linux kernel tun driver integer underflow in tun_get_user() via oversized headroom from OVS, leading to memory corruption. No CVSS assigned, patch status unpatched. Apply kernel updates now. valtersit.com/cve/CVE-2026-810 #CVE #Linux #infosec

##

CVE-2026-80967
(8.4 HIGH)

EPSS: 0.18%

updated 2026-09-14T15:33:27

1 posts

In the Linux kernel, the following vulnerability has been resolved: ALSA: pcxhr: initialize mutexes before requesting threaded IRQ pcxhr_probe() requests pcxhr_threaded_irq() before initializing mgr->lock, even though the threaded handler takes that mutex. Initialize the manager locks before request_threaded_irq() so an early interrupt cannot run against uninitialized mutex state during probe.

hugovalters@mastodon.social at 2026-09-18T01:30:03.000Z ##

CVE-2026-80967 Linux ALSA pcxhr: mutexes initialized after threaded IRQ request, risking uninitialized lock state during probe. Patch status unknown. Update your kernel now. valtersit.com/cve/CVE-2026-809 #CVE #infosec #Linux

##

CVE-2026-80952
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-14T15:33:27

1 posts

In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix info leak and UAF in device unregister path i3c_master_unregister_i3c_devs() clears i3cdev->dev->desc before calling device_unregister(). During device_unregister(), device_del() emits a KOBJ_REMOVE uevent and unbinds the driver while the device descriptor is still expected to be valid. As a result, i3c_device

hugovalters@mastodon.social at 2026-09-17T15:00:02.000Z ##

CVE-2026-80952 Linux kernel i3c UAF and info leak in device unregister path, CVSS N/A, patch status unknown. Assume unpatched. Patch now: valtersit.com/cve/CVE-2026-809 #CVE #infosec #Linux

##

CVE-2026-89483
(7.5 HIGH)

EPSS: 0.56%

updated 2026-09-14T15:32:26

1 posts

In the Linux kernel, the following vulnerability has been resolved: nvme: zero the discard fallback page nvme_setup_discard() always maps sizeof(struct nvme_dsm_range) * NVME_DSM_MAX_RANGES = 4096 bytes as the DSM payload however many ranges the command declares, because some devices ignore the 'Number of Ranges' field - the Fixes: commit records two that read past the declared ranges. A single-

hugovalters@mastodon.social at 2026-09-17T13:20:02.000Z ##

CVE-2026-89483 Linux kernel nvme discard: uninitialized page read leaks 4080 bytes of stale kernel memory to devices. CVSS N/A, patch status unknown. Update kernel now if you run nvme. valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-80982
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-14T15:32:22

1 posts

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix use-after-free in smc_rx_pipe_buf_release() smc_rx_splice() hands RMB pages to a pipe and takes a socket reference per entry so the smc_sock stays alive until the reader finishes. The connection does not: a concurrent close runs smc_conn_free(), which releases the receive buffer back to the link group pool. smc_rx_

hugovalters@mastodon.social at 2026-09-17T18:10:01.000Z ##

CVE-2026-80982 Linux net/smc use-after-free in smc_rx_pipe_buf_release(), patch status unknown, CVSS not assigned. Unpatched kernel race can crash or corrupt memory. Update immediately. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-80938(CVSS UNKNOWN)

EPSS: 0.17%

updated 2026-09-14T15:32:20

1 posts

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex mt7615_suspend() acquired the mt76 mutex and then called cancel_delayed_work_sync() on mac_work. mt7615_mac_work() acquires the same mutex via mt7615_mutex_acquire() at the top of the worker, so if mac_work is already running and blocked on the mutex, the suspe

hugovalters@mastodon.social at 2026-09-17T16:30:03.000Z ##

CVE-2026-80938 Linux kernel mt7615 wifi deadlock in suspend path, MAC work vs mutex. No CVSS or patch yet. Watch for fixes. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-85706
(10.0 CRITICAL)

EPSS: 11.96%

updated 2026-09-14T14:22:15.323000

5 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

13 repos

https://github.com/0xenesbayram/cve-2026-85706

https://github.com/guneykabel/cve-2026-85706

https://github.com/0xlyvio/cve-2026-85706-poc-exploit-gitlab

https://github.com/gagaltotal/CVE-2026-85706-gitlab-poc

https://github.com/solivaquaant/CVE-2026-85706

https://github.com/brigadeops32/CVE-2026-85706

https://github.com/gabrielunknown/CVE-2026-85706

https://github.com/mhtsec/CVE-2026-85706

https://github.com/tc4dy/CVE-2026-85706-PoC-Toolkit

https://github.com/FlowerWitch/CVE-2026-85706_docker_exp

https://github.com/ynsmroztas/GitLabSniper

https://github.com/plur1bu5/gitread

https://github.com/jithinkrishnanrs/gitlab-cve-2026-85706-ioc

relayshieldadmin@infosec.exchange at 2026-09-16T18:20:40.000Z ##

GitLab CVE-2026-85706: unauth arbitrary file read, exploited in the wild, now on CISA KEV. Patch
19.3.2 / 19.2.6 / 19.1.8.
The 10.0 is about the read. The damage is the credentials inside the files, and a commits API
reads history, so secrets you deleted are still there.
Patch, hunt, THEN rotate. Rotating on a readable server hands over the new keys.
blog.relayshield.net/a-file-read-bug-is-a-credential-theft-bug
#GitLab #infosec #DevSecOps

##

thecybermind@infosec.exchange at 2026-09-16T05:37:00.000Z ##

Actionable C-Suite threat intelligence for CVE-2026-85706, covering active path traversal exploitation vectors, endpoint hardening, and patch automation across GitLab environments. thecybermind.co/uzke

##

DailyCyberSecurity@infosec.exchange at 2026-09-16T04:17:24.000Z ##

Learn why CISA added GitLab CVE-2026-85706 to the Known Exploited Vulnerabilities catalog. Discover how this CVSS 10 flaw allows remote secret extraction.

#GitLab #CVE202685706 #CISA #CyberSecurity #Vulnerability

meterpreter.org/gitlab-cve-202

##

censys@infosec.exchange at 2026-09-15T15:32:12.000Z ##

🚨 GitLab CVE-2026-85706 is a critical CVSS 10.0 vulnerability under active exploitation.
Censys sees 86K+ GitLab hosts on the Internet.

Patch immediately. If your instance was exposed while vulnerable, rotate credentials and investigate for compromise. censys.com/advisory/cve-2026-8

#GitLab #Cybersecurity #Vulnerability #CVE

##

benzogaga33@mamot.fr at 2026-09-15T09:20:04.000Z ##

Comment la faille de GitLab peut mettre à nu vos serveurs goodtech.info/gitlab-faille-cr #Développement #Revuedepresse #Sécurité

##

CVE-2026-89491
(0 None)

EPSS: 0.21%

updated 2026-09-14T13:19:06.090000

1 posts

In the Linux kernel, the following vulnerability has been resolved: ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin() Patch series "ocfs2: cluster: o2hb_region_pin() fixes", v2. This series fixes three related issues in o2hb_region_pin(), all are from the original implementation in commit: 58a3158a5d17 ("ocfs2/cluster: Pin/unpin o2hb regions"): 1) It is called with

hugovalters@mastodon.social at 2026-09-17T19:40:07.000Z ##

CVE-2026-89491 Linux kernel ocfs2 flaw: sleep while holding o2hb_live_lock in o2hb_region_pin(). CVSS N/A, patch status unknown. Update immediately. valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-89474
(0 None)

EPSS: 0.17%

updated 2026-09-14T13:19:03.733000

1 posts

In the Linux kernel, the following vulnerability has been resolved: power: supply: bq256xx: drain usb_work before freeing the charger The USB-PHY notifier queues usb_work, whose handler calls power_supply_changed(bq->charger). The reset devm action only unregisters the notifier and was registered before the power supplies, so devm frees bq->charger on unwind before the action runs; a usb_work st

hugovalters@mastodon.social at 2026-09-18T03:00:02.000Z ##

CVE-2026-89474 Linux kernel bq256xx use-after-free in power supply driver, USB work can run after charger freed. No CVSS, no patch yet. Audit and update kernel now. valtersit.com/cve/CVE-2026-894 #CVE #infosec #LinuxKernel

##

CVE-2026-89442
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-14T13:19:01.410000

1 posts

In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Validate socket ID in clos_assoc ioctl isst_if_clos_assoc() validates the user-supplied socket_id with 'socket_id > topology_max_packages()', but isst_common.sst_inst[] is allocated with topology_max_packages() entries, so the valid index range is [0, topology_max_packages()). The '>' comparison lets socket_

hugovalters@mastodon.social at 2026-09-18T03:30:25.000Z ##

CVE-2026-89442: out-of-bounds access in the Linux kernel ISST driver lets a bad socket ID index past sst_inst[]. No CVSS or patch yet. Treat as unpatched, restrict ioctl access. Details: valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-80983
(0 None)

EPSS: 0.17%

updated 2026-09-14T13:18:53.090000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix socket refcount leak in smc_switch_conns() smc_switch_conns() takes a reference on the SMC socket before dropping lgr->conns_lock, so the connection stays alive while the CDC slot is fetched: sock_hold(&smc->sk); read_unlock_bh(&lgr->conns_lock); /* pre-fetch buffer outside of send_lock, mig

hugovalters@mastodon.social at 2026-09-17T10:20:01.000Z ##

CVE-2026-80983 Linux kernel net/smc socket refcount leak in smc_switch_conns(). CVSS N/A, no patch yet. Monitor and apply vendor fix once released. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-80939
(0 None)

EPSS: 0.17%

updated 2026-09-14T13:18:50.037000

1 posts

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot Since the hardware rfkill polling was introduced, arm64 platforms can panic with an asynchronous SError during warm reboot: SError Interrupt on CPU8, code 0x00000000be000011 -- SError Workqueue: events_power_efficient rfkill_poll [rfkill] rtw89_pc

hugovalters@mastodon.social at 2026-09-18T04:20:04.000Z ##

CVE-2026-80939 Linux rtw89 PCI wifi driver can panic arm64 systems with SError on warm reboot due to rfkill polling with no shutdown callback. No CVSS assigned, patch status unknown. Apply kernel updates when valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-90894
(7.8 HIGH)

EPSS: 0.15%

updated 2026-09-14T12:31:44

2 posts

Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_service.socket. PrlSrv_LoginLocal accepts peer credentials. No Parallels signature. No admin group. After login, PrlSrv_InstallAppliance lets you pick the appliance folder (sVmParentPath). The daemon unpacks with one string, tar -xf "%1" -C "%2", then Qt QProcess::splitCommand 

oversecurity@mastodon.social at 2026-09-17T09:30:09.000Z ##

New Parallels Desktop Flaw Lets Local Users Seize Root Control of Macs

A newly documented security flaw in Parallels Desktop, identified as CVE-2026-90894 and nicknamed "ParaShells," could let any local account on

🔗️ [Thecyberexpress] link.is.it/XRBHSO

##

oversecurity@mastodon.social at 2026-09-17T09:30:09.000Z ##

New Parallels Desktop Flaw Lets Local Users Seize Root Control of Macs

A newly documented security flaw in Parallels Desktop, identified as CVE-2026-90894 and nicknamed "ParaShells," could let any local account on

🔗️ [Thecyberexpress] link.is.it/XRBHSO

##

CVE-2026-12518(CVSS UNKNOWN)

EPSS: 0.11%

updated 2026-09-14T09:31:09

1 posts

A local privilege escalation vulnerability in the Logitech Logi Options+ updater service on Windows allows a low-privileged local user to execute arbitrary code as SYSTEM.

CVE-2026-80955
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-13T07:17:02.700000

1 posts

In the Linux kernel, the following vulnerability has been resolved: dm-pcache: fix use-after-free and invalid seg operations in kset_replay() In kset_replay, when key->seg_gen is stale (key->seg_gen < key->cache_pos.cache_seg->gen), cache_key_put(key) is called but then key->cache_pos.cache_seg is accessed as the argument to cache_seg_get(). This is a use-after-free on the freed key memory. Alth

hugovalters@mastodon.social at 2026-09-17T07:10:01.000Z ##

CVE-2026-80955 Linux kernel dm-pcache use-after-free in kset_replay(). CVSS N/A. Patch status unknown. Update now. valtersit.com/cve/CVE-2026-809 #CVE #infosec #Linux

##

CVE-2026-78006
(9.8 CRITICAL)

EPSS: 0.78%

updated 2026-09-12T09:33:41

1 posts

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse, combined with enable_rendering_widget_copied() forging a valid wp_hash integrity attri

2 repos

https://github.com/DeadExpl0it/CVE-2026-78006-POC

https://github.com/user445213/CVE-2026-78006

offseq@infosec.exchange at 2026-09-16T12:00:26.000Z ##

CRITICAL: The Events Calendar WP plugin (<6.17.4.1) has two unauthenticated RCEs — CVE-2026-78159 (code injection) & CVE-2026-78006 (object injection, comments enabled). 240K+ sites at risk. Update now: radar.offseq.com/threat/unauth #OffSeq #WordPress #RCE #Vuln

##

CVE-2026-89529(CVSS UNKNOWN)

EPSS: 0.19%

updated 2026-09-11T21:31:37

1 posts

In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject oversized Read segments at decode time The RPC/RDMA Read list decoder stores wire-supplied segment lengths without validation. xdr_count_read_segments() checks 4-byte alignment for non-zero position values but does not cap the segment length. An oversized rs_length reaches svc_rdma_build_read_segment(), which de

hugovalters@mastodon.social at 2026-09-17T11:50:02.000Z ##

CVE-2026-89529 Linux kernel svcrdma: unvalidated Read segment lengths allow oversized allocation. No CVSS yet, patch status unknown. Update your kernel now: valtersit.com/cve/CVE-2026-895 #CVE #infosec #Linux

##

CVE-2026-89514(CVSS UNKNOWN)

EPSS: 0.17%

updated 2026-09-11T21:31:37

1 posts

In the Linux kernel, the following vulnerability has been resolved: scsi: fnic: Use GFP_ATOMIC for VLAN alloc under spinlock fnic_fcoe_process_vlan_resp() allocates a VLAN descriptor with kzalloc_obj() (default GFP_KERNEL) while holding vlans_lock via spin_lock_irqsave(). GFP_KERNEL may sleep, which is not allowed in this atomic context and can trigger a sleeping-from-invalid-context warning or

hugovalters@mastodon.social at 2026-09-16T07:40:01.000Z ##

CVE-2026-89514 Linux kernel fnic driver allocates memory with GFP_KERNEL under a spinlock, risking deadlock or crash. No CVSS, patch status unknown. Update kernel when fixes land. valtersit.com/cve/CVE-2026-895 #CVE #Linux #infosec

##

CVE-2026-84869
(9.9 CRITICAL)

EPSS: 0.69%

updated 2026-09-11T21:31:17

2 posts

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

thecybermind@infosec.exchange at 2026-09-16T14:42:24.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-84869 – ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

C-Suite threat intelligence and mitigation protocols for CVE-2026-84869, addressing active exploitation vectors within enterprise ConnectWise environments....

thecybermind.co/pxxw

##

beyondmachines1@infosec.exchange at 2026-09-15T11:01:13.000Z ##

ConnectWise Patches Critical ScreenConnect Flaw Exploited in Worm Attacks

ConnectWise fixed a critical vulnerability (CVE-2026-84869) in ScreenConnect that allows unauthorized file execution and worm-like propagation across remote sessions.

**If you use ConnectWise ScreenConnect, update to version 26.6.5 right away and then reinstall every host client. The update only takes effect once the clients are reinstalled, and this flaw is already being exploited to spread from machine to machine. If you can't patch, turn off the TransferFiles permission for all user roles as a mitigating measures. Don't forget to check integrated tools like ConnectWise Automate for their own patched versions.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-42016
(8.1 HIGH)

EPSS: 0.89%

updated 2026-09-11T21:31:06

1 posts

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

thecybermind@infosec.exchange at 2026-09-16T13:23:43.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-42016 – JFrog Artifactory Incorrect Authorization Vulnerability

C-Suite threat intelligence for CVE-2026-42016, covering OAuth scope validation, lateral movement detection, and repository hardening across JFrog Artifactory instances....

thecybermind.co/0vaa

##

CVE-2026-59971
(10.0 CRITICAL)

EPSS: 0.39%

updated 2026-09-11T20:36:20

1 posts

## Summary In SSE/HTTP transport mode, `mysql_mcp_server` constructs `SseServerTransport` without passing `security_settings`. As a result, the MCP Python SDK's DNS-rebinding protection (Origin/Host header validation) is disabled; the Starlette application has no CORS or TrustedHost middleware; and the service binds to `0.0.0.0` by default with no authentication on any route. **Trigger condition

thehackerwire@mastodon.social at 2026-09-15T16:01:54.000Z ##

🔴 CVE-2026-59971 - Critical (10)

MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct SseServerTransport without security_settings or ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81861(CVSS UNKNOWN)

EPSS: 0.38%

updated 2026-09-11T18:31:25

1 posts

CWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information and unauthorized access to RTU functionality.

1 repos

https://github.com/abhinavagarwal07/scadapack-secure-lock-poc

cyberworldops@infosec.exchange at 2026-09-15T18:50:00.000Z ##

Schneider Electric disclosed CVE-2026-81861 (CWE-522) affecting SCADAPack x70 RTUs. Legacy Secure Lock insufficiently protects credentials, exposing RTU authentication data. Exposed credentials matter for OT as they can enable unauthorized access to monitoring and control functions. #IcsSecurity #ScadaSecurity #OtSecurity

cyberworldops.eu/en/schneider-

##

CVE-2026-82079
(8.4 HIGH)

EPSS: 0.16%

updated 2026-09-11T03:31:25

1 posts

A stack-based buffer overflow vulnerability in the Nintendo Switch local wireless networking functionality may allow an attacker within wireless range to execute arbitrary code using return-oriented programming (ROP) through crafted network traffic. This issue affects Nintendo Switch: before 23.0.0.

CVE-2026-59160
(8.8 HIGH)

EPSS: 0.41%

updated 2026-09-09T23:47:56

1 posts

## Unauthenticated Network-Exposed Turborepo Task Execution via /api/run ### Summary `@yeger/turbo-graph` starts its embedded Next.js server without binding to the loopback interface, causing it to listen on all network interfaces (`0.0.0.0:29312` by default). The `/api/run` HTTP endpoint exposed by this server performs no authentication, authorization, CSRF protection, or task allowlist check b

thehackerwire@mastodon.social at 2026-09-15T18:01:29.000Z ##

🟠 CVE-2026-59160 - High (8.8)

Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by default, while t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20079
(10.0 CRITICAL)

EPSS: 75.75%

updated 2026-09-09T21:31:33

1 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerab

3 repos

https://github.com/0xBlackash/CVE-2026-20079

https://github.com/DiegoArias008/CVE-2026-20079-checker

https://github.com/CyberAuth/CVE-2026-20079

NetGuide@social.netguide.io at 2026-09-16T10:01:35.000Z ##

Cisco Secure FMC: Kritische Auth-Bypass-Lücke (CVSS 10.0) wird aktiv ausgenutzt

Cisco bestätigt, dass eine mit dem Höchstwert CVSS 10.0 bewertete Authentifizierungs-Bypass-Lücke (CVE-2026-20079) in seiner Secure Firewall Management Center (FMC) Software […]

netguide.io/news/de/2026/09/14

##

CVE-2026-15534
(5.7 MEDIUM)

EPSS: 0.17%

updated 2026-09-08T22:17:38.113000

1 posts

Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the sig

ottoto2017@prattohome.com at 2026-09-17T00:13:30.000Z ##

#Ubuntu 24.04.5 で #update

aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3

perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38

sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-75650
(10.0 CRITICAL)

EPSS: 2.15%

updated 2026-09-08T21:33:09

1 posts

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

5 repos

https://github.com/jithinkrishnanrs/stylesmuggler-ioc-toolkit

https://github.com/disrex-group/stylesmuggler-adobe-patches

https://github.com/fortbridge/stylesmuggler

https://github.com/dinosn/cve-2026-75650-magento-validation-lab

https://github.com/disrex-group/stylesmuggler-adobe-patches-mageos

CVE-2026-31431
(7.8 HIGH)

EPSS: 99.91%

updated 2026-09-08T09:36:36

1 posts

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just

100 repos

https://github.com/4xura/CVE-2026-31431-Copy-Fail

https://github.com/nisec-eric/cve-2026-31431

https://github.com/SeanRickerd/cve-2026-31431

https://github.com/sec17br/CVE-2026-31431-Copy-Fail

https://github.com/Juguitos/copy-fail

https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431

https://github.com/haydenjames/CVE-2026-31431-check

https://github.com/sgkdev/page_inject

https://github.com/guiimoraes/CVE-2026-31431

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC

https://github.com/Qengineering/RK35xx-CopyFail-Hotfix

https://github.com/novysodope/copy-fail-CVE-2026-31431-C

https://github.com/cs8425/copy-fail-go

https://github.com/abdelkabirouadoukou/CVE-2026-31431-Analysis-and-Fix

https://github.com/lonelyor/CVE-2026-31431-exp

https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE

https://github.com/sudoytang/copyfail-arm64

https://github.com/wuwu001/CVE-2026-31431-exploit

https://github.com/desultory/CVE-2026-31431

https://github.com/diemoeve/copyfail-rs

https://github.com/pedromizz/copy-fail

https://github.com/Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431

https://github.com/Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail

https://github.com/rootsecdev/cve_2026_31431

https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag

https://github.com/KaraZajac/DIRTYFAIL

https://github.com/gagaltotal/cve-2026-31431-copy-fail

https://github.com/AliHzSec/CVE-2026-31431

https://github.com/erlangparasu/mitigate_cve_2026_31431-sh

https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit

https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script

https://github.com/MrAriaNet/cPanel-Fix

https://github.com/b5null/CVE-2026-31431-C

https://github.com/Iamliuxiaozhen/copy_fail

https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail

https://github.com/tgies/copy-fail-c

https://github.com/badsectorlabs/copyfail-go

https://github.com/painoob/Copy-Fail-Exploit-CVE-2026-31431

https://github.com/g1nt0n1x/copy-fail-CVE-2026-31431-shell

https://github.com/cozystack/copy-fail-blocker

https://github.com/ErdemOzgen/copy-fail-cve-2026-31431

https://github.com/Boos4721/copyfail-rs

https://github.com/qi4L/CVE-2026-31431-Container-Escape

https://github.com/ncmprbll/copy-fail-rs

https://github.com/philfry/cve-2026-31431-ftrace

https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized

https://github.com/yuspring/cve-2026-31431-poc

https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe

https://github.com/ExploitEoom/CVE-2026-31431

https://github.com/pascal-gujer/CVE-2026-31431

https://github.com/ZephrFish/CopyFail-CVE-2026-31431

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC

https://github.com/sammwyy/copyfail-rs

https://github.com/0xBlackash/CVE-2026-31431

https://github.com/Shotafry/CopyFail-Exploits-CVE-2026-31431

https://github.com/kinryulabs/rootpacket-cve-2026-31431

https://github.com/mrunalp/block-copyfail

https://github.com/samanzamani/copy-fail-checker

https://github.com/povzayd/CVE-2026-31431

https://github.com/theori-io/copy-fail-CVE-2026-31431

https://github.com/bigwario/copy-fail-CVE-2026-31431-C

https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit

https://github.com/rvzsec/CVE-2026-31431

https://github.com/bootsareme/copyfail-deconstructed

https://github.com/TheMalwareGuardian/CVE-2026-31431

https://github.com/xeloxa/copyfail-exploit

https://github.com/ben-slates/CVE-2026-31431-Exploit

https://github.com/mahdi13830510/CVE-2026-31431-mitigation-suite

https://github.com/hans362/CVE-2026-31431-Copy-Fail-Container-Escape

https://github.com/Alfredooe/CVE-2026-31431

https://github.com/cyber-joker/copy-fail-python

https://github.com/luotian2/CVE-2026-31431

https://github.com/insomnisec/Detections-CVE-2026-31431

https://github.com/MartinPham/copy-fail-CVE-2026-31431-php

https://github.com/jbnetwork-git/copy-fail-check

https://github.com/Xerxes-2/CVE-2026-31431-rs

https://github.com/Smarttfoxx/copyfail

https://github.com/adampielak/CVE-2026-31431_SCA_WAZUH

https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431

https://github.com/pyroceper/copy-fail-CVE-2026-31431

https://github.com/M4xSec/CVE-2026-31431-RCE-Exploit

https://github.com/kadir/copy-fail-CVE-2026-31431-IOC

https://github.com/wesmar/CVE-2026-31431

https://github.com/sgkdev/ptrace_may_dream

https://github.com/JuanBindez/CVE-2026-31431

https://github.com/malwarekid/CVE-2026-31431

https://github.com/scriptzteam/Paranoid-Copy-Fail-CVE-2026-31431

https://github.com/XsanFlip/CVE-2026-31431-Patch

https://github.com/wgnet/wg.copyfail.patch

https://github.com/mym0us3r/COPY-FAIL-Detection-with-Wazuh-4.14.4

https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs

https://github.com/aestechno/cve-2026-31431-ansible

https://github.com/Huchangzhi/autorootlinux

https://github.com/AdityaBhatt3010/CVE-2026-31431

https://github.com/Dabbleam/CVE-2026-31431-mitigation

https://github.com/0xShe/CVE-2026-31431

https://github.com/yandex-cloud-examples/yc-mk8s-copy-fail-mitigation

https://github.com/Sl4cK0TH/CVE-2026-31431-PoC

https://github.com/JnamerZ/CopyFail-CVE-2026-31431

https://github.com/atgreen/block-copyfail

sayzard@mastodon.sayzard.org at 2026-09-17T11:41:42.000Z ##

When the Red Light Goes On: How We Responded to the Linux Kernel 0-Day

Linux 커널의 공개 PoC 로컬 권한 상승 취약점 CVE-2026-31431("Copy Fail")이 Ubuntu 24.04에서 비권한 사용자로부터 root 획득까지 가능하다고 보고됐다. 원인은 Crypto User API의 AF_ALG 경로에서 `algif_aead` 모듈에 도달 가능한 out-of-bounds write이며, 웹 애플리케이션 침해가 호스트 전체 침해로 확대될 수 있어 멀티테넌트 서버와 컨테이너 노드 운영자에게 특히 중요하다. 패치가 배포되기 전에는 `algif_aead`를 언로드하고 modprobe 설정으로 재로딩을 차단하는 방식으로 공...

nine.ch/en/blog/linux-kernel-0

##

CVE-2026-58113
(6.1 MEDIUM)

EPSS: 0.22%

updated 2026-09-08T09:35:45

1 posts

A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All versions < V2606.2607). Affected applications do not properly encode user-supplied input reflected into HTML attribute contexts within the authentication redirect flow (/auth/ endpoint). This could all

cyberworldops@infosec.exchange at 2026-09-16T04:50:00.000Z ##

Siemens patched CVE-2026-58113, a reflected XSS (CWE-79) in Teamcenter /auth/ redirect flow. An unauthenticated attacker can craft a URL executing JavaScript in an authenticated user's session. Update all four affected branches. #SiemensTeamcenter #CrossSiteScripting #PatchManagement

cyberworldops.eu/en/siemens-pa

##

CVE-2026-15315
(8.8 HIGH)

EPSS: 0.30%

updated 2026-09-04T18:32:18

4 posts

Tapo C200 v5 contains an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to bypass normal authentication controls and obtain administrative session tokens. Successful exploitation may allow an attacker to subsequently execute privileged management actions,

1 repos

https://github.com/HORKimhab/CVE-2026-15315

beyondmachines1 at 2026-09-17T11:01:13.911Z ##

TP-Link Patches Critical Flaws in Tapo Surveillance Cameras

TP-Link patched multiple vulnerabilities in its Tapo C200 and C120 cameras, including an authentication bypass (CVE-2026-15315) and a denial-of-service flaw (CVE-2026-15316), while a third critical vulnerability remains under investigation.

**Update your Tapo camera firmware to version V5_1.4.6 ASAP, and check for new updates for the most severe issue that's still not patched. And move all smart cameras to a separate guest network to keep your main computers safe if a device is hacked.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-09-17T11:01:13.000Z ##

TP-Link Patches Critical Flaws in Tapo Surveillance Cameras

TP-Link patched multiple vulnerabilities in its Tapo C200 and C120 cameras, including an authentication bypass (CVE-2026-15315) and a denial-of-service flaw (CVE-2026-15316), while a third critical vulnerability remains under investigation.

**Update your Tapo camera firmware to version V5_1.4.6 ASAP, and check for new updates for the most severe issue that's still not patched. And move all smart cameras to a separate guest network to keep your main computers safe if a device is hacked.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

AAKL@infosec.exchange at 2026-09-16T16:32:55.000Z ##

In case you didn't have enough problems with cameras, here's another one.

OPSWAT, posted yesterday: Authentication Bypass and DoS Vulnerabilities: OPSWAT Discovers CVE-2026-15315 & CVE-2026-15316 in TP-Link Tapo Cameras opswat.com/blog/authentication

More:

Infosecurity-Magazine: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping infosecurity-magazine.com/news #infosec #vulnerability #spyware #zeroday #threatresearch

##

security_crawler_carl@infosec.exchange at 2026-09-16T13:10:27.000Z ##

🏆 New Achievement! Smile, You're on Hacked Camera!

Step right up! For the low, low price of plugging a TP-Link Tapo C200 into your home network, you received two zero-days absolutely free of charge. OPSWAT discovered CVE-2026-15315, a replay-based authentication bypass letting any network-adjacent attacker waltz — sorry, slide — into a valid admin session without ever knowing your password. (1/2)

##

CVE-2026-15316
(6.5 MEDIUM)

EPSS: 0.23%

updated 2026-09-04T18:31:13

4 posts

An improper input validation vulnerability in the configuration service for processing encrypted credential data has been identified in Tapo C200 v5.  An attacker can send oversized crypted ciphertext values that may trigger exception handling failures, due to insufficient validation, causing the affected device to crash or restart. Successful exploitation may temporarily disrupt HTTPS manage

1 repos

https://github.com/HORKimhab/CVE-2026-15315

beyondmachines1 at 2026-09-17T11:01:13.911Z ##

TP-Link Patches Critical Flaws in Tapo Surveillance Cameras

TP-Link patched multiple vulnerabilities in its Tapo C200 and C120 cameras, including an authentication bypass (CVE-2026-15315) and a denial-of-service flaw (CVE-2026-15316), while a third critical vulnerability remains under investigation.

**Update your Tapo camera firmware to version V5_1.4.6 ASAP, and check for new updates for the most severe issue that's still not patched. And move all smart cameras to a separate guest network to keep your main computers safe if a device is hacked.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-09-17T11:01:13.000Z ##

TP-Link Patches Critical Flaws in Tapo Surveillance Cameras

TP-Link patched multiple vulnerabilities in its Tapo C200 and C120 cameras, including an authentication bypass (CVE-2026-15315) and a denial-of-service flaw (CVE-2026-15316), while a third critical vulnerability remains under investigation.

**Update your Tapo camera firmware to version V5_1.4.6 ASAP, and check for new updates for the most severe issue that's still not patched. And move all smart cameras to a separate guest network to keep your main computers safe if a device is hacked.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

AAKL@infosec.exchange at 2026-09-16T16:32:55.000Z ##

In case you didn't have enough problems with cameras, here's another one.

OPSWAT, posted yesterday: Authentication Bypass and DoS Vulnerabilities: OPSWAT Discovers CVE-2026-15315 & CVE-2026-15316 in TP-Link Tapo Cameras opswat.com/blog/authentication

More:

Infosecurity-Magazine: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping infosecurity-magazine.com/news #infosec #vulnerability #spyware #zeroday #threatresearch

##

security_crawler_carl@infosec.exchange at 2026-09-16T13:10:27.000Z ##

CVE-2026-15316 throws in a denial-of-service against the onboarding flow as a bonus gift with purchase.

Perhaps you'd like our Extended Vulnerability Warranty? Only $49.99. Or — and hear me out — you could just update your Tapo C200 to firmware V5_1.4.6, released August 18, for the remarkable price of free.

Reward: You've received a slightly-used Tin Foil Lens Cap. Refurbished. Non-returnable.

infosecurity-magazine.com/news

#ZeroDay #CyberSecurity (2/2)

##

CVE-2026-81573
(8.6 HIGH)

EPSS: 0.46%

updated 2026-09-01T20:56:59.203000

1 posts

If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the

certvde@infosec.exchange at 2026-09-15T08:17:37.000Z ##

🔒 New CSAF advisory published

VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576

The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: trumpf.csaf-tp.certvde.com/.we

#OT #Advisory

##

CVE-2026-56211
(7.1 HIGH)

EPSS: 0.48%

updated 2026-09-01T13:19:51.053000

1 posts

A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted video frame pixels that overlap with internal encoder layer context structures. In fork-based video processing services, an attacker can use this to hijack the cyclic

ottoto2017@prattohome.com at 2026-09-17T00:13:30.000Z ##

#Ubuntu 24.04.5 で #update

aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3

perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38

sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-39113
(4.0 None)

EPSS: 0.21%

updated 2026-08-31T18:31:16

1 posts

Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05cbe61d12c2c448f2f24b6d5d (Git mirror 169f68ed88b34cb68f720191c64c058f2ccec508, 2026-03-11) and later snapshots/builds allows an attacker to cause a denial of service via the ext/misc/sqlar.c, sqlarUncompressFunc(), sqlar_uncompress(), sqlite3_value_int

1 repos

https://github.com/20000419/CVE-2026-39113

ottoto2017@prattohome.com at 2026-09-17T00:13:30.000Z ##

#Ubuntu 24.04.5 で #update

aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3

perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38

sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-56210
(7.1 HIGH)

EPSS: 0.31%

updated 2026-08-31T15:35:36

1 posts

A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can inf

ottoto2017@prattohome.com at 2026-09-17T00:13:30.000Z ##

#Ubuntu 24.04.5 で #update

aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3

perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38

sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-56208
(7.6 HIGH)

EPSS: 0.42%

updated 2026-08-31T15:34:31

1 posts

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An

ottoto2017@prattohome.com at 2026-09-17T00:13:30.000Z ##

#Ubuntu 24.04.5 で #update

aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3

perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38

sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-56209
(7.1 HIGH)

EPSS: 0.35%

updated 2026-08-31T15:34:31

1 posts

An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an arbitrary pointer into the cyclic refresh map field via crafted image pixel values. The encoder then writes approximately 1,200 bytes at the attacker-controlled address. This is full

ottoto2017@prattohome.com at 2026-09-17T00:13:30.000Z ##

#Ubuntu 24.04.5 で #update

aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3

perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38

sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-81572
(7.8 HIGH)

EPSS: 0.17%

updated 2026-08-27T12:30:27

1 posts

cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file operations are performed. A local attacker can create a junction at the temporary file that points to an arbitrary system path. Because CodeMeter Runtime runs with System privileges, thi

certvde@infosec.exchange at 2026-09-15T08:17:37.000Z ##

🔒 New CSAF advisory published

VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576

The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: trumpf.csaf-tp.certvde.com/.we

#OT #Advisory

##

CVE-2026-81576
(7.7 HIGH)

EPSS: 0.33%

updated 2026-08-27T12:30:27

1 posts

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read license information belonging to another handle.

certvde@infosec.exchange at 2026-09-15T08:17:37.000Z ##

🔒 New CSAF advisory published

VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576

The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: trumpf.csaf-tp.certvde.com/.we

#OT #Advisory

##

CVE-2026-81574
(8.2 HIGH)

EPSS: 0.41%

updated 2026-08-27T12:30:27

1 posts

In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory and stack canaries. The attack works locally, for example by using cmu --set-proxy to set the proxy value, and remotely

certvde@infosec.exchange at 2026-09-15T08:17:37.000Z ##

🔒 New CSAF advisory published

VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576

The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: trumpf.csaf-tp.certvde.com/.we

#OT #Advisory

##

CVE-2026-81575
(7.5 HIGH)

EPSS: 0.44%

updated 2026-08-27T12:30:26

1 posts

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and the data itself. Missing bounds checking on the data length value can lead to out of bounds reads, causing a segmentation fault that ultimately crashes the CodeMeter Runtime.

certvde@infosec.exchange at 2026-09-15T08:17:37.000Z ##

🔒 New CSAF advisory published

VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576

The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: trumpf.csaf-tp.certvde.com/.we

#OT #Advisory

##

cyberveille@mastobot.ping.moi at 2026-09-17T15:00:05.000Z ##

📢 Red Heron exploite CVE-2026-60004 dans Gitea pour déployer un rootkit Linux inédit

L'Acronis Threat Research Unit (TRU) a publié le 13 septembre 2026 une analyse détaillée d'une campagne multinationale menée par un acteur malveillant sinophone qu'ils suivent sous le nom Red Heron. La découverte initiale remonte au 4 août 2026, lorsque TRU a…

📖 cyberveille : cyberveille.ch/posts/2026-09-1
🌐 source : acronis.com/en/tru/posts/red-h
🟢 vérification factuelle haute
#RedHeron #RootkitLinux #Cyberveille

##

VirusBulletin@infosec.exchange at 2026-09-15T08:43:23.000Z ##

Acronis TRU uncovered a multinational campaign in which Red Heron, a Chinese-speaking threat actor, rapidly weaponized CVE-2026-60004 to compromise internet-facing instances of Gitea, a self-hosted source-code management platform. acronis.com/en/tru/posts/red-h

##

CVE-2026-56389
(8.6 HIGH)

EPSS: 0.16%

updated 2026-08-24T18:32:30

2 posts

GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can override the executable used for the XML‑to‑HTML transformation step via %define tool.xsltproc, which is accepted without restriction and passed directly to execvp(). When running bison --html on a attacker-provided gramma

ottoto2017@prattohome.com at 2026-09-18T00:27:51.000Z ##

#Ubuntu 24.04.5 で #update

bison (2:3.8.2+dfsg-1ubuntu0.24.04.1)
CVE-2026-56389へのセキュリティ対応。

セキュリティ対応なのでお早めに。

#prattohome #更新

##

ottoto2017@prattohome.com at 2026-09-18T00:27:51.000Z ##

#Ubuntu 24.04.5 で #update

bison (2:3.8.2+dfsg-1ubuntu0.24.04.1)
CVE-2026-56389へのセキュリティ対応。

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-59310
(9.8 CRITICAL)

EPSS: 45.88%

updated 2026-08-19T04:17:24.940000

2 posts

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

2 repos

https://github.com/HORKimhab/CVE-2026-59310

https://github.com/BiuTrap/CVE-2026-59310

DailyCyberSecurity at 2026-09-17T14:01:28.726Z ##

Discover how ransomware gangs actively exploit the critical VMware vCenter flaw, CVE-2026-59310. Learn about the swift weaponization and severe infrastructure risks.

meterpreter.org/vmware-vcenter

##

DailyCyberSecurity@infosec.exchange at 2026-09-17T14:01:28.000Z ##

Discover how ransomware gangs actively exploit the critical VMware vCenter flaw, CVE-2026-59310. Learn about the swift weaponization and severe infrastructure risks.

#VMware #vCenter #CVE202659310 #Ransomware #CyberSecurity

meterpreter.org/vmware-vcenter

##

CVE-2026-19487
(5.3 MEDIUM)

EPSS: 0.42%

updated 2026-08-13T21:37:11

1 posts

Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass. The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear

ottoto2017@prattohome.com at 2026-09-17T00:13:30.000Z ##

#Ubuntu 24.04.5 で #update

aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3

perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38

sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-5430
(10.0 CRITICAL)

EPSS: 0.32%

updated 2026-08-06T09:30:40

4 posts

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of adm

1 repos

https://github.com/HORKimhab/CVE-2026-5430

beyondmachines1 at 2026-09-17T09:01:13.531Z ##

WSO2 Warns of Active Exploitation Targeting Critical Authentication Bypass

WSO2 is warning of active exploitation of a critical authentication bypass vulnerability (CVE-2026-5430) that allows attackers to take over administrative accounts and steal sensitive API credentials. The flaw affects multiple middleware products and has been targeted in the wild since mid-September 2026.

**If you run WSO2 API Manager, API Control Plane, Traffic Manager, or Universal Gateway, check for affected versions and patch immediately to the latest update level from WSO2. If you are using open source version apply the public GitHub fix. Attackers are already using forged tokens to gain full admin access.
After patching, assume your secrets were exposed and rotate all API keys, backend credentials, consumer keys, and application secrets, and check your logs for suspicious access since September 13, 2026.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-09-17T09:01:13.000Z ##

WSO2 Warns of Active Exploitation Targeting Critical Authentication Bypass

WSO2 is warning of active exploitation of a critical authentication bypass vulnerability (CVE-2026-5430) that allows attackers to take over administrative accounts and steal sensitive API credentials. The flaw affects multiple middleware products and has been targeted in the wild since mid-September 2026.

**If you run WSO2 API Manager, API Control Plane, Traffic Manager, or Universal Gateway, check for affected versions and patch immediately to the latest update level from WSO2. If you are using open source version apply the public GitHub fix. Attackers are already using forged tokens to gain full admin access.
After patching, assume your secrets were exposed and rotate all API keys, backend credentials, consumer keys, and application secrets, and check your logs for suspicious access since September 13, 2026.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

security_crawler_carl@infosec.exchange at 2026-09-16T10:21:45.000Z ##

The prosecution notes that your API interception layer, by design, sits squarely between attackers and internal systems, creating what the record describes as "Lateral Movement-as-a-Service." Administrative accounts, sensitive data in transit — all fair game.

Sentencing is immediate. Apply the April patch for CVE-2026-5430 and audit your JWT token validation and administrative account access without further delay. (2/3)

##

security_crawler_carl@infosec.exchange at 2026-09-16T10:21:45.000Z ##

🏆 New Achievement! The Honorable CVE-2026-5430 Finds You Guilty!

The court has reviewed the evidence. WSO2 API Manager, you stand charged with allowing JWT authentication to be bypassed via an unsupported signing algorithm — a flaw patched in April that threat actors are now actively exploiting in the wild. WatchTowr delivered the indictment on Tuesday. (1/3)

##

CVE-2026-15830
(5.3 MEDIUM)

EPSS: 1.26%

updated 2026-08-04T18:31:31

1 posts

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spa

djangonews@mastodon.social at 2026-09-16T20:00:11.000Z ##

[Django Fellow Reports] Django Fellow Report - Jacob

Jacob reviewed six Django pull requests and authored changes covering GEOS 3.10 support removal and expanded WKT depth-check coverage related to CVE-2026-15830.
forum.djangoproject.com/t/djan

##

CVE-2026-13584(CVSS UNKNOWN)

EPSS: 0.13%

updated 2026-08-04T06:32:37

2 posts

Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, Motion Control Board, Block-type remote module, Block-type remote module with safety functions, Analog-Digital converter module, Digital-Ana

cyberworldops at 2026-09-18T02:40:00.943Z ##

Mitsubishi Electric CC-Link IE TSN is affected by CVE-2026-13584, CWE-924 message integrity failure. An adjacent attacker can inject crafted packets under timing conditions to tamper with OT traffic. It matters for ICS integrity and safety assumptions on trusted segments.

cyberworldops.eu/en/mitsubishi

##

cyberworldops@infosec.exchange at 2026-09-18T02:40:00.000Z ##

Mitsubishi Electric CC-Link IE TSN is affected by CVE-2026-13584, CWE-924 message integrity failure. An adjacent attacker can inject crafted packets under timing conditions to tamper with OT traffic. It matters for ICS integrity and safety assumptions on trusted segments. #IcsSecurity #OtSecurity #MessageIntegrity

cyberworldops.eu/en/mitsubishi

##

CVE-2026-45659
(8.8 HIGH)

EPSS: 76.08%

updated 2026-07-01T21:35:53

1 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

2 repos

https://github.com/WismanSec/sharepoint-2026-poc

https://github.com/HORKimhab/CVE-2026-45659

CVE-2026-47203(CVSS UNKNOWN)

EPSS: 0.45%

updated 2026-06-26T21:32:44

1 posts

### Impact **CVSSv4 Baseline Score:** Moderate 6.3 **CVSSv4 Weighted Score:** Low 2.9 The full CVSSv4 Vector for this vulnerability is: > CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:L/IR:L/AR:L/MAV:N/MAC:H/MAT:N/MPR:N/MUI:N/MVC:L/MVI:N/MVA:N/MSC:N/MSI:N/MSA:N/S:N/AU:Y/R:U/V:D/RE:L/U:Green **CVSSv3.1 Baseline Score:** Low 3.7 **CVSSv3.1 Overall Score:** Medium 4.0

IanTwenty@piefed.social at 2026-09-15T19:05:41.993Z ##

Say that new authelia exploit looks like one fail2ban already recognises or relies on timing/brute-force then you’re covered even before a patch is available.

Here’s a real authelia vuln:

https://app.opencve.io/cve/CVE-2026-47203

allowing an attacker to circumvent login throttling or account lockouts by simply altering the case of their credentials.

I think fail2ban would help protect authelia here?

##

CVE-2026-45051(CVSS UNKNOWN)

EPSS: 0.51%

updated 2026-06-24T17:25:29

1 posts

## Summary **Description** A deserialization of untrusted data vulnerability (CWE-502) exists in OpenAM's WebAuthn authentication module. Under certain conditions, this may allow an attacker to achieve arbitrary code execution in the context of the application server. This affects OpenAM Community Edition through version 16.0.6 and was patched in version 16.1.1. This is not the default configur

offseq@infosec.exchange at 2026-09-15T10:30:25.000Z ##

OpenAM <16.1.1 suffers from CRITICAL deserialization vuln (CVE-2026-45051, CVSS 9.2). WebAuthnAuthentication lets attackers run arbitrary code via crafted serialized data. Patch to 16.1.1 ASAP! radar.offseq.com/threat/cve-20 #OffSeq #CVE202645051 #OpenAM #infosec

##

CVE-2026-8024
(9.8 CRITICAL)

EPSS: 0.55%

updated 2026-06-18T15:32:09

2 posts

A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems.

certvde at 2026-09-17T08:41:07.260Z ##

🔄 CSAF advisory updated (version 3.0.0)

VDE-2026-051
iba: Deserialization vulnerability in ibaPDA and ibaDatCoordinator
CVE-2026-8024

Changes: Corrected all CPE numbers and vendor name of all products.

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: iba.csaf-tp.certvde.com/.well-

##

certvde@infosec.exchange at 2026-09-17T08:41:07.000Z ##

🔄 CSAF advisory updated (version 3.0.0)

VDE-2026-051
iba: Deserialization vulnerability in ibaPDA and ibaDatCoordinator
CVE-2026-8024

Changes: Corrected all CPE numbers and vendor name of all products.

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: iba.csaf-tp.certvde.com/.well-

#OT #Advisory

##

CVE-2026-39987
(9.8 CRITICAL)

EPSS: 98.95%

updated 2026-06-17T10:42:51.460000

1 posts

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands. Unlike other WebSocket endpoints (e.g., /ws) that correctly call validate_auth() for authentication, the /terminal/ws endpo

Nuclei template

25 repos

https://github.com/HORKimhab/CVE-2026-39987

https://github.com/MADA0L/CVE-2026-39987-Poc

https://github.com/dodeepsink/CVE-2026-39987.py

https://github.com/alreadyClosed/CVE-2026-39987

https://github.com/Nxploited/CVE-2026-39987

https://github.com/vanhari/CVE-2026-39987

https://github.com/keraattin/CVE-2026-39987

https://github.com/Ghxstsec/CVE-2026-39987

https://github.com/h3raklez/CVE-2026-39987

https://github.com/jasonbernier/CVE-2026-39987

https://github.com/M3PH1569/CVE-2026-39987-POC

https://github.com/rootdirective-sec/CVE-2026-39987-Lab

https://github.com/fevar54/marimo_CVE-2026-39987_RCE_PoC

https://github.com/matesz44/cve-2026-39987

https://github.com/0xBlackash/CVE-2026-39987

https://github.com/iapetus12/cohort-htb

https://github.com/Clara-M-Grossl/Exploit-Marimo

https://github.com/K3ysTr0K3R/CVE-2026-39987

https://github.com/julichaan/CVE-2026-39987_POC

https://github.com/stapat1245/CVE-2026-39987-PoC

https://github.com/Dhiaelhak-Rached/CVE-2026-39987-lab-or-marimo-cve-lab

https://github.com/0xdeadroot/CVE-2026-39987-marimo-rce

https://github.com/mki9/CVE-2026-39987_exploit

https://github.com/gbuyssens/CVE-2026-39987

https://github.com/Wind010/CVE-2026-39987_PoC

cyberworldops@infosec.exchange at 2026-09-15T14:50:01.000Z ##

Sysdig reports a human operator exploited CVE-2026-39987, a pre-auth RCE in Marimo, and pivoted from the notebook to an SSH bastion in eight seconds with a custom Python toolkit. It shows manual tradecraft can match automation speed, shrinking detection windows for exposed dev infrastructure. #MarimoRce #SshBastion #IncidentResponse

cyberworldops.eu/en/human-oper

##

CVE-2025-48595
(8.4 HIGH)

EPSS: 1.71%

updated 2026-06-02T21:30:39

1 posts

In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

3 repos

https://github.com/fevar54/CVE-2025-48595-Android-Framework-Integer-Overflow-

https://github.com/XiaoBaiLovesStirring/CVE-2025-48595-Exploit

https://github.com/HORKimhab/CVE-2025-48595

skyblitz@ieji.de at 2026-09-16T12:00:11.000Z ##

@GrapheneOS funny to see google fixing : CVE-2025-48595 that was fixed looooooong ago in your.

i don't see CVE-2026-58704, is it already fixed ?

bleepingcomputer.com/news/secu

##

CVE-2026-32746
(9.8 CRITICAL)

EPSS: 23.67%

updated 2026-03-23T15:31:40

7 posts

telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full.

8 repos

https://github.com/danindiana/cve-2026-32746-mitigation

https://github.com/chosenonehacks/CVE-2026-32746

https://github.com/MonkeySeC-sys/Kangaroo

https://github.com/ekomsSavior/telnet_scan

https://github.com/watchtowrlabs/watchtowr-vs-telnetd-CVE-2026-32746

https://github.com/duduLiu8787/CVE-2026-32746-Exploit

https://github.com/kaleth4/CVE-2026-32746

https://github.com/jeffaf/cve-2026-32746

hn50@social.lansky.name at 2026-09-17T07:50:07.000Z ##

A 32-year-old bug walks into a Telnet server

Link: labs.watchtowr.com/a-32-year-o
Discussion: news.ycombinator.com/item?id=4

##

hnbot@chrispelli.fun at 2026-09-17T04:59:36.000Z ##

A 32-year-old bug walks into a Telnet server - labs.watchtowr.com/a-32-year-o

#hackernews

##

ngate@mastodon.social at 2026-09-17T04:59:21.000Z ##

😂 Oh, look, a bug older than some of you on this site! GNU #inetutils just realized their #Telnet server had a 32-year-old #exploit hiding like a dusty family heirloom. Who knew pre-auth RCE could double as a boomer joke? 🧐🔍
labs.watchtowr.com/a-32-year-o #bugreport #cybersecurity #humor #technews #HackerNews #ngated

##

h4ckernews@mastodon.social at 2026-09-17T04:59:17.000Z ##

A 32-year-old bug walks into a Telnet server

labs.watchtowr.com/a-32-year-o

Comments: news.ycombinator.com/item?id=4

#HackerNews #bugfix #cybersecurity #Telnet #server #technology #vulnerabilities #GNU #inetutils

##

hn50@social.lansky.name at 2026-09-17T07:50:07.000Z ##

A 32-year-old bug walks into a Telnet server

Link: labs.watchtowr.com/a-32-year-o
Discussion: news.ycombinator.com/item?id=4

##

ngate@mastodon.social at 2026-09-17T04:59:21.000Z ##

😂 Oh, look, a bug older than some of you on this site! GNU #inetutils just realized their #Telnet server had a 32-year-old #exploit hiding like a dusty family heirloom. Who knew pre-auth RCE could double as a boomer joke? 🧐🔍
labs.watchtowr.com/a-32-year-o #bugreport #cybersecurity #humor #technews #HackerNews #ngated

##

h4ckernews@mastodon.social at 2026-09-17T04:59:17.000Z ##

A 32-year-old bug walks into a Telnet server

labs.watchtowr.com/a-32-year-o

Comments: news.ycombinator.com/item?id=4

#HackerNews #bugfix #cybersecurity #Telnet #server #technology #vulnerabilities #GNU #inetutils

##

CVE-2026-27540
(9.0 None)

EPSS: 2.32%

updated 2026-03-19T06:30:33

2 posts

Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture allows Using Malicious Files.This issue affects Woocommerce Wholesale Lead Capture: from n/a through 2.0.3.1.

2 repos

https://github.com/winrarzipsexploit/CVE-2026-27540

https://github.com/Nxploited/CVE-2026-27542-CVE-2026-27540-

cyberworldops@infosec.exchange at 2026-09-16T10:40:01.000Z ##

Attackers are actively exploiting CVE-2026-27540 in the WooCommerce Wholesale Lead Capture WordPress plugin to upload PHP web shells without authentication. The flaw affects a plugin with more than 6,000 active installations and can enable remote code execution. #WordPressSecurity #VulnerabilityManagement #ThreatDetection

cyberworldops.eu/en/attackers-

##

security_crawler_carl@infosec.exchange at 2026-09-15T19:55:23.000Z ##

🏆 New Achievement! Exceeded All KPIs Except Staying Uncompromised!

Your Q3 infrastructure review is in. Uptime: stellar. Deployment pipeline: smooth. WooCommerce Wholesale Lead Capture plugin: actively backdoored via CVE-2026-27540. That last one is what we in management call an "opportunity area."

Attackers are currently exploiting this critical flaw in the wild, planting PHP backdoors and achieving full takeover of WordPress stores. Everything was going so well, team. Really. (1/3)

##

CVE-2023-38198
(9.8 CRITICAL)

EPSS: 1.08%

updated 2024-10-30T21:30:36

1 posts

acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023.

niconiconi@mk.absturztau.be at 2026-09-16T02:31:21.811Z ##

Using acme.sh to renew a certificate as root sounds like a RCE-as-root waiting to happen. A Web client written in pure shell, what could possibly go wrong? I just wrote a script to drop its own privilege when it calls acme.sh, so it's safe to use in a root cronjob.

After writing this, I found RCE-as-root is not just "waiting" to happen, it has already happened as CVE-2023-38198. Someone even argued the case as a possible mechanism responsible for the jabber.ru wiretapping incident.
https://remyhax.xyz/posts/reproducing-lawful-tls-wiretapping/

##

CVE-2024-20260
(8.6 HIGH)

EPSS: 0.62%

updated 2024-10-23T18:33:16

1 posts

A vulnerability in the VPN and management web servers of the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv), formerly Cisco Firepower Threat Defense Virtual, platforms could allow an unauthenticated, remote attacker to cause the virtual devices to run out of system memory, which could cause SSL VPN connection processing to slow down and eve

CVE-2026-54520
(0 None)

EPSS: 0.00%

2 posts

N/A

1 repos

https://github.com/chaitanyagarware/CVE-2026-54520

thehackerwire@mastodon.social at 2026-09-17T23:01:41.000Z ##

🟠 CVE-2026-54520 - High (8.1)

AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.path value...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T23:01:41.000Z ##

🟠 CVE-2026-54520 - High (8.1)

AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.path value...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54670
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-17T23:01:30.000Z ##

🔴 CVE-2026-54670 - Critical (9.1)

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and metodo values without a complete controller and meth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T23:01:30.000Z ##

🔴 CVE-2026-54670 - Critical (9.1)

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and metodo values without a complete controller and meth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54767
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-17T23:01:20.000Z ##

🔴 CVE-2026-54767 - Critical (9.1)

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded chave_correta value embedded...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T23:01:20.000Z ##

🔴 CVE-2026-54767 - Critical (9.1)

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded chave_correta value embedded...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54671
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-17T23:00:35.000Z ##

🟠 CVE-2026-54671 - High (8.8)

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource array in web/controle/control.php, and verificarPermissao in web/dao/MiddlewareDAO.php treats that empty array as unconditional acc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T23:00:35.000Z ##

🟠 CVE-2026-54671 - High (8.8)

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource array in web/controle/control.php, and verificarPermissao in web/dao/MiddlewareDAO.php treats that empty array as unconditional acc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93426
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-17T23:00:26.000Z ##

🟠 CVE-2026-93426 - High (8.5)

SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or higher can embed backticks and quotes in field names ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T23:00:26.000Z ##

🟠 CVE-2026-93426 - High (8.5)

SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or higher can embed backticks and quotes in field names ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54752
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-17T21:01:39.000Z ##

🔴 CVE-2026-54752 - Critical (9.6)

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the read_pickle_d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T21:01:39.000Z ##

🔴 CVE-2026-54752 - Critical (9.6)

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the read_pickle_d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54716
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-17T21:01:30.000Z ##

🟠 CVE-2026-54716 - High (7.5)

Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earlier, a POST request to /sources_to_targets containing an exclude_polygons ring formed by three collinear points can cause unboun...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T21:01:30.000Z ##

🟠 CVE-2026-54716 - High (7.5)

Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earlier, a POST request to /sources_to_targets containing an exclude_polygons ring formed by three collinear points can cause unboun...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54692
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-17T21:01:19.000Z ##

🟠 CVE-2026-54692 - High (7.8)

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to 1.0.0, sail_codec_load_frame_v8_xbm() in src/sail-codecs/xbm/xbm.c allocates the decoded pixel buffer using the X11 one...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T21:01:19.000Z ##

🟠 CVE-2026-54692 - High (7.8)

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to 1.0.0, sail_codec_load_frame_v8_xbm() in src/sail-codecs/xbm/xbm.c allocates the decoded pixel buffer using the X11 one...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92943
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-17T21:00:31.000Z ##

🟠 CVE-2026-92943 - High (8.1)

Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might allow an adversary-in-the-middle actor to impersonate the AWS IoT Core...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T21:00:31.000Z ##

🟠 CVE-2026-92943 - High (8.1)

Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might allow an adversary-in-the-middle actor to impersonate the AWS IoT Core...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93337
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-17T21:00:20.000Z ##

🟠 CVE-2026-93337 - High (7.8)

NetworkManager-l2tp contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd directives by supplying mru or mtu property values containing trailing non-numeric co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T21:00:20.000Z ##

🟠 CVE-2026-93337 - High (7.8)

NetworkManager-l2tp contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd directives by supplying mru or mtu property values containing trailing non-numeric co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85500
(0 None)

EPSS: 0.00%

2 posts

N/A

offseq at 2026-09-17T13:30:29.257Z ##

CVE-2026-85500: team-alembic ash_authentication (4.3.8 – 4.15.0, 5.0.0-rc.14) suffers a CRITICAL auth bypass — unconfirmed users may gain sessions, defeating email confirmation. Patch urgently. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-17T13:30:29.000Z ##

CVE-2026-85500: team-alembic ash_authentication (4.3.8 – 4.15.0, 5.0.0-rc.14) suffers a CRITICAL auth bypass — unconfirmed users may gain sessions, defeating email confirmation. Patch urgently. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #CVE202685500 #AshAuthentication

##

CVE-2026-59347
(0 None)

EPSS: 0.00%

2 posts

N/A

sekurakbot@mastodon.com.pl at 2026-09-17T13:24:00.000Z ##

VMware łata poważne błędy w Workstation i Fusion. Można wyskoczyć z maszyny wirtualnej i wykonać kod na hoście

Broadcom poinformował o załataniu dwóch poważnych błędów w popularnych produktach VMware Workstation oraz VMware Fusion. W określonych warunkach ich wykorzystanie mogło doprowadzić do ucieczki z maszyny wirtualnej oraz wykonanie kodu bezpośrednio na hoście. TLDR: Podatności otrzymały identyfikatory CVE-2026-59346 (CVSS 9.3) oraz CVE-2026-59347 (CVSS 8.1). Pierwsza z nich to błąd typu...

#WBiegu

sekurak.pl/vmware-lata-powazne

##

sekurakbot@mastodon.com.pl at 2026-09-17T13:24:00.000Z ##

VMware łata poważne błędy w Workstation i Fusion. Można wyskoczyć z maszyny wirtualnej i wykonać kod na hoście

Broadcom poinformował o załataniu dwóch poważnych błędów w popularnych produktach VMware Workstation oraz VMware Fusion. W określonych warunkach ich wykorzystanie mogło doprowadzić do ucieczki z maszyny wirtualnej oraz wykonanie kodu bezpośrednio na hoście. TLDR: Podatności otrzymały identyfikatory CVE-2026-59346 (CVSS 9.3) oraz CVE-2026-59347 (CVSS 8.1). Pierwsza z nich to błąd typu...

#WBiegu

sekurak.pl/vmware-lata-powazne

##

CVE-2026-59346
(0 None)

EPSS: 0.00%

2 posts

N/A

1 repos

https://github.com/0xCyberstan/CVE-2026-59346-POC

sekurakbot@mastodon.com.pl at 2026-09-17T13:24:00.000Z ##

VMware łata poważne błędy w Workstation i Fusion. Można wyskoczyć z maszyny wirtualnej i wykonać kod na hoście

Broadcom poinformował o załataniu dwóch poważnych błędów w popularnych produktach VMware Workstation oraz VMware Fusion. W określonych warunkach ich wykorzystanie mogło doprowadzić do ucieczki z maszyny wirtualnej oraz wykonanie kodu bezpośrednio na hoście. TLDR: Podatności otrzymały identyfikatory CVE-2026-59346 (CVSS 9.3) oraz CVE-2026-59347 (CVSS 8.1). Pierwsza z nich to błąd typu...

#WBiegu

sekurak.pl/vmware-lata-powazne

##

sekurakbot@mastodon.com.pl at 2026-09-17T13:24:00.000Z ##

VMware łata poważne błędy w Workstation i Fusion. Można wyskoczyć z maszyny wirtualnej i wykonać kod na hoście

Broadcom poinformował o załataniu dwóch poważnych błędów w popularnych produktach VMware Workstation oraz VMware Fusion. W określonych warunkach ich wykorzystanie mogło doprowadzić do ucieczki z maszyny wirtualnej oraz wykonanie kodu bezpośrednio na hoście. TLDR: Podatności otrzymały identyfikatory CVE-2026-59346 (CVSS 9.3) oraz CVE-2026-59347 (CVSS 8.1). Pierwsza z nich to błąd typu...

#WBiegu

sekurak.pl/vmware-lata-powazne

##

CVE-2026-78428
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-17T11:00:42.000Z ##

🟠 CVE-2026-78428 - High (8)

For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T11:00:42.000Z ##

🟠 CVE-2026-78428 - High (8)

For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90711
(0 None)

EPSS: 0.19%

1 posts

N/A

DailyCyberSecurity@infosec.exchange at 2026-09-16T01:18:01.000Z ##

A critical proxy-addr IP spoofing flaw (CVE-2026-90711) exposes Node.js apps to access control bypasses. Patch this proxy-addr IP spoofing bug today.

#ProxyAddr #NodeJS #IPspoofing #CVE202690711 #Cybersecurity

securityonline.info/proxy-addr

##

CVE-2026-61642
(0 None)

EPSS: 0.00%

1 posts

N/A

DailyCyberSecurity@infosec.exchange at 2026-09-16T00:32:00.000Z ##

Multiple critical Squid proxy vulnerabilities, including CVE-2026-61642, allow request smuggling and buffer overflows. Patch your servers immediately.

#SquidProxy #CVE202661642 #Cybersecurity #Vulnerability #InfoSec

securityonline.info/squid-prox

##

CVE-2026-85498
(0 None)

EPSS: 0.00%

1 posts

N/A

ottoto2017@prattohome.com at 2026-09-16T00:18:47.000Z ##

#Ubuntu 24.04.5 で #update

krb5 (1.20.1-6ubuntu2.10)
セキュリティ対応ではない。
krb5-locales
libgssapi-krb5-2
libk5crypto3
libkrb5-3
libkrb5support0

netplan.io (1.1.2-8ubuntu1~24.04.3)
セキュリティ対応ではない。
libnetplan1
netplan-generator
python3-netplan

policykit-1 (124-2ubuntu1.24.04.4)
CVE-2026-85498へのセキュリティ対応。
libpolkit-agent-1-0
libpolkit-gobject-1-0
libsrt1.5-gnutls
polkitd

セキュリティ対応もあるので、お早めに。

#prattohome #更新

##

CVE-2026-57586
(0 None)

EPSS: 0.15%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-15T16:01:44.000Z ##

🟠 CVE-2026-57586 - High (8.6)

CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the default agent-coderag sync flow in code_rag/entry/cli.py calls sync_dependencies for an indexed path, and code_rag/core/manager.py tre...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites