## Updated at UTC 2026-09-04T00:34:42.153504

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-85455 8.2 0.00% 2 0 2026-09-03T23:17:25.803000 MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOS
CVE-2026-85452 8.8 0.00% 2 0 2026-09-03T23:17:25.330000 MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTa
CVE-2026-85450 7.5 0.00% 2 0 2026-09-03T23:17:25.043000 MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the
CVE-2026-85224 9.1 0.00% 2 0 2026-09-03T22:18:24.260000 A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affec
CVE-2026-64200 7.8 0.00% 2 0 2026-09-03T22:18:10.463000 There is an out-of-bounds read vulnerability in DASYLab due to improper validati
CVE-2026-64199 7.8 0.00% 2 0 2026-09-03T22:18:10.337000 There is an out-of-bounds read vulnerability in DASYLab due to improper validati
CVE-2026-64198 7.8 0.00% 2 0 2026-09-03T22:18:10.207000 There is an out-of-bounds read vulnerability in DASYLab due to improper validati
CVE-2026-64197 7.8 0.00% 2 0 2026-09-03T22:18:10.073000 There is an out-of-bounds write vulnerability in DASYLab due to improper validat
CVE-2026-17615 7.5 0.28% 1 0 2026-09-03T21:32:21 A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unau
CVE-2026-85046 8.8 0.00% 2 0 2026-09-03T21:31:20 Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote at
CVE-2026-85388 8.1 0.00% 2 0 2026-09-03T21:31:20 Worklenz through 3.0.0 fails to properly validate the sort-field query parameter
CVE-2026-85396 7.5 0.00% 2 0 2026-09-03T21:31:20 rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Ent
CVE-2026-85393 7.5 0.00% 2 0 2026-09-03T21:31:20 node-forge through 1.4.0 fails to validate element count in nested DigestAlgorit
CVE-2026-85394 9.1 0.00% 2 0 2026-09-03T21:31:16 python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC ini
CVE-2026-85391 9.8 0.00% 2 0 2026-09-03T21:31:15 Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compo
CVE-2026-85028 7.8 0.00% 2 0 2026-09-03T21:31:15 Creation of a temporary file in a directory with insecure permissions in the FPG
CVE-2026-82404 8.3 0.40% 1 0 2026-09-03T19:52:09 ### Summary Decoding attacker-controlled TOON containing a `__proto__`, `constr
CVE-2026-12554 None 0.21% 1 0 2026-09-03T18:32:33 Potential security vulnerabilities have been identified in HP Easy Start for mac
CVE-2026-83959 7.8 0.00% 2 0 2026-09-03T18:31:58 Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability
CVE-2026-12555 None 0.23% 1 0 2026-09-03T18:31:29 Potential security vulnerabilities have been identified in HP Easy Start for mac
CVE-2026-84292 7.5 0.23% 1 0 2026-09-03T18:11:49.487000 fast-uri serializes the port component of a URI without validating it. When reco
CVE-2026-80047 7.8 0.11% 1 0 2026-09-03T17:53:32.027000 A vulnerability in Hugging Face Transformers (versions >= 4.49.0 and <= 5.8.1) a
CVE-2026-78319 0 0.40% 2 0 2026-09-03T16:57:26.583000 A service running on the affected products contains a potential Time-of-Check Ti
CVE-2026-20277 8.2 0.22% 1 0 2026-09-03T16:37:52.170000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-84353 9.6 0.28% 1 0 2026-09-03T16:37:52.170000 Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.
CVE-2026-12556 0 0.15% 1 0 2026-09-03T16:17:23.523000 Potential security vulnerabilities have been identified in HP Easy Start for mac
CVE-2026-48710 6.5 11.04% 6 5 template 2026-09-03T15:39:44.470000 Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the H
CVE-2026-66786 9.1 0.74% 1 0 2026-09-03T15:33:10 A flaw was found in submariner. In cert-auth mode, the connection configuration
CVE-2023-54391 9.8 0.46% 1 2 2026-09-03T15:33:10 Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypa
CVE-2026-85216 None 0.00% 2 0 2026-09-03T15:32:35 MISP contains an authentication bypass vulnerability in its LDAP and LinOTP auth
CVE-2026-85174 8.8 0.00% 2 0 2026-09-03T15:32:28 SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an ac
CVE-2026-85154 9.8 0.00% 2 0 2026-09-03T15:32:19 WWBN AVideo contains an authentication failure vulnerability where the video_id_
CVE-2026-85175 8.8 0.00% 2 0 2026-09-03T13:06:25.270000 SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in th
CVE-2026-83549 7.8 1.62% 13 0 2026-09-03T13:06:16.230000 Post-authentication Improper Neutralization of Special Elements used in an OS Co
CVE-2026-83548 10.0 0.71% 14 1 2026-09-03T13:06:16.053000 A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Pla
CVE-2026-78689 8.1 0.41% 1 0 2026-09-03T13:06:10.270000 Description NGINX JavaScript (njs) has a vulnerability in the XML module's nam
CVE-2026-75604 9.0 0.82% 1 4 2026-09-03T13:06:07.577000 Next.js is a React framework for building full-stack web applications. From 13.4
CVE-2026-73782 8.8 0.27% 1 0 2026-09-03T13:06:07.180000 A format string vulnerability exists in the command line interface of AOS-CX tha
CVE-2026-59822 8.2 0.87% 6 1 2026-09-03T13:05:59.573000 LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) fo
CVE-2026-9586 9.8 11.85% 8 1 template 2026-09-02T21:32:54 An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB E
CVE-2026-19117 9.8 0.28% 2 0 2026-09-02T21:32:07 Under specific conditions, an attacker can register an attacker-controlled FIDO2
CVE-2026-84372 9.8 0.41% 1 0 2026-09-02T20:17:40.793000 Predis is a flexible and feature-complete Redis and Valkey client for PHP. From
CVE-2026-73773 7.5 0.26% 1 0 2026-09-02T19:34:36.770000 An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpo
CVE-2026-52833 8.0 0.33% 1 0 2026-09-02T19:17:21.110000 Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Pri
CVE-2026-49832 8.0 0.54% 1 0 2026-09-02T19:17:19.197000 DSpace open source software is a repository application which provides durable a
CVE-2026-20280 8.8 0.27% 1 0 2026-09-02T18:32:32 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20275 8.8 0.18% 1 0 2026-09-02T18:32:32 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20276 8.6 0.25% 1 0 2026-09-02T18:32:31 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20274 9.8 0.67% 1 0 2026-09-02T18:32:31 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20212 9.8 0.53% 9 1 2026-09-02T18:32:26 A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switc
CVE-2026-82329 9.8 7.67% 11 5 template 2026-09-02T18:31:57 JFrog Artifactory contains an authentication weakness that, under default config
CVE-2026-53649 9.6 0.21% 1 0 2026-09-02T18:19:59.973000 Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default pro
CVE-2026-84700 8.6 0.35% 1 0 2026-09-02T16:17:32.577000 PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port
CVE-2026-84375 7.5 0.39% 1 0 2026-09-02T16:17:28.813000 js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.
CVE-2026-73749 9.8 0.49% 4 0 2026-09-02T15:34:36 Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper
CVE-2026-76657 10.0 0.43% 1 0 2026-09-02T15:14:09.307000 Vulnerabilities have been identified in the API of HPE Networking Fabric Compose
CVE-2026-84795 9.8 0.28% 1 0 2026-09-02T14:17:17.193000 Craft CMS before 5.10.11 fails to validate the admin flag during user registrati
CVE-2026-84485 7.5 0.35% 1 0 2026-09-02T11:17:25.947000 APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch en
CVE-2026-14828 8.8 1.44% 1 0 2026-09-02T09:31:34 Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 version
CVE-2026-78657 9.8 0.72% 1 0 2026-09-02T06:31:26 The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to ar
CVE-2026-9055 9.8 0.29% 1 1 2026-09-02T06:31:24 The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for W
CVE-2026-14357 8.8 0.65% 1 0 2026-09-02T06:31:24 The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in ve
CVE-2025-46418 7.6 0.68% 1 0 2026-09-02T06:31:19 Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media def
CVE-2026-82393 7.5 0.41% 1 0 2026-09-02T04:18:02.693000 pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped p
CVE-2026-84699 9.1 0.37% 1 0 2026-09-02T03:31:17 Team Password Manager before 14.184.308 fails to enforce authentication requirem
CVE-2026-84715 8.8 0.32% 1 0 2026-09-02T03:31:17 FeatherPanel versions before 1.3.7.10 fail to validate permissions in the Subuse
CVE-2026-14982 8.1 0.52% 1 0 2026-09-02T03:31:14 The WP File Download plugin for WordPress is vulnerable to arbitrary file deleti
CVE-2026-14957 7.5 0.56% 1 0 2026-09-02T03:31:14 In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKe
CVE-2026-84702 7.5 0.38% 1 0 2026-09-02T03:31:13 facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name
CVE-2026-84484 7.5 0.48% 1 0 2026-09-02T02:17:20.450000 ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the
CVE-2026-84374 7.5 0.57% 1 0 2026-09-01T22:17:19.293000 Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3
CVE-2026-76658 10.0 0.43% 1 0 2026-09-01T21:31:59 A vulnerability has been identified in the SSH daemon of HPE Networking Fabric C
CVE-2026-19952 7.5 0.78% 1 0 2026-09-01T20:47:54.130000 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary
CVE-2026-82908 8.8 0.12% 1 0 2026-09-01T20:47:54.130000 A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this
CVE-2026-84202 8.8 0.37% 1 0 2026-09-01T18:30:49 ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files,
CVE-2026-84268 8.8 0.33% 1 0 2026-09-01T18:30:49 A flaw was found in the SFTP backend in gvfs. When mounting a share and reading
CVE-2026-58566 8.8 0.23% 1 0 2026-09-01T18:30:49 Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged atta
CVE-2026-84199 7.7 0.26% 1 0 2026-09-01T16:17:33.853000 Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerabilit
CVE-2026-84115 8.3 0.28% 3 0 2026-09-01T15:31:23 A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element i
CVE-2026-62911 8.0 1.32% 4 1 2026-09-01T15:30:53 Authentication bypass by capture-replay in Microsoft Exchange Server allows an a
CVE-2026-84196 7.7 0.26% 1 0 2026-09-01T12:31:56 Kyverno before 1.18.0 contains a server-side request forgery vulnerability in ap
CVE-2026-84195 7.7 0.29% 1 0 2026-09-01T12:31:56 Kyverno before 1.16.4 automatically attaches the admission controller's ServiceA
CVE-2026-19806 8.8 0.40% 1 0 2026-09-01T06:33:01 The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Tick
CVE-2026-83772 9.9 1.69% 1 0 2026-09-01T06:33:01 A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router
CVE-2026-75865 9.8 0.51% 1 0 2026-09-01T03:31:10 The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Go
CVE-2026-67394 None 1.17% 1 0 2026-09-01T03:31:09 A critical local privilege escalation via OS command injection vulnerability has
CVE-2026-82954 9.9 0.62% 1 0 2026-09-01T00:31:43 A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the fun
CVE-2026-82882 8.8 0.31% 1 0 2026-09-01T00:31:42 Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestr
CVE-2026-83596 8.8 0.29% 1 0 2026-08-31T21:32:23 A flaw was found in WebKitGTK. Processing malicious web content can cause memory
CVE-2026-82226 9.8 0.31% 1 0 2026-08-31T21:32:22 Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.
CVE-2026-81578 9.8 0.77% 6 2 2026-08-31T21:31:56 An improper access control vulnerability exists in the web management interface
CVE-2026-82078 9.1 0.93% 8 2 2026-08-31T21:31:56 An unsafe dynamic class loading vulnerability exists in the database connection
CVE-2026-81934 9.8 0.43% 2 0 2026-08-31T21:31:55 Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' f
CVE-2026-79748 9.9 0.33% 1 0 2026-08-31T19:17:13.667000 MCPHub is a unified hub for centrally managing and dynamically orchestrating mul
CVE-2026-83492 None 0.24% 1 0 2026-08-31T18:31:39 Improper input validation vulnerability in Extend Themes Kubio AI Website Builde
CVE-2026-6876 None 0.40% 1 0 2026-08-28T21:32:13 ServiceNow has remediated a sandbox escape security issue that was identified in
CVE-2026-66147 9.4 2.00% 1 0 2026-08-28T18:58:27.140000 An unauthenticated command injection vulnerability was identified in the GMS Dis
CVE-2026-71362 9.1 25.14% 1 1 template 2026-08-28T00:18:09.390000 Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul
CVE-2023-49105 9.8 43.20% 1 1 template 2026-08-27T21:32:08 An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker ca
CVE-2026-60004 9.8 86.78% 1 9 template 2026-08-27T11:41:19.230000 Gitea before 1.27.1 allows remote code execution via the diffpatch API through G
CVE-2026-19949 8.8 0.54% 4 1 2026-08-25T12:31:24 The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL
CVE-2026-68162 7.8 0.18% 1 0 2026-08-23T13:16:34.493000 In the Linux kernel, the following vulnerability has been resolved: sctp: avoid
CVE-2026-68766 7.8 0.16% 1 0 2026-08-22T15:31:11 hashcat fails to restrict command-line options when parsing restore files, allow
CVE-2026-73570 8.9 32.38% 1 6 2026-08-21T18:34:48 A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) befor
CVE-2026-64849 9.3 16.41% 1 3 template 2026-08-20T19:16:57.867000 MLflow is an open source AI engineering platform for agents, large language mode
CVE-2026-32475 9.0 2.37% 5 4 template 2026-08-19T18:32:57 Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Eleme
CVE-2026-65400 7.1 9.90% 1 3 2026-08-18T18:31:47 An authentication issue was addressed with improved state management. This issue
CVE-2026-58231 10.0 1.71% 1 3 2026-08-17T15:39:24.573000 SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authent
CVE-2026-73296 9.4 2.61% 1 1 2026-08-13T15:20:13.333000 Microsoft UFO open-source framework for intelligent automation across devices an
CVE-2026-18634 8.4 0.22% 1 0 2026-08-12T18:31:15 An insecure handling of serialized objects vulnerability was found in the one of
CVE-2026-66154 8.3 0.13% 1 0 2026-08-12T00:31:10 An insufficient certificate validation in a privileged communication workflow, w
CVE-2026-48376 5.4 13.92% 1 0 2026-08-11T18:31:03 is affected by an Improper Encoding or Escaping of Output vulnerability that cou
CVE-2026-15733 9.8 13.54% 1 0 template 2026-08-07T18:31:37 A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 a
CVE-2026-63077 9.8 87.71% 1 4 template 2026-08-05T18:32:31 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe
CVE-2026-18577 8.1 54.07% 1 2 template 2026-08-04T15:33:20 An incomplete patch for CVE-2026-18556 allows for authentication bypass and acco
CVE-2026-66066 None 27.86% 1 7 2026-07-30T18:23:34 ### Impact In its default configuration, a Rails application that displays image
CVE-2026-43748 9.8 0.49% 1 0 2026-07-28T18:33:55 An out-of-bounds write issue was addressed with improved bounds checking. This i
CVE-2026-61884 9.8 0.66% 2 0 2026-07-25T00:31:53 The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perf
CVE-2026-55985 4.3 0.15% 2 0 2026-07-25T00:31:48 The web management interface in  Tycon Systems TPDIN-Monitor-WEB2 stores and di
CVE-2025-21913 5.5 0.20% 1 0 2026-07-14T13:17:26.703000 In the Linux kernel, the following vulnerability has been resolved: x86/amd_nb:
CVE-2026-6875 None 77.58% 1 3 template 2026-07-13T21:31:30 ServiceNow has addressed a remote code execution vulnerability that was identifi
CVE-2026-52831 10.0 0.32% 1 0 2026-07-08T20:24:21 ## Summary Nuclio controller builds a `curl` invocation string for each cron tr
CVE-2026-8024 9.8 0.55% 1 0 2026-06-22T17:47:16.070000 A remote, unauthenticated attacker may exploit a deserialization of untrusted da
CVE-2026-0768 9.8 2.26% 4 2 2026-06-17T10:11:20.937000 Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerabi
CVE-2021-42260 7.5 3.35% 1 1 2026-06-17T04:09:31.687000 TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxml
CVE-2021-31886 9.8 3.05% 1 0 2026-06-17T03:52:25.290000 A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions),
CVE-2026-45730 8.3 0.26% 1 0 2026-06-04T15:05:58 This vulnerability exists in Nuclio Dashboard's project management API, allowing
CVE-2026-35029 None 25.07% 1 1 template 2026-05-06T18:40:48 ### Impact The `/config/update endpoint` does not enforce admin role authorizat
CVE-2025-9709 None 0.23% 1 0 2025-09-05T18:31:39 On-Chip Debug and Test Interface With Improper Access Control and Improper Prote
CVE-2017-5123 8.8 3.71% 1 8 2023-01-30T05:03:17 Insufficient data validation in waitid allowed an user to escape sandboxes on Li
CVE-2026-85223 0 0.00% 2 0 N/A
CVE-2026-59347 0 0.00% 2 0 N/A
CVE-2026-59346 0 0.00% 3 0 N/A
CVE-2026-58400 0 0.00% 2 0 N/A
CVE-2026-85012 0 0.00% 2 0 N/A
CVE-2026-49869 0 1.92% 6 1 N/A
CVE-2026-73299 0 1.21% 2 0 N/A
CVE-2026-53635 0 0.22% 1 0 N/A
CVE-2026-84394 0 0.22% 1 0 N/A
CVE-2026-84851 0 0.34% 1 0 N/A
CVE-2026-84382 0 0.35% 1 0 N/A
CVE-2026-84381 0 0.08% 1 0 N/A
CVE-2026-55221 0 0.27% 1 0 N/A
CVE-2026-79755 0 0.40% 1 0 N/A
CVE-2026-84370 0 0.34% 1 0 N/A
CVE-2026-64638 0 31.20% 1 26 template N/A
CVE-2026-72898 0 82.32% 1 8 template N/A
CVE-2026-79750 0 0.25% 1 0 N/A
CVE-2026-79746 0 0.25% 1 0 N/A

CVE-2026-85455
(8.2 HIGH)

EPSS: 0.00%

updated 2026-09-03T23:17:25.803000

2 posts

MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory access during deserialization. Attackers can open a TCP connection to the MOOSDB port and send a crafted short packet to read memory before authentication.

thehackerwire@mastodon.social at 2026-09-04T00:00:32.000Z ##

🟠 CVE-2026-85455 - High (8.2)

MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory access during deserialization. Attackers can open a TCP connection to the MOOSDB port and send a crafted...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T00:00:32.000Z ##

🟠 CVE-2026-85455 - High (8.2)

MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory access during deserialization. Attackers can open a TCP connection to the MOOSDB port and send a crafted...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85452
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-03T23:17:25.330000

2 posts

MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and variable names are formatted into fixed 1024-byte buffers using sprintf without length validation. Attackers can supply arbitrarily long MOOS identifiers that overflow the buffers when an operator selects process list entries or pokes variables, enabling code execution.

thehackerwire@mastodon.social at 2026-09-04T00:00:21.000Z ##

🟠 CVE-2026-85452 - High (8.8)

MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and variable names are formatted into fixed 1024-byte buffers using sprintf without length validation. Attackers can supply ar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T00:00:21.000Z ##

🟠 CVE-2026-85452 - High (8.8)

MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and variable names are formatted into fixed 1024-byte buffers using sprintf without length validation. Attackers can supply ar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85450
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-03T23:17:25.043000

2 posts

MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the MOOSDB HTTP server that creates unbounded connections and threads without limits. Attackers can open many connections and send endless header data to exhaust server threads and memory, causing service unavailability.

thehackerwire@mastodon.social at 2026-09-04T00:00:10.000Z ##

🟠 CVE-2026-85450 - High (7.5)

MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the MOOSDB HTTP server that creates unbounded connections and threads without limits. Attackers can open many connections and send endless header data to exhaust server th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T00:00:10.000Z ##

🟠 CVE-2026-85450 - High (7.5)

MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the MOOSDB HTTP server that creates unbounded connections and threads without limits. Attackers can open many connections and send endless header data to exhaust server th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85224
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-03T22:18:24.260000

2 posts

A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

thehackerwire@mastodon.social at 2026-09-03T23:01:10.000Z ##

🔴 CVE-2026-85224 - Critical (9.1)

A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T23:01:10.000Z ##

🔴 CVE-2026-85224 - Critical (9.1)

A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64200
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-03T22:18:10.463000

2 posts

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a past the end of an allocated heap buffer during string conversion.  Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.

thehackerwire@mastodon.social at 2026-09-03T23:02:16.000Z ##

🟠 CVE-2026-64200 - High (7.8)

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a past the end of an allocated heap buffer during string conversion.  Successful exploitation requires an attacker...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T23:02:16.000Z ##

🟠 CVE-2026-64200 - High (7.8)

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a past the end of an allocated heap buffer during string conversion.  Successful exploitation requires an attacker...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64199
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-03T22:18:10.337000

2 posts

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read outside the bounds of an allocated data structure.  Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.

thehackerwire@mastodon.social at 2026-09-03T23:02:06.000Z ##

🟠 CVE-2026-64199 - High (7.8)

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read outside the bounds of an allocated data structure.  Successful exploitation requires an attacker to get a user to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T23:02:06.000Z ##

🟠 CVE-2026-64199 - High (7.8)

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read outside the bounds of an allocated data structure.  Successful exploitation requires an attacker to get a user to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64198
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-03T22:18:10.207000

2 posts

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a few bytes past the end of an allocated heap buffer during file handling.  Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.

thehackerwire@mastodon.social at 2026-09-03T23:01:56.000Z ##

🟠 CVE-2026-64198 - High (7.8)

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a few bytes past the end of an allocated heap buffer during file handling.  Successful exploitation requires an at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T23:01:56.000Z ##

🟠 CVE-2026-64198 - High (7.8)

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a few bytes past the end of an allocated heap buffer during file handling.  Successful exploitation requires an at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64197
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-03T22:18:10.073000

2 posts

There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.

thehackerwire@mastodon.social at 2026-09-03T23:01:19.000Z ##

🟠 CVE-2026-64197 - High (7.8)

There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure. Successful exploitation requires an attacker to get a user to open a spec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T23:01:19.000Z ##

🟠 CVE-2026-64197 - High (7.8)

There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure. Successful exploitation requires an attacker to get a user to open a spec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17615
(7.5 HIGH)

EPSS: 0.28%

updated 2026-09-03T21:32:21

1 posts

A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to an endpoint that accepts application/xml and returns Source or StreamSource, the server can be tricked into resolving the entity and including sensitiv

thehackerwire@mastodon.social at 2026-08-31T17:59:51.000Z ##

🟠 CVE-2026-17615 - High (7.5)

A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85046
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-03T21:31:20

2 posts

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

DailyCyberSecurity at 2026-09-03T21:47:57.607Z ##

Google patched a Chrome zero-day vulnerability currently exploited in the wild. The update resolves a severe V8 type confusion flaw (CVE-2026-85046).

securityonline.info/chrome-zer

##

DailyCyberSecurity@infosec.exchange at 2026-09-03T21:47:57.000Z ##

Google patched a Chrome zero-day vulnerability currently exploited in the wild. The update resolves a severe V8 type confusion flaw (CVE-2026-85046).

#Chrome #ZeroDay #Vulnerability #Cybersecurity #CVE202685046

securityonline.info/chrome-zer

##

CVE-2026-85388
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-03T21:31:20

2 posts

Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolean-based blind SQL injection techniques to extract sensitive database content including password hashes from other tenants. This is an incomplete fix for

thehackerwire@mastodon.social at 2026-09-03T20:01:26.000Z ##

🟠 CVE-2026-85388 - High (8.1)

Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T20:01:26.000Z ##

🟠 CVE-2026-85388 - High (8.1)

Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85396
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-03T21:31:20

2 posts

rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like ../upload_backup/owned.sh to write files outside the intended extraction directory into sibling paths sharing the destination prefix.

thehackerwire@mastodon.social at 2026-09-03T20:00:41.000Z ##

🟠 CVE-2026-85396 - High (7.5)

rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like .....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T20:00:41.000Z ##

🟠 CVE-2026-85396 - High (7.5)

rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like .....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85393
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-03T21:31:20

2 posts

node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitrary messages using low-exponent RSA keys. This is an incomplete fix for CVE-2026-33894.

thehackerwire@mastodon.social at 2026-09-03T20:00:21.000Z ##

🟠 CVE-2026-85393 - High (7.5)

node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitra...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T20:00:21.000Z ##

🟠 CVE-2026-85393 - High (7.5)

node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitra...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85394
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-03T21:31:16

2 posts

python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verification when algorithms are not explicitly restricted. This is an incomplete fix for CVE-2024-33663.

thehackerwire@mastodon.social at 2026-09-03T20:00:30.000Z ##

🔴 CVE-2026-85394 - Critical (9.1)

python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verific...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T20:00:30.000Z ##

🔴 CVE-2026-85394 - Critical (9.1)

python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verific...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85391
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-03T21:31:15

2 posts

Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user IDs and access protected endpoints without credentials.

thehackerwire@mastodon.social at 2026-09-03T20:01:36.000Z ##

🔴 CVE-2026-85391 - Critical (9.8)

Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user ID...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T20:01:36.000Z ##

🔴 CVE-2026-85391 - Critical (9.8)

Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user ID...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85028
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-03T21:31:15

2 posts

Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via crafted shell content placed at a predictable path in a world-writable temporary directory, which the installation step reads after elevating its own pr

thehackerwire@mastodon.social at 2026-09-03T20:01:16.000Z ##

🟠 CVE-2026-85028 - High (7.8)

Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T20:01:16.000Z ##

🟠 CVE-2026-85028 - High (7.8)

Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82404
(8.3 HIGH)

EPSS: 0.40%

updated 2026-09-03T19:52:09

1 posts

### Summary Decoding attacker-controlled TOON containing a `__proto__`, `constructor`, or `prototype` key wrote through the object's prototype chain instead of creating an own property, polluting `Object.prototype` for the whole runtime. The `expandPaths: 'safe'` path (dotted keys such as `a.__proto__.x`) was the strongest vector; plain nested objects, tabular rows, and quoted keys were all affec

thehackerwire@mastodon.social at 2026-09-02T17:59:49.000Z ##

🟠 CVE-2026-82404 - High (8.3)

TOON is a compact, human-readable serialization of JSON data for LLM prompts. Prior to 2.3.1, decoding attacker-controlled TOON with a __proto__, constructor, or prototype key wrote through the object prototype chain instead of creating an own pro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12554(CVSS UNKNOWN)

EPSS: 0.21%

updated 2026-09-03T18:32:33

1 posts

Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.

_r_netsec@infosec.exchange at 2026-09-02T21:28:05.000Z ##

Rooted in Trust: Three privilege-escalation vulnerabilities in HP Easy Start for macOS (CVE-2026-12554, CVE-2026-12555, CVE-2026-12556) ciphersecuritylabs.com/researc

##

CVE-2026-83959
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-03T18:31:58

2 posts

Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

thehackerwire@mastodon.social at 2026-09-03T19:00:19.000Z ##

🟠 CVE-2026-83959 - High (7.8)

Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mal...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T19:00:19.000Z ##

🟠 CVE-2026-83959 - High (7.8)

Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mal...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12555(CVSS UNKNOWN)

EPSS: 0.23%

updated 2026-09-03T18:31:29

1 posts

Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.

_r_netsec@infosec.exchange at 2026-09-02T21:28:05.000Z ##

Rooted in Trust: Three privilege-escalation vulnerabilities in HP Easy Start for macOS (CVE-2026-12554, CVE-2026-12555, CVE-2026-12556) ciphersecuritylabs.com/researc

##

CVE-2026-84292
(7.5 HIGH)

EPSS: 0.23%

updated 2026-09-03T18:11:49.487000

1 posts

fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject authority delimiters, demoting the intended host to userinfo and pointing the authority at an attacker-controlled host. Both fast-uri and Node's URL read

thehackerwire@mastodon.social at 2026-09-02T22:59:49.000Z ##

🟠 CVE-2026-84292 - High (7.5)

fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80047
(7.8 HIGH)

EPSS: 0.11%

updated 2026-09-03T17:53:32.027000

1 posts

A vulnerability in Hugging Face Transformers (versions >= 4.49.0 and <= 5.8.1) allows remote Python files to be written to local disk without user consent when using GenerativePreTrainedModel.load_custom_generate(). The function fetches and caches a remote module file before performing the required trust_remote_code consent check, inverting the security model enforced by other code-loading paths (

DailyCyberSecurity@infosec.exchange at 2026-09-02T02:49:07.000Z ##

A new Hugging Face vulnerability (CVE-2026-80047) writes remote Python code to disk before user consent. Learn how to protect your machine learning models.

#HuggingFace #CyberSecurity #Vulnerability #MachineLearning #CVE202680047

securityonline.info/hugging-fa

##

CVE-2026-78319
(0 None)

EPSS: 0.40%

updated 2026-09-03T16:57:26.583000

2 posts

A service running on the affected products contains a potential Time-of-Check Time-of-Use (TOCTOU) race condition. An unauthenticated remote attacker could exploit this race condition to bypass intended security controls. This may result in the execution of unauthorized code.

DailyCyberSecurity@infosec.exchange at 2026-09-01T08:53:15.000Z ##

Public advisory details CVE-2026-78319, a critical SAUTER building controller vulnerability enabling unauthenticated remote code execution via a TOCTOU flaw.

#SAUTER #ICS #CVE202678319 #TOCTOU #RCE #BuildingAutomation #OTSecurity #InfoSec

securityonline.info/sauter-cve

##

certvde@infosec.exchange at 2026-09-01T06:44:43.000Z ##

🔒 New CSAF advisory published

VDE-2026-093
SAUTER: modulo 6 and EY-modulo 5 Vulnerability in Firmware update mechanism allowing remote code execution
CVE-2026-78319

A vulnerability has been found in the firmware update process of SAUTER Building Controllers. The identified vulnerability could allow unauthorized code execution on affec…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: sauter.csaf-tp.certvde.com/.we

#OT #Advisory

##

CVE-2026-20277
(8.2 HIGH)

EPSS: 0.22%

updated 2026-09-03T16:37:52.170000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20277 are related to protection mechanism failure issues that

thehackerwire@mastodon.social at 2026-09-03T12:01:31.000Z ##

🟠 CVE-2026-20277 - High (8.2)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84353
(9.6 CRITICAL)

EPSS: 0.28%

updated 2026-09-03T16:37:52.170000

1 posts

Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-12556
(0 None)

EPSS: 0.15%

updated 2026-09-03T16:17:23.523000

1 posts

Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.

_r_netsec@infosec.exchange at 2026-09-02T21:28:05.000Z ##

Rooted in Trust: Three privilege-escalation vulnerabilities in HP Easy Start for macOS (CVE-2026-12554, CVE-2026-12555, CVE-2026-12556) ciphersecuritylabs.com/researc

##

CVE-2026-48710
(6.5 MEDIUM)

EPSS: 11.04%

updated 2026-09-03T15:39:44.470000

6 posts

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and e

Nuclei template

5 repos

https://github.com/sb-ox/repro-OXDEV-77637-uv-workspace

https://github.com/CuteeCat/CVE-2026-48710

https://github.com/eris-ths/supply-chain-guard

https://github.com/xtremebeing/starlette-host-header-lab

https://github.com/Bhanunamikaze/BadHost-CVE-2026-48710-Exploit

thecybermind at 2026-09-03T18:01:45.438Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-48710 – Kludex Starlette HTTP Request/Response Smuggling Vulnerability

Active CISA KEV exploitation of CVE-2026-48710 exposes Starlette to request smuggling and auth bypass. Review board-ready governance, asset visibility, and mitigation....

thecybermind.co/r67t

##

thecybermind@infosec.exchange at 2026-09-03T18:01:45.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-48710 – Kludex Starlette HTTP Request/Response Smuggling Vulnerability

Active CISA KEV exploitation of CVE-2026-48710 exposes Starlette to request smuggling and auth bypass. Review board-ready governance, asset visibility, and mitigation....

thecybermind.co/r67t

##

thecybermind@infosec.exchange at 2026-09-03T06:55:48.000Z ##

Mitigate CVE-2026-48710 in Starlette. Attackers exploit path injections in request headers to trigger auth bypasses. Access our T-Suite brief for Splunk, Sentinel, and Chronicle detection rules and rapid reverse proxy hardening steps to secure your perimeter today. thecybermind.co/zyul

##

AAKL@infosec.exchange at 2026-09-02T19:01:22.000Z ##

Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.

- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-02T19:00:11.000Z ##

🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48710 (secdb.nttzen.cloud/cve/detail/)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/Kludex/starlette/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-49869 (secdb.nttzen.cloud/cve/detail/)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/kestra-io/kestra/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-59822 (secdb.nttzen.cloud/cve/detail/)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: github.com/BerriAI/litellm/sec ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82329 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83548 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83549 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9586 (secdb.nttzen.cloud/cve/detail/)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: sangomakb.atlassian.net/wiki/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260902 #cisa20260902 #cve_2026_48710 #cve_2026_49869 #cve_2026_59822 #cve_2026_82329 #cve_2026_83548 #cve_2026_83549 #cve_2026_9586 #cve202648710 #cve202649869 #cve202659822 #cve202682329 #cve202683548 #cve202683549 #cve20269586

##

cisakevtracker@mastodon.social at 2026-09-02T18:01:11.000Z ##

CVE ID: CVE-2026-48710
Vendor: Kludex
Product: Starlette
Date Added: 2026-09-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-66786
(9.1 CRITICAL)

EPSS: 0.74%

updated 2026-09-03T15:33:10

1 posts

A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName that includes newlines and ipsec.conf directives. This allows an attacker to inject arbitrary configuration parameters or execute commands through leftupdo

thehackerwire@mastodon.social at 2026-09-03T00:00:09.000Z ##

🔴 CVE-2026-66786 - Critical (9.1)

A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2023-54391
(9.8 CRITICAL)

EPSS: 0.46%

updated 2026-09-03T15:33:10

1 posts

Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with a

2 repos

https://github.com/disqualifier/psa-2026-00043-recovery

https://github.com/neeythann/Proxmox-VE-7-RCE

CVE-2026-85216(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-09-03T15:32:35

2 posts

MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials. The custom LdapAuthenticate and LinOTPAuthenticate components replace CakePHP's FormAuthenticate implementation but did not replicate its credential validation checks. As a result, empty or non-string values could reach the underlying a

cR0w at 2026-09-03T16:34:01.161Z ##

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.5 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials. The custom LdapAuthenticate and LinOTPAuthenticate components replace CakePHP's FormAuthenticate implementation but did not replicate its credential validation checks. As a result, empty or non-string values could reach the underlying authentication mechanisms. In the LDAP authentication path, an attacker able to identify a valid directory user's email address could submit an empty password. The empty credential could be passed to ldap_bind(), where an LDAP server accepting unauthenticated binds may return a successful result for a valid distinguished name combined with an empty password. MISP could consequently treat the attacker as the corresponding authenticated directory user without verification of the user's password. The issue also affected the LinOTP authentication component. Invalid credential types were not rejected before being processed, and when mixed authentication was enabled, an empty password could be checked against a locally stored MISP password hash. LDAP-provisioned MISP accounts could additionally be created with an empty local password because account creation skipped normal validation, resulting in a hash corresponding to an empty password. This could permit authentication through the local fallback mechanism when such an account was no longer resolved through LDAP. Successful exploitation could allow a remote unauthenticated attacker to impersonate an existing MISP user. If the targeted account has administrative or other privileged permissions, the attacker could gain corresponding access to sensitive threat-intelligence data, modify or delete information, alter configuration, or perform other privileged operations. The patch resolves the vulnerability by requiring authentication identifiers and passwords to be valid strings, rejecting empty passwords where they are not explicitly permitted, and assigning a randomly generated local password to LDAP-provisioned accounts instead of storing a hash derived from an empty password.

##

cR0w@infosec.exchange at 2026-09-03T16:34:01.000Z ##

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.5 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials. The custom LdapAuthenticate and LinOTPAuthenticate components replace CakePHP's FormAuthenticate implementation but did not replicate its credential validation checks. As a result, empty or non-string values could reach the underlying authentication mechanisms. In the LDAP authentication path, an attacker able to identify a valid directory user's email address could submit an empty password. The empty credential could be passed to ldap_bind(), where an LDAP server accepting unauthenticated binds may return a successful result for a valid distinguished name combined with an empty password. MISP could consequently treat the attacker as the corresponding authenticated directory user without verification of the user's password. The issue also affected the LinOTP authentication component. Invalid credential types were not rejected before being processed, and when mixed authentication was enabled, an empty password could be checked against a locally stored MISP password hash. LDAP-provisioned MISP accounts could additionally be created with an empty local password because account creation skipped normal validation, resulting in a hash corresponding to an empty password. This could permit authentication through the local fallback mechanism when such an account was no longer resolved through LDAP. Successful exploitation could allow a remote unauthenticated attacker to impersonate an existing MISP user. If the targeted account has administrative or other privileged permissions, the attacker could gain corresponding access to sensitive threat-intelligence data, modify or delete information, alter configuration, or perform other privileged operations. The patch resolves the vulnerability by requiring authentication identifiers and passwords to be valid strings, rejecting empty passwords where they are not explicitly permitted, and assigning a randomly generated local password to LDAP-provisioned accounts instead of storing a hash derived from an empty password.

##

CVE-2026-85174
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-03T15:32:28

2 posts

SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated attackers can read the log file via the getFile endpoint to recover admin API tokens and gain permanent administrative access.

thehackerwire@mastodon.social at 2026-09-03T14:00:12.000Z ##

🟠 CVE-2026-85174 - High (8.8)

SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated attackers can read the log file via the getFile endpoint to recover admin API ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T14:00:12.000Z ##

🟠 CVE-2026-85174 - High (8.8)

SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated attackers can read the log file via the getFile endpoint to recover admin API ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85154
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-03T15:32:19

2 posts

WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a video_id_hash can replay it indefinitely to authenticate as the video owner with full privileges, and the credential remains valid even after the owner changes

thehackerwire@mastodon.social at 2026-09-03T14:00:35.000Z ##

🔴 CVE-2026-85154 - Critical (9.8)

WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a video_...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T14:00:35.000Z ##

🔴 CVE-2026-85154 - Critical (9.8)

WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a video_...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85175
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-03T13:06:25.270000

2 posts

SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in the IsForbiddenAbsPath() function (kernel/util/path_guard.go), which only blocks conf/conf.json by exact match and does not restrict the TLS private key (conf/key.pem) or CA private key (conf/ca.key) stored in the same conf/ directory. Because the getFile handler skips the blocklist for RoleAdministrator and all authenti

thehackerwire@mastodon.social at 2026-09-03T14:00:24.000Z ##

🟠 CVE-2026-85175 - High (8.8)

SiYuan versions &lt;= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in the IsForbiddenAbsPath() function (kernel/util/path_guard.go), which only blocks conf/conf.json by exact match and does not restrict the TLS private key (conf/key.pem...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T14:00:24.000Z ##

🟠 CVE-2026-85175 - High (8.8)

SiYuan versions &lt;= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in the IsForbiddenAbsPath() function (kernel/util/path_guard.go), which only blocks conf/conf.json by exact match and does not restrict the TLS private key (conf/key.pem...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-83549
(7.8 HIGH)

EPSS: 1.62%

updated 2026-09-03T13:06:16.230000

13 posts

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

Analyst207@mastodon.social at 2026-09-03T23:29:12.000Z ##

Attackers Exploit Zero-Days in SonicWall SMA 1000 Appliances

SonicWall's SMA 1000 appliances are under attack, thanks to two newly disclosed zero-day vulnerabilities - CVE-2026-83548 and CVE-2026-83549 - that can be chained together for a complete network compromise. Attackers are already exploiting these flaws in the wild, prompting urgent patching advice from the vendor and cybersecurity authorities.

osintsights.com/attackers-expl

#ZeroDay #Sonicwall #Cve202683548 #Cve202683549 #Sma1000

##

undercodenews@mastodon.social at 2026-09-03T22:31:48.000Z ##

SonicWall Under Siege Again: Two Zero-Days Turn the SMA 1000 Into a High-Risk Gateway for Attackers + Video

Introduction: Another Warning From the Network Edge SonicWall customers are once again facing a serious security crisis, and this time the danger is concentrated around the SonicWall SMA 1000 remote-access appliance. Two newly disclosed vulnerabilities, CVE-2026-83548 and CVE-2026-83549, are already being exploited in the wild, turning what should be a trusted…

undercodenews.com/sonicwall-un

##

AAKL at 2026-09-03T14:26:43.479Z ##

New.

Rapid7: Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild rapid7.com/blog/post/etr-criti @Rapid7Official

##

AAKL@infosec.exchange at 2026-09-03T14:26:43.000Z ##

New.

Rapid7: Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild rapid7.com/blog/post/etr-criti @Rapid7Official #infosec #vulnerability #SonicWall

##

beyondmachines1@infosec.exchange at 2026-09-03T09:01:31.000Z ##

SonicWall Patches Chained Zero-Day Vulnerabilities in SMA 1000 Series VPNs

SonicWall has patched two zero-day vulnerabilities (CVE-2026-83548 and CVE-2026-83549) in its SMA 1000 series VPN appliances that attackers are chaining to achieve unauthenticated remote code execution.

**If you run SonicWall SMA 1000 appliances (models 6210, 7210, or 8200v), update immediately to version 12.4.3-03526 or 12.5.0-02952. These devices are actively attacked to take over VPN gateways. After patching review your logs for signs of compromise, if anything looks suspicious, re-image the appliance, change all passwords and reset TOTP tokens, and only restore backups from before the breach.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

ottoto2017@prattohome.com at 2026-09-03T05:14:11.000Z ##

「攻撃者がSonicWall SMA 1000の2つのゼロデイ脆弱性を悪用し、攻撃連鎖を形成する可能性 」: #TheHackerNews

「SonicWallは、ゼロデイ攻撃で悪用された、同社のSecure Mobile Access(SMA)1000シリーズVPNアプライアンスに影響を与える2つのセキュリティ上の欠陥に対処するためのセキュリティアップデートをリリースしました。

SonicWallのウィリアム・ペリー氏とアダム・バビス氏が社内で発見した脆弱 性は 以下のとおりです。

CVE-2026-83548 (CVSS スコア: 10.0)
CVE-2026-83549 (CVSS スコア: 7.8)

SonicWallは、「脆弱性が積極的に悪用されていることを示す事例を調査した」と述べ、攻撃者が両方のバグを組み合わせて、脆弱性のあるデバイス上で任意のコードを実行している可能性を示唆した。 」

thehackernews.com/2026/09/atta

#prattohome

##

AAKL@infosec.exchange at 2026-09-02T19:01:22.000Z ##

Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.

- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-02T19:00:11.000Z ##

🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48710 (secdb.nttzen.cloud/cve/detail/)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/Kludex/starlette/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-49869 (secdb.nttzen.cloud/cve/detail/)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/kestra-io/kestra/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-59822 (secdb.nttzen.cloud/cve/detail/)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: github.com/BerriAI/litellm/sec ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82329 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83548 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83549 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9586 (secdb.nttzen.cloud/cve/detail/)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: sangomakb.atlassian.net/wiki/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260902 #cisa20260902 #cve_2026_48710 #cve_2026_49869 #cve_2026_59822 #cve_2026_82329 #cve_2026_83548 #cve_2026_83549 #cve_2026_9586 #cve202648710 #cve202649869 #cve202659822 #cve202682329 #cve202683548 #cve202683549 #cve20269586

##

cisakevtracker@mastodon.social at 2026-09-02T18:02:29.000Z ##

CVE ID: CVE-2026-83549
Vendor: SonicWall
Product: SMA1000 Appliances
Date Added: 2026-09-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cert_fr@social.numerique.gouv.fr at 2026-09-02T12:51:59.000Z ##

⚠️Alerte CERT-FR⚠️

Les vulnérabilités CVE-2026-83548 et CVE-2026-83549 affectent les SMA 1000 et permettent une SSRF ainsi que l'exécution de code arbitraire à distance.
Elles sont activement exploitées.

cert.ssi.gouv.fr/alerte/CERTFR

##

security_crawler_carl@infosec.exchange at 2026-09-02T07:13:42.000Z ##

By also ignoring CVE-2026-83549, an OS command injection flaw in the AMC component, you further agree to let those same strangers chain both bugs together for full remote code execution. SonicWall has confirmed active exploitation in the wild. Ransomware gangs find SonicWall products particularly cozy real estate.

To opt out of these terms, patch your SMA1000 immediately.

Reward: You've received the Binding Arbitration Curse — your incidents are now non-disputable.

#ZeroDay #SonicWall (2/2)

##

decio@infosec.exchange at 2026-09-02T07:06:36.000Z ##

Tiens, encore du #SonicWall SMA1000 ...

Deux nouvelles vulnérabilités 0-day, CVE-2026-83548 (CVSS 10) et CVE-2026-83549, activement exploitées.

La première permet une SSRF sans authentification, la seconde une injection de commandes/RCE. Les deux peuvent être chaînées pour arriver à une RCE sans authentification sur l'appliance.

Sont concernés les SMA1000 6210, 7210 et 8200v.

Pas de workaround : hotfix à appliquer au plus vite. ☹️

Et SonicWall dans la doc dédiée ne s’arrête pas au patch : recherche d’IoC recommandée et, si compromission détectée, re-image/redeploy de l’appliance + reset des mots de passe admin/utilisateurs et des tokens TOTP.

À noter : les SSL-VPN des firewalls SonicWall et la gamme SMA100 ne sont pas concernés.

Bref, si vous avez du SMA1000 exposé, ça mérite clairement un petit détour dans l’inventaire ce matin. 🙃

Advisory 🩹
👇
psirt.global.sonicwall.com/vul

#CyberVeille

##

thehackerwire@mastodon.social at 2026-09-01T23:01:58.000Z ##

🟠 CVE-2026-83549 - High (7.8)

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enabl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-83548
(10.0 CRITICAL)

EPSS: 0.71%

updated 2026-09-03T13:06:16.053000

14 posts

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

1 repos

https://github.com/xoessie/CVE-2026-83548-SonicWall-SMA1000-Analysis

Analyst207@mastodon.social at 2026-09-03T23:29:12.000Z ##

Attackers Exploit Zero-Days in SonicWall SMA 1000 Appliances

SonicWall's SMA 1000 appliances are under attack, thanks to two newly disclosed zero-day vulnerabilities - CVE-2026-83548 and CVE-2026-83549 - that can be chained together for a complete network compromise. Attackers are already exploiting these flaws in the wild, prompting urgent patching advice from the vendor and cybersecurity authorities.

osintsights.com/attackers-expl

#ZeroDay #Sonicwall #Cve202683548 #Cve202683549 #Sma1000

##

undercodenews@mastodon.social at 2026-09-03T22:31:48.000Z ##

SonicWall Under Siege Again: Two Zero-Days Turn the SMA 1000 Into a High-Risk Gateway for Attackers + Video

Introduction: Another Warning From the Network Edge SonicWall customers are once again facing a serious security crisis, and this time the danger is concentrated around the SonicWall SMA 1000 remote-access appliance. Two newly disclosed vulnerabilities, CVE-2026-83548 and CVE-2026-83549, are already being exploited in the wild, turning what should be a trusted…

undercodenews.com/sonicwall-un

##

AAKL at 2026-09-03T14:26:43.479Z ##

New.

Rapid7: Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild rapid7.com/blog/post/etr-criti @Rapid7Official

##

AAKL@infosec.exchange at 2026-09-03T14:26:43.000Z ##

New.

Rapid7: Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild rapid7.com/blog/post/etr-criti @Rapid7Official #infosec #vulnerability #SonicWall

##

beyondmachines1@infosec.exchange at 2026-09-03T09:01:31.000Z ##

SonicWall Patches Chained Zero-Day Vulnerabilities in SMA 1000 Series VPNs

SonicWall has patched two zero-day vulnerabilities (CVE-2026-83548 and CVE-2026-83549) in its SMA 1000 series VPN appliances that attackers are chaining to achieve unauthenticated remote code execution.

**If you run SonicWall SMA 1000 appliances (models 6210, 7210, or 8200v), update immediately to version 12.4.3-03526 or 12.5.0-02952. These devices are actively attacked to take over VPN gateways. After patching review your logs for signs of compromise, if anything looks suspicious, re-image the appliance, change all passwords and reset TOTP tokens, and only restore backups from before the breach.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

ottoto2017@prattohome.com at 2026-09-03T05:14:11.000Z ##

「攻撃者がSonicWall SMA 1000の2つのゼロデイ脆弱性を悪用し、攻撃連鎖を形成する可能性 」: #TheHackerNews

「SonicWallは、ゼロデイ攻撃で悪用された、同社のSecure Mobile Access(SMA)1000シリーズVPNアプライアンスに影響を与える2つのセキュリティ上の欠陥に対処するためのセキュリティアップデートをリリースしました。

SonicWallのウィリアム・ペリー氏とアダム・バビス氏が社内で発見した脆弱 性は 以下のとおりです。

CVE-2026-83548 (CVSS スコア: 10.0)
CVE-2026-83549 (CVSS スコア: 7.8)

SonicWallは、「脆弱性が積極的に悪用されていることを示す事例を調査した」と述べ、攻撃者が両方のバグを組み合わせて、脆弱性のあるデバイス上で任意のコードを実行している可能性を示唆した。 」

thehackernews.com/2026/09/atta

#prattohome

##

AAKL@infosec.exchange at 2026-09-02T19:01:22.000Z ##

Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.

- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-02T19:00:11.000Z ##

🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48710 (secdb.nttzen.cloud/cve/detail/)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/Kludex/starlette/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-49869 (secdb.nttzen.cloud/cve/detail/)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/kestra-io/kestra/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-59822 (secdb.nttzen.cloud/cve/detail/)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: github.com/BerriAI/litellm/sec ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82329 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83548 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83549 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9586 (secdb.nttzen.cloud/cve/detail/)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: sangomakb.atlassian.net/wiki/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260902 #cisa20260902 #cve_2026_48710 #cve_2026_49869 #cve_2026_59822 #cve_2026_82329 #cve_2026_83548 #cve_2026_83549 #cve_2026_9586 #cve202648710 #cve202649869 #cve202659822 #cve202682329 #cve202683548 #cve202683549 #cve20269586

##

cisakevtracker@mastodon.social at 2026-09-02T18:02:13.000Z ##

CVE ID: CVE-2026-83548
Vendor: SonicWall
Product: SMA1000 Appliances
Date Added: 2026-09-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cert_fr@social.numerique.gouv.fr at 2026-09-02T12:51:59.000Z ##

⚠️Alerte CERT-FR⚠️

Les vulnérabilités CVE-2026-83548 et CVE-2026-83549 affectent les SMA 1000 et permettent une SSRF ainsi que l'exécution de code arbitraire à distance.
Elles sont activement exploitées.

cert.ssi.gouv.fr/alerte/CERTFR

##

security_crawler_carl@infosec.exchange at 2026-09-02T07:13:42.000Z ##

🏆 New Achievement! By Continuing to Use This Appliance, You Agree to Be Owned!

Please note that Section 2, Paragraph 4 of your SMA1000 user agreement has been updated. By failing to patch CVE-2026-83548 — a pre-authentication SSRF flaw scoring a perfect 10.0 CVSS in the Appliance Work Place interface — you consent to unauthenticated strangers poking around your network. (1/2)

##

decio@infosec.exchange at 2026-09-02T07:06:36.000Z ##

Tiens, encore du #SonicWall SMA1000 ...

Deux nouvelles vulnérabilités 0-day, CVE-2026-83548 (CVSS 10) et CVE-2026-83549, activement exploitées.

La première permet une SSRF sans authentification, la seconde une injection de commandes/RCE. Les deux peuvent être chaînées pour arriver à une RCE sans authentification sur l'appliance.

Sont concernés les SMA1000 6210, 7210 et 8200v.

Pas de workaround : hotfix à appliquer au plus vite. ☹️

Et SonicWall dans la doc dédiée ne s’arrête pas au patch : recherche d’IoC recommandée et, si compromission détectée, re-image/redeploy de l’appliance + reset des mots de passe admin/utilisateurs et des tokens TOTP.

À noter : les SSL-VPN des firewalls SonicWall et la gamme SMA100 ne sont pas concernés.

Bref, si vous avez du SMA1000 exposé, ça mérite clairement un petit détour dans l’inventaire ce matin. 🙃

Advisory 🩹
👇
psirt.global.sonicwall.com/vul

#CyberVeille

##

cyberworldops@infosec.exchange at 2026-09-02T06:20:01.000Z ##

SonicWall confirmed active exploitation of two zero-days in SMA1000 appliances, including pre-auth SSRF CVE-2026-83548. Chained, the flaws allow unauthenticated remote command execution on SSL-VPN gateways. Operators should patch immediately and hunt for post-exploitation activity. #SonicWall #ZeroDay #InfoSec

cyberworldops.eu/en/sonicwall-

##

DailyCyberSecurity@infosec.exchange at 2026-09-01T22:07:29.000Z ##

CVE-2026-83548, a critical SonicWall SMA1000 vulnerability, is exploited in the wild. The pre-authentication SSRF flaw scores a maximum 10.0 CVSS.

#SonicWall #SMA1000 #CVE202683548 #SSRF #PreAuth #VPNsecurity #InfoSec #ExploitedInTheWild

securityonline.info/sonicwall-

##

CVE-2026-78689
(8.1 HIGH)

EPSS: 0.41%

updated 2026-09-03T13:06:10.270000

1 posts

Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes an externally controlled XML namespace prefix list to that method. Both the njs and the QuickJS (qjs) engines are affected. A crafted prefix list cau

cR0w@infosec.exchange at 2026-09-02T19:12:01.000Z ##

I am fortunate enough to not know anything about NGINX JavaScript ( hashtag blessed ) but if you do, this might be of interest.

nvd.nist.gov/vuln/detail/cve-2

Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes an externally controlled XML namespace prefix list to that method. Both the njs and the QuickJS (qjs) engines are affected. A crafted prefix list causes an out-of-bounds write past the end of a heap allocation. With the njs engine, which is the engine used when the js_engine directive is absent, this corrupts adjacent objects and crashes the NGINX worker. With the QuickJS engine, the same call additionally leaks the prefix list on every invocation, causing worker memory to grow across requests. The official nginxinc/nginx-saml reference implementation is affected during SAML signature verification. It reads InclusiveNamespaces/@PrefixList from an untrusted SAML message and passes it to xml.exclusiveC14n() before the signature has been verified, so a valid SAML signature is not required. A crafted SAML Response, Assertion, LogoutRequest, or LogoutResponse is sufficient. Code execution has not been demonstrated and cannot be ruled out for all platforms, as the effect of the out-of-bounds write depends on conditions beyond the attacker's control. Impact This vulnerability allows remote attackers to cause a denial of service on the NGINX system, either through repeatable worker restarts or through worker memory growth or possibly trigger code execution. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

##

CVE-2026-75604
(9.0 CRITICAL)

EPSS: 0.82%

updated 2026-09-03T13:06:07.577000

1 posts

Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently escape backslashes in route segments before constructing incremental-cache paths. In packages/next/src/shared/lib/router/utils/escape-path-delimiters.ts and packages/

4 repos

https://github.com/FORTBRIDGE-UK/cve-2026-75604

https://github.com/HackSpeak/CVE-2026-75604

https://github.com/e4zyy/Project-CVE-2026-75604

https://github.com/rafabd1/CVE-2026-75604-poc

thehackerwire@mastodon.social at 2026-09-01T23:02:08.000Z ##

🔴 CVE-2026-75604 - Critical (9)

Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently escape backsl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73782
(8.8 HIGH)

EPSS: 0.27%

updated 2026-09-03T13:06:07.180000

1 posts

A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.

thehackerwire@mastodon.social at 2026-09-01T22:00:33.000Z ##

🟠 CVE-2026-73782 - High (8.8)

A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59822
(8.2 HIGH)

EPSS: 0.87%

updated 2026-09-03T13:05:59.573000

6 posts

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a va

1 repos

https://github.com/HORKimhab/CVE-2026-59822

thecybermind at 2026-09-03T15:19:58.534Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-59822 – BerriAI LiteLLM Improper Authentication Vulnerability

BerriAI LiteLLM is impacted by CVE-2026-59822, enabling unauthenticated attackers to bypass token validation. Review detection queries, compensating controls, and patching guides....

thecybermind.co/ng9r

##

thecybermind@infosec.exchange at 2026-09-03T15:19:58.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-59822 – BerriAI LiteLLM Improper Authentication Vulnerability

BerriAI LiteLLM is impacted by CVE-2026-59822, enabling unauthenticated attackers to bypass token validation. Review detection queries, compensating controls, and patching guides....

thecybermind.co/ng9r

##

thecybermind@infosec.exchange at 2026-09-03T07:52:48.000Z ##

Mitigate CVE-2026-59822 in BerriAI LiteLLM. Unauthenticated attackers bypass token checks on MCP endpoints. Read our T-Suite brief for Splunk, Sentinel, and Chronicle detection rules, plus vital hardening controls to lock down your AI infrastructure today. thecybermind.co/5vrg

##

AAKL@infosec.exchange at 2026-09-02T19:01:22.000Z ##

Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.

- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-02T19:00:11.000Z ##

🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48710 (secdb.nttzen.cloud/cve/detail/)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/Kludex/starlette/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-49869 (secdb.nttzen.cloud/cve/detail/)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/kestra-io/kestra/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-59822 (secdb.nttzen.cloud/cve/detail/)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: github.com/BerriAI/litellm/sec ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82329 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83548 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83549 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9586 (secdb.nttzen.cloud/cve/detail/)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: sangomakb.atlassian.net/wiki/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260902 #cisa20260902 #cve_2026_48710 #cve_2026_49869 #cve_2026_59822 #cve_2026_82329 #cve_2026_83548 #cve_2026_83549 #cve_2026_9586 #cve202648710 #cve202649869 #cve202659822 #cve202682329 #cve202683548 #cve202683549 #cve20269586

##

cisakevtracker@mastodon.social at 2026-09-02T18:00:55.000Z ##

CVE ID: CVE-2026-59822
Vendor: BerriAI
Product: LiteLLM
Date Added: 2026-09-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-9586
(9.8 CRITICAL)

EPSS: 11.85%

updated 2026-09-02T21:32:54

8 posts

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL

Nuclei template

1 repos

https://github.com/HORKimhab/CVE-2026-9586

beyondmachines1@infosec.exchange at 2026-09-03T08:01:29.000Z ##

Attackers Exploit Critical Sangoma Switchvox Flaw to Deploy Reverse Shells

Sangoma patched 12 vulnerabilities in Switchvox, including a critical unauthenticated SQL injection (CVE-2026-9586) that attackers are currently using to gain remote code execution and steal authentication keys.

**If you run Sangoma Switchvox, first make sure it isn't reachable from the internet and can only be accessed from trusted networks, then update immediately to version 8.4.0.2. Anything on version 8.3 or earlier is being actively attacked. Because attackers have been stealing keys, tokens and user data, also check /var/log/switchvox/db-quirks.log for signs of SQL injection, block the IP 176.65.148.184, and reset passwords and signing keys if you find anything suspicious.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

oversecurity@mastodon.social at 2026-09-02T21:40:30.000Z ##

Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can...

🔗️ [Bleepingcomputer] link.is.it/o3uhXX

##

AAKL@infosec.exchange at 2026-09-02T19:01:22.000Z ##

Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.

- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-02T19:00:11.000Z ##

🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48710 (secdb.nttzen.cloud/cve/detail/)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/Kludex/starlette/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-49869 (secdb.nttzen.cloud/cve/detail/)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/kestra-io/kestra/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-59822 (secdb.nttzen.cloud/cve/detail/)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: github.com/BerriAI/litellm/sec ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82329 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83548 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83549 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9586 (secdb.nttzen.cloud/cve/detail/)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: sangomakb.atlassian.net/wiki/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260902 #cisa20260902 #cve_2026_48710 #cve_2026_49869 #cve_2026_59822 #cve_2026_82329 #cve_2026_83548 #cve_2026_83549 #cve_2026_9586 #cve202648710 #cve202649869 #cve202659822 #cve202682329 #cve202683548 #cve202683549 #cve20269586

##

cisakevtracker@mastodon.social at 2026-09-02T18:01:58.000Z ##

CVE ID: CVE-2026-9586
Vendor: Sangoma
Product: Switchvox
Date Added: 2026-09-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cyberworldops@infosec.exchange at 2026-09-02T10:10:00.000Z ##

Active exploitation attempts are targeting CVE-2026-9586, a critical unauthenticated SQL injection in Sangoma Switchvox SMB Edition. A single crafted request enables arbitrary SQL execution on PostgreSQL and leads to remote code execution via reverse shell. Immediate patching and exposure review are critical. #Switchvox #SqlInjection #ThreatIntel

cyberworldops.eu/en/switchvox-

##

DailyCyberSecurity@infosec.exchange at 2026-09-01T15:00:39.000Z ##

CVE-2026-9586, a critical Sangoma Switchvox vulnerability, is exploited in the wild, giving unauthenticated attackers SQL injection and remote code execution.

#Sangoma #Switchvox #CVE20269586 #RCE #SQLInjection #VoIP #InfoSec #ExploitedInTheWild

securityonline.info/sangoma-sw

##

_r_netsec@infosec.exchange at 2026-09-01T12:43:04.000Z ##

Off the Hook: Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586 horizon3.ai/attack-research/di

##

CVE-2026-19117
(9.8 CRITICAL)

EPSS: 0.28%

updated 2026-09-02T21:32:07

2 posts

Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only.

thehackerwire@mastodon.social at 2026-09-02T23:02:33.000Z ##

🔴 CVE-2026-19117 - Critical (9.8)

Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as
that user. This issue affects on-premises deployments only.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cR0w@infosec.exchange at 2026-09-02T21:46:36.000Z ##

Credential managers are so hot right now. Here's Delinea's on-prem offering.

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.8 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only.

##

CVE-2026-84372
(9.8 CRITICAL)

EPSS: 0.41%

updated 2026-09-02T20:17:40.793000

1 posts

Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RESP buffer in AbstractAggregateConnection::write() by splitting it with explode("\r\n") instead of honoring RESP length prefixes. Attacker-controlled keys or values containing CRLF s

thehackerwire@mastodon.social at 2026-09-01T23:00:56.000Z ##

🔴 CVE-2026-84372 - Critical (9.8)

Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RESP buffer in AbstractAggrega...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73773
(7.5 HIGH)

EPSS: 0.26%

updated 2026-09-02T19:34:36.770000

1 posts

An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service.

thehackerwire@mastodon.social at 2026-09-01T23:02:18.000Z ##

🟠 CVE-2026-73773 - High (7.5)

An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52833
(8.0 HIGH)

EPSS: 0.33%

updated 2026-09-02T19:17:21.110000

1 posts

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio's Java runtime generates a build.gradle file during function builds using Go's text/template package. The template renders runtimeAttributes.repositories[] values with the {{ . }} action, which performs no escaping. An attacker can embed a closing brace (}) to break out of the repositories

thehackerwire@mastodon.social at 2026-09-03T07:00:32.000Z ##

🟠 CVE-2026-52833 - High (8)

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio's Java runtime generates a build.gradle file during function builds using Go's text/template package. The template renders runtimeAttribut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49832
(8.0 HIGH)

EPSS: 0.54%

updated 2026-09-02T19:17:19.197000

1 posts

DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, versions 9.0-rc1 to before 9.3, and version 10-rc1, Remote Code Execution (RCE) is possible via Velocity Templates used by DSpace for COAR Notify/LDN messages. This issue has been patched in versions 8.4, 9.3, and 10.0.

thehackerwire@mastodon.social at 2026-09-03T00:00:31.000Z ##

🟠 CVE-2026-49832 - High (8)

DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, versions 9.0-rc1 to before 9.3, and version 10-rc1, Remote Code Execution (RCE) is possible via Veloci...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20280
(8.8 HIGH)

EPSS: 0.27%

updated 2026-09-02T18:32:32

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the&nbsp;Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20280 are related to improper checking or handling of excep

hugovalters@mastodon.social at 2026-09-03T11:04:46.000Z ##

CVE-2026-20280 - High severity flaw in Cisco IOS XR Software. Improper handling of exceptional conditions (CWE-703). CVSS 8.8. Update immediately. #CVE #Cisco #infosec

valtersit.com/cve/CVE-2026-202

##

CVE-2026-20275
(8.8 HIGH)

EPSS: 0.18%

updated 2026-09-02T18:32:32

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20275 are related to incorrect calculation issues that are group

AAKL@infosec.exchange at 2026-09-02T16:36:40.000Z ##

New security advisories.

Broadcom has addressed several vulnerabilities,two of them critical support.broadcom.com/web/ecx/s #Broadcom

Cisco: Five advisories, two of them addressing critical vulnerabilities:

- CRITICAL: CVE-2026-20212: Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability sec.cloudapps.cisco.com/securi

- CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi

More: sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

CVE-2026-20276
(8.6 HIGH)

EPSS: 0.25%

updated 2026-09-02T18:32:31

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20276 are related to insufficient control flow management issues

AAKL@infosec.exchange at 2026-09-02T16:36:40.000Z ##

New security advisories.

Broadcom has addressed several vulnerabilities,two of them critical support.broadcom.com/web/ecx/s #Broadcom

Cisco: Five advisories, two of them addressing critical vulnerabilities:

- CRITICAL: CVE-2026-20212: Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability sec.cloudapps.cisco.com/securi

- CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi

More: sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

CVE-2026-20274
(9.8 CRITICAL)

EPSS: 0.67%

updated 2026-09-02T18:32:31

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20274 are related to improper resource control issues that are g

AAKL@infosec.exchange at 2026-09-02T16:36:40.000Z ##

New security advisories.

Broadcom has addressed several vulnerabilities,two of them critical support.broadcom.com/web/ecx/s #Broadcom

Cisco: Five advisories, two of them addressing critical vulnerabilities:

- CRITICAL: CVE-2026-20212: Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability sec.cloudapps.cisco.com/securi

- CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi

More: sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

CVE-2026-20212
(9.8 CRITICAL)

EPSS: 0.53%

updated 2026-09-02T18:32:26

9 posts

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with&nbsp;root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and

1 repos

https://github.com/HORKimhab/CVE-2026-20212

cyberworldops at 2026-09-03T22:20:01.181Z ##

Cisco disclosed CVE-2026-20212, a critical unauthenticated RCE in Silicon One on Nexus 9000 switches. Exploitation yields root execution via crafted data, putting core data-center fabric at risk of full compromise.

cyberworldops.eu/en/cisco-nexu

##

undercodenews@mastodon.social at 2026-09-03T21:27:17.000Z ##

Cisco’s Critical Nexus 9000 Flaw Exposes a Dangerous Path to Root Access + Video

A New Warning for Network Administrators A critical security flaw in certain Cisco Nexus 9000 switches has turned the spotlight back toward one of the most important lessons in modern infrastructure security: even highly specialized network hardware can contain vulnerabilities capable of giving an attacker complete control. Cisco has released security updates for CVE-2026-20212, a…

undercodenews.com/ciscos-criti

##

threatnoir at 2026-09-03T21:05:54.033Z ##

⚠️ CRITICAL: Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Cisco released patches for CVE-2026-20212, a critical unauthenticated remote code execution vulnerability in Nexus 9000 switches (10 Silicon One-based models). Attackers can exploit this via TCP ports 43210 and 43211 to execute commands as root. If you run affected Nexus 9000 hardware, this is imme…

threatnoir.com/focus

🤖 AI generated summary

##

undercodenews@mastodon.social at 2026-09-03T20:53:05.000Z ##

Cisco Nexus 9000 Critical Flaw Exposes Silicon One Switches to Root-Level Remote Code Execution + Video

A Dangerous New Warning for Data Center Networks A critical vulnerability in Cisco Nexus 9000 Series switches has turned a routine software security update into an urgent priority for organizations operating affected data center infrastructure. Tracked as CVE-2026-20212, the flaw carries a CVSS score of 9.8 and can allow an unauthenticated remote attacker to execute…

undercodenews.com/cisco-nexus-

##

Analyst207@mastodon.social at 2026-09-03T17:29:20.000Z ##

Cisco Discloses Critical Flaw in Nexus 9000 Switches

Cisco has uncovered a critical flaw in its Nexus 9000 switches, known as CVE-2026-20212, which could allow an unauthenticated attacker to remotely execute code as root. This vulnerability affects 10 specific models and has already been patched by the company.

osintsights.com/cisco-disclose

#Cisco #Nexus9000 #Cve202620212 #RemoteCodeExecution #SiliconOne

##

cyberworldops@infosec.exchange at 2026-09-03T22:20:01.000Z ##

Cisco disclosed CVE-2026-20212, a critical unauthenticated RCE in Silicon One on Nexus 9000 switches. Exploitation yields root execution via crafted data, putting core data-center fabric at risk of full compromise. #CiscoNexus #SiliconOne #NetworkSecurity

cyberworldops.eu/en/cisco-nexu

##

threatnoir@infosec.exchange at 2026-09-03T21:05:54.000Z ##

⚠️ CRITICAL: Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Cisco released patches for CVE-2026-20212, a critical unauthenticated remote code execution vulnerability in Nexus 9000 switches (10 Silicon One-based models). Attackers can exploit this via TCP ports 43210 and 43211 to execute commands as root. If you run affected Nexus 9000 hardware, this is imme…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

DailyCyberSecurity@infosec.exchange at 2026-09-03T03:39:50.000Z ##

CVE-2026-20212, a critical Cisco Nexus 9000 vulnerability, lets an unauthenticated attacker gain remote code execution with root privileges. CVSS 9.8.

#Cisco #Nexus9000 #SiliconOne #RCE #NXOS #NetworkSecurity #InfoSec #PatchNow

securityonline.info/cisco-nexu

##

AAKL@infosec.exchange at 2026-09-02T16:36:40.000Z ##

New security advisories.

Broadcom has addressed several vulnerabilities,two of them critical support.broadcom.com/web/ecx/s #Broadcom

Cisco: Five advisories, two of them addressing critical vulnerabilities:

- CRITICAL: CVE-2026-20212: Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability sec.cloudapps.cisco.com/securi

- CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi

More: sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

CVE-2026-82329
(9.8 CRITICAL)

EPSS: 7.67%

updated 2026-09-02T18:31:57

11 posts

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

Nuclei template

5 repos

https://github.com/ynsmroztas/CVE-2026-82329-JFrog-Artifactory-Auth-Bypass

https://github.com/0xCyp1337/CVE-2026-82329

https://github.com/realalexandergeorgiev/artifactory-CVE-2026-82329-poc.py

https://github.com/dinosn/cve-2026-82329-jfrog-artifactory

https://github.com/HORKimhab/CVE-2026-82329

Matchbook3469@mastodon.social at 2026-09-03T19:10:28.000Z ##

🔵 THREAT INTELLIGENCE

Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

Vulnerability | CRITICAL
CVEs: CVE-2026-82329

A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide...

Full analysis:
yazoul.net/news/article/hacker

by Yazoul AI

#CyberSecurity #APT #CyberNews

##

AAKL@infosec.exchange at 2026-09-02T19:01:22.000Z ##

Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.

- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-02T19:00:11.000Z ##

🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48710 (secdb.nttzen.cloud/cve/detail/)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/Kludex/starlette/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-49869 (secdb.nttzen.cloud/cve/detail/)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/kestra-io/kestra/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-59822 (secdb.nttzen.cloud/cve/detail/)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: github.com/BerriAI/litellm/sec ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82329 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83548 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83549 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9586 (secdb.nttzen.cloud/cve/detail/)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: sangomakb.atlassian.net/wiki/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260902 #cisa20260902 #cve_2026_48710 #cve_2026_49869 #cve_2026_59822 #cve_2026_82329 #cve_2026_83548 #cve_2026_83549 #cve_2026_9586 #cve202648710 #cve202649869 #cve202659822 #cve202682329 #cve202683548 #cve202683549 #cve20269586

##

cisakevtracker@mastodon.social at 2026-09-02T18:01:42.000Z ##

CVE ID: CVE-2026-82329
Vendor: JFrog
Product: Artifactory
Date Added: 2026-09-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

oversecurity@mastodon.social at 2026-09-02T16:10:21.000Z ##

Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide...

🔗️ [Bleepingcomputer] link.is.it/GGGBsY

##

beyondmachines1@infosec.exchange at 2026-09-02T08:01:30.000Z ##

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens

JFrog Artifactory is facing active exploitation of a critical authentication bypass (CVE-2026-82329) that allows unauthenticated attackers to mint administrator tokens and compromise software supply chains.

**If you run self-managed JFrog Artifactory, update to version 7.161.20 ASAP. Attackers are already exploiting this flaw to take full admin control. Primary systems at risk are internet facing self-hosted Artifactory instances. Cloud-hosted instances managed by JFrog are not affected.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

youranonnewsirc@nerdculture.de at 2026-09-02T04:26:22.000Z ##

Geopolitical tensions persist between the U.S. and Iran regarding actions in the Strait of Hormuz (Sept 1, 2026). On the cybersecurity front, critical infrastructure, including Midwest water utilities, faces new ransomware attacks. Additionally, a severe authentication bypass flaw (CVE-2026-82329) in JFrog Artifactory is actively being exploited. OpenAI has issued a stark warning regarding the escalating threat of AI-enabled cyberattacks.

#AnonNews_irc #Cybersecurity #Anonymous #News

##

AAKL@infosec.exchange at 2026-09-01T16:11:54.000Z ##

New.

WatchTower, on X:

"WatchTowr Intel is already seeing exploitation of the JFrog Artifactory Auth Bypass (CVE-2026-82329), with attackers minting themselves admin tokens."

More:

Security Week: Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild securityweek.com/critical-jfro @SecurityWeek #vulnerability #infosec

##

security_crawler_carl@infosec.exchange at 2026-09-01T16:11:24.000Z ##

🏆 New Achievement! Admin Tokens: A Self-Service Experience!

The System, acting in its capacity as counsel for the prosecution, hereby submits Exhibit A: CVE-2026-82329, a CVSS 9.8 authentication bypass in JFrog Artifactory, patched August 28. Per WatchTowr's testimony, unknown attackers were, within days of public disclosure, "minting themselves admin tokens" via default configurations — no credentials required. Your Honor, the defendant did knowingly operate an unpatched instance. (1/2)

##

cyberworldops@infosec.exchange at 2026-09-01T10:20:00.000Z ##

JFrog Artifactory is affected by critical CVE-2026-82329 (CVSS 9.8) allowing unauthenticated remote attackers to create administrative tokens via default configurations. With reports of active exploitation, this enables full system takeover and severe software supply chain compromise. Immediate patching is essential. #JFrog #SupplyChainSecurity #VulnerabilityManagement

cyberworldops.eu/en/jfrog-arti

##

DailyCyberSecurity@infosec.exchange at 2026-09-01T06:29:28.000Z ##

A critical Artifactory authentication bypass flaw (CVE-2026-82329) is exploited in the wild, letting attackers obtain administrative privileges.

#Artifactory #CVE202682329 #CyberSecurity #AuthenticationBypass #Exploit

securityonline.info/cve-2026-8

##

CVE-2026-53649
(9.6 CRITICAL)

EPSS: 0.21%

updated 2026-09-02T18:19:59.973000

1 posts

Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a wildcard CORS policy. Because plugin uploads use the CORS-safelisted multipart/form-data content type, cross-origin JavaScript on any page the operator visits can reach privileged endpoints - including uploading a native plugin

thehackerwire@mastodon.social at 2026-09-03T00:00:21.000Z ##

🔴 CVE-2026-53649 - Critical (9.6)

Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a wildcard CORS policy. Because plugin uploads use the CORS-safelisted multip...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84700
(8.6 HIGH)

EPSS: 0.35%

updated 2026-09-02T16:17:32.577000

1 posts

PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client port 9221 is used) that does not authenticate incoming requests. Although requirepass is intended to gate replication — a slave presents it as masterauth inside its MetaSync request — only the MetaSync handler (HandleMetaSyncRequest) validates

thehackerwire@mastodon.social at 2026-09-02T11:00:34.000Z ##

🟠 CVE-2026-84700 - High (8.6)

PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client port 9221 is used) that does not authenticate incoming requests. Although requirepass is in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84375
(7.5 HIGH)

EPSS: 0.39%

updated 2026-09-02T16:17:28.813000

1 posts

js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources while processing the merge key <<. An attacker can alias a large sequence of empty mappings into many merge targets, causing O(N * K) processing while totalMergeKeys remains unchanged and the configured resource limit i

thehackerwire@mastodon.social at 2026-09-01T23:00:46.000Z ##

🟠 CVE-2026-84375 - High (7.5)

js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources while processing the merge key &lt;&lt;. An attacker can alias a l...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73749
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-09-02T15:34:36

4 posts

Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could result in remote code execution with elevated privileges.

cyberworldops at 2026-09-03T20:10:00.982Z ##

HPE patched CVE-2026-73749, a critical unauthenticated buffer overflow in ArubaOS-CX. Exploitation via crafted packets to a vulnerable daemon can yield privileged remote code execution on enterprise switches, risking full network takeover.

cyberworldops.eu/en/arubaos-cx

##

Analyst207@mastodon.social at 2026-09-03T18:29:06.000Z ##

HPE Fixes Remote Code Execution Flaw in ArubaOS-CX

HPE has patched a critical flaw in ArubaOS-CX that could let hackers run malicious code with elevated privileges - and all they need to do is send specially crafted packets to an affected device. This remote code execution vulnerability, tracked as CVE-2026-73749, is a serious threat that demands immediate attention.

osintsights.com/hpe-fixes-remo

#RemoteCodeExecution #Arubaoscx #Cve202673749 #BufferOverflow #Hpe

##

cyberworldops@infosec.exchange at 2026-09-03T20:10:00.000Z ##

HPE patched CVE-2026-73749, a critical unauthenticated buffer overflow in ArubaOS-CX. Exploitation via crafted packets to a vulnerable daemon can yield privileged remote code execution on enterprise switches, risking full network takeover. #HpeAruba #ArubaOS #NetworkSecurity

cyberworldops.eu/en/arubaos-cx

##

DailyCyberSecurity@infosec.exchange at 2026-09-03T01:58:31.000Z ##

CVE-2026-73749: Unauth RCE in HPE Networking AOS-CX Scores 9.8

securityonline.info/hpe-aos-cx

##

CVE-2026-76657
(10.0 CRITICAL)

EPSS: 0.43%

updated 2026-09-02T15:14:09.307000

1 posts

Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the HPE Networking Fabric Composer host.

DailyCyberSecurity@infosec.exchange at 2026-09-01T23:48:57.000Z ##

Critical HPE Fabric Composer vulnerabilities, including CVE-2026-76657, allow remote code execution. Update to version 7.4.0 now to secure your network.

#HPE #FabricComposer #Vulnerability #Cybersecurity #CVE202676657

securityonline.info/hpe-fabric

##

CVE-2026-84795
(9.8 CRITICAL)

EPSS: 0.28%

updated 2026-09-02T14:17:17.193000

1 posts

Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled email verification are configured.

cR0w@infosec.exchange at 2026-09-02T14:03:04.000Z ##

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.8 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled email verification are configured.

Seems like a pretty limited scope but it's still interesting to see that sev:CRIT in the CVE when the advisory says sev:MED:

github.com/craftcms/cms/securi

##

CVE-2026-84485
(7.5 HIGH)

EPSS: 0.35%

updated 2026-09-02T11:17:25.947000

1 posts

APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. Attackers can query the endpoint with space identifiers obtained from shared links or public templates to enumerate the complete member directory of any workspace.

thehackerwire@mastodon.social at 2026-09-02T08:00:34.000Z ##

🟠 CVE-2026-84485 - High (7.5)

APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. Attackers can query the endpoint with ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14828
(8.8 HIGH)

EPSS: 1.44%

updated 2026-09-02T09:31:34

1 posts

Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.

thehackerwire@mastodon.social at 2026-09-02T11:00:25.000Z ##

🟠 CVE-2026-14828 - High (8.8)

Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78657
(9.8 CRITICAL)

EPSS: 0.72%

updated 2026-09-02T06:31:26

1 posts

The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_files function in all versions up to, and including, 1.4.11. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted

thehackerwire@mastodon.social at 2026-09-02T07:01:18.000Z ##

🔴 CVE-2026-78657 - Critical (9.8)

The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_files function in all versions up to, and including, 1.4.11. This makes it po...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9055
(9.8 CRITICAL)

EPSS: 0.29%

updated 2026-09-02T06:31:24

1 posts

The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the customer update endpoint, which allows customers to set their role to 'manager' and trigger creation of a WordPress user with the wpamelia-manager role when t

1 repos

https://github.com/EXEcution-py/CVE-2026-9055

thehackerwire@mastodon.social at 2026-09-02T08:00:24.000Z ##

🔴 CVE-2026-9055 - Critical (9.8)

The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the cus...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14357
(8.8 HIGH)

EPSS: 0.65%

updated 2026-09-02T06:31:24

1 posts

The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.3.0. This is due to a missing capability check and missing nonce validation in the DPDEV_install_themes_func() function registered on the wp_ajax_DPDEV_install_themes action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install arbitrary t

thehackerwire@mastodon.social at 2026-09-02T07:01:30.000Z ##

🟠 CVE-2026-14357 - High (8.8)

The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.3.0. This is due to a missing capability check and missing nonce validation in the DPDEV_install_themes_func() function registered on th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-46418
(7.6 HIGH)

EPSS: 0.68%

updated 2026-09-02T06:31:19

1 posts

Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.

thehackerwire@mastodon.social at 2026-09-02T07:01:42.000Z ##

🟠 CVE-2025-46418 - High (7.6)

Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82393
(7.5 HIGH)

EPSS: 0.41%

updated 2026-09-02T04:18:02.693000

1 posts

pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts rejects slash characters only for unscoped names. During pnpm install, the unvalidated name reaches raw path joins in pnpm11/installing/deps-resolver/src/resolvePeers.ts, pnpm11/installing/deps-re

thehackerwire@mastodon.social at 2026-08-31T23:00:16.000Z ##

🟠 CVE-2026-82393 - High (7.5)

pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts rejects slash characters only for unscoped ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84699
(9.1 CRITICAL)

EPSS: 0.37%

updated 2026-09-02T03:31:17

1 posts

Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.

cR0w@infosec.exchange at 2026-09-02T14:01:22.000Z ##

"Just use a password manager."

nvd.nist.gov/vuln/detail/cve-2

Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.

##

CVE-2026-84715
(8.8 HIGH)

EPSS: 0.32%

updated 2026-09-02T03:31:17

1 posts

FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permission records. A subuser with minimal permissions can send a crafted request to grant themselves full server control, enabling unauthorized access to sensitive data, backups, and server configuration.

thehackerwire@mastodon.social at 2026-09-02T08:00:43.000Z ##

🟠 CVE-2026-84715 - High (8.8)

FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permission records. A subuser with minimal permissions can send a crafted reques...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14982
(8.1 HIGH)

EPSS: 0.52%

updated 2026-09-02T03:31:14

1 posts

The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete function in all versions. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

thehackerwire@mastodon.social at 2026-09-02T05:00:54.000Z ##

🟠 CVE-2026-14982 - High (8.1)

The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete function in all versions. This makes it possible for authenticated attackers, with subscriber-level access an...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14957
(7.5 HIGH)

EPSS: 0.56%

updated 2026-09-02T03:31:14

1 posts

In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if the RSA exponent is set to 0. A remote attacker can send a malformed X.509 certificate in a CERT payload to trigger the assertion, causing the pluto daemon to abort and restart. Co

thehackerwire@mastodon.social at 2026-09-02T05:00:43.000Z ##

🟠 CVE-2026-14957 - High (7.5)

In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if the RSA exponent is set to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84702
(7.5 HIGH)

EPSS: 0.38%

updated 2026-09-02T03:31:13

1 posts

facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory. Attackers can supply traversal sequences in the job identifier parameter through the unauthenticated HTTP API to create files at arbitrary locations.

thehackerwire@mastodon.social at 2026-09-02T11:00:46.000Z ##

🟠 CVE-2026-84702 - High (7.5)

facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory. Attackers can supply traversal sequences in the job identifier parameter through the unauthenticated HT...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84484
(7.5 HIGH)

EPSS: 0.48%

updated 2026-09-02T02:17:20.450000

1 posts

ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending truncated SDNV values. Attackers can send a UDP datagram to the LTP link service input port with a truncated SDNV to trigger reads up to nine bytes past buffer boundaries and underflow byte counters.

thehackerwire@mastodon.social at 2026-09-02T05:01:06.000Z ##

🟠 CVE-2026-84484 - High (7.5)

ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending truncated SDNV values. Attackers can send a UDP datagram to the LTP link se...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84374
(7.5 HIGH)

EPSS: 0.57%

updated 2026-09-01T22:17:19.293000

1 posts

Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the Maatwebsite\Excel\Files\Disk::copy() method resolves the caller-controlled $destination supplied through Excel::store(), $export->store(), or storeExcel() against the process working directory with realpath() instead of the configured filesystem disk. If the path names an ex

thehackerwire@mastodon.social at 2026-09-01T23:00:36.000Z ##

🟠 CVE-2026-84374 - High (7.5)

Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the Maatwebsite\Excel\Files\Disk::copy() method resolves the caller-controlled $destination supplied through Excel::store(), $...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76658
(10.0 CRITICAL)

EPSS: 0.43%

updated 2026-09-01T21:31:59

1 posts

A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise.

cR0w@infosec.exchange at 2026-09-01T21:38:56.000Z ##

Vuln or bugdoor?

nvd.nist.gov/vuln/detail/cve-2

A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise.

##

CVE-2026-19952
(7.5 HIGH)

EPSS: 0.78%

updated 2026-09-01T20:47:54.130000

1 posts

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in all versions up to, and including, 3.29.12. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-conf

thehackerwire@mastodon.social at 2026-09-01T10:00:47.000Z ##

🟠 CVE-2026-19952 - High (7.5)

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in all versions up to, and including, 3.29.12. This makes it possible for unauthen...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82908
(8.8 HIGH)

EPSS: 0.12%

updated 2026-09-01T20:47:54.130000

1 posts

A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability is the function MmioWritePath in the library NTIOLib_X64.sys of the component MMIO Write Path Handler. Performing a manipulation of the argument count/elementSize results in integer overflow. The attack requires a local approach. The exploit has been made public and could be used. The vendor was contacte

thehackerwire@mastodon.social at 2026-08-31T22:00:14.000Z ##

🟠 CVE-2026-82908 - High (8.8)

A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability is the function MmioWritePath in the library NTIOLib_X64.sys of the component MMIO Write Path Handler. Performing a manipulation of the argument count/e...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84202
(8.8 HIGH)

EPSS: 0.37%

updated 2026-09-01T18:30:49

1 posts

ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can craft malicious model repositories with poisoned configuration files that execute code when loaded by users.

thehackerwire@mastodon.social at 2026-09-01T18:00:55.000Z ##

🟠 CVE-2026-84202 - High (8.8)

ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can craft malicious model repositories with poisoned configuration files that exec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84268
(8.8 HIGH)

EPSS: 0.33%

updated 2026-09-01T18:30:49

1 posts

A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrup

thehackerwire@mastodon.social at 2026-09-01T18:00:45.000Z ##

🟠 CVE-2026-84268 - High (8.8)

A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58566
(8.8 HIGH)

EPSS: 0.23%

updated 2026-09-01T18:30:49

1 posts

Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

thehackerwire@mastodon.social at 2026-09-01T18:00:36.000Z ##

🟠 CVE-2026-58566 - High (8.8)

Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84199
(7.7 HIGH)

EPSS: 0.26%

updated 2026-09-01T16:17:33.853000

1 posts

Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature. The URL field in a Policy's ServiceCall configuration is not validated, so a user with namespace-level Policy creation permissions can direct Kyverno to make HTTP requests to arbitrary internal resources (e.g., cloud metadata endpoints such as 169.254.169.254 or other tenants' resources). Beca

thehackerwire@mastodon.social at 2026-09-01T13:00:39.000Z ##

🟠 CVE-2026-84199 - High (7.7)

Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature. The URL field in a Policy's ServiceCall configuration is not validated, so a user with namespace-level Policy creation permissions can direct...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84115
(8.3 HIGH)

EPSS: 0.28%

updated 2026-09-01T15:31:23

3 posts

A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connections of the component JWT Refresh Token Handler. Performing a manipulation of the argument Bearer results in improper privilege management. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 5.8.1.11 i

rhudaur@flipboard.com at 2026-09-03T17:05:20.000Z ##

CVE-2026-84115 in Cleo Harmony: JWT Refresh Token Handler Flaw Exposes Remote Attack Risk
thecyberexpress.com/cve-2026-8

Posted into Cybersecurity Today @cybersecurity-today-rhudaur

##

rhudaur@flipboard.com at 2026-09-03T17:05:20.000Z ##

CVE-2026-84115 in Cleo Harmony: JWT Refresh Token Handler Flaw Exposes Remote Attack Risk
thecyberexpress.com/cve-2026-8

Posted into Cybersecurity Today @cybersecurity-today-rhudaur

##

oversecurity@mastodon.social at 2026-09-03T09:40:18.000Z ##

CVE-2026-84115 in Cleo Harmony: JWT Refresh Token Handler Flaw Exposes Remote Attack Risk

A critical vulnerability identified as CVE-2026-84115 affects Cleo Harmony versions through 5.8.1.10, with the weakness tied to the platform’s JWT

🔗️ [Thecyberexpress] link.is.it/lkJ3B6

##

CVE-2026-62911
(8.0 HIGH)

EPSS: 1.32%

updated 2026-09-01T15:30:53

4 posts

Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

1 repos

https://github.com/hypnguyen1209/CVE-2026-62911

DailyCyberSecurity@infosec.exchange at 2026-09-03T08:02:34.000Z ##

Nearly 22,000 internet-facing Exchange servers remain unpatched against CVE-2026-62911, an authentication bypass that can hijack every user's mailbox.

#CVE202662911 #MicrosoftExchange #AuthenticationBypass #Shadowserver #Patch

meterpreter.org/exchange-cve-2

##

benzogaga33@mamot.fr at 2026-09-02T09:40:03.000Z ##

Exchange Server : près de 22 000 serveurs exposés sont vulnérables à la CVE-2026-62911 it-connect.fr/microsoft-exchan #ActuCybersécurité #Cybersécurité #Vulnérabilité #Microsoft #Exchange

##

threatnoir@infosec.exchange at 2026-09-01T20:06:48.000Z ##

⚠️ CRITICAL: Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

A critical authentication bypass vulnerability (CVE-2026-62911) affects approximately 22,000 unpatched Microsoft Exchange servers running versions 2016, 2019, and SE. Attackers can hijack all user mailboxes on vulnerable systems. Exploit code is publicly available; active exploitation in the wild h…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

DailyCyberSecurity@infosec.exchange at 2026-09-01T01:34:19.000Z ##

Security researchers released technical details and PoC code for CVE-2026-62911, a critical Exchange Server pre-auth RCE flaw.

#ExchangeServer #CVE202662911 #CyberSecurity #RCE #Pwn2Own

securityonline.info/cve-2026-6

##

CVE-2026-84196
(7.7 HIGH)

EPSS: 0.26%

updated 2026-09-01T12:31:56

1 posts

Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url that allows authenticated users to send arbitrary HTTP requests by injecting user-controlled input through variable substitution. Attackers can target internal services, cloud metadata endpoints, and loopback addresses, with response data reflected in admission error messages enabling non-blind data e

thehackerwire@mastodon.social at 2026-09-01T13:00:23.000Z ##

🟠 CVE-2026-84196 - High (7.7)

Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url that allows authenticated users to send arbitrary HTTP requests by injecting user-controlled input through variable substitution. Attackers can targe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84195
(7.7 HIGH)

EPSS: 0.29%

updated 2026-09-01T12:31:56

1 posts

Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorization headers. Attackers can exfiltrate the token by directing apiCall requests to external or attacker-controlled endpoints, gaining full control over Kyverno policies and cluster resources.

thehackerwire@mastodon.social at 2026-09-01T13:00:12.000Z ##

🟠 CVE-2026-84195 - High (7.7)

Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorization headers. Attackers can exfiltrate the token by directing apiCall requests...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19806
(8.8 HIGH)

EPSS: 0.40%

updated 2026-09-01T06:33:01

1 posts

The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 1.4.52 via the `guest_ticket_login()` function and its `p` parameter. This is due to the site-wide AES-256-CBC encryption key being derived from only three two-digit `

thehackerwire@mastodon.social at 2026-09-01T10:00:37.000Z ##

🟠 CVE-2026-19806 - High (8.8)

The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 1.4.52 via t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-83772
(9.9 CRITICAL)

EPSS: 1.69%

updated 2026-09-01T06:33:01

1 posts

A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the function c_set_reports_decode of the file mail-report.sh of the component JSON Parsing. The manipulation of the argument sender/recipients results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contact

thehackerwire@mastodon.social at 2026-09-01T10:00:28.000Z ##

🔴 CVE-2026-83772 - Critical (9.9)

A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the function c_set_reports_decode of the file mail-report.sh of the component JSON Parsing. The manipulation of the argument sender...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75865
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-09-01T03:31:10

1 posts

The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the saas_upload_logo() function combined with an authorization bypass on the WPLP connector REST endpoints in all versions up to, and including, 4.4.1. This makes it possible for unauthenticated attacker

thehackerwire@mastodon.social at 2026-09-01T03:59:48.000Z ##

🔴 CVE-2026-75865 - Critical (9.8)

The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the saas_upload_logo() function combined with an...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67394(CVSS UNKNOWN)

EPSS: 1.17%

updated 2026-09-01T03:31:09

1 posts

A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a customer or reseller with shell access (or allowed to change their own shell access) to elevate privileges to the root account on the hosting server.

cR0w@infosec.exchange at 2026-09-01T13:53:17.000Z ##

sev:CRIT LPE in Plesk. Gotta love that shared infra and the inherited risk that comes with it.

nvd.nist.gov/vuln/detail/cve-2

A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a customer or reseller with shell access (or allowed to change their own shell access) to elevate privileges to the root account on the hosting server.

##

CVE-2026-82954
(9.9 CRITICAL)

EPSS: 0.62%

updated 2026-09-01T00:31:43

1 posts

A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. The manipulation of the argument path results in path traversal. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but

thehackerwire@mastodon.social at 2026-08-31T22:59:56.000Z ##

🔴 CVE-2026-82954 - Critical (9.9)

A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. The manipulation of the argument path results in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82882
(8.8 HIGH)

EPSS: 0.31%

updated 2026-09-01T00:31:42

1 posts

Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenticated account can query the endpoint with arbitrary project, environment, and application parameters to retrieve plaintext super-admin JWT tokens for full platform control.

thehackerwire@mastodon.social at 2026-08-31T23:00:05.000Z ##

🟠 CVE-2026-82882 - High (8.8)

Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenticated account can query the endpoint with arbitr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-83596
(8.8 HIGH)

EPSS: 0.29%

updated 2026-08-31T21:32:23

1 posts

A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.

thehackerwire@mastodon.social at 2026-08-31T22:00:03.000Z ##

🟠 CVE-2026-83596 - High (8.8)

A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82226
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-08-31T21:32:22

1 posts

Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.

thehackerwire@mastodon.social at 2026-08-31T22:00:24.000Z ##

🔴 CVE-2026-82226 - Critical (9.8)

Unauthenticated PHP Object Injection in Tickera &lt;= 3.6.0.2 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81578
(9.8 CRITICAL)

EPSS: 0.77%

updated 2026-08-31T21:31:56

6 posts

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

2 repos

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

https://github.com/virologi-info/papercut-toolkit

security_crawler_carl@infosec.exchange at 2026-09-02T09:44:29.000Z ##

Huntress logged confirmed attacks against at least two customers.

SYSTEM NOTE: WatchTowr did not make this worse. The situation was already worse. WatchTowr merely filed a report.

Apply PaperCut's emergency patches for both CVE-2026-81578 and CVE-2026-82078 immediately, and check for indicators of compromise dating back to August 26.

Reward: You've received a Duplicate Incident Ticket — it's the same as the first one but somehow more urgent.

#PaperCut #ZeroDay #CVE #CyberSecurity (2/2)

##

security_crawler_carl@infosec.exchange at 2026-09-02T09:44:29.000Z ##

🏆 New Achievement! Print Job: Ownership Complete!

ERROR: Assumed single zero-day. Actual zero-days: two. PaperCut, the print management software, has had CVE-2026-81578 and CVE-2026-82078 exploited in the wild since August 26 — the first a high-severity authentication bypass letting remote, unauthenticated attackers modify system configurations. WatchTowr then found additional patch bypasses, triggering a second emergency patch before the first one was even officially released. (1/2)

##

secdb@infosec.exchange at 2026-08-31T17:00:11.000Z ##

🚨 [CISA-2026:0831] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-81578 (secdb.nttzen.cloud/cve/detail/)
- Name: PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: PaperCut
- Product: NG/MF
- Notes: papercut.com/kb/Main/security- ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82078 (secdb.nttzen.cloud/cve/detail/)
- Name: PaperCut NG/MF Unsafe Reflection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: PaperCut
- Product: NG/MF
- Notes: papercut.com/kb/Main/security- ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260831 #cisa20260831 #cve_2026_81578 #cve_2026_82078 #cve202681578 #cve202682078

##

AAKL@infosec.exchange at 2026-08-31T16:26:51.000Z ##

PaperCut has made the cut. Two vulnerabilities have been added to the KEV catalogue.

CISA: CVE-2026-81578: PaperCut NG/MF Missing Authentication for Critical Function Vulnerability

CVE-2026-82078: PaperCut NG/MF Unsafe Reflection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability

##

cisakevtracker@mastodon.social at 2026-08-31T16:01:06.000Z ##

CVE ID: CVE-2026-81578
Vendor: PaperCut
Product: NG/MF
Date Added: 2026-08-31
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

thecybermind@infosec.exchange at 2026-08-31T15:32:25.000Z ##

URGENT C-Suite Brief: CVE-2026-81578 active exploitation targets PaperCut NG/MF authentication flaws. Read our executive brief for rapid patch deployment, EDR monitoring, and access controls to safeguard your enterprise perimeter. thecybermind.co/4im9

##

CVE-2026-82078
(9.1 CRITICAL)

EPSS: 0.93%

updated 2026-08-31T21:31:56

8 posts

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on

2 repos

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

https://github.com/virologi-info/papercut-toolkit

security_crawler_carl@infosec.exchange at 2026-09-02T09:44:29.000Z ##

Huntress logged confirmed attacks against at least two customers.

SYSTEM NOTE: WatchTowr did not make this worse. The situation was already worse. WatchTowr merely filed a report.

Apply PaperCut's emergency patches for both CVE-2026-81578 and CVE-2026-82078 immediately, and check for indicators of compromise dating back to August 26.

Reward: You've received a Duplicate Incident Ticket — it's the same as the first one but somehow more urgent.

#PaperCut #ZeroDay #CVE #CyberSecurity (2/2)

##

security_crawler_carl@infosec.exchange at 2026-09-02T09:44:29.000Z ##

🏆 New Achievement! Print Job: Ownership Complete!

ERROR: Assumed single zero-day. Actual zero-days: two. PaperCut, the print management software, has had CVE-2026-81578 and CVE-2026-82078 exploited in the wild since August 26 — the first a high-severity authentication bypass letting remote, unauthenticated attackers modify system configurations. WatchTowr then found additional patch bypasses, triggering a second emergency patch before the first one was even officially released. (1/2)

##

thecybermind@infosec.exchange at 2026-09-01T07:31:08.000Z ##

T-Suite Technical Brief: CVE-2026-82078 active exploitation targets PaperCut NG/MF with unsafe reflection & arbitrary Java execution. Read our engineering runbook for CrowdStrike CQL detection rules, ATT&CK mapping, and hardening controls.
thecybermind.co/zqkw

##

thecybermind@infosec.exchange at 2026-09-01T04:38:34.000Z ##

URGENT C-Suite Brief: CVE-2026-82078 active exploitation targets PaperCut NG/MF with unsafe reflection and arbitrary Java execution. Read our executive brief for rapid EDR tuning, least privilege controls, and asset integrity protection. thecybermind.co/pzil

##

thecybermind@infosec.exchange at 2026-08-31T21:45:29.000Z ##

URGENT C-Suite Brief: CVE-2026-82078 active exploitation targets PaperCut NG/MF with unsafe reflection and arbitrary Java execution. Read our executive brief for rapid EDR tuning, least privilege controls, and asset integrity protection. thecybermind.co/4im9

##

secdb@infosec.exchange at 2026-08-31T17:00:11.000Z ##

🚨 [CISA-2026:0831] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-81578 (secdb.nttzen.cloud/cve/detail/)
- Name: PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: PaperCut
- Product: NG/MF
- Notes: papercut.com/kb/Main/security- ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82078 (secdb.nttzen.cloud/cve/detail/)
- Name: PaperCut NG/MF Unsafe Reflection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: PaperCut
- Product: NG/MF
- Notes: papercut.com/kb/Main/security- ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260831 #cisa20260831 #cve_2026_81578 #cve_2026_82078 #cve202681578 #cve202682078

##

AAKL@infosec.exchange at 2026-08-31T16:26:51.000Z ##

PaperCut has made the cut. Two vulnerabilities have been added to the KEV catalogue.

CISA: CVE-2026-81578: PaperCut NG/MF Missing Authentication for Critical Function Vulnerability

CVE-2026-82078: PaperCut NG/MF Unsafe Reflection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability

##

cisakevtracker@mastodon.social at 2026-08-31T16:00:50.000Z ##

CVE ID: CVE-2026-82078
Vendor: PaperCut
Product: NG/MF
Date Added: 2026-08-31
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-81934
(9.8 CRITICAL)

EPSS: 0.43%

updated 2026-08-31T21:31:55

2 posts

Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server. Fixed in Redis 8.2.9, 8.4.6, 8.6.6, 8.8.2, and 8.10.1.

CVE-2026-79748
(9.9 CRITICAL)

EPSS: 0.33%

updated 2026-08-31T19:17:13.667000

1 posts

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.15, the POST /api/servers and PUT /api/servers/:name endpoints in MCPHub create/update MCP server configurations and then immediately spawn the configured stdio process via child_process.spawn. Authentication is requi

thehackerwire@mastodon.social at 2026-08-31T19:00:17.000Z ##

🔴 CVE-2026-79748 - Critical (9.9)

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.15, the POST /api/servers and PUT /api/servers/:name endpoints i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-83492(CVSS UNKNOWN)

EPSS: 0.24%

updated 2026-08-31T18:31:39

1 posts

Improper input validation vulnerability in Extend Themes Kubio AI Website Builder. This issue affects Kubio AI Website Builder: before 2.9.1.

AAKL@infosec.exchange at 2026-08-31T16:51:36.000Z ##

New. This is CVE-2026-83492, meduim severity.

Tenable Research Advisories: WordPress - Kubio AI Website Builder DoS tenable.com/security/research/ @tenable #infosec #WordPress #vulnerability

##

CVE-2026-6876(CVSS UNKNOWN)

EPSS: 0.40%

updated 2026-08-28T21:32:13

1 posts

ServiceNow has remediated a sandbox escape security issue that was identified in the Now Platform. This security issue could allow an unauthenticated user to execute arbitrary code within the Now Platform, potentially leading to more access to the Now Platform than intended.   ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self

cR0w@infosec.exchange at 2026-09-01T19:20:04.000Z ##

RE: infosec.exchange/@cR0w/1171693

Update:

Update - September 1st, 2026

Due to additional analysis provided by the security researcher who discovered CVE-2026-6875, we have upgraded the severity rating of CVE-2026-6876 from High to Critical. This change affects only the severity rating for CVE-2026-6876; it does not change the other information shared in our August 27th advisory. Based on our monitoring to date, we have not observed evidence of malicious exploitation of this issue.

##

CVE-2026-66147
(9.4 CRITICAL)

EPSS: 2.00%

updated 2026-08-28T18:58:27.140000

1 posts

An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.

pentesttools@infosec.exchange at 2026-09-01T14:29:08.000Z ##

Oh, look, it's a fresh batch of CVEs that our #offensivesecurity research team found (and responsibly reported)!

They all impact SonicWall GMS, which SonicWall has now patched:

👉 CVE-2026-66147 - unauthenticated command injection in the Dispatcher Service, CVSS 9.4
👉 CVE-2026-66154 - weak certificate verification leading to user compromise via MitM, CVSS 8.3*
👉 CVE-2026-18634 - local privilege escalation via deserialization, CVSS 8.4

When it shortens 🤏 the distance between discovery and action - *that’s* what #vulnerabilityresearch does to help security teams.

Here's our team's latest disclosed contribution to the community: psirt.global.sonicwall.com/vul

And here's where you can get more of our research: pentest-tools.com/research

PS: More SonicWALL vulnerabilities coming soon to a research blog near you. 🫵

##

CVE-2026-71362
(9.1 CRITICAL)

EPSS: 25.14%

updated 2026-08-28T00:18:09.390000

1 posts

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

Nuclei template

1 repos

https://github.com/dinosn/cve-2026-71362-magento-lab

secdb@infosec.exchange at 2026-09-01T07:54:00.000Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2023-49105
(9.8 CRITICAL)

EPSS: 43.20%

updated 2026-08-27T21:32:08

1 posts

An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.

Nuclei template

1 repos

https://github.com/ambionics/owncloud-exploits

thecybermind@infosec.exchange at 2026-08-31T14:40:05.000Z ##

URGENT C-Suite Brief: CVE-2023-49105 active exploitation targets ownCloud authentication flaws. Read our executive brief for rapid mitigation steps, identity governance controls, and asset integrity protocols to protect your enterprise perimeter. thecybermind.co/v5jn

##

secdb@infosec.exchange at 2026-09-01T07:54:00.000Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-19949
(8.8 HIGH)

EPSS: 0.54%

updated 2026-08-25T12:31:24

4 posts

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archive restore functionality in all versions up to, and including, 7.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing q

1 repos

https://github.com/HORKimhab/CVE-2026-19949

guru@thecybersecguru.com at 2026-09-03T18:57:21.000Z ##

Critical WordPress vulnerability exposes 3.2 million sites to remote code execution via All-in-One WP Migration

CVE-2026-19949 is a second-order SQL injection in All-in-One WP Migration and Backup that leads to unauthenticated RCE. Full exploit chain and fix

thecybersecguru.com/news/cve-2

##

guru@thecybersecguru.com at 2026-09-03T18:57:21.000Z ##

Critical WordPress vulnerability exposes 3.2 million sites to remote code execution via All-in-One WP Migration

CVE-2026-19949 is a second-order SQL injection in All-in-One WP Migration and Backup that leads to unauthenticated RCE. Full exploit chain and fix

thecybersecguru.com/news/cve-2

##

cyberworldops@infosec.exchange at 2026-09-03T12:10:00.000Z ##

Second-order SQL injection in All-in-One WP Migration and Backup restore function enables RCE, tracked as CVE-2026-19949. Affects versions up to 7.109, with ~3.2M sites exposed. Patch to 7.110 and audit for anomalous restore activity. #WordPressSecurity #SqlInjection #PatchManagement

cyberworldops.eu/en/wordpress-

##

beyondmachines1@infosec.exchange at 2026-09-03T10:01:29.000Z ##

ServMask Patches Critical SQL Injection in All-in-One WP Migration Plugin

ServMask patched a high-severity SQL injection vulnerability (CVE-2026-19949) in the All-in-One WP Migration and Backup plugin. The flaw allows unauthenticated attackers to leak secret keys and execute remote code when an administrator restores a site archive.

**If you use the All-in-One WP Migration and Backup plugin, update it to version 7.110 or later ASAP. Even if the plugin is currently inactive, since it becomes dangerous the moment someone turns it on for a migration. Until you've patched, don't run any import or export, turn off trackbacks and pings on public posts, and check your comments for suspicious entries.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-68162
(7.8 HIGH)

EPSS: 0.18%

updated 2026-08-23T13:16:34.493000

1 posts

In the Linux kernel, the following vulnerability has been resolved: sctp: avoid auth_enable sysctl UAF during netns teardown proc_sctp_do_auth() updates the SCTP control socket after changing net.sctp.auth_enable. The handler gets the per-net SCTP state from ctl->data, so an already opened sysctl file can still target a network namespace while that namespace is being torn down. SCTP previously

CVE-2026-68766
(7.8 HIGH)

EPSS: 0.16%

updated 2026-08-22T15:31:11

1 posts

hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and --potfile-path. Attackers can craft restore files with malicious options to append attacker-controlled content to arbitrary files, enabling code execution when targeting shell startup files.

tychotithonus@infosec.exchange at 2026-09-01T04:39:34.000Z ##

CVE-2026-68766 is a "vulnerability" in hashcat:

github.com/hashcat/hashcat/iss

... where, if you already have write access to hashcat's own restore files (which are locally generated, locally managed, and reachable by the same user invoking hashcat) ... you can ... pass arguments to hashcat other than the ones that were on the original command line. 😐

To be fair, atom did reduce the scope of what the hashcat restore command does -- instead of executing hashcat with the arguments, it just reassembles the cmdline and presents it to the user to review and run as appropriate:

github.com/hashcat/hashcat/com

Still a BS report, IMO -- just CVE farming.

Same reporter, different CVE, rejected outright because it doesn't cross a security boundary:

github.com/hashcat/hashcat/iss

(And I'm told that the CVE-issuance triage ambiguity -- that greenlit these CVEs that would have been rejected -- is being addressed.)

#hashcat

##

CVE-2026-73570
(8.9 HIGH)

EPSS: 32.38%

updated 2026-08-21T18:34:48

1 posts

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands a

6 repos

https://github.com/gabrielunknown/CVE-2026-73570

https://github.com/jishino567/CVE-2026-73570

https://github.com/INFOKOM-KI/Zimbra-CVE-2026-73570-Rules

https://github.com/alsyundawy/eradicate-zimbra-malware

https://github.com/HORKimhab/CVE-2026-73570

https://github.com/BiuTrap/CVE-2026-73570

secdb@infosec.exchange at 2026-09-01T07:54:00.000Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-64849
(9.3 CRITICAL)

EPSS: 16.41%

updated 2026-08-20T19:16:57.867000

1 posts

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated addr

Nuclei template

3 repos

https://github.com/zavisco/CVE-2026-64849.yaml

https://github.com/BiuTrap/CVE-2026-64849

https://github.com/codeb0ssx/CVE-2026-64849-PoC

secdb@infosec.exchange at 2026-09-01T07:54:00.000Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-32475
(9.0 None)

EPSS: 2.37%

updated 2026-08-19T18:32:57

5 posts

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.

Nuclei template

4 repos

https://github.com/sahmsec/CVE-2026-32475

https://github.com/0xBlackash/CVE-2026-32475

https://github.com/Boreas37/CVE-2026-32475-PoC

https://github.com/absholi7ly/Elementor-Pro-Unauthenticated-Arbitrary-File-Upload-to-RCE

undercodenews@mastodon.social at 2026-09-03T21:42:48.000Z ##

Critical Elementor Pro Vulnerability Is Being Actively Exploited — WordPress Sites Face Webshells, Remote Code Execution, and Full Takeover + Video

A New Warning for Millions of WordPress Sites A critical security problem in Elementor Pro has moved from vulnerability disclosure to real-world exploitation, putting vulnerable WordPress websites directly in the crosshairs of attackers. Tracked as CVE-2026-32475, the flaw allows an unauthenticated attacker to abuse the…

undercodenews.com/critical-ele

##

oversecurity@mastodon.social at 2026-09-03T15:00:44.000Z ##

Critical Elementor Pro flaw exploited to take over WordPress sites

A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a...

🔗️ [Bleepingcomputer] link.is.it/zUHe37

##

Analyst207@mastodon.social at 2026-09-03T14:59:05.000Z ##

Elementor Pro Exploit Targets WordPress Sites with Webshell Payload

A critical flaw in Elementor Pro, tracked as CVE-2026-32475, has put thousands of WordPress sites at risk, with nearly 200,000 attempted exploits blocked by Wordfence's web application firewall since August 19. This vulnerability allows attackers to bypass file-upload validation and inject a malicious PHP payload,…

osintsights.com/elementor-pro-

#Wordpress #ElementorPro #Cve202632475 #Webshell #FileuploadValidationBypass

##

oversecurity@mastodon.social at 2026-09-03T15:00:44.000Z ##

Critical Elementor Pro flaw exploited to take over WordPress sites

A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a...

🔗️ [Bleepingcomputer] link.is.it/zUHe37

##

DailyCyberSecurity@infosec.exchange at 2026-09-02T15:25:26.000Z ##

Attackers exploit a critical Elementor Pro vulnerability (CVE-2026-32475) in the wild. Patch this Elementor Pro vulnerability to prevent site takeover.

#ElementorPro #CVE202632475 #WordPress #Cybersecurity #RCE

securityonline.info/elementor-

##

CVE-2026-65400
(7.1 HIGH)

EPSS: 9.90%

updated 2026-08-18T18:31:47

1 posts

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

3 repos

https://github.com/panchocosil/CVE-2026-65400-poc

https://github.com/acheong08/CVE-2026-65400

https://github.com/HORKimhab/CVE-2026-65400

secdb@infosec.exchange at 2026-09-01T07:54:00.000Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-58231
(10.0 CRITICAL)

EPSS: 1.71%

updated 2026-08-17T15:39:24.573000

1 posts

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

3 repos

https://github.com/HORKimhab/CVE-2026-58231

https://github.com/WildanDeveloper/CVE-2026-58231

https://github.com/SAP-system-update/CVE-2026-58231

linuxmint_hun@mastodon.social at 2026-09-01T06:16:59.000Z ##

Az SAP Commerce Cloud CVE-2026-58231 sebezhetőségét már a javítás után napokkal támadások célba vették

linuxmint.hu/hir/2026/09/az-sa

##

CVE-2026-73296
(9.4 CRITICAL)

EPSS: 2.61%

updated 2026-08-13T15:20:13.333000

1 posts

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_server in ufo/client/mcp/http_servers/mobile_mcp_server.py exposed Streamable HTTP MCP services on TCP ports 8020 and 8021 without authentication, allowing an unauthenticated remote attacker to invoke capture_screenshot, get_ui_t

1 repos

https://github.com/0xBlackash/CVE-2026-73296

beyondmachines1@infosec.exchange at 2026-08-31T16:01:41.000Z ##

Microsoft UFO Vulnerability Allows Remote Android Device Takeover

Microsoft patched a critical vulnerability in its UFO automation framework (CVE-2026-73296) that allows unauthenticated attackers to remotely control Android devices and steal sensitive screen data. The flaw affects versions prior to 3.0.8 when configured for remote access.

**If you use Microsoft's UFO automation framework, update it to version 3.0.8 or later ASAP and turn on the required API key authentication. Older versions let anyone on the network fully control your connected Android devices. If you can't update immediately, change the setting back to `localhost` and block incoming traffic to ports 8020 and 8021 at your firewall.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-18634
(8.4 HIGH)

EPSS: 0.22%

updated 2026-08-12T18:31:15

1 posts

An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and earlier versions. A local attacker with the ability to interact with the service could exploit this behavior to perform unauthorized actions through the affected component.

pentesttools@infosec.exchange at 2026-09-01T14:29:08.000Z ##

Oh, look, it's a fresh batch of CVEs that our #offensivesecurity research team found (and responsibly reported)!

They all impact SonicWall GMS, which SonicWall has now patched:

👉 CVE-2026-66147 - unauthenticated command injection in the Dispatcher Service, CVSS 9.4
👉 CVE-2026-66154 - weak certificate verification leading to user compromise via MitM, CVSS 8.3*
👉 CVE-2026-18634 - local privilege escalation via deserialization, CVSS 8.4

When it shortens 🤏 the distance between discovery and action - *that’s* what #vulnerabilityresearch does to help security teams.

Here's our team's latest disclosed contribution to the community: psirt.global.sonicwall.com/vul

And here's where you can get more of our research: pentest-tools.com/research

PS: More SonicWALL vulnerabilities coming soon to a research blog near you. 🫵

##

CVE-2026-66154
(8.3 HIGH)

EPSS: 0.13%

updated 2026-08-12T00:31:10

1 posts

An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlier versions which, under a successful MitM attack and controlled network conditions, could permit unauthorized changes.

pentesttools@infosec.exchange at 2026-09-01T14:29:08.000Z ##

Oh, look, it's a fresh batch of CVEs that our #offensivesecurity research team found (and responsibly reported)!

They all impact SonicWall GMS, which SonicWall has now patched:

👉 CVE-2026-66147 - unauthenticated command injection in the Dispatcher Service, CVSS 9.4
👉 CVE-2026-66154 - weak certificate verification leading to user compromise via MitM, CVSS 8.3*
👉 CVE-2026-18634 - local privilege escalation via deserialization, CVSS 8.4

When it shortens 🤏 the distance between discovery and action - *that’s* what #vulnerabilityresearch does to help security teams.

Here's our team's latest disclosed contribution to the community: psirt.global.sonicwall.com/vul

And here's where you can get more of our research: pentest-tools.com/research

PS: More SonicWALL vulnerabilities coming soon to a research blog near you. 🫵

##

CVE-2026-48376
(5.4 MEDIUM)

EPSS: 13.92%

updated 2026-08-11T18:31:03

1 posts

is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction.

secdb@infosec.exchange at 2026-09-01T07:54:00.000Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-15733
(9.8 CRITICAL)

EPSS: 13.54%

updated 2026-08-07T18:31:37

1 posts

A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attackers to execute arbitrary commands as root.

Nuclei template

secdb@infosec.exchange at 2026-09-01T07:54:00.000Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-63077
(9.8 CRITICAL)

EPSS: 87.71%

updated 2026-08-05T18:32:31

1 posts

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Nuclei template

4 repos

https://github.com/BoredHackerBlog/teamcity-CVE-2026-63077-pcap

https://github.com/sfewer-r7/CVE-2026-63077

https://github.com/bakos-sandor-nx/teamcity-cve-2026-63077-remediation

https://github.com/AnggaTechI/CVE-2026-63077

beyondmachines1@infosec.exchange at 2026-09-01T08:01:41.000Z ##

JetBrains Cadence Service Breached via Unpatched TeamCity RCE Flaw

JetBrains reported a breach of its Cadence cloud service after failing to patch a critical TeamCity vulnerability (CVE-2026-63077). The attack resulted in the theft of user personal data and a 2024 server backup containing sensitive AWS credentials and source code.

**Rotate every secret used in your cloud development workflows immediately to prevent lateral movement. This breach shows that even a single unpatched internal server can expose your entire backup history and cloud credentials.**
#cybersecurity #infosec #incident #databreach
beyondmachines.net/event_detai

##

CVE-2026-18577
(8.1 HIGH)

EPSS: 54.07%

updated 2026-08-04T15:33:20

1 posts

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

Nuclei template

2 repos

https://github.com/CreamyG31337/ncentral-compromise-ioc-triage

https://github.com/HORKimhab/CVE-2026-18577

secdb@infosec.exchange at 2026-09-01T07:54:00.000Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-66066(CVSS UNKNOWN)

EPSS: 27.86%

updated 2026-07-30T18:23:34

1 posts

### Impact In its default configuration, a Rails application that displays image variants may allow an unauthenticated attacker to read arbitrary files from the server, including the process environment. That environment typically holds `secret_key_base` and often credentials for external systems, which may in turn allow escalation to remote code execution or lateral movement to those systems. ##

7 repos

https://github.com/Zer0SumGam3/CVE-2026-66066-POC

https://github.com/HackSpeak/CVE-2026-66066

https://github.com/rails/rails-forensics-CVE-2026-66066

https://github.com/0xsha/KindaRails2Shell

https://github.com/shinthink/CVE-2026-66066

https://github.com/paveg/rails-activestorage-vips-audit

https://github.com/0xBlackash/CVE-2026-66066

cyberworldops@infosec.exchange at 2026-09-01T06:20:01.000Z ##

VulnCheck reports active exploitation of CVE-2026-66066 (KindaRails2Shell), a CVSS 9.5 flaw in Ruby on Rails. A crafted image upload enables arbitrary file read, leading to secret and credential theft with potential for lateral movement and RCE. Unpatched Rails instances handling file uploads are at immediate risk. #RubyOnRails #KindaRails2Shell #InfoSec

cyberworldops.eu/en/kindarails

##

CVE-2026-43748
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-07-28T18:33:55

1 posts

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

DailyCyberSecurity@infosec.exchange at 2026-09-03T02:36:01.000Z ##

CVE-2026-43748 (CVSS 9.8) is an Apple ANE kernel OOB write reachable from a sandbox. Full details and macOS/iOS PoC code are now public. Update now.

#Apple #CVE202643748 #iOS #macOS #KernelBug #InfoSec #ANE

securityonline.info/apple-ane-

##

CVE-2026-61884
(9.8 CRITICAL)

EPSS: 0.66%

updated 2026-07-25T00:31:53

2 posts

The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and establish a valid administrative session. This grants full access to device controls including power relay management, dev

cyberworldops at 2026-09-03T18:20:00.948Z ##

Tycon TPDIN-Monitor-WEB2 before 2.4.5 is affected by CVE-2026-61884, a critical web authentication bypass allowing full admin access, and CVE-2026-55985 exposing cleartext credentials. Exposed OT monitoring units risk relay manipulation and config takeover.

cyberworldops.eu/en/tycon-tpdi

##

cyberworldops@infosec.exchange at 2026-09-03T18:20:00.000Z ##

Tycon TPDIN-Monitor-WEB2 before 2.4.5 is affected by CVE-2026-61884, a critical web authentication bypass allowing full admin access, and CVE-2026-55985 exposing cleartext credentials. Exposed OT monitoring units risk relay manipulation and config takeover. #TyconSystems #IcsSecurity #VulnManagement

cyberworldops.eu/en/tycon-tpdi

##

CVE-2026-55985
(4.3 MEDIUM)

EPSS: 0.15%

updated 2026-07-25T00:31:48

2 posts

The web management interface in  Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network.

cyberworldops at 2026-09-03T18:20:00.948Z ##

Tycon TPDIN-Monitor-WEB2 before 2.4.5 is affected by CVE-2026-61884, a critical web authentication bypass allowing full admin access, and CVE-2026-55985 exposing cleartext credentials. Exposed OT monitoring units risk relay manipulation and config takeover.

cyberworldops.eu/en/tycon-tpdi

##

cyberworldops@infosec.exchange at 2026-09-03T18:20:00.000Z ##

Tycon TPDIN-Monitor-WEB2 before 2.4.5 is affected by CVE-2026-61884, a critical web authentication bypass allowing full admin access, and CVE-2026-55985 exposing cleartext credentials. Exposed OT monitoring units risk relay manipulation and config takeover. #TyconSystems #IcsSecurity #VulnManagement

cyberworldops.eu/en/tycon-tpdi

##

CVE-2025-21913
(5.5 MEDIUM)

EPSS: 0.20%

updated 2026-07-14T13:17:26.703000

1 posts

In the Linux kernel, the following vulnerability has been resolved: x86/amd_nb: Use rdmsr_safe() in amd_get_mmconfig_range() Xen doesn't offer MSR_FAM10H_MMIO_CONF_BASE to all guests. This results in the following warning: unchecked MSR access error: RDMSR from 0xc0010058 at rIP: 0xffffffff8101d19f (xen_do_read_msr+0x7f/0xa0) Call Trace: xen_read_msr+0x1e/0x30 amd_get_mmconfig_range+

andersonc0d3@infosec.exchange at 2026-09-02T17:44:44.000Z ##

RE: infosec.exchange/@andersonc0d3

The exception table mechanism in the page fault handler is popular, but maybe the mechanism in the general protection handler isn't so well-known.

When the code is interacting with MSRs, if the MSR index/address is invalid for the architecture, it triggers a #GP and the kernel oopses. This can happen in some scenarios and most of the cases it shouldn't trigger an oops and crash the kernel. That's why there are two MSR access implementations: rdmsr() / rdmsrq() and rdmsr_safe() / rdmsrq_safe(). The rdmsr variants use split 32-bit values for high/low bits, while rdmsrq handles 64-bit quadwords directly.

There is a proposal to retire legacy 32-bit user-space MSR interfaces, but I haven't followed this closely.

Linux Preparing To Retire Its 32-bit MSR Interfaces
phoronix.com/news/Linux-Ending

The safe ones are supposed to not crash/oops the kernel when the #GP is issued. It implements the same exception table mechanism present in the page fault handler. That's why it contains *_safe() in the function name.

This is checked by the general protection fault handler via fixup_exception() at line below:

github.com/torvalds/linux/blob

There was an oops caused by the use of rdmsrl() when running the Linux kernel as a Xen guest and the fix was to replace rdmsrl() with rdmsrl_safe().

CVE-2025-21913: x86/amd_nb: Use rdmsr_safe() in amd_get_mmconfig_range()
lore.kernel.org/linux-cve-anno

x86/amd_nb: Use rdmsr_safe() in amd_get_mmconfig_range()
git.kernel.org/pub/scm/linux/k

The interface was rdmsrl before being renamed to rdmsrq.

In the case of virtualization, things get more complicated because the hypervisor might have different configurations. That issue in the Linux kernel seems to have been exposed due to a change in Xen regarding MSRs accesses.

xen/pv: support selecting safe/unsafe msr accesses git.kernel.org/pub/scm/linux/k

##

CVE-2026-6875(CVSS UNKNOWN)

EPSS: 77.58%

updated 2026-07-13T21:31:30

1 posts

ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates have also been provided to ServiceN

Nuclei template

3 repos

https://github.com/HORKimhab/CVE-2026-6875

https://github.com/Hunt-Benito/the-sanitizer-is-the-weapon-cve-2026-68749-cve-2026-68750-quadratic-dos-in-elixir-html-sanitize-ex

https://github.com/tc4dy/CVE-2026-6875-PoC-Exploit

cR0w@infosec.exchange at 2026-09-01T19:20:04.000Z ##

RE: infosec.exchange/@cR0w/1171693

Update:

Update - September 1st, 2026

Due to additional analysis provided by the security researcher who discovered CVE-2026-6875, we have upgraded the severity rating of CVE-2026-6876 from High to Critical. This change affects only the severity rating for CVE-2026-6876; it does not change the other information shared in our August 27th advisory. Based on our monitoring to date, we have not observed evidence of malicious exploitation of this issue.

##

CVE-2026-52831
(10.0 CRITICAL)

EPSS: 0.32%

updated 2026-07-08T20:24:21

1 posts

## Summary Nuclio controller builds a `curl` invocation string for each cron trigger and stores it as the `args` of a Kubernetes CronJob container (`/bin/sh`, `-c`, `<command>`). Two fields in the trigger specification flow into this string without adequate sanitization: - `event.headers` keys — interpolated verbatim inside double-quoted `--header` arguments (`lazy.go:2150`); any key containing

thehackerwire@mastodon.social at 2026-09-02T18:00:10.000Z ##

🟠 CVE-2026-52831 - High (8)

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio controller builds a curl invocation string for each cron trigger and stores it as the args of a Kubernetes CronJob container (/bin/sh,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8024
(9.8 CRITICAL)

EPSS: 0.55%

updated 2026-06-22T17:47:16.070000

1 posts

A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems.

certvde@infosec.exchange at 2026-09-02T09:56:27.000Z ##

🔄 CSAF advisory updated (version 2.0.0)

VDE-2026-051
iba: Deserialization vulnerability in ibaPDA and ibaDatCoordinator
CVE-2026-8024

Changes: Added ibaLogic to the affected products and the mitigation for this product.

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: iba.csaf-tp.certvde.com/.well-

#OT #Advisory

##

CVE-2026-0768
(9.8 CRITICAL)

EPSS: 2.26%

updated 2026-06-17T10:11:20.937000

4 posts

Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the code parameter provided to the validate endpoint. The issue results from the lack of proper validation of a use

2 repos

https://github.com/HORKimhab/CVE-2026-0768

https://github.com/rmhowe425/POC-CVE-2026-0768

DailyCyberSecurity@infosec.exchange at 2026-09-03T11:31:50.000Z ##

Attackers exploit Langflow CVE-2026-0768, an unauthenticated root RCE, to harvest OpenAI and AWS keys and admin credentials from exposed AI servers.

#Langflow #CVE20260768 #VulnCheck #OpenAI #AWS

meterpreter.org/langflow-cve-2

##

beyondmachines1@infosec.exchange at 2026-09-02T09:01:31.000Z ##

Hackers Exploit Zero-Day in Langflow AI Platform to Steal Credentials

Langflow's AI platform is under active attack via a zero-day vulnerability (CVE-2026-0768) that allows unauthenticated remote code execution as root. Attackers are using the flaw to steal environment variables, secret keys, and SSH credentials from vulnerable instances.

**If you use Langflow, this is important and urgent. Make sure the server is isolated from the internet and reachable only from trusted internal networks or via VPN. There is no patch for this flaw and attackers are already exploiting it to steal secrets. Treat any internet-exposed instance as potentially compromised and rotate every API key, token and password stored in or used by it.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

oversecurity@mastodon.social at 2026-09-01T18:50:41.000Z ##

Critical Langflow flaw exploited to steal OpenAI and AWS keys

Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for...

🔗️ [Bleepingcomputer] link.is.it/mc2J3U

##

cyberworldops@infosec.exchange at 2026-09-01T18:20:00.000Z ##

Actively exploited unauthenticated RCE in Langflow (CVE-2026-0768) allows remote code execution via the custom component validator. It enables extraction of OpenAI and AWS keys and root credentials, exposing AI infrastructure to full takeover. Patch and rotate all secrets immediately. #Langflow #CVE20260768 #InfoSec

cyberworldops.eu/en/langflow-u

##

CVE-2021-42260
(7.5 HIGH)

EPSS: 3.35%

updated 2026-06-17T04:09:31.687000

1 posts

TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case. It can be triggered by a crafted XML message and leads to a denial of service.

1 repos

https://github.com/vm2mv/tinyxml

cyberworldops@infosec.exchange at 2026-09-02T04:10:01.000Z ##

CISA reports CVE-2021-42260, a DoS vulnerability in Rockwell Automation ControlLogix, CompactLogix and GuardLogix controllers. The CWE-835 infinite loop is triggered by crafted data and results in a Major Non-Recoverable Fault requiring manual recovery, posing high availability risk for OT environments. #RockwellAutomation #ControlLogix #IcsSecurity

cyberworldops.eu/en/rockwell-a

##

CVE-2021-31886
(9.8 CRITICAL)

EPSS: 3.05%

updated 2026-06-17T03:52:25.290000

1 posts

A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.4), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.19), APOGEE PXC Modular (BACnet) (All versions < V3.5.4), APOGEE PXC Modular

cyberworldops@infosec.exchange at 2026-09-02T08:20:01.000Z ##

Forescout Research demonstrated porting a pre-auth RCE exploit for CVE-2021-31886 to a different WAGO PLC model using Anthropic Claude, achieving unauthenticated ARM shellcode execution on physical hardware. It shows how LLMs can accelerate exploit adaptation across OT variants, expanding exposure for unpatched systems. #Cve202131886 #OtSecurity #PlcSecurity

cyberworldops.eu/en/claude-ada

##

CVE-2026-45730
(8.3 HIGH)

EPSS: 0.26%

updated 2026-06-04T15:05:58

1 posts

This vulnerability exists in Nuclio Dashboard's project management API, allowing any authenticated user (without membership in the target project) to bypass OPA authorization checks on write paths (`PUT /api/projects/{id}`, `DELETE /api/projects`) and modify or delete any project along with all its associated resources (functions, API gateways, etc.). CWE classification: CWE-862 (Missing Authoriza

thehackerwire@mastodon.social at 2026-09-03T12:01:20.000Z ##

🟠 CVE-2026-45730 - High (8.3)

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.0, there is a vulnerability in Nuclio Dashboard's project management API, allowing any authenticated user (without membership in the target project)...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-35029(CVSS UNKNOWN)

EPSS: 25.07%

updated 2026-05-06T18:40:48

1 posts

### Impact The `/config/update endpoint` does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to do the following: - Modify proxy configuration and environment variables - Register custom pass-through endpoint handlers pointing to attacker-controlled Python code, achieving remote code execution - Read arbitrary server f

Nuclei template

1 repos

https://github.com/learner202649/CVE-2026-35029-PoC

CVE-2025-9709(CVSS UNKNOWN)

EPSS: 0.23%

updated 2025-09-05T18:31:39

1 posts

On-Chip Debug and Test Interface With Improper Access Control and Improper Protection against Electromagnetic Fault Injection (EM-FI) in Nordic Semiconductor nRF52810 allow attacker to perform EM Fault Injection and bypass APPROTECT at runtime, requiring the least amount of modification to the hardware system possible.

wicca@infosec.exchange at 2026-09-01T14:44:39.000Z ##

First pulse, first success. ⚡

@g0mb4ck (Milena) shows a triggerless EM fault injection attack on Nordic Semi's nRF52810 SoC (CVE-2025-9709) - the first of its kind ever reported and remarkably reproducible.

👉 Program & tickets: wiccon.nl/

##

andersonc0d3@infosec.exchange at 2026-09-01T21:09:07.000Z ##

I discuss Linux kernel exception handling in my training—specifically the mechanism that allows the kernel to trigger page faults at specific locations and handle them gracefully. This is why copy_from_user(), copy_to_user(), and other related functions don't cause a kernel oops when dealing with invalid addresses.

I abuse this mechanism in a vulnerability that leads to an arbitrary read to bypass KASLR during my Linux kernel exploitation training. I had played with it several times, but I had never read the official documentation until I came across it recently while looking for well-written material to send to the class. This mechanism has also been abused in other exploits, such as the one below.

Kernel level exception handling in Linux
kernel.org/doc/Documentation/x

Exploiting CVE-2017-5123
reverse.put.as/2017/11/07/expl

##

CVE-2026-85223
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-03T23:00:59.000Z ##

🔴 CVE-2026-85223 - Critical (9.9)

A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T23:00:59.000Z ##

🔴 CVE-2026-85223 - Critical (9.9)

A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59347
(0 None)

EPSS: 0.00%

2 posts

N/A

beyondmachines1 at 2026-09-03T20:01:31.308Z ##

Broadcom Patches Critical VM-Escape Flaws in VMware Workstation and Fusion

Broadcom patched two critical VM-escape vulnerabilities in VMware Workstation and Fusion (CVE-2026-59346 and CVE-2026-59347) that allow attackers with guest admin privileges to execute code on the host system.

**If you use VMware Workstation or Fusion (versions 25H2 or 26H1), update to 26H1u1 ASAP. Tthere is no workaround or setting that protects you from these flaws. Prioritize the machines that run untrusted code, malware analysis as well as any third party hosting, since an attacker inside a VM can break out and take over your host and from there reach your network.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-09-03T20:01:31.000Z ##

Broadcom Patches Critical VM-Escape Flaws in VMware Workstation and Fusion

Broadcom patched two critical VM-escape vulnerabilities in VMware Workstation and Fusion (CVE-2026-59346 and CVE-2026-59347) that allow attackers with guest admin privileges to execute code on the host system.

**If you use VMware Workstation or Fusion (versions 25H2 or 26H1), update to 26H1u1 ASAP. Tthere is no workaround or setting that protects you from these flaws. Prioritize the machines that run untrusted code, malware analysis as well as any third party hosting, since an attacker inside a VM can break out and take over your host and from there reach your network.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-59346
(0 None)

EPSS: 0.00%

3 posts

N/A

beyondmachines1 at 2026-09-03T20:01:31.308Z ##

Broadcom Patches Critical VM-Escape Flaws in VMware Workstation and Fusion

Broadcom patched two critical VM-escape vulnerabilities in VMware Workstation and Fusion (CVE-2026-59346 and CVE-2026-59347) that allow attackers with guest admin privileges to execute code on the host system.

**If you use VMware Workstation or Fusion (versions 25H2 or 26H1), update to 26H1u1 ASAP. Tthere is no workaround or setting that protects you from these flaws. Prioritize the machines that run untrusted code, malware analysis as well as any third party hosting, since an attacker inside a VM can break out and take over your host and from there reach your network.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-09-03T20:01:31.000Z ##

Broadcom Patches Critical VM-Escape Flaws in VMware Workstation and Fusion

Broadcom patched two critical VM-escape vulnerabilities in VMware Workstation and Fusion (CVE-2026-59346 and CVE-2026-59347) that allow attackers with guest admin privileges to execute code on the host system.

**If you use VMware Workstation or Fusion (versions 25H2 or 26H1), update to 26H1u1 ASAP. Tthere is no workaround or setting that protects you from these flaws. Prioritize the machines that run untrusted code, malware analysis as well as any third party hosting, since an attacker inside a VM can break out and take over your host and from there reach your network.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

DailyCyberSecurity@infosec.exchange at 2026-09-03T09:23:36.000Z ##

CVE-2026-59346, a critical VMware Workstation vulnerability, lets an attacker escape a guest VM and execute code on the host. Broadcom rates it 9.3 CVSS.

#VMware #Workstation #Fusion #CVE202659346 #VMXNET3 #Broadcom #InfoSec #PatchNow

securityonline.info/vmware-cve

##

CVE-2026-58400
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-03T19:00:30.000Z ##

🔴 CVE-2026-58400 - Critical (9.1)

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is configured without secure processing (`FEATURE_SECURE_PROCESSING`) and without...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T19:00:30.000Z ##

🔴 CVE-2026-58400 - Critical (9.1)

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is configured without secure processing (`FEATURE_SECURE_PROCESSING`) and without...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85012
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-03T19:00:08.000Z ##

🟠 CVE-2026-85012 - High (8)

Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository in the pro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T19:00:08.000Z ##

🟠 CVE-2026-85012 - High (8)

Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository in the pro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49869
(0 None)

EPSS: 1.92%

6 posts

N/A

1 repos

https://github.com/Ap0dexMe0/CVE-2026-49869

thecybermind at 2026-09-03T16:09:09.994Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-49869 – Kestra OSS OS Command Injection Vulnerability

Active CISA KEV exploitation of CVE-2026-49869 exposes Kestra OSS to remote OS command injection. Explore board-ready governance, asset enumeration, and risk mitigation....

thecybermind.co/f58i

##

thecybermind@infosec.exchange at 2026-09-03T16:09:09.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-49869 – Kestra OSS OS Command Injection Vulnerability

Active CISA KEV exploitation of CVE-2026-49869 exposes Kestra OSS to remote OS command injection. Explore board-ready governance, asset enumeration, and risk mitigation....

thecybermind.co/f58i

##

thecybermind@infosec.exchange at 2026-09-03T06:18:00.000Z ##

Critical vulnerability CVE-2026-49869 strikes Kestra OSS with active CISA KEV exploitation. Unauthenticated attackers can execute arbitrary OS commands. Read our strategic T-Suite brief for telemetry analysis, CrowdStrike detection queries, and rapid perimeter hardening steps. thecybermind.co/23yx

##

AAKL@infosec.exchange at 2026-09-02T19:01:22.000Z ##

Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.

- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-02T19:00:11.000Z ##

🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48710 (secdb.nttzen.cloud/cve/detail/)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/Kludex/starlette/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-49869 (secdb.nttzen.cloud/cve/detail/)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/kestra-io/kestra/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-59822 (secdb.nttzen.cloud/cve/detail/)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: github.com/BerriAI/litellm/sec ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82329 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83548 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83549 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9586 (secdb.nttzen.cloud/cve/detail/)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: sangomakb.atlassian.net/wiki/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260902 #cisa20260902 #cve_2026_48710 #cve_2026_49869 #cve_2026_59822 #cve_2026_82329 #cve_2026_83548 #cve_2026_83549 #cve_2026_9586 #cve202648710 #cve202649869 #cve202659822 #cve202682329 #cve202683548 #cve202683549 #cve20269586

##

cisakevtracker@mastodon.social at 2026-09-02T18:01:26.000Z ##

CVE ID: CVE-2026-49869
Vendor: Kestra
Product: Kestra OSS
Date Added: 2026-09-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-73299
(0 None)

EPSS: 1.21%

2 posts

N/A

DailyCyberSecurity at 2026-09-03T14:45:57.323Z ##

A critical Prompty vulnerability (CVE-2026-73299, CVSS 10) let a crafted .prompty file escape the template engine and run arbitrary JavaScript in Node.js.

meterpreter.org/prompty-cve-20

##

DailyCyberSecurity@infosec.exchange at 2026-09-03T14:45:57.000Z ##

A critical Prompty vulnerability (CVE-2026-73299, CVSS 10) let a crafted .prompty file escape the template engine and run arbitrary JavaScript in Node.js.

#Prompty #Microsoft #SSTI #RCE #CVE202673299

meterpreter.org/prompty-cve-20

##

CVE-2026-53635
(0 None)

EPSS: 0.22%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-03T12:01:10.000Z ##

🟠 CVE-2026-53635 - High (7.6)

Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 59bb6d6, the view function set_course_mode_price() at lms/djangoapps/instructor/views/instructor_dashboard.py:430 is decorated only with @login_r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84394
(0 None)

EPSS: 0.22%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-03T07:00:21.000Z ##

🟠 CVE-2026-84394 - High (7.5)

fast-uri accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error. A host that starts with an opening bracket but does not end with a closing bracket is neither validated as an IP literal nor canonicaliz...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84851
(0 None)

EPSS: 0.34%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-03T07:00:10.000Z ##

🟠 CVE-2026-84851 - High (7.5)

An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call stack and crashes the application using the library, resulting in a denial...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84382
(0 None)

EPSS: 0.35%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-02T23:02:23.000Z ##

🟠 CVE-2026-84382 - High (7.5)

HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip, deflate, br, or zstd network chunk before iter_bytes() or aiter_bytes() yields bounded piec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84381
(0 None)

EPSS: 0.08%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-02T23:02:13.000Z ##

🟠 CVE-2026-84381 - High (8.1)

HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin uses wss through a SOCKS5 pr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55221
(0 None)

EPSS: 0.27%

1 posts

N/A

offseq@infosec.exchange at 2026-09-02T21:03:29.000Z ##

CVE-2026-55221 | malach-it boruta-server (MEDIUM): Versions before 0.10.0 log OAuth/OpenID tokens in business event logs. Credentials at risk if logs are accessed. Patch to v0.10.0. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #OAuth #LogSecurity

##

CVE-2026-79755
(0 None)

EPSS: 0.40%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-02T17:59:59.000Z ##

🟠 CVE-2026-79755 - High (8)

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, on the Nuclio local Docker platform, the function namespace is interpolated—unvalidated—into a double-quoted docker ps --filter "label=nuclio...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84370
(0 None)

EPSS: 0.34%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-01T22:00:23.000Z ##

🟠 CVE-2026-84370 - High (8.2)

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin, named removeScriptElement in versions 2 and 3, i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

secdb@infosec.exchange at 2026-09-01T07:54:00.000Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

secdb@infosec.exchange at 2026-09-01T07:54:00.000Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-79750
(0 None)

EPSS: 0.25%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-31T19:00:31.000Z ##

🟠 CVE-2026-79750 - High (7.7)

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.30, MCPHub scopes non-admin users to servers they own (list views...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79746
(0 None)

EPSS: 0.25%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-31T19:00:05.000Z ##

🟠 CVE-2026-79746 - High (8.1)

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.31, when a bearer key with accessType: 'servers' (or 'custom') is...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites