##
Updated at UTC 2026-08-13T21:33:23.763424
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-17220 | 8.2 | 0.00% | 2 | 0 | 2026-08-13T20:36:48.443000 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of | |
| CVE-2026-17197 | 8.1 | 0.00% | 2 | 0 | 2026-08-13T20:36:48.443000 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security re | |
| CVE-2026-73653 | 9.4 | 0.00% | 2 | 0 | 2026-08-13T19:17:38.920000 | Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, | |
| CVE-2026-73650 | 8.2 | 0.00% | 2 | 0 | 2026-08-13T19:17:38.460000 | SVGO, short for SVG Optimizer, is a Node.js library and command-line application | |
| CVE-2026-73482 | 8.1 | 0.00% | 2 | 0 | 2026-08-13T19:17:34.423000 | phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerabil | |
| CVE-2026-72777 | 8.6 | 0.00% | 2 | 0 | 2026-08-13T19:17:32.320000 | Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerabil | |
| CVE-2026-73515 | 8.1 | 0.00% | 2 | 0 | 2026-08-13T18:31:43 | PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allo | |
| CVE-2026-73514 | 8.8 | 0.00% | 2 | 0 | 2026-08-13T18:18:18.097000 | The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 42 | |
| CVE-2026-73493 | 7.5 | 0.35% | 2 | 0 | 2026-08-13T18:18:17.740000 | Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP se | |
| CVE-2026-48362 | 10.0 | 2.07% | 2 | 0 | 2026-08-13T18:17:59.073000 | ColdFusion is affected by an Improper Neutralization of Special Elements used in | |
| CVE-2026-17248 | 7.1 | 0.33% | 1 | 0 | 2026-08-13T16:31:58.810000 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to caus | |
| CVE-2026-73570 | 8.9 | 0.00% | 2 | 0 | 2026-08-13T16:19:06.003000 | A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) befor | |
| CVE-2026-73246 | 7.5 | 0.35% | 1 | 0 | 2026-08-13T16:19:03.820000 | Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc | |
| CVE-2026-6464 | 8.1 | 0.00% | 2 | 1 | 2026-08-13T16:18:56.653000 | Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrato | |
| CVE-2026-69105 | 8.1 | 0.13% | 2 | 0 | 2026-08-13T16:18:55.870000 | An unauthenticated attacker may cause untrusted package content to be cached und | |
| CVE-2026-64954 | 8.2 | 0.23% | 1 | 0 | 2026-08-13T16:18:35.927000 | Velociraptor allows scheduling new collections via VQL queries in notebooks. For | |
| CVE-2026-14863 | 8.8 | 1.65% | 2 | 0 | 2026-08-13T15:34:30 | FileRun up to and including version 2026.2.0 contains an OS command injection vu | |
| CVE-2026-55040 | 9.1 | 2.96% | 18 | 2 | 2026-08-13T15:34:13 | Weak authentication in Microsoft Office SharePoint allows an unauthorized attack | |
| CVE-2026-73406 | 7.5 | 0.37% | 2 | 0 | 2026-08-13T15:20:13.780000 | Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/ | |
| CVE-2026-73224 | 8.8 | 0.34% | 1 | 0 | 2026-08-13T15:20:09.360000 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ft | |
| CVE-2026-71398 | 10.0 | 0.64% | 2 | 0 | 2026-08-13T15:20:01.813000 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi | |
| CVE-2026-59507 | 9.3 | 0.32% | 2 | 0 | 2026-08-13T15:19:54.267000 | CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Informatio | |
| CVE-2026-59506 | 9.3 | 0.40% | 2 | 0 | 2026-08-13T15:19:54.160000 | CWE-306: Missing Authentication for Critical Function | |
| CVE-2026-19311 | 8.1 | 0.41% | 2 | 0 | 2026-08-13T15:19:38.027000 | Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting p | |
| CVE-2026-12263 | 8.8 | 0.00% | 2 | 0 | 2026-08-13T15:19:28.560000 | Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 vers | |
| CVE-2026-73498 | 7.7 | 0.33% | 2 | 0 | 2026-08-13T14:17:13.663000 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (C | |
| CVE-2026-71193 | 9.6 | 0.53% | 4 | 0 | 2026-08-13T14:17:12.087000 | In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_sup | |
| CVE-2026-66898 | 9.9 | 0.34% | 2 | 0 | 2026-08-13T14:17:11.320000 | A path traversal vulnerability in LXD allows an attacker to manipulate file syst | |
| CVE-2026-59310 | 9.8 | 1.14% | 17 | 0 | 2026-08-13T14:17:01.890000 | VMware vCenter contains a directory traversal vulnerability in the Syslog server | |
| CVE-2026-0301 | 0 | 0.31% | 2 | 0 | 2026-08-13T14:16:53.247000 | An information disclosure vulnerability in the URL Filtering feature of Palo Alt | |
| CVE-2026-61358 | 7.8 | 3.31% | 1 | 0 | 2026-08-13T13:59:48.317000 | Improper link resolution before file access ('link following') in Windows Access | |
| CVE-2026-73501 | 9.1 | 0.34% | 2 | 0 | 2026-08-13T13:19:18.350000 | kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, Valida | |
| CVE-2026-73418 | 7.5 | 0.46% | 2 | 0 | 2026-08-13T13:19:17.513000 | NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and | |
| CVE-2026-59501 | 8.2 | 0.32% | 2 | 0 | 2026-08-13T12:31:13 | CWE-284: Improper Access Control | |
| CVE-2026-59500 | 10.0 | 0.38% | 2 | 0 | 2026-08-13T12:31:12 | CWE-287: Improper Authentication | |
| CVE-2026-11840 | 8.8 | 1.58% | 1 | 0 | 2026-08-13T09:31:16 | Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngin | |
| CVE-2026-13610 | 0 | 0.15% | 2 | 0 | 2026-08-13T06:17:37.780000 | The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignab | |
| CVE-2026-26035 | 9.8 | 0.51% | 2 | 0 | 2026-08-13T05:17:23.773000 | An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet For | |
| CVE-2026-19556 | 8.8 | 0.34% | 1 | 0 | 2026-08-13T05:17:23.020000 | Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote a | |
| CVE-2026-10534 | 8.4 | 0.18% | 2 | 0 | 2026-08-13T00:31:33 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer | |
| CVE-2026-19003 | 7.8 | 0.13% | 2 | 0 | 2026-08-13T00:31:33 | A data source definition containing an over-length file path setting may cause t | |
| CVE-2026-73519 | 9.8 | 0.62% | 4 | 0 | 2026-08-13T00:31:28 | WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret comp | |
| CVE-2026-71471 | 9.0 | 1.45% | 4 | 0 | 2026-08-13T00:31:26 | A flaw was found in acm-search-v2-rhel9. An attacker with administrative privile | |
| CVE-2026-71473 | 8.5 | 0.26% | 2 | 0 | 2026-08-13T00:31:26 | A flaw was found in the `search-v2-operator` component. A user with specific adm | |
| CVE-2026-73303 | 8.2 | 0.23% | 2 | 0 | 2026-08-12T23:17:24.403000 | Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/emai | |
| CVE-2026-55676 | 8.8 | 0.30% | 1 | 0 | 2026-08-12T23:17:21.683000 | Malcolm is a network traffic analysis tool suite. The file-upload component (Fil | |
| CVE-2026-73433 | 6.6 | 0.13% | 2 | 0 | 2026-08-12T22:17:16.273000 | A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM | |
| CVE-2026-71469 | 7.5 | 0.36% | 2 | 0 | 2026-08-12T22:17:15.760000 | A flaw was found in search-v2-api. An unauthenticated attacker can exploit this | |
| CVE-2026-19002 | 8.1 | 0.29% | 2 | 0 | 2026-08-12T21:31:51 | A missing bounds check when parsing stored procedure parameter metadata in the M | |
| CVE-2026-19001 | 9.8 | 0.38% | 2 | 0 | 2026-08-12T21:31:51 | The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-siz | |
| CVE-2026-73326 | 7.6 | 0.27% | 2 | 0 | 2026-08-12T21:31:50 | CamaleonCMS contains a missing authorization vulnerability that allows any authe | |
| CVE-2026-17083 | 9.8 | 0.46% | 2 | 0 | 2026-08-12T21:31:44 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary | |
| CVE-2026-73332 | 8.7 | 0.23% | 2 | 0 | 2026-08-12T21:31:43 | CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_con | |
| CVE-2026-73329 | 8.7 | 0.23% | 2 | 0 | 2026-08-12T21:17:40.527000 | CamaleonCMS contains a stored cross-site scripting vulnerability that allows aut | |
| CVE-2026-71362 | 9.1 | 0.48% | 11 | 0 | 2026-08-12T21:03:43.743000 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul | |
| CVE-2026-48442 | 7.1 | 0.24% | 1 | 0 | 2026-08-12T21:03:43.743000 | CAI Content Credentials is affected by an Improper Limitation of a Pathname to a | |
| CVE-2026-48381 | 9.0 | 0.48% | 2 | 0 | 2026-08-12T21:03:43.743000 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia | |
| CVE-2026-73325 | 7.8 | 0.26% | 2 | 0 | 2026-08-12T20:17:54.730000 | Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserializati | |
| CVE-2026-73300 | 9.6 | 0.38% | 2 | 0 | 2026-08-12T20:17:54.023000 | Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integra | |
| CVE-2026-72798 | 8.6 | 0.26% | 1 | 0 | 2026-08-12T20:17:51.543000 | SiYuan versions before v3.7.4 fail to properly filter related-database content i | |
| CVE-2026-58115 | 10.0 | 0.65% | 1 | 0 | 2026-08-12T20:17:45.377000 | A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1 | |
| CVE-2026-69106 | 8.8 | 0.35% | 2 | 0 | 2026-08-12T18:31:29 | A low-privileged user may poison cached artifact metadata under specific conditi | |
| CVE-2026-73327 | 7.6 | 0.85% | 2 | 0 | 2026-08-12T18:31:29 | Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate ext | |
| CVE-2026-18634 | 8.4 | 0.22% | 1 | 0 | 2026-08-12T18:31:15 | An insecure handling of serialized objects vulnerability was found in the one of | |
| CVE-2026-73122 | 7.7 | 0.21% | 1 | 0 | 2026-08-12T17:17:31.853000 | A flaw was found in the multicloud-operators-channel component of Red Hat Advanc | |
| CVE-2026-65941 | 8.8 | 0.44% | 2 | 0 | 2026-08-12T17:17:29.610000 | In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote att | |
| CVE-2026-50656 | 7.8 | 10.75% | 11 | 3 | 2026-08-12T17:17:27.983000 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect | |
| CVE-2026-66804 | 7.8 | 3.03% | 3 | 2 | 2026-08-12T16:17:14.650000 | Improper access control in Windows Cross Device Service allows an authorized att | |
| CVE-2026-19560 | 8.8 | 0.34% | 1 | 0 | 2026-08-12T15:31:45 | Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remot | |
| CVE-2026-57858 | 8.9 | 0.41% | 4 | 1 | 2026-08-12T15:30:49 | Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripti | |
| CVE-2026-70468 | 8.1 | 0.59% | 2 | 0 | 2026-08-12T15:30:49 | A authentication bypass using an alternate path or channel vulnerability in Fort | |
| CVE-2026-66147 | 9.4 | 1.05% | 1 | 0 | 2026-08-12T15:18:18.370000 | An unauthenticated command injection vulnerability was identified in the GMS Dis | |
| CVE-2026-20349 | 8.6 | 0.87% | 13 | 0 | 2026-08-12T15:02:21.707000 | A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall A | |
| CVE-2026-67568 | 9.1 | 0.24% | 2 | 0 | 2026-08-12T14:18:33.557000 | The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access | |
| CVE-2026-59124 | 9.8 | 1.72% | 2 | 0 | 2026-08-12T14:18:02.933000 | Deserialization of untrusted data in Microsoft High Performance Computing (HPC) | |
| CVE-2026-73249 | 7.5 | 0.25% | 1 | 0 | 2026-08-12T13:17:26.097000 | calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoi | |
| CVE-2026-72526 | 9.9 | 0.30% | 2 | 0 | 2026-08-12T13:17:25.827000 | A flaw was found in the multicloud-integrations component. The Application propa | |
| CVE-2026-6484 | 8.2 | 0.14% | 1 | 0 | 2026-08-12T13:17:24.500000 | In an UEFI, Lack of verified boot to certain FV may cause arbitrary code executi | |
| CVE-2026-48763 | 8.2 | 0.31% | 1 | 0 | 2026-08-12T13:17:22.633000 | TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated | |
| CVE-2026-19594 | 8.1 | 0.40% | 2 | 0 | 2026-08-12T13:17:22.180000 | Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versi | |
| CVE-2025-41771 | 4.3 | 0.16% | 1 | 0 | 2026-08-12T13:17:18.880000 | An authenticated attacker with low privileges can access an endpoint in the cont | |
| CVE-2026-67282 | None | 0.57% | 2 | 0 | 2026-08-12T09:31:30 | Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabri | |
| CVE-2025-41770 | 7.5 | 0.39% | 3 | 0 | 2026-08-12T09:31:30 | An unauthenticated denial-of-service vulnerability in the device's PLCnext Engin | |
| CVE-2026-19426 | 8.2 | 0.30% | 2 | 0 | 2026-08-12T09:31:30 | POS System developed by FitSoft has a Missing Authentication vulnerability. Unau | |
| CVE-2025-41769 | 9.8 | 0.59% | 7 | 0 | 2026-08-12T09:31:29 | The device's PROFINET service is affected by a buffer overflow vulnerability tha | |
| CVE-2026-66659 | 9.3 | 0.29% | 3 | 0 | 2026-08-12T06:31:00 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti | |
| CVE-2026-58231 | 10.0 | 0.73% | 4 | 0 | 2026-08-12T05:17:56.963000 | SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authent | |
| CVE-2026-18129 | 8.1 | 0.87% | 2 | 0 | 2026-08-12T05:17:42.950000 | Cleartext transmission of sensitive information in the Core of Ivanti Endpoint M | |
| CVE-2026-18961 | 8.1 | 0.45% | 1 | 0 | 2026-08-12T03:31:28 | The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by Ventr | |
| CVE-2026-66878 | 7.7 | 0.21% | 2 | 0 | 2026-08-12T03:31:17 | A flaw was found in multicloud-operators-subscription. A privileged user, specif | |
| CVE-2026-70398 | 9.6 | 0.22% | 2 | 0 | 2026-08-12T03:31:17 | A flaw was found in multicloud-integrations, a component of Red Hat Advanced Clu | |
| CVE-2026-68067 | 9.8 | 0.28% | 2 | 0 | 2026-08-12T00:31:23 | The login endpoint on the Mira cloud API accepts any format-valid string in the | |
| CVE-2026-66875 | 8.8 | 0.24% | 1 | 0 | 2026-08-12T00:31:23 | In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote u | |
| CVE-2026-19579 | 5.4 | 0.24% | 2 | 0 | 2026-08-11T21:33:18 | Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object r | |
| CVE-2026-73282 | 4.8 | 0.16% | 2 | 0 | 2026-08-11T21:33:18 | In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a | |
| CVE-2026-73283 | 2.5 | 0.08% | 2 | 0 | 2026-08-11T21:33:18 | In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was su | |
| CVE-2026-18690 | 8.1 | 0.26% | 1 | 0 | 2026-08-11T21:33:12 | An issue in MongoDB Server could allow an authenticated user with a limited data | |
| CVE-2026-73281 | 3.5 | 0.16% | 2 | 0 | 2026-08-11T21:33:11 | In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were | |
| CVE-2026-68820 | 7.0 | 0.33% | 33 | 1 | 2026-08-11T21:33:01 | Use after free in Windows Ancillary Function Driver for WinSock allows an author | |
| CVE-2026-18687 | 7.1 | 0.17% | 1 | 0 | 2026-08-11T21:17:31.273000 | MongoDB Server's handling of a Queryable Encryption maintenance operation did no | |
| CVE-2026-73226 | 8.8 | 0.39% | 1 | 0 | 2026-08-11T20:18:48.007000 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ft | |
| CVE-2026-73225 | 8.1 | 0.31% | 2 | 0 | 2026-08-11T20:18:47.903000 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ft | |
| CVE-2026-20339 | 7.5 | 0.33% | 1 | 0 | 2026-08-11T18:54:19.877000 | A vulnerability in the PESpin file format parser of ClamAV could allow an unauth | |
| CVE-2026-20338 | 7.5 | 0.33% | 1 | 0 | 2026-08-11T18:54:19.877000 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticat | |
| CVE-2026-62901 | 7.5 | 1.08% | 1 | 0 | 2026-08-11T18:53:58 | ## Executive summary Microsoft is releasing this security advisory to provide i | |
| CVE-2026-27302 | 10.0 | 0.57% | 2 | 0 | 2026-08-11T18:32:00 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi | |
| CVE-2026-72971 | 5.5 | 0.36% | 1 | 0 | 2026-08-11T18:32:00 | Improper link resolution before file access ('link following') in Windows Contai | |
| CVE-2026-71384 | 9.6 | 0.24% | 2 | 0 | 2026-08-11T18:31:59 | is affected by an Incorrect Authorization vulnerability that could result in a S | |
| CVE-2026-66807 | 7.8 | 0.36% | 1 | 0 | 2026-08-11T18:31:49 | Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker | |
| CVE-2026-62832 | 7.8 | 2.39% | 3 | 0 | 2026-08-11T18:31:33 | Improper link resolution before file access ('link following') in Windows User P | |
| CVE-2026-62747 | 7.8 | 0.32% | 1 | 0 | 2026-08-11T18:31:25 | Heap-based buffer overflow in Windows Device Association Service allows an autho | |
| CVE-2026-61353 | 7.8 | 0.32% | 1 | 0 | 2026-08-11T18:31:13 | Heap-based buffer overflow in Windows Telephony Service allows an authorized att | |
| CVE-2026-58641 | 7.8 | 0.40% | 1 | 0 | 2026-08-11T18:31:08 | Integer overflow or wraparound in .NET allows an unauthorized attacker to elevat | |
| CVE-2026-59693 | 4.3 | 0.16% | 2 | 0 | 2026-08-11T18:17:41.267000 | A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16 | |
| CVE-2026-56721 | 8.8 | 0.36% | 2 | 0 | 2026-08-11T18:17:37.757000 | CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerabil | |
| CVE-2026-72915 | 7.5 | 0.28% | 1 | 0 | 2026-08-11T17:19:14.203000 | Mastodon is a free, open-source social network server based on ActivityPub. From | |
| CVE-2026-67180 | 8.4 | 0.17% | 1 | 0 | 2026-08-11T16:17:34.257000 | Google Turbinia allows arbitrary command execution via worker tasks. An attacker | |
| CVE-2026-50060 | 7.8 | 0.11% | 1 | 0 | 2026-08-11T15:32:40 | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 | |
| CVE-2026-19418 | None | 0.21% | 1 | 0 | 2026-08-11T09:32:42 | The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) | |
| CVE-2026-8917 | None | 0.11% | 1 | 0 | 2026-08-11T03:31:59 | Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and | |
| CVE-2026-34265 | 9.8 | 0.44% | 1 | 0 | 2026-08-11T03:31:57 | SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to expl | |
| CVE-2026-44758 | 9.1 | 0.51% | 1 | 0 | 2026-08-11T03:31:55 | SAP Manufacturing Integration and Intelligence (MII) allows an attacker with hig | |
| CVE-2026-64564 | 9.8 | 0.48% | 1 | 4 | 2026-08-09T06:31:34 | In the Linux kernel, the following vulnerability has been resolved: sctp: don't | |
| CVE-2026-66059 | 0 | 0.27% | 1 | 0 | 2026-08-08T04:17:50.503000 | Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, | |
| CVE-2026-67261 | 9.8 | 1.60% | 2 | 0 | 2026-08-07T20:08:27.597000 | Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10. | |
| CVE-2026-20337 | 7.5 | 0.36% | 2 | 0 | 2026-08-07T18:31:52 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticat | |
| CVE-2026-71319 | 9.6 | 0.32% | 2 | 0 | 2026-08-05T21:27:39 | ### Impact Nuxt DevTools (development mode only) exposes a bidirectional RPC ch | |
| CVE-2026-20272 | 9.8 | 0.34% | 1 | 0 | 2026-08-05T18:31:45 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-61515 | 9.8 | 1.58% | 2 | 0 | 2026-08-05T14:17:08.690000 | Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated c | |
| CVE-2026-71209 | 7.5 | 1.76% | 1 | 0 | template | 2026-08-05T09:31:27 | audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches |
| CVE-2026-63456 | 9.8 | 0.43% | 2 | 0 | 2026-08-04T18:31:36 | Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orch | |
| CVE-2026-63455 | 9.8 | 0.43% | 2 | 0 | 2026-08-04T18:31:32 | Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orch | |
| CVE-2026-18577 | 8.1 | 4.10% | 3 | 3 | 2026-08-04T14:27:12.530000 | An incomplete patch for CVE-2026-18556 allows for authentication bypass and acco | |
| CVE-2026-47301 | 8.8 | 0.54% | 2 | 1 | 2026-07-30T19:17:31.990000 | Improper access control in Microsoft Configuration Manager allows an authorized | |
| CVE-2026-59309 | 9.8 | 0.74% | 3 | 0 | 2026-07-30T16:17:15.073000 | VMware vCenter contains an authentication bypass vulnerability in the VMware Dir | |
| CVE-2026-47876 | 9.3 | 0.28% | 1 | 0 | 2026-07-30T14:16:58.467000 | VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual | |
| CVE-2026-64560 | 7.8 | 0.12% | 1 | 1 | 2026-07-30T12:32:18 | In the Linux kernel, the following vulnerability has been resolved: posix-cpu-t | |
| CVE-2025-4318 | 0 | 0.93% | 2 | 0 | 2026-07-29T16:17:47.997000 | The AWS Amplify Studio UI component property expressions in the aws-amplify/ampl | |
| CVE-2026-64747 | 7.8 | 0.14% | 1 | 1 | 2026-07-28T15:32:12 | A buffer overflow was addressed with improved size validation. This issue is fix | |
| CVE-2026-43723 | 7.8 | 0.15% | 2 | 0 | 2026-07-28T00:32:06 | A path handling issue was addressed with improved validation. This issue is fixe | |
| CVE-2026-16756 | 7.5 | 0.42% | 2 | 0 | 2026-07-24T22:37:39 | ## Summary Smithy-RS is a Rust code generation and runtime framework that genera | |
| CVE-2026-53360 | 8.8 | 0.18% | 2 | 1 | 2026-07-22T19:07:37.640000 | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: R | |
| CVE-2026-53361 | 7.1 | 0.13% | 1 | 1 | 2026-07-18T09:32:17 | In the Linux kernel, the following vulnerability has been resolved: af_unix: Se | |
| CVE-2026-43500 | 7.8 | 92.86% | 1 | 24 | 2026-07-15T02:21:44.380000 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also | |
| CVE-2026-43284 | 8.8 | 93.23% | 1 | 44 | 2026-07-15T02:21:43.190000 | In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: | |
| CVE-2026-31431 | 7.8 | 99.91% | 1 | 100 | template | 2026-07-14T15:32:55 | In the Linux kernel, the following vulnerability has been resolved: crypto: alg |
| CVE-2026-12879 | None | 0.19% | 1 | 0 | 2026-07-09T15:32:33 | An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apige | |
| CVE-2026-49478 | 8.7 | 0.00% | 2 | 0 | 2026-06-30T18:38:47 | ## Impact Three security vulnerabilities were identified in the OIDC Discovery | |
| CVE-2026-49473 | 8.8 | 0.28% | 2 | 0 | 2026-06-30T18:09:14 | ### Summary @cedar-policy/authorization-for-expressjs is an open-source Express. | |
| CVE-2026-27912 | 8.0 | 0.24% | 1 | 2 | 2026-06-17T10:27:52.490000 | Improper authorization in Windows Kerberos allows an authorized attacker to elev | |
| CVE-2026-23670 | 5.7 | 0.26% | 1 | 0 | 2026-06-17T10:21:55.793000 | Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enc | |
| CVE-2026-22185 | 0 | 0.13% | 2 | 0 | 2026-06-17T10:19:30.257000 | OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0. | |
| CVE-2026-47717 | 7.5 | 1.20% | 2 | 0 | template | 2026-05-27T22:51:19 | ### Summary The GET /api/project endpoint exposes sensitive project configurati |
| CVE-2021-44228 | 10.0 | 100.00% | 1 | 100 | template | 2025-10-22T19:13:26 | # Summary Log4j versions prior to 2.16.0 are subject to a remote code execution |
| CVE-2025-24472 | 8.1 | 3.87% | 1 | 1 | 2025-10-22T00:34:17 | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-2 | |
| CVE-2024-55591 | 9.8 | 98.26% | 3 | 9 | template | 2025-10-22T00:34:16 | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-2 |
| CVE-2025-24994 | 7.3 | 1.18% | 2 | 0 | 2025-03-11T18:32:28 | Improper access control in Windows Cross Device Service allows an authorized att | |
| CVE-2025-24076 | 7.3 | 3.15% | 2 | 1 | 2025-03-11T18:32:27 | Improper access control in Windows Cross Device Service allows an authorized att | |
| CVE-2026-65640 | 0 | 0.00% | 8 | 1 | N/A | ||
| CVE-2026-72898 | 0 | 10.40% | 10 | 1 | template | N/A | |
| CVE-2026-49827 | 0 | 0.00% | 4 | 0 | N/A | ||
| CVE-2026-48273 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-49481 | 0 | 0.88% | 4 | 0 | N/A | ||
| CVE-2026-49819 | 0 | 0.61% | 4 | 0 | N/A | ||
| CVE-2026-19654 | 0 | 0.40% | 2 | 0 | N/A | ||
| CVE-2026-73299 | 0 | 1.21% | 2 | 0 | N/A | ||
| CVE-2026-18952 | 0 | 0.32% | 2 | 0 | N/A | ||
| CVE-2026-73294 | 0 | 0.45% | 2 | 0 | N/A | ||
| CVE-2026-73293 | 0 | 0.40% | 2 | 0 | N/A | ||
| CVE-2026-73292 | 0 | 0.19% | 2 | 0 | N/A | ||
| CVE-2026-66058 | 0 | 0.22% | 1 | 0 | N/A | ||
| CVE-2026-66000 | 0 | 0.26% | 1 | 0 | N/A | ||
| CVE-2026-44772 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-72916 | 0 | 0.36% | 1 | 0 | N/A | ||
| CVE-2026-72914 | 0 | 0.45% | 1 | 0 | N/A | ||
| CVE-2026-12234 | 0 | 0.08% | 1 | 0 | N/A | ||
| CVE-2026-48765 | 0 | 0.26% | 2 | 0 | N/A | ||
| CVE-2026-73247 | 0 | 0.30% | 1 | 0 | N/A | ||
| CVE-2026-73234 | 0 | 0.16% | 1 | 0 | N/A | ||
| CVE-2026-73232 | 0 | 0.45% | 1 | 0 | N/A | ||
| CVE-2026-73231 | 0 | 0.15% | 1 | 0 | N/A |
updated 2026-08-13T20:36:48.443000
2 posts
🟠 CVE-2026-17220 - High (8.2)
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and modify authentication metadata due to a buffer overflow.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17220/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-17220 - High (8.2)
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and modify authentication metadata due to a buffer overflow.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17220/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T20:36:48.443000
2 posts
🟠 CVE-2026-17197 - High (8.1)
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17197/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-17197 - High (8.1)
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17197/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T19:17:38.920000
2 posts
🔴 CVE-2026-73653 - Critical (9.4)
Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73653/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-73653 - Critical (9.4)
Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73653/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T19:17:38.460000
2 posts
🟠 CVE-2026-73650 - High (8.2)
SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named removeScriptElement in versions 1 through 3, can ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73650/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73650 - High (8.2)
SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named removeScriptElement in versions 1 through 3, can ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73650/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T19:17:34.423000
2 posts
🟠 CVE-2026-73482 - High (8.1)
phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php. The administrator deletion action is triggered via an unauthenticated GET request (?page=admins&delete=N) that is not protected by a CSR...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73482/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73482 - High (8.1)
phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php. The administrator deletion action is triggered via an unauthenticated GET request (?page=admins&delete=N) that is not protected by a CSR...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73482/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T19:17:32.320000
2 posts
🟠 CVE-2026-72777 - High (8.6)
Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation that only checks string patterns without DNS resolution. Unauthenticated attackers can supply hostna...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72777/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-72777 - High (8.6)
Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation that only checks string patterns without DNS resolution. Unauthenticated attackers can supply hostna...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72777/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T18:31:43
2 posts
🟠 CVE-2026-73515 - High (8.1)
PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string l...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73515/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73515 - High (8.1)
PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string l...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73515/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T18:18:18.097000
2 posts
🟠 CVE-2026-73514 - High (8.8)
The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds write vulnerability that allows a database user with the ability to supply caller-controlled relation names to standardize_address() t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73514/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73514 - High (8.8)
The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds write vulnerability that allows a database user with the ability to supply caller-controlled relation names to standardize_address() t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73514/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T18:18:17.740000
2 posts
🟠 CVE-2026-73493 - High (7.5)
Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incoming WebSocket message with no limit on total size or fragment count. A clie...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73493/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73493 - High (7.5)
Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incoming WebSocket message with no limit on total size or fragment count. A clie...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73493/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T18:17:59.073000
2 posts
「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews
「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース
最も深刻な欠陥は以下のとおりです。
CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)
」
https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html
##「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews
「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース
最も深刻な欠陥は以下のとおりです。
CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)
」
https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html
##updated 2026-08-13T16:31:58.810000
1 posts
CVE-2026-17248 - DoS in IBM i 7.3-7.6 via improper OS command neutralization. Remote authenticated attacker can crash systems. CVSS 7.1. No patch yet - monitor advisory. #CVE #IBM #infosec
##updated 2026-08-13T16:19:06.003000
2 posts
🟠 CVE-2026-73570 - High (8.9)
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notificati...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73570/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73570 - High (8.9)
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notificati...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73570/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T16:19:03.820000
1 posts
🟠 CVE-2026-73246 - High (7.5)
Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kestra/worker/endpoint/WorkerEndpoint.java serves GET /worker without authentication and serializes the complete live Task object, ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73246/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T16:18:56.653000
2 posts
1 repos
🟠 CVE-2026-6464 - High (8.1)
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-6464/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-6464 - High (8.1)
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-6464/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T16:18:55.870000
2 posts
🟠 CVE-2026-69105 - High (8.1)
An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69105/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-69105 - High (8.1)
An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69105/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T16:18:35.927000
1 posts
🟠 CVE-2026-64954 - High (8.2)
Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the auth...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64954/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T15:34:30
2 posts
New.
"Today VulnCheck is disclosing CVE-2026-14863, an OS command injection to remote code execution in FileRun, a commercial self-hosted file manager. It is being disclosed in accordance with VulnCheck's coordinated vulnerability disclosure policy."
"The motivation was deliberate. Open-source codebases are getting shredded by AI-assisted auditing, where every researcher and their LLM greps the same GitHub repos and finds the same bugs."
Vulncheck: FileRun: When Your File Manager Runs Your Files https://www.vulncheck.com/blog/filerun-thumbnail-command-injection-rce @vulncheck #infosec #opensource #vulnerability
##New.
"Today VulnCheck is disclosing CVE-2026-14863, an OS command injection to remote code execution in FileRun, a commercial self-hosted file manager. It is being disclosed in accordance with VulnCheck's coordinated vulnerability disclosure policy."
"The motivation was deliberate. Open-source codebases are getting shredded by AI-assisted auditing, where every researcher and their LLM greps the same GitHub repos and finds the same bugs."
Vulncheck: FileRun: When Your File Manager Runs Your Files https://www.vulncheck.com/blog/filerun-thumbnail-command-injection-rce @vulncheck #infosec #opensource #vulnerability
##updated 2026-08-13T15:34:13
18 posts
2 repos
📢 CVE-2026-55040 : vulnérabilité SharePoint exploitée dans la nature après publication d'un PoC
Il rapporte l'exploitation active en conditions réelles de CVE-2026-55040, une vulnérabilité affectant Microsoft SharePoint, corrigée lors du Patch Tuesday de juillet 2026. CVE-2026-55040 est décrite par Microsoft comme un problème d'authentification faible…
📖 cyberveille : https://cyberveille.ch/posts/2026-08-13-cve-2026-55040-vulnerabilite-sharepoint-exploitee-dans-la-nature-apres-publication-d-un-poc/
🌐 source : https://www.securityweek.com/sharepoint-vulnerability-exploited-shortly-after-poc-release/
🟢 vérification factuelle haute
#PoC #SharePoint #Cyberveille
Attackers are actively exploiting CVE-2026-55040, a critical remote code execution vulnerability in Microsoft SharePoint, after a proof-of-concept exploit was released by Rapid7. This flaw affects Sha
https://www.helpnetsecurity.com/2026/08/13/microsoft-sharepoint-cve-2026-55040-poc-exploit/
#cybersecurity #Microsoft #SharePoint
「公開された概念実証(PoC)リリース後、攻撃者がSharePointの認証バイパスを悪用 」: #TheHackerNews
「攻撃者は、概念実証(PoC)コードの公開を受けて、新たに明らかになったMicrosoft SharePointの脆弱性を悪用し始めている。
問題となっている脆弱性は CVE-2026-55040 (CVSSスコア:9.1)で、認証の脆弱性に起因する重大なセキュリティ機能のバイパスに関するものです。この脆弱性は、マイクロソフトが2026年7月のパッチチューズデーアップデートの一環として修正しました。
マイクロソフトは先月、この脆弱性に関する勧告の中で、「この脆弱性によりなりすましが可能になるため、認証機能が回避される可能性がある」と述べた。「この脆弱性を悪用すると、攻撃者はファイルを漏洩させたりデータを改ざんしたりできる可能性があるが、システムの可用性に影響を与えることはできない」としている。 」
https://thehackernews.com/2026/08/attackers-exploit-sharepoint.html
##Attackers Exploit SharePoint Flaw After Public PoC Release
Microsoft warned that a critical SharePoint flaw, patched in July 2026, could allow attackers to bypass authentication and disclose files or modify data. This vulnerability, tracked as CVE-2026-55040, has now been exploited by attackers following the public release of a proof-of-concept exploit.
#Cve202655040 #SharepointFlaw #Microsoft #AuthenticationBypass #SupplyChain
##Microsoft SharePoint Under Attack: Critical CVE-2026-55040 Exploitation Surges After Public PoC Release + Video
A New SharePoint Warning Is Turning Into a Real-World Security Crisis Microsoft SharePoint administrators are facing another serious warning as attackers appear to be testing a critical authentication-bypass vulnerability that can allow unauthenticated users to impersonate legitimate SharePoint accounts. The situation became more urgent after security…
##Cybercriminals are exploiting SharePoint vulnerability CVE-2026-55040, allowing authentication bypass and unauthorized access. Organizations should apply patches immediately to mitigate this risk.
#CyberSecurity #SharePoint #CVE202655040 #AuthenticationBypass #DataBreach #Microsoft
https://thedailytechfeed.com/attackers-exploit-sharepoint-authentication-bypass-vulnerability/
##Rapid7 released a proof-of-concept for CVE-2026-55040, a critical SharePoint vulnerability, on August 12. Within hours, Defused observed the exploit weaponized against SharePoint honeypots. Microsoft patched the flaw in July, yet Shadowserver still reports over 8,500 exposed servers. Patching is no longer optional.
#SharePoint #CVE2026 #VulnerabilityManagement #PatchTuesday
https://cyberworldops.eu/en/sharepoint-proof-of-concept-for-critical-flaw-already-used-in-attacks
##Microsoft SharePoint Under Attack: Hackers Exploit CVE-2026-55040 Shortly After Rapid7 Releases a Proof of Concept + Video
A Dangerous Window Opens for SharePoint Administrators A new Microsoft SharePoint security incident is highlighting one of the most dangerous realities in modern cybersecurity: the moment a working proof of concept becomes public, attackers can move from research to exploitation with astonishing speed. On August 12, 2026, reports emerged that…
##Microsoft SharePoint Under Attack: Critical JWT Authentication Flaw Exploited After Rapid7 Releases Public PoC
A Dangerous SharePoint Vulnerability Has Crossed a Critical Line Microsoft SharePoint administrators are facing another serious cybersecurity warning after a critical authentication-bypass vulnerability moved rapidly from public disclosure to observed exploitation. The flaw, tracked as CVE-2026-55040, affects the way SharePoint validates JSON Web Tokens (JWTs)…
##Tracked as CVE-2026-55040, this authentication bypass security flaw in the JWT token validation pipeline can be exploited by attackers without privileges to perform operations as a SharePoint site user or administrator. https://www.bleepingcomputer.com/news/microsoft/hackers-leverage-new-microsoft-sharepoint-exploit-in-attacks/
##Hackers Exploit New Microsoft SharePoint Vulnerability in Attacks
Hackers are already exploiting a newly discovered critical flaw in Microsoft SharePoint, with over 8,500 servers exposed online and vulnerable to attacks. This authentication bypass vulnerability, known as CVE-2026-55040, allows hackers to disclose files, modify data, and wreak havoc on your system.
#MicrosoftSharepoint #Cve202655040 #AuthenticationBypass #VulnerabilityExploitation #EmergingThreats
##「公開された概念実証(PoC)リリース後、攻撃者がSharePointの認証バイパスを悪用 」: #TheHackerNews
「攻撃者は、概念実証(PoC)コードの公開を受けて、新たに明らかになったMicrosoft SharePointの脆弱性を悪用し始めている。
問題となっている脆弱性は CVE-2026-55040 (CVSSスコア:9.1)で、認証の脆弱性に起因する重大なセキュリティ機能のバイパスに関するものです。この脆弱性は、マイクロソフトが2026年7月のパッチチューズデーアップデートの一環として修正しました。
マイクロソフトは先月、この脆弱性に関する勧告の中で、「この脆弱性によりなりすましが可能になるため、認証機能が回避される可能性がある」と述べた。「この脆弱性を悪用すると、攻撃者はファイルを漏洩させたりデータを改ざんしたりできる可能性があるが、システムの可用性に影響を与えることはできない」としている。 」
https://thehackernews.com/2026/08/attackers-exploit-sharepoint.html
##Rapid7 released a proof-of-concept for CVE-2026-55040, a critical SharePoint vulnerability, on August 12. Within hours, Defused observed the exploit weaponized against SharePoint honeypots. Microsoft patched the flaw in July, yet Shadowserver still reports over 8,500 exposed servers. Patching is no longer optional.
#SharePoint #CVE2026 #VulnerabilityManagement #PatchTuesday
https://cyberworldops.eu/en/sharepoint-proof-of-concept-for-critical-flaw-already-used-in-attacks
##Tracked as CVE-2026-55040, this authentication bypass security flaw in the JWT token validation pipeline can be exploited by attackers without privileges to perform operations as a SharePoint site user or administrator. https://www.bleepingcomputer.com/news/microsoft/hackers-leverage-new-microsoft-sharepoint-exploit-in-attacks/
##Researchers disclosed a full unauthenticated RCE chain in Microsoft SharePoint, tracked as CVE-2026-55040 (CVSS 9.1). The flaw in the authentication pipeline allows an attacker to impersonate any user, including admins, using only the target's AD SID or UPN. No credentials required.
#SharePointRCE #UnauthenticatedExploit #CVE2026 #CriticalVulnerability
https://cyberworldops.eu/en/sharepoint-exploit-chain-enables-unauthenticated-rce
##Rapid7 published full details and a PoC for CVE-2026-55040, a critical SharePoint authentication bypass that forges JWT tokens. Patch now.
#CVE202655040 #SharePoint #AuthenticationBypass #JWT #Rapid7 #PoC #Cybersecurity
##「研究者らが、認証不要のリモートコード実行(RCE)を実現するAI支援型SharePointエクスプロイトチェーンを公開 」: #TheHackerNews
「セキュリティ研究者らは、有効なアカウントを持たずに、管理者を含むあらゆるユーザーとしてMicrosoft SharePointサーバーに侵入する方法を発見した。この発見に大きく貢献したのが、AIエージェントを用いた作業だった。
CVE-2026-55040 (CVSS 9.1)として追跡されているこの脆弱性は 、SharePoint Server Subscription Edition、SharePoint Server 2019、およびSharePoint Server 2016に影響します。マイクロソフトの影響を受ける製品リストには、これら3つのオンプレミス版のみが含まれており、SharePoint Onlineは含まれていません。
この攻撃手法は、認証されていないリモート攻撃者が、選択したユーザーの身元を偽装することを可能にします。 」
https://thehackernews.com/2026/08/researchers-disclose-ai-assisted.html
##New.
Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040) https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/ @Rapid7Official #Microsoft #infosec #threatresearch #SharePoint #vulnerability
##updated 2026-08-13T15:20:13.780000
2 posts
🟠 CVE-2026-73406 - High (7.5)
Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_ENDPOINTS in packages/worker/src/api/index.ts, and tenantUserLookup returned a full PlatformUser document. An unauthenticated cal...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73406/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73406 - High (7.5)
Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_ENDPOINTS in packages/worker/src/api/index.ts, and tenantUserLookup returned a full PlatformUser document. An unauthenticated cal...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73406/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T15:20:09.360000
1 posts
🟠 CVE-2026-73224 - High (8.8)
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to execute arbitrary commands when a user downloads a crafted folder and invokes Properties...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73224/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T15:20:01.813000
2 posts
「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews
「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース
最も深刻な欠陥は以下のとおりです。
CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)
」
https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html
##「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews
「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース
最も深刻な欠陥は以下のとおりです。
CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)
」
https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html
##updated 2026-08-13T15:19:54.267000
2 posts
CVE-2026-59507 (CRITICAL, CVSS 9.3) impacts Priority ERP Portal Generator addon: hard-coded creds, info exposure, improper access control. No patch yet — restrict access & monitor systems. https://radar.offseq.com/threat/cve-2026-59507-cwe-798-use-of-hard-coded-credentials-cwe-200-exposure-of-sensitive-information-to-an-30882f5adf8cd1ad #OffSeq #CVE #Infosec #ERP
##CVE-2026-59507 (CRITICAL, CVSS 9.3) impacts Priority ERP Portal Generator addon: hard-coded creds, info exposure, improper access control. No patch yet — restrict access & monitor systems. https://radar.offseq.com/threat/cve-2026-59507-cwe-798-use-of-hard-coded-credentials-cwe-200-exposure-of-sensitive-information-to-an-30882f5adf8cd1ad #OffSeq #CVE #Infosec #ERP
##updated 2026-08-13T15:19:54.160000
2 posts
CVE-2026-59506 (CRITICAL): Portal Generator addon to Priority ERP lacks authentication for a critical function. Unauthenticated remote attackers can access sensitive data. No patch yet — restrict access & monitor. More info: https://radar.offseq.com/threat/cve-2026-59506-cwe-306-missing-authentication-for-critical-function-in-priority-portal-generator-addon-10b51be16c861426 #OffSeq #CVE202659506 #ERP #Infosec
##CVE-2026-59506 (CRITICAL): Portal Generator addon to Priority ERP lacks authentication for a critical function. Unauthenticated remote attackers can access sensitive data. No patch yet — restrict access & monitor. More info: https://radar.offseq.com/threat/cve-2026-59506-cwe-306-missing-authentication-for-critical-function-in-priority-portal-generator-addon-10b51be16c861426 #OffSeq #CVE202659506 #ERP #Infosec
##updated 2026-08-13T15:19:38.027000
2 posts
🟠 CVE-2026-19311 - High (8.1)
Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19311/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19311 - High (8.1)
Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19311/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T15:19:28.560000
2 posts
🟠 CVE-2026-12263 - High (8.8)
Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12263/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-12263 - High (8.8)
Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12263/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T14:17:13.663000
2 posts
🟠 CVE-2026-73498 - High (7.7)
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplied file_path directly to open(file_path, "rb") in src/mcp_atlassian/confluen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73498/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73498 - High (7.7)
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplied file_path directly to open(file_path, "rb") in src/mcp_atlassian/confluen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73498/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T14:17:12.087000
4 posts
OpenStack Designate CRITICAL vuln (CVE-2026-71193, CVSS 9.6): Authenticated users can hijack or disrupt DNS cross-tenant by bypassing zone checks via AttributeFilter in multi-pool deployments. Disable AttributeFilter until patched. https://radar.offseq.com/threat/cve-2026-71193-cwe-863-incorrect-authorization-in-openstack-designate-01ef425c39443191 #OffSeq #OpenStack #DNS #Vuln
##🔴 CVE-2026-71193 - Critical (9.6)
In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different poo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71193/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##OpenStack Designate CRITICAL vuln (CVE-2026-71193, CVSS 9.6): Authenticated users can hijack or disrupt DNS cross-tenant by bypassing zone checks via AttributeFilter in multi-pool deployments. Disable AttributeFilter until patched. https://radar.offseq.com/threat/cve-2026-71193-cwe-863-incorrect-authorization-in-openstack-designate-01ef425c39443191 #OffSeq #OpenStack #DNS #Vuln
##🔴 CVE-2026-71193 - Critical (9.6)
In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different poo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71193/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T14:17:11.320000
2 posts
🔴 CVE-2026-66898 - Critical (9.9)
A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained w...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66898/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-66898 - Critical (9.9)
A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained w...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66898/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T14:17:01.890000
17 posts
VMware vCenter Under Attack: Critical CVE-2026-59310 Exploited in a Global Reverse-SSH Campaign + Video
Introduction: A Five-Day Warning That A critical vulnerability in VMware vCenter has rapidly turned from a security advisory into an active global intrusion campaign. CVE-2026-59310, a directory traversal flaw affecting the vCenter Server Syslog component, is now being exploited by attackers to gain access to vulnerable infrastructure and install a reverse-SSH tool…
##Critical VMware vCenter RCE flaw exploited for reverse SSH access
A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a...
🔗️ [Bleepingcomputer] https://link.is.it/3RirvF
##VMware vCenter flaw exploited for reverse SSH access globally
A critical VMware vCenter flaw, CVE-2026-59310, is being exploited globally, with 361 Internet-connected systems across 47 countries already compromised. This severe vulnerability allows unauthenticated attackers to execute arbitrary code, making swift action essential to prevent further breaches.
#Vmware #Cve202659310 #Vcenter #DirectoryTraversal #SupplyChain
##VMware vCenter Flaw Exploited Days After Disclosure
Within days of Broadcom's advisory, a critical VMware vCenter flaw, CVE-2026-59310, was exploited, putting 361 victim IP addresses across 47 countries at risk. This severe vulnerability allowed attackers to turn a logging service into a gateway to infiltrate operating systems worldwide.
#Cve202659310 #Vmware #Vcenter #DirectoryTraversal #SupplyChain
##📢 ⚠️ Researchers have linked 361 victim IPs in 47 countries to a suspected APT campaign exploiting a critical VMware vCenter flaw, CVE-2026-59310.
Listen/Read: https://hackread.com/apt-exploits-critical-vmware-vcenter-vulnerabilities/
##Attackers Exploit Critical VMware vCenter Flaws to Gain Persistent Remote Access
German cybersecurity firm QUIRSO reports active exploitation of VMware vCenter and ESXi, critical flaws (CVE-2026-59310 and CVE-2026-59309).
**If you run VMware vCenter, this is important. Make sure it is not reachable from the internet and can only be accessed from trusted internal networks. Then urgently apply the fixes from Broadcom advisory VMSA-2026-0006.1 (vCenter 9.1.0.0300, 9.0.2.0100, or 8.0 U3k / U2f), because the platform is being attacked and there is no workaround for the flaws. If your vCenter was exposed, check it for signs of compromise such as unexpected cron jobs, unknown SSH tools, or unusual outbound connections.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/attackers-exploit-critical-vmware-vcenter-flaws-to-gain-persistent-remote-access-4-o-b-8-9/gD2P6Ple2L
「攻撃者がVMware vCenterの脆弱性を悪用し、永続的なリモートアクセスを取得する 」: #TheHackerNews
「QUIRSOの 新たな調査結果 によると、攻撃者は、最近パッチが適用されたBroadcom VMware vCenterの重大なセキュリティ脆弱性を積極的に悪用し始めている。
問題となっている脆弱性は CVE-2026-59310 (CVSSスコア:9.8)で、VMware vCenterサーバーのディレクトリトラバーサル脆弱性であり、ネットワークアクセス権を持つ悪意のある攻撃者がこれを悪用して任意のコードを実行できる可能性がある。この脆弱性に対するパッチは、ブロードコム社が先月末にリリースした。
ドイツのサイバーセキュリティ企業は、インシデント対応活動中にこの活動を発見したと発表した。 」
https://thehackernews.com/2026/08/attackers-exploit-vmware-vcenter.html
##VMware vCenter Under Attack: CVE-2026-59310 Enables Persistent Access
https://cyberworldops.eu/en/vmware-vcenter-under-attack-cve-2026-59310-enables-persistent-access
##📰 VMware Patches Critical VM Escape Flaw (CVE-2026-47876) in ESXi
Broadcom patches critical VMware flaws, including a VM escape in ESXi (CVE-2026-47876) and unauthenticated RCE in vCenter (CVE-2026-59309, CVE-2026-59310). CVSS scores up to 9.8. Immediate patching is crucial. #VMware #CyberSecurity #PatchTuesday
##VMware vCenter Under Attack: Critical CVE-2026-59310 Exploited in a Rapid Global Intrusion Campaign + Video
A New Warning for Virtualization Administrators Virtualization infrastructure has quietly become one of the most valuable targets in modern cyberattacks. A compromised workstation can expose one user or one endpoint, but a compromised virtualization-management server can potentially open a path toward dozens, hundreds, or even thousands of workloads. That is why…
##The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. https://thehackernews.com/2026/08/attackers-exploit-vmware-vcenter.html
##Critical VMware vCenter RCE flaw exploited for reverse SSH access
A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a...
🔗️ [Bleepingcomputer] https://link.is.it/3RirvF
##📢 ⚠️ Researchers have linked 361 victim IPs in 47 countries to a suspected APT campaign exploiting a critical VMware vCenter flaw, CVE-2026-59310.
Listen/Read: https://hackread.com/apt-exploits-critical-vmware-vcenter-vulnerabilities/
##Attackers Exploit Critical VMware vCenter Flaws to Gain Persistent Remote Access
German cybersecurity firm QUIRSO reports active exploitation of VMware vCenter and ESXi, critical flaws (CVE-2026-59310 and CVE-2026-59309).
**If you run VMware vCenter, this is important. Make sure it is not reachable from the internet and can only be accessed from trusted internal networks. Then urgently apply the fixes from Broadcom advisory VMSA-2026-0006.1 (vCenter 9.1.0.0300, 9.0.2.0100, or 8.0 U3k / U2f), because the platform is being attacked and there is no workaround for the flaws. If your vCenter was exposed, check it for signs of compromise such as unexpected cron jobs, unknown SSH tools, or unusual outbound connections.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/attackers-exploit-critical-vmware-vcenter-flaws-to-gain-persistent-remote-access-4-o-b-8-9/gD2P6Ple2L
「攻撃者がVMware vCenterの脆弱性を悪用し、永続的なリモートアクセスを取得する 」: #TheHackerNews
「QUIRSOの 新たな調査結果 によると、攻撃者は、最近パッチが適用されたBroadcom VMware vCenterの重大なセキュリティ脆弱性を積極的に悪用し始めている。
問題となっている脆弱性は CVE-2026-59310 (CVSSスコア:9.8)で、VMware vCenterサーバーのディレクトリトラバーサル脆弱性であり、ネットワークアクセス権を持つ悪意のある攻撃者がこれを悪用して任意のコードを実行できる可能性がある。この脆弱性に対するパッチは、ブロードコム社が先月末にリリースした。
ドイツのサイバーセキュリティ企業は、インシデント対応活動中にこの活動を発見したと発表した。 」
https://thehackernews.com/2026/08/attackers-exploit-vmware-vcenter.html
##VMware vCenter Under Attack: CVE-2026-59310 Enables Persistent Access
https://cyberworldops.eu/en/vmware-vcenter-under-attack-cve-2026-59310-enables-persistent-access
##The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. https://thehackernews.com/2026/08/attackers-exploit-vmware-vcenter.html
##updated 2026-08-13T14:16:53.247000
2 posts
There are several updates from Broadcom addressing a long list of vulnerabilities, one of them critical https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Yesterday:
CISA:
CISA Unveils New Cybersecurity Resources for K-12 Schools and Districts https://www.cisa.gov/news-events/news/cisa-unveils-new-cybersecurity-resources-k-12-schools-and-districts #CISA
Palo Alto: CVE-2026-0301 PAN-OS: Information Disclosure Vulnerability in URL Filtering https://security.paloaltonetworks.com/CVE-2026-0301 #infosec #vulnerability
##There are several updates from Broadcom addressing a long list of vulnerabilities, one of them critical https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Yesterday:
CISA:
CISA Unveils New Cybersecurity Resources for K-12 Schools and Districts https://www.cisa.gov/news-events/news/cisa-unveils-new-cybersecurity-resources-k-12-schools-and-districts #CISA
Palo Alto: CVE-2026-0301 PAN-OS: Information Disclosure Vulnerability in URL Filtering https://security.paloaltonetworks.com/CVE-2026-0301 #infosec #vulnerability
##updated 2026-08-13T13:59:48.317000
1 posts
CVE-2026-61358 - Privilege escalation in Windows ATBroker.exe via link following. CVSS 7.8. Patch immediately. #CVE #Microsoft #infosec
##updated 2026-08-13T13:19:18.350000
2 posts
🔴 CVE-2026-73501 - Critical (9.1)
kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without checking c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73501/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-73501 - Critical (9.1)
kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without checking c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73501/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T13:19:17.513000
2 posts
🟠 CVE-2026-73418 - High (7.5)
NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the exported getToken() helper in the next-auth/jwt and @auth/core/jwt modules can throw an uncaught exception when it reads a mal...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73418/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73418 - High (7.5)
NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the exported getToken() helper in the next-auth/jwt and @auth/core/jwt modules can throw an uncaught exception when it reads a mal...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73418/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T12:31:13
2 posts
🟠 CVE-2026-59501 - High (8.2)
CWE-284: Improper Access Control
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59501/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-59501 - High (8.2)
CWE-284: Improper Access Control
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59501/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T12:31:12
2 posts
🔴 CVE-2026-59500 - Critical (10)
CWE-287: Improper Authentication
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59500/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-59500 - Critical (10)
CWE-287: Improper Authentication
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59500/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T09:31:16
1 posts
CVE-2026-11840 - Authenticated SQLi in Zohocorp ManageEngine Password Manager Pro & PAM360. CVSS 8.8. Unpatched. Update immediately. #CVE #Zoho #infosec
##updated 2026-08-13T06:17:37.780000
2 posts
CVE-2026-13610 | CRITICAL privilege flaw in KiviCare <4.5.2 lets unauthenticated attackers create privileged staff accounts, risking patient data exposure 🏥. Restrict registration endpoint & monitor user creation. https://radar.offseq.com/threat/cve-2026-13610-cwe-269-improper-privilege-management-in-kivicare-c9bee31557a60fdb #OffSeq #WordPress #Infosec #Healthcare
##CVE-2026-13610 | CRITICAL privilege flaw in KiviCare <4.5.2 lets unauthenticated attackers create privileged staff accounts, risking patient data exposure 🏥. Restrict registration endpoint & monitor user creation. https://radar.offseq.com/threat/cve-2026-13610-cwe-269-improper-privilege-management-in-kivicare-c9bee31557a60fdb #OffSeq #WordPress #Infosec #Healthcare
##updated 2026-08-13T05:17:23.773000
2 posts
🔴 CVE-2026-26035 - Critical (9.8)
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-26035/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-26035 - Critical (9.8)
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-26035/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T05:17:23.020000
1 posts
Google's new Chrome security update patches 5 high-severity use-after-free bugs, including CVE-2026-19556 and CVE-2026-19560. Update now.
#Chrome #Google #UseAfterFree #CVE #BrowserSecurity #PatchNow #Cybersecurity
##updated 2026-08-13T00:31:33
2 posts
🟠 CVE-2026-10534 - High (8.4)
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10534/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-10534 - High (8.4)
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10534/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T00:31:33
2 posts
🟠 CVE-2026-19003 - High (7.8)
A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds of an allocated buffer. The issue stems from an incorrect buffer capacity calculation in t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19003/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19003 - High (7.8)
A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds of an allocated buffer. The issue stems from an incorrect buffer capacity calculation in t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19003/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T00:31:28
4 posts
CVE-2026-73519: WolfStack <25.9.2 vulnerable to hard-coded secret in src/auth/mod.rs — remote attackers can bypass auth & run root commands in containers via the management port. Restrict access & monitor for X-WolfStack-Secret usage. https://radar.offseq.com/threat/cve-2026-73519-use-of-hard-coded-credentials-in-wolfsoftwaresystemsltd-wolfstack-ed98acc25b8c686b #OffSeq #CVE202673519
##🔴 CVE-2026-73519 - Critical (9.8)
WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this value in the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73519/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-73519: WolfStack <25.9.2 vulnerable to hard-coded secret in src/auth/mod.rs — remote attackers can bypass auth & run root commands in containers via the management port. Restrict access & monitor for X-WolfStack-Secret usage. https://radar.offseq.com/threat/cve-2026-73519-use-of-hard-coded-credentials-in-wolfsoftwaresystemsltd-wolfstack-ed98acc25b8c686b #OffSeq #CVE202673519
##🔴 CVE-2026-73519 - Critical (9.8)
WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this value in the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73519/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-13T00:31:26
4 posts
🔴 CVE-2026-71471 - Critical (9)
A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` field. This a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71471/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-71471 (CRITICAL): acm-search-v2-rhel9 lets hub admins with Search CR patch rights deploy arbitrary containers fleet-wide. RCE & data access at risk. Restrict Search CR patch access now. Full details: https://radar.offseq.com/threat/a-flaw-was-found-in-acm-search-v2-rhel9-cve-2026-71471-abe3108354cb7e94 #OffSeq #Kubernetes #RedHat #Infosec
##🔴 CVE-2026-71471 - Critical (9)
A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` field. This a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71471/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-71471 (CRITICAL): acm-search-v2-rhel9 lets hub admins with Search CR patch rights deploy arbitrary containers fleet-wide. RCE & data access at risk. Restrict Search CR patch access now. Full details: https://radar.offseq.com/threat/a-flaw-was-found-in-acm-search-v2-rhel9-cve-2026-71471-abe3108354cb7e94 #OffSeq #Kubernetes #RedHat #Infosec
##updated 2026-08-13T00:31:26
2 posts
🟠 CVE-2026-71473 - High (8.5)
A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerability that allows them to inject arbitrary configuration data. This manipulation can override critic...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71473/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-71473 - High (8.5)
A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerability that allows them to inject arbitrary configuration data. This manipulation can override critic...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71473/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-12T23:17:24.403000
2 posts
🟠 CVE-2026-73303 - High (8.2)
Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a client-controlled accountId without binding it to the authenticated session, while checking only currentEmail. An authenticated at...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73303/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73303 - High (8.2)
Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a client-controlled accountId without binding it to the authenticated session, while checking only currentEmail. An authenticated at...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73303/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-12T23:17:21.683000
1 posts
🟠 CVE-2026-55676 - High (8.8)
Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and stores them in a directory served by the same nginx and php-fpm instance. The allow-list that s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55676/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-12T22:17:16.273000
2 posts
🟠 CVE-2026-73433 - High (7.6)
A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length counter by fixed offsets (98 and 10 bytes) without verifying sufficient data r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73433/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73433 - High (7.6)
A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length counter by fixed offsets (98 and 10 bytes) without verifying sufficient data r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73433/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-12T22:17:15.760000
2 posts
🟠 CVE-2026-71469 - High (7.5)
A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent entry in the unbounded tokenReviews cache, which is not properly cleared. T...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71469/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-71469 - High (7.5)
A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent entry in the unbounded tokenReviews cache, which is not properly cleared. T...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71469/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-12T21:31:51
2 posts
🟠 CVE-2026-19002 - High (8.1)
A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the client application process. Triggering this issue requires control over the server the driv...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19002/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19002 - High (8.1)
A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the client application process. Triggering this issue requires control over the server the driv...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19002/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-12T21:31:51
2 posts
🔴 CVE-2026-19001 - Critical (9.8)
The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19001/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-19001 - Critical (9.8)
The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19001/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-12T21:31:50
2 posts
🟠 CVE-2026-73326 - High (7.6)
CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by reaching four unprotected plugin-administration endpoints without administrator-level authorizatio...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73326/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73326 - High (7.6)
CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by reaching four unprotected plugin-administration endpoints without administrator-level authorizatio...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73326/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-12T21:31:44
2 posts
also: those are some god damn useless CVEs, istg... https://db.gcve.eu/vuln/cve-2026-17083
##also: those are some god damn useless CVEs, istg... https://db.gcve.eu/vuln/cve-2026-17083
##updated 2026-08-12T21:31:43
2 posts
🟠 CVE-2026-73332 - High (8.7)
CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers to inject arbitrary HTML by submitting unsanitized content to the before_html field through the con...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73332/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73332 - High (8.7)
CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers to inject arbitrary HTML by submitting unsanitized content to the before_html field through the con...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73332/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-12T21:17:40.527000
2 posts
🟠 CVE-2026-73329 - High (8.7)
CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to execute arbitrary JavaScript in an administrator's browser by injecting unsanitized HTML payloads into the post title parameter duri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73329/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73329 - High (8.7)
CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to execute arbitrary JavaScript in an administrator's browser by injecting unsanitized HTML payloads into the post title parameter duri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73329/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-12T21:03:43.743000
11 posts
Adobe Commerce CVE-2026-71362 Exploited Almost Immediately, Turning a Critical 91 Flaw Into an Urgent Security Warning + Video
A Critical Vulnerability Moves From Disclosure to Exploitation Some cybersecurity vulnerabilities remain theoretical for months. Others become dangerous the moment the technical details become public. CVE-2026-71362 appears to belong to the second category. A critical Adobe Commerce vulnerability rated 9.1 has reportedly been exploited shortly…
##Critical Adobe Commerce Flaw CVE-2026-71362 Is Under Active Attack: Hackers Can Hijack Customer Accounts Without Logging In + Video
A Dangerous Warning for Every Magento Store Owner A critical vulnerability in Adobe Commerce and Magento Open Source has moved from disclosure to exploitation with alarming speed. CVE-2026-71362, carrying a CVSS score of 9.1, gives unauthenticated attackers a way to manipulate customer sessions, potentially hijack accounts and access…
##「ハッカーがAdobe Commerceの重大な脆弱性を悪用し、顧客アカウントを乗っ取る 」: #BLEEPINGCOMPUTER
「AdobeのeコマースプラットフォームであるCommerceとMagentoにおける重大な脆弱性(CVE-2026-71362)を悪用しようとする試みが検出されました。この脆弱性により、攻撃者が顧客アカウントを乗っ取る可能性があります。
この脆弱性は、認証なしに「機密性の高いリソースへの上位アクセス権を取得する」ために悪用される可能性のある、誤った認証の脆弱性と説明されており、Adobeが昨日のセキュリティアップデートで対処した7つの問題のうちの1つです。
ソフトウェアベンダーは 勧告 の中で、修正された脆弱性に対する実際の攻撃事例は把握していないと述べているが、eコマースセキュリティ企業のSansecは、同社のShieldウェブアプリケーションファイアウォール(WAF)が既にCVE-2026-71362の悪用を阻止していると述べている。 」
##「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews
「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース
最も深刻な欠陥は以下のとおりです。
CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)
」
https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html
##Active exploitation attempts targeting CVE-2026-71362 have been observed since August 12, 2026, affecting Adobe Commerce and Magento installations. The flaw is an authorization bypass that grants unauthenticated access to sensitive resources due to incorrect identity handling.
#CVE202671362 #AdobeCommerce #Magento #AuthorizationBypass
https://cyberworldops.eu/en/adobe-commerce-and-magento-under-attack-cve-2026-71362-exploited
##Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially...
🔗️ [Bleepingcomputer] https://link.is.it/JJqIH9
##Hackers Exploit Adobe Commerce Flaw to Hijack Customer Accounts
Hackers can hijack your customer accounts with just a few clicks, thanks to a critical flaw in Adobe Commerce that lets attackers switch to another customer's session, gaining access to sensitive data. This vulnerability, tracked as CVE-2026-71362, is a wake-up call for businesses to take immediate action and protect…
#AdobeCommerce #Cve202671362 #SessionHijacking #CustomerDataBreach #EcommerceSecurity
##「ハッカーがAdobe Commerceの重大な脆弱性を悪用し、顧客アカウントを乗っ取る 」: #BLEEPINGCOMPUTER
「AdobeのeコマースプラットフォームであるCommerceとMagentoにおける重大な脆弱性(CVE-2026-71362)を悪用しようとする試みが検出されました。この脆弱性により、攻撃者が顧客アカウントを乗っ取る可能性があります。
この脆弱性は、認証なしに「機密性の高いリソースへの上位アクセス権を取得する」ために悪用される可能性のある、誤った認証の脆弱性と説明されており、Adobeが昨日のセキュリティアップデートで対処した7つの問題のうちの1つです。
ソフトウェアベンダーは 勧告 の中で、修正された脆弱性に対する実際の攻撃事例は把握していないと述べているが、eコマースセキュリティ企業のSansecは、同社のShieldウェブアプリケーションファイアウォール(WAF)が既にCVE-2026-71362の悪用を阻止していると述べている。 」
##「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews
「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース
最も深刻な欠陥は以下のとおりです。
CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)
」
https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html
##Active exploitation attempts targeting CVE-2026-71362 have been observed since August 12, 2026, affecting Adobe Commerce and Magento installations. The flaw is an authorization bypass that grants unauthenticated access to sensitive resources due to incorrect identity handling.
#CVE202671362 #AdobeCommerce #Magento #AuthorizationBypass
https://cyberworldops.eu/en/adobe-commerce-and-magento-under-attack-cve-2026-71362-exploited
##Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially...
🔗️ [Bleepingcomputer] https://link.is.it/JJqIH9
##updated 2026-08-12T21:03:43.743000
1 posts
CVE-2026-48442 - Path traversal in CAI Content Credentials allows arbitrary file system read. CVSS 7.1. No user interaction needed. Patch status unknown. Update immediately. #CVE #infosec #CAI
##updated 2026-08-12T21:03:43.743000
2 posts
「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews
「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース
最も深刻な欠陥は以下のとおりです。
CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)
」
https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html
##「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews
「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース
最も深刻な欠陥は以下のとおりです。
CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)
」
https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html
##updated 2026-08-12T20:17:54.730000
2 posts
🟠 CVE-2026-73325 - High (7.8)
Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantized_model_pt() unc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73325/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73325 - High (7.8)
Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantized_model_pt() unc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73325/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-12T20:17:54.023000
2 posts
🔴 CVE-2026-73300 - Critical (9.6)
Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution of multiple SQL statements in a single query. Attackers can inject malicious...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73300/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-73300 - Critical (9.6)
Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution of multiple SQL statements in a single query. Attackers can inject malicious...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73300/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-12T20:17:51.543000
1 posts
CVE-2026-72798 - High severity info disclosure in SiYuan. Unpatched v3.7.4 lets anonymous readers access hidden database content via related-database bypass. CVSS 8.6. Update immediately. #CVE #SiYuan #infosec
##updated 2026-08-12T20:17:45.377000
1 posts
CVE-2026-58115 is a CVSS 10 flaw letting unauthenticated attackers run code on SIMATIC IoT2050 via Node-RED. Siemens urges an immediate update.
#CVE202658115 #Siemens #NodeRED #RCE #SIMATIC #ICS #Cybersecurity
##updated 2026-08-12T18:31:29
2 posts
🟠 CVE-2026-69106 - High (8.8)
A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69106/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-69106 - High (8.8)
A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69106/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-12T18:31:29
2 posts
🟠 CVE-2026-73327 - High (7.6)
Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing directory traversal sequences or absolute paths in ZIP entry filenames. Atta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73327/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73327 - High (7.6)
Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing directory traversal sequences or absolute paths in ZIP entry filenames. Atta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73327/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-12T18:31:15
1 posts
CVE-2026-18634 - High severity deserialization flaw in GMS 9.5.1 and earlier. Local attacker can trigger unauthorized actions via service. CVSS 8.4. Unpatched - update immediately. #CVE #cybersecurity #GMS
##updated 2026-08-12T17:17:31.853000
1 posts
🟠 CVE-2026-73122 - High (7.7)
A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically,...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73122/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-12T17:17:29.610000
2 posts
🟠 CVE-2026-65941 - High (8.8)
In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65941/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-65941 - High (8.8)
In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65941/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-12T17:17:27.983000
11 posts
3 repos
https://github.com/HORKimhab/CVE-2026-50656
https://github.com/g0thamRabb1t/CVE-2026-50656-rogueplanet-validation
📰 New 'ShieldBreak' Exploit Bypasses Microsoft Defender Patch
A new zero-day exploit, 'ShieldBreak,' bypasses Microsoft's patch for the 'RoguePlanet' Defender flaw (CVE-2026-50656). The PoC allows SYSTEM-level access on patched Windows systems. No fix is currently available. #ZeroDay #MicrosoftDefender #CyberSe...
##「Microsoftに恨みを持つハッカーが、完全にパッチが適用されたWindows上でシステム権限を取得できる新たなゼロデイ脆弱性を発見した。
/水曜日の裏技を使おうぜ、ベイビー 」: #TheRegister
「マイクロソフトに恨みを持つ、ゼロデイ攻撃を専門とするNightmare Eclipseは、マイクロソフトのRoguePlanetパッチ(CVE-2026-50656)を回避すると思われる、Defenderの新たなゼロデイ脆弱性「ShieldBreak」を公開した。これにより、攻撃者は完全にパッチが適用されたWindows 10、Windows 11、およびWindows Serverシステム上でSYSTEM権限を取得できる。
少なくとも他の研究者の一人によると、このエクスプロイトは有効だという。「試してみたところ、最新のWindows 11でも動作しました」と、元マイクロソフト社員でセキュリティ専門家のケビン・ボーモント氏 は述べている 。 」
##“Nightmare Eclipse, the serial zero-day hunter who has an axe to grind with Microsoft, published a new Defender zero-day, ShieldBreak, that apparently bypasses Redmond’s RoguePlanet patch (CVE-2026-50656), allowing attackers to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems.”
##A proof-of-concept for ShieldBreak has been disclosed, showing how to bypass the patch Microsoft issued for CVE-2026-50656 (RoguePlanet). The flaw targets SYSTEM-level privilege escalation on Windows systems protected by Microsoft Defender.
#ShieldBreak #CVE202650656 #PrivilegeEscalation #MicrosoftDefender
https://cyberworldops.eu/en/shieldbreak-poc-bypasses-microsoft-defender-patch-and-targets-system
##「Microsoftに恨みを持つハッカーが、完全にパッチが適用されたWindows上でシステム権限を取得できる新たなゼロデイ脆弱性を発見した。
/水曜日の裏技を使おうぜ、ベイビー 」: #TheRegister
「マイクロソフトに恨みを持つ、ゼロデイ攻撃を専門とするNightmare Eclipseは、マイクロソフトのRoguePlanetパッチ(CVE-2026-50656)を回避すると思われる、Defenderの新たなゼロデイ脆弱性「ShieldBreak」を公開した。これにより、攻撃者は完全にパッチが適用されたWindows 10、Windows 11、およびWindows Serverシステム上でSYSTEM権限を取得できる。
少なくとも他の研究者の一人によると、このエクスプロイトは有効だという。「試してみたところ、最新のWindows 11でも動作しました」と、元マイクロソフト社員でセキュリティ専門家のケビン・ボーモント氏 は述べている 。 」
##“Nightmare Eclipse, the serial zero-day hunter who has an axe to grind with Microsoft, published a new Defender zero-day, ShieldBreak, that apparently bypasses Redmond’s RoguePlanet patch (CVE-2026-50656), allowing attackers to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems.”
##A proof-of-concept for ShieldBreak has been disclosed, showing how to bypass the patch Microsoft issued for CVE-2026-50656 (RoguePlanet). The flaw targets SYSTEM-level privilege escalation on Windows systems protected by Microsoft Defender.
#ShieldBreak #CVE202650656 #PrivilegeEscalation #MicrosoftDefender
https://cyberworldops.eu/en/shieldbreak-poc-bypasses-microsoft-defender-patch-and-targets-system
##„Microsoft hat mit dem August 2026-Patchday zwar einige Sicherheitskorrekturen ausgeliefert. Aber die RoguePlanet genannte Schwachstelle (CVE-2026-50656) soll nicht ausreichend abgeschwächt worden sein. Der als Nightmare Eclipse agierende Sicherheitsforscher hat einen ShieldBreak genannten Proof of Concept (PoC) veröffentlicht.“
https://borncity.com/blog/2026/08/12/shieldbreak-poc-fuer-microsoft-defender-0-day-schwachstelle/
##A public PoC named ShieldBreak bypasses Microsoft's CVE-2026-50656 patch, enabling Windows Defender privilege escalation to SYSTEM.
#ShieldBreak #CVE202650656 #WindowsDefender #PrivilegeEscalation #PoC #RoguePlanet #Cybersecurity
https://securityonline.info/shieldbreak-defender-poc/?utm_source=mastodon&utm_medium=jetpack_social
##On another news NightmareEclipse (the goat?) returned with a new PoC, after Microsoft failed to fully patch RoguePlanet (CVE-2026-50656), the current PoC only made for latest Windows 11 release, but they said that Windows 10 also still vulnerable. And yeah, it works even after the latest update
https://github.com/MSNightmare/ShieldBreak
#cybersecurity #infosec #zeroday #vulnerability #windows #nightmareEclipse
##🚨Nightmare Eclipse has released a new zero-day PoC called ShieldBreak
Per the security researcher: "Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass."
##updated 2026-08-12T16:17:14.650000
3 posts
2 repos
https://github.com/DavidCarliez/CVE-2026-66804-CrossDevice-LPE
https://github.com/Rat5ak/CVE-2026-66804-CrossDevice-Service-EoP
CVE-2026-66804 - Windows Cross Device Service LPE - Writeup & PoC
Found another cool one!
https://www.nadsec.online/blog/cve-2026-66804-crossdevice-service-eop
Not sure who found it first, but shoutout to them. Despite not being FTF, my mom thinks this one is cool, which is the only important metric 😎
##@wdormann
CVE-2026-66804
Haha it’s a good one. And yeah not these days, I had thought I might have atleast been first to find but not quite 🤣
##@wdormann
CVE-2026-66804
Haha it’s a good one. And yeah not these days, I had thought I might have atleast been first to find but not quite 🤣
##updated 2026-08-12T15:31:45
1 posts
Google's new Chrome security update patches 5 high-severity use-after-free bugs, including CVE-2026-19556 and CVE-2026-19560. Update now.
#Chrome #Google #UseAfterFree #CVE #BrowserSecurity #PatchNow #Cybersecurity
##updated 2026-08-12T15:30:49
4 posts
1 repos
🟠 CVE-2026-57858 - High (8.9)
Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analytics tracki...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57858/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-57858: CRITICAL stored XSS in Cal.com Self-Hosted (v2.1.1 – 6.2.0). Exploited via BookingPageTagManager by authenticated event owners; affects all booking page visitors. Patch status unknown. Restrict privileges. https://radar.offseq.com/threat/cve-2026-57858-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-in-953e719dabfd2c11 #OffSeq #XSS #SecOps
##🟠 CVE-2026-57858 - High (8.9)
Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analytics tracki...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57858/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-57858: CRITICAL stored XSS in Cal.com Self-Hosted (v2.1.1 – 6.2.0). Exploited via BookingPageTagManager by authenticated event owners; affects all booking page visitors. Patch status unknown. Restrict privileges. https://radar.offseq.com/threat/cve-2026-57858-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-in-953e719dabfd2c11 #OffSeq #XSS #SecOps
##updated 2026-08-12T15:30:49
2 posts
🟠 CVE-2026-70468 - High (8.1)
A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiMan...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70468/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-70468 - High (8.1)
A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiMan...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70468/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-12T15:18:18.370000
1 posts
SonicWall patched a critical GMS vulnerability, CVE-2026-66147 (CVSS 9.4), enabling unauthenticated remote code execution. Update to 9.5.2 now.
##updated 2026-08-12T15:02:21.707000
13 posts
Cisco confirmed active exploitation of CVE-2026-20349, a high-severity flaw (CVSS 8.6) in ASA and FTD firewalls. Insufficient error handling in HTTP processing allows an unauthenticated remote attacker to trigger a device reboot via the Remote Access SSL VPN service, resulting in denial of service.
#CVE202620349 #CiscoASA #FirewallSecurity #DenialOfService
https://cyberworldops.eu/en/cisco-asa-and-ftd-actively-exploited-vulnerability-can-restart
##📰 Cisco Patches Firewall Zero-Day Exploited for DoS Attacks
Cisco patches an actively exploited zero-day (CVE-2026-20349) in ASA and FTD firewalls. The flaw allows a remote, unauthenticated attacker to cause a denial-of-service (DoS). Patch immediately to prevent network disruption. #Cisco #ZeroDay #CyberSecu...
##CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices. https://www.securityweek.com/cisco-patches-firewall-zero-day-exploited-for-dos-attacks/
##⚠️ New security advisory:
CVE-2026-20349 affects multiple systems.
• Impact: Significant security breach potential
• Risk: Unauthorized access or data exposure
• Mitigation: Apply patches within 24-48 hours
Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-20349-cisco-asa-ftd-vpn-dos-exploited-in-wild
by Yazoul AI
##Cisco confirmed active exploitation of CVE-2026-20349, a high-severity flaw (CVSS 8.6) in ASA and FTD firewalls. Insufficient error handling in HTTP processing allows an unauthenticated remote attacker to trigger a device reboot via the Remote Access SSL VPN service, resulting in denial of service.
#CVE202620349 #CiscoASA #FirewallSecurity #DenialOfService
https://cyberworldops.eu/en/cisco-asa-and-ftd-actively-exploited-vulnerability-can-restart
##CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices. https://www.securityweek.com/cisco-patches-firewall-zero-day-exploited-for-dos-attacks/
##🚨 THREAT ALERT: CISA adds CVE-2026-20349 (Cisco ASA/FTD Heap Inspection DoS) to the KEV catalog due to active exploitation. Unauthenticated remote actors can crash perimeter firewalls. Read our full TSUITE brief with SPL, KQL, AQL & Chronicle queries: https://thecybermind.co/jily
##「Ciscoは、ASAおよびFTD VPNの脆弱性が悪用され、デバイスがクラッシュする可能性があると警告している。 」: #BLEEPINGCOMPUTER
「シスコは、Secure Firewall ASAおよびThreat Defense(FTD)ソフトウェアに存在する深刻なサービス拒否攻撃の脆弱性が、影響を受けるデバイスをリモートからクラッシュさせる攻撃で積極的に悪用されていると警告している。
CVE-2026-20349として追跡されているこの脆弱性は、深刻度スコアが8.6であり、特定のリモートアクセスサービスが有効になっているCisco Secure Firewall Adaptive Security Appliance(ASA)またはSecure Firewall Threat Defense(FTD)ソフトウェアを実行しているデバイスに影響を与えます。
シスコは本日公開したセキュリティ勧告の中で、この脆弱性はHTTPリクエスト処理時のエラーチェックが不十分なことに起因すると述べた。 」
##Cisco confirms CVE-2026-20349, a Cisco ASA and FTD VPN vulnerability (CVSS 8.6), is exploited in the wild to crash firewalls. Patch now.
##🚨 [CISA-2026:0811] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-20349 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20349)
- Name: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
- Notes: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20349
⚠️ CVE-2026-68820 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-68820)
- Name: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows Ancillary Function Driver for WinSock
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68820 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-68820
⚠️ CVE-2026-72898 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- Name: Metabase SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Metabase
- Product: Metabase
- Notes: https://www.metabase.com/blog/security-update ; https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-72898
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260811 #cisa20260811 #cve_2026_20349 #cve_2026_68820 #cve_2026_72898 #cve202620349 #cve202668820 #cve202672898
##This is being actively exploited. CVE-2026-20349. Patch now. Like right now. #infosec #vpn #cisco #cve
https://www.bleepingcomputer.com/news/security/cisco-warns-of-asa-and-ftd-vpn-flaw-exploited-to-crash-devices/
CVE ID: CVE-2026-20349
Vendor: Cisco
Product: Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
Date Added: 2026-08-11
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-20349
Broadcom has several new advisories that include two critical vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
CISA:
Industrial vulnerability: Johnson Controls C-CURE 9000 and Victor application server (Update A) https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-01
Blog post: Cyber Storm X: 20 Years of Readiness, Resilience, and Real‑World Impact https://www.cisa.gov/news-events/news/cyber-storm-x-20-years-readiness-resilience-and-real-world-impact #CISA
Cisco:
High-severity: CVE-2026-20349: Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF @TalosSecurity #Cisco
Yesterday:
Tenable Research Advisories:
Medium-severity: CVE-2026-12879: Google Cloud Platform (GCP) Apigee Cross-Tenant Data Exfiltration via Confused Deputy https://www.tenable.com/security/research/tra-2026-53 #infosec #Google #vulnerability
##updated 2026-08-12T14:18:33.557000
2 posts
🔴 CVE-2026-67568 - Critical (9.1)
The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of health information.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67568/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-67568 (CRITICAL, CVSS 9.3) in Mira Firmware 1.7.1.47: Hard-coded credentials let remote attackers read/write sensitive health data. No patch yet — restrict network access & monitor logs. https://radar.offseq.com/threat/cve-2026-67568-cwe-798-use-of-hard-coded-credentials-in-quanovate-tech-inc-operating-as-mira-mira-care-535c1a595418b62d #OffSeq #CVE202667568 #infosec #medtech #vuln
##updated 2026-08-12T14:18:02.933000
2 posts
vulnerability-lookup 6.0 will be released this week with many (really, many!) new features.
One of the smaller, but important, additions is support for multiple SSVC views alongside CVSS. When SSVC information is available from an ADP (such as CISA) , or from additional sources such as GCVE, it is now displayed by default.
This allows users to more easily compare the different severity and prioritization assessments associated with a vulnerability.
The CIRCL vulnerability-lookup instance is running the pre-release of 6.0 -
https://vulnerability.circl.lu/vuln/cve-2026-59124
#cve #gcve #opensource #vulnerabilitylookup #opendata #vulnerabilitymanagement #cyberecurity #ssvc
##vulnerability-lookup 6.0 will be released this week with many (really, many!) new features.
One of the smaller, but important, additions is support for multiple SSVC views alongside CVSS. When SSVC information is available from an ADP (such as CISA) , or from additional sources such as GCVE, it is now displayed by default.
This allows users to more easily compare the different severity and prioritization assessments associated with a vulnerability.
The CIRCL vulnerability-lookup instance is running the pre-release of 6.0 -
https://vulnerability.circl.lu/vuln/cve-2026-59124
#cve #gcve #opensource #vulnerabilitylookup #opendata #vulnerabilitymanagement #cyberecurity #ssvc
##updated 2026-08-12T13:17:26.097000
1 posts
🟠 CVE-2026-73249 - High (7.5)
calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{library_id}/{book_id}/{fmt} in src/calibre/srv/books.py omits needs_db_write=True, causing Router.dispatch() to skip ctx.check_for_wr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73249/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-12T13:17:25.827000
2 posts
CVE-2026-72526 (CRITICAL, CVSS 9.9) in Red Hat Advanced Cluster Management for Kubernetes 2 lets low-priv hub users escalate to cluster-admin on managed clusters. No official fix. Restrict Application creation permissions now. https://radar.offseq.com/threat/cve-2026-72526-unintended-proxy-or-intermediary-confused-deputy-in-red-hat-red-hat-advanced-cluster-d135ff679a7da34d #OffSeq #RedHat #Kubernetes #CVE2026_72526
##🔴 CVE-2026-72526 - Critical (9.9)
A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to creat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72526/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-12T13:17:24.500000
1 posts
🟠 CVE-2026-6484 - High (8.2)
In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-6484/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-12T13:17:22.633000
1 posts
🟠 CVE-2026-48763 - High (8.2)
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-url` that accepts an attacker-controlled `filePath` and returns a presigned...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48763/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-12T13:17:22.180000
2 posts
🟠 CVE-2026-19594 - High (8.1)
Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path segments, a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19594/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19594 - High (8.1)
Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path segments, a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19594/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-12T13:17:18.880000
1 posts
#OT #Advisory VDE-2025-056
Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware
This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.
#CVE CVE-2025-41769, CVE-2025-41770, CVE-2025-41771
https://certvde.com/en/advisories/vde-2025-056/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-056.json
##updated 2026-08-12T09:31:30
2 posts
CRITICAL: CVE-2026-67282 in Joomla Fabrik (v1.0.0 – 4.6.7) allows unauthenticated RCE (CWE-94). No patch yet — disable or restrict Fabrik use and monitor for updates. https://radar.offseq.com/threat/cve-2026-67282-cwe-94-improper-control-of-generation-of-code-code-injection-in-fabrikarcom-fabrik-2c969cc032f2e578 #OffSeq #Joomla #Infosec #RCE #CVE202667282
##CRITICAL: CVE-2026-67282 in Joomla Fabrik (v1.0.0 – 4.6.7) allows unauthenticated RCE (CWE-94). No patch yet — disable or restrict Fabrik use and monitor for updates. https://radar.offseq.com/threat/cve-2026-67282-cwe-94-improper-control-of-generation-of-code-code-injection-in-fabrikarcom-fabrik-2c969cc032f2e578 #OffSeq #Joomla #Infosec #RCE #CVE202667282
##updated 2026-08-12T09:31:30
3 posts
🟠 CVE-2025-41770 - High (7.5)
An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-41770/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2025-41770 - High (7.5)
An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-41770/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
###OT #Advisory VDE-2025-056
Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware
This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.
#CVE CVE-2025-41769, CVE-2025-41770, CVE-2025-41771
https://certvde.com/en/advisories/vde-2025-056/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-056.json
##updated 2026-08-12T09:31:30
2 posts
🟠 CVE-2026-19426 - High (8.2)
POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directly access and operate the system.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19426/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19426 - High (8.2)
POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directly access and operate the system.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19426/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-12T09:31:29
7 posts
Phoenix Contact Patches Critical Buffer Overflow in PLCnext Firmware
Phoenix Contact addressed three vulnerabilities in PLCnext firmware, including a critical buffer overflow (CVE-2025-41769) that allows unauthenticated remote code execution. The update also fixes denial-of-service and SQL injection flaws affecting various industrial controllers.
**If you run Phoenix Contact PLCnext controllers, first make sure these devices are isolated from the internet and reachable only from trusted networks. Then update the firmware to version 2026.0.3 on every compatible device. For the obsolete EPC 1502 and EPC 1522, which will never be patched, take them off the network or replace them with supported hardware.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/phoenix-contact-patches-critical-buffer-overflow-in-plcnext-firmware-s-e-q-h-v/gD2P6Ple2L
BoF in a PROFINET service?! I'm shocked. Shocked! Well, not that shocked.
##🔴 CVE-2025-41769 - Critical (9.8)
The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-41769/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Phoenix Contact Patches Critical Buffer Overflow in PLCnext Firmware
Phoenix Contact addressed three vulnerabilities in PLCnext firmware, including a critical buffer overflow (CVE-2025-41769) that allows unauthenticated remote code execution. The update also fixes denial-of-service and SQL injection flaws affecting various industrial controllers.
**If you run Phoenix Contact PLCnext controllers, first make sure these devices are isolated from the internet and reachable only from trusted networks. Then update the firmware to version 2026.0.3 on every compatible device. For the obsolete EPC 1502 and EPC 1522, which will never be patched, take them off the network or replace them with supported hardware.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/phoenix-contact-patches-critical-buffer-overflow-in-plcnext-firmware-s-e-q-h-v/gD2P6Ple2L
BoF in a PROFINET service?! I'm shocked. Shocked! Well, not that shocked.
##🔴 CVE-2025-41769 - Critical (9.8)
The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-41769/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
###OT #Advisory VDE-2025-056
Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware
This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.
#CVE CVE-2025-41769, CVE-2025-41770, CVE-2025-41771
https://certvde.com/en/advisories/vde-2025-056/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-056.json
##updated 2026-08-12T06:31:00
3 posts
🔴 CVE-2026-66659 - Critical (9.3)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Injection.
This issue affects Tablesome Table: from n/a through 1.2.9.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66659/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-66659 - Critical (9.3)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Injection.
This issue affects Tablesome Table: from n/a through 1.2.9.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66659/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-66659: CRITICAL SQL Injection (CVSS 9.3) in Essekia Tablesome Table ≤1.2.9. Allows unauth’d blind SQLi & data disclosure. No patch yet — monitor vendor updates. https://radar.offseq.com/threat/cve-2026-66659-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-04cbf964b30f2d13 #OffSeq #SQLInjection #Vuln #Infosec
##updated 2026-08-12T05:17:56.963000
4 posts
The vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It has been described as a case of insufficient authorization checks and input validation. https://thehackernews.com/2026/08/sap-commerce-cloud-flaw-could-let.html
##SAP Issues Emergency-Grade Patch for CVSS 100 Commerce Cloud Flaw That Could Enable Unauthenticated Code Execution + Video
A Critical Warning for SAP Enterprise Customers A maximum-severity vulnerability in SAP Commerce Cloud has put enterprise e-commerce environments under renewed security pressure. The newly identified flaw, tracked as CVE-2026-58231, carries the highest possible CVSS score of 10.0 and could allow an unauthenticated attacker to execute arbitrary code…
##The vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It has been described as a case of insufficient authorization checks and input validation. https://thehackernews.com/2026/08/sap-commerce-cloud-flaw-could-let.html
##SAP August 2026 Patch Day Fixes Critical Code Injection and Memory Corruption Flaws
SAP's August 2026 Security Patch Day addresses 31 vulnerabilities, including a critical CVSS 10.0 authentication bypass in Commerce Cloud and code injection flaws in Manufacturing Integration and Intelligence. These vulnerabilities allow remote attackers to execute arbitrary commands and gain unauthorized access to internal enterprise systems.
**If you run SAP products, especially Manufacturing Integration and Intelligence (MII) read the advisory in detail. First make sure these systems are isolated from the internet where possible and reachable only from trusted internal networks. Then apply SAP's August 2026 security notes ASAP starting with the critical fixes for Commerce Cloud (CVE-2026-58231) and MII (CVE-2026-44772, CVE-2026-44758), followed by the ABAP Platform patch (CVE-2026-34265).**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/sap-august-2026-patch-day-fixes-critical-code-injection-and-memory-corruption-flaws-p-s-x-p-k/gD2P6Ple2L
updated 2026-08-12T05:17:42.950000
2 posts
Tracked as CVE-2026-18129, the first is described as a cleartext transmission of sensitive information issue that can be exploited by an attacker in a man-in-the-middle (MitM) position to leak credentials for external SQL connections. https://www.securityweek.com/ivanti-epm-update-patches-remotely-exploitable-flaws/
##Tracked as CVE-2026-18129, the first is described as a cleartext transmission of sensitive information issue that can be exploited by an attacker in a man-in-the-middle (MitM) position to leak credentials for external SQL connections. https://www.securityweek.com/ivanti-epm-update-patches-remotely-exploitable-flaws/
##updated 2026-08-12T03:31:28
1 posts
🟠 CVE-2026-18961 - High (8.1)
The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the pl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18961/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-12T03:31:17
2 posts
🟠 CVE-2026-66878 - High (7.7)
A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel.Spec.SecretRef.Nam...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66878/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-66878 - High (7.7)
A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel.Spec.SecretRef.Nam...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66878/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-12T03:31:17
2 posts
🔴 CVE-2026-70398 - Critical (9.6)
A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a te...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70398/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CRITICAL CVE-2026-70398 in Red Hat Advanced Cluster Management for Kubernetes 2: Authenticated tenants can redirect bearer tokens via GitOpsCluster controller. No official fix. Restrict privileges & monitor activity. https://radar.offseq.com/threat/cve-2026-70398-unintended-proxy-or-intermediary-confused-deputy-in-red-hat-red-hat-advanced-cluster-3d1f26674efa89dc #OffSeq #Kubernetes #RedHat #CVE202670398
##updated 2026-08-12T00:31:23
2 posts
Mira Firmware v1.7.1.47 has a CRITICAL auth bug (CVE-2026-68067): login accepts any valid-format password, exposing hormone records. No patch yet; restrict access & monitor accounts. https://radar.offseq.com/threat/cve-2026-68067-cwe-1390-weak-authentication-in-quanovate-tech-inc-operating-as-mira-mira-care-mira-85cdd6a62acb5a46 #OffSeq #Vulnerability #IoTSecurity #CVE202668067
##🔴 CVE-2026-68067 - Critical (9.8)
The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud acc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68067/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-12T00:31:23
1 posts
🟠 CVE-2026-66875 - High (8.8)
In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measur...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66875/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-11T21:33:18
2 posts
Broadcom has a new advisory for five vulnerabilities, two of them critical https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Posted yesterday:
Tenable Research advisories: CVE-2026-19579: Snipe-IT Checkout Request Cancellation IDOR https://www.tenable.com/security/research/tra-2026-54 @tenable $infosec #vulnerability
##Broadcom has a new advisory for five vulnerabilities, two of them critical https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Posted yesterday:
Tenable Research advisories: CVE-2026-19579: Snipe-IT Checkout Request Cancellation IDOR https://www.tenable.com/security/research/tra-2026-54 @tenable $infosec #vulnerability
##updated 2026-08-11T21:33:18
2 posts
OpenSSHの脆弱性(Medium: CVE-2026-73282, Low: CVE-2026-73281, CVE-2026-73283)とOpenSSH 10.5リリース - SIOS SECURITY BLOG https://security.sios.jp/vulnerability/openssh-security-vulnerability-20260812/
##OpenSSHの脆弱性(Medium: CVE-2026-73282, Low: CVE-2026-73281, CVE-2026-73283)とOpenSSH 10.5リリース - SIOS SECURITY BLOG https://security.sios.jp/vulnerability/openssh-security-vulnerability-20260812/
##updated 2026-08-11T21:33:18
2 posts
OpenSSHの脆弱性(Medium: CVE-2026-73282, Low: CVE-2026-73281, CVE-2026-73283)とOpenSSH 10.5リリース - SIOS SECURITY BLOG https://security.sios.jp/vulnerability/openssh-security-vulnerability-20260812/
##OpenSSHの脆弱性(Medium: CVE-2026-73282, Low: CVE-2026-73281, CVE-2026-73283)とOpenSSH 10.5リリース - SIOS SECURITY BLOG https://security.sios.jp/vulnerability/openssh-security-vulnerability-20260812/
##updated 2026-08-11T21:33:12
1 posts
A BSON symbol namespace bypasses MongoDB's authorization check (CVE-2026-18690)
MongoDB Server의 CVE-2026-18690은 BSON Symbol 타입으로 컬렉션 이름을 전달할 때, 인가 단계는 데이터베이스 수준 권한을 검사하지만 실행 단계는 실제 system.* 컬렉션을 대상으로 처리하는 권한 우회 취약점이다. 제한된 database-scoped 역할을 가진 인증된 사용자가 보호된 시스템 컬렉션에 대해 파괴적 작업을 시도할 수 있으며, MongoDB 7.0.40·8.0.29·8.3.8에서 수정됐다. 같은 패치 묶음에는 복제본 세트 내부 인증 메커니즘 다운그레이드로 내부...
https://hellorecon.com/blog/cve-2026-18690-mongodb-symbol-type-authz-bypass
##updated 2026-08-11T21:33:11
2 posts
OpenSSHの脆弱性(Medium: CVE-2026-73282, Low: CVE-2026-73281, CVE-2026-73283)とOpenSSH 10.5リリース - SIOS SECURITY BLOG https://security.sios.jp/vulnerability/openssh-security-vulnerability-20260812/
##OpenSSHの脆弱性(Medium: CVE-2026-73282, Low: CVE-2026-73281, CVE-2026-73283)とOpenSSH 10.5リリース - SIOS SECURITY BLOG https://security.sios.jp/vulnerability/openssh-security-vulnerability-20260812/
##updated 2026-08-11T21:33:01
33 posts
1 repos
🔵 THREAT INTELLIGENCE
Lazarus hackers exploited Windows zero-day to target defense firms
Vulnerability | CRITICAL
CVEs: CVE-2026-68820
North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the...
Full analysis:
https://www.yazoul.net/news/article/lazarus-hackers-exploited-windows-zero-day-to-target-defense-firms
by Yazoul AI
##📢 Lazarus Group exploite un zero-day Windows (CVE-2026-68820) via de fausses offres d'emploi
Cet article documente une nouvelle vague de la campagne Operation Dream Job, attribuée au groupe nord-coréen Lazarus, ciblant les secteurs de la défense, de l'aérospatiale et de l'aviation en Europe, Asie et Amérique du Sud.
📖 cyberveille : https://cyberveille.ch/posts/2026-08-13-lazarus-group-exploite-un-zero-day-windows-cve-2026-68820-via-de-fausses-offres-d-emploi/
🌐 source : https://blog.checkpoint.com/research/state-sponsored-hackers-use-fake-job-offers-to-deliver-new-zero-day-exploit/
🟢 vérification factuelle haute
#LazarusGroup #ZeroDay #Cyberveille
(CISA TS-SOC) CVE-2026-68820 – Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
Severity: HIGH Impact Summary: Allows an authorized attacker to elevate privileges locally via a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock....
##Microsoft’s Record Patch Tuesday Exposes a New Cybersecurity Reality as AI Finds More Flaws + Video
A Patch Tuesday That Signals a Bigger Change Microsoft’s latest Patch Tuesday has delivered an extraordinary number of security fixes, with 419 vulnerabilities addressed in a single release, including three zero-day flaws. One vulnerability, CVE-2026-68820, was reportedly exploited in the wild and has been linked to activity associated with the Lazarus Group. The scale…
##Lazarus hackers exploited Windows zero-day to target defense firms
북한 연계 Lazarus 그룹이 Windows AFD.sys의 use-after-free 권한 상승 제로데이(CVE-2026-68820)를 악용해 방산·항공우주 기업을 표적화했다. 취약점은 로컬 인증 사용자가 조작된 프로그램으로 레이스 컨디션을 유발해 SYSTEM 권한을 얻을 수 있으며, Microsoft는 8월 Patch Tuesday에서 이를 이미 실제 공격에 악용된 취약점으로 분류해 수정했다. 공격자는 FudModule 커널 루트킷으로 EDR 텔레메트리...
##Lazarus Group is exploiting a Windows zero-day (CVE-2026-68820) to escalate to SYSTEM privileges and deploy backdoors. Targets include defense and aerospace firms in France, Germany, Brazil, and India, lured through fake LinkedIn job offers under Operation Dream Job.
#LazarusGroup #ZeroDayExploit #WindowsSecurity #OperationDreamJob
https://cyberworldops.eu/en/lazarus-exploits-a-windows-zero-day-to-gain-system-privileges
##Lazarus Exploits Windows Zero-Day in Targeted Defense Sector Attacks
The notorious Lazarus threat group has been exploiting a newly patched Windows zero-day vulnerability, CVE-2026-68820, to gain SYSTEM privileges and escalate their attacks on high-value targets in the defense sector. This alarming exploit has been active since early July, making it crucial for organizations to stay vigilant.
#Lazarus #WindowsZeroDay #Cve202668820 #ZeroDay #SupplyChainAttacks
##Lazarus hackers exploited Windows zero-day to target defense firms
North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the...
🔗️ [Bleepingcomputer] https://link.is.it/NpjibN
##🟠 New security advisory:
CVE-2026-68820 affects multiple systems.
• Impact: Significant security breach potential
• Risk: Unauthorized access or data exposure
• Mitigation: Apply patches within 24-48 hours
Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-68820-windows-afd-privilege-escalation-exploited
by Yazoul AI
##Microsoft lança atualização de emergência para corrigir a CVE-2026-68820, uma falha de gravidade elevada no controlador Ancillary Function para WinSock. A vulnerabilidade, que afeta diversas versões do Windows, já está a ser explorada em ataques reais. 🚨
##📰 Lazarus Group Exploits Windows Zero-Day in Espionage Campaign
Microsoft patches actively exploited Windows zero-day (CVE-2026-68820) used by Lazarus Group. The bug allows SYSTEM-level access and was used in the 'Operation Dream Job' campaign to deploy rootkits against the defense sector. #CVE202668820 #Lazarus ...
##⚠️ CRITICAL: August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day
Microsoft patched CVE-2026-68820, a zero-day use-after-free in afd.sys kernel driver actively exploited for SYSTEM privilege escalation. This is the fourth afd.sys zero-day since 2022, with historical links to nation-state actors. All Windows systems running unpatched afd.sys are at immediate risk…
🤖 AI generated summary
##Microsoft's newest patch cycle closes nearly 400 security holes, among them CVE-2026-62832, CVE-2026-68820, and CVE-2026-72971. That volume makes triage the hard part, so plan which systems get updated first and confirm the rollout...
##🏆 New Achievement! CVE-2026-68820: The Lazarus Rises (Again)!
PHASE ONE BEGINS. Emerging from the shadows of Pyongyang's finest state-sponsored hacking collective, Lazarus has arrived — and they brought a use-after-free bug in afd.sys, the Windows kernel-mode driver, as their opening act. CVE-2026-68820 lets a low-privilege, locally authenticated attacker trigger a race condition, escalate straight to SYSTEM, and basically own the stage. (1/3)
##CVE-2026-68820: CRITICAL Windows afd.sys zero-day exploited by Lazarus Group for SYSTEM access in defense/aerospace. Patch released 2026-08-11. Prioritize updates & check for ForestTiger/Troy backdoors. https://radar.offseq.com/threat/fresh-windows-zero-day-exploited-in-north-korean-cyberattacks-bbf9980a8328f4c4 #OffSeq #ZeroDay #Windows #Cybersecurity
##Check Point researchers look into the latest variant of the Operation Dream Job campaign where the threat actor exploited CVE-2026-68820, a zero-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of Lazarus’s kernel-mode rootkit FudModule. https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
##🚨 THREAT ALERT: CISA adds CVE-2026-68820 (Windows WinSock AFD Use-After-Free) to the KEV catalog due to active exploitation. Local attackers can elevate privileges to system level. Access our TSUITE brief with CrowdStrike CQL telemetry queries: https://thecybermind.co/jily
##(CISA TS-SOC) CVE-2026-68820 – Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
Severity: HIGH Impact Summary: Allows an authorized attacker to elevate privileges locally via a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock....
##Lazarus Group is exploiting a Windows zero-day (CVE-2026-68820) to escalate to SYSTEM privileges and deploy backdoors. Targets include defense and aerospace firms in France, Germany, Brazil, and India, lured through fake LinkedIn job offers under Operation Dream Job.
#LazarusGroup #ZeroDayExploit #WindowsSecurity #OperationDreamJob
https://cyberworldops.eu/en/lazarus-exploits-a-windows-zero-day-to-gain-system-privileges
##Lazarus hackers exploited Windows zero-day to target defense firms
North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the...
🔗️ [Bleepingcomputer] https://link.is.it/NpjibN
##Microsoft lança atualização de emergência para corrigir a CVE-2026-68820, uma falha de gravidade elevada no controlador Ancillary Function para WinSock. A vulnerabilidade, que afeta diversas versões do Windows, já está a ser explorada em ataques reais. 🚨
##⚠️ CRITICAL: August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day
Microsoft patched CVE-2026-68820, a zero-day use-after-free in afd.sys kernel driver actively exploited for SYSTEM privilege escalation. This is the fourth afd.sys zero-day since 2022, with historical links to nation-state actors. All Windows systems running unpatched afd.sys are at immediate risk…
🤖 AI generated summary
##🏆 New Achievement! CVE-2026-68820: The Lazarus Rises (Again)!
PHASE ONE BEGINS. Emerging from the shadows of Pyongyang's finest state-sponsored hacking collective, Lazarus has arrived — and they brought a use-after-free bug in afd.sys, the Windows kernel-mode driver, as their opening act. CVE-2026-68820 lets a low-privilege, locally authenticated attacker trigger a race condition, escalate straight to SYSTEM, and basically own the stage. (1/3)
##CVE-2026-68820: CRITICAL Windows afd.sys zero-day exploited by Lazarus Group for SYSTEM access in defense/aerospace. Patch released 2026-08-11. Prioritize updates & check for ForestTiger/Troy backdoors. https://radar.offseq.com/threat/fresh-windows-zero-day-exploited-in-north-korean-cyberattacks-bbf9980a8328f4c4 #OffSeq #ZeroDay #Windows #Cybersecurity
##Check Point researchers look into the latest variant of the Operation Dream Job campaign where the threat actor exploited CVE-2026-68820, a zero-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of Lazarus’s kernel-mode rootkit FudModule. https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
##🚨 THREAT ALERT: CISA adds CVE-2026-68820 (Windows WinSock AFD Use-After-Free) to the KEV catalog due to active exploitation. Local attackers can elevate privileges to system level. Access our TSUITE brief with CrowdStrike CQL telemetry queries: https://thecybermind.co/jily
##「Microsoft 製品の脆弱性対策について(2026年8月)」: #IPA
「 2026年8月12日(日本時間)に Microsoft 製品に関するセキュリティ更新プログラム(月例)が公表されています。
これらの脆弱性を悪用された場合、アプリケーションプログラムが異常終了する、攻撃者によってパソコンを制御される、といった様々な被害が発生するおそれがあります。
この内 CVE-2026-68820 の脆弱性について、Microsoft 社では悪用の事実を確認済みと公表しており、今後被害が拡大するおそれがあるため、至急、セキュリティ更新プログラムを適用してください。 」
https://www.ipa.go.jp/security/security-alert/2026/0812-ms.html
##「マイクロソフトは、現在攻撃を受けているWindowsドライバーのゼロデイ脆弱性を含む398件の脆弱性を修正した。 」: #TheHackerNews
「マイクロソフトは火曜日に月例のセキュリティアップデートを公開したが、修正された脆弱性の1つが既に攻撃に悪用されている。
このバグは、ネットワークソケット操作を処理するWindowsカーネルの中核ドライバに存在します。既にマシン上でコードを実行している攻撃者は、このバグを利用してSYSTEM権限に昇格できます。このパッチが最初にリリースされます。
この脆弱性は CVE-2026-68820 (CVSSスコア:7.0)として追跡されており、今月のリリースでマイクロソフトが現在悪用されていると警告している唯一の脆弱性です。悪用は、ドライバーの競合状態をトリガーすることによって行われます。マイクロソフトは、この悪用を行った組織を公表していません。」
https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html
##Lazarus exploited a Windows zero-day (CVE-2026-68820) in Operation Dream Job to hit defense firms with fake job offers and a new backdoor.
#Lazarus #ZeroDay #CVE202668820 #OperationDreamJob #Cybersecurity #DPRK #FudModule #DefenseSector
##Microsoft August 2026 Patch Tuesday fixes 421 flaws, including CVE-2026-68820, a WinSock zero-day exploited in the wild, plus two disclosed bugs.
#PatchTuesday #Microsoft #ZeroDay #CVE #WindowsSecurity #InfoSec
##🚨 [CISA-2026:0811] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-20349 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20349)
- Name: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
- Notes: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20349
⚠️ CVE-2026-68820 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-68820)
- Name: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows Ancillary Function Driver for WinSock
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68820 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-68820
⚠️ CVE-2026-72898 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- Name: Metabase SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Metabase
- Product: Metabase
- Notes: https://www.metabase.com/blog/security-update ; https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-72898
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260811 #cisa20260811 #cve_2026_20349 #cve_2026_68820 #cve_2026_72898 #cve202620349 #cve202668820 #cve202672898
##Microsoft Patch Tuesday August 2026 patches 421 CVEs including CVE-2026-68820, an actively exploited use-after-free in the kernel driver afd.sys that grants SYSTEM-level privileges. Attacks are ongoing and no operational details have been disclosed yet. Prioritize patching on exposed systems.
#PatchTuesday #ZeroDay #VulnerabilityManagement #Microsoft
https://cyberworldops.eu/en/microsoft-fixes-421-vulnerabilities-including-an-exploited-zero-day-in
##CVE ID: CVE-2026-68820
Vendor: Microsoft
Product: Windows Ancillary Function Driver for WinSock
Date Added: 2026-08-11
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-68820
updated 2026-08-11T21:17:31.273000
1 posts
CVE-2026-18687 - High severity DoS in MongoDB Queryable Encryption. Flawed validation lets authenticated users crash servers or corrupt encrypted indexes via crafted requests. CVSS 7.1. Unpatched—restrict access and monitor. #CVE #MongoDB #infosec
##updated 2026-08-11T20:18:48.007000
1 posts
🟠 CVE-2026-73226 - High (8.8)
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm allows an authenticated WebSocket client to invoke unintended internal functions through client-controlled func values in upgrade...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73226/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-11T20:18:47.903000
2 posts
CVE-2026-73225 - Path traversal in electerm FTP/SFTP client. Malicious server writes files outside download dir. CVSS 8.1. Update to 3.15.120 now. #CVE #infosec #electerm
##🟠 CVE-2026-73225 - High (8.1)
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to write attacker-controlled content outside the selected download directory because recurs...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73225/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-11T18:54:19.877000
1 posts
📢 Cisco alerte sur 7 vulnérabilités ClamAV avec PoC public affectant Secure Endpoint
Cet article rapporte une alerte de sécurité émise par Cisco concernant sept vulnérabilités dans ClamAV affectant ses produits Secure Endpoint Connector sur Windows, macOS et Linux. Les failles sont référencées sous les identifiants CVE-2026-20337 à CVE-2026-20339 et…
📖 cyberveille : https://cyberveille.ch/posts/2026-08-13-cisco-alerte-sur-7-vulnerabilites-clamav-avec-poc-public-affectant-secure-endpoint/
🌐 source : https://www.securityweek.com/cisco-warns-of-high-severity-clamav-vulnerabilities-with-public-poc/amp/
🟢 vérification factuelle haute
#ClamAV #PoCPublic #Cyberveille
updated 2026-08-11T18:54:19.877000
1 posts
「Cisco社、ClamAVの深刻な脆弱性と公開されているエクスプロイトについて警告 」: #BLEEPINGCOMPUTER
「Ciscoは、Secure Endpoint Connectorに影響を与える2つの深刻な脆弱性について警告を発した。これらの脆弱性により、攻撃者はサービス拒否(DoS)攻撃においてClamAVのスキャンプロセスをクラッシュさせることができる。
これらのセキュリティ上の欠陥( CVE-2026-20337 および CVE-2026-20338 として追跡)は、マルウェアのファイルスキャンに使用されるオープンソースかつクロスプラットフォームのエンジンであるClamAV(Clam AntiVirus)のZIPアーカイブパーサーで発見されました。
シスコが金曜日に発表した勧告によると、これら2つの脆弱性はそれぞれ不適切な境界チェックとメモリ処理に起因するものであり、認証されていないリモート攻撃者によって悪用される可能性がある。 」
##updated 2026-08-11T18:53:58
1 posts
Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
Tag
CVE ID
CVE Title
Severity
.NET
CVE-2026-58641
.NET Elevation of Privilege Vulnerability
Important
.NET
CVE-2026-62901
.NET Denial…
#NewsBeep #News #US #USA #UnitedStates #UnitedStatesOfAmerica #Technology
https://www.newsbeep.com/us/810540/
updated 2026-08-11T18:32:00
2 posts
「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews
「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース
最も深刻な欠陥は以下のとおりです。
CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)
」
https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html
##「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews
「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース
最も深刻な欠陥は以下のとおりです。
CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)
」
https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html
##updated 2026-08-11T18:32:00
1 posts
Microsoft's newest patch cycle closes nearly 400 security holes, among them CVE-2026-62832, CVE-2026-68820, and CVE-2026-72971. That volume makes triage the hard part, so plan which systems get updated first and confirm the rollout...
##updated 2026-08-11T18:31:59
2 posts
「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews
「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース
最も深刻な欠陥は以下のとおりです。
CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)
」
https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html
##「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews
「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース
最も深刻な欠陥は以下のとおりです。
CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)
」
https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html
##updated 2026-08-11T18:31:49
1 posts
CVE-2026-66807 - High severity stack buffer overflow in Microsoft Office. Local code execution risk. CVSS 7.8. Patch reported—update immediately. #CVE #Microsoft #infosec
##updated 2026-08-11T18:31:33
3 posts
Microsoft patched the zero-day LegacyHive (CVE-2026-62832) in the August 2026 Patch Tuesday cycle, after it remained unpatched following July's updates. Researcher Nightmare Eclipse released a PoC exploit shortly after the July patches, sparking controversy over Microsoft's bug bounty and disclosure practices.
#ZeroDay #LegacyHive #PatchTuesday #CVE2026
https://cyberworldops.eu/en/microsoft-fixes-legacyhive-windows-zero-day-with-august-patches
##Microsoft's newest patch cycle closes nearly 400 security holes, among them CVE-2026-62832, CVE-2026-68820, and CVE-2026-72971. That volume makes triage the hard part, so plan which systems get updated first and confirm the rollout...
##Microsoft patched the zero-day LegacyHive (CVE-2026-62832) in the August 2026 Patch Tuesday cycle, after it remained unpatched following July's updates. Researcher Nightmare Eclipse released a PoC exploit shortly after the July patches, sparking controversy over Microsoft's bug bounty and disclosure practices.
#ZeroDay #LegacyHive #PatchTuesday #CVE2026
https://cyberworldops.eu/en/microsoft-fixes-legacyhive-windows-zero-day-with-august-patches
##updated 2026-08-11T18:31:25
1 posts
CVE-2026-62747 - Heap buffer overflow in Windows Device Association Service. Local privilege escalation. CVSS 7.8. Patch reported—update immediately. #CVE #Microsoft #infosec
##updated 2026-08-11T18:31:13
1 posts
CVE-2026-61353 - Heap buffer overflow in Windows Telephony Service. Local privilege escalation. CVSS 7.8. Patch reported, apply immediately. #CVE #Microsoft #infosec
##updated 2026-08-11T18:31:08
1 posts
Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
Tag
CVE ID
CVE Title
Severity
.NET
CVE-2026-58641
.NET Elevation of Privilege Vulnerability
Important
.NET
CVE-2026-62901
.NET Denial…
#NewsBeep #News #US #USA #UnitedStates #UnitedStatesOfAmerica #Technology
https://www.newsbeep.com/us/810540/
updated 2026-08-11T18:17:41.267000
2 posts
Siemens disclosed CVE-2026-59693 affecting Desigo DXR and PXC building automation controllers. Malformed BACnet packets can trigger a denial-of-service condition with no remote recovery path, requiring a physical reset of the affected device.
#SiemensDesigo #BuildingAutomation #ICS #BACnet
https://cyberworldops.eu/en/siemens-desigo-malformed-bacnet-packets-can-cause-dos-on-controllers
##Siemens disclosed CVE-2026-59693 affecting Desigo DXR and PXC building automation controllers. Malformed BACnet packets can trigger a denial-of-service condition with no remote recovery path, requiring a physical reset of the affected device.
#SiemensDesigo #BuildingAutomation #ICS #BACnet
https://cyberworldops.eu/en/siemens-desigo-malformed-bacnet-packets-can-cause-dos-on-controllers
##updated 2026-08-11T18:17:37.757000
2 posts
CVE-2026-56721 - Privilege escalation in CamaleonCMS ≤2.9.2 via IDOR. Authenticated low-priv users can overwrite any credentials. CVSS 8.8. Unpatched - update immediately. #CVE #CamaleonCMS #infosec
##🟠 CVE-2026-56721 - High (8.8)
CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference (IDOR) that allows authenticated low-privileged attackers to overwrite any user's credentials by exploiting a parameter confus...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56721/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-11T17:19:14.203000
1 posts
Vulnerabilities in #Mastodon
URL: https://github.com/mastodon/mastodon/security/advisories/GHSA-7jvv-fhmg-wpfw
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5
CVEs: CVE-2026-72914, CVE-2026-72915, CVE-2026-72916
See also:
- https://github.com/mastodon/mastodon/security/advisories/GHSA-hx34-2pfw-2qfj
- https://github.com/mastodon/mastodon/security/advisories/GHSA-vwhj-3g83-v276
CVE-2026-72914 (CVSS: 7.5): A Mastodon statistics endpoint intended for
instance administrators was checking for the appropriate permissions before
returning the results, but not before computing them, allowing anyone to issue
potentially expensive requests.
CVE-2026-72915 (CVSS: 7.5): Mastodon versions 4.6.0 to 4.6.4 allow any
logged-in local user to access personally-identifying information about other
local-users due to an incorrect access control validation.
CVE-2026-72916 (CVSS: 6.3): By nature, Mastodon performs a lot of outbound
requests to user-provided domains. Mastodon however has some protection
mechanism to disallow requests to local IP addresses (unless specified in
ALLOWED_PRIVATE_ADDRESSES) to avoid the “confused deputy” problem. The list of
disallowed IP address ranges was lacking the IPv4-compatible IPv6 address
range that can be used to reach local IP addresses on specific configurations.
updated 2026-08-11T16:17:34.257000
1 posts
🟠 CVE-2026-67180 - High (8.4)
Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evidence path/name obtains code execution on the worker fleet. Fixed on 2026-07-10.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67180/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-11T15:32:40
1 posts
CVE-2026-50060 - Use-after-free in Solid Edge SE2025/2026. Malicious DFT files can trigger code execution. CVSS 7.8. Patch to latest updates now. #CVE #SolidEdge #infosec
##updated 2026-08-11T09:32:42
1 posts
About 52 of your CVEs were missing from our OSV.dev cache, which we use as an independent confirmation source. OSV has them now; they just hadn't synced into our local DB yet.
What we fixed today:
Fixed the version range parser in our consolidator to correctly detect TYPO3's format
Re-synced all 99 TYPO3 CVEs against OSV.dev
Result: 73 now show as PATCHED / FIX AVAILABLE, 25 as PATCH UNDER REVIEW (awaiting OSV confirmation), 1 brand new (yesterday's CVE-2026-19418)
updated 2026-08-11T03:31:59
1 posts
Asus posted an advisory today. Scroll down for the full list:
CVE-2026-8917: Security Update for ASUS GPU Tweak III, GPU Tweak II, AI Suite 3, and Armoury Crate Security Bulletin https://www.asus.com/security-advisory/
PC Gamer: It's time to update Asus Armoury Crate and several other Asus software tools again, as another high severity security vulnerability has been discovered https://www.pcgamer.com/software/security/its-time-to-update-asus-armoury-crate-and-several-other-asus-software-tools-again-as-another-high-severity-security-vulnerability-has-been-discovered/ #infosec #vulnerability #Asus
##updated 2026-08-11T03:31:57
1 posts
SAP August 2026 Patch Day Fixes Critical Code Injection and Memory Corruption Flaws
SAP's August 2026 Security Patch Day addresses 31 vulnerabilities, including a critical CVSS 10.0 authentication bypass in Commerce Cloud and code injection flaws in Manufacturing Integration and Intelligence. These vulnerabilities allow remote attackers to execute arbitrary commands and gain unauthorized access to internal enterprise systems.
**If you run SAP products, especially Manufacturing Integration and Intelligence (MII) read the advisory in detail. First make sure these systems are isolated from the internet where possible and reachable only from trusted internal networks. Then apply SAP's August 2026 security notes ASAP starting with the critical fixes for Commerce Cloud (CVE-2026-58231) and MII (CVE-2026-44772, CVE-2026-44758), followed by the ABAP Platform patch (CVE-2026-34265).**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/sap-august-2026-patch-day-fixes-critical-code-injection-and-memory-corruption-flaws-p-s-x-p-k/gD2P6Ple2L
updated 2026-08-11T03:31:55
1 posts
SAP August 2026 Patch Day Fixes Critical Code Injection and Memory Corruption Flaws
SAP's August 2026 Security Patch Day addresses 31 vulnerabilities, including a critical CVSS 10.0 authentication bypass in Commerce Cloud and code injection flaws in Manufacturing Integration and Intelligence. These vulnerabilities allow remote attackers to execute arbitrary commands and gain unauthorized access to internal enterprise systems.
**If you run SAP products, especially Manufacturing Integration and Intelligence (MII) read the advisory in detail. First make sure these systems are isolated from the internet where possible and reachable only from trusted internal networks. Then apply SAP's August 2026 security notes ASAP starting with the critical fixes for Commerce Cloud (CVE-2026-58231) and MII (CVE-2026-44772, CVE-2026-44758), followed by the ABAP Platform patch (CVE-2026-34265).**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/sap-august-2026-patch-day-fixes-critical-code-injection-and-memory-corruption-flaws-p-s-x-p-k/gD2P6Ple2L
updated 2026-08-09T06:31:34
1 posts
4 repos
https://github.com/suominen/sctphantom
https://github.com/yandex-cloud-examples/yc-mk8s-sctphantom-mitigation
🐧 SIGINT // Ubuntu Watch — 2026-08-13
An 18-year-old SCTP use-after-free hitting Debian 13, Ubuntu 24.04, and RHEL. If SCTP modules load by default on your hosts, blacklist them or patch now, container isolation is not a real security boundary against a kernel root bug.
##updated 2026-08-08T04:17:50.503000
1 posts
ERPNext's Document Follow feature exposed unauthorized data
Frappe/ERPNext의 Document Follow 기능에서 권한 검증이 누락된 취약점 체인 3건(CVE-2026-66058, CVE-2026-66059, CVE-2026-66000)이 공개됐다. 인증된 Desk 사용자는 읽기 권한이 없는 문서를 팔로우할 수 있었고, 이후 변경 시 민감한 필드가 포함된 diff 정보를 이메일로 지속 수신할 수 있었다. 또한 문서 권한이 사후 철회돼도 기존 팔로우 구독이 유지되는 문제가 있어 데이터 유출이 지속될 수 있었다. Frappe v16.23.0 및 v15.112.0에서 수정됐으므로 ERPNext/HRMS 운영자는...
https://robinroy.xyz/blog/frappe-document-follow-vulnerability/
##updated 2026-08-07T20:08:27.597000
2 posts
CVE-2026-67261: Dell VSI RCE Flaw Scores CVSS 9.8
##CVE-2026-67261: Dell VSI RCE Flaw Scores CVSS 9.8
##updated 2026-08-07T18:31:52
2 posts
📢 Cisco alerte sur 7 vulnérabilités ClamAV avec PoC public affectant Secure Endpoint
Cet article rapporte une alerte de sécurité émise par Cisco concernant sept vulnérabilités dans ClamAV affectant ses produits Secure Endpoint Connector sur Windows, macOS et Linux. Les failles sont référencées sous les identifiants CVE-2026-20337 à CVE-2026-20339 et…
📖 cyberveille : https://cyberveille.ch/posts/2026-08-13-cisco-alerte-sur-7-vulnerabilites-clamav-avec-poc-public-affectant-secure-endpoint/
🌐 source : https://www.securityweek.com/cisco-warns-of-high-severity-clamav-vulnerabilities-with-public-poc/amp/
🟢 vérification factuelle haute
#ClamAV #PoCPublic #Cyberveille
「Cisco社、ClamAVの深刻な脆弱性と公開されているエクスプロイトについて警告 」: #BLEEPINGCOMPUTER
「Ciscoは、Secure Endpoint Connectorに影響を与える2つの深刻な脆弱性について警告を発した。これらの脆弱性により、攻撃者はサービス拒否(DoS)攻撃においてClamAVのスキャンプロセスをクラッシュさせることができる。
これらのセキュリティ上の欠陥( CVE-2026-20337 および CVE-2026-20338 として追跡)は、マルウェアのファイルスキャンに使用されるオープンソースかつクロスプラットフォームのエンジンであるClamAV(Clam AntiVirus)のZIPアーカイブパーサーで発見されました。
シスコが金曜日に発表した勧告によると、これら2つの脆弱性はそれぞれ不適切な境界チェックとメモリ処理に起因するものであり、認証されていないリモート攻撃者によって悪用される可能性がある。 」
##updated 2026-08-05T21:27:39
2 posts
CVE-2026-71319 lets attackers run arbitrary commands via unauthenticated Nuxt DevTools RPC. CVSS 9.6, 7.3M monthly downloads. Patch now.
##CVE-2026-71319 lets attackers run arbitrary commands via unauthenticated Nuxt DevTools RPC. CVSS 9.6, 7.3M monthly downloads. Patch now.
##updated 2026-08-05T18:31:45
1 posts
Cisco has released critical security updates for IOS XE Software, addressing vulnerabilities that could expose network devices to remote attacks. Immediate patching is essential due to the severity and lack of workarounds. Affected versions include IOS XE 17.9, 17.12, 17.15, 17.18, and 26.1. Notably, CVE-2026-20272 carries a CVSS score of 9.8, involving improper neutralization of special elements,…
#Cisco #IOSXE #CyberSecurity #NetworkSecurity #Vulnerabilities #Patching
https://thedailytechfe…
##updated 2026-08-05T14:17:08.690000
2 posts
PoC exploit code is public for CVE-2026-61515, an unauthenticated command injection in Puwell IP Camera firmware. CVSS 9.3. Details inside.
##PoC exploit code is public for CVE-2026-61515, an unauthenticated command injection in Puwell IP Camera firmware. CVSS 9.3. Details inside.
##updated 2026-08-05T09:31:27
1 posts
🚨 Critical flaw in Audiobookshelf!
CVE-2026-71209 allows unauthenticated remote attackers to bypass auth and read arbitrary host files via path traversal. Check out the technical deep dive and remediation guide now:
updated 2026-08-04T18:31:36
2 posts
CVE-2026-63455 and CVE-2026-63456 let attackers bypass web authentication on HPE EdgeConnect Orchestrator. CVSS 9.8. Patch now.
##CVE-2026-63455 and CVE-2026-63456 let attackers bypass web authentication on HPE EdgeConnect Orchestrator. CVSS 9.8. Patch now.
##updated 2026-08-04T18:31:32
2 posts
CVE-2026-63455 and CVE-2026-63456 let attackers bypass web authentication on HPE EdgeConnect Orchestrator. CVSS 9.8. Patch now.
##CVE-2026-63455 and CVE-2026-63456 let attackers bypass web authentication on HPE EdgeConnect Orchestrator. CVSS 9.8. Patch now.
##updated 2026-08-04T14:27:12.530000
3 posts
3 repos
https://github.com/HORKimhab/CVE-2026-18577
https://github.com/Yash-Dalvee/stormencryptor-ncentral-defense
https://github.com/CreamyG31337/ncentral-compromise-ioc-triage
📢 CVE-2026-18577 : Bypass d'authentification N-able N-central exploité activement
Cet article analyse CVE-2026-18577, une vulnérabilité de bypass d'authentification affectant la plateforme de Remote Monitoring and Management (RMM) N-able N-central, confirmée comme activement exploitée fin juillet 2026.
📖 cyberveille : https://cyberveille.ch/posts/2026-08-12-cve-2026-18577-bypass-d-authentification-n-able-n-central-exploite-activement/
🌐 source : https://www.criminalip.io/knowledge-hub/blog/37044
🟡 vérification factuelle moyenne
#NAbleNCentral #RMM #Cyberveille
⚪️ N-able Releases Two Patches for N-central Authentication Bypass Vulnerability
🗨️ N-able developers have released a second emergency patch for the N-central remote monitoring and management platform. The follow-up update was required due to ongoing attacks exploiting CVE-2026-18577: attackers are gaining administrator privileges on N-central servers and infiltrating customers’…
##⚪️ N-able Releases Two Patches for N-central Authentication Bypass Vulnerability
🗨️ N-able developers have released a second emergency patch for the N-central remote monitoring and management platform. The follow-up update was required due to ongoing attacks exploiting CVE-2026-18577: attackers are gaining administrator privileges on N-central servers and infiltrating customers’…
##updated 2026-07-30T19:17:31.990000
2 posts
1 repos
https://github.com/OmriBaso/SCCM-CVE-2026-47301-Remote-Code-Execution-Exploit
SCCM RCE PoC (CVE-2026-47301) https://github.com/OmriBaso/SCCM-CVE-2026-47301-Remote-Code-Execution-Exploit
##SCCM RCE PoC (CVE-2026-47301) https://github.com/OmriBaso/SCCM-CVE-2026-47301-Remote-Code-Execution-Exploit
##updated 2026-07-30T16:17:15.073000
3 posts
Attackers Exploit Critical VMware vCenter Flaws to Gain Persistent Remote Access
German cybersecurity firm QUIRSO reports active exploitation of VMware vCenter and ESXi, critical flaws (CVE-2026-59310 and CVE-2026-59309).
**If you run VMware vCenter, this is important. Make sure it is not reachable from the internet and can only be accessed from trusted internal networks. Then urgently apply the fixes from Broadcom advisory VMSA-2026-0006.1 (vCenter 9.1.0.0300, 9.0.2.0100, or 8.0 U3k / U2f), because the platform is being attacked and there is no workaround for the flaws. If your vCenter was exposed, check it for signs of compromise such as unexpected cron jobs, unknown SSH tools, or unusual outbound connections.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/attackers-exploit-critical-vmware-vcenter-flaws-to-gain-persistent-remote-access-4-o-b-8-9/gD2P6Ple2L
📰 VMware Patches Critical VM Escape Flaw (CVE-2026-47876) in ESXi
Broadcom patches critical VMware flaws, including a VM escape in ESXi (CVE-2026-47876) and unauthenticated RCE in vCenter (CVE-2026-59309, CVE-2026-59310). CVSS scores up to 9.8. Immediate patching is crucial. #VMware #CyberSecurity #PatchTuesday
##Attackers Exploit Critical VMware vCenter Flaws to Gain Persistent Remote Access
German cybersecurity firm QUIRSO reports active exploitation of VMware vCenter and ESXi, critical flaws (CVE-2026-59310 and CVE-2026-59309).
**If you run VMware vCenter, this is important. Make sure it is not reachable from the internet and can only be accessed from trusted internal networks. Then urgently apply the fixes from Broadcom advisory VMSA-2026-0006.1 (vCenter 9.1.0.0300, 9.0.2.0100, or 8.0 U3k / U2f), because the platform is being attacked and there is no workaround for the flaws. If your vCenter was exposed, check it for signs of compromise such as unexpected cron jobs, unknown SSH tools, or unusual outbound connections.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/attackers-exploit-critical-vmware-vcenter-flaws-to-gain-persistent-remote-access-4-o-b-8-9/gD2P6Ple2L
updated 2026-07-30T14:16:58.467000
1 posts
📰 VMware Patches Critical VM Escape Flaw (CVE-2026-47876) in ESXi
Broadcom patches critical VMware flaws, including a VM escape in ESXi (CVE-2026-47876) and unauthenticated RCE in vCenter (CVE-2026-59309, CVE-2026-59310). CVSS scores up to 9.8. Immediate patching is crucial. #VMware #CyberSecurity #PatchTuesday
##updated 2026-07-30T12:32:18
1 posts
1 repos
CVE-2026-64560: Linux Kernel CPU Timer Use-After-Free Gives a Root Shell, PoC Exploit Code Publicly Disclosed
##updated 2026-07-29T16:17:47.997000
2 posts
Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-react
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin....
https://aws.amazon.com/security/security-bulletins/rss/2026-066-aws/
##Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-react
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin....
https://aws.amazon.com/security/security-bulletins/rss/2026-066-aws/
##updated 2026-07-28T15:32:12
1 posts
1 repos
@jurjen_heeck @malwaretech it might be not so much agentic yet. There is however a growing number of CVE’s with AI, like CVE-2026-64747 and the early release by Apple recently of multiple fixes as a result https://www.reuters.com/business/apple-says-it-is-releasing-updates-early-response-ai-cybersecurity-concerns-2026-06-29/
##updated 2026-07-28T00:32:06
2 posts
PoC exploit code is public for CVE-2026-43723, an Apple mediaremoted flaw that lets an app gain root privileges. CVSS 7.8. Patch now.
##PoC exploit code is public for CVE-2026-43723, an Apple mediaremoted flaw that lets an app gain root privileges. CVSS 7.8. Patch now.
##updated 2026-07-24T22:37:39
2 posts
CVE-2026-16756 - Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
Bulletin ID: 2026-064-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/23/2026 11:30 AM PDT
Description:
Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and s...
https://aws.amazon.com/security/security-bulletins/rss/2026-064-aws/
##CVE-2026-16756 - Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
Bulletin ID: 2026-064-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/23/2026 11:30 AM PDT
Description:
Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and s...
https://aws.amazon.com/security/security-bulletins/rss/2026-064-aws/
##updated 2026-07-22T19:07:37.640000
2 posts
1 repos
CVE-2026-53360: KVM SEV-SNP guest-to-host heap OOB and analysis of the upstream fix https://blog.himanshuanand.com/2026/08/i-found-a-kvm-guest-to-host-heap-corruption-bug-and-someone-else-got-there-first/
##CVE-2026-53360: KVM SEV-SNP guest-to-host heap OOB and analysis of the upstream fix https://blog.himanshuanand.com/2026/08/i-found-a-kvm-guest-to-host-heap-corruption-bug-and-someone-else-got-there-first/
##updated 2026-07-18T09:32:17
1 posts
1 repos
CVE-2026-53361 AF_Unix GC vs. MSG_PEEK use-after-free container escape
##updated 2026-07-15T02:21:44.380000
1 posts
24 repos
https://github.com/0xlane/pagecache-guard
https://github.com/millikanjohnl-blip/dirtyfrag-detection-rules
https://github.com/nonameuserosint-hue/DirtyFrag-go
https://github.com/DylanClaudio/Reporte-de-Escalada-de-Privilegios-Local-Dirty-Frag
https://github.com/liamromanis101/DirtyFrag-Detector
https://github.com/attaattaatta/CVE-2026-43500
https://github.com/cumakurt/linuxpi
https://github.com/metalx1993/dirtyfrag-patches
https://github.com/MadExploits/CVE-2026-46300
https://github.com/aettern/copyfrag-fuse
https://github.com/gagaltotal/CVE-2026-43284-CVE-2026-43500-scan
https://github.com/XRSecCD/202605_dirty_frag
https://github.com/krisiasty/vcheck
https://github.com/mym0us3r/DIRTY-FRAG-Detection-with-Wazuh-4.14.4
https://github.com/vorkampfer/dirty_frag_mitigation
https://github.com/suominen/CVE-2026-43284
https://github.com/lukeslp/redtail-ioc
https://github.com/haydenjames/dirty-frag-check
https://github.com/KaraZajac/DIRTYFAIL
https://github.com/linnemanlabs/dirtyfrag-arm64
https://github.com/armircetaj/tetragon-dirtyfrag
https://github.com/1neptune/DirtyFrag
CISA republished Hitachi Energy PSIRT 8DBD000256 ("Dirty Frag"). CVE-2026-43284 (8.8, esp4/esp6 IPsec ESP, S:C) and CVE-2026-43500 (7.8, rxrpc, CWE-787) write decrypted packet data into pages the kernel doesn't own —...
##updated 2026-07-15T02:21:43.190000
1 posts
44 repos
https://github.com/0xlane/pagecache-guard
https://github.com/millikanjohnl-blip/dirtyfrag-detection-rules
https://github.com/nonameuserosint-hue/DirtyFrag-go
https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag
https://github.com/xd20111/CVE-2026-43284
https://github.com/dixyes/dirtypatch
https://github.com/ChernStepanov/DirtyFrag-for-dummies
https://github.com/liamromanis101/DirtyFrag-Detector
https://github.com/ryan2929/CVE-2026-43284-
https://github.com/DylanClaudio/Reporte-de-Escalada-de-Privilegios-Local-Dirty-Frag
https://github.com/attaattaatta/CVE-2026-43500
https://github.com/Percivalll/Dirty-Frag-Kubernetes-PoC
https://github.com/0xBlackash/CVE-2026-43284
https://github.com/cumakurt/linuxpi
https://github.com/metalx1993/dirtyfrag-patches
https://github.com/MadExploits/CVE-2026-46300
https://github.com/scriptzteam/Paranoid-Dirty-Frag-CVE-2026-43284
https://github.com/Aiyakami/rust_dirtyfrag
https://github.com/aettern/copyfrag-fuse
https://github.com/gagaltotal/CVE-2026-43284-CVE-2026-43500-scan
https://github.com/XRSecCD/202605_dirty_frag
https://github.com/krisiasty/vcheck
https://github.com/mym0us3r/DIRTY-FRAG-Detection-with-Wazuh-4.14.4
https://github.com/kuniyal08/Dirty-Frag-CVE-2026-43284
https://github.com/FrosterDL/CVE-2026-43284
https://github.com/nabhan-mohy/Dirty-Frag-Research-CVE-2026-43284-
https://github.com/jayhutajulu1/CVE-2026-43284-DirtyFrag-PoC
https://github.com/suominen/CVE-2026-43284
https://github.com/AtlasVector/Dirty-Frag-CVE-2026-43284
https://github.com/lukeslp/redtail-ioc
https://github.com/haydenjames/dirty-frag-check
https://github.com/LucasPDiniz/CVE-2026-43284
https://github.com/KaraZajac/DIRTYFAIL
https://github.com/RevyHub/CVE-2026-43284---DirtyFrag-Analysis-THM-
https://github.com/linnemanlabs/dirtyfrag-arm64
https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe
https://github.com/armircetaj/tetragon-dirtyfrag
https://github.com/t1ckprivate/CVE-2026-43284-Dirty-Frag
https://github.com/1neptune/DirtyFrag
https://github.com/grabesec/XCP_ng_CVE-2026-43284_tester
https://github.com/AK777177/Dirty-Frag-Analysis
https://github.com/First-John/cve_2026_frag_family_fix
https://github.com/6abc/Copy-Fail-CVE-2026-31431-dirty-frag-CVE-2026-43284
https://github.com/g0thamRabb1t/CVE-2026-43284-dirtyfrag-detection
CISA republished Hitachi Energy PSIRT 8DBD000256 ("Dirty Frag"). CVE-2026-43284 (8.8, esp4/esp6 IPsec ESP, S:C) and CVE-2026-43500 (7.8, rxrpc, CWE-787) write decrypted packet data into pages the kernel doesn't own —...
##updated 2026-07-14T15:32:55
1 posts
100 repos
https://github.com/xeloxa/copyfail-exploit
https://github.com/Juguitos/copy-fail
https://github.com/abdullaabdullazade/CVE-2026-31431
https://github.com/XsanFlip/CVE-2026-31431-Patch
https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs
https://github.com/erlangparasu/mitigate_cve_2026_31431-sh
https://github.com/badsectorlabs/copyfail-go
https://github.com/hans362/CVE-2026-31431-Copy-Fail-Container-Escape
https://github.com/lonelyor/CVE-2026-31431-exp
https://github.com/Huchangzhi/autorootlinux
https://github.com/Smarttfoxx/copyfail
https://github.com/JuanBindez/CVE-2026-31431
https://github.com/sgkdev/page_inject
https://github.com/4xura/CVE-2026-31431-Copy-Fail
https://github.com/0xShe/CVE-2026-31431
https://github.com/AdityaBhatt3010/CVE-2026-31431
https://github.com/novysodope/copy-fail-CVE-2026-31431-C
https://github.com/tgies/copy-fail-c
https://github.com/yuspring/cve-2026-31431-poc
https://github.com/insomnisec/Detections-CVE-2026-31431
https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE
https://github.com/TheMalwareGuardian/CVE-2026-31431
https://github.com/Boos4721/copyfail-rs
https://github.com/ErdemOzgen/copy-fail-cve-2026-31431
https://github.com/ExploitEoom/CVE-2026-31431
https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe
https://github.com/ben-slates/CVE-2026-31431-Exploit
https://github.com/pascal-gujer/CVE-2026-31431
https://github.com/cyber-joker/copy-fail-python
https://github.com/Xerxes-2/CVE-2026-31431-rs
https://github.com/sammwyy/copyfail-rs
https://github.com/Dabbleam/CVE-2026-31431-mitigation
https://github.com/ncmprbll/copy-fail-rs
https://github.com/cozystack/copy-fail-blocker
https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit
https://github.com/malwarekid/CVE-2026-31431
https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script
https://github.com/mym0us3r/COPY-FAIL-Detection-with-Wazuh-4.14.4
https://github.com/Shotafry/CopyFail-Exploits-CVE-2026-31431
https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit
https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC
https://github.com/wuwu001/CVE-2026-31431-exploit
https://github.com/atgreen/block-copyfail
https://github.com/philfry/cve-2026-31431-ftrace
https://github.com/ZephrFish/CopyFail-CVE-2026-31431
https://github.com/Qengineering/RK35xx-CopyFail-Hotfix
https://github.com/diemoeve/copyfail-rs
https://github.com/JnamerZ/CopyFail-CVE-2026-31431
https://github.com/qi4L/CVE-2026-31431-Container-Escape
https://github.com/KaraZajac/DIRTYFAIL
https://github.com/rvzsec/CVE-2026-31431
https://github.com/guiimoraes/CVE-2026-31431
https://github.com/yandex-cloud-examples/yc-mk8s-copy-fail-mitigation
https://github.com/haydenjames/CVE-2026-31431-check
https://github.com/Sl4cK0TH/CVE-2026-31431-PoC
https://github.com/Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail
https://github.com/wesmar/CVE-2026-31431
https://github.com/luotian2/CVE-2026-31431
https://github.com/gagaltotal/cve-2026-31431-copy-fail
https://github.com/aestechno/cve-2026-31431-ansible
https://github.com/samanzamani/copy-fail-checker
https://github.com/mrunalp/block-copyfail
https://github.com/painoob/Copy-Fail-Exploit-CVE-2026-31431
https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail
https://github.com/st4rburn/public-passwd
https://github.com/adampielak/CVE-2026-31431_SCA_WAZUH
https://github.com/MartinPham/copy-fail-CVE-2026-31431-php
https://github.com/desultory/CVE-2026-31431
https://github.com/jbnetwork-git/copy-fail-check
https://github.com/AliHzSec/CVE-2026-31431
https://github.com/rootsecdev/cve_2026_31431
https://github.com/scriptzteam/Paranoid-Copy-Fail-CVE-2026-31431
https://github.com/Alfredooe/CVE-2026-31431
https://github.com/M4xSec/CVE-2026-31431-RCE-Exploit
https://github.com/pedromizz/copy-fail
https://github.com/bootsareme/copyfail-deconstructed
https://github.com/sgkdev/ptrace_may_dream
https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized
https://github.com/Iamliuxiaozhen/copy_fail
https://github.com/sec17br/CVE-2026-31431-Copy-Fail
https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431
https://github.com/g1nt0n1x/copy-fail-CVE-2026-31431-shell
https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag
https://github.com/bigwario/copy-fail-CVE-2026-31431-C
https://github.com/mahdi13830510/CVE-2026-31431-mitigation-suite
https://github.com/kvakirsanov/CVE-2026-31431-live-process-code-injection
https://github.com/cs8425/copy-fail-go
https://github.com/kinryulabs/rootpacket-cve-2026-31431
https://github.com/SeanRickerd/cve-2026-31431
https://github.com/b5null/CVE-2026-31431-C
https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC
https://github.com/theori-io/copy-fail-CVE-2026-31431
https://github.com/povzayd/CVE-2026-31431
https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431
https://github.com/kadir/copy-fail-CVE-2026-31431-IOC
https://github.com/Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431
https://github.com/wgnet/wg.copyfail.patch
https://github.com/adysec/cve-2026-31431
🐧 SIGINT // Ubuntu Watch — 2026-08-12
A 732-byte script reportedly roots any Linux since 2017 via a logic flaw, not memory corruption. If accurate this hits every homelab box and container host regardless of distro. Patch fast, verify your kernel version against the advisory.
🔗 https://www.bugcrowd.com/blog/what-we-know-about-copy-fail-cve-2026-31431/
##updated 2026-07-09T15:32:33
1 posts
Broadcom has several new advisories that include two critical vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
CISA:
Industrial vulnerability: Johnson Controls C-CURE 9000 and Victor application server (Update A) https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-01
Blog post: Cyber Storm X: 20 Years of Readiness, Resilience, and Real‑World Impact https://www.cisa.gov/news-events/news/cyber-storm-x-20-years-readiness-resilience-and-real-world-impact #CISA
Cisco:
High-severity: CVE-2026-20349: Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF @TalosSecurity #Cisco
Yesterday:
Tenable Research Advisories:
Medium-severity: CVE-2026-12879: Google Cloud Platform (GCP) Apigee Cross-Tenant Data Exfiltration via Confused Deputy https://www.tenable.com/security/research/tra-2026-53 #infosec #Google #vulnerability
##updated 2026-06-30T18:38:47
2 posts
🟠 CVE-2026-49478 - High (8.7)
Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discovery, allowin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49478/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-49478 - High (8.7)
Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discovery, allowin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49478/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-06-30T18:09:14
2 posts
🟠 CVE-2026-49473 - High (8.8)
@cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by mapping HTTP requests to Cedar actions and evaluating authorization policies before allowing request...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49473/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-49473 - High (8.8)
@cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by mapping HTTP requests to Cedar actions and evaluating authorization policies before allowing request...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49473/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-06-17T10:27:52.490000
1 posts
2 repos
🖲️ #Noticia de #CiberSeguridad #CiberGuerra #CiberAtaque #CiberNoticia
⚫ ResetNightmare: exploit público permite restablecer cualquier contraseña de cuentas de AD (CVE-2026-27912)
🔗 http://blog.segu-info.com.ar/2026/08/resetnightmare-exploit-publico-permite.html
Investigadores publicaron todos los detalles y una herramienta de prueba de
concepto para
CVE-2026-27912
(CVSS 8.0), llamada
ResetNightmare. La falla se encuentra en el protocolo de cambio de contraseña Kerberos de
updated 2026-06-17T10:21:55.793000
1 posts
Researchers find Windows 11 can be hacked with no physical access
버밍엄대·더럼대 연구진은 일부 DDR4/DDR5 DIMM의 SPD 구성 칩이 쓰기 보호되지 않은 점을 악용하는 원격 소프트웨어 공격 ‘Download More RAM’을 공개했다. 공격자는 메모리 용량 정보를 조작해 실제 메모리의 별칭 주소를 만들고, 이를 통해 Windows의 VBS·HVCI를 우회하거나 AV/EDR 비활성화, 차단된 취약 드라이버 재활성화 등을 수행할 수 있다. Microsoft는 CVE-2026-23670을 할당하고 2026년 4월 보안 업데이트...
##updated 2026-06-17T10:19:30.257000
2 posts
As an example of how ridiculous the CVE ecosystem has become... researchers claimed a CVE this year against an LMDB commandline tool (not a server) for a bug fixed in 0.9.15, which was released 2015-06-19 - eleven years ago.
https://www.openeuler.org/zh/security/cve/detail/?cveId=CVE-2026-22185&packageName=lmdb
##As an example of how ridiculous the CVE ecosystem has become... researchers claimed a CVE this year against an LMDB commandline tool (not a server) for a bug fixed in 0.9.15, which was released 2015-06-19 - eleven years ago.
https://www.openeuler.org/zh/security/cve/detail/?cveId=CVE-2026-22185&packageName=lmdb
##updated 2026-05-27T22:51:19
2 posts
🟠 CVE-2026-47717 - High (7.5)
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. Versio...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47717/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-47717 - High (7.5)
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. Versio...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47717/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2025-10-22T19:13:26
1 posts
100 repos
https://github.com/simonis/Log4jPatch
https://github.com/lucab85/log4j-cve-2021-44228
https://github.com/blake-fm/vcenter-log4j
https://github.com/back2root/log4shell-rex
https://github.com/NS-Sp4ce/Vm4J
https://github.com/Adikso/minecraft-log4j-honeypot
https://github.com/Jeromeyoung/log4j2burpscanner
https://github.com/MalwareTech/Log4jTools
https://github.com/yahoo/check-log4j
https://github.com/alexandre-lavoie/python-log4rce
https://github.com/puzzlepeaches/Log4jCenter
https://github.com/KosmX/CVE-2021-44228-example
https://github.com/corretto/hotpatch-for-apache-log4j2
https://github.com/r3kind1e/Log4Shell-obfuscated-payloads-generator
https://github.com/momos1337/Log4j-RCE
https://github.com/aws-samples/kubernetes-log4j-cve-2021-44228-node-agent
https://github.com/1lann/log4shelldetect
https://github.com/stripe/log4j-remediation-tools
https://github.com/Azeemering/CVE-2021-44228-DFIR-Notes
https://github.com/CrackerCat/CVE-2021-44228-Log4j-Payloads
https://github.com/Puliczek/CVE-2021-44228-PoC-log4j-bypass-words
https://github.com/mubix/CVE-2021-44228-Log4Shell-Hashes
https://github.com/LiveOverflow/log4shell
https://github.com/cyberxml/log4j-poc
https://github.com/qingtengyun/cve-2021-44228-qingteng-patch
https://github.com/hackinghippo/log4shell_ioc_ips
https://github.com/BinaryDefense/log4j-honeypot-flask
https://github.com/HyCraftHD/Log4J-RCE-Proof-Of-Concept
https://github.com/wortell/log4j
https://github.com/boundaryx/cloudrasp-log4j2
https://github.com/nu11secur1ty/CVE-2021-44228-VULN-APP
https://github.com/fox-it/log4j-finder
https://github.com/CodeShield-Security/Log4JShell-Bytecode-Detector
https://github.com/leonjza/log4jpwn
https://github.com/rubo77/log4j_checker_beta
https://github.com/mufeedvh/log4jail
https://github.com/thomaspatzke/Log4Pot
https://github.com/bigsizeme/Log4j-check
https://github.com/Kadantte/CVE-2021-44228-poc
https://github.com/NorthwaveSecurity/log4jcheck
https://github.com/fullhunt/log4j-scan
https://github.com/future-client/CVE-2021-44228
https://github.com/puzzlepeaches/Log4jHorizon
https://github.com/f0ng/log4j2burpscanner
https://github.com/tippexs/nginx-njs-waf-cve2021-44228
https://github.com/fireeye/CVE-2021-44228
https://github.com/mr-r3b00t/CVE-2021-44228
https://github.com/kubearmor/log4j-CVE-2021-44228
https://github.com/Nanitor/log4fix
https://github.com/toramanemre/apache-solr-log4j-CVE-2021-44228
https://github.com/redhuntlabs/Log4JHunt
https://github.com/takito1812/log4j-detect
https://github.com/toramanemre/log4j-rce-detect-waf-bypass
https://github.com/HynekPetrak/log4shell-finder
https://github.com/infiniroot/nginx-mitigate-log4shell
https://github.com/logpresso/CVE-2021-44228-Scanner
https://github.com/nccgroup/log4j-jndi-be-gone
https://github.com/mergebase/log4j-detector
https://github.com/qingtengyun/cve-2021-44228-qingteng-online-patch
https://github.com/sec13b/CVE-2021-44228-POC
https://github.com/twseptian/spring-boot-log4j-cve-2021-44228-docker-lab
https://github.com/ssl/scan4log4j
https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce
https://github.com/TaroballzChen/CVE-2021-44228-log4jVulnScanner-metasploit
https://github.com/greymd/CVE-2021-44228
https://github.com/CERTCC/CVE-2021-44228_scanner
https://github.com/alexbakker/log4shell-tools
https://github.com/thecyberneh/Log4j-RCE-Exploiter
https://github.com/jas502n/Log4j2-CVE-2021-44228
https://github.com/mzlogin/CVE-2021-44228-Demo
https://github.com/justakazh/Log4j-CVE-2021-44228
https://github.com/Malwar3Ninja/Exploitation-of-Log4j2-CVE-2021-44228
https://github.com/RedDrip7/Log4Shell_CVE-2021-44228_related_attacks_IOCs
https://github.com/kozmer/log4j-shell-poc
https://github.com/faisalfs10x/Log4j2-CVE-2021-44228-revshell
https://github.com/DragonSurvivalEU/RCE
https://github.com/cisagov/log4j-scanner
https://github.com/Diverto/nse-log4shell
https://github.com/Labout/log4shell-rmi-poc
https://github.com/dtact/divd-2021-00038--log4j-scanner
https://github.com/marcourbano/CVE-2021-44228
https://github.com/darkarnium/Log4j-CVE-Detect
https://github.com/0xInfection/LogMePwn
https://github.com/claranet/ansible-role-log4shell
https://github.com/NCSC-NL/log4shell
https://github.com/corelight/cve-2021-44228
https://github.com/sunnyvale-it/CVE-2021-44228-PoC
https://github.com/irgoncalves/f5-waf-quick-patch-cve-2021-44228
https://github.com/AlexandreHeroux/Fix-CVE-2021-44228
https://github.com/0xDexter0us/Log4J-Scanner
https://github.com/roxas-tan/CVE-2021-44228
https://github.com/christophetd/log4shell-vulnerable-app
https://github.com/giterlizzi/nmap-log4shell
https://github.com/puzzlepeaches/Log4jUnifi
https://github.com/CreeperHost/Log4jPatcher
https://github.com/irgoncalves/f5-waf-enforce-sig-CVE-2021-44228
https://github.com/pedrohavay/exploit-CVE-2021-44228
https://github.com/dwisiswant0/look4jar
Securing your software supply chain shouldn't be manual work. 🤖 Our latest tutorial dives deep into automating dependency scanning within your CI/CD pipelines to block vulnerabilities like CVE-2021-44228. Elevate your DevSecOps game today! https://cvedatabase.com/blog/automating-dependency-scanning-a-practical-guide-to-securing-your-ci-cd-pipeline-2026-08-10 #SCA #DevSecOps #CICD #InfoSec #CyberSecurity #Automation
##updated 2025-10-22T00:34:17
1 posts
1 repos
https://github.com/razureink/cve-2025-24472-fortinet_authbypass_reproduction
Gunra ransomware operators are exploiting two Fortinet vulnerabilities, CVE-2024-55591 and CVE-2025-24472, in campaigns tied to Conti and Golden Community. Reported tooling includes Mega and OpenSSH alongside Conti and Gunra...
##updated 2025-10-22T00:34:16
3 posts
9 repos
https://github.com/watchtowrlabs/fortios-auth-bypass-poc-CVE-2024-55591
https://github.com/exfil0/CVE-2024-55591-POC
https://github.com/UMChacker/CVE-2024-55591-POC
https://github.com/0x7556/CVE-2024-55591
https://github.com/sysirq/fortios-auth-bypass-exploit-CVE-2024-55591
https://github.com/binarywarm/exp-cmd-add-admin-vpn-CVE-2024-55591
https://github.com/virus-or-not/CVE-2024-55591
https://github.com/watchtowrlabs/fortios-auth-bypass-check-CVE-2024-55591
https://github.com/sysirq/fortios-auth-bypass-poc-CVE-2024-55591
Gunra ransomware operators are exploiting two Fortinet vulnerabilities, CVE-2024-55591 and CVE-2025-24472, in campaigns tied to Conti and Golden Community. Reported tooling includes Mega and OpenSSH alongside Conti and Gunra...
##Gunra Ransomware Targets Infrastructure via Fortinet Flaws
Gunra Ransomware is exploiting critical Fortinet flaws, including CVE-2024-55591, to gain super-admin privileges and infiltrate government and critical infrastructure networks. This alarming vulnerability allows remote attackers to craft requests and bypass authentication, putting sensitive systems at risk.
#GunraRansomware #Fortinet #Cve202455591 #Ransomware #SupplyChain
##Gunra Ransomware Targets Infrastructure via Fortinet Flaws
Gunra Ransomware is exploiting critical Fortinet flaws, including CVE-2024-55591, to gain super-admin privileges and infiltrate government and critical infrastructure networks. This alarming vulnerability allows remote attackers to craft requests and bypass authentication, putting sensitive systems at risk.
#GunraRansomware #Fortinet #Cve202455591 #Ransomware #SupplyChain
##updated 2025-03-11T18:32:28
2 posts
@wdormann Ah, its our friend CrossDevice.Streaming.Source.dll again.
@wdormann Ah, its our friend CrossDevice.Streaming.Source.dll again.
updated 2025-03-11T18:32:27
2 posts
1 repos
@wdormann Ah, its our friend CrossDevice.Streaming.Source.dll again.
@wdormann Ah, its our friend CrossDevice.Streaming.Source.dll again.
WordPress 704 Security Update: A Claimed CVE-2026-65640 Flaw Puts Author-Level Uploads Under the Microscope + Video
A New WordPress Security Warning Is Raising Fresh Concerns WordPress powers a huge portion of the modern web, which makes every serious vulnerability in its ecosystem worth watching closely. A seemingly ordinary media upload can become something far more dangerous when the underlying image-processing stack is capable of interpreting complex file formats.…
##…et encore une vulnérabilité critique dans #WordPress, trouvée une nouvelle fois par pwn.ai, qui a nécessité la publication en urgence de la mise à jour 7.0.4
La CVE-2026-65640 est une RCE assez intéressante côté traitement d’images. (ImageMagick)
Un utilisateur avec le rôle Author peut envoyer un fichier nommé comme une innocente image .png, alors que son contenu est en réalité du PostScript/EPS.
WordPress se fiait trop à l’extension ; ImageMagick, lui, regarde le contenu et peut transmettre le fichier à Ghostscript… avec à la clé une exécution de code.
Ce n’est donc pas une RCE pré-auth : il faut déjà disposer d’un compte Author. Mais sur un site multi-auteurs, communautaire ou avec des comptes peu maîtrisés, le risque devient nettement plus concret.
👇
https://wordpress.org/news/2026/08/wordpress-7-0-4-release/
⬇️
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w
🖼️ RCE a WordPress via PNG maliciosos. CVE-2026-65640, fix a 7.0.4.
Atacant amb rol Autor puja `EPS:innocent.png` o un PNG amb PostScript ocult. `Imagick::load()` confiava en l'extensió; ImageMagick llegeix el contingut real → Ghostscript executa. XML-RPC i portades MP3 saltaven la validació.
El patch inspecciona bytes reals: bloqueja PostScript/EPS, PDF sense `%PDF-` i gzip/bzip2.
https://blog.elhacker.net/2026/08/vulnerabilidad-rce-en-wordpress-imagick.html
#WordPress #SecOps #ImageMagick
WordPress 7.0.4 patches CVE-2026-65640, an Author-level remote code execution bug on sites using Imagick and Ghostscript. Update now.
#WordPress #CVE202665640 #RCE #Imagick #Ghostscript #WebSecurity #Cybersecurity
##https://thecybersecguru.com/news/wordpress-7-0-4-cve-2026-65640-imagick-rce/
##…et encore une vulnérabilité critique dans #WordPress, trouvée une nouvelle fois par pwn.ai, qui a nécessité la publication en urgence de la mise à jour 7.0.4
La CVE-2026-65640 est une RCE assez intéressante côté traitement d’images. (ImageMagick)
Un utilisateur avec le rôle Author peut envoyer un fichier nommé comme une innocente image .png, alors que son contenu est en réalité du PostScript/EPS.
WordPress se fiait trop à l’extension ; ImageMagick, lui, regarde le contenu et peut transmettre le fichier à Ghostscript… avec à la clé une exécution de code.
Ce n’est donc pas une RCE pré-auth : il faut déjà disposer d’un compte Author. Mais sur un site multi-auteurs, communautaire ou avec des comptes peu maîtrisés, le risque devient nettement plus concret.
👇
https://wordpress.org/news/2026/08/wordpress-7-0-4-release/
⬇️
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w
🖼️ RCE a WordPress via PNG maliciosos. CVE-2026-65640, fix a 7.0.4.
Atacant amb rol Autor puja `EPS:innocent.png` o un PNG amb PostScript ocult. `Imagick::load()` confiava en l'extensió; ImageMagick llegeix el contingut real → Ghostscript executa. XML-RPC i portades MP3 saltaven la validació.
El patch inspecciona bytes reals: bloqueja PostScript/EPS, PDF sense `%PDF-` i gzip/bzip2.
https://blog.elhacker.net/2026/08/vulnerabilidad-rce-en-wordpress-imagick.html
#WordPress #SecOps #ImageMagick
WordPress 7.0.4 patches CVE-2026-65640, an Author-level remote code execution bug on sites using Imagick and Ghostscript. Update now.
#WordPress #CVE202665640 #RCE #Imagick #Ghostscript #WebSecurity #Cybersecurity
##🚨 CRITICAL ALERT: CVE-2026-72898 (CVSS 10.0)
Unauthenticated SQL Injection in Metabase allows remote attackers to execute arbitrary SQL, hijack admin accounts & exfiltrate enterprise DB credentials. Patch immediately!
Read full analysis: https://denizhalil.com/2026/08/13/cve-2026-72898-metabase-unauthenticated-sql-injection/
##🏆 New Achievement! Query of Doom: Prerequisite — Having a Database — Complete!
QUEST UPDATE: Gain Total Administrative Access. Status: Already completed. By someone else. Without you. Metabase, the business intelligence platform, disclosed CVE-2026-72898, a critical SQL injection zero-day scoring a perfect 10 — the platonic ideal of catastrophe. (1/3)
##(CISA TS-SOC) CVE-2026-72898 – Metabase SQL Injection Vulnerability
Severity: CRITICAL Impact Summary: Allows unauthenticated attackers to gain administrator access, modify configuration, steal credentials, and exfiltrate data from connected databases via SQL injection....
##Metabase Hit by a Critical Zero-Day: CVE-2026-72898 Puts Business Intelligence Data at Risk
Introduction: When the Analytics Layer Becomes the Attack Path Metabase is often treated as the quiet engine behind dashboards, reports, business intelligence, and data-driven decision-making. It may not be the system employees think about every morning, but behind those charts and dashboards can sit connections to production databases, cloud warehouses, customer records,…
##🚨 CRITICAL THREAT: CISA adds CVE-2026-72898 (Metabase SQL Injection) to the KEV catalog due to active exploitation. Unauthenticated attackers can hijack admin rights and steal database credentials. Full TSUITE brief with SPL, KQL, AQL & YARA-L: https://thecybermind.co/jily
##🏆 New Achievement! Query of Doom: Prerequisite — Having a Database — Complete!
QUEST UPDATE: Gain Total Administrative Access. Status: Already completed. By someone else. Without you. Metabase, the business intelligence platform, disclosed CVE-2026-72898, a critical SQL injection zero-day scoring a perfect 10 — the platonic ideal of catastrophe. (1/3)
##(CISA TS-SOC) CVE-2026-72898 – Metabase SQL Injection Vulnerability
Severity: CRITICAL Impact Summary: Allows unauthenticated attackers to gain administrator access, modify configuration, steal credentials, and exfiltrate data from connected databases via SQL injection....
##🚨 CRITICAL THREAT: CISA adds CVE-2026-72898 (Metabase SQL Injection) to the KEV catalog due to active exploitation. Unauthenticated attackers can hijack admin rights and steal database credentials. Full TSUITE brief with SPL, KQL, AQL & YARA-L: https://thecybermind.co/jily
##🚨 [CISA-2026:0811] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-20349 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20349)
- Name: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
- Notes: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20349
⚠️ CVE-2026-68820 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-68820)
- Name: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows Ancillary Function Driver for WinSock
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68820 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-68820
⚠️ CVE-2026-72898 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- Name: Metabase SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Metabase
- Product: Metabase
- Notes: https://www.metabase.com/blog/security-update ; https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-72898
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260811 #cisa20260811 #cve_2026_20349 #cve_2026_68820 #cve_2026_72898 #cve202620349 #cve202668820 #cve202672898
##CVE ID: CVE-2026-72898
Vendor: Metabase
Product: Metabase
Date Added: 2026-08-11
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72898
🔴 CVE-2026-49827 - Critical (9.8)
WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49827/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-49827: SMEWebify WebErpMesv2 ≤1.19 has a CRITICAL vuln — improper input validation lets any self-registered user achieve unauth'd RCE via PHP file upload (scan_file param). Patch with commit 5c54862fa044b363fd2be03d586750e81afd6818 https://radar.offseq.com/threat/cve-2026-49827-cwe-20-improper-input-validation-in-smewebify-weberpmesv2-aa8118e842cafb70 #OffSeq #CVE202649827 #infosec
##🔴 CVE-2026-49827 - Critical (9.8)
WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49827/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-49827: SMEWebify WebErpMesv2 ≤1.19 has a CRITICAL vuln — improper input validation lets any self-registered user achieve unauth'd RCE via PHP file upload (scan_file param). Patch with commit 5c54862fa044b363fd2be03d586750e81afd6818 https://radar.offseq.com/threat/cve-2026-49827-cwe-20-improper-input-validation-in-smewebify-weberpmesv2-aa8118e842cafb70 #OffSeq #CVE202649827 #infosec
##「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews
「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース
最も深刻な欠陥は以下のとおりです。
CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)
」
https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html
##「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews
「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース
最も深刻な欠陥は以下のとおりです。
CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)
」
https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html
##CVE-2026-49481 | UpSnap (<5.4.0) has a CRITICAL OS command injection flaw (CVSS 9.6). Authenticated low-priv users can execute arbitrary commands on the server. Patch: upgrade to 5.4.0. Details: https://radar.offseq.com/threat/cve-2026-49481-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-772a6e1ae64fad76 #OffSeq #infosec #CVE202649481 #remotecodeexecution
##🔴 CVE-2026-49481 - Critical (9.6)
UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality due to the presence of unsafe shell command template interpolation using the ip and the mac field...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49481/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-49481 | UpSnap (<5.4.0) has a CRITICAL OS command injection flaw (CVSS 9.6). Authenticated low-priv users can execute arbitrary commands on the server. Patch: upgrade to 5.4.0. Details: https://radar.offseq.com/threat/cve-2026-49481-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-772a6e1ae64fad76 #OffSeq #infosec #CVE202649481 #remotecodeexecution
##🔴 CVE-2026-49481 - Critical (9.6)
UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality due to the presence of unsafe shell command template interpolation using the ip and the mac field...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49481/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-49819 - Critical (9.8)
UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuser`. The ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49819/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-49819: UpSnap (4.4.1 – 5.3.5) has a CRITICAL flaw (CVSS 9.8) — unauthenticated attackers can register a superuser & achieve root RCE via POST /api/upsnap/init-superuser. Upgrade to 5.4.0 ASAP. https://radar.offseq.com/threat/cve-2026-49819-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-f2cf5294c0d169b6 #OffSeq #Vuln #Infosec #RCE
##🔴 CVE-2026-49819 - Critical (9.8)
UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuser`. The ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49819/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-49819: UpSnap (4.4.1 – 5.3.5) has a CRITICAL flaw (CVSS 9.8) — unauthenticated attackers can register a superuser & achieve root RCE via POST /api/upsnap/init-superuser. Upgrade to 5.4.0 ASAP. https://radar.offseq.com/threat/cve-2026-49819-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-f2cf5294c0d169b6 #OffSeq #Vuln #Infosec #RCE
##🟠 CVE-2026-19654 - High (7.5)
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19654/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19654 - High (7.5)
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19654/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-73299 - Critical (10)
Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled templat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73299/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-73299 - Critical (10)
Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled templat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73299/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18952 - High (8.1)
Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the thr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18952/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18952 - High (8.1)
Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the thr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18952/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-73294 - Critical (9.9)
Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controlled --upload-pack option to CmdGitClient.GetLastRemoteCommitHash through POST /api/project/{id}/rep...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73294/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-73294 - Critical (9.9)
Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controlled --upload-pack option to CmdGitClient.GetLastRemoteCommitHash through POST /api/project/{id}/rep...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73294/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73293 - High (8.8)
Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.19 and from 2.19.0-alpha3 until 2.19.5-beta5, ProjectMiddleware and GetProjectOrGlobalRoleBySlug allow a project manager to use POST /api/project/{id}/roles to create a cust...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73293/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73293 - High (8.8)
Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.19 and from 2.19.0-alpha3 until 2.19.5-beta5, ProjectMiddleware and GetProjectOrGlobalRoleBySlug allow a project manager to use POST /api/project/{id}/roles to create a cust...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73293/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73292 - High (8.3)
Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie without CSRF protection or current-password con...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73292/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73292 - High (8.3)
Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie without CSRF protection or current-password con...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73292/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##ERPNext's Document Follow feature exposed unauthorized data
Frappe/ERPNext의 Document Follow 기능에서 권한 검증이 누락된 취약점 체인 3건(CVE-2026-66058, CVE-2026-66059, CVE-2026-66000)이 공개됐다. 인증된 Desk 사용자는 읽기 권한이 없는 문서를 팔로우할 수 있었고, 이후 변경 시 민감한 필드가 포함된 diff 정보를 이메일로 지속 수신할 수 있었다. 또한 문서 권한이 사후 철회돼도 기존 팔로우 구독이 유지되는 문제가 있어 데이터 유출이 지속될 수 있었다. Frappe v16.23.0 및 v15.112.0에서 수정됐으므로 ERPNext/HRMS 운영자는...
https://robinroy.xyz/blog/frappe-document-follow-vulnerability/
##ERPNext's Document Follow feature exposed unauthorized data
Frappe/ERPNext의 Document Follow 기능에서 권한 검증이 누락된 취약점 체인 3건(CVE-2026-66058, CVE-2026-66059, CVE-2026-66000)이 공개됐다. 인증된 Desk 사용자는 읽기 권한이 없는 문서를 팔로우할 수 있었고, 이후 변경 시 민감한 필드가 포함된 diff 정보를 이메일로 지속 수신할 수 있었다. 또한 문서 권한이 사후 철회돼도 기존 팔로우 구독이 유지되는 문제가 있어 데이터 유출이 지속될 수 있었다. Frappe v16.23.0 및 v15.112.0에서 수정됐으므로 ERPNext/HRMS 운영자는...
https://robinroy.xyz/blog/frappe-document-follow-vulnerability/
##SAP August 2026 Patch Day Fixes Critical Code Injection and Memory Corruption Flaws
SAP's August 2026 Security Patch Day addresses 31 vulnerabilities, including a critical CVSS 10.0 authentication bypass in Commerce Cloud and code injection flaws in Manufacturing Integration and Intelligence. These vulnerabilities allow remote attackers to execute arbitrary commands and gain unauthorized access to internal enterprise systems.
**If you run SAP products, especially Manufacturing Integration and Intelligence (MII) read the advisory in detail. First make sure these systems are isolated from the internet where possible and reachable only from trusted internal networks. Then apply SAP's August 2026 security notes ASAP starting with the critical fixes for Commerce Cloud (CVE-2026-58231) and MII (CVE-2026-44772, CVE-2026-44758), followed by the ABAP Platform patch (CVE-2026-34265).**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/sap-august-2026-patch-day-fixes-critical-code-injection-and-memory-corruption-flaws-p-s-x-p-k/gD2P6Ple2L
Vulnerabilities in #Mastodon
URL: https://github.com/mastodon/mastodon/security/advisories/GHSA-7jvv-fhmg-wpfw
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5
CVEs: CVE-2026-72914, CVE-2026-72915, CVE-2026-72916
See also:
- https://github.com/mastodon/mastodon/security/advisories/GHSA-hx34-2pfw-2qfj
- https://github.com/mastodon/mastodon/security/advisories/GHSA-vwhj-3g83-v276
CVE-2026-72914 (CVSS: 7.5): A Mastodon statistics endpoint intended for
instance administrators was checking for the appropriate permissions before
returning the results, but not before computing them, allowing anyone to issue
potentially expensive requests.
CVE-2026-72915 (CVSS: 7.5): Mastodon versions 4.6.0 to 4.6.4 allow any
logged-in local user to access personally-identifying information about other
local-users due to an incorrect access control validation.
CVE-2026-72916 (CVSS: 6.3): By nature, Mastodon performs a lot of outbound
requests to user-provided domains. Mastodon however has some protection
mechanism to disallow requests to local IP addresses (unless specified in
ALLOWED_PRIVATE_ADDRESSES) to avoid the “confused deputy” problem. The list of
disallowed IP address ranges was lacking the IPv4-compatible IPv6 address
range that can be used to reach local IP addresses on specific configurations.
Vulnerabilities in #Mastodon
URL: https://github.com/mastodon/mastodon/security/advisories/GHSA-7jvv-fhmg-wpfw
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5
CVEs: CVE-2026-72914, CVE-2026-72915, CVE-2026-72916
See also:
- https://github.com/mastodon/mastodon/security/advisories/GHSA-hx34-2pfw-2qfj
- https://github.com/mastodon/mastodon/security/advisories/GHSA-vwhj-3g83-v276
CVE-2026-72914 (CVSS: 7.5): A Mastodon statistics endpoint intended for
instance administrators was checking for the appropriate permissions before
returning the results, but not before computing them, allowing anyone to issue
potentially expensive requests.
CVE-2026-72915 (CVSS: 7.5): Mastodon versions 4.6.0 to 4.6.4 allow any
logged-in local user to access personally-identifying information about other
local-users due to an incorrect access control validation.
CVE-2026-72916 (CVSS: 6.3): By nature, Mastodon performs a lot of outbound
requests to user-provided domains. Mastodon however has some protection
mechanism to disallow requests to local IP addresses (unless specified in
ALLOWED_PRIVATE_ADDRESSES) to avoid the “confused deputy” problem. The list of
disallowed IP address ranges was lacking the IPv4-compatible IPv6 address
range that can be used to reach local IP addresses on specific configurations.
🟠 CVE-2026-12234 - High (7.8)
The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsock_recvmsg() in subsys/net/lib/sockets/sockets.c snapshot the caller-supplied struct net_msghdr into a kernel-side copy with k_usermode_from_copy(), but then re-read the still-li...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12234/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-48765 (CRITICAL, CVSS 9.9): TypeBot.io <3.17.0 suffers from an auth bypass, letting read collaborators hijack OAuth credentials across workspaces. Upgrade to 3.17.0+ ASAP. https://radar.offseq.com/threat/cve-2026-48765-cwe-639-authorization-bypass-through-user-controlled-key-in-baptistearno-typebotio-a7be46425d0039c4 #OffSeq #CVE202648765 #TypeBot #OAuth #Security
##🔴 CVE-2026-48765 - Critical (9.9)
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from a readable bot configuration and then overwrite that credential through `handleUpdateOAuthCredent...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48765/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73247 - High (8.6)
Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/functions/HttpFunction.java passes the user-controlled http() uri argument to URI.create() and the server-side...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73247/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73234 - High (7.8)
FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, PropertyFileIncluded::Restore() in src/App/PropertyFile.cpp concatenates an attacker-controlled file or data attribute from Document.xml with the document trans...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73234/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73232 - High (7.5)
ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory denial of service because the response size guard in pkg/runner/simple.go checks only the compressed Content-Length while io.R...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73232/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73231 - High (7.8)
Faker generates massive amounts of fake data in the browser and Node.js. Prior to 10.5.0, the faker.helpers.fake method in src/modules/helpers/eval.ts allows attacker-controlled fake templates to access the Function constructor through fakeEval.re...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73231/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##