## Updated at UTC 2026-07-30T20:09:23.060378

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-62663 7.5 0.00% 2 0 2026-07-30T19:26:51.190000 Banks generates meaningful LLM prompts using a simple template language. In vers
CVE-2026-67437 7.5 0.35% 1 0 2026-07-30T19:21:23.297000 OliveTin gives access to predefined shell commands from a web interface. From 30
CVE-2026-54719 7.5 0.28% 1 0 2026-07-30T19:19:45.637000 goshs is a feature-rich single-binary file server for red teamers and developers
CVE-2026-59933 7.5 0.69% 1 0 2026-07-30T19:19:45.637000 PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files.
CVE-2026-12940 9.8 0.00% 2 0 2026-07-30T19:17:05.170000 IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote
CVE-2026-16727 0 0.09% 1 0 2026-07-30T19:08:40.437000 Concurrent Execution using Shared Resource with Improper Synchronization (“Race
CVE-2026-55389 7.5 0.36% 1 0 2026-07-30T19:07:59.843000 datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, a
CVE-2026-9322 7.5 0.00% 2 0 2026-07-30T18:31:47 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv
CVE-2026-66066 None 0.00% 12 3 2026-07-30T18:23:34 ### Impact In its default configuration, a Rails application that displays image
CVE-2026-54365 7.5 0.00% 1 0 2026-07-30T16:45:00.353000 CentreStack before 17.3 contains an unauthenticated deserialization vulnerabilit
CVE-2026-66754 5.9 0.40% 1 1 2026-07-30T16:41:25.650000 Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the
CVE-2026-58043 7.5 0.14% 4 0 2026-07-30T16:33:59.580000 A flaw in Node.js Permission Model enforcement can over-grant filesystem access
CVE-2026-56850 4.1 0.08% 1 0 2026-07-30T16:33:59.580000 A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key co
CVE-2026-59310 9.8 0.00% 3 0 2026-07-30T16:17:15.183000 VMware vCenter contains a directory traversal vulnerability in the Syslog server
CVE-2026-59309 9.8 0.00% 4 0 2026-07-30T16:17:15.073000 VMware vCenter contains an authentication bypass vulnerability in the VMware Dir
CVE-2026-16610 9.8 0.58% 2 0 2026-07-30T16:16:57.050000 The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to
CVE-2026-48449 10.0 0.54% 2 0 2026-07-30T14:54:03.443000 Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi
CVE-2026-67428 8.5 0.34% 1 0 2026-07-30T14:48:09 ## Summary Numerous HTTP-emitting modules (`core.api.http_get`, `core.api.http_p
CVE-2026-67429 10.0 0.49% 1 0 2026-07-30T14:46:44 ## Summary `image.download` fetches a URL and writes the response to disk. It d
CVE-2026-67432 7.5 0.44% 1 0 2026-07-30T14:44:08 ## Summary An unauthenticated remote attacker can force any MCP Ruby SDK server
CVE-2026-44106 7.8 0.23% 2 0 2026-07-30T14:31:21.447000 A privilege escalation vulnerability in the init-script for user-applications al
CVE-2026-44101 9.8 0.40% 1 0 2026-07-30T14:31:21.447000 Due to missing authentication the CHARX OCPP Agent service allows an unauthentic
CVE-2026-44105 6.6 0.09% 1 0 2026-07-30T14:31:21.447000 The credentials for the local user "user-app" may be exposed in log files, poten
CVE-2026-44093 7.8 0.23% 1 0 2026-07-30T14:31:21.447000 A local privilege escalation vulnerability in the init-script for user-applicati
CVE-2026-44103 5.3 0.24% 1 0 2026-07-30T14:31:21.447000 An unauthenticated remote attacker can inject malicious firmware into the intern
CVE-2026-14168 8.8 0.28% 2 0 2026-07-30T14:31:21.447000 A low privileged remote attacker can gain administrator privileges due to missin
CVE-2026-5487 7.5 1.54% 1 0 2026-07-30T14:18:46.477000 DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnera
CVE-2026-5491 7.5 1.54% 1 0 2026-07-30T14:18:46.477000 DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnera
CVE-2026-47876 9.3 0.00% 5 0 2026-07-30T14:16:58.467000 VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual
CVE-2026-14356 8.8 0.27% 1 0 2026-07-30T14:16:46.943000 The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in a
CVE-2026-18220 7.8 0.19% 1 1 2026-07-30T14:15:31.167000 An out-of-bounds write vulnerability was found in the BFD library's DLX ELF back
CVE-2026-14981 7.5 0.26% 1 0 2026-07-30T14:08:40.373000 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv
CVE-2026-20316 5.3 0.79% 11 0 2026-07-30T13:13:12.683000 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2026-18363 None 0.00% 1 0 2026-07-30T12:32:26 A logic vulnerability in the password reset token validation routine implemented
CVE-2026-64560 7.8 0.11% 2 0 2026-07-30T12:32:18 In the Linux kernel, the following vulnerability has been resolved: posix-cpu-t
CVE-2026-44095 7.8 0.23% 2 0 2026-07-30T09:31:24 A privilege escalation vulnerability in a script used for network configuration
CVE-2026-44108 9.8 0.46% 2 0 2026-07-30T09:31:24 Due to a flaw in the execution order of scripts during shutdown, the firewall is
CVE-2026-44107 7.5 0.31% 2 0 2026-07-30T09:31:24 A reboot of the charging controller can be triggered via Modbus TCP without auth
CVE-2026-7849 9.8 0.42% 2 0 2026-07-30T09:31:24 Due to improper neutralization of special elements, an unauthenticated remote at
CVE-2026-44094 8.6 0.26% 1 0 2026-07-30T09:31:24 An unauthenticated remote attacker can enforce the system to fall back to a firm
CVE-2026-44102 5.3 0.21% 1 0 2026-07-30T09:31:24 An unauthenticated remote attacker can trigger a firmware update download via th
CVE-2026-44104 9.8 0.24% 1 0 2026-07-30T09:31:24 The firmware update process for the basemodule of the charging controller only v
CVE-2026-44092 9.1 0.38% 1 0 2026-07-30T09:31:24 An unauthenticated remote attacker can inject malicious input into the ModbusSer
CVE-2026-44091 9.1 0.33% 1 0 2026-07-30T09:31:24 An unauthenticated remote attacker can post a malicious ID to the MQTT Broker re
CVE-2026-44090 9.8 0.40% 1 0 2026-07-30T09:31:24 Due to missing authentication, an unauthenticated remote attacker may access the
CVE-2026-44098 8.6 1.37% 1 0 2026-07-30T09:31:18 This vulnerability allows an unauthenticated remote attacker with control over t
CVE-2026-44099 7.8 0.23% 1 0 2026-07-30T09:31:18 A privilege escalation vulnerability in the system configuration allows a low-pr
CVE-2026-44100 9.4 0.28% 1 0 2026-07-30T09:31:18 The CHARX JupiCore service allows an unauthenticated remote attacker to reconfig
CVE-2026-44097 7.1 0.24% 1 0 2026-07-30T09:31:18 A low-privileged remote attacker with "operator" access can upload arbitrary fil
CVE-2026-44096 7.8 0.23% 1 0 2026-07-30T09:31:18 A privilege escalation vulnerability in udhcpc allows a local user "charx-web" t
CVE-2026-64531 7.8 0.12% 1 0 2026-07-30T06:33:35 In the Linux kernel, the following vulnerability has been resolved: net: openvs
CVE-2026-58046 9.9 0.31% 2 0 2026-07-30T06:32:44 Improper neutralization in the Plesk XML-RPC API allows a remote authenticated l
CVE-2026-58066 9.8 0.21% 1 0 2026-07-30T06:32:44 Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7,
CVE-2026-1360 7.5 0.57% 1 0 2026-07-30T06:32:43 The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untruste
CVE-2026-48448 8.6 0.37% 1 0 2026-07-30T03:31:28 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia
CVE-2026-67595 8.1 0.42% 2 0 2026-07-30T00:31:19 VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript p
CVE-2026-5490 8.8 0.48% 1 1 2026-07-29T21:31:08 DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability a
CVE-2026-6267 8.5 0.34% 2 0 2026-07-29T21:31:08 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.
CVE-2026-5056 7.8 0.43% 1 0 2026-07-29T21:31:08 GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerabilit
CVE-2026-13308 8.1 0.57% 1 0 2026-07-29T21:31:08 Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Executi
CVE-2026-6102 7.8 0.09% 1 0 2026-07-29T21:31:08 MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulner
CVE-2026-14529 9.4 0.33% 1 0 2026-07-29T21:31:07 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv
CVE-2026-15975 7.5 0.39% 1 0 2026-07-29T21:31:07 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8
CVE-2026-5057 7.5 0.48% 1 0 2026-07-29T21:31:07 ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability.
CVE-2026-67201 8.6 0.39% 1 0 2026-07-29T20:17:11.330000 V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery
CVE-2026-43698 7.8 0.15% 1 0 2026-07-29T19:16:45.967000 An injection issue was addressed with improved validation. This issue is fixed i
CVE-2026-67215 7.5 0.35% 1 0 2026-07-29T15:31:12 cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack ex
CVE-2026-0667 None 0.37% 1 0 2026-07-29T15:31:11 CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that
CVE-2026-66748 8.8 0.79% 1 1 2026-07-29T15:31:05 Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code
CVE-2026-66745 7.5 0.32% 1 0 2026-07-29T15:16:30.153000 Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) con
CVE-2026-54650 8.6 0.36% 1 0 2026-07-29T15:16:25.093000 openhole exposes localhost to the internet in one command. In 0.1.1 and earlier,
CVE-2026-65883 None 0.50% 3 0 2026-07-29T12:31:30 Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Ca
CVE-2026-14270 8.8 0.55% 1 0 2026-07-29T12:31:30 The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCom
CVE-2026-35226 6.5 0.17% 1 0 2026-07-29T09:31:37 An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows a
CVE-2026-18197 None 0.27% 1 0 2026-07-29T09:31:36 Improper neutralization of input during web page generation ('cross-site scripti
CVE-2026-18072 9.8 0.59% 2 0 2026-07-29T06:32:11 The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick
CVE-2026-12144 8.8 0.37% 1 0 2026-07-29T03:30:21 The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Es
CVE-2026-54658 9.8 0.40% 1 0 2026-07-28T22:19:24 ### Impact A SQL injection vulnerability exists in the `escapeValue()` function
CVE-2026-54638 7.5 0.35% 1 0 2026-07-28T22:15:29 ### Impact A remote, unauthenticated attacker can cause excessive memory alloca
CVE-2026-64863 9.1 0.34% 1 0 2026-07-28T22:03:13 ## Summary The WebDAV mode-flag guard added to fix GHSA-3whc-qvhv-xqjp still do
CVE-2026-62325 9.1 0.34% 1 0 2026-07-28T21:57:19 ## Summary Start goshs v2.1.3 with `-b 'admin:' -sftp`. No `-fkf`. SFTP accepts
CVE-2026-55391 7.5 0.20% 1 0 2026-07-28T21:45:50 ### Summary `datamodel-code-generator`'s anti-SSRF guard validates the resolved
CVE-2026-14973 9.3 0.45% 1 0 2026-07-28T21:31:45 IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow fil
CVE-2026-15057 7.5 0.26% 1 0 2026-07-28T21:31:45 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerab
CVE-2026-14996 8.2 0.22% 1 0 2026-07-28T21:31:45 IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related
CVE-2026-7769 8.1 0.27% 1 0 2026-07-28T21:31:39 IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2
CVE-2026-55390 7.5 0.36% 2 0 2026-07-28T21:26:42 ### Summary When generating models from an XML Schema (`--input-file-type xmlsc
CVE-2026-43749 7.8 0.15% 1 0 2026-07-28T19:52:21.577000 A parsing issue in the handling of directory paths was addressed with improved p
CVE-2026-5674 8.8 0.12% 2 0 2026-07-28T17:16:52.923000 A flaw was found in PipeWire, a multimedia server. This vulnerability allows an
CVE-2026-54635 7.5 0.42% 1 0 2026-07-28T17:09:03 ## Webhook Custom Path Authentication Bypass in pytonapi ### Summary `TonapiWe
CVE-2026-63077 9.8 0.65% 5 0 2026-07-28T16:17:58.820000 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe
CVE-2026-59878 7.5 0.55% 1 0 2026-07-28T15:32:25 Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ
CVE-2026-63727 8.8 0.26% 1 0 2026-07-28T15:32:19 Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper
CVE-2026-7187 8.8 0.21% 1 0 2026-07-28T15:32:18 Missing authentication for critical function vulnerability in Universal Software
CVE-2026-61609 7.5 0.39% 1 0 2026-07-28T14:58:00 ### Summary The `authentication` rate limiter used for the login and two-factor
CVE-2026-45293 8.6 0.18% 1 0 2026-07-28T14:28:13 ### Impact WordPress Coding Standards (WordPressCS) versions before 3.4.1 conta
CVE-2025-15467 8.8 47.62% 1 6 2026-07-28T13:17:14.747000 Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with malic
CVE-2026-16462 9.8 0.42% 1 0 2026-07-28T12:31:27 In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This a
CVE-2026-14169 8.1 0.29% 2 0 2026-07-28T09:31:36 Due to incorrect behavior order a low privileged remote attacker could trigger a
CVE-2026-14167 8.8 0.28% 2 0 2026-07-28T09:31:36 A low privileged remote attacker can perform privileged configuration changes re
CVE-2026-14171 6.1 0.18% 2 0 2026-07-28T09:31:35 An unauthenticated remote attacker can abuse the improper validation of the post
CVE-2026-43723 7.8 0.15% 1 0 2026-07-28T00:32:06 A path handling issue was addressed with improved validation. This issue is fixe
CVE-2026-39874 7.8 0.11% 1 0 2026-07-28T00:32:04 A permissions issue was addressed with additional restrictions. This issue is fi
CVE-2026-66473 7.5 0.20% 1 0 2026-07-28T00:31:11 Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
CVE-2026-43776 7.8 0.15% 1 0 2026-07-28T00:31:02 A buffer overflow was addressed with improved bounds checking. This issue is fix
CVE-2026-16812 10.0 0.88% 6 0 2026-07-27T21:31:22 VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may a
CVE-2025-68686 5.9 1.26% 2 0 2026-07-27T18:31:25 An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE
CVE-2026-61511 9.8 1.27% 4 6 2026-07-27T15:32:39 vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vul
CVE-2026-66373 7.5 0.47% 1 0 2026-07-25T03:30:55 Redis before 8.8.0, in the unusual case where an authenticated attacker can exec
CVE-2026-59952 None 0.52% 1 0 2026-07-24T16:14:33 ## Summary `valibot` 1.4.1 can throw a `TypeError` inside its `flatten()` helpe
CVE-2026-42933 10.0 0.29% 1 0 2026-07-24T00:32:40 Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or inter
CVE-2026-21655 None 0.17% 1 0 2026-07-23T21:31:03 Deserialization of untrusted data vulnerability in Johnson Control victor on Win
CVE-2026-59932 7.5 0.69% 1 0 2026-07-23T15:00:18 ## Summary PhpSpreadsheet's Gnumeric reader reads attacker-supplied `.gnumeric`
CVE-2026-59931 7.7 0.53% 1 0 2026-07-23T14:55:51 ### Summary The domain whitelist introduced in PhpSpreadsheet 5.4.0 for the `WE
CVE-2026-43503 8.8 0.34% 1 9 2026-07-23T11:10:00.120000 In the Linux kernel, the following vulnerability has been resolved: net: skbuff
CVE-2026-16723 9.0 0.41% 2 5 2026-07-23T09:32:08 A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.
CVE-2026-16232 9.1 69.97% 7 2 template 2026-07-22T21:32:05 An authentication bypass vulnerability in the Check Point SmartConsole login pro
CVE-2026-50502 8.0 0.60% 1 0 2026-07-22T16:18:05.400000 Insufficient granularity of access control in Windows Event Logging Service allo
CVE-2026-2291 7.3 0.92% 2 1 2026-07-20T21:31:40 dnsmasqs extract_name() function can be abused to cause a heap buffer overflow,
CVE-2026-53362 7.8 0.27% 1 0 2026-07-18T09:32:17 In the Linux kernel, the following vulnerability has been resolved: ipv6: accou
CVE-2026-42530 8.1 3.68% 2 3 2026-07-16T12:33:31 NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGI
CVE-2026-42533 8.1 3.60% 1 9 2026-07-15T15:33:14 A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive
CVE-2026-54121 8.8 1.05% 2 8 2026-07-14T18:32:37 Improper authorization in Active Directory Certificate Services (AD CS) allows a
CVE-2026-50469 7.8 0.27% 1 0 2026-07-14T18:32:32 Improper link resolution before file access ('link following') in Windows Projec
CVE-2026-59726 10.0 0.48% 1 1 2026-07-10T19:15:15.780000 Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo
CVE-2026-58025 9.8 0.33% 2 1 2026-07-09T19:34:14.067000 Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWik
CVE-2026-5172 7.3 2.68% 2 2 2026-06-30T03:37:45 A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker t
CVE-2026-10702 4.3 0.72% 1 1 2026-06-30T03:36:54 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w
CVE-2026-0160 8.8 0.23% 1 0 2026-06-17T19:22:02.480000 In TextRtpPayloadDecoderNode::DecodeT140 of TextRtpPayloadDecoderNode.cpp, there
CVE-2026-0149 8.8 0.29% 1 0 2026-06-17T18:36:28 In RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap bu
CVE-2026-22796 5.3 0.50% 2 0 2026-06-17T10:20:26.697000 Issue summary: A type confusion vulnerability exists in the signature verificati
CVE-2026-22795 5.5 0.14% 2 0 2026-06-17T10:20:26.520000 Issue summary: An invalid or NULL pointer dereference can happen in an applicati
CVE-2025-69421 7.5 0.84% 2 1 2026-06-17T10:00:40.683000 Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer de
CVE-2025-69420 7.5 0.77% 2 1 2026-06-17T10:00:40.067000 Issue summary: A type confusion vulnerability exists in the TimeStamp Response v
CVE-2025-15435 7.3 0.35% 2 0 2026-06-17T08:37:46.203000 A flaw has been found in Yonyou KSOA 9.0. Affected by this vulnerability is an u
CVE-2024-1813 9.8 1.11% 1 2 2026-06-17T07:05:03.993000 The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection
CVE-2014-0160 7.5 100.00% 1 75 2026-06-17T00:02:24.467000 The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not p
CVE-2013-4786 7.5 78.57% 1 1 2026-06-16T23:57:53.617000 The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (R
CVE-2026-40510 3.8 0.22% 2 0 2026-05-29T15:30:38 OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overf
CVE-2026-42897 8.1 5.64% 5 1 2026-05-15T18:30:32 Improper neutralization of input during web page generation ('cross-site scripti
CVE-2025-69418 4.0 0.11% 2 1 2026-05-12T15:31:14 Issue summary: When using the low-level OCB API directly with AES-NI or<br>other
CVE-2025-69419 7.4 0.44% 2 1 2026-05-12T15:31:14 Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously craft
CVE-2025-68160 4.7 0.15% 2 0 2026-05-12T15:31:14 Issue summary: Writing large, newline-free data into a BIO chain using the line-
CVE-2026-4893 5.3 2.68% 2 5 2026-05-11T21:31:33 An information disclosure vulnerability in dnsmasq allows remote attackers to by
CVE-2026-20079 10.0 38.70% 2 1 2026-03-04T18:32:03 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2026-1623 6.3 2.18% 1 1 2026-01-29T21:30:37 A weakness has been identified in Totolink A7000R 4.1cu.4154. Impacted is the fu
CVE-2023-37327 7.6 1.71% 2 0 2025-11-04T21:32:34 GStreamer FLAC File Parsing Integer Overflow Remote Code Execution Vulnerability
CVE-2023-5217 8.8 49.01% 1 3 2024-02-15T15:02:28 Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5
CVE-2008-1028 None 4.55% 1 0 2023-01-31T05:05:55 Unspecified vulnerability in AppKit in Apple Mac OS X before 10.5 allows user-as
CVE-2026-53921 0 0.00% 3 2 N/A
CVE-2026-58086 0 0.00% 1 0 N/A
CVE-2026-56848 0 0.00% 4 0 N/A
CVE-2026-56846 0 0.00% 2 0 N/A
CVE-2026-65094 0 0.00% 1 0 N/A

CVE-2026-62663
(7.5 HIGH)

EPSS: 0.00%

updated 2026-07-30T19:26:51.190000

2 posts

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filters (image, audio, video, document) in banks accept untrusted user input as file paths via Path(value) and pass them directly to open(file_path, "rb") without any path sanitization, canonicalization, or directory restriction. An attacker who controls template variables passed to

thehackerwire@mastodon.social at 2026-07-30T18:00:38.000Z ##

🟠 CVE-2026-62663 - High (7.5)

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filters (image, audio, video, document) in banks accept untrusted user input as file paths via Path(value) and pass them directly t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-30T18:00:38.000Z ##

🟠 CVE-2026-62663 - High (7.5)

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filters (image, audio, video, document) in banks accept untrusted user input as file paths via Path(value) and pass them directly t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67437
(7.5 HIGH)

EPSS: 0.35%

updated 2026-07-30T19:21:23.297000

1 posts

OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_auth_oauth2.go OAuth2 login handler stores per-login state in the registeredStates map on every /oauth/login request without expiring, deleting, or bounding entries, allowing an unauthenticated attacker to exhaust memory and cause a denial of service. T

thehackerwire@mastodon.social at 2026-07-29T21:59:48.000Z ##

🟠 CVE-2026-67437 - High (7.5)

OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_auth_oauth2.go OAuth2 login handler stores per-login state in the registeredStates map on every /oau...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54719
(7.5 HIGH)

EPSS: 0.28%

updated 2026-07-30T19:19:45.637000

1 posts

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?bulk&file= ZIP downloads did not call findEffectiveACL or applyCustomAuth, allowing unauthenticated reads of files protected only by .goshs folder ACLs and block lists. This issue is fixed in version 2.1.1. This vulnerability exists due to an incomple

thehackerwire@mastodon.social at 2026-07-29T00:00:31.000Z ##

🟠 CVE-2026-54719 - High (7.5)

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?bulk&file= ZIP downloads did not call findEffectiveACL or applyCustomAuth, allowing unauthenticate...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59933
(7.5 HIGH)

EPSS: 0.69%

updated 2026-07-30T19:19:45.637000

1 posts

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, and all releases up to and including 1.30.5, the OLE reader follows sector chains from attacker-controlled XLS/OLE metadata without detecting cycles or enforcing a maximum chain length. A tiny malformed .xls/OLE file can s

thehackerwire@mastodon.social at 2026-07-28T19:00:00.000Z ##

🟠 CVE-2026-59933 - High (7.5)

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, and all releases up to and including 1.30.5, the OLE reader follows s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12940
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-07-30T19:17:05.170000

2 posts

IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py where the DANGEROUS_ENV_VARS blocklist fails to include SHELLOPTS , BASHOPTS , and PS4 environment variables.

thehackerwire@mastodon.social at 2026-07-30T18:00:48.000Z ##

🔴 CVE-2026-12940 - Critical (9.8)

IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py whe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-30T18:00:48.000Z ##

🔴 CVE-2026-12940 - Critical (9.8)

IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py whe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16727
(0 None)

EPSS: 0.09%

updated 2026-07-30T19:08:40.437000

1 posts

Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows a local user to execute arbitrary code with elevated privileges via a crafted file replacement. Refer to the ' Security Update for ASUS Armoury Crate ' section on the ASUS Security Advisory for more information.

offseq@infosec.exchange at 2026-07-30T03:00:24.000Z ##

CVE-2026-16727 (HIGH): Race condition in ASUS Armoury Crate 5.4.1 lets local users escalate privileges via improper synchronization. No patch available. Limit local access & monitor systems. radar.offseq.com/threat/cve-20 #OffSeq #CVE202616727 #ASUS #Vuln

##

CVE-2026-55389
(7.5 HIGH)

EPSS: 0.36%

updated 2026-07-30T19:07:59.843000

1 posts

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.62.0, datamodel-code-generator resolves JSON Schema $ref targets in src/datamodel_code_generator/parser/jsonschema.py through is_url and _get_ref_body without containing file:// or ../ traversal references to th

thehackerwire@mastodon.social at 2026-07-28T23:00:27.000Z ##

🟠 CVE-2026-55389 - High (7.5)

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.62.0, datamodel-code-generator resolves JSON Schema $ref t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9322
(7.5 HIGH)

EPSS: 0.00%

updated 2026-07-30T18:31:47

2 posts

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.

thehackerwire@mastodon.social at 2026-07-30T18:00:27.000Z ##

🟠 CVE-2026-9322 - High (7.5)

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-30T18:00:27.000Z ##

🟠 CVE-2026-9322 - High (7.5)

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66066(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-07-30T18:23:34

12 posts

### Impact In its default configuration, a Rails application that displays image variants may allow an unauthenticated attacker to read arbitrary files from the server, including the process environment. That environment typically holds `secret_key_base` and often credentials for external systems, which may in turn allow escalation to remote code execution or lateral movement to those systems. ##

3 repos

https://github.com/0xBlackash/CVE-2026-66066

https://github.com/Zer0SumGam3/CVE-2026-66066-POC

https://github.com/paveg/rails-activestorage-vips-audit

AAKL at 2026-07-30T16:38:45.144Z ##

New.

Rapaid7: KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails rapid7.com/blog/post/etr-kinda @Rapid7Official

The related Ruby on Rails advisory was published yesterday: Possible arbitrary file read and remote code execution in Active Storage variant processing github.com/rails/rails/securit

##

lobsters@mastodon.social at 2026-07-30T15:10:13.000Z ##

KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066) lobste.rs/s/kkobew #ruby #security
ethiack.com/info-hub/research/

##

_r_netsec at 2026-07-30T14:13:05.219Z ##

KindaRails2Shell: arbitrary file read to RCE in Rails Active Storage via libvips (CVE-2026-66066) ethiack.com/info-hub/research/

##

AAKL@infosec.exchange at 2026-07-30T16:38:45.000Z ##

New.

Rapaid7: KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails rapid7.com/blog/post/etr-kinda @Rapid7Official

The related Ruby on Rails advisory was published yesterday: Possible arbitrary file read and remote code execution in Active Storage variant processing github.com/rails/rails/securit #infosec #vulnerability #Ruby

##

lobsters@mastodon.social at 2026-07-30T15:10:13.000Z ##

KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066) lobste.rs/s/kkobew #ruby #security
ethiack.com/info-hub/research/

##

_r_netsec@infosec.exchange at 2026-07-30T14:13:05.000Z ##

KindaRails2Shell: arbitrary file read to RCE in Rails Active Storage via libvips (CVE-2026-66066) ethiack.com/info-hub/research/

##

jbhall56@infosec.exchange at 2026-07-30T12:07:40.000Z ##

Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials, and API tokens. thehackernews.com/2026/07/crit

##

manyfold@3dp.chat at 2026-07-30T11:42:10.000Z ##

🚨 Manyfold v0.147.1 is out, with a security fix for #Rails CVE-2026-66066. Update your instances! 🚨

##

raul@mastodon.in4matics.cat at 2026-07-30T10:16:42.000Z ##

CVE-2026-66066: un atacant pot llegir fitxers del servidor Rails gràcies a Active Storage + libvips. secret_key_base, master.key, credencials de cloud — tot a l'abast. I després fer RCE amb les claus robades. 🎯

Parcheja a: activestorage 7.2.3.2 / 8.0.5.1 / 8.1.3.1 o libvips ≥ 8.13.0

Si encara uses libvips vell, posa VIPS_BLOCK_UNTRUSTED i resa.

#rails #cybersecurity #RCE #CVE

##

beyondmachines1@infosec.exchange at 2026-07-30T08:01:39.000Z ##

Critical Rails Active Storage Flaw Allows Unauthenticated Arbitrary File Read

Ruby on Rails patched a critical vulnerability (CVE-2026-66066) in Active Storage that allows unauthenticated attackers to read arbitrary server files and steal sensitive secrets.

**Update Rails immediately to a patched version (7.2.3.2, 8.0.5.1, or 8.1.3.1) and make sure libvips is upgraded to 8.13 or later. A public exploit is already available and attacks are expected soon. Because attackers may have already stolen your secrets, rotate every credential the app could access, including secret_key_base, the master key, database passwords, and all API tokens after patching.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

DailyCyberSecurity@infosec.exchange at 2026-07-30T03:01:51.000Z ##

A Rails Active Storage flaw, CVE-2026-66066 (CVSS 9.5), enables arbitrary file read and remote code execution. Patch Rails and rotate secrets now.

#RubyOnRails #ActiveStorage #CVE202666066 #RCE #libvips #InfoSec

securityonline.info/rails-cve-

##

christine@ruby.social at 2026-07-29T18:17:08.000Z ##

RE: christine-seeman.com/cve-2026-

Patch your #rails there's a new CVE out there specifically about active storage and if your app accepts image uploads.

#ruby #rubyonrails

##

CVE-2026-54365
(7.5 HIGH)

EPSS: 0.00%

updated 2026-07-30T16:45:00.353000

1 posts

CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endpoints. Attackers can send a malicious StorageConfigure parameter to the jsonimportuserbyupn, jsonimportuserbyupnex, or japiimportuserbyupn endpoints t

hugovalters@mastodon.social at 2026-07-30T18:06:31.000Z ##

CVE-2026-54365 Unauthenticated deserialization in Centrestack. Attackers create local OS accounts via crafted XML. CVSS 7.5. No patch yet – isolate systems. #CVE #Centrestack #cybersecurity

valtersit.com/cve/CVE-2026-543

##

CVE-2026-66754
(5.9 MEDIUM)

EPSS: 0.40%

updated 2026-07-30T16:41:25.650000

1 posts

Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that allows remote unauthenticated attackers to crash the server by sending a crafted percent-encoded URL. Attackers can send a request whose decoded path matches a configured prefix while the raw percent-encoded path does not, causing the assert! to fail and triggering either a 500 erro

1 repos

https://github.com/theopaid/CVE-2026-66754-Remote-Denial-of-Service-via-Reachable-Assertion-in-URL-Prefix-Handling-rouille-

thehackerwire@mastodon.social at 2026-07-28T17:00:26.000Z ##

🟠 CVE-2026-66754 - High (7.5)

Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that allows remote unauthenticated attackers to crash the server by sending a crafted percent-encoded URL. Attackers can send a request...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58043
(7.5 HIGH)

EPSS: 0.14%

updated 2026-07-30T16:33:59.580000

4 posts

A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**.

thehackerwire@mastodon.social at 2026-07-30T07:00:10.000Z ##

🟠 CVE-2026-58043 - High (7.5)

A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries.

Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T17:29:15.000Z ##

2026-07-29, Version 24.18.1 'Krypton' (LTS), @juanarbol

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:01.000Z ##

2026-07-29, Version 26.5.1 (Current), @RafaelGSS

This is a security release. Notable Changes (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:00.000Z ##

2026-07-29, Version 22.23.2 'Jod' (LTS), @marco-ippolito

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

CVE-2026-56850
(4.1 MEDIUM)

EPSS: 0.08%

updated 2026-07-30T16:33:59.580000

1 posts

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:01.000Z ##

2026-07-29, Version 26.5.1 (Current), @RafaelGSS

This is a security release. Notable Changes (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX...

github.com/nodejs/node/release

#nodejs #javascript

##

CVE-2026-59310
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-07-30T16:17:15.183000

3 posts

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

Analyst207@mastodon.social at 2026-07-30T18:27:06.000Z ##

Broadcom Disrupts VMware with Emergency Patches for Critical Flaws

Broadcom has just released emergency security patches to tackle critical flaws in VMware's vCenter, ESX, Workstation, and Fusion - and it's urging admins to act fast, treating affected systems as immediately vulnerable. Three critical vulnerabilities, including CVE-2026-59309, CVE-2026-59310, and CVE-2026-47876, are among the five…

osintsights.com/broadcom-disru

#Vmware #Broadcom #EmergencyPatches #CriticalFlaws #Cve202659309

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T12:48:35.000Z ##

Broadcom patched a critical VMware vCenter vulnerability. CVE-2026-59309 and CVE-2026-59310 both score 9.8 CVSS and allow auth bypass or code execution.

#VMware #vCenter #CVE202659309 #CVE202659310 #ESXi #InfoSec

meterpreter.org/vmware-vcenter

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T10:28:35.000Z ##

Broadcom released updates to fix a critical VMware authentication bypass (CVE-2026-59309). A directory traversal flaw (CVE-2026-59310) was also patched.

#VMware #CyberSecurity #CVE202659309 #InfoSec

securityonline.info/vmware-aut

##

CVE-2026-59309
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-07-30T16:17:15.073000

4 posts

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

Analyst207@mastodon.social at 2026-07-30T18:27:06.000Z ##

Broadcom Disrupts VMware with Emergency Patches for Critical Flaws

Broadcom has just released emergency security patches to tackle critical flaws in VMware's vCenter, ESX, Workstation, and Fusion - and it's urging admins to act fast, treating affected systems as immediately vulnerable. Three critical vulnerabilities, including CVE-2026-59309, CVE-2026-59310, and CVE-2026-47876, are among the five…

osintsights.com/broadcom-disru

#Vmware #Broadcom #EmergencyPatches #CriticalFlaws #Cve202659309

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T12:48:35.000Z ##

Broadcom patched a critical VMware vCenter vulnerability. CVE-2026-59309 and CVE-2026-59310 both score 9.8 CVSS and allow auth bypass or code execution.

#VMware #vCenter #CVE202659309 #CVE202659310 #ESXi #InfoSec

meterpreter.org/vmware-vcenter

##

offseq@infosec.exchange at 2026-07-29T12:00:27.000Z ##

VMware ESXi, vCenter, Workstation, and Fusion patched for CRITICAL flaws: CVE-2026-47876 enables VM escape and host code execution; CVE-2026-59309/59310 impact vCenter auth & RCE. Patch ASAP — no exploitation reported. radar.offseq.com/threat/critic #OffSeq #VMware #Vuln #PatchNow

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T10:28:35.000Z ##

Broadcom released updates to fix a critical VMware authentication bypass (CVE-2026-59309). A directory traversal flaw (CVE-2026-59310) was also patched.

#VMware #CyberSecurity #CVE202659309 #InfoSec

securityonline.info/vmware-aut

##

CVE-2026-16610
(9.8 CRITICAL)

EPSS: 0.58%

updated 2026-07-30T16:16:57.050000

2 posts

The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a publicly emitted nonce with no authentication check, CAPTCHA validation is bypassable by omitting an attacker-supplied key, and repeater row keys from cfgroup[input

thehackerwire@mastodon.social at 2026-07-30T06:00:07.000Z ##

🔴 CVE-2026-16610 - Critical (9.8)

The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a publicly em...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-30T04:30:24.000Z ##

CVE-2026-16610: ASE Pro plugin (≤8.9.0) for WordPress suffers CRITICAL RCE via recursive_html. Unauth attackers can execute code if [post_cf_form] is public. Update/disable plugin ASAP. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE2026_16610 #Security

##

CVE-2026-48449
(10.0 CRITICAL)

EPSS: 0.54%

updated 2026-07-30T14:54:03.443000

2 posts

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

hugovalters@mastodon.social at 2026-07-30T14:04:22.000Z ##

CVE-2026-48449 - Critical RCE in Adobe Campaign Classic. Incorrect Authorization allows code execution without user interaction. CVSS 10. Unpatched - take immediate action. #CVE #Adobe #infosec

valtersit.com/cve/CVE-2026-484

##

thehackerwire@mastodon.social at 2026-07-30T04:00:14.000Z ##

🔴 CVE-2026-48449 - Critical (10)

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67428
(8.5 HIGH)

EPSS: 0.34%

updated 2026-07-30T14:48:09

1 posts

## Summary Numerous HTTP-emitting modules (`core.api.http_get`, `core.api.http_post`, `graphql.query`/`graphql.mutation`, `monitor.http_check`, `communication.slack_send`, `notification.{discord,slack,teams}.send_message`, `ai.vision_analyze` [anthropic path], `verify.visual_diff`, `browser.proxy_rotate`, and the `agent`/`llm` inline base_url branch) perform outbound requests to a fully client-con

thehackerwire@mastodon.social at 2026-07-29T20:00:14.000Z ##

🟠 CVE-2026-67428 - High (8.5)

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules including src/core/modules/third_party/developer/http/requests.py, core.api.http_get, core.api.http_post, graphql.query, graphql.mutat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67429
(10.0 CRITICAL)

EPSS: 0.49%

updated 2026-07-30T14:46:44

1 posts

## Summary `image.download` fetches a URL and writes the response to disk. It does not use the central path guard (`validate_path_with_env_config`, which confines writes to `FLYTO_SANDBOX_DIR`); instead it confines the output to `output_dir`, but `output_dir` is itself a caller parameter. Since the attacker sets both the target and the base it is checked against, the check is meaningless, and att

thehackerwire@mastodon.social at 2026-07-29T20:00:25.000Z ##

🔴 CVE-2026-67429 - Critical (10)

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config and its FLYTO_SANDBOX_DIR confinem...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67432
(7.5 HIGH)

EPSS: 0.44%

updated 2026-07-30T14:44:08

1 posts

## Summary An unauthenticated remote attacker can force any MCP Ruby SDK server using `MCP::Server::Transports::StreamableHTTPTransport` to allocate gigabytes of memory by sending a single oversized JSON-RPC POST. The transport reads the entire HTTP body into a Ruby `String` and parses it with `JSON.parse(body, symbolize_names: true)` with no size limit, no `Content-Length` pre-check, and no stre

thehackerwire@mastodon.social at 2026-07-29T21:00:00.000Z ##

🟠 CVE-2026-67432 - High (7.5)

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem reads and parses an entire JSON-RPC POST body without a size limit, allowing an ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44106
(7.8 HIGH)

EPSS: 0.23%

updated 2026-07-30T14:31:21.447000

2 posts

A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

thehackerwire@mastodon.social at 2026-07-30T10:00:11.000Z ##

🟠 CVE-2026-44106 - High (7.8)

A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44101
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-07-30T14:31:21.447000

1 posts

Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44105
(6.6 MEDIUM)

EPSS: 0.09%

updated 2026-07-30T14:31:21.447000

1 posts

The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local attacker with access to the logs to authenticate via SSH as the limited user "user-app". Charging could be interrupted.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44093
(7.8 HIGH)

EPSS: 0.23%

updated 2026-07-30T14:31:21.447000

1 posts

A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44103
(5.3 MEDIUM)

EPSS: 0.24%

updated 2026-07-30T14:31:21.447000

1 posts

An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware updates without performing integrity or verification check. Successful exploitation may compromise the integrity of the affected device. This vulnerability could be used in chain with CVE-2026-44104.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-14168
(8.8 HIGH)

EPSS: 0.28%

updated 2026-07-30T14:31:21.447000

2 posts

A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access.

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-5487
(7.5 HIGH)

EPSS: 1.54%

updated 2026-07-30T14:18:46.477000

1 posts

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 4568 by default. The issue results from the lack of proper validation of a us

thehackerwire@mastodon.social at 2026-07-30T05:00:28.000Z ##

🟠 CVE-2026-5487 - High (7.5)

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability.
...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5491
(7.5 HIGH)

EPSS: 1.54%

updated 2026-07-30T14:18:46.477000

1 posts

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 6067 by default. The issue results from the lack of proper validation of a us

thehackerwire@mastodon.social at 2026-07-30T02:00:18.000Z ##

🟠 CVE-2026-5491 - High (7.5)

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability.
...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47876
(9.3 CRITICAL)

EPSS: 0.00%

updated 2026-07-30T14:16:58.467000

5 posts

VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.

Analyst207@mastodon.social at 2026-07-30T18:27:06.000Z ##

Broadcom Disrupts VMware with Emergency Patches for Critical Flaws

Broadcom has just released emergency security patches to tackle critical flaws in VMware's vCenter, ESX, Workstation, and Fusion - and it's urging admins to act fast, treating affected systems as immediately vulnerable. Three critical vulnerabilities, including CVE-2026-59309, CVE-2026-59310, and CVE-2026-47876, are among the five…

osintsights.com/broadcom-disru

#Vmware #Broadcom #EmergencyPatches #CriticalFlaws #Cve202659309

##

offseq at 2026-07-30T13:30:31.401Z ##

CRITICAL vuln: CVE-2026-47876 in VMware Cloud Foundation (9.1.x.x/9.0.x.x/5.x) allows VM admin to execute code on host via VMXNET3 adapter. Restrict admin access, use other adapters if possible. Patch not yet available. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-07-30T13:30:31.000Z ##

CRITICAL vuln: CVE-2026-47876 in VMware Cloud Foundation (9.1.x.x/9.0.x.x/5.x) allows VM admin to execute code on host via VMXNET3 adapter. Restrict admin access, use other adapters if possible. Patch not yet available. radar.offseq.com/threat/cve-20 #OffSeq #VMware #InfoSec #CVE202647876

##

jbhall56@infosec.exchange at 2026-07-29T12:17:18.000Z ##

Three of the vulnerabilities have been assigned a ‘critical’ severity rating. One of them is CVE-2026-47876, an out-of-bounds write issue in ESXi’s VMXNET3 virtual network adapter. securityweek.com/critical-vm-e

##

offseq@infosec.exchange at 2026-07-29T12:00:27.000Z ##

VMware ESXi, vCenter, Workstation, and Fusion patched for CRITICAL flaws: CVE-2026-47876 enables VM escape and host code execution; CVE-2026-59309/59310 impact vCenter auth & RCE. Patch ASAP — no exploitation reported. radar.offseq.com/threat/critic #OffSeq #VMware #Vuln #PatchNow

##

CVE-2026-14356
(8.8 HIGH)

EPSS: 0.27%

updated 2026-07-30T14:16:46.943000

1 posts

The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the email address and password of any WordPress user, including administrat

thehackerwire@mastodon.social at 2026-07-30T06:00:27.000Z ##

🟠 CVE-2026-14356 - High (8.8)

The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18220
(7.8 HIGH)

EPSS: 0.19%

updated 2026-07-30T14:15:31.167000

1 posts

An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled relocation type values (via ELF32_R_TYPE(r_info)) before indexing into the dlx_elf_howto_table[] array. The DLX relocation

1 repos

https://github.com/4D4J/objdump-Out-Of-Bounds-write

thehackerwire@mastodon.social at 2026-07-29T15:00:44.000Z ##

🟠 CVE-2026-18220 - High (7.8)

An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds ch...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14981
(7.5 HIGH)

EPSS: 0.26%

updated 2026-07-30T14:08:40.373000

1 posts

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.

thehackerwire@mastodon.social at 2026-07-28T21:59:58.000Z ##

🟠 CVE-2026-14981 - High (7.5)

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20316
(5.3 MEDIUM)

EPSS: 0.79%

updated 2026-07-30T13:13:12.683000

11 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged&nbsp;account. An attacker could exploit this vu

undercodenews@mastodon.social at 2026-07-30T19:28:11.000Z ##

Cisco Warns of Actively Exploited Secure Firewall Zero-Day as Attackers Target Enterprise Defenses + Video

A New Cybersecurity Alarm Inside the Network Security Industry Cisco has issued an urgent security warning after discovering active exploitation of a zero-day vulnerability affecting its Secure Firewall Management Center (FMC) platform. The flaw, tracked as CVE-2026-20316, exposes organizations using vulnerable firewall management systems to potential unauthorized…

undercodenews.com/cisco-warns-

##

guru@thecybersecguru.com at 2026-07-30T18:42:24.000Z ##

Cisco Warns of Active Exploitation of Secure Firewall Management Center Flaw Caused by Hardcoded Credentials

Cisco confirms active exploitation of CVE-2026-20316, a hardcoded credentials flaw in Secure Firewall Management Center. Learn affected versions, impact, IoCs, and hotfixes

thecybersecguru.com/news/cisco

##

netsecio@mastodon.social at 2026-07-30T17:51:40.000Z ##

📰 CISA Warns of Actively Exploited Cisco Firewall Management Flaw

📢 CISA WARNING: A static credential flaw in Cisco Secure Firewall Management Center (CVE-2026-20316) is actively exploited. The flaw allows unauthorized access. CISA adds it to KEV catalog, mandating federal action. #CVE202620316 #Cisco #KEV

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/ci

##

Matchbook3469@mastodon.social at 2026-07-30T17:36:38.000Z ##

🔵 THREAT INTELLIGENCE

Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

Vulnerability | CRITICAL
CVEs: CVE-2026-20316

Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was...

Full analysis:
yazoul.net/news/article/cisco-

#ThreatIntel #Malware #SecurityOps

##

security_crawler_carl@infosec.exchange at 2026-07-30T11:45:32.000Z ##

🏆 New Achievement! Static Credentials, Static Fate!

RAID ALERT. RAID ALERT. Cisco Secure Firewall Management Center has a hardcoded low-privilege account baked right into the software — CVE-2026-20316 — and unauthenticated remote attackers are already using it to log in and harvest sensitive data. That's Phase One. Phase Two is the wipe: threat actors are chaining it with CVE-2026-20079, which hands them root access via arbitrary script execution. (1/2)

##

beyondmachines1@infosec.exchange at 2026-07-30T11:01:06.000Z ##

Cisco Patches Actively Exploited Hard-Coded Password in Secure Firewall Management Center

Cisco fixed a high-severity vulnerability (CVE-2026-20316) in Secure Firewall Management Center that allows unauthenticated remote attackers to log in using hard-coded credentials. CISA added the flaw to its KEV catalog following reports of zero-day exploitation targeting network security infrastructure.

**Make sure your Cisco Secure Firewall Management Center (FMC) is isolated from the internet and only reachable from trusted internal networks. Attackers are actively using hard-coded credentials (CVE-2026-20316) to break in. Apply Cisco's hotfix immediately (CISA requires it by August 1, 2026), and check your management logs for suspicious entries mentioning /var/tmp/license.tmp to spot any break-in.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

oversecurity@mastodon.social at 2026-07-29T22:20:25.000Z ##

Cisco warns of FMC static credential flaw exploited in zero-day attacks

Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was...

🔗️ [Bleepingcomputer] link.is.it/AKCr32

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T21:44:32.000Z ##

A Cisco FMC vulnerability, CVE-2026-20316, is exploited in the wild. Static credentials let attackers log in. CISA added it to KEV — patch now.

#Cisco #CVE202620316 #FMC #KEV #Vulnerability #InfoSec

securityonline.info/cisco-fmc-

##

secdb@infosec.exchange at 2026-07-29T21:00:20.000Z ##

🚨 [CISA-2026:0729] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-20316 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Management Center (FMC)
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260729 #cisa20260729 #cve_2026_20316 #cve202620316

##

cisakevtracker@mastodon.social at 2026-07-29T20:00:46.000Z ##

CVE ID: CVE-2026-20316
Vendor: Cisco
Product: Secure Firewall Management Center (FMC)
Date Added: 2026-07-29
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-07-29T17:36:00.000Z ##

New Cisco updates:

CRITICAL vulnerability, first released on March 4: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi

High severity: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability sec.cloudapps.cisco.com/securi

New informational advisory: Cisco Advance Notification for Publication of August 5, 2026, Security Advisories sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #vulnerability #Cisco

##

CVE-2026-18363(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-07-30T12:32:26

1 posts

A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.8 and v1.18.4. During the password reset process, the application retrieves the timestamp associated with the provided token and checks whether the configured validity period has expired. Consequently, the expiry check is only performed if the timestamp lookup fails, allowing tok

offseq@infosec.exchange at 2026-07-30T12:00:27.000Z ##

CVE-2026-18363: osTicket <1.17.8 & <1.18.4 has a CRITICAL flaw (CVSS 9.1) in password reset logic — tokens can be reused, risking account takeover. Upgrade when patch is available, monitor resets, and restrict token access. radar.offseq.com/threat/cve-20 #OffSeq #osTicket #CVE202618363

##

CVE-2026-64560
(7.8 HIGH)

EPSS: 0.11%

updated 2026-07-30T12:32:18

2 posts

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwoo decoded and reported a non-leader exec() related race which can result in an UAF: sys_timer_delete() exec() posix_cpu_timer_del() // Observes old leader p = pid_task(pid, pid_type); de_thread() switch_leader(); release

CVE-2026-44095
(7.8 HIGH)

EPSS: 0.23%

updated 2026-07-30T09:31:24

2 posts

A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

hugovalters@mastodon.social at 2026-07-30T17:02:56.000Z ##

CVE-2026-44095 - High privilege escalation in network config script lets local users execute commands as root. CVSS 7.8. No patch available - restrict local access. #CVE #infosec #privilegeescalation

valtersit.com/cve/CVE-2026-440

##

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44108
(9.8 CRITICAL)

EPSS: 0.46%

updated 2026-07-30T09:31:24

2 posts

Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to connect to these services, resulting in full system compromise.

thehackerwire@mastodon.social at 2026-07-30T10:00:30.000Z ##

🔴 CVE-2026-44108 - Critical (9.8)

Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an un...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44107
(7.5 HIGH)

EPSS: 0.31%

updated 2026-07-30T09:31:24

2 posts

A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.

thehackerwire@mastodon.social at 2026-07-30T10:00:21.000Z ##

🟠 CVE-2026-44107 - High (7.5)

A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Deni...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-7849
(9.8 CRITICAL)

EPSS: 0.42%

updated 2026-07-30T09:31:24

2 posts

Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root.

offseq@infosec.exchange at 2026-07-30T07:30:24.000Z ##

Phoenix Contact CHARX SEC-3150 v1.0.0 hit by CRITICAL (CVSS 9.3) command injection (CVE-2026-7849): unauthenticated remote attackers can execute root commands. No mitigation yet — restrict access! radar.offseq.com/threat/cve-20 #OffSeq #ICS #Vuln #CVE2026_7849

##

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44094
(8.6 HIGH)

EPSS: 0.26%

updated 2026-07-30T09:31:24

1 posts

An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configuration including default credentials. This could allow the attacker to gain SSH access to the system as an unprivileged user "user-app". Charging could be interrupted.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44102
(5.3 MEDIUM)

EPSS: 0.21%

updated 2026-07-30T09:31:24

1 posts

An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid firmware file. This will cause the file to remain accessible for a short period before it is deleted due to improper locking during the cleanup process.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44104
(9.8 CRITICAL)

EPSS: 0.24%

updated 2026-07-30T09:31:24

1 posts

The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44092
(9.1 CRITICAL)

EPSS: 0.38%

updated 2026-07-30T09:31:24

1 posts

An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44091
(9.1 CRITICAL)

EPSS: 0.33%

updated 2026-07-30T09:31:24

1 posts

An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system configuration. This may lead to integrity and availability loss.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44090
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-07-30T09:31:24

1 posts

Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the device being fully compromised.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44098
(8.6 HIGH)

EPSS: 1.37%

updated 2026-07-30T09:31:18

1 posts

This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44099
(7.8 HIGH)

EPSS: 0.23%

updated 2026-07-30T09:31:18

1 posts

A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44100
(9.4 CRITICAL)

EPSS: 0.28%

updated 2026-07-30T09:31:18

1 posts

The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44097
(7.1 HIGH)

EPSS: 0.24%

updated 2026-07-30T09:31:18

1 posts

A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in persistent storage of attacker-controlled files and potentially exhausting resources, which might lead to Denial-of-Service.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44096
(7.8 HIGH)

EPSS: 0.23%

updated 2026-07-30T09:31:18

1 posts

A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compromise.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-64531
(7.8 HIGH)

EPSS: 0.12%

updated 2026-07-30T06:33:35

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16. Commit a1e64addf3ff ("net: openvswitch: remove misbehaving actions length check") allowed the total sw_flow_actions stream to grow beyond 64 KiB, which is valid, but also removed the last guar

DailyCyberSecurity@infosec.exchange at 2026-07-28T11:12:26.000Z ##

The OVSwrap local root flaw hits the Linux kernel Open vSwitch datapath. CVE-2026-64531 now has a public patch and PoC. See affected distros and fixes.

#OVSwrap #CVE202664531 #LinuxKernel #OpenvSwitch #LocalRoot #PrivilegeEscalation

securityonline.info/ovswrap-cv

##

CVE-2026-58046
(9.9 CRITICAL)

EPSS: 0.31%

updated 2026-07-30T06:32:44

2 posts

Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.

hugovalters@mastodon.social at 2026-07-30T15:08:10.000Z ##

CVE-2026-58046 - Critical SQLi in Plesk XML-RPC API. Authenticated low-priv user can read entire DB, leading to full panel compromise. CVSS 9.9. No patch available yet. Apply workarounds immediately. #CVE #Plesk #infosec

valtersit.com/cve/CVE-2026-580

##

thehackerwire@mastodon.social at 2026-07-30T07:00:21.000Z ##

🔴 CVE-2026-58046 - Critical (9.9)

Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58066
(9.8 CRITICAL)

EPSS: 0.21%

updated 2026-07-30T06:32:44

1 posts

Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:Assertion. An attacker could submit a wrapped document carrying forged identity attributes alongside any valid signature made by the trusted IdP certificate, and log in as an arbitrary user.

thehackerwire@mastodon.social at 2026-07-30T07:00:31.000Z ##

🔴 CVE-2026-58066 - Critical (9.8)

Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:Assertion. An attacker could submit a wrapped docu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-1360
(7.5 HIGH)

EPSS: 0.57%

updated 2026-07-30T06:32:43

1 posts

The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` parameter on user-controlled XProfile field data. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject ar

thehackerwire@mastodon.social at 2026-07-30T06:00:17.000Z ##

🟠 CVE-2026-1360 - High (7.5)

The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48448
(8.6 HIGH)

EPSS: 0.37%

updated 2026-07-30T03:31:28

1 posts

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to gain file system read access. Exploitation of this issue does not require user interaction. Scope is changed.

thehackerwire@mastodon.social at 2026-07-30T04:00:03.000Z ##

🟠 CVE-2026-48448 - High (8.6)

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to g...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67595
(8.1 HIGH)

EPSS: 0.42%

updated 2026-07-30T00:31:19

2 posts

VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders the affected email template with JavaScript enabled. The payload establishes a WebSocket connection to a hardcoded command-and-control endpoint, install

offseq@infosec.exchange at 2026-07-30T00:00:36.000Z ##

CVE-2026-67595 (CRITICAL): VaahCMS 2.0.0 – 2.3.4 ships with malicious JS in OTP email templates. Enables C2, keylogging, WhatsApp scraping, and remote page control. Avoid JS-enabled viewing until patched. radar.offseq.com/threat/cve-20 #OffSeq #Infosec #CVE202667595 #VaahCMS

##

thehackerwire@mastodon.social at 2026-07-29T23:59:49.000Z ##

🟠 CVE-2026-67595 - High (8.1)

VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5490
(8.8 HIGH)

EPSS: 0.48%

updated 2026-07-29T21:31:08

1 posts

DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of DriveLock. Authentication is required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 4568 by default. The issue results from the lack of proper validation of a user-supplied string befo

1 repos

https://github.com/HORKimhab/CVE-2026-54900

thehackerwire@mastodon.social at 2026-07-30T05:00:39.000Z ##

🟠 CVE-2026-5490 - High (8.8)

DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of DriveLock. Authentication is required to exploit this vulnerability.

The specific flaw exis...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-6267
(8.5 HIGH)

EPSS: 0.34%

updated 2026-07-29T21:31:08

2 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to insufficient access controls on internal request handling.

DailyCyberSecurity@infosec.exchange at 2026-07-30T03:11:14.000Z ##

The latest GitLab patch release fixes 13 vulnerabilities, including CVE-2026-6267, a high-severity data exposure flaw. Update self-managed GitLab now.

#GitLab #CVE20266267 #DevSecOps #Vulnerability #PatchNow #InfoSec

securityonline.info/gitlab-pat

##

thehackerwire@mastodon.social at 2026-07-29T20:59:50.000Z ##

🟠 CVE-2026-6267 - High (8.5)

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5056
(7.8 HIGH)

EPSS: 0.43%

updated 2026-07-29T21:31:08

1 posts

GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of UncompressedFrameConfigBox

thehackerwire@mastodon.social at 2026-07-30T02:00:30.000Z ##

🟠 CVE-2026-5056 - High (7.8)

GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13308
(8.1 HIGH)

EPSS: 0.57%

updated 2026-07-29T21:31:08

1 posts

Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of WebSocket messages related to the OCPP service.

thehackerwire@mastodon.social at 2026-07-29T21:59:57.000Z ##

🟠 CVE-2026-13308 - High (8.1)

Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authen...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-6102
(7.8 HIGH)

EPSS: 0.09%

updated 2026-07-29T21:31:08

1 posts

MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MSI Center. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the NTIOLib_X64.sys driver. The issue

thehackerwire@mastodon.social at 2026-07-29T21:00:10.000Z ##

🟠 CVE-2026-6102 - High (7.8)

MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MSI Center. An attacker must first obtain the ability to execute...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14529
(9.4 CRITICAL)

EPSS: 0.33%

updated 2026-07-29T21:31:07

1 posts

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.

offseq@infosec.exchange at 2026-07-30T06:00:24.000Z ##

CRITICAL SSRF vuln (CVE-2026-14529) in IBM WebSphere App Server 9.0, 8.5, and Liberty 17.0.0.3 – 26.0.0.8 if SIP (sipServlet-1.1) is enabled. Review SIP use, disable if possible. Details: radar.offseq.com/threat/ibm-we #OffSeq #IBM #WebSphere #SSRF #CVE202614529

##

CVE-2026-15975
(7.5 HIGH)

EPSS: 0.39%

updated 2026-07-29T21:31:07

1 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to insufficient resource throttling when processing merge request discussions.

thehackerwire@mastodon.social at 2026-07-30T05:00:49.000Z ##

🟠 CVE-2026-15975 - High (7.5)

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5057
(7.5 HIGH)

EPSS: 0.48%

updated 2026-07-29T21:31:07

1 posts

ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ATEN Unizon. Authentication is not required to exploit this vulnerability. The specific flaw exists within the RpcProvider class. The issue results from the lack of authentication prior to allowing access to

thehackerwire@mastodon.social at 2026-07-30T02:00:44.000Z ##

🟠 CVE-2026-5057 - High (7.5)

ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ATEN Unizon. Authentication is not required to exploit ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67201
(8.6 HIGH)

EPSS: 0.39%

updated 2026-07-29T20:17:11.330000

1 posts

V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows attackers to circumvent host-based allowlists by exploiting a parser differential between net.urllib and net.http. Attackers can craft a URL containing a backslash in the authority section such that net.urllib.parse() extracts the trusted host for allowlist validation while net.

thehackerwire@mastodon.social at 2026-07-29T20:00:35.000Z ##

🟠 CVE-2026-67201 - High (8.6)

V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows attackers to circumvent host-based allowlists by exploiting a parser differential between net.urllib and net.http. Attackers c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-43698
(7.8 HIGH)

EPSS: 0.15%

updated 2026-07-29T19:16:45.967000

1 posts

An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to gain root privileges.

thehackerwire@mastodon.social at 2026-07-28T01:00:38.000Z ##

🟠 CVE-2026-43698 - High (7.8)

An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67215
(7.5 HIGH)

EPSS: 0.35%

updated 2026-07-29T15:31:12

1 posts

cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operations grafts duplicated subtrees to amplify document depth beyond the parser's nesting limit: cJSON_Delete() recurses with no depth bound, and the cJSON

thehackerwire@mastodon.social at 2026-07-29T15:00:21.000Z ##

🟠 CVE-2026-67215 - High (7.5)

cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy oper...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-0667(CVSS UNKNOWN)

EPSS: 0.37%

updated 2026-07-29T15:31:11

1 posts

CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when communicating over the Modbus TCP protocol.

offseq@infosec.exchange at 2026-07-29T13:30:28.000Z ##

CVE-2026-0667 (CRITICAL, CVSS 9.3): Schneider Electric SCADAPack 47x is vulnerable to improper Modbus TCP checks — risk of code execution, DoS, data loss. Review exposure & monitor for patches. radar.offseq.com/threat/cve-20 #OffSeq #ICS #Vulnerability #SCADA

##

CVE-2026-66748
(8.8 HIGH)

EPSS: 0.79%

updated 2026-07-29T15:31:05

1 posts

Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the select_eval custom field type. Attackers can store an attacker-controlled Ruby expression in the field options command parameter, which is evaluated via instance_

1 repos

https://github.com/theopaid/CVE-2026-66748-Camaleon-CMS---Authenticated-RCE-via-select_eval-Custom-Field

thehackerwire@mastodon.social at 2026-07-28T17:00:35.000Z ##

🟠 CVE-2026-66748 - High (8.8)

Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the select_ev...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66745
(7.5 HIGH)

EPSS: 0.32%

updated 2026-07-29T15:16:30.153000

1 posts

Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability that allows unauthenticated attackers to hijack administrative sessions by setting a known PHPSESSID on a victim's browser prior to authentication. Attackers can pre-set a controlled session identifier and wait for a victim to authenticate through fw.login.php, after which the att

thehackerwire@mastodon.social at 2026-07-28T20:00:25.000Z ##

🟠 CVE-2026-66745 - High (7.5)

Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability that allows unauthenticated attackers to hijack administrative sessions by setting a known PHPSESSID on a victim's browser prior...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54650
(8.6 HIGH)

EPSS: 0.36%

updated 2026-07-29T15:16:25.093000

1 posts

openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.Path instead of preserving the original request target with r.URL.EscapedPath(), allowing percent encoded dot segments %2e and separators %2f to reach tunneled local services as ../ and / for path traversal. This issue is fixed in version 0.1.2.

thehackerwire@mastodon.social at 2026-07-29T02:00:25.000Z ##

🟠 CVE-2026-54650 - High (8.6)

openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.Path instead of preserving the original request target with r.URL.EscapedPath(), allowing percent e...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65883(CVSS UNKNOWN)

EPSS: 0.50%

updated 2026-07-29T12:31:30

3 posts

Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.

AAKL at 2026-07-30T16:44:07.315Z ##

New. This is in reference to CVE-2026-65883.

VulnCheck: Aimy Captcha-Less Form Guard: The Anti-Bot Plugin That Hands Bots the Keys vulncheck.com/blog/aimy-captch @vulncheck

##

AAKL@infosec.exchange at 2026-07-30T16:44:07.000Z ##

New. This is in reference to CVE-2026-65883.

VulnCheck: Aimy Captcha-Less Form Guard: The Anti-Bot Plugin That Hands Bots the Keys vulncheck.com/blog/aimy-captch @vulncheck #infosec #vulnerability

##

offseq@infosec.exchange at 2026-07-29T10:30:27.000Z ##

CVE-2026-65883 (CRITICAL, CVSS 10): Aimy Captcha-Less Form Guard for Joomla (v18.0-20.0) is vulnerable to PHP object injection via clfgd field — enabling RCE. Patch or disable plugin urgently. radar.offseq.com/threat/cve-20 #OffSeq #Joomla #Exploit #RCE

##

CVE-2026-14270
(8.8 HIGH)

EPSS: 0.55%

updated 2026-07-29T12:31:30

1 posts

The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing authorization and nonce validation in the eco_save_settings() function, which allows low-privileged authenticated users to modify the tc_eco_custom_file_types upload allowlist setting,

thehackerwire@mastodon.social at 2026-07-29T15:00:33.000Z ##

🟠 CVE-2026-14270 - High (8.8)

The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing authorization and nonce validati...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-35226
(6.5 MEDIUM)

EPSS: 0.17%

updated 2026-07-29T09:31:37

1 posts

An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to send malformed PROFINET communication data that triggers an exception in the affected PLC application. The exception is handled by the CODESYS Control runtime system and results in a controlled stop of the PLC application.

certvde@infosec.exchange at 2026-07-29T07:12:14.000Z ##

#OT #Advisory VDE-2026-041
CODESYS PROFINET Controller - Out-of-bounds Write

CODESYS PROFINET is an add‑on for the CODESYS Development System that provides a fully integrated PROFINET protocol stack along with diagnostic capabilities. When a PROFINET Controller is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems.
#CVE CVE-2026-35226

certvde.com/en/advisories/vde-

#CSAF codesys.csaf-tp.certvde.com/.w

##

CVE-2026-18197(CVSS UNKNOWN)

EPSS: 0.27%

updated 2026-07-29T09:31:36

1 posts

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allows Cross-Site Scripting (XSS). This issue affects Link Library: before 7.9.4.

AAKL@infosec.exchange at 2026-07-29T17:53:33.000Z ##

New.

Tenable Research Advisories: CVE-2026-18197: Link Library - Reflected Cross-Site Scripting tenable.com/security/research/

From yesterday:

Coordinated “cyberattack” on Minnesota water utilities: What you need to know tenable.com/blog/coordinated-c @tenable #infosec #cyberattack #Minnesota #threatresearch

##

CVE-2026-18072
(9.8 CRITICAL)

EPSS: 0.59%

updated 2026-07-29T06:32:11

2 posts

The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` function — registered on WordPress's `init` hook at priority 1 so that it runs before any authentication checks on every request — reads an attacker-supplied t

thehackerwire@mastodon.social at 2026-07-29T06:59:52.000Z ##

🔴 CVE-2026-18072 - Critical (9.8)

The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` func...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T02:48:53.000Z ##

Active exploitation of CVE-2026-18072, a CVSS 9.8 video embedder backdoor, grants attackers full administrative control over 20,000 WordPress sites.

#CVE202618072 #WordPress #CyberSecurity #Backdoor

securityonline.info/cve-2026-1

##

CVE-2026-12144
(8.8 HIGH)

EPSS: 0.37%

updated 2026-07-29T03:30:21

1 posts

The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the `save_requests_meta()` function applying only `sanitize_text_field()` to the `user_role_set` POST parameter before passing it directly to `WP_User::add_role()`, with no allowlist validation against permitted wholesale roles and no capability check

thehackerwire@mastodon.social at 2026-07-29T07:00:02.000Z ##

🟠 CVE-2026-12144 - High (8.8)

The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the `save_requests_meta()` function applying only `sanitize_text_field()` to the `user_role_set` P...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54658
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-07-28T22:19:24

1 posts

### Impact A SQL injection vulnerability exists in the `escapeValue()` function used for parameter substitution. Attackers who can control parameter values can inject arbitrary SQL by using a trailing backslash to escape the closing quote. Who is impacted: All users of @hypequery/clickhouse versions prior to 2.0.2 who pass user-controlled input as query parameters. ### Patches The vulnerability

thehackerwire@mastodon.social at 2026-07-29T02:00:36.000Z ##

🔴 CVE-2026-54658 - Critical (9.8)

Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backslashes before single quotes during parameter substitution, allowing attacker controlled query param...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54638
(7.5 HIGH)

EPSS: 0.35%

updated 2026-07-28T22:15:29

1 posts

### Impact A remote, unauthenticated attacker can cause excessive memory allocation (and resulting CPU / GC pressure, potentially OOM termination) by sending a crafted unencrypted MTProto packet. `(*proto.UnencryptedMessage).Decode` read an attacker-controlled 32-bit `dataLen` field and immediately allocated a buffer of that size via `make([]byte, dataLen)` **before** validating that the underly

thehackerwire@mastodon.social at 2026-07-29T02:00:15.000Z ##

🟠 CVE-2026-54638 - High (7.5)

gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted_message.go read attacker controlled dataLen from an unauthenticated MTProto unencrypted packet and allocated make([]byte, data...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64863
(9.1 CRITICAL)

EPSS: 0.34%

updated 2026-07-28T22:03:13

1 posts

## Summary The WebDAV mode-flag guard added to fix GHSA-3whc-qvhv-xqjp still does not enforce `--no-delete` on the WebDAV `MOVE` verb. `MOVE` deletes the source file (rename removes it from its original path), and with `Overwrite: T` it additionally performs an explicit `RemoveAll` on the destination. Under `-w --no-delete`, `DELETE` is correctly blocked (403) but `MOVE` still destroys existing f

thehackerwire@mastodon.social at 2026-07-29T00:00:21.000Z ##

🔴 CVE-2026-64863 - Critical (9.1)

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOVE as a write-only method and did not enforce --no-delete, allowing WebDAV clients to delete or ove...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62325
(9.1 CRITICAL)

EPSS: 0.34%

updated 2026-07-28T21:57:19

1 posts

## Summary Start goshs v2.1.3 with `-b 'admin:' -sftp`. No `-fkf`. SFTP accepts connections without password. CVE-2026-40884 blocks the empty-username variant (`-b ':pass'`). The empty-password variant bypasses that fix. ## CVE-2026-40884 **CVE-2026-40884** (GHSA-c29w-qq4m-2gcv, Apr 13 2026) reported the empty-username case: `-b ':pass'` with `-sftp`. `sftpserver.go:85` uses `&&`: ```go if s.U

thehackerwire@mastodon.social at 2026-07-29T00:00:11.000Z ##

🔴 CVE-2026-62325 - Critical (9.1)

goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != "" && Password != "", so running goshs with -b 'admin:' -sftp and no -fkf left...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55391
(7.5 HIGH)

EPSS: 0.20%

updated 2026-07-28T21:45:50

1 posts

### Summary `datamodel-code-generator`'s anti-SSRF guard validates the resolved IP of a fetch target once and then lets `httpx` perform its own independent DNS resolution to connect, so the validated address is never pinned. A hostname that resolves to a public IP at validation time and a private IP at connection time (DNS rebinding) bypasses the guard and reaches loopback, link-local cloud-metad

thehackerwire@mastodon.social at 2026-07-28T23:00:47.000Z ##

🟠 CVE-2026-55391 - High (7.5)

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.63.0, datamodel-code-generator validates a URL host once i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14973
(9.3 CRITICAL)

EPSS: 0.45%

updated 2026-07-28T21:31:45

1 posts

IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.

DailyCyberSecurity@infosec.exchange at 2026-07-29T02:03:37.000Z ##

IBM Aspera vulnerabilities affect Faspex 5 and the Desktop App. CVE-2026-14973 and two RCE flaws rate up to 9.3. Update to Faspex 5.0.16 and Desktop 1.1.0.

#IBMAspera #AsperaFaspex #CVE202614973 #RCE #PathTraversal #CyberSecurity

securityonline.info/ibm-aspera

##

CVE-2026-15057
(7.5 HIGH)

EPSS: 0.26%

updated 2026-07-28T21:31:45

1 posts

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.

thehackerwire@mastodon.social at 2026-07-28T22:00:18.000Z ##

🟠 CVE-2026-15057 - High (7.5)

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14996
(8.2 HIGH)

EPSS: 0.22%

updated 2026-07-28T21:31:45

1 posts

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management.

thehackerwire@mastodon.social at 2026-07-28T22:00:08.000Z ##

🟠 CVE-2026-14996 - High (8.2)

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-7769
(8.1 HIGH)

EPSS: 0.27%

updated 2026-07-28T21:31:39

1 posts

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in t

thehackerwire@mastodon.social at 2026-07-28T20:00:38.000Z ##

🟠 CVE-2026-7769 - High (8.1)

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to SQL ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55390
(7.5 HIGH)

EPSS: 0.36%

updated 2026-07-28T21:26:42

2 posts

### Summary When generating models from an XML Schema (`--input-file-type xmlschema`), `datamodel-code-generator` resolves `<xs:include>`, `<xs:import>`, `<xs:redefine>`, and `<xs:override>` `schemaLocation` attributes against the source directory and reads the target with no restriction to the input/base directory. An attacker who controls the input XSD can read arbitrary files via `../` travers

hugovalters@mastodon.social at 2026-07-29T17:02:27.000Z ##

CVE-2026-55390 - High severity path traversal in datamodel-code-generator 0.59.0-0.62.0. Arbitrary local file read via XML schema imports. CVSS 7.5. Update to 0.62.0 immediately. #CVE #Python #infosec

valtersit.com/cve/CVE-2026-553

##

thehackerwire@mastodon.social at 2026-07-28T23:00:37.000Z ##

🟠 CVE-2026-55390 - High (7.5)

datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema parsing in src/datamodel_code_generator/parser/xmlschema.py for --input-file-type xmlschema resolves xs:include, xs:import, xs:rede...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-43749
(7.8 HIGH)

EPSS: 0.15%

updated 2026-07-28T19:52:21.577000

1 posts

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.

thehackerwire@mastodon.social at 2026-07-27T23:00:32.000Z ##

🟠 CVE-2026-43749 - High (7.8)

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5674
(8.8 HIGH)

EPSS: 0.12%

updated 2026-07-28T17:16:52.923000

2 posts

A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.

CVE-2026-54635
(7.5 HIGH)

EPSS: 0.42%

updated 2026-07-28T17:09:03

1 posts

## Webhook Custom Path Authentication Bypass in pytonapi ### Summary `TonapiWebhookDispatcher` in pytonapi 2.2.0 fails to validate the `Authorization` header when a webhook handler is registered with the documented `path=` argument. During `setup()`, bearer tokens are stored only under the default suffix paths (e.g., `/hook/account-tx`), but the custom path (e.g., `/hook/custom`) is never added

thehackerwire@mastodon.social at 2026-07-28T19:00:11.000Z ##

🟠 CVE-2026-54635 - High (7.5)

pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webhook access to the TON blockchain. From 2.0.0 to 2.2.0, TonapiWebhookDispatcher fails to validate the Authorization header when a webhook handler is registered with the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63077
(9.8 CRITICAL)

EPSS: 0.65%

updated 2026-07-28T16:17:58.820000

5 posts

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

oversecurity@mastodon.social at 2026-07-30T12:31:32.000Z ##

CVE-2026-63077 Exposes TeamCity Servers to Unauthenticated RCE

A critical security flaw affecting TeamCity On-Premises has prompted administrators to update their servers immediately after researchers disclosed...

🔗️ [Thecyberexpress] link.is.it/Uo0klI

##

DailyCyberSecurity@infosec.exchange at 2026-07-30T06:17:33.000Z ##

JetBrains patches critical TeamCity On-Premises vulnerability CVE-2026-63077 (CVSS 9.8), preventing unauthenticated remote code execution.

#TeamCity #JetBrains #CVE202663077 #Cybersecurity #CICD

meterpreter.org/teamcity-vulne

##

security_crawler_carl@infosec.exchange at 2026-07-28T21:57:19.000Z ##

🏆 New Achievement! Exhibit A: Your CI Server Did It!

The record will reflect that on or about July 28, 2026, JetBrains disclosed CVE-2026-63077, a CVSS 9.8 vulnerability in TeamCity On-Premises. The record will further reflect that any unauthenticated attacker with mere HTTP(S) access could bypass authentication and execute arbitrary operating system commands. (1/3)

##

beyondmachines1@infosec.exchange at 2026-07-28T20:01:50.000Z ##

JetBrains Fixes Critical TeamCity Authentication Bypass Allowing Remote Code Execution

JetBrains patched a critical authentication bypass (CVE-2026-63077) in TeamCity On-Premises that allows unauthenticated remote code execution. The flaw affects all on-premises versions and could lead to a full takeover of CI/CD pipelines.

**If you run TeamCity On-Premises, urgently update to version 2025.11.7 or 2026.1.3 to patch CVE-2026-63077. All on-premises versions are vulnerable to a full server takeover. TeamCity Cloud is already patched and needs no action. If you can't update right away, install the security patch plugin (for versions 2017.1 and later) and restrict access to your TeamCity server to trusted internal networks or a VPN.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

DailyCyberSecurity@infosec.exchange at 2026-07-28T13:34:19.000Z ##

#TeamCity #CVE202663077 #RCE #RemoteCodeExecution #JetBrains #CyberSecurity

securityonline.info/teamcity-r

##

CVE-2026-59878
(7.5 HIGH)

EPSS: 0.55%

updated 2026-07-28T15:32:25

1 posts

Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remote unauthenticated peer that can reach an exposed AMQP NIO connector can trigger denial-of-service behavior by sending a frame size value. This cause the NIO threads to die and if done rapidly enough can lead to exhaustion of the NIO thread pool denying service to other connections. This i

thehackerwire@mastodon.social at 2026-07-28T16:00:34.000Z ##

🟠 CVE-2026-59878 - High (7.5)

Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All.

A remote unauthenticated peer that can reach an exposed AMQP NIO connector can trigger denial-of-service behavior by sending a frame size value...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63727
(8.8 HIGH)

EPSS: 0.26%

updated 2026-07-28T15:32:19

1 posts

Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capable of modifying user permissions to gain access to additional resources and operations. It is not possible to grant the system-admin role, but a read onl

thehackerwire@mastodon.social at 2026-07-28T16:00:24.000Z ##

🟠 CVE-2026-63727 - High (8.8)

Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capab...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-7187
(8.8 HIGH)

EPSS: 0.21%

updated 2026-07-28T15:32:18

1 posts

Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects UKBS: through 28072026. NOTE: The vendor was contacted and it was learned that the product is not supported.

thehackerwire@mastodon.social at 2026-07-28T16:00:44.000Z ##

🟠 CVE-2026-7187 - High (8.8)

Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects UKBS: through 28072026.
NOTE: The vendor was contacted and it was learn...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61609
(7.5 HIGH)

EPSS: 0.39%

updated 2026-07-28T14:58:00

1 posts

### Summary The `authentication` rate limiter used for the login and two-factor checkpoint endpoints applies a single global bucket shared by every client, instead of keying per IP or per account. An unauthenticated attacker sending ~10 requests per minute from one IP exhausts the shared bucket and causes HTTP 429 for every user on every IP attempting to log in or complete 2FA, for as long as the

thehackerwire@mastodon.social at 2026-07-28T17:00:45.000Z ##

🟠 CVE-2026-61609 - High (7.5)

Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limiter defined in RouteServiceProvider::configureRateLimiting() applied a single global bucket to the login and two-factor checkpoin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45293
(8.6 HIGH)

EPSS: 0.18%

updated 2026-07-28T14:28:13

1 posts

### Impact WordPress Coding Standards (WordPressCS) versions before 3.4.1 contain an arbitrary code execution vulnerability in the `WordPress.WP.EnqueuedResourceParameters` sniff. As a result, running PHPCS with WordPressCS over untrusted PHP code, for example, in a CI pipeline that lints pull requests, or on a developer machine reviewing third-party code, could lead to arbitrary command executio

CVE-2025-15467
(8.8 HIGH)

EPSS: 47.62%

updated 2026-07-28T13:17:14.747000

1 posts

Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encode

6 repos

https://github.com/guiimoraes/CVE-2025-15467

https://github.com/mr-r3b00t/CVE-2025-15467

https://github.com/materaj2/cve-2025-15467

https://github.com/x-stp/cves-2025-11187_15467_69418

https://github.com/WostGit/cve-2025-15467-crash

https://github.com/balgan/CVE-2025-15467

beyondmachines1@infosec.exchange at 2026-07-29T09:01:49.000Z ##

Siemens Patches Critical OpenSSL Flaw in Desigo CC Building Management Systems

Siemens released security updates for Desigo CC to address a critical OpenSSL vulnerability (CVE-2025-15467) that allows unauthenticated remote code execution or denial of service through malformed cryptographic messages.

**First, make sure all Desigo CC building management systems are isolated from the internet and reachable only from trusted networks. Then, if you run V9 update to V9.0 QU1 (or later) and if you run V8 apply patch V8.0 QU2.0021; for V7 there is no patch yet.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-16462
(9.8 CRITICAL)

EPSS: 0.42%

updated 2026-07-28T12:31:27

1 posts

In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.

certvde@infosec.exchange at 2026-07-28T09:28:50.000Z ##

#OT #Advisory VDE-2026-085
Weidmueller: SQL Injection Vulnerability in PROCON-WEB SCADA

A remote unauthenticated attacker can exploit a SQL injection vulnerability in PROCON-WEB SCADA to execute arbitrary commands.
#CVE CVE-2026-16462

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

CVE-2026-14169
(8.1 HIGH)

EPSS: 0.29%

updated 2026-07-28T09:31:36

2 posts

Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites existing user passwords which could result in complete administrative unavailability of the device.

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-14167
(8.8 HIGH)

EPSS: 0.28%

updated 2026-07-28T09:31:36

2 posts

A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level including permission management due to incorrect authorization.

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-14171
(6.1 MEDIUM)

EPSS: 0.18%

updated 2026-07-28T09:31:35

2 posts

An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick users to a malicious website. This can result in a loss of confidentiality and availability.

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-43723
(7.8 HIGH)

EPSS: 0.15%

updated 2026-07-28T00:32:06

1 posts

A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to gain root privileges.

thehackerwire@mastodon.social at 2026-07-27T23:00:42.000Z ##

🟠 CVE-2026-43723 - High (7.8)

A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to gain root pri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-39874
(7.8 HIGH)

EPSS: 0.11%

updated 2026-07-28T00:32:04

1 posts

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.

thehackerwire@mastodon.social at 2026-07-28T01:00:48.000Z ##

🟠 CVE-2026-39874 - High (7.8)

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66473
(7.5 HIGH)

EPSS: 0.20%

updated 2026-07-28T00:31:11

1 posts

Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.

thehackerwire@mastodon.social at 2026-07-28T01:00:26.000Z ##

🟠 CVE-2026-66473 - High (7.5)

Unauthenticated Broken Access Control in Xendit Payment &lt;= 7.1.0 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-43776
(7.8 HIGH)

EPSS: 0.15%

updated 2026-07-28T00:31:02

1 posts

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

thehackerwire@mastodon.social at 2026-07-27T23:00:21.000Z ##

🟠 CVE-2026-43776 - High (7.8)

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16812
(10.0 CRITICAL)

EPSS: 0.88%

updated 2026-07-27T21:31:22

6 posts

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intende

netsecio@mastodon.social at 2026-07-30T17:51:33.000Z ##

📰 Critical Arista VeloCloud Zero-Day Flaw Under Active Exploitation

🚨 CRITICAL: A CVSS 10.0 zero-day (CVE-2026-16812) in Arista's on-prem VeloCloud Orchestrator is actively exploited. Unauthenticated RCE allows full SD-WAN compromise. CISA mandates immediate patching. #CVE202616812 #ZeroDay #SDWAN

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/ar

##

DailyCyberSecurity@infosec.exchange at 2026-07-30T02:16:35.000Z ##

Arista addresses CVE-2026-16812, a critical vulnerability in VeloCloud Orchestrator actively exploited to gain unauthenticated remote code execution.

#Arista #VeloCloud #Cybersecurity #CVE202616812 #RCE

meterpreter.org/arista-veloclo

##

security_crawler_carl@infosec.exchange at 2026-07-28T08:14:53.000Z ##

🏆 New Achievement! Ten Out of Ten, Would Exploit Again!

Step right up, valued on-premises customer! Today's featured item is CVE-2026-16812, a perfect-score CVSS 10.0 OS command injection in Arista's VeloCloud Orchestrator — the centralized management platform you trusted with the confidentiality, integrity, and availability of, well, everything. Unknown attackers are already browsing your privileged internal functionality like it's a clearance rack. (1/2)

##

thecybermind@infosec.exchange at 2026-07-28T01:37:38.000Z ##

(CISA TS-SOC) CVE-2026-16812 – Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

Severity: CRITICAL Impact Summary: Remote attackers may access privileged internal functionality and impact the VCO host, compromising the confidentiality, integrity, and availability of the orchestrator and managed data....

thecybermind.co/2026/07/27/cis

##

DailyCyberSecurity@infosec.exchange at 2026-07-27T21:54:32.000Z ##

CISA KEV additions on July 27 flag two known exploited vulnerabilities: Arista VeloCloud CVE-2026-16812 and FortiOS CVE-2025-68686. Patch both now.

#CISA #KEV #Arista #VeloCloud #Fortinet #FortiOS #CVE #ExploitedInTheWild #Cybersecurity

securityonline.info/cisa-kev-a

##

cisakevtracker@mastodon.social at 2026-07-27T20:00:55.000Z ##

CVE ID: CVE-2026-16812
Vendor: Arista
Product: VeloCloud Orchestrator
Date Added: 2026-07-27
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2025-68686
(5.9 MEDIUM)

EPSS: 1.26%

updated 2026-07-27T18:31:25

2 posts

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases

beyondmachines1@infosec.exchange at 2026-07-28T08:01:42.000Z ##

CISA Warns of Active Exploitation in Fortinet FortiOS SSL-VPN Patch Bypass

CISA reports active explotation of CVE-2025-68686, a flaw in Fortinet FortiOS that allows attackers to bypass security patches and maintain persistent access on compromised devices.

**If you use Fortinet devices, make sure they are isolated from the internet and accessible only from trusted networks. Then update FortiOS ASAP to version 7.6.2, 7.4.7, or later. This flaw is combined with others, so make sure all your Fortinet devices are up-to-date. And check your devices for indicators of compromise, this flaw allowed hackers to maintain access over patch cycles.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

DailyCyberSecurity@infosec.exchange at 2026-07-27T21:54:32.000Z ##

CISA KEV additions on July 27 flag two known exploited vulnerabilities: Arista VeloCloud CVE-2026-16812 and FortiOS CVE-2025-68686. Patch both now.

#CISA #KEV #Arista #VeloCloud #Fortinet #FortiOS #CVE #ExploitedInTheWild #Cybersecurity

securityonline.info/cisa-kev-a

##

CVE-2026-61511
(9.8 CRITICAL)

EPSS: 1.27%

updated 2026-07-27T15:32:39

4 posts

vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style

6 repos

https://github.com/tc4dy/CVE-2026-61511-PoC-Exploit

https://github.com/HORKimhab/CVE-2026-61511

https://github.com/webshellseo8/CVE-2026-61511-POC

https://github.com/puj790201-lab/cve-2026-61511

https://github.com/codeb0ssx/Ultimate-CVE-2026-61511

https://github.com/shootcannon/CVE-2026-61511

cyberveille@mastobot.ping.moi at 2026-07-29T17:00:18.000Z ##

📢 RCE non authentifiée dans vBulletin ≤ 6.2.1 via la méthode runMaths() (CVE-2026-61511)
📝 ## 🔍 Contexte

Publié le 27 juillet 2026 sur le blog de recherche Karma(In)Security (karmainsecurity.com), cet article détaille une vulnérabilité critique d'exécut...
📖 cyberveille : cyberveille.ch/posts/2026-07-2
🌐 source : karmainsecurity.com/KIS-2026-13
#CVE_2026_61511 #IOC #Cyberveille

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T15:03:42.000Z ##

A critical vBulletin pre-auth RCE vulnerability, CVE-2026-61511, threatens unpatched forums. Learn how attackers exploit template math evaluation.

#vBulletin #CVE202661511 #RCE #Cybersecurity #Infosec

meterpreter.org/vbulletin-pre-

##

beyondmachines1@infosec.exchange at 2026-07-29T12:01:49.000Z ##

vBulletin Fixes Critical Pre-Auth Remote Code Execution Flaw

vBulletin released patches for a critical remote code execution vulnerability, tracked as CVE-2026-61511 (CVSS score 9.8), that allows unauthenticated attackers to execute arbitrary PHP code on affected forum servers. The flaw affects vBulletin 5.x and 6.x installations, and a public proof-of-concept exploit is available.

**If you run a self-hosted vBulletin forum, upgrade to version 6.2.2 or apply the available security patch immediately. A public exploit allows unauthenticated attackers to target vulnerable servers. Users running the unsupported 5.x branch should migrate to a patched 6.x release.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

DarkWebInformer@infosec.exchange at 2026-07-28T18:15:24.000Z ##

‼️ CVE-2026-61511: Improper Neutralization of Directives in Dynamically Evaluated Code

FOFA Query: app="vBulletin"

FOFA: en.fofa.info/result?qbase64=YX

Results: 11,081

##

CVE-2026-66373
(7.5 HIGH)

EPSS: 0.47%

updated 2026-07-25T03:30:55

1 posts

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.

CVE-2026-59952(CVSS UNKNOWN)

EPSS: 0.52%

updated 2026-07-24T16:14:33

1 posts

## Summary `valibot` 1.4.1 can throw a `TypeError` inside its `flatten()` helper when validation issues contain attacker-controlled object keys such as `toString`, `valueOf`, or `hasOwnProperty`. The issue is reachable through normal `record()` validation. `record()` intentionally filters `__proto__`, `prototype`, and `constructor`, but it still accepts other own keys that collide with inherited

offseq@infosec.exchange at 2026-07-30T01:30:28.000Z ##

CVE-2026-59952 | open-circle valibot <1.4.2 suffers from improper exception handling in flatten(), causing TypeErrors & potential DoS if attacker-controlled keys collide w/ Object.prototype methods. Severity: MEDIUM. Upgrade to 1.4.2+ radar.offseq.com/threat/cve-20 #OffSeq #Valibot #AppSec

##

CVE-2026-42933
(10.0 CRITICAL)

EPSS: 0.29%

updated 2026-07-24T00:32:40

1 posts

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypass OT segmentation.

DailyCyberSecurity@infosec.exchange at 2026-07-28T14:04:40.000Z ##

A Panduit IntraVUE vulnerability tracked as CVE-2026-42933 scores CVSS 10. Five flaws let attackers cross OT segmentation and steal credentials.

#PanduitIntraVUE #CVE202642933 #ICSSecurity #OTSecurity

securityonline.info/panduit-in

##

CVE-2026-21655(CVSS UNKNOWN)

EPSS: 0.17%

updated 2026-07-23T21:31:03

1 posts

Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586. This issue affects victor: from 2.9 before 3.0.

DailyCyberSecurity@infosec.exchange at 2026-07-29T14:30:41.000Z ##

A C-CURE 9000 vulnerability chain hits CVSS 9.6. CVE-2026-21655 allows remote code execution on Johnson Controls victor application servers.

#CCURE9000 #CVE202621655 #JohnsonControls #ICSSecurity

securityonline.info/c-cure-900

##

CVE-2026-59932
(7.5 HIGH)

EPSS: 0.69%

updated 2026-07-23T15:00:18

1 posts

## Summary PhpSpreadsheet's Gnumeric reader reads attacker-supplied `.gnumeric` files into memory and, when the file starts with gzip magic bytes, calls `gzdecode()` on the full compressed contents without enforcing a decompressed-size limit. A very small compressed `.gnumeric` file can expand to data larger than the PHP memory limit and crash the process during `Gnumeric::canRead()` before the f

thehackerwire@mastodon.social at 2026-07-28T20:00:48.000Z ##

🟠 CVE-2026-59932 - High (7.5)

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, and all releases up to and including 1.30.5, the Gnumeric reader read...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59931
(7.7 HIGH)

EPSS: 0.53%

updated 2026-07-23T14:55:51

1 posts

### Summary The domain whitelist introduced in PhpSpreadsheet 5.4.0 for the `WEBSERVICE()` formula function can be bypassed via HTTP redirect. The whitelist validates only the initial URL's hostname, but `file_get_contents()` follows 302/301 redirects by default without re-validating the redirect target against the whitelist. This allows an attacker to reach internal services through a whiteliste

thehackerwire@mastodon.social at 2026-07-28T19:00:20.000Z ##

🟠 CVE-2026-59931 - High (7.7)

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, and all releases up to and including 1.30.5, the WEBSERVICE() domain ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-43503
(8.8 HIGH)

EPSS: 0.34%

updated 2026-07-23T11:10:00.120000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail to propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()->flags when moving frags from source to destination. __pskb_copy_fclone() defers the rest of the shinfo metadata to skb_copy_header(

9 repos

https://github.com/gl1tch0x1/DirtyClone

https://github.com/mooder1/dirtyclone-CVE-2026-43503

https://github.com/entra1337/DirtyClone

https://github.com/0xBlackash/CVE-2026-43503

https://github.com/lieehrdiansyah12/CVE-2026-43503

https://github.com/rjt-gupta/page-cache-corruption-lpes

https://github.com/sec0x/CVE-2026-43503

https://github.com/douglasmun/pagecache-lpe-containment-kit

https://github.com/SecureWithUmer/CVE-2026-43503

DarkWebInformer@infosec.exchange at 2026-07-29T18:58:30.000Z ##

‼️ CVE-2026-43503: DirtyClone is a Linux kernel local privilege escalation (LPE) vulnerability caused by page-cache corruption.

PoC: github.com/entra1337/DirtyClone

##

CVE-2026-16723
(9.0 None)

EPSS: 0.41%

updated 2026-07-23T09:32:08

2 posts

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.

5 repos

https://github.com/why-success/fastjson-rce-lab

https://github.com/dinosn/fastjson-jsontype-rce-lab

https://github.com/HORKimhab/CVE-2026-16723

https://github.com/EQSTLab/CVE-2026-16723

https://github.com/Nowafen/CVE-2026-16723

DailyCyberSecurity@infosec.exchange at 2026-07-29T12:34:32.000Z ##

Discover the critical Fastjson RCE CVE-2026-16723 vulnerability. Learn how attackers exploit Spring Boot applications and find mitigation strategies.

#Fastjson #CVE202616723 #Cybersecurity #SpringBoot #Malware

meterpreter.org/fastjson-rce-c

##

threatnoir@infosec.exchange at 2026-07-29T07:07:47.000Z ##

⚠️ CRITICAL: Hackers target US firms in FastJson RCE zero-day attacks

A critical RCE zero-day (CVE-2026-16723) in FastJson Java library versions 1.2.68-1.2.83 is actively exploited against U.S. firms across multiple sectors. Attackers can execute arbitrary code without user interaction. FastJson 1.x is unmaintained, leaving affected systems without patches.

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-16232
(9.1 CRITICAL)

EPSS: 69.97%

updated 2026-07-22T21:32:05

7 posts

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server I

Nuclei template

2 repos

https://github.com/sfewer-r7/CVE-2026-16232

https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review

halildeniz@mastodon.social at 2026-07-30T16:30:41.000Z ##

🚨 CRITICAL ADVISORY:

Check Point SmartConsole Authentication Bypass (CVE-2026-16232) is actively exploited in the wild! Learn how unauthenticated attackers forge SSO tokens to hijack servers & discover key mitigations:

denizhalil.com/2026/07/30/chec

#CheckPoint #CyberSecurity #CVE202616232

##

daniel1820815@infosec.exchange at 2026-07-30T07:47:53.000Z ##

From our Check Point Research Team:

July 2026 Security Update

Check Point has addressed CVE-2026-16232, an authentication bypass vulnerability in SmartConsole that is under active exploitation, affecting a handful of customers. The flaw allows remote attackers to bypass authentication and gain administrative access to Check Point management servers. Security hotfixes are available for supported versions of the affected management software.

blog.checkpoint.com/security/s

#CheckPoint #CheckPointSoftwareTechnologies #CVE202616232

##

obivan@infosec.exchange at 2026-07-29T17:57:51.000Z ##

Authentication bypass for Check Point Security Management Server and Multi-Domain Security Management Server github.com/sfewer-r7/CVE-2026-

##

AAKL@infosec.exchange at 2026-07-29T17:49:40.000Z ##

Rapid7, from yesterday: Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232) rapid7.com/blog/post/ra-check- @Rapid7Official #infosec #vulnerability #threatresearch

##

threatcodex@infosec.exchange at 2026-07-29T13:18:07.000Z ##

Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)
#CVE_2026_16232
rapid7.com/blog/post/ra-check-

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T02:27:22.000Z ##

CVE-2026-16232 is a SmartConsole authentication bypass in Check Point Security Management. Exploited in the wild, with a public PoC now available.

#CheckPoint #SmartConsole #CVE202616232 #AuthenticationBypass #ZeroDay #CyberSecurity

securityonline.info/check-poin

##

hackmag@infosec.exchange at 2026-07-28T21:30:05.000Z ##

⚪️ Hackers Exploit a Zero-Day in Check Point SmartConsole

🗨️ Check Point has warned customers about a critical vulnerability, CVE-2026-16232, affecting its Security Management and Multi-Domain Management products. The flaw allows attackers to bypass authentication, gain administrator privileges, and modify security policies. The vulnerability is already be…

🔗 hackmag.com/news/cve-2026-1623

#news

##

CVE-2026-50502
(8.0 HIGH)

EPSS: 0.60%

updated 2026-07-22T16:18:05.400000

1 posts

Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.

DailyCyberSecurity@infosec.exchange at 2026-07-29T13:04:49.000Z ##

A public PoC exploit now targets CVE-2026-50502, an RCE in the Windows Event Log service. Microsoft patched the flaw on July 14, 2026. Details below.

#CVE202650502 #WindowsEventLog #RCE #PatchTuesday #InfoSec #Microsoft

securityonline.info/cve-2026-5

##

CVE-2026-2291
(7.3 HIGH)

EPSS: 0.92%

updated 2026-07-20T21:31:40

2 posts

dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.

1 repos

https://github.com/JianrongXiao-Linksys/dnsmasq-cve-2026

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-53362
(7.8 HIGH)

EPSS: 0.27%

updated 2026-07-18T09:32:17

1 posts

In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlen = datalen - transhdrlen; datalen already includes fraggap (datalen = length +

CVE-2026-42530
(8.1 HIGH)

EPSS: 3.68%

updated 2026-07-16T12:33:31

2 posts

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers

3 repos

https://github.com/v4ltonn/CVE-2026-42530

https://github.com/HORKimhab/CVE-2026-42530

https://github.com/0xBlackash/CVE-2026-42530

DailyCyberSecurity at 2026-07-30T13:04:48.572Z ##

A public PoC now details CVE-2026-42530, an NGINX HTTP/3 RCE from a QPACK use-after-free. Upgrade to NGINX 1.31.2 to close the flaw now.

securityonline.info/nginx-http

##

DailyCyberSecurity@infosec.exchange at 2026-07-30T13:04:48.000Z ##

A public PoC now details CVE-2026-42530, an NGINX HTTP/3 RCE from a QPACK use-after-free. Upgrade to NGINX 1.31.2 to close the flaw now.

#NGINX #HTTP3 #CVE202642530 #RCE #UseAfterFree #QUIC #QPACK #PoC #Cybersecurity

securityonline.info/nginx-http

##

CVE-2026-42533
(8.1 HIGH)

EPSS: 3.60%

updated 2026-07-15T15:33:14

1 posts

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyon

9 repos

https://github.com/gagaltotal/CVE-2026-42533-nginx

https://github.com/Daniyal48/ghostlock-vagrant-box

https://github.com/jelasin/CVE-2026-42533

https://github.com/seguridadentrerios/CVE-2026-42533

https://github.com/ChPratik/NGINX_2026_CVE_Bundle_CTI_Report

https://github.com/suominen/CVE-2026-42533

https://github.com/imbas007/CVE-2026-42533

https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner

https://github.com/srkyn/nginx-map-risk-audit

DailyCyberSecurity@infosec.exchange at 2026-07-29T13:30:38.000Z ##

Certighost AD CS vulnerability details and PoC code for CVE-2026-54121 are public. The flaw let a low-privileged user impersonate a Domain Controller.

#Certighost #CVE202654121 #ADCS #ActiveDirectory

securityonline.info/certighost

##

tugatech@masto.pt at 2026-07-28T16:03:08.000Z ##

Exploit público para a falha Certighost expôs domínios do Windows a controlo total. Uma nova vulnerabilidade, rastreada como CVE-2026-54121, coloca redes empresariais em risco e permite que um atacante assuma o controlo completo de um domínio informático. 🚨

🔗 tugatech.com.pt/t88205-exploit

#controlo #exploit #falha #windows 

##

CVE-2026-50469
(7.8 HIGH)

EPSS: 0.27%

updated 2026-07-14T18:32:32

1 posts

Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally.

CVE-2026-59726
(10.0 CRITICAL)

EPSS: 0.48%

updated 2026-07-10T19:15:15.780000

1 posts

Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without authentication, allowing an unauthenticated network attacker to invoke tools/call to terminal_execute, obtain a shell in the bridge container, read provider API keys, and poison AgentDB learning-store patterns.

1 repos

https://github.com/HORKimhab/CVE-2026-59726

offseq@infosec.exchange at 2026-07-30T10:30:29.000Z ##

Ruflo <3.16.3 has a CRITICAL flaw (CVE-2026-59726): exposed /mcp endpoint allows unauth RCE in MCP bridge container. Attackers can spawn rogue AI swarms & steal API keys. Upgrade to 3.16.3 asap. radar.offseq.com/threat/critic #OffSeq #AIsecurity #infosec #CVE202659726

##

CVE-2026-58025
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-07-09T19:34:14.067000

2 posts

Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Import/WikiImporter.Php, includes/Import/WikiRevision.Php, includes/Logging/LogEntryBase.Php. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

1 repos

https://github.com/shinthink/CVE-2026-58025

DarkWebInformer at 2026-07-30T19:21:53.918Z ##

🚨 PoC for CVE-2026-58025, a CVSS 9.8 MediaWiki deserialization flaw that could enable RCE through malicious log entry imports.

Exploitation requires import permissions. Upgrade to 1.43.9, 1.44.6, 1.45.4, or 1.46.0.

GitHub: github.com/shinthink/CVE-2026-

##

DarkWebInformer@infosec.exchange at 2026-07-30T19:21:53.000Z ##

🚨 PoC for CVE-2026-58025, a CVSS 9.8 MediaWiki deserialization flaw that could enable RCE through malicious log entry imports.

Exploitation requires import permissions. Upgrade to 1.43.9, 1.44.6, 1.45.4, or 1.46.0.

GitHub: github.com/shinthink/CVE-2026-

##

CVE-2026-5172
(7.3 HIGH)

EPSS: 2.68%

updated 2026-06-30T03:37:45

2 posts

A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advance the pointer past the record’s end.

2 repos

https://github.com/JianrongXiao-Linksys/dnsmasq-cve-2026

https://github.com/lottiedeyan/CVE20265172poc

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-10702
(4.3 MEDIUM)

EPSS: 0.72%

updated 2026-06-30T03:36:54

1 posts

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.

1 repos

https://github.com/HORKimhab/CVE-2026-10702

jbhall56@infosec.exchange at 2026-07-30T12:34:28.000Z ##

Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update. thehackernews.com/2026/07/rese

##

CVE-2026-0160
(8.8 HIGH)

EPSS: 0.23%

updated 2026-06-17T19:22:02.480000

1 posts

In TextRtpPayloadDecoderNode::DecodeT140 of TextRtpPayloadDecoderNode.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

0v1@infosec.exchange at 2026-07-28T15:06:01.000Z ##

@drwhax also CVE-2026-0160 affecting RTT (US mandated). Reachability is via RTT call.

##

CVE-2026-0149
(8.8 HIGH)

EPSS: 0.29%

updated 2026-06-17T18:36:28

1 posts

In RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-22796
(5.3 MEDIUM)

EPSS: 0.50%

updated 2026-06-17T10:20:26.697000

2 posts

Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing malformed PKCS#7 data. Impact summary: An application performing signature verification of PKCS#7 data or calling directly the PKCS7_digest_from_attribu

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-22795
(5.5 MEDIUM)

EPSS: 0.14%

updated 2026-06-17T10:20:26.520000

2 posts

Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file. Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service. A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2025-69421
(7.5 HIGH)

EPSS: 0.84%

updated 2026-06-17T10:00:40.683000

2 posts

Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function. Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS#12 files. The PKCS12_item_decrypt_d2i_ex() function does not check whether the oct parameter is NULL before dereferencing it. When

1 repos

https://github.com/Kha-Beleh/PoC-CVE-2025-69421

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2025-69420
(7.5 HIGH)

EPSS: 0.77%

updated 2026-06-17T10:00:40.067000

2 posts

Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file. Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to deref

1 repos

https://github.com/Kha-Beleh/PoC-CVE-2025-69420

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2025-15435
(7.3 HIGH)

EPSS: 0.35%

updated 2026-06-17T08:37:46.203000

2 posts

A flaw has been found in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksheet/work_update.jsp. This manipulation of the argument Report causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

jyasskin@hachyderm.io at 2026-07-30T18:14:29.000Z ##

@fugueish Was going to shill Kagi, but their first result is CVE-2025-15435 (i.e. wrong year). The second result is correct. Quotes don't uprank that second result for some reason. It's still the first day, so maybe their crawls aren't as aggressive?

##

jyasskin@hachyderm.io at 2026-07-30T18:14:29.000Z ##

@fugueish Was going to shill Kagi, but their first result is CVE-2025-15435 (i.e. wrong year). The second result is correct. Quotes don't uprank that second result for some reason. It's still the first day, so maybe their crawls aren't as aggressive?

##

CVE-2024-1813
(9.8 CRITICAL)

EPSS: 1.11%

updated 2026-06-17T07:05:03.993000

1 posts

The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.11.0 via deserialization of untrusted input in the job_board_applicant_list_columns_value function. This makes it possible for unauthenticated attackers to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could al

2 repos

https://github.com/MobetaSec/CVE-2024-1813-POC

https://github.com/webshellseo8/CVE-2024-1813-Proof-of-Concept

_r_netsec@infosec.exchange at 2026-07-28T14:13:04.000Z ##

Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813) mobeta.fr/simple-job-board-una

##

CVE-2014-0160
(7.5 HIGH)

EPSS: 100.00%

updated 2026-06-17T00:02:24.467000

1 posts

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

75 repos

https://github.com/siddolo/knockbleed

https://github.com/0x90/CVE-2014-0160

https://github.com/einaros/heartbleed-tools

https://github.com/jdauphant/patch-openssl-CVE-2014-0160

https://github.com/undacmic/heartbleed-proof-of-concept

https://github.com/WildfootW/CVE-2014-0160_OpenSSL_1.0.1f_Heartbleed

https://github.com/mozilla-services/Heartbleed

https://github.com/hmlio/vaas-cve-2014-0160

https://github.com/Saymeis/HeartBleed

https://github.com/marstornado/cve-2014-0160-Yunfeng-Jiang

https://github.com/MrE-Fog/CVE-2014-0160-Chrome-Plugin

https://github.com/vortextube/ssl_scanner

https://github.com/iSCInc/heartbleed

https://github.com/isgroup/openmagic

https://github.com/pierceoneill/bleeding-heart

https://github.com/0xinf0/bleeding_onions

https://github.com/cheese-hub/heartbleed

https://github.com/cyphar/heartthreader

https://github.com/obayesshelton/CVE-2014-0160-Scanner

https://github.com/ingochris/heartpatch.us

https://github.com/PinkP4nther/Heartbleed_PoC

https://github.com/indrajeetmp11/Heartbleed-PoC-Exploit-Script

https://github.com/sammyfung/openssl-heartbleed-fix

https://github.com/hreese/heartbleed-dtls

https://github.com/pblittle/aws-suture

https://github.com/timsonner/cve-2014-0160-heartbleed

https://github.com/iwaffles/heartbleed-test.crx

https://github.com/waqasjamal-zz/HeartBleed-Vulnerability-Checker

https://github.com/FiloSottile/Heartbleed

https://github.com/Ryo-Soikutsu/Heartbleed

https://github.com/GuillermoEscobero/heartbleed

https://github.com/zouguangxian/heartbleed

https://github.com/ArtemCyberLab/Project-Field-Analysis-and-Memory-Leak-Demonstration

https://github.com/ice-security88/CVE-2014-0160

https://github.com/0xBlackash/CVE-2014-0160

https://github.com/roganartu/heartbleedchecker-chrome

https://github.com/tomdevman/heartbleed-bug

https://github.com/amerine/coronary

https://github.com/cbk914/heartbleed-checker

https://github.com/hybridus/heartbleedscanner

https://github.com/titanous/heartbleeder

https://github.com/DisK0nn3cT/MaltegoHeartbleed

https://github.com/yryz/heartbleed.js

https://github.com/Lekensteyn/pacemaker

https://github.com/mpgn/heartbleed-PoC

https://github.com/SimoesCTT/CTT-HEARTBLEED-Temporal-Resonance-Memory-Leak-Exploit-Heartbleed-CVE-2014-0160

https://github.com/ThanHuuTuan/Heartexploit

https://github.com/indiw0rm/-Heartbleed-

https://github.com/cved-sources/cve-2014-0160

https://github.com/h3x0v3rl0rd/CVE-2014-0160_Heartbleed

https://github.com/yashfren/CVE-2014-0160-HeartBleed

https://github.com/belmind/heartbleed

https://github.com/victoriacfigueiredo/heartbleed-lab

https://github.com/GardeniaWhite/fuzzing

https://github.com/xanas/heartbleed.py

https://github.com/froyo75/Heartbleed_Dockerfile_with_Nginx

https://github.com/idkqh7/heatbleeding

https://github.com/OffensivePython/HeartLeak

https://github.com/caiqiqi/OpenSSL-HeartBleed-CVE-2014-0160-PoC

https://github.com/22imer/CVE-2014-0160

https://github.com/artofscripting-zz/cmty-ssl-heartbleed-CVE-2014-0160-HTTP-HTTPS

https://github.com/Shayhha/HeartbleedAttack

https://github.com/GeeksXtreme/ssl-heartbleed.nse

https://github.com/a0726h77/heartbleed-test

https://github.com/fb1h2s/CVE-2014-0160

https://github.com/rouze-d/heartbleed

https://github.com/tungduongNT/CVE-2014-0160.

https://github.com/xlucas/heartbleed

https://github.com/musalbas/heartbleed-masstest

https://github.com/sensepost/heartbleed-poc

https://github.com/DominikTo/bleed

https://github.com/anthophilee/A2SV--SSL-VUL-Scan

https://github.com/takeshixx/ssl-heartbleed.nse

https://github.com/Xyl2k/CVE-2014-0160-Chrome-Plugin

https://github.com/proactiveRISK/heartbleed-extention

g0rb@infosec.exchange at 2026-07-29T17:09:54.000Z ##

Shodan-Query of the day:

asn:"AS59399" vuln:"cve-2014-0160"

#ThruntersAnonymous #shodansafari #yeet

##

CVE-2013-4786
(7.5 HIGH)

EPSS: 78.57%

updated 2026-06-16T23:57:53.617000

1 posts

The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC.

1 repos

https://github.com/fin3ss3g0d/CosmicRakp

hrbrmstr@mastodon.social at 2026-07-28T12:18:05.000Z ##

RE: infosec.exchange/@BleepingComp

The firm that provided the story to BC is a new startup aiming to help "Manage and Secure Data Centers".

They exploited CVE-2013-4786

This is advertising a new startup by flogging a report by extremely lazy "researchers" (did they even do *any* "is this a honeypot" tests?)

Perhaps don't let your C-suite give Lava any business?

##

CVE-2026-40510
(3.8 LOW)

EPSS: 0.22%

updated 2026-05-29T15:30:38

2 posts

OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically present attackers to trigger memory corruption by presenting a crafted PIV smart card or USB device returning a URL field longer than 118 bytes in the Key History Object ASN.1 response.

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-42897
(8.1 HIGH)

EPSS: 5.64%

updated 2026-05-15T18:30:32

5 posts

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

1 repos

https://github.com/atiilla/CVE-2026-42897

sayzard@mastodon.sayzard.org at 2026-07-30T13:43:28.000Z ##

Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit

Proofpoint는 러시아 연계 위협 행위자 TA488이 Outlook Web Access(OWA)의 HTML sanitization XSS 취약점 CVE-2026-42897을 악용해, 이메일을 열기만 해도 JavaScript가 실행되는 ‘half-click’ 공격을 수행했다고 밝혔다. 페이로드인 OWAReaper는 OWA 읽기 창에서만 동작하며 localStorage, IndexedDB 오프라인 캐시, Exchange 폴더 권한...

proofpoint.com/us/blog/threat-

##

jbhall56@infosec.exchange at 2026-07-30T12:09:26.000Z ##

The activity, which began on July 22, 2026, involves the weaponization of CVE-2026-42897 (CVSS score: 8.1), a cross-site scripting (XSS) vulnerability in OWA. It was flagged by Microsoft as having been exploited in attacks as far back as May 2026. thehackernews.com/2026/07/russ

##

VirusBulletin@infosec.exchange at 2026-07-30T09:01:00.000Z ##

Proofpoint analyses a campaign from Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) exploiting Outlook CVE-2026-42897 and targeting US & European government entities, as well as the telecommunications, financial, hospitality & aerospace sectors. proofpoint.com/us/blog/threat-

##

AAKL@infosec.exchange at 2026-07-29T18:03:12.000Z ##

New.

"On 22 July 2026, one day prior to Proofpoint’s recent joint release with the NSA on Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear), the actor began a campaign abusing CVE-2026-42897, a cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA)."

Proofpoint: Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit proofpoint.com/us/blog/threat-

More:

The Record: Laundry Bear’s webmail hackers had more in store after February, report says therecord.media/russia-hackers @therecord_media @jwarminsky #infosec #threatresearch #Outlook #Microsoft

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T12:41:20.000Z ##

A TA488 half-click exploit abuses CVE-2026-42897 in Outlook Web Access to drop OWAReaper, a stealthy implant that survives device reimaging.

#TA488 #OWAReaper #HalfClickExploit #CVE202642897 #OutlookWebAccess #InfoSec

securityonline.info/ta488-owar

##

CVE-2025-69418
(4.0 None)

EPSS: 0.11%

updated 2026-05-12T15:31:14

2 posts

Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed in<br>cleartext on encryption and are not covered by the authentication tag,<br>allowing an

1 repos

https://github.com/x-stp/cves-2025-11187_15467_69418

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2025-69419
(7.4 HIGH)

EPSS: 0.44%

updated 2026-05-12T15:31:14

2 posts

Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer. Impact summary: The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service. The OPENSSL_uni2utf8() functi

1 repos

https://github.com/Kha-Beleh/PoC-CVE-2025-69419

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2025-68160
(4.7 MEDIUM)

EPSS: 0.15%

updated 2026-05-12T15:31:14

2 posts

Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write. Impact summary: This out-of-bounds write can cause memory corruption which typically results in a crash, leading to Denial of Service for an application. The line-buffering BIO filter (BIO_f_linebuffer) is not used

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-4893
(5.3 MEDIUM)

EPSS: 2.68%

updated 2026-05-11T21:31:33

2 posts

An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS packet with RFC 7871 client subnet information.

5 repos

https://github.com/Polosss/By-Poloss..-..CVE-2026-48939

https://github.com/ChiefYoru/CVE-2026-48939_PoC

https://github.com/lottiedeyan/CVE20264893poc

https://github.com/shinthink/CVE-2026-48939

https://github.com/JianrongXiao-Linksys/dnsmasq-cve-2026

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-20079
(10.0 CRITICAL)

EPSS: 38.70%

updated 2026-03-04T18:32:03

2 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerab

1 repos

https://github.com/0xBlackash/CVE-2026-20079

security_crawler_carl@infosec.exchange at 2026-07-30T11:45:32.000Z ##

🏆 New Achievement! Static Credentials, Static Fate!

RAID ALERT. RAID ALERT. Cisco Secure Firewall Management Center has a hardcoded low-privilege account baked right into the software — CVE-2026-20316 — and unauthenticated remote attackers are already using it to log in and harvest sensitive data. That's Phase One. Phase Two is the wipe: threat actors are chaining it with CVE-2026-20079, which hands them root access via arbitrary script execution. (1/2)

##

AAKL@infosec.exchange at 2026-07-29T17:36:00.000Z ##

New Cisco updates:

CRITICAL vulnerability, first released on March 4: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi

High severity: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability sec.cloudapps.cisco.com/securi

New informational advisory: Cisco Advance Notification for Publication of August 5, 2026, Security Advisories sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #vulnerability #Cisco

##

CVE-2026-1623
(6.3 MEDIUM)

EPSS: 2.18%

updated 2026-01-29T21:30:37

1 posts

A weakness has been identified in Totolink A7000R 4.1cu.4154. Impacted is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument FileName causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

1 repos

https://github.com/sfewer-r7/CVE-2026-16232

hackmag@infosec.exchange at 2026-07-28T21:30:05.000Z ##

⚪️ Hackers Exploit a Zero-Day in Check Point SmartConsole

🗨️ Check Point has warned customers about a critical vulnerability, CVE-2026-16232, affecting its Security Management and Multi-Domain Management products. The flaw allows attackers to bypass authentication, gain administrator privileges, and modify security policies. The vulnerability is already be…

🔗 hackmag.com/news/cve-2026-1623

#news

##

CVE-2023-37327
(7.6 HIGH)

EPSS: 1.71%

updated 2025-11-04T21:32:34

2 posts

GStreamer FLAC File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of FLAC audio files. The issue

hugovalters@mastodon.social at 2026-07-30T05:55:09.000Z ##

@slomo No need for the hostility. The text summary might pull context from reference links mentioning 1.22.5, but our 'Patch Status' flag operates strictly on machine-readable data from the NVD API.
If you look at the official NVD record for CVE-2023-37327, the CPE configurations only map up to 1.22.4 and do not explicitly record the patched status. We explicitly do not accept vendor GitHub releases as evidence until they are validated by NVD.

##

slomo@toot.cat at 2026-07-29T19:32:02.000Z ##

@hugovalters Bullshit. Get your data updated and fix your website instead of spreading fud.

It's very funny that e.g. valtersit.com/cve/CVE-2023-373 claims to be "unpatched" and at the top says that it's fixed in 1.22.5, contains completely wrong information (just follow your own NVD link and compare: it's describing completely different issues), and a wrong patch for code that does not even exist in this shape in 1.22.5 or any other version.

Not enough that we have to deal with a flood of new issues reported thanks to LLMs, on top of that we also have to deal with clowns like you.

##

CVE-2023-5217
(8.8 HIGH)

EPSS: 49.01%

updated 2024-02-15T15:02:28

1 posts

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

3 repos

https://github.com/Trinadh465/platform_external_libvpx_v1.4.0_CVE-2023-5217

https://github.com/UT-Security/cve-2023-5217-poc

https://github.com/Trinadh465/platform_external_libvpx_v1.8.0_CVE-2023-5217

nyanbinary@infosec.exchange at 2026-07-28T14:50:54.000Z ##

now to figure out if CVE-2023-5217 on our NAS actually matters...

##

CVE-2008-1028(CVSS UNKNOWN)

EPSS: 4.55%

updated 2023-01-31T05:05:55

1 posts

Unspecified vulnerability in AppKit in Apple Mac OS X before 10.5 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted document file, as demonstrated by opening the document with TextEdit.

rosyna@mastodon.social at 2026-07-27T21:40:58.000Z ##

Apple was much more verbose in describing security issues in 2008 (look at CVE-2008-1028)
support.apple.com/en-ie/102486

##

netsecio@mastodon.social at 2026-07-30T17:51:48.000Z ##

📰 Critical RCE Flaw in OpenWrt Allows Root Access via DHCPv6

🚨 CRITICAL RCE: A vulnerability in OpenWrt (CVE-2026-53921) allows unauthenticated attackers to gain root access via the DHCPv6 server. All versions before 24.10.8 are affected. Update your routers immediately! #OpenWrt #RCE #CVE

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/cr

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T14:01:16.000Z ##

OpenWrt Vulnerability CVE-2026-53921 Demands Immediate Action

securityexpress.info/openwrt-v

##

threatnoir@infosec.exchange at 2026-07-29T08:06:52.000Z ##

⚠️ CRITICAL: Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

OpenWrt released a critical patch (v24.10.8) for CVE-2026-53921, a stack overflow in the DHCPv6 service (odhcpd) that allows unauthenticated remote code execution as root. Any unpatched OpenWrt device is exploitable by sending crafted DHCPv6 packets. This affects routers and edge devices across ent…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-58086
(0 None)

EPSS: 0.00%

1 posts

N/A

CVE-2026-56848
(0 None)

EPSS: 0.00%

4 posts

N/A

nodejs_release_watcher@kodesumber.com at 2026-07-29T17:29:15.000Z ##

2026-07-29, Version 24.18.1 'Krypton' (LTS), @juanarbol

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T15:30:05.000Z ##

Node.js patched 11 vulnerabilities in its July 2026 release. The high-severity bugs include a HTTP/2 use-after-free (CVE-2026-56848). Update now.

#NodeJS #CVE202656848 #HTTP2 #UseAfterFree #Vulnerability #InfoSec

securityonline.info/nodejs-jul

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:01.000Z ##

2026-07-29, Version 26.5.1 (Current), @RafaelGSS

This is a security release. Notable Changes (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:00.000Z ##

2026-07-29, Version 22.23.2 'Jod' (LTS), @marco-ippolito

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

CVE-2026-56846
(0 None)

EPSS: 0.00%

2 posts

N/A

nodejs_release_watcher@kodesumber.com at 2026-07-29T17:29:15.000Z ##

2026-07-29, Version 24.18.1 'Krypton' (LTS), @juanarbol

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:00.000Z ##

2026-07-29, Version 22.23.2 'Jod' (LTS), @marco-ippolito

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

CVE-2026-65094
(0 None)

EPSS: 0.00%

1 posts

N/A

DailyCyberSecurity@infosec.exchange at 2026-07-29T02:15:59.000Z ##

NVIDIA BlueField has a critical VIRTIO-Net flaw, CVE-2026-65094, rated CVSS 9.0. A VM user could trigger code execution. Update to the fixed DOCA build.

#NVIDIA #BlueField #VIRTIONet #CVE202665094 #CodeExecution #CyberSecurity

securityonline.info/nvidia-blu

##

Visit counter For Websites