## Updated at UTC 2026-06-18T00:46:11.720030

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-53843 8.8 0.29% 1 0 2026-06-17T21:03:35.460000 OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a
CVE-2026-53849 8.1 0.21% 1 0 2026-06-17T21:03:01.847000 OpenClaw before 2026.5.7 contains a privilege escalation vulnerability where the
CVE-2026-53853 8.3 0.34% 1 0 2026-06-17T21:01:52.893000 OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the
CVE-2026-53866 8.1 0.27% 1 0 2026-06-17T20:31:38.593000 OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell in
CVE-2026-3894 0 0.00% 2 1 2026-06-17T20:20:10.920000 Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) al
CVE-2026-55200 8.1 0.00% 2 0 2026-06-17T20:17:28.667000 libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write
CVE-2026-50656 7.8 0.39% 6 0 2026-06-17T19:10:40.163000 Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect
CVE-2026-48907 9.8 4.66% 8 6 template 2026-06-17T18:36:17 A vulnerability in the JCE editor extension for Joomla allows the creation of ne
CVE-2026-20190 7.5 0.00% 2 0 2026-06-17T18:36:07 A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote
CVE-2026-20181 9.1 0.00% 4 0 2026-06-17T18:36:07 A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote at
CVE-2026-54187 9.3 0.00% 1 0 2026-06-17T18:35:59 Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions.
CVE-2026-12442 8.8 0.39% 1 0 2026-06-17T18:35:53 Use after free in Passwords in Google Chrome on Android prior to 149.0.7827.155
CVE-2026-46850 9.9 0.45% 1 0 2026-06-17T18:35:38 Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for V
CVE-2026-5079 7.5 0.28% 1 0 2026-06-17T18:12:28 ### Impact Multer is vulnerable to a Denial of Service (DoS) via deeply nested
CVE-2026-39560 8.1 0.00% 1 0 2026-06-17T17:16:50.220000 Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.
CVE-2026-22313 9.1 0.92% 2 0 2026-06-17T17:16:43.687000 The device has a webserver that exposes a REST API authenticated with a token on
CVE-2026-47750 7.8 0.14% 1 0 2026-06-17T15:16:58.713000 stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable
CVE-2019-25293 7.8 0.13% 1 0 2026-06-17T15:16:33.170000 BlueStacks App Player 2.4.44.62.57 contains an unquoted service path vulnerabili
CVE-2026-12440 9.6 0.31% 1 0 2026-06-17T14:49:58.487000 Use after free in DigitalCredentials in Google Chrome on Windows prior to 149.0.
CVE-2026-12441 8.8 0.29% 1 0 2026-06-17T14:49:58.487000 Use after free in File Input in Google Chrome on Linux prior to 149.0.7827.155 a
CVE-2026-12443 8.8 0.44% 1 0 2026-06-17T14:49:58.487000 Use after free in Web Authentication in Google Chrome prior to 149.0.7827.155 al
CVE-2026-47964 7.8 0.20% 1 0 2026-06-17T13:20:42.017000 DNG SDK versions 1.7.1 2536 and earlier are affected by a Heap-based Buffer Over
CVE-2026-24228 7.8 0.16% 4 0 2026-06-17T13:20:10.550000 NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may c
CVE-2026-24155 7.8 0.19% 4 0 2026-06-17T13:20:10.417000 NVIDIA NeMo Framework for all platforms contains a code injection vulnerability.
CVE-2026-22312 8.6 0.23% 2 0 2026-06-17T13:20:06.023000 The device has a webserver that exposes a REST API authenticated with a constant
CVE-2026-8176 7.5 0.35% 1 0 2026-06-17T11:03:34.817000 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for W
CVE-2026-5416 8.8 0.77% 2 0 2026-06-17T10:58:59.553000 Due to the improper neutralization of special elements used in a name parameter
CVE-2026-52715 9.3 0.25% 1 0 2026-06-17T10:57:51.463000 Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions.
CVE-2026-49110 7.5 0.24% 1 0 2026-06-17T10:55:31.073000 Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce
CVE-2026-49109 9.8 0.38% 1 0 2026-06-17T10:55:30.973000 Unauthenticated PHP Object Injection in Integration for Salesforce and Contact F
CVE-2026-49106 9.8 0.38% 1 0 2026-06-17T10:55:30.877000 Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Const
CVE-2026-49105 9.8 0.38% 1 1 2026-06-17T10:55:30.777000 Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms,
CVE-2026-49104 9.8 0.38% 1 1 2026-06-17T10:55:30.680000 Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Co
CVE-2026-49085 9.8 0.38% 1 1 2026-06-17T10:55:30.020000 Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms
CVE-2026-49068 7.5 0.40% 1 0 2026-06-17T10:55:29.337000 Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions.
CVE-2026-49066 7.5 0.30% 1 0 2026-06-17T10:55:29.137000 Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway <= 6.0.0 vers
CVE-2026-49065 8.2 0.24% 1 0 2026-06-17T10:55:29.037000 Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.
CVE-2026-49064 7.5 0.24% 1 0 2026-06-17T10:55:28.940000 Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPa
CVE-2026-49062 8.8 0.30% 1 0 2026-06-17T10:55:28.747000 Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Eng
CVE-2026-49061 7.5 0.37% 1 0 2026-06-17T10:55:28.650000 Unauthenticated Arbitrary File Download in WPC Product Options for WooCommerce <
CVE-2026-48853 0 0.57% 1 0 2026-06-17T10:55:18.207000 Deserialization of Untrusted Data and Allocation of Resources Without Limits or
CVE-2026-48095 8.8 0.70% 1 1 2026-06-17T10:54:50.997000 7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior
CVE-2026-47777 7.5 0.17% 1 0 2026-06-17T10:54:40.050000 Mastodon is a free, open-source social network server based on ActivityPub. In v
CVE-2026-47749 7.8 0.16% 1 0 2026-06-17T10:54:39.427000 stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable
CVE-2026-39581 8.5 0.27% 1 0 2026-06-17T10:42:19.677000 Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4
CVE-2026-25089 9.8 2.66% 1 2 2026-06-17T10:24:06.250000 A improper neutralization of special elements used in an os command ('os command
CVE-2026-12205 9.1 0.29% 1 0 2026-06-17T10:14:40.940000 Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, lea
CVE-2026-12161 8.8 0.29% 1 0 2026-06-17T10:14:38.280000 Improper input validation in the SSH Elevate Shell feature in Devolutions Remot
CVE-2026-12087 9.1 0.39% 1 0 2026-06-17T10:14:37.383000 Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socke
CVE-2026-11832 9.1 0.33% 1 0 2026-06-17T10:14:29.377000 Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predicta
CVE-2026-0843 6.3 0.20% 1 0 2026-06-17T10:11:29.160000 A vulnerability has been found in jiujiujia/victor123/wxw850227 jjjfood and jjjs
CVE-2025-8088 8.8 81.35% 1 32 2026-06-17T10:06:17.243000 A path traversal vulnerability affecting the Windows version of WinRAR allows th
CVE-2025-71261 8.6 0.21% 1 0 2026-06-17T10:03:58.203000 An attacker with network-level access between the SUSE Virtualization and Ranch
CVE-2019-16534 6.1 0.80% 1 0 2026-06-17T02:22:23.067000 On DrayTek Vigor2925 devices with firmware 3.8.4.3, XSS exists via a crafted WAN
CVE-2019-16533 6.1 0.80% 1 0 2026-06-17T02:22:22.927000 On DrayTek Vigor2925 devices with firmware 3.8.4.3, Incorrect Access Control exi
CVE-2017-9542 9.8 5.07% 1 0 2026-06-17T01:28:19.940000 D-Link DIR-615 Wireless N 300 Router allows authentication bypass via a modified
CVE-2026-12317 7.5 0.31% 1 0 2026-06-16T21:33:05 Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox
CVE-2026-12316 9.1 0.27% 1 0 2026-06-16T21:33:05 Mitigation bypass in the DOM: Security component. This vulnerability was fixed i
CVE-2026-12314 7.5 0.27% 1 0 2026-06-16T21:33:05 Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox
CVE-2026-12305 7.5 0.40% 1 0 2026-06-16T21:33:04 Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox
CVE-2026-53864 8.1 0.25% 1 0 2026-06-16T21:32:08 OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in
CVE-2026-53855 8.1 0.27% 1 0 2026-06-16T21:31:59 OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing a
CVE-2026-53857 8.1 0.21% 1 0 2026-06-16T21:31:59 OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo
CVE-2026-12003 None 0.14% 4 0 2026-06-16T21:31:56 To allow builds of Python to be run from an in-tree layout (rather than an insta
CVE-2026-12312 7.5 0.27% 1 0 2026-06-16T21:31:56 Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox
CVE-2026-12310 7.5 0.27% 1 0 2026-06-16T21:31:56 Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox
CVE-2026-12315 9.1 0.28% 1 0 2026-06-16T21:31:56 Mitigation bypass in the DOM: Security component. This vulnerability was fixed i
CVE-2026-10649 8.6 0.46% 1 0 2026-06-16T21:31:56 A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an
CVE-2026-12304 9.1 0.19% 1 0 2026-06-16T21:31:55 Same-origin policy bypass in the Networking: Cookies component. This vulnerabili
CVE-2026-12289 8.8 0.32% 1 0 2026-06-16T18:33:39 Privilege escalation in the Graphics: WebRender component. This vulnerability wa
CVE-2026-44932 8.8 0.49% 1 0 2026-06-16T18:32:44 Passing of unsanitized strings from DHCP replies into the wicked dhcp client bef
CVE-2026-12328 8.1 0.30% 1 0 2026-06-16T18:32:38 Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbir
CVE-2026-20253 9.8 1.73% 2 3 template 2026-06-16T15:34:50 In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform
CVE-2026-12398 7.5 0.89% 1 0 2026-06-16T15:34:03 A command injection vulnerability was found in galaxy_ng. The do_git_checkout()
CVE-2026-11317 None 0.30% 1 0 2026-06-16T15:34:02 A denial of service security issue exists in the affected product. The security
CVE-2026-40750 9.9 0.27% 1 0 2026-06-16T12:32:12 Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52
CVE-2026-8442 8.1 0.52% 1 0 2026-06-16T12:32:12 The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File De
CVE-2025-68045 7.5 0.23% 1 0 2026-06-16T12:32:07 Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.
CVE-2026-52712 7.6 0.24% 1 0 2026-06-16T12:32:07 Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions.
CVE-2026-52711 7.5 0.23% 1 0 2026-06-16T12:32:07 Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions.
CVE-2026-49774 9.9 0.41% 1 0 2026-06-16T12:32:07 Improper Control of Generation of Code ('Code Injection') vulnerability in Filip
CVE-2026-49772 9.3 0.24% 1 0 2026-06-16T12:32:07 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CVE-2026-39574 9.3 0.23% 1 0 2026-06-16T12:32:07 Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions.
CVE-2026-39490 7.5 0.30% 1 0 2026-06-16T12:32:07 Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.
CVE-2026-8444 8.8 0.25% 1 0 2026-06-16T09:32:42 The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via
CVE-2026-8443 8.8 0.25% 1 0 2026-06-16T06:30:31 The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via
CVE-2026-6933 8.8 0.59% 1 0 2026-06-16T06:30:31 The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execut
CVE-2026-7273 8.8 0.28% 1 0 2026-06-16T03:30:37 A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-4
CVE-2026-20262 6.5 1.15% 11 2 2026-06-15T21:31:39 A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN
CVE-2026-49112 7.5 0.33% 1 0 2026-06-15T21:31:02 Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.
CVE-2026-49781 9.8 0.38% 2 0 2026-06-15T21:31:02 Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions.
CVE-2026-52693 9.3 0.30% 2 0 2026-06-15T21:31:02 Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions.
CVE-2026-49769 9.8 0.38% 1 0 2026-06-15T21:31:02 Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions.
CVE-2026-49768 9.8 0.55% 1 0 2026-06-15T21:31:02 Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions.
CVE-2026-49766 9.9 0.51% 1 0 2026-06-15T21:31:02 Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions.
CVE-2026-49765 9.8 0.38% 1 0 2026-06-15T21:31:02 Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Fo
CVE-2026-49764 9.8 0.40% 1 0 2026-06-15T21:31:02 Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions.
CVE-2026-52703 9.6 0.35% 2 0 2026-06-15T21:31:02 Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.
CVE-2026-49763 9.8 0.38% 1 0 2026-06-15T21:31:02 Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <
CVE-2026-49780 8.8 0.28% 1 0 2026-06-15T21:31:02 Customer Privilege Escalation in Dokan <= 5.0.2 versions.
CVE-2026-49776 9.3 0.29% 1 0 2026-06-15T21:31:02 Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for W
CVE-2026-49770 9.8 0.38% 1 0 2026-06-15T21:31:02 Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.
CVE-2026-52692 7.5 0.24% 1 0 2026-06-15T21:31:02 Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions
CVE-2026-52700 8.5 0.35% 1 0 2026-06-15T21:31:02 Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions.
CVE-2026-52699 7.5 0.24% 1 0 2026-06-15T21:31:02 Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5
CVE-2026-52697 8.5 0.35% 1 0 2026-06-15T21:31:02 Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions.
CVE-2026-52695 7.5 0.25% 1 0 2026-06-15T21:31:02 Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions
CVE-2026-9691 9.8 0.38% 1 1 2026-06-15T21:31:02 Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Conta
CVE-2026-52694 7.5 0.24% 1 0 2026-06-15T21:31:02 Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2
CVE-2026-49067 9.3 0.30% 1 0 2026-06-15T21:30:59 Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions
CVE-2026-49083 7.5 0.31% 1 2 2026-06-15T21:30:59 Contributor Privilege Escalation in LatePoint <= 5.5.1 versions.
CVE-2026-54420 8.5 0.65% 6 3 2026-06-15T21:30:32 LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn bef
CVE-2026-11526 9.8 2.46% 1 0 2026-06-15T18:32:21 GD versions before 2.86 for Perl allow OS command injection and file overwrite v
CVE-2026-9863 7.5 0.57% 1 0 2026-06-15T18:31:25 Fortra BoKS Manager contains an OS command injection vulnerability in the client
CVE-2026-9862 9.8 0.84% 2 0 2026-06-15T18:31:25 Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection
CVE-2026-49111 8.8 0.24% 1 0 2026-06-15T15:31:40 Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allow
CVE-2026-52704 10.0 0.31% 2 0 2026-06-15T15:31:39 Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar
CVE-2026-5242 8.8 0.30% 1 0 2026-06-15T15:31:39 Improper neutralization of formula elements in a CSV file vulnerability in MIA T
CVE-2026-34022 None 0.12% 1 0 2026-06-15T15:31:32 The Wertheim SafeController Family 65000, Controller 65000 - AssemblyVersion 6.1
CVE-2026-5482 None 0.45% 1 0 2026-06-15T12:32:56 Responsive FileManager's allows an unauthenticated attacker to upload files of a
CVE-2026-12057 8.6 0.13% 1 0 2026-06-15T12:32:51 When the application executes the JavaScript script embedded in the PDF within t
CVE-2026-44188 5.3 0.44% 1 0 2026-06-15T12:32:51 A flaw was found in Ansible Lightspeed. This vulnerability, related to insuffici
CVE-2026-11860 None 0.36% 1 0 2026-06-15T12:32:51 Quick.CMS deserializes user-controlled data received over plaintext HTTP without
CVE-2026-12221 8.0 0.37% 1 0 2026-06-15T06:31:46 A vulnerability was found in Yealink SIP-T46U 108.86.0.118. This impacts the fun
CVE-2026-44488 7.5 0.49% 1 0 2026-06-12T19:24:52 ## Summary Axios versions `1.7.0` through `1.15.x` did not enforce configured r
CVE-2026-44487 None 0.43% 1 0 2026-06-12T19:24:48 ## Summary Axios’s Node.js HTTP adapter may forward a `Proxy-Authorization` hea
CVE-2026-48558 10.0 0.63% 2 0 2026-06-12T18:32:06 SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an aut
CVE-2026-35273 9.8 0.72% 2 3 2026-06-12T18:31:50 Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleS
CVE-2026-53435 8.8 0.37% 1 1 2026-06-10T18:31:45 In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attack
CVE-2026-11645 8.8 0.71% 1 3 2026-06-09T18:30:35 Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allo
CVE-2026-42271 8.8 53.70% 2 2 template 2026-06-09T13:07:08 ### Impact Two endpoints used to preview an MCP server before saving it — `POST
CVE-2026-0257 9.1 18.58% 2 10 template 2026-06-09T12:32:02 Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of
CVE-2026-48017 8.8 0.58% 1 1 2026-06-05T16:39:39 ### Summary The `POST /runners/load-reader` endpoint in DbGate accepts a `funct
CVE-2026-47684 7.7 0.38% 1 0 2026-06-05T16:35:00 Summary: The private IP blocklist regex used in the URL download feature does no
CVE-2026-42824 6.5 0.50% 3 0 2026-06-05T00:32:02 Improper neutralization of special elements used in a command ('command injectio
CVE-2026-8206 9.8 0.62% 1 3 2026-06-02T06:30:33 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordP
CVE-2026-42089 8.6 0.19% 1 0 2026-05-26T23:10:40 ### Impact `yeoman-environment` versions `>= 2.9.0` and `< 6.0.1` install missi
CVE-2026-39808 9.8 66.17% 1 5 template 2026-04-22T15:32:37 A improper neutralization of special elements used in an os command ('os command
CVE-2026-39813 9.8 18.01% 1 2 2026-04-14T18:30:41 A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 thro
CVE-2026-4272 8.1 0.45% 1 0 2026-04-06T00:30:31 Missing Authentication for Critical Function vulnerability in Honeywell Handheld
CVE-2026-4020 7.5 2.98% 4 0 template 2026-03-31T03:31:35 The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exp
CVE-2026-2751 8.3 0.27% 1 1 2026-02-27T15:34:20 Blind SQL Injection via unsanitized array keys in Service Dependencies deletion.
CVE-2026-21265 6.4 0.97% 1 0 2026-01-13T18:31:19 Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These
CVE-2026-20953 8.4 0.60% 1 0 2026-01-13T18:31:18 Use after free in Microsoft Office allows an unauthorized attacker to execute co
CVE-2026-20952 8.4 0.50% 1 0 2026-01-13T18:31:18 Use after free in Microsoft Office allows an unauthorized attacker to execute co
CVE-2024-39683 5.7 0.61% 1 0 2024-08-08T05:06:35 ### Impact ZITADEL provides users the ability to list all user sessions of the
CVE-2021-45464 8.8 0.38% 1 0 2024-04-04T03:30:13 kvmtool through 39181fc allows an out-of-bounds write, related to virtio/balloon
CVE-2019-16193 5.4 0.62% 1 0 2024-04-04T01:55:17 In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a C
CVE-2026-46701 0 0.00% 1 0 N/A
CVE-2026-12530 0 0.00% 2 0 N/A
CVE-2026-48814 0 0.00% 2 0 N/A
CVE-2026-8024 0 0.00% 2 0 N/A
CVE-2026-24252 0 0.00% 3 0 N/A
CVE-2026-4855 0 0.00% 2 0 N/A
CVE-2026-47103 0 0.00% 2 0 N/A
CVE-2026-48745 0 0.41% 1 0 N/A
CVE-2026-48797 0 0.44% 1 0 N/A
CVE-2026-47747 0 0.14% 1 0 N/A
CVE-2026-53776 0 0.36% 1 0 N/A
CVE-2026-48780 0 0.22% 1 0 N/A
CVE-2025-68615 0 42.69% 1 0 N/A
CVE-2026-48713 0 0.38% 2 0 N/A
CVE-2026-48714 0 0.38% 2 0 N/A
CVE-2026-48723 0 0.53% 1 0 N/A
CVE-2026-49757 0 0.44% 1 0 N/A

CVE-2026-53843
(8.8 HIGH)

EPSS: 0.29%

updated 2026-06-17T21:03:35.460000

1 posts

OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped device session can re-establish node token authority after revocation. Attackers with a paired device can regain WebSocket node-level access without renewed approval, weakening revocation controls and maintaining unauthorized access longer than intended.

thehackerwire@mastodon.social at 2026-06-17T02:00:14.000Z ##

🟠 CVE-2026-53843 - High (8.8)

OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped device session can re-establish node token authority after revocation. Attackers with a paired device can regain WebSocket node-level access ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53849
(8.1 HIGH)

EPSS: 0.21%

updated 2026-06-17T21:03:01.847000

1 posts

OpenClaw before 2026.5.7 contains a privilege escalation vulnerability where the allowFrom feature improperly validates Discord account identity using mutable display names instead of immutable user IDs. Attackers with Discord accounts can change their display name to match a policy entry and gain unauthorized agent access intended for another Discord identity.

thehackerwire@mastodon.social at 2026-06-16T21:01:05.000Z ##

🟠 CVE-2026-53849 - High (8.1)

OpenClaw before 2026.5.7 contains a privilege escalation vulnerability where the allowFrom feature improperly validates Discord account identity using mutable display names instead of immutable user IDs. Attackers with Discord accounts can change ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53853
(8.3 HIGH)

EPSS: 0.34%

updated 2026-06-17T21:01:52.893000

1 posts

OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows attackers to execute disallowed arguments for allowlisted executables on Linux and macOS systems. Attackers can bypass configured argPattern restrictions by directly invoking allowlisted executables with unrestricted arguments, potentially enabling unauthorized file access, network access, or

thehackerwire@mastodon.social at 2026-06-16T21:01:14.000Z ##

🟠 CVE-2026-53853 - High (8.3)

OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows attackers to execute disallowed arguments for allowlisted executables on Linux and macOS systems. Attackers can bypass configured argPattern...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53866
(8.1 HIGH)

EPSS: 0.27%

updated 2026-06-17T20:31:38.593000

1 posts

OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authenticated operators to execute unapproved commands. A command request using shell inline-command forms could route through a parser case missing the expected allowlist decision, enabling shell content execution without intended approval prompts.

thehackerwire@mastodon.social at 2026-06-16T19:59:50.000Z ##

🟠 CVE-2026-53866 - High (8.1)

OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authenticated operators to execute unapproved commands. A command request using shell inline-command forms could route through a parse...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-3894
(0 None)

EPSS: 0.00%

updated 2026-06-17T20:20:10.920000

2 posts

Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.0.0 before 5.2.*.

1 repos

https://github.com/Wise-Security/CVE-2026-38945

offseq at 2026-06-17T23:30:11.603Z ##

CVE-2026-3894 (CRITICAL, CVSS 9.2): Out-of-bounds read in RTI Connext Professional (versions 7.4.0, 7.0.0, 6.1.0, 6.0.0, 5.3.0, 5.0.0). Remote exploitation possible, no patch yet. Monitor vendor updates! radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-06-17T23:30:11.000Z ##

CVE-2026-3894 (CRITICAL, CVSS 9.2): Out-of-bounds read in RTI Connext Professional (versions 7.4.0, 7.0.0, 6.1.0, 6.0.0, 5.3.0, 5.0.0). Remote exploitation possible, no patch yet. Monitor vendor updates! radar.offseq.com/threat/cve-20 #OffSeq #CVE20263894 #ICS #vuln

##

CVE-2026-55200
(8.1 HIGH)

EPSS: 0.00%

updated 2026-06-17T20:17:28.667000

2 posts

libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution.

cR0w at 2026-06-17T22:07:09.667Z ##

Oh my.

nvd.nist.gov/vuln/detail/CVE-2

sev:HIGH 8.1 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution.

##

cR0w@infosec.exchange at 2026-06-17T22:07:09.000Z ##

Oh my.

nvd.nist.gov/vuln/detail/CVE-2

sev:HIGH 8.1 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution.

##

CVE-2026-50656
(7.8 HIGH)

EPSS: 0.39%

updated 2026-06-17T19:10:40.163000

6 posts

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;RoguePlanet &quot;. We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.

sayzard@mastodon.sayzard.org at 2026-06-17T23:41:05.000Z ##

Zero-Day 'RoguePlanet' in Microsoft Defender Grants System-Level Control

Microsoft Defender에서 발견된 'RoguePlanet' 제로데이 취약점은 TOCTOU 경쟁 조건을 악용해 일반 사용자 권한으로 SYSTEM 권한을 획득할 수 있는 심각한 로컬 권한 상승(LPE) 문제입니다. 이 취약점은 2026년 6월 패치 이후에도 작동하며, 공격자는 악성 파일을 Defender가 검사하는 순간 심볼릭 링크로 교체해 보호된 시스템 파일에 임의 쓰기 및 코드 실행이 가능합니다. Microsoft는 CVE-2026-50656으로 공식...

cyber.netsecops.io/articles/ro

##

halildeniz@mastodon.social at 2026-06-17T21:45:23.000Z ##

New zero-day Local Privilege Escalation (EoP) flaw in Microsoft Defender: CVE-2026-50656 (RoguePlanet)! 🚨

Low-privilege users can abuse a TOCTOU race condition to hijack system paths and spawn an NT AUTHORITY\SYSTEM shell. Deep dive analysis here:👇

denizhalil.com/2026/06/18/cve-

#CVE202650656 #MicrosoftDefender #infosec

##

AAKL at 2026-06-17T18:01:10.869Z ##

New.

Tenable research advisories:

CRITICAL: CVE-2026-8024: iba ibaPDA / ibaDatCoordinator .NET Deserialization Remote Code Execution tenable.com/security/research/ @tenable

Cisco:

CRITICAL: CVE-2026-20181 and CVE-2026-20190: Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities

Three others of medium-severity: sec.cloudapps.cisco.com/securi @TalosSecurity

Broadcom:

Several critical and high-severity vulnerabilities. A login is needed for details support.broadcom.com/web/ecx/s

Dell:

Several advisories, one of them critical:

CRITICAL: Security Update for Dell Data Protection Central Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0

More: dell.com/support/security/en-us

Google:

Chrome Beta for iOS Update chromereleases.googleblog.com/

Yesterday:

Microsoft:

CVE-2026-50656: Microsoft Defender Elevation of Privilege Vulnerability msrc.microsoft.com/update-guid

Nvidia:

Security Bulletin addressing CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228:

NVIDIA NeMo - June 2026 nvidia.custhelp.com/app/answer

##

AAKL@infosec.exchange at 2026-06-17T18:01:10.000Z ##

New.

Tenable research advisories:

CRITICAL: CVE-2026-8024: iba ibaPDA / ibaDatCoordinator .NET Deserialization Remote Code Execution tenable.com/security/research/ @tenable

Cisco:

CRITICAL: CVE-2026-20181 and CVE-2026-20190: Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities

Three others of medium-severity: sec.cloudapps.cisco.com/securi @TalosSecurity

Broadcom:

Several critical and high-severity vulnerabilities. A login is needed for details support.broadcom.com/web/ecx/s

Dell:

Several advisories, one of them critical:

CRITICAL: Security Update for Dell Data Protection Central Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0

More: dell.com/support/security/en-us

Google:

Chrome Beta for iOS Update chromereleases.googleblog.com/

Yesterday:

Microsoft:

CVE-2026-50656: Microsoft Defender Elevation of Privilege Vulnerability msrc.microsoft.com/update-guid

Nvidia:

Security Bulletin addressing CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228:

NVIDIA NeMo - June 2026 nvidia.custhelp.com/app/answer #Nvidia #Dell #Cisco #infosec #vulnerability #threatresearch #Broadcom #Google #Chrome #Microsoft #Windows

##

thehackerwire@mastodon.social at 2026-06-17T02:00:23.000Z ##

🟠 CVE-2026-50656 - High (7.8)

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;RoguePlanet &quot;. We are working to provide a high quality security update that addresses this vulnera...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

nyanbinary@infosec.exchange at 2026-06-16T20:59:06.000Z ##

Nightmare Eclipses RoguePlanet now has a CVE 🎉: nvd.nist.gov/vuln/detail/cve-2

Not any new detail in there & no fix yet (has only been a week, give them some time...).

Much less relevant but annoying me personally: It taking them a week to ... sorry, shit this out. Broken description in the CVE form & even in the MSRC page it's pretty obvious no one even proofread the non-description. Also empty Acknoledgement section despite link to the Github (not the first time btw)... at least they didn't have it taken down this time? 🙃

##

CVE-2026-48907
(9.8 CRITICAL)

EPSS: 4.66%

updated 2026-06-17T18:36:17

8 posts

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

Nuclei template

6 repos

https://github.com/ywh-jfellus/CVE-2026-48907

https://github.com/0xBlackash/CVE-2026-48907

https://github.com/87achrafg-stack/CVE-2026-48907

https://github.com/webshellseo8/CVE-2026-48907-Unauthenticated-RCE-in-JCE

https://github.com/wearehackers160/CVE-2026-48907

https://github.com/HORKimhab/CVE-2026-48907

thecybermind at 2026-06-17T20:40:10.946Z ##

Alert: CVE-2026-48907. A severe access control flaw in Widget Factory Joomla Content Editor allows unauthenticated PHP script execution. Lock down your CMS. Read our tactical engineering runbook for full IOCs and endpoint hardening steps. thecybermind.co/unjv

🛡️

##

thecybermind at 2026-06-17T16:26:42.070Z ##

URGENT: CVE-2026-48907 is seeing active exploitation in Joomla! JCE extensions. This critical RCE flaw allows unauthenticated attackers to take full control. Read our executive remediation brief to harden your environment now.
thecybermind.co/ic6z

##

thecybermind@infosec.exchange at 2026-06-17T20:40:10.000Z ##

Alert: CVE-2026-48907. A severe access control flaw in Widget Factory Joomla Content Editor allows unauthenticated PHP script execution. Lock down your CMS. Read our tactical engineering runbook for full IOCs and endpoint hardening steps. thecybermind.co/unjv

🛡️ #CyberSecurity #CVE #ThreatIntel

##

thecybermind@infosec.exchange at 2026-06-17T16:26:42.000Z ##

URGENT: CVE-2026-48907 is seeing active exploitation in Joomla! JCE extensions. This critical RCE flaw allows unauthenticated attackers to take full control. Read our executive remediation brief to harden your environment now.
thecybermind.co/ic6z
#CyberSecurity #Joomla #Infosec #KEV

##

decio@infosec.exchange at 2026-06-17T11:54:50.000Z ##

⚠️ Vous administrez un site Joomla ?

Petit point sécurité : la faille CVE-2026-48907 touche l’extension **JCE / Joomla Content Editor **et elle est déjà exploitée automatiquement sur Internet.
👇 🩹
joomlacontenteditor.net/news/j

En clair : un site vulnérable peut être compromis même sans compte public ni inscription ouverte.

À faire dès que possible:
• mettre JCE à jour en 2.9.99.6 ou plus récent
• vérifier les profils/comptes suspects
• changer les mots de passe admin, base de données et hébergement
• lancer un scan serveur

(La mise à jour ferme la porte, mais ne nettoie pas forcément ce qui aurait déjà été déposé.)

🔍
⬇️
vulnerability.circl.lu/vuln/cv

#CyberVeille #Joomla

##

rxerium@infosec.exchange at 2026-06-17T11:20:24.000Z ##

🚨 New critical improper access control vulnerability tagged CVE-2026-48907, affecting Widget Factory Joomla Content Editor is seeing active exploitation in the wild as reported by CISA.

Vulnerability detection script available below:
github.com/rxerium/rxerium-tem

Patches and mitigations are available:
sentinelone.com/vulnerability-

##

secdb@infosec.exchange at 2026-06-16T21:00:17.000Z ##

🚨 [CISA-2026:0616] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48907 (secdb.nttzen.cloud/cve/detail/)
- Name: Widget Factory Joomla Content Editor Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Widget Factory
- Product: Joomla Content Editor
- Notes: joomlacontenteditor.net/news/j ; joomlacontenteditor.net/suppor ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260616 #cisa20260616 #cve_2026_48907 #cve202648907

##

cisakevtracker@mastodon.social at 2026-06-16T20:00:46.000Z ##

CVE ID: CVE-2026-48907
Vendor: Widget Factory
Product: Joomla Content Editor
Date Added: 2026-06-16
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-20190
(7.5 HIGH)

EPSS: 0.00%

updated 2026-06-17T18:36:07

2 posts

A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to sensitive

AAKL at 2026-06-17T18:01:10.869Z ##

New.

Tenable research advisories:

CRITICAL: CVE-2026-8024: iba ibaPDA / ibaDatCoordinator .NET Deserialization Remote Code Execution tenable.com/security/research/ @tenable

Cisco:

CRITICAL: CVE-2026-20181 and CVE-2026-20190: Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities

Three others of medium-severity: sec.cloudapps.cisco.com/securi @TalosSecurity

Broadcom:

Several critical and high-severity vulnerabilities. A login is needed for details support.broadcom.com/web/ecx/s

Dell:

Several advisories, one of them critical:

CRITICAL: Security Update for Dell Data Protection Central Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0

More: dell.com/support/security/en-us

Google:

Chrome Beta for iOS Update chromereleases.googleblog.com/

Yesterday:

Microsoft:

CVE-2026-50656: Microsoft Defender Elevation of Privilege Vulnerability msrc.microsoft.com/update-guid

Nvidia:

Security Bulletin addressing CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228:

NVIDIA NeMo - June 2026 nvidia.custhelp.com/app/answer

##

AAKL@infosec.exchange at 2026-06-17T18:01:10.000Z ##

New.

Tenable research advisories:

CRITICAL: CVE-2026-8024: iba ibaPDA / ibaDatCoordinator .NET Deserialization Remote Code Execution tenable.com/security/research/ @tenable

Cisco:

CRITICAL: CVE-2026-20181 and CVE-2026-20190: Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities

Three others of medium-severity: sec.cloudapps.cisco.com/securi @TalosSecurity

Broadcom:

Several critical and high-severity vulnerabilities. A login is needed for details support.broadcom.com/web/ecx/s

Dell:

Several advisories, one of them critical:

CRITICAL: Security Update for Dell Data Protection Central Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0

More: dell.com/support/security/en-us

Google:

Chrome Beta for iOS Update chromereleases.googleblog.com/

Yesterday:

Microsoft:

CVE-2026-50656: Microsoft Defender Elevation of Privilege Vulnerability msrc.microsoft.com/update-guid

Nvidia:

Security Bulletin addressing CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228:

NVIDIA NeMo - June 2026 nvidia.custhelp.com/app/answer #Nvidia #Dell #Cisco #infosec #vulnerability #threatresearch #Broadcom #Google #Chrome #Microsoft #Windows

##

CVE-2026-20181
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-06-17T18:36:07

4 posts

A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a c

AAKL at 2026-06-17T18:01:10.869Z ##

New.

Tenable research advisories:

CRITICAL: CVE-2026-8024: iba ibaPDA / ibaDatCoordinator .NET Deserialization Remote Code Execution tenable.com/security/research/ @tenable

Cisco:

CRITICAL: CVE-2026-20181 and CVE-2026-20190: Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities

Three others of medium-severity: sec.cloudapps.cisco.com/securi @TalosSecurity

Broadcom:

Several critical and high-severity vulnerabilities. A login is needed for details support.broadcom.com/web/ecx/s

Dell:

Several advisories, one of them critical:

CRITICAL: Security Update for Dell Data Protection Central Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0

More: dell.com/support/security/en-us

Google:

Chrome Beta for iOS Update chromereleases.googleblog.com/

Yesterday:

Microsoft:

CVE-2026-50656: Microsoft Defender Elevation of Privilege Vulnerability msrc.microsoft.com/update-guid

Nvidia:

Security Bulletin addressing CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228:

NVIDIA NeMo - June 2026 nvidia.custhelp.com/app/answer

##

offseq at 2026-06-17T17:30:12.559Z ##

🚨 CRITICAL: CVE-2026-20181 in Cisco ISE (v3.1 – 3.5) allows authenticated attackers to run OS commands & escalate to root, risking DoS. Restrict admin access & monitor for patches. radar.offseq.com/threat/cve-20

##

AAKL@infosec.exchange at 2026-06-17T18:01:10.000Z ##

New.

Tenable research advisories:

CRITICAL: CVE-2026-8024: iba ibaPDA / ibaDatCoordinator .NET Deserialization Remote Code Execution tenable.com/security/research/ @tenable

Cisco:

CRITICAL: CVE-2026-20181 and CVE-2026-20190: Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities

Three others of medium-severity: sec.cloudapps.cisco.com/securi @TalosSecurity

Broadcom:

Several critical and high-severity vulnerabilities. A login is needed for details support.broadcom.com/web/ecx/s

Dell:

Several advisories, one of them critical:

CRITICAL: Security Update for Dell Data Protection Central Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0

More: dell.com/support/security/en-us

Google:

Chrome Beta for iOS Update chromereleases.googleblog.com/

Yesterday:

Microsoft:

CVE-2026-50656: Microsoft Defender Elevation of Privilege Vulnerability msrc.microsoft.com/update-guid

Nvidia:

Security Bulletin addressing CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228:

NVIDIA NeMo - June 2026 nvidia.custhelp.com/app/answer #Nvidia #Dell #Cisco #infosec #vulnerability #threatresearch #Broadcom #Google #Chrome #Microsoft #Windows

##

offseq@infosec.exchange at 2026-06-17T17:30:12.000Z ##

🚨 CRITICAL: CVE-2026-20181 in Cisco ISE (v3.1 – 3.5) allows authenticated attackers to run OS commands & escalate to root, risking DoS. Restrict admin access & monitor for patches. radar.offseq.com/threat/cve-20 #OffSeq #Cisco #Vuln #BlueTeam

##

CVE-2026-54187
(9.3 CRITICAL)

EPSS: 0.00%

updated 2026-06-17T18:35:59

1 posts

Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions.

hugovalters@mastodon.social at 2026-06-17T17:13:35.000Z ##

CVE-2026-54187 - Critical SQLi in JetEngine <= 3.8.10.1. Unauthenticated exploit. CVSS 9.3. Update immediately. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-541

##

CVE-2026-12442
(8.8 HIGH)

EPSS: 0.39%

updated 2026-06-17T18:35:53

1 posts

Use after free in Passwords in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

offseq@infosec.exchange at 2026-06-17T04:30:28.000Z ##

🔴 CRITICAL: CVE-2026-12442 — Chrome on Android <149.0.7827.155 has a use-after-free vuln in Passwords. Remote attackers can execute code via crafted HTML. Update Chrome now! radar.offseq.com/threat/cve-20 #OffSeq #Chrome #Android #Vuln #InfoSec

##

CVE-2026-46850
(9.9 CRITICAL)

EPSS: 0.45%

updated 2026-06-17T18:35:38

1 posts

Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is affected is 2026.2.0+9.6.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise MySQL Shell. While the vulnerability is in MySQL Shell, attacks may significantly impact additional products (scope change). Successful attack

offseq@infosec.exchange at 2026-06-17T10:30:27.000Z ##

Oracle's June 2026 CRITICAL update fixes 245 vulns (incl. CVE-2026-46850) in MySQL Shell, Router, NDB Cluster, Server (8.0.11-8.0.46, 8.4.0-8.4.9, 9.0.0-9.7.0, 2026.2.0+9.6.1). Patch promptly — no exploits yet. radar.offseq.com/threat/kwetsb #OffSeq #MySQL #Oracle #CVE202646850

##

CVE-2026-5079
(7.5 HIGH)

EPSS: 0.28%

updated 2026-06-17T18:12:28

1 posts

### Impact Multer is vulnerable to a Denial of Service (DoS) via deeply nested field names in multipart form data. The `append-field` dependency parses bracket notation in field names (e.g., `a[b][c]`) with no limit on nesting depth, allowing an attacker to force allocation of deeply nested object structures that consume CPU and memory. A single HTTP request with a crafted multipart body is suffi

thehackerwire@mastodon.social at 2026-06-15T18:01:17.000Z ##

🟠 CVE-2026-5079 - High (7.5)

Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested field names in multipart form data. The append-field dependency parses bracket notation in field names with no limit on nesting d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-39560
(8.1 HIGH)

EPSS: 0.00%

updated 2026-06-17T17:16:50.220000

1 posts

Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.

hugovalters@mastodon.social at 2026-06-17T23:13:36.000Z ##

CVE-2026-39560 - Critical PHP Object Injection in Hiroshi <= 1.5.1. Unauthenticated exploit. CVSS 8.1. No patch available. Disable immediately. #CVE #infosec #PHP

valtersit.com/cve/CVE-2026-395

##

CVE-2026-22313
(9.1 CRITICAL)

EPSS: 0.92%

updated 2026-06-17T17:16:43.687000

2 posts

The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability an authenticated attacker can send arbitrary commands to the device that are executed with administrative permissions by the underlying operating system.

cR0w@infosec.exchange at 2026-06-17T12:41:08.000Z ##

Command injection and hardcoded creds in Radiflow iSAP Smart Collector. Nice.

cve.org/CVERecord?id=CVE-2026-

cve.org/CVERecord?id=CVE-2026-

##

thehackerwire@mastodon.social at 2026-06-16T21:00:55.000Z ##

🔴 CVE-2026-22313 - Critical (9.1)

The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability an authenticated attacker can send
arbitrary commands to the device that are executed with...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47750
(7.8 HIGH)

EPSS: 0.14%

updated 2026-06-17T15:16:58.713000

1 posts

stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. In versions prior to master-584-0a7ae07, the pickle .ckpt parser in src/model.cpp contained a heap buffer overflow vulnerability in the GLOBAL opcode handler. The issue was caused by missing validation when searching for newline-delimited fields. A craft

thehackerwire@mastodon.social at 2026-06-16T21:00:11.000Z ##

🟠 CVE-2026-47750 - High (7.8)

stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. In versions prior to master-584-0a7ae07, the pickle .ckpt parser in src/model.cpp contained a heap bu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2019-25293
(7.8 HIGH)

EPSS: 0.13%

updated 2026-06-17T15:16:33.170000

1 posts

BlueStacks App Player 2.4.44.62.57 contains an unquoted service path vulnerability in the BstHdLogRotatorSvc service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe to inject malicious executables and escalate privileges.

nyanbinary@infosec.exchange at 2026-06-17T07:32:12.000Z ##

All* CVE reference URLs are either http, https, or ftp. Y'all need to up your weird protocol games!

*: There is one CVE with a typo in the reference url, https:/ (CVE-2019-25293)

##

CVE-2026-12440
(9.6 CRITICAL)

EPSS: 0.31%

updated 2026-06-17T14:49:58.487000

1 posts

Use after free in DigitalCredentials in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

offseq@infosec.exchange at 2026-06-17T07:30:25.000Z ##

🚨 CRITICAL: CVE-2026-12440 in Chrome DigitalCredentials (Windows <149.0.7827.155) allows remote sandbox escape. Patch to 149.0.7827.155 ASAP! Exploitation risk is high. radar.offseq.com/threat/cve-20 #OffSeq #Chrome #InfoSec #Vulnerability

##

CVE-2026-12441
(8.8 HIGH)

EPSS: 0.29%

updated 2026-06-17T14:49:58.487000

1 posts

Use after free in File Input in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

offseq@infosec.exchange at 2026-06-17T06:00:27.000Z ##

🔒 CRITICAL: CVE-2026-12441 in Chrome <149.0.7827.155 on Linux — use-after-free in File Input. Remote attacker can trigger heap corruption via crafted HTML. Update Chrome ASAP! radar.offseq.com/threat/cve-20 #OffSeq #Chrome #Linux #Vuln

##

CVE-2026-12443
(8.8 HIGH)

EPSS: 0.44%

updated 2026-06-17T14:49:58.487000

1 posts

Use after free in Web Authentication in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

offseq@infosec.exchange at 2026-06-17T03:00:25.000Z ##

🚩 CRITICAL: Chrome Web Authentication use-after-free (CVE-2026-12443) enables remote code execution in versions <149.0.7827.155. Patch immediately to stay secure. Vendor fix available. radar.offseq.com/threat/cve-20 #OffSeq #Chrome #InfoSec #Vuln

##

CVE-2026-47964
(7.8 HIGH)

EPSS: 0.20%

updated 2026-06-17T13:20:42.017000

1 posts

DNG SDK versions 1.7.1 2536 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

thehackerwire@mastodon.social at 2026-06-17T02:00:33.000Z ##

🟠 CVE-2026-47964 - High (7.8)

DNG SDK versions 1.7.1 2536 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vic...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-24228
(7.8 HIGH)

EPSS: 0.16%

updated 2026-06-17T13:20:10.550000

4 posts

NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, data tampering, and information disclosure.

AAKL at 2026-06-17T18:01:10.869Z ##

New.

Tenable research advisories:

CRITICAL: CVE-2026-8024: iba ibaPDA / ibaDatCoordinator .NET Deserialization Remote Code Execution tenable.com/security/research/ @tenable

Cisco:

CRITICAL: CVE-2026-20181 and CVE-2026-20190: Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities

Three others of medium-severity: sec.cloudapps.cisco.com/securi @TalosSecurity

Broadcom:

Several critical and high-severity vulnerabilities. A login is needed for details support.broadcom.com/web/ecx/s

Dell:

Several advisories, one of them critical:

CRITICAL: Security Update for Dell Data Protection Central Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0

More: dell.com/support/security/en-us

Google:

Chrome Beta for iOS Update chromereleases.googleblog.com/

Yesterday:

Microsoft:

CVE-2026-50656: Microsoft Defender Elevation of Privilege Vulnerability msrc.microsoft.com/update-guid

Nvidia:

Security Bulletin addressing CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228:

NVIDIA NeMo - June 2026 nvidia.custhelp.com/app/answer

##

AAKL@infosec.exchange at 2026-06-17T18:01:10.000Z ##

New.

Tenable research advisories:

CRITICAL: CVE-2026-8024: iba ibaPDA / ibaDatCoordinator .NET Deserialization Remote Code Execution tenable.com/security/research/ @tenable

Cisco:

CRITICAL: CVE-2026-20181 and CVE-2026-20190: Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities

Three others of medium-severity: sec.cloudapps.cisco.com/securi @TalosSecurity

Broadcom:

Several critical and high-severity vulnerabilities. A login is needed for details support.broadcom.com/web/ecx/s

Dell:

Several advisories, one of them critical:

CRITICAL: Security Update for Dell Data Protection Central Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0

More: dell.com/support/security/en-us

Google:

Chrome Beta for iOS Update chromereleases.googleblog.com/

Yesterday:

Microsoft:

CVE-2026-50656: Microsoft Defender Elevation of Privilege Vulnerability msrc.microsoft.com/update-guid

Nvidia:

Security Bulletin addressing CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228:

NVIDIA NeMo - June 2026 nvidia.custhelp.com/app/answer #Nvidia #Dell #Cisco #infosec #vulnerability #threatresearch #Broadcom #Google #Chrome #Microsoft #Windows

##

thehackerwire@mastodon.social at 2026-06-16T19:00:15.000Z ##

🟠 CVE-2026-24228 - High (7.8)

NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, data tampering, and informatio...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

AAKL@infosec.exchange at 2026-06-16T15:46:34.000Z ##

Nvidia has a new advisory relating to CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228, all high-severity:

Security Bulletin: NVIDIA NeMo - June 2026 nvidia.custhelp.com/app/answer #Nvidia

Broadcom:

Seven advisories addressing one critical vulnerability and several high-severity flaws: You'll need a login for details.

CRITICAL: MICS 14.3, 14.4, and 14.5 Vulnerabilities

More: support.broadcom.com/web/ecx/s #Broadcom

Yesterday:

Google:

Chrome Dev for Desktop Update chromereleases.googleblog.com/ #Google #Chrome

Dell:

Update for a critical vulnerability yesterday that encompasses multiple CVEs:

Security Update for Dell PowerProtect DP Series Appliance (IDPA) Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #infosec #vulnerability

##

CVE-2026-24155
(7.8 HIGH)

EPSS: 0.19%

updated 2026-06-17T13:20:10.417000

4 posts

NVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

AAKL at 2026-06-17T18:01:10.869Z ##

New.

Tenable research advisories:

CRITICAL: CVE-2026-8024: iba ibaPDA / ibaDatCoordinator .NET Deserialization Remote Code Execution tenable.com/security/research/ @tenable

Cisco:

CRITICAL: CVE-2026-20181 and CVE-2026-20190: Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities

Three others of medium-severity: sec.cloudapps.cisco.com/securi @TalosSecurity

Broadcom:

Several critical and high-severity vulnerabilities. A login is needed for details support.broadcom.com/web/ecx/s

Dell:

Several advisories, one of them critical:

CRITICAL: Security Update for Dell Data Protection Central Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0

More: dell.com/support/security/en-us

Google:

Chrome Beta for iOS Update chromereleases.googleblog.com/

Yesterday:

Microsoft:

CVE-2026-50656: Microsoft Defender Elevation of Privilege Vulnerability msrc.microsoft.com/update-guid

Nvidia:

Security Bulletin addressing CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228:

NVIDIA NeMo - June 2026 nvidia.custhelp.com/app/answer

##

AAKL@infosec.exchange at 2026-06-17T18:01:10.000Z ##

New.

Tenable research advisories:

CRITICAL: CVE-2026-8024: iba ibaPDA / ibaDatCoordinator .NET Deserialization Remote Code Execution tenable.com/security/research/ @tenable

Cisco:

CRITICAL: CVE-2026-20181 and CVE-2026-20190: Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities

Three others of medium-severity: sec.cloudapps.cisco.com/securi @TalosSecurity

Broadcom:

Several critical and high-severity vulnerabilities. A login is needed for details support.broadcom.com/web/ecx/s

Dell:

Several advisories, one of them critical:

CRITICAL: Security Update for Dell Data Protection Central Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0

More: dell.com/support/security/en-us

Google:

Chrome Beta for iOS Update chromereleases.googleblog.com/

Yesterday:

Microsoft:

CVE-2026-50656: Microsoft Defender Elevation of Privilege Vulnerability msrc.microsoft.com/update-guid

Nvidia:

Security Bulletin addressing CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228:

NVIDIA NeMo - June 2026 nvidia.custhelp.com/app/answer #Nvidia #Dell #Cisco #infosec #vulnerability #threatresearch #Broadcom #Google #Chrome #Microsoft #Windows

##

thehackerwire@mastodon.social at 2026-06-16T19:00:05.000Z ##

🟠 CVE-2026-24155 - High (7.8)

NVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

AAKL@infosec.exchange at 2026-06-16T15:46:34.000Z ##

Nvidia has a new advisory relating to CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228, all high-severity:

Security Bulletin: NVIDIA NeMo - June 2026 nvidia.custhelp.com/app/answer #Nvidia

Broadcom:

Seven advisories addressing one critical vulnerability and several high-severity flaws: You'll need a login for details.

CRITICAL: MICS 14.3, 14.4, and 14.5 Vulnerabilities

More: support.broadcom.com/web/ecx/s #Broadcom

Yesterday:

Google:

Chrome Dev for Desktop Update chromereleases.googleblog.com/ #Google #Chrome

Dell:

Update for a critical vulnerability yesterday that encompasses multiple CVEs:

Security Update for Dell PowerProtect DP Series Appliance (IDPA) Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #infosec #vulnerability

##

CVE-2026-22312
(8.6 HIGH)

EPSS: 0.23%

updated 2026-06-17T13:20:06.023000

2 posts

The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be used by an attacker to get access to system settings, modify the configuration and execute some commands (e.g. system reboot).

cR0w@infosec.exchange at 2026-06-17T12:41:08.000Z ##

Command injection and hardcoded creds in Radiflow iSAP Smart Collector. Nice.

cve.org/CVERecord?id=CVE-2026-

cve.org/CVERecord?id=CVE-2026-

##

thehackerwire@mastodon.social at 2026-06-16T21:00:19.000Z ##

🟠 CVE-2026-22312 - High (8.6)

The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be used by an attacker to get access to system settings, modify the configuration
and execute some commands (e.g. system reboot).

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8176
(7.5 HIGH)

EPSS: 0.35%

updated 2026-06-17T11:03:34.817000

1 posts

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 5.5.1. The plugin chains three independent flaws that together allow an authenticated Agent (Agent+) to overwrite a WordPress Administrator's password without ever invoking an Administrator-only API. This makes it possible

thehackerwire@mastodon.social at 2026-06-16T11:01:09.000Z ##

🟠 CVE-2026-8176 - High (7.5)

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 5.5.1. The plugin chains three independent flaws that together allo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5416
(8.8 HIGH)

EPSS: 0.77%

updated 2026-06-17T10:58:59.553000

2 posts

Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker can exploit a command injection vulnerability in the Managed Ethernet Switch, resulting in full system compromise.

thehackerwire@mastodon.social at 2026-06-16T11:00:32.000Z ##

🟠 CVE-2026-5416 - High (8.8)

Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker can exploit a command injection vulnerability in the Managed Ethernet Switch, resulting in full system compromise.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

certvde@infosec.exchange at 2026-06-16T08:17:56.000Z ##

#OT #Advisory VDE-2026-038
TURCK: Multiple Vulnerabilities in Managed Ethernet Switches

Multiple vulnerabilities have been identified in the TBEN-Lx-SE-M2 firmware prior to version 2.1.2.0 in Managed Ethernet Switches.
#CVE CVE-2025-68615, CVE-2026-5416

certvde.com/en/advisories/vde-

#CSAF turck.csaf-tp.certvde.com/.wel

##

CVE-2026-52715
(9.3 CRITICAL)

EPSS: 0.25%

updated 2026-06-17T10:57:51.463000

1 posts

Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions.

thehackerwire@mastodon.social at 2026-06-16T11:00:21.000Z ##

🔴 CVE-2026-52715 - Critical (9.3)

Unauthenticated SQL Injection in GEO my WordPress &lt;= 4.5.5 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49110
(7.5 HIGH)

EPSS: 0.24%

updated 2026-06-17T10:55:31.073000

1 posts

Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce <= 3.1.4 versions.

thehackerwire@mastodon.social at 2026-06-17T10:00:15.000Z ##

🟠 CVE-2026-49110 - High (7.5)

Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce &lt;= 3.1.4 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49109
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-06-17T10:55:30.973000

1 posts

Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 versions.

thehackerwire@mastodon.social at 2026-06-17T10:00:04.000Z ##

🔴 CVE-2026-49109 - Critical (9.8)

Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms &lt;= 1.4.3 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49106
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-06-17T10:55:30.877000

1 posts

Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions.

thehackerwire@mastodon.social at 2026-06-17T09:59:55.000Z ##

🔴 CVE-2026-49106 - Critical (9.8)

Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact &lt;= 1.1.6 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49105
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-06-17T10:55:30.777000

1 posts

Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.

1 repos

https://github.com/izxci/CVE-2026-49105

thehackerwire@mastodon.social at 2026-06-17T08:00:16.000Z ##

🔴 CVE-2026-49105 - Critical (9.8)

Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms &lt;= 1.1.4 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49104
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-06-17T10:55:30.680000

1 posts

Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 versions.

1 repos

https://github.com/izxci/CVE-2026-49104-

thehackerwire@mastodon.social at 2026-06-17T08:00:04.000Z ##

🔴 CVE-2026-49104 - Critical (9.8)

Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms &lt;= 1.2.1 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49085
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-06-17T10:55:30.020000

1 posts

Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.

1 repos

https://github.com/izxci/CVE-2026-49085

thehackerwire@mastodon.social at 2026-06-17T07:59:55.000Z ##

🔴 CVE-2026-49085 - Critical (9.8)

Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms &lt;= 1.1.4 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49068
(7.5 HIGH)

EPSS: 0.40%

updated 2026-06-17T10:55:29.337000

1 posts

Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions.

thehackerwire@mastodon.social at 2026-06-17T13:00:12.000Z ##

🟠 CVE-2026-49068 - High (7.5)

Subscriber Sensitive Data Exposure in Coupon Affiliates &lt;= 7.8.1 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49066
(7.5 HIGH)

EPSS: 0.30%

updated 2026-06-17T10:55:29.137000

1 posts

Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway <= 6.0.0 versions.

thehackerwire@mastodon.social at 2026-06-17T12:59:52.000Z ##

🟠 CVE-2026-49066 - High (7.5)

Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway &lt;= 6.0.0 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49065
(8.2 HIGH)

EPSS: 0.24%

updated 2026-06-17T10:55:29.037000

1 posts

Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions.

thehackerwire@mastodon.social at 2026-06-17T12:00:19.000Z ##

🟠 CVE-2026-49065 - High (8.2)

Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce &lt;= 1.9.5 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49064
(7.5 HIGH)

EPSS: 0.24%

updated 2026-06-17T10:55:28.940000

1 posts

Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensitive Data. This issue affects GetPaid: from n/a through 2.8.49.

thehackerwire@mastodon.social at 2026-06-15T20:00:21.000Z ##

🟠 CVE-2026-49064 - High (7.5)

Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensitive Data.

This issue affects GetPaid: from n/a through 2.8.49.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49062
(8.8 HIGH)

EPSS: 0.30%

updated 2026-06-17T10:55:28.747000

1 posts

Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recovery Exploitation. This issue affects Faust.Js: from n/a through 1.8.7.

thehackerwire@mastodon.social at 2026-06-15T18:02:43.000Z ##

🟠 CVE-2026-49062 - High (8.8)

Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recovery Exploitation.

This issue affects Faust.Js: from n/a through 1.8.7.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49061
(7.5 HIGH)

EPSS: 0.37%

updated 2026-06-17T10:55:28.650000

1 posts

Unauthenticated Arbitrary File Download in WPC Product Options for WooCommerce <= 3.2.1 versions.

thehackerwire@mastodon.social at 2026-06-17T12:00:09.000Z ##

🟠 CVE-2026-49061 - High (7.5)

Unauthenticated Arbitrary File Download in WPC Product Options for WooCommerce &lt;= 3.2.1 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48853
(0 None)

EPSS: 0.57%

updated 2026-06-17T10:55:18.207000

1 posts

Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flows into a call site that invokes it, achieve remote code execution on the server. 'Elixir.GRPC.Codec.Erlpack':decode/2 (lib/grpc/codec/erlpack.ex) calls :erlang.bi

offseq@infosec.exchange at 2026-06-16T00:00:34.000Z ##

🚨 CRITICAL: elixir-grpc grpc (0.4.0-<1.0.0) vulnerable to unauthenticated RCE & DoS via unsafe :erlang.binary_to_term/1 use. Patch status pending — restrict 'application/grpc+erlpack' inputs now! CVE-2026-48853 radar.offseq.com/threat/cve-20 #OffSeq #elixir #CVE202648853 #infosec

##

CVE-2026-48095
(8.8 HIGH)

EPSS: 0.70%

updated 2026-06-17T10:54:50.997000

1 posts

7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buffer overflow vulnerability caused by an under-allocation in the NTFS compressed stream buffer (GetCuSize shift UB), potentially allowing attackers to cause arbitrary code execution or application crashes. CInStream::GetCuSize() in the NTFS handler computes the compression-unit buffer size as (UInt32)

1 repos

https://github.com/HORKimhab/CVE-2026-48095

ruari@velocipederider.com at 2026-06-17T12:52:27.000Z ##

Just two recent examples of vulnerablities from 7-Zip and RAR.

Also keep in mind that distros are not always great at updating and if you installed one of these yourself, it is also on you (plus neither autoupdate on Windows or macOS).

• 7-Zip: nvd.nist.gov/vuln/detail/cve-2

• WinRAR: nvd.nist.gov/vuln/detail/cve-2

##

CVE-2026-47777
(7.5 HIGH)

EPSS: 0.17%

updated 2026-06-17T10:54:40.050000

1 posts

Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a missing condition in the check if remote accounts consented to be featured in a remote Collection could lead to attackers bypassing the check and faking consent. An attacker could forge the FeatureAuthorization object that is used to verify consent to be featured in a Collection and thus make it appe

thehackerwire@mastodon.social at 2026-06-15T19:00:14.000Z ##

🟠 CVE-2026-47777 - High (7.5)

Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a missing condition in the check if remote accounts consented to be featured in a remote Collection could lead to attackers bypassing the check and fa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47749
(7.8 HIGH)

EPSS: 0.16%

updated 2026-06-17T10:54:39.427000

1 posts

stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. Versions prior to master-584-0a7ae07 are vulnerable to heap buffer overflow in SHORT_BINUNICODE parsing for PyTorch checkpoint files. The pickle .ckpt parser in src/model.cpp contained a heap buffer overflow vulnerability in the SHORT_BINUNICODE opcode ha

thehackerwire@mastodon.social at 2026-06-17T03:00:02.000Z ##

🟠 CVE-2026-47749 - High (7.8)

stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. Versions prior to master-584-0a7ae07 are vulnerable to heap buffer overflow in SHORT_BINUNICODE parsin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-39581
(8.5 HIGH)

EPSS: 0.27%

updated 2026-06-17T10:42:19.677000

1 posts

Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.

thehackerwire@mastodon.social at 2026-06-16T13:00:20.000Z ##

🟠 CVE-2026-39581 - High (8.5)

Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic &lt;= 1.1.4 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-25089
(9.8 CRITICAL)

EPSS: 2.66%

updated 2026-06-17T10:24:06.250000

1 posts

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP req

2 repos

https://github.com/HORKimhab/CVE-2026-25089

https://github.com/0xBlackash/CVE-2026-25089

threatnoir@infosec.exchange at 2026-06-16T18:06:05.000Z ##

⚠️ CRITICAL: Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week

Fortinet FortiSandbox is under active exploitation for three critical unauthenticated RCE vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089). All three bypass authentication and allow arbitrary command execution via HTTP requests. Organizations running FortiSandbox are at immediate ri…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-12205
(9.1 CRITICAL)

EPSS: 0.29%

updated 2026-06-17T10:14:40.940000

1 posts

Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. Crypt::DSA::sign caches the per-signature nonce material in the Key object without ever clearing it. The first sign() on a Key object picks a nonce, and every later sign() on that same object reuses it, producing an identical "r". Keys used to sign more than once with an affected versio

thehackerwire@mastodon.social at 2026-06-17T06:59:56.000Z ##

🔴 CVE-2026-12205 - Critical (9.1)

Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery.

Crypt::DSA::sign caches the per-signature nonce material in the Key object without ever clearing it.

The first sign() on a Key object p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12161
(8.8 HIGH)

EPSS: 0.29%

updated 2026-06-17T10:14:38.280000

1 posts

Improper input validation in the SSH Elevate Shell feature in Devolutions Remote Desktop Manager 2026.2.7 allows an authenticated user with permission to create or modify a shared SSH entry to execute arbitrary commands on a remote SSH host using stored elevation credentials via a crafted alternate username and user interaction with the Elevate Shell action.

thehackerwire@mastodon.social at 2026-06-17T06:00:09.000Z ##

🟠 CVE-2026-12161 - High (8.8)

Improper input validation in the SSH Elevate Shell feature in
Devolutions Remote Desktop Manager 2026.2.7 allows an authenticated user
with permission to create or modify a shared SSH entry to execute
arbitrary commands on a remote SSH host usi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12087
(9.1 CRITICAL)

EPSS: 0.39%

updated 2026-06-17T10:14:37.383000

1 posts

Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then c

thehackerwire@mastodon.social at 2026-06-17T07:00:06.000Z ##

🔴 CVE-2026-12087 - Critical (9.1)

Socket versions before 2.041 for Perl have an out-of-bounds heap read.

In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding mu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-11832
(9.1 CRITICAL)

EPSS: 0.33%

updated 2026-06-17T10:14:29.377000

1 posts

Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was generated using an MD5 hash of the epoch time, which is predictable.

thehackerwire@mastodon.social at 2026-06-17T07:00:22.000Z ##

🔴 CVE-2026-11832 - Critical (9.1)

Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce.

The default nonce was generated using an MD5 hash of the epoch time, which is predictable.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-0843
(6.3 MEDIUM)

EPSS: 0.20%

updated 2026-06-17T10:11:29.160000

1 posts

A vulnerability has been found in jiujiujia/victor123/wxw850227 jjjfood and jjjshop_food up to 20260103. This vulnerability affects unknown code of the file /index.php/api/product.category/index. Such manipulation of the argument latitude leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product is distributed under mult

nyanbinary@infosec.exchange at 2026-06-17T08:06:04.000Z ##

cve.org/CVERecord?id=CVE-2026- - do I dare click that reference... :neocat_scream_scared:

##

CVE-2025-8088
(8.8 HIGH)

EPSS: 81.35%

updated 2026-06-17T10:06:17.243000

1 posts

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.

32 repos

https://github.com/ilhamrzr/RAR-Anomaly-Inspector

https://github.com/jordan922/CVE-2025-8088

https://github.com/undefined-name12/CVE-2025-8088-Winrar

https://github.com/walidpyh/CVE-2025-8088

https://github.com/hbesljx/CVE-2025-8088-EXP

https://github.com/techcorp/CVE-2025-8088-Exploit

https://github.com/xi0onamdev/WinRAR-CVE-2025-8088-Exploitation-Toolkit

https://github.com/0xAbolfazl/CVE-2025-8088-WinRAR-PathTraversal-PoC

https://github.com/papcaii2004/CVE-2025-8088-WinRAR-builder

https://github.com/nhattanhh/CVE-2025-8088

https://github.com/pentestfunctions/CVE-2025-8088-Multi-Document

https://github.com/kitsuneshade/WinRAR-Exploit-Tool---Rust-Edition

https://github.com/shaheeryasirofficial/CVE-2025-8088

https://github.com/pentestfunctions/best-CVE-2025-8088

https://github.com/lennertdefauw/CVE-2025-8088

https://github.com/Markusino488/cve-2025-8088

https://github.com/IsmaelCosma/CVE-2025-8088

https://github.com/knight0x07/WinRAR-CVE-2025-8088-PoC-RAR

https://github.com/Shinkirou789/Cve-2025-8088-WinRar-vulnerability

https://github.com/hexsecteam/CVE-2025-8088-Winrar-Tool

https://github.com/onlytoxi/CVE-2025-8088-Winrar-Tool

https://github.com/sxyrxyy/CVE-2025-8088-WinRAR-Proof-of-Concept-PoC-Exploit-

https://github.com/travisbgreen/cve-2025-8088

https://github.com/nuky-alt/CVE-2025-8088

https://github.com/DeepBlue-dot/CVE-2025-8088-WinRAR-Startup-PoC

https://github.com/pexlexity/WinRAR-CVE-2025-8088-Path-Traversal-PoC

https://github.com/AdityaBhatt3010/CVE-2025-8088-WinRAR-Zero-Day-Path-Traversal

https://github.com/starfallreverie/winrar-exploit

https://github.com/Syrins/CVE-2025-8088-Winrar-Tool-Gui

https://github.com/pescada-dev/-CVE-2025-8088

https://github.com/aldisakti2/CVE-2025-8088-BUILDER-Winrar-Tool

https://github.com/ghostn4444/CVE-2025-8088

ruari@velocipederider.com at 2026-06-17T12:52:27.000Z ##

Just two recent examples of vulnerablities from 7-Zip and RAR.

Also keep in mind that distros are not always great at updating and if you installed one of these yourself, it is also on you (plus neither autoupdate on Windows or macOS).

• 7-Zip: nvd.nist.gov/vuln/detail/cve-2

• WinRAR: nvd.nist.gov/vuln/detail/cve-2

##

CVE-2025-71261
(8.6 HIGH)

EPSS: 0.21%

updated 2026-06-17T10:03:58.203000

1 posts

An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the TLS handshake and abuse it to bypass TLS as a security control.

thehackerwire@mastodon.social at 2026-06-16T19:00:25.000Z ##

🟠 CVE-2025-71261 - High (8.6)

An attacker with network-level access between the SUSE Virtualization
and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the TLS handshake and abuse it
to bypass TLS as a security control.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2019-16534
(6.1 MEDIUM)

EPSS: 0.80%

updated 2026-06-17T02:22:23.067000

1 posts

On DrayTek Vigor2925 devices with firmware 3.8.4.3, XSS exists via a crafted WAN name on the General Setup screen. NOTE: this is an end-of-life product.

nyanbinary@infosec.exchange at 2026-06-16T08:12:36.000Z ##

Here, have some CVE references pointing to facebook posts...
cve.org/CVERecord?id=CVE-2019-
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
... would you be surprised they are all dead?

This one links a Facebook video which is also dead. At least it also links a Twitter post by the same person...
cve.org/CVERecord?id=CVE-2017-
...which just links to the dead Facebook post.

##

CVE-2019-16533
(6.1 MEDIUM)

EPSS: 0.80%

updated 2026-06-17T02:22:22.927000

1 posts

On DrayTek Vigor2925 devices with firmware 3.8.4.3, Incorrect Access Control exists in loginset.htm, and can be used to trigger XSS. NOTE: this is an end-of-life product.

nyanbinary@infosec.exchange at 2026-06-16T08:12:36.000Z ##

Here, have some CVE references pointing to facebook posts...
cve.org/CVERecord?id=CVE-2019-
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
... would you be surprised they are all dead?

This one links a Facebook video which is also dead. At least it also links a Twitter post by the same person...
cve.org/CVERecord?id=CVE-2017-
...which just links to the dead Facebook post.

##

CVE-2017-9542
(9.8 CRITICAL)

EPSS: 5.07%

updated 2026-06-17T01:28:19.940000

1 posts

D-Link DIR-615 Wireless N 300 Router allows authentication bypass via a modified POST request to login.cgi. This issue occurs because it fails to validate the password field. Successful exploitation of this issue allows an attacker to take control of the affected device.

nyanbinary@infosec.exchange at 2026-06-16T08:12:36.000Z ##

Here, have some CVE references pointing to facebook posts...
cve.org/CVERecord?id=CVE-2019-
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
... would you be surprised they are all dead?

This one links a Facebook video which is also dead. At least it also links a Twitter post by the same person...
cve.org/CVERecord?id=CVE-2017-
...which just links to the dead Facebook post.

##

CVE-2026-12317
(7.5 HIGH)

EPSS: 0.31%

updated 2026-06-16T21:33:05

1 posts

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152.

thehackerwire@mastodon.social at 2026-06-17T04:00:26.000Z ##

🟠 CVE-2026-12317 - High (7.5)

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12316
(9.1 CRITICAL)

EPSS: 0.27%

updated 2026-06-16T21:33:05

1 posts

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152.

thehackerwire@mastodon.social at 2026-06-17T04:00:16.000Z ##

🔴 CVE-2026-12316 - Critical (9.1)

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12314
(7.5 HIGH)

EPSS: 0.27%

updated 2026-06-16T21:33:05

1 posts

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.

thehackerwire@mastodon.social at 2026-06-17T03:00:27.000Z ##

🟠 CVE-2026-12314 - High (7.5)

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12305
(7.5 HIGH)

EPSS: 0.40%

updated 2026-06-16T21:33:04

1 posts

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.

thehackerwire@mastodon.social at 2026-06-17T05:59:49.000Z ##

🟠 CVE-2026-12305 - High (7.5)

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53864
(8.1 HIGH)

EPSS: 0.25%

updated 2026-06-16T21:32:08

1 posts

OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.

thehackerwire@mastodon.social at 2026-06-16T19:59:59.000Z ##

🟠 CVE-2026-53864 - High (8.1)

OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53855
(8.1 HIGH)

EPSS: 0.27%

updated 2026-06-16T21:31:59

1 posts

OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict allowlist checks via shell positional parameters. Attackers can combine allowlisted tools with shell positional arguments to place inline-eval content in shell carriers outside intended allowlist rules, enabling execution of unapproved shell-provided content.

thehackerwire@mastodon.social at 2026-06-16T22:00:00.000Z ##

🟠 CVE-2026-53855 - High (8.1)

OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict allowlist checks via shell positional parameters. Attackers can combine allowlisted tools with shell positional arguments to pl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53857
(8.1 HIGH)

EPSS: 0.21%

updated 2026-06-16T21:31:59

1 posts

OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display metadata could match allowFrom policy entries through display name changes. Attackers with mutable display names could receive agent responses intended for different Zalo identities when the feature is enabled.

thehackerwire@mastodon.social at 2026-06-16T20:00:10.000Z ##

🟠 CVE-2026-53857 - High (8.1)

OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display metadata could match allowFrom policy entries through display name changes. Attackers with mutable display names could receive agent resp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12003(CVSS UNKNOWN)

EPSS: 0.14%

updated 2026-06-16T21:31:56

4 posts

To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark is found relative to VPATH relative to the executable, Python assumes it is running in a source tree and generates a different default sys.path. This code remains i

canartuc@mastodon.social at 2026-06-17T17:54:30.000Z ##

Who is affected by CVE-2026-12003? Anyone running CPython on Windows across 3.11.15, 3.12.13, 3.13.14, 3.14.6, 3.15.0b2 and earlier. Jake Yamaki of Bishop Fox showed that a low-privilege user can create a path CPython checks for in-tree builds and inject malicious library folders to escalate privileges. It is rated CVSSv4 5.3. With this many affected versions, how do you even inventory every CPython on a Windows fleet?

#Python #Security

##

canartuc@mastodon.social at 2026-06-17T17:07:30.000Z ##

Jake Yamaki of Bishop Fox disclosed CVE-2026-12003 in CPython. The interpreter's VPATH variable, combined with a Modules/setup.local landmark used to locate in-tree builds, lets a low-privilege Windows user create that path outside the install directory and inject malicious library folders, escalating privileges. Rated CVSSv4 5.3, it affects 3.11.15, 3.12.13, 3.13.14, 3.14.6, 3.15.0b2 and earlier. Should build-detection logic ever survive into a release binary?

#Python #Security

##

canartuc@mastodon.social at 2026-06-17T17:54:30.000Z ##

Who is affected by CVE-2026-12003? Anyone running CPython on Windows across 3.11.15, 3.12.13, 3.13.14, 3.14.6, 3.15.0b2 and earlier. Jake Yamaki of Bishop Fox showed that a low-privilege user can create a path CPython checks for in-tree builds and inject malicious library folders to escalate privileges. It is rated CVSSv4 5.3. With this many affected versions, how do you even inventory every CPython on a Windows fleet?

#Python #Security

##

canartuc@mastodon.social at 2026-06-17T17:07:30.000Z ##

Jake Yamaki of Bishop Fox disclosed CVE-2026-12003 in CPython. The interpreter's VPATH variable, combined with a Modules/setup.local landmark used to locate in-tree builds, lets a low-privilege Windows user create that path outside the install directory and inject malicious library folders, escalating privileges. Rated CVSSv4 5.3, it affects 3.11.15, 3.12.13, 3.13.14, 3.14.6, 3.15.0b2 and earlier. Should build-detection logic ever survive into a release binary?

#Python #Security

##

CVE-2026-12312
(7.5 HIGH)

EPSS: 0.27%

updated 2026-06-16T21:31:56

1 posts

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.

thehackerwire@mastodon.social at 2026-06-17T05:00:13.000Z ##

🟠 CVE-2026-12312 - High (7.5)

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12310
(7.5 HIGH)

EPSS: 0.27%

updated 2026-06-16T21:31:56

1 posts

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.

thehackerwire@mastodon.social at 2026-06-17T05:00:02.000Z ##

🟠 CVE-2026-12310 - High (7.5)

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12315
(9.1 CRITICAL)

EPSS: 0.28%

updated 2026-06-16T21:31:56

1 posts

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.

thehackerwire@mastodon.social at 2026-06-17T04:00:03.000Z ##

🔴 CVE-2026-12315 - Critical (9.1)

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-10649
(8.6 HIGH)

EPSS: 0.46%

updated 2026-06-16T21:31:56

1 posts

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.

thehackerwire@mastodon.social at 2026-06-17T03:00:15.000Z ##

🟠 CVE-2026-10649 - High (8.6)

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacke...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12304
(9.1 CRITICAL)

EPSS: 0.19%

updated 2026-06-16T21:31:55

1 posts

Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.

thehackerwire@mastodon.social at 2026-06-17T05:00:22.000Z ##

🔴 CVE-2026-12304 - Critical (9.1)

Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12289
(8.8 HIGH)

EPSS: 0.32%

updated 2026-06-16T18:33:39

1 posts

Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.

thehackerwire@mastodon.social at 2026-06-16T17:00:20.000Z ##

🟠 CVE-2026-12289 - High (8.8)

Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44932
(8.8 HIGH)

EPSS: 0.49%

updated 2026-06-16T18:32:44

1 posts

Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious DHCP server to execute code on the local machine.

thehackerwire@mastodon.social at 2026-06-16T18:00:34.000Z ##

🟠 CVE-2026-44932 - High (8.8)

Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious DHCP server to execute code on the local machine.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12328
(8.1 HIGH)

EPSS: 0.30%

updated 2026-06-16T18:32:38

1 posts

Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.

thehackerwire@mastodon.social at 2026-06-16T17:00:11.000Z ##

🟠 CVE-2026-12328 - High (8.1)

Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20253
(9.8 CRITICAL)

EPSS: 1.73%

updated 2026-06-16T15:34:50

2 posts

In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and 10.2.2510.14, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.<br><br>The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file

Nuclei template

3 repos

https://github.com/watchtowrlabs/watchTowr-vs-Splunk-CVE-2026-20253

https://github.com/0xBlackash/CVE-2026-20253

https://github.com/HORKimhab/CVE-2026-20253

patrickcmiller@infosec.exchange at 2026-06-16T23:42:00.000Z ##

Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE) labs.watchtowr.com/why-use-app

##

jbhall56@infosec.exchange at 2026-06-16T12:09:06.000Z ##

The vulnerability, tracked as CVE-2026-20253, is rated 9.8 on the CVSS scoring system. thehackernews.com/2026/06/crit

##

CVE-2026-12398
(7.5 HIGH)

EPSS: 0.89%

updated 2026-06-16T15:34:03

1 posts

A command injection vulnerability was found in galaxy_ng. The do_git_checkout() function in the legacy role import API (v1) interpolates unsanitized git ref names (branch/tag names) into shell commands executed via subprocess.run() with shell=True. An authenticated user who controls a git repository can create a branch or tag with shell metacharacters in the name to achieve remote code execution o

thehackerwire@mastodon.social at 2026-06-16T16:00:13.000Z ##

🟠 CVE-2026-12398 - High (7.5)

A command injection vulnerability was found in galaxy_ng. The do_git_checkout() function in the legacy role import API (v1) interpolates unsanitized git ref names (branch/tag names) into shell commands executed via subprocess.run() with shell=True...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-11317(CVSS UNKNOWN)

EPSS: 0.30%

updated 2026-06-16T15:34:02

1 posts

A denial of service security issue exists in the affected product. The security issue stems from a fault occurring when a crafted CIP message is sent. Devices with less memory are more likely to be affected. This can result in a major nonrecoverable fault (MNRF). A program download is required to recover.

netsecio@mastodon.social at 2026-06-17T15:45:09.000Z ##

📰 CISA Warns of Disruptive DoS Flaw in Rockwell Automation Industrial Controllers

🏭 CISA WARNING 🏭 A denial-of-service flaw (CVE-2026-11317) affects widely-used Rockwell Automation industrial controllers. Exploitation can cause a major fault, halting operations. Isolate your ICS networks now! #ICS #OTsecurity #CISA #Vulnerability

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/ci

##

CVE-2026-40750
(9.9 CRITICAL)

EPSS: 0.27%

updated 2026-06-16T12:32:12

1 posts

Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This issue affects Kids Online Store: from n/a through 0.8.9.

thehackerwire@mastodon.social at 2026-06-16T13:00:10.000Z ##

🔴 CVE-2026-40750 - Critical (9.9)

Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server.

This issue affects Kids Online Store: from n/a through 0.8.9.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8442
(8.1 HIGH)

EPSS: 0.52%

updated 2026-06-16T12:32:12

1 posts

The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 12.6.8. This is due to missing authorization checks on the wpfb_hide_review and wprp_save_review_admin AJAX handlers combined with insufficient path validation in the wpfb_hidereview_ajax() function, which uses strpos() to check that a stored media URL starts with the expected pre

thehackerwire@mastodon.social at 2026-06-16T11:00:09.000Z ##

🟠 CVE-2026-8442 - High (8.1)

The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 12.6.8. This is due to missing authorization checks on the wpfb_hide_review and wprp_save_review_admin AJAX handlers combined wi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-68045
(7.5 HIGH)

EPSS: 0.23%

updated 2026-06-16T12:32:07

1 posts

Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.

thehackerwire@mastodon.social at 2026-06-16T17:00:33.000Z ##

🟠 CVE-2025-68045 - High (7.5)

Unauthenticated Broken Access Control in WP Event SOlution &lt;= 4.1.12 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52712
(7.6 HIGH)

EPSS: 0.24%

updated 2026-06-16T12:32:07

1 posts

Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions.

thehackerwire@mastodon.social at 2026-06-16T14:00:38.000Z ##

🟠 CVE-2026-52712 - High (7.6)

Subscriber SQL Injection in Attendance Manager &lt;= 0.6.2 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52711
(7.5 HIGH)

EPSS: 0.23%

updated 2026-06-16T12:32:07

1 posts

Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions.

thehackerwire@mastodon.social at 2026-06-16T14:00:28.000Z ##

🟠 CVE-2026-52711 - High (7.5)

Unauthenticated Broken Access Control in WooCommerce POS &lt;= 1.8.14 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49774
(9.9 CRITICAL)

EPSS: 0.41%

updated 2026-06-16T12:32:07

1 posts

Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion. This issue affects RD Station: from n/a through 5.6.0.

thehackerwire@mastodon.social at 2026-06-16T14:00:19.000Z ##

🔴 CVE-2026-49774 - Critical (9.9)

Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion.

This issue affects RD Station: from n/a through 5.6.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49772
(9.3 CRITICAL)

EPSS: 0.24%

updated 2026-06-16T12:32:07

1 posts

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection. This issue affects The Events Calendar: from 6.15.12 through 6.16.2.

thehackerwire@mastodon.social at 2026-06-16T13:00:39.000Z ##

🔴 CVE-2026-49772 - Critical (9.3)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection.

This issue affects The Events Calendar: from 6.15.12 through 6.16.2.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-39574
(9.3 CRITICAL)

EPSS: 0.23%

updated 2026-06-16T12:32:07

1 posts

Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions.

thehackerwire@mastodon.social at 2026-06-16T11:01:30.000Z ##

🔴 CVE-2026-39574 - Critical (9.3)

Unauthenticated SQL Injection in InPost Gallery &lt;= 2.1.4.6 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-39490
(7.5 HIGH)

EPSS: 0.30%

updated 2026-06-16T12:32:07

1 posts

Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.

thehackerwire@mastodon.social at 2026-06-16T11:01:19.000Z ##

🟠 CVE-2026-39490 - High (7.5)

Unauthenticated Broken Access Control in JupiterX Core &lt;= 4.14.1 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8444
(8.8 HIGH)

EPSS: 0.25%

updated 2026-06-16T09:32:42

1 posts

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpfb_find_reviews AJAX action in versions up to, and including, 12.6.8. This is due to the handler reading $_POST['curselrevs'] raw with no sanitization or type casting, then concatenating each array element directly into a `WHERE id IN ( ... )` clause without quoting and executing

thehackerwire@mastodon.social at 2026-06-17T05:59:59.000Z ##

🟠 CVE-2026-8444 - High (8.8)

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpfb_find_reviews AJAX action in versions up to, and including, 12.6.8. This is due to the handler reading $_POST['curselrevs'] ra...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8443
(8.8 HIGH)

EPSS: 0.25%

updated 2026-06-16T06:30:31

1 posts

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameters of the wppro_get_overall_chart_data AJAX action in versions up to, and including, 12.6.8. This is due to the use of stripslashes() on user-supplied JSON strings prior to json_decode(), which removes the escaping applied by WordPress's wp_magic_quotes; the resulting decoded arra

thehackerwire@mastodon.social at 2026-06-16T06:59:55.000Z ##

🟠 CVE-2026-8443 - High (8.8)

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameters of the wppro_get_overall_chart_data AJAX action in versions up to, and including, 12.6.8. This is due to the use of stripslas...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-6933
(8.8 HIGH)

EPSS: 0.59%

updated 2026-06-16T06:30:31

1 posts

The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in versions up to and including 2.0. This is due to the 'generatePluginHandler' function lacking any authorization check before processing user-supplied POST data, combined with the 'createFromStub' function performing unsanitized string substitution of the 'premmerce_plugin_namespace' par

thehackerwire@mastodon.social at 2026-06-16T06:59:46.000Z ##

🟠 CVE-2026-6933 - High (8.8)

The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in versions up to and including 2.0. This is due to the 'generatePluginHandler' function lacking any authorization check before processin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-7273
(8.8 HIGH)

EPSS: 0.28%

updated 2026-06-16T03:30:37

1 posts

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

thehackerwire@mastodon.social at 2026-06-16T04:59:59.000Z ##

🟠 CVE-2026-7273 - High (8.8)

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20262
(6.5 MEDIUM)

EPSS: 1.15%

updated 2026-06-15T21:31:39

11 posts

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate user-supplied input during a file upload process. An attacker could exploit this vulnerability by sen

2 repos

https://github.com/HORKimhab/CVE-2026-20262

https://github.com/fevar54/CVE-2026-20262-Cisco-Catalyst-SD-WAN-Manager-Arbitrary-File-Write-

netsecio@mastodon.social at 2026-06-17T15:45:25.000Z ##

📰 Actively Exploited Cisco SD-WAN Flaw Added to CISA KEV Catalog

⚠️ Cisco Catalyst SD-WAN Manager flaw CVE-2026-20262 is actively exploited! The bug allows root privilege escalation. CISA has added it to the KEV catalog, mandating a patch by June 29. Update now! #Cisco #CVE #CyberSecurity #KEV

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/ci

##

jbhall56@infosec.exchange at 2026-06-16T13:35:58.000Z ##

Cisco recently became aware of the exploitation of CVE-2026-20262, a Catalyst SD-WAN Manager zero-day that allows arbitrary file write. securityweek.com/cisco-patches

##

thecybermind@infosec.exchange at 2026-06-16T13:05:16.000Z ##

CRITICAL: Cisco Catalyst SD-WAN Manager CVE-2026-20262 is under active exploitation. Path traversal flaw allows unauthorized file access. Review our TSUITE forensic intelligence brief to secure your SD-WAN perimeter and prevent persistence thecybermind.co/jt3x

##

thecybermind@infosec.exchange at 2026-06-16T11:09:56.000Z ##

CSUITE CRITICAL: Cisco Catalyst SD-WAN Manager CVE-2026-20262 is under active exploitation. Path traversal flaw allows unauthorized file access. Review our full forensic intelligence brief to secure your SD-WAN perimeter and prevent persistence. Act now. thecybermind.co/8bs2

#CiscoSecurity #CVE202620262 #CyberMindCo

##

beyondmachines1@infosec.exchange at 2026-06-16T10:01:07.000Z ##

Cisco Patches Actively Exploited Zero-Day in Catalyst SD-WAN Manager

Cisco patched an actively exploited zero-day vulnerability (CVE-2026-20262) in its Catalyst SD-WAN Manager that allows authenticated attackers to gain root access through arbitrary file writes.

**Make sure your Cisco Catalyst SD-WAN Manager is isolated from the internet and reachable only from trusted networks. This is an actively exploited flaw so don't ignore it. Update ASAP to one of the fixed versions (20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, or 26.1.1.2) and check your logs for suspicious uploads like `.war` or `index.jsp` files.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

hbrpgm@adalta.social at 2026-06-16T09:34:41.000Z ##

📺 peer.adalta.social/w/bStPSWakC
🔗 [🇩🇪🇺🇸🇫🇷](adalta.info/articles/116759030)
🔗 [ℹ️](pc-fluesterer.info/wordpress/2")

La vulnérabilité CVE-2026-20262 confirme la cadence infernale des correctifs chez le géant américain, exposant des milliers de réseaux d'entreprise à une prise de contrôle distante.

#cve #sicherheit #rce #exploit #loi

##

offseq@infosec.exchange at 2026-06-16T09:00:26.000Z ##

🚨 CRITICAL: Cisco Catalyst SD-WAN Manager zero-day (CVE-2026-20262) exploited in the wild. Attackers w/ write access can escalate to root via crafted HTTP requests. Patch now & review access controls! radar.offseq.com/threat/cisco- #OffSeq #Cisco #ZeroDay #Vuln

##

secdb@infosec.exchange at 2026-06-15T21:01:49.000Z ##

🚨 [CISA-2026:0615] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-20262 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Catalyst SD-WAN Manager
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-54420 (secdb.nttzen.cloud/cve/detail/)
- Name: LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: LiteSpeed
- Product: cPanel Plugin
- Notes: blog.litespeedtech.com/2026/06 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260615 #cisa20260615 #cve_2026_20262 #cve_2026_54420 #cve202620262 #cve202654420

##

cisakevtracker@mastodon.social at 2026-06-15T20:01:09.000Z ##

CVE ID: CVE-2026-20262
Vendor: Cisco
Product: Catalyst SD-WAN Manager
Date Added: 2026-06-15
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

oversecurity@mastodon.social at 2026-06-15T17:20:35.000Z ##

Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks

Cisco has released security updates to address a vulnerability in the Catalyst SD-WAN Manager, tracked as CVE-2026-20262, that was exploited in...

🔗️ [Bleepingcomputer] link.is.it/fhfuuC

##

AAKL@infosec.exchange at 2026-06-15T16:09:55.000Z ##

Broadcom has a new advisory for a critical vulnerability:

Endevor Bridge for Git 2.4.4 to 2.15.19 Vulnerabilities support.broadcom.com/web/ecx/s

Cisco:

Medium-severity: CVE-2026-20262: Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability sec.cloudapps.cisco.com/securi

Cisco has also tagged Microsoft for a zero-day report, expected on June 16 talosintelligence.com/vulnerab @TalosSecurity
#Cisco #Broadcom #infosec #vulnerability

##

CVE-2026-49112
(7.5 HIGH)

EPSS: 0.33%

updated 2026-06-15T21:31:02

1 posts

Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.

thehackerwire@mastodon.social at 2026-06-17T11:59:59.000Z ##

🟠 CVE-2026-49112 - High (7.5)

Unauthenticated Path Traversal in Shared Files &lt;= 1.7.64 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49781
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-06-15T21:31:02

2 posts

Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions.

offseq@infosec.exchange at 2026-06-16T07:30:27.000Z ##

🚨 CVE-2026-49781 (CRITICAL): Brainstorm Force OttoKit <=1.1.27 is vulnerable to unauthenticated PHP object injection (CWE-502). Full system compromise possible. No patch — restrict access & monitor for threats. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #AppSec #PHP

##

thehackerwire@mastodon.social at 2026-06-16T03:00:20.000Z ##

🔴 CVE-2026-49781 - Critical (9.8)

Unauthenticated PHP Object Injection in OttoKit &lt;= 1.1.27 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52693
(9.3 CRITICAL)

EPSS: 0.30%

updated 2026-06-15T21:31:02

2 posts

Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions.

offseq@infosec.exchange at 2026-06-16T06:00:25.000Z ##

🔴 CRITICAL: CVE-2026-52693 in impleCode eCommerce Product Catalog <=3.5.5 enables unauthenticated SQL Injection. Sensitive data at risk — patch status unconfirmed. Apply input validation & watch for vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #SQLInjection #Infosec #Vuln

##

thehackerwire@mastodon.social at 2026-06-16T01:00:24.000Z ##

🔴 CVE-2026-52693 - Critical (9.3)

Unauthenticated SQL Injection in eCommerce Product Catalog &lt;= 3.5.5 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49769
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-06-15T21:31:02

1 posts

Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions.

thehackerwire@mastodon.social at 2026-06-16T06:00:13.000Z ##

🔴 CVE-2026-49769 - Critical (9.8)

Unauthenticated PHP Object Injection in wpForo Forum &lt;= 3.1.0 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49768
(9.8 CRITICAL)

EPSS: 0.55%

updated 2026-06-15T21:31:02

1 posts

Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions.

thehackerwire@mastodon.social at 2026-06-16T06:00:02.000Z ##

🔴 CVE-2026-49768 - Critical (9.8)

Unauthenticated PHP Object Injection in Happyforms &lt;= 1.26.13 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49766
(9.9 CRITICAL)

EPSS: 0.51%

updated 2026-06-15T21:31:02

1 posts

Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions.

thehackerwire@mastodon.social at 2026-06-16T05:00:45.000Z ##

🔴 CVE-2026-49766 - Critical (9.9)

Subscriber Arbitrary File Deletion in WP User Manager &lt;= 2.9.16 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49765
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-06-15T21:31:02

1 posts

Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions.

thehackerwire@mastodon.social at 2026-06-16T05:00:36.000Z ##

🔴 CVE-2026-49765 - Critical (9.8)

Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms &lt;= 1.1.8 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49764
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-06-15T21:31:02

1 posts

Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions.

thehackerwire@mastodon.social at 2026-06-16T05:00:26.000Z ##

🔴 CVE-2026-49764 - Critical (9.8)

Unauthenticated Broken Authentication in RegistrationMagic &lt;= 6.0.8.6 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52703
(9.6 CRITICAL)

EPSS: 0.35%

updated 2026-06-15T21:31:02

2 posts

Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.

offseq@infosec.exchange at 2026-06-16T04:30:26.000Z ##

⚠️ CRITICAL: CVE-2026-52703 in Ninja Team FastDup (<=2.7.2) enables unauthenticated path traversal. Attackers could access restricted files. Monitor for vendor updates and restrict access! radar.offseq.com/threat/cve-20 #OffSeq #vulnerability #infosec

##

thehackerwire@mastodon.social at 2026-06-15T23:01:05.000Z ##

🔴 CVE-2026-52703 - Critical (9.6)

Unauthenticated Path Traversal in FastDup &lt;= 2.7.2 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49763
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-06-15T21:31:02

1 posts

Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions.

thehackerwire@mastodon.social at 2026-06-16T03:00:29.000Z ##

🔴 CVE-2026-49763 - Critical (9.8)

Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot &lt;= 1.3.7 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49780
(8.8 HIGH)

EPSS: 0.28%

updated 2026-06-15T21:31:02

1 posts

Customer Privilege Escalation in Dokan <= 5.0.2 versions.

CVE-2026-49776
(9.3 CRITICAL)

EPSS: 0.29%

updated 2026-06-15T21:31:02

1 posts

Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites <= 2.32.6 versions.

thehackerwire@mastodon.social at 2026-06-16T01:00:44.000Z ##

🔴 CVE-2026-49776 - Critical (9.3)

Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites &lt;= 2.32.6 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49770
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-06-15T21:31:02

1 posts

Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.

thehackerwire@mastodon.social at 2026-06-16T01:00:33.000Z ##

🔴 CVE-2026-49770 - Critical (9.8)

Unauthenticated PHP Object Injection in WP Travel Engine &lt;= 6.7.12 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52692
(7.5 HIGH)

EPSS: 0.24%

updated 2026-06-15T21:31:02

1 posts

Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions.

thehackerwire@mastodon.social at 2026-06-15T23:01:15.000Z ##

🟠 CVE-2026-52692 - High (7.5)

Unauthenticated Sensitive Data Exposure in Affiliates Manager &lt;= 2.9.50 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52700
(8.5 HIGH)

EPSS: 0.35%

updated 2026-06-15T21:31:02

1 posts

Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions.

CVE-2026-52699
(7.5 HIGH)

EPSS: 0.24%

updated 2026-06-15T21:31:02

1 posts

Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions.

thehackerwire@mastodon.social at 2026-06-15T22:01:15.000Z ##

🟠 CVE-2026-52699 - High (7.5)

Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar &lt;= 1.4.5 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52697
(8.5 HIGH)

EPSS: 0.35%

updated 2026-06-15T21:31:02

1 posts

Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions.

CVE-2026-52695
(7.5 HIGH)

EPSS: 0.25%

updated 2026-06-15T21:31:02

1 posts

Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions.

thehackerwire@mastodon.social at 2026-06-15T22:00:27.000Z ##

🟠 CVE-2026-52695 - High (7.5)

Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout &lt;= 1.8.2 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9691
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-06-15T21:31:02

1 posts

Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions.

1 repos

https://github.com/izxci/CVE-2026-9691

thehackerwire@mastodon.social at 2026-06-15T22:00:07.000Z ##

🔴 CVE-2026-9691 - Critical (9.8)

Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms &lt;= 1.1.1 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52694
(7.5 HIGH)

EPSS: 0.24%

updated 2026-06-15T21:31:02

1 posts

Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions.

thehackerwire@mastodon.social at 2026-06-15T22:00:17.000Z ##

🟠 CVE-2026-52694 - High (7.5)

Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce &lt;= 2.0 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49067
(9.3 CRITICAL)

EPSS: 0.30%

updated 2026-06-15T21:30:59

1 posts

Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions.

thehackerwire@mastodon.social at 2026-06-17T13:00:02.000Z ##

🔴 CVE-2026-49067 - Critical (9.3)

Unauthenticated SQL Injection in Advanced 301 and 302 Redirect &lt;= 1.6.9 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49083
(7.5 HIGH)

EPSS: 0.31%

updated 2026-06-15T21:30:59

1 posts

Contributor Privilege Escalation in LatePoint <= 5.5.1 versions.

2 repos

https://github.com/izxci/CVE-2026-49083

https://github.com/87achrafg-stack/CVE-2026-49083

CVE-2026-54420
(8.5 HIGH)

EPSS: 0.65%

updated 2026-06-15T21:30:32

6 posts

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.

3 repos

https://github.com/HORKimhab/CVE-2026-54420

https://github.com/Resellnom/litespeed-cpanel-cve-2026-54420-fix

https://github.com/mahfuzreham/litespeed-cpanel-cve-2026-54420-fix

Matchbook3469@mastodon.social at 2026-06-17T18:18:47.000Z ##

🔵 THREAT INTELLIGENCE

CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation

Vulnerability | CRITICAL
CVEs: CVE-2026-54420

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. government agencies three days to secure their servers against an...

Full analysis:
yazoul.net/news/article/cisa-f

#CyberSecurity #APT #IncidentResponse

##

gtronix@infosec.exchange at 2026-06-16T11:00:38.000Z ##

"CISA warns of another cPanel plugin flaw exploited in attacks"

"[...] government agencies three days to secure their servers against an actively exploited vulnerability (CVE-2026-54420) in the LiteSpeed cPanel user-end plugin. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. The U.S."

bleepingcomputer.com/news/secu

#Cybersecurity

##

thecybermind@infosec.exchange at 2026-06-16T00:40:49.000Z ##

Stop symlink privilege escalation in its tracks. The Cyber Mind Co. has deployed the T-Suite Defense Playbook for CVE-2026-54420, featuring kernel overrides and FIM rules to protect LiteSpeed cPanel environments. Lock down your shared hosting infrastructure now: thecybermind.co/q7ni

##

thecybermind@infosec.exchange at 2026-06-15T22:33:05.000Z ##

Active exploitation verified by CISA: CVE-2026-54420 exposes LiteSpeed cPanel environments to critical symlink privilege escalation. Threat actors are actively breaching shared hosting isolation. Read the full high-authority C-Suite briefing from The Cyber Mind Co. to harden your perimeter right now. thecybermind.co/ez9o

##

secdb@infosec.exchange at 2026-06-15T21:01:49.000Z ##

🚨 [CISA-2026:0615] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-20262 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Catalyst SD-WAN Manager
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-54420 (secdb.nttzen.cloud/cve/detail/)
- Name: LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: LiteSpeed
- Product: cPanel Plugin
- Notes: blog.litespeedtech.com/2026/06 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260615 #cisa20260615 #cve_2026_20262 #cve_2026_54420 #cve202620262 #cve202654420

##

cisakevtracker@mastodon.social at 2026-06-15T20:00:53.000Z ##

CVE ID: CVE-2026-54420
Vendor: LiteSpeed
Product: cPanel Plugin
Date Added: 2026-06-15
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-11526
(9.8 CRITICAL)

EPSS: 2.46%

updated 2026-06-15T18:32:21

1 posts

GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle. GD::Image::_make_filehandle opens a filename argument with Perl's 2-arg open(), so a filename that begins or ends with a pipe ("| cmd", "cmd |") or begins with a redirect ("> path", ">> path") is run as a command or redirect rather than opened as a file. _ma

canartuc@mastodon.social at 2026-06-16T15:35:45.000Z ##

Perl's GD module released 2.86 to fix CVE-2026-11526, a command-injection flaw where GD::Image constructors passed untrusted filenames to Perl's 2-argument open(), so a name beginning or ending with a pipe, or starting with a redirect, ran as a shell command or truncated a file. The fix opens filenames with a 3-argument read open. In-memory Data constructors were never affected. Is 2-arg open() still lurking in your dependencies?
#Perl #security

##

CVE-2026-9863
(7.5 HIGH)

EPSS: 0.57%

updated 2026-06-15T18:31:25

1 posts

Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Master during client version handling.

thehackerwire@mastodon.social at 2026-06-15T18:01:07.000Z ##

🟠 CVE-2026-9863 - High (7.5)

Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be ab...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9862
(9.8 CRITICAL)

EPSS: 0.84%

updated 2026-06-15T18:31:25

2 posts

Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.

thehackerwire@mastodon.social at 2026-06-15T18:00:57.000Z ##

🔴 CVE-2026-9862 - Critical (9.8)

Fortra's 
Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileg...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-06-15T16:30:11.000Z ##

🚨 CRITICAL: CVE-2026-9862 in Fortra Core Privileged Access Manager (BoKS) allows unauthenticated remote OS command injection via boks_autoregisterd (CVSS 9.8). Restrict network access & monitor activity. No patch yet. radar.offseq.com/threat/cve-20 #OffSeq #CVE20269862 #Infosec

##

CVE-2026-49111
(8.8 HIGH)

EPSS: 0.24%

updated 2026-06-15T15:31:40

1 posts

Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation. This issue affects Masteriyo - LMS: from n/a through 2.2.0.

thehackerwire@mastodon.social at 2026-06-15T20:00:31.000Z ##

🟠 CVE-2026-49111 - High (8.8)

Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation.

This issue affects Masteriyo - LMS: from n/a through 2.2.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52704
(10.0 CRITICAL)

EPSS: 0.31%

updated 2026-06-15T15:31:39

2 posts

Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion. This issue affects WooCommerce PDF Invoice Builder: from n/a through 2.0.8.

thehackerwire@mastodon.social at 2026-06-15T18:02:33.000Z ##

🔴 CVE-2026-52704 - Critical (10)

Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion.

This issue affects WooCommerce PDF Invoice Builder: from n/a through 2.0.8.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-06-15T15:00:11.000Z ##

🚨 CRITICAL: CVE-2026-52704 in WooCommerce PDF Invoice Builder ≤2.0.8 enables remote code execution via code injection (CWE-94). No patch yet — disable/remove plugin to prevent full system compromise. More info: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln

##

CVE-2026-5242
(8.8 HIGH)

EPSS: 0.30%

updated 2026-06-15T15:31:39

1 posts

Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc. Pizzy Library allows Code Injection. This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.

thehackerwire@mastodon.social at 2026-06-15T18:02:23.000Z ##

🟠 CVE-2026-5242 - High (8.8)

Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc. Pizzy Library allows Code Injection.

This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-34022(CVSS UNKNOWN)

EPSS: 0.12%

updated 2026-06-15T15:31:32

1 posts

The Wertheim SafeController Family 65000, Controller 65000 - AssemblyVersion 6.11.8130.22319, uses weak custom cryptographic algorithms with hard-coded cryptographic keys to protect communication. An attacker in an adversary-in-the-middle position can decrypt the data traffic. During reassessment, it was possible to break the encryption/decryption routine and decrypt messages without knowledge of

nyanbinary@infosec.exchange at 2026-06-15T15:17:33.000Z ##

Trawling recent CVEs to make my brain stfu, stumbled across these:
sec-consult.com/vulnerability- / sec-consult.com/vulnerability- / db.gcve.eu/search?vendor=Werth

I dont know much about safes & stuff so I won't comment on impact but a few things stood out to me:

  • Disclosure timeline: Man, this is fucked, this shit ran for 3 years?
  • CVE-2026-34022: "The Safecontroller Family 65000 is secured with weak and custom cryptographic algorithms with hard-coded keys." "Cannot be fixed due to missing hardware support." "Proof of concept removed because no patch will be provided" :eyes_squint:
  • RCE on the server: This is actually a quite neat chaining of vulnerabilities/"features" being used in the second advisory to get from Arbitrary File read & Directory Traversal Upload to RCE :blobcatsurprised:
##

CVE-2026-5482(CVSS UNKNOWN)

EPSS: 0.45%

updated 2026-06-15T12:32:56

1 posts

Responsive FileManager's allows an unauthenticated attacker to upload files of any type and extension without restriction using dialog.php endpoint, leading to Remote Code Execution.  This project is unmaintained at the time of CVE assignment. The vulnerability was found in the latest release 9.14.0

offseq@infosec.exchange at 2026-06-15T13:30:26.000Z ##

🚨 CVE-2026-5482 (CRITICAL): Tecrail Responsive FileManager ≤9.14.0 lets unauth'd attackers upload dangerous files via dialog.php, leading to RCE. Project is unmaintained — no patch. Restrict access & monitor now. radar.offseq.com/threat/cve-20 #OffSeq #RCE #Vulnerability

##

CVE-2026-12057
(8.6 HIGH)

EPSS: 0.13%

updated 2026-06-15T12:32:51

1 posts

When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some dangerous interfaces, which allows remote scripts to be loaded, resulting in arbitrary code execution.

thehackerwire@mastodon.social at 2026-06-15T20:00:41.000Z ##

🟠 CVE-2026-12057 - High (8.6)

When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some dangerous interfaces, which allows remote scripts to be loaded, resulting in arbitrary code execution.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44188
(5.3 MEDIUM)

EPSS: 0.44%

updated 2026-06-15T12:32:51

1 posts

A flaw was found in Ansible Lightspeed. This vulnerability, related to insufficient session expiration, allows a remote attacker to maintain persistent access to the Ansible Lightspeed instance. If an attacker exfiltrates a valid OAuth (Open Authorization) access token before a user logs out, they can continue to authenticate and access sensitive data. This is because the application fails to inva

offseq@infosec.exchange at 2026-06-15T12:00:27.000Z ##

🚩 Red Hat Ansible Automation Platform 2.7 container update resolves HIGH severity issues (CVE-2026-44188 & more). Flaws include resource mgmt errors & info exposure. No known exploitation, but update ASAP after prior errata. radar.offseq.com/threat/red-ha #OffSeq #RedHat #Ansible #Vuln

##

CVE-2026-11860(CVSS UNKNOWN)

EPSS: 0.36%

updated 2026-06-15T12:32:51

1 posts

Quick.CMS deserializes user-controlled data received over plaintext HTTP without ensuring integrity or authenticity. This allows attackers to tamper with serialized payloads in transit and inject malicious objects. Because deserialization is performed without proper validation or class restrictions, crafted payloads can trigger dangerous magic methods (e.g., __wakeup() and __destruct()) and levera

offseq@infosec.exchange at 2026-06-15T10:30:24.000Z ##

⚠️ CVE-2026-11860 (HIGH): OpenSolution Quick.CMS vulnerable to deserialization of untrusted data over HTTP. Remote code execution possible if admin accesses panel. Upgrade to v6.8+ to enforce HTTPS and mitigate risk. radar.offseq.com/threat/cve-20 #OffSeq #infosec #vuln #php

##

CVE-2026-12221
(8.0 HIGH)

EPSS: 0.37%

updated 2026-06-15T06:31:46

1 posts

A vulnerability was found in Yealink SIP-T46U 108.86.0.118. This impacts the function sprintf of the file /api/upgrade/upgrade of the component Firmware Chunk Upload Handler. Performing a manipulation of the argument uid/start_offset results in stack-based buffer overflow. The attack needs to be approached within the local network. The exploit has been made public and could be used. The vendor was

offseq@infosec.exchange at 2026-06-15T09:00:26.000Z ##

🔎 CVE-2026-12221: HIGH severity stack-based buffer overflow in Yealink SIP-T46U (108.86.0.118). Exploitable via local network — potential code execution or DoS. No fix yet; restrict device access & monitor updates. radar.offseq.com/threat/cve-20 #OffSeq #VoIP #Infosec

##

CVE-2026-44488
(7.5 HIGH)

EPSS: 0.49%

updated 2026-06-12T19:24:52

1 posts

## Summary Axios versions `1.7.0` through `1.15.x` did not enforce configured request and response size limits when requests were sent with the `fetch` adapter. Applications that selected `adapter: 'fetch'`, or ran in environments where axios resolved to the fetch adapter, could receive or send bodies larger than `maxContentLength` or `maxBodyLength` despite those limits being explicitly configur

thehackerwire@mastodon.social at 2026-06-15T09:00:44.000Z ##

🟠 CVE-2026-44488 - High (7.5)

Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Applications that selected adapter: '...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44487(CVSS UNKNOWN)

EPSS: 0.43%

updated 2026-06-12T19:24:48

1 posts

## Summary Axios’s Node.js HTTP adapter may forward a `Proxy-Authorization` header to a redirected origin during specific proxy-to-direct redirect flows. This affects Node.js usage, where an initial HTTP request is sent through an authenticated HTTP proxy, redirects are followed, and the redirected URL is no longer proxied. Under affected redirect shapes, the final origin can receive the proxy c

thehackerwire@mastodon.social at 2026-06-15T09:00:34.000Z ##

🟠 CVE-2026-44487 - High (7.5)

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows. This affec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48558
(10.0 CRITICAL)

EPSS: 0.63%

updated 2026-06-12T18:32:06

2 posts

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary

cyberveille@mastobot.ping.moi at 2026-06-17T17:00:21.000Z ##

📢 CVE-2026-48558 : Contournement d'authentification critique dans SimpleHelp via OIDC
📝 ## 🔍 Contexte

Le 12 juin 2026, Horizon3.ai publie une divulgation technique concernant **CVE-2026-4855...
📖 cyberveille : cyberveille.ch/posts/2026-06-1
🌐 source : horizon3.ai/attack-research/di
#CVE_2026_48558 #IOC #Cyberveille

##

cyberveille@mastobot.ping.moi at 2026-06-17T17:00:21.000Z ##

📢 CVE-2026-48558 : Contournement d'authentification critique dans SimpleHelp via OIDC
📝 ## 🔍 Contexte

Le 12 juin 2026, Horizon3.ai publie une divulgation technique concernant **CVE-2026-4855...
📖 cyberveille : cyberveille.ch/posts/2026-06-1
🌐 source : horizon3.ai/attack-research/di
#CVE_2026_48558 #IOC #Cyberveille

##

CVE-2026-35273
(9.8 CRITICAL)

EPSS: 0.72%

updated 2026-06-12T18:31:50

2 posts

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of Peopl

3 repos

https://github.com/0xBlackash/CVE-2026-35273

https://github.com/HORKimhab/CVE-2026-35273

https://github.com/ekomsSavior/POC_cve_2026_35273

PC_Fluesterer@social.tchncs.de at 2026-06-16T17:18:43.000Z ##

Europarat gehackt – dank Oracle.

Die Besetzungsliste: ShinyHunters, Oracle, der Europarat. Die Handlung: Vor mehr als zwanzig Jahren hat Oracle* nach einer wahren Übernahmeschlacht die Firma PeopleSoft geschluckt. Deren Software wird vor allem in den USA eingesetzt, aber eben auch im Europarat. Die Software enthielt eine Zero-Day Sicherheitslücke CVE-2026-35273, die von ShinyHunters ausgenutzt wurde. Die Hackergruppe will darüber mehr als 100 Institutionen gehackt haben, darunter den Europarat. Dabei seien fast 300 GByte an Daten in die Hände der Erpresser gefallen, darunter Personalakten, Gehaltsabrechnungen, Einkäufe; Lebensläufe, Gehälter,

pc-fluesterer.info/wordpress/2

#0day #closedsource #cybercrime #datenleck #datenschutz #exploits #sicherheit #UnplugOracle #UnplugTrump #zeroday

##

hackmag@infosec.exchange at 2026-06-16T08:00:04.000Z ##

⚪️ Zero‑day vulnerability in Oracle PeopleSoft used to hack hundreds of organizations

🗨️ The ShinyHunters group has exploited a critical zero‑day vulnerability in Oracle PeopleSoft (CVE-2026-35273) to attack organizations around the world. According to experts from Google and Mandiant, since late May the hackers have been actively abusing this flaw, ultimately compromising more…

🔗 hackmag.com/news/oracle-people

#news

##

CVE-2026-53435
(8.8 HIGH)

EPSS: 0.37%

updated 2026-06-10T18:31:45

1 posts

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards. This can be used to impersonate any user and send HTTP requests on their behalf, up to and including use of the Script Cons

1 repos

https://github.com/AmesianX/CVE-2026-53435

rxerium@infosec.exchange at 2026-06-16T08:19:24.000Z ##

🚨 CVE-2026-53435, a high severity (CVSS 8.8) deserialization vulnerability in Jenkins is now seeing active exploitation as per Defused

Scan your infrastructure: github.com/rxerium/rxerium-tem

Patches are available per the vendor advisory: jenkins.io/security/advisory/2

##

CVE-2026-11645
(8.8 HIGH)

EPSS: 0.71%

updated 2026-06-09T18:30:35

1 posts

Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

3 repos

https://github.com/adamshaikhma/CVE-2026-11645

https://github.com/fevar54/CVE-2026-11645-Out-of-bounds-Read-Write

https://github.com/0xBlackash/CVE-2026-11645

serigala_tropis@lgbtqia.space at 2026-06-16T02:34:32.000Z ##

For anyone here who is using Google Chrome, update your Chrome to 149.0.7827.102/103 (Windows/Mac) and 149.0.7827.102 (Linux).

Google patches actively exploited vulnerability and 73 others. The actively exploited in the wild is tracked as CVE-2026-11645, the one which “Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.”

The vulnerability allows malicious website to execute arbitrary code in the Chrome sandbox. Just because your browser is in a sandbox, it only limits the severity of an attack, cyber attack usually need to chain multiple vulnerabilities to achieve serious compromise.

malwarebytes.com/blog/bugs/202

#cybersecurity #tech #google #googlechrome #chrome #browser

##

CVE-2026-42271
(8.8 HIGH)

EPSS: 53.70%

updated 2026-06-09T13:07:08

2 posts

### Impact Two endpoints used to preview an MCP server before saving it — `POST /mcp-rest/test/connection` and `POST /mcp-rest/test/tools/list` — accepted a full server configuration in the request body, including the `command`, `args`, and `env` fields used by the stdio transport. When called with a stdio configuration, the endpoints attempted to connect, which spawned the supplied command as a

Nuclei template

2 repos

https://github.com/HORKimhab/CVE-2026-42271

https://github.com/learner202649/CVE-2026-42271-PoC

patrickcmiller at 2026-06-17T18:42:00.672Z ##

LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE thehackernews.com/2026/06/lite

##

patrickcmiller@infosec.exchange at 2026-06-17T18:42:00.000Z ##

LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE thehackernews.com/2026/06/lite

##

CVE-2026-0257
(9.1 CRITICAL)

EPSS: 18.58%

updated 2026-06-09T12:32:02

2 posts

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

Nuclei template

10 repos

https://github.com/0xBlackash/CVE-2026-0257

https://github.com/bolubey/CVE-2026-0257

https://github.com/Mr-Robot-LP/CVE-2026-0257

https://github.com/grayxploit/CVE-2026-0257

https://github.com/tushargurav28/CVE-2026-0257

https://github.com/akashsingh0454/CVE-2026-0257-PoC

https://github.com/Ez4rd1x1/CVE-2026-0257

https://github.com/jenniferreire26/CVE-2026-0257

https://github.com/HORKimhab/CVE-2026-0257

https://github.com/sfewer-r7/CVE-2026-0257

jbhall56@infosec.exchange at 2026-06-16T12:47:41.000Z ##

The vulnerability in question is CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software that could be exploited by bad actors to set up VPN connections. thehackernews.com/2026/06/palo

##

patrickcmiller@infosec.exchange at 2026-06-15T13:12:01.000Z ##

Palo Alto Warns of Exploitation of VPN Bypass Exploits (CVE-2026-0257) in PAN-OS Flaw securityaffairs.com/193638/sec

##

CVE-2026-48017
(8.8 HIGH)

EPSS: 0.58%

updated 2026-06-05T16:39:39

1 posts

### Summary The `POST /runners/load-reader` endpoint in DbGate accepts a `functionName` parameter that is directly interpolated into a JavaScript code template without any sanitization or validation. An authenticated user (with basic access, no special permissions required) can inject arbitrary JavaScript code that executes on the server with full process privileges, bypassing the `require=null`

1 repos

https://github.com/romain-deperne/CVE-2026-48017

thehackerwire@mastodon.social at 2026-06-15T23:00:30.000Z ##

🟠 CVE-2026-48017 - High (8.8)

DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate accepts a functionName parameter that is directly interpolated into a JavaScript code template without any sanitization or val...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47684
(7.7 HIGH)

EPSS: 0.38%

updated 2026-06-05T16:35:00

1 posts

Summary: The private IP blocklist regex used in the URL download feature does not match IPv4-mapped IPv6 addresses (e.g. ::ffff:127.0.0.1), allowing SSRF protection to be bypassed on dual-stack systems. Affected components backend/src/applications/files/services/files-manager.service.ts – downloadFromUrl() checks regExpPrivateIP against request.socket.remoteAddress. backend/src/applications/file

thehackerwire@mastodon.social at 2026-06-16T15:59:50.000Z ##

🟠 CVE-2026-47684 - High (7.7)

Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.3.0, the private IP blocklist regex used in the URL download feature does not match IPv4-mapped IPv6 addresses (e.g. ::ffff:...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-42824
(6.5 MEDIUM)

EPSS: 0.50%

updated 2026-06-05T00:32:02

3 posts

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

yayafa@jforo.com at 2026-06-16T10:47:06.000Z ##

SearchLeak:Microsoft 365 Copilotのワンクリック脆弱性により機微なデータの窃取が可能に(CVE-2026-42824) | Codebook|Security News yayafa.com/2823631/ #AgenticAi #AI #ArtificialGeneralIntelligence #ArtificialIntelligence #Copilot #Microsoft #MicrosoftAI #MicrosoftCopilot #エージェント型AI #人工知能 #汎用人工知能

##

beyondmachines1@infosec.exchange at 2026-06-16T09:01:07.000Z ##

Microsoft Patches Critical SearchLeak Vulnerability in Copilot Enterprise

Microsoft patched a critical vulnerability in Copilot Enterprise (CVE-2026-42824) that allowed attackers to steal sensitive organizational data via a single-click link. The flaw chained prompt injection with web vulnerabilities to silently steal emails, files, and MFA codes through Bing.

**You don't need to do anything to patch this flaw. Make a note of it for vendor evaluation. As an extra precaution, educate your users to avoid clicking links with long, complex query parameters, and have your security team watch for unusual Copilot Search URLs containing encoded HTML tags.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

brian_greenberg@infosec.exchange at 2026-06-15T19:13:10.000Z ##

The most interesting thing about the new SearchLeak attack on Microsoft 365 Copilot isn't any single bug. It's that none of the three pieces was dangerous on its own. Varonis combined a prompt injection via a URL parameter, an HTML rendering race condition, and a server-side request forgery in Bing's image search. Each of these is a common bug that security teams usually consider minor. But when you put them together with a Copilot that can access your mailbox, OneDrive, and SharePoint, they create a critical flaw. Microsoft has since patched this issue (CVE-2026-42824).

This is how the attack worked:

* The victim clicks a link. That's the whole interaction. They type nothing.

* The link instructs Copilot to search the mailbox, find sensitive information such as access codes, and place it into an image URL.

* Bing retrieves that image, which sends the stolen data to the attacker's server. Bing serves as the delivery service, allowing the attack to bypass the content security policy intended to stop it.

From the user's perspective, Copilot just pauses for a moment. There is no visible sign that any data has been taken.

In the past, we've spent years rating bugs by their severity on their own. An SSRF here, an HTML injection there—each seemed minor. But when an AI assistant can follow instructions from untrusted input and access your real data, those minor bugs become much more serious. Old types of vulnerabilities become important again in this new context.

If your company uses Copilot or any AI assistant that can access company data, it is important to ask your team how they are rating bugs that affect it. The way we judge what is low risk has changed.

bleepingcomputer.com/news/secu

#AI #Cybersecurity #InfoSec #security #privacy #cloud #AttackChain

##

CVE-2026-8206
(9.8 CRITICAL)

EPSS: 0.62%

updated 2026-06-02T06:30:33

1 posts

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. This makes it possible for unauthenticated attackers to send a password reset link for any user registered

3 repos

https://github.com/izxci/CVE-2026-8206

https://github.com/rootdirective-sec/CVE-2026-8206-Lab

https://github.com/Jenderal92/CVE-2026-8206

sekurakbot@mastodon.com.pl at 2026-06-16T17:25:00.000Z ##

Błąd w popularnej wtyczce do WordPressa pozwala na przejęcie konta administratora (CVE-2026-8206 – Kirki)

WordPress to niewątpliwie najpopularniejszy na świecie system do zarządzania treścią (CMS) typu open source. Pozwala na łatwe tworzenie i zarządzanie stronami internetowymi bez konieczności znajomości programowania. O ile krytyczne błędy w samym silniku zdarzają się niezwykle rzadko, o tyle platforma wspiera wiele zewnętrznych pluginów, co zwiększa płaszczyznę ataku. TLDR: Tym...

#WBiegu #BugBounty #Cve #Php #Plugin #Wordpress

sekurak.pl/blad-w-popularnej-w

##

CVE-2026-42089
(8.6 HIGH)

EPSS: 0.19%

updated 2026-05-26T23:10:40

1 posts

### Impact `yeoman-environment` versions `>= 2.9.0` and `< 6.0.1` install missing local generator packages from caller-supplied package names without user confirmation. In downstream consumers that pass attacker-controlled project configuration into this path, this can result in arbitrary package installation and code execution during CLI bootstrap. The vulnerable method is `installLocalGenerato

thehackerwire@mastodon.social at 2026-06-16T18:00:23.000Z ##

🟠 CVE-2026-42089 - High (8.6)

Yeoman Environment provides an API to discover, create, and run generators, and to configure where and how a generator is resolved. Versions 2.9.0 through 6.0.0 install missing local generator packages from caller-supplied package names without us...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-39808
(9.8 CRITICAL)

EPSS: 66.17%

updated 2026-04-22T15:32:37

1 posts

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

Nuclei template

5 repos

https://github.com/HORKimhab/CVE-2026-39808

https://github.com/Lechansky/CVE-2026-39808

https://github.com/0xBlackash/CVE-2026-39808

https://github.com/samu-delucas/CVE-2026-39808

https://github.com/ynsmroztas/FortiSandbox-RCE-Exploit-CVE-2026-39808

threatnoir@infosec.exchange at 2026-06-16T18:06:05.000Z ##

⚠️ CRITICAL: Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week

Fortinet FortiSandbox is under active exploitation for three critical unauthenticated RCE vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089). All three bypass authentication and allow arbitrary command execution via HTTP requests. Organizations running FortiSandbox are at immediate ri…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-39813
(9.8 CRITICAL)

EPSS: 18.01%

updated 2026-04-14T18:30:41

1 posts

A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via <insert attack vector here>

2 repos

https://github.com/0xBlackash/CVE-2026-39813

https://github.com/HORKimhab/CVE-2026-39813

threatnoir@infosec.exchange at 2026-06-16T18:06:05.000Z ##

⚠️ CRITICAL: Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week

Fortinet FortiSandbox is under active exploitation for three critical unauthenticated RCE vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089). All three bypass authentication and allow arbitrary command execution via HTTP requests. Organizations running FortiSandbox are at immediate ri…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-4272
(8.1 HIGH)

EPSS: 0.45%

updated 2026-04-06T00:30:31

1 posts

Missing Authentication for Critical Function vulnerability in Honeywell Handheld Scanners allows Authentication Abuse.This issue affects Handheld Scanners: from C1 Base(Ingenic x1000) before GK000432BAA, from D1 Base(Ingenic x1600) before HE000085BAA, from A1/B1 Base(IMX25) before BK000763BAA_BK000765BAA_CU000101BAA. This vulnerability could allow a remote attacker within Bluetooth range of the s

nyanbinary@infosec.exchange at 2026-06-17T14:54:22.000Z ##

Q: Am I counting these?

('https://https:', {'https://https://docs.tenable.com/release-notes/Content/security-center/2026.htm', 'https://https://www.asustor.com/security/security_advisory_detail?id=55', 'https://https://www.tenable.com/security/tns-2026-07', 'https://https://talosintelligence.com/vulnerability_reports/', 'https://https://mail.python.org/archives/list/security-announce@python.org/thread/JIFOBO7UX3LY4VJKJUOKYJV62CFR2IRH/', 'https://https://www.geovision.com.tw/cyber_security.php', 'https://https://nvd.nist.gov/vuln/detail/CVE-2026-4272', 'https://https://github.com/videolan/vlc-android/releases/tag/3.7.0', 'https://https://thewatch.centreon.com/latest-security-bulletins-64/cve-2026-2751-centreon-web-high-severity-5504'})
##

CVE-2026-4020
(7.5 HIGH)

EPSS: 2.98%

updated 2026-03-31T03:31:35

4 posts

The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. This is due to a REST API endpoint registered at /wp-json/gravitysmtp/v1/tests/mock-data with a permission_callback that unconditionally returns true, allowing any unauthenticated visitor to access it. When the ?page=gravitysmtp-settings query parameter is appended, th

Nuclei template

hrbrmstr@mastodon.social at 2026-06-17T10:42:14.000Z ##

Solid breakdown by @honeylabs of the opportunistic activity against CVE-2026-4020

~560 IPs rotating through ~3,300 UAs

Rly important to heed the info further down in the article re: "attacking the CVE" vs "added yet-another-cred path to existing scans".

honeylabs.net/blog/the-cloud-f

##

hnbot@chrispelli.fun at 2026-06-17T09:14:09.000Z ##

Most of the CVE-2026-4020 attackers are the same client - honeylabs.net/blog/the-cloud-f

#hackernews

##

ngate@mastodon.social at 2026-06-17T09:13:14.000Z ##

🤔 Ah, the classic "same client" saga with CVE-2026-4020—because who needs originality in #hacking when you have a Google Cloud fleet playing dress-up with 3,299 user agents? 🌍📬 Apparently, exploiting Gravity #SMTP is a team sport, but only if your team is a single IP address with a personality disorder. What a performance! 🎭💻
honeylabs.net/blog/the-cloud-f #CVE20264020 #GoogleCloud #SecurityFlaw #Cybersecurity #HackerNews #ngated

##

h4ckernews@mastodon.social at 2026-06-17T09:13:08.000Z ##

Most of the CVE-2026-4020 attackers are the same client

honeylabs.net/blog/the-cloud-f

#HackerNews #CVE20264020 #cybersecurity #cloudfleet #attackers #analysis

##

CVE-2026-2751
(8.3 HIGH)

EPSS: 0.27%

updated 2026-02-27T15:34:20

1 posts

Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web on Central Server on Linux (Service Dependencies modules) allows Blind SQL Injection.This issue affects Centreon Web on Central Server before 25.10.8, 24.10.20, 24.04.24.

1 repos

https://github.com/hakaioffsec/Centreon-Exploits-2026

nyanbinary@infosec.exchange at 2026-06-17T14:54:22.000Z ##

Q: Am I counting these?

('https://https:', {'https://https://docs.tenable.com/release-notes/Content/security-center/2026.htm', 'https://https://www.asustor.com/security/security_advisory_detail?id=55', 'https://https://www.tenable.com/security/tns-2026-07', 'https://https://talosintelligence.com/vulnerability_reports/', 'https://https://mail.python.org/archives/list/security-announce@python.org/thread/JIFOBO7UX3LY4VJKJUOKYJV62CFR2IRH/', 'https://https://www.geovision.com.tw/cyber_security.php', 'https://https://nvd.nist.gov/vuln/detail/CVE-2026-4272', 'https://https://github.com/videolan/vlc-android/releases/tag/3.7.0', 'https://https://thewatch.centreon.com/latest-security-bulletins-64/cve-2026-2751-centreon-web-high-severity-5504'})
##

CVE-2026-21265
(6.4 MEDIUM)

EPSS: 0.97%

updated 2026-01-13T18:31:19

1 posts

Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot functionality and avoid compromising security by losing security fixes related to Windows boot manager or Secure Boot. The operating system’s certificate update protection mech

serigala_tropis@lgbtqia.space at 2026-06-15T13:50:34.000Z ##

Kabar mengenai security holes di Microsoft yang dipublikasi di awal tahun 2026, mulai dari Microsoft Office remote code execution bugs CVE-2026-20952, CVE-2026-20953 hingga vulnerability secure boot bypass CVE-2026-21265 yang bersifat critical karena sudah menyangkut ancaman bootkit dan rootkit, sedangkan certificate secure boot device lama akan kadaluarsa pada Juni 2026. Dan masih banyak lagi.

krebsonsecurity.com/2026/01/pa

##

CVE-2026-20953
(8.4 HIGH)

EPSS: 0.60%

updated 2026-01-13T18:31:18

1 posts

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

serigala_tropis@lgbtqia.space at 2026-06-15T13:50:34.000Z ##

Kabar mengenai security holes di Microsoft yang dipublikasi di awal tahun 2026, mulai dari Microsoft Office remote code execution bugs CVE-2026-20952, CVE-2026-20953 hingga vulnerability secure boot bypass CVE-2026-21265 yang bersifat critical karena sudah menyangkut ancaman bootkit dan rootkit, sedangkan certificate secure boot device lama akan kadaluarsa pada Juni 2026. Dan masih banyak lagi.

krebsonsecurity.com/2026/01/pa

##

CVE-2026-20952
(8.4 HIGH)

EPSS: 0.50%

updated 2026-01-13T18:31:18

1 posts

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

serigala_tropis@lgbtqia.space at 2026-06-15T13:50:34.000Z ##

Kabar mengenai security holes di Microsoft yang dipublikasi di awal tahun 2026, mulai dari Microsoft Office remote code execution bugs CVE-2026-20952, CVE-2026-20953 hingga vulnerability secure boot bypass CVE-2026-21265 yang bersifat critical karena sudah menyangkut ancaman bootkit dan rootkit, sedangkan certificate secure boot device lama akan kadaluarsa pada Juni 2026. Dan masih banyak lagi.

krebsonsecurity.com/2026/01/pa

##

CVE-2024-39683
(5.7 MEDIUM)

EPSS: 0.61%

updated 2024-08-08T05:06:35

1 posts

### Impact ZITADEL provides users the ability to list all user sessions of the current user agent (browser) by API and in the Console UI. Due to a missing check, user sessions without that information (e.g. when created though the session service) were incorrectly listed exposing potentially other user's sessions. Note that the Login UI was never affected and there was no possibility to take ov

nyanbinary@infosec.exchange at 2026-06-15T21:06:11.000Z ##

Previously I posted that no one had included discord links in CVE references...

... turns out I made a mistake in the query ...

cve.org/CVERecord?id=CVE-2021- : Discord Attachment link (of course since dead) for a source code snippet.
cve.org/CVERecord?id=CVE-2024- : Actually just a message link - which means, unless you already know what server that is & you are on it... you cant actually access it...?

##

CVE-2021-45464
(8.8 HIGH)

EPSS: 0.38%

updated 2024-04-04T03:30:13

1 posts

kvmtool through 39181fc allows an out-of-bounds write, related to virtio/balloon.c and virtio/pci.c. This allows a guest OS user to execute arbitrary code on the host machine.

nyanbinary@infosec.exchange at 2026-06-15T21:06:11.000Z ##

Previously I posted that no one had included discord links in CVE references...

... turns out I made a mistake in the query ...

cve.org/CVERecord?id=CVE-2021- : Discord Attachment link (of course since dead) for a source code snippet.
cve.org/CVERecord?id=CVE-2024- : Actually just a message link - which means, unless you already know what server that is & you are on it... you cant actually access it...?

##

CVE-2019-16193
(5.4 MEDIUM)

EPSS: 0.62%

updated 2024-04-04T01:55:17

1 posts

In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a Cross Frame Scripting (XFS) attack through the EDIT MY PROFILE feature.

nyanbinary@infosec.exchange at 2026-06-16T08:12:36.000Z ##

Here, have some CVE references pointing to facebook posts...
cve.org/CVERecord?id=CVE-2019-
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
... would you be surprised they are all dead?

This one links a Facebook video which is also dead. At least it also links a Twitter post by the same person...
cve.org/CVERecord?id=CVE-2017-
...which just links to the dead Facebook post.

##

CVE-2026-46701
(0 None)

EPSS: 0.00%

1 posts

N/A

EUVD_Bot@mastodon.social at 2026-06-17T22:00:21.000Z ##

🚨 EUVD-2026-37787

📊 Score: 9.1/10 (CVSS v3.1)
📦 Product: Network-AI
🏢 Vendor: Jovancoding
📅 Updated: 2026-06-17

📝 Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows unauthenticated cross-origin MCP tool invocation due to an empty default secret. This issue was partially addressed by CVE-2026-46701...

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2026-12530
(0 None)

EPSS: 0.00%

2 posts

N/A

offseq at 2026-06-17T22:00:14.215Z ##

🚨 CRITICAL: CVE-2026-12530 impacts AWS Bedrock AgentCore Python SDK (v1.1.3 – 1.6.1). Incomplete input sanitization in install_packages() lets attackers abuse pip flags. Update now! radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-06-17T22:00:14.000Z ##

🚨 CRITICAL: CVE-2026-12530 impacts AWS Bedrock AgentCore Python SDK (v1.1.3 – 1.6.1). Incomplete input sanitization in install_packages() lets attackers abuse pip flags. Update now! radar.offseq.com/threat/cve-20 #OffSeq #AWSSecurity #Python #CVE2026_12530

##

CVE-2026-48814
(0 None)

EPSS: 0.00%

2 posts

N/A

offseq at 2026-06-17T20:30:11.898Z ##

🚨 CRITICAL: CVE-2026-48814 in Jovancoding Network-AI ≤5.7.1 lets unauthenticated users access all 22 MCP tools if default secret is unset. Patch to 5.7.2 now! Details: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-06-17T20:30:11.000Z ##

🚨 CRITICAL: CVE-2026-48814 in Jovancoding Network-AI ≤5.7.1 lets unauthenticated users access all 22 MCP tools if default secret is unset. Patch to 5.7.2 now! Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE202648814 #Nodejs #Infosec

##

CVE-2026-8024
(0 None)

EPSS: 0.00%

2 posts

N/A

AAKL at 2026-06-17T18:01:10.869Z ##

New.

Tenable research advisories:

CRITICAL: CVE-2026-8024: iba ibaPDA / ibaDatCoordinator .NET Deserialization Remote Code Execution tenable.com/security/research/ @tenable

Cisco:

CRITICAL: CVE-2026-20181 and CVE-2026-20190: Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities

Three others of medium-severity: sec.cloudapps.cisco.com/securi @TalosSecurity

Broadcom:

Several critical and high-severity vulnerabilities. A login is needed for details support.broadcom.com/web/ecx/s

Dell:

Several advisories, one of them critical:

CRITICAL: Security Update for Dell Data Protection Central Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0

More: dell.com/support/security/en-us

Google:

Chrome Beta for iOS Update chromereleases.googleblog.com/

Yesterday:

Microsoft:

CVE-2026-50656: Microsoft Defender Elevation of Privilege Vulnerability msrc.microsoft.com/update-guid

Nvidia:

Security Bulletin addressing CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228:

NVIDIA NeMo - June 2026 nvidia.custhelp.com/app/answer

##

AAKL@infosec.exchange at 2026-06-17T18:01:10.000Z ##

New.

Tenable research advisories:

CRITICAL: CVE-2026-8024: iba ibaPDA / ibaDatCoordinator .NET Deserialization Remote Code Execution tenable.com/security/research/ @tenable

Cisco:

CRITICAL: CVE-2026-20181 and CVE-2026-20190: Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities

Three others of medium-severity: sec.cloudapps.cisco.com/securi @TalosSecurity

Broadcom:

Several critical and high-severity vulnerabilities. A login is needed for details support.broadcom.com/web/ecx/s

Dell:

Several advisories, one of them critical:

CRITICAL: Security Update for Dell Data Protection Central Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0

More: dell.com/support/security/en-us

Google:

Chrome Beta for iOS Update chromereleases.googleblog.com/

Yesterday:

Microsoft:

CVE-2026-50656: Microsoft Defender Elevation of Privilege Vulnerability msrc.microsoft.com/update-guid

Nvidia:

Security Bulletin addressing CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228:

NVIDIA NeMo - June 2026 nvidia.custhelp.com/app/answer #Nvidia #Dell #Cisco #infosec #vulnerability #threatresearch #Broadcom #Google #Chrome #Microsoft #Windows

##

CVE-2026-24252
(0 None)

EPSS: 0.00%

3 posts

N/A

AAKL at 2026-06-17T18:01:10.869Z ##

New.

Tenable research advisories:

CRITICAL: CVE-2026-8024: iba ibaPDA / ibaDatCoordinator .NET Deserialization Remote Code Execution tenable.com/security/research/ @tenable

Cisco:

CRITICAL: CVE-2026-20181 and CVE-2026-20190: Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities

Three others of medium-severity: sec.cloudapps.cisco.com/securi @TalosSecurity

Broadcom:

Several critical and high-severity vulnerabilities. A login is needed for details support.broadcom.com/web/ecx/s

Dell:

Several advisories, one of them critical:

CRITICAL: Security Update for Dell Data Protection Central Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0

More: dell.com/support/security/en-us

Google:

Chrome Beta for iOS Update chromereleases.googleblog.com/

Yesterday:

Microsoft:

CVE-2026-50656: Microsoft Defender Elevation of Privilege Vulnerability msrc.microsoft.com/update-guid

Nvidia:

Security Bulletin addressing CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228:

NVIDIA NeMo - June 2026 nvidia.custhelp.com/app/answer

##

AAKL@infosec.exchange at 2026-06-17T18:01:10.000Z ##

New.

Tenable research advisories:

CRITICAL: CVE-2026-8024: iba ibaPDA / ibaDatCoordinator .NET Deserialization Remote Code Execution tenable.com/security/research/ @tenable

Cisco:

CRITICAL: CVE-2026-20181 and CVE-2026-20190: Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities

Three others of medium-severity: sec.cloudapps.cisco.com/securi @TalosSecurity

Broadcom:

Several critical and high-severity vulnerabilities. A login is needed for details support.broadcom.com/web/ecx/s

Dell:

Several advisories, one of them critical:

CRITICAL: Security Update for Dell Data Protection Central Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0

More: dell.com/support/security/en-us

Google:

Chrome Beta for iOS Update chromereleases.googleblog.com/

Yesterday:

Microsoft:

CVE-2026-50656: Microsoft Defender Elevation of Privilege Vulnerability msrc.microsoft.com/update-guid

Nvidia:

Security Bulletin addressing CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228:

NVIDIA NeMo - June 2026 nvidia.custhelp.com/app/answer #Nvidia #Dell #Cisco #infosec #vulnerability #threatresearch #Broadcom #Google #Chrome #Microsoft #Windows

##

AAKL@infosec.exchange at 2026-06-16T15:46:34.000Z ##

Nvidia has a new advisory relating to CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228, all high-severity:

Security Bulletin: NVIDIA NeMo - June 2026 nvidia.custhelp.com/app/answer #Nvidia

Broadcom:

Seven advisories addressing one critical vulnerability and several high-severity flaws: You'll need a login for details.

CRITICAL: MICS 14.3, 14.4, and 14.5 Vulnerabilities

More: support.broadcom.com/web/ecx/s #Broadcom

Yesterday:

Google:

Chrome Dev for Desktop Update chromereleases.googleblog.com/ #Google #Chrome

Dell:

Update for a critical vulnerability yesterday that encompasses multiple CVEs:

Security Update for Dell PowerProtect DP Series Appliance (IDPA) Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #infosec #vulnerability

##

CVE-2026-4855
(0 None)

EPSS: 0.00%

2 posts

N/A

cyberveille@mastobot.ping.moi at 2026-06-17T17:00:21.000Z ##

📢 CVE-2026-48558 : Contournement d'authentification critique dans SimpleHelp via OIDC
📝 ## 🔍 Contexte

Le 12 juin 2026, Horizon3.ai publie une divulgation technique concernant **CVE-2026-4855...
📖 cyberveille : cyberveille.ch/posts/2026-06-1
🌐 source : horizon3.ai/attack-research/di
#CVE_2026_48558 #IOC #Cyberveille

##

cyberveille@mastobot.ping.moi at 2026-06-17T17:00:21.000Z ##

📢 CVE-2026-48558 : Contournement d'authentification critique dans SimpleHelp via OIDC
📝 ## 🔍 Contexte

Le 12 juin 2026, Horizon3.ai publie une divulgation technique concernant **CVE-2026-4855...
📖 cyberveille : cyberveille.ch/posts/2026-06-1
🌐 source : horizon3.ai/attack-research/di
#CVE_2026_48558 #IOC #Cyberveille

##

CVE-2026-47103
(0 None)

EPSS: 0.00%

2 posts

N/A

offseq at 2026-06-17T16:00:33.540Z ##

⚡️ CRITICAL: CVE-2026-47103 in python-statemachine (3.0.0 – <3.2.0) lets attackers execute code remotely via unsanitized eval() in SCXML. Avoid untrusted SCXML until patch. Details: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-06-17T16:00:33.000Z ##

⚡️ CRITICAL: CVE-2026-47103 in python-statemachine (3.0.0 – <3.2.0) lets attackers execute code remotely via unsanitized eval() in SCXML. Avoid untrusted SCXML until patch. Details: radar.offseq.com/threat/cve-20 #OffSeq #python #security #CVE202647103

##

CVE-2026-48745
(0 None)

EPSS: 0.41%

1 posts

N/A

offseq@infosec.exchange at 2026-06-17T01:30:30.000Z ##

🚨 CRITICAL: CVE-2026-48745 in traccar-client <=9.7.19 allows silent GPS data redirection via crafted deep links — no user prompt, persists after restart. Update to 9.7.20 now! radar.offseq.com/threat/cve-20 #OffSeq #Infosec #MobileSecurity #CVE202648745

##

CVE-2026-48797
(0 None)

EPSS: 0.44%

1 posts

N/A

offseq@infosec.exchange at 2026-06-17T00:00:36.000Z ##

🚨 CRITICAL vuln in mcp-tool-shop-org backpropagate <1.2.0: Reflex UI lacks real auth, letting anyone trigger training, access datasets, & export models. Patch to 1.2.0 ASAP. CVE-2026-48797 radar.offseq.com/threat/cve-20 #OffSeq #Python #Infosec

##

CVE-2026-47747
(0 None)

EPSS: 0.14%

1 posts

N/A

thehackerwire@mastodon.social at 2026-06-16T21:00:01.000Z ##

🟠 CVE-2026-47747 - High (7.8)

stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. In versions prior to master-584-0a7ae07, the pickle .ckpt parser in src/model.cpp contained a heap buf...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53776
(0 None)

EPSS: 0.36%

1 posts

N/A

thehackerwire@mastodon.social at 2026-06-16T18:00:13.000Z ##

🔴 CVE-2026-53776 - Critical (9.1)

Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by exploiting the unconditional setting of validate_exp = false in the verify_decode helper within the stdlib JWT verification pa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48780
(0 None)

EPSS: 0.22%

1 posts

N/A

thehackerwire@mastodon.social at 2026-06-16T16:00:00.000Z ##

🟠 CVE-2026-48780 - High (8.2)

Forem is open source software for building communities. Prior to commit a2ab6d4, a maliciously crafted email address could allow an attacker to bypass domain allowlist or denylist restrictions and gain access to invite-only forem deployments. The ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-68615
(0 None)

EPSS: 42.69%

1 posts

N/A

certvde@infosec.exchange at 2026-06-16T08:17:56.000Z ##

#OT #Advisory VDE-2026-038
TURCK: Multiple Vulnerabilities in Managed Ethernet Switches

Multiple vulnerabilities have been identified in the TBEN-Lx-SE-M2 firmware prior to version 2.1.2.0 in Managed Ethernet Switches.
#CVE CVE-2025-68615, CVE-2026-5416

certvde.com/en/advisories/vde-

#CSAF turck.csaf-tp.certvde.com/.wel

##

CVE-2026-48713
(0 None)

EPSS: 0.38%

2 posts

N/A

offseq@infosec.exchange at 2026-06-16T03:00:24.000Z ##

🚨 CVE-2026-48713: Prototype pollution in i18next-fs-backend <2.6.6 (CVSS 9.1, CRITICAL). Exploitable via crafted missing-key strings, leading to crashes or security bypass. Upgrade to 2.6.6 or apply mitigations now! radar.offseq.com/threat/cve-20 #OffSeq #infosec #NodeJS #vuln

##

thehackerwire@mastodon.social at 2026-06-15T23:00:12.000Z ##

🔴 CVE-2026-48713 - Critical (9.1)

Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missing translation keys (e.g. via i18next-http-middleware's missingKeyHandler exposed to untrusted input). Backend.writeFile() spli...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48714
(0 None)

EPSS: 0.38%

2 posts

N/A

offseq@infosec.exchange at 2026-06-16T01:30:25.000Z ##

🚨 CRITICAL: CVE-2026-48714 in i18next-http-middleware (<3.9.7) enables remote prototype pollution via missingKeyHandler. Impacts: app crashes, translation corruption, config poisoning. Upgrade to 3.9.7 or apply mitigations! radar.offseq.com/threat/cve-20 #OffSeq #CVE202648714 #infosec

##

thehackerwire@mastodon.social at 2026-06-15T23:00:21.000Z ##

🔴 CVE-2026-48714 - Critical (9.1)

i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. In versions prior to 3.9.7, the missingKeyHandler blocked the literal request-body keys __proto__, constructor, and prototype...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48723
(0 None)

EPSS: 0.53%

1 posts

N/A

thehackerwire@mastodon.social at 2026-06-16T01:00:02.000Z ##

🟠 CVE-2026-48723 - High (7.8)

The browserstack-cypress-cli is BrowserStack's CLI which allows users to run Cypress tests on BrowserStack. Versions prior to 1.36.4 are vulnerable to OS command injection via the cypress_config_file configuration parameter. In readCypressConfigUt...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49757
(0 None)

EPSS: 0.44%

1 posts

N/A

offseq@infosec.exchange at 2026-06-15T18:00:15.000Z ##

🚨 CRITICAL: CVE-2026-49757 in ash_authentication lets attackers bypass auth by spoofing email in OAuth2/OIDC, risking local account takeover. Patch status unconfirmed — check vendor advisory. Affected: v0.1.0, 5.0.0-rc.0. radar.offseq.com/threat/cve-20 #OffSeq #CVE202649757 #OAuth2 #infosec

##

Visit counter For Websites