##
Updated at UTC 2026-10-09T09:27:55.802532
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-14992 | 9.8 | 0.00% | 1 | 0 | 2026-10-09T04:18:07.413000 | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0. | |
| CVE-2015-5477 | 7.5 | 91.28% | 2 | 8 | 2026-10-09T04:18:00.970000 | named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote | |
| CVE-2015-3306 | 10.0 | 96.75% | 2 | 18 | 2026-10-09T04:17:53.027000 | The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write t | |
| CVE-2026-77900 | 9.8 | 0.00% | 2 | 0 | 2026-10-09T00:31:56 | Missing authentication for critical function in Azure App Service allows an unau | |
| CVE-2026-88131 | 9.8 | 0.00% | 2 | 0 | 2026-10-09T00:31:56 | Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized | |
| CVE-2026-94510 | 9.9 | 0.00% | 2 | 0 | 2026-10-09T00:31:56 | Authorization bypass through user-controlled key in Microsoft Bookings allows an | |
| CVE-2026-96207 | 10.0 | 0.00% | 2 | 0 | 2026-10-09T00:31:56 | Improper certificate validation in Microsoft Partner Center allows an unauthoriz | |
| CVE-2026-84058 | 8.1 | 0.00% | 1 | 0 | 2026-10-09T00:31:56 | IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer over | |
| CVE-2026-84057 | 8.1 | 0.00% | 1 | 0 | 2026-10-09T00:31:56 | IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to e | |
| CVE-2026-84035 | 8.1 | 0.00% | 1 | 0 | 2026-10-09T00:31:56 | IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker | |
| CVE-2026-84875 | 7.5 | 0.00% | 1 | 0 | 2026-10-09T00:31:56 | IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker | |
| CVE-2026-84249 | 9.8 | 0.00% | 1 | 0 | 2026-10-09T00:31:56 | IBM Guardium Data Protection 12.2, and 12.2.2 could allow a remote attacker to e | |
| CVE-2026-89091 | 8.8 | 0.00% | 1 | 0 | 2026-10-09T00:31:56 | A flaw was found in ansible-core. When installing a collection with `ansible-gal | |
| CVE-2026-69435 | 9.6 | 0.00% | 2 | 0 | 2026-10-08T23:17:02.783000 | Missing authorization in Azure SRE Agent allows an authorized attacker to elevat | |
| CVE-2026-107406 | 0 | 0.00% | 9 | 3 | 2026-10-08T22:17:26.847000 | Memory overflow vulnerability leading to Remote Code Execution or Denial of Serv | |
| CVE-2026-11318 | 7.8 | 0.00% | 1 | 1 | 2026-10-08T21:35:53.890000 | Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com. | |
| CVE-2026-107701 | 8.2 | 0.00% | 1 | 0 | 2026-10-08T21:35:53.890000 | dot-access through 1.0.0 contains a prototype pollution vulnerability that allow | |
| CVE-2026-107376 | 8.2 | 0.00% | 1 | 0 | 2026-10-08T21:34:48.800000 | webonyx graphql-php is a PHP implementation of the GraphQL specification. Prior | |
| CVE-2026-104078 | 7.8 | 0.00% | 1 | 0 | 2026-10-08T21:33:42.423000 | Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bun | |
| CVE-2026-79842 | 9.1 | 0.00% | 3 | 0 | 2026-10-08T21:33:42 | An authentication bypass vulnerability exists in HPE Intelligent Management Cent | |
| CVE-2026-19482 | 8.8 | 0.00% | 1 | 0 | 2026-10-08T21:33:42 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-19491 | 9.1 | 0.00% | 1 | 0 | 2026-10-08T21:33:42 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-19493 | 7.5 | 0.00% | 1 | 0 | 2026-10-08T21:33:42 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-78401 | 9.8 | 0.00% | 1 | 0 | 2026-10-08T21:33:42 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-17189 | 8.2 | 0.00% | 1 | 0 | 2026-10-08T21:33:41 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-16916 | 9.1 | 0.00% | 1 | 0 | 2026-10-08T21:33:41 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-19494 | 8.1 | 0.00% | 1 | 0 | 2026-10-08T21:33:41 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-107779 | 9.8 | 0.00% | 1 | 0 | 2026-10-08T21:33:35 | Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains | |
| CVE-2026-84275 | 7.5 | 0.00% | 1 | 0 | 2026-10-08T21:33:34 | IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the GIM fil | |
| CVE-2026-107704 | 9.8 | 0.00% | 1 | 0 | 2026-10-08T21:33:34 | The image_optimizer Ruby gem 1.3.0 through 1.9.0 contains an OS command injectio | |
| CVE-2026-107703 | 9.8 | 0.00% | 1 | 0 | 2026-10-08T21:33:33 | @enmaso/node-convert through 1.0.0 contains an OS command injection vulnerabilit | |
| CVE-2026-107699 | 9.8 | 0.00% | 1 | 0 | 2026-10-08T21:33:33 | ppt2png through 0.0.6 contains an OS command injection vulnerability that allows | |
| CVE-2026-107700 | 9.8 | 0.00% | 1 | 0 | 2026-10-08T21:33:33 | dot-access 0.0.3 through 1.0.0 contains a code injection vulnerability that allo | |
| CVE-2026-107782 | 7.8 | 0.00% | 1 | 0 | 2026-10-08T21:33:32 | System Informer before 4.0.26241.138 contains an incorrect authorization vulnera | |
| CVE-2026-84244 | 9.3 | 0.00% | 1 | 0 | 2026-10-08T21:33:28 | IBM Guardium Data Protection 12.2 IBM Security Guardium Data Protection is vulne | |
| CVE-2026-84276 | 7.5 | 0.00% | 1 | 0 | 2026-10-08T21:33:26 | IBM Guardium Data Protection 12.2.2 is affected by a denial-of-service vulnerabi | |
| CVE-2026-95210 | 9.1 | 0.00% | 1 | 0 | 2026-10-08T21:33:23 | Improper certificate validation in gnutls v3.8.13 causes the application to acce | |
| CVE-2026-76281 | 5.3 | 0.15% | 1 | 0 | 2026-10-08T21:33:09 | Improper Access Control. Splunk addressed multiple internally identified vulnera | |
| CVE-2026-18740 | 8.8 | 0.00% | 1 | 0 | 2026-10-08T21:26:32.080000 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-16823 | 9.1 | 0.00% | 1 | 0 | 2026-10-08T21:26:32.080000 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-78406 | 9.8 | 0.00% | 1 | 0 | 2026-10-08T21:26:32.080000 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-62253 | 9.8 | 0.42% | 1 | 0 | 2026-10-08T21:09:00.643000 | Homer is open source telecom observability software. Prior to version 11.0.283, | |
| CVE-2026-82344 | 8.1 | 0.00% | 1 | 0 | 2026-10-08T20:49:50.083000 | IBM Guardium Data Protection 12.0, 12.1 is vulnerable to a heap-based buffer ove | |
| CVE-2026-107302 | 7.5 | 0.00% | 1 | 0 | 2026-10-08T20:48:36.970000 | msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6. | |
| CVE-2026-107295 | 7.6 | 0.00% | 1 | 0 | 2026-10-08T20:35:31.200000 | Pydantic AI is a Python agent framework for building applications and workflows | |
| CVE-2026-107212 | 7.5 | 0.34% | 1 | 0 | 2026-10-08T20:33:41.757000 | Excelize is a Go language library for reading and writing Microsoft Excel spread | |
| CVE-2026-107214 | 7.5 | 0.27% | 1 | 0 | 2026-10-08T20:33:41.757000 | Excelize is a Go language library for reading and writing Microsoft Excel spread | |
| CVE-2026-107383 | 7.5 | 0.00% | 1 | 0 | 2026-10-08T20:25:00.647000 | MariaDB Connector/Node.js is used to connect applications developed on Node.js t | |
| CVE-2026-107322 | 7.8 | 0.00% | 1 | 0 | 2026-10-08T20:17:31.590000 | An incomplete list of disallowed inputs in Amazon Agent Plugins for AWS database | |
| CVE-2026-20362 | 7.2 | 0.47% | 4 | 0 | 2026-10-08T20:08:45.857000 | A vulnerability in the web-based management interface of Cisco Finesse could all | |
| CVE-2026-76463 | 8.8 | 0.14% | 2 | 0 | 2026-10-08T20:08:45.857000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-76465 | 9.8 | 0.45% | 3 | 0 | 2026-10-08T20:08:45.857000 | A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) fea | |
| CVE-2026-76456 | 8.6 | 0.28% | 1 | 0 | 2026-10-08T20:08:45.857000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-76455 | 9.8 | 0.28% | 2 | 0 | 2026-10-08T20:08:45.857000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-76458 | 8.6 | 0.28% | 1 | 0 | 2026-10-08T20:08:45.857000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-76457 | 8.6 | 0.28% | 1 | 0 | 2026-10-08T20:08:45.857000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-76472 | 8.8 | 0.12% | 1 | 0 | 2026-10-08T20:08:45.857000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-76499 | 9.8 | 0.31% | 1 | 0 | 2026-10-08T20:08:45.857000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-76501 | 9.8 | 0.51% | 1 | 0 | 2026-10-08T20:08:45.857000 | A vulnerability in the Segment Routing over IPv6 (SRv6) Operation, Administratio | |
| CVE-2026-107384 | 8.1 | 0.00% | 1 | 0 | 2026-10-08T19:42:25 | ### Description With the non-default permitSetMultiParamEntries option enabled, | |
| CVE-2021-3199 | 9.8 | 8.21% | 2 | 0 | 2026-10-08T18:32:52 | Directory traversal with remote code execution can occur in /upload in ONLYOFFIC | |
| CVE-2026-107333 | 8.1 | 0.00% | 1 | 0 | 2026-10-08T18:32:39 | Malcolm's nginx based reverse proxy contains a URL path normalization inconsiste | |
| CVE-2026-104077 | 7.8 | 0.00% | 1 | 0 | 2026-10-08T18:32:31 | Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability th | |
| CVE-2026-105436 | 8.8 | 0.00% | 1 | 0 | 2026-10-08T18:32:31 | Deserialization of Untrusted Data vulnerability in MainWP MainWP Child mainwp-ch | |
| CVE-2026-107377 | 7.5 | 0.00% | 1 | 0 | 2026-10-08T17:58:02 | ## Summary When processing an attacker-controlled Protobuf schema, vulnerable v | |
| CVE-2026-107375 | 8.8 | 0.00% | 1 | 0 | 2026-10-08T17:40:37 | # SQL Injection in the `sort` Parameter of JHipster-Generated Reactive (WebFlux | |
| CVE-2026-107303 | 7.6 | 0.00% | 1 | 0 | 2026-10-08T17:40:32 | ## Summary Applications generated by generator-jhipster v9.2.0 can persist user- | |
| CVE-2026-107300 | 7.5 | 0.00% | 1 | 0 | 2026-10-08T17:40:07 | ### Impact The streaming decoder recursively invokes itself for every complete | |
| CVE-2026-107352 | 7.7 | 0.20% | 1 | 0 | 2026-10-08T17:26:22.830000 | Missing authorization checks in Amazon Athena engine version 3 request handling | |
| CVE-2026-92414 | 0 | 0.62% | 1 | 0 | 2026-10-08T17:26:22.830000 | : Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabb | |
| CVE-2026-17609 | 9.1 | 0.31% | 1 | 0 | 2026-10-08T17:24:11.230000 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to | |
| CVE-2026-107215 | 7.5 | 0.22% | 1 | 0 | 2026-10-08T16:31:27 | ### Summary `extractPart` allocates directly from the mscfb directory-entry siz | |
| CVE-2026-107216 | 7.5 | 0.31% | 1 | 0 | 2026-10-08T16:31:23 | ### Summary `ANCHORARRAY` (calc.go:15137 on current master) evaluates each cell | |
| CVE-2026-71895 | 7.1 | 0.17% | 1 | 0 | 2026-10-08T15:33:58 | An authorization vulnerability in Apache DolphinScheduler allows authenticated n | |
| CVE-2026-9209 | 9.8 | 0.00% | 1 | 1 | 2026-10-08T15:33:16 | mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulne | |
| CVE-2026-93017 | 7.7 | 0.00% | 1 | 0 | 2026-10-08T15:33:15 | The `insights-operator-gather` ClusterRole grants the operator's service account | |
| CVE-2026-14502 | 9.8 | 0.00% | 1 | 0 | 2026-10-08T15:33:10 | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0. | |
| CVE-2026-14497 | 8.1 | 0.00% | 1 | 0 | 2026-10-08T15:33:10 | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0. | |
| CVE-2026-15762 | 9.8 | 0.00% | 1 | 0 | 2026-10-08T15:33:07 | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0. | |
| CVE-2026-16340 | 9.8 | 0.00% | 2 | 0 | 2026-10-08T15:33:05 | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0. | |
| CVE-2026-107510 | 9.1 | 0.00% | 1 | 0 | 2026-10-08T15:32:55 | An authenticated high privilege user can inject arguments in troubleshooting com | |
| CVE-2026-71896 | 6.5 | 0.16% | 1 | 0 | 2026-10-08T15:32:55 | An authorization vulnerability in Apache DolphinScheduler allows authenticated u | |
| CVE-2024-50623 | 9.8 | 98.61% | 2 | 4 | 2026-10-08T10:35:08.200000 | In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5. | |
| CVE-2026-105110 | 9.8 | 2.79% | 1 | 0 | 2026-10-08T09:32:03 | OS Command Injection in the login.xgi CGI endpoint in Iskratel Innbox GPON ONT d | |
| CVE-2026-12260 | None | 0.23% | 1 | 0 | 2026-10-08T09:32:03 | SQL injection in the NetBoard CRM demo platform; specifically, the vulnerable co | |
| CVE-2026-107459 | 9.8 | 1.47% | 1 | 0 | 2026-10-08T06:31:28 | The SecuShare Pro developed by Openfind has an OS Command Injection vulnerabilit | |
| CVE-2026-102406 | 8.8 | 0.35% | 1 | 0 | 2026-10-08T04:17:08.777000 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana could lead | |
| CVE-2025-64393 | 0 | 0.36% | 3 | 0 | 2026-10-08T04:16:55.397000 | This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execu | |
| CVE-2026-107161 | 7.5 | 0.24% | 1 | 0 | 2026-10-07T21:33:37 | A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge( | |
| CVE-2026-76268 | 9.8 | 0.40% | 2 | 0 | 2026-10-07T21:33:30 | In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user w | |
| CVE-2026-76266 | 7.7 | 0.12% | 1 | 0 | 2026-10-07T21:33:30 | In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15 on Linux | |
| CVE-2026-107217 | 7.5 | 0.34% | 1 | 0 | 2026-10-07T20:23:32 | ### Summary `ColumnNameToNumber` (lib.go:220-237) accumulates the bijective bas | |
| CVE-2026-107219 | 7.5 | 0.34% | 1 | 0 | 2026-10-07T20:23:23 | Opening a file whose first eight bytes are the OLE magic number sends excelize d | |
| CVE-2026-76471 | 9.8 | 0.52% | 3 | 0 | 2026-10-07T18:32:21 | A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an una | |
| CVE-2026-76485 | 9.8 | 0.51% | 3 | 0 | 2026-10-07T18:32:21 | A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) fe | |
| CVE-2026-95606 | 9.8 | 0.33% | 2 | 0 | 2026-10-07T18:32:21 | Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Ev | |
| CVE-2026-76453 | 8.8 | 0.34% | 1 | 0 | 2026-10-07T18:32:21 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-76483 | 9.1 | 0.22% | 1 | 0 | 2026-10-07T18:32:21 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-96335 | 7.5 | 0.20% | 1 | 0 | 2026-10-07T18:32:21 | Missing Authorization vulnerability in WPMU DEV Forminator allows Exploiting Inc | |
| CVE-2026-76480 | 9.8 | 0.33% | 1 | 0 | 2026-10-07T18:32:21 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-76470 | 8.8 | 0.18% | 1 | 0 | 2026-10-07T18:32:21 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-76498 | 9.8 | 0.30% | 1 | 0 | 2026-10-07T18:32:21 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-76486 | 9.8 | 0.51% | 1 | 0 | 2026-10-07T18:32:21 | A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) fe | |
| CVE-2026-76484 | 8.8 | 0.28% | 1 | 0 | 2026-10-07T18:32:21 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-95534 | 8.8 | 0.29% | 1 | 0 | 2026-10-07T18:32:21 | Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited | |
| CVE-2026-95605 | 9.3 | 0.25% | 1 | 0 | 2026-10-07T18:32:21 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti | |
| CVE-2026-76467 | 7.5 | 0.25% | 2 | 0 | 2026-10-07T18:32:20 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-76464 | 9.6 | 0.19% | 2 | 0 | 2026-10-07T18:32:20 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-76454 | 9.1 | 0.58% | 1 | 0 | 2026-10-07T18:32:20 | A vulnerability in the Cisco Smart Licensing Utility API of Cisco License On-Pre | |
| CVE-2026-76459 | 8.8 | 0.28% | 1 | 0 | 2026-10-07T18:32:20 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-76468 | 8.2 | 0.23% | 1 | 0 | 2026-10-07T18:32:20 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-76482 | 10.0 | 0.20% | 2 | 0 | 2026-10-07T18:32:20 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-20328 | 9.1 | 0.52% | 2 | 0 | 2026-10-07T18:32:14 | A vulnerability in the web-based management interface of Cisco License On-Prem, | |
| CVE-2026-76500 | 9.8 | 0.33% | 1 | 0 | 2026-10-07T18:32:14 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-107206 | 9.4 | 0.58% | 1 | 0 | 2026-10-07T18:32:14 | LMCache through 0.5.5 contains a missing authentication vulnerability in the mul | |
| CVE-2026-107205 | 8.6 | 0.39% | 1 | 0 | 2026-10-07T18:32:14 | LMCache through 0.5.5 contains a missing authentication vulnerability in the mul | |
| CVE-2026-107204 | 9.8 | 0.77% | 1 | 0 | 2026-10-07T18:32:14 | LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerab | |
| CVE-2026-106510 | 7.7 | 0.44% | 1 | 0 | 2026-10-07T18:17:16.660000 | Backstage is an open framework for building developer portals. Prior to 1.14.6, | |
| CVE-2026-105192 | 9.8 | 0.48% | 3 | 1 | 2026-10-07T18:17:15.427000 | LMCache multiprocess mode, also called distributed mode, opens an unauthenticate | |
| CVE-2026-106558 | 8.8 | 0.47% | 1 | 0 | 2026-10-07T18:03:15 | ### Impact An attacker who can provide configuration to a TechDocs build may ex | |
| CVE-2026-102489 | 9.8 | 1.26% | 1 | 2 | 2026-10-07T18:03:07.387000 | Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability tha | |
| CVE-2026-106501 | 9.6 | 0.47% | 1 | 0 | 2026-10-07T17:59:20 | ### Impact An authenticated Backstage user who can read another user's Scaffold | |
| CVE-2026-102255 | 10.0 | 0.48% | 4 | 0 | 2026-10-07T16:17:32.440000 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Pla | |
| CVE-2026-62251 | 8.1 | 0.34% | 1 | 0 | 2026-10-07T16:13:09 | ### Summary The `V4StatisticsQuery` handler passes the user-supplied `rawquery` | |
| CVE-2026-62252 | 9.8 | 0.65% | 1 | 0 | 2026-10-07T16:12:03 | ### Summary On every fresh Homer deployment using internal authentication, the b | |
| CVE-2026-62176 | 9.1 | 0.46% | 1 | 0 | 2026-10-07T16:05:54 | ### Summary The `deploy/api.py` module generates Python server code by directly | |
| CVE-2026-16516 | 0 | 0.15% | 1 | 0 | 2026-10-07T16:02:27.613000 | wolfSSH does not validate that the ECDSA curve identifier in a KEXDH_REPLY host | |
| CVE-2026-77214 | 8.2 | 0.55% | 1 | 0 | 2026-10-07T15:32:08 | libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in | |
| CVE-2026-107181 | 8.1 | 0.34% | 2 | 0 | 2026-10-07T15:32:07 | Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnera | |
| CVE-2026-21589 | None | 1.77% | 18 | 10 | 2026-10-07T15:31:33 | h3. Summary This is a vulnerability in Bitbucket Data Center, Confluence Data C | |
| CVE-2026-96408 | 9.4 | 0.64% | 1 | 0 | 2026-10-07T12:32:00 | A code injection vulnerability exists in the upgrade script of Movable Type, whi | |
| CVE-2026-107104 | None | 0.42% | 1 | 0 | 2026-10-07T09:32:29 | This vulnerability exists in the ERP system due to unsafe deserialization of use | |
| CVE-2026-59346 | 9.3 | 0.26% | 2 | 1 | 2026-10-07T06:33:08 | VMware Workstation and Fusion contain an integer-overflow vulnerability. A malic | |
| CVE-2026-19572 | None | 0.37% | 1 | 0 | 2026-10-07T06:33:01 | A security vulnerability has been identified in FlexNet Publisher lmadmin. The v | |
| CVE-2026-83540 | None | 0.34% | 1 | 0 | 2026-10-07T03:30:31 | When password or public key authentication is used with the Windows port of wolf | |
| CVE-2026-14911 | None | 0.32% | 2 | 0 | 2026-10-07T03:30:31 | Improper Neutralization of Input During Web Page Generation (“Cross-site Scripti | |
| CVE-2026-19386 | None | 0.19% | 1 | 0 | 2026-10-07T03:30:23 | A stack-based buffer overflow in the ASUS router modules allows an authenticated | |
| CVE-2026-103007 | 7.2 | 0.34% | 1 | 0 | 2026-10-06T21:31:57 | Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalat | |
| CVE-2026-106382 | 9.6 | 0.40% | 1 | 0 | 2026-10-06T21:31:51 | Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a r | |
| CVE-2026-91140 | 9.6 | 1.92% | 1 | 0 | 2026-10-06T15:32:06 | An OS command injection vulnerability in the shell-based temporary-file cleanup | |
| CVE-2026-63277 | 0 | 0.14% | 1 | 1 | 2026-10-06T15:03:59.427000 | LibreOffice Calc can link a cell range to an external data source, and the link | |
| CVE-2026-79820 | 9.0 | 0.27% | 2 | 0 | 2026-10-05T18:34:22 | A remote user validation failure vulnerability exists in HPE Integrated Lights-O | |
| CVE-2026-88779 | 7.5 | 0.59% | 2 | 2 | 2026-10-05T13:35:24.663000 | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: b | |
| CVE-2026-53359 | 8.8 | 0.98% | 1 | 7 | 2026-10-03T12:32:07 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: F | |
| CVE-2026-96940 | 8.8 | 0.50% | 1 | 1 | 2026-10-02T21:32:13 | Weak authorization in Microsoft Exchange Server allows an authenticated attacker | |
| CVE-2026-88771 | 9.8 | 1.08% | 4 | 14 | 2026-09-29T04:18:01.603000 | Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetSc | |
| CVE-2026-77516 | 5.4 | 0.24% | 1 | 0 | 2026-09-28T21:17:18.890000 | MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through | |
| CVE-2026-54915 | 5.4 | 0.26% | 1 | 0 | 2026-09-24T23:17:11.303000 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. P | |
| CVE-2026-94504 | 7.2 | 0.41% | 1 | 0 | 2026-09-22T19:04:55.677000 | Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it wit | |
| CVE-2026-77520 | 5.4 | 0.23% | 1 | 0 | 2026-09-22T16:17:54.987000 | MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, | |
| CVE-2026-79317 | 4.8 | 0.29% | 1 | 0 | 2026-09-22T15:33:35 | A session invalidation flaw exists in x-ui 0.3.2. The full user object is stored | |
| CVE-2026-93836 | 7.2 | 0.24% | 1 | 0 | 2026-09-22T09:31:18 | The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to St | |
| CVE-2026-94572 | None | 0.53% | 1 | 0 | 2026-09-21T21:32:02 | In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate | |
| CVE-2026-82165 | 5.5 | 0.13% | 1 | 0 | 2026-09-21T21:32:00 | Dell Command | Integration Suite for System Center, versions prior to 6.7.2, con | |
| CVE-2026-85046 | 8.8 | 48.88% | 1 | 8 | 2026-09-21T13:17:10.970000 | Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote at | |
| CVE-2026-93485 | 7.1 | 0.38% | 2 | 4 | 2026-09-19T15:17:08.323000 | Improper neutralization of input during web page generation ('cross-site scripti | |
| CVE-2026-87491 | 8.8 | 3.14% | 1 | 2 | 2026-09-09T21:31:35 | Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remo | |
| CVE-2026-23870 | 7.5 | 1.53% | 1 | 2 | 2026-08-12T15:51:57.517000 | A denial of service vulnerability could be triggered by sending specially crafte | |
| CVE-2026-47483 | 8.2 | 0.55% | 1 | 0 | 2026-07-28T18:33:11 | NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pp | |
| CVE-2025-41691 | 7.5 | 0.55% | 1 | 0 | 2026-06-17T09:22:58.030000 | An unauthenticated remote attacker may trigger a NULL pointer dereference in the | |
| CVE-2026-10520 | 10.0 | 99.91% | 2 | 9 | 2026-06-11T21:31:50 | An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6 | |
| CVE-2025-41739 | 5.9 | 0.35% | 1 | 0 | 2025-12-01T12:30:34 | An unauthenticated remote attacker, who beats a race condition, can exploit a fl | |
| CVE-2025-41738 | 7.5 | 0.39% | 1 | 0 | 2025-12-01T12:30:33 | An unauthenticated remote attacker may cause the visualisation server of the COD | |
| CVE-2025-41659 | 8.3 | 0.22% | 1 | 0 | 2025-08-04T09:30:34 | A low-privileged attacker can remotely access the PKI folder of the CODESYS Cont | |
| CVE-2023-22894 | 7.5 | 1.66% | 2 | 2 | 2023-11-07T05:05:45 | ### Summary Strapi through 4.7.1 allows unauthenticated attackers to discover s | |
| CVE-2016-3081 | 8.1 | 93.35% | 2 | 0 | template | 2023-11-01T19:47:30 | Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when |
| CVE-2026-77525 | 0 | 0.19% | 1 | 0 | N/A | ||
| CVE-2026-77518 | 0 | 0.27% | 1 | 0 | N/A | ||
| CVE-2026-72898 | 0 | 19.05% | 3 | 10 | template | N/A | |
| CVE-2026-106433 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-107332 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-77459 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-101027 | 0 | 0.17% | 1 | 0 | N/A | ||
| CVE-2026-103059 | 0 | 0.28% | 1 | 0 | N/A | ||
| CVE-2026-103416 | 0 | 0.21% | 1 | 0 | N/A |
updated 2026-10-09T04:18:07.413000
1 posts
🔴 CVE-2026-14992 - Critical (9.8)
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 vulnerable to buffer overflow.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14992/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T04:18:00.970000
2 posts
8 repos
https://github.com/hmlio/vaas-cve-2015-5477
https://github.com/robertdavidgraham/cve-2015-5477
https://github.com/knqyf263/cve-2015-5477
https://github.com/xycloops123/TKEY-remote-DoS-vulnerability-exploit
https://github.com/likekabin/ShareDoc_cve-2015-5477
https://github.com/ilanyu/cve-2015-5477
🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:1008)
CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3306 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3306)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: http://www.proftpd.org/ ; https://lists.debian.org/debian-security-announce/2015/msg00154.html ; https://lists.opensuse.org/archives/list/updates@lists.opensuse.org/message/WE6YZRG5UVXMGQ7IVDRYBPIWV4M6UUGM/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3306
⚠️ CVE-2015-5477 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5477)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://web.archive.org/web/20150729014733/https://kb.isc.org/article/AA-01272 ; https://access.redhat.com/errata/RHSA-2015:1513.html; https://supportportal.juniper.net/s/article/2016-01-Security-Bulletin-Junos-Vulnerability-in-ISC-BIND-named-CVE-2015-5477 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5477
⚠️ CVE-2016-3081 (https://secdb.nttzen.cloud/cve/detail/CVE-2016-3081)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://cwiki.apache.org/confluence/display/WW/S2-032 ; ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2016-3081
⚠️ CVE-2021-3199 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-3199)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://github.com/ONLYOFFICE/DocumentServer/blob/903fe5ab7a275bd69c3c3346af2d21cf87ebeabf/CHANGELOG.md#563 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-3199
⚠️ CVE-2023-22894 (https://secdb.nttzen.cloud/cve/detail/CVE-2023-22894)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://strapi.io/blog/security-disclosure-of-vulnerabilities-cve ; https://github.com/strapi/strapi/releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2023-22894
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261008 #cisa20261008 #cve_2015_3306 #cve_2015_5477 #cve_2016_3081 #cve_2021_3199 #cve_2023_22894 #cve20153306 #cve20155477 #cve20163081 #cve20213199 #cve202322894
##CVE ID: CVE-2015-5477
Vendor: ISC
Product: BIND
Date Added: 2026-10-08
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2015-5477
updated 2026-10-09T04:17:53.027000
2 posts
18 repos
https://github.com/0xm4ud/ProFTPD_CVE-2015-3306
https://github.com/diegslva/cve-2015-3306-lab
https://github.com/jptr218/proftpd_bypass
https://github.com/bcononugbor-source/OpenVAS-Vulnerability-Analysis-Incident-Response-Report
https://github.com/xyk0x/cpx_proftpd
https://github.com/cdedmondson/Modified-CVE-2015-3306-Exploit
https://github.com/davidtavarez/CVE-2015-3306
https://github.com/canpilayda/proftpd-mod_copy-cve-2015-3306
https://github.com/donmedfor/CVE-2015-3306
https://github.com/hackarada/cve-2015-3306
https://github.com/t0kx/exploit-CVE-2015-3306
https://github.com/cd6629/CVE-2015-3306-Python-PoC
https://github.com/cybersensei-EH/hackviser_labs_CVE-2015-3306
https://github.com/JoseLRC97/ProFTPd-1.3.5-mod_copy-Remote-Command-Execution
https://github.com/nootropics/propane
https://github.com/cved-sources/cve-2015-3306
🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:1008)
CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3306 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3306)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: http://www.proftpd.org/ ; https://lists.debian.org/debian-security-announce/2015/msg00154.html ; https://lists.opensuse.org/archives/list/updates@lists.opensuse.org/message/WE6YZRG5UVXMGQ7IVDRYBPIWV4M6UUGM/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3306
⚠️ CVE-2015-5477 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5477)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://web.archive.org/web/20150729014733/https://kb.isc.org/article/AA-01272 ; https://access.redhat.com/errata/RHSA-2015:1513.html; https://supportportal.juniper.net/s/article/2016-01-Security-Bulletin-Junos-Vulnerability-in-ISC-BIND-named-CVE-2015-5477 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5477
⚠️ CVE-2016-3081 (https://secdb.nttzen.cloud/cve/detail/CVE-2016-3081)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://cwiki.apache.org/confluence/display/WW/S2-032 ; ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2016-3081
⚠️ CVE-2021-3199 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-3199)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://github.com/ONLYOFFICE/DocumentServer/blob/903fe5ab7a275bd69c3c3346af2d21cf87ebeabf/CHANGELOG.md#563 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-3199
⚠️ CVE-2023-22894 (https://secdb.nttzen.cloud/cve/detail/CVE-2023-22894)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://strapi.io/blog/security-disclosure-of-vulnerabilities-cve ; https://github.com/strapi/strapi/releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2023-22894
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261008 #cisa20261008 #cve_2015_3306 #cve_2015_5477 #cve_2016_3081 #cve_2021_3199 #cve_2023_22894 #cve20153306 #cve20155477 #cve20163081 #cve20213199 #cve202322894
##CVE ID: CVE-2015-3306
Vendor: ProFTPD
Product: ProFTPD
Date Added: 2026-10-08
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2015-3306
updated 2026-10-09T00:31:56
2 posts
Microsoft Azure App Service for Linux hit by CVE-2026-77900 (CRITICAL, CVSS 9.8): missing authentication enables unauthenticated remote code execution. Patch released — update now. https://radar.offseq.com/threat/cve-2026-77900-cwe-306-missing-authentication-for-critical-function-in-microsoft-azure-app-service-for-806c7a8fa62ffe41 #OffSeq #Azure #CVE202677900 #Infosec #CloudSecurity
##Microsoft Azure App Service for Linux hit by CVE-2026-77900 (CRITICAL, CVSS 9.8): missing authentication enables unauthenticated remote code execution. Patch released — update now. https://radar.offseq.com/threat/cve-2026-77900-cwe-306-missing-authentication-for-critical-function-in-microsoft-azure-app-service-for-806c7a8fa62ffe41 #OffSeq #Azure #CVE202677900 #Infosec #CloudSecurity
##updated 2026-10-09T00:31:56
2 posts
Microsoft Dataverse is affected by CVE-2026-88131 (CRITICAL, CVSS 9.8): deserialization of untrusted data allows unauthenticated RCE. Patch available — apply ASAP! https://radar.offseq.com/threat/cve-2026-88131-cwe-502-deserialization-of-untrusted-data-in-microsoft-microsoft-dataverse-eba5097c3e4671bb #OffSeq #CVE202688131 #Microsoft #RCE #Infosec
##Microsoft Dataverse is affected by CVE-2026-88131 (CRITICAL, CVSS 9.8): deserialization of untrusted data allows unauthenticated RCE. Patch available — apply ASAP! https://radar.offseq.com/threat/cve-2026-88131-cwe-502-deserialization-of-untrusted-data-in-microsoft-microsoft-dataverse-eba5097c3e4671bb #OffSeq #CVE202688131 #Microsoft #RCE #Infosec
##updated 2026-10-09T00:31:56
2 posts
CVE-2026-94510 (CRITICAL, CVSS 9.9) in Microsoft Bookings enables remote privilege escalation via authorization bypass (CWE-639). Apply the official Microsoft patch now: https://radar.offseq.com/threat/cve-2026-94510-cwe-639-authorization-bypass-through-user-controlled-key-in-microsoft-microsoft-bookings-0e362c50ebe161b6 #OffSeq #Microsoft #Vuln #CVE #Infosec
##CVE-2026-94510 (CRITICAL, CVSS 9.9) in Microsoft Bookings enables remote privilege escalation via authorization bypass (CWE-639). Apply the official Microsoft patch now: https://radar.offseq.com/threat/cve-2026-94510-cwe-639-authorization-bypass-through-user-controlled-key-in-microsoft-microsoft-bookings-0e362c50ebe161b6 #OffSeq #Microsoft #Vuln #CVE #Infosec
##updated 2026-10-09T00:31:56
2 posts
CVE-2026-96207 (CRITICAL, CVSS 10) affects Microsoft Partner Center: improper certificate validation (CWE-295) allows remote privilege escalation. Patch available — apply ASAP. No public exploits seen. https://radar.offseq.com/threat/cve-2026-96207-cwe-295-improper-certificate-validation-in-microsoft-microsoft-partner-center-0f13dc5f1a15e1f3 #OffSeq #Microsoft #CVE202696207 #Infosec
##CVE-2026-96207 (CRITICAL, CVSS 10) affects Microsoft Partner Center: improper certificate validation (CWE-295) allows remote privilege escalation. Patch available — apply ASAP. No public exploits seen. https://radar.offseq.com/threat/cve-2026-96207-cwe-295-improper-certificate-validation-in-microsoft-microsoft-partner-center-0f13dc5f1a15e1f3 #OffSeq #Microsoft #CVE202696207 #Infosec
##updated 2026-10-09T00:31:56
1 posts
🟠 CVE-2026-84058 - High (8.1)
IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer overrun in the TDS (Microsoft SQL Server) PRELOGIN packet decoder. A remote attacker who can send a specially crafted TDS PRELOGIN packet to a network monitored by an IBM...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84058/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T00:31:56
1 posts
🟠 CVE-2026-84057 - High (8.1)
IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84057/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T00:31:56
1 posts
🟠 CVE-2026-84035 - High (8.1)
IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84035/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T00:31:56
1 posts
🟠 CVE-2026-84875 - High (7.5)
IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84875/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T00:31:56
1 posts
🔴 CVE-2026-84249 - Critical (9.8)
IBM Guardium Data Protection 12.2, and 12.2.2 could allow a remote attacker to execute arbitrary management operations due to missing authentication for critical function.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84249/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T00:31:56
1 posts
🟠 CVE-2026-89091 - High (8.8)
A flaw was found in ansible-core. When installing a collection with
`ansible-galaxy collection install`, the archive extractor validates member
paths using lexical path normalisation (os.path.abspath) instead of resolving
symbolic links (os.path.r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89091/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T23:17:02.783000
2 posts
CVE-2026-69435: CRITICAL SSRF (CVSS 9.6) in Microsoft Azure SRE Agent. Missing authorization controls let authorized attackers escalate privileges, risking confidentiality & integrity. Microsoft has issued a fix. https://radar.offseq.com/threat/cve-2026-69435-cwe-918-server-side-request-forgery-ssrf-in-microsoft-azure-sre-agent-10f6e62769899cfe #OffSeq #Azure #SSRF #Infosec
##CVE-2026-69435: CRITICAL SSRF (CVSS 9.6) in Microsoft Azure SRE Agent. Missing authorization controls let authorized attackers escalate privileges, risking confidentiality & integrity. Microsoft has issued a fix. https://radar.offseq.com/threat/cve-2026-69435-cwe-918-server-side-request-forgery-ssrf-in-microsoft-azure-sre-agent-10f6e62769899cfe #OffSeq #Azure #SSRF #Infosec
##updated 2026-10-08T22:17:26.847000
9 posts
3 repos
https://github.com/techupdate24/citrix-netscaler-rce-cve-2026-107406
https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker
Citrix Warns of Immediate Patching Need for NetScaler RCE Flaw
Citrix is sounding the alarm on a critical vulnerability, CVE-2026-107406, that can lead to remote code execution or a denial-of-service state in NetScaler devices - and it's urging admins to patch immediately.
#Citrix #Netscaler #Cve2026107406 #RemoteCodeExecution #DenialOfService
##Citrix has urged customers to update NetScaler ADC and Gateway for CVE-2026-107406, a serious flaw that could allow remote code execution or service disruption.
For versions 14.1-73.37–14.1-73.41 and 13.1-64.23–13.1-64.28, exposure applies when configured as a SAML IdP; older supported releases may also be affected when configured as a SAML SP or IdP.
For the standard 14.1 and 13.1 branches, fixed releases are 14.1-73.46+ and 1…
https://en.hacks.gr/i-citrix-zita-enimerosi-gia-to-netscaler-meta-apo-sovaro-provlima-asfaleias/
##Critical Citrix NetScaler vulnerability CVE-2026-107406 (CVSS 9.5) can lead to RCE on SAML-configured ADC and Gateway. Upgrade now.
#Citrix #NetScaler #NetScalerGateway #CVE2026107406 #SAML #RCE #PatchNow #Vulnerability
##I thought it was a Sunday because Citrix posted another yet another NetScaler security advisory:
CVE-2026-107406 (9.5 critical) pre-auth memory overflow > RCE or DoS
As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability.
https://support.citrix.com/external/article/CTX697191
https://community.citrix.com/techzone-blogs/110_security-updates/protecting-customers-immediate-guidance-for-cve-2026-107406-in-netscaler-adc-and-netscaler-gateway-r1631/
Critical Citrix NetScaler vulnerability CVE-2026-107406 (CVSS 9.5) can lead to RCE on SAML-configured ADC and Gateway. Upgrade now.
#Citrix #NetScaler #NetScalerGateway #CVE2026107406 #SAML #RCE #PatchNow #Vulnerability
##I thought it was a Sunday because Citrix posted another yet another NetScaler security advisory:
CVE-2026-107406 (9.5 critical) pre-auth memory overflow > RCE or DoS
As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability.
https://support.citrix.com/external/article/CTX697191
https://community.citrix.com/techzone-blogs/110_security-updates/protecting-customers-immediate-guidance-for-cve-2026-107406-in-netscaler-adc-and-netscaler-gateway-r1631/
There’s yet another Citrix Netscaler vuln (new patch today) which allows unauth RCE - CVE-2026-107406
Same attack surface (SAML) as two of the other vulns exploited in the wild during the past month.
##@GossiTheDog https://community.citrix.com/techzone-blogs/110_security-updates/protecting-customers-immediate-guidance-for-cve-2026-107406-in-netscaler-adc-and-netscaler-gateway-r1631/
They did it again :D
##I'm tired, boss.
A new #Citrix CVE affecting SAML IdP/SP-configured devices is out.
https://ifin.network/t/cve-2026-107406-somehow-another-citrix-netscaler-saml-vulnerability/891
##updated 2026-10-08T21:35:53.890000
1 posts
1 repos
🟠 CVE-2026-11318 - High (7.8)
Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com.deskin.service.installer XPC service that allows local unprivileged attackers to execute arbitrary installer packages as root by connecting to the root-owned service w...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-11318/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:35:53.890000
1 posts
🟠 CVE-2026-107701 - High (8.2)
dot-access through 1.0.0 contains a prototype pollution vulnerability that allows attackers to modify Object.prototype by supplying a crafted dotted path to set(). Attackers controlling the path, such as through user-supplied field names, can use ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107701/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:34:48.800000
1 posts
🟠 CVE-2026-107376 - High (8.2)
webonyx graphql-php is a PHP implementation of the GraphQL specification. Prior to 15.32.3, GraphQL\Language\Parser performs recursive descent without a recursion limit in parseSelectionSet, parseValueLiteral, and parseTypeReference. A remote atta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107376/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:42.423000
1 posts
🟠 CVE-2026-104078 - High (7.8)
Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute arbitrary code by embedding a crafted \href value with a TAB byte in the URL scheme, causing filterU...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-104078/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:42
3 posts
HPE fixes a critical HPE iLO 7 vulnerability, CVE-2026-79820, and iMC authentication bypass CVE-2026-79842. Update iLO to 1.25.01 now.
#HPE #iLO #iMC #CVE202679820 #CVE202679842 #AuthBypass #ServerSecurity #Vulnerability
##HPE fixes a critical HPE iLO 7 vulnerability, CVE-2026-79820, and iMC authentication bypass CVE-2026-79842. Update iLO to 1.25.01 now.
#HPE #iLO #iMC #CVE202679820 #CVE202679842 #AuthBypass #ServerSecurity #Vulnerability
##🔴 CVE-2026-79842 - Critical (9.1)
An authentication bypass vulnerability exists in HPE Intelligent Management Center (iMC) prior to v7.3 E0713
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79842/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:42
1 posts
🟠 CVE-2026-19482 - High (8.8)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of command arguments.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19482/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:42
1 posts
🔴 CVE-2026-19491 - Critical (9.1)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to bypass authentication due to improper authentication.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19491/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:42
1 posts
🟠 CVE-2026-19493 - High (7.5)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to perform an arbitrary file write due to path traversal.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19493/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:42
1 posts
🔴 CVE-2026-78401 - Critical (9.8)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78401/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:41
1 posts
🟠 CVE-2026-17189 - High (8.2)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI thus alt...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17189/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:41
1 posts
🔴 CVE-2026-16916 - Critical (9.1)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to execute arbitrary code due to a protection mechanism failure.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16916/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:41
1 posts
🟠 CVE-2026-19494 - High (8.1)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19494/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:35
1 posts
🔴 CVE-2026-107779 - Critical (9.8)
Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a missing authentication vulnerability in bundled xxl-job-admin JobInfoController endpoints annotated with @PermissionLimit(limit = false). Unauthenticated attackers c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107779/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:34
1 posts
🟠 CVE-2026-84275 - High (7.5)
IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the GIM file-upload functionality. An unauthenticated attacker could exploit this vulnerability to write arbitrary files to the Collector.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84275/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:34
1 posts
🔴 CVE-2026-107704 - Critical (9.8)
The image_optimizer Ruby gem 1.3.0 through 1.9.0 contains an OS command injection vulnerability in ImageOptimizer#identify_format that allows attackers to execute commands by supplying a crafted image path when the identify option is enabled. Atta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107704/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:33
1 posts
🔴 CVE-2026-107703 - Critical (9.8)
@enmaso/node-convert through 1.0.0 contains an OS command injection vulnerability in convert.js that allows attackers to execute shell commands via unsanitized filepath and convertTo arguments. Attackers can inject shell metacharacters or a single...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107703/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:33
1 posts
🔴 CVE-2026-107699 - Critical (9.8)
ppt2png through 0.0.6 contains an OS command injection vulnerability that allows attackers to execute operating system commands by supplying unsanitized input or output path arguments. Attackers can append shell metacharacters such as ';' to file ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107699/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:33
1 posts
🔴 CVE-2026-107700 - Critical (9.8)
dot-access 0.0.3 through 1.0.0 contains a code injection vulnerability that allows remote attackers to execute JavaScript by supplying crafted paths to get(). The path is concatenated into a new Function body in index.js, so attackers can reach co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107700/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:32
1 posts
🟠 CVE-2026-107782 - High (7.8)
System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc helper that allows local attackers to reach privileged APIs by connecting from any Authenticode-signed process. Attackers can load code into a Micr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107782/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:28
1 posts
🔴 CVE-2026-84244 - Critical (9.3)
IBM Guardium Data Protection 12.2 IBM Security Guardium Data Protection is vulnerable to stored cross-site scripting (XSS) in the Quick Search results grid. An unauthenticated attacker who can influence monitored database traffic could execute mal...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84244/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:26
1 posts
🟠 CVE-2026-84276 - High (7.5)
IBM Guardium Data Protection 12.2.2 is affected by a denial-of-service vulnerability in the edge-controller. An unauthenticated remote attacker with network access to the edge-controller gRPC service can provide malformed task data that triggers a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84276/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:23
1 posts
🔴 CVE-2026-95210 - Critical (9.1)
Improper certificate validation in gnutls v3.8.13 causes the application to accept certificates containing invalid extensions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-95210/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:09
1 posts
Splunk fixes 22 Splunk Enterprise vulnerabilities, including critical Patroni API flaw CVE-2026-76268 and CVE-2026-76281. Upgrade to 10.4.3 now.
#Splunk #SplunkEnterprise #SIEM #CVE202676268 #CVE202676281 #RCE #PatchNow #Vulnerability
##updated 2026-10-08T21:26:32.080000
1 posts
🟠 CVE-2026-18740 - High (8.8)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to perform unauthorized actions due to argument injection.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18740/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:26:32.080000
1 posts
🔴 CVE-2026-16823 - Critical (9.1)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to bypass security restrictions due to improper authentication.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16823/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:26:32.080000
1 posts
🔴 CVE-2026-78406 - Critical (9.8)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78406/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:09:00.643000
1 posts
🔴 CVE-2026-62253 - Critical (9.8)
Homer is open source telecom observability software. Prior to version 11.0.283, both JWT middleware functions (`JWTMiddleware` and `JWTMiddlewareV4`) immediately return `next(c)` when `jwtSecret == ""`. The JWT secret defaults to an empty string. ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62253/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T20:49:50.083000
1 posts
🟠 CVE-2026-82344 - High (8.1)
IBM Guardium Data Protection 12.0, 12.1 is vulnerable to a heap-based buffer overflow in the S-TAP TrafficTap TDS login reassembly functionality. An unauthenticated remote attacker can send crafted TDS login fragments that exceed the fixed-size r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82344/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T20:48:36.970000
1 posts
🟠 CVE-2026-107302 - High (7.5)
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the decoder reads the four-byte length of a map32 value before validating that the complete five-byte header is available. A truncated map32 header therefore caus...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107302/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T20:35:31.200000
1 posts
🟠 CVE-2026-107295 - High (7.6)
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 1.107.4 and 2.28.0, the Agent.to_web() and clai web development chat endpoint has missing request content-type validation. A webs...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107295/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T20:33:41.757000
1 posts
🟠 CVE-2026-107212 - High (7.5)
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, Rows.Columns accepts a look-ahead row number above TotalRows without applying the limit enforced by Rows.Next. File.GetRows relies on Row...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107212/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T20:33:41.757000
1 posts
🟠 CVE-2026-107214 - High (7.5)
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, the decryption dispatch performs insufficient structural and parameter validation before standard and agile decryptors slice, index, allo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107214/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T20:25:00.647000
1 posts
🟠 CVE-2026-107383 - High (7.5)
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4, the GeoJSON Polygon and MultiPolygon binary encoders size a Buffer.allocUnsafe() allocation fro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107383/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T20:17:31.590000
1 posts
🟠 CVE-2026-107322 - High (7.8)
An incomplete list of disallowed inputs in Amazon Agent Plugins for AWS databases-on-aws plugin before 1.7.1 might allow a remote unauthenticated actor to execute arbitrary operating system commands on the host running the helper via a crafted dat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107322/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T20:08:45.857000
4 posts
SANS Stormcast Friday, October 9th, 2026: AI Agent Forensics; AI-Assisted Attack on South Korean Banks; IDN Typosquatting; Cisco Finesse SSRF (CVE-2026-20362)
https://isc.sans.edu/podcastdetail/10130
SANS Stormcast Friday, October 9th, 2026: AI Agent Forensics; AI-Assisted Attack on South Korean Banks; IDN Typosquatting; Cisco Finesse SSRF (CVE-2026-20362)
https://isc.sans.edu/podcastdetail/10130
A Cisco Finesse vulnerability, SSRF flaw CVE-2026-20362, has been publicly disclosed. Fixes arrive in early 2027, with no workarounds.
#Cisco #CiscoFinesse #ContactCenter #CVE202620362 #SSRF #Horizon3 #UnifiedCCX #Vulnerability
##There are 14 Cisco security advisories that came out today. https://sec.cloudapps.cisco.com/security/center/publicationListing.x
A lot of 9.8 and even 10.0 across multiple products. While there's no mention of exploitation, there's zero-day disclosure pre-patch for Cisco Finesse Server-Side Request Forgery Vulnerability CVE-2026-20362 (7.2)
##The Cisco PSIRT is aware that a public announcement is available for the vulnerability that is described in this advisory.
updated 2026-10-08T20:08:45.857000
2 posts
Two more Cisco advisories today addressing critical vulnerabilities:
- CVE-2026-76471: Cisco NX-OS Software NX-API Remote Code Execution Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-napi-rce-r2shwu2j
- CVE-2026-76463, CVE-2026-76464, and CVE-2026-76467: Cisco Meraki Security Hardening Release: October 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-meraki-os-drbEX9GH @TalosSecurity #infosec #Cisco #vulnerability
##🟠 CVE-2026-76463 - High (8.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses mult...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76463/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T20:08:45.857000
3 posts
CVE-2026-76465 (CRITICAL, CVSS 9.8) in Cisco NX-OS for Nexus 3000/9000: Remote, unauthenticated attackers can gain root or cause DoS via crafted MPLS echo-requests. Patch status unknown — check Cisco advisories. https://radar.offseq.com/threat/a-vulnerability-in-the-mpls-operation-administration-and-maintenance-oam-feature-of-cisco-nx-os-d888a485aa841e27 #OffSeq #Cisco #Vulnerability #CVE202676465
##🔴 CVE-2026-76465 - Critical (9.8)
A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute arbit...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76465/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Four critical Cisco Nexus vulnerabilities, including CVE-2026-76485 and CVE-2026-76465 (CVSS 9.8), allow root RCE on NX-OS switches. Patch now.
#Cisco #Nexus #NXOS #CVE202676485 #CVE202676465 #RCE #NetworkSecurity #Vulnerability
##updated 2026-10-08T20:08:45.857000
1 posts
🟠 CVE-2026-76456 - High (8.6)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76456/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T20:08:45.857000
2 posts
🔴 CVE-2026-76455 - Critical (9.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76455/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Cisco NX-OS vulnerabilities fixed, including critical NX-API RCE flaw CVE-2026-76471 and CVE-2026-76455, across Nexus, MDS and UCS gear. Patch now.
#Cisco #NXOS #Nexus #CVE202676471 #CVE202676455 #RCE #NetworkSecurity #Vulnerability
##updated 2026-10-08T20:08:45.857000
1 posts
🟠 CVE-2026-76458 - High (8.6)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76458/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T20:08:45.857000
1 posts
🟠 CVE-2026-76457 - High (8.6)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76457/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T20:08:45.857000
1 posts
🟠 CVE-2026-76472 - High (8.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multipl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76472/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T20:08:45.857000
1 posts
🔴 CVE-2026-76499 - Critical (9.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in softwar...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76499/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T20:08:45.857000
1 posts
🔴 CVE-2026-76501 - Critical (9.8)
A vulnerability in the Segment Routing over IPv6 (SRv6) Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privilege...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76501/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T19:42:25
1 posts
🟠 CVE-2026-107384 - High (8.1)
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. From 3.2.0 until 3.2.5, 3.3.4, 3.4.7, and 3.5.4, applications that enable permitSetMultiParamEntries can pass objects whose keys are exp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107384/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T18:32:52
2 posts
🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:1008)
CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3306 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3306)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: http://www.proftpd.org/ ; https://lists.debian.org/debian-security-announce/2015/msg00154.html ; https://lists.opensuse.org/archives/list/updates@lists.opensuse.org/message/WE6YZRG5UVXMGQ7IVDRYBPIWV4M6UUGM/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3306
⚠️ CVE-2015-5477 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5477)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://web.archive.org/web/20150729014733/https://kb.isc.org/article/AA-01272 ; https://access.redhat.com/errata/RHSA-2015:1513.html; https://supportportal.juniper.net/s/article/2016-01-Security-Bulletin-Junos-Vulnerability-in-ISC-BIND-named-CVE-2015-5477 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5477
⚠️ CVE-2016-3081 (https://secdb.nttzen.cloud/cve/detail/CVE-2016-3081)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://cwiki.apache.org/confluence/display/WW/S2-032 ; ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2016-3081
⚠️ CVE-2021-3199 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-3199)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://github.com/ONLYOFFICE/DocumentServer/blob/903fe5ab7a275bd69c3c3346af2d21cf87ebeabf/CHANGELOG.md#563 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-3199
⚠️ CVE-2023-22894 (https://secdb.nttzen.cloud/cve/detail/CVE-2023-22894)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://strapi.io/blog/security-disclosure-of-vulnerabilities-cve ; https://github.com/strapi/strapi/releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2023-22894
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261008 #cisa20261008 #cve_2015_3306 #cve_2015_5477 #cve_2016_3081 #cve_2021_3199 #cve_2023_22894 #cve20153306 #cve20155477 #cve20163081 #cve20213199 #cve202322894
##CVE ID: CVE-2021-3199
Vendor: ONLYOFFICE
Product: Docs
Date Added: 2026-10-08
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2021-3199
updated 2026-10-08T18:32:39
1 posts
🟠 CVE-2026-107333 - High (8.1)
Malcolm's nginx based reverse proxy contains a URL path normalization inconsistency between its Lua based role-based access control (RBAC) authorization layer and nginx's own request routing logic. An authenticated user can craft a specially forma...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107333/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T18:32:31
1 posts
🟠 CVE-2026-104077 - High (7.8)
Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability that allows attackers to craft malicious Markdown notes exploiting insufficient sanitization of the data-background-iframe attribute, which bypasses DOMPurify and is pro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-104077/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T18:32:31
1 posts
🟠 CVE-2026-105436 - High (8.8)
Deserialization of Untrusted Data vulnerability in MainWP MainWP Child mainwp-child allows Object Injection.This issue affects MainWP Child: from n/a through 6.2.1.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-105436/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T17:58:02
1 posts
🟠 CVE-2026-107377 - High (7.5)
datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.81.0, an attacker-controlled Protobuf schema can supply absolute or parent-directory paths captured by WEAK_IMPORT_PATTERN and consumed by _write_mi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107377/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T17:40:37
1 posts
🟠 CVE-2026-107375 - High (8.8)
JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures. From 7.0.0 until 9.4.0, reactive applications generated with Spring WebFlux, Spring Data R2DBC, and a SQL database ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107375/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T17:40:32
1 posts
🟠 CVE-2026-107303 - High (7.6)
JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures. Prior to generator-jhipster 9.4.0 and react-jhipster 1.1.0, generated applications can persist attacker-controlled ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107303/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T17:40:07
1 posts
🟠 CVE-2026-107300 - High (7.5)
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invokes itself for each complete MessagePack value remaining in a chunk. A remote peer can send one chunk containing many small ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107300/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T17:26:22.830000
1 posts
🟠 CVE-2026-107352 - High (7.7)
Missing authorization checks in Amazon Athena engine version 3 request handling could have allowed an authenticated user to read limited query metadata (AWS account identifiers and SQL statement text) from other AWS accounts. Query results, creden...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107352/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T17:26:22.830000
1 posts
Two Apache Jackrabbit vulnerabilities, including critical session hijack flaw CVE-2026-92414 (CVSS 9.3), are fixed. Upgrade to 2.23.6 now.
#Apache #Jackrabbit #WebDAV #CVE202692414 #CVE202692415 #SessionHijack #Java #Vulnerability
##updated 2026-10-08T17:24:11.230000
1 posts
CRITICAL: CVE-2026-17609 in Super Forms – Drag & Drop Form Builder (<=6.3.316) lets unauthenticated attackers recursively delete server directories if 'Delete files after form submissions' is enabled. Disable it! https://radar.offseq.com/threat/cve-2026-17609-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-webrehab-super-forms-drag-f4228d5a610b35bd #OffSeq #WordPress #Vuln #Infosec
##updated 2026-10-08T16:31:27
1 posts
🟠 CVE-2026-107215 - High (7.5)
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, extractPart allocates a byte slice directly from an attacker-controlled CFB directory-entry size before validating the sector chain or si...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107215/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T16:31:23
1 posts
🟠 CVE-2026-107216 - High (7.5)
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.1 to 2.11.0, ANCHORARRAY recursively calls the exported CalcCellValue function, creating a fresh calculation context at each cycle and bypassing in-fl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107216/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T15:33:58
1 posts
Six Apache DolphinScheduler vulnerabilities, including CVE-2026-71896 and Kubernetes credential leak CVE-2026-71895, are fixed in 3.4.3.
#Apache #DolphinScheduler #Kubernetes #CVE202671896 #CVE202671895 #AccessControl #DataSecurity #Vulnerability
##updated 2026-10-08T15:33:16
1 posts
1 repos
🔴 CVE-2026-9209 - Critical (9.8)
mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the backing...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9209/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T15:33:15
1 posts
🟠 CVE-2026-93017 - High (7.7)
The `insights-operator-gather` ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or resourceNames restriction — therefore, access to every secret in every namespace in the cluster.
...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93017/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T15:33:10
1 posts
🔴 CVE-2026-14502 - Critical (9.8)
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to obtain administrative access due to failure to reject empty passwords during LDAP a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14502/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T15:33:10
1 posts
🟠 CVE-2026-14497 - High (8.1)
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote authenticated attacker to bypass security restrictions due to improper verification of cryptogr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14497/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T15:33:07
1 posts
IBM fixes 23 IBM DataPower Gateway vulnerabilities, including critical RCE flaws CVE-2026-15762 and CVE-2026-16340. Upgrade to 11.0.0.3 now.
#IBM #DataPower #APIGateway #CVE202615762 #CVE202616340 #CVE202614990 #RCE #Vulnerability
##updated 2026-10-08T15:33:05
2 posts
IBM fixes 23 IBM DataPower Gateway vulnerabilities, including critical RCE flaws CVE-2026-15762 and CVE-2026-16340. Upgrade to 11.0.0.3 now.
#IBM #DataPower #APIGateway #CVE202615762 #CVE202616340 #CVE202614990 #RCE #Vulnerability
##CVE-2026-16340 (CRITICAL, CVSS 9.8): IBM DataPower Gateway 10.5.0.0 – 10.5.0.22, 10.6.0.0 – 10.6.0.10, 10.6.1 – 10.6.6, 11.0.0.0 – 11.0.0.2 vulnerable to remote code execution via out-of-bounds write. Patch priority high. https://radar.offseq.com/threat/cve-2026-16340-cwe-787-out-of-bounds-write-in-ibm-datapower-gateway-106cd-0c7cd2fb359c85f5 #OffSeq #IBM #Vuln #Cybersecurity
##updated 2026-10-08T15:32:55
1 posts
CVE-2026-107510: CRITICAL vuln in Infoblox NIOS 9.0.x – 9.1.0. Auth'd high-priv users can escalate privileges via argument injection. Restrict admin access & watch for vendor updates. https://radar.offseq.com/threat/cve-2026-107510-vulnerability-in-infoblox-nios-dd277637e9e73e9d #OffSeq #Infosec #CVE2026107510
##updated 2026-10-08T15:32:55
1 posts
Six Apache DolphinScheduler vulnerabilities, including CVE-2026-71896 and Kubernetes credential leak CVE-2026-71895, are fixed in 3.4.3.
#Apache #DolphinScheduler #Kubernetes #CVE202671896 #CVE202671895 #AccessControl #DataSecurity #Vulnerability
##updated 2026-10-08T10:35:08.200000
2 posts
4 repos
https://github.com/iSee857/Cleo-CVE-2024-50623-PoC
https://github.com/verylazytech/CVE-2024-50623
The verdict on whether Aon was actually breached, encrypted, or exfiltrated remains, as of October 7, 2026, unconfirmed. The court is unimpressed by this lack of closure.
Sentencing is pending, but the docket is clear: patch your Cleo managed file-transfer software against CVE-2024-50623 immediately or await your own summons.
Reward: You've received a Subpoena of Moderate Urgency. It is not transferable.
https://shattered.io/aon-ransomware-cve-2024-50623-cleo-2026
#Ransomware #Cleo (2/2)
##🏆 New Achievement! Exhibit A: Two-Year-Old Bug, Still Loaded!
The court finds as follows. Aon, insurance and risk-advisory colossus, stands named in connection with the Termite ransomware group's exploitation of CVE-2024-50623, a vulnerability in Cleo's managed file-transfer software that has been kicking around since 2024. Rescana and BleepingComputer raised the charges. (1/2)
##updated 2026-10-08T09:32:03
1 posts
CVE-2026-105110 (CRITICAL, CVSS 9.8): Iskratel Innbox GPON ONT devices have an OS command injection flaw in login.xgi. Remote, unauthenticated code execution as root possible. Restrict access & monitor until patch. https://radar.offseq.com/threat/cve-2026-105110-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-2e83a9c5703badaa #OffSeq #infosec #zeroday #vuln
##updated 2026-10-08T09:32:03
1 posts
CVE-2026-12260: CRITICAL SQL injection in NetBoard CRM Demo (user-name param in /module/auth/recovery.php). Exploitable via multiple SQLi techniques — data theft or CRM compromise possible. Mitigation needed now. https://radar.offseq.com/threat/cve-2026-12260-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-0022aae9b62fa698 #OffSeq #SQLi #NetBoardCRM #CVE202612260
##updated 2026-10-08T06:31:28
1 posts
Openfind SecuShare Pro v4 is affected by CVE-2026-107459 (CRITICAL, CVSS 9.3) — unauthenticated OS command injection allows remote code execution. No patch yet; restrict access and monitor activity. https://radar.offseq.com/threat/cve-2026-107459-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-864ce7371e089cbd #OffSeq #CVE #Vuln
##updated 2026-10-08T04:17:08.777000
1 posts
Elastic fixes 14 Elastic Stack vulnerabilities, including Kibana flaw CVE-2026-102406 and Elasticsearch bug CVE-2026-103007. Upgrade now.
#Elastic #Elasticsearch #Kibana #ElasticDefend #CVE2026102406 #CVE2026103007 #DataSecurity #Vulnerability
##updated 2026-10-08T04:16:55.397000
3 posts
Veeam Patches Critical Remote Code Execution Flaw in Backup & Replication Software
Veeam patched four vulnerabilities in Backup & Replication version 12, including a critical RCE flaw (CVE-2025-64393) that allows low-privileged users to take control of the backup server.
**If you use Veeam Backup & Replication version 12, update ASAP to 12.3.2 P4 (build 12.3.2.4934). Review and remove the Backup Viewer role from anyone who doesn't really need it, and keep your backup servers isolated from the rest of the network.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/veeam-patches-critical-remote-code-execution-flaw-in-backup-replication-software-9-s-8-u-1/gD2P6Ple2L
Veeam Patches Critical Remote Code Execution Flaw in Backup & Replication Software
Veeam patched four vulnerabilities in Backup & Replication version 12, including a critical RCE flaw (CVE-2025-64393) that allows low-privileged users to take control of the backup server.
**If you use Veeam Backup & Replication version 12, update ASAP to 12.3.2 P4 (build 12.3.2.4934). Review and remove the Backup Viewer role from anyone who doesn't really need it, and keep your backup servers isolated from the rest of the network.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/veeam-patches-critical-remote-code-execution-flaw-in-backup-replication-software-9-s-8-u-1/gD2P6Ple2L
Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2 P4 from 10/6
CVE-2025-64393 (9.4 critical) low-privileged RCE
##updated 2026-10-07T21:33:37
1 posts
🟠 CVE-2026-107161 - High (7.5)
A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107161/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T21:33:30
2 posts
Splunk fixes 22 Splunk Enterprise vulnerabilities, including critical Patroni API flaw CVE-2026-76268 and CVE-2026-76281. Upgrade to 10.4.3 now.
#Splunk #SplunkEnterprise #SIEM #CVE202676268 #CVE202676281 #RCE #PatchNow #Vulnerability
##🔴 CVE-2026-76268 - Critical (9.8)
In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with network access to the Patroni Representational State Transfer (REST) Application Programming Interface (API) on a search head cluster member could execute attacker...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76268/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T21:33:30
1 posts
🟠 CVE-2026-76266 - High (7.7)
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15 on Linux, a local user who can run commands as the user account running Splunk Enterprise could cause an affected Linux package upgrade to run attacker-controlled operating-sy...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76266/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T20:23:32
1 posts
🟠 CVE-2026-107217 - High (7.5)
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.0.0 to 2.11.0 in github.com/xuri/excelize/v2 and from 1.1.0 to 1.4.1 in github.com/xuri/excelize, ColumnNameToNumber accumulates a bijective base-26 val...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107217/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T20:23:23
1 posts
🟠 CVE-2026-107219 - High (7.5)
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, agile decryption accepts an attacker-controlled spinCount and performs that many password-key derivation iterations before verifier valid...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107219/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:21
3 posts
Two more Cisco advisories today addressing critical vulnerabilities:
- CVE-2026-76471: Cisco NX-OS Software NX-API Remote Code Execution Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-napi-rce-r2shwu2j
- CVE-2026-76463, CVE-2026-76464, and CVE-2026-76467: Cisco Meraki Security Hardening Release: October 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-meraki-os-drbEX9GH @TalosSecurity #infosec #Cisco #vulnerability
##🔴 CVE-2026-76471 - Critical (9.8)
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device.
The vulnerabi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76471/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Cisco NX-OS vulnerabilities fixed, including critical NX-API RCE flaw CVE-2026-76471 and CVE-2026-76455, across Nexus, MDS and UCS gear. Patch now.
#Cisco #NXOS #Nexus #CVE202676471 #CVE202676455 #RCE #NetworkSecurity #Vulnerability
##updated 2026-10-07T18:32:21
3 posts
CVE-2026-76485: CRITICAL (CVSS 9.8) vulnerability in Cisco NX-OS NGOAM allows remote code execution or DoS via crafted packets. Disable NGOAM if unused. Awaiting official patch. Details: https://radar.offseq.com/threat/a-vulnerability-in-the-vxlan-operation-administration-and-maintenance-oam-feature-of-cisco-nx-os-41bf2bad6a99d754 #OffSeq #Cisco #CVE202676485 #Infosec
##🔴 CVE-2026-76485 - Critical (9.8)
A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a Denial-of-Serv...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76485/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Four critical Cisco Nexus vulnerabilities, including CVE-2026-76485 and CVE-2026-76465 (CVSS 9.8), allow root RCE on NX-OS switches. Patch now.
#Cisco #Nexus #NXOS #CVE202676485 #CVE202676465 #RCE #NetworkSecurity #Vulnerability
##updated 2026-10-07T18:32:21
2 posts
CVE-2026-95606: CRITICAL deserialization of untrusted data in The Events Calendar (<=6.17.4) enables remote object injection & code execution. No patch confirmed — review vendor advisory. https://radar.offseq.com/threat/deserialization-of-untrusted-data-vulnerability-in-liquid-web-stellarwp-the-events-calendar-allows-c423d4d18fa2f1a5 #OffSeq #WordPress #Vulnerability #CVE202695606
##🔴 CVE-2026-95606 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Events Calendar allows Object Injection.
This issue affects The Events Calendar: from n/a through 6.17.4.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-95606/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:21
1 posts
🟠 CVE-2026-76453 - High (8.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76453/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:21
1 posts
🔴 CVE-2026-76483 - Critical (9.1)
As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. T...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76483/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:21
1 posts
🟠 CVE-2026-96335 - High (7.5)
Missing Authorization vulnerability in WPMU DEV Forminator allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Forminator: from n/a through 1.57.2.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-96335/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:21
1 posts
🔴 CVE-2026-76480 - Critical (9.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. T...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76480/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:21
1 posts
🟠 CVE-2026-76470 - High (8.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses mult...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76470/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:21
1 posts
🔴 CVE-2026-76498 - Critical (9.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in softwar...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76498/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:21
1 posts
🔴 CVE-2026-76486 - Critical (9.8)
A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a Denial-of-Serv...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76486/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:21
1 posts
🟠 CVE-2026-76484 - High (8.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. T...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76484/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:21
1 posts
🟠 CVE-2026-95534 - High (8.8)
Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Object Injection.
This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-95534/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:21
1 posts
🔴 CVE-2026-95605 - Critical (9.3)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Passionate Programmer Peter WP Data Access allows Blind SQL Injection.
This issue affects WP Data Access: from n/a through 5.5.82.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-95605/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:20
2 posts
Two more Cisco advisories today addressing critical vulnerabilities:
- CVE-2026-76471: Cisco NX-OS Software NX-API Remote Code Execution Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-napi-rce-r2shwu2j
- CVE-2026-76463, CVE-2026-76464, and CVE-2026-76467: Cisco Meraki Security Hardening Release: October 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-meraki-os-drbEX9GH @TalosSecurity #infosec #Cisco #vulnerability
##🟠 CVE-2026-76467 - High (7.5)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses mult...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76467/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:20
2 posts
Two more Cisco advisories today addressing critical vulnerabilities:
- CVE-2026-76471: Cisco NX-OS Software NX-API Remote Code Execution Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-napi-rce-r2shwu2j
- CVE-2026-76463, CVE-2026-76464, and CVE-2026-76467: Cisco Meraki Security Hardening Release: October 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-meraki-os-drbEX9GH @TalosSecurity #infosec #Cisco #vulnerability
##🔴 CVE-2026-76464 - Critical (9.6)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses mult...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76464/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:20
1 posts
🔴 CVE-2026-76454 - Critical (9.1)
A vulnerability in the Cisco Smart Licensing Utility API of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to write arbitrary files to the system or cause a DoS c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76454/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:20
1 posts
🟠 CVE-2026-76459 - High (8.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76459/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:20
1 posts
🟠 CVE-2026-76468 - High (8.2)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses mult...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76468/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:20
2 posts
🔴 CVE-2026-76482 - Critical (10)
As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. T...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76482/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Cisco License On-Prem vulnerabilities include CVSS 10 flaw CVE-2026-76482 and password reset bug CVE-2026-20328. APIC and Meraki also patched.
#Cisco #SmartLicensing #APIC #Meraki #CVE202676482 #CVE202620328 #PatchNow #Vulnerability
##updated 2026-10-07T18:32:14
2 posts
🔴 CVE-2026-20328 - Critical (9.1)
A vulnerability in the web-based management interface of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to gain unauthorized access to an affected application.
...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20328/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Cisco License On-Prem vulnerabilities include CVSS 10 flaw CVE-2026-76482 and password reset bug CVE-2026-20328. APIC and Meraki also patched.
#Cisco #SmartLicensing #APIC #Meraki #CVE202676482 #CVE202620328 #PatchNow #Vulnerability
##updated 2026-10-07T18:32:14
1 posts
🔴 CVE-2026-76500 - Critical (9.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in softwar...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76500/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:14
1 posts
🔴 CVE-2026-107206 - Critical (9.4)
LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess mode HTTP server that allows remote unauthenticated attackers to access management endpoints listening on all interfaces by default. Attackers can read envir...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107206/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:14
1 posts
🟠 CVE-2026-107205 - High (8.6)
LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess coordinator that allows remote unauthenticated attackers to access its HTTP fleet control API listening on all interfaces by default. Attackers can register ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107205/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:14
1 posts
🔴 CVE-2026-107204 - Critical (9.8)
LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run_script endpoint. Attackers can recover real builtins through the injected Fast...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107204/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:17:16.660000
1 posts
🟠 CVE-2026-106510 - High (7.7)
Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by remote code execution via crafted markdown_extensions in techdocs mkdocs.yml. An authenticated user who can ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-106510/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:17:15.427000
3 posts
1 repos
Unpatched Critical RCE Vulnerability in LMCache Exposes LLM Infrastructure to Remote Takeover
LMCache suffers from a critical unpatched vulnerability (CVE-2026-105192) that allows unauthenticated attackers to execute arbitrary code with root privileges via malicious ZeroMQ messages. The flaw stems from the unsafe use of Python's pickle library for data deserialization in the platform's multiprocess mode.
**If you run LMCache in multiprocess mode (versions 0.3.9 through 0.5.5), be aware that your system is critically vulnerable and there is no fix yet. Make sure its port is reachable only from localhost or a trusted internal network. Also update vLLM to version 0.30.0 or later, so a single bad request can't crash your AI service for everyone.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/unpatched-critical-rce-vulnerability-in-lmcache-exposes-llm-infrastructure-to-remote-takeover-u-2-9-i-r/gD2P6Ple2L
LMCache multiprocess mode is affected by CVE-2026-105192, an unauthenticated RCE via pickle deserialization over ZeroMQ, rated CVSS 9.8. Localhost binding by default limits exposure, but any reachable instance allows full process compromise. Prioritize network restriction and patching. #LmCache #RemoteCodeExecution #PickleDeserialization
https://cyberworldops.eu/en/lmcache-distributed-mode-exposes-critical-code-execution-path-through
##what. the. fuck.
https://nvd.nist.gov/vuln/detail/cve-2026-105192
sev:CRIT 9.8 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
##LMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and share KV cache blocks. Messages on that socket are msgpack. Extension code 1 is passed to DeviceIPCWrapper.Deserialize, which calls pickle.loads, while the server is still decoding request arguments and before the handler runs. A single unauthenticated ZMQ DEALER message to the transport port (default 5555) therefore executes code as the user the LMCache process runs as. Official container images run that process as root. The transport binds to localhost unless the operator sets a routable address with --host, which is how multi-node deployments let peers connect.
updated 2026-10-07T18:03:15
1 posts
🟠 CVE-2026-106558 - High (8.8)
Backstage is an open framework for building developer portals. Prior to 1.14.8, 1.15.6, and 2.0.1, the @backstage/plugin-techdocs-node package improperly validated mapping-style markdown_extensions configuration. An authenticated attacker who can ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-106558/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:03:07.387000
1 posts
2 repos
CVE-2026-102489 Deep-Dive: Zammad Session Leak to RCE https://horizon3.ai/attack-research/disclosures/cve-2026-102489-zammad-session-leak-rce/
##updated 2026-10-07T17:59:20
1 posts
CVE-2026-106501: @backstage/plugin-scaffolder-backend CRITICAL vuln (CVSS 9.6) allows authenticated users to access other users’ task data, incl. credentials. Patch to 4.1.0 now. Restrict task read perms as interim measure. https://radar.offseq.com/threat/plugin-scaffolder-backend-backstage-sensitive-information-exposure-in-scaffolder-cve-2026-106501-af878d1e8ab7288a #OffSeq #Backstage #Vuln
##updated 2026-10-07T16:17:32.440000
4 posts
SonicWall Patches Critical Pre-Auth SSRF in SMA 1000 Series Appliances
SonicWall patched four vulnerabilities in its SMA 1000 series appliances, including a critical pre-authentication SSRF (CVE-2026-102255) with a CVSS score of 10.0. The flaws allow unauthenticated attackers to access internal services and authenticated users to execute arbitrary code.
**If you use SonicWall SMA 1000 series appliances (SMA 6210, SMA 7210 or SMA 8200v), update them ASAP to firmware 12.4.3-03670 or 12.5.0-03082 or newer. Make sure the management console is reachable only from trusted internal networks, and check the appliance logs for unusual activity, since these gateways are a favorite entry point for ransomware groups.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/sonicwall-patches-critical-pre-auth-ssrf-in-sma-1000-series-appliances-5-j-n-v-v/gD2P6Ple2L
🚨 Rapid Response: SonicWall has patched a critical CVSS 10.0 pre-authentication SSRF in SMA1000 appliances (CVE-2026-102255).
Censys detects 5,966 Internet-exposed hosts and 39,310 web properties running SMA1000/Secure Mobile Access after excluding honeypot-labeled systems. This indicates product presence, not confirmed-vulnerable systems.
Full Censys ARC advisory: https://censys.com/advisory/cve-2026-102255/
##Chat, is it bad if your zero-trust VPN device forwards network requests without auth? Asking for thousands of friends.
SonicWall SMA1000 devices have a SSRF vulnerability that needs patching.
https://ifin.network/t/cve-2026-102255-pre-auth-ssrf-in-sonicwall-sma1000-devices/889
##Tracked as CVE-2026-102255, the vulnerability was found in the Appliance WorkPlace interface of SMA1000 6210, 7210, and 8200v models, but it does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls. https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-max-severity-ssrf-flaw-in-sma1000-gateways/
##updated 2026-10-07T16:13:09
1 posts
🟠 CVE-2026-62251 - High (8.1)
Homer is open source telecom observability software. Prior to version 11.0.283, the `V4StatisticsQuery` handler passes the user-supplied `rawquery` field directly to DuckDB without calling the `sqlvalidator.ValidateRawSQL` function used throughout...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62251/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T16:12:03
1 posts
🔴 CVE-2026-62252 - Critical (9.8)
Homer is open source telecom observability software. Prior to version 11.0.283, on every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an `admin` account with the password `sipcapture` (stored as...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62252/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T16:05:54
1 posts
🔴 CVE-2026-62176 - Critical (9.1)
PraisonAI is a multi-agent teams system. Prior to version 4.6.78, the `deploy/api.py` module generates Python server code by directly interpolating the `agents_file` parameter into an f-string that is then written to a file and executed via `subpr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62176/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T16:02:27.613000
1 posts
wolfSSH 1.6.0 fixes five wolfSSH vulnerabilities, including critical host key flaw CVE-2026-16516 and Windows login bug CVE-2026-83540.
#wolfSSH #wolfSSL #SSH #CVE202616516 #CVE202683540 #EmbeddedSecurity #MitM #Vulnerability
##updated 2026-10-07T15:32:08
1 posts
🟠 CVE-2026-77214 - High (8.2)
libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated b...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77214/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T15:32:07
2 posts
A critical Telegram Desktop account takeover vulnerability (CVE-2026-107181) exposes users to session hijacking. Exploit details and PoC are now public.
#Telegram #Cybersecurity #CVE2026107181 #AccountTakeover #PoC
##A critical Telegram Desktop account takeover vulnerability (CVE-2026-107181) exposes users to session hijacking. Exploit details and PoC are now public.
#Telegram #Cybersecurity #CVE2026107181 #AccountTakeover #PoC
##updated 2026-10-07T15:31:33
18 posts
10 repos
https://github.com/rxsklife/CVE-2026-21589
https://github.com/watchtowrlabs/watchTowr-vs-Atlassian-CVE-2026-21589
https://github.com/ynsmroztas/AtlasSniper
https://github.com/BimBoxH4/CVE-2026-21589
https://github.com/murrez/CVE-2026-21589
https://github.com/0xBlackash/CVE-2026-21589
https://github.com/renzi25031469/CVE-2026-21589
https://github.com/MarcusProgram/CVE-2026-21589
You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589) https://labs.watchtowr.com/you-wont-hear-about-these-even-in-myths-atlassian-jira-confluence-and-more-pre-auth-arbitrary-file-read-cve-2026-21589/
##You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589) https://labs.watchtowr.com/you-wont-hear-about-these-even-in-myths-atlassian-jira-confluence-and-more-pre-auth-arbitrary-file-read-cve-2026-21589/
##CVE-2026-21589 kritikus arbitrary file access hiba érinti több Atlassian Data Center terméket (Jira, Confluence, Bitbucket) és bejelentkezés nélkül hozzáférhetők lehetnek fájlok. Van internetre kitett példányod, ami veszélyben lehet, aggódsz? A végleges megoldás a frissítés; ideiglenes WAF/Tomcat RewriteValve mitigációk lehetségesek.
https://linuxmint.hu/hir/2026/10/kritikus-fajleleresi-hiba-az-atlassian-data-center-termekekben
#Atlassian #CVE202621589 #Jira #Confluence #Bitbucket #DataCenter #WAF #Tomcat #kiberbiztonság #infosec
##Oh, Atlassian, never change! 😭
"CVE-2026-21589 - Arbitrary File Access Vulnerability impacts Multiple Products"
CVSS Score 9.3, so, you know, you better "Test that your rule blocks .. immediately adjacent to /".
APT /../../../../../../etc/passwd strikes again.
##Atlassian Patches Critical File Access Flaw Exploited in the Wild
Atlassian released emergency patches for a critical arbitrary file access vulnerability (CVE-2026-21589) affecting eight Data Center products, which attackers are actively exploiting to gain administrator privileges.
**If you run self-hosted Atlassian Data Center or Server products (Jira, Confluence, Bitbucket, Bamboo, Crowd, Crucible/Fisheye), apply Atlassian's security update immediately, because this flaw is being actively exploited to steal passwords and take over admin accounts. If you can't patch, remove the instance from the public internet now, then check your logs for access attempts to WEB-INF or crowd.properties. Change any Crowd credentials that may have been exposed.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/atlassian-patches-critical-file-access-flaw-exploited-in-the-wild-d-o-s-h-y/gD2P6Ple2L
Atlassian : une faille critique permet de lire des fichiers sur Jira, Confluence et Bitbucket https://www.it-connect.fr/atlassian-cve-2026-21589-faille-critique-jira-confluence-bitbucket/ #ActuCybersécurité #Cybersécurité #Vulnérabilité
##⚠️ CRITICAL: Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details
A critical arbitrary file access vulnerability (CVE-2026-21589) in Atlassian Data Center products is under active exploitation as of public disclosure. Threat actors attempted exploitation within two hours of details going public, with potential access to credentials and sensitive files. All Atlass…
🤖 AI generated summary
##🚨 Rapid Response: CVE-2026-21589 (CVSS 9.3) is a critical arbitrary file access vulnerability affecting eight Atlassian Data Center products, including Confluence, Jira, Bitbucket, and Bamboo.
Censys currently detects 95,366 Internet-facing hosts and 431,502 web properties running affected products after excluding assets labeled as honeypots. This is product exposure, not a confirmed-vulnerable count.
Atlassian has released fixes for all eight products.
Full Censys ARC advisory: https://censys.com/advisory/cve-2026-21589/
##Scans for Atlassian vulnerablity (CVE-2026-21589)
#CVE_2026_21589
https://isc.sans.edu/diary/rss/33406
Recent developments include the US evacuating B-1 bombers from the UK due to an Iranian threat, while Hamas is reportedly plotting attacks in Gaza for October 7th. In cybersecurity, ASOS experienced a cloud breach via its Snowflake platform, and active exploitation of a critical Atlassian flaw (CVE-2026-21589) has begun. An FBI breach was also linked to a contractor error. Microsoft is hosting an AI-focused Surface event today.
##Unauthenticated arbitrary file access in eight self-hosted Atlassian families (CVE-2026-21589) is seeing active probing after public PoC release. Exploitation requires exact file path and is limited to web root, without directory listing. Data Center operators should patch and reduce exposure promptly. #Atlassian #DataCenter #ThreatIntel
https://cyberworldops.eu/en/public-exploit-code-triggers-rapid-probing-of-eight-atlassian-product
##Scans for Atlassian vulnerablity (CVE-2026-21589) https://isc.sans.edu/diary/33406
##Atlassian Warns of Critical Flaw Affecting Eight Self-Managed Products
Atlassian's CVE-2026-21589 lets unauthenticated attackers read files in Confluence and seven other Data Center products.
🔗️ [Thecyberexpress] https://link.is.it/gJ99W6
##Hackers exploit critical Atlassian flaw after public PoC release
A critical vulnerability (CVE-2026-21589) affecting multiple Atlassian product families, including Jira, Confluence, and Bitbucket, is being...
🔗️ [Bleepingcomputer] https://link.is.it/J8wKmL
##An unauthenticated attacker can exploit CVE-2026-21589 to access specific files in the application's web root directory if they know the file's exact name and path. https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-atlassian-flaw-after-public-poc-release/
##You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589)
#CVE_2026_21589 #Bitbucket #Confluence #Jira #AtlassianBamboo #AtlassianCrowd
https://labs.watchtowr.com/you-wont-hear-about-these-even-in-myths-atlassian-jira-confluence-and-more-pre-auth-arbitrary-file-read-cve-2026-21589/
CVE-2026-21589 exploitation is underway against Atlassian servers after researchers published arbitrary file read PoC and technical details.
#Atlassian #Jira #Confluence #Bitbucket #CVE202621589 #PathTraversal #ExploitedInTheWild #Vulnerability
##OK, this is an innovative directory traversal vuln:
GET /download/resources/jira.webresources:color-picker-popup/images/..::..::..::..::..::WEB-INF::web.xml HTTP/1.1
This is from CVE-2026-21589, https://labs.watchtowr.com/you-wont-hear-about-these-even-in-myths-atlassian-jira-confluence-and-more-pre-auth-arbitrary-file-read-cve-2026-21589/
The "::" gets replaced with "/" by some weird sanitation method, read more about it in the writeup.
Tagging @nynbinary for humorous memeing.
##updated 2026-10-07T12:32:00
1 posts
CVE-2026-96408 (CRITICAL): Movable Type Cloud Edition (v2.0 – 9.2.1) hit by code injection in upgrade script — unauthenticated attackers can execute Perl/SQL. No patch yet; restrict script access. https://radar.offseq.com/threat/cve-2026-96408-code-injection-in-six-apart-ltd-movable-type-cloud-edition-535c78e66ddee34d #OffSeq #CVE202696408 #infosec #vuln
##updated 2026-10-07T09:32:29
1 posts
Manacle Technologies Multi-tenant ERP System hit by CVE-2026-107104 (CRITICAL, CVSS 9.3): Unsafe deserialization lets unauthenticated attackers execute code remotely. No fix yet — restrict access & monitor systems. https://radar.offseq.com/threat/cve-2026-107104-cwe-502-deserialization-of-untrusted-data-in-manacle-technologies-multi-tenant-erp-9e646ff6d0c210e4 #OffSeq #CVE2026107104 #ERP #infosec
##updated 2026-10-07T06:33:08
2 posts
1 repos
https://thecybersecguru.com/exploits/cve-2026-59346-vmware-vmxnet3-poc/
##A VMware VMXNET3 vulnerability, CVE-2026-59346 (CVSS 9.3), allows VM escape. Full details and PoC exploit code are now public. Patch to 26H1u1.
#VMware #VMXNET3 #CVE202659346 #VMEscape #Virtualization #Broadcom #PoC #Vulnerability
##updated 2026-10-07T06:33:01
1 posts
Flexera FlexNet Publisher (≤11.19.11) suffers a CRITICAL auth bypass (CVE-2026-19572, CVSS 9.3). SOAP handler flaw allows unauthenticated admin access. Patch not yet available — monitor systems closely. https://radar.offseq.com/threat/cve-2026-19572-cwe-288-authentication-bypass-using-an-alternate-path-or-channel-in-flexera-flexnet-56f758677e3ccac3 #OffSeq #CVE202619572 #infosec #vuln
##updated 2026-10-07T03:30:31
1 posts
wolfSSH 1.6.0 fixes five wolfSSH vulnerabilities, including critical host key flaw CVE-2026-16516 and Windows login bug CVE-2026-83540.
#wolfSSH #wolfSSL #SSH #CVE202616516 #CVE202683540 #EmbeddedSecurity #MitM #Vulnerability
##updated 2026-10-07T03:30:31
2 posts
ASUS Router XSS (CVE-2026-14911, CRITICAL, CVSS 9.3): Remote attackers can exploit improper input neutralization to execute scripts, alter settings, or cause DoS if visited by authenticated users. No patch yet. Details: https://radar.offseq.com/threat/cve-2026-14911-cwe-79-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-81fca42ab40cabc9 #OffSeq #XSS #Cybersecurity
##Four ASUS router vulnerabilities are fixed, including critical XSS flaw CVE-2026-14911 and code execution bug CVE-2026-19386. Update firmware now.
#ASUS #ASUSRouter #RouterSecurity #CVE202614911 #CVE202619386 #XSS #FirmwareUpdate #Vulnerability
##updated 2026-10-07T03:30:23
1 posts
Four ASUS router vulnerabilities are fixed, including critical XSS flaw CVE-2026-14911 and code execution bug CVE-2026-19386. Update firmware now.
#ASUS #ASUSRouter #RouterSecurity #CVE202614911 #CVE202619386 #XSS #FirmwareUpdate #Vulnerability
##updated 2026-10-06T21:31:57
1 posts
Elastic fixes 14 Elastic Stack vulnerabilities, including Kibana flaw CVE-2026-102406 and Elasticsearch bug CVE-2026-103007. Upgrade now.
#Elastic #Elasticsearch #Kibana #ElasticDefend #CVE2026102406 #CVE2026103007 #DataSecurity #Vulnerability
##updated 2026-10-06T21:31:51
1 posts
Chrome 155 patches 247 vulnerabilities, including 4 CRITICAL use-after-free bugs (CVE-2026-106382, - 106197, - 106358, - 106347) across Chromecast, Browser, Navigation & Track. Update on Windows, macOS & Linux. No active exploits. https://radar.offseq.com/threat/chrome-155-update-patches-247-vulnerabilities-28750e8d96fdecb9 #OffSeq #Chrome #Security
##updated 2026-10-06T15:32:06
1 posts
Progress Software Fixes Critical Command Injection Flaw in DataDirect ARC GenAI Agents
Progress Software patched a critical command injection vulnerability (CVE-2026-91140) in its DataDirect ARC GenAI Agents that allowed attackers to execute code via malicious OpenAPI filenames.
**If you use Progress DataDirect ARC GenAI agents (the ARCGenAI-Generator or ARCGenAI-EntityGen files), update ASAP by pulling the latest version 2.1 files from GitHub. If you've recently fed it any OpenAPI or Swagger files from outside sources, check your developer machines and CI/CD pipelines for unexpected files or changes. From now on treat every external spec file as untrusted.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/progress-software-fixes-critical-command-injection-flaw-in-datadirect-arc-genai-agents-r-5-e-v-a/gD2P6Ple2L
updated 2026-10-06T15:03:59.427000
1 posts
1 repos
LibreOffice and OpenOffice Patch Critical Remote Code Execution Vulnerabilities
LibreOffice and Apache OpenOffice patched several critical vulnerabilities, including a remote code execution flaw (CVE-2026-63277) that allows attackers to run malicious Java code via manipulated spreadsheet documents.
**If you use LibreOffice, update it to version 26.2.5 or 26.8.0 ASAP, and until you do, don't open documents from unknown senders or unexpected sources. If you use Apache OpenOffice, there's no fix yet, so turn off Java in the program's options now and install version 4.1.17 as soon as it's released. Or better yet, switch to the patched LibreOffice.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/libreoffice-and-openoffice-patch-critical-remote-code-execution-vulnerabilities-1-z-e-q-7/gD2P6Ple2L
updated 2026-10-05T18:34:22
2 posts
HPE fixes a critical HPE iLO 7 vulnerability, CVE-2026-79820, and iMC authentication bypass CVE-2026-79842. Update iLO to 1.25.01 now.
#HPE #iLO #iMC #CVE202679820 #CVE202679842 #AuthBypass #ServerSecurity #Vulnerability
##HPE fixes a critical HPE iLO 7 vulnerability, CVE-2026-79820, and iMC authentication bypass CVE-2026-79842. Update iLO to 1.25.01 now.
#HPE #iLO #iMC #CVE202679820 #CVE202679842 #AuthBypass #ServerSecurity #Vulnerability
##updated 2026-10-05T13:35:24.663000
2 posts
2 repos
https://github.com/orjanj/netscaler_threat_hunt_helper
https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker
Citrix reveals CVE-2026-88779, a critical memory overflow flaw in NetScaler SAML configurations leading to DoS, following recent RCE zero-day attacks.
#CitrixNetScaler #Cybersecurity #CVE202688779 #SAML #ZeroDay
##Vorfall-Lagebild: Citrix NetScaler: Zero-Day CVE-2026-88779 wird aktiv
Nach 24 Stunden: was bekannt ist, was offen ist und was wahrscheinlich passiert ist – Citrix NetScaler: Zero-Day CVE-2026-88779 wird aktiv ausgenutzt – SAML-G
#OTSecurity #ICS #KRITIS #NIS2 #Cybersicherheit
https://ot-cyber.de/blog/vorfall-lagebild-citrix-netscaler-zero-day-cve-2026-88779-wird-aktiv.html
updated 2026-10-03T12:32:07
1 posts
7 repos
https://github.com/HORKimhab/CVE-2026-53359
https://github.com/0xBlackash/CVE-2026-53359
https://github.com/ndouglas-cloudsmith/CVE-2026-53359
https://github.com/Aoripus-LTD/Januscape-Hotfix
https://github.com/xj2268-TA/KVM-Januscape
Patching an entire KVM cloud | https://blog.ovhcloud.com/en/posts/cve-2026-53359-kvm-patching-lessons-learned/
##updated 2026-10-02T21:32:13
1 posts
1 repos
Microsoft Exchange : la faille CVE-2026-96940 permet de lire les boîtes aux lettres des autres utilisateurs https://www.it-connect.fr/exchange-server-cve-2026-96940/ #ActuCybersécurité #Cybersécurité #Vulnérabilité #Microsoft
##updated 2026-09-29T04:18:01.603000
4 posts
14 repos
https://github.com/EXEcution-py/CVE-2026-88771-POC
https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88771
https://github.com/emilstahl/pitscaler
https://github.com/grupooruss/netscaler-defensive-checker
https://github.com/technion/netscaler_scanner
https://github.com/LETHAL-FORENSICS/Get-NetScalerTimeline
https://github.com/orjanj/netscaler_threat_hunt_helper
https://github.com/securekomodo/citrixInspector
https://github.com/techupdate24/citrix-netscaler-cve-2026-88771-rce
https://github.com/craigsblackie/cve-2026-88771-netscaler
https://github.com/bkchaudhari/NetScaler-CTX697096-Assessment-Script
https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker
https://github.com/SwiftSecur/CVE-2026-88771-HuntScript
https://github.com/watchtowrlabs/citrix-netscaler-cve-2026-88771-iocs
@GossiTheDog Meanwhile I've updated my Citrix honeypot to handle CVE-2026-88771 - but so far have seen absolutely no attacks. I'll run some tests later today to check if it doesn't miss them due to some kind of bug.
Visualization (empty so far):
##@GossiTheDog Meanwhile I've updated my Citrix honeypot to handle CVE-2026-88771 - but so far have seen absolutely no attacks. I'll run some tests later today to check if it doesn't miss them due to some kind of bug.
Visualization (empty so far):
##Watchtowr have a good look at pray and spray #PitScaler exploitation. This isn’t the initial exploitation - their timeline should expand back to September 4th for that.
Also they make a good point re the latest SAML bug - by using it to DoS, it causes attacker commands in the logs to process immediately post reboot with PitScaler vuln. Not covered in blog: Attackers are actually doing this, they’re preloading the logs using the username field for failed logins.
##eSentire tracks four clusters behind CVE-2026-88771 exploitation, planting NetScaler web shells and backdoor accounts. Learn how to detect them.
#CVE202688771 #CitrixNetScaler #WebShell #ZeroDay #Platypus #eSentire #EdgeSecurity #CyberSecurity
https://securityonline.info/cve-2026-88771-netscaler/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-09-28T21:17:18.890000
1 posts
CVE-2026-77516 MaxKB 2.0.0-2.9.2: low-priv workspace users bypass tool permissions to execute denied tools and leak server-side credentials. CVSS 5.4, no patch yet. Restrict access and monitor. https://www.valtersit.com/cve/CVE-2026-77516/ #CVE #infosec #MaxKB
##updated 2026-09-24T23:17:11.303000
1 posts
CVE-2026-54915: Tautulli open redirect. CVSS 5.4. Unauthenticated /auth/redirect leaves tab and CR/LF chars intact, so urljoin can bounce users to an attacker site. Fix under review before 2.17.2. Apply patch when ready. https://www.valtersit.com/cve/CVE-2026-54915/ #CVE #infosec #Tautulli
##updated 2026-09-22T19:04:55.677000
1 posts
An active WordPress XSS campaign exploits Ninja Forms flaw CVE-2026-94504 and CVE-2026-93836 to plant hidden admin accounts. Patch now.
#WordPress #NinjaForms #WooCommerce #CVE202694504 #CVE202693836 #XSS #ExploitedInTheWild #Malware
##updated 2026-09-22T16:17:54.987000
1 posts
CVE-2026-77520: MaxKB 2.10.2-lts and earlier leaks app IDs via the question-ranking endpoint, bypassing access controls. CVSS 5.4, unpatched. Restrict ranking endpoint access and patch now. https://www.valtersit.com/cve/CVE-2026-77520/ #CVE #infosec #MaxKB
##updated 2026-09-22T15:33:35
1 posts
CVE-2026-79317: x-ui 0.3.2 fails to invalidate session cookies after admin credential changes, letting stolen admin cookies persist. CVSS 4.8. No patch yet. Review sessions and rotate creds now. https://www.valtersit.com/cve/CVE-2026-79317/ #CVE #infosec #cybersecurity
##updated 2026-09-22T09:31:18
1 posts
An active WordPress XSS campaign exploits Ninja Forms flaw CVE-2026-94504 and CVE-2026-93836 to plant hidden admin accounts. Patch now.
#WordPress #NinjaForms #WooCommerce #CVE202694504 #CVE202693836 #XSS #ExploitedInTheWild #Malware
##updated 2026-09-21T21:32:02
1 posts
CVE-2026-94572: OpenStack Octavia Amphora driver config injection, CVSS 8.5. Authenticated project members can inject HAProxy directives via tls_ciphers. Patch is under review, hold off yet. Details: https://www.valtersit.com/cve/CVE-2026-94572/ #CVE #OpenStack #infosec
##updated 2026-09-21T21:32:00
1 posts
CVE-2026-82165 Dell Command Integration Suite for System Center <6.7.2, incorrect default permissions lets a local low-priv attacker disclose info. CVSS 5.5, no patch confirmed. Update now if 6.7.2 is out.
https://www.valtersit.com/cve/CVE-2026-82165/
#CVE #infosec #Dell
updated 2026-09-21T13:17:10.970000
1 posts
8 repos
https://github.com/adriyansyah-mf/cve-2026-85046-poc
https://github.com/Eliot-code/CVE-2026-85046
https://github.com/SneakyNachos/CVE-2026-85046-who-put-the-silverback-guerilla-in-the-wasm
https://github.com/HORKimhab/CVE-2026-85046
https://github.com/atiilla/CVE-2026-85046
https://github.com/SneakyNachos/CVE-2026-87491-and-CVE-2026-85046-the-bagel-fell-off-the-counter
New.
Picus: How BlueMoon Exploits Chrome CVE-2026-85046 and CVE-2026-87491 https://www.picussecurity.com/resource/blog/how-bluemoon-exploits-chrome-cve-2026-85046-and-cve-2026-87491 #infosec #vulnerability #Chrome #Google #threatresearch
##updated 2026-09-19T15:17:08.323000
2 posts
4 repos
https://github.com/DeathShotXD/Comment2Shell
https://github.com/HORKimhab/CVE-2026-93485
Ataki na strony WordPress chwilę po wydaniu poprawki
17 września 2026 r. WordPress wydał wersję 7.1.1, w której załatano dwie podatności – kojarzone jako Click2Shell i Comment2Shell (CVE-2026-93485). To jednak dopiero początek historii. Kilka dni później – 22 września – wydano wersję 7.1.2 łatającą kolejną podatność. Atakujący nie czekali jednak na publikację jej szczegółów – wszystko wskazuje na...
#WBiegu #Podatność #Rce #Wordpress
https://sekurak.pl/ataki-na-strony-wordpress-chwile-po-wydaniu-poprawki/
##Ataki na strony WordPress chwilę po wydaniu poprawki
17 września 2026 r. WordPress wydał wersję 7.1.1, w której załatano dwie podatności – kojarzone jako Click2Shell i Comment2Shell (CVE-2026-93485). To jednak dopiero początek historii. Kilka dni później – 22 września – wydano wersję 7.1.2 łatającą kolejną podatność. Atakujący nie czekali jednak na publikację jej szczegółów – wszystko wskazuje na...
#WBiegu #Podatność #Rce #Wordpress
https://sekurak.pl/ataki-na-strony-wordpress-chwile-po-wydaniu-poprawki/
##updated 2026-09-09T21:31:35
1 posts
2 repos
https://github.com/SneakyNachos/CVE-2026-87491-and-CVE-2026-85046-the-bagel-fell-off-the-counter
New.
Picus: How BlueMoon Exploits Chrome CVE-2026-85046 and CVE-2026-87491 https://www.picussecurity.com/resource/blog/how-bluemoon-exploits-chrome-cve-2026-85046-and-cve-2026-87491 #infosec #vulnerability #Chrome #Google #threatresearch
##updated 2026-08-12T15:51:57.517000
1 posts
2 repos
https://github.com/emresandikci/nextjs-cve-2026-23870-checker
CVE-2026-23870 is a denial-of-service flaw in React Server Components.
A crafted remote POST request can trigger excessive processing and freeze vulnerable Next.js servers.
Affected versions include React 19.0.0–19.0.5, 19.1.0–19.1.6 and 19.2.0–19.2.5, including some Next.js deployments using Server Actions.
Possible effects include slow pages, timed-out requests and HTTP 503 errors.
Fixed React releases are 19.0.6, 19.1.…
##updated 2026-07-28T18:33:11
1 posts
How We Found Thousands of Exposed NVIDIA GPUs and a Way to Disrupt Them (CVE-2026-47483) https://lava.security/research/cve-2026-47483-nvidia-dcgm-exporter-vulnerability
##updated 2026-06-17T09:22:58.030000
1 posts
🔒 New CSAF advisory published
VDE-2026-105
KEB Automation: Multiple Vulnerabilities in COMBIVIS Control Runtime
CVE-2025-41659, CVE-2025-41691, CVE-2025-41739, CVE-2025-41738
The Docker-based COMBIVIS Control Runtime service is affected by several vulnerabilities in CODESYS Runtime Toolkit 3.5.21.10. These vulnerabilities are…
HTML: https://certvde.com/en/advisories/VDE-2026-105
CSAF JSON: https://keb-automation.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-105.json
updated 2026-06-11T21:31:50
2 posts
9 repos
https://github.com/01xJB/CVE-2026-10520-POC
https://github.com/imbas007/RCE-CVE-2026-10520-CVE-2026-10523
https://github.com/gagaltotal/CVE-2026-10523-Ivanti-sentry
https://github.com/gduma-phData/patch-CVE-2026-10520
https://github.com/emilliewatson96/spryCVE-2026-10520
https://github.com/HORKimhab/CVE-2026-10520-10523
https://github.com/error-inside/CVE-2026-10520
https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523
Patch Ivanti Sentry against CVE-2026-10520 and scan your environment for PoeLLM infections before the next stanza drops.
Reward: You've received a Tattered Broadside of Suspicious Verse. We recommend not parsing it.
#Malware #CyberSecurity #Ivanti #ZeroDay #APT #PatchedOrPerish (3/3)
##It locates its command-and-control server not through conventional means, but by parsing poetry — extracting keywords, converting them to numbers via a hard-coded dictionary, and silently pivoting to wherever the operator rewrites the verse. Keats never had this kind of reach.
The compromised host, much like the lesser-spotted migratory waterfowl before a storm, immediately began scanning for further vulnerable devices. CVE-2026-10520 is the wound; the poem is the leash. (2/3)
##updated 2025-12-01T12:30:34
1 posts
🔒 New CSAF advisory published
VDE-2026-105
KEB Automation: Multiple Vulnerabilities in COMBIVIS Control Runtime
CVE-2025-41659, CVE-2025-41691, CVE-2025-41739, CVE-2025-41738
The Docker-based COMBIVIS Control Runtime service is affected by several vulnerabilities in CODESYS Runtime Toolkit 3.5.21.10. These vulnerabilities are…
HTML: https://certvde.com/en/advisories/VDE-2026-105
CSAF JSON: https://keb-automation.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-105.json
updated 2025-12-01T12:30:33
1 posts
🔒 New CSAF advisory published
VDE-2026-105
KEB Automation: Multiple Vulnerabilities in COMBIVIS Control Runtime
CVE-2025-41659, CVE-2025-41691, CVE-2025-41739, CVE-2025-41738
The Docker-based COMBIVIS Control Runtime service is affected by several vulnerabilities in CODESYS Runtime Toolkit 3.5.21.10. These vulnerabilities are…
HTML: https://certvde.com/en/advisories/VDE-2026-105
CSAF JSON: https://keb-automation.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-105.json
updated 2025-08-04T09:30:34
1 posts
🔒 New CSAF advisory published
VDE-2026-105
KEB Automation: Multiple Vulnerabilities in COMBIVIS Control Runtime
CVE-2025-41659, CVE-2025-41691, CVE-2025-41739, CVE-2025-41738
The Docker-based COMBIVIS Control Runtime service is affected by several vulnerabilities in CODESYS Runtime Toolkit 3.5.21.10. These vulnerabilities are…
HTML: https://certvde.com/en/advisories/VDE-2026-105
CSAF JSON: https://keb-automation.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-105.json
updated 2023-11-07T05:05:45
2 posts
2 repos
🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:1008)
CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3306 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3306)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: http://www.proftpd.org/ ; https://lists.debian.org/debian-security-announce/2015/msg00154.html ; https://lists.opensuse.org/archives/list/updates@lists.opensuse.org/message/WE6YZRG5UVXMGQ7IVDRYBPIWV4M6UUGM/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3306
⚠️ CVE-2015-5477 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5477)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://web.archive.org/web/20150729014733/https://kb.isc.org/article/AA-01272 ; https://access.redhat.com/errata/RHSA-2015:1513.html; https://supportportal.juniper.net/s/article/2016-01-Security-Bulletin-Junos-Vulnerability-in-ISC-BIND-named-CVE-2015-5477 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5477
⚠️ CVE-2016-3081 (https://secdb.nttzen.cloud/cve/detail/CVE-2016-3081)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://cwiki.apache.org/confluence/display/WW/S2-032 ; ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2016-3081
⚠️ CVE-2021-3199 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-3199)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://github.com/ONLYOFFICE/DocumentServer/blob/903fe5ab7a275bd69c3c3346af2d21cf87ebeabf/CHANGELOG.md#563 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-3199
⚠️ CVE-2023-22894 (https://secdb.nttzen.cloud/cve/detail/CVE-2023-22894)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://strapi.io/blog/security-disclosure-of-vulnerabilities-cve ; https://github.com/strapi/strapi/releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2023-22894
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261008 #cisa20261008 #cve_2015_3306 #cve_2015_5477 #cve_2016_3081 #cve_2021_3199 #cve_2023_22894 #cve20153306 #cve20155477 #cve20163081 #cve20213199 #cve202322894
##CVE ID: CVE-2023-22894
Vendor: Strapi
Product: Strapi
Date Added: 2026-10-08
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2023-22894
updated 2023-11-01T19:47:30
2 posts
🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:1008)
CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3306 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3306)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: http://www.proftpd.org/ ; https://lists.debian.org/debian-security-announce/2015/msg00154.html ; https://lists.opensuse.org/archives/list/updates@lists.opensuse.org/message/WE6YZRG5UVXMGQ7IVDRYBPIWV4M6UUGM/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3306
⚠️ CVE-2015-5477 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5477)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://web.archive.org/web/20150729014733/https://kb.isc.org/article/AA-01272 ; https://access.redhat.com/errata/RHSA-2015:1513.html; https://supportportal.juniper.net/s/article/2016-01-Security-Bulletin-Junos-Vulnerability-in-ISC-BIND-named-CVE-2015-5477 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5477
⚠️ CVE-2016-3081 (https://secdb.nttzen.cloud/cve/detail/CVE-2016-3081)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://cwiki.apache.org/confluence/display/WW/S2-032 ; ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2016-3081
⚠️ CVE-2021-3199 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-3199)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://github.com/ONLYOFFICE/DocumentServer/blob/903fe5ab7a275bd69c3c3346af2d21cf87ebeabf/CHANGELOG.md#563 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-3199
⚠️ CVE-2023-22894 (https://secdb.nttzen.cloud/cve/detail/CVE-2023-22894)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://strapi.io/blog/security-disclosure-of-vulnerabilities-cve ; https://github.com/strapi/strapi/releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2023-22894
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261008 #cisa20261008 #cve_2015_3306 #cve_2015_5477 #cve_2016_3081 #cve_2021_3199 #cve_2023_22894 #cve20153306 #cve20155477 #cve20163081 #cve20213199 #cve202322894
##CVE ID: CVE-2016-3081
Vendor: Apache
Product: Struts
Date Added: 2026-10-08
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2016-3081
CVE-2026-77525 MaxKB 2.10.2-lts and earlier: IDOR lets any workspace user read another app's chat records by reusing chat_id. CVSS 4.2, no patch yet. Restrict access or update when fixed. https://www.valtersit.com/cve/CVE-2026-77525/ #CVE #infosec #MaxKB
##CVE-2026-77518 MaxKB auth bypass leaks MCP tool config incl. headers to any workspace user. CVSS 5.0, no patch yet. Restrict access or update when fixed. https://www.valtersit.com/cve/CVE-2026-77518/ #CVE #infosec #MaxKB
##3 posts
10 repos
https://github.com/amier-ge/CVE-2026-72898
https://github.com/d-maggipinto/CVE-2026-72898-metabase-sqli
https://github.com/VuxNx/CVE-2026-72898
https://github.com/0xBlackash/CVE-2026-72898
https://github.com/4minx/CVE-2026-72898
https://github.com/codeb0ssx/CVE-2026-72898-PoC
https://github.com/34zY/CVE-2026-72898
https://github.com/ubitquity/Metabase-Setup-Endpoint-SQLi-Fix
直近で相次いでいる国内組織における不正アクセスに関する注意喚起 https://www.jpcert.or.jp/m/at/2026/at260030.html 2026-10-08
JPCERT/CCに寄せられた情報などでは:
ケースA:...既知の脆弱性を探索し攻撃試行するもの
ケースB:API経由での不正な操作
ケースC:MetabaseのSQLインジェクションの脆弱性(CVE-2026-72898)
ケースBの場合:
(a)一般公開しているスマートフォンアプリを解析しAPIのエンドポイントやキーを特定する
(b)本来画面操作では実行できない内部APIに対する攻撃
(c)他のシステムの侵害で窃取したAPIキーを使用する
直近で相次いでいる国内組織における不正アクセスに関する注意喚起 https://www.jpcert.or.jp/m/at/2026/at260030.html 2026-10-08
JPCERT/CCに寄せられた情報などでは:
ケースA:...既知の脆弱性を探索し攻撃試行するもの
ケースB:API経由での不正な操作
ケースC:MetabaseのSQLインジェクションの脆弱性(CVE-2026-72898)
ケースBの場合:
(a)一般公開しているスマートフォンアプリを解析しAPIのエンドポイントやキーを特定する
(b)本来画面操作では実行できない内部APIに対する攻撃
(c)他のシステムの侵害で窃取したAPIキーを使用する
JPCERT/CC has issued a warning on the wave of data breaches at Japanese organizations since around September.
Not one shared flaw. Three patterns:
- Scanning each target for known vulns and exposed config/backup files
- Internal API abuse, with endpoints and keys pulled from public smartphone apps
- Metabase SQLi (CVE-2026-72898)
Attacker IPs published. Macnica counts 119 similar breaches in Japan this year, 81 since July.
https://japancyberwatch.com/articles/jpcert-warning-api-abuse-japan-breach-wave-2026
##🟠 CVE-2026-106433 - High (8.8)
Improper state management in MongoDB libmongocrypt can cause provider-specific data to be treated as an incompatible type when cleaning up a key document containing duplicate masterKey fields. An authenticated actor who can modify key vault docume...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-106433/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-107332 - Insecure default file permissions on cached credentials in AWS Toolkit for Visual Studio Code
Bulletin ID: 2026-129-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 10/08/2026 10:30 PM PDT
Description:
AWS Toolkit for Visual Studio Code is an open source extension that lets developers ...
https://aws.amazon.com/security/security-bulletins/rss/2026-129-aws/
##Four critical Argo CD vulnerabilities, including AppProject bypass CVE-2026-77459, threaten the repo-server and clusters. Upgrade to v3.5.4 now.
#ArgoCD #Kubernetes #GitOps #CVE202677459 #Kustomize #Jsonnet #DevSecOps #Vulnerability
##A Gitea security update fixes 27 flaws, including SSRF bug CVE-2026-101027 and SSH key flaw CVE-2026-103059. Upgrade to Gitea 28.1.0 now.
#Gitea #Git #DevSecOps #SSRF #CVE2026101027 #CVE2026103059 #SupplyChainSecurity #Vulnerability
https://securityonline.info/gitea-security-update-28/?utm_source=mastodon&utm_medium=jetpack_social
##A Gitea security update fixes 27 flaws, including SSRF bug CVE-2026-101027 and SSH key flaw CVE-2026-103059. Upgrade to Gitea 28.1.0 now.
#Gitea #Git #DevSecOps #SSRF #CVE2026101027 #CVE2026103059 #SupplyChainSecurity #Vulnerability
https://securityonline.info/gitea-security-update-28/?utm_source=mastodon&utm_medium=jetpack_social
##CVE-2026-103416: CRITICAL out-of-bounds write in Eclipse ThreadX NetX Duo (≤6.5.1.202602). Exploitable pre-cert auth; risk of code execution or DoS. Patch not released — check vendor updates. https://radar.offseq.com/threat/cve-2026-103416-cwe-787-out-of-bounds-write-in-eclipse-foundation-eclipse-threadx-netx-duo-509a4f871398c232 #OffSeq #CVE2026103416 #infosec #vuln
##