##
Updated at UTC 2026-08-25T03:47:24.976474
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-78676 | 9.8 | 0.00% | 2 | 0 | 2026-08-25T02:16:52.030000 | GitPython before 3.1.59 fails to safely re-serialize multi-line git-config value | |
| CVE-2026-32556 | 7.1 | 0.00% | 2 | 0 | 2026-08-25T00:30:37 | Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions. | |
| CVE-2026-78267 | 9.8 | 0.00% | 4 | 0 | 2026-08-25T00:30:37 | Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions. | |
| CVE-2026-78268 | 7.5 | 0.00% | 2 | 0 | 2026-08-25T00:30:37 | Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & | |
| CVE-2026-78284 | 8.6 | 0.00% | 2 | 0 | 2026-08-25T00:30:37 | Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions. | |
| CVE-2026-78265 | 9.8 | 0.00% | 4 | 0 | 2026-08-24T22:17:20.407000 | Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions. | |
| CVE-2026-19685 | 9.8 | 0.00% | 2 | 0 | 2026-08-24T21:34:43 | NetworkManager did not apply the private_user restriction to the 802-1x.ca-path | |
| CVE-2026-19568 | 7.8 | 0.00% | 2 | 0 | 2026-08-24T21:33:53 | A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force | |
| CVE-2026-7455 | 7.8 | 0.00% | 2 | 0 | 2026-08-24T21:33:53 | A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force | |
| CVE-2026-61419 | 7.8 | 0.00% | 2 | 0 | 2026-08-24T21:33:52 | Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Contr | |
| CVE-2026-16783 | 7.8 | 0.00% | 2 | 0 | 2026-08-24T21:33:46 | A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force | |
| CVE-2026-71366 | 7.7 | 0.00% | 2 | 0 | 2026-08-24T21:33:38 | A server-side request forgery (SSRF) vulnerability was found in multiple AWX not | |
| CVE-2026-77567 | 8.1 | 0.00% | 2 | 0 | 2026-08-24T21:17:48.150000 | Filament is a collection of full-stack components for accelerated Laravel develo | |
| CVE-2026-78541 | 0 | 0.00% | 2 | 0 | 2026-08-24T20:17:23.490000 | A stored OS command injection vulnerability exists in the parent-control module | |
| CVE-2026-63310 | 7.1 | 0.11% | 4 | 0 | 2026-08-24T20:16:55.243000 | NLTK before 3.9.3 fails to verify file integrity after downloading packages and | |
| CVE-2026-61824 | 8.2 | 0.23% | 1 | 0 | 2026-08-24T20:16:52.567000 | Defuddle cleans up HTML pages. Prior to 0.19.1, site extractors interpolate page | |
| CVE-2026-60084 | 8.7 | 0.35% | 2 | 0 | 2026-08-24T20:16:51.410000 | SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability i | |
| CVE-2026-19874 | 9.1 | 0.00% | 2 | 1 | 2026-08-24T20:16:42.277000 | A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online | |
| CVE-2026-21962 | 10.0 | 43.23% | 6 | 9 | 2026-08-24T19:58:10.590000 | Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in pr | |
| CVE-2026-7808 | 9.8 | 0.35% | 4 | 0 | 2026-08-24T19:17:04.697000 | justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that ca | |
| CVE-2026-76070 | 9.8 | 0.00% | 2 | 1 | 2026-08-24T19:16:58.433000 | Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow v | |
| CVE-2026-68766 | 7.8 | 0.16% | 3 | 0 | 2026-08-24T19:16:43.757000 | hashcat fails to restrict command-line options when parsing restore files, allow | |
| CVE-2026-63312 | 7.5 | 0.49% | 4 | 0 | 2026-08-24T19:16:42.383000 | NLTK before 3.10.0 contains an arbitrary local file read vulnerability in Stream | |
| CVE-2026-76835 | 9.1 | 0.00% | 2 | 0 | 2026-08-24T18:32:04 | OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whet | |
| CVE-2026-76838 | 8.5 | 0.00% | 2 | 0 | 2026-08-24T18:32:04 | Hi.Events validates a webhook destination only when it is registered, never when | |
| CVE-2026-76071 | 9.8 | 0.00% | 2 | 1 | 2026-08-24T18:31:59 | Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow v | |
| CVE-2026-76073 | 8.8 | 0.00% | 2 | 0 | 2026-08-24T18:31:57 | Label Studio does not scope the annotation detail endpoint to the requesting use | |
| CVE-2026-9769 | 7.5 | 0.28% | 2 | 0 | 2026-08-24T18:17:35.520000 | justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion | |
| CVE-2026-9254 | 0 | 0.00% | 2 | 1 | 2026-08-24T18:17:34.973000 | An unauthenticated OS command injection vulnerability exists in the parental con | |
| CVE-2026-78170 | 8.8 | 0.44% | 2 | 0 | 2026-08-24T18:17:27.187000 | A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the fu | |
| CVE-2026-16348 | 0 | 0.00% | 2 | 1 | 2026-08-24T18:16:59.710000 | An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allo | |
| CVE-2026-77683 | 9.9 | 1.51% | 2 | 0 | 2026-08-24T16:41:13.950000 | A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this | |
| CVE-2026-77234 | 8.8 | 0.11% | 1 | 0 | 2026-08-24T16:37:45.780000 | Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unpriv | |
| CVE-2026-59568 | 9.1 | 0.00% | 2 | 0 | 2026-08-24T15:31:57 | Multiple vulnerabilities on affected versions of Zscaler Client Connector allow | |
| CVE-2026-77995 | None | 0.00% | 2 | 0 | 2026-08-24T15:31:57 | Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAu | |
| CVE-2026-78155 | 9.9 | 0.27% | 4 | 0 | 2026-08-24T14:17:03.663000 | privilege escalation in StackGres operator allows a low-privilege tenant who own | |
| CVE-2026-47895 | 7.5 | 0.67% | 3 | 0 | 2026-08-24T14:16:55.217000 | In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-I | |
| CVE-2026-73570 | 8.9 | 1.51% | 14 | 2 | 2026-08-24T13:19:17.577000 | A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) befor | |
| CVE-2026-28171 | 8.6 | 0.00% | 1 | 0 | 2026-08-24T12:31:46 | Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 ver | |
| CVE-2026-77994 | None | 0.23% | 2 | 0 | 2026-08-24T09:33:52 | Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < | |
| CVE-2026-8173 | 5.3 | 0.21% | 2 | 0 | 2026-08-24T09:33:52 | The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from t | |
| CVE-2026-78211 | 9.8 | 1.54% | 2 | 0 | 2026-08-24T06:30:35 | 4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injec | |
| CVE-2026-78168 | 9.8 | 0.93% | 4 | 0 | 2026-08-24T03:31:14 | A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. | |
| CVE-2026-78169 | 9.9 | 0.44% | 4 | 0 | 2026-08-24T03:31:14 | A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This | |
| CVE-2026-78167 | 10.0 | 1.03% | 2 | 0 | 2026-08-24T03:31:14 | A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted eleme | |
| CVE-2026-78208 | 7.5 | 0.37% | 2 | 0 | 2026-08-24T03:31:14 | exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Wor | |
| CVE-2026-78207 | 9.4 | 0.44% | 2 | 0 | 2026-08-24T03:31:14 | exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in th | |
| CVE-2026-78209 | 8.2 | 0.29% | 2 | 0 | 2026-08-24T03:31:06 | exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, | |
| CVE-2026-18052 | 8.1 | 0.27% | 2 | 0 | 2026-08-23T18:32:50 | The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account bei | |
| CVE-2026-76793 | 8.1 | 0.35% | 2 | 0 | 2026-08-23T18:31:45 | The Firebase Authentication WordPress plugin before 1.7.1 does not require the e | |
| CVE-2026-76789 | 8.8 | 0.34% | 2 | 0 | 2026-08-23T18:31:44 | The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 d | |
| CVE-2026-77002 | 9.8 | 0.34% | 3 | 0 | 2026-08-23T18:31:44 | The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any s | |
| CVE-2026-77001 | 9.8 | 0.42% | 4 | 0 | 2026-08-23T18:31:44 | The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin t | |
| CVE-2026-77000 | 9.8 | 0.34% | 2 | 0 | 2026-08-23T16:16:38.360000 | The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a | |
| CVE-2026-8445 | 9.8 | 0.38% | 4 | 0 | 2026-08-23T15:33:12 | justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-si | |
| CVE-2026-4671 | 7.5 | 0.37% | 2 | 1 | 2026-08-23T15:33:12 | justhtml before 1.18.0 contains multiple low-severity denial-of-service issues i | |
| CVE-2026-5388 | 9.8 | 0.34% | 2 | 0 | 2026-08-23T15:33:04 | justhtml before 1.15.0 contains multiple security issues in URL sanitization hel | |
| CVE-2026-10053 | 8.5 | 0.72% | 3 | 1 | 2026-08-23T12:31:12 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 | |
| CVE-2026-13598 | None | 0.15% | 2 | 0 | 2026-08-23T06:30:28 | The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role | |
| CVE-2026-78136 | 7.8 | 0.19% | 6 | 0 | 2026-08-23T03:34:57 | chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. Th | |
| CVE-2026-16149 | 8.8 | 0.43% | 5 | 0 | 2026-08-23T00:30:30 | The Security Hardener plugin for WordPress is vulnerable to Missing Authorizatio | |
| CVE-2026-78122 | 7.4 | 0.32% | 3 | 1 | 2026-08-23T00:30:30 | docker-socket-proxy fails to properly gate read endpoints in the /containers Doc | |
| CVE-2026-0551 | 8.8 | 0.53% | 4 | 0 | 2026-08-23T00:30:30 | The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Obje | |
| CVE-2026-78050 | 9.9 | 0.57% | 4 | 0 | 2026-08-23T00:30:30 | A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is th | |
| CVE-2026-74671 | None | 0.18% | 1 | 0 | 2026-08-22T18:30:37 | In the Linux kernel, the following vulnerability has been resolved: ima: fix ou | |
| CVE-2026-4703 | 9.8 | 0.62% | 5 | 0 | 2026-08-22T18:30:25 | The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vuln | |
| CVE-2026-74708 | 0 | 0.17% | 1 | 0 | 2026-08-22T16:16:45.540000 | In the Linux kernel, the following vulnerability has been resolved: xsk: valida | |
| CVE-2026-62384 | 7.5 | 0.49% | 5 | 0 | 2026-08-22T15:31:11 | NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCo | |
| CVE-2026-71513 | 8.8 | 0.78% | 3 | 0 | 2026-08-22T15:31:11 | NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUn | |
| CVE-2026-62243 | 7.5 | 0.15% | 2 | 0 | 2026-08-22T15:31:11 | Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final an | |
| CVE-2026-2996 | 7.5 | 0.49% | 2 | 0 | 2026-08-22T15:31:11 | The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPres | |
| CVE-2026-62388 | 7.5 | 0.33% | 2 | 0 | 2026-08-22T15:31:11 | NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all | |
| CVE-2026-59808 | 8.8 | 0.34% | 2 | 0 | 2026-08-22T15:31:05 | AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability w | |
| CVE-2026-57998 | 7.8 | 0.14% | 2 | 0 | 2026-08-22T15:31:02 | better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm a | |
| CVE-2026-66393 | 7.5 | 0.34% | 4 | 0 | 2026-08-22T15:16:19.633000 | NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONT | |
| CVE-2026-59256 | 7.5 | 0.27% | 2 | 0 | 2026-08-22T13:16:38.817000 | WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerabili | |
| CVE-2026-77946 | 10.0 | 0.62% | 5 | 0 | 2026-08-22T12:30:34 | A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by thi | |
| CVE-2026-77945 | 7.4 | 1.28% | 1 | 0 | 2026-08-22T12:30:26 | A vulnerability was found in TRENDnet TEW-821DAP 2.2.01b05. Affected is an unkno | |
| CVE-2026-78003 | 9.8 | 0.57% | 4 | 0 | 2026-08-22T09:30:32 | The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Requ | |
| CVE-2026-12710 | 0 | 0.32% | 2 | 0 | 2026-08-22T09:16:53.340000 | A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud App | |
| CVE-2026-16835 | 9.6 | 0.23% | 2 | 0 | 2026-08-22T04:17:16.273000 | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 thr | |
| CVE-2026-19883 | 8.8 | 0.37% | 1 | 0 | 2026-08-22T03:31:33 | The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorize | |
| CVE-2026-63343 | 9.9 | 0.27% | 2 | 0 | 2026-08-21T22:16:42.227000 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, | |
| CVE-2026-53528 | 8.8 | 0.35% | 1 | 0 | 2026-08-21T22:16:39.290000 | LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a path traver | |
| CVE-2026-48755 | 9.9 | 0.44% | 2 | 0 | 2026-08-21T22:16:37.973000 | Incus is a system container and virtual machine manager. Prior to version 7.1.0, | |
| CVE-2026-33240 | 8.8 | 0.27% | 1 | 0 | 2026-08-21T22:16:36.863000 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there wa | |
| CVE-2026-31880 | 8.0 | 0.23% | 1 | 0 | 2026-08-21T22:16:36.430000 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is | |
| CVE-2026-31803 | 8.0 | 0.23% | 1 | 0 | 2026-08-21T22:16:36.303000 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, 3.2.3, t | |
| CVE-2026-76904 | 9.8 | 0.52% | 2 | 1 | 2026-08-21T21:17:06.143000 | GeoTools is an open source Java library that provides tools for geospatial data. | |
| CVE-2026-63135 | 8.2 | 0.25% | 1 | 0 | 2026-08-21T21:17:01.493000 | YOURLS is a self-hosted, customizable URL shortener written in PHP. From 1.5.1 u | |
| CVE-2026-54457 | 7.7 | 0.29% | 1 | 0 | 2026-08-21T21:17:00.267000 | TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observ | |
| CVE-2026-77415 | None | 0.51% | 1 | 0 | 2026-08-21T21:04:20 | Before JSONata `2.2.1` and `1.8.8` it was possible to execute arbitrary code wit | |
| CVE-2026-77414 | None | 0.35% | 1 | 0 | 2026-08-21T20:58:02 | Before JSONata `2.2.1` and `1.8.8` it was possible to execute arbitrary code wit | |
| CVE-2026-68508 | 7.8 | 0.25% | 1 | 0 | 2026-08-21T20:57:32 | ## Summary `hydra.utils.instantiate()` resolves and calls Python objects from c | |
| CVE-2026-77413 | None | 0.41% | 1 | 0 | 2026-08-21T20:57:09 | ## Impact Before JSONata `2.2.0` and `1.8.8` it was possible to execute arbitra | |
| CVE-2026-61539 | 10.0 | 0.66% | 2 | 0 | 2026-08-21T20:56:39 | ### Summary Xinference used Python's unsafe `eval()` function when parsing Llam | |
| CVE-2026-76905 | 7.5 | 0.35% | 2 | 0 | 2026-08-21T20:55:47 | ### Summary A nil-pointer dereference in `openapi3filter.ConvertErrors` lets an | |
| CVE-2026-64679 | 8.1 | 0.38% | 1 | 0 | 2026-08-21T20:55:33 | ### Summary Atlantis versions `>= 0.19.8` and `< 0.45.0` did not consistently va | |
| CVE-2026-63421 | 7.5 | 0.47% | 1 | 0 | 2026-08-21T20:55:12 | # Summary The value of `graphql.maxTake` can be bypassed by providing a negative | |
| CVE-2026-27490 | 7.5 | 0.31% | 1 | 0 | 2026-08-21T20:16:34.157000 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline i | |
| CVE-2026-63462 | 7.5 | 0.38% | 1 | 0 | 2026-08-21T19:17:31.927000 | Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, an | |
| CVE-2026-62675 | 8.8 | 0.45% | 1 | 0 | 2026-08-21T19:17:12.840000 | Omnigent is an open-source AI agent framework and meta-harness for orchestrating | |
| CVE-2026-41451 | 7.8 | 0.72% | 1 | 0 | 2026-08-21T18:35:08 | UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command in | |
| CVE-2026-41449 | 7.8 | 0.64% | 1 | 0 | 2026-08-21T18:35:08 | UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command in | |
| CVE-2026-17250 | None | 0.19% | 2 | 0 | 2026-08-21T18:35:07 | A stack-based buffer overflow vulnerability exists in the firmware update functi | |
| CVE-2026-39909 | 8.1 | 0.77% | 1 | 0 | 2026-08-21T18:35:07 | llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server | |
| CVE-2026-75932 | 8.6 | 0.40% | 1 | 0 | 2026-08-21T18:35:02 | Jet Admin allows an attacker to create a malicious app and connect it to a targe | |
| CVE-2026-69502 | 10.0 | 0.58% | 2 | 0 | 2026-08-21T18:35:01 | Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized | |
| CVE-2026-47827 | 7.5 | 1.16% | 2 | 0 | 2026-08-21T18:34:56 | Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote a | |
| CVE-2026-54789 | 7.5 | 0.39% | 1 | 0 | 2026-08-21T18:16:48.680000 | mod_auth_openidc is an OpenID Certified authentication and authorization module | |
| CVE-2026-41450 | 7.8 | 0.70% | 1 | 0 | 2026-08-21T18:16:48.257000 | UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command in | |
| CVE-2026-54796 | 7.2 | 2.36% | 2 | 0 | 2026-08-21T17:56:59.057000 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutra | |
| CVE-2026-48752 | 9.9 | 0.81% | 2 | 0 | 2026-08-21T17:16:31.087000 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, | |
| CVE-2026-22681 | 8.5 | 0.28% | 2 | 1 | 2026-08-21T17:16:30.683000 | OpenViking before 0.3.4 contains a server-side request forgery vulnerability tha | |
| CVE-2026-75501 | 0 | 0.37% | 2 | 0 | 2026-08-21T16:18:17.470000 | A vulnerability in the Calix EXOS firmware for the GS7 XGS (GS5239XG) residentia | |
| CVE-2026-55622 | 7.7 | 0.20% | 2 | 0 | 2026-08-21T16:17:19.623000 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, | |
| CVE-2026-48749 | 9.9 | 0.81% | 2 | 0 | 2026-08-21T16:17:17.413000 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, | |
| CVE-2026-77806 | 9.8 | 0.78% | 2 | 1 | 2026-08-21T15:32:18 | SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary | |
| CVE-2026-77812 | None | 0.06% | 1 | 0 | 2026-08-21T15:32:18 | DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over | |
| CVE-2026-77767 | 7.5 | 0.36% | 2 | 0 | 2026-08-21T12:30:41 | Reconmap's API applies a fallback authorization policy in apps/api/app/Program.c | |
| CVE-2026-77086 | 9.1 | 0.65% | 2 | 0 | 2026-08-21T12:16:36.273000 | SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar insta | |
| CVE-2026-69836 | 10.0 | 1.59% | 9 | 2 | 2026-08-21T00:31:31 | Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized a | |
| CVE-2026-72843 | 9.8 | 0.59% | 3 | 0 | 2026-08-21T00:31:24 | The customer update route in EverShop is declared with "access": "public" in pac | |
| CVE-2026-19586 | None | 5.04% | 2 | 0 | 2026-08-20T21:31:30 | A pre-authentication OS command injection vulnerability has been identified in O | |
| CVE-2026-64849 | 9.3 | 16.41% | 4 | 3 | template | 2026-08-20T19:16:57.867000 | MLflow is an open source AI engineering platform for agents, large language mode |
| CVE-2026-20231 | 9.9 | 0.50% | 2 | 0 | 2026-08-20T19:16:51.497000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-72530 | 9.0 | 1.83% | 4 | 0 | 2026-08-20T18:31:47 | A remote unauthorized attacker with network access via port 4307/TCP to the True | |
| CVE-2026-18264 | 8.8 | 1.24% | 2 | 0 | 2026-08-20T18:30:55 | NoMachine getstat Command Injection Remote Code Execution Vulnerability. This vu | |
| CVE-2026-72529 | 9.8 | 1.55% | 4 | 0 | 2026-08-20T18:30:43 | A remote unauthorized attacker with network access via port 4307/TCP to the True | |
| CVE-2026-19490 | None | 0.40% | 5 | 0 | 2026-08-20T15:34:03 | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: f | |
| CVE-2026-19976 | 6.6 | 2.05% | 2 | 0 | 2026-08-20T12:48:10.287000 | A security vulnerability has been detected in COMFAST CF-N1-S 2.6.0.1. Impacted | |
| CVE-2026-76565 | None | 0.32% | 2 | 1 | 2026-08-20T09:31:23 | Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter par | |
| CVE-2026-75616 | None | 1.91% | 2 | 1 | 2026-08-19T21:30:40 | An OS command injection vulnerability exists in the web management interface of | |
| CVE-2026-16687 | 9.6 | 0.21% | 2 | 0 | 2026-08-19T21:30:30 | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 thr | |
| CVE-2026-74480 | 9.8 | 0.53% | 2 | 0 | 2026-08-19T17:21:05.127000 | In the Linux kernel, the following vulnerability has been resolved: net: bridge | |
| CVE-2026-71961 | 8.8 | 3.05% | 2 | 0 | 2026-08-19T15:32:47 | Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection | |
| CVE-2026-54795 | 8.8 | 2.39% | 2 | 0 | 2026-08-19T15:32:33 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutra | |
| CVE-2026-65400 | 9.8 | 10.43% | 1 | 3 | 2026-08-19T04:17:34.547000 | An authentication issue was addressed with improved state management. This issue | |
| CVE-2026-33824 | 9.8 | 72.69% | 2 | 2 | 2026-08-19T04:16:58.560000 | Double free in Windows IKE Extension allows an unauthorized attacker to execute | |
| CVE-2026-18963 | 9.1 | 0.52% | 13 | 6 | template | 2026-08-19T03:31:21 | A flaw was found in the reset-credentials flow of the keycloak-services componen |
| CVE-2026-59310 | 9.8 | 45.88% | 1 | 2 | 2026-08-18T18:32:52 | VMware vCenter contains a directory traversal vulnerability in the Syslog server | |
| CVE-2026-55040 | 9.1 | 5.58% | 4 | 2 | 2026-08-18T18:32:50 | Weak authentication in Microsoft Office SharePoint allows an unauthorized attack | |
| CVE-2026-53365 | 5.5 | 0.17% | 2 | 2 | 2026-08-18T14:17:10.330000 | In the Linux kernel, the following vulnerability has been resolved: vsock/virti | |
| CVE-2026-15748 | 9.8 | 4.43% | 2 | 3 | 2026-08-18T06:31:55 | The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload | |
| CVE-2026-75094 | 9.1 | 2.11% | 2 | 0 | 2026-08-18T03:31:14 | A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_ | |
| CVE-2026-19478 | 9.4 | 6.00% | 3 | 6 | template | 2026-08-17T21:31:30 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 |
| CVE-2026-73522 | 7.5 | 2.36% | 2 | 0 | 2026-08-17T18:31:28 | COVESA Open1722 through 0.9.2 contains a stack buffer overflow vulnerability tha | |
| CVE-2026-19598 | 9.8 | 0.80% | 2 | 3 | 2026-08-15T18:31:24 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to | |
| CVE-2026-33818 | 7.5 | 0.57% | 1 | 0 | 2026-08-14T18:31:34 | Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing | |
| CVE-2026-61979 | 8.1 | 0.26% | 3 | 0 | 2026-08-13T15:34:46 | Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions | |
| CVE-2026-14669 | 8.8 | 0.53% | 2 | 1 | 2026-08-13T15:34:40 | Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosin | |
| CVE-2026-63520 | 8.1 | 2.93% | 6 | 0 | 2026-08-13T13:38:30.453000 | Improper input validation in Microsoft Office SharePoint allows an unauthorized | |
| CVE-2026-72898 | 10.0 | 79.22% | 2 | 6 | 2026-08-12T15:18:30.347000 | Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via t | |
| CVE-2026-68820 | 7.0 | 6.18% | 2 | 3 | 2026-08-11T21:33:01 | Use after free in Windows Ancillary Function Driver for WinSock allows an author | |
| CVE-2026-63077 | 9.8 | 84.73% | 2 | 4 | template | 2026-08-05T18:32:31 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe |
| CVE-2026-59309 | 9.8 | 8.18% | 1 | 0 | 2026-07-30T15:31:54 | VMware vCenter contains an authentication bypass vulnerability in the VMware Dir | |
| CVE-2026-15981 | 9.8 | 0.80% | 3 | 1 | 2026-07-23T21:31:09 | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authen | |
| CVE-2026-40575 | 9.1 | 0.48% | 2 | 0 | 2026-07-15T02:21:07.520000 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 provid | |
| CVE-2026-54071 | 7.8 | 0.14% | 1 | 0 | 2026-07-10T19:32:48 | ## Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer | |
| CVE-2026-52912 | 7.8 | 0.19% | 2 | 0 | 2026-07-08T15:13:08.090000 | In the Linux kernel, the following vulnerability has been resolved: netfilter: | |
| CVE-2026-12077 | 7.5 | 0.46% | 1 | 0 | 2026-06-29T20:17:32.607000 | The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via | |
| CVE-2026-42945 | 8.1 | 68.05% | 1 | 44 | 2026-06-27T06:30:25 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_mo | |
| CVE-2026-48769 | 9.9 | 0.44% | 2 | 0 | 2026-06-26T19:13:19 | ### Summary An arbitrary file write exists in the Incus client when a malicious | |
| CVE-2026-48753 | 9.9 | 0.71% | 2 | 0 | 2026-06-26T18:47:27 | ## Summary The S3 protocol upload endpoint is vulnerable to path traversal and | |
| CVE-2026-48751 | 9.9 | 0.70% | 2 | 0 | 2026-06-26T18:33:56 | ### Summary Instance snapshots ignore the `restricted.containers.lowlevel=block | |
| CVE-2026-48750 | 9.9 | 0.78% | 2 | 0 | 2026-06-26T18:32:53 | ### Summary The `record-output` parameter of the `/instances/$name/exec` endpoi | |
| CVE-2026-12569 | 9.8 | 40.59% | 1 | 1 | 2026-06-26T15:33:15 | A critical remote code execution (RCE) vulnerability has been reported in PTC Wi | |
| CVE-2020-5135 | 9.8 | 26.87% | 1 | 0 | 2026-06-17T03:20:57.470000 | A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Den | |
| CVE-2025-9615 | 3.3 | 0.16% | 4 | 0 | 2026-05-19T15:31:20 | A flaw was found in NetworkManager. The NetworkManager package allows access to | |
| CVE-2012-0158 | 8.8 | 99.98% | 1 | 2 | 2025-10-22T03:31:35 | The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX control | |
| CVE-2021-43226 | 7.8 | 3.07% | 1 | 1 | 2025-10-22T00:33:30 | Windows Common Log File System Driver Elevation of Privilege Vulnerability This | |
| CVE-2021-33045 | 9.8 | 99.56% | 2 | 3 | 2025-10-22T00:32:21 | The identity authentication bypass vulnerability found in some Dahua products du | |
| CVE-2021-33044 | 9.8 | 99.87% | 2 | 9 | template | 2025-10-22T00:32:20 | The identity authentication bypass vulnerability found in some Dahua products du |
| CVE-2026-76098 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-66897 | 0 | 0.62% | 2 | 0 | N/A | ||
| CVE-2026-78251 | 0 | 0.39% | 2 | 0 | N/A | ||
| CVE-2026-55621 | 0 | 0.20% | 2 | 0 | N/A | ||
| CVE-2026-39113 | 0 | 0.00% | 2 | 1 | N/A | ||
| CVE-2026-50538 | 0 | 0.32% | 2 | 0 | N/A | ||
| CVE-2026-63125 | 0 | 0.42% | 2 | 0 | N/A | ||
| CVE-2026-62941 | 0 | 0.25% | 2 | 0 | N/A | ||
| CVE-2026-62940 | 0 | 0.23% | 2 | 0 | N/A | ||
| CVE-2026-62867 | 0 | 0.29% | 2 | 0 | N/A | ||
| CVE-2026-55241 | 0 | 0.44% | 1 | 0 | N/A | ||
| CVE-2026-30826 | 0 | 0.23% | 1 | 0 | N/A | ||
| CVE-2026-30890 | 0 | 0.23% | 1 | 0 | N/A | ||
| CVE-2026-62316 | 0 | 0.32% | 1 | 0 | N/A | ||
| CVE-2026-62283 | 0 | 0.37% | 1 | 0 | N/A | ||
| CVE-2026-49849 | 0 | 0.70% | 2 | 0 | N/A | ||
| CVE-2026-34948 | 0 | 0.23% | 1 | 0 | N/A | ||
| CVE-2026-31936 | 0 | 0.27% | 1 | 0 | N/A | ||
| CVE-2026-34741 | 0 | 0.45% | 1 | 0 | N/A | ||
| CVE-2026-53527 | 0 | 0.24% | 1 | 0 | N/A | ||
| CVE-2026-77811 | 0 | 0.37% | 1 | 0 | N/A | ||
| CVE-2026-62677 | 0 | 0.45% | 1 | 0 | N/A | ||
| CVE-2026-27462 | 0 | 0.31% | 1 | 0 | N/A | ||
| CVE-2026-30866 | 0 | 0.27% | 1 | 0 | N/A | ||
| CVE-2026-77810 | 0 | 0.35% | 1 | 0 | N/A | ||
| CVE-2026-54682 | 0 | 0.14% | 1 | 0 | N/A | ||
| CVE-2026-62674 | 0 | 0.34% | 1 | 0 | N/A | ||
| CVE-2026-71862 | 0 | 0.35% | 1 | 0 | N/A |
updated 2026-08-25T02:16:52.030000
2 posts
CVE-2026-78676 | GitPython <3.1.59 has a CRITICAL argument injection flaw: multi-line git-config values can become active directives, enabling arbitrary code execution via git hooks. Patch status unknown — avoid untrusted configs. https://radar.offseq.com/threat/cve-2026-78676-improper-neutralization-of-argument-delimiters-in-a-command-argument-injection-in-98aef85f24190fbe #OffSeq #CVE202678676 #git #infosec
##CVE-2026-78676 | GitPython <3.1.59 has a CRITICAL argument injection flaw: multi-line git-config values can become active directives, enabling arbitrary code execution via git hooks. Patch status unknown — avoid untrusted configs. https://radar.offseq.com/threat/cve-2026-78676-improper-neutralization-of-argument-delimiters-in-a-command-argument-injection-in-98aef85f24190fbe #OffSeq #CVE202678676 #git #infosec
##updated 2026-08-25T00:30:37
2 posts
CVE-2026-32556 - Unauthenticated XSS in Boost <= 2.0.4. CVSS 7.1. Currently unpatched. Audit systems and mitigate risk immediately. #CVE #XSS #infosec
##CVE-2026-32556 - Unauthenticated XSS in Boost <= 2.0.4. CVSS 7.1. Currently unpatched. Audit systems and mitigate risk immediately. #CVE #XSS #infosec
##updated 2026-08-25T00:30:37
4 posts
CVE-2026-78267 (CRITICAL, CVSS 9.8): Cozmoslabs TranslatePress <=3.3.2 is vulnerable to unauthenticated privilege escalation (CWE-266). No patch yet — monitor vendor advisories for updates. https://radar.offseq.com/threat/cve-2026-78267-cwe-266-incorrect-privilege-assignment-in-cozmoslabs-translatepress-ba0caba45d17d814 #OffSeq #WordPress #Vuln #PrivilegeEscalation
##🔴 CVE-2026-78267 - Critical (9.8)
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78267/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-78267 (CRITICAL, CVSS 9.8): Cozmoslabs TranslatePress <=3.3.2 is vulnerable to unauthenticated privilege escalation (CWE-266). No patch yet — monitor vendor advisories for updates. https://radar.offseq.com/threat/cve-2026-78267-cwe-266-incorrect-privilege-assignment-in-cozmoslabs-translatepress-ba0caba45d17d814 #OffSeq #WordPress #Vuln #PrivilegeEscalation
##🔴 CVE-2026-78267 - Critical (9.8)
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78267/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T00:30:37
2 posts
🟠 CVE-2026-78268 - High (7.5)
Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78268/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-78268 - High (7.5)
Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78268/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T00:30:37
2 posts
🟠 CVE-2026-78284 - High (8.6)
Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78284/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-78284 - High (8.6)
Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78284/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T22:17:20.407000
4 posts
CRITICAL CVE-2026-78265: Nexcess The Events Calendar <=6.17.2 has unauthenticated PHP Object Injection (CWE-502). Full system compromise possible. No patch yet — remove or disable plugin for now. https://radar.offseq.com/threat/cve-2026-78265-cwe-502-deserialization-of-untrusted-data-in-nexcess-the-events-calendar-3dd3af18547313e0 #OffSeq #WordPress #Infosec #CVE2026_78265
##🔴 CVE-2026-78265 - Critical (9.8)
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78265/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CRITICAL CVE-2026-78265: Nexcess The Events Calendar <=6.17.2 has unauthenticated PHP Object Injection (CWE-502). Full system compromise possible. No patch yet — remove or disable plugin for now. https://radar.offseq.com/threat/cve-2026-78265-cwe-502-deserialization-of-untrusted-data-in-nexcess-the-events-calendar-3dd3af18547313e0 #OffSeq #WordPress #Infosec #CVE2026_78265
##🔴 CVE-2026-78265 - Critical (9.8)
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78265/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T21:34:43
2 posts
i uSe lInUx bEcAuSe iT'S SeCuRe.
https://access.redhat.com/security/cve/cve-2026-19685
##NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.
i uSe lInUx bEcAuSe iT'S SeCuRe.
https://access.redhat.com/security/cve/cve-2026-19685
##NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.
updated 2026-08-24T21:33:53
2 posts
🟠 CVE-2026-19568 - High (7.8)
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19568/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19568 - High (7.8)
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19568/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T21:33:53
2 posts
🟠 CVE-2026-7455 - High (7.8)
A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the conte...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-7455/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-7455 - High (7.8)
A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the conte...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-7455/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T21:33:52
2 posts
🟠 CVE-2026-61419 - High (7.8)
Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61419/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-61419 - High (7.8)
Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61419/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T21:33:46
2 posts
🟠 CVE-2026-16783 - High (7.8)
A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the conte...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16783/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-16783 - High (7.8)
A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the conte...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16783/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T21:33:38
2 posts
🟠 CVE-2026-71366 - High (7.7)
A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template URLs as direct HTTP request targets without valid...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71366/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-71366 - High (7.7)
A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template URLs as direct HTTP request targets without valid...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71366/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T21:17:48.150000
2 posts
🟠 CVE-2026-77567 - High (8.1)
Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when recovery c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77567/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-77567 - High (8.1)
Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when recovery c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77567/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T20:17:23.490000
2 posts
TP-Link patched an unauthenticated OS command injection flaw (CVE-2026-9254) and other risks like CVE-2026-16348 and CVE-2026-78541 in Archer routers.
##TP-Link patched an unauthenticated OS command injection flaw (CVE-2026-9254) and other risks like CVE-2026-16348 and CVE-2026-78541 in Archer routers.
##updated 2026-08-24T20:16:55.243000
4 posts
CVE-2026-63310 - MITM package injection flaw in NLTK downloader module. CVSS 7.1. Update NLTK to 3.9.3+ immediately. #CVE #Python #infosec
##CVE-2026-63310: NLTK <3.9.3 has a CRITICAL flaw where package integrity isn't checked post-download in the downloader module. Exposes users to MITM & DNS poisoning attacks. Upgrade to 3.9.3+ or avoid insecure networks. https://radar.offseq.com/threat/nltk-before-393-fails-to-verify-file-integrity-after-downloading-packages-and-before-extraction-in-the-f6492d4a6dda17c2 #OffSeq #NLTK #CVE202663310 #infosec
##CVE-2026-63310 - MITM package injection flaw in NLTK downloader module. CVSS 7.1. Update NLTK to 3.9.3+ immediately. #CVE #Python #infosec
##CVE-2026-63310: NLTK <3.9.3 has a CRITICAL flaw where package integrity isn't checked post-download in the downloader module. Exposes users to MITM & DNS poisoning attacks. Upgrade to 3.9.3+ or avoid insecure networks. https://radar.offseq.com/threat/nltk-before-393-fails-to-verify-file-integrity-after-downloading-packages-and-before-extraction-in-the-f6492d4a6dda17c2 #OffSeq #NLTK #CVE202663310 #infosec
##updated 2026-08-24T20:16:52.567000
1 posts
🟠 CVE-2026-61824 - High (8.2)
Defuddle cleans up HTML pages. Prior to 0.19.1, site extractors interpolate page-derived image alt and src values, og:image values, and video descriptions into HTML strings without context-appropriate escaping, and buildExtractorResponse() returns...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61824/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T20:16:51.410000
2 posts
🟠 CVE-2026-60084 - High (8.7)
SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTemplate endpoint that accepts an unvalidated path parameter passed directly to os.RemoveAll. Authenticated admin attackers can supply absolute...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-60084/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-60084 - High (8.7)
SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTemplate endpoint that accepts an unvalidated path parameter passed directly to os.RemoveAll. Authenticated admin attackers can supply absolute...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-60084/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T20:16:42.277000
2 posts
1 repos
Metal Gear Online 3 RCE vulnerability CVE-2026-19874 fixed. Update the game to prevent attackers from executing remote code on your system.
#MetalGearOnline3 #CyberSecurity #Vulnerability #CVE202619874
##Metal Gear Online 3 RCE vulnerability CVE-2026-19874 fixed. Update the game to prevent attackers from executing remote code on your system.
#MetalGearOnline3 #CyberSecurity #Vulnerability #CVE202619874
##updated 2026-08-24T19:58:10.590000
6 posts
9 repos
https://github.com/gregk4sec/CVE-2026-21962-o
https://github.com/boroeurnprach/Ashwesker-CVE-2026-21962
https://github.com/samael0x4/CVE-2026-21962
https://github.com/gregk4sec/cve-2026-21962
https://github.com/gglessner/cve_2026_21962_scanner
https://github.com/naozibuhao/CVE-2026-21962_Java_GUI_Exploit_Tool
CISA warned that the CVE-2026-21962 Oracle flaw with a CVSS 10 score is actively exploited in the wild. Patch Oracle Fusion Middleware systems now.
##🚨 [CISA-2026:0824] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-21962 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-21962)
- Name: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Oracle
- Product: HTTP Server and Oracle Weblogic Server Proxy Plug-in
- Notes: https://www.oracle.com/security-alerts/cpujan2026.html ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-21962
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260824 #cisa20260824 #cve_2026_21962 #cve202621962
##CVE ID: CVE-2026-21962
Vendor: Oracle
Product: HTTP Server and Oracle Weblogic Server Proxy Plug-in
Date Added: 2026-08-24
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-21962
CISA warned that the CVE-2026-21962 Oracle flaw with a CVSS 10 score is actively exploited in the wild. Patch Oracle Fusion Middleware systems now.
##🚨 [CISA-2026:0824] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-21962 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-21962)
- Name: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Oracle
- Product: HTTP Server and Oracle Weblogic Server Proxy Plug-in
- Notes: https://www.oracle.com/security-alerts/cpujan2026.html ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-21962
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260824 #cisa20260824 #cve_2026_21962 #cve202621962
##CVE ID: CVE-2026-21962
Vendor: Oracle
Product: HTTP Server and Oracle Weblogic Server Proxy Plug-in
Date Added: 2026-08-24
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-21962
updated 2026-08-24T19:17:04.697000
4 posts
CVE-2026-7808 | justhtml <1.16.0 faces CRITICAL XSS risk via HTML sanitization bypass in advanced use cases. Upgrade to 1.16.0+ to fix. Impacts apps with custom/mutated policies. Details: https://radar.offseq.com/threat/cve-2026-7808-improper-input-validation-in-emilstenstrom-justhtml-86dd54d29e0645e9 #OffSeq #CVE20267808 #infosec #XSS
##🔴 CVE-2026-7808 - Critical (9.8)
justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scripting. The issues primarily affect advanced usa...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-7808/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-7808 | justhtml <1.16.0 faces CRITICAL XSS risk via HTML sanitization bypass in advanced use cases. Upgrade to 1.16.0+ to fix. Impacts apps with custom/mutated policies. Details: https://radar.offseq.com/threat/cve-2026-7808-improper-input-validation-in-emilstenstrom-justhtml-86dd54d29e0645e9 #OffSeq #CVE20267808 #infosec #XSS
##🔴 CVE-2026-7808 - Critical (9.8)
justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scripting. The issues primarily affect advanced usa...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-7808/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T19:16:58.433000
2 posts
1 repos
🔴 CVE-2026-76070 - Critical (9.8)
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base64-encoded password to the login handler in /bi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76070/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-76070 - Critical (9.8)
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base64-encoded password to the login handler in /bi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76070/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T19:16:43.757000
3 posts
CVE-2026-68766 - Code execution in hashcat. Command-line option injection via restore files enables arbitrary file writes. CVSS 7.8. Avoid untrusted restore files. #CVE #hashcat #infosec
##🟠 CVE-2026-68766 - High (7.8)
hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and --potfile-path. Attackers can craft restore files with malicious options to append attacker-contr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68766/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-68766 - High (7.8)
hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and --potfile-path. Attackers can craft restore files with malicious options to append attacker-contr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68766/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T19:16:42.383000
4 posts
CVE-2026-63312 - Arbitrary local file read in NLTK StreamBackedCorpusView bypasses pathsec. CVSS 7.5. Exposes sensitive system files. Update to NLTK 3.10.0+. #CVE #Python #infosec
##🟠 CVE-2026-63312 - High (7.5)
NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63312/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-63312 - Arbitrary local file read in NLTK StreamBackedCorpusView bypasses pathsec. CVSS 7.5. Exposes sensitive system files. Update to NLTK 3.10.0+. #CVE #Python #infosec
##🟠 CVE-2026-63312 - High (7.5)
NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63312/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T18:32:04
2 posts
🔴 CVE-2026-76835 - Critical (9.1)
OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/ut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76835/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-76835 - Critical (9.1)
OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/ut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76835/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T18:32:04
2 posts
🟠 CVE-2026-76838 - High (8.5)
Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backend/app/Validators/Rules/NoInternalUrlRule.php resolves the hostname with gethostbyname() and rejects private and reserved ranges...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76838/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-76838 - High (8.5)
Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backend/app/Validators/Rules/NoInternalUrlRule.php resolves the hostname with gethostbyname() and rejects private and reserved ranges...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76838/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T18:31:59
2 posts
1 repos
🔴 CVE-2026-76071 - Critical (9.8)
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod action in...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76071/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-76071 - Critical (9.8)
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod action in...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76071/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T18:31:57
2 posts
🟠 CVE-2026-76073 - High (8.8)
Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_studio/tasks/api.py declares queryset = Annotation.objects.all() and provides no get_queryset override, so the default lookup ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76073/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-76073 - High (8.8)
Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_studio/tasks/api.py declares queryset = Annotation.objects.all() and provides no get_queryset override, so the default lookup ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76073/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T18:17:35.520000
2 posts
🟠 CVE-2026-9769 - High (7.5)
justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish() unconditionally calls _populate_selectedcontent(), which recursively traverses the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9769/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-9769 - High (7.5)
justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish() unconditionally calls _populate_selectedcontent(), which recursively traverses the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9769/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T18:17:34.973000
2 posts
1 repos
TP-Link patched an unauthenticated OS command injection flaw (CVE-2026-9254) and other risks like CVE-2026-16348 and CVE-2026-78541 in Archer routers.
##TP-Link patched an unauthenticated OS command injection flaw (CVE-2026-9254) and other risks like CVE-2026-16348 and CVE-2026-78541 in Archer routers.
##updated 2026-08-24T18:17:27.187000
2 posts
🟠 CVE-2026-78170 - High (8.8)
A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. Executing a manipulation of the argument ssid can lead to buffer overflow. The attack may be performed from...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78170/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-78170 - High (8.8)
A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. Executing a manipulation of the argument ssid can lead to buffer overflow. The attack may be performed from...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78170/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T18:16:59.710000
2 posts
1 repos
TP-Link patched an unauthenticated OS command injection flaw (CVE-2026-9254) and other risks like CVE-2026-16348 and CVE-2026-78541 in Archer routers.
##TP-Link patched an unauthenticated OS command injection flaw (CVE-2026-9254) and other risks like CVE-2026-16348 and CVE-2026-78541 in Archer routers.
##updated 2026-08-24T16:41:13.950000
2 posts
🔴 CVE-2026-77683 - Critical (9.9)
A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method=SET§ion=ntp_timezone. The manipulation of the argument timestr results in command injection. ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77683/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-77683 - Critical (9.9)
A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method=SET§ion=ntp_timezone. The manipulation of the argument timestr results in command injection. ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77683/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T16:37:45.780000
1 posts
🟠 CVE-2026-77234 - High (8.8)
Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context. To remediate this issue, users should upgrade to version 11.3.1 or later.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77234/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T15:31:57
2 posts
https://nvd.nist.gov/vuln/detail/CVE-2026-59568
##Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.
https://nvd.nist.gov/vuln/detail/CVE-2026-59568
##Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.
updated 2026-08-24T15:31:57
2 posts
CVE-2026-77995 (CRITICAL, CVSS 10): miniOrange OAuth Client for Joomla (v1.0.0 – 3.1.9) allows arbitrary account takeover via cookie manipulation. Patch to 3.2.0+ required. https://radar.offseq.com/threat/cve-2026-77995-cwe-639-authorization-bypass-through-user-controlled-key-in-miniorangecom-miniorange-0e8da876ce4c7e51 #OffSeq #Joomla #Vuln #OAuth
##CVE-2026-77995 (CRITICAL, CVSS 10): miniOrange OAuth Client for Joomla (v1.0.0 – 3.1.9) allows arbitrary account takeover via cookie manipulation. Patch to 3.2.0+ required. https://radar.offseq.com/threat/cve-2026-77995-cwe-639-authorization-bypass-through-user-controlled-key-in-miniorangecom-miniorange-0e8da876ce4c7e51 #OffSeq #Joomla #Vuln #OAuth
##updated 2026-08-24T14:17:03.663000
4 posts
🔴 CVE-2026-78155 - Critical (9.9)
privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78155/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-78155: OnGres StackGres operator has a critical (CVSS 9.9) priv esc vuln via untrusted search path (CWE-426). No patch yet. Restrict tenant privileges & monitor for escalation attempts. More info: https://radar.offseq.com/threat/cve-2026-78155-cwe-426-untrusted-search-path-in-ongres-stackgres-7d9e77e1189aa5d6 #OffSeq #Vulnerability #PrivilegeEscalation
##🔴 CVE-2026-78155 - Critical (9.9)
privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78155/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-78155: OnGres StackGres operator has a critical (CVSS 9.9) priv esc vuln via untrusted search path (CWE-426). No patch yet. Restrict tenant privileges & monitor for escalation attempts. More info: https://radar.offseq.com/threat/cve-2026-78155-cwe-426-untrusted-search-path-in-ongres-stackgres-7d9e77e1189aa5d6 #OffSeq #Vulnerability #PrivilegeEscalation
##updated 2026-08-24T14:16:55.217000
3 posts
CVE-2026-47895 - Double-Free vulnerability in strongSwan EAP identity parsing. CVSS 7.5. Update to version 6.0.7 immediately. #CVE #strongSwan #infosec
##🟠 CVE-2026-47895 - High (7.5)
In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47895/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-47895 - High (7.5)
In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47895/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T13:19:17.577000
14 posts
2 repos
CISA Sounds the Alarm: Actively Exploited Zimbra Vulnerability Puts Mail Servers at Risk + Video
A Critical Warning for Zimbra Administrators A serious cybersecurity warning has emerged for organizations running Zimbra Collaboration Suite, as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-73570 to its Known Exploited Vulnerabilities catalog. The vulnerability is reportedly being exploited in the wild, turning what might otherwise be…
##⚠️ CRITICAL: CISA orders urgent patching of actively exploited Zimbra flaw
Zimbra Collaboration Suite (ZCS) has a critical unauthenticated RCE vulnerability (CVE-2026-73570) that is actively exploited in the wild. Any organization running ZCS is at immediate risk of full system compromise. CISA has mandated U.S. government agencies patch within three days.
🤖 AI generated summary
##CVE-2026-73570 is an OS command injection in Zimbra Collaboration Suite being actively exploited. CISA added it to the KEV catalog with a 72-hour remediation window. This class of flaw allows full remote code execution, making it one of the most severe issues in any mail and collaboration platform.
#Zimbra #CVE202673570 #CISA #KnownExploitedVulnerabilities
https://cyberworldops.eu/en/zimbra-under-attack-command-injection-exploited-in-the-wild-cisa
##CVE-2026-73570: Actively exploited CRITICAL RCE in Zimbra Collaboration Suite <10.1.20 via SNMP command injection. Patch to 10.1.20 now. Watch for suspicious service restarts & files in /opt/zimbra/jetty/webapps/. Details: https://radar.offseq.com/threat/cisa-orders-urgent-patching-of-actively-exploited-zimbra-flaw-b89f77b410f3bb5f #OffSeq #Zimbra #Infosec #RCE
##CISA Mandates Emergency Patching for Exploited Zimbra Flaw
A critical Zimbra flaw, CVE-2026-73570, allows hackers to inject malicious code, and the CISA is mandating emergency patching to prevent devastating attacks - don't wait, get protected now!
#Cve202673570 #Zimbra #CommandInjection #RemoteCodeExecution #Snmp
##Geopolitical tensions rise as the US escalates economic pressure on Iran, which labels new sanctions as a "declaration of war". Ukraine faces critical missile shortages amid intensified Russian strikes. In technology, major investments continue in AI infrastructure, with Google backing Marvell's custom AI chips. Cybersecurity sees CISA adding a critical Zimbra vulnerability (CVE-2026-73570) to its KEV catalog and new banking Trojans actively exploited globally.
##Critical Zimbra Vulnerability Enters CISA’s KEV Catalog as Attackers Exploit Unauthenticated Remote Code Execution + Video
A New Warning for Zimbra Administrators A serious security warning is now hanging over organizations running Zimbra Collaboration Suite (ZCS). The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-73570 to its Known Exploited Vulnerabilities (KEV) catalog after Poland’s national cybersecurity response team confirmed…
##⚠️ CRITICAL: CISA orders urgent patching of actively exploited Zimbra flaw
Zimbra Collaboration Suite (ZCS) has a critical unauthenticated RCE vulnerability (CVE-2026-73570) that is actively exploited in the wild. Any organization running ZCS is at immediate risk of full system compromise. CISA has mandated U.S. government agencies patch within three days.
🤖 AI generated summary
##CVE-2026-73570 is an OS command injection in Zimbra Collaboration Suite being actively exploited. CISA added it to the KEV catalog with a 72-hour remediation window. This class of flaw allows full remote code execution, making it one of the most severe issues in any mail and collaboration platform.
#Zimbra #CVE202673570 #CISA #KnownExploitedVulnerabilities
https://cyberworldops.eu/en/zimbra-under-attack-command-injection-exploited-in-the-wild-cisa
##CVE-2026-73570: Actively exploited CRITICAL RCE in Zimbra Collaboration Suite <10.1.20 via SNMP command injection. Patch to 10.1.20 now. Watch for suspicious service restarts & files in /opt/zimbra/jetty/webapps/. Details: https://radar.offseq.com/threat/cisa-orders-urgent-patching-of-actively-exploited-zimbra-flaw-b89f77b410f3bb5f #OffSeq #Zimbra #Infosec #RCE
##Geopolitical tensions rise as the US escalates economic pressure on Iran, which labels new sanctions as a "declaration of war". Ukraine faces critical missile shortages amid intensified Russian strikes. In technology, major investments continue in AI infrastructure, with Google backing Marvell's custom AI chips. Cybersecurity sees CISA adding a critical Zimbra vulnerability (CVE-2026-73570) to its KEV catalog and new banking Trojans actively exploited globally.
##🏆 New Achievement! Patch Notes: Server Owned by Community!
CHANGELOG v-Oh-No: ADDED — unauthenticated remote attackers executing arbitrary OS commands as the Zimbra user. ADDED — full control of your enterprise email server, courtesy of CVE-2026-73570. FIXED (by the developers, on July 20, in version 10.1.20) — the exact hole threat actors are currently crawling through, per Poland's CERT Polska. KNOWN ISSUE — you haven't patched yet.
The fix shipped over a month ago. (1/2)
##🚨 [CISA-2026:0821] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-69836 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-69836)
- Name: Microsoft Entra ID Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Entra ID
- Notes: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-69836
⚠️ CVE-2026-73570 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73570)
- Name: Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Synacor
- Product: Zimbra Collaboration Suite (ZCS)
- Notes: https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories ; https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-73570
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260821 #cisa20260821 #cve_2026_69836 #cve_2026_73570 #cve202669836 #cve202673570
##CVE ID: CVE-2026-73570
Vendor: Synacor
Product: Zimbra Collaboration Suite (ZCS)
Date Added: 2026-08-21
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73570
updated 2026-08-24T12:31:46
1 posts
CVE-2026-28171 - Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7. CVSS 8.6. Currently unpatched. Deactivate plugin now. #CVE #WordPress #infosec
##updated 2026-08-24T09:33:52
2 posts
CVE-2026-77994: CRITICAL SQL injection in Joomla Page Builder CK (v1.0.0-3.6.4). Unauthenticated remote SQL execution possible. No official fix yet — disable/remove vulnerable versions. CVSS 9.3. https://radar.offseq.com/threat/cve-2026-77994-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-d508026cac86e490 #OffSeq #Joomla #SQLInjection #Infosec
##CVE-2026-77994: CRITICAL SQL injection in Joomla Page Builder CK (v1.0.0-3.6.4). Unauthenticated remote SQL execution possible. No official fix yet — disable/remove vulnerable versions. CVSS 9.3. https://radar.offseq.com/threat/cve-2026-77994-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-d508026cac86e490 #OffSeq #Joomla #SQLInjection #Infosec
##updated 2026-08-24T09:33:52
2 posts
#OT #Advisory VDE-2026-061
Vulnerability in 'Copy learned MAC Addresses' function enables MAC Spoofing on Xelity Switches
An information disclosure vulnerability in the web GUI of Murrelektronik Xelity switches causes MAC addresses from the device's MAC address table to be written into a server-side log that is exposed via the device's web interface to unauthenticated users. The leak is triggered when an authenticated administrator invokes the 'Copy learned MAC Addresses' function, which causes a syslog error that inserts the affected MAC addresses into the log output. Once the error has been triggered, any unauthenticated attacker with network access to the web interface can retrieve the leaked MAC addresses via common browser developer tools. The vulnerable functionality was introduced in version 2.1.0 and is fixed in version 2.1.1.
#CVE CVE-2026-8173
https://certvde.com/en/advisories/vde-2026-061/
#CSAF https://murrelektronik.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-061.json
###OT #Advisory VDE-2026-061
Vulnerability in 'Copy learned MAC Addresses' function enables MAC Spoofing on Xelity Switches
An information disclosure vulnerability in the web GUI of Murrelektronik Xelity switches causes MAC addresses from the device's MAC address table to be written into a server-side log that is exposed via the device's web interface to unauthenticated users. The leak is triggered when an authenticated administrator invokes the 'Copy learned MAC Addresses' function, which causes a syslog error that inserts the affected MAC addresses into the log output. Once the error has been triggered, any unauthenticated attacker with network access to the web interface can retrieve the leaked MAC addresses via common browser developer tools. The vulnerable functionality was introduced in version 2.1.0 and is fixed in version 2.1.1.
#CVE CVE-2026-8173
https://certvde.com/en/advisories/vde-2026-061/
#CSAF https://murrelektronik.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-061.json
##updated 2026-08-24T06:30:35
2 posts
4MOSAn GCB Doctor faces a CRITICAL OS Command Injection (CVE-2026-78211, CVSS 9.8). Unauthenticated attackers can execute arbitrary system commands via ADOdb test page parameter. No patch — restrict access & monitor closely. https://radar.offseq.com/threat/cve-2026-78211-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-91902877a695e366 #OffSeq #CVE202678211 #Vuln #BlueTeam
##4MOSAn GCB Doctor faces a CRITICAL OS Command Injection (CVE-2026-78211, CVSS 9.8). Unauthenticated attackers can execute arbitrary system commands via ADOdb test page parameter. No patch — restrict access & monitor closely. https://radar.offseq.com/threat/cve-2026-78211-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-91902877a695e366 #OffSeq #CVE202678211 #Vuln #BlueTeam
##updated 2026-08-24T03:31:14
4 posts
CRITICAL vuln (CVE-2026-78168) in EFM ipTIME T24000M ≤14.20.0: improper authentication in httpcon_check_session_url enables remote exploit. Public exploit disclosed, no vendor fix. Review access controls now. https://radar.offseq.com/threat/cve-2026-78168-improper-authentication-in-efm-iptime-t24000m-bfa2e716a3fcf0b6 #OffSeq #CVE #IoTSecurity #Exploit
##🔴 CVE-2026-78168 - Critical (9.8)
A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such manipulation leads to improper authentication. The attack can be ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78168/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CRITICAL vuln (CVE-2026-78168) in EFM ipTIME T24000M ≤14.20.0: improper authentication in httpcon_check_session_url enables remote exploit. Public exploit disclosed, no vendor fix. Review access controls now. https://radar.offseq.com/threat/cve-2026-78168-improper-authentication-in-efm-iptime-t24000m-bfa2e716a3fcf0b6 #OffSeq #CVE #IoTSecurity #Exploit
##🔴 CVE-2026-78168 - Critical (9.8)
A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such manipulation leads to improper authentication. The attack can be ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78168/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T03:31:14
4 posts
🔴 CVE-2026-78169 - Critical (9.9)
A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request Handler. Performing a manipulation of the argument Profile resul...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78169/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CRITICAL: Stack-based buffer overflow (CVE-2026-78169) in UTT HiPER 1250GW v3.2.7-210907-180535. Public exploit code available — no patch yet. Restrict device access & monitor /goform/aspRemoteApConfTempSend traffic. https://radar.offseq.com/threat/cve-2026-78169-stack-based-buffer-overflow-in-utt-hiper-1250gw-b9697a669a575a95 #OffSeq #CVE #Infosec #IoT
##🔴 CVE-2026-78169 - Critical (9.9)
A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request Handler. Performing a manipulation of the argument Profile resul...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78169/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CRITICAL: Stack-based buffer overflow (CVE-2026-78169) in UTT HiPER 1250GW v3.2.7-210907-180535. Public exploit code available — no patch yet. Restrict device access & monitor /goform/aspRemoteApConfTempSend traffic. https://radar.offseq.com/threat/cve-2026-78169-stack-based-buffer-overflow-in-utt-hiper-1250gw-b9697a669a575a95 #OffSeq #CVE #Infosec #IoT
##updated 2026-08-24T03:31:14
2 posts
🔴 CVE-2026-78167 - Critical (10)
A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper authentication. Remote exploitation of the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78167/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-78167 - Critical (10)
A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper authentication. Remote exploitation of the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78167/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T03:31:14
2 posts
🟠 CVE-2026-78208 - High (7.5)
exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths. Attackers can supply arbitrary file paths to read any file accessible to the Node.js process and embed it ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78208/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-78208 - High (7.5)
exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths. Attackers can supply arbitrary file paths to read any file accessible to the Node.js process and embed it ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78208/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T03:31:14
2 posts
🔴 CVE-2026-78207 - Critical (9.4)
exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed JSON with a malicious __proto_...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78207/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-78207 - Critical (9.4)
exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed JSON with a malicious __proto_...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78207/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T03:31:06
2 posts
🟠 CVE-2026-78209 - High (8.2)
exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence exported cell values can inject formulas that execute when the CSV file is opened ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78209/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-78209 - High (8.2)
exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence exported cell values can inject formulas that execute when the CSV file is opened ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78209/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-23T18:32:50
2 posts
🟠 CVE-2026-18052 - High (8.1)
The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who obtain such a link to gain...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18052/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18052 - High (8.1)
The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who obtain such a link to gain...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18052/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-23T18:31:45
2 posts
🟠 CVE-2026-76793 - High (8.1)
The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to log in as...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76793/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-76793 - High (8.1)
The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to log in as...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76793/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-23T18:31:44
2 posts
🟠 CVE-2026-76789 - High (8.8)
The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and does not escape a stored setting before outputting it, allowing unauthenticated users t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76789/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-76789 - High (8.8)
The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and does not escape a stored setting before outputting it, allowing unauthenticated users t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76789/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-23T18:31:44
3 posts
🔴 CVE-2026-77002 - Critical (9.8)
The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any registered account, including administrators.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77002/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-77002 - Critical (9.8)
The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any registered account, including administrators.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77002/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CRITICAL: CVE-2026-77002 in SmilePass Selfie Login WP plugin (≤1.0.2) allows full account takeover — no auth needed. Remove/disable plugin until patched. Details: https://radar.offseq.com/threat/cve-2026-77002-cwe-287-improper-authentication-in-smilepass-selfie-login-581c897a80f66e83 #OffSeq #WordPress #Vuln #CVE202677002
##updated 2026-08-23T18:31:44
4 posts
🔴 CVE-2026-77001 - Critical (9.8)
The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77001/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-77001: CRITICAL vuln in Social Login & Sharing buttons with Analytics By SoClever (≤1.2.0). No auth checks — attackers can hijack any user session, including admin. Remove/disable plugin pending fix. https://radar.offseq.com/threat/cve-2026-77001-cwe-287-improper-authentication-in-social-login-sharing-buttons-with-analytics-by-c2f4b63e61e43745 #OffSeq #WordPress #CVE202677001 #Vulnerability
##🔴 CVE-2026-77001 - Critical (9.8)
The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77001/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-77001: CRITICAL vuln in Social Login & Sharing buttons with Analytics By SoClever (≤1.2.0). No auth checks — attackers can hijack any user session, including admin. Remove/disable plugin pending fix. https://radar.offseq.com/threat/cve-2026-77001-cwe-287-improper-authentication-in-social-login-sharing-buttons-with-analytics-by-c2f4b63e61e43745 #OffSeq #WordPress #CVE202677001 #Vulnerability
##updated 2026-08-23T16:16:38.360000
2 posts
🔴 CVE-2026-77000 - Critical (9.8)
The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, incl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77000/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-77000 - Critical (9.8)
The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, incl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77000/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-23T15:33:12
4 posts
CVE-2026-8445: EmilStenstrom justhtml <=1.11.0 suffers CRITICAL XSS due to improper escaping in Markdown output. Remote attackers can inject scripts. Update to v1.12.0 now. https://radar.offseq.com/threat/cve-2026-8445-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-in-42aabed1c30bf24b #OffSeq #XSS #AppSec #CVE20268445
##🔴 CVE-2026-8445 - Critical (9.8)
justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to Markdown via to_markdown(). While a small set of Markdown metacharacters ar...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8445/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-8445: EmilStenstrom justhtml <=1.11.0 suffers CRITICAL XSS due to improper escaping in Markdown output. Remote attackers can inject scripts. Update to v1.12.0 now. https://radar.offseq.com/threat/cve-2026-8445-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-in-42aabed1c30bf24b #OffSeq #XSS #AppSec #CVE20268445
##🔴 CVE-2026-8445 - Critical (9.8)
justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to Markdown via to_markdown(). While a small set of Markdown metacharacters ar...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8445/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-23T15:33:12
2 posts
1 repos
🟠 CVE-2026-4671 - High (7.5)
justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate attacker-controlled selector strings (via query(), matches(), or selector-based transforms), run ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-4671/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-4671 - High (7.5)
justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate attacker-controlled selector strings (via query(), matches(), or selector-based transforms), run ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-4671/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-23T15:33:04
2 posts
🔴 CVE-2026-5388 - Critical (9.8)
justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and several custom sanitization-policy edge cases. Dep...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-5388/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-5388 - Critical (9.8)
justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and several custom sanitization-policy edge cases. Dep...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-5388/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-23T12:31:12
3 posts
1 repos
🟠 New security advisory:
CVE-2026-10053 affects multiple systems.
• Impact: Significant security breach potential
• Risk: Unauthorized access or data exposure
• Mitigation: Apply patches within 24-48 hours
Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-10053-gitlab-rce-via-package-registry-path-traversal-poc
by Yazoul AI
##🟠 CVE-2026-10053 - High (8.5)
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10053/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-10053 - High (8.5)
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10053/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-23T06:30:28
2 posts
CVE-2026-13598: RestrictMate <1.3.0 (WordPress) CRITICAL vuln lets unauthenticated users create admin accounts via improper privilege management. Disable user registration or validate roles until patched. https://radar.offseq.com/threat/cve-2026-13598-cwe-269-improper-privilege-management-in-restrictmate-53a767aba3099df7 #OffSeq #WordPress #CVE202613598 #Infosec
##CVE-2026-13598: RestrictMate <1.3.0 (WordPress) CRITICAL vuln lets unauthenticated users create admin accounts via improper privilege management. Disable user registration or validate roles until patched. https://radar.offseq.com/threat/cve-2026-13598-cwe-269-improper-privilege-management-in-restrictmate-53a767aba3099df7 #OffSeq #WordPress #CVE202613598 #Infosec
##updated 2026-08-23T03:34:57
6 posts
CVE-2026-78136 - High-severity Eval Injection in CHIRP via crafted CSV data. CVSS 7.8. Update to the latest build immediately. #CVE #infosec #cybersecurity
##CVE-2026-78136 - CHIRP RCE via eval injection in crafted CSV (kenwood_itm.py). CVSS 7.8. Unpatched - upgrade once available. #CVE #infosec #CHIRP
##CVE-2026-78136: HIGH severity eval injection in chirpmyradio CHIRP (<39178db). Malicious CSV data can trigger arbitrary code execution. No patch yet — avoid untrusted files. Full details: https://radar.offseq.com/threat/cve-2026-78136-cwe-95-improper-neutralization-of-directives-in-dynamically-evaluated-code-eval-1763cf4fec8c29f0 #OffSeq #chirpmyradio #Vulnerability #InfoSec
##🟠 CVE-2026-78136 - High (7.8)
chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/kenwood_itm.py.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78136/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-78136: HIGH severity eval injection in chirpmyradio CHIRP (<39178db). Malicious CSV data can trigger arbitrary code execution. No patch yet — avoid untrusted files. Full details: https://radar.offseq.com/threat/cve-2026-78136-cwe-95-improper-neutralization-of-directives-in-dynamically-evaluated-code-eval-1763cf4fec8c29f0 #OffSeq #chirpmyradio #Vulnerability #InfoSec
##🟠 CVE-2026-78136 - High (7.8)
chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/kenwood_itm.py.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78136/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-23T00:30:30
5 posts
CVE-2026-16149 - Missing Authorization in WordPress Security Hardener plugin (<=2.4.4). Bypasses REST API protections. CVSS 8.8. Monitor for patch now. #CVE #WordPress #infosec
##CVE-2026-16149 (HIGH, CVSS 8.8): marc4 Security Hardener <=2.4.4 allows Subscriber-level users to create Admin accounts or reset passwords via REST API. Disable plugin or limit API access pending patch. https://radar.offseq.com/threat/cve-2026-16149-cwe-269-improper-privilege-management-in-marc4-security-hardener-a438d1f2a5360b5c #OffSeq #WordPress #Vulnerability #Infosec
##🟠 CVE-2026-16149 - High (8.8)
The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.4. The vulnerability exists because the plugin's user-enumeration protection, which is enabled by default, hooks the rest_e...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16149/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-16149 (HIGH, CVSS 8.8): marc4 Security Hardener <=2.4.4 allows Subscriber-level users to create Admin accounts or reset passwords via REST API. Disable plugin or limit API access pending patch. https://radar.offseq.com/threat/cve-2026-16149-cwe-269-improper-privilege-management-in-marc4-security-hardener-a438d1f2a5360b5c #OffSeq #WordPress #Vulnerability #Infosec
##🟠 CVE-2026-16149 - High (8.8)
The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.4. The vulnerability exists because the plugin's user-enumeration protection, which is enabled by default, hooks the rest_e...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16149/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-23T00:30:30
3 posts
1 repos
CVE-2026-78122 - Arbitrary file read in docker-socket-proxy allows leaks of container filesystems and logs. CVSS 7.4. Review and restrict proxy access now. #CVE #Docker #infosec
##CVE-2026-78122: HIGH severity in Tecnativa docker-socket-proxy (CVSS 8.3). Insufficient access control enables attackers to read files & export entire container filesystems via Docker API. Restrict access, check vendor guidance. https://radar.offseq.com/threat/cve-2026-78122-insufficient-granularity-of-access-control-in-tecnativa-docker-socket-proxy-6e8e6aaf03a19cce #OffSeq #Docker #Infosec #Vuln
##CVE-2026-78122: HIGH severity in Tecnativa docker-socket-proxy (CVSS 8.3). Insufficient access control enables attackers to read files & export entire container filesystems via Docker API. Restrict access, check vendor guidance. https://radar.offseq.com/threat/cve-2026-78122-insufficient-granularity-of-access-control-in-tecnativa-docker-socket-proxy-6e8e6aaf03a19cce #OffSeq #Docker #Infosec #Vuln
##updated 2026-08-23T00:30:30
4 posts
CVE-2026-0551: HIGH severity deserialization vulnerability in buildwps PPWP – Password Protect Pages (<=1.9.18). Contributor+ users can inject PHP objects if a POP chain exists in other plugins/themes. Review access & patch status. https://radar.offseq.com/threat/cve-2026-0551-cwe-502-deserialization-of-untrusted-data-in-buildwps-ppwp-password-protect-pages-dde9c11a2d958ff8 #OffSeq #WordPress #Vuln
##🟠 CVE-2026-0551 - High (8.8)
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.18 via deserialization of untrusted input from the 'post_protection_roles' vulnerable parameter. This makes it...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-0551/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-0551: HIGH severity deserialization vulnerability in buildwps PPWP – Password Protect Pages (<=1.9.18). Contributor+ users can inject PHP objects if a POP chain exists in other plugins/themes. Review access & patch status. https://radar.offseq.com/threat/cve-2026-0551-cwe-502-deserialization-of-untrusted-data-in-buildwps-ppwp-password-protect-pages-dde9c11a2d958ff8 #OffSeq #WordPress #Vuln
##🟠 CVE-2026-0551 - High (8.8)
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.18 via deserialization of untrusted input from the 'post_protection_roles' vulnerable parameter. This makes it...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-0551/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-23T00:30:30
4 posts
🔴 CVE-2026-78050 - Critical (9.9)
A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET§ion=ntp_timezone of the component Web Management. The manipulation of the argument timestr/ntp_cl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78050/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CRITICAL: CVE-2026-78050 in Comfast CF-N1-S (2.6.0.1) enables remote code execution via stack-based buffer overflow in web mgmt (/cgi-bin/mbox-config). Public exploit out, no patch yet. Restrict access! https://radar.offseq.com/threat/cve-2026-78050-stack-based-buffer-overflow-in-comfast-cf-n1-s-d1eec38193291471 #OffSeq #CVE202678050 #infosec #IoT
##🔴 CVE-2026-78050 - Critical (9.9)
A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET§ion=ntp_timezone of the component Web Management. The manipulation of the argument timestr/ntp_cl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78050/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CRITICAL: CVE-2026-78050 in Comfast CF-N1-S (2.6.0.1) enables remote code execution via stack-based buffer overflow in web mgmt (/cgi-bin/mbox-config). Public exploit out, no patch yet. Restrict access! https://radar.offseq.com/threat/cve-2026-78050-stack-based-buffer-overflow-in-comfast-cf-n1-s-d1eec38193291471 #OffSeq #CVE202678050 #infosec #IoT
##updated 2026-08-22T18:30:37
1 posts
Speicher-Leck im Linux-Kernel (CVE-2026-74671)
Eine Schwachstelle in der Integritätsmessarchitektur (IMA) bedroht Linux-Systeme. Ein Vorzeichenfehler (Type-Mismatch) in der Funktion xattr_verify() führt bei manipulierten security.ima-Erweiterungen zu einem Unterlauf.
Dadurch entsteht ein gefährlicher Out-of-Bounds-Lesefehler, über den Angreifer potenziell sensible Daten direkt aus dem Speicher abgreifen können. Admins sollten umgehend patchen!
##updated 2026-08-22T18:30:25
5 posts
CVE-2026-4703 - Critical PHP Object Injection in WS Form for WordPress leads to remote code execution via insecure deserialization. CVSS 9.8. Update now. #CVE #WordPress #infosec
##CVE-2026-4703: WS Form LITE ≤1.10.80 has a CRITICAL PHP Object Injection vuln via form meta deserialization. Exploitable if a POP chain exists in another plugin/theme — possible RCE, file deletion, or data leak. Audit plugins/themes. https://radar.offseq.com/threat/the-ws-form-lite-drag-drop-contact-form-builder-plugin-for-wordpress-is-vulnerable-to-php-object-f688cffee1daa479 #OffSeq #WordPress #CVE20264703
##🔴 CVE-2026-4703 - Critical (9.8)
The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values. This makes it p...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-4703/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-4703: WS Form LITE ≤1.10.80 has a CRITICAL PHP Object Injection vuln via form meta deserialization. Exploitable if a POP chain exists in another plugin/theme — possible RCE, file deletion, or data leak. Audit plugins/themes. https://radar.offseq.com/threat/the-ws-form-lite-drag-drop-contact-form-builder-plugin-for-wordpress-is-vulnerable-to-php-object-f688cffee1daa479 #OffSeq #WordPress #CVE20264703
##🔴 CVE-2026-4703 - Critical (9.8)
The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values. This makes it p...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-4703/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-22T16:16:45.540000
1 posts
Kritischer Fix im Linux-Kernel (CVE-2026-74708)
Das MITRE-Institut meldet eine behobene Schwachstelle im xsk-Netzwerk-Subsystem. Eine fehlerhafte Größenprüfung von „Launch-time“-Metadaten konnte durch manipulierte Anfragen zu Pipeline-Ausfällen führen.
Die Patches wurden bereits erfolgreich eingepflegt. System-Updates werden empfohlen!
##updated 2026-08-22T15:31:11
5 posts
CVE-2026-62384 - Symlink sandbox bypass in NLTK leads to arbitrary file read. CVSS 7.5. Update to version 3.10.2 now. #CVE #Python #infosec
##CVE-2026-62384 - Symlink sandbox bypass in NLTK FramenetCorpusReader. Arbitrary XML file read. CVSS 7.5. Update to 3.10.2 now. #CVE #NLTK #infosec
##🟠 CVE-2026-62384 - High (7.5)
NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators inside the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62384/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-62384 - Symlink sandbox bypass in NLTK leads to arbitrary file read. CVSS 7.5. Update to version 3.10.2 now. #CVE #Python #infosec
##🟠 CVE-2026-62384 - High (7.5)
NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators inside the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62384/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-22T15:31:11
3 posts
CVE-2026-71513 - Critical RCE in NLTK AllowlistUnpickler. Attribute traversal bypasses allowlist to execute arbitrary code via crafted transition-parser models. CVSS 8.8. Update to NLTK 3.10.3 immediately. #CVE #NLTK #infosec
##🟠 CVE-2026-71513 - High (8.8)
NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables outside th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71513/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-71513 - High (8.8)
NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables outside th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71513/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-22T15:31:11
2 posts
🟠 CVE-2026-62243 - High (7.5)
Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on the SslProvider.OPENSSL client path when a plain (non-extended) X509TrustManager is used and Unsa...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62243/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-62243 - High (7.5)
Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on the SslProvider.OPENSSL client path when a plain (non-extended) X509TrustManager is used and Unsa...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62243/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-22T15:31:11
2 posts
🟠 CVE-2026-2996 - High (7.5)
The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart_data' function. This makes...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-2996/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-2996 - High (7.5)
The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart_data' function. This makes...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-2996/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-22T15:31:11
2 posts
🟠 CVE-2026-62388 - High (7.5)
NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62388/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-62388 - High (7.5)
NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62388/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-22T15:31:05
2 posts
🟠 CVE-2026-59808 - High (8.8)
AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials for any video by encoder_queue_id without ownership verification, and useVideoHashOrLogin() conver...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59808/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-59808 - High (8.8)
AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials for any video by encoder_queue_id without ownership verification, and useVideoHashOrLogin() conver...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59808/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-22T15:31:02
2 posts
🟠 CVE-2026-57998 - High (7.8)
better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-supplied --registry option into a command string in src/handlers/handleInput.ts without validation or quoting, then passes that ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57998/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-57998 - High (7.8)
better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-supplied --registry option into a command string in src/handlers/handleInput.ts without validation or quoting, then passes that ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57998/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-22T15:16:19.633000
4 posts
CVE-2026-66393 - DoS vulnerability in NLTK. Deeply nested JSON triggers unhandled recursion crash in Python. CVSS 7.5. Update to 3.9.4 immediately. #CVE #Python #infosec
##🟠 CVE-2026-66393 - High (7.5)
NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures. Attackers can craft JSON payloads exceeding the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66393/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-66393 - DoS vulnerability in NLTK. Deeply nested JSON triggers unhandled recursion crash in Python. CVSS 7.5. Update to 3.9.4 immediately. #CVE #Python #infosec
##🟠 CVE-2026-66393 - High (7.5)
NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures. Attackers can craft JSON payloads exceeding the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66393/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-22T13:16:38.817000
2 posts
🟠 CVE-2026-59256 - High (7.5)
WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or purpose, and plugin/Gallery/view/sections.php issues valid tokens to unauthenticated visitors. A...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59256/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-59256 - High (7.5)
WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or purpose, and plugin/Gallery/view/sections.php issues valid tokens to unauthenticated visitors. A...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59256/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-22T12:30:34
5 posts
CVE-2026-77946 - Critical stack buffer overflow in TRENDnet TEW-821DAP NTP handler. Remote exploit public, unpatched. CVSS 10. Isolate/disable affected devices until patch. #CVE #TRENDnet #infosec
##CVE-2026-77946: Stack-based buffer overflow in TRENDnet TEW-821DAP v2.2.01b05 (CRITICAL, CVSS 10). Remote code execution possible via NTP config. No patch — limit exposure & monitor traffic. https://radar.offseq.com/threat/cve-2026-77946-stack-based-buffer-overflow-in-trendnet-tew-821dap-679ce40e9d7aa62a #OffSeq #CVE202677946 #infosec #vulnerability
##🔴 CVE-2026-77946 - Critical (10)
A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler. Executing a manipulation of the a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77946/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-77946: Stack-based buffer overflow in TRENDnet TEW-821DAP v2.2.01b05 (CRITICAL, CVSS 10). Remote code execution possible via NTP config. No patch — limit exposure & monitor traffic. https://radar.offseq.com/threat/cve-2026-77946-stack-based-buffer-overflow-in-trendnet-tew-821dap-679ce40e9d7aa62a #OffSeq #CVE202677946 #infosec #vulnerability
##🔴 CVE-2026-77946 - Critical (10)
A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler. Executing a manipulation of the a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77946/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-22T12:30:26
1 posts
CVE-2026-77945 - Command injection in TRENDnet TEW-821DAP 2.2.01b05 via /cgi-bin/upload.cgi. CVSS 7.4. Unpatched. Disable remote access now. #CVE #TRENDnet #infosec
##updated 2026-08-22T09:30:32
4 posts
🔴 CVE-2026-78003 - Critical (9.8)
The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which accepts use...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78003/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CRITICAL: Mailgun for WordPress ≤2.2.0 vulnerable to SSRF (CVE-2026-78003). Attackers can exploit input validation in add_list() to hijack admin resets & compromise sites. Update/disable plugin now. https://radar.offseq.com/threat/cve-2026-78003-cwe-918-server-side-request-forgery-ssrf-in-mailgun-mailgun-for-wordpress-6ee94923f1ee4923 #OffSeq #WordPress #Infosec #SSRF
##🔴 CVE-2026-78003 - Critical (9.8)
The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which accepts use...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78003/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CRITICAL: Mailgun for WordPress ≤2.2.0 vulnerable to SSRF (CVE-2026-78003). Attackers can exploit input validation in add_list() to hijack admin resets & compromise sites. Update/disable plugin now. https://radar.offseq.com/threat/cve-2026-78003-cwe-918-server-side-request-forgery-ssrf-in-mailgun-mailgun-for-wordpress-6ee94923f1ee4923 #OffSeq #WordPress #Infosec #SSRF
##updated 2026-08-22T09:16:53.340000
2 posts
CRITICAL (CVSS 9.3): CVE-2026-12710 in Google Cloud Application Integration (QueryEngineTask) enabled unauthorized data access. Patched by Google on 2026-04-04 — no customer action needed. Details: https://radar.offseq.com/threat/cve-2026-12710-cwe-862-missing-authorization-in-google-cloud-application-integration-f732bf9f6ab56812 #OffSeq #CloudSecurity #CVE #Vuln
##CRITICAL (CVSS 9.3): CVE-2026-12710 in Google Cloud Application Integration (QueryEngineTask) enabled unauthorized data access. Patched by Google on 2026-04-04 — no customer action needed. Details: https://radar.offseq.com/threat/cve-2026-12710-cwe-862-missing-authorization-in-google-cloud-application-integration-f732bf9f6ab56812 #OffSeq #CloudSecurity #CVE #Vuln
##updated 2026-08-22T04:17:16.273000
2 posts
IBM patches two Power Systems Firmware flaws, CVE-2026-16687 and CVE-2026-16835, both CVSS 9.6, that grant full control of the managed system.
#IBM #PowerSystems #Firmware #CVE #RCE #AuthBypass #InfoSec #PatchNow
##IBM patches two Power Systems Firmware flaws, CVE-2026-16687 and CVE-2026-16835, both CVSS 9.6, that grant full control of the managed system.
#IBM #PowerSystems #Firmware #CVE #RCE #AuthBypass #InfoSec #PatchNow
##updated 2026-08-22T03:31:33
1 posts
🟠 CVE-2026-19883 - High (8.8)
The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the wpematico_import_settings function in all versions up to, and inc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19883/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T22:16:42.227000
2 posts
🔴 CVE-2026-63343 - Critical (9.9)
Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any file on the host...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63343/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-63343 - Critical (9.9)
Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any file on the host...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63343/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T22:16:39.290000
1 posts
🟠 CVE-2026-53528 - High (8.8)
LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a path traversal vulnerability in LeafWiki’s asset rename functionality. An authenticated user with editor permissions could move files that are accessible to the LeafWiki server...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53528/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T22:16:37.973000
2 posts
🔴 CVE-2026-48755 - Critical (9.9)
Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file write o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48755/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-48755 - Critical (9.9)
Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file write o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48755/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T22:16:36.863000
1 posts
🟠 CVE-2026-33240 - High (8.8)
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-Site Scripting (XSS) vulnerability in the foreign key search criteria API. This issue has been fixed in version 3.2.3.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-33240/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T22:16:36.430000
1 posts
🟠 CVE-2026-31880 - High (8)
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the universal search. This issue has been fixed in version 3.2.3.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-31880/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T22:16:36.303000
1 posts
🟠 CVE-2026-31803 - High (8)
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in pages/tagadmin.php. This issue has been fixed in version 3.2.3.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-31803/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T21:17:06.143000
2 posts
1 repos
AI scanner AgentGG found GeoServer SQL injection before zero-day
GeoServer/GeoTools의 `jsonArrayContains` 필터에서 인증 없이 도달 가능한 SQL 인젝션(CVE-2026-76904, CVSS 9.8)이 공개됐으며, PostGIS 12 이상 구성에서는 입력값이 SQL 문자열에 적절히 이스케이프되지 않는 것이 원인이다. 공개 직후 인터넷 노출 GeoServer 인스턴스를 대상으로 대규모 스캔·탐색 시도가 관측됐고, GeoServer는 긴급 패치를 배포했다. 이는 2023...
##🔴 CVE-2026-76904 - Critical (9.8)
GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6, an SQL Injection Vulnerability is present when executing OGC Filters with PostGIS DataStore imple...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76904/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T21:17:01.493000
1 posts
🟠 CVE-2026-63135 - High (8.2)
YOURLS is a self-hosted, customizable URL shortener written in PHP. From 1.5.1 until 1.10.4, YOURLS stores the HTTP Referer header through yourls_get_referrer(), yourls_sanitize_url_safe(), and yourls_log_redirect(), then aggregates the value in y...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63135/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T21:17:00.267000
1 posts
🟠 CVE-2026-54457 - High (7.7)
TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026.6.0, the TensorZero Gateway /internal/object_storage endpoint accepts a caller-supplied JSON stor...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54457/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T21:04:20
1 posts
CVE-2026-77415 (CRITICAL, CVSS 9.3) in jsonata-js (<1.8.8, <2.2.1): Attackers can chain object-integrity flaws to achieve arbitrary code execution. Patch to 1.8.8/2.2.1 ASAP. Details: https://radar.offseq.com/threat/cve-2026-77415-cwe-94-improper-control-of-generation-of-code-code-injection-in-jsonata-js-jsonata-b49c30a44f0e9211 #OffSeq #jsonata #security #vuln
##updated 2026-08-21T20:58:02
1 posts
CRITICAL: CVE-2026-77414 in jsonata-js (<1.8.8, <2.2.1) enables remote code execution via code injection (CWE-94). Update to 1.8.8/2.2.1 now. No workaround. Details: https://radar.offseq.com/threat/cve-2026-77414-cwe-94-improper-control-of-generation-of-code-code-injection-in-jsonata-js-jsonata-247817ff13af01bb #OffSeq #CVE202677414 #infosec #security
##updated 2026-08-21T20:57:32
1 posts
🟠 CVE-2026-68508 - High (7.8)
Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.4, hydra.utils.instantiate() resolves and calls Python objects selected by configuration through _resolve_target() in hydra/_internal/instantiate/_instantiate2.py, a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68508/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T20:57:09
1 posts
jsonata-js (<1.8.8, <2.2.0) is affected by CRITICAL CVE-2026-77413 (CVSS 9.3) due to a code injection flaw in the lookup function. Attackers can execute arbitrary code remotely. Upgrade to 1.8.8 or 2.2.0+ ASAP. https://radar.offseq.com/threat/cve-2026-77413-cwe-94-improper-control-of-generation-of-code-code-injection-in-jsonata-js-jsonata-43a95a44c76d7f7e #OffSeq #CVE #infosec #security
##updated 2026-08-21T20:56:39
2 posts
CVE-2026-61539: CRITICAL RCE in xorbitsai Xinference <=2.5.0 — attacker-controlled input reaches Python eval(), enabling unauthenticated code execution. Patch to 2.7.0. CVSS: 10.0 🛡️ https://radar.offseq.com/threat/cve-2026-61539-cwe-95-improper-neutralization-of-directives-in-dynamically-evaluated-code-eval-03188a31614e6f78 #OffSeq #CVE202661539 #infosec #remotecodeexecution
##🔴 CVE-2026-61539 - Critical (10)
Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output to eval() in xinference/model/llm/tool_parsers/llama3_tool_parser.py and xin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61539/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T20:55:47
2 posts
CVE-2026-76905 - Unpatched DoS in kin-openapi. Malformed multipart request triggers nil pointer panic in error handling. CVSS 7.5. No fix yet - monitor for updates and apply workarounds. #CVE #infosec #Go
##🟠 CVE-2026-76905 - High (7.5)
kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 until 0.141.0, openapi3filter.convertParseError in openapi3filter/validation_error_encoder.go dereferences e.Parameter.In without checking whether e.Parameter is nil. A malformed ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76905/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T20:55:33
1 posts
🟠 CVE-2026-64679 - High (8.1)
Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. From 0.19.8 until 0.45.0, Atlantis does not consistently validate user-controlled workspace values supplied through accepted repository-level...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64679/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T20:55:12
1 posts
🟠 CVE-2026-63421 - High (7.5)
Keystone is a content management system for Node.js. Prior to 6.5.3, the findMany resolver in packages/core/src/lib/core/queries/resolvers.ts compares the signed take argument directly with graphql.maxTake, allowing a remote unauthenticated GraphQ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63421/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T20:16:34.157000
1 posts
🟠 CVE-2026-27490 - High (7.5)
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue has been fixed in version 3.2.3.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-27490/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T19:17:31.927000
1 posts
🟠 CVE-2026-63462 - High (7.5)
Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the shared OpenAPI validation error path in src/lib/error/bad-data-error.ts passes a raw request value from lodash.get to JSON.stringify in genericErrorMessag...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63462/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T19:17:12.840000
1 posts
🟠 CVE-2026-62675 - High (8.8)
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, multipart POST /v1/sessions accepts an authenticated user's agent bundle and omnigent/server/bundles.py validate_agent_bundle does not ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62675/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T18:35:08
1 posts
🟠 CVE-2026-41451 - High (7.8)
UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the user substitution logic within parse_artifact.sh where usernames and home directories from /etc/passwd are substituted directly into comma...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-41451/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T18:35:08
1 posts
🟠 CVE-2026-41449 - High (7.8)
UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _run_command function that allows attackers to execute arbitrary commands by injecting shell metacharacters into untrusted data such as us...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-41449/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T18:35:07
2 posts
Three high-severity TL-MR6400 router flaws, including CVE-2026-17250, expose devices to code execution.
#TPLink #CyberSecurity #Vulnerability #CVE202617250
https://securityonline.info/tl-mr6400-router-flaws/?utm_source=mastodon&utm_medium=jetpack_social
##Three high-severity TL-MR6400 router flaws, including CVE-2026-17250, expose devices to code execution.
#TPLink #CyberSecurity #Vulnerability #CVE202617250
https://securityonline.info/tl-mr6400-router-flaws/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-08-21T18:35:07
1 posts
🟠 CVE-2026-39909 - High (8.1)
llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server's GRAPH_RECOMPUTE handler that allows unauthenticated remote attackers to achieve arbitrary read and write access by storing a computation graph, freeing referenced b...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-39909/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T18:35:02
1 posts
CVE-2026-75932 - Critical Jet Admin vuln: malicious app can hijack custom domain & steal OAuth secrets. CVSS 8.6. Unpatched — audit configs & block app creation. #CVE #JetAdmin #infosec
##updated 2026-08-21T18:35:01
2 posts
CVE-2026-69502 - Critical SSRF in Azure SQL DB allows privilege escalation. CVSS 10. Patch under review - update when available. #CVE #Azure #infosec
##🔴 CVE-2026-69502 - Critical (10)
Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69502/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T18:34:56
2 posts
🟠 CVE-2026-47827 - High (7.5)
Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vulnerabilities
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47827/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-47827 - High (7.5)
Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vulnerabilities
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47827/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T18:16:48.680000
1 posts
🟠 CVE-2026-54789 - High (7.5)
mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds wr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54789/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T18:16:48.257000
1 posts
🟠 CVE-2026-41450 - High (7.8)
UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _command_collector function where foreach command output lines are substituted directly into command strings via sed without proper escapi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-41450/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T17:56:59.057000
2 posts
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
updated 2026-08-21T17:16:31.087000
2 posts
🔴 CVE-2026-48752 - Critical (9.9)
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48752/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-48752 - Critical (9.9)
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48752/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T17:16:30.683000
2 posts
1 repos
🟠 CVE-2026-22681 - High (8.5)
OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticated low-privilege attackers to access internal network services by submitting arbitrary URLs to the resources API endpoint. Attackers can POST a cr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-22681/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-22681 - High (8.5)
OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticated low-privilege attackers to access internal network services by submitting arbitrary URLs to the resources API endpoint. Attackers can POST a cr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-22681/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T16:18:17.470000
2 posts
Calix GS7 XGS Routers Face a Dangerous Unpatched Flaw That Could Open Home Networks to the Internet + Video
A Quiet Router Vulnerability With Serious Consequences A newly disclosed security flaw in Calix GS7 XGS residential routers is raising concern because it can allow a remote attacker to manipulate network port-forwarding rules without authenticating to the device. Tracked as CVE-2026-75501, the vulnerability affects Calix GS7 XGS (GS5239XG) routers running…
##Unpatched Calix Routers Expose Internal Devices to Internet Threats
A single, unauthorized request can create a permanent vulnerability in your Calix router's firewall, exposing internal devices to internet threats - no password or prompt required. This shocking flaw, tracked as CVE-2026-75501, leaves devices running EXOS/6.6.47 firmware alarmingly susceptible to attack.
#Cve202675501 #CalixRouterVulnerability #Exos #Upnp #Wanipconnection
##updated 2026-08-21T16:17:19.623000
2 posts
🟠 CVE-2026-55622 - High (7.7)
Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an instance in ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55622/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-55622 - High (7.7)
Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an instance in ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55622/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T16:17:17.413000
2 posts
🔴 CVE-2026-48749 - Critical (9.9)
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 fixes the is...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48749/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-48749 - Critical (9.9)
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 fixes the is...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48749/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T15:32:18
2 posts
1 repos
🔴 CVE-2026-77806 - Critical (9.8)
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resultat_skel.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77806/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-77806 - Critical (9.8)
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resultat_skel.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77806/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T15:32:18
1 posts
updated 2026-08-21T12:30:41
2 posts
🟠 CVE-2026-77767 - High (7.5)
Reconmap's API applies a fallback authorization policy in apps/api/app/Program.cs that requires an authenticated user holding the administrator role, so controllers without their own attribute reject anonymous callers. The report preview action in...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77767/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-77767 - High (7.5)
Reconmap's API applies a fallback authorization policy in apps/api/app/Program.cs that requires an authenticated user holding the administrator role, so controllers without their own attribute reject anonymous callers. The report preview action in...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77767/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T12:16:36.273000
2 posts
🔴 CVE-2026-77086 - Critical (9.1)
SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform path traversal via directory traversal sequences. Attackers with admin access can write ar...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77086/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-77086 - Critical (9.1)
SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform path traversal via directory traversal sequences. Attackers with admin access can write ar...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77086/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T00:31:31
9 posts
2 repos
Mysterien um Microsofts kritisches Sicherheitsloch in Entra ID
Am vorigen Donnerstag macht Microsoft (MS) ein riesiges Trara um eine höchst gefährliche Sicherheitslücke CVE-2026-69836 (Risiko 10 von 10) in Entra ID*. Ein entfernter, nicht autorisierter Angreifer könne durch Ausnutzung dieser Sicherheitslücke beliebigen Programmcode ausführen (RCE). Und die Lücke würde bereits für Angriffe ausgenutzt. Meldungen beispielsweise hier oder hier. Wie die Ausnutzung entdeckt wurde und wer vielleicht betroffen ist, verlautet MS nicht. Einen Tag später zieht MS die Auskunft "wird bereits ausgenutzt" zurück. Hä? Interessant ist auch, dass ... Weiterlesen:
#0day #backdoor #cloud #exploits #identität #Microsoft #sicherheit #unplugMicrosoft #UnplugTrump
##Microsoft released 22 security patches including a zero-day in Entra ID (CVE-2026-69836) actively exploited for remote code execution. The critical identity-layer flaw was weaponized before a fix became available. ShieldBreak remains unpatched, leaving a documented gap in the security posture of affected organizations.
#MicrosoftPatches #EntraIDZeroDay #ShieldBreak #CVE202669836
https://cyberworldops.eu/en/microsoft-patches-22-flaws-entra-id-already-secured-but-shieldbreak
##Microsoft Entra ID Faces Maximum-Severity Security Emergency as CVE-2026-69836 Reportedly Comes Under Active Exploitation + Video
A Critical Warning for Organizations That Depend on Cloud Identity Identity infrastructure has become the front door to the modern enterprise. Employees sign in through it, administrators manage systems through it, cloud services trust it, and security teams depend on it to decide who should and should not have access. That is why a newly…
##Microsoft released 22 security patches including a zero-day in Entra ID (CVE-2026-69836) actively exploited for remote code execution. The critical identity-layer flaw was weaponized before a fix became available. ShieldBreak remains unpatched, leaving a documented gap in the security posture of affected organizations.
#MicrosoftPatches #EntraIDZeroDay #ShieldBreak #CVE202669836
https://cyberworldops.eu/en/microsoft-patches-22-flaws-entra-id-already-secured-but-shieldbreak
##“Microsoft warned on Aug. 20 that a maximum-severity deserialization flaw in Entra ID was actively exploited.
In releasing a patch for CVE-2026-69836, Microsoft said it had already fully mitigated the vulnerability, so there’s no further action for Entra ID users to take.”
https://www.scworld.com/news/microsoft-patches-flaw-in-entra-id-identity-software
##「マイクロソフトが警鐘を鳴らす、Entra IDの完全な欠陥が攻撃を受けている
/マイクロソフトはクラウドIDのバグは既に修正済みだと述べているが、誰がどの程度悪用したのかは明らかにしていない。 」: #TheRegister
「マイクロソフトは、攻撃者が既に悪用していたEntra IDの深刻度が最大レベルの脆弱性を修正した。
CVE-2026-69836として追跡されているこの脆弱性は、CVSSスコアが最高値の10.0であり、認証されていない攻撃者がMicrosoftのクラウドIDサービス上でリモートからコードを実行できる可能性がある。Microsoft は木曜日にこの脆弱性を公表し 、既に悪用が確認されているという残念なニュースも同時に発表した。
Entra ID(旧称Azure Active Directory)は、マイクロソフトのお客様向けIDおよびアクセス管理の中核を担い、クラウドアプリケーションやその他の企業リソースへの認証とアクセスを管理します。」
##🚨 [CISA-2026:0821] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-69836 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-69836)
- Name: Microsoft Entra ID Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Entra ID
- Notes: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-69836
⚠️ CVE-2026-73570 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73570)
- Name: Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Synacor
- Product: Zimbra Collaboration Suite (ZCS)
- Notes: https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories ; https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-73570
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260821 #cisa20260821 #cve_2026_69836 #cve_2026_73570 #cve202669836 #cve202673570
##CVE-2026-69836 was added to the KEV. It was published yesterday by Microsoft:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836
Microsoft says:
Publicly disclosed: No
Exploited: No
Exploitability assessment: Exploitation Less Likely
and
This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.
So does this mean that Microsoft was made aware by a third party that it was EITW? Because presumably it was exploited before it was published if no action is needed by the customer and Microsoft doesn't list it as EITW.
Edit: I now see this revision in the advisory:
Corrected Exploited to No. This vulnerability was not exploited in the wild. This is an informational change only.
So I assume that because it was incorrectly listed as EITW it ended up in the KEV. But now they say it wasn't EITW. Which is it? That's kind of important you fucking sloppy ass clanker fuckers.
##CVE ID: CVE-2026-69836
Vendor: Microsoft
Product: Entra ID
Date Added: 2026-08-21
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-69836
updated 2026-08-21T00:31:24
3 posts
🚨 🔃 EverShop flaw enables account takeover
CVE-2026-72843 lets attackers overwrite customer email and passwords using an exposed UUID; fixed in 2.2.1.
##A critical EverShop account takeover flaw, CVE-2026-72843, exposes systems to an eCommerce platform vulnerability. Update to version 2.2.1 immediately.
#EverShop #CyberSecurity #CVE202672843 #Vulnerability #eCommerce
##A critical EverShop account takeover flaw, CVE-2026-72843, exposes systems to an eCommerce platform vulnerability. Update to version 2.2.1 immediately.
#EverShop #CyberSecurity #CVE202672843 #Vulnerability #eCommerce
##updated 2026-08-20T21:31:30
2 posts
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
updated 2026-08-20T19:16:57.867000
4 posts
3 repos
https://github.com/zavisco/CVE-2026-64849.yaml
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
Attackers are exploiting a critical MLflow bug to reach internal systems and cloud metadata, putting cloud secrets at risk. CISA has added CVE-2026-64849 to its KEV catalog.
Listen/Read: https://hackread.com/attackers-exploit-critical-mlflow-ai-platform-flaw/
##📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
Attackers are exploiting a critical MLflow bug to reach internal systems and cloud metadata, putting cloud secrets at risk. CISA has added CVE-2026-64849 to its KEV catalog.
Listen/Read: https://hackread.com/attackers-exploit-critical-mlflow-ai-platform-flaw/
##updated 2026-08-20T19:16:51.497000
2 posts
Fuck it, CVE dumpster diving.
CVE-2026-20231 - this is one of a batch of Cisco CVEs that stood out to me because they have multiple descriptions: One by the CNA, one by an ADP, "CVE" itself. The ADP one is just "please please please dont do this (bundling multiple vulns into a single cve) :neobot_angel_pleading: ". Cisco dont care, they put out 9 of those over the last 7 days.
##Fuck it, CVE dumpster diving.
CVE-2026-20231 - this is one of a batch of Cisco CVEs that stood out to me because they have multiple descriptions: One by the CNA, one by an ADP, "CVE" itself. The ADP one is just "please please please dont do this (bundling multiple vulns into a single cve) :neobot_angel_pleading: ". Cisco dont care, they put out 9 of those over the last 7 days.
##updated 2026-08-20T18:31:47
4 posts
🏆 New Achievement! Port 4307 Is Not a Safe Harbor!
Conducting inventory audit on your TrueConf Server installation. Status: compromised. Line items include two unauthenticated RCE vulnerabilities — CVE-2026-72529 and CVE-2026-72530 — currently checked out under the name Head Mare, a hacktivist group who used them to swap a server file for a web shell and deploy PhantomCore malware. Item condition: cursed. (1/2)
##⚠️ CRITICAL: CISA orders feds to patch actively exploited TrueConf Server flaws
Two critical unauthenticated RCE vulnerabilities (CVE-2026-72529, CVE-2026-72530) in TrueConf Server are being actively exploited by Head Mare group to deploy backdoor malware via trojanized installers. Any organization running TrueConf Server is at immediate risk of compromise.
🤖 AI generated summary
##🏆 New Achievement! Port 4307 Is Not a Safe Harbor!
Conducting inventory audit on your TrueConf Server installation. Status: compromised. Line items include two unauthenticated RCE vulnerabilities — CVE-2026-72529 and CVE-2026-72530 — currently checked out under the name Head Mare, a hacktivist group who used them to swap a server file for a web shell and deploy PhantomCore malware. Item condition: cursed. (1/2)
##⚠️ CRITICAL: CISA orders feds to patch actively exploited TrueConf Server flaws
Two critical unauthenticated RCE vulnerabilities (CVE-2026-72529, CVE-2026-72530) in TrueConf Server are being actively exploited by Head Mare group to deploy backdoor malware via trojanized installers. Any organization running TrueConf Server is at immediate risk of compromise.
🤖 AI generated summary
##updated 2026-08-20T18:30:55
2 posts
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
updated 2026-08-20T18:30:43
4 posts
🏆 New Achievement! Port 4307 Is Not a Safe Harbor!
Conducting inventory audit on your TrueConf Server installation. Status: compromised. Line items include two unauthenticated RCE vulnerabilities — CVE-2026-72529 and CVE-2026-72530 — currently checked out under the name Head Mare, a hacktivist group who used them to swap a server file for a web shell and deploy PhantomCore malware. Item condition: cursed. (1/2)
##⚠️ CRITICAL: CISA orders feds to patch actively exploited TrueConf Server flaws
Two critical unauthenticated RCE vulnerabilities (CVE-2026-72529, CVE-2026-72530) in TrueConf Server are being actively exploited by Head Mare group to deploy backdoor malware via trojanized installers. Any organization running TrueConf Server is at immediate risk of compromise.
🤖 AI generated summary
##🏆 New Achievement! Port 4307 Is Not a Safe Harbor!
Conducting inventory audit on your TrueConf Server installation. Status: compromised. Line items include two unauthenticated RCE vulnerabilities — CVE-2026-72529 and CVE-2026-72530 — currently checked out under the name Head Mare, a hacktivist group who used them to swap a server file for a web shell and deploy PhantomCore malware. Item condition: cursed. (1/2)
##⚠️ CRITICAL: CISA orders feds to patch actively exploited TrueConf Server flaws
Two critical unauthenticated RCE vulnerabilities (CVE-2026-72529, CVE-2026-72530) in TrueConf Server are being actively exploited by Head Mare group to deploy backdoor malware via trojanized installers. Any organization running TrueConf Server is at immediate risk of compromise.
🤖 AI generated summary
##updated 2026-08-20T15:34:03
5 posts
🏆 New Achievement! No Password? No Problem!
Welcome, new player, to the Authentication Bypass Tutorial! This mandatory segment introduces CVE-2026-19490, a CVSS 9.3 critical flaw in Citrix NetScaler ADC and NetScaler Gateway. No account required. No user interaction needed. No elevated privileges. The game just... lets attackers in. Think of it as a permanent debuff applied to your enterprise perimeter. (1/2)
##📢 [VULN] Citrix NetScaler (CVE-2026-19490) : cette faille permet de contourner l'authentification
Le 19 août 2026, Citrix a publié un nouveau bulletin de sécurité pour NetScaler ADC et NetScaler Gateway. Il fait référence à deux failles de sécurité, dont l'une particulièrement inquiétante : la CVE-2026-19490.
🔗 https://www.it-connect.fr/citrix-netscaler-cve-2026-19490-contournement-authentification/
💬 discussion : https://infosec.pub/post/51278994
#CVE #Cyberveille
Citrix NetScaler (CVE-2026-19490) : cette faille critique permet de contourner l’authentification https://www.it-connect.fr/citrix-netscaler-cve-2026-19490-contournement-authentification/ #ActuCybersécurité #Cybersécurité #Vulnérabilité
##🏆 New Achievement! No Password? No Problem!
Welcome, new player, to the Authentication Bypass Tutorial! This mandatory segment introduces CVE-2026-19490, a CVSS 9.3 critical flaw in Citrix NetScaler ADC and NetScaler Gateway. No account required. No user interaction needed. No elevated privileges. The game just... lets attackers in. Think of it as a permanent debuff applied to your enterprise perimeter. (1/2)
##Citrix NetScaler (CVE-2026-19490) : cette faille critique permet de contourner l’authentification https://www.it-connect.fr/citrix-netscaler-cve-2026-19490-contournement-authentification/ #ActuCybersécurité #Cybersécurité #Vulnérabilité
##updated 2026-08-20T12:48:10.287000
2 posts
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
updated 2026-08-20T09:31:23
2 posts
1 repos
‼️ CVE PoC Published: CVE-2026-76565 - Reflected XSS in PhocaCart
GitHub: https://github.com/toanln-cov/CVE-2026-76565
A proof-of-concept has been released for CVE-2026-76565, a reflected cross-site scripting (XSS) vulnerability affecting PhocaCart ≤ 6.1.7 for Joomla.
The vulnerability exists in the price_from and price_to filter parameters within the mod_phocacart_filter module. Due to improper output encoding, unauthenticated attackers can craft a malicious URL that injects JavaScript into the page when viewed by a victim.
The PoC demonstrates:
• Reflected XSS through crafted GET parameters
• Exploitation of vulnerable price filter inputs
• Attribute-context injection caused by missing htmlspecialchars() encoding
• No authentication requirement for exploitation
• Affected versions: PhocaCart ≤ 6.1.7
• Fixed version: PhocaCart 6.1.8
💥 No delays. No guessing. No redactions. Get the intel before everyone else with Dark Web Informer.
##‼️ CVE PoC Published: CVE-2026-76565 - Reflected XSS in PhocaCart
GitHub: https://github.com/toanln-cov/CVE-2026-76565
A proof-of-concept has been released for CVE-2026-76565, a reflected cross-site scripting (XSS) vulnerability affecting PhocaCart ≤ 6.1.7 for Joomla.
The vulnerability exists in the price_from and price_to filter parameters within the mod_phocacart_filter module. Due to improper output encoding, unauthenticated attackers can craft a malicious URL that injects JavaScript into the page when viewed by a victim.
The PoC demonstrates:
• Reflected XSS through crafted GET parameters
• Exploitation of vulnerable price filter inputs
• Attribute-context injection caused by missing htmlspecialchars() encoding
• No authentication requirement for exploitation
• Affected versions: PhocaCart ≤ 6.1.7
• Fixed version: PhocaCart 6.1.8
💥 No delays. No guessing. No redactions. Get the intel before everyone else with Dark Web Informer.
##updated 2026-08-19T21:30:40
2 posts
1 repos
TP-Link patches CVE-2026-75616, an Archer C20 command injection flaw that can lead to full device compromise. Update firmware now.
#TPLink #ArcherC20 #CommandInjection #CVE #RouterSecurity #InfoSec #PatchNow
##TP-Link patches CVE-2026-75616, an Archer C20 command injection flaw that can lead to full device compromise. Update firmware now.
#TPLink #ArcherC20 #CommandInjection #CVE #RouterSecurity #InfoSec #PatchNow
##updated 2026-08-19T21:30:30
2 posts
IBM patches two Power Systems Firmware flaws, CVE-2026-16687 and CVE-2026-16835, both CVSS 9.6, that grant full control of the managed system.
#IBM #PowerSystems #Firmware #CVE #RCE #AuthBypass #InfoSec #PatchNow
##IBM patches two Power Systems Firmware flaws, CVE-2026-16687 and CVE-2026-16835, both CVSS 9.6, that grant full control of the managed system.
#IBM #PowerSystems #Firmware #CVE #RCE #AuthBypass #InfoSec #PatchNow
##updated 2026-08-19T17:21:05.127000
2 posts
CVE-2026-74480 (CVSS 9.8) is a Linux kernel bridge flaw enabling root privilege escalation. Exploit code and a demo video are now public.
#Linux #CVE202674480 #PrivilegeEscalation #KernelSecurity #CyberSecurity #InfoSec
https://securityonline.info/linux-cve-2026-74480/?utm_source=mastodon&utm_medium=jetpack_social
##CVE-2026-74480 (CVSS 9.8) is a Linux kernel bridge flaw enabling root privilege escalation. Exploit code and a demo video are now public.
#Linux #CVE202674480 #PrivilegeEscalation #KernelSecurity #CyberSecurity #InfoSec
https://securityonline.info/linux-cve-2026-74480/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-08-19T15:32:47
2 posts
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
updated 2026-08-19T15:32:33
2 posts
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
updated 2026-08-19T04:17:34.547000
1 posts
3 repos
https://github.com/acheong08/CVE-2026-65400
Apple macOS Screen Sharing Under Attack: Someone Claims a Dark Web List Exposes 24,000 Potentially Vulnerable Hosts + Video
A New Warning for Mac Users A disturbing development surrounding a recently disclosed Apple macOS vulnerability has pushed Screen Sharing security back into the spotlight. A threat actor on an underground forum has reportedly distributed a list containing approximately 24,000 internet-accessible hosts that may be relevant to CVE-2026-65400, a…
##updated 2026-08-19T04:16:58.560000
2 posts
2 repos
🏆 New Achievement! UDP Knocking, Nobody's Dropping!
COMPLIANCE MODE ENGAGED. Action item detected: patch CVE-2026-33824. Executing optimal response: notifying you that Microsoft patched this in April 2026 and that Palo Alto Networks Unit 42 has observed a Chinese-speaking threat actor actively exploiting it anyway, on every supported Windows 10, 11, and Server release, via maliciously crafted packets on UDP ports 500 or 4500, requiring zero privileges. Patch applied? No? Logging that. (1/2)
##🏆 New Achievement! UDP Knocking, Nobody's Dropping!
COMPLIANCE MODE ENGAGED. Action item detected: patch CVE-2026-33824. Executing optimal response: notifying you that Microsoft patched this in April 2026 and that Palo Alto Networks Unit 42 has observed a Chinese-speaking threat actor actively exploiting it anyway, on every supported Windows 10, 11, and Server release, via maliciously crafted packets on UDP ports 500 or 4500, requiring zero privileges. Patch applied? No? Logging that. (1/2)
##updated 2026-08-19T03:31:21
13 posts
6 repos
https://github.com/Snizi/CVE-2026-18963-Exploit
https://github.com/Red-Darkin/CVE-2026-18963-keycloak
https://github.com/kyos-public/keycloak-cve-2026-18963-hunt
https://github.com/T0w0T/POC-CVE-2026-18963
Note the recently disclosed CVE-2026-18963 for #Keycloak OIDC: https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html . It allows unauthorized users to take over any account on your server.
On the #Slackware #Forgejo instance https://forge.slackware.nl/ I have upgraded Keycloak to 26.7.2 to address this vulnerability.
⚠️ CRITICAL: Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
Critical flaw in Keycloak (CVE-2026-18963, CVSS 9.1) allows unauthenticated attackers to reset any user password and take over accounts due to improper state validation in the password recovery flow. Any organization running Keycloak without patches is immediately at risk of account takeover on all…
🤖 AI generated summary
##⚠️ Critical Keycloak flaw enables account takeover
CVE-2026-18963 lets unauthenticated attackers reset any user's password, bypassing email verification.
##🏆 New Achievement! Exhibit A: Your Password Reset Button!
Counsel will direct the court's attention to CVE-2026-18963, rated a damning 9.1 out of 10, wherein Keycloak's reset-credentials authentication flow failed to properly validate state — legally speaking, an open invitation any unauthenticated remote party was fully entitled to accept. No user interaction required. The attacker needed nothing. No account, no session, no strongly-worded letter. (1/2)
##Geopolitical tensions rise as US-Iran dispute over Strait of Hormuz escalates; UK pledges long-range missile tech to Ukraine. Nvidia increases AI server prices over 15% due to memory costs. Critical Keycloak flaw (CVE-2026-18963) found allowing account takeovers, while Apple warns of mercenary spyware.
##Critical Keycloak Password Reset Flaw Allows Unauthenticated Account Takeover
Red Hat and Keycloak patched a critical vulnerability (CVE-2026-18963) that allows unauthenticated attackers to bypass email verification and take over any account via the password reset flow. The update also addresses over 20 other security flaws, including account-linking bypasses and administrative permission leaks.
**If you run Keycloak or Red Hat Build of Keycloak, update immediately to Keycloak 26.7.2 or RHBK 26.4.15 / 26.6.6 since the older versions let anyone reset the password of any account, including admins. If you cannot patch right away, turn off the "Forgot password" option in every realm (Realm settings → Login → Forgot password) until the update is applied.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/critical-keycloak-password-reset-flaw-allows-unauthenticated-account-takeover-p-n-m-j-1/gD2P6Ple2L
📰 Critical Keycloak Flaw (CVE-2026-18963) Allows Account Takeover
🚨 CRITICAL FLAW: Keycloak is vulnerable to CVE-2026-18963 (CVSS 9.1), allowing unauthenticated remote attackers to take over any account. Patches are available—update immediately! #Keycloak #Cybersecurity #Vulnerability #CVE #IAM
##Keycloak Flaw Exposes Accounts to Unauthenticated Takeover
A critical flaw in Keycloak, rated 9.1 by Red Hat, allows hackers to hijack any account, including admin ones, by manipulating the password reset process. This vulnerability, CVE-2026-18963, lets attackers take control without even logging in.
#Cve202618963 #Keycloak #AccountTakeover #AuthenticationBypass #RedHat
##Note the recently disclosed CVE-2026-18963 for #Keycloak OIDC: https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html . It allows unauthorized users to take over any account on your server.
On the #Slackware #Forgejo instance https://forge.slackware.nl/ I have upgraded Keycloak to 26.7.2 to address this vulnerability.
⚠️ CRITICAL: Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
Critical flaw in Keycloak (CVE-2026-18963, CVSS 9.1) allows unauthenticated attackers to reset any user password and take over accounts due to improper state validation in the password recovery flow. Any organization running Keycloak without patches is immediately at risk of account takeover on all…
🤖 AI generated summary
##🏆 New Achievement! Exhibit A: Your Password Reset Button!
Counsel will direct the court's attention to CVE-2026-18963, rated a damning 9.1 out of 10, wherein Keycloak's reset-credentials authentication flow failed to properly validate state — legally speaking, an open invitation any unauthenticated remote party was fully entitled to accept. No user interaction required. The attacker needed nothing. No account, no session, no strongly-worded letter. (1/2)
##Geopolitical tensions rise as US-Iran dispute over Strait of Hormuz escalates; UK pledges long-range missile tech to Ukraine. Nvidia increases AI server prices over 15% due to memory costs. Critical Keycloak flaw (CVE-2026-18963) found allowing account takeovers, while Apple warns of mercenary spyware.
##Critical Keycloak Password Reset Flaw Allows Unauthenticated Account Takeover
Red Hat and Keycloak patched a critical vulnerability (CVE-2026-18963) that allows unauthenticated attackers to bypass email verification and take over any account via the password reset flow. The update also addresses over 20 other security flaws, including account-linking bypasses and administrative permission leaks.
**If you run Keycloak or Red Hat Build of Keycloak, update immediately to Keycloak 26.7.2 or RHBK 26.4.15 / 26.6.6 since the older versions let anyone reset the password of any account, including admins. If you cannot patch right away, turn off the "Forgot password" option in every realm (Realm settings → Login → Forgot password) until the update is applied.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/critical-keycloak-password-reset-flaw-allows-unauthenticated-account-takeover-p-n-m-j-1/gD2P6Ple2L
updated 2026-08-18T18:32:52
1 posts
2 repos
Chińskie grupy APT wykorzystują podatność CVE-2026-59310 do masowych ataków na środowiska VMware vCenter
Zespół reagowania na incydenty firmy QUIRSO podczas analizy powłamaniowej serwera VMware vCenter natrafił na ślady globalnej kampanii, sterowanej najprawdopodobniej przez chińską grupę APT. Badania wykazały, że cyberprzestępcy wykorzystali krytyczną podatność CVE-2026-59310 (CVSS 9.8) w usłudze Syslog Server. Równolegle zidentyfikowali próby użycia drugiej luki CVE-2026-59309 (CVSS 9.8) jednak analitycy nie powiązali...
##updated 2026-08-18T18:32:50
4 posts
2 repos
New.
VulnCheck: Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce @vulncheck #infosec #threatresearch #Microsoft #SharePoint #vulnerability
##Chaining CVE-2026-55040 and CVE-2026-63520 for full auth bypass-to-RCE in Microsoft SharePoint: https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce
##New.
VulnCheck: Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce @vulncheck #infosec #threatresearch #Microsoft #SharePoint #vulnerability
##Chaining CVE-2026-55040 and CVE-2026-63520 for full auth bypass-to-RCE in Microsoft SharePoint: https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce
##updated 2026-08-18T14:17:10.330000
2 posts
2 repos
A public PoC named VsockDrop turns CVE-2026-53365 into unprivileged local privilege escalation to root on Linux.
#CVE202653365 #VsockDrop #LinuxKernel #PrivilegeEscalation #vsock #LPE
##A public PoC named VsockDrop turns CVE-2026-53365 into unprivileged local privilege escalation to root on Linux.
#CVE202653365 #VsockDrop #LinuxKernel #PrivilegeEscalation #vsock #LPE
##updated 2026-08-18T06:31:55
2 posts
3 repos
https://github.com/yora1928/cve-2026-15748
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
updated 2026-08-18T03:31:14
2 posts
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
updated 2026-08-17T21:31:30
3 posts
6 repos
https://github.com/HORKimhab/CVE-2026-19650-CVE-2026-19478
https://github.com/punitdarji/Gitlab-CVE-2026-19478
https://github.com/davkharrr/CVE-2026-19478-PoC
https://github.com/dinosn/gitlab-cve-2026-19478-lab
Critical GitLab vulnerability CVE-2026-19478 lets unauthenticated attackers delete public projects. It is exploited in the wild with public PoC.
#GitLab #CVE202619478 #Vulnerability #InfoSec #CyberSecurity #PatchNow
https://securityonline.info/gitlab-cve-2026-19478/?utm_source=mastodon&utm_medium=jetpack_social
##GitLab CVE-2026-19478: A Critical Zero-Click Risk Puts Public Projects and User Data in the Crosshairs + Video
A Dangerous GitLab Flaw Is Already Being Exploited A critical vulnerability in GitLab has moved from a security advisory to an active exploitation problem, raising the pressure on organizations that operate self-managed GitLab servers. Tracked as CVE-2026-19478 and rated CVSS 9.4, the flaw can allow an attacker with no credentials to remotely modify or delete…
##Critical GitLab vulnerability CVE-2026-19478 lets unauthenticated attackers delete public projects. It is exploited in the wild with public PoC.
#GitLab #CVE202619478 #Vulnerability #InfoSec #CyberSecurity #PatchNow
https://securityonline.info/gitlab-cve-2026-19478/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-08-17T18:31:28
2 posts
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
updated 2026-08-15T18:31:24
2 posts
3 repos
https://github.com/DeadExpl0it/CVE-2026-19598-PoC
Critical Authorization Bypass in Pods Plugin Allows Full WordPress Site Takeover
A critical vulnerability in the Pods WordPress plugin (CVE-2026-19598) allows unauthenticated attackers to bypass security checks and gain administrator access. The flaw enables full site takeover by letting attackers reset administrator passwords through an exposed AJAX router.
**If you use the Pods Custom Content Types and Fields plugin on WordPress, update it ASAP to version 3.3.9.1 (or the patched release matching your branch: 2.8.23.4, 2.9.19.4, 3.0.10.4, 3.1.4.2, or 3.2.8.3). Then check your user list for admin accounts you don't recognise and reset your administrator passwords, since attackers could already have taken over the site.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/critical-authorization-bypass-in-pods-plugin-allows-full-wordpress-site-takeover-1-j-h-h-0/gD2P6Ple2L
Critical Authorization Bypass in Pods Plugin Allows Full WordPress Site Takeover
A critical vulnerability in the Pods WordPress plugin (CVE-2026-19598) allows unauthenticated attackers to bypass security checks and gain administrator access. The flaw enables full site takeover by letting attackers reset administrator passwords through an exposed AJAX router.
**If you use the Pods Custom Content Types and Fields plugin on WordPress, update it ASAP to version 3.3.9.1 (or the patched release matching your branch: 2.8.23.4, 2.9.19.4, 3.0.10.4, 3.1.4.2, or 3.2.8.3). Then check your user list for admin accounts you don't recognise and reset your administrator passwords, since attackers could already have taken over the site.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/critical-authorization-bypass-in-pods-plugin-allows-full-wordpress-site-takeover-1-j-h-h-0/gD2P6Ple2L
updated 2026-08-14T18:31:34
1 posts
🔍 Lambda Watchdog detected that CVE-2026-33818 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/666 #AWS #Lambda #Security #CVE #DevOps #SecOps
##updated 2026-08-13T15:34:46
3 posts
Two critical authentication bypass flaws in the miniOrange SAML SSO WordPress plugin can be chained to forge SAML responses and obtain admin access without credentials. Both CVE-2026-61979 and CVE-2026-15981 affect a family of seven plugins, including a free version. Exploitation attempts are already in the wild.
#WordPressSecurity #AuthenticationBypass #CriticalVulnerability #SAMLAttacks
https://cyberworldops.eu/en/wordpress-attacks-two-vulnerabilities-in-miniorange-saml-sso-plugin
##Hackers Exploit WordPress Sites in miniOrange Auth Bypass Attacks
Hackers are actively exploiting WordPress sites using a clever combination of two vulnerabilities, CVE-2026-61979 and CVE-2026-15981, to bypass authentication and gain administrator access. This stealthy attack uses the miniOrange SAML 2.0 Single Sign On plugin to forge SAML responses and hijack user sessions.
##Two critical authentication bypass flaws in the miniOrange SAML SSO WordPress plugin can be chained to forge SAML responses and obtain admin access without credentials. Both CVE-2026-61979 and CVE-2026-15981 affect a family of seven plugins, including a free version. Exploitation attempts are already in the wild.
#WordPressSecurity #AuthenticationBypass #CriticalVulnerability #SAMLAttacks
https://cyberworldops.eu/en/wordpress-attacks-two-vulnerabilities-in-miniorange-saml-sso-plugin
##updated 2026-08-13T15:34:40
2 posts
1 repos
A PostgreSQL vulnerability (CVE-2026-14669, CVSS 8.8) with public PoC exploit code allows remote code execution via to_char. Update now.
#PostgreSQL #CVE202614669 #RCE #HeapOverflow #Database #InfoSec
##A PostgreSQL vulnerability (CVE-2026-14669, CVSS 8.8) with public PoC exploit code allows remote code execution via to_char. Update now.
#PostgreSQL #CVE202614669 #RCE #HeapOverflow #Database #InfoSec
##updated 2026-08-13T13:38:30.453000
6 posts
New.
VulnCheck: Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce @vulncheck #infosec #threatresearch #Microsoft #SharePoint #vulnerability
##New.
Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520) https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520/ @Rapid7Official #infosec #Microsoft #vulnerability #threatresearch #SharePoint
##Chaining CVE-2026-55040 and CVE-2026-63520 for full auth bypass-to-RCE in Microsoft SharePoint: https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce
##New.
VulnCheck: Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce @vulncheck #infosec #threatresearch #Microsoft #SharePoint #vulnerability
##New.
Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520) https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520/ @Rapid7Official #infosec #Microsoft #vulnerability #threatresearch #SharePoint
##Chaining CVE-2026-55040 and CVE-2026-63520 for full auth bypass-to-RCE in Microsoft SharePoint: https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce
##updated 2026-08-12T15:18:30.347000
2 posts
6 repos
https://github.com/codeb0ssx/CVE-2026-72898-PoC
https://github.com/Franc-Zar/CVE-2026-72898-safe-detection
https://github.com/0xBlackash/CVE-2026-72898
https://github.com/ubitquity/Metabase-Setup-Endpoint-SQLi-Fix
🚨🇫🇷 iMapper allegedly breached through critical Metabase vulnerability, account data and database access leaked on a cybercrime forum
⠀
A forum actor claims to have compromised iMapper, a French web-connected 2D laser measurement platform for building professionals, using a vulnerability identified in the listing as CVE-2026-72898 with a claimed CVSS score of 10.0.
⠀
The exposed account dataset reportedly contains 2,463 records and includes:
⠀
• User IDs and usernames
• Password hashes
• Account roles
• Email addresses
• Phone numbers
• Professions
• MFA status and related metadata
• Language preferences
• Stripe customer IDs
• Stripe tax-related identifiers
• Measurement and display configuration fields
⠀
The data is being distributed in XLSX format. The listing also claims the compromised environment contains additional database tables and offers credentials that could provide access to those systems.
⠀
The claims, exploitation method and authenticity, availability and scope of the allegedly exposed data and database access have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇫🇷 iMapper allegedly breached through critical Metabase vulnerability, account data and database access leaked on a cybercrime forum
⠀
A forum actor claims to have compromised iMapper, a French web-connected 2D laser measurement platform for building professionals, using a vulnerability identified in the listing as CVE-2026-72898 with a claimed CVSS score of 10.0.
⠀
The exposed account dataset reportedly contains 2,463 records and includes:
⠀
• User IDs and usernames
• Password hashes
• Account roles
• Email addresses
• Phone numbers
• Professions
• MFA status and related metadata
• Language preferences
• Stripe customer IDs
• Stripe tax-related identifiers
• Measurement and display configuration fields
⠀
The data is being distributed in XLSX format. The listing also claims the compromised environment contains additional database tables and offers credentials that could provide access to those systems.
⠀
The claims, exploitation method and authenticity, availability and scope of the allegedly exposed data and database access have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
updated 2026-08-11T21:33:01
2 posts
3 repos
https://github.com/fevar54/CVE-2026-68820-Mitigation-PoC-
From Check Point Research:
Check Point Research has exposed a new wave of the #Lazarus-linked Operation Dream Job targeting defense organizations in Europe, India and Brazil. Attackers used fraudulent job opportunities and trojanized PDF software to deploy #malware, while exploiting Windows zero-day CVE-2026-68820 to obtain SYSTEM privileges and disable security visibility.
##From Check Point Research:
Check Point Research has exposed a new wave of the #Lazarus-linked Operation Dream Job targeting defense organizations in Europe, India and Brazil. Attackers used fraudulent job opportunities and trojanized PDF software to deploy #malware, while exploiting Windows zero-day CVE-2026-68820 to obtain SYSTEM privileges and disable security visibility.
##updated 2026-08-05T18:32:31
2 posts
4 repos
https://github.com/unveiledhistory49/teamcity-cve-2026-63077-remediation
https://github.com/sfewer-r7/CVE-2026-63077
https://github.com/BoredHackerBlog/teamcity-CVE-2026-63077-pcap
CVE-2026-63077 is a TeamCity unauthenticated RCE, now exploited in the wild with a public PoC. Australia's ACSC confirms active attacks.
#TeamCity #CVE202663077 #RCE #CyberSecurity #JetBrains #CISAKEV
https://securityonline.info/teamcity-cve-2026-63077/?utm_source=mastodon&utm_medium=jetpack_social
##CVE-2026-63077 is a TeamCity unauthenticated RCE, now exploited in the wild with a public PoC. Australia's ACSC confirms active attacks.
#TeamCity #CVE202663077 #RCE #CyberSecurity #JetBrains #CISAKEV
https://securityonline.info/teamcity-cve-2026-63077/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-07-30T15:31:54
1 posts
Chińskie grupy APT wykorzystują podatność CVE-2026-59310 do masowych ataków na środowiska VMware vCenter
Zespół reagowania na incydenty firmy QUIRSO podczas analizy powłamaniowej serwera VMware vCenter natrafił na ślady globalnej kampanii, sterowanej najprawdopodobniej przez chińską grupę APT. Badania wykazały, że cyberprzestępcy wykorzystali krytyczną podatność CVE-2026-59310 (CVSS 9.8) w usłudze Syslog Server. Równolegle zidentyfikowali próby użycia drugiej luki CVE-2026-59309 (CVSS 9.8) jednak analitycy nie powiązali...
##updated 2026-07-23T21:31:09
3 posts
1 repos
Two critical authentication bypass flaws in the miniOrange SAML SSO WordPress plugin can be chained to forge SAML responses and obtain admin access without credentials. Both CVE-2026-61979 and CVE-2026-15981 affect a family of seven plugins, including a free version. Exploitation attempts are already in the wild.
#WordPressSecurity #AuthenticationBypass #CriticalVulnerability #SAMLAttacks
https://cyberworldops.eu/en/wordpress-attacks-two-vulnerabilities-in-miniorange-saml-sso-plugin
##Hackers Exploit WordPress Sites in miniOrange Auth Bypass Attacks
Hackers are actively exploiting WordPress sites using a clever combination of two vulnerabilities, CVE-2026-61979 and CVE-2026-15981, to bypass authentication and gain administrator access. This stealthy attack uses the miniOrange SAML 2.0 Single Sign On plugin to forge SAML responses and hijack user sessions.
##Two critical authentication bypass flaws in the miniOrange SAML SSO WordPress plugin can be chained to forge SAML responses and obtain admin access without credentials. Both CVE-2026-61979 and CVE-2026-15981 affect a family of seven plugins, including a free version. Exploitation attempts are already in the wild.
#WordPressSecurity #AuthenticationBypass #CriticalVulnerability #SAMLAttacks
https://cyberworldops.eu/en/wordpress-attacks-two-vulnerabilities-in-miniorange-saml-sso-plugin
##updated 2026-07-15T02:21:07.520000
2 posts
🔴 CVE-2026-76835 - Critical (9.1)
OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/ut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76835/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-76835 - Critical (9.1)
OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/ut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76835/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-10T19:32:48
1 posts
🟠 CVE-2026-54071 - High (7.8)
BabelDOC is a document translation tool. Prior to 0.6.3, BabelDOC's vendored PDF parser in babeldoc/pdfminer/cmapdb.py deserializes untrusted pickle data when CMapDB._load_data() loads CMap files. PDF-controlled Encoding or CMapName values and emb...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54071/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-08T15:13:08.090000
2 posts
CVE-2026-52912, a Linux kernel netfilter use-after-free, now has public PoC exploit code enabling root privilege escalation.
#CVE202652912 #LinuxKernel #PrivilegeEscalation #Netfilter #UseAfterFree #PoC #Exploit #InfoSec
##CVE-2026-52912, a Linux kernel netfilter use-after-free, now has public PoC exploit code enabling root privilege escalation.
#CVE202652912 #LinuxKernel #PrivilegeEscalation #Netfilter #UseAfterFree #PoC #Exploit #InfoSec
##updated 2026-06-29T20:17:32.607000
1 posts
updated 2026-06-27T06:30:25
1 posts
44 repos
https://github.com/jelasin/CVE-2026-42945
https://github.com/nu0l/NGINX-Rift
https://github.com/quantumworld-dpdns-io/CVE-2026-42945
https://github.com/rheodev/CVE-2026-42945
https://github.com/oseasfr/Scanner_CVE_2026-42945
https://github.com/sibersan/web-server-audit_CVE-2026-42945
https://github.com/edgecases-PurpleHax/cve-images
https://github.com/nanwinata/nginxrift-CVE-2026-42945
https://github.com/gagaltotal/CVE-2026-42945-NGINX-Rift-Toolkit
https://github.com/lowilol/CVE-2026-42945-NGINX-Rift-Check-Script
https://github.com/forxiucn/nginx-cve-2026-42945-poc
https://github.com/BarAppTeam/nginx-cve-fix
https://github.com/simota/nginx-rift-scanner
https://github.com/limo57640-crypto/nginx-rift-detector
https://github.com/azilRababe/CVE-2026-42945
https://github.com/LiaoZiqi-GZFLS/CVE-2026-42945
https://github.com/Kentox493/CVE-2026-42945_NginxRift
https://github.com/hnytgl/CVE-2026-42945
https://github.com/imSre9/CVE-2026-42945
https://github.com/cipherspy/CVE-2026-42945-POC
https://github.com/tal7aouy/nginx-cve-2026-42945
https://github.com/friparia/NGINX_RIFT_SCAN_CVE_2026_42945
https://github.com/ChamsBouzaiene/ai-vuln-rediscovery-nginx-cve-2026-42945
https://github.com/dinosn/cve-2026-42945-nginx32-lab
https://github.com/yusufdalbudak/CVE-2026-42945
https://github.com/chenqin231/CVE-2026-42945
https://github.com/realityone/cve-2026-42945-scan
https://github.com/sec-sys/CVE-2026-42945-Reverse-Shell-POC
https://github.com/0xBlackash/CVE-2026-42945
https://github.com/byezero/nginx-cve-2026-42945-check
https://github.com/CynepMyx/nginx-rift-check
https://github.com/josephfelix/CVE-2026-42945-nginx-rift
https://github.com/strivepan/Nginx_cve-2026-42945-scanner-gui
https://github.com/MateusVerass/nGixshell
https://github.com/p3Nt3st3r-sTAr/CVE-2026-42945-POC
https://github.com/webdev75950-ux/nginx-rce-cve-2026-42945
https://github.com/hulina9900-boop/DIY-CVE-2026-42945-POC
https://github.com/Renison-Gohel/CVE-2026-42945-NGINX-Rift
https://github.com/aratane/CVE-2026-42945
https://github.com/fkj-src/fix_nginx_cve_2026_42945
https://github.com/soksofos/wazuh-nginx-cve-2026-42945-sca-lab
https://github.com/iammerrida-source/nginx-rift-detect
Nginx Rift is a proof of concept for CVE-2026-42945, a heap buffer overflow in NGINX's rewrite module that allows unauthenticated remote code execution on servers using rewrite and set directives
The README lists affected and fixed versions
updated 2026-06-26T19:13:19
2 posts
🔴 CVE-2026-48769 - Critical (9.9)
Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48769/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-48769 - Critical (9.9)
Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48769/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-06-26T18:47:27
2 posts
🔴 CVE-2026-48753 - Critical (9.9)
Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command exec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48753/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-48753 - Critical (9.9)
Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command exec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48753/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-06-26T18:33:56
2 posts
🔴 CVE-2026-48751 - Critical (9.9)
Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusing lowlevel hooks s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48751/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-48751 - Critical (9.9)
Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusing lowlevel hooks s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48751/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-06-26T18:32:53
2 posts
🔴 CVE-2026-48750 - Critical (9.9)
Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the instance. If `exec-output...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48750/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-48750 - Critical (9.9)
Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the instance. If `exec-output...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48750/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-06-26T15:33:15
1 posts
1 repos
⚠️ Cl0p names 40 Windchill victims
Cl0p exploited CVE-2026-12569 to deploy web shells and steal blueprints and project data.
##updated 2026-06-17T03:20:57.470000
1 posts
CVE-2020-5135 - Changed to Known Ransomware Status
SonicWall SonicOS Buffer Overflow VulnerabilityVendor: SonicWallProduct: SonicOSA buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 21, 2026 at 13:08:17 UTCDate Added tohttps://nvd.nist.gov/vuln/detail/CVE-2020-5135
##updated 2026-05-19T15:31:20
4 posts
@agowa338 It's an incomplete fix for CVE-2025-9615:
##A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.
i uSe lInUx bEcAuSe iT'S SeCuRe.
https://access.redhat.com/security/cve/cve-2026-19685
##NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.
@agowa338 It's an incomplete fix for CVE-2025-9615:
##A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.
i uSe lInUx bEcAuSe iT'S SeCuRe.
https://access.redhat.com/security/cve/cve-2026-19685
##NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.
updated 2025-10-22T03:31:35
1 posts
2 repos
https://github.com/Sunqiz/CVE-2012-0158-reproduction
https://github.com/RobertoLeonFR-ES/Exploit-Win32.CVE-2012-0158.F.doc
CVE-2012-0158 - Changed to Known Ransomware Status
Microsoft MSCOMCTL.OCX Remote Code Execution VulnerabilityVendor: MicrosoftProduct: MSCOMCTL.OCXMicrosoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current user.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August https://nvd.nist.gov/vuln/detail/CVE-2012-0158
##updated 2025-10-22T00:33:30
1 posts
1 repos
CVE-2021-43226 - Changed to Known Ransomware Status
Microsoft Windows Privilege Escalation VulnerabilityVendor: MicrosoftProduct: WindowsMicrosoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 21, 2026 at 13:08:17 UTCDate Added to https://nvd.nist.gov/vuln/detail/CVE-2021-43226
##updated 2025-10-22T00:32:21
2 posts
3 repos
https://github.com/bp2008/DahuaLoginBypass
Ktoś przejął 14 530 kamer Dahua
W okresie od 17 czerwca do 22 lipca 2026r. ktoś zhackował co najmniej 14 530 kamer IP (i innych urządzeń) marki Dahua. Ale popełnił jeden błąd, dzięki czemu cała operacja wyszła na jaw — narzędzia włamywaczy wykorzystane do tej operacji, wraz z dodatkowymi informacjami zostały znalezione na jednym z hostów wykorzystywanych do ataków.
Operacja CameraSwarm
Jak ustalili badacze, atak na kamery realizowano głównie na terytorium Ukrainy i Rosji, a włamywacze wykorzystywali 3 techniki:
zgadywanie loginów i haseł na porcie TCP/37777 (skutek: 12324 przejętych urządzeń)
wykorzystanie podatności CVE-2021-33044 i CVE-2021-33045 (umożliwiły dostęp do niezałatanych urządzeń i instaloacje konta-backdoora p2pwn na 1923 kamerach. Tak, to podatność załatana 5 lat temu…)
mechanizm P2P Dahua (dostęp do 283 kamer za NAT-em przy użyciu numeru seryjnego i danych zaszytych w klientach Dahua).
Analiza narzędzi opublikowanych przez włamywaczy ujawniła też, że z przejętych kamer odrzucali ciemne/nieużyteczne klatki a resztę (plus ewentualne dane logowania) wysyłali na Telegram.
Mam kamerę Dahua, co robić, jak żyć?
Choć raport badaczy nie wymienia Polski wśród głównych obszarów potwierdzonych przejęć, to skanowanie miało zasięg globalny. Marka ma w Polsce oficjalnych dystrybutorów i szeroką ofertę sprzętu do domu i firm, dlatego powinniście sprawdzić swoje urządzenia, nawet jeśli nie otrzymaliście żadnego alertu.
Jeśli kamera Dahua była dostępna z internetu na porcie 37777/tcp w czerwcu lub lipcu 2026r., potraktujcie ją jako potencjalnie przejętą i:
sprawdź listę użytkowników i usuń konto p2pwn, jeśli istnieje;
zaktualizuj firmware do najnowszej wersji właściwej dla konkretnego modelu;
wyłącz P2P, jeśli go nie potrzebujesz, oraz nie wystawiaj portu 37777 do internetu;
zmień hasła kamery, [...]
#CCTV #Dahua #Kamery #Monitoring #Rosja #Ukraina
https://niebezpiecznik.pl/post/ktos-przejal-14-530-kamer-dahua/
##Ktoś przejął 14 530 kamer Dahua
W okresie od 17 czerwca do 22 lipca 2026r. ktoś zhackował co najmniej 14 530 kamer IP (i innych urządzeń) marki Dahua. Ale popełnił jeden błąd, dzięki czemu cała operacja wyszła na jaw — narzędzia włamywaczy wykorzystane do tej operacji, wraz z dodatkowymi informacjami zostały znalezione na jednym z hostów wykorzystywanych do ataków.
Operacja CameraSwarm
Jak ustalili badacze, atak na kamery realizowano głównie na terytorium Ukrainy i Rosji, a włamywacze wykorzystywali 3 techniki:
zgadywanie loginów i haseł na porcie TCP/37777 (skutek: 12324 przejętych urządzeń)
wykorzystanie podatności CVE-2021-33044 i CVE-2021-33045 (umożliwiły dostęp do niezałatanych urządzeń i instaloacje konta-backdoora p2pwn na 1923 kamerach. Tak, to podatność załatana 5 lat temu…)
mechanizm P2P Dahua (dostęp do 283 kamer za NAT-em przy użyciu numeru seryjnego i danych zaszytych w klientach Dahua).
Analiza narzędzi opublikowanych przez włamywaczy ujawniła też, że z przejętych kamer odrzucali ciemne/nieużyteczne klatki a resztę (plus ewentualne dane logowania) wysyłali na Telegram.
Mam kamerę Dahua, co robić, jak żyć?
Choć raport badaczy nie wymienia Polski wśród głównych obszarów potwierdzonych przejęć, to skanowanie miało zasięg globalny. Marka ma w Polsce oficjalnych dystrybutorów i szeroką ofertę sprzętu do domu i firm, dlatego powinniście sprawdzić swoje urządzenia, nawet jeśli nie otrzymaliście żadnego alertu.
Jeśli kamera Dahua była dostępna z internetu na porcie 37777/tcp w czerwcu lub lipcu 2026r., potraktujcie ją jako potencjalnie przejętą i:
sprawdź listę użytkowników i usuń konto p2pwn, jeśli istnieje;
zaktualizuj firmware do najnowszej wersji właściwej dla konkretnego modelu;
wyłącz P2P, jeśli go nie potrzebujesz, oraz nie wystawiaj portu 37777 do internetu;
zmień hasła kamery, [...]
#CCTV #Dahua #Kamery #Monitoring #Rosja #Ukraina
https://niebezpiecznik.pl/post/ktos-przejal-14-530-kamer-dahua/
##updated 2025-10-22T00:32:20
2 posts
9 repos
https://github.com/Baza-NATO/CVE-2021-33044
https://github.com/litndat/Camera-Dahua-Research-l-h-ng-CVE-2021-33044
https://github.com/haingn/LoHongCam-CVE-2021-33044
https://github.com/umair-aziz025/dahua-cve-research
https://github.com/jorhelp/Ingram
https://github.com/nasimanpha-create/ing-switch
https://github.com/eagle-nett/DAHUA_AUTH-BYPASS-CVE-2021-33044
Ktoś przejął 14 530 kamer Dahua
W okresie od 17 czerwca do 22 lipca 2026r. ktoś zhackował co najmniej 14 530 kamer IP (i innych urządzeń) marki Dahua. Ale popełnił jeden błąd, dzięki czemu cała operacja wyszła na jaw — narzędzia włamywaczy wykorzystane do tej operacji, wraz z dodatkowymi informacjami zostały znalezione na jednym z hostów wykorzystywanych do ataków.
Operacja CameraSwarm
Jak ustalili badacze, atak na kamery realizowano głównie na terytorium Ukrainy i Rosji, a włamywacze wykorzystywali 3 techniki:
zgadywanie loginów i haseł na porcie TCP/37777 (skutek: 12324 przejętych urządzeń)
wykorzystanie podatności CVE-2021-33044 i CVE-2021-33045 (umożliwiły dostęp do niezałatanych urządzeń i instaloacje konta-backdoora p2pwn na 1923 kamerach. Tak, to podatność załatana 5 lat temu…)
mechanizm P2P Dahua (dostęp do 283 kamer za NAT-em przy użyciu numeru seryjnego i danych zaszytych w klientach Dahua).
Analiza narzędzi opublikowanych przez włamywaczy ujawniła też, że z przejętych kamer odrzucali ciemne/nieużyteczne klatki a resztę (plus ewentualne dane logowania) wysyłali na Telegram.
Mam kamerę Dahua, co robić, jak żyć?
Choć raport badaczy nie wymienia Polski wśród głównych obszarów potwierdzonych przejęć, to skanowanie miało zasięg globalny. Marka ma w Polsce oficjalnych dystrybutorów i szeroką ofertę sprzętu do domu i firm, dlatego powinniście sprawdzić swoje urządzenia, nawet jeśli nie otrzymaliście żadnego alertu.
Jeśli kamera Dahua była dostępna z internetu na porcie 37777/tcp w czerwcu lub lipcu 2026r., potraktujcie ją jako potencjalnie przejętą i:
sprawdź listę użytkowników i usuń konto p2pwn, jeśli istnieje;
zaktualizuj firmware do najnowszej wersji właściwej dla konkretnego modelu;
wyłącz P2P, jeśli go nie potrzebujesz, oraz nie wystawiaj portu 37777 do internetu;
zmień hasła kamery, [...]
#CCTV #Dahua #Kamery #Monitoring #Rosja #Ukraina
https://niebezpiecznik.pl/post/ktos-przejal-14-530-kamer-dahua/
##Ktoś przejął 14 530 kamer Dahua
W okresie od 17 czerwca do 22 lipca 2026r. ktoś zhackował co najmniej 14 530 kamer IP (i innych urządzeń) marki Dahua. Ale popełnił jeden błąd, dzięki czemu cała operacja wyszła na jaw — narzędzia włamywaczy wykorzystane do tej operacji, wraz z dodatkowymi informacjami zostały znalezione na jednym z hostów wykorzystywanych do ataków.
Operacja CameraSwarm
Jak ustalili badacze, atak na kamery realizowano głównie na terytorium Ukrainy i Rosji, a włamywacze wykorzystywali 3 techniki:
zgadywanie loginów i haseł na porcie TCP/37777 (skutek: 12324 przejętych urządzeń)
wykorzystanie podatności CVE-2021-33044 i CVE-2021-33045 (umożliwiły dostęp do niezałatanych urządzeń i instaloacje konta-backdoora p2pwn na 1923 kamerach. Tak, to podatność załatana 5 lat temu…)
mechanizm P2P Dahua (dostęp do 283 kamer za NAT-em przy użyciu numeru seryjnego i danych zaszytych w klientach Dahua).
Analiza narzędzi opublikowanych przez włamywaczy ujawniła też, że z przejętych kamer odrzucali ciemne/nieużyteczne klatki a resztę (plus ewentualne dane logowania) wysyłali na Telegram.
Mam kamerę Dahua, co robić, jak żyć?
Choć raport badaczy nie wymienia Polski wśród głównych obszarów potwierdzonych przejęć, to skanowanie miało zasięg globalny. Marka ma w Polsce oficjalnych dystrybutorów i szeroką ofertę sprzętu do domu i firm, dlatego powinniście sprawdzić swoje urządzenia, nawet jeśli nie otrzymaliście żadnego alertu.
Jeśli kamera Dahua była dostępna z internetu na porcie 37777/tcp w czerwcu lub lipcu 2026r., potraktujcie ją jako potencjalnie przejętą i:
sprawdź listę użytkowników i usuń konto p2pwn, jeśli istnieje;
zaktualizuj firmware do najnowszej wersji właściwej dla konkretnego modelu;
wyłącz P2P, jeśli go nie potrzebujesz, oraz nie wystawiaj portu 37777 do internetu;
zmień hasła kamery, [...]
#CCTV #Dahua #Kamery #Monitoring #Rosja #Ukraina
https://niebezpiecznik.pl/post/ktos-przejal-14-530-kamer-dahua/
##🟠 CVE-2026-76098 - High (7.5)
Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76098/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-76098 - High (7.5)
Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76098/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-66897: Canonical LXD CRITICAL path traversal (CVSS 9.9). Attackers with container edit rights or crafted images can overwrite host files as root. Restrict permissions & avoid untrusted images. Patch status unknown. https://radar.offseq.com/threat/cve-2026-66897-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-b6ae23dfc47f5562 #OffSeq #LXD #CVE #Linux
##CVE-2026-66897: Canonical LXD CRITICAL path traversal (CVSS 9.9). Attackers with container edit rights or crafted images can overwrite host files as root. Restrict permissions & avoid untrusted images. Patch status unknown. https://radar.offseq.com/threat/cve-2026-66897-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-b6ae23dfc47f5562 #OffSeq #LXD #CVE #Linux
##CVE-2026-78251 (CRITICAL): DJI Neo & related drones have hard-coded FTP creds, letting attackers fill storage & disrupt logging/updates via network or USB. Patch required! https://radar.offseq.com/threat/cve-2026-78251-cwe-798-use-of-hard-coded-credentials-in-dji-neo-98f2d4e34b35b2e0 #OffSeq #CVE2026_78251 #DJI #DroneSec
##CVE-2026-78251 (CRITICAL): DJI Neo & related drones have hard-coded FTP creds, letting attackers fill storage & disrupt logging/updates via network or USB. Patch required! https://radar.offseq.com/threat/cve-2026-78251-cwe-798-use-of-hard-coded-credentials-in-dji-neo-98f2d4e34b35b2e0 #OffSeq #CVE2026_78251 #DJI #DroneSec
##🟠 CVE-2026-55621 - High (7.7)
Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where an attacker knowing the name of a project that they don't have access to and the name of a custom v...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55621/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-55621 - High (7.7)
Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where an attacker knowing the name of a project that they don't have access to and the name of a custom v...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55621/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##‼️ CVE-2026-39113: Heap Buffer Overflow in SQLite's Optional SQLAR Extension
##‼️ CVE-2026-39113: Heap Buffer Overflow in SQLite's Optional SQLAR Extension
##CVE-2026-50538 - Critical OOB heap write in LibVNCServer's libvncclient. Malicious VNC server can overwrite memory pre-auth. CVSS 8.8. Update to fixed version now. #CVE #infosec #LibVNCServer
##🟠 CVE-2026-50538 - High (8.8)
LibVNCClient is a library for easy implementation of a VNC client. In versions 0.9.12 through 0.9.15, a malicious (or man-in-the-middle) VNC server can force a connecting `libvncclient` to write attacker-controlled data past the end of its framebu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50538/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-63125 - Critical (9.9)
Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can execute arbitrary code as root on...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63125/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-63125 - Critical (9.9)
Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can execute arbitrary code as root on...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63125/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-62941 - Critical (9.9)
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs BEFORE the source instance's configuration is merged into the r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62941/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-62941 - Critical (9.9)
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs BEFORE the source instance's configuration is merged into the r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62941/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-62940 - Critical (9.9)
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied configuration overrides (including security-critical keys like `security.privileged` and `raw.lxc`...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62940/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-62940 - Critical (9.9)
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied configuration overrides (including security-critical keys like `security.privileged` and `raw.lxc`...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62940/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-62867 - Critical (9.9)
Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument injection in the constructed filesystem creation command...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62867/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-62867 - Critical (9.9)
Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument injection in the constructed filesystem creation command...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62867/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-55241 - High (7.5)
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. Prior to 3.9.1, the public POST /api/v1/auth/register route in server/sr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55241/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-30826 - High (8)
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the testing OQL query functionality. This issue has been fixed in version 3.2.3.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-30826/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-30890 - High (8)
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the synchro import script. This issue has been fixed in version 3.2.3.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-30890/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-62316 - High (8.8)
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_server.py binds a FastMCP streamable HTTP server to localhost:8010 but does not validate the Host, O...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62316/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-62283 - Critical (9.9)
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 through 2.0.9 do not bind stream identifiers created by CreateStream in service/rpc/io_stream.go to th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62283/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-49849 (CRITICAL): 4xmen xShop <3.0.4 lets authenticated admins upload dangerous files, leading to remote code execution 🛡️. Patch to 3.0.4 now. https://radar.offseq.com/threat/cve-2026-49849-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-4xmen-xshop-bbb8f71dbe4a15a6 #OffSeq #CVE202649849 #remotecodeexecution #infosec
##🔴 CVE-2026-49849 - Critical (9.1)
xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allows an authenticated administrator to upload executable files (e.g., .php). By uploading a specially crafted php file, an attack...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49849/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-34948 - High (7.7)
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, only classes present in the SELECT clause are protected by the silos access check in OQL. This issue has been fixed in version 3.2.3.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-34948/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-31936 - High (8.8)
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, users can access to unauthorized object information through the search operation. This issue has been fixed in version 3.2.3.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-31936/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-34741 - High (8.6)
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass allows unauthenticated remote attackers to execute arbitrary PHP files from the env-production directory on a new iTop instance in the production environ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-34741/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-53527 - High (8.8)
LeafWiki is a self-hosted wiki. Versions 0.1.0 through 0.10.0 have a privilege escalation vulnerability in the user update API. An authenticated user could update their own account role and escalate privileges from a regular user, such as `viewer`...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53527/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-77811 - High (8.7)
Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated user with write permissions to OpenSearch Dashboards saved objects to execute arbitrary JavaScript in the context of other user...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77811/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-62677 - High (8.8)
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, an authenticated user can upload a session-scoped agent bundle with an absolute or traversal-containing os_env.cwd value because omnige...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62677/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-27462 - High (7.5)
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, leading to user enumeration. This issue has been fi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-27462/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-30866 - High (7.5)
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has been fixed in version 3.2.3.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-30866/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-77810 - Critical (9.9)
In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector. To remediate this issue, users should upgrade to aws-athena-query-federat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77810/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-54682 - High (8.2)
DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and FormatEmbedMarkdownAsync in DiscordChatExporter.Core/...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54682/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-62674 - Critical (9)
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent checks LEVEL_EDIT permission for a session but does not reject a bound shared or template agent whose ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62674/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-71862 - High (7.5)
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.3.0 until 3.9.2, enabling the global showURL setting causes the u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71862/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##