##
Updated at UTC 2026-09-18T05:14:06.871053
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-20341 | 9.1 | 0.00% | 1 | 0 | 2026-09-18T04:17:47.180000 | A vulnerability in the sftunnel inter-device communication protocol of Cisco Sec | |
| CVE-2026-93456 | 8.2 | 0.00% | 2 | 0 | 2026-09-18T02:17:09.113000 | django-page-cms through 2.0.13 exempts five admin mutation views from CSRF prote | |
| CVE-2026-85889 | 10.0 | 0.00% | 2 | 0 | 2026-09-18T00:31:16 | Missing authentication for critical function in Azure AI Foundry allows an unaut | |
| CVE-2026-87886 | 7.8 | 0.00% | 8 | 0 | 2026-09-18T00:31:15 | Local privilege escalation due to insecure file permissions. The following produ | |
| CVE-2026-93452 | 7.5 | 0.00% | 2 | 0 | 2026-09-18T00:17:49.540000 | snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy. | |
| CVE-2026-93450 | 7.5 | 0.00% | 2 | 0 | 2026-09-18T00:17:49.230000 | go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability | |
| CVE-2026-54734 | 10.0 | 0.00% | 2 | 0 | 2026-09-17T22:17:03.317000 | Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certai | |
| CVE-2026-70469 | 7.5 | 0.00% | 1 | 0 | 2026-09-17T21:32:42 | Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the appli | |
| CVE-2026-84858 | 8.8 | 0.00% | 1 | 0 | 2026-09-17T21:32:41 | ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote | |
| CVE-2026-79752 | None | 0.00% | 2 | 0 | 2026-09-17T20:28:17 | ### Impact The `FunctionsBuilder::cast($field, $dataType)`, `extract($part, $exp | |
| CVE-2026-92956 | 10.0 | 0.00% | 2 | 0 | 2026-09-17T20:18:59.730000 | vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a def | |
| CVE-2026-92935 | 9.0 | 0.00% | 2 | 0 | 2026-09-17T20:18:59.093000 | vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and < | |
| CVE-2026-91989 | 7.5 | 1.26% | 1 | 0 | 2026-09-17T20:18:54.893000 | atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the | |
| CVE-2026-54627 | 9.8 | 0.00% | 2 | 0 | 2026-09-17T20:16:52.117000 | SAIL is a cross-platform library for loading and saving images with support for | |
| CVE-2026-87286 | 8.1 | 0.24% | 1 | 0 | 2026-09-17T18:34:49 | Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compil | |
| CVE-2026-12793 | 9.8 | 0.39% | 1 | 3 | 2026-09-17T18:16:36.517000 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnera | |
| CVE-2026-86863 | 9.8 | 0.00% | 2 | 0 | 2026-09-17T17:16:51.633000 | pgAdmin 4's Webserver authentication source is intended to accept an identity as | |
| CVE-2026-92941 | 10.0 | 0.00% | 2 | 0 | 2026-09-17T16:18:34.520000 | vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sand | |
| CVE-2026-86865 | 7.2 | 0.00% | 1 | 0 | 2026-09-17T16:18:18.163000 | Tanium addressed a SQL injection vulnerability in Asset. | |
| CVE-2026-86320 | 7.8 | 0.00% | 2 | 0 | 2026-09-17T16:18:17.403000 | A flaw was found in flatpak-builder where Git hooks are not disabled when applyi | |
| CVE-2026-92938 | 9.9 | 0.00% | 2 | 0 | 2026-09-17T15:32:28 | vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to c | |
| CVE-2026-92939 | 9.9 | 0.00% | 2 | 0 | 2026-09-17T15:32:28 | vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM san | |
| CVE-2026-92954 | 8.6 | 0.00% | 2 | 0 | 2026-09-17T15:32:28 | vm2 is a sandbox library for running untrusted JavaScript in Node.js. In version | |
| CVE-2026-92940 | 10.0 | 0.00% | 2 | 0 | 2026-09-17T15:32:27 | vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAg | |
| CVE-2026-92960 | 10.0 | 0.00% | 2 | 0 | 2026-09-17T15:32:27 | vm2 before 3.11.6 fails to restrict access to os and dns builtins under the buil | |
| CVE-2026-92951 | 9.9 | 0.00% | 2 | 0 | 2026-09-17T15:32:26 | vm2 before 3.11.7 contains an incorrect authorization vulnerability in the exter | |
| CVE-2026-92944 | 9.8 | 0.00% | 2 | 0 | 2026-09-17T15:32:26 | vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Nod | |
| CVE-2026-92957 | 9.9 | 0.00% | 2 | 0 | 2026-09-17T15:32:26 | vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when e | |
| CVE-2026-92918 | 8.8 | 0.00% | 2 | 0 | 2026-09-17T15:32:24 | admin3 through 3.0.0 persists user session tokens in the audit log event body wh | |
| CVE-2026-92937 | 10.0 | 0.00% | 2 | 0 | 2026-09-17T15:32:23 | vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in | |
| CVE-2026-92919 | 8.1 | 0.00% | 2 | 0 | 2026-09-17T15:32:23 | admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload h | |
| CVE-2026-92946 | 10.0 | 0.00% | 2 | 0 | 2026-09-17T15:32:22 | vm2 before 3.11.7 contains a remote code execution vulnerability when require.ex | |
| CVE-2026-92953 | 10.0 | 0.00% | 2 | 0 | 2026-09-17T15:32:22 | vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and Array | |
| CVE-2026-92947 | 10.0 | 0.00% | 2 | 0 | 2026-09-17T15:32:21 | vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing | |
| CVE-2026-81481 | 7.5 | 0.00% | 2 | 0 | 2026-09-17T15:32:18 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Im | |
| CVE-2026-92955 | 10.0 | 0.00% | 2 | 0 | 2026-09-17T15:32:17 | vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows | |
| CVE-2026-92950 | 8.6 | 0.00% | 2 | 0 | 2026-09-17T15:17:00.910000 | vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that a | |
| CVE-2026-92934 | 9.0 | 0.00% | 2 | 0 | 2026-09-17T15:17:00.520000 | vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that a | |
| CVE-2026-92948 | 9.9 | 0.00% | 2 | 0 | 2026-09-17T14:18:00.420000 | vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist b | |
| CVE-2026-92838 | 7.8 | 0.00% | 2 | 0 | 2026-09-17T14:17:56.873000 | A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop ap | |
| CVE-2026-15688 | 0 | 0.00% | 2 | 0 | 2026-09-17T13:16:42.530000 | Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi | |
| CVE-2026-76460 | 10.0 | 0.00% | 30 | 1 | 2026-09-17T12:46:31.670000 | A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an | |
| CVE-2026-92913 | 7.4 | 0.00% | 2 | 0 | 2026-09-17T12:18:30.290000 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptograp | |
| CVE-2026-91843 | 9.8 | 0.00% | 6 | 1 | 2026-09-17T12:18:29.687000 | A stack overflow during the unauthenticated login process may allow an attacker | |
| CVE-2026-20307 | 9.9 | 0.00% | 1 | 0 | 2026-09-17T12:17:25.977000 | A vulnerability in the web-based management interface of Cisco ISE could allow a | |
| CVE-2026-87796 | 9.8 | 0.00% | 2 | 1 | 2026-09-17T06:30:45 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbit | |
| CVE-2026-73453 | 10.0 | 0.75% | 1 | 0 | 2026-09-17T04:17:59.823000 | An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors | |
| CVE-2026-69486 | 8.8 | 0.66% | 1 | 0 | 2026-09-17T04:17:55.620000 | Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthor | |
| CVE-2026-92578 | 8.1 | 0.00% | 1 | 0 | 2026-09-17T00:31:30 | WWBN AVideo through 29.0 contains an authentication bypass vulnerability where t | |
| CVE-2026-92576 | 8.6 | 0.00% | 1 | 0 | 2026-09-17T00:31:25 | HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability | |
| CVE-2026-20332 | 9.9 | 0.00% | 2 | 0 | 2026-09-16T21:32:55 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-89082 | None | 0.00% | 2 | 0 | 2026-09-16T21:32:55 | HP has identified potential security vulnerabilities in the HP Advance software | |
| CVE-2026-20324 | 9.9 | 0.00% | 1 | 0 | 2026-09-16T21:32:50 | A vulnerability in the sftunnel inter-device communication protocol of Cisco Sec | |
| CVE-2026-20192 | 10.0 | 0.00% | 2 | 0 | 2026-09-16T21:32:50 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-20211 | 9.1 | 0.00% | 1 | 0 | 2026-09-16T21:32:50 | A vulnerability in Cisco ISE could allow an authenticated, remote attacker to ex | |
| CVE-2026-20176 | 9.1 | 0.00% | 1 | 0 | 2026-09-16T21:32:50 | A vulnerability in Cisco ISE could allow an authenticated, remote attacker to ex | |
| CVE-2026-87976 | None | 0.00% | 1 | 0 | 2026-09-16T21:32:48 | Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when | |
| CVE-2026-87024 | 7.2 | 0.00% | 1 | 0 | 2026-09-16T21:32:47 | Tanium addressed a SQL injection vulnerability in Asset. | |
| CVE-2026-88975 | 7.5 | 0.62% | 1 | 0 | 2026-09-16T20:39:16.610000 | Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, E | |
| CVE-2026-77179 | 0 | 0.16% | 2 | 1 | 2026-09-16T20:38:33.883000 | On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows | |
| CVE-2026-70416 | 10.0 | 0.00% | 1 | 0 | 2026-09-16T20:37:16.870000 | Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untru | |
| CVE-2026-63696 | 9.1 | 0.32% | 1 | 0 | 2026-09-16T20:37:16.870000 | Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download | |
| CVE-2026-92176 | 7.8 | 0.17% | 1 | 0 | 2026-09-16T20:26:50.280000 | pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulne | |
| CVE-2026-92177 | 7.8 | 0.17% | 1 | 0 | 2026-09-16T20:26:50.280000 | pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Executio | |
| CVE-2026-15638 | 0 | 0.20% | 1 | 0 | 2026-09-16T20:17:20.950000 | An unauthenticated user with access to Secret Server could leverage a padding or | |
| CVE-2026-87289 | 7.5 | 0.46% | 1 | 0 | 2026-09-16T19:42:12.090000 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: hel | |
| CVE-2026-80217 | 8.8 | 0.28% | 1 | 0 | 2026-09-16T19:27:25.623000 | Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allo | |
| CVE-2026-76670 | 9.9 | 0.45% | 1 | 0 | 2026-09-16T19:20:52.817000 | Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConn | |
| CVE-2026-27564 | 7.2 | 2.02% | 3 | 0 | 2026-09-16T19:17:13.860000 | A high-privileged remote attacker can exploit a command injection vulnerability | |
| CVE-2026-27561 | 7.2 | 2.23% | 3 | 0 | 2026-09-16T19:17:13.633000 | A high-privileged remote attacker can exploit a command injection vulnerability | |
| CVE-2026-40854 | 0 | 0.00% | 1 | 0 | 2026-09-16T19:14:25.980000 | WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability i | |
| CVE-2026-87288 | 8.1 | 0.24% | 1 | 0 | 2026-09-16T18:32:58 | Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compil | |
| CVE-2026-20331 | 9.6 | 0.00% | 1 | 0 | 2026-09-16T18:32:09 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-92397 | 9.1 | 0.00% | 1 | 0 | 2026-09-16T18:32:09 | A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected | |
| CVE-2026-89775 | 9.3 | 0.18% | 1 | 0 | 2026-09-16T18:31:58 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: | |
| CVE-2026-87287 | 8.1 | 0.24% | 1 | 0 | 2026-09-16T18:31:53 | Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compil | |
| CVE-2026-90999 | 0 | 0.00% | 2 | 0 | 2026-09-16T17:18:18.923000 | Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows | |
| CVE-2026-61595 | 7.7 | 0.00% | 1 | 0 | 2026-09-16T15:32:15 | ### Impact `djust.tenants` isolation was enforced only on the HTTP path. The cur | |
| CVE-2026-73172 | None | 0.00% | 1 | 0 | 2026-09-16T15:31:13 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele | |
| CVE-2026-58704 | 8.0 | 0.11% | 23 | 0 | 2026-09-16T15:30:57 | In Cellular Modem, there is a possible permission bypass due to a logic error in | |
| CVE-2026-88065 | 7.5 | 0.37% | 1 | 0 | 2026-09-16T14:17:12.413000 | `tts-be` is a backend for a timetable selector that aims to help students better | |
| CVE-2026-27565 | 9.8 | 0.94% | 4 | 0 | 2026-09-16T09:30:35 | An unauthenticated remote attacker can upload a malicious IODD file that places | |
| CVE-2026-27563 | 7.2 | 2.02% | 3 | 0 | 2026-09-16T09:30:35 | A high-privileged remote attacker can exploit a command injection vulnerability | |
| CVE-2026-27562 | 7.2 | 2.23% | 3 | 0 | 2026-09-16T09:30:34 | A high-privileged remote attacker can exploit a command injection vulnerability | |
| CVE-2026-81642 | None | 0.52% | 5 | 1 | 2026-09-16T09:30:28 | In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in t | |
| CVE-2026-14349 | 9.8 | 0.42% | 1 | 0 | 2026-09-16T06:31:34 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress i | |
| CVE-2026-79994 | None | 0.11% | 1 | 0 | 2026-09-16T00:32:32 | The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a | |
| CVE-2026-85893 | 8.8 | 0.68% | 1 | 0 | 2026-09-16T00:31:42 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacke | |
| CVE-2026-15640 | None | 0.28% | 2 | 0 | 2026-09-16T00:31:41 | Under certain conditions a valid SAML IdP response may be used to impersonate an | |
| CVE-2026-92248 | 7.8 | 0.18% | 1 | 0 | 2026-09-16T00:31:36 | A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail pre | |
| CVE-2026-73807 | 9.8 | 0.65% | 2 | 0 | 2026-09-16T00:31:35 | The mySCADA myPRO Manager command API does not properly enforce authentication f | |
| CVE-2026-15639 | None | 0.39% | 2 | 0 | 2026-09-16T00:31:33 | An attacker can craft a malicious link that, if used by a legitimate user, may c | |
| CVE-2026-91939 | 9.8 | 0.59% | 1 | 0 | 2026-09-15T21:33:15 | Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() witho | |
| CVE-2026-92000 | 7.5 | 0.39% | 1 | 0 | 2026-09-15T21:33:15 | adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output li | |
| CVE-2026-68070 | 8.8 | 0.27% | 1 | 0 | 2026-09-15T21:33:13 | The affected products are missing authentication for a critical function, which | |
| CVE-2026-66890 | 9.6 | 0.20% | 1 | 0 | 2026-09-15T21:33:13 | The affected products use hard-coded credentials, which could allow remote acces | |
| CVE-2026-89040 | 9.8 | 0.93% | 1 | 0 | 2026-09-15T21:33:13 | Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated a | |
| CVE-2026-92179 | 7.8 | 0.17% | 1 | 0 | 2026-09-15T21:31:29 | pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Executio | |
| CVE-2026-92178 | 7.8 | 0.17% | 1 | 0 | 2026-09-15T21:31:28 | pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution | |
| CVE-2026-92180 | 7.8 | 0.14% | 1 | 0 | 2026-09-15T21:31:25 | pdfforge PDF Architect activation-service Update Service Uncontrolled Search Pat | |
| CVE-2026-69213 | 7.5 | 0.36% | 1 | 0 | 2026-09-15T20:00:36 | Ember's HTTP/2 connection serializes all outgoing frames through a single unboun | |
| CVE-2026-20274 | 9.8 | 0.73% | 1 | 0 | 2026-09-15T18:33:13 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-89026 | 9.8 | 0.52% | 3 | 1 | 2026-09-15T18:32:43 | The Issabel Framework, the web framework supporting Issabel PBX software, before | |
| CVE-2026-91985 | 7.5 | 0.38% | 1 | 0 | 2026-09-15T18:32:43 | Vikunja before 2.6.0 fails to properly restrict access to the link-share hash fi | |
| CVE-2026-91990 | 7.5 | 0.41% | 1 | 0 | 2026-09-15T18:32:43 | Tornado before 6.5.8 contains a memory amplification vulnerability in parse_mult | |
| CVE-2026-20276 | 8.6 | 0.27% | 1 | 0 | 2026-09-15T18:32:13 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-63443 | 8.3 | 0.42% | 1 | 0 | 2026-09-15T18:17:29.010000 | Coder allows organizations to provision remote development environments via Terr | |
| CVE-2026-20275 | 8.8 | 0.19% | 1 | 0 | 2026-09-15T18:17:18.413000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-63695 | 9.8 | 0.53% | 1 | 0 | 2026-09-15T15:32:20 | Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session F | |
| CVE-2026-89025 | 7.5 | 0.42% | 1 | 0 | 2026-09-15T15:32:20 | Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerabilit | |
| CVE-2026-39919 | 9.8 | 0.49% | 1 | 0 | 2026-09-15T15:17:14.723000 | Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability i | |
| CVE-2026-81915 | 0 | 0.37% | 1 | 0 | 2026-09-15T14:40:24.370000 | Concrete CMS below 9.5.3 does not perform an object-level authorization check wh | |
| CVE-2026-89308 | 0 | 2.97% | 1 | 0 | 2026-09-15T13:16:45.543000 | An unauthenticated OS command injection vulnerability exists in the ping.php end | |
| CVE-2026-76461 | 9.8 | 2.01% | 12 | 4 | 2026-09-15T12:47:32.497000 | A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure | |
| CVE-2026-91995 | 9.1 | 0.61% | 1 | 0 | 2026-09-15T12:31:54 | pig before 4.1.0 contains an authentication bypass vulnerability in the /registe | |
| CVE-2026-77853 | 8.8 | 1.03% | 1 | 0 | 2026-09-15T09:30:39 | Improper neutralization of special elements used in an OS command ('OS Command I | |
| CVE-2026-91001 | 9.9 | 0.48% | 1 | 0 | 2026-09-15T06:30:39 | A security flaw has been discovered in D-Link DI-8400 16.07. This affects the fu | |
| CVE-2026-12944 | 9.6 | 0.25% | 1 | 2 | 2026-09-15T00:31:21 | IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary P | |
| CVE-2026-65352 | 4.3 | 0.25% | 1 | 0 | 2026-09-15T00:31:13 | An information disclosure issue was addressed with improved state management. Th | |
| CVE-2026-82232 | 9.8 | 0.56% | 1 | 0 | 2026-09-14T21:32:45 | Improper neutralization of special elements used in an SQL command ('SQL injecti | |
| CVE-2026-78159 | 9.8 | 0.76% | 1 | 0 | 2026-09-14T17:17:51.410000 | The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execut | |
| CVE-2026-81005 | None | 0.18% | 3 | 0 | 2026-09-14T15:33:28 | In the Linux kernel, the following vulnerability has been resolved: ipmi: si: F | |
| CVE-2026-81000 | 7.8 | 0.16% | 1 | 0 | 2026-09-14T15:33:28 | In the Linux kernel, the following vulnerability has been resolved: net: tun: b | |
| CVE-2026-80967 | 8.4 | 0.18% | 1 | 0 | 2026-09-14T15:33:27 | In the Linux kernel, the following vulnerability has been resolved: ALSA: pcxhr | |
| CVE-2026-80952 | 7.8 | 0.12% | 1 | 0 | 2026-09-14T15:33:27 | In the Linux kernel, the following vulnerability has been resolved: i3c: master | |
| CVE-2026-89483 | 7.5 | 0.56% | 1 | 0 | 2026-09-14T15:32:26 | In the Linux kernel, the following vulnerability has been resolved: nvme: zero | |
| CVE-2026-80982 | 7.8 | 0.16% | 1 | 0 | 2026-09-14T15:32:22 | In the Linux kernel, the following vulnerability has been resolved: net/smc: fi | |
| CVE-2026-80938 | None | 0.17% | 1 | 0 | 2026-09-14T15:32:20 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: | |
| CVE-2026-85706 | 10.0 | 11.96% | 5 | 13 | 2026-09-14T14:22:15.323000 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 | |
| CVE-2026-89491 | 0 | 0.21% | 1 | 0 | 2026-09-14T13:19:06.090000 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: clus | |
| CVE-2026-89474 | 0 | 0.17% | 1 | 0 | 2026-09-14T13:19:03.733000 | In the Linux kernel, the following vulnerability has been resolved: power: supp | |
| CVE-2026-89442 | 7.8 | 0.16% | 1 | 0 | 2026-09-14T13:19:01.410000 | In the Linux kernel, the following vulnerability has been resolved: platform/x8 | |
| CVE-2026-80983 | 0 | 0.17% | 1 | 0 | 2026-09-14T13:18:53.090000 | In the Linux kernel, the following vulnerability has been resolved: net/smc: fi | |
| CVE-2026-80939 | 0 | 0.17% | 1 | 0 | 2026-09-14T13:18:50.037000 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89 | |
| CVE-2026-90894 | 7.8 | 0.15% | 2 | 0 | 2026-09-14T12:31:44 | Parallels Desktop runs prl_disp_service as root. Local clients reach it on the w | |
| CVE-2026-12518 | None | 0.11% | 1 | 0 | 2026-09-14T09:31:09 | A local privilege escalation vulnerability in the Logitech Logi Options+ updater | |
| CVE-2026-80955 | 7.8 | 0.16% | 1 | 0 | 2026-09-13T07:17:02.700000 | In the Linux kernel, the following vulnerability has been resolved: dm-pcache: | |
| CVE-2026-78006 | 9.8 | 0.78% | 1 | 2 | 2026-09-12T09:33:41 | The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execut | |
| CVE-2026-89529 | None | 0.19% | 1 | 0 | 2026-09-11T21:31:37 | In the Linux kernel, the following vulnerability has been resolved: svcrdma: Re | |
| CVE-2026-89514 | None | 0.17% | 1 | 0 | 2026-09-11T21:31:37 | In the Linux kernel, the following vulnerability has been resolved: scsi: fnic: | |
| CVE-2026-84869 | 9.9 | 0.69% | 2 | 0 | 2026-09-11T21:31:17 | A condition in the ScreenConnect client may allow files to be transferred and ex | |
| CVE-2026-42016 | 8.1 | 0.89% | 1 | 0 | 2026-09-11T21:31:06 | JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a pri | |
| CVE-2026-59971 | 10.0 | 0.39% | 1 | 0 | 2026-09-11T20:36:20 | ## Summary In SSE/HTTP transport mode, `mysql_mcp_server` constructs `SseServer | |
| CVE-2026-81861 | None | 0.38% | 1 | 1 | 2026-09-11T18:31:25 | CWE-522: Insufficiently Protected Credentials vulnerability that could result in | |
| CVE-2026-82079 | 8.4 | 0.16% | 1 | 0 | 2026-09-11T03:31:25 | A stack-based buffer overflow vulnerability in the Nintendo Switch local wireles | |
| CVE-2026-59160 | 8.8 | 0.41% | 1 | 0 | 2026-09-09T23:47:56 | ## Unauthenticated Network-Exposed Turborepo Task Execution via /api/run ### Su | |
| CVE-2026-20079 | 10.0 | 75.75% | 1 | 3 | 2026-09-09T21:31:33 | A vulnerability in the web interface of Cisco Secure Firewall Management Center | |
| CVE-2026-15534 | 5.7 | 0.17% | 1 | 0 | 2026-09-08T22:17:38.113000 | Perl versions through 5.45.1 have out-of-bounds heap reads and writes during reg | |
| CVE-2026-75650 | 10.0 | 2.15% | 1 | 5 | 2026-09-08T21:33:09 | Adobe Commerce is affected by an Improper Neutralization of Special Elements Use | |
| CVE-2026-31431 | 7.8 | 99.91% | 1 | 100 | 2026-09-08T09:36:36 | In the Linux kernel, the following vulnerability has been resolved: crypto: alg | |
| CVE-2026-58113 | 6.1 | 0.22% | 1 | 0 | 2026-09-08T09:35:45 | A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.00 | |
| CVE-2026-15315 | 8.8 | 0.30% | 4 | 1 | 2026-09-04T18:32:18 | Tapo C200 v5 contains an improper authentication vulnerability within the login | |
| CVE-2026-15316 | 6.5 | 0.23% | 4 | 1 | 2026-09-04T18:31:13 | An improper input validation vulnerability in the configuration service for proc | |
| CVE-2026-81573 | 8.6 | 0.46% | 1 | 0 | 2026-09-01T20:56:59.203000 | If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configu | |
| CVE-2026-56211 | 7.1 | 0.48% | 1 | 0 | 2026-09-01T13:19:51.053000 | A remote code execution vulnerability was found in libaom, the reference AV1 cod | |
| CVE-2026-39113 | 4.0 | 0.21% | 1 | 1 | 2026-08-31T18:31:16 | Buffer Overflow vulnerability in SQLite affected version source snapshots/builds | |
| CVE-2026-56210 | 7.1 | 0.31% | 1 | 0 | 2026-08-31T15:35:36 | A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 | |
| CVE-2026-56208 | 7.6 | 0.42% | 1 | 0 | 2026-08-31T15:34:31 | A heap buffer overflow vulnerability was found in libaom, the reference AV1 code | |
| CVE-2026-56209 | 7.1 | 0.35% | 1 | 0 | 2026-08-31T15:34:31 | An arbitrary address write vulnerability was found in libaom, the reference AV1 | |
| CVE-2026-81572 | 7.8 | 0.17% | 1 | 0 | 2026-08-27T12:30:27 | cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-S | |
| CVE-2026-81576 | 7.7 | 0.33% | 1 | 0 | 2026-08-27T12:30:27 | If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issu | |
| CVE-2026-81574 | 8.2 | 0.41% | 1 | 0 | 2026-08-27T12:30:27 | In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitiz | |
| CVE-2026-81575 | 7.5 | 0.44% | 1 | 0 | 2026-08-27T12:30:26 | If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 acce | |
| CVE-2026-60004 | 9.8 | 86.78% | 2 | 10 | 2026-08-27T11:41:19.230000 | Gitea before 1.27.1 allows remote code execution via the diffpatch API through G | |
| CVE-2026-56389 | 8.6 | 0.16% | 2 | 0 | 2026-08-24T18:32:30 | GNU Bison allows for an execution of an arbitrary program during HTML report gen | |
| CVE-2026-59310 | 9.8 | 45.88% | 2 | 2 | 2026-08-19T04:17:24.940000 | VMware vCenter contains a directory traversal vulnerability in the Syslog server | |
| CVE-2026-19487 | 5.3 | 0.42% | 1 | 0 | 2026-08-13T21:37:11 | Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression matc | |
| CVE-2026-5430 | 10.0 | 0.32% | 4 | 1 | 2026-08-06T09:30:40 | The JWT authentication mechanism accepts tokens signed with algorithms other tha | |
| CVE-2026-15830 | 5.3 | 1.26% | 1 | 0 | 2026-08-04T18:31:31 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDja | |
| CVE-2026-13584 | None | 0.13% | 2 | 0 | 2026-08-04T06:32:37 | Improper Enforcement of Message Integrity During Transmission in a Communication | |
| CVE-2026-45659 | 8.8 | 76.08% | 1 | 2 | 2026-07-01T21:35:53 | Deserialization of untrusted data in Microsoft Office SharePoint allows an autho | |
| CVE-2026-47203 | None | 0.45% | 1 | 0 | 2026-06-26T21:32:44 | ### Impact **CVSSv4 Baseline Score:** Moderate 6.3 **CVSSv4 Weighted Score:** | |
| CVE-2026-45051 | None | 0.51% | 1 | 0 | 2026-06-24T17:25:29 | ## Summary **Description** A deserialization of untrusted data vulnerability ( | |
| CVE-2026-8024 | 9.8 | 0.55% | 2 | 0 | 2026-06-18T15:32:09 | A remote, unauthenticated attacker may exploit a deserialization of untrusted da | |
| CVE-2026-39987 | 9.8 | 98.95% | 1 | 25 | template | 2026-06-17T10:42:51.460000 | marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE |
| CVE-2025-48595 | 8.4 | 1.71% | 1 | 3 | 2026-06-02T21:30:39 | In multiple locations, there is a possible way to achieve code execution due to | |
| CVE-2026-32746 | 9.8 | 23.67% | 7 | 8 | 2026-03-23T15:31:40 | telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMO | |
| CVE-2026-27540 | 9.0 | 2.32% | 2 | 2 | 2026-03-19T06:30:33 | Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co P | |
| CVE-2023-38198 | 9.8 | 1.08% | 1 | 0 | 2024-10-30T21:30:36 | acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as e | |
| CVE-2024-20260 | 8.6 | 0.62% | 1 | 0 | 2024-10-23T18:33:16 | A vulnerability in the VPN and management web servers of the Cisco Adaptive Secu | |
| CVE-2026-54520 | 0 | 0.00% | 2 | 1 | N/A | ||
| CVE-2026-54670 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-54767 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-54671 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-93426 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-54752 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-54716 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-54692 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-92943 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-93337 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-85500 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-59347 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-59346 | 0 | 0.00% | 2 | 1 | N/A | ||
| CVE-2026-78428 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-90711 | 0 | 0.19% | 1 | 0 | N/A | ||
| CVE-2026-61642 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-85498 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-57586 | 0 | 0.15% | 1 | 0 | N/A |
updated 2026-09-18T04:17:47.180000
1 posts
CVE-2026-20341: CRITICAL flaw in Cisco Secure FMC Software sftunnel protocol. Admin remote attackers can gain root via insecure deserialization. Limit admin access, monitor for abuse, and check for patch updates. https://radar.offseq.com/threat/a-vulnerability-in-the-sftunnel-inter-device-communication-protocol-of-cisco-secure-fmc-software-could-c3ce1a1e4096035e #OffSeq #Cisco #Infosec #Vulnerability
##updated 2026-09-18T02:17:09.113000
2 posts
🟠 CVE-2026-93456 - High (8.2)
django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify page content. Signed-in editors visiting a malicious page can be tricked into storing u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93456/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93456 - High (8.2)
django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify page content. Signed-in editors visiting a malicious page can be tricked into storing u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93456/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T00:31:16
2 posts
CVE-2026-85889 | CRITICAL flaw in Azure AI Foundry: missing authentication for a critical function (CVSS 10) allows remote privilege escalation. Microsoft patched this cloud vulnerability — verify your environment per MSRC: https://radar.offseq.com/threat/cve-2026-85889-cwe-306-missing-authentication-for-critical-function-in-microsoft-azure-ai-foundry-e4d903ee0861658f #OffSeq #Azure #Infosec #CVE202685889
##CVE-2026-85889 | CRITICAL flaw in Azure AI Foundry: missing authentication for a critical function (CVSS 10) allows remote privilege escalation. Microsoft patched this cloud vulnerability — verify your environment per MSRC: https://radar.offseq.com/threat/cve-2026-85889-cwe-306-missing-authentication-for-critical-function-in-microsoft-azure-ai-foundry-e4d903ee0861658f #OffSeq #Azure #Infosec #CVE202685889
##updated 2026-09-18T00:31:15
8 posts
🟠 New security advisory:
CVE-2026-87886 affects multiple systems.
• Impact: Significant security breach potential
• Risk: Unauthorized access or data exposure
• Mitigation: Apply patches within 24-48 hours
Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-87886-acronis-cpanel-plugin-root-escalation-exploited
by Yazoul AI
##📰 CISA Adds Actively Exploited Cisco and Acronis Flaws to KEV Catalog
CISA adds two actively exploited vulnerabilities to its KEV catalog: a critical Cisco ISE auth bypass (CVE-2026-76460) and an Acronis Backup flaw (CVE-2026-87886). Federal agencies must patch urgently. #CISA #KEV #PatchNow
##(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-87886 – Acronis Backup Incorrect Default Permissions Vulnerability
A strategic executive briefing detailing permission hardening, risk deliberation, and incident response frameworks for CVE-2026-87886 in Acronis Backup environments....
##Acronis Patches Actively Exploited Privilege Escalation Flaw in Hosting Plugins
Acronis patched a high-severity privilege escalation vulnerability (CVE-2026-87886) in its cPanel and Plesk backup plugins that attackers are actively exploiting in the wild. The flaw allows local users to gain root access by taking advantage of insecure file permissions.
**Check your Linux hosting servers for the Acronis backup plugin and update it to the latest version right now. Attackers are already using this flaw to gain root access, so do not wait for your next scheduled maintenance window.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/acronis-patches-actively-exploited-privilege-escalation-flaw-in-hosting-plugins-a-s-1-m-a/gD2P6Ple2L
(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-87886 – Acronis Backup Incorrect Default Permissions Vulnerability
A strategic executive briefing detailing permission hardening, risk deliberation, and incident response frameworks for CVE-2026-87886 in Acronis Backup environments....
##Acronis Patches Actively Exploited Privilege Escalation Flaw in Hosting Plugins
Acronis patched a high-severity privilege escalation vulnerability (CVE-2026-87886) in its cPanel and Plesk backup plugins that attackers are actively exploiting in the wild. The flaw allows local users to gain root access by taking advantage of insecure file permissions.
**Check your Linux hosting servers for the Acronis backup plugin and update it to the latest version right now. Attackers are already using this flaw to gain root access, so do not wait for your next scheduled maintenance window.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/acronis-patches-actively-exploited-privilege-escalation-flaw-in-hosting-plugins-a-s-1-m-a/gD2P6Ple2L
CVE ID: CVE-2026-87886
Vendor: Acronis
Product: Backup
Date Added: 2026-09-16
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87886
Acronis confirmed active exploitation of CVE-2026-87886, a CVSS 7.8 local privilege escalation in its backup plugin for cPanel and WHM and Plesk. Any local user on shared hosting could escalate to root and compromise all tenants, making immediate patching and audit critical. #LinuxSecurity #PrivilegeEscalation #CpanelSecurity
https://cyberworldops.eu/en/acronis-warns-of-exploited-privilege-escalation-flaw-in-cpanel-backup
##updated 2026-09-18T00:17:49.540000
2 posts
🟠 CVE-2026-93452 - High (7.5)
snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination buffer's rem...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93452/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93452 - High (7.5)
snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination buffer's rem...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93452/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T00:17:49.230000
2 posts
🟠 CVE-2026-93450 - High (7.5)
go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attackers can submit deeply nested JSON documents to s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93450/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93450 - High (7.5)
go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attackers can submit deeply nested JSON documents to s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93450/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-17T22:17:03.317000
2 posts
🔴 CVE-2026-54734 - Critical (10)
Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the resulting domain or path segment. A malicious ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54734/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-54734 - Critical (10)
Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the resulting domain or path segment. A malicious ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54734/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-17T21:32:42
1 posts
Learn about recent Apache NiFi vulnerabilities (CVE-2026-87976, CVE-2026-70469) and Apache MyFaces flaws. Apply Apache security updates to prevent DoS attacks.
#ApacheNiFi #ApacheMyFaces #Vulnerability #CVE202687976 #Cybersecurity
##updated 2026-09-17T21:32:41
1 posts
New.
Cisco has advisories to address 13 critical vulnerabilities, among other lower-ranking flaws https://sec.cloudapps.cisco.com/security/center/publicationListing.x
This one is new, but there are others:
CRITICAL: CVE-2026-20176, CVE-2026-20211, and CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerabilities https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-se7bYU57
Broadcom:
Broadcom has a long list of advisories addressing at least two critical vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Tenable:
Tenable Research Advisories: CVE-2026-84858: ScadaLTS Multiple Vulnerabilities https://www.tenable.com/security/research/tra-2026-60
And if you missed this, Microsoft posted two advisories for Edge yesterday: https://msrc.microsoft.com/update-guide #Microsoft #infosec #Cisco #vulnerability
##updated 2026-09-17T20:28:17
2 posts
CVE-2026-79752: CakePHP <4.5.12, 4.6.0-4.6.4, 5.0.0-5.1.8, 5.2.0-5.2.13, 5.3.0-5.3.6 FunctionsBuilder SQL injection risk! CRITICAL severity — patch ASAP or avoid user input in $dataType, $part, $unit. https://radar.offseq.com/threat/database-cakephp-multiple-methods-in-functionsbuilder-vulnerable-to-sql-injection-cve-2026-79752-16b04fe3ca4b5527 #OffSeq #CakePHP #SQLi #Infosec
##CVE-2026-79752: CakePHP <4.5.12, 4.6.0-4.6.4, 5.0.0-5.1.8, 5.2.0-5.2.13, 5.3.0-5.3.6 FunctionsBuilder SQL injection risk! CRITICAL severity — patch ASAP or avoid user input in $dataType, $part, $unit. https://radar.offseq.com/threat/database-cakephp-multiple-methods-in-functionsbuilder-vulnerable-to-sql-injection-cve-2026-79752-16b04fe3ca4b5527 #OffSeq #CakePHP #SQLi #Infosec
##updated 2026-09-17T20:18:59.730000
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T20:18:59.093000
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T20:18:54.893000
1 posts
🟠 CVE-2026-91989 - High (7.5)
atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths. Attackers can bypass path conta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91989/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-17T20:16:52.117000
2 posts
🔴 CVE-2026-54627 - Critical (9.8)
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_private_sail_pixel_format() in src/sail-codecs/psd/helpers.c resolves a one-channel PSD in Bitmap col...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54627/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-54627 - Critical (9.8)
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_private_sail_pixel_format() in src/sail-codecs/psd/helpers.c resolves a one-channel PSD in Bitmap col...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54627/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-17T18:34:49
1 posts
🟠 CVE-2026-87286 - High (8.1)
Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via H...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87286/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-17T18:16:36.517000
1 posts
3 repos
https://github.com/abraxas/CVE-2026-12793
CVE-2026-12793: CRITICAL privilege escalation in JetFormBuilder Dynamic Blocks Form Builder (<=3.6.2). Unauthenticated attackers can create admin accounts. Restrict access & monitor until patch. https://radar.offseq.com/threat/cve-2026-12793-cwe-269-improper-privilege-management-in-jetmonsters-jetformbuilder-dynamic-blocks-form-fa1c70f5eeec8d4c #OffSeq #WordPress #CVE202612793 #Infosec
##updated 2026-09-17T17:16:51.633000
2 posts
A critical pgAdmin 4 authentication bypass (CVE-2026-86863) allows remote admin takeover. Patch this pgAdmin 4 authentication bypass vulnerability now.
#pgAdmin #PostgreSQL #CVE202686863 #AuthenticationBypass #Cybersecurity
##A critical pgAdmin 4 authentication bypass (CVE-2026-86863) allows remote admin takeover. Patch this pgAdmin 4 authentication bypass vulnerability now.
#pgAdmin #PostgreSQL #CVE202686863 #AuthenticationBypass #Cybersecurity
##updated 2026-09-17T16:18:34.520000
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T16:18:18.163000
1 posts
🟠 CVE-2026-86865 - High (8.8)
Tanium addressed a SQL injection vulnerability in Asset.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86865/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-17T16:18:17.403000
2 posts
🟠 CVE-2026-86320 - High (7.8)
A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch hook can cause the hook to execute on the host ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86320/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86320 - High (7.8)
A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch hook can cause the hook to execute on the host ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86320/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-17T15:32:28
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T15:32:28
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T15:32:28
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T15:32:27
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T15:32:27
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T15:32:26
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T15:32:26
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T15:32:26
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T15:32:24
2 posts
🟠 CVE-2026-92918 - High (8.8)
admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /logs endpoint to harvest session tokens and repla...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92918/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-92918 - High (8.8)
admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /logs endpoint to harvest session tokens and repla...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92918/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-17T15:32:23
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T15:32:23
2 posts
🟠 CVE-2026-92919 - High (8.1)
admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. Attackers can use dot-dot path segments in filenames to escape the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92919/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-92919 - High (8.1)
admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. Attackers can use dot-dot path segments in filenames to escape the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92919/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-17T15:32:22
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T15:32:22
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T15:32:21
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T15:32:18
2 posts
🟠 CVE-2026-81481 - High (7.5)
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81481/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81481 - High (7.5)
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81481/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-17T15:32:17
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T15:17:00.910000
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T15:17:00.520000
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T14:18:00.420000
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T14:17:56.873000
2 posts
CVE-2026-92838: HIGH severity DLL hijack in GeoVision GV-Remote E-map 18.3.1 🖥️. Local attackers can execute arbitrary code via unsafe DLL load paths. Restrict directory write access; check vendor guidance. https://radar.offseq.com/threat/cve-2026-92838-cwe-427-uncontrolled-search-path-element-in-geovision-inc-gv-remote-e-map-0688637b5de2fbea #OffSeq #Vuln #InfoSec #Windows
##CVE-2026-92838: HIGH severity DLL hijack in GeoVision GV-Remote E-map 18.3.1 🖥️. Local attackers can execute arbitrary code via unsafe DLL load paths. Restrict directory write access; check vendor guidance. https://radar.offseq.com/threat/cve-2026-92838-cwe-427-uncontrolled-search-path-element-in-geovision-inc-gv-remote-e-map-0688637b5de2fbea #OffSeq #Vuln #InfoSec #Windows
##updated 2026-09-17T13:16:42.530000
2 posts
CVE-2026-15688 | Mitsubishi Electric GX Works3 (CVSS 9.2, CRITICAL): Local attackers can bypass authentication by modifying memory, risking control program compromise. No fix yet — restrict local access. #OffSeq #ICS #CVE202615688 https://radar.offseq.com/threat/cve-2026-15688-cwe-303-incorrect-implementation-of-authentication-algorithm-in-mitsubishi-electric-b35e18a6ba962469
##CVE-2026-15688 | Mitsubishi Electric GX Works3 (CVSS 9.2, CRITICAL): Local attackers can bypass authentication by modifying memory, risking control program compromise. No fix yet — restrict local access. #OffSeq #ICS #CVE202615688 https://radar.offseq.com/threat/cve-2026-15688-cwe-303-incorrect-implementation-of-authentication-algorithm-in-mitsubishi-electric-b35e18a6ba962469
##updated 2026-09-17T12:46:31.670000
30 posts
1 repos
Critical cybersecurity alerts issued as Check Point (CVE-2026-91843) and Cisco (CVE-2026-76460) disclose severe vulnerabilities, with Cisco's already exploited. Geopolitically, USCG/FBI investigate suspected foreign cyberattacks on two oil tankers; Iran reportedly targeted another in the Strait of Hormuz. Tech advances with OpenAI's 'Astra for Law' for legal AI workflows.
##⚠️ CRITICAL: Cisco alerts customers to second actively exploited zero-day in as many days
Cisco ISE zero-day CVE-2026-76460 is actively exploited in the wild. Remote attackers can bypass authentication, take full device control, modify network policies, and steal credentials. If you run ISE, this is a direct threat to your network perimeter and access controls.
🤖 AI generated summary
##Cisco ISE Faces a Critical Zero-Day Threat as CISA Adds CVE-2026-76460 to the KEV Catalog + Video
A Critical Warning for Cisco ISE Administrators A new Cisco security vulnerability has moved rapidly from a newly disclosed flaw to an active-exploitation concern. On September 16, 2026, Cisco disclosed CVE-2026-76460, a critical authentication-bypass vulnerability affecting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). Cisco…
##🔵 THREAT INTELLIGENCE
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
Vulnerability | CRITICAL
CVEs: CVE-2026-76460
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in...
Full analysis:
https://www.yazoul.net/news/article/cisco-warns-of-new-zero-day-ise-auth-bypass-cvss-10-0-exploited-in-active-attack
by Yazoul AI
##📰 CISA Adds Actively Exploited Cisco and Acronis Flaws to KEV Catalog
CISA adds two actively exploited vulnerabilities to its KEV catalog: a critical Cisco ISE auth bypass (CVE-2026-76460) and an Acronis Backup flaw (CVE-2026-87886). Federal agencies must patch urgently. #CISA #KEV #PatchNow
##📰 Cisco ISE Zero-Day (CVSS 10.0) Under Active Attack, Bypasses Auth
Cisco warns of a critical (CVSS 10.0) zero-day in Identity Services Engine (ISE) actively exploited in the wild. The flaw, CVE-2026-76460, allows full authentication bypass. CISA added to KEV catalog. Patch immediately! #Cisco #ZeroDay #CyberSecurity
##Cisco Discloses Zero-Day ISE Auth Bypass Under Active Exploitation
Cisco has uncovered a critical zero-day vulnerability, CVE-2026-76460, that lets hackers bypass authentication on its Identity Services Engine and Passive Identity Connector, and it's already being exploited by attackers. This flaw allows unauthorized access to affected devices with just a crafted request.
##Cisco Patches 21 Flaws in ISE Identity Infrastructure Including Actively Exploited Zero-Days
Cisco released a set of security updates for Identity Services Engine (ISE) addressing 21 vulnerabilities, including two critical authentication bypasses (CVE-2026-20192 and CVE-2026-76460) currently exploited by attackers to gain root access.
**Treat this as a top-priority emergency attackers are already using some of these flaws to take over identity servers. If you run Cisco ISE or ISE-PIC, first make sure the management interface is never reachable from the internet. Then patch ASAP to 3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7 or 3.5 P4. Check your access logs for strange accounts like "dummyuser". Assume a breach if you find anything weird.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/cisco-patches-21-flaws-in-ise-identity-infrastructure-including-actively-exploited-zero-days-e-2-9-l-x/gD2P6Ple2L
🔴 New security advisory:
CVE-2026-76460 affects multiple systems.
• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems
Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-76460-cisco-ise-auth-bypass-exploited-in-wild
by Yazoul AI
##Cisco ISE Under Attack: Critical CVE-2026-76460 Gives Attackers a Path to Root Access + Video
A Maximum-Severity Warning for Network Defenders Cisco has issued an urgent warning over active exploitation of a maximum-severity vulnerability in Cisco Identity Services Engine (ISE), a platform used by organizations to control and enforce access to corporate networks. The vulnerability, tracked as CVE-2026-76460, carries the highest possible CVSS score of 10.0 and has now…
##Cisco Discloses Active Exploitation of ISE Flaw
Cisco warns that a critical API vulnerability, CVE-2026-76460, is under active exploitation, allowing attackers to bypass security and gain unauthorized access to devices with a simple crafted request. This maximum-severity flaw scores a perfect 10.0 on the CVSS scale, making it a high-risk threat that demands immediate attention.
#Cve202676460 #ApiVulnerability #ActiveExploitation #Cisco #IseFlaw
##(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-76460 – Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
A strategic executive briefing detailing privileged API mitigation, network segmentation, and zero-trust verification frameworks for CVE-2026-76460 in Cisco ISE....
##CVE-2026-76460: CRITICAL auth bypass in Cisco ISE & ISE-PIC is actively exploited. Remote attackers can gain admin access via crafted API requests. Patch ISE 3.1 – 3.5 now — no workarounds. More: https://radar.offseq.com/threat/cisco-warns-of-max-severity-ise-zero-day-exploited-in-attacks-7c00b7de95d29289 #OffSeq #Cisco #ZeroDay #Vuln #Cybersecurity
##https://thecybersecguru.com/news/cisco-ise-cve-2026-76460-authentication-bypass/
##Cisco ISE Zero-Day Under Active Attack: Critical Authentication Bypass Puts Network Identity Systems at Risk
A Dangerous New Attack on the Network’s Identity Gatekeeper Cisco has released emergency security updates for a maximum-severity vulnerability in Cisco Identity Services Engine (ISE) after confirming that attackers are already exploiting the flaw in real-world attacks. Tracked as CVE-2026-76460, the vulnerability carries a CVSS score of 10.0 and allows an…
##「Ciscoは、ISEのゼロデイ脆弱性が攻撃に悪用され、深刻な被害を受ける可能性があると警告している。 」: #BLEEPINGCOMPUTER
「シスコは、攻撃者が実際に悪用している、深刻度が最大レベルのアイデンティティサービスエンジンの脆弱性に対処するためのセキュリティアップデートをリリースしました。
Cisco ISEは、IT管理者がエンドポイント、ユーザー、およびデバイスのネットワークリソースへのアクセスを管理するために使用する集中型ポリシープラットフォームであり、多くの場合、ゼロトラストセキュリティモデルを適用しながら使用されます。
このセキュリティ上の欠陥( CVE-2026-76460 として追跡)により、リモートの攻撃者は、Cisco Identity Services Engine(ISE)およびCisco ISE Passive Identity Connector(ISE-PIC)のAPIの脆弱性を悪用することで、設定に関係なく認証を回避できます。 」
##CRITICAL auth bypass (CVE-2026-76460) in Cisco ISE & ISE-PIC is being actively exploited. Remote attackers gain root on management interface via crafted API calls. Patch ASAP — no workarounds except ACLs. Details: https://radar.offseq.com/threat/active-exploitation-triggers-emergency-patch-for-cisco-ise-zero-day-d5bd452a61e0a8f8 #OffSeq #Cisco #ZeroDay
##Cisco’s Critical ISE Zero-Day Is Being Exploited: CVE-2026-76460 Gives Remote Attackers a Path to Root Access + Video
A New Cisco Emergency for Security Teams A serious new vulnerability in Cisco Identity Services Engine has moved rapidly from disclosure to active exploitation, creating an immediate security concern for organizations that rely on ISE to control identity, authentication, and network access. Cisco has assigned the flaw CVE-2026-76460, giving it the…
##Cisco confirmed active exploitation of CVE-2026-76460, an authentication bypass in an ISE API endpoint. Unauthenticated remote access can lead to root compromise of ISE and ISE-PIC, now listed in CISA KEV. Patching and log review are urgent. #CiscoIse #AuthBypass #CisaKev
https://cyberworldops.eu/en/cisco-ise-api-authentication-flaw-opens-a-remote-path-to-root-access
##Critical cybersecurity alerts issued as Check Point (CVE-2026-91843) and Cisco (CVE-2026-76460) disclose severe vulnerabilities, with Cisco's already exploited. Geopolitically, USCG/FBI investigate suspected foreign cyberattacks on two oil tankers; Iran reportedly targeted another in the Strait of Hormuz. Tech advances with OpenAI's 'Astra for Law' for legal AI workflows.
##⚠️ CRITICAL: Cisco alerts customers to second actively exploited zero-day in as many days
Cisco ISE zero-day CVE-2026-76460 is actively exploited in the wild. Remote attackers can bypass authentication, take full device control, modify network policies, and steal credentials. If you run ISE, this is a direct threat to your network perimeter and access controls.
🤖 AI generated summary
##Cisco Patches 21 Flaws in ISE Identity Infrastructure Including Actively Exploited Zero-Days
Cisco released a set of security updates for Identity Services Engine (ISE) addressing 21 vulnerabilities, including two critical authentication bypasses (CVE-2026-20192 and CVE-2026-76460) currently exploited by attackers to gain root access.
**Treat this as a top-priority emergency attackers are already using some of these flaws to take over identity servers. If you run Cisco ISE or ISE-PIC, first make sure the management interface is never reachable from the internet. Then patch ASAP to 3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7 or 3.5 P4. Check your access logs for strange accounts like "dummyuser". Assume a breach if you find anything weird.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/cisco-patches-21-flaws-in-ise-identity-infrastructure-including-actively-exploited-zero-days-e-2-9-l-x/gD2P6Ple2L
(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-76460 – Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
A strategic executive briefing detailing privileged API mitigation, network segmentation, and zero-trust verification frameworks for CVE-2026-76460 in Cisco ISE....
##CVE-2026-76460: CRITICAL auth bypass in Cisco ISE & ISE-PIC is actively exploited. Remote attackers can gain admin access via crafted API requests. Patch ISE 3.1 – 3.5 now — no workarounds. More: https://radar.offseq.com/threat/cisco-warns-of-max-severity-ise-zero-day-exploited-in-attacks-7c00b7de95d29289 #OffSeq #Cisco #ZeroDay #Vuln #Cybersecurity
##https://thecybersecguru.com/news/cisco-ise-cve-2026-76460-authentication-bypass/
##「Ciscoは、ISEのゼロデイ脆弱性が攻撃に悪用され、深刻な被害を受ける可能性があると警告している。 」: #BLEEPINGCOMPUTER
「シスコは、攻撃者が実際に悪用している、深刻度が最大レベルのアイデンティティサービスエンジンの脆弱性に対処するためのセキュリティアップデートをリリースしました。
Cisco ISEは、IT管理者がエンドポイント、ユーザー、およびデバイスのネットワークリソースへのアクセスを管理するために使用する集中型ポリシープラットフォームであり、多くの場合、ゼロトラストセキュリティモデルを適用しながら使用されます。
このセキュリティ上の欠陥( CVE-2026-76460 として追跡)により、リモートの攻撃者は、Cisco Identity Services Engine(ISE)およびCisco ISE Passive Identity Connector(ISE-PIC)のAPIの脆弱性を悪用することで、設定に関係なく認証を回避できます。 」
##CRITICAL auth bypass (CVE-2026-76460) in Cisco ISE & ISE-PIC is being actively exploited. Remote attackers gain root on management interface via crafted API calls. Patch ASAP — no workarounds except ACLs. Details: https://radar.offseq.com/threat/active-exploitation-triggers-emergency-patch-for-cisco-ise-zero-day-d5bd452a61e0a8f8 #OffSeq #Cisco #ZeroDay
##Cisco confirmed active exploitation of CVE-2026-76460, an authentication bypass in an ISE API endpoint. Unauthenticated remote access can lead to root compromise of ISE and ISE-PIC, now listed in CISA KEV. Patching and log review are urgent. #CiscoIse #AuthBypass #CisaKev
https://cyberworldops.eu/en/cisco-ise-api-authentication-flaw-opens-a-remote-path-to-root-access
##Patch your Cisco ISE. CVE-2026-76460 a perfect 10 and is EITW. 🥳
##The Cisco PSIRT is aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.
An exploited Cisco ISE vulnerability (CVE-2026-76460) allows remote root access. Patch this critical Cisco ISE vulnerability to secure networks.
##updated 2026-09-17T12:18:30.290000
2 posts
CVE-2026-92913 | WWBN AVideo (CRITICAL, CVSS 9.1): Weak random pairing codes + exposed microtime API = unauthenticated account takeover risk. No patch yet — restrict API access if possible. https://radar.offseq.com/threat/cve-2026-92913-use-of-insufficiently-random-values-in-wwbn-avideo-bdf60cd1a8224a92 #OffSeq #AVideo #CVE202692913 #AccountSecurity
##CVE-2026-92913 | WWBN AVideo (CRITICAL, CVSS 9.1): Weak random pairing codes + exposed microtime API = unauthenticated account takeover risk. No patch yet — restrict API access if possible. https://radar.offseq.com/threat/cve-2026-92913-use-of-insufficiently-random-values-in-wwbn-avideo-bdf60cd1a8224a92 #OffSeq #AVideo #CVE202692913 #AccountSecurity
##updated 2026-09-17T12:18:29.687000
6 posts
1 repos
Critical cybersecurity alerts issued as Check Point (CVE-2026-91843) and Cisco (CVE-2026-76460) disclose severe vulnerabilities, with Cisco's already exploited. Geopolitically, USCG/FBI investigate suspected foreign cyberattacks on two oil tankers; Iran reportedly targeted another in the Strait of Hormuz. Tech advances with OpenAI's 'Astra for Law' for legal AI workflows.
##Critical Check Point Security Flaw Exposes Management Servers to Root-Level Remote Code Execution + Video
A Dangerous Vulnerability in the Security Control Plane A newly disclosed vulnerability in Check Point management infrastructure has created an urgent patching situation for organizations relying on the company’s security platforms. Tracked as CVE-2026-91843, the flaw is rated CVSS 9.8, Critical, and could allow an unauthenticated remote attacker to execute…
##Critical cybersecurity alerts issued as Check Point (CVE-2026-91843) and Cisco (CVE-2026-76460) disclose severe vulnerabilities, with Cisco's already exploited. Geopolitically, USCG/FBI investigate suspected foreign cyberattacks on two oil tankers; Iran reportedly targeted another in the Strait of Hormuz. Tech advances with OpenAI's 'Astra for Law' for legal AI workflows.
##🚨New Censys Advisory: CVE-2026-91843
A critical (CVSS 9.8) unauthenticated RCE affects Check Point Quantum Security Management and Log Servers.
Censys observes 3,836 hosts globally exposing the management/log server role. This is total product presence, not a confirmed-vulnerable count.
No public PoC or confirmed exploitation has been reported as of publication. Check Point has released patches for supported versions via LivePatch.
Read the analysis and remediation details: https://censys.com/advisory/cve-2026-91843/
##🚨 Please read this important update from Check Point:
CVE-2026-91843 - Stack overflow in login process to the Security Management and Log Servers
https://support.checkpoint.com/results/sk/sk1000155
#CheckPoint #CheckPointsoftwareTechnologies #CVE #CVE202691843
##Check Point fixed a critical Check Point login flaw (CVE-2026-91843). Patch this Check Point login flaw now to block unauthenticated remote root takeovers.
#CheckPoint #Cybersecurity #CVE202691843 #InfoSec #Vulnerability
##updated 2026-09-17T12:17:25.977000
1 posts
New.
Cisco has advisories to address 13 critical vulnerabilities, among other lower-ranking flaws https://sec.cloudapps.cisco.com/security/center/publicationListing.x
This one is new, but there are others:
CRITICAL: CVE-2026-20176, CVE-2026-20211, and CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerabilities https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-se7bYU57
Broadcom:
Broadcom has a long list of advisories addressing at least two critical vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Tenable:
Tenable Research Advisories: CVE-2026-84858: ScadaLTS Multiple Vulnerabilities https://www.tenable.com/security/research/tra-2026-60
And if you missed this, Microsoft posted two advisories for Edge yesterday: https://msrc.microsoft.com/update-guide #Microsoft #infosec #Cisco #vulnerability
##updated 2026-09-17T06:30:45
2 posts
1 repos
CVE-2026-87796 (CRITICAL, CVSS 9.8): sh1zen Multi Uploader for Gravity Forms ≤1.1.9 lets unauthenticated attackers upload arbitrary files, risking remote code execution. No patch yet — disable the plugin or restrict uploads. https://radar.offseq.com/threat/cve-2026-87796-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-sh1zen-multi-uploader-for-cfd4181d51e0b5e2 #OffSeq #WordPress #CVE #RCE
##CVE-2026-87796 (CRITICAL, CVSS 9.8): sh1zen Multi Uploader for Gravity Forms ≤1.1.9 lets unauthenticated attackers upload arbitrary files, risking remote code execution. No patch yet — disable the plugin or restrict uploads. https://radar.offseq.com/threat/cve-2026-87796-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-sh1zen-multi-uploader-for-cfd4181d51e0b5e2 #OffSeq #WordPress #CVE #RCE
##updated 2026-09-17T04:17:59.823000
1 posts
CVE-2026-73453: CRITICAL code injection in Arista EOS (4.29.2F – 4.36.1F) via P4Runtime. Allows unauthenticated code execution & admin control if enabled. Disable P4Runtime if not needed. No active exploits yet. https://radar.offseq.com/threat/cve-2026-73453-cwe-94-improper-control-of-generation-of-code-code-injection-in-arista-networks-eos-86cb5135e8adffc5 #OffSeq #CVE202673453 #NetworkSecurity
##updated 2026-09-17T04:17:55.620000
1 posts
🟠 CVE-2026-69486 - High (8.8)
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69486/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-17T00:31:30
1 posts
CVE-2026-92578: CRITICAL auth bypass in WWBN AVideo (≤29.0) allows attackers with stolen password hashes to log in as any user — no password needed. Patch pending — restrict hash access, monitor for abuse. https://radar.offseq.com/threat/cve-2026-92578-improper-authentication-in-wwbn-avideo-d660bbe72d13e3dc #OffSeq #CVE202692578 #authentication #infosec
##updated 2026-09-17T00:31:25
1 posts
CRITICAL SSRF vuln (CVE-2026-92576) in HKUDS nanobot <0.3.0: Inadequate URL validation lets attackers access internal cloud metadata & services. Restrict WebFetchTool, monitor for suspicious requests. Patch status: unconfirmed. https://radar.offseq.com/threat/cve-2026-92576-server-side-request-forgery-ssrf-in-hkuds-nanobot-4673f42d188d2ce5 #OffSeq #infosec #CVE202692576
##updated 2026-09-16T21:32:55
2 posts
Cisco Patches 18 Critical and High-Severity Firewall Vulnerabilities, One Actively Exploited
Cisco released a massive security hardening update fixing 18 vulnerabilities in its Secure Firewall suite, including an actively exploited authentication bypass (CVE-2026-20332) and multiple critical remote code execution flaws.
**If you use Cisco Secure Firewall (ASA, FTD, or FMC), this is urgent. Patch now to the fixed versions Cisco lists. At least one flaw is already being exploited by attackers. Make sure the management interfaces are reachable only from your trusted internal network and never from the internet.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/cisco-patches-18-critical-and-high-severity-firewall-vulnerabilities-one-actively-exploited-3-v-t-c-t/gD2P6Ple2L
Cisco Patches 18 Critical and High-Severity Firewall Vulnerabilities, One Actively Exploited
Cisco released a massive security hardening update fixing 18 vulnerabilities in its Secure Firewall suite, including an actively exploited authentication bypass (CVE-2026-20332) and multiple critical remote code execution flaws.
**If you use Cisco Secure Firewall (ASA, FTD, or FMC), this is urgent. Patch now to the fixed versions Cisco lists. At least one flaw is already being exploited by attackers. Make sure the management interfaces are reachable only from your trusted internal network and never from the internet.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/cisco-patches-18-critical-and-high-severity-firewall-vulnerabilities-one-actively-exploited-3-v-t-c-t/gD2P6Ple2L
updated 2026-09-16T21:32:55
2 posts
HP released updates to fix critical HP Advance vulnerabilities (CVE-2026-89082). Patch these HP Advance vulnerabilities to stop remote code execution.
##HP released updates to fix critical HP Advance vulnerabilities (CVE-2026-89082). Patch these HP Advance vulnerabilities to stop remote code execution.
##updated 2026-09-16T21:32:50
1 posts
Cisco Secure Firewall Management Center Hit by Critical CVE-2026-20324 Root RCE Vulnerability + Video
A Critical Warning for Cisco Firewall Administrators A critical vulnerability in Cisco Secure Firewall Management Center (FMC) has raised concerns for organizations relying on Cisco infrastructure to manage and protect their networks. Tracked as CVE-2026-20324, the flaw carries a CVSS score of 9.9 and can allow an authenticated remote attacker to execute arbitrary…
##updated 2026-09-16T21:32:50
2 posts
Cisco Patches 21 Flaws in ISE Identity Infrastructure Including Actively Exploited Zero-Days
Cisco released a set of security updates for Identity Services Engine (ISE) addressing 21 vulnerabilities, including two critical authentication bypasses (CVE-2026-20192 and CVE-2026-76460) currently exploited by attackers to gain root access.
**Treat this as a top-priority emergency attackers are already using some of these flaws to take over identity servers. If you run Cisco ISE or ISE-PIC, first make sure the management interface is never reachable from the internet. Then patch ASAP to 3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7 or 3.5 P4. Check your access logs for strange accounts like "dummyuser". Assume a breach if you find anything weird.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/cisco-patches-21-flaws-in-ise-identity-infrastructure-including-actively-exploited-zero-days-e-2-9-l-x/gD2P6Ple2L
Cisco Patches 21 Flaws in ISE Identity Infrastructure Including Actively Exploited Zero-Days
Cisco released a set of security updates for Identity Services Engine (ISE) addressing 21 vulnerabilities, including two critical authentication bypasses (CVE-2026-20192 and CVE-2026-76460) currently exploited by attackers to gain root access.
**Treat this as a top-priority emergency attackers are already using some of these flaws to take over identity servers. If you run Cisco ISE or ISE-PIC, first make sure the management interface is never reachable from the internet. Then patch ASAP to 3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7 or 3.5 P4. Check your access logs for strange accounts like "dummyuser". Assume a breach if you find anything weird.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/cisco-patches-21-flaws-in-ise-identity-infrastructure-including-actively-exploited-zero-days-e-2-9-l-x/gD2P6Ple2L
updated 2026-09-16T21:32:50
1 posts
New.
Cisco has advisories to address 13 critical vulnerabilities, among other lower-ranking flaws https://sec.cloudapps.cisco.com/security/center/publicationListing.x
This one is new, but there are others:
CRITICAL: CVE-2026-20176, CVE-2026-20211, and CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerabilities https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-se7bYU57
Broadcom:
Broadcom has a long list of advisories addressing at least two critical vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Tenable:
Tenable Research Advisories: CVE-2026-84858: ScadaLTS Multiple Vulnerabilities https://www.tenable.com/security/research/tra-2026-60
And if you missed this, Microsoft posted two advisories for Edge yesterday: https://msrc.microsoft.com/update-guide #Microsoft #infosec #Cisco #vulnerability
##updated 2026-09-16T21:32:50
1 posts
New.
Cisco has advisories to address 13 critical vulnerabilities, among other lower-ranking flaws https://sec.cloudapps.cisco.com/security/center/publicationListing.x
This one is new, but there are others:
CRITICAL: CVE-2026-20176, CVE-2026-20211, and CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerabilities https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-se7bYU57
Broadcom:
Broadcom has a long list of advisories addressing at least two critical vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Tenable:
Tenable Research Advisories: CVE-2026-84858: ScadaLTS Multiple Vulnerabilities https://www.tenable.com/security/research/tra-2026-60
And if you missed this, Microsoft posted two advisories for Edge yesterday: https://msrc.microsoft.com/update-guide #Microsoft #infosec #Cisco #vulnerability
##updated 2026-09-16T21:32:48
1 posts
Learn about recent Apache NiFi vulnerabilities (CVE-2026-87976, CVE-2026-70469) and Apache MyFaces flaws. Apply Apache security updates to prevent DoS attacks.
#ApacheNiFi #ApacheMyFaces #Vulnerability #CVE202687976 #Cybersecurity
##updated 2026-09-16T21:32:47
1 posts
🟠 CVE-2026-87024 - High (7.5)
Tanium addressed a SQL injection vulnerability in Asset.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87024/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-16T20:39:16.610000
1 posts
🟠 CVE-2026-88975 - High (7.5)
Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, Ember’s HTTP/2 read loop parses a frame’s 24-bit declared length but waits to buffer the entire payload before comparing it with SETTINGS_MAX_FRAME_SIZE. An unauthe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88975/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-16T20:38:33.883000
2 posts
1 repos
Docker Flaw Lets Guest Code Read, Modify macOS Host Files
A newly discovered Docker flaw on macOS could allow malicious code in a virtual machine to break free from its sandbox and read or modify sensitive host files, potentially leading to code execution on the host. This vulnerability, tracked as CVE-2026-77179, leverages a weakness in the virtio-fs host server to gain unauthorized access.
#DockerFlaw #Macos #Cve202677179 #Containerization #VirtualMachine
##Docker released an update for critical Docker Sandboxes vulnerabilities (CVE-2026-77179, CVE-2026-79994). Patch these Docker Sandboxes vulnerabilities today.
#Docker #DockerSandboxes #CVE202677179 #CVE202679994 #Cybersecurity
##updated 2026-09-16T20:37:16.870000
1 posts
🔴 CVE-2026-70416 - Critical (10)
Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70416/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-16T20:37:16.870000
1 posts
🔴 CVE-2026-63696 - Critical (9.1)
Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63696/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-16T20:26:50.280000
1 posts
🟠 CVE-2026-92176 - High (7.8)
pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92176/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-16T20:26:50.280000
1 posts
🟠 CVE-2026-92177 - High (7.8)
pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92177/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-16T20:17:20.950000
1 posts
Go hack more Secret Server shit.
https://delinea.com/security-advisories
##Authentication Bypass via SAML Response Manipulation - CVE-2026-15640
Reflected Cross-Site Scripting - CVE-2026-15639
Cryptographic Padding Oracle - CVE-2026-15638
updated 2026-09-16T19:42:12.090000
1 posts
🟠 CVE-2026-87289 - High (7.5)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-static-content). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network ac...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87289/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-16T19:27:25.623000
1 posts
🟠 CVE-2026-80217 - High (8.8)
Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode on the product to execute arbitrary OS commands.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80217/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-16T19:20:52.817000
1 posts
A critical HPE EdgeConnect authorization bypass (CVE-2026-76670) enables full system compromise. Patch this HPE EdgeConnect authorization bypass now.
#HPE #EdgeConnect #AuthorizationBypass #CVE202676670 #Cybersecurity
##updated 2026-09-16T19:17:13.860000
3 posts
🔒 New CSAF advisory published
VDE-2026-028
Carlo Gavazzi Automation: YL212* and YN115* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)
The affected devices have security vulnerabilities that can be used to bypass authentication. Code…
HTML: https://certvde.com/en/advisories/VDE-2026-028
CSAF JSON: https://gavazziautomation.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-028.json
🔒 New CSAF advisory published
VDE-2026-027
Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)
The firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices is affected by security vulnerab…
HTML: https://certvde.com/en/advisories/VDE-2026-027
CSAF JSON: https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-027.json
🔒 New CSAF advisory published
VDE-2026-014
Pepperl+Fuchs: ICE2-* and ICE3-* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)
The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be execute…
HTML: https://certvde.com/en/advisories/VDE-2026-014
CSAF JSON: https://pepperl-fuchs.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-014.json
updated 2026-09-16T19:17:13.633000
3 posts
🔒 New CSAF advisory published
VDE-2026-028
Carlo Gavazzi Automation: YL212* and YN115* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)
The affected devices have security vulnerabilities that can be used to bypass authentication. Code…
HTML: https://certvde.com/en/advisories/VDE-2026-028
CSAF JSON: https://gavazziautomation.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-028.json
🔒 New CSAF advisory published
VDE-2026-027
Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)
The firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices is affected by security vulnerab…
HTML: https://certvde.com/en/advisories/VDE-2026-027
CSAF JSON: https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-027.json
🔒 New CSAF advisory published
VDE-2026-014
Pepperl+Fuchs: ICE2-* and ICE3-* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)
The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be execute…
HTML: https://certvde.com/en/advisories/VDE-2026-014
CSAF JSON: https://pepperl-fuchs.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-014.json
updated 2026-09-16T19:14:25.980000
1 posts
Vulnerabilities in a 5g router from T-Mobile, the company known for its security?! I'm shocked. Shocked! Well, not that shocked.
##updated 2026-09-16T18:32:58
1 posts
🟠 CVE-2026-87288 - High (8.1)
Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via H...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87288/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-16T18:32:09
1 posts
@cR0w was just looking at those, lol. Don't sleep on this great advertisment of a CVE though: https://db.gcve.eu/vuln/cve-2026-20331
##updated 2026-09-16T18:32:09
1 posts
🔴 CVE-2026-92397 - Critical (9.1)
A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. Such manipulation of the argument data.url leads to os comma...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92397/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-16T18:31:58
1 posts
A critical KVM guest escape (CVE-2026-89775) enables an LPE to gain root on Linux hosts. Patch this KVM guest escape vulnerability now.
##updated 2026-09-16T18:31:53
1 posts
🟠 CVE-2026-87287 - High (8.1)
Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via H...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87287/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-16T17:18:18.923000
2 posts
CVE-2026-90999: A fabricated Sentry bug report can make Seer's coding agent run attacker code https://agyn.io/blog/sentry-seer-autofix-vulnerability
##CVE-2026-90999: A fabricated Sentry bug report can make Seer's coding agent run attacker code https://agyn.io/blog/sentry-seer-autofix-vulnerability
##updated 2026-09-16T15:32:15
1 posts
🟠 CVE-2026-61595 - High (7.7)
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.tenants` isolation was enforced only on the HTTP path. The current tenant was stored in `threading.local(...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61595/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-16T15:31:13
1 posts
Advantech EKI-1242IEIMS (fw ≤1.06.01) suffers CRITICAL CVE-2026-73172: unauthenticated OS command injection via TCP 5058 enables remote root access. No patch yet — restrict device exposure & monitor traffic. Details: https://radar.offseq.com/threat/cve-2026-73172-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-273be6f3526b5b8e #OffSeq #ICS #CVE202673172 #infosec
##updated 2026-09-16T15:30:57
23 posts
Google Pixel Zero-Day Warning: CVE-2026-58704 Exploited in Targeted Attacks + Video
Google Pixel Zero-Day Warning: CVE-2026-58704 Exploited in Targeted Attacks A Silent Pixel Attack Has Triggered a New Security Warning Google Pixel users are facing a serious security warning after Google disclosed that a high-severity vulnerability in the cellular modem may have already been exploited in limited, targeted attacks. Tracked as CVE-2026-58704, the flaw involves a…
##🚨 Google confirms Pixel phones targeted in zero-click zero-day attacks
Google has patched CVE-2026-58704, a high-severity vulnerability in Pixel phones' cellular modem that the company says was already under "limited, targeted exploitation."
⠀
The flaw is caused by a logic error that can allow an attacker to bypass permission checks and escalate privileges beyond the modem's isolated environment.
⠀
Most importantly, exploitation requires no interaction from the victim.
No malicious link needs to be clicked and no file needs to be opened, making it a zero-click attack.
⠀
Google has not disclosed:
• Who carried out the attacks
• How many Pixel owners were targeted
• How the victims were selected
• What tools or spyware may have been deployed
⠀
CISA has added CVE-2026-58704 to its Known Exploited Vulnerabilities catalog and set a September 19 remediation deadline for affected federal systems.
⠀
Google says Pixel devices with the September 5, 2026 security patch level or later are protected.
Pixel owners should update their devices immediately.
##Google Pixel phones pwned in zero-click attacks
Google Pixel 휴대폰의 셀룰러 모뎀에서 권한 검증을 우회하고 권한 상승을 가능하게 하는 제로데이 취약점 CVE-2026-58704가 제한적 표적 공격에 악용된 정황이 공개됐다. 사용자 상호작용이 필요 없는 zero-click 공격이 가능하며, 이런 유형은 상용 스파이웨어 기반 표적 감시에 자주 활용된다. Google은 패치를 배포했고, CISA는 이 취약점을 KEV 카탈로그에 추가하며 미국 연방기관에 9월 19일까지 패치하도록 지시했다. AI 개발 자체와 직접 관련되지는 않지만, Android 기기를...
##Google Patches Pixel Modem Zero-Day Exploited in Targeted Attacks
Google's September 2026 update for Pixel devices fixes 110 vulnerabilities, including a high-severity modem flaw (CVE-2026-58704) that attackers are actively exploiting to escalate privileges without user interaction.
**Update your Pixel devices to the September 2026 patch level ASAP to block an active modem exploit and patch a huge set of issues.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/google-patches-pixel-modem-zero-day-exploited-in-targeted-attacks-w-p-u-q-l/gD2P6Ple2L
「Google Pixel端末がゼロクリック攻撃でハッキングされる
/CISAは連邦政府機関に対し、パッチ適用にわずか3日間しか猶予を与えていない。 」: #TheRegister
「Googleと米国政府は、Pixelスマートフォンの携帯モデムに存在するゼロデイ脆弱性を悪用した攻撃者が、権限チェックを回避し、ユーザーの操作なしに権限を昇格できると警告した。この脆弱性は、アップデートを行うことで既に修正されている。
Googleは 火曜日に、 CVE-2026-58704 として追跡されているこの重大な脆弱性 を公表し 、その際、このセキュリティホールが「限定的かつ標的を絞った悪用を受けている可能性がある」と警告した。つまり、Googleが問題を修正する前に、悪意のある人物がこのバグを発見し、悪用していたということだ。」
##「Google、限定的な標的型攻撃の兆候が見られる中、Pixelモデムの脆弱性を修正 」: #TheHackerNews
「Googleは、 明らかにした。 同社のPixel Cellular Modemに存在する深刻なセキュリティ上の欠陥が、実際に悪用されていることを
(CVSSスコア:8.0)として追跡されているこの脆弱性は CVE-2026-58704 、権限昇格の欠陥です。
によると、「セルラーモデムには、コードの論理エラーにより権限がバイパスされる可能性がある」とのことです NIST(米国国立標準技術研究所)の国家脆弱性データベース(NVD)に掲載されているバグの説明 。「これにより、追加の実行権限を必要とせずに、リモート(近接/隣接)での権限昇格が可能になる可能性がある。悪用にはユーザーの操作は不要である。」 」
https://thehackernews.com/2026/09/google-patches-pixel-modem-flaw-amid.html
##🚨 Google confirms Pixel phones targeted in zero-click zero-day attacks
Google has patched CVE-2026-58704, a high-severity vulnerability in Pixel phones' cellular modem that the company says was already under "limited, targeted exploitation."
⠀
The flaw is caused by a logic error that can allow an attacker to bypass permission checks and escalate privileges beyond the modem's isolated environment.
⠀
Most importantly, exploitation requires no interaction from the victim.
No malicious link needs to be clicked and no file needs to be opened, making it a zero-click attack.
⠀
Google has not disclosed:
• Who carried out the attacks
• How many Pixel owners were targeted
• How the victims were selected
• What tools or spyware may have been deployed
⠀
CISA has added CVE-2026-58704 to its Known Exploited Vulnerabilities catalog and set a September 19 remediation deadline for affected federal systems.
⠀
Google says Pixel devices with the September 5, 2026 security patch level or later are protected.
Pixel owners should update their devices immediately.
##Google Patches Pixel Modem Zero-Day Exploited in Targeted Attacks
Google's September 2026 update for Pixel devices fixes 110 vulnerabilities, including a high-severity modem flaw (CVE-2026-58704) that attackers are actively exploiting to escalate privileges without user interaction.
**Update your Pixel devices to the September 2026 patch level ASAP to block an active modem exploit and patch a huge set of issues.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/google-patches-pixel-modem-zero-day-exploited-in-targeted-attacks-w-p-u-q-l/gD2P6Ple2L
「Google Pixel端末がゼロクリック攻撃でハッキングされる
/CISAは連邦政府機関に対し、パッチ適用にわずか3日間しか猶予を与えていない。 」: #TheRegister
「Googleと米国政府は、Pixelスマートフォンの携帯モデムに存在するゼロデイ脆弱性を悪用した攻撃者が、権限チェックを回避し、ユーザーの操作なしに権限を昇格できると警告した。この脆弱性は、アップデートを行うことで既に修正されている。
Googleは 火曜日に、 CVE-2026-58704 として追跡されているこの重大な脆弱性 を公表し 、その際、このセキュリティホールが「限定的かつ標的を絞った悪用を受けている可能性がある」と警告した。つまり、Googleが問題を修正する前に、悪意のある人物がこのバグを発見し、悪用していたということだ。」
##「Google、限定的な標的型攻撃の兆候が見られる中、Pixelモデムの脆弱性を修正 」: #TheHackerNews
「Googleは、 明らかにした。 同社のPixel Cellular Modemに存在する深刻なセキュリティ上の欠陥が、実際に悪用されていることを
(CVSSスコア:8.0)として追跡されているこの脆弱性は CVE-2026-58704 、権限昇格の欠陥です。
によると、「セルラーモデムには、コードの論理エラーにより権限がバイパスされる可能性がある」とのことです NIST(米国国立標準技術研究所)の国家脆弱性データベース(NVD)に掲載されているバグの説明 。「これにより、追加の実行権限を必要とせずに、リモート(近接/隣接)での権限昇格が可能になる可能性がある。悪用にはユーザーの操作は不要である。」 」
https://thehackernews.com/2026/09/google-patches-pixel-modem-flaw-amid.html
##Google confirmed a Pixel modem zero-day (CVE-2026-58704) exploited in a zero-click spyware attack to escape the modem sandbox. Update now.
#Pixel #ZeroDay #CVE202658704 #Google #Spyware #ZeroClick #CyberSecurity
https://securityexpress.info/pixel-modem-zero-day/?utm_source=mastodon&utm_medium=jetpack_social
##(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-58704 – Google Pixel Improper Authorization Vulnerability
A strategic executive briefing detailing governance, risk mitigation, and compliance frameworks for CVE-2026-58704 on Google Pixel mobile devices....
##Google and CISA warned that an actively exploited zero-day vulnerability (CVE-2026-58704) affecting Pixel cellular modems.
This allows attackers to silently bypass permission checks and escalate privileges with no user interaction!
It was quickly added to CISA's Known Exploited Vulnerabilities (KEV) catalog [1.2.1, 1.5.1].
Would be an excellent idea for Pixel owners to ownload and apply the September Android OS patches ASAP!
##(CISA TS-MAN) The Cyber Mind TSUITE Brief: CVE-2026-58704 – Google Pixel Improper Authorization Vulnerability
Actionable threat intelligence and end-to-end hardening strategies for CVE-2026-58704, addressing improper authorization flaws in Google Pixel cellular modems....
##Google patched CVE-2026-58704, a high-severity Pixel Cellular Modem privilege-escalation flaw reportedly exploited in limited, targeted attacks. Its addition to CISA’s KEV Catalog underscores the need to prioritize affected device updates. #ZeroDay #MobileSecurity #ThreatIntelligence
https://cyberworldops.eu/en/google-patches-pixel-modem-zero-day-exploited-in-targeted-attacks
##New.
Press release: New CISA Guidance Helps Critical Infrastructure Detect, Observe and Impede Malicious Cyber Activity https://www.cisa.gov/news-events/news/new-cisa-guidance-helps-critical-infrastructure-detect-observe-and-impede-malicious-cyber-activity
The guide: Using Cyber Decoys to Strengthen Detection and Response https://www.cisa.gov/resources-tools/resources/using-cyber-decoys-strengthen-detection-and-response
CISA has also added one vulnerability to the catalogue.
CVE-2026-58704: Google Pixel Improper Authorization Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-58704 #Google #infosec #vulnerability #CISA
##🏆 New Achievement! Tutorial: Learning to Live With Being Actively Exploited!
Welcome to the Mandatory Pixel Debuff Sequence. Before you proceed, please note that CVE-2026-58704 has been equipped to your device without your consent. This is a zero-day — that means the tutorial boss was already in your pocket before the level loaded. (1/3)
##🚨 [CISA-2026:0916] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0916)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-58704 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-58704)
- Name: Google Pixel Improper Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Pixel
- Notes: https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-58704
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260916 #cisa20260916 #cve_2026_58704 #cve202658704
##If you've got a Google Pixel cell phone, do a system patch immediately. There is an active vulnerability that allows the hacker to take control of your device with no user interaction. It is being actively used in the wild.
##Google corrige falha zero-day em telemóveis Pixel com atualização que resolve 110 vulnerabilidades. A falha, identificada como CVE-2026-58704, está a ser explorada em ataques direcionados de alcance limitado. 📱
##CVE ID: CVE-2026-58704
Vendor: Google
Product: Pixel
Date Added: 2026-09-16
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-58704
@skyblitz CVE-2026-58704 is a modem firmware vulnerability with a patch released today and it will be included in our upcoming release.
##@GrapheneOS funny to see google fixing : CVE-2025-48595 that was fixed looooooong ago in your.
i don't see CVE-2026-58704, is it already fixed ?
##updated 2026-09-16T14:17:12.413000
1 posts
🟠 CVE-2026-88065 - High (7.5)
`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions prior to 2.1.0 have a Broken Access Control vulnerability across several API endpoints (such as `/api/student/{id}/photo` and `...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88065/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-16T09:30:35
4 posts
Patch critical industrial firmware vulnerabilities and authentication bypass flaws like CVE-2026-27565 in Pepperl+Fuchs, Phoenix Contact & Carlo Gavazzi.
#IndustrialSecurity #FirmwareFlaws #Cybersecurity #CVE202627565 #InfoSec
##🔒 New CSAF advisory published
VDE-2026-028
Carlo Gavazzi Automation: YL212* and YN115* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)
The affected devices have security vulnerabilities that can be used to bypass authentication. Code…
HTML: https://certvde.com/en/advisories/VDE-2026-028
CSAF JSON: https://gavazziautomation.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-028.json
🔒 New CSAF advisory published
VDE-2026-027
Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)
The firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices is affected by security vulnerab…
HTML: https://certvde.com/en/advisories/VDE-2026-027
CSAF JSON: https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-027.json
🔒 New CSAF advisory published
VDE-2026-014
Pepperl+Fuchs: ICE2-* and ICE3-* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)
The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be execute…
HTML: https://certvde.com/en/advisories/VDE-2026-014
CSAF JSON: https://pepperl-fuchs.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-014.json
updated 2026-09-16T09:30:35
3 posts
🔒 New CSAF advisory published
VDE-2026-028
Carlo Gavazzi Automation: YL212* and YN115* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)
The affected devices have security vulnerabilities that can be used to bypass authentication. Code…
HTML: https://certvde.com/en/advisories/VDE-2026-028
CSAF JSON: https://gavazziautomation.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-028.json
🔒 New CSAF advisory published
VDE-2026-027
Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)
The firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices is affected by security vulnerab…
HTML: https://certvde.com/en/advisories/VDE-2026-027
CSAF JSON: https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-027.json
🔒 New CSAF advisory published
VDE-2026-014
Pepperl+Fuchs: ICE2-* and ICE3-* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)
The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be execute…
HTML: https://certvde.com/en/advisories/VDE-2026-014
CSAF JSON: https://pepperl-fuchs.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-014.json
updated 2026-09-16T09:30:34
3 posts
🔒 New CSAF advisory published
VDE-2026-028
Carlo Gavazzi Automation: YL212* and YN115* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)
The affected devices have security vulnerabilities that can be used to bypass authentication. Code…
HTML: https://certvde.com/en/advisories/VDE-2026-028
CSAF JSON: https://gavazziautomation.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-028.json
🔒 New CSAF advisory published
VDE-2026-027
Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)
The firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices is affected by security vulnerab…
HTML: https://certvde.com/en/advisories/VDE-2026-027
CSAF JSON: https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-027.json
🔒 New CSAF advisory published
VDE-2026-014
Pepperl+Fuchs: ICE2-* and ICE3-* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)
The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be execute…
HTML: https://certvde.com/en/advisories/VDE-2026-014
CSAF JSON: https://pepperl-fuchs.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-014.json
updated 2026-09-16T09:30:28
5 posts
1 repos
Critical Unbound DNSSEC Flaw Opens a Dangerous Path to Remote Code Execution + Video
Critical Unbound DNSSEC Flaw Could Turn a Malicious DNS Zone Into a Remote Code Execution Gateway A Critical Weakness Hidden Inside DNS Validation A critical security flaw in the Unbound DNS resolver has placed organizations running older versions under serious patching pressure. Tracked as CVE-2026-81642, the vulnerability is a heap buffer overflow in Unbound's DNSSEC validation…
##NLnet Labs Unbound before 1.26.1 contains heap overflow CVE-2026-81642 in the DNSSEC validator via crafted DNSKEY with compression pointer into RDATA. Any resolver induced to query a malicious zone risks crash or potential RCE, exposing core DNS infrastructure. #Unbound #DnsSec #HeapOverflow
https://cyberworldops.eu/en/unbound-dnssec-heap-overflow-puts-vulnerable-resolvers-at-risk-of
##Unbound DNSSEC Validator Flaw Enables Remote Code Execution
A critical flaw in the Unbound DNSSEC Validator, known as CVE-2026-81642, allows attackers to trigger a heap overflow, potentially enabling remote code execution on vulnerable systems. This vulnerability affects all Unbound DNS resolver releases before 1.26.1, putting countless systems at risk.
#DnssecValidatorFlaw #RemoteCodeExecution #Cve202681642 #Unbound #HeapOverflow
##NLnet Labs Unbound before 1.26.1 contains heap overflow CVE-2026-81642 in the DNSSEC validator via crafted DNSKEY with compression pointer into RDATA. Any resolver induced to query a malicious zone risks crash or potential RCE, exposing core DNS infrastructure. #Unbound #DnsSec #HeapOverflow
https://cyberworldops.eu/en/unbound-dnssec-heap-overflow-puts-vulnerable-resolvers-at-risk-of
##CVE-2026-81642: CRITICAL heap buffer overflow in NLnet Labs Unbound ≤1.26.0. Exploitable via DNSKEY with owner compression pointer — possible DoS & RCE. Patch ASAP. https://radar.offseq.com/threat/cve-2026-81642-cwe-122-heap-based-buffer-overflow-in-nlnet-labs-unbound-2ab04cc5a0313c65 #OffSeq #DNS #Unbound #Vuln #RCE
##updated 2026-09-16T06:31:34
1 posts
TrueBooker (<=1.2.3) WordPress plugin hit by CVE-2026-14349 (CRITICAL, CVSS 9.8): missing auth lets unauthenticated attackers change user emails & reset passwords. No patch yet — restrict access & monitor! https://radar.offseq.com/threat/cve-2026-14349-cwe-862-missing-authorization-in-themetechmount-truebooker-appointment-booking-and-c8c43284d888ee3a #OffSeq #WordPress #CVE202614349 #AppSec
##updated 2026-09-16T00:32:32
1 posts
Docker released an update for critical Docker Sandboxes vulnerabilities (CVE-2026-77179, CVE-2026-79994). Patch these Docker Sandboxes vulnerabilities today.
#Docker #DockerSandboxes #CVE202677179 #CVE202679994 #Cybersecurity
##updated 2026-09-16T00:31:42
1 posts
🟠 CVE-2026-85893 - High (8.8)
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85893/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-16T00:31:41
2 posts
Go hack more Secret Server shit.
https://delinea.com/security-advisories
##Authentication Bypass via SAML Response Manipulation - CVE-2026-15640
Reflected Cross-Site Scripting - CVE-2026-15639
Cryptographic Padding Oracle - CVE-2026-15638
Delinea Secret Server (On-Prem, v10.5.0 – 12.1.3) hit by CRITICAL auth bypass (CVE-2026-15640). SAML spoofing may allow attacker impersonation. Patch info not yet available. Details: https://radar.offseq.com/threat/cve-2026-15640-cwe-290-authentication-bypass-by-spoofing-in-delinea-secret-server-on-prem-e1dc96081cdc3445 #OffSeq #Vuln #Delinea #CVE202615640
##updated 2026-09-16T00:31:36
1 posts
🟠 CVE-2026-92248 - High (7.8)
A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header. This lea...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92248/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-16T00:31:35
2 posts
Discover the latest mySCADA myPRO Manager vulnerabilities, including CVE-2026-73807, and learn how to patch your systems to prevent remote attacks.
##CVE-2026-73807 | CRITICAL: mySCADA myPRO (v0 – 2.1) API flaw allows unauthenticated access to privileged functions. No patch yet — restrict API network access & monitor logs. https://radar.offseq.com/threat/cve-2026-73807-cwe-862-in-myscada-technologies-myscada-mypro-e06debb83925d7aa #OffSeq #ICS #SCADA #Vulnerability
##updated 2026-09-16T00:31:33
2 posts
Go hack more Secret Server shit.
https://delinea.com/security-advisories
##Authentication Bypass via SAML Response Manipulation - CVE-2026-15640
Reflected Cross-Site Scripting - CVE-2026-15639
Cryptographic Padding Oracle - CVE-2026-15638
CVE-2026-15639: CRITICAL XSS in Delinea Secret Server (On-Prem, 10.2.19 – 11.9.48). Exploitation allows remote attackers to run JS in user sessions. Patch status unknown — check vendor advisories. https://radar.offseq.com/threat/cve-2026-15639-cwe-79-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-ac80ea2cb57f59e8 #OffSeq #XSS #Vuln #Delinea #Cybersecurity
##updated 2026-09-15T21:33:15
1 posts
🔴 CVE-2026-91939 - Critical (9.8)
Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91939/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T21:33:15
1 posts
🟠 CVE-2026-92000 - High (7.5)
adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92000/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T21:33:13
1 posts
🟠 CVE-2026-68070 - High (8.8)
The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68070/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T21:33:13
1 posts
🔴 CVE-2026-66890 - Critical (9.6)
The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66890/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T21:33:13
1 posts
🔴 CVE-2026-89040 - Critical (9.8)
Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code as root.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89040/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T21:31:29
1 posts
🟠 CVE-2026-92179 - High (7.8)
pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92179/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T21:31:28
1 posts
🟠 CVE-2026-92178 - High (7.8)
pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92178/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T21:31:25
1 posts
🟠 CVE-2026-92180 - High (7.8)
pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92180/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T20:00:36
1 posts
🟠 CVE-2026-69213 - High (7.5)
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/2 serializes outbound frames through one unbounded queue consumed by writeLoop. When the peer stops reading, an unauthenticated HTTP/2 client can continue se...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69213/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T18:33:13
1 posts
Cisco has addressed a critical September 2 vulnerability.
CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM @TalosSecurity
More related to Cisco:
Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild/ @Rapid7Official #threatresearch #infosec #Cisco #vulnerability
##updated 2026-09-15T18:32:43
3 posts
1 repos
Unauthenticated RCE in Issabel Framework (CVE-2026-89026) is being exploited in the wild. A hardcoded JWT secret in pbxapi/index.php allows token forgery and OS command execution as the Asterisk user, risking full PBX takeover. #Issabel #RemoteCodeExecution #InfoSec
https://cyberworldops.eu/en/one-shared-jwt-secret-exposes-issabel-pbx-servers-to-remote-command
##Thank you to @vulncheck for the smooth collaboration throughout the CNA process.
More details:
https://www.cve.org/CVERecord?id=CVE-2026-89026
🔴 CVE-2026-89026 - Critical (9.8)
The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89026/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T18:32:43
1 posts
🟠 CVE-2026-91985 - High (7.5)
Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the disclosed hash for a link-share JWT ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91985/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T18:32:43
1 posts
🟠 CVE-2026-91990 - High (7.5)
Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create large transie...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91990/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T18:32:13
1 posts
Cisco has addressed a critical September 2 vulnerability.
CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM @TalosSecurity
More related to Cisco:
Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild/ @Rapid7Official #threatresearch #infosec #Cisco #vulnerability
##updated 2026-09-15T18:17:29.010000
1 posts
🟠 CVE-2026-63443 - High (8.3)
Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected request U...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63443/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T18:17:18.413000
1 posts
Cisco has addressed a critical September 2 vulnerability.
CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM @TalosSecurity
More related to Cisco:
Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild/ @Rapid7Official #threatresearch #infosec #Cisco #vulnerability
##updated 2026-09-15T15:32:20
1 posts
🔴 CVE-2026-63695 - Critical (9.8)
Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63695/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T15:32:20
1 posts
🟠 CVE-2026-89025 - High (7.5)
Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specif...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89025/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T15:17:14.723000
1 posts
A Ghostscript buffer overflow enables unauthenticated remote code execution. Patch this Ghostscript buffer overflow flaw (CVE-2026-39919) immediately.
#Ghostscript #CVE202639919 #RemoteCodeExecution #Cybersecurity #InfoSec
##updated 2026-09-15T14:40:24.370000
1 posts
CVE-2026-81915 Concrete CMS below 9.5.3: broken object-level authz lets any dashboard user edit Page Types outside their scope. CVSS N/A, patch status unknown. Update immediately. https://www.valtersit.com/cve/CVE-2026-81915/ #CVE #infosec #ConcreteCMS
##updated 2026-09-15T13:16:45.543000
1 posts
CVE-2026-89308 in TREXOM TrxTimeATTENDANCE (v1.0.5 – 1.9.5): CRITICAL OS command injection in ping.php allows unauthenticated RCE. Remediate ASAP. https://radar.offseq.com/threat/cve-2026-89308-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-8f863d468f1bf361 #OffSeq #CVE202689308 #infosec #vuln #remediation
##updated 2026-09-15T12:47:32.497000
12 posts
4 repos
https://github.com/S3v3n-JG/CVE-2026-76461
https://github.com/HORKimhab/CVE-2026-76461
Cisco Zero-Day wird aktiv angegriffen
Mal was neues - ach nein, Hintertüren bei Cisco sind ja gar nicht neu, sondern schon fast Gewohnheit. Am Montag hat die Firma ihre Kunden informiert, dass im Secure Email Gateway (SEG) eine Sicherheitslücke steckt, die bereits aktiv angegriffen wird. Dabei ist gleichgültig, ob das SEG auf eigener Hardware (Appliance) läuft oder als virtuelle Maschine oder Cloud-Dienst. Auch die Konfiguration des SEG macht keinen Unterschied. Das muss man sich mal auf der Zunge zergehen lassen: Das SEG, das vor schädlichen E-Mails schützen soll, kann durch genau solche angegriffen werden! Die Sicherheitslücke CVE-2026-76461 ... Weiterlesen:
https://www.pc-fluesterer.info/wordpress/2026/09/17/cisco-zero-day-wird-aktiv-angegriffen/
#0day #backdoor #closedsource #email #exploits #hersteller #sicherheit #UnplugTrump #zeroday #cisco
##🏆 New Achievement! Root Access? We'll Get That Escalated for You!
Your ticket has been received. We see you're experiencing an issue where an unauthenticated attacker is executing arbitrary commands with root privileges on your Cisco Secure Email Gateway via CVE-2026-76461. Great news: we've reproduced the bug! It's the email parsing in Cisco AsyncOS — sending a specially crafted email with malicious SQL statements is all it takes. (1/3)
##Recent developments include Cisco patching a critical zero-day (CVE-2026-76461) in its Secure Email Gateway, which was actively exploited for root command execution. Geopolitically, China warned against weaponizing space after the US confirmed orbital weapon deployments. In technology, debates continue on AI safety versus national competitive advantage, with US Speaker Johnson rejecting development pauses.
##Global cybersecurity agencies, including CISA & NSA, issued guidance to mitigate 17 Active Directory compromise techniques (Sept 16). Cisco patched an actively exploited email gateway zero-day (CVE-2026-76461). Geopolitically, the US confirmed deploying space weapons, drawing warnings from China about an arms race (Sept 15). AI is now the leading driver for new cybersecurity spending.
##A critical Cisco Secure Email Gateway vulnerability allows unauthenticated attackers to gain root access via a single email. Learn about CVE-2026-76461.
##⚠️ CRITICAL: Cisco warns customers of actively exploited zero-day in email gateways
Cisco Secure Email Gateway contains a critical unauthenticated root privilege escalation vulnerability (CVE-2026-76461) that was actively exploited in the wild before patches were available. Multiple customers are likely already compromised. This is now tracked in CISA's Known Exploited Vulnerabili…
🤖 AI generated summary
##⚠️ CRITICAL: Cisco patches Secure Email Gateway zero-day exploited in attacks
Cisco Secure Email Gateway has a critical zero-day (CVE-2026-76461) that allows unauthenticated attackers to execute arbitrary commands as root via malicious SQL in crafted emails. This is actively exploited in the wild. Any organization running SEG is at immediate risk of full compromise.
🤖 AI generated summary
##Geopolitical tensions: A Russian drone struck a Kyiv-Warsaw train near the Polish border (Sept 13), and Houthi forces secured Yemen's Red Sea coast (Sept 11), affecting maritime routes. Tech news: Apple's Siri AI, powered by Apple Intelligence, began its beta rollout (Sept 14). Cybersecurity: Cisco warned of active exploitation of a critical Secure Email Gateway flaw (CVE-2026-76461) (Sept 15), and Anthropic reported Russia-linked spies used its AI Claude for hacking campaigns.
##Actionable C-Suite threat intelligence and mitigation strategies for CVE-2026-76461, addressing active SQL injection exploitation vectors within enterprise Cisco Secure Email Gateway infrastructures. https://thecybermind.co/r5ry
##Cisco has addressed a critical September 2 vulnerability.
CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM @TalosSecurity
More related to Cisco:
Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild/ @Rapid7Official #threatresearch #infosec #Cisco #vulnerability
##📢 [VULN] ⚠️Injection SQL exploitée dans Cisco Secure Email Gateway - CVE-2026-76461
Le 14 septembre 2026 à 16 h 00 UTC, Cisco a publié deux avis de sécurité sur sa passerelle de messagerie.
🔗 https://blog.marcfredericgomez.fr/injection-sql-exploitee-dans-cisco-secure-email-gateway/
💬 discussion : https://infosec.pub/post/52317366
#CVE #Cyberveille
「Ciscoのセキュアメールゲートウェイの脆弱性が実際に悪用され、ルート権限でのコマンド実行が可能になる 」: #TheHackerNews
「スコは、Cisco Secure Email Gateway向けAsyncOSソフトウェアに影響を与える新たな重大な脆弱性が、実際に悪用されていると警告した。
CVE-2026-76461 として追跡されているこの脆弱性は 、CVSSスコアが10.0点満点中9.8点です。これは、メール解析ロジックにおける検証の不備が原因で、認証されていないリモート攻撃者が、基盤となるオペレーティングシステム上でroot権限で任意のコマンドを実行できる可能性があるとされています。
シスコは月曜日の勧告で、「攻撃者は、悪意のあるSQL文を含む細工された電子メールメッセージを影響を受けるデバイスに送信することで、この脆弱性を悪用する可能性がある」 と述べた 。」
https://thehackernews.com/2026/09/cisco-secure-email-gateway-flaw.html
##updated 2026-09-15T12:31:54
1 posts
pig-mesh pig <4.1.0 hit by CRITICAL vuln (CVE-2026-91995, CVSS 9.3): remote attackers can reset any account password — admin included — via /register/password auth bypass. Restrict access & monitor logs while awaiting patch. https://radar.offseq.com/threat/cve-2026-91995-unverified-password-change-in-pig-mesh-pig-6a0b879ab4cc0e5c #OffSeq #vulnerability #CVE #infosec
##updated 2026-09-15T09:30:39
1 posts
🟠 CVE-2026-77853 - High (8.8)
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77853/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T06:30:39
1 posts
🔴 CVE-2026-91001 - Critical (9.9)
A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip results in stac...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91001/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T00:31:21
1 posts
2 repos
A critical Langflow SSRF flaw (CVE-2026-12944) exposes cloud credentials and internal networks. Patch your Langflow OSS servers immediately.
##updated 2026-09-15T00:31:13
1 posts
Apple acknowledges fixing the Private Relay bug leaking the IP in the secure release notes of iOS 26.6.1 and macOS 26.6.2.
CVE-2026-65352 was assigned to it
updated 2026-09-14T21:32:45
1 posts
Six Apache Syncope vulnerabilities, including CVE-2026-82232, expose severe identity management flaws. Patch your Apache Syncope servers immediately.
#ApacheSyncope #IdentityManagement #CVE202682232 #Cybersecurity #Vulnerability
##updated 2026-09-14T17:17:51.410000
1 posts
CRITICAL: The Events Calendar WP plugin (<6.17.4.1) has two unauthenticated RCEs — CVE-2026-78159 (code injection) & CVE-2026-78006 (object injection, comments enabled). 240K+ sites at risk. Update now: https://radar.offseq.com/threat/unauthenticated-rce-flaws-could-expose-200000-wordpress-sites-to-takeover-7f3911d49bdf2638 #OffSeq #WordPress #RCE #Vuln
##updated 2026-09-14T15:33:28
3 posts
CVE-2026-81005 Linux kernel NULL pointer dereference in ipmi_si after failed SMI registration. CVSS N/A. Unpatched. A BMC that fails Get Device ID can crash the kernel. Patch now. https://www.valtersit.com/cve/CVE-2026-81005/ #CVE #Linux #infosec
##@hugovalters Thanks for flagging CVE-2026-81005. This NULL pointer dereference in ipmi_si is nasty — BMC failure during Get Device ID shouldn't crash the kernel. Mitigation: disable ipmi_si module if BMC is unresponsive (modprobe -r ipmi_si) or ensure ipmi_si.force_kipmi=0 to avoid kernel thread hang. Patch backports likely in stable kernel queue. #infosec #Linux #CVE
##CVE-2026-81005 Linux kernel NULL pointer dereference in ipmi_si after failed SMI registration. CVSS N/A. Unpatched. A BMC that fails Get Device ID can crash the kernel. Patch now. https://www.valtersit.com/cve/CVE-2026-81005/ #CVE #Linux #infosec
##updated 2026-09-14T15:33:28
1 posts
CVE-2026-81000 Linux kernel tun driver integer underflow in tun_get_user() via oversized headroom from OVS, leading to memory corruption. No CVSS assigned, patch status unpatched. Apply kernel updates now. https://www.valtersit.com/cve/CVE-2026-81000/ #CVE #Linux #infosec
##updated 2026-09-14T15:33:27
1 posts
CVE-2026-80967 Linux ALSA pcxhr: mutexes initialized after threaded IRQ request, risking uninitialized lock state during probe. Patch status unknown. Update your kernel now. https://www.valtersit.com/cve/CVE-2026-80967/ #CVE #infosec #Linux
##updated 2026-09-14T15:33:27
1 posts
CVE-2026-80952 Linux kernel i3c UAF and info leak in device unregister path, CVSS N/A, patch status unknown. Assume unpatched. Patch now: https://www.valtersit.com/cve/CVE-2026-80952/ #CVE #infosec #Linux
##updated 2026-09-14T15:32:26
1 posts
CVE-2026-89483 Linux kernel nvme discard: uninitialized page read leaks 4080 bytes of stale kernel memory to devices. CVSS N/A, patch status unknown. Update kernel now if you run nvme. https://www.valtersit.com/cve/CVE-2026-89483/ #CVE #Linux #infosec
##updated 2026-09-14T15:32:22
1 posts
CVE-2026-80982 Linux net/smc use-after-free in smc_rx_pipe_buf_release(), patch status unknown, CVSS not assigned. Unpatched kernel race can crash or corrupt memory. Update immediately. https://www.valtersit.com/cve/CVE-2026-80982/ #CVE #Linux #infosec
##updated 2026-09-14T15:32:20
1 posts
CVE-2026-80938 Linux kernel mt7615 wifi deadlock in suspend path, MAC work vs mutex. No CVSS or patch yet. Watch for fixes. https://www.valtersit.com/cve/CVE-2026-80938/ #CVE #Linux #infosec
##updated 2026-09-14T14:22:15.323000
5 posts
13 repos
https://github.com/0xenesbayram/cve-2026-85706
https://github.com/guneykabel/cve-2026-85706
https://github.com/0xlyvio/cve-2026-85706-poc-exploit-gitlab
https://github.com/gagaltotal/CVE-2026-85706-gitlab-poc
https://github.com/solivaquaant/CVE-2026-85706
https://github.com/brigadeops32/CVE-2026-85706
https://github.com/gabrielunknown/CVE-2026-85706
https://github.com/mhtsec/CVE-2026-85706
https://github.com/tc4dy/CVE-2026-85706-PoC-Toolkit
https://github.com/FlowerWitch/CVE-2026-85706_docker_exp
https://github.com/ynsmroztas/GitLabSniper
https://github.com/plur1bu5/gitread
https://github.com/jithinkrishnanrs/gitlab-cve-2026-85706-ioc
GitLab CVE-2026-85706: unauth arbitrary file read, exploited in the wild, now on CISA KEV. Patch
19.3.2 / 19.2.6 / 19.1.8.
The 10.0 is about the read. The damage is the credentials inside the files, and a commits API
reads history, so secrets you deleted are still there.
Patch, hunt, THEN rotate. Rotating on a readable server hands over the new keys.
blog.relayshield.net/a-file-read-bug-is-a-credential-theft-bug
#GitLab #infosec #DevSecOps
Actionable C-Suite threat intelligence for CVE-2026-85706, covering active path traversal exploitation vectors, endpoint hardening, and patch automation across GitLab environments. https://thecybermind.co/uzke
##Learn why CISA added GitLab CVE-2026-85706 to the Known Exploited Vulnerabilities catalog. Discover how this CVSS 10 flaw allows remote secret extraction.
##🚨 GitLab CVE-2026-85706 is a critical CVSS 10.0 vulnerability under active exploitation.
Censys sees 86K+ GitLab hosts on the Internet.
Patch immediately. If your instance was exposed while vulnerable, rotate credentials and investigate for compromise. https://censys.com/advisory/cve-2026-85706/
##Comment la faille de GitLab peut mettre à nu vos serveurs https://goodtech.info/gitlab-faille-critique-cve-2026-85706-cisa-cert-fr/ #Développement #Revuedepresse #Sécurité
##updated 2026-09-14T13:19:06.090000
1 posts
CVE-2026-89491 Linux kernel ocfs2 flaw: sleep while holding o2hb_live_lock in o2hb_region_pin(). CVSS N/A, patch status unknown. Update immediately. https://www.valtersit.com/cve/CVE-2026-89491/ #CVE #Linux #infosec
##updated 2026-09-14T13:19:03.733000
1 posts
CVE-2026-89474 Linux kernel bq256xx use-after-free in power supply driver, USB work can run after charger freed. No CVSS, no patch yet. Audit and update kernel now. https://www.valtersit.com/cve/CVE-2026-89474/ #CVE #infosec #LinuxKernel
##updated 2026-09-14T13:19:01.410000
1 posts
CVE-2026-89442: out-of-bounds access in the Linux kernel ISST driver lets a bad socket ID index past sst_inst[]. No CVSS or patch yet. Treat as unpatched, restrict ioctl access. Details: https://www.valtersit.com/cve/CVE-2026-89442/ #CVE #Linux #infosec
##updated 2026-09-14T13:18:53.090000
1 posts
CVE-2026-80983 Linux kernel net/smc socket refcount leak in smc_switch_conns(). CVSS N/A, no patch yet. Monitor and apply vendor fix once released. https://www.valtersit.com/cve/CVE-2026-80983/ #CVE #Linux #infosec
##updated 2026-09-14T13:18:50.037000
1 posts
CVE-2026-80939 Linux rtw89 PCI wifi driver can panic arm64 systems with SError on warm reboot due to rfkill polling with no shutdown callback. No CVSS assigned, patch status unknown. Apply kernel updates when https://www.valtersit.com/cve/CVE-2026-80939/ #CVE #Linux #infosec
##updated 2026-09-14T12:31:44
2 posts
New Parallels Desktop Flaw Lets Local Users Seize Root Control of Macs
A newly documented security flaw in Parallels Desktop, identified as CVE-2026-90894 and nicknamed "ParaShells," could let any local account on
🔗️ [Thecyberexpress] https://link.is.it/XRBHSO
##New Parallels Desktop Flaw Lets Local Users Seize Root Control of Macs
A newly documented security flaw in Parallels Desktop, identified as CVE-2026-90894 and nicknamed "ParaShells," could let any local account on
🔗️ [Thecyberexpress] https://link.is.it/XRBHSO
##updated 2026-09-14T09:31:09
1 posts
Logitech Options+ : une faille donne les privilèges SYSTEM à n’importe quel utilisateur Windows https://www.it-connect.fr/logitech-options-plus-faille-system-cve-2026-12518/ #ActuCybersécurité #Cybersécurité #Vulnérabilité
##updated 2026-09-13T07:17:02.700000
1 posts
CVE-2026-80955 Linux kernel dm-pcache use-after-free in kset_replay(). CVSS N/A. Patch status unknown. Update now. https://www.valtersit.com/cve/CVE-2026-80955/ #CVE #infosec #Linux
##updated 2026-09-12T09:33:41
1 posts
2 repos
CRITICAL: The Events Calendar WP plugin (<6.17.4.1) has two unauthenticated RCEs — CVE-2026-78159 (code injection) & CVE-2026-78006 (object injection, comments enabled). 240K+ sites at risk. Update now: https://radar.offseq.com/threat/unauthenticated-rce-flaws-could-expose-200000-wordpress-sites-to-takeover-7f3911d49bdf2638 #OffSeq #WordPress #RCE #Vuln
##updated 2026-09-11T21:31:37
1 posts
CVE-2026-89529 Linux kernel svcrdma: unvalidated Read segment lengths allow oversized allocation. No CVSS yet, patch status unknown. Update your kernel now: https://www.valtersit.com/cve/CVE-2026-89529/ #CVE #infosec #Linux
##updated 2026-09-11T21:31:37
1 posts
CVE-2026-89514 Linux kernel fnic driver allocates memory with GFP_KERNEL under a spinlock, risking deadlock or crash. No CVSS, patch status unknown. Update kernel when fixes land. https://www.valtersit.com/cve/CVE-2026-89514/ #CVE #Linux #infosec
##updated 2026-09-11T21:31:17
2 posts
(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-84869 – ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
C-Suite threat intelligence and mitigation protocols for CVE-2026-84869, addressing active exploitation vectors within enterprise ConnectWise environments....
##ConnectWise Patches Critical ScreenConnect Flaw Exploited in Worm Attacks
ConnectWise fixed a critical vulnerability (CVE-2026-84869) in ScreenConnect that allows unauthorized file execution and worm-like propagation across remote sessions.
**If you use ConnectWise ScreenConnect, update to version 26.6.5 right away and then reinstall every host client. The update only takes effect once the clients are reinstalled, and this flaw is already being exploited to spread from machine to machine. If you can't patch, turn off the TransferFiles permission for all user roles as a mitigating measures. Don't forget to check integrated tools like ConnectWise Automate for their own patched versions.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/connectwise-patches-critical-screenconnect-flaw-exploited-in-worm-attacks-n-t-h-f-x/gD2P6Ple2L
updated 2026-09-11T21:31:06
1 posts
(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-42016 – JFrog Artifactory Incorrect Authorization Vulnerability
C-Suite threat intelligence for CVE-2026-42016, covering OAuth scope validation, lateral movement detection, and repository hardening across JFrog Artifactory instances....
##updated 2026-09-11T20:36:20
1 posts
🔴 CVE-2026-59971 - Critical (10)
MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct SseServerTransport without security_settings or ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59971/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-11T18:31:25
1 posts
1 repos
https://github.com/abhinavagarwal07/scadapack-secure-lock-poc
Schneider Electric disclosed CVE-2026-81861 (CWE-522) affecting SCADAPack x70 RTUs. Legacy Secure Lock insufficiently protects credentials, exposing RTU authentication data. Exposed credentials matter for OT as they can enable unauthorized access to monitoring and control functions. #IcsSecurity #ScadaSecurity #OtSecurity
https://cyberworldops.eu/en/schneider-electric-scadapack-credential-flaw-exposes-rtu
##updated 2026-09-11T03:31:25
1 posts
Nintendo Switch : une faille permet d’exécuter du code via le code QR affiché à l’écran https://www.it-connect.fr/nintendo-switch-faille-code-qr-cve-2026-82079/ #ActuCybersécurité #Cybersécurité #Vulnérabilité
##updated 2026-09-09T23:47:56
1 posts
🟠 CVE-2026-59160 - High (8.8)
Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by default, while t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59160/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-09T21:31:33
1 posts
3 repos
https://github.com/0xBlackash/CVE-2026-20079
Cisco Secure FMC: Kritische Auth-Bypass-Lücke (CVSS 10.0) wird aktiv ausgenutzt
Cisco bestätigt, dass eine mit dem Höchstwert CVSS 10.0 bewertete Authentifizierungs-Bypass-Lücke (CVE-2026-20079) in seiner Secure Firewall Management Center (FMC) Software […]
https://netguide.io/news/de/2026/09/14/cisco-secure-fmc-cve-2026-20079-auth-bypass/
##updated 2026-09-08T22:17:38.113000
1 posts
aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3
perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38
sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0
セキュリティ対応なのでお早めに。
##updated 2026-09-08T21:33:09
1 posts
5 repos
https://github.com/jithinkrishnanrs/stylesmuggler-ioc-toolkit
https://github.com/disrex-group/stylesmuggler-adobe-patches
https://github.com/fortbridge/stylesmuggler
https://github.com/dinosn/cve-2026-75650-magento-validation-lab
https://github.com/disrex-group/stylesmuggler-adobe-patches-mageos
CVE-2026-75650: StyleSmuggler — Critical RCE in Adobe Commerce and Magento
#CVE_2026_75650 #AdobeCommerce
https://www.akamai.com/blog/security-research/2026/sep/cve-2026-75650-stylesmuggler-adobe-commerce-magento
updated 2026-09-08T09:36:36
1 posts
100 repos
https://github.com/4xura/CVE-2026-31431-Copy-Fail
https://github.com/nisec-eric/cve-2026-31431
https://github.com/SeanRickerd/cve-2026-31431
https://github.com/sec17br/CVE-2026-31431-Copy-Fail
https://github.com/Juguitos/copy-fail
https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431
https://github.com/haydenjames/CVE-2026-31431-check
https://github.com/sgkdev/page_inject
https://github.com/guiimoraes/CVE-2026-31431
https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC
https://github.com/Qengineering/RK35xx-CopyFail-Hotfix
https://github.com/novysodope/copy-fail-CVE-2026-31431-C
https://github.com/cs8425/copy-fail-go
https://github.com/abdelkabirouadoukou/CVE-2026-31431-Analysis-and-Fix
https://github.com/lonelyor/CVE-2026-31431-exp
https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE
https://github.com/sudoytang/copyfail-arm64
https://github.com/wuwu001/CVE-2026-31431-exploit
https://github.com/desultory/CVE-2026-31431
https://github.com/diemoeve/copyfail-rs
https://github.com/pedromizz/copy-fail
https://github.com/Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431
https://github.com/Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail
https://github.com/rootsecdev/cve_2026_31431
https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag
https://github.com/KaraZajac/DIRTYFAIL
https://github.com/gagaltotal/cve-2026-31431-copy-fail
https://github.com/AliHzSec/CVE-2026-31431
https://github.com/erlangparasu/mitigate_cve_2026_31431-sh
https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit
https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script
https://github.com/MrAriaNet/cPanel-Fix
https://github.com/b5null/CVE-2026-31431-C
https://github.com/Iamliuxiaozhen/copy_fail
https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail
https://github.com/tgies/copy-fail-c
https://github.com/badsectorlabs/copyfail-go
https://github.com/painoob/Copy-Fail-Exploit-CVE-2026-31431
https://github.com/g1nt0n1x/copy-fail-CVE-2026-31431-shell
https://github.com/cozystack/copy-fail-blocker
https://github.com/ErdemOzgen/copy-fail-cve-2026-31431
https://github.com/Boos4721/copyfail-rs
https://github.com/qi4L/CVE-2026-31431-Container-Escape
https://github.com/ncmprbll/copy-fail-rs
https://github.com/philfry/cve-2026-31431-ftrace
https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized
https://github.com/yuspring/cve-2026-31431-poc
https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe
https://github.com/ExploitEoom/CVE-2026-31431
https://github.com/pascal-gujer/CVE-2026-31431
https://github.com/ZephrFish/CopyFail-CVE-2026-31431
https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC
https://github.com/sammwyy/copyfail-rs
https://github.com/0xBlackash/CVE-2026-31431
https://github.com/Shotafry/CopyFail-Exploits-CVE-2026-31431
https://github.com/kinryulabs/rootpacket-cve-2026-31431
https://github.com/mrunalp/block-copyfail
https://github.com/samanzamani/copy-fail-checker
https://github.com/povzayd/CVE-2026-31431
https://github.com/theori-io/copy-fail-CVE-2026-31431
https://github.com/bigwario/copy-fail-CVE-2026-31431-C
https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit
https://github.com/rvzsec/CVE-2026-31431
https://github.com/bootsareme/copyfail-deconstructed
https://github.com/TheMalwareGuardian/CVE-2026-31431
https://github.com/xeloxa/copyfail-exploit
https://github.com/ben-slates/CVE-2026-31431-Exploit
https://github.com/mahdi13830510/CVE-2026-31431-mitigation-suite
https://github.com/hans362/CVE-2026-31431-Copy-Fail-Container-Escape
https://github.com/Alfredooe/CVE-2026-31431
https://github.com/cyber-joker/copy-fail-python
https://github.com/luotian2/CVE-2026-31431
https://github.com/insomnisec/Detections-CVE-2026-31431
https://github.com/MartinPham/copy-fail-CVE-2026-31431-php
https://github.com/jbnetwork-git/copy-fail-check
https://github.com/Xerxes-2/CVE-2026-31431-rs
https://github.com/Smarttfoxx/copyfail
https://github.com/adampielak/CVE-2026-31431_SCA_WAZUH
https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431
https://github.com/pyroceper/copy-fail-CVE-2026-31431
https://github.com/M4xSec/CVE-2026-31431-RCE-Exploit
https://github.com/kadir/copy-fail-CVE-2026-31431-IOC
https://github.com/wesmar/CVE-2026-31431
https://github.com/sgkdev/ptrace_may_dream
https://github.com/JuanBindez/CVE-2026-31431
https://github.com/malwarekid/CVE-2026-31431
https://github.com/scriptzteam/Paranoid-Copy-Fail-CVE-2026-31431
https://github.com/XsanFlip/CVE-2026-31431-Patch
https://github.com/wgnet/wg.copyfail.patch
https://github.com/mym0us3r/COPY-FAIL-Detection-with-Wazuh-4.14.4
https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs
https://github.com/aestechno/cve-2026-31431-ansible
https://github.com/Huchangzhi/autorootlinux
https://github.com/AdityaBhatt3010/CVE-2026-31431
https://github.com/Dabbleam/CVE-2026-31431-mitigation
https://github.com/0xShe/CVE-2026-31431
https://github.com/yandex-cloud-examples/yc-mk8s-copy-fail-mitigation
https://github.com/Sl4cK0TH/CVE-2026-31431-PoC
When the Red Light Goes On: How We Responded to the Linux Kernel 0-Day
Linux 커널의 공개 PoC 로컬 권한 상승 취약점 CVE-2026-31431("Copy Fail")이 Ubuntu 24.04에서 비권한 사용자로부터 root 획득까지 가능하다고 보고됐다. 원인은 Crypto User API의 AF_ALG 경로에서 `algif_aead` 모듈에 도달 가능한 out-of-bounds write이며, 웹 애플리케이션 침해가 호스트 전체 침해로 확대될 수 있어 멀티테넌트 서버와 컨테이너 노드 운영자에게 특히 중요하다. 패치가 배포되기 전에는 `algif_aead`를 언로드하고 modprobe 설정으로 재로딩을 차단하는 방식으로 공...
##updated 2026-09-08T09:35:45
1 posts
Siemens patched CVE-2026-58113, a reflected XSS (CWE-79) in Teamcenter /auth/ redirect flow. An unauthenticated attacker can craft a URL executing JavaScript in an authenticated user's session. Update all four affected branches. #SiemensTeamcenter #CrossSiteScripting #PatchManagement
https://cyberworldops.eu/en/siemens-patches-teamcenter-authentication-redirect-xss-across-four
##updated 2026-09-04T18:32:18
4 posts
1 repos
TP-Link Patches Critical Flaws in Tapo Surveillance Cameras
TP-Link patched multiple vulnerabilities in its Tapo C200 and C120 cameras, including an authentication bypass (CVE-2026-15315) and a denial-of-service flaw (CVE-2026-15316), while a third critical vulnerability remains under investigation.
**Update your Tapo camera firmware to version V5_1.4.6 ASAP, and check for new updates for the most severe issue that's still not patched. And move all smart cameras to a separate guest network to keep your main computers safe if a device is hacked.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/tp-link-patches-critical-flaws-in-tapo-surveillance-cameras-w-h-9-n-b/gD2P6Ple2L
TP-Link Patches Critical Flaws in Tapo Surveillance Cameras
TP-Link patched multiple vulnerabilities in its Tapo C200 and C120 cameras, including an authentication bypass (CVE-2026-15315) and a denial-of-service flaw (CVE-2026-15316), while a third critical vulnerability remains under investigation.
**Update your Tapo camera firmware to version V5_1.4.6 ASAP, and check for new updates for the most severe issue that's still not patched. And move all smart cameras to a separate guest network to keep your main computers safe if a device is hacked.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/tp-link-patches-critical-flaws-in-tapo-surveillance-cameras-w-h-9-n-b/gD2P6Ple2L
In case you didn't have enough problems with cameras, here's another one.
OPSWAT, posted yesterday: Authentication Bypass and DoS Vulnerabilities: OPSWAT Discovers CVE-2026-15315 & CVE-2026-15316 in TP-Link Tapo Cameras https://www.opswat.com/blog/authentication-bypass-and-dos-vulnerabilities-opswat-discovers-cve-2026-15315-cve-2026-15316-in-tp-link-tapo-cameras
More:
Infosecurity-Magazine: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping https://www.infosecurity-magazine.com/news/zeroday-tplink-cameras/ #infosec #vulnerability #spyware #zeroday #threatresearch
##🏆 New Achievement! Smile, You're on Hacked Camera!
Step right up! For the low, low price of plugging a TP-Link Tapo C200 into your home network, you received two zero-days absolutely free of charge. OPSWAT discovered CVE-2026-15315, a replay-based authentication bypass letting any network-adjacent attacker waltz — sorry, slide — into a valid admin session without ever knowing your password. (1/2)
##updated 2026-09-04T18:31:13
4 posts
1 repos
TP-Link Patches Critical Flaws in Tapo Surveillance Cameras
TP-Link patched multiple vulnerabilities in its Tapo C200 and C120 cameras, including an authentication bypass (CVE-2026-15315) and a denial-of-service flaw (CVE-2026-15316), while a third critical vulnerability remains under investigation.
**Update your Tapo camera firmware to version V5_1.4.6 ASAP, and check for new updates for the most severe issue that's still not patched. And move all smart cameras to a separate guest network to keep your main computers safe if a device is hacked.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/tp-link-patches-critical-flaws-in-tapo-surveillance-cameras-w-h-9-n-b/gD2P6Ple2L
TP-Link Patches Critical Flaws in Tapo Surveillance Cameras
TP-Link patched multiple vulnerabilities in its Tapo C200 and C120 cameras, including an authentication bypass (CVE-2026-15315) and a denial-of-service flaw (CVE-2026-15316), while a third critical vulnerability remains under investigation.
**Update your Tapo camera firmware to version V5_1.4.6 ASAP, and check for new updates for the most severe issue that's still not patched. And move all smart cameras to a separate guest network to keep your main computers safe if a device is hacked.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/tp-link-patches-critical-flaws-in-tapo-surveillance-cameras-w-h-9-n-b/gD2P6Ple2L
In case you didn't have enough problems with cameras, here's another one.
OPSWAT, posted yesterday: Authentication Bypass and DoS Vulnerabilities: OPSWAT Discovers CVE-2026-15315 & CVE-2026-15316 in TP-Link Tapo Cameras https://www.opswat.com/blog/authentication-bypass-and-dos-vulnerabilities-opswat-discovers-cve-2026-15315-cve-2026-15316-in-tp-link-tapo-cameras
More:
Infosecurity-Magazine: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping https://www.infosecurity-magazine.com/news/zeroday-tplink-cameras/ #infosec #vulnerability #spyware #zeroday #threatresearch
##CVE-2026-15316 throws in a denial-of-service against the onboarding flow as a bonus gift with purchase.
Perhaps you'd like our Extended Vulnerability Warranty? Only $49.99. Or — and hear me out — you could just update your Tapo C200 to firmware V5_1.4.6, released August 18, for the remarkable price of free.
Reward: You've received a slightly-used Tin Foil Lens Cap. Refurbished. Non-returnable.
https://www.infosecurity-magazine.com/news/zeroday-tplink-cameras
#ZeroDay #CyberSecurity (2/2)
##updated 2026-09-01T20:56:59.203000
1 posts
🔒 New CSAF advisory published
VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576
The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…
HTML: https://certvde.com/en/advisories/VDE-2026-091
CSAF JSON: https://trumpf.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-091.json
updated 2026-09-01T13:19:51.053000
1 posts
aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3
perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38
sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0
セキュリティ対応なのでお早めに。
##updated 2026-08-31T18:31:16
1 posts
1 repos
aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3
perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38
sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0
セキュリティ対応なのでお早めに。
##updated 2026-08-31T15:35:36
1 posts
aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3
perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38
sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0
セキュリティ対応なのでお早めに。
##updated 2026-08-31T15:34:31
1 posts
aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3
perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38
sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0
セキュリティ対応なのでお早めに。
##updated 2026-08-31T15:34:31
1 posts
aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3
perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38
sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0
セキュリティ対応なのでお早めに。
##updated 2026-08-27T12:30:27
1 posts
🔒 New CSAF advisory published
VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576
The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…
HTML: https://certvde.com/en/advisories/VDE-2026-091
CSAF JSON: https://trumpf.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-091.json
updated 2026-08-27T12:30:27
1 posts
🔒 New CSAF advisory published
VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576
The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…
HTML: https://certvde.com/en/advisories/VDE-2026-091
CSAF JSON: https://trumpf.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-091.json
updated 2026-08-27T12:30:27
1 posts
🔒 New CSAF advisory published
VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576
The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…
HTML: https://certvde.com/en/advisories/VDE-2026-091
CSAF JSON: https://trumpf.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-091.json
updated 2026-08-27T12:30:26
1 posts
🔒 New CSAF advisory published
VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576
The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…
HTML: https://certvde.com/en/advisories/VDE-2026-091
CSAF JSON: https://trumpf.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-091.json
updated 2026-08-27T11:41:19.230000
2 posts
10 repos
https://github.com/Sachinart/CVE-2026-60004-gitea-0day
https://github.com/fevar54/cve-2026-60004
https://github.com/shinthink/CVE-2026-60004
https://github.com/0xBlackash/CVE-2026-60004
https://github.com/imbas007/CVE-2026-60004-POC
https://github.com/erberkan/CVE-2026-60004-PoC
https://github.com/HackSpeak/CVE-2026-60004
https://github.com/EQSTLab/CVE-2026-60004
📢 Red Heron exploite CVE-2026-60004 dans Gitea pour déployer un rootkit Linux inédit
L'Acronis Threat Research Unit (TRU) a publié le 13 septembre 2026 une analyse détaillée d'une campagne multinationale menée par un acteur malveillant sinophone qu'ils suivent sous le nom Red Heron. La découverte initiale remonte au 4 août 2026, lorsque TRU a…
📖 cyberveille : https://cyberveille.ch/posts/2026-09-17-red-heron-exploite-cve-2026-60004-dans-gitea-pour-deployer-un-rootkit-linux-inedit/
🌐 source : https://www.acronis.com/en/tru/posts/red-heron-exploits-gitea-n-day-flaw-in-multinational-campaign-exposing-new-linux-rootkit/
🟢 vérification factuelle haute
#RedHeron #RootkitLinux #Cyberveille
Acronis TRU uncovered a multinational campaign in which Red Heron, a Chinese-speaking threat actor, rapidly weaponized CVE-2026-60004 to compromise internet-facing instances of Gitea, a self-hosted source-code management platform. https://www.acronis.com/en/tru/posts/red-heron-exploits-gitea-n-day-flaw-in-multinational-campaign-exposing-new-linux-rootkit/
##updated 2026-08-24T18:32:30
2 posts
bison (2:3.8.2+dfsg-1ubuntu0.24.04.1)
CVE-2026-56389へのセキュリティ対応。
セキュリティ対応なのでお早めに。
##bison (2:3.8.2+dfsg-1ubuntu0.24.04.1)
CVE-2026-56389へのセキュリティ対応。
セキュリティ対応なのでお早めに。
##updated 2026-08-19T04:17:24.940000
2 posts
2 repos
Discover how ransomware gangs actively exploit the critical VMware vCenter flaw, CVE-2026-59310. Learn about the swift weaponization and severe infrastructure risks.
##Discover how ransomware gangs actively exploit the critical VMware vCenter flaw, CVE-2026-59310. Learn about the swift weaponization and severe infrastructure risks.
##updated 2026-08-13T21:37:11
1 posts
aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3
perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38
sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0
セキュリティ対応なのでお早めに。
##updated 2026-08-06T09:30:40
4 posts
1 repos
WSO2 Warns of Active Exploitation Targeting Critical Authentication Bypass
WSO2 is warning of active exploitation of a critical authentication bypass vulnerability (CVE-2026-5430) that allows attackers to take over administrative accounts and steal sensitive API credentials. The flaw affects multiple middleware products and has been targeted in the wild since mid-September 2026.
**If you run WSO2 API Manager, API Control Plane, Traffic Manager, or Universal Gateway, check for affected versions and patch immediately to the latest update level from WSO2. If you are using open source version apply the public GitHub fix. Attackers are already using forged tokens to gain full admin access.
After patching, assume your secrets were exposed and rotate all API keys, backend credentials, consumer keys, and application secrets, and check your logs for suspicious access since September 13, 2026.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/wso2-warns-of-active-exploitation-targeting-critical-authentication-bypass-6-5-6-k-k/gD2P6Ple2L
WSO2 Warns of Active Exploitation Targeting Critical Authentication Bypass
WSO2 is warning of active exploitation of a critical authentication bypass vulnerability (CVE-2026-5430) that allows attackers to take over administrative accounts and steal sensitive API credentials. The flaw affects multiple middleware products and has been targeted in the wild since mid-September 2026.
**If you run WSO2 API Manager, API Control Plane, Traffic Manager, or Universal Gateway, check for affected versions and patch immediately to the latest update level from WSO2. If you are using open source version apply the public GitHub fix. Attackers are already using forged tokens to gain full admin access.
After patching, assume your secrets were exposed and rotate all API keys, backend credentials, consumer keys, and application secrets, and check your logs for suspicious access since September 13, 2026.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/wso2-warns-of-active-exploitation-targeting-critical-authentication-bypass-6-5-6-k-k/gD2P6Ple2L
The prosecution notes that your API interception layer, by design, sits squarely between attackers and internal systems, creating what the record describes as "Lateral Movement-as-a-Service." Administrative accounts, sensitive data in transit — all fair game.
Sentencing is immediate. Apply the April patch for CVE-2026-5430 and audit your JWT token validation and administrative account access without further delay. (2/3)
##🏆 New Achievement! The Honorable CVE-2026-5430 Finds You Guilty!
The court has reviewed the evidence. WSO2 API Manager, you stand charged with allowing JWT authentication to be bypassed via an unsupported signing algorithm — a flaw patched in April that threat actors are now actively exploiting in the wild. WatchTowr delivered the indictment on Tuesday. (1/3)
##updated 2026-08-04T18:31:31
1 posts
[Django Fellow Reports] Django Fellow Report - Jacob
Jacob reviewed six Django pull requests and authored changes covering GEOS 3.10 support removal and expanded WKT depth-check coverage related to CVE-2026-15830.
https://forum.djangoproject.com/t/django-fellow-report-jacob-2026/43851/39
updated 2026-08-04T06:32:37
2 posts
Mitsubishi Electric CC-Link IE TSN is affected by CVE-2026-13584, CWE-924 message integrity failure. An adjacent attacker can inject crafted packets under timing conditions to tamper with OT traffic. It matters for ICS integrity and safety assumptions on trusted segments. #IcsSecurity #OtSecurity #MessageIntegrity
https://cyberworldops.eu/en/mitsubishi-protocol-flaw-exposes-industrial-control-traffic-to-on
##Mitsubishi Electric CC-Link IE TSN is affected by CVE-2026-13584, CWE-924 message integrity failure. An adjacent attacker can inject crafted packets under timing conditions to tamper with OT traffic. It matters for ICS integrity and safety assumptions on trusted segments. #IcsSecurity #OtSecurity #MessageIntegrity
https://cyberworldops.eu/en/mitsubishi-protocol-flaw-exposes-industrial-control-traffic-to-on
##updated 2026-07-01T21:35:53
1 posts
2 repos
CVE-2026-45659: SharePoint Authenticated Deserialization RCE
#CVE_2026_45659
https://blog.securelayer7.net/cve-2026-45659-sharepoint-deserialization-rce/
updated 2026-06-26T21:32:44
1 posts
Say that new authelia exploit looks like one fail2ban already recognises or relies on timing/brute-force then you’re covered even before a patch is available.
Here’s a real authelia vuln:
https://app.opencve.io/cve/CVE-2026-47203
allowing an attacker to circumvent login throttling or account lockouts by simply altering the case of their credentials.
I think fail2ban would help protect authelia here?
##updated 2026-06-24T17:25:29
1 posts
OpenAM <16.1.1 suffers from CRITICAL deserialization vuln (CVE-2026-45051, CVSS 9.2). WebAuthnAuthentication lets attackers run arbitrary code via crafted serialized data. Patch to 16.1.1 ASAP! https://radar.offseq.com/threat/cve-2026-45051-cwe-502-deserialization-of-untrusted-data-in-openidentityplatform-openam-946ad921c23871b6 #OffSeq #CVE202645051 #OpenAM #infosec
##updated 2026-06-18T15:32:09
2 posts
🔄 CSAF advisory updated (version 3.0.0)
VDE-2026-051
iba: Deserialization vulnerability in ibaPDA and ibaDatCoordinator
CVE-2026-8024
Changes: Corrected all CPE numbers and vendor name of all products.
HTML: https://certvde.com/en/advisories/VDE-2026-051
CSAF JSON: https://iba.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-051.json
🔄 CSAF advisory updated (version 3.0.0)
VDE-2026-051
iba: Deserialization vulnerability in ibaPDA and ibaDatCoordinator
CVE-2026-8024
Changes: Corrected all CPE numbers and vendor name of all products.
HTML: https://certvde.com/en/advisories/VDE-2026-051
CSAF JSON: https://iba.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-051.json
updated 2026-06-17T10:42:51.460000
1 posts
25 repos
https://github.com/HORKimhab/CVE-2026-39987
https://github.com/MADA0L/CVE-2026-39987-Poc
https://github.com/dodeepsink/CVE-2026-39987.py
https://github.com/alreadyClosed/CVE-2026-39987
https://github.com/Nxploited/CVE-2026-39987
https://github.com/vanhari/CVE-2026-39987
https://github.com/keraattin/CVE-2026-39987
https://github.com/Ghxstsec/CVE-2026-39987
https://github.com/h3raklez/CVE-2026-39987
https://github.com/jasonbernier/CVE-2026-39987
https://github.com/M3PH1569/CVE-2026-39987-POC
https://github.com/rootdirective-sec/CVE-2026-39987-Lab
https://github.com/fevar54/marimo_CVE-2026-39987_RCE_PoC
https://github.com/matesz44/cve-2026-39987
https://github.com/0xBlackash/CVE-2026-39987
https://github.com/iapetus12/cohort-htb
https://github.com/Clara-M-Grossl/Exploit-Marimo
https://github.com/K3ysTr0K3R/CVE-2026-39987
https://github.com/julichaan/CVE-2026-39987_POC
https://github.com/stapat1245/CVE-2026-39987-PoC
https://github.com/Dhiaelhak-Rached/CVE-2026-39987-lab-or-marimo-cve-lab
https://github.com/0xdeadroot/CVE-2026-39987-marimo-rce
https://github.com/mki9/CVE-2026-39987_exploit
Sysdig reports a human operator exploited CVE-2026-39987, a pre-auth RCE in Marimo, and pivoted from the notebook to an SSH bastion in eight seconds with a custom Python toolkit. It shows manual tradecraft can match automation speed, shrinking detection windows for exposed dev infrastructure. #MarimoRce #SshBastion #IncidentResponse
https://cyberworldops.eu/en/human-operator-exploits-marimo-rce-and-reaches-ssh-bastion-in-eight
##updated 2026-06-02T21:30:39
1 posts
3 repos
https://github.com/fevar54/CVE-2025-48595-Android-Framework-Integer-Overflow-
https://github.com/XiaoBaiLovesStirring/CVE-2025-48595-Exploit
@GrapheneOS funny to see google fixing : CVE-2025-48595 that was fixed looooooong ago in your.
i don't see CVE-2026-58704, is it already fixed ?
##updated 2026-03-23T15:31:40
7 posts
8 repos
https://github.com/danindiana/cve-2026-32746-mitigation
https://github.com/chosenonehacks/CVE-2026-32746
https://github.com/MonkeySeC-sys/Kangaroo
https://github.com/ekomsSavior/telnet_scan
https://github.com/watchtowrlabs/watchtowr-vs-telnetd-CVE-2026-32746
https://github.com/duduLiu8787/CVE-2026-32746-Exploit
A 32-year-old bug walks into a Telnet server
Link: https://labs.watchtowr.com/a-32-year-old-bug-walks-into-a-telnet-server-gnu-inetutils-telnetd-cve-2026-32746/
Discussion: https://news.ycombinator.com/item?id=49721291
A 32-year-old bug walks into a Telnet server - https://labs.watchtowr.com/a-32-year-old-bug-walks-into-a-telnet-server-gnu-inetutils-telnetd-cve-2026-32746/
##😂 Oh, look, a bug older than some of you on this site! GNU #inetutils just realized their #Telnet server had a 32-year-old #exploit hiding like a dusty family heirloom. Who knew pre-auth RCE could double as a boomer joke? 🧐🔍
https://labs.watchtowr.com/a-32-year-old-bug-walks-into-a-telnet-server-gnu-inetutils-telnetd-cve-2026-32746/ #bugreport #cybersecurity #humor #technews #HackerNews #ngated
A 32-year-old bug walks into a Telnet server
Comments: https://news.ycombinator.com/item?id=49721291
#HackerNews #bugfix #cybersecurity #Telnet #server #technology #vulnerabilities #GNU #inetutils
##A 32-year-old bug walks into a Telnet server
Link: https://labs.watchtowr.com/a-32-year-old-bug-walks-into-a-telnet-server-gnu-inetutils-telnetd-cve-2026-32746/
Discussion: https://news.ycombinator.com/item?id=49721291
😂 Oh, look, a bug older than some of you on this site! GNU #inetutils just realized their #Telnet server had a 32-year-old #exploit hiding like a dusty family heirloom. Who knew pre-auth RCE could double as a boomer joke? 🧐🔍
https://labs.watchtowr.com/a-32-year-old-bug-walks-into-a-telnet-server-gnu-inetutils-telnetd-cve-2026-32746/ #bugreport #cybersecurity #humor #technews #HackerNews #ngated
A 32-year-old bug walks into a Telnet server
Comments: https://news.ycombinator.com/item?id=49721291
#HackerNews #bugfix #cybersecurity #Telnet #server #technology #vulnerabilities #GNU #inetutils
##updated 2026-03-19T06:30:33
2 posts
2 repos
Attackers are actively exploiting CVE-2026-27540 in the WooCommerce Wholesale Lead Capture WordPress plugin to upload PHP web shells without authentication. The flaw affects a plugin with more than 6,000 active installations and can enable remote code execution. #WordPressSecurity #VulnerabilityManagement #ThreatDetection
https://cyberworldops.eu/en/attackers-exploit-woocommerce-plugin-flaw-to-install-php-web-shells
##🏆 New Achievement! Exceeded All KPIs Except Staying Uncompromised!
Your Q3 infrastructure review is in. Uptime: stellar. Deployment pipeline: smooth. WooCommerce Wholesale Lead Capture plugin: actively backdoored via CVE-2026-27540. That last one is what we in management call an "opportunity area."
Attackers are currently exploiting this critical flaw in the wild, planting PHP backdoors and achieving full takeover of WordPress stores. Everything was going so well, team. Really. (1/3)
##updated 2024-10-30T21:30:36
1 posts
Using acme.sh to renew a certificate as root sounds like a RCE-as-root waiting to happen. A Web client written in pure shell, what could possibly go wrong? I just wrote a script to drop its own privilege when it calls acme.sh, so it's safe to use in a root cronjob.
After writing this, I found RCE-as-root is not just "waiting" to happen, it has already happened as CVE-2023-38198. Someone even argued the case as a possible mechanism responsible for the jabber.ru wiretapping incident. https://remyhax.xyz/posts/reproducing-lawful-tls-wiretapping/
updated 2024-10-23T18:33:16
1 posts
Nice of Cisco to finally publish CVE-2024-20260 now that we're almost in 3Q2026.
##🟠 CVE-2026-54520 - High (8.1)
AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.path value...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54520/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-54520 - High (8.1)
AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.path value...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54520/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-54670 - Critical (9.1)
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and metodo values without a complete controller and meth...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54670/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-54670 - Critical (9.1)
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and metodo values without a complete controller and meth...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54670/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-54767 - Critical (9.1)
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded chave_correta value embedded...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54767/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-54767 - Critical (9.1)
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded chave_correta value embedded...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54767/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-54671 - High (8.8)
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource array in web/controle/control.php, and verificarPermissao in web/dao/MiddlewareDAO.php treats that empty array as unconditional acc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54671/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-54671 - High (8.8)
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource array in web/controle/control.php, and verificarPermissao in web/dao/MiddlewareDAO.php treats that empty array as unconditional acc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54671/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93426 - High (8.5)
SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or higher can embed backticks and quotes in field names ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93426/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93426 - High (8.5)
SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or higher can embed backticks and quotes in field names ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93426/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-54752 - Critical (9.6)
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the read_pickle_d...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54752/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-54752 - Critical (9.6)
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the read_pickle_d...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54752/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-54716 - High (7.5)
Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earlier, a POST request to /sources_to_targets containing an exclude_polygons ring formed by three collinear points can cause unboun...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54716/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-54716 - High (7.5)
Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earlier, a POST request to /sources_to_targets containing an exclude_polygons ring formed by three collinear points can cause unboun...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54716/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-54692 - High (7.8)
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to 1.0.0, sail_codec_load_frame_v8_xbm() in src/sail-codecs/xbm/xbm.c allocates the decoded pixel buffer using the X11 one...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54692/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-54692 - High (7.8)
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to 1.0.0, sail_codec_load_frame_v8_xbm() in src/sail-codecs/xbm/xbm.c allocates the decoded pixel buffer using the X11 one...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54692/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-92943 - High (8.1)
Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might allow an adversary-in-the-middle actor to impersonate the AWS IoT Core...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92943/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-92943 - High (8.1)
Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might allow an adversary-in-the-middle actor to impersonate the AWS IoT Core...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92943/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93337 - High (7.8)
NetworkManager-l2tp contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd directives by supplying mru or mtu property values containing trailing non-numeric co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93337/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93337 - High (7.8)
NetworkManager-l2tp contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd directives by supplying mru or mtu property values containing trailing non-numeric co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93337/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-85500: team-alembic ash_authentication (4.3.8 – 4.15.0, 5.0.0-rc.14) suffers a CRITICAL auth bypass — unconfirmed users may gain sessions, defeating email confirmation. Patch urgently. https://radar.offseq.com/threat/cve-2026-85500-cwe-305-authentication-bypass-by-primary-weakness-in-team-alembic-ashauthentication-cb315bb57ae7fd92 #OffSeq #Vuln #CVE202685500 #AshAuthentication
##CVE-2026-85500: team-alembic ash_authentication (4.3.8 – 4.15.0, 5.0.0-rc.14) suffers a CRITICAL auth bypass — unconfirmed users may gain sessions, defeating email confirmation. Patch urgently. https://radar.offseq.com/threat/cve-2026-85500-cwe-305-authentication-bypass-by-primary-weakness-in-team-alembic-ashauthentication-cb315bb57ae7fd92 #OffSeq #Vuln #CVE202685500 #AshAuthentication
##VMware łata poważne błędy w Workstation i Fusion. Można wyskoczyć z maszyny wirtualnej i wykonać kod na hoście
Broadcom poinformował o załataniu dwóch poważnych błędów w popularnych produktach VMware Workstation oraz VMware Fusion. W określonych warunkach ich wykorzystanie mogło doprowadzić do ucieczki z maszyny wirtualnej oraz wykonanie kodu bezpośrednio na hoście. TLDR: Podatności otrzymały identyfikatory CVE-2026-59346 (CVSS 9.3) oraz CVE-2026-59347 (CVSS 8.1). Pierwsza z nich to błąd typu...
##VMware łata poważne błędy w Workstation i Fusion. Można wyskoczyć z maszyny wirtualnej i wykonać kod na hoście
Broadcom poinformował o załataniu dwóch poważnych błędów w popularnych produktach VMware Workstation oraz VMware Fusion. W określonych warunkach ich wykorzystanie mogło doprowadzić do ucieczki z maszyny wirtualnej oraz wykonanie kodu bezpośrednio na hoście. TLDR: Podatności otrzymały identyfikatory CVE-2026-59346 (CVSS 9.3) oraz CVE-2026-59347 (CVSS 8.1). Pierwsza z nich to błąd typu...
##VMware łata poważne błędy w Workstation i Fusion. Można wyskoczyć z maszyny wirtualnej i wykonać kod na hoście
Broadcom poinformował o załataniu dwóch poważnych błędów w popularnych produktach VMware Workstation oraz VMware Fusion. W określonych warunkach ich wykorzystanie mogło doprowadzić do ucieczki z maszyny wirtualnej oraz wykonanie kodu bezpośrednio na hoście. TLDR: Podatności otrzymały identyfikatory CVE-2026-59346 (CVSS 9.3) oraz CVE-2026-59347 (CVSS 8.1). Pierwsza z nich to błąd typu...
##VMware łata poważne błędy w Workstation i Fusion. Można wyskoczyć z maszyny wirtualnej i wykonać kod na hoście
Broadcom poinformował o załataniu dwóch poważnych błędów w popularnych produktach VMware Workstation oraz VMware Fusion. W określonych warunkach ich wykorzystanie mogło doprowadzić do ucieczki z maszyny wirtualnej oraz wykonanie kodu bezpośrednio na hoście. TLDR: Podatności otrzymały identyfikatory CVE-2026-59346 (CVSS 9.3) oraz CVE-2026-59347 (CVSS 8.1). Pierwsza z nich to błąd typu...
##🟠 CVE-2026-78428 - High (8)
For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78428/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-78428 - High (8)
For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78428/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##A critical proxy-addr IP spoofing flaw (CVE-2026-90711) exposes Node.js apps to access control bypasses. Patch this proxy-addr IP spoofing bug today.
##Multiple critical Squid proxy vulnerabilities, including CVE-2026-61642, allow request smuggling and buffer overflows. Patch your servers immediately.
#SquidProxy #CVE202661642 #Cybersecurity #Vulnerability #InfoSec
##krb5 (1.20.1-6ubuntu2.10)
セキュリティ対応ではない。
krb5-locales
libgssapi-krb5-2
libk5crypto3
libkrb5-3
libkrb5support0
netplan.io (1.1.2-8ubuntu1~24.04.3)
セキュリティ対応ではない。
libnetplan1
netplan-generator
python3-netplan
policykit-1 (124-2ubuntu1.24.04.4)
CVE-2026-85498へのセキュリティ対応。
libpolkit-agent-1-0
libpolkit-gobject-1-0
libsrt1.5-gnutls
polkitd
セキュリティ対応もあるので、お早めに。
##🟠 CVE-2026-57586 - High (8.6)
CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the default agent-coderag sync flow in code_rag/entry/cli.py calls sync_dependencies for an indexed path, and code_rag/core/manager.py tre...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57586/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##