## Updated at UTC 2026-09-03T00:45:24.578759

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-82641 8.6 0.34% 1 0 2026-09-02T21:33:01 keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to
CVE-2026-9586 9.8 1.09% 19 1 template 2026-09-02T20:55:56.223000 An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB E
CVE-2026-83548 10.0 0.27% 19 0 2026-09-02T20:40:13.683000 A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Pla
CVE-2026-84372 9.8 0.41% 2 0 2026-09-02T20:17:40.793000 Predis is a flexible and feature-complete Redis and Valkey client for PHP. From
CVE-2026-84292 7.5 0.00% 2 0 2026-09-02T20:17:39.543000 fast-uri serializes the port component of a URI without validating it. When reco
CVE-2026-20276 8.6 0.00% 2 0 2026-09-02T19:23:13.660000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-84382 7.5 0.00% 2 0 2026-09-02T19:18:08.353000 HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2
CVE-2026-84381 8.1 0.00% 2 0 2026-09-02T19:18:08.217000 HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 f
CVE-2026-49832 8.0 0.00% 2 0 2026-09-02T19:17:19.197000 DSpace open source software is a repository application which provides durable a
CVE-2026-19117 9.8 0.00% 4 0 2026-09-02T19:17:16.490000 Under specific conditions, an attacker can register an attacker-controlled FIDO2
CVE-2026-20275 8.8 0.00% 2 0 2026-09-02T18:32:32 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20274 9.8 0.00% 2 0 2026-09-02T18:32:31 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20212 9.8 0.00% 2 0 2026-09-02T18:32:26 A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switc
CVE-2026-78689 8.1 0.00% 2 0 2026-09-02T18:32:17 Description NGINX JavaScript (njs) has a vulnerability in the XML module's nam
CVE-2026-83549 7.8 0.92% 16 0 2026-09-02T18:32:06 Post-authentication Improper Neutralization of Special Elements used in an OS Co
CVE-2026-73773 7.5 0.26% 2 0 2026-09-02T18:32:05 An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpo
CVE-2026-82329 9.8 1.24% 27 4 template 2026-09-02T18:31:57 JFrog Artifactory contains an authentication weakness that, under default config
CVE-2026-66786 9.1 0.00% 2 0 2026-09-02T18:21:10.517000 A flaw was found in submariner. In cert-auth mode, the connection configuration
CVE-2026-53649 9.6 0.00% 2 0 2026-09-02T18:19:59.973000 Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default pro
CVE-2026-48710 6.5 2.10% 6 5 template 2026-09-02T18:19:22.917000 Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the H
CVE-2026-79755 8.0 0.00% 2 0 2026-09-02T17:17:59.940000 Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Pri
CVE-2026-84715 8.8 0.32% 2 0 2026-09-02T16:17:32.813000 FeatherPanel versions before 1.3.7.10 fail to validate permissions in the Subuse
CVE-2026-47864 6.4 3.44% 1 0 2026-09-02T15:40:07.763000 SerializingHttpMessageConverter deserializes the body of incoming HTTP requests
CVE-2026-73782 8.8 0.27% 2 0 2026-09-02T15:34:39 A format string vulnerability exists in the command line interface of AOS-CX tha
CVE-2026-73780 8.3 0.24% 1 0 2026-09-02T15:34:38 A vulnerability in the web-based management interface of AOS-CX switches exposes
CVE-2026-79750 7.7 0.25% 1 0 2026-09-02T15:17:42.163000 MCPHub is a unified hub for centrally managing and dynamically orchestrating mul
CVE-2026-76657 10.0 0.43% 2 0 2026-09-02T15:14:09.307000 Vulnerabilities have been identified in the API of HPE Networking Fabric Compose
CVE-2026-76658 10.0 0.43% 2 0 2026-09-02T15:12:31.233000 A vulnerability has been identified in the SSH daemon of HPE Networking Fabric C
CVE-2026-84702 7.5 0.38% 2 0 2026-09-02T14:17:16.917000 facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name
CVE-2026-14982 8.1 0.52% 2 0 2026-09-02T13:55:27.963000 The WP File Download plugin for WordPress is vulnerable to arbitrary file deleti
CVE-2026-84795 9.8 0.00% 2 0 2026-09-02T12:31:39 Craft CMS before 5.10.11 fails to validate the admin flag during user registrati
CVE-2025-46418 7.6 0.68% 2 0 2026-09-02T12:17:11.690000 Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media def
CVE-2026-84353 9.6 0.28% 2 0 2026-09-02T10:17:11.080000 Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.
CVE-2026-14828 8.8 1.44% 2 0 2026-09-02T09:31:34 Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 version
CVE-2026-78657 9.8 0.72% 2 0 2026-09-02T06:31:26 The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to ar
CVE-2026-9055 9.8 0.29% 2 1 2026-09-02T06:31:24 The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for W
CVE-2026-14357 8.8 0.65% 2 0 2026-09-02T06:31:24 The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in ve
CVE-2026-82393 7.5 0.41% 1 0 2026-09-02T04:18:02.693000 pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped p
CVE-2026-65643 0 0.64% 1 1 2026-09-02T04:18:01.387000 Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated user
CVE-2026-62911 8.0 1.32% 8 1 2026-09-02T04:18:00.460000 Authentication bypass by capture-replay in Microsoft Exchange Server allows an a
CVE-2026-84485 7.5 0.35% 2 0 2026-09-02T03:31:18 APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch en
CVE-2026-84484 7.5 0.48% 2 0 2026-09-02T03:31:18 ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the
CVE-2026-84699 9.1 0.37% 2 0 2026-09-02T03:31:17 Team Password Manager before 14.184.308 fails to enforce authentication requirem
CVE-2026-14957 7.5 0.56% 2 0 2026-09-02T03:31:14 In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKe
CVE-2026-84700 8.6 0.35% 2 0 2026-09-02T03:31:13 PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port
CVE-2023-54391 9.8 0.46% 2 1 2026-09-02T00:31:39 Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypa
CVE-2026-6876 0 0.40% 2 0 2026-09-01T20:55:19.100000 ServiceNow has remediated a sandbox escape security issue that was identified in
CVE-2026-82226 9.8 0.31% 1 0 2026-09-01T20:48:22.513000 Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.
CVE-2026-84268 8.8 0.33% 2 0 2026-09-01T18:30:49 A flaw was found in the SFTP backend in gvfs. When mounting a share and reading
CVE-2026-58566 8.8 0.23% 2 0 2026-09-01T18:30:49 Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged atta
CVE-2026-84202 8.8 0.37% 2 0 2026-09-01T18:17:48.503000 ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files,
CVE-2026-78319 0 0.40% 5 0 2026-09-01T18:17:46.253000 A service running on the affected products contains a potential Time-of-Check Ti
CVE-2026-80047 None 0.11% 2 0 2026-09-01T15:31:13 A vulnerability in Hugging Face Transformers (versions 4.49.0, <= 5.8.1) allows
CVE-2026-84196 7.7 0.26% 2 0 2026-09-01T15:17:43.613000 Kyverno before 1.18.0 contains a server-side request forgery vulnerability in ap
CVE-2026-56718 7.5 0.58% 1 0 2026-09-01T15:17:21.027000 AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path travers
CVE-2026-84199 7.7 0.26% 2 0 2026-09-01T12:31:56 Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerabilit
CVE-2026-84195 7.7 0.29% 2 0 2026-09-01T12:31:56 Kyverno before 1.16.4 automatically attaches the admission controller's ServiceA
CVE-2026-19806 8.8 0.40% 2 0 2026-09-01T06:33:01 The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Tick
CVE-2026-83772 9.9 1.69% 2 0 2026-09-01T06:33:01 A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router
CVE-2026-19952 7.5 0.78% 2 0 2026-09-01T06:33:00 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary
CVE-2026-82078 9.1 0.93% 15 2 2026-09-01T04:18:02.160000 An unsafe dynamic class loading vulnerability exists in the database connection
CVE-2026-75865 9.8 0.51% 1 0 2026-09-01T03:31:10 The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Go
CVE-2026-67394 None 1.17% 2 0 2026-09-01T03:31:09 A critical local privilege escalation via OS command injection vulnerability has
CVE-2026-82954 9.9 0.62% 1 0 2026-09-01T00:31:43 A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the fun
CVE-2026-82882 8.8 0.31% 1 0 2026-09-01T00:31:42 Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestr
CVE-2026-83596 8.8 0.29% 1 0 2026-08-31T21:32:23 A flaw was found in WebKitGTK. Processing malicious web content can cause memory
CVE-2026-82908 8.8 0.12% 1 0 2026-08-31T21:32:22 A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this
CVE-2026-81578 9.8 0.77% 13 2 2026-08-31T21:31:56 An improper access control vulnerability exists in the web management interface
CVE-2026-81934 9.8 0.43% 2 0 2026-08-31T21:31:55 Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' f
CVE-2026-82450 8.8 0.57% 1 0 2026-08-31T20:56:08.800000 BookStack before 26.05.4 contains a remote code execution vulnerability in the p
CVE-2026-82645 8.6 0.13% 1 0 2026-08-31T20:56:08.800000 AVideo (current commit e01e41ecc and earlier) exposes stream credentials through
CVE-2026-82655 7.5 0.33% 1 0 2026-08-31T20:56:08.800000 Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relati
CVE-2026-54745 10.0 0.43% 1 0 2026-08-31T20:17:05.990000 Kubeflow Pipelines enables users to build and deploy portable, scalable machine
CVE-2026-82635 8.8 0.40% 1 0 2026-08-31T19:27:23.020000 Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file
CVE-2026-12556 0 0.15% 2 0 2026-08-31T19:20:26.140000 Potential security vulnerabilities have been identified in HP Easy Start for mac
CVE-2026-55247 9.1 0.34% 1 0 2026-08-31T19:16:55.260000 plone.app.event provides the event content type for Plone. Prior to versions 5.2
CVE-2026-17615 7.5 0.28% 1 0 2026-08-31T18:31:39 A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unau
CVE-2026-83492 0 0.24% 1 0 2026-08-31T17:17:47.483000 Improper input validation vulnerability in Extend Themes Kubio AI Website Builde
CVE-2026-82639 7.5 0.30% 1 0 2026-08-31T17:17:45.737000 NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation
CVE-2026-82636 7.9 0.79% 1 0 2026-08-31T17:17:45.603000 Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during
CVE-2026-82616 9.9 0.61% 1 0 2026-08-31T06:30:34 A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is
CVE-2026-82592 9.9 0.77% 1 1 2026-08-31T00:30:32 A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function
CVE-2026-82593 9.9 0.51% 1 0 2026-08-31T00:30:32 A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41
CVE-2026-82549 8.3 0.19% 1 0 2026-08-30T18:33:59 A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an
CVE-2026-82644 7.5 0.26% 1 0 2026-08-30T15:30:35 WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting
CVE-2026-82638 7.5 0.30% 1 0 2026-08-30T15:30:34 jina-ai reader disables its private-address guard outside Google Cloud deploymen
CVE-2026-82642 8.8 0.38% 1 0 2026-08-30T15:30:34 Readest is an open-source e-book reader built on Tauri. In versions prior to 0.1
CVE-2026-82542 10.0 0.64% 2 0 2026-08-30T15:30:34 A weakness has been identified in Tenda HG10 300001138. Affected by this issue i
CVE-2026-82657 7.5 0.27% 1 0 2026-08-30T15:30:29 Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS fee
CVE-2026-82654 8.9 0.22% 1 0 2026-08-30T15:30:28 SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields
CVE-2026-82653 8.9 0.22% 1 0 2026-08-30T15:30:28 SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in con
CVE-2026-82539 9.1 0.60% 1 1 2026-08-30T12:31:39 A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This imp
CVE-2026-15980 9.8 0.45% 1 0 2026-08-30T06:30:22 The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in a
CVE-2026-82461 8.1 0.19% 1 0 2026-08-29T18:31:31 pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audien
CVE-2026-80714 9.8 0.40% 1 0 2026-08-29T07:16:52.880000 In the Linux kernel, the following vulnerability has been resolved: ipvs: do no
CVE-2026-38638 7.5 0.45% 1 0 2026-08-29T00:32:03 An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allo
CVE-2026-37237 7.5 0.53% 1 0 2026-08-29T00:30:58 vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Ser
CVE-2026-56854 7.5 0.33% 1 0 2026-08-28T22:16:52.220000 The source-address critical option in the Permissions returned by an authenticat
CVE-2026-55484 7.5 0.34% 1 0 2026-08-28T22:16:50.640000 ALOS HTTP is a Linux-first Go web framework and application server built around
CVE-2026-50979 8.1 1.43% 1 1 2026-08-28T21:32:17 A command injection vulnerability in the 'advanced/curl' component of Osbil Tech
CVE-2026-76581 9.8 0.34% 1 2 2026-08-28T20:19:54.767000 The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypa
CVE-2026-53362 7.8 0.51% 1 1 2026-08-28T20:18:10.133000 In the Linux kernel, the following vulnerability has been resolved: ipv6: accou
CVE-2026-37736 7.5 0.34% 1 0 2026-08-28T20:17:27.030000 An issue in the JsonSanitizer.sanitize() component of OWASP json-sanitizer v1.2.
CVE-2026-55215 7.5 0.42% 1 0 2026-08-28T19:03:39 ### Summary When SSL/TLS is enabled but no CA / server certificate is provided,
CVE-2026-18634 8.4 0.22% 2 0 2026-08-28T18:58:27.140000 An insecure handling of serialized objects vulnerability was found in the one of
CVE-2026-55248 9.1 0.32% 1 0 2026-08-28T18:41:35 ### Impact By adding an RSS portlet, and giving this a link to a very large file
CVE-2026-55485 8.8 0.39% 1 0 2026-08-28T18:14:13 ## Summary `piccolo_admin` uses a helper called `superuser_validators` to gate
CVE-2026-55559 9.8 0.55% 1 0 2026-08-28T17:23:05 ### Summary `templateArgs` sent to `POST /api/instances` (and `PATCH /api/insta
CVE-2026-55552 7.5 0.43% 1 0 2026-08-28T17:20:43 ### Attack type:  Unauthenticated remote  ### Impact: Attackers can access an
CVE-2026-55521 8.8 0.36% 1 0 2026-08-28T17:09:36 ### Summary Multiple Missing Function Level Access Control vulnerabilities exist
CVE-2026-55511 9.1 0.68% 1 1 2026-08-28T17:06:57 ## Overview Yamcs compiles StreamSQL expressions to Java on the fly with the Ja
CVE-2026-55065 8.1 0.35% 1 0 2026-08-28T16:50:36 ### Summary A user with only a single self-owned project can permanently destro
CVE-2026-54788 7.5 0.56% 1 0 2026-08-28T16:35:04 ### Impact Datadog tracing libraries that implement W3C Trace Context (`tracecon
CVE-2026-54755 9.6 0.39% 1 0 2026-08-28T16:25:49 ## Summary The per-entry percentages of a KDA asset's **split royalties** are v
CVE-2026-54754 9.6 0.30% 1 0 2026-08-28T16:22:16 ## Summary When a marketplace order is settled (`MarketBuy` / `BuyItNow`, and a
CVE-2026-55108 8.5 0.57% 1 0 2026-08-28T16:13:22 ### Summary KubeVela's Terraform remote configuration loader can be abused to m
CVE-2026-82222 10.0 0.42% 2 3 2026-08-28T12:30:36 Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP
CVE-2026-71362 9.1 25.14% 2 1 template 2026-08-28T00:18:09.390000 Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul
CVE-2023-49105 9.8 43.20% 1 1 template 2026-08-27T21:32:08 An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker ca
CVE-2026-71906 7.2 3.05% 1 0 2026-08-26T19:16:58.790000 Multiple DrayTek VigorAP models contain a command injection vulnerability in the
CVE-2026-18431 9.8 0.64% 1 1 2026-08-26T18:32:03 The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versi
CVE-2026-19632 9.8 0.79% 1 2 2026-08-26T18:31:52 The TranslatePress – Translate Multilingual sites with AI Translation plugin for
CVE-2026-71910 7.2 3.05% 1 0 2026-08-26T17:10:09.810000 Multiple DrayTek VigorAP models contain a command injection vulnerability in the
CVE-2026-69836 10.0 1.55% 1 2 2026-08-25T16:08:43.290000 Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized a
CVE-2026-71905 7.2 3.05% 1 0 2026-08-25T15:33:57 Multiple DrayTek VigorAP models contain a command injection vulnerability in the
CVE-2026-19949 8.8 0.54% 1 0 2026-08-25T12:31:24 The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL
CVE-2026-71914 9.8 3.07% 1 0 2026-08-24T18:31:59 Multiple DrayTek VigorAP models contain a command injection vulnerability in the
CVE-2026-71907 7.2 3.05% 1 0 2026-08-24T18:31:59 Multiple DrayTek VigorAP models contain a command injection vulnerability in the
CVE-2026-71909 7.2 3.05% 1 0 2026-08-24T18:31:59 Multiple DrayTek VigorAP models contain a command injection vulnerability in the
CVE-2026-71921 9.8 3.25% 1 0 2026-08-24T18:31:59 Multiple DrayTek VigorSwitch models contain a pre-authentication command injecti
CVE-2026-71908 7.2 3.05% 1 0 2026-08-24T18:31:58 Multiple DrayTek VigorAP models contain a command injection vulnerability in the
CVE-2026-12555 None 0.23% 2 0 2026-08-24T18:31:53 Potential security vulnerabilities have been identified in HP Easy Start for mac
CVE-2026-12554 None 0.21% 2 0 2026-08-24T18:31:53 Potential security vulnerabilities have been identified in HP Easy Start for mac
CVE-2026-68162 7.8 0.18% 2 0 2026-08-23T15:32:57 In the Linux kernel, the following vulnerability has been resolved: sctp: avoid
CVE-2026-68766 7.8 0.16% 1 0 2026-08-22T15:31:11 hashcat fails to restrict command-line options when parsing restore files, allow
CVE-2026-73570 8.9 20.53% 2 7 template 2026-08-21T18:34:48 A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) befor
CVE-2026-64849 9.3 16.41% 2 3 template 2026-08-20T19:16:57.867000 MLflow is an open source AI engineering platform for agents, large language mode
CVE-2026-32475 9.0 2.37% 2 4 template 2026-08-20T12:48:31.843000 Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Eleme
CVE-2026-65400 7.1 9.90% 2 3 2026-08-18T18:31:47 An authentication issue was addressed with improved state management. This issue
CVE-2026-19598 9.8 2.79% 1 4 2026-08-15T18:31:24 The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to
CVE-2026-14669 8.8 0.58% 1 1 2026-08-13T15:34:40 Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosin
CVE-2026-66154 8.3 0.13% 2 0 2026-08-12T00:31:10 An insufficient certificate validation in a privileged communication workflow, w
CVE-2026-66147 9.4 2.00% 2 0 2026-08-12T00:31:09 An unauthenticated command injection vulnerability was identified in the GMS Dis
CVE-2026-48376 5.4 13.92% 2 0 2026-08-11T18:31:03 is affected by an Improper Encoding or Escaping of Output vulnerability that cou
CVE-2026-58231 10.0 1.71% 1 3 2026-08-11T12:30:28 SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authent
CVE-2026-64638 0 31.20% 2 26 template 2026-08-07T19:18:51.610000 WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login s
CVE-2026-15733 9.8 13.54% 2 0 template 2026-08-07T18:31:37 A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 a
CVE-2026-63077 9.8 87.71% 2 4 template 2026-08-06T05:17:05.170000 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe
CVE-2026-18577 8.1 54.07% 2 2 template 2026-08-04T15:33:20 An incomplete patch for CVE-2026-18556 allows for authentication bypass and acco
CVE-2026-66066 None 27.86% 3 7 2026-07-30T18:23:34 ### Impact In its default configuration, a Rails application that displays image
CVE-2026-59822 None 0.52% 6 0 2026-07-22T22:38:34 ### Impact LiteLLM's MCP Streamable HTTP endpoint could allow an unauthenticate
CVE-2026-46595 10.0 0.50% 1 0 2026-07-17T15:32:15 Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server
CVE-2026-50661 6.1 0.48% 1 0 2026-07-14T18:32:36 Protection mechanism failure in Windows BitLocker allows an unauthorized attacke
CVE-2025-21913 5.5 0.20% 2 0 2026-07-14T15:32:25 In the Linux kernel, the following vulnerability has been resolved: x86/amd_nb:
CVE-2026-6875 None 77.58% 2 3 2026-07-13T21:31:30 ServiceNow has addressed a remote code execution vulnerability that was identifi
CVE-2026-52831 10.0 0.00% 2 0 2026-07-08T20:24:21 ## Summary Nuclio controller builds a `curl` invocation string for each cron tr
CVE-2026-52933 7.8 0.12% 1 0 2026-07-08T15:31:45 In the Linux kernel, the following vulnerability has been resolved: io_uring/po
CVE-2025-31277 8.8 1.48% 1 1 2026-06-30T03:35:21 The issue was addressed with improved memory handling. This issue is fixed in wa
CVE-2026-8024 9.8 0.55% 2 0 2026-06-18T15:32:09 A remote, unauthenticated attacker may exploit a deserialization of untrusted da
CVE-2025-9709 0 0.23% 2 0 2026-06-17T10:09:34.830000 On-Chip Debug and Test Interface With Improper Access Control and Improper Prote
CVE-2026-35029 None 25.07% 2 1 template 2026-05-06T18:40:48 ### Impact The `/config/update endpoint` does not enforce admin role authorizat
CVE-2026-0768 9.8 2.26% 11 2 2026-01-23T06:31:32 Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerabi
CVE-2025-43529 8.8 8.89% 1 8 2025-12-17T21:31:01 A use-after-free issue was addressed with improved memory management. This issue
CVE-2021-42260 7.5 3.35% 2 1 2025-11-04T21:31:31 TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxml
CVE-2022-38181 8.8 13.56% 1 7 2025-10-22T00:32:38 An Arm product family through 2022-08-12 mail GPU kernel driver allows non-privi
CVE-2021-31886 9.8 3.05% 3 0 2023-01-30T05:05:55 A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions),
CVE-2017-5123 8.8 3.71% 2 8 2023-01-30T05:03:17 Insufficient data validation in waitid allowed an user to escape sandboxes on Li
CVE-2026-55221 0 0.00% 2 0 N/A
CVE-2026-49869 0 0.99% 6 1 N/A
CVE-2026-82404 0 0.00% 2 0 N/A
CVE-2026-84374 0 0.57% 3 0 N/A
CVE-2026-75604 0 0.82% 3 3 N/A
CVE-2026-84375 0 0.39% 2 0 N/A
CVE-2026-84370 0 0.34% 2 0 N/A
CVE-2026-72898 0 82.32% 4 8 template N/A
CVE-2026-60004 0 86.78% 3 9 template N/A
CVE-2026-79748 0 0.33% 1 0 N/A
CVE-2026-79746 0 0.25% 1 0 N/A
CVE-2026-73296 0 2.61% 1 1 N/A
CVE-2026-31337 0 0.00% 1 1 N/A
CVE-2026-77846 0 0.14% 1 0 N/A

CVE-2026-82641
(8.6 HIGH)

EPSS: 0.34%

updated 2026-09-02T21:33:01

1 posts

keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data. Attackers can access the /agent/pcap/keylog endpoint to retrieve NSS keylog lines and decrypt recorded TLS traffic, or invoke /agent/stop and /agent/storemocks to manipulate recording sessions.

thehackerwire@mastodon.social at 2026-08-30T15:00:29.000Z ##

🟠 CVE-2026-82641 - High (8.6)

keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data. Attackers can access the /agent/pcap/keylog endpoint to retri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9586
(9.8 CRITICAL)

EPSS: 1.09%

updated 2026-09-02T20:55:56.223000

19 posts

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL

Nuclei template

1 repos

https://github.com/HORKimhab/CVE-2026-9586

undercodenews@mastodon.social at 2026-09-02T23:13:49.000Z ##

Hackers Are Actively Exploiting a Critical Sangoma Switchvox Flaw to Deploy Reverse Shells + Video

A New Threat Is Turning Business Phone Systems Into Attack Platforms A vulnerability in Sangoma Switchvox has moved rapidly from security research into real-world exploitation, creating a serious warning for organizations that expose their VoIP management systems to the internet. Security researchers have observed attackers targeting CVE-2026-9586, a critical…

undercodenews.com/hackers-are-

##

oversecurity@mastodon.social at 2026-09-02T21:40:30.000Z ##

Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can...

🔗️ [Bleepingcomputer] link.is.it/o3uhXX

##

Analyst207@mastodon.social at 2026-09-02T21:29:14.000Z ##

Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

Hackers are actively exploiting a vulnerability in Sangoma Switchvox, CVE-2026-9586, to gain unauthorized access and deploy reverse shells on vulnerable devices, with around 4,000 exposed devices, mostly in the US, at risk. This security flaw allows attackers to inject malicious SQL code, making it crucial to update to Switchvox…

osintsights.com/hackers-exploi

#Cve20269586 #Sangoma #Switchvox #SqlInjection #UnauthenticatedVulnerability

##

undercodenews@mastodon.social at 2026-09-02T21:28:22.000Z ##

Sangoma Switchvox Under Attack: Critical CVE-2026-9586 Turns Internet-Exposed VoIP Systems Into Prime Targets + Video

Introduction: A Quiet VoIP Flaw Becomes a Live Cybersecurity Threat A vulnerability buried inside an enterprise phone-management platform has suddenly become a serious security concern for organizations around the world. CVE-2026-9586, a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox, is now being actively exploited in the…

undercodenews.com/sangoma-swit

##

AAKL at 2026-09-02T19:01:22.277Z ##

Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.

- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

##

secdb at 2026-09-02T19:00:11.414Z ##

🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48710 (secdb.nttzen.cloud/cve/detail/)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/Kludex/starlette/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-49869 (secdb.nttzen.cloud/cve/detail/)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/kestra-io/kestra/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-59822 (secdb.nttzen.cloud/cve/detail/)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: github.com/BerriAI/litellm/sec ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82329 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83548 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83549 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9586 (secdb.nttzen.cloud/cve/detail/)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: sangomakb.atlassian.net/wiki/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-09-02T18:01:58.000Z ##

CVE ID: CVE-2026-9586
Vendor: Sangoma
Product: Switchvox
Date Added: 2026-09-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cyberworldops at 2026-09-02T10:10:00.614Z ##

Active exploitation attempts are targeting CVE-2026-9586, a critical unauthenticated SQL injection in Sangoma Switchvox SMB Edition. A single crafted request enables arbitrary SQL execution on PostgreSQL and leads to remote code execution via reverse shell. Immediate patching and exposure review are critical.

cyberworldops.eu/en/switchvox-

##

Analyst207@mastodon.social at 2026-09-02T08:30:34.000Z ##

Attackers Exploit Switchvox Flaw to Deploy Reverse Shells

A critical flaw in Sangoma Switchvox SMB Edition 8.3 can let attackers execute malicious code without credentials, giving them alarming control over your system. This unauthenticated SQL injection vulnerability, tracked as CVE-2026-9586, is a serious threat that demands immediate attention.

osintsights.com/attackers-expl

#SqlInjection #SupplyChain #EmergingThreats #Cve20269586 #Switchvox

##

undercodenews@mastodon.social at 2026-09-02T08:01:22.000Z ##

Critical Sangoma Switchvox Flaw Is Now Being Exploited: CVE-2026-9586 Gives Attackers a Direct Path to Remote Code Execution + Video

A Dangerous VoIP Vulnerability Has Moved From Disclosure to Active Exploitation Enterprise phone systems rarely receive the same attention as web servers, VPN appliances, or cloud infrastructure. Yet they can be just as valuable to attackers—and sometimes even more dangerous because they sit at the center of an organization's…

undercodenews.com/critical-san

##

DailyCyberSecurity at 2026-09-01T15:00:39.477Z ##

CVE-2026-9586, a critical Sangoma Switchvox vulnerability, is exploited in the wild, giving unauthenticated attackers SQL injection and remote code execution.

securityonline.info/sangoma-sw

##

_r_netsec at 2026-09-01T12:43:04.782Z ##

Off the Hook: Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586 horizon3.ai/attack-research/di

##

oversecurity@mastodon.social at 2026-09-02T21:40:30.000Z ##

Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can...

🔗️ [Bleepingcomputer] link.is.it/o3uhXX

##

AAKL@infosec.exchange at 2026-09-02T19:01:22.000Z ##

Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.

- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-02T19:00:11.000Z ##

🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48710 (secdb.nttzen.cloud/cve/detail/)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/Kludex/starlette/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-49869 (secdb.nttzen.cloud/cve/detail/)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/kestra-io/kestra/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-59822 (secdb.nttzen.cloud/cve/detail/)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: github.com/BerriAI/litellm/sec ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82329 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83548 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83549 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9586 (secdb.nttzen.cloud/cve/detail/)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: sangomakb.atlassian.net/wiki/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260902 #cisa20260902 #cve_2026_48710 #cve_2026_49869 #cve_2026_59822 #cve_2026_82329 #cve_2026_83548 #cve_2026_83549 #cve_2026_9586 #cve202648710 #cve202649869 #cve202659822 #cve202682329 #cve202683548 #cve202683549 #cve20269586

##

cisakevtracker@mastodon.social at 2026-09-02T18:01:58.000Z ##

CVE ID: CVE-2026-9586
Vendor: Sangoma
Product: Switchvox
Date Added: 2026-09-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cyberworldops@infosec.exchange at 2026-09-02T10:10:00.000Z ##

Active exploitation attempts are targeting CVE-2026-9586, a critical unauthenticated SQL injection in Sangoma Switchvox SMB Edition. A single crafted request enables arbitrary SQL execution on PostgreSQL and leads to remote code execution via reverse shell. Immediate patching and exposure review are critical. #Switchvox #SqlInjection #ThreatIntel

cyberworldops.eu/en/switchvox-

##

DailyCyberSecurity@infosec.exchange at 2026-09-01T15:00:39.000Z ##

CVE-2026-9586, a critical Sangoma Switchvox vulnerability, is exploited in the wild, giving unauthenticated attackers SQL injection and remote code execution.

#Sangoma #Switchvox #CVE20269586 #RCE #SQLInjection #VoIP #InfoSec #ExploitedInTheWild

securityonline.info/sangoma-sw

##

_r_netsec@infosec.exchange at 2026-09-01T12:43:04.000Z ##

Off the Hook: Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586 horizon3.ai/attack-research/di

##

CVE-2026-83548
(10.0 CRITICAL)

EPSS: 0.27%

updated 2026-09-02T20:40:13.683000

19 posts

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

AAKL at 2026-09-02T19:01:22.277Z ##

Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.

- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

##

secdb at 2026-09-02T19:00:11.414Z ##

🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48710 (secdb.nttzen.cloud/cve/detail/)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/Kludex/starlette/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-49869 (secdb.nttzen.cloud/cve/detail/)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/kestra-io/kestra/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-59822 (secdb.nttzen.cloud/cve/detail/)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: github.com/BerriAI/litellm/sec ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82329 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83548 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83549 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9586 (secdb.nttzen.cloud/cve/detail/)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: sangomakb.atlassian.net/wiki/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

Matchbook3469@mastodon.social at 2026-09-02T18:07:18.000Z ##

🔴 New security advisory:

CVE-2026-83548 affects multiple systems.

• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#InfoSec #ZeroDay #ThreatIntel

##

cisakevtracker@mastodon.social at 2026-09-02T18:02:13.000Z ##

CVE ID: CVE-2026-83548
Vendor: SonicWall
Product: SMA1000 Appliances
Date Added: 2026-09-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

netsecio@mastodon.social at 2026-09-02T17:14:29.000Z ##

📰 SonicWall Warns of Two Actively Exploited Zero-Days in SMA1000

🚨 BREAKING: SonicWall warns of two actively exploited zero-days (CVE-2026-83548, CVE-2026-83549) in SMA 1000 appliances. Attackers chain the flaws for unauthenticated RCE. Patches are available and must be applied immediately. #ZeroDay #SonicWall #C...

🔗 cyber.netsecops.io/articles/so

##

cert_fr@social.numerique.gouv.fr at 2026-09-02T12:51:59.000Z ##

⚠️Alerte CERT-FR⚠️

Les vulnérabilités CVE-2026-83548 et CVE-2026-83549 affectent les SMA 1000 et permettent une SSRF ainsi que l'exécution de code arbitraire à distance.
Elles sont activement exploitées.

cert.ssi.gouv.fr/alerte/CERTFR

##

Analyst207@mastodon.social at 2026-09-02T09:29:15.000Z ##

SonicWall Zero-Days Exploited in Wild, Firm Urges Immediate Patching

SonicWall is urging immediate patching for two zero-day vulnerabilities in its SMA1000 appliances, which are being actively exploited in the wild by hackers. The more critical flaw, CVE-2026-83548, has a severity rating of 10.0 and can be triggered without authentication, putting sensitive data at risk.

osintsights.com/sonicwall-zero

#ZeroDay #Sonicwall #Cve202683548 #SupplyChain #EmergingThreats

##

security_crawler_carl at 2026-09-02T07:13:42.147Z ##

🏆 New Achievement! By Continuing to Use This Appliance, You Agree to Be Owned!

Please note that Section 2, Paragraph 4 of your SMA1000 user agreement has been updated. By failing to patch CVE-2026-83548 — a pre-authentication SSRF flaw scoring a perfect 10.0 CVSS in the Appliance Work Place interface — you consent to unauthenticated strangers poking around your network. (1/2)

##

decio at 2026-09-02T07:06:36.586Z ##

Tiens, encore du SMA1000 ...

Deux nouvelles vulnérabilités 0-day, CVE-2026-83548 (CVSS 10) et CVE-2026-83549, activement exploitées.

La première permet une SSRF sans authentification, la seconde une injection de commandes/RCE. Les deux peuvent être chaînées pour arriver à une RCE sans authentification sur l'appliance.

Sont concernés les SMA1000 6210, 7210 et 8200v.

Pas de workaround : hotfix à appliquer au plus vite. ☹️

Et SonicWall dans la doc dédiée ne s’arrête pas au patch : recherche d’IoC recommandée et, si compromission détectée, re-image/redeploy de l’appliance + reset des mots de passe admin/utilisateurs et des tokens TOTP.

À noter : les SSL-VPN des firewalls SonicWall et la gamme SMA100 ne sont pas concernés.

Bref, si vous avez du SMA1000 exposé, ça mérite clairement un petit détour dans l’inventaire ce matin. 🙃

Advisory 🩹
👇
psirt.global.sonicwall.com/vul

##

cyberworldops at 2026-09-02T06:20:01.076Z ##

SonicWall confirmed active exploitation of two zero-days in SMA1000 appliances, including pre-auth SSRF CVE-2026-83548. Chained, the flaws allow unauthenticated remote command execution on SSL-VPN gateways. Operators should patch immediately and hunt for post-exploitation activity.

cyberworldops.eu/en/sonicwall-

##

DailyCyberSecurity at 2026-09-01T22:07:29.724Z ##

CVE-2026-83548, a critical SonicWall SMA1000 vulnerability, is exploited in the wild. The pre-authentication SSRF flaw scores a maximum 10.0 CVSS.

securityonline.info/sonicwall-

##

AAKL@infosec.exchange at 2026-09-02T19:01:22.000Z ##

Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.

- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-02T19:00:11.000Z ##

🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48710 (secdb.nttzen.cloud/cve/detail/)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/Kludex/starlette/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-49869 (secdb.nttzen.cloud/cve/detail/)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/kestra-io/kestra/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-59822 (secdb.nttzen.cloud/cve/detail/)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: github.com/BerriAI/litellm/sec ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82329 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83548 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83549 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9586 (secdb.nttzen.cloud/cve/detail/)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: sangomakb.atlassian.net/wiki/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260902 #cisa20260902 #cve_2026_48710 #cve_2026_49869 #cve_2026_59822 #cve_2026_82329 #cve_2026_83548 #cve_2026_83549 #cve_2026_9586 #cve202648710 #cve202649869 #cve202659822 #cve202682329 #cve202683548 #cve202683549 #cve20269586

##

cisakevtracker@mastodon.social at 2026-09-02T18:02:13.000Z ##

CVE ID: CVE-2026-83548
Vendor: SonicWall
Product: SMA1000 Appliances
Date Added: 2026-09-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cert_fr@social.numerique.gouv.fr at 2026-09-02T12:51:59.000Z ##

⚠️Alerte CERT-FR⚠️

Les vulnérabilités CVE-2026-83548 et CVE-2026-83549 affectent les SMA 1000 et permettent une SSRF ainsi que l'exécution de code arbitraire à distance.
Elles sont activement exploitées.

cert.ssi.gouv.fr/alerte/CERTFR

##

security_crawler_carl@infosec.exchange at 2026-09-02T07:13:42.000Z ##

🏆 New Achievement! By Continuing to Use This Appliance, You Agree to Be Owned!

Please note that Section 2, Paragraph 4 of your SMA1000 user agreement has been updated. By failing to patch CVE-2026-83548 — a pre-authentication SSRF flaw scoring a perfect 10.0 CVSS in the Appliance Work Place interface — you consent to unauthenticated strangers poking around your network. (1/2)

##

decio@infosec.exchange at 2026-09-02T07:06:36.000Z ##

Tiens, encore du #SonicWall SMA1000 ...

Deux nouvelles vulnérabilités 0-day, CVE-2026-83548 (CVSS 10) et CVE-2026-83549, activement exploitées.

La première permet une SSRF sans authentification, la seconde une injection de commandes/RCE. Les deux peuvent être chaînées pour arriver à une RCE sans authentification sur l'appliance.

Sont concernés les SMA1000 6210, 7210 et 8200v.

Pas de workaround : hotfix à appliquer au plus vite. ☹️

Et SonicWall dans la doc dédiée ne s’arrête pas au patch : recherche d’IoC recommandée et, si compromission détectée, re-image/redeploy de l’appliance + reset des mots de passe admin/utilisateurs et des tokens TOTP.

À noter : les SSL-VPN des firewalls SonicWall et la gamme SMA100 ne sont pas concernés.

Bref, si vous avez du SMA1000 exposé, ça mérite clairement un petit détour dans l’inventaire ce matin. 🙃

Advisory 🩹
👇
psirt.global.sonicwall.com/vul

#CyberVeille

##

cyberworldops@infosec.exchange at 2026-09-02T06:20:01.000Z ##

SonicWall confirmed active exploitation of two zero-days in SMA1000 appliances, including pre-auth SSRF CVE-2026-83548. Chained, the flaws allow unauthenticated remote command execution on SSL-VPN gateways. Operators should patch immediately and hunt for post-exploitation activity. #SonicWall #ZeroDay #InfoSec

cyberworldops.eu/en/sonicwall-

##

DailyCyberSecurity@infosec.exchange at 2026-09-01T22:07:29.000Z ##

CVE-2026-83548, a critical SonicWall SMA1000 vulnerability, is exploited in the wild. The pre-authentication SSRF flaw scores a maximum 10.0 CVSS.

#SonicWall #SMA1000 #CVE202683548 #SSRF #PreAuth #VPNsecurity #InfoSec #ExploitedInTheWild

securityonline.info/sonicwall-

##

CVE-2026-84372
(9.8 CRITICAL)

EPSS: 0.41%

updated 2026-09-02T20:17:40.793000

2 posts

Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RESP buffer in AbstractAggregateConnection::write() by splitting it with explode("\r\n") instead of honoring RESP length prefixes. Attacker-controlled keys or values containing CRLF s

thehackerwire@mastodon.social at 2026-09-01T23:00:56.000Z ##

🔴 CVE-2026-84372 - Critical (9.8)

Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RESP buffer in AbstractAggrega...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-01T23:00:56.000Z ##

🔴 CVE-2026-84372 - Critical (9.8)

Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RESP buffer in AbstractAggrega...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84292
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-02T20:17:39.543000

2 posts

fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject authority delimiters, demoting the intended host to userinfo and pointing the authority at an attacker-controlled host. Both fast-uri and Node's URL read

thehackerwire@mastodon.social at 2026-09-02T22:59:49.000Z ##

🟠 CVE-2026-84292 - High (7.5)

fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-02T22:59:49.000Z ##

🟠 CVE-2026-84292 - High (7.5)

fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20276
(8.6 HIGH)

EPSS: 0.00%

updated 2026-09-02T19:23:13.660000

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20276 are related to insufficient control flow management issu

AAKL at 2026-09-02T16:36:40.192Z ##

New security advisories.

Broadcom has addressed several vulnerabilities,two of them critical support.broadcom.com/web/ecx/s

Cisco: Five advisories, two of them addressing critical vulnerabilities:

- CRITICAL: CVE-2026-20212: Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability sec.cloudapps.cisco.com/securi

- CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi

More: sec.cloudapps.cisco.com/securi @TalosSecurity

##

AAKL@infosec.exchange at 2026-09-02T16:36:40.000Z ##

New security advisories.

Broadcom has addressed several vulnerabilities,two of them critical support.broadcom.com/web/ecx/s #Broadcom

Cisco: Five advisories, two of them addressing critical vulnerabilities:

- CRITICAL: CVE-2026-20212: Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability sec.cloudapps.cisco.com/securi

- CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi

More: sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

CVE-2026-84382
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-02T19:18:08.353000

2 posts

HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip, deflate, br, or zstd network chunk before iter_bytes() or aiter_bytes() yields bounded pieces to the application. A 64 KiB compressed chunk can expand to approximately 64 MiB in one intermediate allocation, so an attacker-controlled or compromi

thehackerwire@mastodon.social at 2026-09-02T23:02:23.000Z ##

🟠 CVE-2026-84382 - High (7.5)

HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip, deflate, br, or zstd network chunk before iter_bytes() or aiter_bytes() yields bounded piec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-02T23:02:23.000Z ##

🟠 CVE-2026-84382 - High (7.5)

HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip, deflate, br, or zstd network chunk before iter_bytes() or aiter_bytes() yields bounded piec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84381
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-02T19:18:08.217000

2 posts

HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin uses wss through a SOCKS5 proxy because the TLS upgrade condition only recognizes https. HTTPX2 exposes the flaw through Client.websocket() and AsyncClient.websocket() from 2.6.0 th

thehackerwire@mastodon.social at 2026-09-02T23:02:13.000Z ##

🟠 CVE-2026-84381 - High (8.1)

HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin uses wss through a SOCKS5 pr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-02T23:02:13.000Z ##

🟠 CVE-2026-84381 - High (8.1)

HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin uses wss through a SOCKS5 pr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49832
(8.0 HIGH)

EPSS: 0.00%

updated 2026-09-02T19:17:19.197000

2 posts

DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, versions 9.0-rc1 to before 9.3, and version 10-rc1, Remote Code Execution (RCE) is possible via Velocity Templates used by DSpace for COAR Notify/LDN messages. This issue has been patched in versions 8.4, 9.3, and 10.0.

thehackerwire@mastodon.social at 2026-09-03T00:00:31.000Z ##

🟠 CVE-2026-49832 - High (8)

DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, versions 9.0-rc1 to before 9.3, and version 10-rc1, Remote Code Execution (RCE) is possible via Veloci...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T00:00:31.000Z ##

🟠 CVE-2026-49832 - High (8)

DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, versions 9.0-rc1 to before 9.3, and version 10-rc1, Remote Code Execution (RCE) is possible via Veloci...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19117
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-02T19:17:16.490000

4 posts

Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only.

thehackerwire@mastodon.social at 2026-09-02T23:02:33.000Z ##

🔴 CVE-2026-19117 - Critical (9.8)

Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as
that user. This issue affects on-premises deployments only.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cR0w at 2026-09-02T21:46:36.621Z ##

Credential managers are so hot right now. Here's Delinea's on-prem offering.

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.8 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only.

##

thehackerwire@mastodon.social at 2026-09-02T23:02:33.000Z ##

🔴 CVE-2026-19117 - Critical (9.8)

Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as
that user. This issue affects on-premises deployments only.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cR0w@infosec.exchange at 2026-09-02T21:46:36.000Z ##

Credential managers are so hot right now. Here's Delinea's on-prem offering.

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.8 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only.

##

CVE-2026-20275
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-02T18:32:32

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20275 are related to incorrect calculation issues that are group

AAKL at 2026-09-02T16:36:40.192Z ##

New security advisories.

Broadcom has addressed several vulnerabilities,two of them critical support.broadcom.com/web/ecx/s

Cisco: Five advisories, two of them addressing critical vulnerabilities:

- CRITICAL: CVE-2026-20212: Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability sec.cloudapps.cisco.com/securi

- CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi

More: sec.cloudapps.cisco.com/securi @TalosSecurity

##

AAKL@infosec.exchange at 2026-09-02T16:36:40.000Z ##

New security advisories.

Broadcom has addressed several vulnerabilities,two of them critical support.broadcom.com/web/ecx/s #Broadcom

Cisco: Five advisories, two of them addressing critical vulnerabilities:

- CRITICAL: CVE-2026-20212: Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability sec.cloudapps.cisco.com/securi

- CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi

More: sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

CVE-2026-20274
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-02T18:32:31

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20274 are related to improper resource control issues that are g

AAKL at 2026-09-02T16:36:40.192Z ##

New security advisories.

Broadcom has addressed several vulnerabilities,two of them critical support.broadcom.com/web/ecx/s

Cisco: Five advisories, two of them addressing critical vulnerabilities:

- CRITICAL: CVE-2026-20212: Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability sec.cloudapps.cisco.com/securi

- CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi

More: sec.cloudapps.cisco.com/securi @TalosSecurity

##

AAKL@infosec.exchange at 2026-09-02T16:36:40.000Z ##

New security advisories.

Broadcom has addressed several vulnerabilities,two of them critical support.broadcom.com/web/ecx/s #Broadcom

Cisco: Five advisories, two of them addressing critical vulnerabilities:

- CRITICAL: CVE-2026-20212: Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability sec.cloudapps.cisco.com/securi

- CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi

More: sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

CVE-2026-20212
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-02T18:32:26

2 posts

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with&nbsp;root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and

AAKL at 2026-09-02T16:36:40.192Z ##

New security advisories.

Broadcom has addressed several vulnerabilities,two of them critical support.broadcom.com/web/ecx/s

Cisco: Five advisories, two of them addressing critical vulnerabilities:

- CRITICAL: CVE-2026-20212: Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability sec.cloudapps.cisco.com/securi

- CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi

More: sec.cloudapps.cisco.com/securi @TalosSecurity

##

AAKL@infosec.exchange at 2026-09-02T16:36:40.000Z ##

New security advisories.

Broadcom has addressed several vulnerabilities,two of them critical support.broadcom.com/web/ecx/s #Broadcom

Cisco: Five advisories, two of them addressing critical vulnerabilities:

- CRITICAL: CVE-2026-20212: Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability sec.cloudapps.cisco.com/securi

- CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi

More: sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

CVE-2026-78689
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-02T18:32:17

2 posts

Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes an externally controlled XML namespace prefix list to that method. Both the njs and the QuickJS (qjs) engines are affected. A crafted prefix list cau

cR0w at 2026-09-02T19:12:01.119Z ##

I am fortunate enough to not know anything about NGINX JavaScript ( hashtag blessed ) but if you do, this might be of interest.

nvd.nist.gov/vuln/detail/cve-2

Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes an externally controlled XML namespace prefix list to that method. Both the njs and the QuickJS (qjs) engines are affected. A crafted prefix list causes an out-of-bounds write past the end of a heap allocation. With the njs engine, which is the engine used when the js_engine directive is absent, this corrupts adjacent objects and crashes the NGINX worker. With the QuickJS engine, the same call additionally leaks the prefix list on every invocation, causing worker memory to grow across requests. The official nginxinc/nginx-saml reference implementation is affected during SAML signature verification. It reads InclusiveNamespaces/@PrefixList from an untrusted SAML message and passes it to xml.exclusiveC14n() before the signature has been verified, so a valid SAML signature is not required. A crafted SAML Response, Assertion, LogoutRequest, or LogoutResponse is sufficient. Code execution has not been demonstrated and cannot be ruled out for all platforms, as the effect of the out-of-bounds write depends on conditions beyond the attacker's control. Impact This vulnerability allows remote attackers to cause a denial of service on the NGINX system, either through repeatable worker restarts or through worker memory growth or possibly trigger code execution. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

##

cR0w@infosec.exchange at 2026-09-02T19:12:01.000Z ##

I am fortunate enough to not know anything about NGINX JavaScript ( hashtag blessed ) but if you do, this might be of interest.

nvd.nist.gov/vuln/detail/cve-2

Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes an externally controlled XML namespace prefix list to that method. Both the njs and the QuickJS (qjs) engines are affected. A crafted prefix list causes an out-of-bounds write past the end of a heap allocation. With the njs engine, which is the engine used when the js_engine directive is absent, this corrupts adjacent objects and crashes the NGINX worker. With the QuickJS engine, the same call additionally leaks the prefix list on every invocation, causing worker memory to grow across requests. The official nginxinc/nginx-saml reference implementation is affected during SAML signature verification. It reads InclusiveNamespaces/@PrefixList from an untrusted SAML message and passes it to xml.exclusiveC14n() before the signature has been verified, so a valid SAML signature is not required. A crafted SAML Response, Assertion, LogoutRequest, or LogoutResponse is sufficient. Code execution has not been demonstrated and cannot be ruled out for all platforms, as the effect of the out-of-bounds write depends on conditions beyond the attacker's control. Impact This vulnerability allows remote attackers to cause a denial of service on the NGINX system, either through repeatable worker restarts or through worker memory growth or possibly trigger code execution. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

##

CVE-2026-83549
(7.8 HIGH)

EPSS: 0.92%

updated 2026-09-02T18:32:06

16 posts

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

Matchbook3469@mastodon.social at 2026-09-02T19:16:13.000Z ##

⚠️ New security advisory:

CVE-2026-83549 affects multiple systems.

• Impact: Significant security breach potential
• Risk: Unauthorized access or data exposure
• Mitigation: Apply patches within 24-48 hours

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#CVE #PatchNow #InfoSecCommunity

##

AAKL at 2026-09-02T19:01:22.277Z ##

Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.

- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

##

secdb at 2026-09-02T19:00:11.414Z ##

🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48710 (secdb.nttzen.cloud/cve/detail/)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/Kludex/starlette/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-49869 (secdb.nttzen.cloud/cve/detail/)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/kestra-io/kestra/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-59822 (secdb.nttzen.cloud/cve/detail/)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: github.com/BerriAI/litellm/sec ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82329 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83548 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83549 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9586 (secdb.nttzen.cloud/cve/detail/)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: sangomakb.atlassian.net/wiki/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-09-02T18:02:29.000Z ##

CVE ID: CVE-2026-83549
Vendor: SonicWall
Product: SMA1000 Appliances
Date Added: 2026-09-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

netsecio@mastodon.social at 2026-09-02T17:14:29.000Z ##

📰 SonicWall Warns of Two Actively Exploited Zero-Days in SMA1000

🚨 BREAKING: SonicWall warns of two actively exploited zero-days (CVE-2026-83548, CVE-2026-83549) in SMA 1000 appliances. Attackers chain the flaws for unauthenticated RCE. Patches are available and must be applied immediately. #ZeroDay #SonicWall #C...

🔗 cyber.netsecops.io/articles/so

##

cert_fr@social.numerique.gouv.fr at 2026-09-02T12:51:59.000Z ##

⚠️Alerte CERT-FR⚠️

Les vulnérabilités CVE-2026-83548 et CVE-2026-83549 affectent les SMA 1000 et permettent une SSRF ainsi que l'exécution de code arbitraire à distance.
Elles sont activement exploitées.

cert.ssi.gouv.fr/alerte/CERTFR

##

security_crawler_carl at 2026-09-02T07:13:42.307Z ##

By also ignoring CVE-2026-83549, an OS command injection flaw in the AMC component, you further agree to let those same strangers chain both bugs together for full remote code execution. SonicWall has confirmed active exploitation in the wild. Ransomware gangs find SonicWall products particularly cozy real estate.

To opt out of these terms, patch your SMA1000 immediately.

Reward: You've received the Binding Arbitration Curse — your incidents are now non-disputable.

(2/2)

##

decio at 2026-09-02T07:06:36.586Z ##

Tiens, encore du SMA1000 ...

Deux nouvelles vulnérabilités 0-day, CVE-2026-83548 (CVSS 10) et CVE-2026-83549, activement exploitées.

La première permet une SSRF sans authentification, la seconde une injection de commandes/RCE. Les deux peuvent être chaînées pour arriver à une RCE sans authentification sur l'appliance.

Sont concernés les SMA1000 6210, 7210 et 8200v.

Pas de workaround : hotfix à appliquer au plus vite. ☹️

Et SonicWall dans la doc dédiée ne s’arrête pas au patch : recherche d’IoC recommandée et, si compromission détectée, re-image/redeploy de l’appliance + reset des mots de passe admin/utilisateurs et des tokens TOTP.

À noter : les SSL-VPN des firewalls SonicWall et la gamme SMA100 ne sont pas concernés.

Bref, si vous avez du SMA1000 exposé, ça mérite clairement un petit détour dans l’inventaire ce matin. 🙃

Advisory 🩹
👇
psirt.global.sonicwall.com/vul

##

thehackerwire@mastodon.social at 2026-09-01T23:01:58.000Z ##

🟠 CVE-2026-83549 - High (7.8)

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enabl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

AAKL@infosec.exchange at 2026-09-02T19:01:22.000Z ##

Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.

- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-02T19:00:11.000Z ##

🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48710 (secdb.nttzen.cloud/cve/detail/)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/Kludex/starlette/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-49869 (secdb.nttzen.cloud/cve/detail/)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/kestra-io/kestra/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-59822 (secdb.nttzen.cloud/cve/detail/)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: github.com/BerriAI/litellm/sec ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82329 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83548 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83549 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9586 (secdb.nttzen.cloud/cve/detail/)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: sangomakb.atlassian.net/wiki/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260902 #cisa20260902 #cve_2026_48710 #cve_2026_49869 #cve_2026_59822 #cve_2026_82329 #cve_2026_83548 #cve_2026_83549 #cve_2026_9586 #cve202648710 #cve202649869 #cve202659822 #cve202682329 #cve202683548 #cve202683549 #cve20269586

##

cisakevtracker@mastodon.social at 2026-09-02T18:02:29.000Z ##

CVE ID: CVE-2026-83549
Vendor: SonicWall
Product: SMA1000 Appliances
Date Added: 2026-09-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cert_fr@social.numerique.gouv.fr at 2026-09-02T12:51:59.000Z ##

⚠️Alerte CERT-FR⚠️

Les vulnérabilités CVE-2026-83548 et CVE-2026-83549 affectent les SMA 1000 et permettent une SSRF ainsi que l'exécution de code arbitraire à distance.
Elles sont activement exploitées.

cert.ssi.gouv.fr/alerte/CERTFR

##

security_crawler_carl@infosec.exchange at 2026-09-02T07:13:42.000Z ##

By also ignoring CVE-2026-83549, an OS command injection flaw in the AMC component, you further agree to let those same strangers chain both bugs together for full remote code execution. SonicWall has confirmed active exploitation in the wild. Ransomware gangs find SonicWall products particularly cozy real estate.

To opt out of these terms, patch your SMA1000 immediately.

Reward: You've received the Binding Arbitration Curse — your incidents are now non-disputable.

#ZeroDay #SonicWall (2/2)

##

decio@infosec.exchange at 2026-09-02T07:06:36.000Z ##

Tiens, encore du #SonicWall SMA1000 ...

Deux nouvelles vulnérabilités 0-day, CVE-2026-83548 (CVSS 10) et CVE-2026-83549, activement exploitées.

La première permet une SSRF sans authentification, la seconde une injection de commandes/RCE. Les deux peuvent être chaînées pour arriver à une RCE sans authentification sur l'appliance.

Sont concernés les SMA1000 6210, 7210 et 8200v.

Pas de workaround : hotfix à appliquer au plus vite. ☹️

Et SonicWall dans la doc dédiée ne s’arrête pas au patch : recherche d’IoC recommandée et, si compromission détectée, re-image/redeploy de l’appliance + reset des mots de passe admin/utilisateurs et des tokens TOTP.

À noter : les SSL-VPN des firewalls SonicWall et la gamme SMA100 ne sont pas concernés.

Bref, si vous avez du SMA1000 exposé, ça mérite clairement un petit détour dans l’inventaire ce matin. 🙃

Advisory 🩹
👇
psirt.global.sonicwall.com/vul

#CyberVeille

##

thehackerwire@mastodon.social at 2026-09-01T23:01:58.000Z ##

🟠 CVE-2026-83549 - High (7.8)

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enabl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73773
(7.5 HIGH)

EPSS: 0.26%

updated 2026-09-02T18:32:05

2 posts

An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service.

thehackerwire@mastodon.social at 2026-09-01T23:02:18.000Z ##

🟠 CVE-2026-73773 - High (7.5)

An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-01T23:02:18.000Z ##

🟠 CVE-2026-73773 - High (7.5)

An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82329
(9.8 CRITICAL)

EPSS: 1.24%

updated 2026-09-02T18:31:57

27 posts

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

Nuclei template

4 repos

https://github.com/realalexandergeorgiev/artifactory-CVE-2026-82329-poc.py

https://github.com/ynsmroztas/CVE-2026-82329-JFrog-Artifactory-Auth-Bypass

https://github.com/dinosn/cve-2026-82329-jfrog-artifactory

https://github.com/HORKimhab/CVE-2026-82329

AAKL at 2026-09-02T19:01:22.277Z ##

Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.

- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

##

secdb at 2026-09-02T19:00:11.414Z ##

🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48710 (secdb.nttzen.cloud/cve/detail/)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/Kludex/starlette/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-49869 (secdb.nttzen.cloud/cve/detail/)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/kestra-io/kestra/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-59822 (secdb.nttzen.cloud/cve/detail/)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: github.com/BerriAI/litellm/sec ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82329 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83548 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83549 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9586 (secdb.nttzen.cloud/cve/detail/)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: sangomakb.atlassian.net/wiki/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-09-02T18:01:42.000Z ##

CVE ID: CVE-2026-82329
Vendor: JFrog
Product: Artifactory
Date Added: 2026-09-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

netsecio@mastodon.social at 2026-09-02T17:14:50.000Z ##

📰 Critical JFrog Artifactory Auth Bypass Flaw Under Active Exploit

Critical auth bypass flaw (CVE-2026-82329) in self-hosted JFrog Artifactory is actively exploited. Attackers can gain admin access, posing a severe software supply chain risk. Patch immediately! #JFrog #Artifactory #CyberSecurity #CVE

🔗 cyber.netsecops.io/articles/cr

##

oversecurity@mastodon.social at 2026-09-02T16:10:21.000Z ##

Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide...

🔗️ [Bleepingcomputer] link.is.it/GGGBsY

##

Analyst207@mastodon.social at 2026-09-02T15:59:27.000Z ##

Hackers exploit JFrog flaw to forge admin tokens

Hackers are actively exploiting a critical flaw in JFrog Artifactory, CVE-2026-82329, to gain admin access and forge tokens, putting your entire system at risk. This authentication bypass vulnerability can allow attackers to elevate their permissions and automatically gain access to trusted and sensitive data.

osintsights.com/hackers-exploi

#Cve202682329 #Jfrog #JfrogArtifactory #AuthenticationBypass #AdminTokenForgery

##

Byte0x90@mastodon.social at 2026-09-02T15:57:26.000Z ##

Angreifer nutzen derzeit eine kritische Schwachstelle in JFrog Artifactory (CVE-2026-82329) aktiv aus. Die Sicherheitslücke erlaubt das Umgehen der Authentifizierung, wodurch unberechtigte administrative Token erstellt werden können. Betroffene Betreiber müssen umgehend die bereitgestellten Software-Aktualisierungen einspielen und bestehende Tokens prüfen.

#InfoSec #CyberSecurity #ITSecurity #Vulnerability #JFrog

##

beyondmachines1 at 2026-09-02T08:01:30.900Z ##

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens

JFrog Artifactory is facing active exploitation of a critical authentication bypass (CVE-2026-82329) that allows unauthenticated attackers to mint administrator tokens and compromise software supply chains.

**If you run self-managed JFrog Artifactory, update to version 7.161.20 ASAP. Attackers are already exploiting this flaw to take full admin control. Primary systems at risk are internet facing self-hosted Artifactory instances. Cloud-hosted instances managed by JFrog are not affected.**

beyondmachines.net/event_detai

##

undercodenews@mastodon.social at 2026-09-02T06:53:43.000Z ##

Critical JFrog Artifactory Flaw Is Being Exploited After Patching — CVE-2026-82329 Puts Software Supply Chains at Risk + Video

A Dangerous Race Between Disclosure and Exploitation A critical vulnerability in JFrog Artifactory has rapidly moved from a newly disclosed security weakness to an apparent real-world exploitation concern. CVE-2026-82329, rated 9.8 Critical, can potentially allow an unauthenticated attacker with network access to obtain administrative…

undercodenews.com/critical-jfr

##

youranonnewsirc@nerdculture.de at 2026-09-02T04:26:22.000Z ##

Geopolitical tensions persist between the U.S. and Iran regarding actions in the Strait of Hormuz (Sept 1, 2026). On the cybersecurity front, critical infrastructure, including Midwest water utilities, faces new ransomware attacks. Additionally, a severe authentication bypass flaw (CVE-2026-82329) in JFrog Artifactory is actively being exploited. OpenAI has issued a stark warning regarding the escalating threat of AI-enabled cyberattacks.

#AnonNews_irc #Cybersecurity #Anonymous #News

##

undercodenews@mastodon.social at 2026-09-01T21:58:20.000Z ##

Critical JFrog Artifactory Flaw Is Already Under Attack, Putting Software Supply Chains in the Crosshairs + Video

A Dangerous Race Against Time A critical vulnerability in JFrog Artifactory has moved from public disclosure to real-world exploitation with startling speed. CVE-2026-82329, rated CVSS 9.8, allows an unauthenticated attacker to bypass authentication on vulnerable self-hosted Artifactory deployments and potentially obtain administrator-level access. That…

undercodenews.com/critical-jfr

##

Analyst207@mastodon.social at 2026-09-01T18:29:18.000Z ##

Attackers Exploit JFrog Artifactory Flaw to Mint Admin Tokens

A critical flaw in JFrog Artifactory, known as CVE-2026-82329, allows attackers to easily gain admin access without needing authentication or user interaction, posing a huge risk to affected instances. This near-maximum-score vulnerability has already been patched in Artifactory version 7.161.20.

osintsights.com/attackers-expl

#JfrogArtifactory #Cve202682329 #AuthenticationBypass #SupplyChain #EmergingThreats

##

netsecio@mastodon.social at 2026-09-01T17:58:50.000Z ##

📰 Critical JFrog Artifactory Auth Bypass Flaw Under Active Exploit

Critical auth bypass flaw (CVE-2026-82329) in self-hosted JFrog Artifactory is actively exploited. Attackers can gain admin access, posing a severe software supply chain risk. Patch immediately! #JFrog #Artifactory #CyberSecurity #CVE

🔗 cyber.netsecops.io/articles/cr

##

AAKL at 2026-09-01T16:11:54.380Z ##

New.

WatchTower, on X:

"WatchTowr Intel is already seeing exploitation of the JFrog Artifactory Auth Bypass (CVE-2026-82329), with attackers minting themselves admin tokens."

More:

Security Week: Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild securityweek.com/critical-jfro @SecurityWeek

##

security_crawler_carl at 2026-09-01T16:11:24.192Z ##

🏆 New Achievement! Admin Tokens: A Self-Service Experience!

The System, acting in its capacity as counsel for the prosecution, hereby submits Exhibit A: CVE-2026-82329, a CVSS 9.8 authentication bypass in JFrog Artifactory, patched August 28. Per WatchTowr's testimony, unknown attackers were, within days of public disclosure, "minting themselves admin tokens" via default configurations — no credentials required. Your Honor, the defendant did knowingly operate an unpatched instance. (1/2)

##

cyberworldops at 2026-09-01T10:20:00.504Z ##

JFrog Artifactory is affected by critical CVE-2026-82329 (CVSS 9.8) allowing unauthenticated remote attackers to create administrative tokens via default configurations. With reports of active exploitation, this enables full system takeover and severe software supply chain compromise. Immediate patching is essential.

cyberworldops.eu/en/jfrog-arti

##

DailyCyberSecurity at 2026-09-01T06:29:28.981Z ##

A critical Artifactory authentication bypass flaw (CVE-2026-82329) is exploited in the wild, letting attackers obtain administrative privileges.

securityonline.info/cve-2026-8

##

AAKL@infosec.exchange at 2026-09-02T19:01:22.000Z ##

Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.

- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-02T19:00:11.000Z ##

🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48710 (secdb.nttzen.cloud/cve/detail/)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/Kludex/starlette/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-49869 (secdb.nttzen.cloud/cve/detail/)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/kestra-io/kestra/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-59822 (secdb.nttzen.cloud/cve/detail/)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: github.com/BerriAI/litellm/sec ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82329 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83548 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83549 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9586 (secdb.nttzen.cloud/cve/detail/)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: sangomakb.atlassian.net/wiki/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260902 #cisa20260902 #cve_2026_48710 #cve_2026_49869 #cve_2026_59822 #cve_2026_82329 #cve_2026_83548 #cve_2026_83549 #cve_2026_9586 #cve202648710 #cve202649869 #cve202659822 #cve202682329 #cve202683548 #cve202683549 #cve20269586

##

cisakevtracker@mastodon.social at 2026-09-02T18:01:42.000Z ##

CVE ID: CVE-2026-82329
Vendor: JFrog
Product: Artifactory
Date Added: 2026-09-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

oversecurity@mastodon.social at 2026-09-02T16:10:21.000Z ##

Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide...

🔗️ [Bleepingcomputer] link.is.it/GGGBsY

##

beyondmachines1@infosec.exchange at 2026-09-02T08:01:30.000Z ##

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens

JFrog Artifactory is facing active exploitation of a critical authentication bypass (CVE-2026-82329) that allows unauthenticated attackers to mint administrator tokens and compromise software supply chains.

**If you run self-managed JFrog Artifactory, update to version 7.161.20 ASAP. Attackers are already exploiting this flaw to take full admin control. Primary systems at risk are internet facing self-hosted Artifactory instances. Cloud-hosted instances managed by JFrog are not affected.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

youranonnewsirc@nerdculture.de at 2026-09-02T04:26:22.000Z ##

Geopolitical tensions persist between the U.S. and Iran regarding actions in the Strait of Hormuz (Sept 1, 2026). On the cybersecurity front, critical infrastructure, including Midwest water utilities, faces new ransomware attacks. Additionally, a severe authentication bypass flaw (CVE-2026-82329) in JFrog Artifactory is actively being exploited. OpenAI has issued a stark warning regarding the escalating threat of AI-enabled cyberattacks.

#AnonNews_irc #Cybersecurity #Anonymous #News

##

AAKL@infosec.exchange at 2026-09-01T16:11:54.000Z ##

New.

WatchTower, on X:

"WatchTowr Intel is already seeing exploitation of the JFrog Artifactory Auth Bypass (CVE-2026-82329), with attackers minting themselves admin tokens."

More:

Security Week: Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild securityweek.com/critical-jfro @SecurityWeek #vulnerability #infosec

##

security_crawler_carl@infosec.exchange at 2026-09-01T16:11:24.000Z ##

🏆 New Achievement! Admin Tokens: A Self-Service Experience!

The System, acting in its capacity as counsel for the prosecution, hereby submits Exhibit A: CVE-2026-82329, a CVSS 9.8 authentication bypass in JFrog Artifactory, patched August 28. Per WatchTowr's testimony, unknown attackers were, within days of public disclosure, "minting themselves admin tokens" via default configurations — no credentials required. Your Honor, the defendant did knowingly operate an unpatched instance. (1/2)

##

cyberworldops@infosec.exchange at 2026-09-01T10:20:00.000Z ##

JFrog Artifactory is affected by critical CVE-2026-82329 (CVSS 9.8) allowing unauthenticated remote attackers to create administrative tokens via default configurations. With reports of active exploitation, this enables full system takeover and severe software supply chain compromise. Immediate patching is essential. #JFrog #SupplyChainSecurity #VulnerabilityManagement

cyberworldops.eu/en/jfrog-arti

##

DailyCyberSecurity@infosec.exchange at 2026-09-01T06:29:28.000Z ##

A critical Artifactory authentication bypass flaw (CVE-2026-82329) is exploited in the wild, letting attackers obtain administrative privileges.

#Artifactory #CVE202682329 #CyberSecurity #AuthenticationBypass #Exploit

securityonline.info/cve-2026-8

##

CVE-2026-66786
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-02T18:21:10.517000

2 posts

A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName that includes newlines and ipsec.conf directives. This allows an attacker to inject arbitrary configuration parameters or execute commands through leftupdo

thehackerwire@mastodon.social at 2026-09-03T00:00:09.000Z ##

🔴 CVE-2026-66786 - Critical (9.1)

A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T00:00:09.000Z ##

🔴 CVE-2026-66786 - Critical (9.1)

A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53649
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-09-02T18:19:59.973000

2 posts

Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a wildcard CORS policy. Because plugin uploads use the CORS-safelisted multipart/form-data content type, cross-origin JavaScript on any page the operator visits can reach privileged endpoints - including uploading a native plugin

thehackerwire@mastodon.social at 2026-09-03T00:00:21.000Z ##

🔴 CVE-2026-53649 - Critical (9.6)

Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a wildcard CORS policy. Because plugin uploads use the CORS-safelisted multip...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T00:00:21.000Z ##

🔴 CVE-2026-53649 - Critical (9.6)

Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a wildcard CORS policy. Because plugin uploads use the CORS-safelisted multip...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48710
(6.5 MEDIUM)

EPSS: 2.10%

updated 2026-09-02T18:19:22.917000

6 posts

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and e

Nuclei template

5 repos

https://github.com/Bhanunamikaze/BadHost-CVE-2026-48710-Exploit

https://github.com/CuteeCat/CVE-2026-48710

https://github.com/xtremebeing/starlette-host-header-lab

https://github.com/sb-ox/repro-OXDEV-77637-uv-workspace

https://github.com/eris-ths/supply-chain-guard

AAKL at 2026-09-02T19:01:22.277Z ##

Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.

- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

##

secdb at 2026-09-02T19:00:11.414Z ##

🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48710 (secdb.nttzen.cloud/cve/detail/)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/Kludex/starlette/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-49869 (secdb.nttzen.cloud/cve/detail/)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/kestra-io/kestra/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-59822 (secdb.nttzen.cloud/cve/detail/)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: github.com/BerriAI/litellm/sec ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82329 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83548 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83549 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9586 (secdb.nttzen.cloud/cve/detail/)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: sangomakb.atlassian.net/wiki/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-09-02T18:01:11.000Z ##

CVE ID: CVE-2026-48710
Vendor: Kludex
Product: Starlette
Date Added: 2026-09-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-09-02T19:01:22.000Z ##

Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.

- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-02T19:00:11.000Z ##

🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48710 (secdb.nttzen.cloud/cve/detail/)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/Kludex/starlette/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-49869 (secdb.nttzen.cloud/cve/detail/)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/kestra-io/kestra/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-59822 (secdb.nttzen.cloud/cve/detail/)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: github.com/BerriAI/litellm/sec ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82329 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83548 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83549 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9586 (secdb.nttzen.cloud/cve/detail/)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: sangomakb.atlassian.net/wiki/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260902 #cisa20260902 #cve_2026_48710 #cve_2026_49869 #cve_2026_59822 #cve_2026_82329 #cve_2026_83548 #cve_2026_83549 #cve_2026_9586 #cve202648710 #cve202649869 #cve202659822 #cve202682329 #cve202683548 #cve202683549 #cve20269586

##

cisakevtracker@mastodon.social at 2026-09-02T18:01:11.000Z ##

CVE ID: CVE-2026-48710
Vendor: Kludex
Product: Starlette
Date Added: 2026-09-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-79755
(8.0 HIGH)

EPSS: 0.00%

updated 2026-09-02T17:17:59.940000

2 posts

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, on the Nuclio local Docker platform, the function namespace is interpolated—unvalidated—into a double-quoted docker ps --filter "label=nuclio.io/namespace=<value>" command that is executed via the host shell (/bin/sh -c). Because the default auth kind is nop (unauthenticated), a remote attacker ca

thehackerwire@mastodon.social at 2026-09-02T17:59:59.000Z ##

🟠 CVE-2026-79755 - High (8)

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, on the Nuclio local Docker platform, the function namespace is interpolated—unvalidated—into a double-quoted docker ps --filter "label=nuclio...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-02T17:59:59.000Z ##

🟠 CVE-2026-79755 - High (8)

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, on the Nuclio local Docker platform, the function namespace is interpolated—unvalidated—into a double-quoted docker ps --filter "label=nuclio...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84715
(8.8 HIGH)

EPSS: 0.32%

updated 2026-09-02T16:17:32.813000

2 posts

FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permission records. A subuser with minimal permissions can send a crafted request to grant themselves full server control, enabling unauthorized access to sensitive data, backups, and server configuration.

thehackerwire@mastodon.social at 2026-09-02T08:00:43.000Z ##

🟠 CVE-2026-84715 - High (8.8)

FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permission records. A subuser with minimal permissions can send a crafted reques...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-02T08:00:43.000Z ##

🟠 CVE-2026-84715 - High (8.8)

FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permission records. A subuser with minimal permissions can send a crafted reques...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47864
(6.4 MEDIUM)

EPSS: 3.44%

updated 2026-09-02T15:40:07.763000

1 posts

SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInputStream and no class filtering. Any request with Content-Type application/x-java-serialized-object whose body resolves to a Serializable type is read directly via readObject(). If an application using this converter on an inbound HTTP endpoint has any known Java deserialization "gadget" on

secdb@infosec.exchange at 2026-08-31T00:01:12.000Z ##

📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461

Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194

CISA KEVs:
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90

Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47864 - 3.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71921 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71914 - 3.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71905 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71906 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71907 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71908 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71909 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71910 - 3.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-73782
(8.8 HIGH)

EPSS: 0.27%

updated 2026-09-02T15:34:39

2 posts

A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.

thehackerwire@mastodon.social at 2026-09-01T22:00:33.000Z ##

🟠 CVE-2026-73782 - High (8.8)

A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-01T22:00:33.000Z ##

🟠 CVE-2026-73782 - High (8.8)

A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73780
(8.3 HIGH)

EPSS: 0.24%

updated 2026-09-02T15:34:38

1 posts

A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a remote unauthenticated attacker to execute arbitrary input against the affected interface if the attacker can convince an authenticated user of the interface to interact with a specially crafted URL.

hugovalters@mastodon.social at 2026-09-02T01:10:59.000Z ##

CVE-2026-73780 - High CSRF vulnerability in AOS-CX switch web interface allows arbitrary input execution. CVSS 8.3. Restrict web UI access immediately. #CVE #Aruba #infosec

valtersit.com/cve/CVE-2026-737

##

CVE-2026-79750
(7.7 HIGH)

EPSS: 0.25%

updated 2026-09-02T15:17:42.163000

1 posts

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.30, MCPHub scopes non-admin users to servers they own (list views and config edits enforce ownership), but the tool-execution API does not. Any authenticated non-admin user can invoke tools on MCP servers owned by othe

thehackerwire@mastodon.social at 2026-08-31T19:00:31.000Z ##

🟠 CVE-2026-79750 - High (7.7)

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.30, MCPHub scopes non-admin users to servers they own (list views...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76657
(10.0 CRITICAL)

EPSS: 0.43%

updated 2026-09-02T15:14:09.307000

2 posts

Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the HPE Networking Fabric Composer host.

DailyCyberSecurity at 2026-09-01T23:48:57.897Z ##

Critical HPE Fabric Composer vulnerabilities, including CVE-2026-76657, allow remote code execution. Update to version 7.4.0 now to secure your network.

securityonline.info/hpe-fabric

##

DailyCyberSecurity@infosec.exchange at 2026-09-01T23:48:57.000Z ##

Critical HPE Fabric Composer vulnerabilities, including CVE-2026-76657, allow remote code execution. Update to version 7.4.0 now to secure your network.

#HPE #FabricComposer #Vulnerability #Cybersecurity #CVE202676657

securityonline.info/hpe-fabric

##

CVE-2026-76658
(10.0 CRITICAL)

EPSS: 0.43%

updated 2026-09-02T15:12:31.233000

2 posts

A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise.

cR0w at 2026-09-01T21:38:56.642Z ##

Vuln or bugdoor?

nvd.nist.gov/vuln/detail/cve-2

A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise.

##

cR0w@infosec.exchange at 2026-09-01T21:38:56.000Z ##

Vuln or bugdoor?

nvd.nist.gov/vuln/detail/cve-2

A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise.

##

CVE-2026-84702
(7.5 HIGH)

EPSS: 0.38%

updated 2026-09-02T14:17:16.917000

2 posts

facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory. Attackers can supply traversal sequences in the job identifier parameter through the unauthenticated HTTP API to create files at arbitrary locations.

thehackerwire@mastodon.social at 2026-09-02T11:00:46.000Z ##

🟠 CVE-2026-84702 - High (7.5)

facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory. Attackers can supply traversal sequences in the job identifier parameter through the unauthenticated HT...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-02T11:00:46.000Z ##

🟠 CVE-2026-84702 - High (7.5)

facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory. Attackers can supply traversal sequences in the job identifier parameter through the unauthenticated HT...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14982
(8.1 HIGH)

EPSS: 0.52%

updated 2026-09-02T13:55:27.963000

2 posts

The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete function in all versions. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

thehackerwire@mastodon.social at 2026-09-02T05:00:54.000Z ##

🟠 CVE-2026-14982 - High (8.1)

The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete function in all versions. This makes it possible for authenticated attackers, with subscriber-level access an...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-02T05:00:54.000Z ##

🟠 CVE-2026-14982 - High (8.1)

The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete function in all versions. This makes it possible for authenticated attackers, with subscriber-level access an...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84795
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-02T12:31:39

2 posts

Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled email verification are configured.

cR0w at 2026-09-02T14:03:04.194Z ##

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.8 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled email verification are configured.

Seems like a pretty limited scope but it's still interesting to see that sev:CRIT in the CVE when the advisory says sev:MED:

github.com/craftcms/cms/securi

##

cR0w@infosec.exchange at 2026-09-02T14:03:04.000Z ##

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.8 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled email verification are configured.

Seems like a pretty limited scope but it's still interesting to see that sev:CRIT in the CVE when the advisory says sev:MED:

github.com/craftcms/cms/securi

##

CVE-2025-46418
(7.6 HIGH)

EPSS: 0.68%

updated 2026-09-02T12:17:11.690000

2 posts

Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.

thehackerwire@mastodon.social at 2026-09-02T07:01:42.000Z ##

🟠 CVE-2025-46418 - High (7.6)

Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-02T07:01:42.000Z ##

🟠 CVE-2025-46418 - High (7.6)

Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84353
(9.6 CRITICAL)

EPSS: 0.28%

updated 2026-09-02T10:17:11.080000

2 posts

Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

DailyCyberSecurity at 2026-09-02T02:59:15.750Z ##

Google patched critical Google Chrome vulnerabilities, including CVE-2026-84353. Update your browser now to block potential remote attacks.

securityonline.info/google-chr

##

DailyCyberSecurity@infosec.exchange at 2026-09-02T02:59:15.000Z ##

Google patched critical Google Chrome vulnerabilities, including CVE-2026-84353. Update your browser now to block potential remote attacks.

#GoogleChrome #Cybersecurity #Vulnerability #ChromeUpdate #CVE202684353

securityonline.info/google-chr

##

CVE-2026-14828
(8.8 HIGH)

EPSS: 1.44%

updated 2026-09-02T09:31:34

2 posts

Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.

thehackerwire@mastodon.social at 2026-09-02T11:00:25.000Z ##

🟠 CVE-2026-14828 - High (8.8)

Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-02T11:00:25.000Z ##

🟠 CVE-2026-14828 - High (8.8)

Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78657
(9.8 CRITICAL)

EPSS: 0.72%

updated 2026-09-02T06:31:26

2 posts

The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_files function in all versions up to, and including, 1.4.11. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted

thehackerwire@mastodon.social at 2026-09-02T07:01:18.000Z ##

🔴 CVE-2026-78657 - Critical (9.8)

The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_files function in all versions up to, and including, 1.4.11. This makes it po...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-02T07:01:18.000Z ##

🔴 CVE-2026-78657 - Critical (9.8)

The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_files function in all versions up to, and including, 1.4.11. This makes it po...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9055
(9.8 CRITICAL)

EPSS: 0.29%

updated 2026-09-02T06:31:24

2 posts

The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the customer update endpoint, which allows customers to set their role to 'manager' and trigger creation of a WordPress user with the wpamelia-manager role when t

1 repos

https://github.com/EXEcution-py/CVE-2026-9055

thehackerwire@mastodon.social at 2026-09-02T08:00:24.000Z ##

🔴 CVE-2026-9055 - Critical (9.8)

The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the cus...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-02T08:00:24.000Z ##

🔴 CVE-2026-9055 - Critical (9.8)

The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the cus...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14357
(8.8 HIGH)

EPSS: 0.65%

updated 2026-09-02T06:31:24

2 posts

The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.3.0. This is due to a missing capability check and missing nonce validation in the DPDEV_install_themes_func() function registered on the wp_ajax_DPDEV_install_themes action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install arbitrary t

thehackerwire@mastodon.social at 2026-09-02T07:01:30.000Z ##

🟠 CVE-2026-14357 - High (8.8)

The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.3.0. This is due to a missing capability check and missing nonce validation in the DPDEV_install_themes_func() function registered on th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-02T07:01:30.000Z ##

🟠 CVE-2026-14357 - High (8.8)

The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.3.0. This is due to a missing capability check and missing nonce validation in the DPDEV_install_themes_func() function registered on th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82393
(7.5 HIGH)

EPSS: 0.41%

updated 2026-09-02T04:18:02.693000

1 posts

pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts rejects slash characters only for unscoped names. During pnpm install, the unvalidated name reaches raw path joins in pnpm11/installing/deps-resolver/src/resolvePeers.ts, pnpm11/installing/deps-re

thehackerwire@mastodon.social at 2026-08-31T23:00:16.000Z ##

🟠 CVE-2026-82393 - High (7.5)

pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts rejects slash characters only for unscoped ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65643
(0 None)

EPSS: 0.64%

updated 2026-09-02T04:18:01.387000

1 posts

Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.

1 repos

https://github.com/HORKimhab/CVE-2026-65643

DailyCyberSecurity@infosec.exchange at 2026-08-31T13:50:56.000Z ##

Discover the details of the critical CVE-2026-65643 vulnerability in cPanel & WHM, allowing attackers to gain full root access on shared hosting servers.

#cPanel #Cybersecurity #Vulnerability #SharedHosting #InfoSec

securityexpress.info/cpanel-rc

##

CVE-2026-62911
(8.0 HIGH)

EPSS: 1.32%

updated 2026-09-02T04:18:00.460000

8 posts

Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

1 repos

https://github.com/hypnguyen1209/CVE-2026-62911

yhitaz@mastodon.acm.org at 2026-09-02T10:47:37.000Z ##

bleepingcomputer.com/news/secu
Lähes 22 000 Exchange-palvelinta alttiina postilaatikoiden haltuunottohaasteelle Shadowserver tunnisti 21 899 internetistä alttiina ollutta Microsoft Exchange -palvelinta, joita ei ole vielä korjattu CVE-2026-62911 -haavoittuvuudelle. Kyseessä on Exchange 2016-, 2019- ja Subscription Edition -versioita koskeva todennuksen ohitusongelma.

##

benzogaga33@mamot.fr at 2026-09-02T09:40:03.000Z ##

Exchange Server : près de 22 000 serveurs exposés sont vulnérables à la CVE-2026-62911 it-connect.fr/microsoft-exchan #ActuCybersécurité #Cybersécurité #Vulnérabilité #Microsoft #Exchange

##

threatnoir at 2026-09-01T20:06:48.564Z ##

⚠️ CRITICAL: Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

A critical authentication bypass vulnerability (CVE-2026-62911) affects approximately 22,000 unpatched Microsoft Exchange servers running versions 2016, 2019, and SE. Attackers can hijack all user mailboxes on vulnerable systems. Exploit code is publicly available; active exploitation in the wild h…

threatnoir.com/focus

🤖 AI generated summary

##

undercodenews@mastodon.social at 2026-09-01T13:16:42.000Z ##

Microsoft Exchange Faces Another Critical Wake-Up Call as Nearly 22,000 Servers Remain Exposed + Video

Introduction: A Familiar Risk That Refuses to Disappear Microsoft Exchange Server has once again become the center of a serious cybersecurity warning, and this time the concern is not merely theoretical. Nearly 22,000 internet-exposed Exchange servers reportedly remain vulnerable to CVE-2026-62911, a high-severity authentication-bypass flaw that could allow an…

undercodenews.com/microsoft-ex

##

Analyst207@mastodon.social at 2026-09-01T12:59:06.000Z ##

Unpatched Microsoft Exchange Servers Exposed to Hijack Attacks

Thousands of Microsoft Exchange servers remain vulnerable to a high-severity flaw, leaving 21,899 internet-facing systems open to hijack attacks that could give attackers control of every mailbox. This unpatched authentication-bypass vulnerability, CVE-2026-62911, was fixed by Microsoft in August, but many servers…

osintsights.com/unpatched-micr

#Cve202662911 #MicrosoftExchange #AuthenticationBypass #MailboxHijacking #UnpatchedServers

##

benzogaga33@mamot.fr at 2026-09-02T09:40:03.000Z ##

Exchange Server : près de 22 000 serveurs exposés sont vulnérables à la CVE-2026-62911 it-connect.fr/microsoft-exchan #ActuCybersécurité #Cybersécurité #Vulnérabilité #Microsoft #Exchange

##

threatnoir@infosec.exchange at 2026-09-01T20:06:48.000Z ##

⚠️ CRITICAL: Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

A critical authentication bypass vulnerability (CVE-2026-62911) affects approximately 22,000 unpatched Microsoft Exchange servers running versions 2016, 2019, and SE. Attackers can hijack all user mailboxes on vulnerable systems. Exploit code is publicly available; active exploitation in the wild h…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

DailyCyberSecurity@infosec.exchange at 2026-09-01T01:34:19.000Z ##

Security researchers released technical details and PoC code for CVE-2026-62911, a critical Exchange Server pre-auth RCE flaw.

#ExchangeServer #CVE202662911 #CyberSecurity #RCE #Pwn2Own

securityonline.info/cve-2026-6

##

CVE-2026-84485
(7.5 HIGH)

EPSS: 0.35%

updated 2026-09-02T03:31:18

2 posts

APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. Attackers can query the endpoint with space identifiers obtained from shared links or public templates to enumerate the complete member directory of any workspace.

thehackerwire@mastodon.social at 2026-09-02T08:00:34.000Z ##

🟠 CVE-2026-84485 - High (7.5)

APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. Attackers can query the endpoint with ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-02T08:00:34.000Z ##

🟠 CVE-2026-84485 - High (7.5)

APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. Attackers can query the endpoint with ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84484
(7.5 HIGH)

EPSS: 0.48%

updated 2026-09-02T03:31:18

2 posts

ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending truncated SDNV values. Attackers can send a UDP datagram to the LTP link service input port with a truncated SDNV to trigger reads up to nine bytes past buffer boundaries and underflow byte counters.

thehackerwire@mastodon.social at 2026-09-02T05:01:06.000Z ##

🟠 CVE-2026-84484 - High (7.5)

ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending truncated SDNV values. Attackers can send a UDP datagram to the LTP link se...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-02T05:01:06.000Z ##

🟠 CVE-2026-84484 - High (7.5)

ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending truncated SDNV values. Attackers can send a UDP datagram to the LTP link se...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84699
(9.1 CRITICAL)

EPSS: 0.37%

updated 2026-09-02T03:31:17

2 posts

Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.

cR0w at 2026-09-02T14:01:22.806Z ##

"Just use a password manager."

nvd.nist.gov/vuln/detail/cve-2

Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.

##

cR0w@infosec.exchange at 2026-09-02T14:01:22.000Z ##

"Just use a password manager."

nvd.nist.gov/vuln/detail/cve-2

Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.

##

CVE-2026-14957
(7.5 HIGH)

EPSS: 0.56%

updated 2026-09-02T03:31:14

2 posts

In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if the RSA exponent is set to 0. A remote attacker can send a malformed X.509 certificate in a CERT payload to trigger the assertion, causing the pluto daemon to abort and restart. Co

thehackerwire@mastodon.social at 2026-09-02T05:00:43.000Z ##

🟠 CVE-2026-14957 - High (7.5)

In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if the RSA exponent is set to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-02T05:00:43.000Z ##

🟠 CVE-2026-14957 - High (7.5)

In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if the RSA exponent is set to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84700
(8.6 HIGH)

EPSS: 0.35%

updated 2026-09-02T03:31:13

2 posts

PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client port 9221 is used) that does not authenticate incoming requests. Although requirepass is intended to gate replication — a slave presents it as masterauth inside its MetaSync request — only the MetaSync handler (HandleMetaSyncRequest) validates

thehackerwire@mastodon.social at 2026-09-02T11:00:34.000Z ##

🟠 CVE-2026-84700 - High (8.6)

PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client port 9221 is used) that does not authenticate incoming requests. Although requirepass is in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-02T11:00:34.000Z ##

🟠 CVE-2026-84700 - High (8.6)

PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client port 9221 is used) that does not authenticate incoming requests. Although requirepass is in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2023-54391
(9.8 CRITICAL)

EPSS: 0.46%

updated 2026-09-02T00:31:39

2 posts

Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with a

1 repos

https://github.com/neeythann/Proxmox-VE-7-RCE

obivan at 2026-09-02T10:15:30.828Z ##

Proxmox VE 7.0–8.0.3: unauthenticated, single-request root auth bypass (CVE-2023-54391) blog.nathangolez.com/2026/08/p

##

obivan@infosec.exchange at 2026-09-02T10:15:30.000Z ##

Proxmox VE 7.0–8.0.3: unauthenticated, single-request root auth bypass (CVE-2023-54391) blog.nathangolez.com/2026/08/p

##

CVE-2026-6876
(0 None)

EPSS: 0.40%

updated 2026-09-01T20:55:19.100000

2 posts

ServiceNow has remediated a sandbox escape security issue that was identified in the ServiceNow AI Platform. This security issue could allow an unauthenticated user to execute arbitrary code within the ServiceNow AI Platform, potentially leading to more access to the ServiceNow AI Platform than intended.  ServiceNow deployed a security update to hosted instances and ServiceNow provided th

cR0w at 2026-09-01T19:20:04.523Z ##

RE: infosec.exchange/@cR0w/1171693

Update:

Update - September 1st, 2026

Due to additional analysis provided by the security researcher who discovered CVE-2026-6875, we have upgraded the severity rating of CVE-2026-6876 from High to Critical. This change affects only the severity rating for CVE-2026-6876; it does not change the other information shared in our August 27th advisory. Based on our monitoring to date, we have not observed evidence of malicious exploitation of this issue.

##

cR0w@infosec.exchange at 2026-09-01T19:20:04.000Z ##

RE: infosec.exchange/@cR0w/1171693

Update:

Update - September 1st, 2026

Due to additional analysis provided by the security researcher who discovered CVE-2026-6875, we have upgraded the severity rating of CVE-2026-6876 from High to Critical. This change affects only the severity rating for CVE-2026-6876; it does not change the other information shared in our August 27th advisory. Based on our monitoring to date, we have not observed evidence of malicious exploitation of this issue.

##

CVE-2026-82226
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-09-01T20:48:22.513000

1 posts

Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.

thehackerwire@mastodon.social at 2026-08-31T22:00:24.000Z ##

🔴 CVE-2026-82226 - Critical (9.8)

Unauthenticated PHP Object Injection in Tickera &lt;= 3.6.0.2 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84268
(8.8 HIGH)

EPSS: 0.33%

updated 2026-09-01T18:30:49

2 posts

A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrup

thehackerwire@mastodon.social at 2026-09-01T18:00:45.000Z ##

🟠 CVE-2026-84268 - High (8.8)

A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-01T18:00:45.000Z ##

🟠 CVE-2026-84268 - High (8.8)

A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58566
(8.8 HIGH)

EPSS: 0.23%

updated 2026-09-01T18:30:49

2 posts

Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

thehackerwire@mastodon.social at 2026-09-01T18:00:36.000Z ##

🟠 CVE-2026-58566 - High (8.8)

Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-01T18:00:36.000Z ##

🟠 CVE-2026-58566 - High (8.8)

Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84202
(8.8 HIGH)

EPSS: 0.37%

updated 2026-09-01T18:17:48.503000

2 posts

ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can craft malicious model repositories with poisoned configuration files that execute code when loaded by users.

thehackerwire@mastodon.social at 2026-09-01T18:00:55.000Z ##

🟠 CVE-2026-84202 - High (8.8)

ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can craft malicious model repositories with poisoned configuration files that exec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-01T18:00:55.000Z ##

🟠 CVE-2026-84202 - High (8.8)

ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can craft malicious model repositories with poisoned configuration files that exec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78319
(0 None)

EPSS: 0.40%

updated 2026-09-01T18:17:46.253000

5 posts

A service running on the affected products contains a potential Time-of-Check Time-of-Use (TOCTOU) race condition. An unauthenticated remote attacker could exploit this race condition to bypass intended security controls. This may result in the execution of unauthorized code.

netsecio@mastodon.social at 2026-09-01T17:58:56.000Z ##

📰 Critical RCE Flaw in SAUTER Building Controllers Threatens Physical Systems

Critical 9.8 CVSS RCE flaw (CVE-2026-78319) disclosed in SAUTER building automation controllers. Attackers could control HVAC & other physical systems. Patch immediately! #ICS #OTsecurity #CyberSecurity #CVE #BuildingAutomation

🔗 cyber.netsecops.io/articles/cr

##

DailyCyberSecurity at 2026-09-01T08:53:15.603Z ##

Public advisory details CVE-2026-78319, a critical SAUTER building controller vulnerability enabling unauthenticated remote code execution via a TOCTOU flaw.

securityonline.info/sauter-cve

##

certvde at 2026-09-01T06:44:43.329Z ##

🔒 New CSAF advisory published

VDE-2026-093
SAUTER: modulo 6 and EY-modulo 5 Vulnerability in Firmware update mechanism allowing remote code execution
CVE-2026-78319

A vulnerability has been found in the firmware update process of SAUTER Building Controllers. The identified vulnerability could allow unauthorized code execution on affec…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: sauter.csaf-tp.certvde.com/.we

##

DailyCyberSecurity@infosec.exchange at 2026-09-01T08:53:15.000Z ##

Public advisory details CVE-2026-78319, a critical SAUTER building controller vulnerability enabling unauthenticated remote code execution via a TOCTOU flaw.

#SAUTER #ICS #CVE202678319 #TOCTOU #RCE #BuildingAutomation #OTSecurity #InfoSec

securityonline.info/sauter-cve

##

certvde@infosec.exchange at 2026-09-01T06:44:43.000Z ##

🔒 New CSAF advisory published

VDE-2026-093
SAUTER: modulo 6 and EY-modulo 5 Vulnerability in Firmware update mechanism allowing remote code execution
CVE-2026-78319

A vulnerability has been found in the firmware update process of SAUTER Building Controllers. The identified vulnerability could allow unauthorized code execution on affec…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: sauter.csaf-tp.certvde.com/.we

#OT #Advisory

##

CVE-2026-80047(CVSS UNKNOWN)

EPSS: 0.11%

updated 2026-09-01T15:31:13

2 posts

A vulnerability in Hugging Face Transformers (versions 4.49.0, <= 5.8.1) allows remote Python files to be written to local disk without user consent when using GenerativePreTrainedModel.load_custom_generate(). The function fetches and caches a remote module file before performing the required trust_remote_code consent check, inverting the security model enforced by other code-loading paths (such a

DailyCyberSecurity at 2026-09-02T02:49:07.507Z ##

A new Hugging Face vulnerability (CVE-2026-80047) writes remote Python code to disk before user consent. Learn how to protect your machine learning models.

securityonline.info/hugging-fa

##

DailyCyberSecurity@infosec.exchange at 2026-09-02T02:49:07.000Z ##

A new Hugging Face vulnerability (CVE-2026-80047) writes remote Python code to disk before user consent. Learn how to protect your machine learning models.

#HuggingFace #CyberSecurity #Vulnerability #MachineLearning #CVE202680047

securityonline.info/hugging-fa

##

CVE-2026-84196
(7.7 HIGH)

EPSS: 0.26%

updated 2026-09-01T15:17:43.613000

2 posts

Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url that allows authenticated users to send arbitrary HTTP requests by injecting user-controlled input through variable substitution. Attackers can target internal services, cloud metadata endpoints, and loopback addresses, with response data reflected in admission error messages enabling non-blind data e

thehackerwire@mastodon.social at 2026-09-01T13:00:23.000Z ##

🟠 CVE-2026-84196 - High (7.7)

Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url that allows authenticated users to send arbitrary HTTP requests by injecting user-controlled input through variable substitution. Attackers can targe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-01T13:00:23.000Z ##

🟠 CVE-2026-84196 - High (7.7)

Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url that allows authenticated users to send arbitrary HTTP requests by injecting user-controlled input through variable substitution. Attackers can targe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56718
(7.5 HIGH)

EPSS: 0.58%

updated 2026-09-01T15:17:21.027000

1 posts

AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to read arbitrary files with root privileges by supplying path traversal sequences in the HTTP request URI. Attackers can send crafted HTTP requests to port 80 without authentication to access sensitive files including cleartext R

thehackerwire@mastodon.social at 2026-08-31T01:00:33.000Z ##

🟠 CVE-2026-56718 - High (7.5)

AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to read arbitrary files with root privileges by supplying path traversal sequ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84199
(7.7 HIGH)

EPSS: 0.26%

updated 2026-09-01T12:31:56

2 posts

Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature. The URL field in a Policy's ServiceCall configuration is not validated, so a user with namespace-level Policy creation permissions can direct Kyverno to make HTTP requests to arbitrary internal resources (e.g., cloud metadata endpoints such as 169.254.169.254 or other tenants' resources). Beca

thehackerwire@mastodon.social at 2026-09-01T13:00:39.000Z ##

🟠 CVE-2026-84199 - High (7.7)

Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature. The URL field in a Policy's ServiceCall configuration is not validated, so a user with namespace-level Policy creation permissions can direct...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-01T13:00:39.000Z ##

🟠 CVE-2026-84199 - High (7.7)

Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature. The URL field in a Policy's ServiceCall configuration is not validated, so a user with namespace-level Policy creation permissions can direct...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84195
(7.7 HIGH)

EPSS: 0.29%

updated 2026-09-01T12:31:56

2 posts

Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorization headers. Attackers can exfiltrate the token by directing apiCall requests to external or attacker-controlled endpoints, gaining full control over Kyverno policies and cluster resources.

thehackerwire@mastodon.social at 2026-09-01T13:00:12.000Z ##

🟠 CVE-2026-84195 - High (7.7)

Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorization headers. Attackers can exfiltrate the token by directing apiCall requests...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-01T13:00:12.000Z ##

🟠 CVE-2026-84195 - High (7.7)

Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorization headers. Attackers can exfiltrate the token by directing apiCall requests...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19806
(8.8 HIGH)

EPSS: 0.40%

updated 2026-09-01T06:33:01

2 posts

The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 1.4.52 via the `guest_ticket_login()` function and its `p` parameter. This is due to the site-wide AES-256-CBC encryption key being derived from only three two-digit `

thehackerwire@mastodon.social at 2026-09-01T10:00:37.000Z ##

🟠 CVE-2026-19806 - High (8.8)

The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 1.4.52 via t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-01T10:00:37.000Z ##

🟠 CVE-2026-19806 - High (8.8)

The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 1.4.52 via t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-83772
(9.9 CRITICAL)

EPSS: 1.69%

updated 2026-09-01T06:33:01

2 posts

A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the function c_set_reports_decode of the file mail-report.sh of the component JSON Parsing. The manipulation of the argument sender/recipients results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contact

thehackerwire@mastodon.social at 2026-09-01T10:00:28.000Z ##

🔴 CVE-2026-83772 - Critical (9.9)

A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the function c_set_reports_decode of the file mail-report.sh of the component JSON Parsing. The manipulation of the argument sender...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-01T10:00:28.000Z ##

🔴 CVE-2026-83772 - Critical (9.9)

A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the function c_set_reports_decode of the file mail-report.sh of the component JSON Parsing. The manipulation of the argument sender...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19952
(7.5 HIGH)

EPSS: 0.78%

updated 2026-09-01T06:33:00

2 posts

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in all versions up to, and including, 3.29.12. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-conf

thehackerwire@mastodon.social at 2026-09-01T10:00:47.000Z ##

🟠 CVE-2026-19952 - High (7.5)

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in all versions up to, and including, 3.29.12. This makes it possible for unauthen...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-01T10:00:47.000Z ##

🟠 CVE-2026-19952 - High (7.5)

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in all versions up to, and including, 3.29.12. This makes it possible for unauthen...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82078
(9.1 CRITICAL)

EPSS: 0.93%

updated 2026-09-01T04:18:02.160000

15 posts

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on

2 repos

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

https://github.com/virologi-info/papercut-toolkit

security_crawler_carl at 2026-09-02T09:44:29.936Z ##

Huntress logged confirmed attacks against at least two customers.

SYSTEM NOTE: WatchTowr did not make this worse. The situation was already worse. WatchTowr merely filed a report.

Apply PaperCut's emergency patches for both CVE-2026-81578 and CVE-2026-82078 immediately, and check for indicators of compromise dating back to August 26.

Reward: You've received a Duplicate Incident Ticket — it's the same as the first one but somehow more urgent.

(2/2)

##

security_crawler_carl at 2026-09-02T09:44:29.800Z ##

🏆 New Achievement! Print Job: Ownership Complete!

ERROR: Assumed single zero-day. Actual zero-days: two. PaperCut, the print management software, has had CVE-2026-81578 and CVE-2026-82078 exploited in the wild since August 26 — the first a high-severity authentication bypass letting remote, unauthenticated attackers modify system configurations. WatchTowr then found additional patch bypasses, triggering a second emergency patch before the first one was even officially released. (1/2)

##

cyberveille@mastobot.ping.moi at 2026-09-02T02:00:05.000Z ##

📢 Deux zero-days PaperCut NG/MF exploités activement : second patch d'urgence publié

Deux CVE ont été officiellement attribuées : CVE-2026-81578 : Contournement d'authentification de haute sévérité permettant à un attaquant distant non authentifié de modifier certaines configurations système. CVE-2026-82078 : Faille critique liée au chargement dynamique…

📖 cyberveille : cyberveille.ch/posts/2026-09-0
🌐 source : securityweek.com/more-details-
🟢 vérification factuelle haute
#PaperCut #ZeroDay #Cyberveille

##

Byte0x90@mastodon.social at 2026-09-01T09:26:35.000Z ##

Frisch geschlossene Sicherheitslücken in PaperCut NG und MF (CVE-2026-81578 & CVE-2026-82078) dienen Angreifern aktuell aktiv als Einfallstor für massiven Datendiebstahl. Die Kombination aus Authentifizierungs-Bypasses und Remote Code Execution erlaubt vollständige Systemübernahmen im Netz exponierter Printserver. Administratoren müssen ausstehende Patches zwingend einspielen und den Zugriff sofort einschränken.

#PaperCut #Infosec #Vulnerability #CyberSecurity #DataTheft #SysAdmin

##

guardingpearsoftware@mastodon.social at 2026-09-01T08:09:33.000Z ##

Two vulnerabilities in PaperCut NG and MF print management software are now being used by attackers in data theft campaigns.
PaperCut software is used by millions of people across thousands of organizations.
The flaws are tracked as CVE-2026-81578 and CVE-2026-82078.

##

thecybermind at 2026-09-01T07:31:08.365Z ##

T-Suite Technical Brief: CVE-2026-82078 active exploitation targets PaperCut NG/MF with unsafe reflection & arbitrary Java execution. Read our engineering runbook for CrowdStrike CQL detection rules, ATT&CK mapping, and hardening controls.
thecybermind.co/zqkw

##

security_crawler_carl@infosec.exchange at 2026-09-02T09:44:29.000Z ##

Huntress logged confirmed attacks against at least two customers.

SYSTEM NOTE: WatchTowr did not make this worse. The situation was already worse. WatchTowr merely filed a report.

Apply PaperCut's emergency patches for both CVE-2026-81578 and CVE-2026-82078 immediately, and check for indicators of compromise dating back to August 26.

Reward: You've received a Duplicate Incident Ticket — it's the same as the first one but somehow more urgent.

#PaperCut #ZeroDay #CVE #CyberSecurity (2/2)

##

security_crawler_carl@infosec.exchange at 2026-09-02T09:44:29.000Z ##

🏆 New Achievement! Print Job: Ownership Complete!

ERROR: Assumed single zero-day. Actual zero-days: two. PaperCut, the print management software, has had CVE-2026-81578 and CVE-2026-82078 exploited in the wild since August 26 — the first a high-severity authentication bypass letting remote, unauthenticated attackers modify system configurations. WatchTowr then found additional patch bypasses, triggering a second emergency patch before the first one was even officially released. (1/2)

##

thecybermind@infosec.exchange at 2026-09-01T07:31:08.000Z ##

T-Suite Technical Brief: CVE-2026-82078 active exploitation targets PaperCut NG/MF with unsafe reflection & arbitrary Java execution. Read our engineering runbook for CrowdStrike CQL detection rules, ATT&CK mapping, and hardening controls.
thecybermind.co/zqkw

##

thecybermind@infosec.exchange at 2026-09-01T04:38:34.000Z ##

URGENT C-Suite Brief: CVE-2026-82078 active exploitation targets PaperCut NG/MF with unsafe reflection and arbitrary Java execution. Read our executive brief for rapid EDR tuning, least privilege controls, and asset integrity protection. thecybermind.co/pzil

##

thecybermind@infosec.exchange at 2026-08-31T21:45:29.000Z ##

URGENT C-Suite Brief: CVE-2026-82078 active exploitation targets PaperCut NG/MF with unsafe reflection and arbitrary Java execution. Read our executive brief for rapid EDR tuning, least privilege controls, and asset integrity protection. thecybermind.co/4im9

##

secdb@infosec.exchange at 2026-08-31T17:00:11.000Z ##

🚨 [CISA-2026:0831] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-81578 (secdb.nttzen.cloud/cve/detail/)
- Name: PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: PaperCut
- Product: NG/MF
- Notes: papercut.com/kb/Main/security- ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82078 (secdb.nttzen.cloud/cve/detail/)
- Name: PaperCut NG/MF Unsafe Reflection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: PaperCut
- Product: NG/MF
- Notes: papercut.com/kb/Main/security- ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260831 #cisa20260831 #cve_2026_81578 #cve_2026_82078 #cve202681578 #cve202682078

##

AAKL@infosec.exchange at 2026-08-31T16:26:51.000Z ##

PaperCut has made the cut. Two vulnerabilities have been added to the KEV catalogue.

CISA: CVE-2026-81578: PaperCut NG/MF Missing Authentication for Critical Function Vulnerability

CVE-2026-82078: PaperCut NG/MF Unsafe Reflection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability

##

cisakevtracker@mastodon.social at 2026-08-31T16:00:50.000Z ##

CVE ID: CVE-2026-82078
Vendor: PaperCut
Product: NG/MF
Date Added: 2026-08-31
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

DailyCyberSecurity@infosec.exchange at 2026-08-31T08:51:14.000Z ##

A PaperCut zero-day (CVE-2026-81578, CVE-2026-82078) is exploited in the wild. Attackers run malicious SQL for RCE, and a Metasploit PoC is now public.

#PaperCut #CVE202682078 #ZeroDay #RCE #InfoSec #Metasploit #SQLi

securityonline.info/papercut-z

##

CVE-2026-75865
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-09-01T03:31:10

1 posts

The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the saas_upload_logo() function combined with an authorization bypass on the WPLP connector REST endpoints in all versions up to, and including, 4.4.1. This makes it possible for unauthenticated attacker

thehackerwire@mastodon.social at 2026-09-01T03:59:48.000Z ##

🔴 CVE-2026-75865 - Critical (9.8)

The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the saas_upload_logo() function combined with an...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67394(CVSS UNKNOWN)

EPSS: 1.17%

updated 2026-09-01T03:31:09

2 posts

A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a customer or reseller with shell access (or allowed to change their own shell access) to elevate privileges to the root account on the hosting server.

cR0w at 2026-09-01T13:53:17.433Z ##

sev:CRIT LPE in Plesk. Gotta love that shared infra and the inherited risk that comes with it.

nvd.nist.gov/vuln/detail/cve-2

A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a customer or reseller with shell access (or allowed to change their own shell access) to elevate privileges to the root account on the hosting server.

##

cR0w@infosec.exchange at 2026-09-01T13:53:17.000Z ##

sev:CRIT LPE in Plesk. Gotta love that shared infra and the inherited risk that comes with it.

nvd.nist.gov/vuln/detail/cve-2

A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a customer or reseller with shell access (or allowed to change their own shell access) to elevate privileges to the root account on the hosting server.

##

CVE-2026-82954
(9.9 CRITICAL)

EPSS: 0.62%

updated 2026-09-01T00:31:43

1 posts

A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. The manipulation of the argument path results in path traversal. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but

thehackerwire@mastodon.social at 2026-08-31T22:59:56.000Z ##

🔴 CVE-2026-82954 - Critical (9.9)

A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. The manipulation of the argument path results in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82882
(8.8 HIGH)

EPSS: 0.31%

updated 2026-09-01T00:31:42

1 posts

Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenticated account can query the endpoint with arbitrary project, environment, and application parameters to retrieve plaintext super-admin JWT tokens for full platform control.

thehackerwire@mastodon.social at 2026-08-31T23:00:05.000Z ##

🟠 CVE-2026-82882 - High (8.8)

Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenticated account can query the endpoint with arbitr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-83596
(8.8 HIGH)

EPSS: 0.29%

updated 2026-08-31T21:32:23

1 posts

A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.

thehackerwire@mastodon.social at 2026-08-31T22:00:03.000Z ##

🟠 CVE-2026-83596 - High (8.8)

A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82908
(8.8 HIGH)

EPSS: 0.12%

updated 2026-08-31T21:32:22

1 posts

A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability is the function MmioWritePath in the library NTIOLib_X64.sys of the component MMIO Write Path Handler. Performing a manipulation of the argument count/elementSize results in integer overflow. The attack requires a local approach. The exploit has been made public and could be used. The vendor was contacte

thehackerwire@mastodon.social at 2026-08-31T22:00:14.000Z ##

🟠 CVE-2026-82908 - High (8.8)

A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability is the function MmioWritePath in the library NTIOLib_X64.sys of the component MMIO Write Path Handler. Performing a manipulation of the argument count/e...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81578
(9.8 CRITICAL)

EPSS: 0.77%

updated 2026-08-31T21:31:56

13 posts

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

2 repos

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

https://github.com/virologi-info/papercut-toolkit

security_crawler_carl at 2026-09-02T09:44:29.936Z ##

Huntress logged confirmed attacks against at least two customers.

SYSTEM NOTE: WatchTowr did not make this worse. The situation was already worse. WatchTowr merely filed a report.

Apply PaperCut's emergency patches for both CVE-2026-81578 and CVE-2026-82078 immediately, and check for indicators of compromise dating back to August 26.

Reward: You've received a Duplicate Incident Ticket — it's the same as the first one but somehow more urgent.

(2/2)

##

security_crawler_carl at 2026-09-02T09:44:29.800Z ##

🏆 New Achievement! Print Job: Ownership Complete!

ERROR: Assumed single zero-day. Actual zero-days: two. PaperCut, the print management software, has had CVE-2026-81578 and CVE-2026-82078 exploited in the wild since August 26 — the first a high-severity authentication bypass letting remote, unauthenticated attackers modify system configurations. WatchTowr then found additional patch bypasses, triggering a second emergency patch before the first one was even officially released. (1/2)

##

cyberveille@mastobot.ping.moi at 2026-09-02T02:00:05.000Z ##

📢 Deux zero-days PaperCut NG/MF exploités activement : second patch d'urgence publié

Deux CVE ont été officiellement attribuées : CVE-2026-81578 : Contournement d'authentification de haute sévérité permettant à un attaquant distant non authentifié de modifier certaines configurations système. CVE-2026-82078 : Faille critique liée au chargement dynamique…

📖 cyberveille : cyberveille.ch/posts/2026-09-0
🌐 source : securityweek.com/more-details-
🟢 vérification factuelle haute
#PaperCut #ZeroDay #Cyberveille

##

Byte0x90@mastodon.social at 2026-09-01T09:26:35.000Z ##

Frisch geschlossene Sicherheitslücken in PaperCut NG und MF (CVE-2026-81578 & CVE-2026-82078) dienen Angreifern aktuell aktiv als Einfallstor für massiven Datendiebstahl. Die Kombination aus Authentifizierungs-Bypasses und Remote Code Execution erlaubt vollständige Systemübernahmen im Netz exponierter Printserver. Administratoren müssen ausstehende Patches zwingend einspielen und den Zugriff sofort einschränken.

#PaperCut #Infosec #Vulnerability #CyberSecurity #DataTheft #SysAdmin

##

guardingpearsoftware@mastodon.social at 2026-09-01T08:09:33.000Z ##

Two vulnerabilities in PaperCut NG and MF print management software are now being used by attackers in data theft campaigns.
PaperCut software is used by millions of people across thousands of organizations.
The flaws are tracked as CVE-2026-81578 and CVE-2026-82078.

##

security_crawler_carl@infosec.exchange at 2026-09-02T09:44:29.000Z ##

Huntress logged confirmed attacks against at least two customers.

SYSTEM NOTE: WatchTowr did not make this worse. The situation was already worse. WatchTowr merely filed a report.

Apply PaperCut's emergency patches for both CVE-2026-81578 and CVE-2026-82078 immediately, and check for indicators of compromise dating back to August 26.

Reward: You've received a Duplicate Incident Ticket — it's the same as the first one but somehow more urgent.

#PaperCut #ZeroDay #CVE #CyberSecurity (2/2)

##

security_crawler_carl@infosec.exchange at 2026-09-02T09:44:29.000Z ##

🏆 New Achievement! Print Job: Ownership Complete!

ERROR: Assumed single zero-day. Actual zero-days: two. PaperCut, the print management software, has had CVE-2026-81578 and CVE-2026-82078 exploited in the wild since August 26 — the first a high-severity authentication bypass letting remote, unauthenticated attackers modify system configurations. WatchTowr then found additional patch bypasses, triggering a second emergency patch before the first one was even officially released. (1/2)

##

secdb@infosec.exchange at 2026-08-31T17:00:11.000Z ##

🚨 [CISA-2026:0831] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-81578 (secdb.nttzen.cloud/cve/detail/)
- Name: PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: PaperCut
- Product: NG/MF
- Notes: papercut.com/kb/Main/security- ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82078 (secdb.nttzen.cloud/cve/detail/)
- Name: PaperCut NG/MF Unsafe Reflection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: PaperCut
- Product: NG/MF
- Notes: papercut.com/kb/Main/security- ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260831 #cisa20260831 #cve_2026_81578 #cve_2026_82078 #cve202681578 #cve202682078

##

AAKL@infosec.exchange at 2026-08-31T16:26:51.000Z ##

PaperCut has made the cut. Two vulnerabilities have been added to the KEV catalogue.

CISA: CVE-2026-81578: PaperCut NG/MF Missing Authentication for Critical Function Vulnerability

CVE-2026-82078: PaperCut NG/MF Unsafe Reflection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability

##

cisakevtracker@mastodon.social at 2026-08-31T16:01:06.000Z ##

CVE ID: CVE-2026-81578
Vendor: PaperCut
Product: NG/MF
Date Added: 2026-08-31
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

thecybermind@infosec.exchange at 2026-08-31T15:32:25.000Z ##

URGENT C-Suite Brief: CVE-2026-81578 active exploitation targets PaperCut NG/MF authentication flaws. Read our executive brief for rapid patch deployment, EDR monitoring, and access controls to safeguard your enterprise perimeter. thecybermind.co/4im9

##

benzogaga33@mamot.fr at 2026-08-31T09:40:04.000Z ##

PaperCut NG/MF : deux failles exploitées et un premier correctif contourné it-connect.fr/papercut-ng-mf-c #ActuCybersécurité #Vulnérabilités #Cybersécurité

##

DailyCyberSecurity@infosec.exchange at 2026-08-31T08:51:14.000Z ##

A PaperCut zero-day (CVE-2026-81578, CVE-2026-82078) is exploited in the wild. Attackers run malicious SQL for RCE, and a Metasploit PoC is now public.

#PaperCut #CVE202682078 #ZeroDay #RCE #InfoSec #Metasploit #SQLi

securityonline.info/papercut-z

##

CVE-2026-81934
(9.8 CRITICAL)

EPSS: 0.43%

updated 2026-08-31T21:31:55

2 posts

Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server. Fixed in Redis 8.2.9, 8.4.6, 8.6.6, 8.8.2, and 8.10.1.

DailyCyberSecurity at 2026-09-01T13:04:20.390Z ##

CVE-2026-81934, a critical Redis RCE flaw (CVSS 9.2), now has public exploit details and PoC code. Patch your TLS-enabled servers now.

securityonline.info/redis-cve-

##

DailyCyberSecurity@infosec.exchange at 2026-09-01T13:04:20.000Z ##

CVE-2026-81934, a critical Redis RCE flaw (CVSS 9.2), now has public exploit details and PoC code. Patch your TLS-enabled servers now.

#Redis #CVE202681934 #RCE #Vulnerability #InfoSec #UseAfterFree #TLS

securityonline.info/redis-cve-

##

CVE-2026-82450
(8.8 HIGH)

EPSS: 0.57%

updated 2026-08-31T20:56:08.800000

1 posts

BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover. Attackers can bypass image extension validation by embedding a PHP file with a .php filename in the ZIP archive, which is stored in the public web root and executed by unaut

hugovalters@mastodon.social at 2026-09-01T11:14:48.000Z ##

CVE-2026-82450 - RCE vulnerability in BookStack portable ZIP import via PHP polyglot file upload. CVSS 8.8. Update immediately. #CVE #BookStack #cybersecurity

valtersit.com/cve/CVE-2026-824

##

CVE-2026-82645
(8.6 HIGH)

EPSS: 0.13%

updated 2026-08-31T20:56:08.800000

1 posts

AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' request parameter waives both the Live::canRestream() access gate and the restream ownership check, causing the endpoint to return any restream's stream_key and stream_url (credentials for external platforms such as YouTube, Facebook

thehackerwire@mastodon.social at 2026-08-30T16:02:53.000Z ##

🟠 CVE-2026-82645 - High (8.6)

AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' request parameter waives both the Live::canRestream() access gate and the restre...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82655
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-31T20:56:08.800000

1 posts

Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can bypass authentication by providing a dummy UUID in role_list and inject SQL through relation_type_list to extract database contents including password hashes and user credentials.

thehackerwire@mastodon.social at 2026-08-30T16:01:52.000Z ##

🟠 CVE-2026-82655 - High (7.5)

Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can bypass authentication by providing a dum...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54745
(10.0 CRITICAL)

EPSS: 0.43%

updated 2026-08-31T20:17:05.990000

1 posts

Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ route in frontend/server/proxy-middleware.ts. The _routePathWithReferer() function accepts an arbitrary attacker-controlled HTTP or HTTPS target and passes its o

thehackerwire@mastodon.social at 2026-08-30T17:00:19.000Z ##

🔴 CVE-2026-54745 - Critical (10)

Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ route in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82635
(8.8 HIGH)

EPSS: 0.40%

updated 2026-08-31T19:27:23.020000

1 posts

Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containing path traversal sequences (for example ../Library/LaunchAgents/com.evil.plist) or an absolute path resolves outside ~/Downloads. The command then fetches attacker-controlled content from the supplied URL (via Rust HTTP, not the

thehackerwire@mastodon.social at 2026-08-30T14:00:48.000Z ##

🟠 CVE-2026-82635 - High (8.8)

Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containing path traversal sequences (for example ../Library/LaunchAgents/com.evil.pl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12556
(0 None)

EPSS: 0.15%

updated 2026-08-31T19:20:26.140000

2 posts

Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.

_r_netsec at 2026-09-02T21:28:05.309Z ##

Rooted in Trust: Three privilege-escalation vulnerabilities in HP Easy Start for macOS (CVE-2026-12554, CVE-2026-12555, CVE-2026-12556) ciphersecuritylabs.com/researc

##

_r_netsec@infosec.exchange at 2026-09-02T21:28:05.000Z ##

Rooted in Trust: Three privilege-escalation vulnerabilities in HP Easy Start for macOS (CVE-2026-12554, CVE-2026-12555, CVE-2026-12556) ciphersecuritylabs.com/researc

##

CVE-2026-55247
(9.1 CRITICAL)

EPSS: 0.34%

updated 2026-08-31T19:16:55.260000

1 posts

plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iCalendar import in src/plone/app/event/ical/importer.py accepts insufficiently restricted calendar and event URLs, does not adequately bound downloaded bytes or imported events, and commits work per event. A logged-in editor can make the server request internal network resources or local calendar fil

thehackerwire@mastodon.social at 2026-08-30T14:01:38.000Z ##

🔴 CVE-2026-55247 - Critical (9.1)

plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iCalendar import in src/plone/app/event/ical/importer.py accepts insufficiently restricted calendar and event URLs, does not adequately bound downloa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17615
(7.5 HIGH)

EPSS: 0.28%

updated 2026-08-31T18:31:39

1 posts

A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to an endpoint that accepts application/xml and returns Source or StreamSource, the server can be tricked into resolving the entity and including sensitiv

thehackerwire@mastodon.social at 2026-08-31T17:59:51.000Z ##

🟠 CVE-2026-17615 - High (7.5)

A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-83492
(0 None)

EPSS: 0.24%

updated 2026-08-31T17:17:47.483000

1 posts

Improper input validation vulnerability in Extend Themes Kubio AI Website Builder. This issue affects Kubio AI Website Builder: before 2.9.1.

AAKL@infosec.exchange at 2026-08-31T16:51:36.000Z ##

New. This is CVE-2026-83492, meduim severity.

Tenable Research Advisories: WordPress - Kubio AI Website Builder DoS tenable.com/security/research/ @tenable #infosec #WordPress #vulnerability

##

CVE-2026-82639
(7.5 HIGH)

EPSS: 0.30%

updated 2026-08-31T17:17:45.737000

1 posts

NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key. The x-base-url header is validated using substring matching instead of hostname parsing, allowing any URL containing 'api.openai.com' to pass validation and receive the server's credentials in the Authorization header.

thehackerwire@mastodon.social at 2026-08-30T15:01:38.000Z ##

🟠 CVE-2026-82639 - High (7.5)

NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key. The x-base-url header is validated using substring matching instead of...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82636
(7.9 HIGH)

EPSS: 0.79%

updated 2026-08-31T17:17:45.603000

1 posts

Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, because the "system" library function is used to process an error message that may have shell metacharacters. This occurs in core-admin-linux/file-copy-vm/qfile-dom0-agent.c.

thehackerwire@mastodon.social at 2026-08-30T15:00:50.000Z ##

🟠 CVE-2026-82636 - High (7.9)

Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, because the "system" library function is used to process an error message that may have shell metachara...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82616
(9.9 CRITICAL)

EPSS: 0.61%

updated 2026-08-31T06:30:34

1 posts

A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.

thehackerwire@mastodon.social at 2026-08-31T06:00:08.000Z ##

🔴 CVE-2026-82616 - Critical (9.9)

A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName results in stack-based buffer overflow. The attack can be ex...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82592
(9.9 CRITICAL)

EPSS: 0.77%

updated 2026-08-31T00:30:32

1 posts

A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of the argument partition results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.

1 repos

https://github.com/HackSpeak/CVE-2026-82592

thehackerwire@mastodon.social at 2026-08-31T01:00:21.000Z ##

🔴 CVE-2026-82592 - Critical (9.9)

A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of the argument partition results in stack-based buf...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82593
(9.9 CRITICAL)

EPSS: 0.51%

updated 2026-08-31T00:30:32

1 posts

A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgrade. This manipulation of the argument fota_url causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used.

thehackerwire@mastodon.social at 2026-08-31T01:00:11.000Z ##

🔴 CVE-2026-82593 - Critical (9.9)

A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgrade. This manipulation of the argument fota_url causes stack-based buffer o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82549
(8.3 HIGH)

EPSS: 0.19%

updated 2026-08-30T18:33:59

1 posts

A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to improper validation of integrity check value. The attack may be launched remotely. The exploit is publicly available and might be used.

thehackerwire@mastodon.social at 2026-08-30T16:59:58.000Z ##

🟠 CVE-2026-82549 - High (8.3)

A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to improper validation of integrity check value. The attack may be launched rem...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82644
(7.5 HIGH)

EPSS: 0.26%

updated 2026-08-30T15:30:35

1 posts

WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which protects login.json.php and 13 other endpoints. The function stores its attempt counter via a cache layer (ObjectYPT::setCacheGlobal) that silently discards writes for any client identified as a bot by isBot(). Because isBot() treats a missing User-Agent header as a bot by default —

thehackerwire@mastodon.social at 2026-08-30T16:02:43.000Z ##

🟠 CVE-2026-82644 - High (7.5)

WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which protects login.json.php and 13 other endpoints. The function stores its attempt counter via a cache layer (ObjectYPT::setCacheGlob...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82638
(7.5 HIGH)

EPSS: 0.30%

updated 2026-08-30T15:30:34

1 posts

jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply publicly resolvable hostnames mapping to private addresses to retrieve cloud metadata and internal service content.

thehackerwire@mastodon.social at 2026-08-30T15:01:25.000Z ##

🟠 CVE-2026-82638 - High (7.5)

jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply publicly resolvable hostnames mapping to private addresses to retri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82642
(8.8 HIGH)

EPSS: 0.38%

updated 2026-08-30T15:30:34

1 posts

Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is sanitized with DOMPurify using a configuration that forbade only the <script> tag (FORBID_TAGS: ['script']) in apps/readest-app/src/services/transformers/sanitizer.ts. DOMPurify does not parse the contents of the srcdoc attribute on <iframe> elements, treating it as an opaque string attribute

thehackerwire@mastodon.social at 2026-08-30T15:00:40.000Z ##

🟠 CVE-2026-82642 - High (8.8)

Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is sanitized with DOMPurify using a configuration that forbade only the tag (FORBID_TAGS: ['script']) in apps/readest-app/src/services/transfo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82542
(10.0 CRITICAL)

EPSS: 0.64%

updated 2026-08-30T15:30:34

2 posts

A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

thehackerwire@mastodon.social at 2026-08-30T14:00:37.000Z ##

🔴 CVE-2026-82542 - Critical (10)

A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer over...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cR0w@infosec.exchange at 2026-08-30T13:48:52.000Z ##

cve.org/CVERecord?id=CVE-2026-

sev:CRIT 10.0 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P

A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

##

CVE-2026-82657
(7.5 HIGH)

EPSS: 0.27%

updated 2026-08-30T15:30:29

1 posts

Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements modules. Unauthenticated attackers can retrieve forum topics and announcements by sending GET requests to rss/forum.php or rss/announcements.php, disclosing titles, full post text, author names, and timestamps.

thehackerwire@mastodon.social at 2026-08-30T16:02:32.000Z ##

🟠 CVE-2026-82657 - High (7.5)

Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements modules. Unauthenticated attackers can retrieve forum topics and announcements by sending GET requests to rss/forum.php or rss/...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82654
(8.9 HIGH)

EPSS: 0.22%

updated 2026-08-30T15:30:28

1 posts

SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to contain HTML/script tags that execute when another user views documents referencing or displaying that block.

thehackerwire@mastodon.social at 2026-08-30T16:01:42.000Z ##

🟠 CVE-2026-82654 - High (8.9)

SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to contain HTML/script tags that execute when another user views documents ref...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82653
(8.9 HIGH)

EPSS: 0.22%

updated 2026-08-30T15:30:28

1 posts

SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Attackers can submit malicious bazaar packages with HTML/script payloads in the name field that execute in users' browsers when uninstalling packages or unlocking encrypted notebooks.

thehackerwire@mastodon.social at 2026-08-30T16:01:34.000Z ##

🟠 CVE-2026-82653 - High (8.9)

SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Attackers can submit malicious bazaar packages with...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82539
(9.1 CRITICAL)

EPSS: 0.60%

updated 2026-08-30T12:31:39

1 posts

A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation of the argument desc can lead to memory corruption. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

1 repos

https://github.com/Xernary/CVE-2026-82539

thehackerwire@mastodon.social at 2026-08-30T12:00:15.000Z ##

🔴 CVE-2026-82539 - Critical (9.1)

A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation of the argument desc can lead to memory corruption...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15980
(9.8 CRITICAL)

EPSS: 0.45%

updated 2026-08-30T06:30:22

1 posts

The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_link() AJAX handler and improper token validation in the activate() function. This makes it possible for unauthenticated attackers to generate an activation token for an unconfirmed user account and obtain a valid authentication c

hugovalters@mastodon.social at 2026-08-30T15:01:43.000Z ##

CVE-2026-15980 - Critical Auth Bypass in WordPress MyHome Core plugin (<= 4.4.5) allows unauthenticated admin account takeover. CVSS 9.8. Mitigate now. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-159

##

CVE-2026-82461
(8.1 HIGH)

EPSS: 0.19%

updated 2026-08-29T18:31:31

1 posts

pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm and client roles. Attackers can forge access tokens with administrative roles paired with valid ID tokens to bypass authorization checks in applications relying on pac4j role validation.

hugovalters@mastodon.social at 2026-08-30T12:04:12.000Z ##

CVE-2026-82461 - Auth bypass in pac4j-oidc. Unverified access tokens allow forging admin roles. CVSS 8.1. Update to v6.5.6 now. #CVE #infosec #cybersecurity

valtersit.com/cve/CVE-2026-824

##

CVE-2026-80714
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-08-29T07:16:52.880000

1 posts

In the Linux kernel, the following vulnerability has been resolved: ipvs: do not propagate one-packet flag to synced conns Synced connections can be created before their destination exists. When the destination is later added, ip_vs_bind_dest() copies connection flags from the destination into cp->flags. IP_VS_CONN_F_ONE_PACKET connections are not synced. If a synced connection inherits IP_VS_C

CVE-2026-38638
(7.5 HIGH)

EPSS: 0.45%

updated 2026-08-29T00:32:03

1 posts

An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.

thehackerwire@mastodon.social at 2026-08-31T02:59:57.000Z ##

🟠 CVE-2026-38638 - High (7.5)

An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-37237
(7.5 HIGH)

EPSS: 0.53%

updated 2026-08-29T00:30:58

1 posts

vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion. The AsyncMediaIO.fetch_audio and AsyncMediaIO.fetch_image functions in multimodal/inputs.py fetch user-supplied media URLs using aiohttp and call r.read() without enforcing a maximum response size, allowing an attacker to exhaust server memory by providing a URL to an arbitrarily large file.

thehackerwire@mastodon.social at 2026-08-31T03:00:07.000Z ##

🟠 CVE-2026-37237 - High (7.5)

vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion. The AsyncMediaIO.fetch_audio and AsyncMediaIO.fetch_image functions in multimodal/inputs.py fetch user-supplied media URLs using aiohttp an...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56854
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-28T22:16:52.220000

1 posts

The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote

thehackerwire@mastodon.social at 2026-08-31T02:00:42.000Z ##

🟠 CVE-2026-56854 - High (7.5)

The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the Passwor...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55484
(7.5 HIGH)

EPSS: 0.34%

updated 2026-08-28T22:16:50.640000

1 posts

ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack. Prior to 0.0.0-20260617230736-314b6783e196, core/utils.go::sanitizeRequestPath calls splitPathQuery on a request path beginning with a question mark and then performs the unchecked p[0] access without checking whether the resulting path is empty. An unauthenticated client can send a malformed

thehackerwire@mastodon.social at 2026-08-30T12:01:36.000Z ##

🟠 CVE-2026-55484 - High (7.5)

ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack. Prior to 0.0.0-20260617230736-314b6783e196, core/utils.go::sanitizeRequestPath calls splitPathQuery on a request path beginning with a quest...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-50979
(8.1 HIGH)

EPSS: 1.43%

updated 2026-08-28T21:32:17

1 posts

A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arbitrary shell commands via the 'url' parameter

1 repos

https://github.com/bugresearch/CVE-2026-50979

thehackerwire@mastodon.social at 2026-08-31T02:00:53.000Z ##

🟠 CVE-2026-50979 - High (8.1)

A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arbitrary shell commands via the 'url' parameter

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76581
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-08-28T20:19:54.767000

1 posts

The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction between the unauthenticated `wdpsso_step1` and `wdpsso_step2` AJAX actions, where step 1 signs and discloses an unseparated concatenation of the token, state, redirect, and domain values, while step 2 ver

2 repos

https://github.com/hackersroot/CVE-2026-76581-Detector

https://github.com/HORKimhab/CVE-2026-76581

hacksgr@mastodon.social at 2026-09-01T21:22:47.000Z ##

Wordfence and Patchstack report five vulnerabilities in WordPress products: WPMU DEV Dashboard (CVE-2026-76581), Avada/Fusion Builder (CVE-2026-18431), TranslatePress (CVE-2026-19632), Pods (CVE-2026-19598) and GiveWP (CVE-2026-82222).

Scores range from CVSS 9.8 to 10.0.

Depending on the affected version and configuration, the flaws can enable authentication bypass, administrator takeover, file creation or command execution on the serve…

en.hacks.gr/synagermos-sto-wor

#WordPress #Vulnerability #CVE

##

CVE-2026-53362
(7.8 HIGH)

EPSS: 0.51%

updated 2026-08-28T20:18:10.133000

1 posts

In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlen = datalen - transhdrlen; datalen already includes fraggap (datalen = length +

1 repos

https://github.com/suominen/ipv6_frag_escape

sayzard@mastodon.sayzard.org at 2026-09-02T21:40:43.000Z ##

OpenAI's agents exploited a patched Linux bug in Hugging Face incident

Linux 커널 IPv6 패킷 출력 경로의 범위 밖 쓰기 취약점 CVE-2026-53362(Fraggap)가 실제 악용 목록(CISA KEV)에 추가됐다. 공격자는 로컬 실행 권한 또는 컨테이너 내부 발판이 있는 상태에서 IPv6 UDP와 특정 플래그 조합을 이용해 커널 힙 손상을 유발하고 권한 상승, 서비스 거부, 데이터 손상을 노릴 수 있다. 기사에 따르면 OpenAI의 에이전트는 공개 PoC를 대상 아키텍처에 맞게 변형해 Hugging Face 관련 보안 사고에서 Artifactory 컨테이너...

zdnet.com/tech/cve-2026-53362-

##

CVE-2026-37736
(7.5 HIGH)

EPSS: 0.34%

updated 2026-08-28T20:17:27.030000

1 posts

An issue in the JsonSanitizer.sanitize() component of OWASP json-sanitizer v1.2.3 allows attackers to cause a Denial of Service (DoS) via a crafted input.

thehackerwire@mastodon.social at 2026-08-31T03:00:17.000Z ##

🟠 CVE-2026-37736 - High (7.5)

An issue in the JsonSanitizer.sanitize() component of OWASP json-sanitizer v1.2.3 allows attackers to cause a Denial of Service (DoS) via a crafted input.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55215
(7.5 HIGH)

EPSS: 0.42%

updated 2026-08-28T19:03:39

1 posts

### Summary When SSL/TLS is enabled but no CA / server certificate is provided, the connector verifies the server's identity using fingerprint validation. The check is effective, the connection is ultimately rejected when it fails, but it happens *after* the authentication exchange. As a result, the credentials are sent before validation occurs, so an active man-in-the-middle who presents their

thehackerwire@mastodon.social at 2026-08-30T14:01:27.000Z ##

🟠 CVE-2026-55215 - High (7.5)

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to versions 3.3.3, 3.4.6, and 3.5.3, when ssl is enabled without a pinned CA or server certificate, MariaDB Connector/Node.js send...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18634
(8.4 HIGH)

EPSS: 0.22%

updated 2026-08-28T18:58:27.140000

2 posts

An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and earlier versions. A local attacker with the ability to interact with the service could exploit this behavior to perform unauthorized actions through the affected component.

pentesttools at 2026-09-01T14:29:08.746Z ##

Oh, look, it's a fresh batch of CVEs that our research team found (and responsibly reported)!

They all impact SonicWall GMS, which SonicWall has now patched:

👉 CVE-2026-66147 - unauthenticated command injection in the Dispatcher Service, CVSS 9.4
👉 CVE-2026-66154 - weak certificate verification leading to user compromise via MitM, CVSS 8.3*
👉 CVE-2026-18634 - local privilege escalation via deserialization, CVSS 8.4

When it shortens 🤏 the distance between discovery and action - *that’s* what does to help security teams.

Here's our team's latest disclosed contribution to the community: psirt.global.sonicwall.com/vul

And here's where you can get more of our research: pentest-tools.com/research

PS: More SonicWALL vulnerabilities coming soon to a research blog near you. 🫵

##

pentesttools@infosec.exchange at 2026-09-01T14:29:08.000Z ##

Oh, look, it's a fresh batch of CVEs that our #offensivesecurity research team found (and responsibly reported)!

They all impact SonicWall GMS, which SonicWall has now patched:

👉 CVE-2026-66147 - unauthenticated command injection in the Dispatcher Service, CVSS 9.4
👉 CVE-2026-66154 - weak certificate verification leading to user compromise via MitM, CVSS 8.3*
👉 CVE-2026-18634 - local privilege escalation via deserialization, CVSS 8.4

When it shortens 🤏 the distance between discovery and action - *that’s* what #vulnerabilityresearch does to help security teams.

Here's our team's latest disclosed contribution to the community: psirt.global.sonicwall.com/vul

And here's where you can get more of our research: pentest-tools.com/research

PS: More SonicWALL vulnerabilities coming soon to a research blog near you. 🫵

##

CVE-2026-55248
(9.1 CRITICAL)

EPSS: 0.32%

updated 2026-08-28T18:41:35

1 posts

### Impact By adding an RSS portlet, and giving this a link to a very large file, a member can cause a denial of service attack, because Plone will use lots of memory. The member could also use different urls to try to get information about the internal network and open port numbers (SSRF). A malicious RSS feed could cause stored XSS, when the url of a feed item is a javascript url. ### Patches T

thehackerwire@mastodon.social at 2026-08-30T11:00:12.000Z ##

🔴 CVE-2026-55248 - Critical (9.1)

plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets. Prior to 5.0.8, 6.0.4, and 7.0.2, a member who can add an RSS portlet can set its feed URL to a very large response, causing src/plone/app/portlets/portle...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55485
(8.8 HIGH)

EPSS: 0.39%

updated 2026-08-28T18:14:13

1 posts

## Summary `piccolo_admin` uses a helper called `superuser_validators` to gate access to the user and session tables for non-superusers. The helper rejects `PUT`, `PATCH`, `DELETE`, and `POST`, but **does not reject `GET`**. The `sessions` table stores live session tokens **in plaintext**, and the token column is not marked `secret=True`, so it is included in every `GET` response. Any non-superu

thehackerwire@mastodon.social at 2026-08-30T12:01:46.000Z ##

🟠 CVE-2026-55485 - High (8.8)

Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0, piccolo_admin/endpoints.py uses superuser_validators to block PUT, PATCH, DELETE, and POST requests by non-superusers but permi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55559
(9.8 CRITICAL)

EPSS: 0.55%

updated 2026-08-28T17:23:05

1 posts

### Summary `templateArgs` sent to `POST /api/instances` (and `PATCH /api/instances/{instance}`) are written into the rendered instance config as raw text, then parsed as YAML and loaded. Yamcs instantiates each `services:` entry by its `class:`, so injecting YAML through a template arg lets you add a `services:` entry for `org.yamcs.ProcessRunner` and run a command on the host. The args aren't e

thehackerwire@mastodon.social at 2026-08-30T11:00:01.000Z ##

🔴 CVE-2026-55559 - Critical (9.8)

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into YAML through VarStatement.append in yamcs-core/src/main/java/org/yamcs/templating/VarSta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55552
(7.5 HIGH)

EPSS: 0.43%

updated 2026-08-28T17:20:43

1 posts

### Attack type:  Unauthenticated remote  ### Impact: Attackers can access any system files from the underlying host. ### Affected components: HttpRequestHandler.java, StaticFileHandler.java An Unauthenticated Directory Traversal vulnerability exists in Yamcs <=5.8.6, allowing anyone to access any file on the underlying operating system. This allows unauthenticated attackers to download sensi

thehackerwire@mastodon.social at 2026-08-30T10:59:51.000Z ##

🟠 CVE-2026-55552 - High (7.5)

Yamcs is a mission control framework. Prior to 5.11.13, Yamcs StaticFileHandler.locateFile resolves an unauthenticated request path without using Path.normalize and Path.toAbsolutePath to confirm that the absolute path remains within the configure...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55521
(8.8 HIGH)

EPSS: 0.36%

updated 2026-08-28T17:09:36

1 posts

### Summary Multiple Missing Function Level Access Control vulnerabilities exist in the Yamcs Core API. These vulnerabilities allow any authenticated user, regardless of their assigned roles or privileges (e.g., an unprivileged "Guest"), to bypass intended access controls. An attacker can exploit these flaws to extract sensitive telemetry metadata, disrupt satellite communication link protocols (C

thehackerwire@mastodon.social at 2026-08-30T09:00:12.000Z ##

🟠 CVE-2026-55521 - High (8.8)

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks in IndexesApi.listPacketIndex, IndexesApi.listEventIndex, Cop1Api.disable, Cop1Api.resume, Cop1Api.initialize, Cop1Api.updateConfig, and TimeApi.set...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55511
(9.1 CRITICAL)

EPSS: 0.68%

updated 2026-08-28T17:06:57

1 posts

## Overview Yamcs compiles StreamSQL expressions to Java on the fly with the Janino `SimpleCompiler` (no restrictive class-loading policy or expression sandbox). When a StreamSQL aggregate such as `sum(...)` is applied to a **column**, the column's *name* is interpolated **unescaped** into the generated Java source. Because Yamcs accepts arbitrary characters in a double-quoted column identifier a

1 repos

https://github.com/junfuture1103/CVE-2026-55511

thehackerwire@mastodon.social at 2026-08-30T12:01:57.000Z ##

🔴 CVE-2026-55511 - Critical (9.1)

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiving to create a double-quoted StreamSQL column name that is interpolated into generated Java source by Expression.fillCode_Inpu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55065
(8.1 HIGH)

EPSS: 0.35%

updated 2026-08-28T16:50:36

1 posts

### Summary A user with only a single self-owned project can permanently destroy the Kanban bucket assignments (`task_buckets`) and task ordering (`task_positions`) of **any other project view in the entire instance**. The `ProjectView.Delete` model method runs three SQL statements: the first is properly scoped to `(view_id, project_id)`, but the next two cascading deletes on `task_buckets` and `

thehackerwire@mastodon.social at 2026-08-30T15:01:49.000Z ##

🟠 CVE-2026-55065 - High (8.1)

Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:project/views/:view permits an authenticated user to supply a view identifier from another project while authorizing only against an ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54788
(7.5 HIGH)

EPSS: 0.56%

updated 2026-08-28T16:35:04

1 posts

### Impact Datadog tracing libraries that implement W3C Trace Context (`tracecontext`) propagation parse the incoming `tracestate` header without enforcing a size cap on the Datadog vendor entry (`dd=...`). The `dd=` value contains semicolon-separated `key:value` pairs, and the parser allocates a hash-map entry for each pair. A remote, unauthenticated attacker can send a `tracestate` header whose

thehackerwire@mastodon.social at 2026-08-31T02:00:31.000Z ##

🟠 CVE-2026-54788 - High (7.5)

dd-trace-rs provides Datadog application performance monitoring for Rust. From 0.1.0 until 0.3.3, datadog-opentelemetry/src/propagation/tracecontext.rs parses the W3C tracestate header and collects every semicolon-separated key and value pair in t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54755
(9.6 CRITICAL)

EPSS: 0.39%

updated 2026-08-28T16:25:49

1 posts

## Summary The per-entry percentages of a KDA asset's **split royalties** are validated by summing them into a **`uint32`** accumulator and checking the *sum* against `HundredPercent (10000)`, with **no upper bound on each individual entry**. Two split entries whose percentages sum to just over `2^32` **wrap around** below `10000` and pass validation, while each stored value remains astronomicall

thehackerwire@mastodon.social at 2026-08-30T17:00:39.000Z ##

🔴 CVE-2026-54755 - Critical (9.6)

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain values greater than core.HundredPercent, and core/kapp/kda/create.go and core/ka...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54754
(9.6 CRITICAL)

EPSS: 0.30%

updated 2026-08-28T16:22:16

1 posts

## Summary When a marketplace order is settled (`MarketBuy` / `BuyItNow`, and auction `Claim`), the buyer's payment is split three ways — **referral**, **royalties**, and the **seller (market-order owner) remainder**: ``` marketOwnerAmount = CurrentBid − referralAmount − royaltiesAmount ``` Referral and royalties are paid out **unconditionally**, but the seller remainder is only paid **when pos

thehackerwire@mastodon.social at 2026-08-30T17:00:29.000Z ##

🔴 CVE-2026-54754 - Critical (9.6)

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, marketplace settlement in core/kapp/market/market.go reads MarketOrderData.ReferralPercentage from the listing while reading asset.Royalties.MarketPercentage li...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55108
(8.5 HIGH)

EPSS: 0.57%

updated 2026-08-28T16:13:22

1 posts

### Summary KubeVela's Terraform remote configuration loader can be abused to make `vela-core` read an unbounded byte stream into memory, causing an out-of-memory kill and a control-plane denial of service. The issue is reachable when a user with permission to create or update a `core.oam.dev/v1beta1` `ComponentDefinition` registers a Terraform `remote` schematic that points to a malicious or co

thehackerwire@mastodon.social at 2026-08-30T14:01:49.000Z ##

🟠 CVE-2026-55108 - High (8.5)

KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.11.0-alpha.1 until 1.11.0-alpha.4, the Terraform remote configuration loader in pkg/controller/utils/capability.go, GetTerrafor...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82222
(10.0 CRITICAL)

EPSS: 0.42%

updated 2026-08-28T12:30:36

2 posts

Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1.

3 repos

https://github.com/dinosn/givewp-cve-2026-82222-rce-lab

https://github.com/R0x19/CVE-2026-82222

https://github.com/UdinChan/cve-2026-82222-poc

hacksgr@mastodon.social at 2026-09-01T21:22:47.000Z ##

Wordfence and Patchstack report five vulnerabilities in WordPress products: WPMU DEV Dashboard (CVE-2026-76581), Avada/Fusion Builder (CVE-2026-18431), TranslatePress (CVE-2026-19632), Pods (CVE-2026-19598) and GiveWP (CVE-2026-82222).

Scores range from CVSS 9.8 to 10.0.

Depending on the affected version and configuration, the flaws can enable authentication bypass, administrator takeover, file creation or command execution on the serve…

en.hacks.gr/synagermos-sto-wor

#WordPress #Vulnerability #CVE

##

beyondmachines1@infosec.exchange at 2026-08-30T09:01:41.000Z ##

GiveWP Vulnerability Allows Unauthenticated Remote Code Execution

GiveWP released a security update to fix a maximum-severity vulnerability (CVE-2026-82222) that allows unauthenticated attackers to execute remote code and take over WordPress servers.

**If you run the GiveWP donation plugin on your WordPress site, update it to version 4.16.7.2 immediately. This flaw lets anyone take over your server without logging in, and the update also cleans out any malicious code already planted in your database. If you can't update immediately, put a web application firewall in front of the site to block PHP serialization attacks, and check your user accounts for any you didn't create.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-71362
(9.1 CRITICAL)

EPSS: 25.14%

updated 2026-08-28T00:18:09.390000

2 posts

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

Nuclei template

1 repos

https://github.com/dinosn/cve-2026-71362-magento-lab

secdb at 2026-09-01T07:54:00.828Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-01T07:54:00.000Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2023-49105
(9.8 CRITICAL)

EPSS: 43.20%

updated 2026-08-27T21:32:08

1 posts

An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.

Nuclei template

1 repos

https://github.com/ambionics/owncloud-exploits

thecybermind@infosec.exchange at 2026-08-31T14:40:05.000Z ##

URGENT C-Suite Brief: CVE-2023-49105 active exploitation targets ownCloud authentication flaws. Read our executive brief for rapid mitigation steps, identity governance controls, and asset integrity protocols to protect your enterprise perimeter. thecybermind.co/v5jn

##

CVE-2026-71906
(7.2 HIGH)

EPSS: 3.05%

updated 2026-08-26T19:16:58.790000

1 posts

Multiple DrayTek VigorAP models contain a command injection vulnerability in the setLan function. The vulnerability is caused by insufficient validation of the lanIp and lanNetmask fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the devi

secdb@infosec.exchange at 2026-08-31T00:01:12.000Z ##

📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461

Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194

CISA KEVs:
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90

Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47864 - 3.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71921 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71914 - 3.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71905 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71906 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71907 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71908 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71909 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71910 - 3.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-18431
(9.8 CRITICAL)

EPSS: 0.64%

updated 2026-08-26T18:32:03

1 posts

The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses across the two components that makes it possible for unauthenticated attackers to write attacker-controlled files to the s

1 repos

https://github.com/HORKimhab/CVE-2026-18431

hacksgr@mastodon.social at 2026-09-01T21:22:47.000Z ##

Wordfence and Patchstack report five vulnerabilities in WordPress products: WPMU DEV Dashboard (CVE-2026-76581), Avada/Fusion Builder (CVE-2026-18431), TranslatePress (CVE-2026-19632), Pods (CVE-2026-19598) and GiveWP (CVE-2026-82222).

Scores range from CVSS 9.8 to 10.0.

Depending on the affected version and configuration, the flaws can enable authentication bypass, administrator takeover, file creation or command execution on the serve…

en.hacks.gr/synagermos-sto-wor

#WordPress #Vulnerability #CVE

##

CVE-2026-19632
(9.8 CRITICAL)

EPSS: 0.79%

updated 2026-08-26T18:31:52

1 posts

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. This makes it possible for unauthenticated attackers to extract the raw administrator password-reset URL — including the plaintext reset key and login parameters sto

2 repos

https://github.com/DeadExpl0it/CVE-2026-19632-POC

https://github.com/YonLiud/CVE-2026-19632

hacksgr@mastodon.social at 2026-09-01T21:22:47.000Z ##

Wordfence and Patchstack report five vulnerabilities in WordPress products: WPMU DEV Dashboard (CVE-2026-76581), Avada/Fusion Builder (CVE-2026-18431), TranslatePress (CVE-2026-19632), Pods (CVE-2026-19598) and GiveWP (CVE-2026-82222).

Scores range from CVSS 9.8 to 10.0.

Depending on the affected version and configuration, the flaws can enable authentication bypass, administrator takeover, file creation or command execution on the serve…

en.hacks.gr/synagermos-sto-wor

#WordPress #Vulnerability #CVE

##

CVE-2026-71910
(7.2 HIGH)

EPSS: 3.05%

updated 2026-08-26T17:10:09.810000

1 posts

Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotest function. The vulnerability is caused by insufficient validation of the CMD0, CMD3, and CMD6 fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the

secdb@infosec.exchange at 2026-08-31T00:01:12.000Z ##

📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461

Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194

CISA KEVs:
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90

Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47864 - 3.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71921 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71914 - 3.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71905 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71906 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71907 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71908 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71909 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71910 - 3.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-69836
(10.0 CRITICAL)

EPSS: 1.55%

updated 2026-08-25T16:08:43.290000

1 posts

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

2 repos

https://github.com/HORKimhab/CVE-2026-69836

https://github.com/sentinel-aidefense/CVE-2026-69836-EXP

oversecurity@mastodon.social at 2026-08-30T13:42:26.000Z ##

Microsoft Reverses Its Own ‘Exploitation’ Warning on Entra ID Flaw CVE-2026-69836

Microsoft disclosed and fixed a maximum-severity remote code execution vulnerability in Entra ID, its cloud identity platform, on August 20,

🔗️ [Thecyberexpress] link.is.it/15Q8CF

##

CVE-2026-71905
(7.2 HIGH)

EPSS: 3.05%

updated 2026-08-25T15:33:57

1 posts

Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings function. The vulnerability is caused by insufficient filtering of the backupkey, backuptype, and realtime fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative cr

secdb@infosec.exchange at 2026-08-31T00:01:12.000Z ##

📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461

Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194

CISA KEVs:
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90

Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47864 - 3.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71921 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71914 - 3.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71905 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71906 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71907 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71908 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71909 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71910 - 3.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-19949
(8.8 HIGH)

EPSS: 0.54%

updated 2026-08-25T12:31:24

1 posts

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archive restore functionality in all versions up to, and including, 7.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing q

Analyst207@mastodon.social at 2026-09-02T19:59:20.000Z ##

WordPress Plugin Flaw Enables Takeover Attacks on Millions of Sites

Millions of WordPress sites are at risk of takeover due to a high-severity vulnerability in the popular All-in-One WP Migration and Backup plugin, with 3.25 million sites still running a vulnerable version. This flaw, tracked as CVE-2026-19949, allows attackers to execute remote code and take full control of…

osintsights.com/wordpress-plug

#Wordpress #Cve202619949 #AllinoneWpMigrationAndBackup #SqlInjection #RemoteCodeExecution

##

CVE-2026-71914
(9.8 CRITICAL)

EPSS: 3.07%

updated 2026-08-24T18:31:59

1 posts

Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient validation of UDP message content after START_SPEED_TEST before command execution. A remote attacker can trigger this vulnerability via a crafted message to execute arbitrary commands with root privileges.

secdb@infosec.exchange at 2026-08-31T00:01:12.000Z ##

📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461

Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194

CISA KEVs:
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90

Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47864 - 3.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71921 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71914 - 3.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71905 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71906 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71907 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71908 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71909 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71910 - 3.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-71907
(7.2 HIGH)

EPSS: 3.05%

updated 2026-08-24T18:31:59

1 posts

Multiple DrayTek VigorAP models contain a command injection vulnerability in the setcamset function. The vulnerability is caused by insufficient filtering of the selectSlaves field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's we

secdb@infosec.exchange at 2026-08-31T00:01:12.000Z ##

📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461

Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194

CISA KEVs:
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90

Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47864 - 3.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71921 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71914 - 3.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71905 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71906 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71907 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71908 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71909 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71910 - 3.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-71909
(7.2 HIGH)

EPSS: 3.05%

updated 2026-08-24T18:31:59

1 posts

Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime function. The vulnerability is caused by insufficient filtering of the time field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web mana

secdb@infosec.exchange at 2026-08-31T00:01:12.000Z ##

📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461

Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194

CISA KEVs:
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90

Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47864 - 3.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71921 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71914 - 3.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71905 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71906 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71907 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71908 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71909 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71910 - 3.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-71921
(9.8 CRITICAL)

EPSS: 3.25%

updated 2026-08-24T18:31:59

1 posts

Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges.

secdb@infosec.exchange at 2026-08-31T00:01:12.000Z ##

📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461

Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194

CISA KEVs:
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90

Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47864 - 3.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71921 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71914 - 3.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71905 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71906 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71907 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71908 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71909 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71910 - 3.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-71908
(7.2 HIGH)

EPSS: 3.05%

updated 2026-08-24T18:31:58

1 posts

Multiple DrayTek VigorAP models contain a command injection vulnerability in the mesh_start_speed_test function. The vulnerability is caused by insufficient sanitization of the meshdevice_index and meshdevice_ip fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administ

secdb@infosec.exchange at 2026-08-31T00:01:12.000Z ##

📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461

Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194

CISA KEVs:
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90

Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47864 - 3.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71921 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71914 - 3.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71905 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71906 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71907 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71908 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71909 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71910 - 3.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-12555(CVSS UNKNOWN)

EPSS: 0.23%

updated 2026-08-24T18:31:53

2 posts

Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.

_r_netsec at 2026-09-02T21:28:05.309Z ##

Rooted in Trust: Three privilege-escalation vulnerabilities in HP Easy Start for macOS (CVE-2026-12554, CVE-2026-12555, CVE-2026-12556) ciphersecuritylabs.com/researc

##

_r_netsec@infosec.exchange at 2026-09-02T21:28:05.000Z ##

Rooted in Trust: Three privilege-escalation vulnerabilities in HP Easy Start for macOS (CVE-2026-12554, CVE-2026-12555, CVE-2026-12556) ciphersecuritylabs.com/researc

##

CVE-2026-12554(CVSS UNKNOWN)

EPSS: 0.21%

updated 2026-08-24T18:31:53

2 posts

Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.

_r_netsec at 2026-09-02T21:28:05.309Z ##

Rooted in Trust: Three privilege-escalation vulnerabilities in HP Easy Start for macOS (CVE-2026-12554, CVE-2026-12555, CVE-2026-12556) ciphersecuritylabs.com/researc

##

_r_netsec@infosec.exchange at 2026-09-02T21:28:05.000Z ##

Rooted in Trust: Three privilege-escalation vulnerabilities in HP Easy Start for macOS (CVE-2026-12554, CVE-2026-12555, CVE-2026-12556) ciphersecuritylabs.com/researc

##

CVE-2026-68162
(7.8 HIGH)

EPSS: 0.18%

updated 2026-08-23T15:32:57

2 posts

In the Linux kernel, the following vulnerability has been resolved: sctp: avoid auth_enable sysctl UAF during netns teardown proc_sctp_do_auth() updates the SCTP control socket after changing net.sctp.auth_enable. The handler gets the per-net SCTP state from ctl->data, so an already opened sysctl file can still target a network namespace while that namespace is being torn down. SCTP previously

CVE-2026-68766
(7.8 HIGH)

EPSS: 0.16%

updated 2026-08-22T15:31:11

1 posts

hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and --potfile-path. Attackers can craft restore files with malicious options to append attacker-controlled content to arbitrary files, enabling code execution when targeting shell startup files.

tychotithonus@infosec.exchange at 2026-09-01T04:39:34.000Z ##

CVE-2026-68766 is a "vulnerability" in hashcat:

github.com/hashcat/hashcat/iss

... where, if you already have write access to hashcat's own restore files (which are locally generated, locally managed, and reachable by the same user invoking hashcat) ... you can ... pass arguments to hashcat other than the ones that were on the original command line. 😐

To be fair, atom did reduce the scope of what the hashcat restore command does -- instead of executing hashcat with the arguments, it just reassembles the cmdline and presents it to the user to review and run as appropriate:

github.com/hashcat/hashcat/com

Still a BS report, IMO -- just CVE farming.

Same reporter, different CVE, rejected outright because it doesn't cross a security boundary:

github.com/hashcat/hashcat/iss

(And I'm told that the CVE-issuance triage ambiguity -- that greenlit these CVEs that would have been rejected -- is being addressed.)

#hashcat

##

CVE-2026-73570
(8.9 HIGH)

EPSS: 20.53%

updated 2026-08-21T18:34:48

2 posts

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands a

Nuclei template

7 repos

https://github.com/HORKimhab/CVE-2026-73570

https://github.com/jishino567/CVE-2026-73570

https://github.com/byt3l0rd/CVE-2026-73570

https://github.com/alsyundawy/eradicate-zimbra-malware

https://github.com/gabrielunknown/CVE-2026-73570

https://github.com/INFOKOM-KI/Zimbra-CVE-2026-73570-Rules

https://github.com/BiuTrap/CVE-2026-73570

secdb at 2026-09-01T07:54:00.828Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-01T07:54:00.000Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-64849
(9.3 CRITICAL)

EPSS: 16.41%

updated 2026-08-20T19:16:57.867000

2 posts

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated addr

Nuclei template

3 repos

https://github.com/BiuTrap/CVE-2026-64849

https://github.com/codeb0ssx/CVE-2026-64849-PoC

https://github.com/zavisco/CVE-2026-64849.yaml

secdb at 2026-09-01T07:54:00.828Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-01T07:54:00.000Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-32475
(9.0 CRITICAL)

EPSS: 2.37%

updated 2026-08-20T12:48:31.843000

2 posts

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.

Nuclei template

4 repos

https://github.com/Boreas37/CVE-2026-32475-PoC

https://github.com/sahmsec/CVE-2026-32475

https://github.com/0xBlackash/CVE-2026-32475

https://github.com/absholi7ly/Elementor-Pro-Unauthenticated-Arbitrary-File-Upload-to-RCE

DailyCyberSecurity at 2026-09-02T15:25:26.197Z ##

Attackers exploit a critical Elementor Pro vulnerability (CVE-2026-32475) in the wild. Patch this Elementor Pro vulnerability to prevent site takeover.

securityonline.info/elementor-

##

DailyCyberSecurity@infosec.exchange at 2026-09-02T15:25:26.000Z ##

Attackers exploit a critical Elementor Pro vulnerability (CVE-2026-32475) in the wild. Patch this Elementor Pro vulnerability to prevent site takeover.

#ElementorPro #CVE202632475 #WordPress #Cybersecurity #RCE

securityonline.info/elementor-

##

CVE-2026-65400
(7.1 HIGH)

EPSS: 9.90%

updated 2026-08-18T18:31:47

2 posts

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

3 repos

https://github.com/panchocosil/CVE-2026-65400-poc

https://github.com/acheong08/CVE-2026-65400

https://github.com/HORKimhab/CVE-2026-65400

secdb at 2026-09-01T07:54:00.828Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-01T07:54:00.000Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-19598
(9.8 CRITICAL)

EPSS: 2.79%

updated 2026-08-15T18:31:24

1 posts

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check — including the method allowlist, nonce verification, login enforcement, and capability gate — through pods_error(), which under the JSON met

4 repos

https://github.com/sag-asab/CVE-2026-19598

https://github.com/DeadExpl0it/CVE-2026-19598-PoC

https://github.com/ksotaria1337/CVE-2026-19598

https://github.com/HackfutSecRoot/multi_exploit_wp

hacksgr@mastodon.social at 2026-09-01T21:22:47.000Z ##

Wordfence and Patchstack report five vulnerabilities in WordPress products: WPMU DEV Dashboard (CVE-2026-76581), Avada/Fusion Builder (CVE-2026-18431), TranslatePress (CVE-2026-19632), Pods (CVE-2026-19598) and GiveWP (CVE-2026-82222).

Scores range from CVSS 9.8 to 10.0.

Depending on the affected version and configuration, the flaws can enable authentication bypass, administrator takeover, file creation or command execution on the serve…

en.hacks.gr/synagermos-sto-wor

#WordPress #Vulnerability #CVE

##

CVE-2026-14669
(8.8 HIGH)

EPSS: 0.58%

updated 2026-08-13T15:34:40

1 posts

Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

1 repos

https://github.com/HackSpeak/CVE-2026-14669

mastokukei@social.josko.org at 2026-09-02T18:02:09.000Z ##

from server images; CVE-2026-14669 heap buffer overflow fix.
- **NetBSD package updates**: Frequent updates to packages like `freenginx`, `ruby-sequel`, `chezscheme`, `sbcl`, and `haproxy`.
- **AI coding tools and debates**: Discussions on AI for discovery, analysis, and code generation; tools like `OpenClaw`, `LLM::Graph`, and `hypruse`.
- **Arduino libraries**: New/updated libraries (e.g., `AMY Synthesizer`, `ESP32KeyBridge`, `HomeAssistantDiscovery`). [2/2]

##

CVE-2026-66154
(8.3 HIGH)

EPSS: 0.13%

updated 2026-08-12T00:31:10

2 posts

An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlier versions which, under a successful MitM attack and controlled network conditions, could permit unauthorized changes.

pentesttools at 2026-09-01T14:29:08.746Z ##

Oh, look, it's a fresh batch of CVEs that our research team found (and responsibly reported)!

They all impact SonicWall GMS, which SonicWall has now patched:

👉 CVE-2026-66147 - unauthenticated command injection in the Dispatcher Service, CVSS 9.4
👉 CVE-2026-66154 - weak certificate verification leading to user compromise via MitM, CVSS 8.3*
👉 CVE-2026-18634 - local privilege escalation via deserialization, CVSS 8.4

When it shortens 🤏 the distance between discovery and action - *that’s* what does to help security teams.

Here's our team's latest disclosed contribution to the community: psirt.global.sonicwall.com/vul

And here's where you can get more of our research: pentest-tools.com/research

PS: More SonicWALL vulnerabilities coming soon to a research blog near you. 🫵

##

pentesttools@infosec.exchange at 2026-09-01T14:29:08.000Z ##

Oh, look, it's a fresh batch of CVEs that our #offensivesecurity research team found (and responsibly reported)!

They all impact SonicWall GMS, which SonicWall has now patched:

👉 CVE-2026-66147 - unauthenticated command injection in the Dispatcher Service, CVSS 9.4
👉 CVE-2026-66154 - weak certificate verification leading to user compromise via MitM, CVSS 8.3*
👉 CVE-2026-18634 - local privilege escalation via deserialization, CVSS 8.4

When it shortens 🤏 the distance between discovery and action - *that’s* what #vulnerabilityresearch does to help security teams.

Here's our team's latest disclosed contribution to the community: psirt.global.sonicwall.com/vul

And here's where you can get more of our research: pentest-tools.com/research

PS: More SonicWALL vulnerabilities coming soon to a research blog near you. 🫵

##

CVE-2026-66147
(9.4 CRITICAL)

EPSS: 2.00%

updated 2026-08-12T00:31:09

2 posts

An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.

pentesttools at 2026-09-01T14:29:08.746Z ##

Oh, look, it's a fresh batch of CVEs that our research team found (and responsibly reported)!

They all impact SonicWall GMS, which SonicWall has now patched:

👉 CVE-2026-66147 - unauthenticated command injection in the Dispatcher Service, CVSS 9.4
👉 CVE-2026-66154 - weak certificate verification leading to user compromise via MitM, CVSS 8.3*
👉 CVE-2026-18634 - local privilege escalation via deserialization, CVSS 8.4

When it shortens 🤏 the distance between discovery and action - *that’s* what does to help security teams.

Here's our team's latest disclosed contribution to the community: psirt.global.sonicwall.com/vul

And here's where you can get more of our research: pentest-tools.com/research

PS: More SonicWALL vulnerabilities coming soon to a research blog near you. 🫵

##

pentesttools@infosec.exchange at 2026-09-01T14:29:08.000Z ##

Oh, look, it's a fresh batch of CVEs that our #offensivesecurity research team found (and responsibly reported)!

They all impact SonicWall GMS, which SonicWall has now patched:

👉 CVE-2026-66147 - unauthenticated command injection in the Dispatcher Service, CVSS 9.4
👉 CVE-2026-66154 - weak certificate verification leading to user compromise via MitM, CVSS 8.3*
👉 CVE-2026-18634 - local privilege escalation via deserialization, CVSS 8.4

When it shortens 🤏 the distance between discovery and action - *that’s* what #vulnerabilityresearch does to help security teams.

Here's our team's latest disclosed contribution to the community: psirt.global.sonicwall.com/vul

And here's where you can get more of our research: pentest-tools.com/research

PS: More SonicWALL vulnerabilities coming soon to a research blog near you. 🫵

##

CVE-2026-48376
(5.4 MEDIUM)

EPSS: 13.92%

updated 2026-08-11T18:31:03

2 posts

is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction.

secdb at 2026-09-01T07:54:00.828Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-01T07:54:00.000Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-58231
(10.0 CRITICAL)

EPSS: 1.71%

updated 2026-08-11T12:30:28

1 posts

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

3 repos

https://github.com/HORKimhab/CVE-2026-58231

https://github.com/SAP-system-update/CVE-2026-58231

https://github.com/WildanDeveloper/CVE-2026-58231

linuxmint_hun@mastodon.social at 2026-09-01T06:16:59.000Z ##

Az SAP Commerce Cloud CVE-2026-58231 sebezhetőségét már a javítás után napokkal támadások célba vették

linuxmint.hu/hir/2026/09/az-sa

##

CVE-2026-64638
(0 None)

EPSS: 31.20%

updated 2026-08-07T19:18:51.610000

2 posts

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all

Nuclei template

26 repos

https://github.com/ZSecur1ty/XSS2Shell-CVE-2026-64638

https://github.com/5yu4n/CVE-2026-64638

https://github.com/0xBlackash/CVE-2026-64638

https://github.com/686f6c61/POC-WP-XSS2Shell-CVE-2026-64638

https://github.com/G33l0/Cve-2026-64638

https://github.com/kaleth4/CVE-2026-64638

https://github.com/imbas007/CVE-2026-64638-POC

https://github.com/wordsec/XSS2Shell

https://github.com/ZildanZ/CVE-2026-64638

https://github.com/mohwahyudi/poc-CVE-2026-64638-

https://github.com/SanaullahAmanullah/xss2shell-check

https://github.com/HORKimhab/CVE-2026-64638

https://github.com/jendmaoul/XSS2Shell-CVE-2026-64638

https://github.com/xAL6/cve-2026-64638-banner-poc

https://github.com/yogaGymn/XSS2Shell-CVE-2026-64638

https://github.com/tc4dy/CVE-2026-64638-PoC-Exploit

https://github.com/Boreas37/CVE-2026-64638-PoC-XSS2Shell-

https://github.com/4minx/CVE-2026-64638

https://github.com/eh-amish/CVE-2026-64638-XSS-to-Shell-PoC

https://github.com/Alixploit22/CVEX2SHEL

https://github.com/0xlipon/xss2shell

https://github.com/Dungsocool/CVE-2026-64638

https://github.com/MR-LeonardoGomes/XSS2Shell-CVE-2026-64638

https://github.com/HackSpeak/CVE-2026-64638

https://github.com/g0d150ne/XSS2Shell

https://github.com/renzi25031469/CVE-2026-64638-WordPress-Core-XSS2Shell

secdb at 2026-09-01T07:54:00.828Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-01T07:54:00.000Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-15733
(9.8 CRITICAL)

EPSS: 13.54%

updated 2026-08-07T18:31:37

2 posts

A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attackers to execute arbitrary commands as root.

Nuclei template

secdb at 2026-09-01T07:54:00.828Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-01T07:54:00.000Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-63077
(9.8 CRITICAL)

EPSS: 87.71%

updated 2026-08-06T05:17:05.170000

2 posts

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Nuclei template

4 repos

https://github.com/bakos-sandor-nx/teamcity-cve-2026-63077-remediation

https://github.com/AnggaTechI/CVE-2026-63077

https://github.com/sfewer-r7/CVE-2026-63077

https://github.com/BoredHackerBlog/teamcity-CVE-2026-63077-pcap

beyondmachines1 at 2026-09-01T08:01:41.479Z ##

JetBrains Cadence Service Breached via Unpatched TeamCity RCE Flaw

JetBrains reported a breach of its Cadence cloud service after failing to patch a critical TeamCity vulnerability (CVE-2026-63077). The attack resulted in the theft of user personal data and a 2024 server backup containing sensitive AWS credentials and source code.

**Rotate every secret used in your cloud development workflows immediately to prevent lateral movement. This breach shows that even a single unpatched internal server can expose your entire backup history and cloud credentials.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-09-01T08:01:41.000Z ##

JetBrains Cadence Service Breached via Unpatched TeamCity RCE Flaw

JetBrains reported a breach of its Cadence cloud service after failing to patch a critical TeamCity vulnerability (CVE-2026-63077). The attack resulted in the theft of user personal data and a 2024 server backup containing sensitive AWS credentials and source code.

**Rotate every secret used in your cloud development workflows immediately to prevent lateral movement. This breach shows that even a single unpatched internal server can expose your entire backup history and cloud credentials.**
#cybersecurity #infosec #incident #databreach
beyondmachines.net/event_detai

##

CVE-2026-18577
(8.1 HIGH)

EPSS: 54.07%

updated 2026-08-04T15:33:20

2 posts

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

Nuclei template

2 repos

https://github.com/CreamyG31337/ncentral-compromise-ioc-triage

https://github.com/HORKimhab/CVE-2026-18577

secdb at 2026-09-01T07:54:00.828Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-01T07:54:00.000Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-66066(CVSS UNKNOWN)

EPSS: 27.86%

updated 2026-07-30T18:23:34

3 posts

### Impact In its default configuration, a Rails application that displays image variants may allow an unauthenticated attacker to read arbitrary files from the server, including the process environment. That environment typically holds `secret_key_base` and often credentials for external systems, which may in turn allow escalation to remote code execution or lateral movement to those systems. ##

7 repos

https://github.com/shinthink/CVE-2026-66066

https://github.com/paveg/rails-activestorage-vips-audit

https://github.com/0xsha/KindaRails2Shell

https://github.com/HackSpeak/CVE-2026-66066

https://github.com/rails/rails-forensics-CVE-2026-66066

https://github.com/Zer0SumGam3/CVE-2026-66066-POC

https://github.com/0xBlackash/CVE-2026-66066

undercodenews@mastodon.social at 2026-09-01T19:19:27.000Z ##

Hackers Are Exploiting a Critical Ruby on Rails Flaw That Can Expose Secrets and Enable Remote Code Execution

A Dangerous New Chapter for Ruby on Rails Security A critical vulnerability in Ruby on Rails has moved from a theoretical security concern to an active exploitation threat, raising fresh alarms for organizations that rely on Rails applications to handle sensitive data, authentication, file uploads, and internal business operations. Tracked as CVE-2026-66066,…

undercodenews.com/hackers-are-

##

cyberworldops at 2026-09-01T06:20:01.103Z ##

VulnCheck reports active exploitation of CVE-2026-66066 (KindaRails2Shell), a CVSS 9.5 flaw in Ruby on Rails. A crafted image upload enables arbitrary file read, leading to secret and credential theft with potential for lateral movement and RCE. Unpatched Rails instances handling file uploads are at immediate risk.

cyberworldops.eu/en/kindarails

##

cyberworldops@infosec.exchange at 2026-09-01T06:20:01.000Z ##

VulnCheck reports active exploitation of CVE-2026-66066 (KindaRails2Shell), a CVSS 9.5 flaw in Ruby on Rails. A crafted image upload enables arbitrary file read, leading to secret and credential theft with potential for lateral movement and RCE. Unpatched Rails instances handling file uploads are at immediate risk. #RubyOnRails #KindaRails2Shell #InfoSec

cyberworldops.eu/en/kindarails

##

CVE-2026-59822(CVSS UNKNOWN)

EPSS: 0.52%

updated 2026-07-22T22:38:34

6 posts

### Impact LiteLLM's MCP Streamable HTTP endpoint could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token. The MCP auth handler supported OAuth2 passthrough for upstream MCP servers, but the fallback path could replace failed LiteLLM key validation with an empty `UserAPIKeyAuth()` object. This allowed requests with a fabricated `Authoriza

AAKL at 2026-09-02T19:01:22.277Z ##

Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.

- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

##

secdb at 2026-09-02T19:00:11.414Z ##

🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48710 (secdb.nttzen.cloud/cve/detail/)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/Kludex/starlette/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-49869 (secdb.nttzen.cloud/cve/detail/)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/kestra-io/kestra/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-59822 (secdb.nttzen.cloud/cve/detail/)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: github.com/BerriAI/litellm/sec ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82329 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83548 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83549 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9586 (secdb.nttzen.cloud/cve/detail/)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: sangomakb.atlassian.net/wiki/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-09-02T18:00:55.000Z ##

CVE ID: CVE-2026-59822
Vendor: BerriAI
Product: LiteLLM
Date Added: 2026-09-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-09-02T19:01:22.000Z ##

Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.

- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-02T19:00:11.000Z ##

🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48710 (secdb.nttzen.cloud/cve/detail/)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/Kludex/starlette/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-49869 (secdb.nttzen.cloud/cve/detail/)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/kestra-io/kestra/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-59822 (secdb.nttzen.cloud/cve/detail/)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: github.com/BerriAI/litellm/sec ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82329 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83548 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83549 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9586 (secdb.nttzen.cloud/cve/detail/)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: sangomakb.atlassian.net/wiki/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260902 #cisa20260902 #cve_2026_48710 #cve_2026_49869 #cve_2026_59822 #cve_2026_82329 #cve_2026_83548 #cve_2026_83549 #cve_2026_9586 #cve202648710 #cve202649869 #cve202659822 #cve202682329 #cve202683548 #cve202683549 #cve20269586

##

cisakevtracker@mastodon.social at 2026-09-02T18:00:55.000Z ##

CVE ID: CVE-2026-59822
Vendor: BerriAI
Product: LiteLLM
Date Added: 2026-09-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-46595
(10.0 CRITICAL)

EPSS: 0.50%

updated 2026-07-17T15:32:15

1 posts

Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.

thehackerwire@mastodon.social at 2026-08-31T02:00:42.000Z ##

🟠 CVE-2026-56854 - High (7.5)

The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the Passwor...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-50661
(6.1 MEDIUM)

EPSS: 0.48%

updated 2026-07-14T18:32:36

1 posts

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

security_crawler_carl@infosec.exchange at 2026-08-31T12:00:41.000Z ##

Elsewhere, CVE-2026-50661 lets physical-access attackers bypass BitLocker encryption, and Scattered Spider defendants pleaded guilty on day one of trial.

Per protocol: rotate every exposed AWS GovCloud credential and CISA internal password immediately, enforce MFA, and audit AWS Workspace access logs for unauthorized activity.

Reward: You've unlocked the Plaintext Pantry — a decorative chest containing your own credentials, already sorted alphabetically for the attacker's convenience. (2/2)

##

CVE-2025-21913
(5.5 MEDIUM)

EPSS: 0.20%

updated 2026-07-14T15:32:25

2 posts

In the Linux kernel, the following vulnerability has been resolved: x86/amd_nb: Use rdmsr_safe() in amd_get_mmconfig_range() Xen doesn't offer MSR_FAM10H_MMIO_CONF_BASE to all guests. This results in the following warning: unchecked MSR access error: RDMSR from 0xc0010058 at rIP: 0xffffffff8101d19f (xen_do_read_msr+0x7f/0xa0) Call Trace: xen_read_msr+0x1e/0x30 amd_get_mmconfig_range+

andersonc0d3 at 2026-09-02T17:44:44.713Z ##

RE: infosec.exchange/@andersonc0d3

The exception table mechanism in the page fault handler is popular, but maybe the mechanism in the general protection handler isn't so well-known.

When the code is interacting with MSRs, if the MSR index/address is invalid for the architecture, it triggers a and the kernel oopses. This can happen in some scenarios and most of the cases it shouldn't trigger an oops and crash the kernel. That's why there are two MSR access implementations: rdmsr() / rdmsrq() and rdmsr_safe() / rdmsrq_safe(). The rdmsr variants use split 32-bit values for high/low bits, while rdmsrq handles 64-bit quadwords directly.

There is a proposal to retire legacy 32-bit user-space MSR interfaces, but I haven't followed this closely.

Linux Preparing To Retire Its 32-bit MSR Interfaces
phoronix.com/news/Linux-Ending

The safe ones are supposed to not crash/oops the kernel when the is issued. It implements the same exception table mechanism present in the page fault handler. That's why it contains *_safe() in the function name.

This is checked by the general protection fault handler via fixup_exception() at line below:

github.com/torvalds/linux/blob

There was an oops caused by the use of rdmsrl() when running the Linux kernel as a Xen guest and the fix was to replace rdmsrl() with rdmsrl_safe().

CVE-2025-21913: x86/amd_nb: Use rdmsr_safe() in amd_get_mmconfig_range()
lore.kernel.org/linux-cve-anno

x86/amd_nb: Use rdmsr_safe() in amd_get_mmconfig_range()
git.kernel.org/pub/scm/linux/k

The interface was rdmsrl before being renamed to rdmsrq.

In the case of virtualization, things get more complicated because the hypervisor might have different configurations. That issue in the Linux kernel seems to have been exposed due to a change in Xen regarding MSRs accesses.

xen/pv: support selecting safe/unsafe msr accesses git.kernel.org/pub/scm/linux/k

##

andersonc0d3@infosec.exchange at 2026-09-02T17:44:44.000Z ##

RE: infosec.exchange/@andersonc0d3

The exception table mechanism in the page fault handler is popular, but maybe the mechanism in the general protection handler isn't so well-known.

When the code is interacting with MSRs, if the MSR index/address is invalid for the architecture, it triggers a #GP and the kernel oopses. This can happen in some scenarios and most of the cases it shouldn't trigger an oops and crash the kernel. That's why there are two MSR access implementations: rdmsr() / rdmsrq() and rdmsr_safe() / rdmsrq_safe(). The rdmsr variants use split 32-bit values for high/low bits, while rdmsrq handles 64-bit quadwords directly.

There is a proposal to retire legacy 32-bit user-space MSR interfaces, but I haven't followed this closely.

Linux Preparing To Retire Its 32-bit MSR Interfaces
phoronix.com/news/Linux-Ending

The safe ones are supposed to not crash/oops the kernel when the #GP is issued. It implements the same exception table mechanism present in the page fault handler. That's why it contains *_safe() in the function name.

This is checked by the general protection fault handler via fixup_exception() at line below:

github.com/torvalds/linux/blob

There was an oops caused by the use of rdmsrl() when running the Linux kernel as a Xen guest and the fix was to replace rdmsrl() with rdmsrl_safe().

CVE-2025-21913: x86/amd_nb: Use rdmsr_safe() in amd_get_mmconfig_range()
lore.kernel.org/linux-cve-anno

x86/amd_nb: Use rdmsr_safe() in amd_get_mmconfig_range()
git.kernel.org/pub/scm/linux/k

The interface was rdmsrl before being renamed to rdmsrq.

In the case of virtualization, things get more complicated because the hypervisor might have different configurations. That issue in the Linux kernel seems to have been exposed due to a change in Xen regarding MSRs accesses.

xen/pv: support selecting safe/unsafe msr accesses git.kernel.org/pub/scm/linux/k

##

CVE-2026-6875(CVSS UNKNOWN)

EPSS: 77.58%

updated 2026-07-13T21:31:30

2 posts

ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates have also been provided to ServiceN

3 repos

https://github.com/tc4dy/CVE-2026-6875-PoC-Exploit

https://github.com/Hunt-Benito/the-sanitizer-is-the-weapon-cve-2026-68749-cve-2026-68750-quadratic-dos-in-elixir-html-sanitize-ex

https://github.com/HORKimhab/CVE-2026-6875

cR0w at 2026-09-01T19:20:04.523Z ##

RE: infosec.exchange/@cR0w/1171693

Update:

Update - September 1st, 2026

Due to additional analysis provided by the security researcher who discovered CVE-2026-6875, we have upgraded the severity rating of CVE-2026-6876 from High to Critical. This change affects only the severity rating for CVE-2026-6876; it does not change the other information shared in our August 27th advisory. Based on our monitoring to date, we have not observed evidence of malicious exploitation of this issue.

##

cR0w@infosec.exchange at 2026-09-01T19:20:04.000Z ##

RE: infosec.exchange/@cR0w/1171693

Update:

Update - September 1st, 2026

Due to additional analysis provided by the security researcher who discovered CVE-2026-6875, we have upgraded the severity rating of CVE-2026-6876 from High to Critical. This change affects only the severity rating for CVE-2026-6876; it does not change the other information shared in our August 27th advisory. Based on our monitoring to date, we have not observed evidence of malicious exploitation of this issue.

##

CVE-2026-52831
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-07-08T20:24:21

2 posts

## Summary Nuclio controller builds a `curl` invocation string for each cron trigger and stores it as the `args` of a Kubernetes CronJob container (`/bin/sh`, `-c`, `<command>`). Two fields in the trigger specification flow into this string without adequate sanitization: - `event.headers` keys — interpolated verbatim inside double-quoted `--header` arguments (`lazy.go:2150`); any key containing

thehackerwire@mastodon.social at 2026-09-02T18:00:10.000Z ##

🟠 CVE-2026-52831 - High (8)

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio controller builds a curl invocation string for each cron trigger and stores it as the args of a Kubernetes CronJob container (/bin/sh,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-02T18:00:10.000Z ##

🟠 CVE-2026-52831 - High (8)

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio controller builds a curl invocation string for each cron trigger and stores it as the args of a Kubernetes CronJob container (/bin/sh,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52933
(7.8 HIGH)

EPSS: 0.12%

updated 2026-07-08T15:31:45

1 posts

In the Linux kernel, the following vulnerability has been resolved: io_uring/poll: fix signed comparison in io_poll_get_ownership() io_poll_get_ownership() uses a signed comparison to check whether poll_refs has reached the threshold for the slowpath: if (unlikely(atomic_read(&req->poll_refs) >= IO_POLL_REF_BIAS)) atomic_read() returns int (signed). When IO_POLL_CANCEL_FLAG (BIT(31)) is se

DailyCyberSecurity@infosec.exchange at 2026-08-31T12:50:07.000Z ##

A public proof-of-concept for the CVE-2026-52933 privilege escalation flaw is available. This Linux kernel io_uring exploit carries a CVSS 7.8 score.

#Linux #CVE202652933 #PrivilegeEscalation #KernelExploit #Cybersecurity

securityonline.info/cve-2026-5

##

CVE-2025-31277
(8.8 HIGH)

EPSS: 1.48%

updated 2026-06-30T03:35:21

1 posts

The issue was addressed with improved memory handling. This issue is fixed in watchOS 11.6, visionOS 2.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6. Processing maliciously crafted web content may lead to memory corruption.

1 repos

https://github.com/stationedK-06/DarkSword_analysis

hacksgr@mastodon.social at 2026-09-01T16:49:45.000Z ##

13 malicious Composer themes on Packagist are being used on Vietnamese streaming sites. Installed on OphimCMS or KKPhim, they inject JavaScript and a hidden iframe: mobile visitors may be redirected to ad-fraud and gambling pages, while vulnerable iPhones can be targeted through Safari with an exploit chain reaching the kernel.

The campaign exploits CVE-2025-31277 and CVE-2025-43529, patched in iOS 18.6, 18.7.3…

en.hacks.gr/13-kakovoyla-paket

#iOS #MobileSecurity #SupplyChainSecurity #CyberSecurity

##

CVE-2026-8024
(9.8 CRITICAL)

EPSS: 0.55%

updated 2026-06-18T15:32:09

2 posts

A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems.

certvde at 2026-09-02T09:56:27.281Z ##

🔄 CSAF advisory updated (version 2.0.0)

VDE-2026-051
iba: Deserialization vulnerability in ibaPDA and ibaDatCoordinator
CVE-2026-8024

Changes: Added ibaLogic to the affected products and the mitigation for this product.

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: iba.csaf-tp.certvde.com/.well-

##

certvde@infosec.exchange at 2026-09-02T09:56:27.000Z ##

🔄 CSAF advisory updated (version 2.0.0)

VDE-2026-051
iba: Deserialization vulnerability in ibaPDA and ibaDatCoordinator
CVE-2026-8024

Changes: Added ibaLogic to the affected products and the mitigation for this product.

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: iba.csaf-tp.certvde.com/.well-

#OT #Advisory

##

CVE-2025-9709
(0 None)

EPSS: 0.23%

updated 2026-06-17T10:09:34.830000

2 posts

On-Chip Debug and Test Interface With Improper Access Control and Improper Protection against Electromagnetic Fault Injection (EM-FI) in Nordic Semiconductor nRF52810 allow attacker to perform EM Fault Injection and bypass APPROTECT at runtime, requiring the least amount of modification to the hardware system possible.

wicca at 2026-09-01T14:44:39.070Z ##

First pulse, first success. ⚡

@g0mb4ck (Milena) shows a triggerless EM fault injection attack on Nordic Semi's nRF52810 SoC (CVE-2025-9709) - the first of its kind ever reported and remarkably reproducible.

👉 Program & tickets: wiccon.nl/

##

wicca@infosec.exchange at 2026-09-01T14:44:39.000Z ##

First pulse, first success. ⚡

@g0mb4ck (Milena) shows a triggerless EM fault injection attack on Nordic Semi's nRF52810 SoC (CVE-2025-9709) - the first of its kind ever reported and remarkably reproducible.

👉 Program & tickets: wiccon.nl/

##

CVE-2026-35029(CVSS UNKNOWN)

EPSS: 25.07%

updated 2026-05-06T18:40:48

2 posts

### Impact The `/config/update endpoint` does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to do the following: - Modify proxy configuration and environment variables - Register custom pass-through endpoint handlers pointing to attacker-controlled Python code, achieving remote code execution - Read arbitrary server f

Nuclei template

1 repos

https://github.com/learner202649/CVE-2026-35029-PoC

CVE-2026-0768
(9.8 CRITICAL)

EPSS: 2.26%

updated 2026-01-23T06:31:32

11 posts

Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the code parameter provided to the validate endpoint. The issue results from the lack of proper validation of a use

2 repos

https://github.com/rmhowe425/POC-CVE-2026-0768

https://github.com/HORKimhab/CVE-2026-0768

tierrasapiens@mastodon.social at 2026-09-02T09:21:12.000Z ##

🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
⚫ Critical Langflow Flaw Exploited as Attacks on AI Platform Rise
🔗 darkreading.com/vulnerabilitie

The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year.

##

beyondmachines1 at 2026-09-02T09:01:31.851Z ##

Hackers Exploit Zero-Day in Langflow AI Platform to Steal Credentials

Langflow's AI platform is under active attack via a zero-day vulnerability (CVE-2026-0768) that allows unauthenticated remote code execution as root. Attackers are using the flaw to steal environment variables, secret keys, and SSH credentials from vulnerable instances.

**If you use Langflow, this is important and urgent. Make sure the server is isolated from the internet and reachable only from trusted internal networks or via VPN. There is no patch for this flaw and attackers are already exploiting it to steal secrets. Treat any internet-exposed instance as potentially compromised and rotate every API key, token and password stored in or used by it.**

beyondmachines.net/event_detai

##

oversecurity@mastodon.social at 2026-09-01T18:50:41.000Z ##

Critical Langflow flaw exploited to steal OpenAI and AWS keys

Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for...

🔗️ [Bleepingcomputer] link.is.it/mc2J3U

##

cyberworldops at 2026-09-01T18:20:00.824Z ##

Actively exploited unauthenticated RCE in Langflow (CVE-2026-0768) allows remote code execution via the custom component validator. It enables extraction of OpenAI and AWS keys and root credentials, exposing AI infrastructure to full takeover. Patch and rotate all secrets immediately.

cyberworldops.eu/en/langflow-u

##

Byte0x90@mastodon.social at 2026-09-01T18:02:04.000Z ##

Cyberkriminelle nutzen aktiv eine ungepatchte RCE-Schwachstelle (CVE-2026-0768) im KI-Framework Langflow aus. Über den kritischen Fehler erlangen Angreifer unautorisierten Zugriff auf Systeme, um sensible API-Schlüssel, Tokens und Anmeldedaten von Plattformen wie OpenAI oder AWS abzugreifen. Anwender sollten die Software umgehend absichern.

#Langflow #AI #CyberSecurity #InfoSec #ITSecurity #TechNews

##

Analyst207@mastodon.social at 2026-09-01T17:59:11.000Z ##

Langflow vulnerability exploited to harvest OpenAI, AWS keys

Attackers are actively exploiting a critical vulnerability in Langflow to harvest sensitive keys, including OpenAI and AWS credentials, by querying environment variables and reading secret files. This severe flaw, known as CVE-2026-0768, allows hackers to execute arbitrary Python code with root privileges, putting systems at risk.

osintsights.com/langflow-vulne

#Langflow #Cve20260768 #Openai #Aws #RemoteCodeExecution

##

netsecio@mastodon.social at 2026-09-01T17:58:53.000Z ##

📰 Critical RCE Flaw in Langflow AI Platform Actively Exploited

Critical RCE flaw (CVE-2026-0768, 9.8 CVSS) in the Langflow AI platform is actively exploited. Unauthenticated attackers can get root access to steal credentials. Patch to version 1.4.3+ now! #Langflow #AI #CyberSecurity #RCE #CVE

🔗 cyber.netsecops.io/articles/cr

##

beyondmachines1@infosec.exchange at 2026-09-02T09:01:31.000Z ##

Hackers Exploit Zero-Day in Langflow AI Platform to Steal Credentials

Langflow's AI platform is under active attack via a zero-day vulnerability (CVE-2026-0768) that allows unauthenticated remote code execution as root. Attackers are using the flaw to steal environment variables, secret keys, and SSH credentials from vulnerable instances.

**If you use Langflow, this is important and urgent. Make sure the server is isolated from the internet and reachable only from trusted internal networks or via VPN. There is no patch for this flaw and attackers are already exploiting it to steal secrets. Treat any internet-exposed instance as potentially compromised and rotate every API key, token and password stored in or used by it.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

oversecurity@mastodon.social at 2026-09-01T18:50:41.000Z ##

Critical Langflow flaw exploited to steal OpenAI and AWS keys

Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for...

🔗️ [Bleepingcomputer] link.is.it/mc2J3U

##

cyberworldops@infosec.exchange at 2026-09-01T18:20:00.000Z ##

Actively exploited unauthenticated RCE in Langflow (CVE-2026-0768) allows remote code execution via the custom component validator. It enables extraction of OpenAI and AWS keys and root credentials, exposing AI infrastructure to full takeover. Patch and rotate all secrets immediately. #Langflow #CVE20260768 #InfoSec

cyberworldops.eu/en/langflow-u

##

Byte0x90@mastodon.social at 2026-09-01T18:02:04.000Z ##

Cyberkriminelle nutzen aktiv eine ungepatchte RCE-Schwachstelle (CVE-2026-0768) im KI-Framework Langflow aus. Über den kritischen Fehler erlangen Angreifer unautorisierten Zugriff auf Systeme, um sensible API-Schlüssel, Tokens und Anmeldedaten von Plattformen wie OpenAI oder AWS abzugreifen. Anwender sollten die Software umgehend absichern.

#Langflow #AI #CyberSecurity #InfoSec #ITSecurity #TechNews

##

CVE-2025-43529
(8.8 HIGH)

EPSS: 8.89%

updated 2025-12-17T21:31:01

1 posts

A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 26.2, Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, tvOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated at

8 repos

https://github.com/SimoesCTT/Convergent-Time-Theory-Enhanced-iOS-Safari-RCE-CVE-2025-43529-

https://github.com/0xjohnnydev/WebKit-UAF-ANGLE-OOB-Analysis

https://github.com/jir4vv1t/CVE-2025-43529

https://github.com/SimoesCTT/CTT-Apple-Silicon-Refraction

https://github.com/stationedK-06/DarkSword_analysis

https://github.com/kmeps4/bugtest

https://github.com/GenericCoding/pois0nSword

https://github.com/bjrjk/CVE-2025-43529

hacksgr@mastodon.social at 2026-09-01T16:49:45.000Z ##

13 malicious Composer themes on Packagist are being used on Vietnamese streaming sites. Installed on OphimCMS or KKPhim, they inject JavaScript and a hidden iframe: mobile visitors may be redirected to ad-fraud and gambling pages, while vulnerable iPhones can be targeted through Safari with an exploit chain reaching the kernel.

The campaign exploits CVE-2025-31277 and CVE-2025-43529, patched in iOS 18.6, 18.7.3…

en.hacks.gr/13-kakovoyla-paket

#iOS #MobileSecurity #SupplyChainSecurity #CyberSecurity

##

CVE-2021-42260
(7.5 HIGH)

EPSS: 3.35%

updated 2025-11-04T21:31:31

2 posts

TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case. It can be triggered by a crafted XML message and leads to a denial of service.

1 repos

https://github.com/vm2mv/tinyxml

cyberworldops at 2026-09-02T04:10:01.028Z ##

CISA reports CVE-2021-42260, a DoS vulnerability in Rockwell Automation ControlLogix, CompactLogix and GuardLogix controllers. The CWE-835 infinite loop is triggered by crafted data and results in a Major Non-Recoverable Fault requiring manual recovery, posing high availability risk for OT environments.

cyberworldops.eu/en/rockwell-a

##

cyberworldops@infosec.exchange at 2026-09-02T04:10:01.000Z ##

CISA reports CVE-2021-42260, a DoS vulnerability in Rockwell Automation ControlLogix, CompactLogix and GuardLogix controllers. The CWE-835 infinite loop is triggered by crafted data and results in a Major Non-Recoverable Fault requiring manual recovery, posing high availability risk for OT environments. #RockwellAutomation #ControlLogix #IcsSecurity

cyberworldops.eu/en/rockwell-a

##

CVE-2022-38181
(8.8 HIGH)

EPSS: 13.56%

updated 2025-10-22T00:32:38

1 posts

An Arm product family through 2022-08-12 mail GPU kernel driver allows non-privileged users to make improper GPU processing operations to gain access to already freed memory.

7 repos

https://github.com/R0rt1z2/CVE-2022-38181

https://github.com/Pro-me3us/CVE_2022_38181_Gazelle

https://github.com/soralis0912/CVE-2022-38181-aristotle

https://github.com/Pro-me3us/CVE_2022_38181_Raven

https://github.com/hackintoanetwork/SCRoot

https://github.com/ericpardee/fire-hd-ownership

https://github.com/Bariskizilkaya/CVE_2022_38181-Mali-SAMSUNG-S6-Lite-Tablet

tobru@mstdn.social at 2026-08-30T16:07:14.000Z ##

Amazon kept shutting down my tablet, so I spent $266 on four AI models to own it

"Owning a tablet Amazon kept shutting down: CVE-2022-38181, four AI models, five months"

Link: ericpardee.github.io/fire-hd-o

#linkdump #ai #llm #security #story

##

CVE-2021-31886
(9.8 CRITICAL)

EPSS: 3.05%

updated 2023-01-30T05:05:55

3 posts

A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions), APOGEE PXC Compact (P2 Ethernet) (All versions), APOGEE PXC Modular (BACnet) (All versions), APOGEE PXC Modular (P2 Ethernet) (All versions

Analyst207@mastodon.social at 2026-09-02T08:29:24.000Z ##

AI-Powered Exploit Porting Threatens Industrial Control Systems

A recent exploit development stage for targeting Industrial Control Systems racked up a hefty $535.74 API usage bill over just 8 hours and 32 minutes, highlighting the costly and disturbing potential of AI-powered threat tactics. This unsettling advancement centers around CVE-2021-31886, a severe vulnerability in…

osintsights.com/ai-powered-exp

#IndustrialControlSystems #AipoweredThreats #ExploitDevelopment #Cve202131886 #NucleusFtp

##

cyberworldops at 2026-09-02T08:20:01.052Z ##

Forescout Research demonstrated porting a pre-auth RCE exploit for CVE-2021-31886 to a different WAGO PLC model using Anthropic Claude, achieving unauthenticated ARM shellcode execution on physical hardware. It shows how LLMs can accelerate exploit adaptation across OT variants, expanding exposure for unpatched systems.

cyberworldops.eu/en/claude-ada

##

cyberworldops@infosec.exchange at 2026-09-02T08:20:01.000Z ##

Forescout Research demonstrated porting a pre-auth RCE exploit for CVE-2021-31886 to a different WAGO PLC model using Anthropic Claude, achieving unauthenticated ARM shellcode execution on physical hardware. It shows how LLMs can accelerate exploit adaptation across OT variants, expanding exposure for unpatched systems. #Cve202131886 #OtSecurity #PlcSecurity

cyberworldops.eu/en/claude-ada

##

andersonc0d3 at 2026-09-01T21:09:07.145Z ##

I discuss Linux kernel exception handling in my training—specifically the mechanism that allows the kernel to trigger page faults at specific locations and handle them gracefully. This is why copy_from_user(), copy_to_user(), and other related functions don't cause a kernel oops when dealing with invalid addresses.

I abuse this mechanism in a vulnerability that leads to an arbitrary read to bypass KASLR during my Linux kernel exploitation training. I had played with it several times, but I had never read the official documentation until I came across it recently while looking for well-written material to send to the class. This mechanism has also been abused in other exploits, such as the one below.

Kernel level exception handling in Linux
kernel.org/doc/Documentation/x

Exploiting CVE-2017-5123
reverse.put.as/2017/11/07/expl

##

andersonc0d3@infosec.exchange at 2026-09-01T21:09:07.000Z ##

I discuss Linux kernel exception handling in my training—specifically the mechanism that allows the kernel to trigger page faults at specific locations and handle them gracefully. This is why copy_from_user(), copy_to_user(), and other related functions don't cause a kernel oops when dealing with invalid addresses.

I abuse this mechanism in a vulnerability that leads to an arbitrary read to bypass KASLR during my Linux kernel exploitation training. I had played with it several times, but I had never read the official documentation until I came across it recently while looking for well-written material to send to the class. This mechanism has also been abused in other exploits, such as the one below.

Kernel level exception handling in Linux
kernel.org/doc/Documentation/x

Exploiting CVE-2017-5123
reverse.put.as/2017/11/07/expl

##

CVE-2026-55221
(0 None)

EPSS: 0.00%

2 posts

N/A

offseq at 2026-09-02T21:03:29.013Z ##

CVE-2026-55221 | malach-it boruta-server (MEDIUM): Versions before 0.10.0 log OAuth/OpenID tokens in business event logs. Credentials at risk if logs are accessed. Patch to v0.10.0. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-02T21:03:29.000Z ##

CVE-2026-55221 | malach-it boruta-server (MEDIUM): Versions before 0.10.0 log OAuth/OpenID tokens in business event logs. Credentials at risk if logs are accessed. Patch to v0.10.0. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #OAuth #LogSecurity

##

CVE-2026-49869
(0 None)

EPSS: 0.99%

6 posts

N/A

1 repos

https://github.com/Ap0dexMe0/CVE-2026-49869

AAKL at 2026-09-02T19:01:22.277Z ##

Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.

- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

##

secdb at 2026-09-02T19:00:11.414Z ##

🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48710 (secdb.nttzen.cloud/cve/detail/)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/Kludex/starlette/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-49869 (secdb.nttzen.cloud/cve/detail/)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/kestra-io/kestra/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-59822 (secdb.nttzen.cloud/cve/detail/)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: github.com/BerriAI/litellm/sec ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82329 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83548 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83549 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9586 (secdb.nttzen.cloud/cve/detail/)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: sangomakb.atlassian.net/wiki/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-09-02T18:01:26.000Z ##

CVE ID: CVE-2026-49869
Vendor: Kestra
Product: Kestra OSS
Date Added: 2026-09-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-09-02T19:01:22.000Z ##

Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.

- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-02T19:00:11.000Z ##

🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48710 (secdb.nttzen.cloud/cve/detail/)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/Kludex/starlette/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-49869 (secdb.nttzen.cloud/cve/detail/)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/kestra-io/kestra/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-59822 (secdb.nttzen.cloud/cve/detail/)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: github.com/BerriAI/litellm/sec ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82329 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83548 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83549 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9586 (secdb.nttzen.cloud/cve/detail/)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: sangomakb.atlassian.net/wiki/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260902 #cisa20260902 #cve_2026_48710 #cve_2026_49869 #cve_2026_59822 #cve_2026_82329 #cve_2026_83548 #cve_2026_83549 #cve_2026_9586 #cve202648710 #cve202649869 #cve202659822 #cve202682329 #cve202683548 #cve202683549 #cve20269586

##

cisakevtracker@mastodon.social at 2026-09-02T18:01:26.000Z ##

CVE ID: CVE-2026-49869
Vendor: Kestra
Product: Kestra OSS
Date Added: 2026-09-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-82404
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-02T17:59:49.000Z ##

🟠 CVE-2026-82404 - High (8.3)

TOON is a compact, human-readable serialization of JSON data for LLM prompts. Prior to 2.3.1, decoding attacker-controlled TOON with a __proto__, constructor, or prototype key wrote through the object prototype chain instead of creating an own pro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-02T17:59:49.000Z ##

🟠 CVE-2026-82404 - High (8.3)

TOON is a compact, human-readable serialization of JSON data for LLM prompts. Prior to 2.3.1, decoding attacker-controlled TOON with a __proto__, constructor, or prototype key wrote through the object prototype chain instead of creating an own pro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84374
(0 None)

EPSS: 0.57%

3 posts

N/A

hugovalters@mastodon.social at 2026-09-02T11:01:45.000Z ##

CVE-2026-84374 - RCE vulnerability in Laravel Excel (3.1.8-3.1.70) due to unsafe path resolution in Disk::copy(). CVSS 7.5. Update immediately. #CVE #Laravel #infosec

valtersit.com/cve/CVE-2026-843

##

thehackerwire@mastodon.social at 2026-09-01T23:00:36.000Z ##

🟠 CVE-2026-84374 - High (7.5)

Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the Maatwebsite\Excel\Files\Disk::copy() method resolves the caller-controlled $destination supplied through Excel::store(), $...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-01T23:00:36.000Z ##

🟠 CVE-2026-84374 - High (7.5)

Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the Maatwebsite\Excel\Files\Disk::copy() method resolves the caller-controlled $destination supplied through Excel::store(), $...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-01T23:02:08.000Z ##

🔴 CVE-2026-75604 - Critical (9)

Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently escape backsl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-01T23:02:08.000Z ##

🔴 CVE-2026-75604 - Critical (9)

Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently escape backsl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

security_crawler_carl@infosec.exchange at 2026-08-31T05:57:09.000Z ##

🏆 New Achievement! Terms and Conditions of Your Own Destruction!

IMPORTANT: By running Next.js on a Windows server, you have agreed to receive one (1) randomized loot drop from our Critical Vulnerability Collection. This month's pull includes CVE-2026-75604, a CVSS 9.0 Windows path traversal enabling unauthenticated remote code execution — congrats, you hit the worst box in the crate. Linux and macOS users received the "nothing" tier, as advertised in the fine print nobody read. (1/2)

##

CVE-2026-84375
(0 None)

EPSS: 0.39%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-01T23:00:46.000Z ##

🟠 CVE-2026-84375 - High (7.5)

js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources while processing the merge key &lt;&lt;. An attacker can alias a l...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-01T23:00:46.000Z ##

🟠 CVE-2026-84375 - High (7.5)

js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources while processing the merge key &lt;&lt;. An attacker can alias a l...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84370
(0 None)

EPSS: 0.34%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-01T22:00:23.000Z ##

🟠 CVE-2026-84370 - High (8.2)

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin, named removeScriptElement in versions 2 and 3, i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-01T22:00:23.000Z ##

🟠 CVE-2026-84370 - High (8.2)

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin, named removeScriptElement in versions 2 and 3, i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Byte0x90@mastodon.social at 2026-09-01T11:52:50.000Z ##

Eine kritische Schwachstelle in Metabase (CVE-2026-72898) reißt ein massives Sicherheitsloch auf: Die ungeauth-fähige Lücke mit dem Höchstwert CVSS 10.0 erlaubt Angreifern den direkten Zugriff auf Anmeldedaten aller verknüpften Datenbanken. Prominente Unternehmen wie Framework, n8n und Checkly wurden bereits Opfer von Datenabflüssen. Betreiber müssen Instanzen sofort patchen und alle Credentials rotieren.

#Metabase #CyberSecurity #DataLeak #Infosec #Database #TechNews

##

secdb at 2026-09-01T07:54:00.828Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

##

Byte0x90@mastodon.social at 2026-09-01T11:52:50.000Z ##

Eine kritische Schwachstelle in Metabase (CVE-2026-72898) reißt ein massives Sicherheitsloch auf: Die ungeauth-fähige Lücke mit dem Höchstwert CVSS 10.0 erlaubt Angreifern den direkten Zugriff auf Anmeldedaten aller verknüpften Datenbanken. Prominente Unternehmen wie Framework, n8n und Checkly wurden bereits Opfer von Datenabflüssen. Betreiber müssen Instanzen sofort patchen und alle Credentials rotieren.

#Metabase #CyberSecurity #DataLeak #Infosec #Database #TechNews

##

secdb@infosec.exchange at 2026-09-01T07:54:00.000Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

secdb at 2026-09-01T07:54:00.828Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-01T07:54:00.000Z ##

📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482

Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396

Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-72898 - 82.32 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18577 - 54.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64638 - 31.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71362 - 25.14 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73570 - 20.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64849 - 16.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48376 - 13.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15733 - 13.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65400 - 9.90 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

secdb@infosec.exchange at 2026-08-31T00:01:12.000Z ##

📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461

Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194

CISA KEVs:
- CISA-2026:0825 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0824 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0826 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0827 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90

Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29

Top EPSS Score:
- CVE-2026-60004 - 84.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47864 - 3.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71921 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71914 - 3.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71905 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71906 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71907 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71908 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71909 - 3.05 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71910 - 3.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-79748
(0 None)

EPSS: 0.33%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-31T19:00:17.000Z ##

🔴 CVE-2026-79748 - Critical (9.9)

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.15, the POST /api/servers and PUT /api/servers/:name endpoints i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79746
(0 None)

EPSS: 0.25%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-31T19:00:05.000Z ##

🟠 CVE-2026-79746 - High (8.1)

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.31, when a bearer key with accessType: 'servers' (or 'custom') is...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73296
(0 None)

EPSS: 2.61%

1 posts

N/A

1 repos

https://github.com/0xBlackash/CVE-2026-73296

beyondmachines1@infosec.exchange at 2026-08-31T16:01:41.000Z ##

Microsoft UFO Vulnerability Allows Remote Android Device Takeover

Microsoft patched a critical vulnerability in its UFO automation framework (CVE-2026-73296) that allows unauthenticated attackers to remotely control Android devices and steal sensitive screen data. The flaw affects versions prior to 3.0.8 when configured for remote access.

**If you use Microsoft's UFO automation framework, update it to version 3.0.8 or later ASAP and turn on the required API key authentication. Older versions let anyone on the network fully control your connected Android devices. If you can't update immediately, change the setting back to `localhost` and block incoming traffic to ports 8020 and 8021 at your firewall.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

Elizafox@treehouse.systems at 2026-08-31T10:01:09.000Z ##

"Hacking the planet" incident post-mortem:

Initial access was obtained through an unpatched volcanic vent. Attackers achieved mantle persistence by exploiting a flaw in plate-tectonic privilege separation.

The core was still running a legacy geomagnetic service as root, which was exploited via a magmatic overflow.

The breach was detected when lateral movement was observed along several transform faults.

The Pacific Plate has been rotated out of production pending forensic analysis.

Earth confirms that no evidence of core exfiltration has been found.

The vulnerability has been assigned CVE-2026-31337: "Improper Boundary Validation in Terrestrial Lithosphere."

Mitigation involved removing the rootkit with sudo rm -rf /mantle/.rootkit, which caused approximately three minutes of elevated seismic activity.

Earth has reset all tectonic credentials and strongly recommends that other terrestrial planets rotate their cores immediately. Note this may result in a magnetic pole reversal as a side effect; consider this effect during any rotation, and plan accordingly.

##

CVE-2026-77846
(0 None)

EPSS: 0.14%

1 posts

N/A

oversecurity@mastodon.social at 2026-08-31T09:30:36.000Z ##

AshSqlite Vulnerability (CVE-2026-77846) Exposes Hidden JSON Fields

CVE-2026-77846, a newly disclosed AshSqlite vulnerability, can allow attackers to access hidden or sensitive fields stored inside JSON and map

🔗️ [Thecyberexpress] link.is.it/jyTNki

##

Visit counter For Websites