## Updated at UTC 2026-06-20T13:03:04.981867

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-11911 7.5 0.00% 2 0 2026-06-20T09:33:32 The Simple File List plugin for WordPress is vulnerable to arbitrary file deleti
CVE-2026-11912 7.5 0.00% 2 1 2026-06-20T09:16:15.460000 The Simple File List plugin for WordPress is vulnerable to arbitrary file modifi
CVE-2026-9843 8.1 0.00% 2 0 2026-06-20T02:16:26.910000 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress i
CVE-2026-56082 7.5 0.00% 2 0 2026-06-20T00:34:15 Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnera
CVE-2026-56081 9.1 0.00% 4 0 2026-06-20T00:34:14 Cap-go before 12.128.2 contains an authentication logic flaw that lets an attack
CVE-2026-11551 9.8 0.00% 4 2 2026-06-20T00:34:09 The Branda plugin for WordPress is vulnerable to privilege escalation via accoun
CVE-2026-56073 9.4 0.00% 2 0 2026-06-20T00:34:08 Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP ve
CVE-2026-47645 8.8 0.00% 1 0 2026-06-19T21:16:58.720000 Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's B
CVE-2026-42824 6.5 0.50% 1 0 2026-06-19T21:16:42.893000 Missing authentication for critical function in M365 Copilot allows an unauthori
CVE-2026-12398 7.5 0.89% 1 0 2026-06-19T20:48:07 A command injection vulnerability was found in galaxy_ng. The do_git_checkout()
CVE-2026-56099 5.3 0.00% 2 0 2026-06-19T18:33:37 OpenBSD before commit 6a23123 (2026-06-18) contains an out-of-bounds read vulner
CVE-2026-11718 None 0.20% 1 0 2026-06-19T16:59:28 An authentication bypass vulnerability exists in the generic opaque token valida
CVE-2026-11717 None 0.19% 1 0 2026-06-19T16:58:23 An authentication bypass vulnerability exists in the generic opaque token valida
CVE-2026-43495 8.8 0.25% 1 0 2026-06-19T13:16:30.457000 In the Linux kernel, the following vulnerability has been resolved: net: wwan:
CVE-2026-46461 7.8 0.00% 1 0 2026-06-19T08:16:16.840000 Dell Server Hardware Manager, versions prior to 3.2.2, contains an Improper Acce
CVE-2026-8713 9.1 0.00% 2 0 2026-06-19T06:32:02 The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file
CVE-2026-7515 9.8 0.00% 1 2 2026-06-19T06:32:02 The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in
CVE-2026-54414 9.8 0.00% 1 0 2026-06-19T06:32:02 FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder uplo
CVE-2026-54104 8.8 0.00% 2 0 2026-06-19T06:17:09.720000 The U.S. Government Accountability Office (GAO) Electronic Protest Docketing Sys
CVE-2026-54103 9.8 0.00% 3 0 2026-06-19T06:17:09.580000 The U.S. Government Accountability Office (GAO) Electronic Protest Docketing Sys
CVE-2026-12044 8.8 0.00% 1 0 2026-06-19T00:31:46 SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT O
CVE-2026-47633 7.5 0.00% 1 0 2026-06-19T00:31:41 Exposure of sensitive information to an unauthorized actor in Cost Management In
CVE-2026-40624 9.8 0.00% 1 0 2026-06-19T00:16:47.693000 Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras
CVE-2026-12048 9.3 0.00% 1 0 2026-06-19T00:16:47.200000 Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-renderi
CVE-2026-54130 9.8 0.00% 1 0 2026-06-18T22:16:32.223000 Missing authentication for critical function in M365 Copilot allows an unauthori
CVE-2026-47647 9.9 0.00% 1 0 2026-06-18T22:16:31.747000 Improper access control in Microsoft Dynamics 365 allows an authorized attacker
CVE-2026-32174 7.7 0.00% 1 0 2026-06-18T22:16:30.290000 Improper authentication in Azure Bot Service allows an authorized attacker to el
CVE-2026-48937 5.3 0.00% 1 0 2026-06-18T21:32:38 A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data eve
CVE-2026-49454 9.1 0.00% 1 0 2026-06-18T21:16:29.920000 Relyra is a strict-by-default SAML 2.0 Service Provider library for Elixir and P
CVE-2026-49252 9.9 0.00% 1 0 2026-06-18T21:16:29.643000 deepstream is a server that allows clients and backend services to sync data, se
CVE-2026-53849 8.1 0.21% 1 0 2026-06-18T20:36:32 ### Summary Discord allowFrom could bind to mutable display names. In affected
CVE-2026-53853 7.1 0.33% 1 0 2026-06-18T20:33:23 ### Summary OpenClaw's exec allowlist supported optional `argPattern` entries t
CVE-2026-48814 9.1 0.30% 1 0 2026-06-18T20:16:14.080000 Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 a
CVE-2026-53855 8.1 0.26% 1 0 2026-06-18T20:12:14 ### Summary Shell positional parameters could weaken strict inline-eval checks.
CVE-2026-12317 7.5 0.29% 1 0 2026-06-18T19:16:21.870000 Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox
CVE-2026-12312 7.5 0.25% 1 0 2026-06-18T19:16:21.527000 Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox
CVE-2026-12310 7.5 0.25% 1 0 2026-06-18T19:16:21.367000 Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox
CVE-2026-28573 5.5 0.15% 1 0 2026-06-18T18:38:48.913000 In AndroidManifest.xml, there is a possible persistent denial of service due to
CVE-2026-20253 9.8 10.04% 18 3 template 2026-06-18T18:35:18 In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform
CVE-2026-54390 9.8 0.00% 1 0 2026-06-18T18:16:19.943000 JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection
CVE-2026-55203 7.5 0.00% 1 0 2026-06-18T17:16:34.373000 HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vul
CVE-2026-53864 8.1 0.25% 1 0 2026-06-18T16:16:55.997000 OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in
CVE-2026-53857 8.1 0.21% 1 0 2026-06-18T14:44:41.247000 OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo
CVE-2026-47103 9.8 0.80% 1 0 2026-06-18T14:28:03 ### Summary python-statemachine 3.1.2 evaluates `<data expr="...">` attributes
CVE-2026-8024 9.8 0.55% 2 0 2026-06-18T14:17:35.190000 A remote, unauthenticated attacker may exploit a deserialization of untrusted da
CVE-2026-55740 9.8 0.37% 1 0 2026-06-18T14:17:33.980000 Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26
CVE-2026-12569 0 0.50% 1 1 2026-06-18T14:17:23.863000 A critical remote code execution (RCE) vulnerability has been reported in PTC Wi
CVE-2026-12530 7.3 0.30% 1 0 2026-06-18T14:17:22.310000 Improper neutralization of argument delimiters in the install_packages() method
CVE-2026-12442 8.8 0.38% 1 0 2026-06-18T13:46:17.917000 Use after free in Passwords in Google Chrome on Android prior to 149.0.7827.155
CVE-2026-55200 8.1 0.55% 1 0 2026-06-18T04:17:02.430000 libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write
CVE-2026-53866 8.1 0.26% 1 0 2026-06-18T04:17:02.290000 OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell in
CVE-2026-53843 8.8 0.27% 1 0 2026-06-18T04:17:00.750000 OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a
CVE-2026-46850 9.9 0.48% 1 0 2026-06-18T04:16:48.923000 Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for V
CVE-2026-20181 9.1 0.57% 7 0 2026-06-18T04:16:45 A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote at
CVE-2026-3894 0 0.20% 1 1 2026-06-17T20:20:10.920000 Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) al
CVE-2026-20266 9.1 0.45% 1 0 2026-06-17T20:17:50.620000 In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk r
CVE-2026-53805 9.8 0.69% 1 0 2026-06-17T19:18:10.363000 NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote
CVE-2026-47747 7.8 0.14% 1 0 2026-06-17T19:18:08.253000 stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable
CVE-2026-48907 9.8 6.85% 10 7 template 2026-06-17T18:36:17 A vulnerability in the JCE editor extension for Joomla allows the creation of ne
CVE-2026-42530 8.1 0.76% 7 3 2026-06-17T18:36:07 NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGI
CVE-2026-20190 7.5 0.37% 4 0 2026-06-17T18:36:07 A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote
CVE-2026-42055 8.1 0.64% 4 1 2026-06-17T18:36:07 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_m
CVE-2026-2467 None 0.21% 1 0 2026-06-17T18:35:58 Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libra
CVE-2026-12440 9.6 0.31% 1 0 2026-06-17T18:35:53 Use after free in DigitalCredentials in Google Chrome on Windows prior to 149.0.
CVE-2026-12441 8.8 0.29% 1 0 2026-06-17T18:35:53 Use after free in File Input in Google Chrome on Linux prior to 149.0.7827.155 a
CVE-2026-12443 8.8 0.52% 1 0 2026-06-17T18:35:53 Use after free in Web Authentication in Google Chrome prior to 149.0.7827.155 al
CVE-2026-22313 9.1 0.92% 2 0 2026-06-17T17:16:43.687000 The device has a webserver that exposes a REST API authenticated with a token on
CVE-2026-48745 9.3 0.41% 1 0 2026-06-17T16:28:34.830000 Traccar Client is a GPS tracking mobile app for sending location updates to priv
CVE-2026-5667 0 0.15% 1 0 2026-06-17T16:21:32.403000 Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Cond
CVE-2026-48780 8.2 0.22% 1 0 2026-06-17T14:17:56.423000 Forem is open source software for building communities. Prior to commit a2ab6d4,
CVE-2026-47964 7.8 0.20% 1 0 2026-06-17T13:20:42.017000 DNG SDK versions 1.7.1 2536 and earlier are affected by a Heap-based Buffer Over
CVE-2026-24155 7.8 0.19% 3 0 2026-06-17T13:20:10.417000 NVIDIA NeMo Framework for all platforms contains a code injection vulnerability.
CVE-2026-22312 8.6 0.23% 2 0 2026-06-17T13:20:06.023000 The device has a webserver that exposes a REST API authenticated with a constant
CVE-2026-54420 8.5 0.65% 1 4 2026-06-17T10:58:13.830000 LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn bef
CVE-2026-50751 9.3 41.15% 1 8 template 2026-06-17T10:57:46.373000 A logic flow weakness in Remote Access and Mobile Access certificate validation
CVE-2026-4272 8.1 0.45% 1 0 2026-06-17T10:56:20.347000 Missing Authentication for Critical Function vulnerability in Honeywell Handheld
CVE-2026-4020 7.5 2.98% 5 0 template 2026-06-17T10:55:52.033000 The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exp
CVE-2026-49112 7.5 0.33% 1 0 2026-06-17T10:55:31.270000 Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.
CVE-2026-49110 7.5 0.24% 1 0 2026-06-17T10:55:31.073000 Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce
CVE-2026-49106 9.8 0.38% 1 0 2026-06-17T10:55:30.877000 Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Const
CVE-2026-49105 9.8 0.38% 1 1 2026-06-17T10:55:30.777000 Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms,
CVE-2026-49104 9.8 0.38% 1 1 2026-06-17T10:55:30.680000 Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Co
CVE-2026-49068 7.5 0.40% 1 0 2026-06-17T10:55:29.337000 Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions.
CVE-2026-49067 9.3 0.30% 1 0 2026-06-17T10:55:29.237000 Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions
CVE-2026-49066 7.5 0.30% 1 0 2026-06-17T10:55:29.137000 Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway <= 6.0.0 vers
CVE-2026-49065 8.2 0.24% 1 0 2026-06-17T10:55:29.037000 Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.
CVE-2026-49061 7.5 0.37% 1 0 2026-06-17T10:55:28.650000 Unauthenticated Arbitrary File Download in WPC Product Options for WooCommerce <
CVE-2026-48558 10.0 0.63% 2 0 2026-06-17T10:55:05.230000 SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an aut
CVE-2026-48095 8.8 0.70% 1 1 2026-06-17T10:54:50.997000 7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior
CVE-2026-47749 7.8 0.16% 1 0 2026-06-17T10:54:39.427000 stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable
CVE-2026-47684 7.7 0.38% 1 0 2026-06-17T10:54:37.403000 Sync-in Server is a secure, open-source platform for file storage, sharing, coll
CVE-2026-42271 8.8 53.70% 1 2 template 2026-06-17T10:47:36.560000 LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) fo
CVE-2026-2751 8.3 0.27% 1 1 2026-06-17T10:31:39.420000 Blind SQL Injection via unsanitized array keys in Service Dependencies deletion.
CVE-2026-11526 9.8 2.46% 1 0 2026-06-17T10:14:12.300000 GD versions before 2.86 for Perl allow OS command injection and file overwrite v
CVE-2026-0843 6.3 0.20% 1 0 2026-06-17T10:11:29.160000 A vulnerability has been found in jiujiujia/victor123/wxw850227 jjjfood and jjjs
CVE-2025-8088 8.8 81.35% 1 31 2026-06-17T10:06:17.243000 A path traversal vulnerability affecting the Windows version of WinRAR allows th
CVE-2025-71261 8.6 0.21% 1 0 2026-06-17T10:03:58.203000 An attacker with network-level access between the SUSE Virtualization and Ranch
CVE-2024-7730 7.4 0.29% 1 0 2026-06-17T08:20:48.370000 A heap buffer overflow was found in the virtio-snd device in QEMU. When reading
CVE-2026-12316 9.1 0.24% 1 0 2026-06-16T21:33:05 Mitigation bypass in the DOM: Security component. This vulnerability was fixed i
CVE-2026-12314 7.5 0.25% 1 0 2026-06-16T21:33:05 Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox
CVE-2026-12305 7.5 0.37% 1 0 2026-06-16T21:33:04 Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox
CVE-2026-50656 7.8 0.34% 5 1 2026-06-16T21:31:57 Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect
CVE-2026-12003 None 0.14% 2 0 2026-06-16T21:31:56 To allow builds of Python to be run from an in-tree layout (rather than an insta
CVE-2026-12315 9.1 0.25% 1 0 2026-06-16T21:31:56 Mitigation bypass in the DOM: Security component. This vulnerability was fixed i
CVE-2026-10649 8.6 0.46% 1 0 2026-06-16T21:31:56 A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an
CVE-2026-12304 9.1 0.17% 1 0 2026-06-16T21:31:55 Same-origin policy bypass in the Networking: Cookies component. This vulnerabili
CVE-2026-11832 9.1 0.33% 1 0 2026-06-16T18:33:40 Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predicta
CVE-2026-12087 9.1 0.39% 1 0 2026-06-16T18:33:40 Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socke
CVE-2026-12205 9.1 0.29% 1 0 2026-06-16T18:33:40 Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, lea
CVE-2026-12161 8.8 0.29% 1 0 2026-06-16T18:33:40 Improper input validation in the SSH Elevate Shell feature in Devolutions Remot
CVE-2026-12289 8.8 0.32% 1 0 2026-06-16T18:33:39 Privilege escalation in the Graphics: WebRender component. This vulnerability wa
CVE-2026-24228 7.8 0.16% 3 0 2026-06-16T18:32:44 NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may c
CVE-2026-44932 8.8 0.49% 1 0 2026-06-16T18:32:44 Passing of unsanitized strings from DHCP replies into the wicked dhcp client bef
CVE-2026-12328 8.1 0.30% 1 0 2026-06-16T18:32:38 Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbir
CVE-2025-68045 7.5 0.23% 1 0 2026-06-16T12:32:07 Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.
CVE-2026-8444 8.8 0.25% 1 0 2026-06-16T09:32:42 The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via
CVE-2026-49109 9.8 0.38% 1 0 2026-06-15T21:30:58 Unauthenticated PHP Object Injection in Integration for Salesforce and Contact F
CVE-2026-49085 9.8 0.38% 1 1 2026-06-15T21:30:58 Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms
CVE-2025-55649 5.5 0.19% 1 0 2026-06-15T21:30:42 A NULL pointer dereference in the gf_media_map_esd function (media_tools/isom_to
CVE-2026-35273 9.8 7.51% 2 3 template 2026-06-12T18:31:50 Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleS
CVE-2026-25089 9.8 2.66% 1 2 2026-06-09T18:30:47 A improper neutralization of special elements used in an os command ('os command
CVE-2026-8206 9.8 0.62% 2 3 2026-06-02T06:30:33 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordP
CVE-2025-60485 5.5 0.17% 1 0 2026-06-02T00:31:54 A segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/iso
CVE-2026-47717 7.5 0.00% 2 0 template 2026-05-27T22:51:19 ### Summary The GET /api/project endpoint exposes sensitive project configurati
CVE-2026-42089 8.6 0.19% 1 0 2026-05-26T23:10:40 ### Impact `yeoman-environment` versions `>= 2.9.0` and `< 6.0.1` install missi
CVE-2026-42069 None 0.23% 1 0 2026-05-13T13:38:50 ### TL;DR This vulnerability affects all Kirby sites that might have potential
CVE-2026-41175 8.1 0.30% 1 0 2026-04-24T20:52:07 ### Impact Manipulating query parameters on Control Panel and REST API endpoint
CVE-2026-39808 9.8 66.17% 1 6 template 2026-04-22T15:32:37 A improper neutralization of special elements used in an os command ('os command
CVE-2026-39813 9.8 18.70% 1 2 2026-04-14T18:30:41 A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 thro
CVE-2025-20701 8.8 3.40% 2 0 2025-08-04T21:31:49 In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth aud
CVE-2026-9142 0 0.00% 3 0 N/A
CVE-2026-48773 0 0.00% 2 0 N/A
CVE-2026-47846 0 0.00% 2 0 N/A
CVE-2025-60467 0 0.00% 4 0 N/A
CVE-2025-60474 0 0.00% 2 0 N/A
CVE-2026-48772 0 0.00% 2 0 N/A
CVE-2025-60473 0 0.00% 2 0 N/A
CVE-2025-60466 0 0.00% 2 0 N/A
CVE-2025-60465 0 0.00% 2 0 N/A
CVE-2025-60471 0 0.00% 4 0 N/A
CVE-2025-60464 0 0.00% 2 0 N/A
CVE-2026-48768 0 0.27% 2 0 N/A
CVE-2026-48979 0 0.27% 2 0 N/A
CVE-2026-48618 0 0.00% 4 0 N/A
CVE-2026-47729 0 0.00% 1 0 N/A
CVE-2026-49257 0 0.00% 1 0 N/A
CVE-2026-55074 0 0.00% 1 0 N/A
CVE-2026-48933 0 0.00% 3 0 N/A
CVE-2026-48615 0 0.00% 2 0 N/A
CVE-2025-55640 0 0.00% 1 0 N/A
CVE-2025-52291 0 0.00% 1 0 N/A
CVE-2025-55639 0 0.00% 1 0 N/A
CVE-2025-55654 0 0.00% 1 0 N/A
CVE-2025-55653 0 0.00% 1 0 N/A
CVE-2026-24252 0 0.00% 2 0 N/A
CVE-2026-4855 0 0.00% 1 0 N/A
CVE-2019-25293 0 0.13% 1 0 N/A
CVE-2026-48797 0 0.44% 1 0 N/A
CVE-2026-47750 0 0.14% 1 0 N/A
CVE-2026-53776 0 0.36% 1 0 N/A

CVE-2026-11911
(7.5 HIGH)

EPSS: 0.00%

updated 2026-06-20T09:33:32

2 posts

The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the eeSFL_DeleteFile function in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). T

offseq at 2026-06-20T10:30:26.475Z ##

CVE-2026-11911: HIGH severity path traversal in eemitch Simple File List (≤6.3.7). Unauth attackers can delete files via exposed AJAX action, risking RCE. Restrict admin-ajax.php or disable plugin. Details: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-06-20T10:30:26.000Z ##

CVE-2026-11911: HIGH severity path traversal in eemitch Simple File List (≤6.3.7). Unauth attackers can delete files via exposed AJAX action, risking RCE. Restrict admin-ajax.php or disable plugin. Details: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Security

##

CVE-2026-11912
(7.5 HIGH)

EPSS: 0.00%

updated 2026-06-20T09:16:15.460000

2 posts

The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authorization checks in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers to delete and modify files on the serve. This vulnerability is exploitable even when the administrator has not enabled the AllowFrontManage setting, because the is_admin() ch

1 repos

https://github.com/Polosss/By-Poloss..-..CVE-2026-11912

offseq at 2026-06-20T12:00:26.053Z ##

CVE-2026-11912: HIGH severity vulnerability in eemitch Simple File List ≤6.3.7 lets unauthenticated attackers modify/delete server files due to missing auth checks. No patch yet — restrict or disable plugin. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-06-20T12:00:26.000Z ##

CVE-2026-11912: HIGH severity vulnerability in eemitch Simple File List ≤6.3.7 lets unauthenticated attackers modify/delete server files due to missing auth checks. No patch yet — restrict or disable plugin. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #vuln

##

CVE-2026-9843
(8.1 HIGH)

EPSS: 0.00%

updated 2026-06-20T02:16:26.910000

2 posts

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the view_page function in all versions up to, and including, 1.5.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is dele

offseq at 2026-06-20T09:00:28.039Z ##

CVE-2026-9843: HIGH severity (CVSS 8.1) path traversal in crmperks Database for Contact Form 7, WPforms, Elementor forms (≤1.5.1). Unauthenticated file deletion possible if admin interacts with malicious entries. Restrict access, monitor logs. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-06-20T09:00:28.000Z ##

CVE-2026-9843: HIGH severity (CVSS 8.1) path traversal in crmperks Database for Contact Form 7, WPforms, Elementor forms (≤1.5.1). Unauthenticated file deletion possible if admin interacts with malicious entries. Restrict access, monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE20269843 #BlueTeam

##

CVE-2026-56082
(7.5 HIGH)

EPSS: 0.00%

updated 2026-06-20T00:34:15

2 posts

Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnerability in the SECURITY DEFINER PostgREST RPC function public.record_build_time, which is granted to the anon role and callable with only the public Supabase publishable (sb_publishable_*) anon key. An unauthenticated attacker can insert rows into public.build_logs for arbitrary organizations and, because the function u

thehackerwire@mastodon.social at 2026-06-20T01:00:41.000Z ##

🟠 CVE-2026-56082 - High (7.5)

Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnerability in the SECURITY DEFINER PostgREST RPC function public.record_build_time, which is granted to the anon role and callable with only the public Supabase publishabl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-06-20T01:00:41.000Z ##

🟠 CVE-2026-56082 - High (7.5)

Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnerability in the SECURITY DEFINER PostgREST RPC function public.record_build_time, which is granted to the anon role and callable with only the public Supabase publishabl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56081
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-06-20T00:34:14

4 posts

Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound to a victim's email address before that email is verified. By enabling two-factor authentication on the pre-registered account, the attacker gains control over the account claimed under the victim's identity, allowing them to read and modify its state and enforce organization-le

offseq at 2026-06-20T01:30:26.400Z ##

CRITICAL: Cap-go capgo (<12.128.2) hit by CVE-2026-56081. Attackers can register with victim emails pre-verification, enable 2FA, and fully take over accounts — including org policy control. No patch confirmed. Monitor new signups. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-06-20T01:00:31.000Z ##

🔴 CVE-2026-56081 - Critical (9.1)

Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound to a victim's email address before that email is verified. By enabling two-factor authentication on the pre-registered account...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-06-20T01:30:26.000Z ##

CRITICAL: Cap-go capgo (<12.128.2) hit by CVE-2026-56081. Attackers can register with victim emails pre-verification, enable 2FA, and fully take over accounts — including org policy control. No patch confirmed. Monitor new signups. radar.offseq.com/threat/cve-20 #OffSeq #CVE202656081 #Infosec

##

thehackerwire@mastodon.social at 2026-06-20T01:00:31.000Z ##

🔴 CVE-2026-56081 - Critical (9.1)

Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound to a victim's email address before that email is verified. By enabling two-factor authentication on the pre-registered account...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-11551
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-06-20T00:34:09

4 posts

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their ac

2 repos

https://github.com/xxconi/2026-11551

https://github.com/Polosss/By-Poloss..-..CVE-2026-11551-PoC

thehackerwire@mastodon.social at 2026-06-20T01:00:21.000Z ##

🔴 CVE-2026-11551 - Critical (9.8)

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity prior to updating their password. This mak...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-06-20T00:00:36.600Z ##

CVE-2026-11551: CRITICAL (CVSS 9.8) privilege escalation in wpmudev Branda ≤3.4.29. Weak password recovery lets unauthenticated attackers reset admin passwords. No patch. Restrict or disable plugin, monitor activity. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-06-20T01:00:21.000Z ##

🔴 CVE-2026-11551 - Critical (9.8)

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity prior to updating their password. This mak...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-06-20T00:00:36.000Z ##

CVE-2026-11551: CRITICAL (CVSS 9.8) privilege escalation in wpmudev Branda ≤3.4.29. Weak password recovery lets unauthenticated attackers reset admin passwords. No patch. Restrict or disable plugin, monitor activity. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #BlueTeam

##

CVE-2026-56073
(9.4 CRITICAL)

EPSS: 0.00%

updated 2026-06-20T00:34:08

2 posts

Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypass email verification by modifying server responses. Attackers can intercept OTP verification requests and manipulate HTTP responses to falsely mark verification successful, enabling unauthorized 2FA enablement and account takeover.

offseq at 2026-06-20T03:00:25.854Z ##

CVE-2026-56073 (CRITICAL) affects Cap-go capgo <12.128.2: Insufficient data authenticity checks allow OTP bypass, enabling attackers to activate 2FA & take over accounts. No patch yet — monitor vendor updates. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-06-20T03:00:25.000Z ##

CVE-2026-56073 (CRITICAL) affects Cap-go capgo <12.128.2: Insufficient data authenticity checks allow OTP bypass, enabling attackers to activate 2FA & take over accounts. No patch yet — monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Infosec #AppSec

##

CVE-2026-47645
(8.8 HIGH)

EPSS: 0.00%

updated 2026-06-19T21:16:58.720000

1 posts

Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network.

hugovalters@mastodon.social at 2026-06-19T23:03:57.000Z ##

CVE-2026-47645 - Open redirect in Microsoft 365 Copilot. CVSS 8.8. Privilege escalation via untrusted URL redirection. No patch available. Monitor activity and restrict access. #CVE #Microsoft #infosec

valtersit.com/cve/CVE-2026-476

##

CVE-2026-42824
(6.5 MEDIUM)

EPSS: 0.50%

updated 2026-06-19T21:16:42.893000

1 posts

Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.

hackmag@infosec.exchange at 2026-06-18T18:00:03.000Z ##

⚪️ Critical Copilot bug allowed theft of two-factor authentication codes

🗨️ In early June, Microsoft engineers announced that they had fixed a critical vulnerability, CVE-2026-42824. Now specialists from Varonis have revealed the details of this issue and described an attack that has been dubbed SearchLeak. As it turned out, the vulnerability…

🔗 hackmag.com/news/searchleak?ut

#news

##

CVE-2026-12398
(7.5 HIGH)

EPSS: 0.89%

updated 2026-06-19T20:48:07

1 posts

A command injection vulnerability was found in galaxy_ng. The do_git_checkout() function in the legacy role import API (v1) interpolates unsanitized git ref names (branch/tag names) into shell commands executed via subprocess.run() with shell=True. An authenticated user who controls a git repository can create a branch or tag with shell metacharacters in the name to achieve remote code execution o

thehackerwire@mastodon.social at 2026-06-16T16:00:13.000Z ##

🟠 CVE-2026-12398 - High (7.5)

A command injection vulnerability was found in galaxy_ng. The do_git_checkout() function in the legacy role import API (v1) interpolates unsanitized git ref names (branch/tag names) into shell commands executed via subprocess.run() with shell=True...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56099
(5.3 MEDIUM)

EPSS: 0.00%

updated 2026-06-19T18:33:37

2 posts

OpenBSD before commit 6a23123 (2026-06-18) contains an out-of-bounds read vulnerability in the mpls_do_error function within sys/netmpls/mpls_input.c that allows remote attackers to disclose kernel stack memory by sending crafted MPLS frames with 16 labels and no Bottom-of-Stack bit set.

_r_netsec at 2026-06-19T13:28:05.477Z ##

OpenBSD MPLS kernel stack leaks remotely (CVE-2026-56099) pop.argus-systems.ai/advisory/

##

_r_netsec@infosec.exchange at 2026-06-19T13:28:05.000Z ##

OpenBSD MPLS kernel stack leaks remotely (CVE-2026-56099) pop.argus-systems.ai/advisory/

##

CVE-2026-11718(CVSS UNKNOWN)

EPSS: 0.20%

updated 2026-06-19T16:59:28

1 posts

An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When the toolbox validates an opaque token via an OAuth 2.0 introspection endpoint (RFC 7662), it decodes the response into an introspectResp struct. However, the subsequent claim-checking logic (validateClaims) evaluates the issuer condition as if a.issuer !=

offseq@infosec.exchange at 2026-06-18T14:00:14.000Z ##

CVE-2026-11718 (CRITICAL): Google MCP Toolbox for Databases v1.0.0 has an auth bypass flaw in token validation. Issuer checks can be skipped, enabling unauthorized access. Avoid v1.0.0 & monitor for fixes. radar.offseq.com/threat/cve-20 #OffSeq #CVE202611718 #infosec #oauth2

##

CVE-2026-11717(CVSS UNKNOWN)

EPSS: 0.19%

updated 2026-06-19T16:58:23

1 posts

An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When verifying an unparsed opaque token via an OAuth 2.0 introspection endpoint (RFC 7662), the toolbox decodes the response into an introspectResp struct where the Active field is declared as a pointer to a boolean (*bool). The code only explicitly rejects a

offseq@infosec.exchange at 2026-06-18T15:30:20.000Z ##

CVE-2026-11717: CRITICAL vuln in googleapis/mcp-toolbox v1.0.0. Improper auth check lets tokens without 'active' field bypass controls — unauthorized access risk. Patch unconfirmed, monitor advisories: radar.offseq.com/threat/cve-20 #OffSeq #CVE202611717 #OAuth2 #CloudSecurity

##

CVE-2026-43495
(8.8 HIGH)

EPSS: 0.25%

updated 2026-06-19T13:16:30.457000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler t7xx_port_enum_msg_handler() uses the modem-supplied port_count field as a loop bound over port_msg->data[] without checking that the message buffer contains sufficient data. A modem sending port_count=65535 in a 12-byte buffer triggers a s

canartuc@mastodon.social at 2026-06-19T18:47:45.000Z ##

CVE-2026-43495 is a slab out-of-bounds read in the Linux kernel MediaTek t7xx WWAN driver. The function t7xx_port_enum_msg_handler() fails to check that the buffer length covers the space implied by port_count, so a malicious modem payload can read roughly 262 KB beyond allocated memory. Affected versions run from v5.18-rc1 through mainline, with a claimed CVSS of 8.8. Laptops and devices with cellular modems run this code. Should WWAN drivers get more security review?

#kernel #security

##

CVE-2026-46461
(7.8 HIGH)

EPSS: 0.00%

updated 2026-06-19T08:16:16.840000

1 posts

Dell Server Hardware Manager, versions prior to 3.2.2, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

hugovalters@mastodon.social at 2026-06-20T09:13:09.000Z ##

CVE-2026-46461 - Dell Server Hardware Manager improper access control. Low-privileged local user can gain elevated privileges. CVSS 7.8. No patch yet. Restrict local access immediately. #CVE #Dell #infosec

valtersit.com/cve/CVE-2026-464

##

CVE-2026-8713
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-06-19T06:32:02

2 posts

The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function in all versions up to, and including, 3.15.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-confi

undercodenews@mastodon.social at 2026-06-19T13:19:17.000Z ##

CVE-2026-8713: The Silent WordPress Plugin Flaw That Could Erase Your Entire Website in Seconds + Video

A Hidden Danger Inside One of WordPress’ Most Popular Builders In the vast ecosystem of WordPress plugins, few tools are as widely used for page design and form building as the Avada Builder plugin, developed for the popular WordPress environment. With nearly one million active installations, it powers countless business websites, portfolios, and online platforms.…

undercodenews.com/cve-2026-871

##

offseq@infosec.exchange at 2026-06-19T10:30:27.000Z ##

CVE-2026-8713: CRITICAL path traversal (CVSS 9.1) in Avada (Fusion) Builder ≤3.15.3. Unauthenticated file deletion possible; RCE risk if wp-config.php is removed. Restrict access, monitor usage, check vendor for fixes. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec

##

CVE-2026-7515
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-06-19T06:32:02

1 posts

The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code e

2 repos

https://github.com/izxci/CVE_2026_7515

https://github.com/Polosss/By-Poloss..-..CVE-2026-7515-PoC

offseq@infosec.exchange at 2026-06-19T09:00:28.000Z ##

CVE-2026-7515 | CRITICAL LFI in BetterDocs Pro ≤3.8.0: Unauthenticated attackers can execute arbitrary PHP via doc_style, risking full server compromise. Patch status unknown — check vendor. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vulnerability #CVE20267515

##

CVE-2026-54414
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-06-19T06:32:02

1 posts

FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover. The upload filename is validated by FolderController with basename() and REGEX_FILE_NAME, which permit URL-encoded sequences (the regex blocks / and \ but not %). The raw filename is then passed to Up

offseq@infosec.exchange at 2026-06-19T07:30:27.000Z ##

CVE-2026-54414: Critical path traversal in FileRise <3.16.0 allows attackers with a valid shared-folder upload link to write files outside the intended dir — can lead to admin takeover & RCE. Patch to 3.16.0+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #vuln #FileRise

##

CVE-2026-54104
(8.8 HIGH)

EPSS: 0.00%

updated 2026-06-19T06:17:09.720000

2 posts

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the 'epds_role_id' parameter without verification, allowing a remote, authenticated attacker to escalate their own privileges.

CVE-2026-54103
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-06-19T06:17:09.580000

3 posts

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) does not authenticate password change requests to the '/update-profile/N' API endpoint. A remote, unauthenticated attacker could change an arbitrary user's password.

cR0w@infosec.exchange at 2026-06-18T19:39:54.000Z ##

lol. lmao.

nvd.nist.gov/vuln/detail/CVE-2

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) does not authenticate password change requests to the '/update-profile/N' API endpoint. A remote, unauthenticated attacker could change an arbitrary user's password.

##

nyanbinary@infosec.exchange at 2026-06-18T17:43:30.000Z ##

db.gcve.eu/vuln/cve-2026-54103
db.gcve.eu/vuln/cve-2026-54104

:blobcatthinkingglare:

##

offseq@infosec.exchange at 2026-06-18T17:00:11.000Z ##

CVE-2026-54103 (CRITICAL, CVSS 9.8): GAO EPDS & CBCA EDS lack authentication on password change API, enabling remote takeover. No patch yet. Restrict access, monitor logs. Details: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #CVE202654103 #GovSec

##

CVE-2026-12044
(8.8 HIGH)

EPSS: 0.00%

updated 2026-06-19T00:31:46

1 posts

SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS '<description>'`` for a user-supplied description field. The Jinja templates for Domains (and their constraints), Foreign Tables, Languages, and Event Triggers, plus the Views OID-lookup query, interpolated the description directly inside a single-quoted SQL literal -- ``'{{ data.description }}'`` -- instead o

thehackerwire@mastodon.social at 2026-06-19T05:00:44.000Z ##

🟠 CVE-2026-12044 - High (8.8)

SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS ''`` for a user-supplied description field. The Jinja templates for Domains (and their constraints), Foreign Tables, Languages, and Event Triggers, plus the V...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47633
(7.5 HIGH)

EPSS: 0.00%

updated 2026-06-19T00:31:41

1 posts

Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network.

offseq@infosec.exchange at 2026-06-19T06:00:39.000Z ##

Microsoft Cost Management is affected by CVE-2026-47633 (HIGH, CVSS 7.5) — remote attackers can access sensitive info with no auth or user interaction. Patch available: radar.offseq.com/threat/cve-20 #OffSeq #Microsoft #CVE #BlueTeam

##

CVE-2026-40624
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-06-19T00:16:47.693000

1 posts

Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote, unauthenticated attacker to achieve arbitrary code execution via a specially crafted web request.

thehackerwire@mastodon.social at 2026-06-19T05:00:30.000Z ##

🔴 CVE-2026-40624 - Critical (9.8)

Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+
cameras may allow a remote, unauthenticated attacker to achieve
arbitrary code execution via a specially crafted web request.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12048
(9.3 CRITICAL)

EPSS: 0.00%

updated 2026-06-19T00:16:47.200000

1 posts

Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL server (ErrorResponse messages, including object names quoted back inside relation-does-not-exist errors and inside EXPLAIN Recheck Cond / Exact Heap Blocks fields) was passed verbatim through html-react-parser at every user-facing sink — the notifier toasts, FormFooterMessage /

thehackerwire@mastodon.social at 2026-06-19T05:00:19.000Z ##

🔴 CVE-2026-12048 - Critical (9.3)

Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL server (ErrorResponse messages, including object names quoted back inside relation-does-not-exist errors and inside EXPLAIN Rec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54130
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-06-18T22:16:32.223000

1 posts

Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.

offseq@infosec.exchange at 2026-06-19T00:00:37.000Z ##

Microsoft 365 Copilot hit by CVE-2026-54130 (CRITICAL, CVSS 9.8): Missing authentication lets attackers disclose info over the network. Official fix deployed — verify your cloud service is updated. 📢 radar.offseq.com/threat/cve-20 #OffSeq #Microsoft365 #CVE #CloudSecurity

##

CVE-2026-47647
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-06-18T22:16:31.747000

1 posts

Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.

offseq@infosec.exchange at 2026-06-18T23:00:22.000Z ##

CVE-2026-47647 (CRITICAL, CVSS 9.9) affects Microsoft Dynamics 365: improper access control lets authorized users escalate privileges over the network. Fix applied by Microsoft server-side — admins should confirm updates. Details: radar.offseq.com/threat/cve-20 #OffSeq #Microsoft #Infosec #CVE

##

CVE-2026-32174
(7.7 HIGH)

EPSS: 0.00%

updated 2026-06-18T22:16:30.290000

1 posts

Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.

offseq@infosec.exchange at 2026-06-19T04:30:25.000Z ##

CVE-2026-32174: HIGH severity improper authentication in Microsoft Azure AI Bot Service (CVSS 7.7). Privilege escalation possible for authorized users. Microsoft has issued a server-side fix. No active exploits. Details: radar.offseq.com/threat/cve-20 #OffSeq #Azure #Vuln #CloudSec

##

CVE-2026-48937
(5.3 MEDIUM)

EPSS: 0.00%

updated 2026-06-18T21:32:38

1 posts

A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This vulnerability affects two supported release lines: **Node.js 22** and **Node.js 24**.

nodejs_release_watcher@kodesumber.com at 2026-06-18T05:45:58.000Z ##

2026-06-18, Version 22.23.0 'Jod' (LTS), @aduh95

This is a security release. Notable Changes (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High (CVE-2026-48937) deps: fix...

github.com/nodejs/node/release

#nodejs #javascript

##

CVE-2026-49454
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-06-18T21:16:29.920000

1 posts

Relyra is a strict-by-default SAML 2.0 Service Provider library for Elixir and Phoenix. Versions 1.0.0 and 1.1.0 accept forged SAML signatures because SignatureValue was not cryptographically verified before the library returned a successful authentication result. The XMLDSig trust boundary was incomplete as :public_key.verify over the exclusive-C14N canonicalized SignedInfo was not performed agai

offseq@infosec.exchange at 2026-06-19T01:30:26.000Z ##

CVE-2026-49454: szTheory relyra (<1.2.0) has a CRITICAL SAML authentication flaw — improper signature verification lets attackers forge responses & impersonate users. Fixed in v1.2.0. Patch now! radar.offseq.com/threat/cve-20 #OffSeq #CVE202649454 #SAML #Elixir #InfoSec

##

CVE-2026-49252
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-06-18T21:16:29.643000

1 posts

deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. Versions prior to 10.0.5 are vulnerable to Prototype Pollution. Exploitation can lead to potential privilege escalation from any authenticated user with write permission to any record. This issue has been fixed in version 10.0.5.

offseq@infosec.exchange at 2026-06-19T03:00:30.000Z ##

deepstream.io <10.0.5 has a CRITICAL Prototype Pollution flaw (CVE-2026-49252, CVSS 9.9). Authenticated users with write access can escalate privileges. Patch to 10.0.5+ ASAP! radar.offseq.com/threat/cve-20 #OffSeq #CVE202649252 #deepstreamio #infosec

##

CVE-2026-53849
(8.1 HIGH)

EPSS: 0.21%

updated 2026-06-18T20:36:32

1 posts

### Summary Discord allowFrom could bind to mutable display names. In affected versions, a Discord account able to change display or global name metadata could match a policy entry through mutable display metadata. This advisory is scoped to the named feature and configuration. It does not change OpenClaw's trusted-operator model: authenticated Gateway operators, installed plugins, and intention

thehackerwire@mastodon.social at 2026-06-16T21:01:05.000Z ##

🟠 CVE-2026-53849 - High (8.1)

OpenClaw before 2026.5.7 contains a privilege escalation vulnerability where the allowFrom feature improperly validates Discord account identity using mutable display names instead of immutable user IDs. Attackers with Discord accounts can change ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53853
(7.1 HIGH)

EPSS: 0.33%

updated 2026-06-18T20:33:23

1 posts

### Summary OpenClaw's exec allowlist supported optional `argPattern` entries to restrict the arguments accepted for an allowlisted executable. In affected releases, Linux and macOS gateways skipped `argPattern` checks and treated a matching executable path as sufficient to satisfy the allowlist. This meant an operator could configure an allowlist entry that appeared to permit only a narrow argv

thehackerwire@mastodon.social at 2026-06-16T21:01:14.000Z ##

🟠 CVE-2026-53853 - High (8.3)

OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows attackers to execute disallowed arguments for allowlisted executables on Linux and macOS systems. Attackers can bypass configured argPattern...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48814
(9.1 CRITICAL)

EPSS: 0.30%

updated 2026-06-18T20:16:14.080000

1 posts

Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows unauthenticated cross-origin MCP tool invocation due to an empty default secret. This issue was partially addressed by CVE-2026-46701 in version 5.4.5 by closing the CORS flaw (with Access-Control-Allow-Origin now set only for localhost origins), but the empty-default-secret flaw d

offseq@infosec.exchange at 2026-06-17T20:30:11.000Z ##

🚨 CRITICAL: CVE-2026-48814 in Jovancoding Network-AI ≤5.7.1 lets unauthenticated users access all 22 MCP tools if default secret is unset. Patch to 5.7.2 now! Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE202648814 #Nodejs #Infosec

##

CVE-2026-53855
(8.1 HIGH)

EPSS: 0.26%

updated 2026-06-18T20:12:14

1 posts

### Summary Shell positional parameters could weaken strict inline-eval checks. In affected versions, a command request that combines allowlisted tools with shell positional arguments could place inline-eval content in a shell carrier not covered by the strict check. This advisory is scoped to the named feature and configuration. It does not change OpenClaw's trusted-operator model: authenticate

thehackerwire@mastodon.social at 2026-06-16T22:00:00.000Z ##

🟠 CVE-2026-53855 - High (8.1)

OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict allowlist checks via shell positional parameters. Attackers can combine allowlisted tools with shell positional arguments to pl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12317
(7.5 HIGH)

EPSS: 0.29%

updated 2026-06-18T19:16:21.870000

1 posts

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

thehackerwire@mastodon.social at 2026-06-17T04:00:26.000Z ##

🟠 CVE-2026-12317 - High (7.5)

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12312
(7.5 HIGH)

EPSS: 0.25%

updated 2026-06-18T19:16:21.527000

1 posts

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

thehackerwire@mastodon.social at 2026-06-17T05:00:13.000Z ##

🟠 CVE-2026-12312 - High (7.5)

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12310
(7.5 HIGH)

EPSS: 0.25%

updated 2026-06-18T19:16:21.367000

1 posts

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

thehackerwire@mastodon.social at 2026-06-17T05:00:02.000Z ##

🟠 CVE-2026-12310 - High (7.5)

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-28573
(5.5 MEDIUM)

EPSS: 0.15%

updated 2026-06-18T18:38:48.913000

1 posts

In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

offseq@infosec.exchange at 2026-06-18T09:30:26.000Z ##

CRITICAL: CVE-2026-28573 targets Android 14 & 16 via missing permission check, enabling persistent local DoS — no user interaction or privileges needed. Patch status unknown. Stay updated: radar.offseq.com/threat/cve-20 #OffSeq #Android #InfoSec #CVE #Vuln

##

CVE-2026-20253
(9.8 CRITICAL)

EPSS: 10.04%

updated 2026-06-18T18:35:18

18 posts

In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and 10.2.2510.14, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.<br><br>The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file

Nuclei template

3 repos

https://github.com/watchtowrlabs/watchTowr-vs-Splunk-CVE-2026-20253

https://github.com/HORKimhab/CVE-2026-20253

https://github.com/0xBlackash/CVE-2026-20253

halildeniz@mastodon.social at 2026-06-20T10:04:28.000Z ##

🚨 Attention Splunk Users: The Threat is Still Active!

Despite security advisories, recent scans reveal that thousands of global Splunk systems remain unpatched against CVE-2026-20253. Threat actors are already actively scanning for this critical flaw.

This dangerous multi-stage exploit abuses the PostgreSQL sidecar service, allowing attackers to achieve full Pre-Auth RCE with zero authentication.
👉 denizhalil.com/2026/06/15/cve-

#Cybersecurity #Splunk #Vulnerability #RCE #Infosec #ThreatIntel

##

beyondmachines1 at 2026-06-20T08:01:21.261Z ##

Splunk Enterprise PostgreSQL Sidecar Vulnerability Exploited in the Wild

A critical, actively exploited vulnerability (CVE-2026-20253) in Splunk Enterprise allows anyone on the network to bypass authentication and manipulate files, leading to potential system takeover. Patches are available in versions 10.4.0, 10.2.4, and 10.0.7.

**Check your versions and patch Splunk Enterprise to 10.4.0, 10.2.4, or 10.0.7 immediately. If you cannot patch today, mitigate the risk right now by disabling the PostgreSQL sidecar service. Finally, verify your network architecture: ensure Splunk Web (port 8000) and management ports are restricted by a firewall, placed on an isolated network segment, and only accessible remotely via a VPN.**

beyondmachines.net/event_detai

##

youranonnewsirc@nerdculture.de at 2026-06-19T22:23:33.000Z ##

Here's a summary of recent geopolitical, technology, and cybersecurity news:

Geopolitical: Western allies pledged $4B military aid to Ukraine (June 18). US-Iran talks stalled, and a Lebanon ceasefire was agreed. France emphasized tech sovereignty, ditching US vendors.

Technology: Anthropic's Fable 5 AI model returned with restricted access after a government-forced shutdown.

Cybersecurity: An unpatchable 'usbliter8' exploit impacts Apple A12/A13 chips. A critical Splunk Enterprise vulnerability (CVE-2026-20253) is actively exploited; CISA urged urgent patching (June 19).

#Cybersecurity #Geopolitics #TechNews

##

netsecio@mastodon.social at 2026-06-19T21:58:07.000Z ##

📰 Splunk Scrambles to Patch Critical 9.8 CVSS Flaw Allowing Unauthenticated RCE

🚨 CRITICAL Splunk Enterprise flaw (CVE-2026-20253) allows unauthenticated RCE! CVSS 9.8. Attackers can execute code via an insecure PostgreSQL endpoint. On-premise versions 10.0.x and 10.2.x are vulnerable. Patch now! #Splunk #RCE #CyberSecurity

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/cr

##

thecybermind at 2026-06-19T20:12:50.974Z ##

CVE-2026-20253 Splunk Vulnerability. Active exploitation is confirmed. CROs and Boards must prioritize this directive to secure enterprise assets and prevent privilege escalation. Review our latest C-SUITE intelligence brief now. thecybermind.co/xo4x

##

youranonnewsirc@nerdculture.de at 2026-06-19T14:23:38.000Z ##

Latest Geopolitical: An interim US-Iran agreement aims to de-escalate tensions and reopen the Strait of Hormuz, while Moscow endured its largest Ukrainian drone attack, hitting an oil refinery.

Technology: Anthropic's Claude Fable 5 AI is back online after a six-day shutdown, as Google makes Gemini 2.5 Flash its default model.

Cybersecurity: CISA issued alerts for an actively exploited Splunk vulnerability (CVE-2026-20253) and widespread Fortinet "FortiBleed" attacks. Accenture also acquired key OT security firms.

#AnonNews_irc #Cybersecurity #News

##

undercodenews@mastodon.social at 2026-06-19T11:16:06.000Z ##

CISA Sounds the Alarm as Critical Splunk Enterprise Vulnerability Enters KEV Catalog Amid Active Exploitation + Video

A New Cybersecurity Emergency Unfolds for Splunk Users A fresh cybersecurity threat is forcing security teams into immediate action after the U.S. Cybersecurity and Infrastructure Security Agency (CISA) officially added a severe Splunk Enterprise vulnerability, tracked as CVE-2026-20253, to its Known Exploited Vulnerabilities (KEV) catalog. The flaw…

undercodenews.com/cisa-sounds-

##

Analyst207@mastodon.social at 2026-06-19T11:08:26.000Z ##

CISA Warns of Active Exploitation of Splunk Enterprise Flaw

A critical vulnerability in Splunk Enterprise, tracked as CVE-2026-20253, allows remote attackers to create or delete files on vulnerable systems without needing any login credentials. This security flaw affects specific versions of Splunk Enterprise, including 10.2.0 through 10.2.3 and 10.0.0 through 10.0.6.

osintsights.com/cisa-warns-of-

#SplunkEnterprise #Cve202620253 #VulnerabilityExploitation #EmergingThreats #ZeroDay

##

beyondmachines1@infosec.exchange at 2026-06-20T08:01:21.000Z ##

Splunk Enterprise PostgreSQL Sidecar Vulnerability Exploited in the Wild

A critical, actively exploited vulnerability (CVE-2026-20253) in Splunk Enterprise allows anyone on the network to bypass authentication and manipulate files, leading to potential system takeover. Patches are available in versions 10.4.0, 10.2.4, and 10.0.7.

**Check your versions and patch Splunk Enterprise to 10.4.0, 10.2.4, or 10.0.7 immediately. If you cannot patch today, mitigate the risk right now by disabling the PostgreSQL sidecar service. Finally, verify your network architecture: ensure Splunk Web (port 8000) and management ports are restricted by a firewall, placed on an isolated network segment, and only accessible remotely via a VPN.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

youranonnewsirc@nerdculture.de at 2026-06-19T22:23:33.000Z ##

Here's a summary of recent geopolitical, technology, and cybersecurity news:

Geopolitical: Western allies pledged $4B military aid to Ukraine (June 18). US-Iran talks stalled, and a Lebanon ceasefire was agreed. France emphasized tech sovereignty, ditching US vendors.

Technology: Anthropic's Fable 5 AI model returned with restricted access after a government-forced shutdown.

Cybersecurity: An unpatchable 'usbliter8' exploit impacts Apple A12/A13 chips. A critical Splunk Enterprise vulnerability (CVE-2026-20253) is actively exploited; CISA urged urgent patching (June 19).

#Cybersecurity #Geopolitics #TechNews

##

thecybermind@infosec.exchange at 2026-06-19T20:12:50.000Z ##

CVE-2026-20253 Splunk Vulnerability. Active exploitation is confirmed. CROs and Boards must prioritize this directive to secure enterprise assets and prevent privilege escalation. Review our latest C-SUITE intelligence brief now. thecybermind.co/xo4x

#CyberSecurity #Splunk #CISO #RiskManagement

##

youranonnewsirc@nerdculture.de at 2026-06-19T14:23:38.000Z ##

Latest Geopolitical: An interim US-Iran agreement aims to de-escalate tensions and reopen the Strait of Hormuz, while Moscow endured its largest Ukrainian drone attack, hitting an oil refinery.

Technology: Anthropic's Claude Fable 5 AI is back online after a six-day shutdown, as Google makes Gemini 2.5 Flash its default model.

Cybersecurity: CISA issued alerts for an actively exploited Splunk vulnerability (CVE-2026-20253) and widespread Fortinet "FortiBleed" attacks. Accenture also acquired key OT security firms.

#AnonNews_irc #Cybersecurity #News

##

thecybermind@infosec.exchange at 2026-06-19T08:32:18.000Z ##

ACTIVE THREAT: CVE-2026-20253 Splunk Enterprise vulnerability is being exploited in the wild. Our latest TSUITE Brief provides a full SQL injection defense playbook, including n8n automation triggers for your SOC. Secure your infrastructure now. thecybermind.co/2yn5

#Cybersecurity #Splunk #CVE202620253

##

cyberveille@mastobot.ping.moi at 2026-06-18T22:00:21.000Z ##

📢 CVE-2026-20253 : RCE pré-authentifiée dans Splunk Enterprise via le service PostgreSQL Sidecar
📝 ## 🔍 Contexte

Le 12 juin 2026, watchTowr Labs (Piotr Bazy...
📖 cyberveille : cyberveille.ch/posts/2026-06-1
🌐 source : labs.watchtowr.com/why-use-app
#CVE_2026_20253 #IOC #Cyberveille

##

cisakevtracker@mastodon.social at 2026-06-18T17:00:47.000Z ##

CVE ID: CVE-2026-20253
Vendor: Splunk
Product: Enterprise
Date Added: 2026-06-18
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-06-18T17:00:12.000Z ##

🚨 [CISA-2026:0618] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-20253 (secdb.nttzen.cloud/cve/detail/)
- Name: Splunk Enterprise Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Splunk
- Product: Enterprise
- Notes: advisory.splunk.com/advisories ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260618 #cisa20260618 #cve_2026_20253 #cve202620253

##

AAKL@infosec.exchange at 2026-06-18T16:34:07.000Z ##

CISA has added one vulnerability to the KEV catalogue.

- CVE-2026-20253: Splunk Enterprise Missing Authentication for Critical Function Vulnerability cve.org/CVERecord?id=CVE-2026- #infosec #vulnerability

##

patrickcmiller@infosec.exchange at 2026-06-16T23:42:00.000Z ##

Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE) labs.watchtowr.com/why-use-app

##

CVE-2026-54390
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-06-18T18:16:19.943000

1 posts

JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows unauthenticated attackers to inject malicious template syntax due to unsanitized user-supplied input passed to the Smarty template engine. Attackers can exploit this flaw to read sensitive server-side values such as database credentials and encryption keys, and on versions 5.4.0 through 5.7.1,

offseq@infosec.exchange at 2026-06-18T18:30:13.000Z ##

CRITICAL: CVE-2026-54390 in JTL Shop (5.2.0 – 5.7.1) enables unauthenticated template injection. Attackers can extract secrets; RCE possible in 5.4.0+. No patch yet — restrict access & monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #CVE202654390 #infosec #websecurity

##

CVE-2026-55203
(7.5 HIGH)

EPSS: 0.00%

updated 2026-06-18T17:16:34.373000

1 posts

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potential

cR0w@infosec.exchange at 2026-06-18T19:42:03.000Z ##

:blobcat_thisisfine:

nvd.nist.gov/vuln/detail/CVE-2

sev:CRIT 9.0 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.

##

CVE-2026-53864
(8.1 HIGH)

EPSS: 0.25%

updated 2026-06-18T16:16:55.997000

1 posts

OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.

thehackerwire@mastodon.social at 2026-06-16T19:59:59.000Z ##

🟠 CVE-2026-53864 - High (8.1)

OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53857
(8.1 HIGH)

EPSS: 0.21%

updated 2026-06-18T14:44:41.247000

1 posts

OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display metadata could match allowFrom policy entries through display name changes. Attackers with mutable display names could receive agent responses intended for different Zalo identities when the feature is enabled.

thehackerwire@mastodon.social at 2026-06-16T20:00:10.000Z ##

🟠 CVE-2026-53857 - High (8.1)

OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display metadata could match allowFrom policy entries through display name changes. Attackers with mutable display names could receive agent resp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47103
(9.8 CRITICAL)

EPSS: 0.80%

updated 2026-06-18T14:28:03

1 posts

### Summary python-statemachine 3.1.2 evaluates `<data expr="...">` attributes in SCXML documents using Python's `eval()`. Any application that passes attacker-controlled SCXML content to `SCXMLProcessor` is vulnerable to arbitrary code execution in the context of the hosting process. ### Details `SCXMLProcessor.parse_scxml_file()` processes SCXML documents and evaluates `<data>` element `expr`

offseq@infosec.exchange at 2026-06-17T16:00:33.000Z ##

⚡️ CRITICAL: CVE-2026-47103 in python-statemachine (3.0.0 – <3.2.0) lets attackers execute code remotely via unsanitized eval() in SCXML. Avoid untrusted SCXML until patch. Details: radar.offseq.com/threat/cve-20 #OffSeq #python #security #CVE202647103

##

CVE-2026-8024
(9.8 CRITICAL)

EPSS: 0.55%

updated 2026-06-18T14:17:35.190000

2 posts

A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems.

certvde@infosec.exchange at 2026-06-18T10:01:15.000Z ##

#OT #Advisory VDE-2026-051
iba: Deserialization vulnerability in ibaPDA and ibaDatCoordinator

Remote Code Execution (RCE) running under the service user account, thereby allowing privilege escalation.
#CVE CVE-2026-8024

certvde.com/en/advisories/vde-
#oCSAF
#CSAF iba.csaf-tp.certvde.com/.well-

##

AAKL@infosec.exchange at 2026-06-17T18:01:10.000Z ##

New.

Tenable research advisories:

CRITICAL: CVE-2026-8024: iba ibaPDA / ibaDatCoordinator .NET Deserialization Remote Code Execution tenable.com/security/research/ @tenable

Cisco:

CRITICAL: CVE-2026-20181 and CVE-2026-20190: Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities

Three others of medium-severity: sec.cloudapps.cisco.com/securi @TalosSecurity

Broadcom:

Several critical and high-severity vulnerabilities. A login is needed for details support.broadcom.com/web/ecx/s

Dell:

Several advisories, one of them critical:

CRITICAL: Security Update for Dell Data Protection Central Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0

More: dell.com/support/security/en-us

Google:

Chrome Beta for iOS Update chromereleases.googleblog.com/

Yesterday:

Microsoft:

CVE-2026-50656: Microsoft Defender Elevation of Privilege Vulnerability msrc.microsoft.com/update-guid

Nvidia:

Security Bulletin addressing CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228:

NVIDIA NeMo - June 2026 nvidia.custhelp.com/app/answer #Nvidia #Dell #Cisco #infosec #vulnerability #threatresearch #Broadcom #Google #Chrome #Microsoft #Windows

##

CVE-2026-55740
(9.8 CRITICAL)

EPSS: 0.37%

updated 2026-06-18T14:17:33.980000

1 posts

Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthenticated SQL injection vulnerability in bus_info.php. The busid parameter received via HTTP POST is concatenated directly into a MySQL query (select * from bus_info where id=$busid) without sanitization, escaping, or parameterization, and in a numeric (unquoted) context. A remote

offseq@infosec.exchange at 2026-06-18T06:00:33.000Z ##

🚨 CRITICAL: CVE-2026-55740 in Nur-Alam39 bus-ticket — unauthenticated SQL injection via busid in bus_info.php. Runs as MySQL root/no password! Restrict access & avoid use in production until fixed. Details: radar.offseq.com/threat/cve-20 #OffSeq #SQLInjection #Vuln

##

CVE-2026-12569
(0 None)

EPSS: 0.50%

updated 2026-06-18T14:17:23.863000

1 posts

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

1 repos

https://github.com/west-wind/Threat-Hunting-With-Splunk

offseq@infosec.exchange at 2026-06-18T01:30:26.000Z ##

🔥 CRITICAL: CVE-2026-12569 in PTC Windchill PDMLink (RCE, CVSS 9.3). Affects versions 11.2.1.0 — 13.1.3.0. No patch yet — restrict access & monitor advisories. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE202612569 #Vuln #RCE

##

CVE-2026-12530
(7.3 HIGH)

EPSS: 0.30%

updated 2026-06-18T14:17:22.310000

1 posts

Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK versions >= 1.1.3 and < 1.6.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. To mitigate this issue, users should upgrade to version 1.6.1.

offseq@infosec.exchange at 2026-06-17T22:00:14.000Z ##

🚨 CRITICAL: CVE-2026-12530 impacts AWS Bedrock AgentCore Python SDK (v1.1.3 – 1.6.1). Incomplete input sanitization in install_packages() lets attackers abuse pip flags. Update now! radar.offseq.com/threat/cve-20 #OffSeq #AWSSecurity #Python #CVE2026_12530

##

CVE-2026-12442
(8.8 HIGH)

EPSS: 0.38%

updated 2026-06-18T13:46:17.917000

1 posts

Use after free in Passwords in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

offseq@infosec.exchange at 2026-06-17T04:30:28.000Z ##

🔴 CRITICAL: CVE-2026-12442 — Chrome on Android <149.0.7827.155 has a use-after-free vuln in Passwords. Remote attackers can execute code via crafted HTML. Update Chrome now! radar.offseq.com/threat/cve-20 #OffSeq #Chrome #Android #Vuln #InfoSec

##

CVE-2026-55200
(8.1 HIGH)

EPSS: 0.55%

updated 2026-06-18T04:17:02.430000

1 posts

libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution.

cR0w@infosec.exchange at 2026-06-17T22:07:09.000Z ##

Oh my.

nvd.nist.gov/vuln/detail/CVE-2

sev:CRIT 9.2 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution.

##

CVE-2026-53866
(8.1 HIGH)

EPSS: 0.26%

updated 2026-06-18T04:17:02.290000

1 posts

OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authenticated operators to execute unapproved commands. A command request using shell inline-command forms could route through a parser case missing the expected allowlist decision, enabling shell content execution without intended approval prompts.

thehackerwire@mastodon.social at 2026-06-16T19:59:50.000Z ##

🟠 CVE-2026-53866 - High (8.1)

OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authenticated operators to execute unapproved commands. A command request using shell inline-command forms could route through a parse...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53843
(8.8 HIGH)

EPSS: 0.27%

updated 2026-06-18T04:17:00.750000

1 posts

OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped device session can re-establish node token authority after revocation. Attackers with a paired device can regain WebSocket node-level access without renewed approval, weakening revocation controls and maintaining unauthorized access longer than intended.

thehackerwire@mastodon.social at 2026-06-17T02:00:14.000Z ##

🟠 CVE-2026-53843 - High (8.8)

OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped device session can re-establish node token authority after revocation. Attackers with a paired device can regain WebSocket node-level access ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-46850
(9.9 CRITICAL)

EPSS: 0.48%

updated 2026-06-18T04:16:48.923000

1 posts

Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is affected is 2026.2.0+9.6.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise MySQL Shell. While the vulnerability is in MySQL Shell, attacks may significantly impact additional products (scope change). Successful attack

offseq@infosec.exchange at 2026-06-17T10:30:27.000Z ##

Oracle's June 2026 CRITICAL update fixes 245 vulns (incl. CVE-2026-46850) in MySQL Shell, Router, NDB Cluster, Server (8.0.11-8.0.46, 8.4.0-8.4.9, 9.0.0-9.7.0, 2026.2.0+9.6.1). Patch promptly — no exploits yet. radar.offseq.com/threat/kwetsb #OffSeq #MySQL #Oracle #CVE202646850

##

CVE-2026-20181
(9.1 CRITICAL)

EPSS: 0.57%

updated 2026-06-18T04:16:45

7 posts

A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a

cyberveille@mastobot.ping.moi at 2026-06-19T20:30:21.000Z ##

📢 Cisco corrige une vulnérabilité critique d'exécution de commandes dans ISE (CVE-2026-20181)
📝 📰 Source : SecurityWeek, publié le 18 juin 2026 par Ionut Arghire.
📖 cyberveille : cyberveille.ch/posts/2026-06-1
🌐 source : securityweek.com/critical-comm
#CVE_2026_20181 #CVE_2026_20190 #Cyberveille

##

AAKL at 2026-06-19T17:19:43.672Z ##

New advisory.

This relates to critical CVE-2026-20181 and CVE-2026-20190 vulnerabilities, published on the 17th.

Cisco: CRITICAL: Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities sec.cloudapps.cisco.com/securi @TalosSecurity

@cR0w

##

AAKL@infosec.exchange at 2026-06-19T17:19:43.000Z ##

New advisory.

This relates to critical CVE-2026-20181 and CVE-2026-20190 vulnerabilities, published on the 17th.

Cisco: CRITICAL: Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

@cR0w

##

beyondmachines1@infosec.exchange at 2026-06-19T09:01:22.000Z ##

Cisco Patches Critical Root RCE and Credential Theft Flaws in ISE

Cisco patched a critical root RCE vulnerability (CVE-2026-20181) and a high-severity information disclosure flaw (CVE-2026-20190) in its Identity Services Engine. These vulnerabilities allow authenticated root access or theft of hashed credentials.

**Make sure your Cisco ISE and ISE-PIC systems are isolated from the internet and reachable only from trusted management networks. Apply the latest patches immediately (ISE 3.3 Patch 11, 3.4 Patch 6, or 3.5 Patch 3) and for the 3.5 command-execution fix, request the hotfix from Cisco TAC now. Don't wait for Patch 4 in August 2026.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

offseq@infosec.exchange at 2026-06-18T11:00:27.000Z ##

CVE-2026-20181: Cisco ISE/ISE-PIC critical command execution vuln lets authenticated admins run arbitrary OS commands & escalate to root. Patch ISE 3.3/3.4/3.5 ASAP. No active exploitation reported. radar.offseq.com/threat/critic #OffSeq #Cisco #Vuln #Infosec

##

AAKL@infosec.exchange at 2026-06-17T18:01:10.000Z ##

New.

Tenable research advisories:

CRITICAL: CVE-2026-8024: iba ibaPDA / ibaDatCoordinator .NET Deserialization Remote Code Execution tenable.com/security/research/ @tenable

Cisco:

CRITICAL: CVE-2026-20181 and CVE-2026-20190: Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities

Three others of medium-severity: sec.cloudapps.cisco.com/securi @TalosSecurity

Broadcom:

Several critical and high-severity vulnerabilities. A login is needed for details support.broadcom.com/web/ecx/s

Dell:

Several advisories, one of them critical:

CRITICAL: Security Update for Dell Data Protection Central Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0

More: dell.com/support/security/en-us

Google:

Chrome Beta for iOS Update chromereleases.googleblog.com/

Yesterday:

Microsoft:

CVE-2026-50656: Microsoft Defender Elevation of Privilege Vulnerability msrc.microsoft.com/update-guid

Nvidia:

Security Bulletin addressing CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228:

NVIDIA NeMo - June 2026 nvidia.custhelp.com/app/answer #Nvidia #Dell #Cisco #infosec #vulnerability #threatresearch #Broadcom #Google #Chrome #Microsoft #Windows

##

offseq@infosec.exchange at 2026-06-17T17:30:12.000Z ##

🚨 CRITICAL: CVE-2026-20181 in Cisco ISE (v3.1 – 3.5) allows authenticated attackers to run OS commands & escalate to root, risking DoS. Restrict admin access & monitor for patches. radar.offseq.com/threat/cve-20 #OffSeq #Cisco #Vuln #BlueTeam

##

CVE-2026-3894
(0 None)

EPSS: 0.20%

updated 2026-06-17T20:20:10.920000

1 posts

Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.0.0 before 5.2.*.

1 repos

https://github.com/Wise-Security/CVE-2026-38945

offseq@infosec.exchange at 2026-06-17T23:30:11.000Z ##

CVE-2026-3894 (CRITICAL, CVSS 9.2): Out-of-bounds read in RTI Connext Professional (versions 7.4.0, 7.0.0, 6.1.0, 6.0.0, 5.3.0, 5.0.0). Remote exploitation possible, no patch yet. Monitor vendor updates! radar.offseq.com/threat/cve-20 #OffSeq #CVE20263894 #ICS #vuln

##

CVE-2026-20266
(9.1 CRITICAL)

EPSS: 0.45%

updated 2026-06-17T20:17:50.620000

1 posts

In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance. The vulnerability is possible because of an unsafe shell execution pattern in the btool configuration helper, which constructs OS command strings from dynamic parameters without disabling shell interpretation.

offseq@infosec.exchange at 2026-06-18T04:30:24.000Z ##

🚨 CRITICAL: CVE-2026-20266 in Splunk AI Toolkit 5.7 lets admins run arbitrary OS commands due to unsafe shell execution. Restrict admin roles & monitor for abuse until patched. Details: radar.offseq.com/threat/cve-20 #OffSeq #Splunk #Vuln #CommandInjection

##

CVE-2026-53805
(9.8 CRITICAL)

EPSS: 0.69%

updated 2026-06-17T19:18:10.363000

1 posts

NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP request bodies using Python's pickle.loads() without authentication or input validation. Attackers can supply a crafted payload containing a __reduce__ gadget to the inference API port t

offseq@infosec.exchange at 2026-06-18T07:30:27.000Z ##

⚠️ CRITICAL: nv-tlabs GEN3C has a remote code execution bug (CVE-2026-53805). Unauthenticated attackers can run code via /request-inference & /seed-model endpoints using pickle.loads(). No patch yet — restrict access! radar.offseq.com/threat/cve-20 #OffSeq #CVE202653805 #NVIDIA #infosec

##

CVE-2026-47747
(7.8 HIGH)

EPSS: 0.14%

updated 2026-06-17T19:18:08.253000

1 posts

stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. In versions prior to master-584-0a7ae07, the pickle .ckpt parser in src/model.cpp contained a heap buffer overflow vulnerability in the BINUNICODE opcode handler. The issue was caused by sign confusion on the opcode length field. A crafted .ckpt file coul

thehackerwire@mastodon.social at 2026-06-16T21:00:01.000Z ##

🟠 CVE-2026-47747 - High (7.8)

stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. In versions prior to master-584-0a7ae07, the pickle .ckpt parser in src/model.cpp contained a heap buf...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

oversecurity@mastodon.social at 2026-06-19T13:01:02.000Z ##

CVE-2026-48907 and LiteSpeed cPanel Plugin Flaws Come Under Active Attack

Attackers are exploiting CVE-2026-48907 in Joomla JCE and a LiteSpeed cPanel plugin flaw, enabling PHP code execution and privilege escalation.

🔗️ [Thecyberexpress] link.is.it/SGbmfn

##

oversecurity@mastodon.social at 2026-06-19T13:01:02.000Z ##

CVE-2026-48907 and LiteSpeed cPanel Plugin Flaws Come Under Active Attack

Attackers are exploiting CVE-2026-48907 in Joomla JCE and a LiteSpeed cPanel plugin flaw, enabling PHP code execution and privilege escalation.

🔗️ [Thecyberexpress] link.is.it/SGbmfn

##

threatnoir@infosec.exchange at 2026-06-18T18:06:31.000Z ##

⚠️ CRITICAL: Joomla, LiteSpeed Vulnerabilities Exploited in Attacks

Attackers are actively exploiting CVE-2026-48907 in Joomla Content Editor (JCE) to upload malicious PHP files and execute arbitrary code on all versions before 2.9.99.5. CVE-2026-54420 in LiteSpeed's cPanel plugin allows privilege escalation to root on shared hosting environments. Both vulnerabilit…

threatnoir.com/focus

#infosec #cybersecurity

##

beyondmachines1@infosec.exchange at 2026-06-18T11:01:47.000Z ##

Joomla Content Editor Flaw Allows Unauthenticated Remote Code Execution

A critical vulnerability in the Joomla Content Editor (JCE) extension (CVE-2026-48907) allows unauthenticated attackers to create rogue profiles and execute PHP code. CISA has confirmed active exploitation.

**If you run the JCE extension on your Joomla site, this is urgent. Attackers are actively taking over sites through this flaw. Update it to version 2.9.99.6 or later right away (or apply the free stopgap patch if you're on an older 2.7.x–2.9.x version). Patching alone won't remove malware already planted, so also check for rogue editor profiles and unexpected PHP files in your /images, /media, and /tmp folders, delete anything suspicious, run a full malware scan, and change all admin passwords and database credentials.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

thecybermind@infosec.exchange at 2026-06-17T20:40:10.000Z ##

Alert: CVE-2026-48907. A severe access control flaw in Widget Factory Joomla Content Editor allows unauthenticated PHP script execution. Lock down your CMS. Read our tactical engineering runbook for full IOCs and endpoint hardening steps. thecybermind.co/unjv

🛡️ #CyberSecurity #CVE #ThreatIntel

##

thecybermind@infosec.exchange at 2026-06-17T16:26:42.000Z ##

URGENT: CVE-2026-48907 is seeing active exploitation in Joomla! JCE extensions. This critical RCE flaw allows unauthenticated attackers to take full control. Read our executive remediation brief to harden your environment now.
thecybermind.co/ic6z
#CyberSecurity #Joomla #Infosec #KEV

##

decio@infosec.exchange at 2026-06-17T11:54:50.000Z ##

⚠️ Vous administrez un site Joomla ?

Petit point sécurité : la faille CVE-2026-48907 touche l’extension **JCE / Joomla Content Editor **et elle est déjà exploitée automatiquement sur Internet.
👇 🩹
joomlacontenteditor.net/news/j

En clair : un site vulnérable peut être compromis même sans compte public ni inscription ouverte.

À faire dès que possible:
• mettre JCE à jour en 2.9.99.6 ou plus récent
• vérifier les profils/comptes suspects
• changer les mots de passe admin, base de données et hébergement
• lancer un scan serveur

(La mise à jour ferme la porte, mais ne nettoie pas forcément ce qui aurait déjà été déposé.)

🔍
⬇️
vulnerability.circl.lu/vuln/cv

#CyberVeille #Joomla

##

rxerium@infosec.exchange at 2026-06-17T11:20:24.000Z ##

🚨 New critical improper access control vulnerability tagged CVE-2026-48907, affecting Widget Factory Joomla Content Editor is seeing active exploitation in the wild as reported by CISA.

Vulnerability detection script available below:
github.com/rxerium/rxerium-tem

Patches and mitigations are available:
sentinelone.com/vulnerability-

##

secdb@infosec.exchange at 2026-06-16T21:00:17.000Z ##

🚨 [CISA-2026:0616] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48907 (secdb.nttzen.cloud/cve/detail/)
- Name: Widget Factory Joomla Content Editor Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Widget Factory
- Product: Joomla Content Editor
- Notes: joomlacontenteditor.net/news/j ; joomlacontenteditor.net/suppor ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260616 #cisa20260616 #cve_2026_48907 #cve202648907

##

cisakevtracker@mastodon.social at 2026-06-16T20:00:46.000Z ##

CVE ID: CVE-2026-48907
Vendor: Widget Factory
Product: Joomla Content Editor
Date Added: 2026-06-16
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-42530
(8.1 HIGH)

EPSS: 0.76%

updated 2026-06-17T18:36:07

7 posts

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers

3 repos

https://github.com/0xBlackash/CVE-2026-42530

https://github.com/HORKimhab/CVE-2026-42530

https://github.com/v4ltonn/CVE-2026-42530

_r_netsec at 2026-06-19T19:28:05.452Z ##

Use-after-free in the QPACK encoder of nginx HTTP/3 - CVE-2026-42530 cystack.net/vi/research/cve-20

##

jerry at 2026-06-19T12:34:49.432Z ##

@c0dec0dec0de RCEs this time, not DoS. CVE-2026-42530 & CVE-2026-42055

##

_r_netsec@infosec.exchange at 2026-06-19T19:28:05.000Z ##

Use-after-free in the QPACK encoder of nginx HTTP/3 - CVE-2026-42530 cystack.net/vi/research/cve-20

##

jerry@infosec.exchange at 2026-06-19T12:34:49.000Z ##

@c0dec0dec0de RCEs this time, not DoS. CVE-2026-42530 & CVE-2026-42055

##

beyondmachines1@infosec.exchange at 2026-06-19T08:01:21.000Z ##

F5 Patches Critical Remote Code Execution Flaws in NGINX Open Source and Plus

F5 addressed two critical vulnerabilities (CVE-2026-42530 and CVE-2026-42055) in NGINX that allow unauthenticated remote code execution or denial-of-service. The flaws affect NGINX Open Source, NGINX Plus, and several related gateway and controller products.

**If you run NGINX (Open Source, Plus, Ingress Controller, Gateway Fabric, Instance Manager, or App Protect WAF), update immediately to the fixed versions F5 released: NGINX Open Source 1.31.2 or 1.30.3, and NGINX Plus 37.0.2.1 or R36 P6. If you can't patch right away, temporarily disable HTTP/3 by removing "quic" from all listen directives, and remove the "ignore_invalid_headers off" directive or shrink "large_client_header_buffers" to block these attacks until you update.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

threatnoir@infosec.exchange at 2026-06-18T18:06:26.000Z ##

⚠️ CRITICAL: F5 Patches Critical, High-Severity NGINX Vulnerabilities

F5 released patches for critical unauthenticated RCE and DoS vulnerabilities in NGINX (CVE-2026-42530, CVE-2026-42055) affecting NGINX Plus, Controller, and related products. Attackers can exploit heap buffer overflows and use-after-free flaws without credentials to crash services or execute arbitr…

threatnoir.com/focus

#infosec #cybersecurity

##

lobsters@mastodon.social at 2026-06-18T13:45:11.000Z ##

CVE-2026-42530: Use after free in nginx HTTP/3 QUIC module lobste.rs/s/pbvqlz #security
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-20190
(7.5 HIGH)

EPSS: 0.37%

updated 2026-06-17T18:36:07

4 posts

A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to sensitive

AAKL at 2026-06-19T17:19:43.672Z ##

New advisory.

This relates to critical CVE-2026-20181 and CVE-2026-20190 vulnerabilities, published on the 17th.

Cisco: CRITICAL: Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities sec.cloudapps.cisco.com/securi @TalosSecurity

@cR0w

##

AAKL@infosec.exchange at 2026-06-19T17:19:43.000Z ##

New advisory.

This relates to critical CVE-2026-20181 and CVE-2026-20190 vulnerabilities, published on the 17th.

Cisco: CRITICAL: Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

@cR0w

##

beyondmachines1@infosec.exchange at 2026-06-19T09:01:22.000Z ##

Cisco Patches Critical Root RCE and Credential Theft Flaws in ISE

Cisco patched a critical root RCE vulnerability (CVE-2026-20181) and a high-severity information disclosure flaw (CVE-2026-20190) in its Identity Services Engine. These vulnerabilities allow authenticated root access or theft of hashed credentials.

**Make sure your Cisco ISE and ISE-PIC systems are isolated from the internet and reachable only from trusted management networks. Apply the latest patches immediately (ISE 3.3 Patch 11, 3.4 Patch 6, or 3.5 Patch 3) and for the 3.5 command-execution fix, request the hotfix from Cisco TAC now. Don't wait for Patch 4 in August 2026.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

AAKL@infosec.exchange at 2026-06-17T18:01:10.000Z ##

New.

Tenable research advisories:

CRITICAL: CVE-2026-8024: iba ibaPDA / ibaDatCoordinator .NET Deserialization Remote Code Execution tenable.com/security/research/ @tenable

Cisco:

CRITICAL: CVE-2026-20181 and CVE-2026-20190: Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities

Three others of medium-severity: sec.cloudapps.cisco.com/securi @TalosSecurity

Broadcom:

Several critical and high-severity vulnerabilities. A login is needed for details support.broadcom.com/web/ecx/s

Dell:

Several advisories, one of them critical:

CRITICAL: Security Update for Dell Data Protection Central Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0

More: dell.com/support/security/en-us

Google:

Chrome Beta for iOS Update chromereleases.googleblog.com/

Yesterday:

Microsoft:

CVE-2026-50656: Microsoft Defender Elevation of Privilege Vulnerability msrc.microsoft.com/update-guid

Nvidia:

Security Bulletin addressing CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228:

NVIDIA NeMo - June 2026 nvidia.custhelp.com/app/answer #Nvidia #Dell #Cisco #infosec #vulnerability #threatresearch #Broadcom #Google #Chrome #Microsoft #Windows

##

CVE-2026-42055
(8.1 HIGH)

EPSS: 0.64%

updated 2026-06-17T18:36:07

4 posts

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attack

1 repos

https://github.com/HORKimhab/CVE-2026-42055

jerry at 2026-06-19T12:34:49.432Z ##

@c0dec0dec0de RCEs this time, not DoS. CVE-2026-42530 & CVE-2026-42055

##

jerry@infosec.exchange at 2026-06-19T12:34:49.000Z ##

@c0dec0dec0de RCEs this time, not DoS. CVE-2026-42530 & CVE-2026-42055

##

beyondmachines1@infosec.exchange at 2026-06-19T08:01:21.000Z ##

F5 Patches Critical Remote Code Execution Flaws in NGINX Open Source and Plus

F5 addressed two critical vulnerabilities (CVE-2026-42530 and CVE-2026-42055) in NGINX that allow unauthenticated remote code execution or denial-of-service. The flaws affect NGINX Open Source, NGINX Plus, and several related gateway and controller products.

**If you run NGINX (Open Source, Plus, Ingress Controller, Gateway Fabric, Instance Manager, or App Protect WAF), update immediately to the fixed versions F5 released: NGINX Open Source 1.31.2 or 1.30.3, and NGINX Plus 37.0.2.1 or R36 P6. If you can't patch right away, temporarily disable HTTP/3 by removing "quic" from all listen directives, and remove the "ignore_invalid_headers off" directive or shrink "large_client_header_buffers" to block these attacks until you update.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

threatnoir@infosec.exchange at 2026-06-18T18:06:26.000Z ##

⚠️ CRITICAL: F5 Patches Critical, High-Severity NGINX Vulnerabilities

F5 released patches for critical unauthenticated RCE and DoS vulnerabilities in NGINX (CVE-2026-42530, CVE-2026-42055) affecting NGINX Plus, Controller, and related products. Attackers can exploit heap buffer overflows and use-after-free flaws without credentials to crash services or execute arbitr…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-2467(CVSS UNKNOWN)

EPSS: 0.21%

updated 2026-06-17T18:35:58

1 posts

Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.0.0 before 5.2.*.

offseq@infosec.exchange at 2026-06-18T03:00:27.000Z ##

🔍 CRITICAL: CVE-2026-2467 in RTI Connext Professional (v5.0.0 – 7.4.0) enables heap-based buffer overflow, risking RCE & DoS. No patch yet — monitor vendor updates. CVSS 9.2. Details: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #CVE20262467 #RTI #Infosec

##

CVE-2026-12440
(9.6 CRITICAL)

EPSS: 0.31%

updated 2026-06-17T18:35:53

1 posts

Use after free in DigitalCredentials in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

offseq@infosec.exchange at 2026-06-17T07:30:25.000Z ##

🚨 CRITICAL: CVE-2026-12440 in Chrome DigitalCredentials (Windows <149.0.7827.155) allows remote sandbox escape. Patch to 149.0.7827.155 ASAP! Exploitation risk is high. radar.offseq.com/threat/cve-20 #OffSeq #Chrome #InfoSec #Vulnerability

##

CVE-2026-12441
(8.8 HIGH)

EPSS: 0.29%

updated 2026-06-17T18:35:53

1 posts

Use after free in File Input in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

offseq@infosec.exchange at 2026-06-17T06:00:27.000Z ##

🔒 CRITICAL: CVE-2026-12441 in Chrome <149.0.7827.155 on Linux — use-after-free in File Input. Remote attacker can trigger heap corruption via crafted HTML. Update Chrome ASAP! radar.offseq.com/threat/cve-20 #OffSeq #Chrome #Linux #Vuln

##

CVE-2026-12443
(8.8 HIGH)

EPSS: 0.52%

updated 2026-06-17T18:35:53

1 posts

Use after free in Web Authentication in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

offseq@infosec.exchange at 2026-06-17T03:00:25.000Z ##

🚩 CRITICAL: Chrome Web Authentication use-after-free (CVE-2026-12443) enables remote code execution in versions <149.0.7827.155. Patch immediately to stay secure. Vendor fix available. radar.offseq.com/threat/cve-20 #OffSeq #Chrome #InfoSec #Vuln

##

CVE-2026-22313
(9.1 CRITICAL)

EPSS: 0.92%

updated 2026-06-17T17:16:43.687000

2 posts

The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability an authenticated attacker can send arbitrary commands to the device that are executed with administrative permissions by the underlying operating system.

cR0w@infosec.exchange at 2026-06-17T12:41:08.000Z ##

Command injection and hardcoded creds in Radiflow iSAP Smart Collector. Nice.

cve.org/CVERecord?id=CVE-2026-

cve.org/CVERecord?id=CVE-2026-

##

thehackerwire@mastodon.social at 2026-06-16T21:00:55.000Z ##

🔴 CVE-2026-22313 - Critical (9.1)

The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability an authenticated attacker can send
arbitrary commands to the device that are executed with...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48745
(9.3 CRITICAL)

EPSS: 0.41%

updated 2026-06-17T16:28:34.830000

1 posts

Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Traccar platform. In versions 9.7.19 and below, a single crafted deep link can silently hijack all GPS tracking parameters and redirect telemetry to an attacker-controlled server. The app registers a custom org.traccar.client://config deep-link scheme that silently writes attacker-supp

offseq@infosec.exchange at 2026-06-17T01:30:30.000Z ##

🚨 CRITICAL: CVE-2026-48745 in traccar-client <=9.7.19 allows silent GPS data redirection via crafted deep links — no user prompt, persists after restart. Update to 9.7.20 now! radar.offseq.com/threat/cve-20 #OffSeq #Infosec #MobileSecurity #CVE202648745

##

CVE-2026-5667
(0 None)

EPSS: 0.15%

updated 2026-06-17T16:21:32.403000

1 posts

Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Packaged Air Conditioners (for Japan and outside Japan); Refrigerators (for Japan); Heat Pump Water Heaters / HEMS-Compatible Adapters / Wireless LAN Adapters (for Japan); Bat

_r_netsec@infosec.exchange at 2026-06-18T18:13:05.000Z ##

CVE-2026-5667: Unauthenticated Remote Control of Mitsubishi MAC-577IF-2E WiFi Adapters via Probe Request Reconnaissance innerfirez.github.io/posts/the

##

CVE-2026-48780
(8.2 HIGH)

EPSS: 0.22%

updated 2026-06-17T14:17:56.423000

1 posts

Forem is open source software for building communities. Prior to commit a2ab6d4, a maliciously crafted email address could allow an attacker to bypass domain allowlist or denylist restrictions and gain access to invite-only forem deployments. The issue is patched as of `a2ab6d4`. As a workaround, some SMTP servers and email delivery providers may drop or refuse to send maliciously crafted email ad

thehackerwire@mastodon.social at 2026-06-16T16:00:00.000Z ##

🟠 CVE-2026-48780 - High (8.2)

Forem is open source software for building communities. Prior to commit a2ab6d4, a maliciously crafted email address could allow an attacker to bypass domain allowlist or denylist restrictions and gain access to invite-only forem deployments. The ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47964
(7.8 HIGH)

EPSS: 0.20%

updated 2026-06-17T13:20:42.017000

1 posts

DNG SDK versions 1.7.1 2536 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

thehackerwire@mastodon.social at 2026-06-17T02:00:33.000Z ##

🟠 CVE-2026-47964 - High (7.8)

DNG SDK versions 1.7.1 2536 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vic...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-24155
(7.8 HIGH)

EPSS: 0.19%

updated 2026-06-17T13:20:10.417000

3 posts

NVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

AAKL@infosec.exchange at 2026-06-17T18:01:10.000Z ##

New.

Tenable research advisories:

CRITICAL: CVE-2026-8024: iba ibaPDA / ibaDatCoordinator .NET Deserialization Remote Code Execution tenable.com/security/research/ @tenable

Cisco:

CRITICAL: CVE-2026-20181 and CVE-2026-20190: Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities

Three others of medium-severity: sec.cloudapps.cisco.com/securi @TalosSecurity

Broadcom:

Several critical and high-severity vulnerabilities. A login is needed for details support.broadcom.com/web/ecx/s

Dell:

Several advisories, one of them critical:

CRITICAL: Security Update for Dell Data Protection Central Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0

More: dell.com/support/security/en-us

Google:

Chrome Beta for iOS Update chromereleases.googleblog.com/

Yesterday:

Microsoft:

CVE-2026-50656: Microsoft Defender Elevation of Privilege Vulnerability msrc.microsoft.com/update-guid

Nvidia:

Security Bulletin addressing CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228:

NVIDIA NeMo - June 2026 nvidia.custhelp.com/app/answer #Nvidia #Dell #Cisco #infosec #vulnerability #threatresearch #Broadcom #Google #Chrome #Microsoft #Windows

##

thehackerwire@mastodon.social at 2026-06-16T19:00:05.000Z ##

🟠 CVE-2026-24155 - High (7.8)

NVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

AAKL@infosec.exchange at 2026-06-16T15:46:34.000Z ##

Nvidia has a new advisory relating to CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228, all high-severity:

Security Bulletin: NVIDIA NeMo - June 2026 nvidia.custhelp.com/app/answer #Nvidia

Broadcom:

Seven advisories addressing one critical vulnerability and several high-severity flaws: You'll need a login for details.

CRITICAL: MICS 14.3, 14.4, and 14.5 Vulnerabilities

More: support.broadcom.com/web/ecx/s #Broadcom

Yesterday:

Google:

Chrome Dev for Desktop Update chromereleases.googleblog.com/ #Google #Chrome

Dell:

Update for a critical vulnerability yesterday that encompasses multiple CVEs:

Security Update for Dell PowerProtect DP Series Appliance (IDPA) Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #infosec #vulnerability

##

CVE-2026-22312
(8.6 HIGH)

EPSS: 0.23%

updated 2026-06-17T13:20:06.023000

2 posts

The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be used by an attacker to get access to system settings, modify the configuration and execute some commands (e.g. system reboot).

cR0w@infosec.exchange at 2026-06-17T12:41:08.000Z ##

Command injection and hardcoded creds in Radiflow iSAP Smart Collector. Nice.

cve.org/CVERecord?id=CVE-2026-

cve.org/CVERecord?id=CVE-2026-

##

thehackerwire@mastodon.social at 2026-06-16T21:00:19.000Z ##

🟠 CVE-2026-22312 - High (8.6)

The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be used by an attacker to get access to system settings, modify the configuration
and execute some commands (e.g. system reboot).

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54420
(8.5 HIGH)

EPSS: 0.65%

updated 2026-06-17T10:58:13.830000

1 posts

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.

4 repos

https://github.com/Resellnom/litespeed-cpanel-cve-2026-54420-fix

https://github.com/mahfuzreham/litespeed-cpanel-cve-2026-54420-fix

https://github.com/fevar54/CVE-2026-54420-LiteSpeed-Symlink-Exploit

https://github.com/HORKimhab/CVE-2026-54420

threatnoir@infosec.exchange at 2026-06-18T18:06:31.000Z ##

⚠️ CRITICAL: Joomla, LiteSpeed Vulnerabilities Exploited in Attacks

Attackers are actively exploiting CVE-2026-48907 in Joomla Content Editor (JCE) to upload malicious PHP files and execute arbitrary code on all versions before 2.9.99.5. CVE-2026-54420 in LiteSpeed's cPanel plugin allows privilege escalation to root on shared hosting environments. Both vulnerabilit…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-4272
(8.1 HIGH)

EPSS: 0.45%

updated 2026-06-17T10:56:20.347000

1 posts

Missing Authentication for Critical Function vulnerability in Honeywell Handheld Scanners allows Authentication Abuse.This issue affects Handheld Scanners: from C1 Base(Ingenic x1000) before GK000432BAA, from D1 Base(Ingenic x1600) before HE000085BAA, from A1/B1 Base(IMX25) before BK000763BAA_BK000765BAA_CU000101BAA. This vulnerability could allow a remote attacker within Bluetooth range of the s

nyanbinary@infosec.exchange at 2026-06-17T14:54:22.000Z ##

Q: Am I counting these?

('https://https:', {'https://https://docs.tenable.com/release-notes/Content/security-center/2026.htm', 'https://https://www.asustor.com/security/security_advisory_detail?id=55', 'https://https://www.tenable.com/security/tns-2026-07', 'https://https://talosintelligence.com/vulnerability_reports/', 'https://https://mail.python.org/archives/list/security-announce@python.org/thread/JIFOBO7UX3LY4VJKJUOKYJV62CFR2IRH/', 'https://https://www.geovision.com.tw/cyber_security.php', 'https://https://nvd.nist.gov/vuln/detail/CVE-2026-4272', 'https://https://github.com/videolan/vlc-android/releases/tag/3.7.0', 'https://https://thewatch.centreon.com/latest-security-bulletins-64/cve-2026-2751-centreon-web-high-severity-5504'})
##

CVE-2026-4020
(7.5 HIGH)

EPSS: 2.98%

updated 2026-06-17T10:55:52.033000

5 posts

The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. This is due to a REST API endpoint registered at /wp-json/gravitysmtp/v1/tests/mock-data with a permission_callback that unconditionally returns true, allowing any unauthenticated visitor to access it. When the ?page=gravitysmtp-settings query parameter is appended, th

Nuclei template

undercodenews@mastodon.social at 2026-06-19T23:55:26.000Z ##

Critical WordPress Security Alert: Gravity SMTP Vulnerability Could Expose API Keys and Email Credentials Across 100,000+ Websites, Dark Web Recent Claims + Video

Introduction: A New WordPress Threat Raises Concerns Across the Website Security Community A newly reported cybersecurity warning is drawing attention from researchers and website administrators after claims emerged that attackers are actively exploiting a vulnerability identified as CVE-2026-4020 in Gravity…

undercodenews.com/critical-wor

##

hrbrmstr@mastodon.social at 2026-06-17T10:42:14.000Z ##

Solid breakdown by @honeylabs of the opportunistic activity against CVE-2026-4020

~560 IPs rotating through ~3,300 UAs

Rly important to heed the info further down in the article re: "attacking the CVE" vs "added yet-another-cred path to existing scans".

honeylabs.net/blog/the-cloud-f

##

hnbot@chrispelli.fun at 2026-06-17T09:14:09.000Z ##

Most of the CVE-2026-4020 attackers are the same client - honeylabs.net/blog/the-cloud-f

#hackernews

##

ngate@mastodon.social at 2026-06-17T09:13:14.000Z ##

🤔 Ah, the classic "same client" saga with CVE-2026-4020—because who needs originality in #hacking when you have a Google Cloud fleet playing dress-up with 3,299 user agents? 🌍📬 Apparently, exploiting Gravity #SMTP is a team sport, but only if your team is a single IP address with a personality disorder. What a performance! 🎭💻
honeylabs.net/blog/the-cloud-f #CVE20264020 #GoogleCloud #SecurityFlaw #Cybersecurity #HackerNews #ngated

##

h4ckernews@mastodon.social at 2026-06-17T09:13:08.000Z ##

Most of the CVE-2026-4020 attackers are the same client

honeylabs.net/blog/the-cloud-f

#HackerNews #CVE20264020 #cybersecurity #cloudfleet #attackers #analysis

##

CVE-2026-49112
(7.5 HIGH)

EPSS: 0.33%

updated 2026-06-17T10:55:31.270000

1 posts

Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.

thehackerwire@mastodon.social at 2026-06-17T11:59:59.000Z ##

🟠 CVE-2026-49112 - High (7.5)

Unauthenticated Path Traversal in Shared Files &lt;= 1.7.64 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49110
(7.5 HIGH)

EPSS: 0.24%

updated 2026-06-17T10:55:31.073000

1 posts

Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce <= 3.1.4 versions.

thehackerwire@mastodon.social at 2026-06-17T10:00:15.000Z ##

🟠 CVE-2026-49110 - High (7.5)

Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce &lt;= 3.1.4 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49106
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-06-17T10:55:30.877000

1 posts

Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions.

thehackerwire@mastodon.social at 2026-06-17T09:59:55.000Z ##

🔴 CVE-2026-49106 - Critical (9.8)

Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact &lt;= 1.1.6 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49105
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-06-17T10:55:30.777000

1 posts

Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.

1 repos

https://github.com/izxci/CVE-2026-49105

thehackerwire@mastodon.social at 2026-06-17T08:00:16.000Z ##

🔴 CVE-2026-49105 - Critical (9.8)

Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms &lt;= 1.1.4 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49104
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-06-17T10:55:30.680000

1 posts

Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 versions.

1 repos

https://github.com/izxci/CVE-2026-49104-

thehackerwire@mastodon.social at 2026-06-17T08:00:04.000Z ##

🔴 CVE-2026-49104 - Critical (9.8)

Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms &lt;= 1.2.1 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49068
(7.5 HIGH)

EPSS: 0.40%

updated 2026-06-17T10:55:29.337000

1 posts

Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions.

thehackerwire@mastodon.social at 2026-06-17T13:00:12.000Z ##

🟠 CVE-2026-49068 - High (7.5)

Subscriber Sensitive Data Exposure in Coupon Affiliates &lt;= 7.8.1 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49067
(9.3 CRITICAL)

EPSS: 0.30%

updated 2026-06-17T10:55:29.237000

1 posts

Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions.

thehackerwire@mastodon.social at 2026-06-17T13:00:02.000Z ##

🔴 CVE-2026-49067 - Critical (9.3)

Unauthenticated SQL Injection in Advanced 301 and 302 Redirect &lt;= 1.6.9 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49066
(7.5 HIGH)

EPSS: 0.30%

updated 2026-06-17T10:55:29.137000

1 posts

Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway <= 6.0.0 versions.

thehackerwire@mastodon.social at 2026-06-17T12:59:52.000Z ##

🟠 CVE-2026-49066 - High (7.5)

Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway &lt;= 6.0.0 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49065
(8.2 HIGH)

EPSS: 0.24%

updated 2026-06-17T10:55:29.037000

1 posts

Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions.

thehackerwire@mastodon.social at 2026-06-17T12:00:19.000Z ##

🟠 CVE-2026-49065 - High (8.2)

Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce &lt;= 1.9.5 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49061
(7.5 HIGH)

EPSS: 0.37%

updated 2026-06-17T10:55:28.650000

1 posts

Unauthenticated Arbitrary File Download in WPC Product Options for WooCommerce <= 3.2.1 versions.

thehackerwire@mastodon.social at 2026-06-17T12:00:09.000Z ##

🟠 CVE-2026-49061 - High (7.5)

Unauthenticated Arbitrary File Download in WPC Product Options for WooCommerce &lt;= 3.2.1 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48558
(10.0 CRITICAL)

EPSS: 0.63%

updated 2026-06-17T10:55:05.230000

2 posts

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary

cyberveille@mastobot.ping.moi at 2026-06-18T18:30:12.000Z ##

📢 ~14 000 serveurs SimpleHelp exposés via un contournement d'authentification critique (CVE-2026-48558)
📝 📰 **Source** : CybersecurityNews.com — **Date de publication** : 16 juin 2026

...
📖 cyberveille : cyberveille.ch/posts/2026-06-1
🌐 source : cybersecuritynews.com/simplehe
#CVE_2026_48558 #IOC #Cyberveille

##

cyberveille@mastobot.ping.moi at 2026-06-17T17:00:21.000Z ##

📢 CVE-2026-48558 : Contournement d'authentification critique dans SimpleHelp via OIDC
📝 ## 🔍 Contexte

Le 12 juin 2026, Horizon3.ai publie une divulgation technique concernant **CVE-2026-4855...
📖 cyberveille : cyberveille.ch/posts/2026-06-1
🌐 source : horizon3.ai/attack-research/di
#CVE_2026_48558 #IOC #Cyberveille

##

CVE-2026-48095
(8.8 HIGH)

EPSS: 0.70%

updated 2026-06-17T10:54:50.997000

1 posts

7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buffer overflow vulnerability caused by an under-allocation in the NTFS compressed stream buffer (GetCuSize shift UB), potentially allowing attackers to cause arbitrary code execution or application crashes. CInStream::GetCuSize() in the NTFS handler computes the compression-unit buffer size as (UInt32)

1 repos

https://github.com/HORKimhab/CVE-2026-48095

ruari@velocipederider.com at 2026-06-17T12:52:27.000Z ##

Just two recent examples of vulnerablities from 7-Zip and RAR.

Also keep in mind that distros are not always great at updating and if you installed one of these yourself, it is also on you (plus neither autoupdate on Windows or macOS).

• 7-Zip: nvd.nist.gov/vuln/detail/cve-2

• WinRAR: nvd.nist.gov/vuln/detail/cve-2

##

CVE-2026-47749
(7.8 HIGH)

EPSS: 0.16%

updated 2026-06-17T10:54:39.427000

1 posts

stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. Versions prior to master-584-0a7ae07 are vulnerable to heap buffer overflow in SHORT_BINUNICODE parsing for PyTorch checkpoint files. The pickle .ckpt parser in src/model.cpp contained a heap buffer overflow vulnerability in the SHORT_BINUNICODE opcode ha

thehackerwire@mastodon.social at 2026-06-17T03:00:02.000Z ##

🟠 CVE-2026-47749 - High (7.8)

stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. Versions prior to master-584-0a7ae07 are vulnerable to heap buffer overflow in SHORT_BINUNICODE parsin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47684
(7.7 HIGH)

EPSS: 0.38%

updated 2026-06-17T10:54:37.403000

1 posts

Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.3.0, the private IP blocklist regex used in the URL download feature does not match IPv4-mapped IPv6 addresses (e.g. ::ffff:127.0.0.1), allowing SSRF protection to be bypassed on dual-stack systems. Version 2.3.0 fixes the issue.

thehackerwire@mastodon.social at 2026-06-16T15:59:50.000Z ##

🟠 CVE-2026-47684 - High (7.7)

Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.3.0, the private IP blocklist regex used in the URL download feature does not match IPv4-mapped IPv6 addresses (e.g. ::ffff:...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-42271
(8.8 HIGH)

EPSS: 53.70%

updated 2026-06-17T10:47:36.560000

1 posts

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration in the request body, including the command, args, and env fields used by the stdio transport. When c

Nuclei template

2 repos

https://github.com/learner202649/CVE-2026-42271-PoC

https://github.com/HORKimhab/CVE-2026-42271

patrickcmiller@infosec.exchange at 2026-06-17T18:42:00.000Z ##

LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE thehackernews.com/2026/06/lite

##

CVE-2026-2751
(8.3 HIGH)

EPSS: 0.27%

updated 2026-06-17T10:31:39.420000

1 posts

Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web on Central Server on Linux (Service Dependencies modules) allows Blind SQL Injection.This issue affects Centreon Web on Central Server before 25.10.8, 24.10.20, 24.04.24.

1 repos

https://github.com/hakaioffsec/Centreon-Exploits-2026

nyanbinary@infosec.exchange at 2026-06-17T14:54:22.000Z ##

Q: Am I counting these?

('https://https:', {'https://https://docs.tenable.com/release-notes/Content/security-center/2026.htm', 'https://https://www.asustor.com/security/security_advisory_detail?id=55', 'https://https://www.tenable.com/security/tns-2026-07', 'https://https://talosintelligence.com/vulnerability_reports/', 'https://https://mail.python.org/archives/list/security-announce@python.org/thread/JIFOBO7UX3LY4VJKJUOKYJV62CFR2IRH/', 'https://https://www.geovision.com.tw/cyber_security.php', 'https://https://nvd.nist.gov/vuln/detail/CVE-2026-4272', 'https://https://github.com/videolan/vlc-android/releases/tag/3.7.0', 'https://https://thewatch.centreon.com/latest-security-bulletins-64/cve-2026-2751-centreon-web-high-severity-5504'})
##

CVE-2026-11526
(9.8 CRITICAL)

EPSS: 2.46%

updated 2026-06-17T10:14:12.300000

1 posts

GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle. GD::Image::_make_filehandle opens a filename argument with Perl's 2-arg open(), so a filename that begins or ends with a pipe ("| cmd", "cmd |") or begins with a redirect ("> path", ">> path") is run as a command or redirect rather than opened as a file. _ma

canartuc@mastodon.social at 2026-06-16T15:35:45.000Z ##

Perl's GD module released 2.86 to fix CVE-2026-11526, a command-injection flaw where GD::Image constructors passed untrusted filenames to Perl's 2-argument open(), so a name beginning or ending with a pipe, or starting with a redirect, ran as a shell command or truncated a file. The fix opens filenames with a 3-argument read open. In-memory Data constructors were never affected. Is 2-arg open() still lurking in your dependencies?
#Perl #security

##

CVE-2026-0843
(6.3 MEDIUM)

EPSS: 0.20%

updated 2026-06-17T10:11:29.160000

1 posts

A vulnerability has been found in jiujiujia/victor123/wxw850227 jjjfood and jjjshop_food up to 20260103. This vulnerability affects unknown code of the file /index.php/api/product.category/index. Such manipulation of the argument latitude leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product is distributed under mult

nyanbinary@infosec.exchange at 2026-06-17T08:06:04.000Z ##

cve.org/CVERecord?id=CVE-2026- - do I dare click that reference... :neocat_scream_scared:

##

CVE-2025-8088
(8.8 HIGH)

EPSS: 81.35%

updated 2026-06-17T10:06:17.243000

1 posts

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.

31 repos

https://github.com/nhattanhh/CVE-2025-8088

https://github.com/0xAbolfazl/CVE-2025-8088-WinRAR-PathTraversal-PoC

https://github.com/kitsuneshade/WinRAR-Exploit-Tool---Rust-Edition

https://github.com/pescada-dev/-CVE-2025-8088

https://github.com/DeepBlue-dot/CVE-2025-8088-WinRAR-Startup-PoC

https://github.com/hexsecteam/CVE-2025-8088-Winrar-Tool

https://github.com/ilhamrzr/RAR-Anomaly-Inspector

https://github.com/undefined-name12/CVE-2025-8088-Winrar

https://github.com/xi0onamdev/WinRAR-CVE-2025-8088-Exploitation-Toolkit

https://github.com/papcaii2004/CVE-2025-8088-WinRAR-builder

https://github.com/lennertdefauw/CVE-2025-8088

https://github.com/pentestfunctions/best-CVE-2025-8088

https://github.com/ghostn4444/CVE-2025-8088

https://github.com/nuky-alt/CVE-2025-8088

https://github.com/hbesljx/CVE-2025-8088-EXP

https://github.com/IsmaelCosma/CVE-2025-8088

https://github.com/AdityaBhatt3010/CVE-2025-8088-WinRAR-Zero-Day-Path-Traversal

https://github.com/shaheeryasirofficial/CVE-2025-8088

https://github.com/sxyrxyy/CVE-2025-8088-WinRAR-Proof-of-Concept-PoC-Exploit-

https://github.com/onlytoxi/CVE-2025-8088-Winrar-Tool

https://github.com/techcorp/CVE-2025-8088-Exploit

https://github.com/aldisakti2/CVE-2025-8088-BUILDER-Winrar-Tool

https://github.com/knight0x07/WinRAR-CVE-2025-8088-PoC-RAR

https://github.com/pentestfunctions/CVE-2025-8088-Multi-Document

https://github.com/Syrins/CVE-2025-8088-Winrar-Tool-Gui

https://github.com/starfallreverie/winrar-exploit

https://github.com/Shinkirou789/Cve-2025-8088-WinRar-vulnerability

https://github.com/walidpyh/CVE-2025-8088

https://github.com/jordan922/CVE-2025-8088

https://github.com/pexlexity/WinRAR-CVE-2025-8088-Path-Traversal-PoC

https://github.com/travisbgreen/cve-2025-8088

ruari@velocipederider.com at 2026-06-17T12:52:27.000Z ##

Just two recent examples of vulnerablities from 7-Zip and RAR.

Also keep in mind that distros are not always great at updating and if you installed one of these yourself, it is also on you (plus neither autoupdate on Windows or macOS).

• 7-Zip: nvd.nist.gov/vuln/detail/cve-2

• WinRAR: nvd.nist.gov/vuln/detail/cve-2

##

CVE-2025-71261
(8.6 HIGH)

EPSS: 0.21%

updated 2026-06-17T10:03:58.203000

1 posts

An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the TLS handshake and abuse it to bypass TLS as a security control.

thehackerwire@mastodon.social at 2026-06-16T19:00:25.000Z ##

🟠 CVE-2025-71261 - High (8.6)

An attacker with network-level access between the SUSE Virtualization
and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the TLS handshake and abuse it
to bypass TLS as a security control.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2024-7730
(7.4 HIGH)

EPSS: 0.29%

updated 2026-06-17T08:20:48.370000

1 posts

A heap buffer overflow was found in the virtio-snd device in QEMU. When reading input audio in the virtio-snd input callback, virtio_snd_pcm_in_cb, the function did not check whether the iov can fit the data buffer. This issue can trigger an out-of-bounds write if the size of the virtio queue element is equal to virtio_snd_pcm_status, which makes the available space for audio data zero.

EUVD_Bot@mastodon.social at 2026-06-19T18:00:36.000Z ##

🚨 EUVD-2026-38043

📊 Score: 7.4/10 (CVSS v3.1)
📅 Updated: 2026-06-19

📝 A flaw was found in QEMU. When reading input audio in the virtio-snd device input callback, the `virtio_snd_pcm_in_cb` function did not check whether the iov could fit the data buffer, potentially leading to a heap out-of-bounds write. This issue exists due to an incomplete fix for CVE-2024-7730.

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2026-12316
(9.1 CRITICAL)

EPSS: 0.24%

updated 2026-06-16T21:33:05

1 posts

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152.

thehackerwire@mastodon.social at 2026-06-17T04:00:16.000Z ##

🔴 CVE-2026-12316 - Critical (9.1)

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12314
(7.5 HIGH)

EPSS: 0.25%

updated 2026-06-16T21:33:05

1 posts

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.

thehackerwire@mastodon.social at 2026-06-17T03:00:27.000Z ##

🟠 CVE-2026-12314 - High (7.5)

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12305
(7.5 HIGH)

EPSS: 0.37%

updated 2026-06-16T21:33:04

1 posts

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.

thehackerwire@mastodon.social at 2026-06-17T05:59:49.000Z ##

🟠 CVE-2026-12305 - High (7.5)

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-50656
(7.8 HIGH)

EPSS: 0.34%

updated 2026-06-16T21:31:57

5 posts

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;RoguePlanet &quot;. We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.

1 repos

https://github.com/0xBlackash/CVE-2026-50656

maniabel@mastodon.de at 2026-06-19T19:18:12.000Z ##

Windows. Neuer Proof-of-Concept-Exploit von Chaotic Eclipse (aka Nightmare Eclipse) für
RoguePlanet ZeroDay in Defender.

Microsoft bestätigt, dass der RoguePlanet Zero-Day Microsoft Defender betrifft und als CVE-2026-50656 (CVSS-Score von 7,8) getrackt wird. Die Sicherheitslücke ermöglicht eine Rechteausweitung über die Microsoft Malware Protection Engine.

github.com/MSNightmare/RoguePl

#Microsoft #Windows #ZeroDay #infosec

##

oversecurity@mastodon.social at 2026-06-18T08:20:56.000Z ##

Windows Defender Vulnerability Exposed as RoguePlanet PoC Spreads Online

A newly disclosed Windows Defender vulnerability, tracked as CVE-2026-50656 and dubbed RoguePlanet, has raised concerns across the cybersecurity...

🔗️ [Thecyberexpress] link.is.it/k5s4I4

##

AAKL@infosec.exchange at 2026-06-17T18:01:10.000Z ##

New.

Tenable research advisories:

CRITICAL: CVE-2026-8024: iba ibaPDA / ibaDatCoordinator .NET Deserialization Remote Code Execution tenable.com/security/research/ @tenable

Cisco:

CRITICAL: CVE-2026-20181 and CVE-2026-20190: Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities

Three others of medium-severity: sec.cloudapps.cisco.com/securi @TalosSecurity

Broadcom:

Several critical and high-severity vulnerabilities. A login is needed for details support.broadcom.com/web/ecx/s

Dell:

Several advisories, one of them critical:

CRITICAL: Security Update for Dell Data Protection Central Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0

More: dell.com/support/security/en-us

Google:

Chrome Beta for iOS Update chromereleases.googleblog.com/

Yesterday:

Microsoft:

CVE-2026-50656: Microsoft Defender Elevation of Privilege Vulnerability msrc.microsoft.com/update-guid

Nvidia:

Security Bulletin addressing CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228:

NVIDIA NeMo - June 2026 nvidia.custhelp.com/app/answer #Nvidia #Dell #Cisco #infosec #vulnerability #threatresearch #Broadcom #Google #Chrome #Microsoft #Windows

##

thehackerwire@mastodon.social at 2026-06-17T02:00:23.000Z ##

🟠 CVE-2026-50656 - High (7.8)

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;RoguePlanet &quot;. We are working to provide a high quality security update that addresses this vulnera...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

nyanbinary@infosec.exchange at 2026-06-16T20:59:06.000Z ##

Nightmare Eclipses RoguePlanet now has a CVE 🎉: nvd.nist.gov/vuln/detail/cve-2

Not any new detail in there & no fix yet (has only been a week, give them some time...).

Much less relevant but annoying me personally: It taking them a week to ... sorry, shit this out. Broken description in the CVE form & even in the MSRC page it's pretty obvious no one even proofread the non-description. Also empty Acknoledgement section despite link to the Github (not the first time btw)... at least they didn't have it taken down this time? 🙃

##

CVE-2026-12003(CVSS UNKNOWN)

EPSS: 0.14%

updated 2026-06-16T21:31:56

2 posts

To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark is found relative to VPATH relative to the executable, Python assumes it is running in a source tree and generates a different default sys.path. This code remains i

canartuc@mastodon.social at 2026-06-17T17:54:30.000Z ##

Who is affected by CVE-2026-12003? Anyone running CPython on Windows across 3.11.15, 3.12.13, 3.13.14, 3.14.6, 3.15.0b2 and earlier. Jake Yamaki of Bishop Fox showed that a low-privilege user can create a path CPython checks for in-tree builds and inject malicious library folders to escalate privileges. It is rated CVSSv4 5.3. With this many affected versions, how do you even inventory every CPython on a Windows fleet?

#Python #Security

##

canartuc@mastodon.social at 2026-06-17T17:07:30.000Z ##

Jake Yamaki of Bishop Fox disclosed CVE-2026-12003 in CPython. The interpreter's VPATH variable, combined with a Modules/setup.local landmark used to locate in-tree builds, lets a low-privilege Windows user create that path outside the install directory and inject malicious library folders, escalating privileges. Rated CVSSv4 5.3, it affects 3.11.15, 3.12.13, 3.13.14, 3.14.6, 3.15.0b2 and earlier. Should build-detection logic ever survive into a release binary?

#Python #Security

##

CVE-2026-12315
(9.1 CRITICAL)

EPSS: 0.25%

updated 2026-06-16T21:31:56

1 posts

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.

thehackerwire@mastodon.social at 2026-06-17T04:00:03.000Z ##

🔴 CVE-2026-12315 - Critical (9.1)

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-10649
(8.6 HIGH)

EPSS: 0.46%

updated 2026-06-16T21:31:56

1 posts

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.

thehackerwire@mastodon.social at 2026-06-17T03:00:15.000Z ##

🟠 CVE-2026-10649 - High (8.6)

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacke...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12304
(9.1 CRITICAL)

EPSS: 0.17%

updated 2026-06-16T21:31:55

1 posts

Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.

thehackerwire@mastodon.social at 2026-06-17T05:00:22.000Z ##

🔴 CVE-2026-12304 - Critical (9.1)

Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-11832
(9.1 CRITICAL)

EPSS: 0.33%

updated 2026-06-16T18:33:40

1 posts

Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was generated using an MD5 hash of the epoch time, which is predictable.

thehackerwire@mastodon.social at 2026-06-17T07:00:22.000Z ##

🔴 CVE-2026-11832 - Critical (9.1)

Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce.

The default nonce was generated using an MD5 hash of the epoch time, which is predictable.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12087
(9.1 CRITICAL)

EPSS: 0.39%

updated 2026-06-16T18:33:40

1 posts

Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then c

thehackerwire@mastodon.social at 2026-06-17T07:00:06.000Z ##

🔴 CVE-2026-12087 - Critical (9.1)

Socket versions before 2.041 for Perl have an out-of-bounds heap read.

In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding mu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12205
(9.1 CRITICAL)

EPSS: 0.29%

updated 2026-06-16T18:33:40

1 posts

Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. Crypt::DSA::sign caches the per-signature nonce material in the Key object without ever clearing it. The first sign() on a Key object picks a nonce, and every later sign() on that same object reuses it, producing an identical "r". Keys used to sign more than once with an affected versio

thehackerwire@mastodon.social at 2026-06-17T06:59:56.000Z ##

🔴 CVE-2026-12205 - Critical (9.1)

Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery.

Crypt::DSA::sign caches the per-signature nonce material in the Key object without ever clearing it.

The first sign() on a Key object p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12161
(8.8 HIGH)

EPSS: 0.29%

updated 2026-06-16T18:33:40

1 posts

Improper input validation in the SSH Elevate Shell feature in Devolutions Remote Desktop Manager 2026.2.7 allows an authenticated user with permission to create or modify a shared SSH entry to execute arbitrary commands on a remote SSH host using stored elevation credentials via a crafted alternate username and user interaction with the Elevate Shell action.

thehackerwire@mastodon.social at 2026-06-17T06:00:09.000Z ##

🟠 CVE-2026-12161 - High (8.8)

Improper input validation in the SSH Elevate Shell feature in
Devolutions Remote Desktop Manager 2026.2.7 allows an authenticated user
with permission to create or modify a shared SSH entry to execute
arbitrary commands on a remote SSH host usi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12289
(8.8 HIGH)

EPSS: 0.32%

updated 2026-06-16T18:33:39

1 posts

Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.

thehackerwire@mastodon.social at 2026-06-16T17:00:20.000Z ##

🟠 CVE-2026-12289 - High (8.8)

Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-24228
(7.8 HIGH)

EPSS: 0.16%

updated 2026-06-16T18:32:44

3 posts

NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, data tampering, and information disclosure.

AAKL@infosec.exchange at 2026-06-17T18:01:10.000Z ##

New.

Tenable research advisories:

CRITICAL: CVE-2026-8024: iba ibaPDA / ibaDatCoordinator .NET Deserialization Remote Code Execution tenable.com/security/research/ @tenable

Cisco:

CRITICAL: CVE-2026-20181 and CVE-2026-20190: Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities

Three others of medium-severity: sec.cloudapps.cisco.com/securi @TalosSecurity

Broadcom:

Several critical and high-severity vulnerabilities. A login is needed for details support.broadcom.com/web/ecx/s

Dell:

Several advisories, one of them critical:

CRITICAL: Security Update for Dell Data Protection Central Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0

More: dell.com/support/security/en-us

Google:

Chrome Beta for iOS Update chromereleases.googleblog.com/

Yesterday:

Microsoft:

CVE-2026-50656: Microsoft Defender Elevation of Privilege Vulnerability msrc.microsoft.com/update-guid

Nvidia:

Security Bulletin addressing CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228:

NVIDIA NeMo - June 2026 nvidia.custhelp.com/app/answer #Nvidia #Dell #Cisco #infosec #vulnerability #threatresearch #Broadcom #Google #Chrome #Microsoft #Windows

##

thehackerwire@mastodon.social at 2026-06-16T19:00:15.000Z ##

🟠 CVE-2026-24228 - High (7.8)

NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, data tampering, and informatio...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

AAKL@infosec.exchange at 2026-06-16T15:46:34.000Z ##

Nvidia has a new advisory relating to CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228, all high-severity:

Security Bulletin: NVIDIA NeMo - June 2026 nvidia.custhelp.com/app/answer #Nvidia

Broadcom:

Seven advisories addressing one critical vulnerability and several high-severity flaws: You'll need a login for details.

CRITICAL: MICS 14.3, 14.4, and 14.5 Vulnerabilities

More: support.broadcom.com/web/ecx/s #Broadcom

Yesterday:

Google:

Chrome Dev for Desktop Update chromereleases.googleblog.com/ #Google #Chrome

Dell:

Update for a critical vulnerability yesterday that encompasses multiple CVEs:

Security Update for Dell PowerProtect DP Series Appliance (IDPA) Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #infosec #vulnerability

##

CVE-2026-44932
(8.8 HIGH)

EPSS: 0.49%

updated 2026-06-16T18:32:44

1 posts

Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious DHCP server to execute code on the local machine.

thehackerwire@mastodon.social at 2026-06-16T18:00:34.000Z ##

🟠 CVE-2026-44932 - High (8.8)

Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious DHCP server to execute code on the local machine.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12328
(8.1 HIGH)

EPSS: 0.30%

updated 2026-06-16T18:32:38

1 posts

Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.

thehackerwire@mastodon.social at 2026-06-16T17:00:11.000Z ##

🟠 CVE-2026-12328 - High (8.1)

Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-68045
(7.5 HIGH)

EPSS: 0.23%

updated 2026-06-16T12:32:07

1 posts

Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.

thehackerwire@mastodon.social at 2026-06-16T17:00:33.000Z ##

🟠 CVE-2025-68045 - High (7.5)

Unauthenticated Broken Access Control in WP Event SOlution &lt;= 4.1.12 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8444
(8.8 HIGH)

EPSS: 0.25%

updated 2026-06-16T09:32:42

1 posts

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpfb_find_reviews AJAX action in versions up to, and including, 12.6.8. This is due to the handler reading $_POST['curselrevs'] raw with no sanitization or type casting, then concatenating each array element directly into a `WHERE id IN ( ... )` clause without quoting and executing

thehackerwire@mastodon.social at 2026-06-17T05:59:59.000Z ##

🟠 CVE-2026-8444 - High (8.8)

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpfb_find_reviews AJAX action in versions up to, and including, 12.6.8. This is due to the handler reading $_POST['curselrevs'] ra...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49109
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-06-15T21:30:58

1 posts

Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 versions.

thehackerwire@mastodon.social at 2026-06-17T10:00:04.000Z ##

🔴 CVE-2026-49109 - Critical (9.8)

Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms &lt;= 1.4.3 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49085
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-06-15T21:30:58

1 posts

Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.

1 repos

https://github.com/izxci/CVE-2026-49085

thehackerwire@mastodon.social at 2026-06-17T07:59:55.000Z ##

🔴 CVE-2026-49085 - Critical (9.8)

Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms &lt;= 1.1.4 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-55649
(5.5 MEDIUM)

EPSS: 0.19%

updated 2026-06-15T21:30:42

1 posts

A NULL pointer dereference in the gf_media_map_esd function (media_tools/isom_tools.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

sigdevel@infosec.exchange at 2026-06-18T03:26:49.000Z ##

@iamleot Of course, requests to add links were sent in the follow-up email regarding the publication. I noticed that the original links were missing for some CVE entries, but my process hasn't changed recently.
full-context:
cve.org/CVERecord?id=CVE-2025-
truncated:
cve.org/CVERecord?id=CVE-2025-

##

CVE-2026-35273
(9.8 CRITICAL)

EPSS: 7.51%

updated 2026-06-12T18:31:50

2 posts

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of Peopl

Nuclei template

3 repos

https://github.com/HORKimhab/CVE-2026-35273

https://github.com/0xBlackash/CVE-2026-35273

https://github.com/ekomsSavior/POC_cve_2026_35273

beyondmachines1@infosec.exchange at 2026-06-18T10:01:46.000Z ##

Oracle Patches 245 Vulnerabilities Including Actively Exploited PeopleSoft Zero-Day

Oracle's June 2026 monthly Critical Security Patch Update delivers 245 patches across eleven product families, roughly 120 rated critical including eleven maximum-severity (CVSS 10.0) remotely exploitable unauthenticated flaws concentrated in Fusion Middleware (Coherence, WebCenter, WebLogic) plus Solaris, alongside the fix for a PeopleSoft code-injection vulnerability (CVE-2026-35273) that's reportedly exploited in the wild.

**If you are using Oracle products, review the advisory in detail. Prioritize the maximum-severity (CVSS 10.0) flaws in Fusion Middleware products like Coherence, WebCenter, and WebLogic, since these can be exploited remotely without any login. Pay urgent attention to the PeopleSoft fix (CVE-2026-35273), as attackers are already actively breaking into organizations. Use isolation from the internet and reduced user privileges only as a temporary fix until you can fully patch.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

PC_Fluesterer@social.tchncs.de at 2026-06-16T17:18:43.000Z ##

Europarat gehackt – dank Oracle.

Die Besetzungsliste: ShinyHunters, Oracle, der Europarat. Die Handlung: Vor mehr als zwanzig Jahren hat Oracle* nach einer wahren Übernahmeschlacht die Firma PeopleSoft geschluckt. Deren Software wird vor allem in den USA eingesetzt, aber eben auch im Europarat. Die Software enthielt eine Zero-Day Sicherheitslücke CVE-2026-35273, die von ShinyHunters ausgenutzt wurde. Die Hackergruppe will darüber mehr als 100 Institutionen gehackt haben, darunter den Europarat. Dabei seien fast 300 GByte an Daten in die Hände der Erpresser gefallen, darunter Personalakten, Gehaltsabrechnungen, Einkäufe; Lebensläufe, Gehälter,

pc-fluesterer.info/wordpress/2

#0day #closedsource #cybercrime #datenleck #datenschutz #exploits #sicherheit #UnplugOracle #UnplugTrump #zeroday

##

CVE-2026-25089
(9.8 CRITICAL)

EPSS: 2.66%

updated 2026-06-09T18:30:47

1 posts

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP req

2 repos

https://github.com/0xBlackash/CVE-2026-25089

https://github.com/HORKimhab/CVE-2026-25089

threatnoir@infosec.exchange at 2026-06-16T18:06:05.000Z ##

⚠️ CRITICAL: Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week

Fortinet FortiSandbox is under active exploitation for three critical unauthenticated RCE vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089). All three bypass authentication and allow arbitrary command execution via HTTP requests. Organizations running FortiSandbox are at immediate ri…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-8206
(9.8 CRITICAL)

EPSS: 0.62%

updated 2026-06-02T06:30:33

2 posts

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. This makes it possible for unauthenticated attackers to send a password reset link for any user registered

3 repos

https://github.com/rootdirective-sec/CVE-2026-8206-Lab

https://github.com/Jenderal92/CVE-2026-8206

https://github.com/izxci/CVE-2026-8206

mstankiewicz@mastodon.com.pl at 2026-06-19T06:40:15.000Z ##

🚨 KTRYTYCZNA PODSTNOŚĆ WE WTYCZCE #WORDPRESS!
Jak podaje #Sekurak, we wtyczce #Kirki wykryto lukę, pozwalającą na przejęcie dowolnego konta, w tym administratora.
Jeśli masz to rozszerzenie, zaktualizuj je natychmiast do najnowszej wersji!

CVE-2026-8206
CVSS: 9.8

sekurak.pl/blad-w-popularnej-w

##

sekurakbot@mastodon.com.pl at 2026-06-16T17:25:00.000Z ##

Błąd w popularnej wtyczce do WordPressa pozwala na przejęcie konta administratora (CVE-2026-8206 – Kirki)

WordPress to niewątpliwie najpopularniejszy na świecie system do zarządzania treścią (CMS) typu open source. Pozwala na łatwe tworzenie i zarządzanie stronami internetowymi bez konieczności znajomości programowania. O ile krytyczne błędy w samym silniku zdarzają się niezwykle rzadko, o tyle platforma wspiera wiele zewnętrznych pluginów, co zwiększa płaszczyznę ataku. TLDR: Tym...

#WBiegu #BugBounty #Cve #Php #Plugin #Wordpress

sekurak.pl/blad-w-popularnej-w

##

CVE-2025-60485
(5.5 MEDIUM)

EPSS: 0.17%

updated 2026-06-02T00:31:54

1 posts

A segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/isom_write.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

sigdevel@infosec.exchange at 2026-06-18T03:26:49.000Z ##

@iamleot Of course, requests to add links were sent in the follow-up email regarding the publication. I noticed that the original links were missing for some CVE entries, but my process hasn't changed recently.
full-context:
cve.org/CVERecord?id=CVE-2025-
truncated:
cve.org/CVERecord?id=CVE-2025-

##

CVE-2026-47717
(7.5 HIGH)

EPSS: 0.00%

updated 2026-05-27T22:51:19

2 posts

### Summary The GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. ### Details File: `server/api/projects/index.js` ```javascript prjApp.get("/api/project", secureFnc, function(req, res) { const permission = checkGroupsFnc(req); runtime.project.getProject(req.userId, permission).then(result => { i

Nuclei template

halildeniz@mastodon.social at 2026-06-19T18:55:00.000Z ##

🚨 CVE-2026-47717: Dive into my deep technical analysis of the FUXA SCADA API logic flaw that allows unauthenticated attackers to leak critical project configurations and operational data.

Read the full analysis here: 👇 denizhalil.com/2026/06/19/cve-

#SCADA #infosec

##

halildeniz@mastodon.social at 2026-06-19T18:55:00.000Z ##

🚨 CVE-2026-47717: Dive into my deep technical analysis of the FUXA SCADA API logic flaw that allows unauthenticated attackers to leak critical project configurations and operational data.

Read the full analysis here: 👇 denizhalil.com/2026/06/19/cve-

#SCADA #infosec

##

CVE-2026-42089
(8.6 HIGH)

EPSS: 0.19%

updated 2026-05-26T23:10:40

1 posts

### Impact `yeoman-environment` versions `>= 2.9.0` and `< 6.0.1` install missing local generator packages from caller-supplied package names without user confirmation. In downstream consumers that pass attacker-controlled project configuration into this path, this can result in arbitrary package installation and code execution during CLI bootstrap. The vulnerable method is `installLocalGenerato

thehackerwire@mastodon.social at 2026-06-16T18:00:23.000Z ##

🟠 CVE-2026-42089 - High (8.6)

Yeoman Environment provides an API to discover, create, and run generators, and to configure where and how a generator is resolved. Versions 2.9.0 through 6.0.0 install missing local generator packages from caller-supplied package names without us...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-42069(CVSS UNKNOWN)

EPSS: 0.23%

updated 2026-05-13T13:38:50

1 posts

### TL;DR This vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. **This vulnerability is of high severity for affected sites.** Sites using Kirby are *not* affected if they intend all users of the site to be able to list and access the site model and all users and roles, including the content stored within these models. Write ac

nyanbinary@infosec.exchange at 2026-06-18T12:28:29.000Z ##

the moment you visit cve.org you are loading 1.xMB of data. This includes everything except binary data (images etc) and CVE data itself.

You wanna learn more about the board? the DOM is built from that one script & populated from a json blob in that script. Well, a string which is then decoded

Wanna look up the contact method for NVIDIAs CNA? Every website on the path to get there is built from that script & already contained in that script as a json blob.

Want to know the geometry of Antarctica? You bet there is a couple of polygons in that script! (I don't know where they are used).

Every linked youtube video that explains something? It's in there!!

Or in other words: You are downloading 1.xMB of data (uncompressed: 4MB) that is probably not very cacheable data past the current session & of which you probably aren't gonna use much of anyway - you just clicked a link to see whats up with CVE-2026-42069 & now you downloaded 400kB of CNA data!

##

CVE-2026-41175
(8.1 HIGH)

EPSS: 0.30%

updated 2026-04-24T20:52:07

1 posts

### Impact Manipulating query parameters on Control Panel and REST API endpoints, or arguments in GraphQL queries, could result in the loss of content, assets, and user accounts. The Control Panel requires authentication with minimal permissions in order to exploit. e.g. "view entries" permission to delete entries, or "view users" permission to delete users, etc. The REST and GraphQL API exploi

EUVD_Bot@mastodon.social at 2026-06-19T19:00:13.000Z ##

🚨 EUVD-2026-38057

📊 Score: 7.4/10 (CVSS v3.1)
📦 Product: CMS, CMS
🏢 Vendor: statamic
📅 Updated: 2026-06-19

📝 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, the fix for CVE-2026-41175 was incomplete. It addressed the issue in the query builder, but the same protection was not applied to in-memory collection sort...

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2026-39808
(9.8 CRITICAL)

EPSS: 66.17%

updated 2026-04-22T15:32:37

1 posts

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

Nuclei template

6 repos

https://github.com/samu-delucas/CVE-2026-39808

https://github.com/error-inside/CVE-2026-39808

https://github.com/ynsmroztas/FortiSandbox-RCE-Exploit-CVE-2026-39808

https://github.com/0xBlackash/CVE-2026-39808

https://github.com/Lechansky/CVE-2026-39808

https://github.com/HORKimhab/CVE-2026-39808

threatnoir@infosec.exchange at 2026-06-16T18:06:05.000Z ##

⚠️ CRITICAL: Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week

Fortinet FortiSandbox is under active exploitation for three critical unauthenticated RCE vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089). All three bypass authentication and allow arbitrary command execution via HTTP requests. Organizations running FortiSandbox are at immediate ri…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-39813
(9.8 CRITICAL)

EPSS: 18.70%

updated 2026-04-14T18:30:41

1 posts

A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via <insert attack vector here>

2 repos

https://github.com/0xBlackash/CVE-2026-39813

https://github.com/HORKimhab/CVE-2026-39813

threatnoir@infosec.exchange at 2026-06-16T18:06:05.000Z ##

⚠️ CRITICAL: Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week

Fortinet FortiSandbox is under active exploitation for three critical unauthenticated RCE vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089). All three bypass authentication and allow arbitrary command execution via HTTP requests. Organizations running FortiSandbox are at immediate ri…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2025-20701
(8.8 HIGH)

EPSS: 3.40%

updated 2025-08-04T21:31:49

2 posts

In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

beyondmachines1 at 2026-06-20T11:01:35.778Z ##

Apple Patches Beats Studio Buds Eavesdropping Flaw

Apple patched a high-severity flaw (CVE-2025-20701) in Beats Studio Buds that allowed nearby attackers to eavesdrop via the microphone.

**Update your Beats Studio Buds firmware immediately to version 1B211 to prevent unauthorized microphone access.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-06-20T11:01:35.000Z ##

Apple Patches Beats Studio Buds Eavesdropping Flaw

Apple patched a high-severity flaw (CVE-2025-20701) in Beats Studio Buds that allowed nearby attackers to eavesdrop via the microphone.

**Update your Beats Studio Buds firmware immediately to version 1B211 to prevent unauthorized microphone access.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-9142
(0 None)

EPSS: 0.00%

3 posts

N/A

offseq at 2026-06-20T07:30:30.876Z ##

NI grpc-device ≤2.17.0 hit by CRITICAL vuln (CVE-2026-9142, CVSS 9.1) 🛡️ Missing authentication when TLS isn't set & server exposed beyond loopback. Unauthenticated LAN access possible. Mitigate by enabling TLS & restricting binding. radar.offseq.com/threat/cve-20

##

hugovalters@mastodon.social at 2026-06-19T17:00:54.000Z ##

CVE-2026-9142 - Critical RCE in Ni grpc-device. Insecure default credentials allow unauthenticated network access. CVSS 9.1. Update immediately. #CVE #infosec #cybersecurity

valtersit.com/cve/CVE-2026-914

##

offseq@infosec.exchange at 2026-06-20T07:30:30.000Z ##

NI grpc-device ≤2.17.0 hit by CRITICAL vuln (CVE-2026-9142, CVSS 9.1) 🛡️ Missing authentication when TLS isn't set & server exposed beyond loopback. Unauthenticated LAN access possible. Mitigate by enabling TLS & restricting binding. radar.offseq.com/threat/cve-20 #OffSeq #NI #Vuln

##

CVE-2026-48773
(0 None)

EPSS: 0.00%

2 posts

N/A

offseq at 2026-06-20T06:00:22.988Z ##

ProxySQL (2.0.18 – 3.0.8) hit by CRITICAL CVE-2026-48773: pre-auth heap memory corruption (CWE-787) allows remote unauthenticated attackers to trigger out-of-bounds write. Upgrade to 3.0.9 ASAP. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-06-20T06:00:22.000Z ##

ProxySQL (2.0.18 – 3.0.8) hit by CRITICAL CVE-2026-48773: pre-auth heap memory corruption (CWE-787) allows remote unauthenticated attackers to trigger out-of-bounds write. Upgrade to 3.0.9 ASAP. radar.offseq.com/threat/cve-20 #OffSeq #ProxySQL #CVE202648773 #infosec

##

CVE-2026-47846
(0 None)

EPSS: 0.00%

2 posts

N/A

hugovalters@mastodon.social at 2026-06-20T05:05:17.000Z ##

CVE-2026-47846 - Critical supply chain attack in Bitnami Cassandra containers. Default superuser cassandra:cassandra retained after custom admin setup. CVSS 9.8. Update all affected images immediately. #CVE #Bitnami #infosec

valtersit.com/cve/CVE-2026-478

##

offseq@infosec.exchange at 2026-06-18T20:00:13.000Z ##

Bitnami Cassandra container images (4.0.0, 4.1.0, 5.0.0) have a CRITICAL flaw (CVE-2026-47846): default cassandra:cassandra superuser may remain after custom admin setup. Update urgently! radar.offseq.com/threat/cve-20 #OffSeq #Cassandra #Vuln #CloudSecurity

##

CVE-2025-60467
(0 None)

EPSS: 0.00%

4 posts

N/A

sigdevel at 2026-06-20T04:41:57.256Z ##

Security Advisory: CVE-2025-60467 - Use-After-Free in GPAC MP4Box Filter PID Cleanup

A use-after-free vulnerability exists in GPAC MP4Box when processing a crafted MPEG-2 TS/MP4 file. The issue is triggered during filter teardown in `gf_filter_pid_inst_swap_delete_task()` and can cause MP4Box to crash.

Summary:
AddressSanitizer confirms a heap-use-after-free in `filter_core/filter_pid.c:580`, where code reads from a PID instance object after it has already been freed during swap/delete cleanup.
The crafted file contains malformed MPEG-2 TS structures, including broken PMT descriptors and invalid PID metadata. While MP4Box processes the file with `-info`, the filter core performs PID instance cleanup. During this cleanup path, a PID instance is freed and later accessed again by `gf_filter_pid_inst_swap_delete_task()`.

CWE:
CWE-416 - Use After Free

Affected Component:
```
filter_core/filter_pid.c:580
Function: gf_filter_pid_inst_swap_delete_task()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
```
2.5-DEV-rev1593-gfe88c3545-master
Commit: fe88c3545aadd597b250ccf23271d5d3de50ccc8
```

Attack Conditions:
An attacker supplies a crafted input file that is processed by MP4Box. The issue can be reproduced locally with:
```
./MP4Box -info 39_gf_filter_pid_inst_swap_delete_task_filter_core_filter_pid_c_580
```

The prepared CVSS vector:
```
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
```

Impact:
denial of service via application crash; local triage notes also identify potential arbitrary code execution risk

Fix / mitigation status:
Users should update to a fixed GPAC release or apply the vendor-confirmed patch. Verify the final vendor fix commit before public release if the advisory is published independently.

References:

- Issue: github.com/gpac/gpac/issues/32
- Fix: github.com/gpac/gpac/commit/ae
- PoC: github.com/sigdevel/pocs/blob/
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

##

sigdevel at 2026-06-20T04:21:31.924Z ##

Security Advisory: CVE-2025-60467 - Use-After-Free in GPAC MP4Box PID Swap Delete Task

Processing a crafted media file with MP4Box `-info` can trigger a heap use-after-free in `gf_filter_pid_inst_swap_delete_task()`, causing a crash and potential code execution.

Summary:
The `gf_filter_pid_inst_swap_delete_task()` function in `filter_core/filter_pid.c` can access a `GF_FilterPidInstance` object after it has already been freed by `gf_filter_pid_inst_swap_delete()`. Crafted input that exercises filter reconfiguration and deferred teardown paths can cause the scheduler to process a delete task with a stale pointer.

AddressSanitizer reports a `heap-use-after-free` at `filter_core/filter_pid.c:574`, with a `READ of size 4` from a previously freed 336-byte heap region.

CWE:
CWE-416 - Use After Free

Affected Component:
```
filter_core/filter_pid.c:574
Function: gf_filter_pid_inst_swap_delete_task()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
The issue was reproduced on:
```
GPAC version: 2.5-DEV-rev1570-g6208015df-master
Commit: 6208015dff3a6735a26e413c484c714666eb3ea2
```

The MITRE response states that GPAC Project/MP4Box before `26.02.0` is affected. Builds before the fix commit `976dacf65cb6986a4e4f350fb8d3ed0a17dc3a77` should be considered affected if they contain the vulnerable deferred PID swap delete task path.

Attack Conditions:
An attacker supplies a crafted media file or filter graph input that is processed by MP4Box through the info/import path and triggers PID reconfiguration and deferred teardown. The issue can be reproduced locally with:
```
./MP4Box -info 37_gf_filter_pid_inst_swap_delete_task_filter_core_filter_pid_c_574
```

No elevated privileges are required. User interaction is required when the victim manually processes the malicious file, or an automated media workflow invokes MP4Box on attacker-controlled input.

The prepared CVSS vector:
```
AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
```

Impact:
The immediate observed impact is Denial of Service due to process termination. Because the vulnerability is a heap use-after-free, memory corruption and potential arbitrary code execution are possible.

Fix / mitigation status:
The issue was fixed in GPAC commit:
```
976dacf65cb6986a4e4f350fb8d3ed0a17dc3a77
```

Users should update to a GPAC build containing this commit or later. The affected deferred task path should ensure that `GF_FilterPidInstance` lifetime remains valid before a scheduled delete task accesses it.

References:

- Issue: github.com/gpac/gpac/issues/32
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/97
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

##

sigdevel@infosec.exchange at 2026-06-20T04:41:57.000Z ##

Security Advisory: CVE-2025-60467 - Use-After-Free in GPAC MP4Box Filter PID Cleanup

A use-after-free vulnerability exists in GPAC MP4Box when processing a crafted MPEG-2 TS/MP4 file. The issue is triggered during filter teardown in `gf_filter_pid_inst_swap_delete_task()` and can cause MP4Box to crash.

Summary:
AddressSanitizer confirms a heap-use-after-free in `filter_core/filter_pid.c:580`, where code reads from a PID instance object after it has already been freed during swap/delete cleanup.
The crafted file contains malformed MPEG-2 TS structures, including broken PMT descriptors and invalid PID metadata. While MP4Box processes the file with `-info`, the filter core performs PID instance cleanup. During this cleanup path, a PID instance is freed and later accessed again by `gf_filter_pid_inst_swap_delete_task()`.

CWE:
CWE-416 - Use After Free

Affected Component:
```
filter_core/filter_pid.c:580
Function: gf_filter_pid_inst_swap_delete_task()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
```
2.5-DEV-rev1593-gfe88c3545-master
Commit: fe88c3545aadd597b250ccf23271d5d3de50ccc8
```

Attack Conditions:
An attacker supplies a crafted input file that is processed by MP4Box. The issue can be reproduced locally with:
```
./MP4Box -info 39_gf_filter_pid_inst_swap_delete_task_filter_core_filter_pid_c_580
```

The prepared CVSS vector:
```
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
```

Impact:
denial of service via application crash; local triage notes also identify potential arbitrary code execution risk

Fix / mitigation status:
Users should update to a fixed GPAC release or apply the vendor-confirmed patch. Verify the final vendor fix commit before public release if the advisory is published independently.

References:

- Issue: github.com/gpac/gpac/issues/32
- Fix: github.com/gpac/gpac/commit/ae
- PoC: github.com/sigdevel/pocs/blob/
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

#fuzzing #infosec #security #aflplusplus #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory #media #gpac

##

sigdevel@infosec.exchange at 2026-06-20T04:21:31.000Z ##

Security Advisory: CVE-2025-60467 - Use-After-Free in GPAC MP4Box PID Swap Delete Task

Processing a crafted media file with MP4Box `-info` can trigger a heap use-after-free in `gf_filter_pid_inst_swap_delete_task()`, causing a crash and potential code execution.

Summary:
The `gf_filter_pid_inst_swap_delete_task()` function in `filter_core/filter_pid.c` can access a `GF_FilterPidInstance` object after it has already been freed by `gf_filter_pid_inst_swap_delete()`. Crafted input that exercises filter reconfiguration and deferred teardown paths can cause the scheduler to process a delete task with a stale pointer.

AddressSanitizer reports a `heap-use-after-free` at `filter_core/filter_pid.c:574`, with a `READ of size 4` from a previously freed 336-byte heap region.

CWE:
CWE-416 - Use After Free

Affected Component:
```
filter_core/filter_pid.c:574
Function: gf_filter_pid_inst_swap_delete_task()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
The issue was reproduced on:
```
GPAC version: 2.5-DEV-rev1570-g6208015df-master
Commit: 6208015dff3a6735a26e413c484c714666eb3ea2
```

The MITRE response states that GPAC Project/MP4Box before `26.02.0` is affected. Builds before the fix commit `976dacf65cb6986a4e4f350fb8d3ed0a17dc3a77` should be considered affected if they contain the vulnerable deferred PID swap delete task path.

Attack Conditions:
An attacker supplies a crafted media file or filter graph input that is processed by MP4Box through the info/import path and triggers PID reconfiguration and deferred teardown. The issue can be reproduced locally with:
```
./MP4Box -info 37_gf_filter_pid_inst_swap_delete_task_filter_core_filter_pid_c_574
```

No elevated privileges are required. User interaction is required when the victim manually processes the malicious file, or an automated media workflow invokes MP4Box on attacker-controlled input.

The prepared CVSS vector:
```
AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
```

Impact:
The immediate observed impact is Denial of Service due to process termination. Because the vulnerability is a heap use-after-free, memory corruption and potential arbitrary code execution are possible.

Fix / mitigation status:
The issue was fixed in GPAC commit:
```
976dacf65cb6986a4e4f350fb8d3ed0a17dc3a77
```

Users should update to a GPAC build containing this commit or later. The affected deferred task path should ensure that `GF_FilterPidInstance` lifetime remains valid before a scheduled delete task accesses it.

References:

- Issue: github.com/gpac/gpac/issues/32
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/97
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

#fuzzing #infosec #security #aflplusplus #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory #media #gpac

##

CVE-2025-60474
(0 None)

EPSS: 0.00%

2 posts

N/A

sigdevel at 2026-06-20T04:33:55.408Z ##

Security Advisory: CVE-2025-60474 - Heap Buffer Overflow in GPAC MP4Box Media Import

A heap buffer overflow vulnerability exists in GPAC MP4Box when processing a crafted media file with the `-info` option. The issue occurs in `gf_media_import()` in `media_tools/media_import.c` and can be triggered by supplying a malformed input file to MP4Box.

Summary:
AddressSanitizer confirms an out-of-bounds read at `media_tools/media_import.c:1297`. The vulnerable code reads 1 byte at offset `[1]` from a 1-byte heap buffer allocated from an empty string via `strdup("")`, where only offset `[0]` is valid.
The crafted input reaches MP4Box media import handling and causes `gf_media_import()` to access memory immediately after a 1-byte heap allocation. The allocation originates from property handling for an empty string and is later read out of bounds during media import processing.

CWE:
CWE-122 - Heap-based Buffer Overflow

Affected Component:
```
media_tools/media_import.c:1297
Function: gf_media_import()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
```
2.5-DEV-rev1570-g6208015df-master
Commit: 6208015dff3a6735a26e413c484c714666eb3ea2
```

Attack Conditions:
An attacker supplies a crafted input file that is processed by MP4Box. The issue can be reproduced locally with:
```
./MP4Box -info 38_gf_media_import_media_tools_media_import_c_1297
```

The prepared CVSS vector:
```
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
```

Impact:
denial of service via application crash; local triage notes also identify potential code execution risk

Fix / mitigation status:
The issue was fixed in GPAC commit:
```
bd7fd6be546e0cd9e599c6b262c338c5f2ecec5c
```
Users should update to a GPAC build containing this commit or later.

References:
- Issue: github.com/gpac/gpac/issues/32
- Fix: github.com/gpac/gpac/commit/bd
- PoC: github.com/sigdevel/pocs/blob/
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

##

sigdevel@infosec.exchange at 2026-06-20T04:33:55.000Z ##

Security Advisory: CVE-2025-60474 - Heap Buffer Overflow in GPAC MP4Box Media Import

A heap buffer overflow vulnerability exists in GPAC MP4Box when processing a crafted media file with the `-info` option. The issue occurs in `gf_media_import()` in `media_tools/media_import.c` and can be triggered by supplying a malformed input file to MP4Box.

Summary:
AddressSanitizer confirms an out-of-bounds read at `media_tools/media_import.c:1297`. The vulnerable code reads 1 byte at offset `[1]` from a 1-byte heap buffer allocated from an empty string via `strdup("")`, where only offset `[0]` is valid.
The crafted input reaches MP4Box media import handling and causes `gf_media_import()` to access memory immediately after a 1-byte heap allocation. The allocation originates from property handling for an empty string and is later read out of bounds during media import processing.

CWE:
CWE-122 - Heap-based Buffer Overflow

Affected Component:
```
media_tools/media_import.c:1297
Function: gf_media_import()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
```
2.5-DEV-rev1570-g6208015df-master
Commit: 6208015dff3a6735a26e413c484c714666eb3ea2
```

Attack Conditions:
An attacker supplies a crafted input file that is processed by MP4Box. The issue can be reproduced locally with:
```
./MP4Box -info 38_gf_media_import_media_tools_media_import_c_1297
```

The prepared CVSS vector:
```
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
```

Impact:
denial of service via application crash; local triage notes also identify potential code execution risk

Fix / mitigation status:
The issue was fixed in GPAC commit:
```
bd7fd6be546e0cd9e599c6b262c338c5f2ecec5c
```
Users should update to a GPAC build containing this commit or later.

References:
- Issue: github.com/gpac/gpac/issues/32
- Fix: github.com/gpac/gpac/commit/bd
- PoC: github.com/sigdevel/pocs/blob/
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

#fuzzing #infosec #security #aflplusplus #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory #media #gpac

##

CVE-2026-48772
(0 None)

EPSS: 0.00%

2 posts

N/A

offseq at 2026-06-20T04:30:25.911Z ##

CVE-2026-48772 (CRITICAL): ProxySQL 2.0.0 – 3.0.8 lets attackers spoof source IPs via PROXY protocol v1, bypassing routing & ACLs. Upgrade to 3.0.9 or later. Restrict frontend port access. Details: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-06-20T04:30:25.000Z ##

CVE-2026-48772 (CRITICAL): ProxySQL 2.0.0 – 3.0.8 lets attackers spoof source IPs via PROXY protocol v1, bypassing routing & ACLs. Upgrade to 3.0.9 or later. Restrict frontend port access. Details: radar.offseq.com/threat/cve-20 #OffSeq #ProxySQL #CVE202648772 #Security

##

CVE-2025-60473
(0 None)

EPSS: 0.00%

2 posts

N/A

sigdevel at 2026-06-20T04:09:34.521Z ##

Security Advisory: CVE-2025-60473 - NULL Pointer Dereference in GPAC MP4Box Filter Parent Chain

Processing a crafted media file with MP4Box `-info` can trigger a NULL pointer dereference in `gf_filter_in_parent_chain()`, causing a Denial of Service.

Summary:
The `gf_filter_in_parent_chain()` function in `filter_core/filter_pid.c` does not sufficiently validate a parent filter pointer before dereferencing it. When MP4Box processes a specially crafted media file with malformed MPEG-2 TS data and a corrupted PID/filter chain, the vulnerable path can attempt to read from address `0x000000000008`.

CWE:
CWE-476 - NULL Pointer Dereference

Affected Component:
```
filter_core/filter_pid.c:2145
Function: gf_filter_in_parent_chain()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
The issue was reproduced on:
```
GPAC version: 2.5-DEV-rev1570-g6208015df-master
Commit: 6208015dff3a6735a26e413c484c714666eb3ea2
```

The MITRE response states that GPAC Project/MP4Box before `26.02.0` is affected. Builds before the fix commit `b8d80b44718de10b101e1d7fc17c84d69feb092e` should be considered affected if they contain the vulnerable filter parent-chain validation path.

Attack Conditions:
An attacker supplies a crafted media file with malformed MPEG-2 TS packet data and a corrupted PID/filter chain. The issue can be reproduced locally with:
```
./MP4Box -info 36_gf_filter_in_parent_chain_filter_core_filter_pid_c_2145
```

No elevated privileges are required. User interaction is required when the victim manually processes the malicious file, or an automated media workflow invokes MP4Box on attacker-controlled input.

The prepared CVSS vector:
```
AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
```

Impact:
The immediate observed impact is Denial of Service due to process termination. The local MITRE/BDU data also notes potential arbitrary code execution, although the available ASAN evidence shows a NULL pointer dereference crash.

Fix / mitigation status:
The issue was fixed in GPAC commit:
```
b8d80b44718de10b101e1d7fc17c84d69feb092e
```

Users should update to a GPAC build containing this commit or later. The affected filter graph code should validate parent filter pointers before dereferencing them during PID initialization.

References:

- Issue: github.com/gpac/gpac/issues/32
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/b8
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

##

sigdevel@infosec.exchange at 2026-06-20T04:09:34.000Z ##

Security Advisory: CVE-2025-60473 - NULL Pointer Dereference in GPAC MP4Box Filter Parent Chain

Processing a crafted media file with MP4Box `-info` can trigger a NULL pointer dereference in `gf_filter_in_parent_chain()`, causing a Denial of Service.

Summary:
The `gf_filter_in_parent_chain()` function in `filter_core/filter_pid.c` does not sufficiently validate a parent filter pointer before dereferencing it. When MP4Box processes a specially crafted media file with malformed MPEG-2 TS data and a corrupted PID/filter chain, the vulnerable path can attempt to read from address `0x000000000008`.

CWE:
CWE-476 - NULL Pointer Dereference

Affected Component:
```
filter_core/filter_pid.c:2145
Function: gf_filter_in_parent_chain()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
The issue was reproduced on:
```
GPAC version: 2.5-DEV-rev1570-g6208015df-master
Commit: 6208015dff3a6735a26e413c484c714666eb3ea2
```

The MITRE response states that GPAC Project/MP4Box before `26.02.0` is affected. Builds before the fix commit `b8d80b44718de10b101e1d7fc17c84d69feb092e` should be considered affected if they contain the vulnerable filter parent-chain validation path.

Attack Conditions:
An attacker supplies a crafted media file with malformed MPEG-2 TS packet data and a corrupted PID/filter chain. The issue can be reproduced locally with:
```
./MP4Box -info 36_gf_filter_in_parent_chain_filter_core_filter_pid_c_2145
```

No elevated privileges are required. User interaction is required when the victim manually processes the malicious file, or an automated media workflow invokes MP4Box on attacker-controlled input.

The prepared CVSS vector:
```
AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
```

Impact:
The immediate observed impact is Denial of Service due to process termination. The local MITRE/BDU data also notes potential arbitrary code execution, although the available ASAN evidence shows a NULL pointer dereference crash.

Fix / mitigation status:
The issue was fixed in GPAC commit:
```
b8d80b44718de10b101e1d7fc17c84d69feb092e
```

Users should update to a GPAC build containing this commit or later. The affected filter graph code should validate parent filter pointers before dereferencing them during PID initialization.

References:

- Issue: github.com/gpac/gpac/issues/32
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/b8
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

#fuzzing #infosec #security #aflplusplus #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory #media #gpac

##

CVE-2025-60466
(0 None)

EPSS: 0.00%

2 posts

N/A

sigdevel at 2026-06-20T03:52:04.572Z ##

Security Advisory: CVE-2025-60466 - Expired Pointer Dereference in GPAC MP4Box Packet Retrieval

Processing a crafted media file with MP4Box `-info` can trigger an expired pointer dereference in `gf_filter_pid_get_packet()`, causing a heap use-after-free crash and potential code execution.

Summary:
The `gf_filter_pid_get_packet()` function in `filter_core/filter_pid.c` may operate on an invalidated Packet ID (PID) object after it has been freed by `gf_filter_pid_del()`. When MP4Box processes a specially crafted media file through the filter graph, the `inspect` filter can request packets from a stale PID object, leading to access to freed heap memory.

CWE:
CWE-825 - Expired Pointer Dereference

Affected Component:
```
filter_core/filter_pid.c:6827
Function: gf_filter_pid_get_packet()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
The issue was reproduced on:
```
GPAC version: 2.5-DEV-rev1570-g6208015df-master
Commit: 6208015dff3a6735a26e413c484c714666eb3ea2
```

The MITRE response states that GPAC Project/MP4Box before `26.02.0` is affected. Builds before the fix commit `4a7ea06dd1b2cc65fe0dabc60189eb6bc814f7bb` should be considered affected if they contain the vulnerable PID packet retrieval path.

Attack Conditions:
An attacker supplies a crafted media file that is processed by MP4Box through the info/import path and drives the inspect/filter pipeline through PID deletion and packet retrieval paths. The issue can be reproduced locally with:

```
./MP4Box -info 35_gf_filter_pid_get_packet_filter_core_filter_pid_c_6827
```
No elevated privileges are required. User interaction is required when the victim manually processes the malicious file, or an automated media workflow invokes MP4Box on attacker-controlled input.

The prepared CVSS vector in the local BDU data is:
```
AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
```

Impact:
The immediate observed impact is Denial of Service due to process termination. Because the vulnerability is a heap use-after-free / expired pointer dereference, memory corruption and potential arbitrary code execution are possible.

Fix / mitigation status:
The issue was fixed in GPAC commit:
```
4a7ea06dd1b2cc65fe0dabc60189eb6bc814f7bb
```

Users should update to a GPAC build containing this commit or later. The fix adds checks to ignore tasks when PID or filter objects have been removed or finalized, preventing stale object use.

References:

- Issue: github.com/gpac/gpac/issues/32
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/4a
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

##

sigdevel@infosec.exchange at 2026-06-20T03:52:04.000Z ##

Security Advisory: CVE-2025-60466 - Expired Pointer Dereference in GPAC MP4Box Packet Retrieval

Processing a crafted media file with MP4Box `-info` can trigger an expired pointer dereference in `gf_filter_pid_get_packet()`, causing a heap use-after-free crash and potential code execution.

Summary:
The `gf_filter_pid_get_packet()` function in `filter_core/filter_pid.c` may operate on an invalidated Packet ID (PID) object after it has been freed by `gf_filter_pid_del()`. When MP4Box processes a specially crafted media file through the filter graph, the `inspect` filter can request packets from a stale PID object, leading to access to freed heap memory.

CWE:
CWE-825 - Expired Pointer Dereference

Affected Component:
```
filter_core/filter_pid.c:6827
Function: gf_filter_pid_get_packet()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
The issue was reproduced on:
```
GPAC version: 2.5-DEV-rev1570-g6208015df-master
Commit: 6208015dff3a6735a26e413c484c714666eb3ea2
```

The MITRE response states that GPAC Project/MP4Box before `26.02.0` is affected. Builds before the fix commit `4a7ea06dd1b2cc65fe0dabc60189eb6bc814f7bb` should be considered affected if they contain the vulnerable PID packet retrieval path.

Attack Conditions:
An attacker supplies a crafted media file that is processed by MP4Box through the info/import path and drives the inspect/filter pipeline through PID deletion and packet retrieval paths. The issue can be reproduced locally with:

```
./MP4Box -info 35_gf_filter_pid_get_packet_filter_core_filter_pid_c_6827
```
No elevated privileges are required. User interaction is required when the victim manually processes the malicious file, or an automated media workflow invokes MP4Box on attacker-controlled input.

The prepared CVSS vector in the local BDU data is:
```
AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
```

Impact:
The immediate observed impact is Denial of Service due to process termination. Because the vulnerability is a heap use-after-free / expired pointer dereference, memory corruption and potential arbitrary code execution are possible.

Fix / mitigation status:
The issue was fixed in GPAC commit:
```
4a7ea06dd1b2cc65fe0dabc60189eb6bc814f7bb
```

Users should update to a GPAC build containing this commit or later. The fix adds checks to ignore tasks when PID or filter objects have been removed or finalized, preventing stale object use.

References:

- Issue: github.com/gpac/gpac/issues/32
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/4a
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

#fuzzing #infosec #security #aflplusplus #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory #media #gpac

##

CVE-2025-60465
(0 None)

EPSS: 0.00%

2 posts

N/A

sigdevel at 2026-06-19T19:46:49.687Z ##

Security Advisory: CVE-2025-60465 - Use-After-Free in GPAC MP4Box PID Instance Swap

Processing a crafted media file with MP4Box `-info` can trigger a heap use-after-free in `gf_filter_pid_inst_swap()`, causing a crash and potential code execution.

Summary:
The `gf_filter_pid_inst_swap()` function in `filter_core/filter_pid.c` does not reset `ctx->pid_inst` to NULL after freeing the PID instance. Subsequent PID configuration and reconfiguration steps can reuse this dangling pointer, leading to access to freed heap memory.

CWE:
CWE-416 - Use After Free

Affected Component:
```
filter_core/filter_pid.c:633
Function: gf_filter_pid_inst_swap()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
The issue was reproduced on:
```
GPAC version: 2.5-DEV-rev1570-g6208015df-master
Commit: 6208015dff3a6735a26e413c484c714666eb3ea2
```
The MITRE response states that GPAC Project/MP4Box before `26.02.0` is affected. Builds before the fix commit `55b351bd078c950592544ab4c708a613c1725b9b` should be considered affected if they contain the vulnerable PID instance swap path.

Attack Conditions:
An attacker supplies a crafted media or MPEG-2 TS input that is processed by MP4Box through the info/import path and triggers filter PID reconfiguration. The issue can be reproduced locally with:
```
./MP4Box -info 34_gf_filter_pid_inst_swap_filter_core_filter_pid_c_633
```

No elevated privileges are required. User interaction is required when the victim manually processes the malicious file, or an automated media workflow invokes MP4Box on attacker-controlled input.

The prepared CVSS vector in the local BDU data is:
```
AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
```

Impact:
The immediate observed impact is Denial of Service due to process termination. Because the vulnerability is a heap use-after-free, memory corruption and potential arbitrary code execution are possible.

Fix / mitigation status:
The issue was fixed in GPAC commit:
```
55b351bd078c950592544ab4c708a613c1725b9b
```
Users should update to a GPAC build containing this commit or later. The affected PID instance swap path should clear `ctx->pid_inst` after freeing it and avoid later use of stale PID object pointers.

References:

- Issue: github.com/gpac/gpac/issues/32
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/55
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

##

sigdevel@infosec.exchange at 2026-06-19T19:46:49.000Z ##

Security Advisory: CVE-2025-60465 - Use-After-Free in GPAC MP4Box PID Instance Swap

Processing a crafted media file with MP4Box `-info` can trigger a heap use-after-free in `gf_filter_pid_inst_swap()`, causing a crash and potential code execution.

Summary:
The `gf_filter_pid_inst_swap()` function in `filter_core/filter_pid.c` does not reset `ctx->pid_inst` to NULL after freeing the PID instance. Subsequent PID configuration and reconfiguration steps can reuse this dangling pointer, leading to access to freed heap memory.

CWE:
CWE-416 - Use After Free

Affected Component:
```
filter_core/filter_pid.c:633
Function: gf_filter_pid_inst_swap()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
The issue was reproduced on:
```
GPAC version: 2.5-DEV-rev1570-g6208015df-master
Commit: 6208015dff3a6735a26e413c484c714666eb3ea2
```
The MITRE response states that GPAC Project/MP4Box before `26.02.0` is affected. Builds before the fix commit `55b351bd078c950592544ab4c708a613c1725b9b` should be considered affected if they contain the vulnerable PID instance swap path.

Attack Conditions:
An attacker supplies a crafted media or MPEG-2 TS input that is processed by MP4Box through the info/import path and triggers filter PID reconfiguration. The issue can be reproduced locally with:
```
./MP4Box -info 34_gf_filter_pid_inst_swap_filter_core_filter_pid_c_633
```

No elevated privileges are required. User interaction is required when the victim manually processes the malicious file, or an automated media workflow invokes MP4Box on attacker-controlled input.

The prepared CVSS vector in the local BDU data is:
```
AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
```

Impact:
The immediate observed impact is Denial of Service due to process termination. Because the vulnerability is a heap use-after-free, memory corruption and potential arbitrary code execution are possible.

Fix / mitigation status:
The issue was fixed in GPAC commit:
```
55b351bd078c950592544ab4c708a613c1725b9b
```
Users should update to a GPAC build containing this commit or later. The affected PID instance swap path should clear `ctx->pid_inst` after freeing it and avoid later use of stale PID object pointers.

References:

- Issue: github.com/gpac/gpac/issues/32
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/55
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

#fuzzing #infosec #security #aflplusplus #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory #media #gpac

##

CVE-2025-60471
(0 None)

EPSS: 0.00%

4 posts

N/A

sigdevel at 2026-06-19T19:39:05.098Z ##

Security Advisory: CVE-2025-60471 - Use-After-Free in GPAC MP4Box PID Reconfiguration

Processing a crafted media file with MP4Box `-info` can trigger a heap use-after-free in `gf_filter_pid_reconfigure_task_discard()`, causing a crash and potential code execution.

Summary:
The `gf_filter_pid_reconfigure_task_discard()` function in `filter_core/filter_pid.c` can access a freed Packet ID (PID) object during filter reconfiguration cleanup. When MP4Box processes a specially crafted file with malformed MPEG-2 TS packet data, broken PMT descriptors, unsupported stream types, and invalid packet structure, the vulnerable path may free a PID instance through `gf_filter_pid_inst_swap()` and later dereference it during reconfiguration task discard.
AddressSanitizer reports a `heap-use-after-free` at `filter_core/filter_pid.c:1346`, with a `READ of size 8` from a freed 336-byte heap region.

CWE:
CWE-416 - Use After Free

Affected Component:
```
filter_core/filter_pid.c:1346
Function: gf_filter_pid_reconfigure_task_discard()
```
Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
The issue was reproduced on:

```
GPAC version: 2.5-DEV-rev1570-g6208015df-master
Commit: 6208015dff3a6735a26e413c484c714666eb3ea2
```

Builds before the fix commit `48b0f505679ee41004cb521ac3b76b610650c0cb` should be considered affected if they contain the vulnerable PID reconfiguration cleanup path.

Attack Conditions:
An attacker supplies a crafted media file that is processed by MP4Box through the info/import path. The issue can be reproduced locally with:
```
./MP4Box -info 33_gf_filter_pid_reconfigure_task_discard_filter_core_filter_pid_c_1346
```
No elevated privileges are required. User interaction is required when the victim manually processes the malicious file, or an automated media workflow invokes MP4Box on attacker-controlled input.

The prepared CVSS vector in the local BDU data is:
```
AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
```

Impact:
The immediate observed impact is Denial of Service due to process termination. Because the vulnerability is a heap use-after-free, memory corruption and potential arbitrary code execution are possible.

Fix / mitigation status:
The issue was fixed in GPAC commit:
```
48b0f505679ee41004cb521ac3b76b610650c0cb
```

Users should update to a GPAC build containing this commit or later. The affected PID reconfiguration path should ensure that PID object lifetime remains valid before discard logic accesses the object.

References:

- Issue: github.com/gpac/gpac/issues/32
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/48
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

##

sigdevel at 2026-06-19T18:57:48.529Z ##

Security Advisory: CVE-2025-60471 - Use-After-Free in GPAC MP4Box PID Reconfiguration

Processing a crafted MPEG-2 TS file with MP4Box `-info` can trigger a heap use-after-free in `gf_filter_pid_reconfigure_task_discard()`, causing a crash and potential code execution.

Summary:
The `gf_filter_pid_reconfigure_task_discard()` function in `filter_core/filter_pid.c` can access a freed `pid_inst` structure during PID reconfiguration task disposal. When MP4Box processes a specially crafted MPEG-2 Transport Stream file containing broken PMT descriptors, missing packet sync markers, unsupported stream types, and invalid packet data, a PID instance can be freed by `gf_filter_pid_inst_swap_delete()` and later accessed in `gf_filter_pid_reconfigure_task_discard()`.

AddressSanitizer reports a `heap-use-after-free` at `filter_core/filter_pid.c:1341`, with a `READ of size 8` from a freed 336-byte heap region.

CWE:
CWE-416 - Use After Free

Affected Component:
```
filter_core/filter_pid.c:1341
Function: gf_filter_pid_reconfigure_task_discard()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
The issue was reproduced on:
```
GPAC version: 2.5-DEV-rev1557-g62714f27c-master
Commit: 62714f27c64a3d1eb7e880f9eed2d38673cb43ce
```

The MITRE response states that GPAC Project/MP4Box before `26.02.0` is affected. Local MITRE data also describes affected GPAC MP4Box 2.4 and earlier, including development branches that contain the vulnerable PID reconfiguration lifecycle handling.
Builds before the fix commit `868c6801c226e9964cace54cfd5a759f152780b4` should be considered affected if they contain the vulnerable path.

Attack Conditions:
An attacker supplies a crafted MPEG-2 TS file with corrupted PMT descriptors and invalid packet data. The issue can be reproduced locally with:
```
./MP4Box -info 31_gf_filter_pid_reconfigure_task_discard_filter_core_filter_pid_c_1341
```

No elevated privileges are required. User interaction is required when the victim manually processes the malicious file, or an automated media workflow invokes MP4Box on attacker-controlled input.

Impact:
The immediate observed impact is Denial of Service due to process termination. Because the vulnerability is a heap use-after-free, memory corruption and potential arbitrary code execution are possible.

Fix / mitigation status:
The issue was fixed in GPAC commit:
```
868c6801c226e9964cace54cfd5a759f152780b4
```
Users should update to a GPAC build containing this commit or later. The affected filter PID reconfiguration path should ensure that PID instance lifetime is valid before task discard logic accesses the object.

References:

- Issue: github.com/gpac/gpac/issues/32
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/86
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

##

sigdevel@infosec.exchange at 2026-06-19T19:39:05.000Z ##

Security Advisory: CVE-2025-60471 - Use-After-Free in GPAC MP4Box PID Reconfiguration

Processing a crafted media file with MP4Box `-info` can trigger a heap use-after-free in `gf_filter_pid_reconfigure_task_discard()`, causing a crash and potential code execution.

Summary:
The `gf_filter_pid_reconfigure_task_discard()` function in `filter_core/filter_pid.c` can access a freed Packet ID (PID) object during filter reconfiguration cleanup. When MP4Box processes a specially crafted file with malformed MPEG-2 TS packet data, broken PMT descriptors, unsupported stream types, and invalid packet structure, the vulnerable path may free a PID instance through `gf_filter_pid_inst_swap()` and later dereference it during reconfiguration task discard.
AddressSanitizer reports a `heap-use-after-free` at `filter_core/filter_pid.c:1346`, with a `READ of size 8` from a freed 336-byte heap region.

CWE:
CWE-416 - Use After Free

Affected Component:
```
filter_core/filter_pid.c:1346
Function: gf_filter_pid_reconfigure_task_discard()
```
Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
The issue was reproduced on:

```
GPAC version: 2.5-DEV-rev1570-g6208015df-master
Commit: 6208015dff3a6735a26e413c484c714666eb3ea2
```

Builds before the fix commit `48b0f505679ee41004cb521ac3b76b610650c0cb` should be considered affected if they contain the vulnerable PID reconfiguration cleanup path.

Attack Conditions:
An attacker supplies a crafted media file that is processed by MP4Box through the info/import path. The issue can be reproduced locally with:
```
./MP4Box -info 33_gf_filter_pid_reconfigure_task_discard_filter_core_filter_pid_c_1346
```
No elevated privileges are required. User interaction is required when the victim manually processes the malicious file, or an automated media workflow invokes MP4Box on attacker-controlled input.

The prepared CVSS vector in the local BDU data is:
```
AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
```

Impact:
The immediate observed impact is Denial of Service due to process termination. Because the vulnerability is a heap use-after-free, memory corruption and potential arbitrary code execution are possible.

Fix / mitigation status:
The issue was fixed in GPAC commit:
```
48b0f505679ee41004cb521ac3b76b610650c0cb
```

Users should update to a GPAC build containing this commit or later. The affected PID reconfiguration path should ensure that PID object lifetime remains valid before discard logic accesses the object.

References:

- Issue: github.com/gpac/gpac/issues/32
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/48
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

#fuzzing #infosec #security #aflplusplus #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory #media #gpac

##

sigdevel@infosec.exchange at 2026-06-19T18:57:48.000Z ##

Security Advisory: CVE-2025-60471 - Use-After-Free in GPAC MP4Box PID Reconfiguration

Processing a crafted MPEG-2 TS file with MP4Box `-info` can trigger a heap use-after-free in `gf_filter_pid_reconfigure_task_discard()`, causing a crash and potential code execution.

Summary:
The `gf_filter_pid_reconfigure_task_discard()` function in `filter_core/filter_pid.c` can access a freed `pid_inst` structure during PID reconfiguration task disposal. When MP4Box processes a specially crafted MPEG-2 Transport Stream file containing broken PMT descriptors, missing packet sync markers, unsupported stream types, and invalid packet data, a PID instance can be freed by `gf_filter_pid_inst_swap_delete()` and later accessed in `gf_filter_pid_reconfigure_task_discard()`.

AddressSanitizer reports a `heap-use-after-free` at `filter_core/filter_pid.c:1341`, with a `READ of size 8` from a freed 336-byte heap region.

CWE:
CWE-416 - Use After Free

Affected Component:
```
filter_core/filter_pid.c:1341
Function: gf_filter_pid_reconfigure_task_discard()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
The issue was reproduced on:
```
GPAC version: 2.5-DEV-rev1557-g62714f27c-master
Commit: 62714f27c64a3d1eb7e880f9eed2d38673cb43ce
```

The MITRE response states that GPAC Project/MP4Box before `26.02.0` is affected. Local MITRE data also describes affected GPAC MP4Box 2.4 and earlier, including development branches that contain the vulnerable PID reconfiguration lifecycle handling.
Builds before the fix commit `868c6801c226e9964cace54cfd5a759f152780b4` should be considered affected if they contain the vulnerable path.

Attack Conditions:
An attacker supplies a crafted MPEG-2 TS file with corrupted PMT descriptors and invalid packet data. The issue can be reproduced locally with:
```
./MP4Box -info 31_gf_filter_pid_reconfigure_task_discard_filter_core_filter_pid_c_1341
```

No elevated privileges are required. User interaction is required when the victim manually processes the malicious file, or an automated media workflow invokes MP4Box on attacker-controlled input.

Impact:
The immediate observed impact is Denial of Service due to process termination. Because the vulnerability is a heap use-after-free, memory corruption and potential arbitrary code execution are possible.

Fix / mitigation status:
The issue was fixed in GPAC commit:
```
868c6801c226e9964cace54cfd5a759f152780b4
```
Users should update to a GPAC build containing this commit or later. The affected filter PID reconfiguration path should ensure that PID instance lifetime is valid before task discard logic accesses the object.

References:

- Issue: github.com/gpac/gpac/issues/32
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/86
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

#fuzzing #infosec #security #aflplusplus #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory #media #gpac

##

CVE-2025-60464
(0 None)

EPSS: 0.00%

2 posts

N/A

sigdevel at 2026-06-19T19:15:28.554Z ##

Security Advisory: CVE-2025-60464 - Use-After-Free in GPAC MP4Box SEI State Handling

Processing a crafted MPEG-2 TS file with MP4Box `-info` can trigger a heap use-after-free in `gf_sei_load_from_state_internal()`, causing a crash and potential code execution.

Summary:
The `gf_sei_load_from_state_internal()` function in `filters/sei_load.c` can access codec/SEI state after the related heap buffer has been freed by the NALU demuxer setup path. When MP4Box processes a specially crafted MPEG-2 Transport Stream file containing malformed AVC/HEVC/VVC NAL units and corrupted PMT descriptors, `naludmx_configure_pid()` can release a state buffer that is later read during SEI state loading.

CWE:
CWE-416 - Use After Free

Affected Component:
```
filters/sei_load.c:225
Function: gf_sei_load_from_state_internal()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
The issue was reproduced on:
```
GPAC version: 2.5-DEV-rev1557-g62714f27c-master
Commit: 62714f27c64a3d1eb7e880f9eed2d38673cb43ce
```

The MITRE response states that GPAC Project/MP4Box before `26.02.0` is affected. Builds before the fix commit `8f404bd581e455267482f86272169a742f654b97` should be considered affected if they contain the vulnerable SEI state handling path.

Attack Conditions:
An attacker supplies a crafted MPEG-2 TS file containing malformed AVC/HEVC/VVC bitstream data, corrupted PMT descriptors, and invalid NAL/SEI state. The issue can be reproduced locally with:
```
./MP4Box -info 32_filters_sei_load_c_225_in_gf_sei_load_from_state_internal
```

No elevated privileges are required. User interaction is required when the victim manually processes the malicious file, or an automated media workflow invokes MP4Box on attacker-controlled input.

The prepared CVSS vector in the local BDU data is:

```
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
```

Impact:
The immediate observed impact is Denial of Service due to process termination. Because the vulnerability is a heap use-after-free, memory corruption and potential arbitrary code execution are possible.

Fix / mitigation status:
The issue was fixed in GPAC commit:

```
8f404bd581e455267482f86272169a742f654b97
```
Users should update to a GPAC build containing this commit or later. The affected SEI/NALU handling path should ensure state buffers remain valid before SEI parsing reads from them.

References:

- Issue: github.com/gpac/gpac/issues/32
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/8f
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

##

sigdevel@infosec.exchange at 2026-06-19T19:15:28.000Z ##

Security Advisory: CVE-2025-60464 - Use-After-Free in GPAC MP4Box SEI State Handling

Processing a crafted MPEG-2 TS file with MP4Box `-info` can trigger a heap use-after-free in `gf_sei_load_from_state_internal()`, causing a crash and potential code execution.

Summary:
The `gf_sei_load_from_state_internal()` function in `filters/sei_load.c` can access codec/SEI state after the related heap buffer has been freed by the NALU demuxer setup path. When MP4Box processes a specially crafted MPEG-2 Transport Stream file containing malformed AVC/HEVC/VVC NAL units and corrupted PMT descriptors, `naludmx_configure_pid()` can release a state buffer that is later read during SEI state loading.

CWE:
CWE-416 - Use After Free

Affected Component:
```
filters/sei_load.c:225
Function: gf_sei_load_from_state_internal()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
The issue was reproduced on:
```
GPAC version: 2.5-DEV-rev1557-g62714f27c-master
Commit: 62714f27c64a3d1eb7e880f9eed2d38673cb43ce
```

The MITRE response states that GPAC Project/MP4Box before `26.02.0` is affected. Builds before the fix commit `8f404bd581e455267482f86272169a742f654b97` should be considered affected if they contain the vulnerable SEI state handling path.

Attack Conditions:
An attacker supplies a crafted MPEG-2 TS file containing malformed AVC/HEVC/VVC bitstream data, corrupted PMT descriptors, and invalid NAL/SEI state. The issue can be reproduced locally with:
```
./MP4Box -info 32_filters_sei_load_c_225_in_gf_sei_load_from_state_internal
```

No elevated privileges are required. User interaction is required when the victim manually processes the malicious file, or an automated media workflow invokes MP4Box on attacker-controlled input.

The prepared CVSS vector in the local BDU data is:

```
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
```

Impact:
The immediate observed impact is Denial of Service due to process termination. Because the vulnerability is a heap use-after-free, memory corruption and potential arbitrary code execution are possible.

Fix / mitigation status:
The issue was fixed in GPAC commit:

```
8f404bd581e455267482f86272169a742f654b97
```
Users should update to a GPAC build containing this commit or later. The affected SEI/NALU handling path should ensure state buffers remain valid before SEI parsing reads from them.

References:

- Issue: github.com/gpac/gpac/issues/32
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/8f
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

#fuzzing #infosec #security #aflplusplus #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory #media #gpac

##

CVE-2026-48768
(0 None)

EPSS: 0.27%

2 posts

N/A

hugovalters@mastodon.social at 2026-06-19T14:10:37.000Z ##

CVE-2026-48768 - Critical XSS in Typebot. Unauthenticated file upload to arbitrary S3 paths. Malicious HTML/SVG/JS can be injected into other tenants' results. CVSS 9.3. No patch available. Disable file input blocks immediately. #CVE #Typebot #infosec

valtersit.com/cve/CVE-2026-487

##

offseq@infosec.exchange at 2026-06-18T00:00:42.000Z ##

⚠️ CRITICAL: CVE-2026-48768 in typebot.io (≤3.16.1) allows unauthenticated path injection — attackers can upload HTML/JS to public paths, risking stored XSS. Upgrade to 3.17.0. radar.offseq.com/threat/cve-20 #OffSeq #CVE202648768 #Infosec #PathTraversal

##

CVE-2026-48979
(0 None)

EPSS: 0.27%

2 posts

N/A

hugovalters@mastodon.social at 2026-06-19T12:01:41.000Z ##

CVE-2026-48979 - HTTP/2 request smuggling in PHP standard library (PSL). Unvalidated DATA frame bytes allow content overflow. CVSS 7.5. No patch yet; disable PSL H2 servers or upgrade if fix released. #CVE #PHP #infosec

valtersit.com/cve/CVE-2026-489

##

hugovalters@mastodon.social at 2026-06-19T12:01:41.000Z ##

CVE-2026-48979 - HTTP/2 request smuggling in PHP standard library (PSL). Unvalidated DATA frame bytes allow content overflow. CVSS 7.5. No patch yet; disable PSL H2 servers or upgrade if fix released. #CVE #PHP #infosec

valtersit.com/cve/CVE-2026-489

##

CVE-2026-48618
(0 None)

EPSS: 0.00%

4 posts

N/A

canartuc@mastodon.social at 2026-06-19T11:45:45.000Z ##

The item worth reading twice in Node.js's June 18 release is CVE-2026-48618: a TLS wildcard-depth check that a Unicode dot separator can bypass, defeating hostname authentication without any obvious signal. It rides alongside 12 other CVEs across 22.23.0, 24.17.0 and 26.3.1, including a HIGH-rated WebCrypto AES integer overflow. Most teams patch crashers fast and silent auth bypasses slowly. Which kind does your process prioritize?

#nodejs #security

##

nodejs_release_watcher@kodesumber.com at 2026-06-18T05:46:04.000Z ##

2026-06-18, Version 26.3.1 (Current), @aduh95

This is a security release. Notable Changes (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High (CVE-2026-48615) lib,test:...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-06-18T05:45:59.000Z ##

2026-06-18, Version 24.17.0 'Krypton' (LTS), @aduh95

This is a security release. Notable Changes (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High (CVE-2026-48615) lib,test:...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-06-18T05:45:58.000Z ##

2026-06-18, Version 22.23.0 'Jod' (LTS), @aduh95

This is a security release. Notable Changes (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High (CVE-2026-48937) deps: fix...

github.com/nodejs/node/release

#nodejs #javascript

##

CVE-2026-47729
(0 None)

EPSS: 0.00%

1 posts

N/A

_r_netsec@infosec.exchange at 2026-06-19T10:28:05.000Z ##

Squidbleed (CVE-2026-47729) - Heartbleed-style vulnerability that leaks internal memory from every version of Squid Proxy, in its default configuration blog.calif.io/p/squidbleed-cve

##

CVE-2026-49257
(0 None)

EPSS: 0.00%

1 posts

N/A

offseq@infosec.exchange at 2026-06-18T21:30:12.000Z ##

CVE-2026-49257: startreedata mcp-pinot <=3.0.1 has a CRITICAL auth bypass. MCP server exposes full read/write access to Pinot clusters on 0.0.0.0:8080. Upgrade to 3.1.0 ASAP. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #CVE202649257 #Infosec

##

CVE-2026-55074
(0 None)

EPSS: 0.00%

1 posts

N/A

Larvitz@burningboard.net at 2026-06-18T20:21:44.000Z ##

I'm more than 25 years into IT at this point, but this is a first for me. Not one I'm proud of, but one I take responsibility for:

My project ansible_jailexec (an Ansible connection plugin for FreeBSD Jails) had a bug that turned out to be a vulnerability. Improper Link Resolution Before File Access (CWE-59), a jail escape. It's been assigned CVE-2026-55074 so people can scan for it (I know it's bundled into Collections out there).

If you're running < 2.0.0: please upgrade. 2.0.0 fixes it.

Advisory: github.com/chofstede/ansible_j
Release: github.com/chofstede/ansible_j

#ansible #cve #security #freebsd

##

CVE-2026-48933
(0 None)

EPSS: 0.00%

3 posts

N/A

nodejs_release_watcher@kodesumber.com at 2026-06-18T05:46:04.000Z ##

2026-06-18, Version 26.3.1 (Current), @aduh95

This is a security release. Notable Changes (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High (CVE-2026-48615) lib,test:...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-06-18T05:45:59.000Z ##

2026-06-18, Version 24.17.0 'Krypton' (LTS), @aduh95

This is a security release. Notable Changes (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High (CVE-2026-48615) lib,test:...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-06-18T05:45:58.000Z ##

2026-06-18, Version 22.23.0 'Jod' (LTS), @aduh95

This is a security release. Notable Changes (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High (CVE-2026-48937) deps: fix...

github.com/nodejs/node/release

#nodejs #javascript

##

CVE-2026-48615
(0 None)

EPSS: 0.00%

2 posts

N/A

nodejs_release_watcher@kodesumber.com at 2026-06-18T05:46:04.000Z ##

2026-06-18, Version 26.3.1 (Current), @aduh95

This is a security release. Notable Changes (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High (CVE-2026-48615) lib,test:...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-06-18T05:45:59.000Z ##

2026-06-18, Version 24.17.0 'Krypton' (LTS), @aduh95

This is a security release. Notable Changes (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High (CVE-2026-48615) lib,test:...

github.com/nodejs/node/release

#nodejs #javascript

##

CVE-2025-55640
(0 None)

EPSS: 0.00%

1 posts

N/A

sigdevel@infosec.exchange at 2026-06-18T04:41:26.000Z ##

Security Advisory: CVE-2025-55640 - Heap Buffer Overflow in GPAC MP4Box Sample Size Handling

Processing a crafted MP4 file with MP4Box `-add` can trigger a heap buffer overflow in `stbl_AddSize()`, causing a crash and potential code execution.

Summary:
The `stbl_AddSize()` function in `isomedia/stbl_write.c` does not sufficiently validate sample count boundaries before writing to the sample size table. When MP4Box imports a specially crafted MP4 file containing manipulated sample metadata, corrupted sample counts, invalid aspect ratios, and oversized box declarations, the vulnerable path writes beyond the allocated heap buffer for `stbl->sampleSize->sizes`.

AddressSanitizer reports a `heap-buffer-overflow` at `isomedia/stbl_write.c:492`, with a `WRITE of size 4` immediately after a 64-byte heap allocation.

CWE:
CWE-122 - Heap-based Buffer Overflow

Affected Component:
```
isomedia/stbl_write.c:492
Function: stbl_AddSize()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
GPAC MP4Box version 2.4 is affected according to the prepared CVE/MITRE data. The issue was reproduced on a GPAC build at commit:
```
027ce139dda498ee95df36db9f9f6f3cadce8ec9
```
Builds before the fix commit `321624f28d19a413449fd1718d1eb59037f8f7fc` should be considered affected if they contain the vulnerable sample size table update path.

Attack Conditions:
An attacker supplies a crafted MP4 file with manipulated sample metadata. The issue can be reproduced locally with:

```
./MP4Box -add 25_poc.mp4 -new /dev/null
```

No elevated privileges are required. User interaction is required when the victim manually processes the malicious file, or an automated media workflow invokes MP4Box on attacker-controlled input.

Impact:
The immediate observed impact is Denial of Service due to process termination. Because the vulnerability is an out-of-bounds heap write, memory corruption and potential arbitrary code execution are possible.

Fix / mitigation status:
The issue was fixed in GPAC commit:
```
321624f28d19a413449fd1718d1eb59037f8f7fc
```
Users should update to a GPAC build containing this commit or later. The affected sample size table path should validate `sampleCount` and ensure capacity before writing sample size entries.

References:

- Issue: github.com/gpac/gpac/issues/32
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/32
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

#fuzzing #infosec #security #aflplusplus #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory #media #gpac

##

CVE-2025-52291
(0 None)

EPSS: 0.00%

1 posts

N/A

sigdevel@infosec.exchange at 2026-06-18T04:35:05.000Z ##

Security Advisory: CVE-2025-52291 - NULL Pointer Dereference in GPAC MP4Box Movie Info Dumping

Processing a crafted MP4 file with MP4Box `-info` can trigger a NULL pointer dereference in `DumpMovieInfo()`, causing a Denial of Service.

Summary:
The `DumpMovieInfo()` function in `applications/mp4box/filedump.c` does not sufficiently validate metadata tag values before printing them. When MP4Box processes a specially crafted MP4 file containing corrupted metadata tags, a NULL tag value can be passed to `fputs()`.

AddressSanitizer reports a segmentation fault caused by a read from address `0x0` in `strlen()` during `fputs()`, reached from `DumpMovieInfo()` at `applications/mp4box/filedump.c:4230`.

CWE:
CWE-476 - NULL Pointer Dereference

Affected Component:
```
applications/mp4box/filedump.c:4230
Function: DumpMovieInfo()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
GPAC MP4Box version 2.4 is affected according to the prepared CVE/MITRE data. The issue was reproduced on a GPAC build at commit:
```
6681656e841649ef91c2b76e561192fe9da791f8
```
Builds before the fix commit `4bbb6e5f7cb827e56f32b2f7a5918b0b8e395eb8` should be considered affected if they contain the vulnerable movie information dumping path.

Attack Conditions:
An attacker supplies a crafted MP4 file with corrupted metadata tags, such as a malformed or NULL `minor_version` tag value. The issue can be reproduced locally with:
```
./MP4Box -info 24_data
```

No elevated privileges are required. User interaction is required when the victim manually processes the malicious file, or an automated media workflow invokes MP4Box on attacker-controlled input.

Impact:
The immediate observed impact is Denial of Service due to process termination. No evidence of arbitrary code execution was observed in the local crash data.

Fix / mitigation status:
The issue was fixed in GPAC commit:
```
4bbb6e5f7cb827e56f32b2f7a5918b0b8e395eb8
```
Users should update to a GPAC build containing this commit or later. The affected metadata dumping path should validate tag pointers and tag values before printing them.

References:

- Issue: github.com/gpac/gpac/issues/32
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/4b
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

#fuzzing #infosec #security #aflplusplus #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory #media #gpac

##

CVE-2025-55639
(0 None)

EPSS: 0.00%

1 posts

N/A

sigdevel@infosec.exchange at 2026-06-18T04:19:20.000Z ##

Security Advisory: CVE-2025-55639 - NULL Pointer Dereference in GPAC MP4Box Track Kind Handling

Processing a crafted MP4 file with MP4Box `-add` can trigger a NULL pointer dereference in `gf_isom_add_track_kind()`, causing a Denial of Service.

Summary:
The `gf_isom_add_track_kind()` function in `isomedia/isom_write.c` does not sufficiently validate the `kind` string before passing it to `strdup()`. When MP4Box imports a specially crafted MP4 file containing corrupted MPEG-2 TS PMT descriptors and empty track metadata, a NULL `kind` pointer can reach `gf_isom_add_track_kind()`.

AddressSanitizer reports a segmentation fault caused by a read from address `0x0` in `strlen()` during `strdup()`, reached from `gf_isom_add_track_kind()` at `isomedia/isom_write.c:3153`.

CWE:
CWE-476 - NULL Pointer Dereference

Affected Component:
```
isomedia/isom_write.c:3153
Function: gf_isom_add_track_kind()
``

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
MP4Box version 2.4 is affected according to the prepared CVE/MITRE data. The issue was reproduced on a GPAC build at commit:
```
78c2c9be29a41b38eca2c53d280442088a71dab9
```
Builds before the fix commit `027ce139dda498ee95df36db9f9f6f3cadce8ec9` should be considered affected if they contain the vulnerable track kind handling path.

Attack Conditions:
An attacker supplies a crafted MP4 file with corrupted PMT descriptors in an MPEG-2 TS stream and malformed or empty track metadata. The issue can be reproduced locally with:

```
./MP4Box -add 23_poc.mp4 -new /dev/null
```

No elevated privileges are required. User interaction is required when the victim manually processes the malicious file, or an automated media workflow invokes MP4Box on attacker-controlled input.

Impact:
The immediate observed impact is Denial of Service due to process termination. No evidence of arbitrary code execution was observed.

Fix / mitigation status:
The issue was fixed in GPAC commit:
```
027ce139dda498ee95df36db9f9f6f3cadce8ec9
```

Users should update to a GPAC build containing this commit or later. The affected track metadata path should validate `kind` before duplicating it and fail cleanly when malformed input omits the expected metadata.

References:

- Issue: github.com/gpac/gpac/issues/32
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/02
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

#fuzzing #infosec #security #aflplusplus #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory #media #gpac

##

CVE-2025-55654
(0 None)

EPSS: 0.00%

1 posts

N/A

sigdevel@infosec.exchange at 2026-06-18T03:57:24.000Z ##

Security Advisory: CVE-2025-55654 - Use-After-Free in GPAC MP4Box Packet Filtering

Processing a crafted media file with MP4Box `-nhml` export can trigger a heap use-after-free in `gf_filter_pid_get_packet()`, causing a crash and potential memory corruption.

Summary:
The `gf_filter_pid_get_packet()` function in `filter_core/filter_pid.c` may be called on a `gf_pid_filter_t` object that has already been freed by `gf_filter_pid_del()`. When MP4Box exports a specially crafted file through the `-nhml` path, the file output filter can continue packet processing after the related PID filter object has been released.

AddressSanitizer reports a `heap-use-after-free` at `filter_core/filter_pid.c:6792`, with a `READ of size 8` from a freed 336-byte heap region.

CWE:
CWE-416 - Use After Free

Affected Component:
```
filter_core/filter_pid.c:6792
Function: gf_filter_pid_get_packet()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
MP4Box versions 2.4 and earlier are affected according to the prepared CVE/MITRE data. The issue was reproduced on a GPAC build at commit:
```
63eccc33d4a2b731ebb31581ff5673a2c0b13ad4
```
Builds before the fix commit `0ccd2927c7145f5ab0352c5b15f787757b34eb18` should be considered affected if they contain the vulnerable packet filtering/export path.

Attack Conditions:
An attacker supplies a crafted media file that is processed by MP4Box through the NHML export path. The issue can be reproduced locally with:

```
./MP4Box -nhml trackID 22_data -out /dev/null
```

No elevated privileges are required. User interaction is required when the victim manually processes the malicious file, or an automated media workflow invokes MP4Box on attacker-controlled input.

Impact:
The immediate observed impact is Denial of Service due to process termination. Because the vulnerability is a heap use-after-free, memory corruption and potential arbitrary code execution cannot be ruled out.

Fix / mitigation status:
The issue was fixed in GPAC commit:
```
0ccd2927c7145f5ab0352c5b15f787757b34eb18
```

Users should update to a GPAC build containing this commit or later. The affected filtering path should ensure that a PID filter object remains valid before packet retrieval continues.

References:

- Issue: github.com/gpac/gpac/issues/32
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/0c
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

#fuzzing #infosec #security #aflplusplus #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory #media #gpac

##

CVE-2025-55653
(0 None)

EPSS: 0.00%

1 posts

N/A

sigdevel@infosec.exchange at 2026-06-18T03:52:25.000Z ##

Security Advisory: CVE-2025-55653 - Divide by Zero in GPAC MP4Box

Processing a crafted MP4 file containing a zero-denominator fraction string causes gf_parse_lfrac() to divide by zero in utils/error.c:2290, terminating the process with SIGFPE.

Summary:
The gf_parse_lfrac() function in utils/error.c parses fractional timestamp or rate values extracted from media file metadata during file list processing. When a crafted MP4 causes filelist_next_url() to supply a fraction string whose denominator is zero, gf_parse_lfrac() performs the division at line 2290 without first validating that the divisor is non-zero. The resulting SIGFPE (floating-point exception) immediately kills the process with no possibility of recovery.

CWE:
CWE-369 - Divide by Zero

Affected Component:
```
utils/error.c:2290
Function: gf_parse_lfrac()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
MP4Box 2.4 and earlier; tested at commit 63eccc33d4a2b731ebb31581ff5673a2c0b13ad4

Attack Conditions:
An attacker supplies a locally accessible crafted MP4 file containing an invalid fractional value with a zero denominator in its metadata. The victim runs MP4Box -add ./21_poc.mp4 -new /dev/null on the file. No elevated privileges are required.

Impact:
The division by zero causes an immediate fatal crash (Denial of Service). No evidence of arbitrary code execution was observed.

Fix / mitigation status:
The issue was fixed in GPAC commit:
```
4bbb6e5f7cb827e56f32b2f7a5918b0b8e395eb8
```
Users should update to a GPAC build containing this commit or later.

References:

- Issue: github.com/gpac/gpac/issues/32
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/4b
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

#fuzzing #infosec #security #aflplusplus #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory #media #gpac

##

CVE-2026-24252
(0 None)

EPSS: 0.00%

2 posts

N/A

AAKL@infosec.exchange at 2026-06-17T18:01:10.000Z ##

New.

Tenable research advisories:

CRITICAL: CVE-2026-8024: iba ibaPDA / ibaDatCoordinator .NET Deserialization Remote Code Execution tenable.com/security/research/ @tenable

Cisco:

CRITICAL: CVE-2026-20181 and CVE-2026-20190: Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities

Three others of medium-severity: sec.cloudapps.cisco.com/securi @TalosSecurity

Broadcom:

Several critical and high-severity vulnerabilities. A login is needed for details support.broadcom.com/web/ecx/s

Dell:

Several advisories, one of them critical:

CRITICAL: Security Update for Dell Data Protection Central Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0

More: dell.com/support/security/en-us

Google:

Chrome Beta for iOS Update chromereleases.googleblog.com/

Yesterday:

Microsoft:

CVE-2026-50656: Microsoft Defender Elevation of Privilege Vulnerability msrc.microsoft.com/update-guid

Nvidia:

Security Bulletin addressing CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228:

NVIDIA NeMo - June 2026 nvidia.custhelp.com/app/answer #Nvidia #Dell #Cisco #infosec #vulnerability #threatresearch #Broadcom #Google #Chrome #Microsoft #Windows

##

AAKL@infosec.exchange at 2026-06-16T15:46:34.000Z ##

Nvidia has a new advisory relating to CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228, all high-severity:

Security Bulletin: NVIDIA NeMo - June 2026 nvidia.custhelp.com/app/answer #Nvidia

Broadcom:

Seven advisories addressing one critical vulnerability and several high-severity flaws: You'll need a login for details.

CRITICAL: MICS 14.3, 14.4, and 14.5 Vulnerabilities

More: support.broadcom.com/web/ecx/s #Broadcom

Yesterday:

Google:

Chrome Dev for Desktop Update chromereleases.googleblog.com/ #Google #Chrome

Dell:

Update for a critical vulnerability yesterday that encompasses multiple CVEs:

Security Update for Dell PowerProtect DP Series Appliance (IDPA) Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #infosec #vulnerability

##

CVE-2026-4855
(0 None)

EPSS: 0.00%

1 posts

N/A

cyberveille@mastobot.ping.moi at 2026-06-17T17:00:21.000Z ##

📢 CVE-2026-48558 : Contournement d'authentification critique dans SimpleHelp via OIDC
📝 ## 🔍 Contexte

Le 12 juin 2026, Horizon3.ai publie une divulgation technique concernant **CVE-2026-4855...
📖 cyberveille : cyberveille.ch/posts/2026-06-1
🌐 source : horizon3.ai/attack-research/di
#CVE_2026_48558 #IOC #Cyberveille

##

CVE-2019-25293
(0 None)

EPSS: 0.13%

1 posts

N/A

nyanbinary@infosec.exchange at 2026-06-17T07:32:12.000Z ##

All* CVE reference URLs are either http, https, or ftp. Y'all need to up your weird protocol games!

*: There is one CVE with a typo in the reference url, https:/ (CVE-2019-25293)

##

CVE-2026-48797
(0 None)

EPSS: 0.44%

1 posts

N/A

offseq@infosec.exchange at 2026-06-17T00:00:36.000Z ##

🚨 CRITICAL vuln in mcp-tool-shop-org backpropagate <1.2.0: Reflex UI lacks real auth, letting anyone trigger training, access datasets, & export models. Patch to 1.2.0 ASAP. CVE-2026-48797 radar.offseq.com/threat/cve-20 #OffSeq #Python #Infosec

##

CVE-2026-47750
(0 None)

EPSS: 0.14%

1 posts

N/A

thehackerwire@mastodon.social at 2026-06-16T21:00:11.000Z ##

🟠 CVE-2026-47750 - High (7.8)

stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. In versions prior to master-584-0a7ae07, the pickle .ckpt parser in src/model.cpp contained a heap bu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53776
(0 None)

EPSS: 0.36%

1 posts

N/A

thehackerwire@mastodon.social at 2026-06-16T18:00:13.000Z ##

🔴 CVE-2026-53776 - Critical (9.1)

Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by exploiting the unconditional setting of validate_exp = false in the verify_decode helper within the stdlib JWT verification pa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites