## Updated at UTC 2026-09-27T18:47:45.546402

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-88778 0 0.00% 6 0 2026-09-27T17:16:57.110000 Predictable exact value from previous values vulnerability in Citrix NetScaler A
CVE-2026-88777 0 0.00% 4 0 2026-09-27T17:16:56.990000 Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix N
CVE-2026-88776 0 0.00% 4 0 2026-09-27T17:16:56.870000 Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix N
CVE-2026-88775 0 0.00% 4 0 2026-09-27T17:16:56.750000 Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gatew
CVE-2026-88774 0 0.00% 4 0 2026-09-27T17:16:56.633000 Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue
CVE-2026-88773 0 0.00% 6 0 2026-09-27T17:16:56.507000 Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling')
CVE-2026-88772 0 0.00% 10 0 2026-09-27T17:16:56.390000 Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue
CVE-2026-88771 0 0.00% 14 0 2026-09-27T17:16:56.260000 Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetSc
CVE-2026-100865 8.8 0.45% 2 0 2026-09-27T17:16:55.700000 Heym before 0.0.53 evaluates workflow condition expressions using Python's eval(
CVE-2026-100841 7.8 0.12% 2 0 2026-09-27T17:16:55.463000 In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the
CVE-2026-100741 9.8 1.73% 2 0 2026-09-27T09:31:17 Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's
CVE-2026-96896 None 0.18% 2 0 2026-09-27T06:30:28 The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19
CVE-2026-81655 None 0.15% 2 0 2026-09-27T06:30:27 The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict acce
CVE-2026-100840 7.8 0.21% 2 0 2026-09-27T03:31:13 MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle
CVE-2026-100847 7.5 0.26% 2 0 2026-09-27T03:31:13 AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder
CVE-2026-100851 7.6 0.21% 2 0 2026-09-27T03:31:13 AzuraCast before 0.23.8 contains a broken access control vulnerability in the GE
CVE-2026-100857 8.0 0.34% 2 0 2026-09-27T03:31:13 AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWri
CVE-2026-100856 8.8 0.37% 2 0 2026-09-27T03:31:13 AzuraCast before 0.23.6 contains a code injection vulnerability in the remote re
CVE-2026-100864 8.8 0.69% 2 0 2026-09-27T03:31:13 heym before 0.0.91 contains a sandbox escape vulnerability in the expression eng
CVE-2026-100721 9.0 0.40% 2 0 2026-09-27T03:31:12 vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module
CVE-2026-100838 8.1 0.22% 2 0 2026-09-27T03:31:12 Contrast is a confidential-computing runtime for Kubernetes. In versions before
CVE-2026-100852 8.8 3.72% 2 0 2026-09-27T03:31:12 AzuraCast through 0.23.x contains a command injection vulnerability in the Liqui
CVE-2026-100740 9.9 0.45% 4 1 2026-09-27T03:31:12 A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the funct
CVE-2026-100845 7.8 0.14% 2 0 2026-09-27T03:31:05 MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the Numpy
CVE-2026-100850 7.7 0.22% 2 0 2026-09-27T02:17:24.007000 AzuraCast before 0.23.8 contains a server-side request forgery and local file re
CVE-2026-100846 7.6 0.27% 2 0 2026-09-27T02:17:23.283000 MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in
CVE-2026-100839 8.4 0.15% 2 0 2026-09-27T02:17:22.230000 Contrast is a confidential-computing runtime for Kubernetes. In versions before
CVE-2026-100835 7.4 0.22% 2 1 2026-09-27T02:17:21.640000 Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contr
CVE-2026-96533 5.8 0.19% 1 0 2026-09-26T23:16:41.497000 The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-
CVE-2026-77203 8.8 0.33% 1 0 2026-09-26T23:16:35.700000 The Groups – Memberships and Access Control plugin for WordPress is vulnerable t
CVE-2026-100709 7.5 0.29% 2 0 2026-09-26T23:16:32.930000 Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA tokens (p
CVE-2026-82901 9.8 1.11% 3 1 2026-09-26T21:30:34 The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitr
CVE-2026-85984 9.8 0.67% 3 0 2026-09-26T18:31:08 The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPres
CVE-2026-97163 None 0.42% 1 2 2026-09-26T15:31:32 Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP pl
CVE-2026-100720 8.7 0.21% 1 0 2026-09-26T15:31:32 Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When
CVE-2026-100705 7.6 0.20% 2 0 2026-09-26T15:31:28 Kyverno before 1.19.1 is vulnerable to server-side request forgery. The default
CVE-2026-100711 7.5 0.26% 2 0 2026-09-26T15:31:28 froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API k
CVE-2026-100717 9.9 0.30% 2 0 2026-09-26T15:31:28 froxlor is a server administration panel. In versions 2.3.10 and earlier, Valida
CVE-2026-100716 9.9 0.39% 2 0 2026-09-26T15:31:28 Froxlor is a server administration panel. In versions 2.3.10 and earlier, the cu
CVE-2026-100713 7.8 0.16% 1 0 2026-09-26T15:31:28 Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race con
CVE-2026-100672 7.5 0.45% 2 0 2026-09-26T15:31:27 The Comments plugin (getgrav/grav-plugin-comments) for Grav CMS through version
CVE-2026-100676 8.2 0.40% 2 0 2026-09-26T15:31:27 January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), befor
CVE-2026-100673 8.2 0.29% 2 0 2026-09-26T15:31:27 The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 th
CVE-2026-100685 7.7 0.21% 2 0 2026-09-26T15:31:27 Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint
CVE-2026-100683 8.0 0.21% 2 0 2026-09-26T15:31:27 Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename D
CVE-2026-100682 8.8 0.57% 2 0 2026-09-26T15:31:27 Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in
CVE-2026-100690 7.5 0.35% 2 0 2026-09-26T15:31:27 Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css
CVE-2026-100686 8.1 0.21% 2 0 2026-09-26T15:31:27 Budibase versions before 3.45.0 fail to validate per-app authorization in the PO
CVE-2026-100697 8.6 0.31% 2 0 2026-09-26T15:31:27 Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins
CVE-2026-100706 9.9 0.61% 2 0 2026-09-26T15:31:27 kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Po
CVE-2026-100703 7.7 0.23% 2 0 2026-09-26T15:31:27 Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib CEL library in its
CVE-2026-100714 9.1 0.55% 1 0 2026-09-26T15:31:27 Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchalleng
CVE-2026-100670 8.8 0.30% 2 0 2026-09-26T15:31:26 Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in
CVE-2026-100669 7.5 0.44% 2 0 2026-09-26T15:31:26 Grav before 2.0.25 ships web server configuration samples whose access-control d
CVE-2026-100700 7.5 0.28% 2 0 2026-09-26T15:31:24 nodemailer before 10.0.6 contains a denial of service vulnerability in the addre
CVE-2026-100661 7.5 0.34% 2 0 2026-09-26T15:31:23 Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4
CVE-2026-100692 7.5 0.44% 2 0 2026-09-26T15:31:23 Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0,
CVE-2026-100693 8.4 0.13% 2 0 2026-09-26T15:31:23 Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation
CVE-2026-100715 9.6 0.40% 1 0 2026-09-26T14:16:57.537000 Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink foll
CVE-2026-100707 7.7 0.46% 2 0 2026-09-26T14:16:55.983000 Kyverno before 1.19.1 contains a namespace isolation bypass in the apiCall conte
CVE-2026-100704 7.7 0.18% 2 0 2026-09-26T14:16:55.563000 Kyverno is a policy engine for Kubernetes. In versions 1.14.0 through 1.19.0, th
CVE-2026-100684 8.1 0.33% 2 0 2026-09-26T14:16:52.720000 Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the O
CVE-2026-100680 8.1 0.23% 2 0 2026-09-26T14:16:52.150000 Budibase versions before 3.45.0 fail to disable external JSON reference resoluti
CVE-2026-100679 8.8 0.32% 2 0 2026-09-26T14:16:51.993000 stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authent
CVE-2026-100671 8.0 0.29% 2 0 2026-09-26T14:16:50.860000 Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24 — and in 2.0.0 throug
CVE-2026-18143 9.8 0.41% 2 1 2026-09-26T09:30:26 The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitr
CVE-2026-91840 7.8 0.19% 1 0 2026-09-26T04:17:51.307000 A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unpri
CVE-2026-100596 8.8 0.25% 1 0 2026-09-26T03:30:36 OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users exe
CVE-2026-100560 7.5 0.58% 1 0 2026-09-26T03:30:35 OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability
CVE-2026-100568 8.3 0.25% 1 0 2026-09-26T03:30:35 OpenClaw versions before 2026.8.1 fail to properly restrict access to operator c
CVE-2026-100567 8.2 0.25% 1 0 2026-09-26T03:30:35 OpenClaw is an agent gateway distributed as the npm package 'openclaw'. In versi
CVE-2026-100580 8.8 0.34% 1 0 2026-09-26T03:30:35 OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensit
CVE-2026-100579 7.6 0.23% 1 0 2026-09-26T03:30:35 OpenClaw (npm package 'openclaw') before 2026.7.1 incorrectly trusts requester p
CVE-2026-100578 7.6 0.23% 1 0 2026-09-26T03:30:35 OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only i
CVE-2026-100585 8.0 0.19% 1 0 2026-09-26T03:30:35 OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-onl
CVE-2026-100582 6.5 0.21% 1 0 2026-09-26T03:30:35 OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix,
CVE-2026-100559 8.0 0.25% 1 0 2026-09-26T03:30:34 OpenClaw versions before 2026.8.1 contain a command parser vulnerability where e
CVE-2026-100557 8.3 0.24% 1 0 2026-09-26T03:30:34 OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability
CVE-2026-100589 8.3 0.32% 1 0 2026-09-26T03:30:29 OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the
CVE-2026-100532 8.1 0.27% 1 0 2026-09-26T03:30:28 @openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through
CVE-2026-100535 7.5 0.26% 1 0 2026-09-26T03:30:28 OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose t
CVE-2026-100588 8.3 0.30% 1 0 2026-09-26T03:30:28 OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administr
CVE-2026-100587 8.8 0.25% 1 0 2026-09-26T03:30:28 OpenClaw versions before 2026.7.1 fail to properly validate owner authorization
CVE-2026-100599 8.8 0.30% 1 0 2026-09-26T03:30:28 OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec ap
CVE-2026-100543 7.5 0.35% 1 0 2026-09-26T03:30:25 OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hash
CVE-2026-100552 8.8 0.26% 1 0 2026-09-26T03:30:25 OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per
CVE-2026-100551 8.3 0.17% 2 0 2026-09-26T03:30:25 OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gatew
CVE-2026-100520 8.8 0.94% 1 0 2026-09-26T03:30:23 Laranode versions before 1.2.1 contain a path traversal vulnerability in the POS
CVE-2026-100597 7.8 0.08% 1 0 2026-09-26T03:17:08.337000 OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-che
CVE-2026-100586 8.8 0.25% 1 0 2026-09-26T03:17:06.660000 OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization whe
CVE-2026-100575 8.8 0.26% 2 0 2026-09-26T03:17:05.030000 OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlis
CVE-2026-100570 7.8 0.13% 1 0 2026-09-26T03:17:04.177000 OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 allow an
CVE-2026-100561 8.0 0.25% 1 0 2026-09-26T03:17:02.987000 OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain a
CVE-2026-100558 7.5 0.28% 1 0 2026-09-26T03:17:02.533000 OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in
CVE-2026-100544 8.8 0.25% 1 0 2026-09-26T03:17:00.440000 openclaw's @openclaw/voice-call package before 2026.8.1 launches the configured
CVE-2026-100541 7.5 0.30% 1 0 2026-09-26T03:16:59.987000 OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.
CVE-2026-100382 None 0.95% 2 1 2026-09-26T00:32:22 Improper Neutralization of Special Elements used in an OS Command ('OS Command I
CVE-2026-96795 8.8 0.30% 1 0 2026-09-25T23:16:55.020000 Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data i
CVE-2026-57443 7.5 0.57% 1 0 2026-09-25T21:48:04 ### Summary The AetherBrowser API server (`scripts/aetherbrowser/api_server.py`
CVE-2026-100368 8.4 0.58% 1 0 2026-09-25T21:41:49 ### Impact An OS command injection vulnerability exists in the PowerShell and Cm
CVE-2026-100369 8.4 0.36% 1 0 2026-09-25T21:41:37 ### Impact An argument-injection vulnerability exists in the `CliInvoke` package
CVE-2026-100390 7.4 0.29% 1 0 2026-09-25T21:33:12 Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the
CVE-2026-10758 7.5 0.33% 1 0 2026-09-25T21:33:12 Esri LERC is an open-source image or raster format which supports rapid encoding
CVE-2026-100389 8.1 0.57% 2 0 2026-09-25T21:33:11 GestSup versions before 3.2.61 contain a remote code execution vulnerability in
CVE-2026-100391 8.2 0.31% 1 0 2026-09-25T21:33:11 MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerabili
CVE-2026-97063 9.1 0.29% 1 0 2026-09-25T21:33:06 X-SpringBoot through 6.0 returns login verification codes in HTTP responses from
CVE-2026-100208 7.5 0.35% 1 0 2026-09-25T21:33:06 Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorize
CVE-2026-5267 7.5 0.36% 1 0 2026-09-25T21:17:23.633000 Ciena Navigator Network Control Suite (NCS) contains an information exposure vul
CVE-2026-100387 8.1 0.32% 1 0 2026-09-25T21:17:22.163000 pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in d
CVE-2026-92161 9.8 0.27% 1 0 2026-09-25T20:31:30 ### Impact An unauthenticated account takeover vulnerability exists in `fof/oau
CVE-2026-97064 9.1 0.30% 1 0 2026-09-25T19:17:59.427000 X-SpringBoot through 6.0 ships with a hardcoded static master login verification
CVE-2026-67279 6.5 1.03% 5 3 2026-09-25T18:32:21 RouterOS SSH enters the connection protocol after a client-requested rekey even
CVE-2026-65660 6.5 2.10% 8 2 2026-09-25T18:32:20 Improper control of generation of code ('code injection') in Microsoft Office Sh
CVE-2026-91841 7.8 0.19% 1 0 2026-09-25T18:31:36 A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A loca
CVE-2026-91839 7.8 0.20% 1 0 2026-09-25T18:31:36 A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for Netwo
CVE-2026-91838 7.8 0.10% 1 0 2026-09-25T18:31:36 A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager.
CVE-2026-89032 7.7 0.27% 1 0 2026-09-25T18:31:35 BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerabi
CVE-2026-94445 8.8 0.36% 1 0 2026-09-25T18:31:35 A malicious txtar could escape the intended execution context and force arbitrar
CVE-2026-91837 7.8 0.14% 1 0 2026-09-25T17:17:18.983000 A flaw was found in NetworkManager-iodine, the iodine VPN plugin for NetworkMana
CVE-2026-92609 9.8 0.38% 1 0 2026-09-25T15:32:40 Session fixation in HTTP management authentication allows remote attackers to ga
CVE-2026-61825 8.7 0.22% 1 0 2026-09-25T15:00:45 ### Impact The vulnerability allows an attacker to bypass the HTML sanitizer by
CVE-2026-97818 8.6 0.32% 1 0 2026-09-25T14:17:26.837000 phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all"
CVE-2026-92573 6.5 0.29% 1 0 2026-09-25T14:17:22.150000 Improper handling of compressed data in the shared GZIP decompressor used for AM
CVE-2026-89426 8.8 0.47% 1 0 2026-09-25T14:17:21.750000 The Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more plugin for WordPre
CVE-2026-97433 8.2 0.32% 1 0 2026-09-25T13:17:26.930000 In the Linux kernel, the following vulnerability has been resolved: nvme: valid
CVE-2026-14281 9.8 0.53% 1 3 2026-09-25T13:08:26.930000 The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Co
CVE-2026-71362 9.1 87.51% 1 1 2026-09-25T12:53:15.757000 Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul
CVE-2026-92564 None 0.19% 1 0 2026-09-25T09:31:16 A pre-authentication attacker could leverage type nesting to cause a StackOverfl
CVE-2026-89406 7.5 0.39% 1 0 2026-09-25T09:31:16 The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vu
CVE-2026-93399 9.1 0.37% 2 2 2026-09-25T09:31:15 The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Referenc
CVE-2026-19804 8.8 1.04% 1 0 2026-09-25T09:31:15 The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywa
CVE-2026-92713 8.1 0.27% 1 0 2026-09-25T09:31:15 The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vu
CVE-2026-89055 9.1 0.39% 2 1 2026-09-25T09:31:14 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to autho
CVE-2026-62062 8.8 0.13% 2 1 2026-09-25T09:31:05 Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder all
CVE-2026-97428 7.7 0.14% 1 0 2026-09-25T06:31:36 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu:
CVE-2026-97444 7.7 0.14% 1 0 2026-09-25T06:31:36 In the Linux kernel, the following vulnerability has been resolved: ACPICA: add
CVE-2026-97450 8.4 0.14% 1 0 2026-09-25T06:31:35 In the Linux kernel, the following vulnerability has been resolved: ACPICA: val
CVE-2026-97448 7.7 0.14% 1 0 2026-09-25T06:31:35 In the Linux kernel, the following vulnerability has been resolved: ACPICA: Add
CVE-2026-97509 8.8 0.24% 1 0 2026-09-25T06:31:35 In the Linux kernel, the following vulnerability has been resolved: thunderbolt
CVE-2026-97508 7.5 0.21% 1 0 2026-09-25T06:31:35 In the Linux kernel, the following vulnerability has been resolved: thunderbolt
CVE-2026-97445 7.7 0.15% 1 0 2026-09-25T06:31:34 In the Linux kernel, the following vulnerability has been resolved: ACPICA: Enh
CVE-2026-97442 8.8 0.24% 1 0 2026-09-25T06:31:34 In the Linux kernel, the following vulnerability has been resolved: wifi: ath11
CVE-2026-97452 8.4 0.14% 1 0 2026-09-25T06:31:34 In the Linux kernel, the following vulnerability has been resolved: ACPICA: Pre
CVE-2026-97478 7.8 0.12% 1 0 2026-09-25T06:31:34 In the Linux kernel, the following vulnerability has been resolved: virt: acrn:
CVE-2026-97454 7.7 0.14% 1 0 2026-09-25T06:31:19 In the Linux kernel, the following vulnerability has been resolved: ACPICA: add
CVE-2026-97513 7.8 0.11% 1 0 2026-09-25T05:17:07.540000 In the Linux kernel, the following vulnerability has been resolved: media: chip
CVE-2026-97497 7.8 0.13% 1 0 2026-09-25T05:17:07.180000 In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd:
CVE-2026-97455 8.4 0.14% 1 0 2026-09-25T05:17:06.673000 In the Linux kernel, the following vulnerability has been resolved: ACPICA: Fix
CVE-2026-97451 8.4 0.14% 1 0 2026-09-25T05:17:06.323000 In the Linux kernel, the following vulnerability has been resolved: ACPICA: Fix
CVE-2026-89078 9.9 0.36% 1 0 2026-09-25T04:17:48.843000 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2
CVE-2026-48842 8.1 0.89% 3 2 2026-09-25T04:17:35.357000 Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authenticat
CVE-2026-81473 8.1 0.09% 1 0 2026-09-24T21:32:59 Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper
CVE-2026-89325 7.8 0.13% 1 0 2026-09-24T21:32:58 An uncontrolled search path element in InsightVM assessment content in Rapid7 In
CVE-2026-13248 8.8 0.44% 1 0 2026-09-24T21:32:57 An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec
CVE-2026-13249 9.8 0.57% 1 1 2026-09-24T21:32:57 An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability
CVE-2026-81455 8.6 0.26% 1 0 2026-09-24T21:32:57 Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Miss
CVE-2026-5430 10.0 0.59% 3 2 2026-09-24T21:32:26 The JWT authentication mechanism accepts tokens signed with algorithms other tha
CVE-2026-28324 9.8 0.65% 1 0 2026-09-24T21:00:46.893000 SolarWinds Observability Self-Hosted was found to be affected by an unauthentica
CVE-2026-61816 7.5 0.39% 1 0 2026-09-24T19:45:08 ### Impact An uncontrolled resource consumption / algorithmic complexity vulner
CVE-2026-61741 9.3 0.29% 1 0 2026-09-24T19:35:18 http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that pars
CVE-2026-75907 7.5 0.36% 1 0 2026-09-24T19:17:16.220000 The door access control on a Norwegian Cruise Line asset grants entry based only
CVE-2026-57440 7.5 0.26% 1 0 2026-09-24T19:17:14.630000 The EmbedVideo Extension is a MediaWiki extension which adds a parser function c
CVE-2026-95985 8.8 0.14% 1 0 2026-09-24T18:31:48 The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remot
CVE-2026-85057 8.7 0.39% 1 0 2026-09-24T18:19:34 ### Summary A vulnerability in ZITADEL Actions V1 allows an organization Action
CVE-2026-85056 8.2 0.29% 1 0 2026-09-24T18:19:04.180000 ZITADEL is an open source identity management platform. From 4.0.0 until 4.16.1,
CVE-2026-61782 7.5 0.36% 1 0 2026-09-24T18:17:16.333000 Rsdoctor is a build analyzer tailored for projects built with Rspack. Prior to v
CVE-2026-93577 9.9 0.43% 1 0 2026-09-24T00:30:34 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2
CVE-2026-94127 9.8 2.23% 2 2 2026-09-22T21:31:17 When a BIG-IP APM access policy and an OAuth profile is configured on a virtual
CVE-2026-93616 9.8 19.65% 1 1 2026-09-22T21:31:15 A directory traversal and file upload vulnerability allows an unauthenticated at
CVE-2026-85102 9.8 0.99% 1 0 2026-09-22T21:30:40 Improper certificate trust validation during VPN negotiation in Check Point Quan
CVE-2026-93854 0 0.41% 1 0 2026-09-22T19:56:19.073000 In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-leve
CVE-2026-93579 6.5 0.58% 1 0 2026-09-22T18:34:29 A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote att
CVE-2026-93871 5.4 0.27% 1 0 2026-09-18T21:32:44 Cotonti through 1.0.0 fails to validate redirect destinations in page bodies pre
CVE-2026-82890 5.9 0.32% 2 0 2026-09-18T21:32:36 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-11722 4.8 0.18% 1 0 2026-09-18T21:32:27 IBM WebSphere Application Server and WebSphere Application Server Liberty are af
CVE-2026-93432 6.1 0.42% 1 0 2026-09-18T20:17:32.267000 A flaw was found in the Quarkus Qute template engine. When the {#eval} section h
CVE-2026-93751 6.5 0.40% 1 0 2026-09-18T18:32:05 uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDec
CVE-2026-77608 6.1 0.26% 1 0 2026-09-18T16:42:52 #### Failure mode The `value` parameter was reflected back into rendered output
CVE-2025-39964 3.3 1.00% 2 2 2026-09-18T15:31:06 In the Linux kernel, the following vulnerability has been resolved: crypto: af_
CVE-2026-91843 9.8 0.52% 1 1 2026-09-16T15:31:14 A stack overflow during the unauthenticated login process may allow an attacker
CVE-2026-0310 0 0.37% 2 0 2026-09-11T04:17:13.060000 A buffer overflow vulnerability in the XML processing functionality of Palo Alto
CVE-2026-55074 None 0.44% 2 0 2026-08-13T15:58:54 Through version 1.3.0, the jailexec connection plugin's put_file resolved a tran
CVE-2026-63077 9.8 9.76% 1 6 2026-08-05T18:32:31 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe
CVE-2026-39808 9.8 47.36% 1 6 2026-07-16T18:32:24 A improper neutralization of special elements used in an os command ('os command
CVE-2026-44661 4.7 0.20% 1 0 2026-06-17T10:51:12.463000 python-utcp is the python implementation of UTCP. Prior to 1.1.3, the utcp-http
CVE-2026-0257 9.1 96.38% 1 8 template 2026-06-17T10:10:37.953000 Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of
CVE-2026-35273 9.8 9.44% 4 4 2026-06-12T18:31:50 Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleS
CVE-2026-32996 None 0.17% 1 1 2026-05-28T06:31:09 This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privile
CVE-2026-42608 None 0.52% 1 0 2026-05-13T13:52:36 # Vulnerability Report: Grav CMS Unauthenticated Path Traversal & Arbitrary File
CVE-2026-39813 9.8 0.72% 1 2 2026-04-14T18:30:41 A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 thro
CVE-2025-13032 9.9 0.25% 7 0 2025-11-11T18:30:23 Double fetch in sandbox kernel driver in Avast/AVG Antivirus <25.3  on windows a
CVE-2026-61722 0 0.20% 1 0 N/A
CVE-2026-85271 0 0.35% 1 0 N/A
CVE-2026-87902 0 18.17% 4 22 template N/A
CVE-2026-76654 0 0.00% 1 0 N/A
CVE-2026-2270 0 0.00% 1 0 N/A
CVE-2026-76902 0 0.27% 1 0 N/A
CVE-2026-57229 0 0.41% 1 0 N/A
CVE-2026-61720 0 0.18% 1 0 N/A
CVE-2026-91765 0 0.52% 1 0 N/A
CVE-2026-93676 0 0.14% 1 0 N/A
CVE-2026-87766 0 0.15% 1 0 N/A
CVE-2026-100000 0 0.00% 1 0 N/A
CVE-2026-63645 0 0.33% 1 0 N/A
CVE-2026-71540 0 0.35% 1 0 N/A
CVE-2026-77294 0 0.31% 1 0 N/A
CVE-2026-96749 0 0.13% 1 0 N/A

CVE-2026-88778
(0 None)

EPSS: 0.00%

updated 2026-09-27T17:16:57.110000

6 posts

Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23.

DarkWebInformer at 2026-09-27T17:25:15.269Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

pedro at 2026-09-27T16:22:43.765Z ##

@watchTowr Thanks for being on top of it 💪
community.citrix.com/techzone-

##

AAKL at 2026-09-27T15:50:36.241Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom

@mttaggart

##

DarkWebInformer@infosec.exchange at 2026-09-27T17:25:15.000Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

pedro@infosec.exchange at 2026-09-27T16:22:43.000Z ##

@watchTowr Thanks for being on top of it 💪
community.citrix.com/techzone-

##

AAKL@infosec.exchange at 2026-09-27T15:50:36.000Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom #infosec #Citrix #NetScaler #vulnerability

@mttaggart

##

CVE-2026-88777
(0 None)

EPSS: 0.00%

updated 2026-09-27T17:16:56.990000

4 posts

Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23  leading to unpredictable or erroneous behavior or Denial of Service

DarkWebInformer at 2026-09-27T17:25:15.269Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

AAKL at 2026-09-27T15:50:36.241Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom

@mttaggart

##

DarkWebInformer@infosec.exchange at 2026-09-27T17:25:15.000Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

AAKL@infosec.exchange at 2026-09-27T15:50:36.000Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom #infosec #Citrix #NetScaler #vulnerability

@mttaggart

##

CVE-2026-88776
(0 None)

EPSS: 0.00%

updated 2026-09-27T17:16:56.870000

4 posts

Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23  leading to unpredictable or erroneous behavior or Denial of Service

DarkWebInformer at 2026-09-27T17:25:15.269Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

AAKL at 2026-09-27T15:50:36.241Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom

@mttaggart

##

DarkWebInformer@infosec.exchange at 2026-09-27T17:25:15.000Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

AAKL@infosec.exchange at 2026-09-27T15:50:36.000Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom #infosec #Citrix #NetScaler #vulnerability

@mttaggart

##

CVE-2026-88775
(0 None)

EPSS: 0.00%

updated 2026-09-27T17:16:56.750000

4 posts

Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service

DarkWebInformer at 2026-09-27T17:25:15.269Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

AAKL at 2026-09-27T15:50:36.241Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom

@mttaggart

##

DarkWebInformer@infosec.exchange at 2026-09-27T17:25:15.000Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

AAKL@infosec.exchange at 2026-09-27T15:50:36.000Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom #infosec #Citrix #NetScaler #vulnerability

@mttaggart

##

CVE-2026-88774
(0 None)

EPSS: 0.00%

updated 2026-09-27T17:16:56.633000

4 posts

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage.

DarkWebInformer at 2026-09-27T17:25:15.269Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

AAKL at 2026-09-27T15:50:36.241Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom

@mttaggart

##

DarkWebInformer@infosec.exchange at 2026-09-27T17:25:15.000Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

AAKL@infosec.exchange at 2026-09-27T15:50:36.000Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom #infosec #Citrix #NetScaler #vulnerability

@mttaggart

##

CVE-2026-88773
(0 None)

EPSS: 0.00%

updated 2026-09-27T17:16:56.507000

6 posts

Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.

DarkWebInformer at 2026-09-27T17:25:15.269Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

AAKL at 2026-09-27T15:50:36.241Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom

@mttaggart

##

GossiTheDog@cyberplace.social at 2026-09-27T15:33:35.000Z ##

Netscaler CVEs are out:

support.citrix.com/support-hom

Patch isn’t yet through QA at Citrix still, been a week :02angery:

The primary vulns being exploited are CVE-2026-88771, CVE-2026-88772, CVE-2026-88773 chained.

It gives unauth RCE in default appliance config. Attackers using it to drop webshells all month of September.

Probably nation state aligned as well resourced, espionage rather than teens.

##

DarkWebInformer@infosec.exchange at 2026-09-27T17:25:15.000Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

AAKL@infosec.exchange at 2026-09-27T15:50:36.000Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom #infosec #Citrix #NetScaler #vulnerability

@mttaggart

##

GossiTheDog@cyberplace.social at 2026-09-27T15:33:35.000Z ##

Netscaler CVEs are out:

support.citrix.com/support-hom

Patch isn’t yet through QA at Citrix still, been a week :02angery:

The primary vulns being exploited are CVE-2026-88771, CVE-2026-88772, CVE-2026-88773 chained.

It gives unauth RCE in default appliance config. Attackers using it to drop webshells all month of September.

Probably nation state aligned as well resourced, espionage rather than teens.

##

CVE-2026-88772
(0 None)

EPSS: 0.00%

updated 2026-09-27T17:16:56.390000

10 posts

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

DarkWebInformer at 2026-09-27T17:25:15.269Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

DailyCyberSecurity at 2026-09-27T16:18:08.529Z ##

Two Citrix NetScaler zero-day RCE flaws are under active exploitation. Citrix confirmed CVE-2026-88771 and CVE-2026-88772 and shipped patches. Update now.

securityonline.info/citrix-net

##

ssvc at 2026-09-27T15:56:01.672Z ##

Citrix NetScaler zero-days

Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.

This is a Monday problem for me, but you're better off knowing what to expect when coming into work tomorrow. h/t @mttaggart

support.citrix.com/support-hom

##

AAKL at 2026-09-27T15:50:36.241Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom

@mttaggart

##

GossiTheDog@cyberplace.social at 2026-09-27T15:33:35.000Z ##

Netscaler CVEs are out:

support.citrix.com/support-hom

Patch isn’t yet through QA at Citrix still, been a week :02angery:

The primary vulns being exploited are CVE-2026-88771, CVE-2026-88772, CVE-2026-88773 chained.

It gives unauth RCE in default appliance config. Attackers using it to drop webshells all month of September.

Probably nation state aligned as well resourced, espionage rather than teens.

##

DarkWebInformer@infosec.exchange at 2026-09-27T17:25:15.000Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

DailyCyberSecurity@infosec.exchange at 2026-09-27T16:18:08.000Z ##

Two Citrix NetScaler zero-day RCE flaws are under active exploitation. Citrix confirmed CVE-2026-88771 and CVE-2026-88772 and shipped patches. Update now.

#Citrix #NetScaler #ZeroDay #RCE #CyberSecurity #VPN #watchTowr #PatchNow

securityonline.info/citrix-net

##

ssvc@infosec.exchange at 2026-09-27T15:56:01.000Z ##

Citrix NetScaler zero-days

Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.

This is a Monday problem for me, but you're better off knowing what to expect when coming into work tomorrow. h/t @mttaggart

support.citrix.com/support-hom

#citrix #netscaler #zeroday #cve

##

AAKL@infosec.exchange at 2026-09-27T15:50:36.000Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom #infosec #Citrix #NetScaler #vulnerability

@mttaggart

##

GossiTheDog@cyberplace.social at 2026-09-27T15:33:35.000Z ##

Netscaler CVEs are out:

support.citrix.com/support-hom

Patch isn’t yet through QA at Citrix still, been a week :02angery:

The primary vulns being exploited are CVE-2026-88771, CVE-2026-88772, CVE-2026-88773 chained.

It gives unauth RCE in default appliance config. Attackers using it to drop webshells all month of September.

Probably nation state aligned as well resourced, espionage rather than teens.

##

CVE-2026-88771
(0 None)

EPSS: 0.00%

updated 2026-09-27T17:16:56.260000

14 posts

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

jela@social.tchncs.de at 2026-09-27T17:31:47.000Z ##

Zusätzlich sehr nützliche Betriebs- und Incident-Response-Hinweise gibt es hier: cyberkendra.com/2026/09/cve-20

##

DarkWebInformer at 2026-09-27T17:25:15.269Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

pedro at 2026-09-27T16:22:43.765Z ##

@watchTowr Thanks for being on top of it 💪
community.citrix.com/techzone-

##

DailyCyberSecurity at 2026-09-27T16:18:08.529Z ##

Two Citrix NetScaler zero-day RCE flaws are under active exploitation. Citrix confirmed CVE-2026-88771 and CVE-2026-88772 and shipped patches. Update now.

securityonline.info/citrix-net

##

ssvc at 2026-09-27T15:56:01.672Z ##

Citrix NetScaler zero-days

Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.

This is a Monday problem for me, but you're better off knowing what to expect when coming into work tomorrow. h/t @mttaggart

support.citrix.com/support-hom

##

AAKL at 2026-09-27T15:50:36.241Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom

@mttaggart

##

GossiTheDog@cyberplace.social at 2026-09-27T15:33:35.000Z ##

Netscaler CVEs are out:

support.citrix.com/support-hom

Patch isn’t yet through QA at Citrix still, been a week :02angery:

The primary vulns being exploited are CVE-2026-88771, CVE-2026-88772, CVE-2026-88773 chained.

It gives unauth RCE in default appliance config. Attackers using it to drop webshells all month of September.

Probably nation state aligned as well resourced, espionage rather than teens.

##

jela@social.tchncs.de at 2026-09-27T17:31:47.000Z ##

Zusätzlich sehr nützliche Betriebs- und Incident-Response-Hinweise gibt es hier: cyberkendra.com/2026/09/cve-20

##

DarkWebInformer@infosec.exchange at 2026-09-27T17:25:15.000Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

pedro@infosec.exchange at 2026-09-27T16:22:43.000Z ##

@watchTowr Thanks for being on top of it 💪
community.citrix.com/techzone-

##

DailyCyberSecurity@infosec.exchange at 2026-09-27T16:18:08.000Z ##

Two Citrix NetScaler zero-day RCE flaws are under active exploitation. Citrix confirmed CVE-2026-88771 and CVE-2026-88772 and shipped patches. Update now.

#Citrix #NetScaler #ZeroDay #RCE #CyberSecurity #VPN #watchTowr #PatchNow

securityonline.info/citrix-net

##

ssvc@infosec.exchange at 2026-09-27T15:56:01.000Z ##

Citrix NetScaler zero-days

Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.

This is a Monday problem for me, but you're better off knowing what to expect when coming into work tomorrow. h/t @mttaggart

support.citrix.com/support-hom

#citrix #netscaler #zeroday #cve

##

AAKL@infosec.exchange at 2026-09-27T15:50:36.000Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom #infosec #Citrix #NetScaler #vulnerability

@mttaggart

##

GossiTheDog@cyberplace.social at 2026-09-27T15:33:35.000Z ##

Netscaler CVEs are out:

support.citrix.com/support-hom

Patch isn’t yet through QA at Citrix still, been a week :02angery:

The primary vulns being exploited are CVE-2026-88771, CVE-2026-88772, CVE-2026-88773 chained.

It gives unauth RCE in default appliance config. Attackers using it to drop webshells all month of September.

Probably nation state aligned as well resourced, espionage rather than teens.

##

CVE-2026-100865
(8.8 HIGH)

EPSS: 0.45%

updated 2026-09-27T17:16:55.700000

2 posts

Heym before 0.0.53 evaluates workflow condition expressions using Python's eval() with insufficient sandboxing in the workflow executor service. Authenticated users can edit workflow condition nodes or import malicious templates to execute arbitrary Python and OS commands as the backend process user.

thehackerwire@mastodon.social at 2026-09-27T02:31:42.000Z ##

🟠 CVE-2026-100865 - High (8.8)

Heym before 0.0.53 contains multiple independent vulnerabilities. (1) The workflow condition evaluator uses Python eval() without an effective sandbox, allowing any user who can edit a workflow branch/condition node — or who can import a workflo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T02:31:42.000Z ##

🟠 CVE-2026-100865 - High (8.8)

Heym before 0.0.53 contains multiple independent vulnerabilities. (1) The workflow condition evaluator uses Python eval() without an effective sandbox, allowing any user who can edit a workflow branch/condition node — or who can import a workflo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100841
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-27T17:16:55.463000

2 posts

In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weights_only=True, forcing users who cache MetaTensors (the default tensor type in MONAI >= 1.0) to run torch.load(hashfile, weights_only=False). Related cache helpers in monai/data/utils.py also call pickle.loads on cached content and derive cache keys with hashlib.md5. As a result, a

thehackerwire@mastodon.social at 2026-09-27T03:02:12.000Z ##

🟠 CVE-2026-100841 - High (7.8)

In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weights_only=True, forcing users who cache MetaTensors (the default tensor type in MONAI >= 1.0) to run torch.load(hashfile, weights_...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T03:02:12.000Z ##

🟠 CVE-2026-100841 - High (7.8)

In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weights_only=True, forcing users who cache MetaTensors (the default tensor type in MONAI >= 1.0) to run torch.load(hashfile, weights_...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100741
(9.8 CRITICAL)

EPSS: 1.73%

updated 2026-09-27T09:31:17

2 posts

Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3.3 on Windows, allows a remote, unauthenticated attacker to run arbitrary JScript inside the hMailServer service process, with the privileges of the service account, via a password containing a backslash followed by an apostrophe, sent in any logon (SMTP AUTH, POP3, IMAP) that na

offseq at 2026-09-27T09:00:26.014Z ##

CVE-2026-100741: CRITICAL eval injection in hMailServer (Windows, 6.0.0 – 6.3.3) enables remote code execution via JScript event scripting. Requires non-default config. Disable event scripting/JScript now. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-27T09:00:26.000Z ##

CVE-2026-100741: CRITICAL eval injection in hMailServer (Windows, 6.0.0 – 6.3.3) enables remote code execution via JScript event scripting. Requires non-default config. Disable event scripting/JScript now. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #CyberSec #CVE #hMailServer

##

CVE-2026-96896(CVSS UNKNOWN)

EPSS: 0.18%

updated 2026-09-27T06:30:28

2 posts

The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing users with a subsite administrator role on a multisite network to write and delete arbitrary files in the network's shared filesystem, which can lead to remote code execution.

offseq at 2026-09-27T07:30:23.913Z ##

CVE-2026-96896: Malcure Malware Shield <19.9.7 has a CRITICAL auth flaw. Subsite admins in WP multisite can write/delete arbitrary files, enabling RCE. Upgrade to 19.9.7+ now. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-27T07:30:23.000Z ##

CVE-2026-96896: Malcure Malware Shield <19.9.7 has a CRITICAL auth flaw. Subsite admins in WP multisite can write/delete arbitrary files, enabling RCE. Upgrade to 19.9.7+ now. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #RCE

##

CVE-2026-81655(CVSS UNKNOWN)

EPSS: 0.15%

updated 2026-09-27T06:30:27

2 posts

The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict access to one of its settings pages, making it reachable by every logged in user under a configuration its own settings allow, and does not filter the content saved there, allowing users with a role as low as subscriber to store code which is then executed as PHP or served unescaped to site visitors.

offseq at 2026-09-27T10:30:24.343Z ##

CVE-2026-81655: CRITICAL code injection in Ad Inserter WP plugin (2.8.12 – 2.8.18). Subscribers can execute PHP or unescaped content. Patch to 2.8.19+ ASAP. More: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-27T10:30:24.000Z ##

CVE-2026-81655: CRITICAL code injection in Ad Inserter WP plugin (2.8.12 – 2.8.18). Subscribers can execute PHP or unescaped content. Patch to 2.8.19+ ASAP. More: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #Vuln

##

CVE-2026-100840
(7.8 HIGH)

EPSS: 0.21%

updated 2026-09-27T03:31:13

2 posts

MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _target_ values to arbitrary importable callables without an allow list and passes $ expressions to Python eval(). Attackers can publish a malicious bundle with crafted configuration containing arbitrary code that executes when a victim loads the bundle using monai.bundle.load() or m

thehackerwire@mastodon.social at 2026-09-27T03:02:01.000Z ##

🟠 CVE-2026-100840 - High (7.8)

MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _target_ values to arbitrary importable callables without an allow list and passes $ expressions to Python eval(). Attackers can pu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T03:02:01.000Z ##

🟠 CVE-2026-100840 - High (7.8)

MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _target_ values to arbitrary importable callables without an allow list and passes $ expressions to Python eval(). Attackers can pu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100847
(7.5 HIGH)

EPSS: 0.26%

updated 2026-09-27T03:31:13

2 posts

AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder API parameter of AbstractSearchableListAction.php. Attackers can inject arbitrary DQL expressions through the sortOrder parameter to extract sensitive database information including user credentials and station settings.

thehackerwire@mastodon.social at 2026-09-27T02:47:10.000Z ##

🟠 CVE-2026-100847 - High (7.5)

AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder API parameter of AbstractSearchableListAction.php. Attackers can inject arbitrary DQL expressions through the sortOrder parameter to extract sensitive database informa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T02:47:10.000Z ##

🟠 CVE-2026-100847 - High (7.5)

AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder API parameter of AbstractSearchableListAction.php. Attackers can inject arbitrary DQL expressions through the sortOrder parameter to extract sensitive database informa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100851
(7.6 HIGH)

EPSS: 0.21%

updated 2026-09-27T03:31:13

2 posts

AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint that allows authenticated users with only View Station Page permission to read Icecast/Shoutcast admin, source, and relay passwords. Attackers with View-only access can call this endpoint and receive plaintext frontend credentials in the JSON response, then use the admin passwor

thehackerwire@mastodon.social at 2026-09-27T02:32:51.000Z ##

🟠 CVE-2026-100851 - High (7.6)

AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint that allows authenticated users with only View Station Page permission to read Icecast/Shoutcast admin, source, and relay pass...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T02:32:51.000Z ##

🟠 CVE-2026-100851 - High (7.6)

AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint that allows authenticated users with only View Station Page permission to read Icecast/Shoutcast admin, source, and relay pass...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100857
(8.0 HIGH)

EPSS: 0.34%

updated 2026-09-27T03:31:13

2 posts

AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media or Profile permissions to inject arbitrary Liquidsoap code into station configuration. Attackers can inject #{process.run()} expressions into playlist URLs or station metadata fields tha

thehackerwire@mastodon.social at 2026-09-27T02:32:33.000Z ##

🟠 CVE-2026-100857 - High (8)

AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media or Profile permissions to inject ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T02:32:33.000Z ##

🟠 CVE-2026-100857 - High (8)

AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media or Profile permissions to inject ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100856
(8.8 HIGH)

EPSS: 0.37%

updated 2026-09-27T03:31:13

2 posts

AzuraCast before 0.23.6 contains a code injection vulnerability in the remote relay password field due to incomplete migration from the vulnerable cleanUpString method to toRawString. Attackers with RemoteRelays station permission can inject nested Liquidsoap interpolation syntax to execute arbitrary code in the Liquidsoap process, disclose internal API keys, or disrupt station operation.

thehackerwire@mastodon.social at 2026-09-27T02:31:50.000Z ##

🟠 CVE-2026-100856 - High (8.8)

AzuraCast before 0.23.6 contains a code injection vulnerability in the remote relay password field due to incomplete migration from the vulnerable cleanUpString method to toRawString. Attackers with RemoteRelays station permission can inject neste...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T02:31:50.000Z ##

🟠 CVE-2026-100856 - High (8.8)

AzuraCast before 0.23.6 contains a code injection vulnerability in the remote relay password field due to incomplete migration from the vulnerable cleanUpString method to toRawString. Attackers with RemoteRelays station permission can inject neste...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100864
(8.8 HIGH)

EPSS: 0.69%

updated 2026-09-27T03:31:13

2 posts

heym before 0.0.91 contains a sandbox escape vulnerability in the expression engine's DotList map/filter and fallback resolver that allows authenticated users to execute arbitrary Python code. Attackers can craft workflow expressions using dunder attribute access through item expressions or the fallback resolver to access os.system and execute commands as the backend process.

thehackerwire@mastodon.social at 2026-09-27T02:31:33.000Z ##

🟠 CVE-2026-100864 - High (8.8)

heym before 0.0.91 contains a sandbox escape vulnerability in the expression engine's DotList map/filter and fallback resolver that allows authenticated users to execute arbitrary Python code. Attackers can craft workflow expressions using dunder ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T02:31:33.000Z ##

🟠 CVE-2026-100864 - High (8.8)

heym before 0.0.91 contains a sandbox escape vulnerability in the expression engine's DotList map/filter and fallback resolver that allows authenticated users to execute arbitrary Python code. Attackers can craft workflow expressions using dunder ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100721
(9.0 None)

EPSS: 0.40%

updated 2026-09-27T03:31:12

2 posts

vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with a custom resolver (and `context: 'host'`), `LegacyResolver.customResolve` in lib/resolver-compat.js records the resolved module directory in `this.externals` as `new RegExp('^' + escapeRegExp(resolvedPath))`, without requiring a path separator or end-of-str

offseq at 2026-09-27T06:00:23.538Z ##

CVE-2026-100721: CRITICAL auth bypass in vm2 <3.12.2's NodeVM external-module resolver. Sandbox escape & arbitrary code exec possible. Upgrade to 3.12.2+ ASAP. radar.offseq.com/threat/vm2-be

##

offseq@infosec.exchange at 2026-09-27T06:00:23.000Z ##

CVE-2026-100721: CRITICAL auth bypass in vm2 <3.12.2's NodeVM external-module resolver. Sandbox escape & arbitrary code exec possible. Upgrade to 3.12.2+ ASAP. radar.offseq.com/threat/vm2-be #OffSeq #CVE2026100721 #vm2 #infosec

##

CVE-2026-100838
(8.1 HIGH)

EPSS: 0.22%

updated 2026-09-27T03:31:12

2 posts

Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generated by the Contrast CLI contained a flaw in the CopyFile verification that allowed arbitrary writes to the guest root filesystem. A malicious process on the untrusted host able to connect to the Kata agent VSOCK could issue a series of CopyFile requests to overwrite security-critic

thehackerwire@mastodon.social at 2026-09-27T02:47:19.000Z ##

🟠 CVE-2026-100838 - High (8.1)

Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generated by the Contrast CLI contained a flaw in the CopyFile verification that allowed arbitrary writes to the guest root filesystem....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T02:47:19.000Z ##

🟠 CVE-2026-100838 - High (8.1)

Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generated by the Contrast CLI contained a flaw in the CopyFile verification that allowed arbitrary writes to the guest root filesystem....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100852
(8.8 HIGH)

EPSS: 3.72%

updated 2026-09-27T03:31:12

2 posts

AzuraCast through 0.23.x contains a command injection vulnerability in the Liquidsoap config generation for live recording that fails to quote the streamer username in process.run calls. Authenticated station users with Streamers and Profile permissions can set a username containing shell metacharacters and trigger command execution as the Liquidsoap process user when recording closes.

thehackerwire@mastodon.social at 2026-09-27T02:46:15.000Z ##

🟠 CVE-2026-100852 - High (8.8)

AzuraCast through 0.23.x contains a command injection vulnerability in the Liquidsoap config generation for live recording that fails to quote the streamer username in process.run calls. Authenticated station users with Streamers and Profile permi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T02:46:15.000Z ##

🟠 CVE-2026-100852 - High (8.8)

AzuraCast through 0.23.x contains a command injection vulnerability in the Liquidsoap config generation for live recording that fails to quote the streamer username in process.run calls. Authenticated station users with Streamers and Profile permi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100740
(9.9 CRITICAL)

EPSS: 0.45%

updated 2026-09-27T03:31:12

4 posts

A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack may be initiated remotely. The exploit is now public and may be used.

1 repos

https://github.com/murrez/CVE-2026-100740

thehackerwire@mastodon.social at 2026-09-27T01:32:18.000Z ##

🔴 CVE-2026-100740 - Critical (9.9)

A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack may be in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-27T01:30:24.040Z ##

D-Link DIR-895L hit by CRITICAL vuln: CVE-2026-100740 (CVSS 9.4) in tunnel_set_params — public exploit code enables remote RCE or DoS via out-of-bounds write. No patch yet. Monitor for updates: radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-27T01:32:18.000Z ##

🔴 CVE-2026-100740 - Critical (9.9)

A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack may be in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-27T01:30:24.000Z ##

D-Link DIR-895L hit by CRITICAL vuln: CVE-2026-100740 (CVSS 9.4) in tunnel_set_params — public exploit code enables remote RCE or DoS via out-of-bounds write. No patch yet. Monitor for updates: radar.offseq.com/threat/cve-20 #OffSeq #CVE2026100740 #infosec #RouterSecurity

##

CVE-2026-100845
(7.8 HIGH)

EPSS: 0.14%

updated 2026-09-27T03:31:05

2 posts

MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses numpy.load with allow_pickle=True when loading .npy and .npz files. Attackers can craft malicious .npy files with pickle payloads that execute arbitrary code when loaded through MONAI's standard data pipeline.

thehackerwire@mastodon.social at 2026-09-27T02:46:24.000Z ##

🟠 CVE-2026-100845 - High (7.8)

MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses numpy.load with allow_pickle=True when loading .npy and .npz files. Attackers can craft malicious .npy files with pickle payload...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T02:46:24.000Z ##

🟠 CVE-2026-100845 - High (7.8)

MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses numpy.load with allow_pickle=True when loading .npy and .npz files. Attackers can craft malicious .npy files with pickle payload...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100850
(7.7 HIGH)

EPSS: 0.22%

updated 2026-09-27T02:17:24.007000

2 posts

AzuraCast before 0.23.8 contains a server-side request forgery and local file read vulnerability in the AutoDJ remote playlist fetch (backend/src/Radio/AutoDJ/QueueBuilder.php, getMediaFromRemoteUrl()). A user with the station Media permission can create or update a playlist with source=remote_url and remote_type=playlist whose remote_url points at a file:// path or an internal/loopback/link-local

thehackerwire@mastodon.social at 2026-09-27T02:32:42.000Z ##

🟠 CVE-2026-100850 - High (7.7)

AzuraCast before 0.23.8 contains a server-side request forgery and local file read vulnerability in the AutoDJ remote playlist fetch (backend/src/Radio/AutoDJ/QueueBuilder.php, getMediaFromRemoteUrl()). A user with the station Media permission can...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T02:32:42.000Z ##

🟠 CVE-2026-100850 - High (7.7)

AzuraCast before 0.23.8 contains a server-side request forgery and local file read vulnerability in the AutoDJ remote playlist fetch (backend/src/Radio/AutoDJ/QueueBuilder.php, getMediaFromRemoteUrl()). A user with the station Media permission can...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100846
(7.6 HIGH)

EPSS: 0.27%

updated 2026-09-27T02:17:23.283000

2 posts

MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its contents to pickle.loads without validating the data source or content. If an application invokes algo_from_pickle on an attacker-supplied pickle file, an object defining __reduce__ is executed during deserializati

thehackerwire@mastodon.social at 2026-09-27T02:46:33.000Z ##

🟠 CVE-2026-100846 - High (7.6)

MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its contents to pickle.loads without validating the data source o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T02:46:33.000Z ##

🟠 CVE-2026-100846 - High (7.6)

MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its contents to pickle.loads without validating the data source o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100839
(8.4 HIGH)

EPSS: 0.15%

updated 2026-09-27T02:17:22.230000

2 posts

Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.18.0, the guest kernel's ACPI/AML handling is vulnerable to an AML injection attack ("BadAML"). ACPI tables containing AML bytecode are passed from the untrusted host (QEMU) to the guest firmware (OVMF) and on to the Linux kernel, whose AML interpreter executes them. An attacker controlling the host — an assumed adve

thehackerwire@mastodon.social at 2026-09-27T02:47:28.000Z ##

🟠 CVE-2026-100839 - High (8.4)

Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.18.0, the guest kernel's ACPI/AML handling is vulnerable to an AML injection attack ("BadAML"). ACPI tables containing AML bytecode are passed from the untrusted hos...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T02:47:28.000Z ##

🟠 CVE-2026-100839 - High (8.4)

Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.18.0, the guest kernel's ACPI/AML handling is vulnerable to an AML injection attack ("BadAML"). ACPI tables containing AML bytecode are passed from the untrusted hos...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100835
(7.4 HIGH)

EPSS: 0.22%

updated 2026-09-27T02:17:21.640000

2 posts

Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report that verified correctly and contained the expected firmware patch levels and software measurements, regardless of which machine produced it, so attestation was not bound to specific, physically trusted hardware. An attacker who can both intercept network traffic between the CLI a

1 repos

https://github.com/murrez/CVE-2026-100835

offseq at 2026-09-27T04:30:24.129Z ##

CVE-2026-100835: Contrast <1.16.0 faces CRITICAL remote attestation relay attacks. Any valid TEE attestation report is accepted, risking trust bypass. Upgrade ASAP. radar.offseq.com/threat/contra

##

offseq@infosec.exchange at 2026-09-27T04:30:24.000Z ##

CVE-2026-100835: Contrast <1.16.0 faces CRITICAL remote attestation relay attacks. Any valid TEE attestation report is accepted, risking trust bypass. Upgrade ASAP. radar.offseq.com/threat/contra #OffSeq #CVE2026100835 #infosec #security

##

CVE-2026-96533
(5.8 MEDIUM)

EPSS: 0.19%

updated 2026-09-26T23:16:41.497000

1 posts

The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-supplied URL before fetching it server-side and storing the response as a public file, allowing unauthenticated users to make the server issue requests to internal services and read the responses.

offseq@infosec.exchange at 2026-09-26T12:00:25.000Z ##

CVE-2026-96533: HIGH severity SSRF in Testimonials Widget (<=4.0.4). Unauthenticated users can make the server fetch internal URLs, exposing responses 🛡️. Disable or restrict plugin until patched. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #SSRF #Infosec

##

CVE-2026-77203
(8.8 HIGH)

EPSS: 0.33%

updated 2026-09-26T23:16:35.700000

1 posts

The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.6.0. This is due to the groups_join() function deriving group-join eligibility from the ambient post's author capabilities via the global $post->post_author rather than from the currently authenticated user's own capabilities, while simultaneously minting a

thehackerwire@mastodon.social at 2026-09-26T23:46:56.000Z ##

🟠 CVE-2026-77203 - High (8.8)

The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.6.0. This is due to the groups_join() function deriving group-join eligibility from the ambient post's...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100709
(7.5 HIGH)

EPSS: 0.29%

updated 2026-09-26T23:16:32.930000

2 posts

Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA tokens (panel_2fa_tokens) without recording the account namespace, and the remembered-token lookup during login is not constrained to the customer or administrator account type. Because customer and administrator IDs are allocated from separate namespaces, a remembered-2FA token legitimately issued to a customer with a given ID

thehackerwire@mastodon.social at 2026-09-27T00:16:17.000Z ##

🟠 CVE-2026-100709 - High (7.5)

Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA tokens (panel_2fa_tokens) without recording the account namespace, and the remembered-token lookup during login is not constrained to the customer or administrator account type...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T00:16:17.000Z ##

🟠 CVE-2026-100709 - High (7.5)

Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA tokens (panel_2fa_tokens) without recording the account namespace, and the remembered-token lookup during login is not constrained to the customer or administrator account type...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82901
(9.8 CRITICAL)

EPSS: 1.11%

updated 2026-09-26T21:30:34

3 posts

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.5.50. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: This is o

1 repos

https://github.com/murrez/CVE-2026-82901

Matchbook3469@mastodon.social at 2026-09-27T12:50:53.000Z ##

🚨 New security advisory:

CVE-2026-82901 affects multiple systems.

• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#Cybersecurity #VulnerabilityManagement #CyberSec

##

offseq@infosec.exchange at 2026-09-27T00:00:34.000Z ##

CVE-2026-82901: CRITICAL (CVSS 9.8) file upload vuln in Ultra Addons for Contact Form 7 (≤3.5.50). RCE risk if PDF Generator enabled (off by default). Disable/monitor plugin & watch for patches. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #Vulnerability

##

thehackerwire@mastodon.social at 2026-09-26T23:46:38.000Z ##

🔴 CVE-2026-82901 - Critical (9.8)

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.5.50. This makes it poss...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85984
(9.8 CRITICAL)

EPSS: 0.67%

updated 2026-09-26T18:31:08

3 posts

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-intent guard in the skip_pass_fallback-enabled configuration branch of the mo_by_pass_login() function, which treats administrator role membership alone as suffici

offseq at 2026-09-27T03:00:25.315Z ##

CVE-2026-85984: CRITICAL auth bypass in miniOrange OTP Login plugin ≤5.5.5. Attackers can log in as admin with just a username if certain options are enabled. Disable risky settings and check vendor guidance. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-27T03:00:25.000Z ##

CVE-2026-85984: CRITICAL auth bypass in miniOrange OTP Login plugin ≤5.5.5. Attackers can log in as admin with just a username if certain options are enabled. Disable risky settings and check vendor guidance. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202685984

##

thehackerwire@mastodon.social at 2026-09-26T23:46:48.000Z ##

🔴 CVE-2026-85984 - Critical (9.8)

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-intent gua...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97163(CVSS UNKNOWN)

EPSS: 0.42%

updated 2026-09-26T15:31:32

1 posts

Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29

2 repos

https://github.com/murrez/CVE-2026-97163

https://github.com/qeize/cve-2026-97163-payload

Matchbook3469@mastodon.social at 2026-09-27T12:23:23.000Z ##

🔴 New security advisory:

CVE-2026-97163 affects multiple systems.

• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#CVE #PatchNow #InfoSecCommunity

##

CVE-2026-100720
(8.7 HIGH)

EPSS: 0.21%

updated 2026-09-26T15:31:32

1 posts

Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authenticated role) uploads an SSL certificate for one of their own domains, the Certificates API add()/update() methods parse it with openssl_x509_parse() and store the issuer organization (issuer['O']) value verbatim without sanitization. Froxlor's table-listing renderer then emits s

thehackerwire@mastodon.social at 2026-09-27T00:01:38.000Z ##

🟠 CVE-2026-100720 - High (8.7)

Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authenticated role) uploads an SSL certificate for one of their own domains, the Certificates API add()/update() methods parse it wit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100705
(7.6 HIGH)

EPSS: 0.20%

updated 2026-09-26T15:31:28

2 posts

Kyverno before 1.19.1 is vulnerable to server-side request forgery. The default egress blocklist (169.254.169.254, 169.254.169.253, metadata.google.internal, 127.0.0.0/8, ::1/128) and the scoped-token control were wired only into the new CEL http.Get/Post library and were never applied to the legacy apiCall service executor (pkg/engine/apicall/executor.go) or to the GlobalContextEntry external-API

thehackerwire@mastodon.social at 2026-09-27T00:46:29.000Z ##

🟠 CVE-2026-100705 - High (7.6)

Kyverno before 1.19.1 is vulnerable to server-side request forgery. The default egress blocklist (169.254.169.254, 169.254.169.253, metadata.google.internal, 127.0.0.0/8, ::1/128) and the scoped-token control were wired only into the new CEL http....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T00:46:29.000Z ##

🟠 CVE-2026-100705 - High (7.6)

Kyverno before 1.19.1 is vulnerable to server-side request forgery. The default egress blocklist (169.254.169.254, 169.254.169.253, metadata.google.internal, 127.0.0.0/8, ::1/128) and the scoped-token control were wired only into the new CEL http....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100711
(7.5 HIGH)

EPSS: 0.26%

updated 2026-09-26T15:31:28

2 posts

froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked sessions, valid API keys, or 2FA trust tokens retain full account access after password rotation, bypassing incident response actions.

thehackerwire@mastodon.social at 2026-09-27T00:16:25.000Z ##

🟠 CVE-2026-100711 - High (7.5)

froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked sessions, valid API keys, or 2FA trust tokens retain full account access after p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T00:16:25.000Z ##

🟠 CVE-2026-100711 - High (7.5)

froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked sessions, valid API keys, or 2FA trust tokens retain full account access after p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100717
(9.9 CRITICAL)

EPSS: 0.30%

updated 2026-09-26T15:31:28

2 posts

froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo (user:pass@) components. This is an incomplete fix for GHSA-c3p2. An authenticated low-privilege customer with subdomain-create rights (no admin or chan

thehackerwire@mastodon.social at 2026-09-27T00:16:08.000Z ##

🔴 CVE-2026-100717 - Critical (9.9)

froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T00:16:08.000Z ##

🔴 CVE-2026-100717 - Critical (9.9)

froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100716
(9.9 CRITICAL)

EPSS: 0.39%

updated 2026-09-26T15:31:28

2 posts

Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: Froxlor\FileDir::makeCorrectDir() contains an off-by-one in its path-component walk that skips the first segment below the customer home directory, and the guard in ExportCron.php checks only the final component

thehackerwire@mastodon.social at 2026-09-27T00:02:44.000Z ##

🔴 CVE-2026-100716 - Critical (9.9)

Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: Froxlor\FileDir::makeCorrectDir() contains an off-by-one i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T00:02:44.000Z ##

🔴 CVE-2026-100716 - Critical (9.9)

Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: Froxlor\FileDir::makeCorrectDir() contains an off-by-one i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100713
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-26T15:31:28

1 posts

Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race condition in the SSH key synchronization cron (lib/Froxlor/Cron/System/SshKeys.php, SshKeys::generateFiles). The containment/symlink validation performed by FileDir::makeCorrectDir()/makeCorrectFile() is done only at check time; the live filesystem path is re-resolved as root at write time (file_put_contents with FILE_APP

thehackerwire@mastodon.social at 2026-09-27T00:01:47.000Z ##

🟠 CVE-2026-100713 - High (7.8)

Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race condition in the SSH key synchronization cron (lib/Froxlor/Cron/System/SshKeys.php, SshKeys::generateFiles). The containment/symlink validation performed by FileDir::make...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100672
(7.5 HIGH)

EPSS: 0.45%

updated 2026-09-26T15:31:27

2 posts

The Comments plugin (getgrav/grav-plugin-comments) for Grav CMS through version 1.2.10 registers an admin handler that returns comment data as JSON without any authentication check. The handler branches on isAdmin(), which only indicates that the admin service is registered on the current route rather than that the visitor is authenticated, and it echoes the JSON and calls exit() during the plugin

thehackerwire@mastodon.social at 2026-09-27T02:16:52.000Z ##

🟠 CVE-2026-100672 - High (7.5)

The Comments plugin (getgrav/grav-plugin-comments) for Grav CMS through version 1.2.10 registers an admin handler that returns comment data as JSON without any authentication check. The handler branches on isAdmin(), which only indicates that the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T02:16:52.000Z ##

🟠 CVE-2026-100672 - High (7.5)

The Comments plugin (getgrav/grav-plugin-comments) for Grav CMS through version 1.2.10 registers an admin handler that returns comment data as JSON without any authentication check. The handler branches on isAdmin(), which only indicates that the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100676
(8.2 HIGH)

EPSS: 0.40%

updated 2026-09-26T15:31:27

2 posts

January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), before version 0.15.5 improperly resolves SVG <image href> values as local filesystem paths when a fetched resource is served as image/svg+xml. An unauthenticated remote attacker who causes the service to proxy an attacker-hosted SVG (e.g. via the /proxy endpoint) can determine whether local files exist through observable r

thehackerwire@mastodon.social at 2026-09-27T01:46:42.000Z ##

🟠 CVE-2026-100676 - High (8.2)

January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), before version 0.15.5 improperly resolves SVG values as local filesystem paths when a fetched resource is served as image/svg+xml. An unauthenticated remote attacker who c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T01:46:42.000Z ##

🟠 CVE-2026-100676 - High (8.2)

January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), before version 0.15.5 improperly resolves SVG values as local filesystem paths when a fetched resource is served as image/svg+xml. An unauthenticated remote attacker who c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100673
(8.2 HIGH)

EPSS: 0.29%

updated 2026-09-26T15:31:27

2 posts

The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter — in some cases after a striptags('<br>') call that PHP's strip_tags() bypasses by preserving allowed tags together with their attributes. An unauthenticated visitor wh

thehackerwire@mastodon.social at 2026-09-27T01:46:33.000Z ##

🟠 CVE-2026-100673 - High (8.2)

The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter — in some cas...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T01:46:33.000Z ##

🟠 CVE-2026-100673 - High (8.2)

The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter — in some cas...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100685
(7.7 HIGH)

EPSS: 0.21%

updated 2026-09-26T15:31:27

2 posts

Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate chat identity link records across all workspaces in a tenant. Attackers with builder access to a single workspace can retrieve sensitive chat identity linking data including user IDs and external chat service identifiers from other workspaces they have no permission to acces

thehackerwire@mastodon.social at 2026-09-27T01:46:25.000Z ##

🟠 CVE-2026-100685 - High (7.7)

Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate chat identity link records across all workspaces in a tenant. Attackers with builder access to a single workspace can retr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T01:46:25.000Z ##

🟠 CVE-2026-100685 - High (7.7)

Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate chat identity link records across all workspaces in a tenant. Attackers with builder access to a single workspace can retr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100683
(8.0 HIGH)

EPSS: 0.21%

updated 2026-09-26T15:31:27

2 posts

Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename DDL in packages/backend-core/src/sql/sqlTable.ts by interpolating identifiers directly into a raw query string (backtick-quoted for MySQL, a single-quoted sp_rename literal for MSSQL) without applying the project's quoteMySqlIdentifier / quoteSqlServerIdentifier helpers. An attacker with DDL rights on a connected MySQL/

thehackerwire@mastodon.social at 2026-09-27T01:32:50.000Z ##

🟠 CVE-2026-100683 - High (8)

Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename DDL in packages/backend-core/src/sql/sqlTable.ts by interpolating identifiers directly into a raw query string (backtick-quoted for MySQL, a single-quoted sp_rename lit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T01:32:50.000Z ##

🟠 CVE-2026-100683 - High (8)

Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename DDL in packages/backend-core/src/sql/sqlTable.ts by interpolating identifiers directly into a raw query string (backtick-quoted for MySQL, a single-quoted sp_rename lit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100682
(8.8 HIGH)

EPSS: 0.57%

updated 2026-09-26T15:31:27

2 posts

Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extracts user-supplied ZIP archives without proper symlink validation. Attackers with BUILDER role can craft a malicious ZIP with leaf symlink entries followed by duplicate file entries to write arbitrary files as root, enabling remote code execution.

thehackerwire@mastodon.social at 2026-09-27T01:32:41.000Z ##

🟠 CVE-2026-100682 - High (8.8)

Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extracts user-supplied ZIP archives without proper symlink validation. Attackers with BUILDER role can craft a malicious ZIP with lea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T01:32:41.000Z ##

🟠 CVE-2026-100682 - High (8.8)

Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extracts user-supplied ZIP archives without proper symlink validation. Attackers with BUILDER role can craft a malicious ZIP with lea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100690
(7.5 HIGH)

EPSS: 0.35%

updated 2026-09-26T15:31:27

2 posts

Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model to restrict file system reads to the project directory and configured mounts. Because the Node.js permission model validates only the lexical path and follows symbolic links that point outside the allowed set, Hugo did not detect symlinks escaping the sandbox.

thehackerwire@mastodon.social at 2026-09-27T01:16:15.000Z ##

🟠 CVE-2026-100690 - High (7.5)

Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model to restrict file system reads to the project directory and configured mounts. Because the Node.js permission...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T01:16:15.000Z ##

🟠 CVE-2026-100690 - High (7.5)

Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model to restrict file system reads to the project directory and configured mounts. Because the Node.js permission...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100686
(8.1 HIGH)

EPSS: 0.21%

updated 2026-09-26T15:31:27

2 posts

Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign application roles across workspace boundaries. A builder of a single workspace can exploit missing per-app authorization checks to grant themselves admin roles in other workspaces by modifying user group role mappings.

thehackerwire@mastodon.social at 2026-09-27T01:01:48.000Z ##

🟠 CVE-2026-100686 - High (8.1)

Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign application roles across workspace boundaries. A builder of a single workspace can exploit mi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T01:01:48.000Z ##

🟠 CVE-2026-100686 - High (8.1)

Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign application roles across workspace boundaries. A builder of a single workspace can exploit mi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100697
(8.6 HIGH)

EPSS: 0.31%

updated 2026-09-26T15:31:27

2 posts

Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6.0.0) is loaded, is vulnerable to pre-authentication server-side request forgery. An unauthenticated attacker can submit auth[driver]=clickhouse with auth[server] set to an arbitrary URL (for example http://127.0.0.1:18089), causing the Adminer server to issue an HTTP POST contain

thehackerwire@mastodon.social at 2026-09-27T01:01:39.000Z ##

🟠 CVE-2026-100697 - High (8.6)

Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6.0.0) is loaded, is vulnerable to pre-authentication server-side request forgery. An unauthenticated attacker can submit auth[dr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T01:01:39.000Z ##

🟠 CVE-2026-100697 - High (8.6)

Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6.0.0) is loaded, is vulnerable to pre-authentication server-side request forgery. An unauthenticated attacker can submit auth[dr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100706
(9.9 CRITICAL)

EPSS: 0.61%

updated 2026-09-26T15:31:27

2 posts

kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tenants to bypass the per-namespace clamp and create objects in other namespaces as the admission-controller ServiceAccount. Attackers can exploit this by using percent-encoded directory traversal sequences to create MutatingWebhookConfiguration objects cluster-wide or PolicyExc

thehackerwire@mastodon.social at 2026-09-27T00:46:38.000Z ##

🔴 CVE-2026-100706 - Critical (9.9)

kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tenants to bypass the per-namespace clamp and create objects in other namespaces as the admission-controller ServiceAccount. A...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T00:46:38.000Z ##

🔴 CVE-2026-100706 - Critical (9.9)

kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tenants to bypass the per-namespace clamp and create objects in other namespaces as the admission-controller ServiceAccount. A...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100703
(7.7 HIGH)

EPSS: 0.23%

updated 2026-09-26T15:31:27

2 posts

Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib CEL library in its policy environment without confining it to the policy's namespace, unlike the sibling libraries (resource.Lib, http.Lib, configMap loader) which are handed the policy namespace. A tenant who can create a namespaced policy (e.g. NamespacedValidatingPolicy, and likewise the namespaced mutating, deleting, generating, and

thehackerwire@mastodon.social at 2026-09-27T00:31:25.000Z ##

🟠 CVE-2026-100703 - High (7.7)

Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib CEL library in its policy environment without confining it to the policy's namespace, unlike the sibling libraries (resource.Lib, http.Lib, configMap loader) which are handed the policy...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T00:31:25.000Z ##

🟠 CVE-2026-100703 - High (7.7)

Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib CEL library in its policy environment without confining it to the policy's namespace, unlike the sibling libraries (resource.Lib, http.Lib, configMap loader) which are handed the policy...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100714
(9.1 CRITICAL)

EPSS: 0.55%

updated 2026-09-26T15:31:27

1 posts

Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings hardened in GHSA-33mp, the field has no string_regexp or required_otp guard, and its value is concatenated unescaped into the acme.sh command line built in lib/Froxlor/Cron/Http/LetsEncrypt/AcmeSh.php and executed by the root cron via FileDir::safe_exec. Because safe_exec only bla

thehackerwire@mastodon.social at 2026-09-27T00:02:27.000Z ##

🔴 CVE-2026-100714 - Critical (9.1)

Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings hardened in GHSA-33mp, the field has no string_regexp or required_otp guard, and its value is concatenated unescaped into the ac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100670
(8.8 HIGH)

EPSS: 0.30%

updated 2026-09-26T15:31:26

2 posts

Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in the group and account blueprints. The access map is gated by a `security@: admin.super` guard that is resolved by the field's exact path, so a submitted flat dot-notation key such as `access.admin.super` (instead of the nested `access[admin][super]`) matches no blueprint rule, survives BlueprintSchema::filterArray() an

thehackerwire@mastodon.social at 2026-09-27T02:01:51.000Z ##

🟠 CVE-2026-100670 - High (8.8)

Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in the group and account blueprints. The access map is gated by a `security@: admin.super` guard that is resolved by the field's exact path, so a submitted flat dot-notat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T02:01:51.000Z ##

🟠 CVE-2026-100670 - High (8.8)

Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in the group and account blueprints. The access map is gated by a `security@: admin.super` guard that is resolved by the field's exact path, so a submitted flat dot-notat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100669
(7.5 HIGH)

EPSS: 0.44%

updated 2026-09-26T15:31:26

2 posts

Grav before 2.0.25 ships web server configuration samples whose access-control deny rules are matched case-sensitively. In webserver-configs/web.config (IIS), every deny rule (user_sensitive_folders, user_accounts, user_data, user_error_redirect, user_pages, system, vendor, ignore_folders) sets ignoreCase="false" on its URL Rewrite <match> element, overriding the IIS default of ignoreCase="true";

thehackerwire@mastodon.social at 2026-09-27T02:01:42.000Z ##

🟠 CVE-2026-100669 - High (7.5)

Grav before 2.0.25 ships web server configuration samples whose access-control deny rules are matched case-sensitively. In webserver-configs/web.config (IIS), every deny rule (user_sensitive_folders, user_accounts, user_data, user_error_redirect, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T02:01:42.000Z ##

🟠 CVE-2026-100669 - High (7.5)

Grav before 2.0.25 ships web server configuration samples whose access-control deny rules are matched case-sensitively. In webserver-configs/web.config (IIS), every deny rule (user_sensitive_folders, user_accounts, user_data, user_error_redirect, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100700
(7.5 HIGH)

EPSS: 0.28%

updated 2026-09-26T15:31:24

2 posts

nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback regex pattern that exhibits quadratic backtracking behavior. Attackers can supply crafted email header values with long whitespace-free runs to block the Node.js event loop for tens of seconds, causing service unavailability.

thehackerwire@mastodon.social at 2026-09-27T00:31:17.000Z ##

🟠 CVE-2026-100700 - High (7.5)

nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback regex pattern that exhibits quadratic backtracking behavior. Attackers can supply crafted email header values with long whitespace-free run...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T00:31:17.000Z ##

🟠 CVE-2026-100700 - High (7.5)

nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback regex pattern that exhibits quadratic backtracking behavior. Attackers can supply crafted email header values with long whitespace-free run...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100661
(7.5 HIGH)

EPSS: 0.34%

updated 2026-09-26T15:31:23

2 posts

Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain a denial-of-service vulnerability in the QPACK prefixed-integer decoder (QpackUtil.decodePrefixedInteger), which does not bound the number of continuation bytes it will process. A remote, unauthenticated peer can open a QPACK unidirectional stream (type 0x02 encoder or 0x03 decoder) and send a first

thehackerwire@mastodon.social at 2026-09-27T02:17:02.000Z ##

🟠 CVE-2026-100661 - High (7.5)

Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain a denial-of-service vulnerability in the QPACK prefixed-integer decoder (QpackUtil.decodePrefixedInteger), which does not bound the number of conti...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T02:17:02.000Z ##

🟠 CVE-2026-100661 - High (7.5)

Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain a denial-of-service vulnerability in the QPACK prefixed-integer decoder (QpackUtil.decodePrefixedInteger), which does not bound the number of conti...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100692
(7.5 HIGH)

EPSS: 0.44%

updated 2026-09-26T15:31:23

2 posts

Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement checks stopped at the mount root itself, so a theme or module checked into themes/ (or a vendored module) could contain a symlink at a mount root (for example themes/mytheme/assets -> /some/dir/outside). Files behind such a symlink were readable during a site build through resources.Get, res

thehackerwire@mastodon.social at 2026-09-27T01:16:24.000Z ##

🟠 CVE-2026-100692 - High (7.5)

Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement checks stopped at the mount root itself, so a theme or module checked into themes/ (or a vendored module) could contain a symlink at a moun...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T01:16:24.000Z ##

🟠 CVE-2026-100692 - High (7.5)

Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement checks stopped at the mount root itself, so a theme or module checked into themes/ (or a vendored module) could contain a symlink at a moun...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100693
(8.4 HIGH)

EPSS: 0.13%

updated 2026-09-26T15:31:23

2 posts

Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that allows attackers to bypass restrictions. Attackers can use mixed-case URL schemes in resources.GetRemote calls to fetch from restricted IP addresses like localhost.

thehackerwire@mastodon.social at 2026-09-27T01:01:30.000Z ##

🟠 CVE-2026-100693 - High (8.4)

Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that allows attackers to bypass restrictions. Attackers can use mixed-case URL schemes in resources.GetRemote calls...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T01:01:30.000Z ##

🟠 CVE-2026-100693 - High (8.4)

Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that allows attackers to bypass restrictions. Attackers can use mixed-case URL schemes in resources.GetRemote calls...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100715
(9.6 CRITICAL)

EPSS: 0.40%

updated 2026-09-26T14:16:57.537000

1 posts

Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task. Cron task 8 (deleteFtpData), queued when an FTP account is deleted, calls FileDir::makeCorrectDir() without the $fixed_homedir argument, so the symlink component walk is skipped, and then executes 'rm -rf' as root on the resulting path with string-level guards only. Because mak

thehackerwire@mastodon.social at 2026-09-27T00:02:35.000Z ##

🔴 CVE-2026-100715 - Critical (9.6)

Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task. Cron task 8 (deleteFtpData), queued when an FTP account is deleted, calls FileDir::makeCorrectDir() without the $fixed_homedi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100707
(7.7 HIGH)

EPSS: 0.46%

updated 2026-09-26T14:16:55.983000

2 posts

Kyverno before 1.19.1 contains a namespace isolation bypass in the apiCall context entry of namespaced Policy resources due to inconsistent path interpretation between validation and execution. A low-privilege tenant can use percent-encoded dot-segments in urlPath to bypass namespace checks and read resources from other namespaces using the Kyverno admission controller's ServiceAccount credentials

thehackerwire@mastodon.social at 2026-09-27T00:46:46.000Z ##

🟠 CVE-2026-100707 - High (7.7)

Kyverno before 1.19.1 contains a namespace isolation bypass in the apiCall context entry of namespaced Policy resources due to inconsistent path interpretation between validation and execution. A low-privilege tenant can use percent-encoded dot-se...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T00:46:46.000Z ##

🟠 CVE-2026-100707 - High (7.7)

Kyverno before 1.19.1 contains a namespace isolation bypass in the apiCall context entry of namespaced Policy resources due to inconsistent path interpretation between validation and execution. A low-privilege tenant can use percent-encoded dot-se...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100704
(7.7 HIGH)

EPSS: 0.18%

updated 2026-09-26T14:16:55.563000

2 posts

Kyverno is a policy engine for Kubernetes. In versions 1.14.0 through 1.19.0, the ImageValidatingPolicy (policies.kyverno.io/v1beta1) evaluator never reads the spec.images and spec.allowedValues fields of a PolicyException. Any PolicyException whose policyRefs and matchConditions match a resource causes image signature verification to be skipped for the entire resource rather than only for the lis

thehackerwire@mastodon.social at 2026-09-27T00:31:33.000Z ##

🟠 CVE-2026-100704 - High (7.7)

Kyverno is a policy engine for Kubernetes. In versions 1.14.0 through 1.19.0, the ImageValidatingPolicy (policies.kyverno.io/v1beta1) evaluator never reads the spec.images and spec.allowedValues fields of a PolicyException. Any PolicyException who...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T00:31:33.000Z ##

🟠 CVE-2026-100704 - High (7.7)

Kyverno is a policy engine for Kubernetes. In versions 1.14.0 through 1.19.0, the ImageValidatingPolicy (policies.kyverno.io/v1beta1) evaluator never reads the spec.images and spec.allowedValues fields of a PolicyException. Any PolicyException who...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100684
(8.1 HIGH)

EPSS: 0.33%

updated 2026-09-26T14:16:52.720000

2 posts

Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In sso.authenticate, when no existing user matches the incoming SSO subject, the server looks up pending user invites by the IdP-asserted email address alone — without validating an invite code and without an email_verified check (the email_verified gate protects only the existin

thehackerwire@mastodon.social at 2026-09-27T01:32:58.000Z ##

🟠 CVE-2026-100684 - High (8.1)

Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In sso.authenticate, when no existing user matches the incoming SSO subject, the server looks up pending user invites by the Id...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T01:32:58.000Z ##

🟠 CVE-2026-100684 - High (8.1)

Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In sso.authenticate, when no existing user matches the incoming SSO subject, the server looks up pending user invites by the Id...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100680
(8.1 HIGH)

EPSS: 0.23%

updated 2026-09-26T14:16:52.150000

2 posts

Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validator, allowing authenticated builders to read arbitrary local files. Attackers with builder access can embed file:// references in OpenAPI specifications submitted to the import endpoint to exfiltrate sensitive files including environment variables containing JWT secrets, API keys,

thehackerwire@mastodon.social at 2026-09-27T01:16:32.000Z ##

🟠 CVE-2026-100680 - High (8.1)

Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validator, allowing authenticated builders to read arbitrary local files. Attackers with builder access can embed file:// references i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T01:16:32.000Z ##

🟠 CVE-2026-100680 - High (8.1)

Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validator, allowing authenticated builders to read arbitrary local files. Attackers with builder access can embed file:// references i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100679
(8.8 HIGH)

EPSS: 0.32%

updated 2026-09-26T14:16:51.993000

2 posts

stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authenticated user, allowing attackers to bypass MFA by using their own valid ticket with another user's session token. Attackers can obtain a ticket from their own account and use it with a victim's session token to disable TOTP, view recovery codes, or perform other sensitive operations without providing the victim's creden

thehackerwire@mastodon.social at 2026-09-27T02:01:33.000Z ##

🟠 CVE-2026-100679 - High (8.8)

stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authenticated user, allowing attackers to bypass MFA by using their own valid ticket with another user's session token. Attackers can obtain a ticket from their own account a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T02:01:33.000Z ##

🟠 CVE-2026-100679 - High (8.8)

stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authenticated user, allowing attackers to bypass MFA by using their own valid ticket with another user's session token. Attackers can obtain a ticket from their own account a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100671
(8.0 HIGH)

EPSS: 0.29%

updated 2026-09-26T14:16:50.860000

2 posts

Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24 — and in 2.0.0 through 2.0.18 and 1.7.x only where content Twig has been explicitly enabled — page content authored by a user holding only page-write permission is rendered through a Twig sandbox that allowlists get_cookie(), which returns any cookie sent with the current request, including the visitor's session cookie. Because the read oc

thehackerwire@mastodon.social at 2026-09-27T02:16:42.000Z ##

🟠 CVE-2026-100671 - High (8)

Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24 — and in 2.0.0 through 2.0.18 and 1.7.x only where content Twig has been explicitly enabled — page content authored by a user holding only page-write permission is rendered through a T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-27T02:16:42.000Z ##

🟠 CVE-2026-100671 - High (8)

Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24 — and in 2.0.0 through 2.0.18 and 1.7.x only where content Twig has been explicitly enabled — page content authored by a user holding only page-write permission is rendered through a T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18143
(9.8 CRITICAL)

EPSS: 0.41%

updated 2026-09-26T09:30:26

2 posts

The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is due to missing file extension and MIME type validation in the popup upload handler, which uses the raw attacker-supplied filename directly as the destination for `move_uploaded_file()`. This makes it p

1 repos

https://github.com/murrez/CVE-2026-18143

thehackerwire@mastodon.social at 2026-09-26T07:30:13.000Z ##

🔴 CVE-2026-18143 - Critical (9.8)

The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is due to missing file extension and MIME type vali...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-26T07:30:22.000Z ##

CVE-2026-18143 | CRITICAL unrestricted file upload in Addify Request a Quote for WooCommerce (<=2.9.2). Unauth attackers can achieve RCE. Disable public quote rule/multi-page popup or restrict uploads. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #RCE

##

CVE-2026-91840
(7.8 HIGH)

EPSS: 0.19%

updated 2026-09-26T04:17:51.307000

1 posts

A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker can manipulate the vpnc configuration to execute an arbitrary program with root privileges when the malicious VPN connection is activated.

thehackerwire@mastodon.social at 2026-09-26T08:00:45.000Z ##

🟠 CVE-2026-91840 - High (7.8)

A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker can manipulate the vpnc configuration to execute...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100596
(8.8 HIGH)

EPSS: 0.25%

updated 2026-09-26T03:30:36

1 posts

OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands. Attackers can persist arbitrary stdio MCP commands that execute with OpenClaw process privileges when configuration loads, compromising host confidentiality, integrity, and availability.

thehackerwire@mastodon.social at 2026-09-26T03:46:38.000Z ##

🟠 CVE-2026-100596 - High (8.8)

OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands. Attackers can persist arbitrary stdio MCP commands that execute with OpenClaw process privil...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100560
(7.5 HIGH)

EPSS: 0.58%

updated 2026-09-26T03:30:35

1 posts

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals for exact commands persist as path-only grants on macOS and Linux. Attackers can reuse the same executable with different arguments to execute commands without triggering new approval prompts, potentially accessing files or internal services.

thehackerwire@mastodon.social at 2026-09-26T07:00:56.000Z ##

🟠 CVE-2026-100560 - High (7.5)

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals for exact commands persist as path-only grants on macOS and Linux. Attackers can reuse the same executable with different arguments to exe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100568
(8.3 HIGH)

EPSS: 0.25%

updated 2026-09-26T03:30:35

1 posts

OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible agent callers to read and execute ownerless command jobs. Attackers can inspect stored environment variables and force-run disabled or unscheduled command jobs to access secrets and execute operator-authored commands.

thehackerwire@mastodon.social at 2026-09-26T06:32:55.000Z ##

🟠 CVE-2026-100568 - High (8.3)

OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible agent callers to read and execute ownerless command jobs. Attackers can inspect stored environment variables and force-run dis...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100567
(8.2 HIGH)

EPSS: 0.25%

updated 2026-09-26T03:30:35

1 posts

OpenClaw is an agent gateway distributed as the npm package 'openclaw'. In versions >= 2026.4.5 and < 2026.8.1, the Gateway validated a single DNS resolution result for a configured remote Chrome DevTools Protocol (CDP) hostname, but the raw WebSocket and Playwright transports performed a later, independent DNS resolution, discarding the DNS pinning enforced at validation time. An attacker who con

thehackerwire@mastodon.social at 2026-09-26T06:32:46.000Z ##

🟠 CVE-2026-100567 - High (8.2)

OpenClaw is an agent gateway distributed as the npm package 'openclaw'. In versions >= 2026.4.5 and &lt; 2026.8.1, the Gateway validated a single DNS resolution result for a configured remote Chrome DevTools Protocol (CDP) hostname, but the raw We...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100580
(8.8 HIGH)

EPSS: 0.34%

updated 2026-09-26T03:30:35

1 posts

OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a mixed-case payload kind can pass the agent-facing shell-execution guard and later normalize into a command job. An actor able to steer a tool-enabled agent can therefore create a persistent cron job that executes attacker-selected commands with the privileges of the OpenClaw proce

thehackerwire@mastodon.social at 2026-09-26T05:48:39.000Z ##

🟠 CVE-2026-100580 - High (8.8)

OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a mixed-case payload kind can pass the agent-facing shell-execution guard and later normalize into a command job. An actor able to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100579
(7.6 HIGH)

EPSS: 0.23%

updated 2026-09-26T03:30:35

1 posts

OpenClaw (npm package 'openclaw') before 2026.7.1 incorrectly trusts requester provenance in message.action. In identity-bearing Gateway deployments (authentication modes that honor caller identity and narrower operator scopes), a write-scoped caller can supply another sender's identifier to the channel authorization checks and invoke a channel action under that spoofed requester identity, reachin

thehackerwire@mastodon.social at 2026-09-26T05:48:30.000Z ##

🟠 CVE-2026-100579 - High (7.6)

OpenClaw (npm package 'openclaw') before 2026.7.1 incorrectly trusts requester provenance in message.action. In identity-bearing Gateway deployments (authentication modes that honor caller identity and narrower operator scopes), a write-scoped cal...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100578
(7.6 HIGH)

EPSS: 0.23%

updated 2026-09-26T03:30:35

1 posts

OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only infrastructure tools exposed through the chat.send endpoint. In Gateway deployments using authentication modes that honor caller identity and narrower operator scopes, a write-scoped non-owner caller can start a chat turn whose tool inventory includes the `gateway` and `cron` tools, causing the agent to invoke owner-onl

thehackerwire@mastodon.social at 2026-09-26T05:48:21.000Z ##

🟠 CVE-2026-100578 - High (7.6)

OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only infrastructure tools exposed through the chat.send endpoint. In Gateway deployments using authentication modes that honor caller identity and narrower operator scopes, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100585
(8.0 HIGH)

EPSS: 0.19%

updated 2026-09-26T03:30:35

1 posts

OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude Code permission prompts delivered through the MCP channel bridge. An authorized non-owner channel sender with channel command access can approve or deny a pending permission request intended for the owner, causing the requested action to proceed without owner consent. The practica

thehackerwire@mastodon.social at 2026-09-26T03:47:46.000Z ##

🟠 CVE-2026-100585 - High (8)

OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude Code permission prompts delivered through the MCP channel bridge. An authorized non-owner channel sender with channel command ac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100582
(6.5 MEDIUM)

EPSS: 0.21%

updated 2026-09-26T03:30:35

1 posts

OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) before 2026.8.1 do not enforce the configured channel read allowlist for caller-supplied explicit read targets in message, reaction, pin, member, and related metadata read actions. A lower-trust sender or a steered agent with access to a channel read action can therefore retrieve content or m

offseq@infosec.exchange at 2026-09-26T03:00:25.000Z ##

CVE-2026-100582 (HIGH): openclaw msteams <2026.8.1 has a missing authorization flaw — low-trust users can bypass channel read allowlists and access restricted data. Patch to 2026.8.1 ASAP. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #OpenClaw #Security

##

CVE-2026-100559
(8.0 HIGH)

EPSS: 0.25%

updated 2026-09-26T03:30:34

1 posts

OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist parsing, allowing hidden commands to execute. Attackers can craft input with escaped newlines to bypass allowlist validation and execute additional commands without expected authorization prompts.

thehackerwire@mastodon.social at 2026-09-26T06:45:37.000Z ##

🟠 CVE-2026-100559 - High (8)

OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist parsing, allowing hidden commands to execute. Attackers can craft input with escaped newlines to bypass allowlist validation and...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100557
(8.3 HIGH)

EPSS: 0.24%

updated 2026-09-26T03:30:34

1 posts

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in skill tool dispatch that fails to carry the sender's owner status. Non-owner senders authorized to invoke skill commands can access owner-only tools and server credentials reserved for owners.

thehackerwire@mastodon.social at 2026-09-26T06:45:18.000Z ##

🟠 CVE-2026-100557 - High (8.3)

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in skill tool dispatch that fails to carry the sender's owner status. Non-owner senders authorized to invoke skill commands can access owner-only tools and server cred...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100589
(8.3 HIGH)

EPSS: 0.32%

updated 2026-09-26T03:30:29

1 posts

OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessions to access paired node browser actions despite allowHostControl=false configuration. Attackers with control over sandboxed agent input can select a paired node and perform host browser operations, inspecting or manipulating the connected browser profile and its authenticated s

thehackerwire@mastodon.social at 2026-09-26T03:47:37.000Z ##

🟠 CVE-2026-100589 - High (8.3)

OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessions to access paired node browser actions despite allowHostControl=false configuration. Attackers with control over sandboxed a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100532
(8.1 HIGH)

EPSS: 0.27%

updated 2026-09-26T03:30:28

1 posts

@openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the originating sender's owner status, so the owner-only tool boundary is not enforced. An admitted non-owner sender able to steer the tool can request a forced login and receive a new QR code for a configured account, disconnecting the Gateway's WhatsApp account and ca

thehackerwire@mastodon.social at 2026-09-26T07:30:57.000Z ##

🟠 CVE-2026-100532 - High (8.1)

@OpenClaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the originating sender's owner status, so the owner-only tool boundary is not enforced. An admitted non-owner sender ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100535
(7.5 HIGH)

EPSS: 0.26%

updated 2026-09-26T03:30:28

1 posts

OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose the originating requester's restrictions and untrusted provenance when session-derived text is persisted to session memory. In deployments where session-memory capture and dreaming are enabled, a restricted external sender whose messages are admitted with limited tools can persist instructions that are later supplied to

thehackerwire@mastodon.social at 2026-09-26T07:30:39.000Z ##

🟠 CVE-2026-100535 - High (7.5)

OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and &lt; 2026.8.1 can lose the originating requester&#039;s restrictions and untrusted provenance when session-derived text is persisted to session memory. In deployments where session-memory ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100588
(8.3 HIGH)

EPSS: 0.30%

updated 2026-09-26T03:30:28

1 posts

OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control when it is reached through the node.invoke method, although direct browser.request access requires administrator scope. In Gateway deployments that honor caller identity and narrower operator scopes, a write-scoped caller with access to a connected browser-capable node can insp

thehackerwire@mastodon.social at 2026-09-26T05:47:32.000Z ##

🟠 CVE-2026-100588 - High (8.3)

OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control when it is reached through the node.invoke method, although direct browser.request access requires administrator scope. In Ga...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100587
(8.8 HIGH)

EPSS: 0.25%

updated 2026-09-26T03:30:28

1 posts

OpenClaw versions before 2026.7.1 fail to properly validate owner authorization in the Codex computer-use installation command. Non-owner channel senders can install arbitrary plugins and execute MCP processes with OpenClaw user privileges, affecting host confidentiality, integrity, and availability.

thehackerwire@mastodon.social at 2026-09-26T05:47:23.000Z ##

🟠 CVE-2026-100587 - High (8.8)

OpenClaw versions before 2026.7.1 fail to properly validate owner authorization in the Codex computer-use installation command. Non-owner channel senders can install arbitrary plugins and execute MCP processes with OpenClaw user privileges, affect...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100599
(8.8 HIGH)

EPSS: 0.30%

updated 2026-09-26T03:30:28

1 posts

OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands. The googlemeet.chrome command accepts caller-supplied audio command arrays and executes them on a paired node without going through the normal system.run approval flow. In deployments with the Google Meet plugin enabled, a paired Chrome node, and the googlemeet.chrome node comm

thehackerwire@mastodon.social at 2026-09-26T03:46:56.000Z ##

🟠 CVE-2026-100599 - High (8.8)

OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands. The googlemeet.chrome command accepts caller-supplied audio command arrays and executes them on a paired node without going t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100543
(7.5 HIGH)

EPSS: 0.35%

updated 2026-09-26T03:30:25

1 posts

OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacted configuration in redacted configuration responses. When the Gateway password had low entropy and the remaining configuration values were reconstructable, these hashes acted as offline password verifiers: a caller able to obtain the redacted configuration (for example via config

thehackerwire@mastodon.social at 2026-09-26T07:15:31.000Z ##

🟠 CVE-2026-100543 - High (7.5)

OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacted configuration in redacted configuration responses. When the Gateway password had low entropy and the remaining configuration ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100552
(8.8 HIGH)

EPSS: 0.26%

updated 2026-09-26T03:30:25

1 posts

OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server runtime tools. A conversation-level tools.allow rule filtered OpenClaw tools but did not restrict the shell, process, file, and patch tools owned by the Codex runtime. When a lower-trust conversation was assigned to a Codex runtime and restricted with a per-chat tool allowlist,

thehackerwire@mastodon.social at 2026-09-26T07:15:22.000Z ##

🟠 CVE-2026-100552 - High (8.8)

OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server runtime tools. A conversation-level tools.allow rule filtered OpenClaw tools but did not restrict the shell, process, file, an...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100551
(8.3 HIGH)

EPSS: 0.17%

updated 2026-09-26T03:30:25

2 posts

OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it. If a user had accepted a Gateway fingerprint, an attacker able to redirect the same host and port and present a different certificate that is accepted by

thehackerwire@mastodon.social at 2026-09-26T07:01:14.000Z ##

🟠 CVE-2026-100551 - High (8.3)

OpenClaw for iOS versions >= 2026.7.1 and &lt; 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-26T06:00:25.000Z ##

CVE-2026-100551: OpenClaw for iOS (>=2026.7.1, <2026.8.11) has a CRITICAL vuln in Control UI WebViews — TLS pins not enforced. Attackers can steal Gateway creds if they can redirect traffic. Patch to 2026.8.11 ASAP! radar.offseq.com/threat/opencl #OffSeq #Vulnerability #iOS #AppSec

##

CVE-2026-100520
(8.8 HIGH)

EPSS: 0.94%

updated 2026-09-26T03:30:23

1 posts

Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory. Attackers can supply directory traversal sequences in the path parameter to write PHP files into other tenants' web roots and execute code as those tenants.

thehackerwire@mastodon.social at 2026-09-26T03:16:42.000Z ##

🟠 CVE-2026-100520 - High (8.8)

Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory. Attackers can supply directory traversal seq...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100597
(7.8 HIGH)

EPSS: 0.08%

updated 2026-09-26T03:17:08.337000

1 posts

OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition in OpenShell local mirror filesystem mutation operations. The remove, mkdir, and rename operations could act on a different filesystem target after OpenClaw completed its sandbox path-safety check, if the path is changed concurrently. An attacker able to win the race can cause a sandboxed

thehackerwire@mastodon.social at 2026-09-26T03:46:47.000Z ##

🟠 CVE-2026-100597 - High (7.8)

OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition in OpenShell local mirror filesystem mutation operations. The remove, mkdir, and rename operations could act on a different filesystem ta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100586
(8.8 HIGH)

EPSS: 0.25%

updated 2026-09-26T03:17:06.660000

1 posts

OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings. Non-owner channel senders with command access can create bindings to the native Codex runtime and execute host-capable turns with access to files, tools, and processes.

thehackerwire@mastodon.social at 2026-09-26T03:47:54.000Z ##

🟠 CVE-2026-100586 - High (8.8)

OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings. Non-owner channel senders with command access can create bindings to the native Codex runtime and execute host-capable turns w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100575
(8.8 HIGH)

EPSS: 0.26%

updated 2026-09-26T03:17:05.030000

2 posts

OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages. Disallowed participants can trigger Slack agents and access tools and data granted to those agents by bypassing configured sender policies.

thehackerwire@mastodon.social at 2026-09-26T05:47:41.000Z ##

🟠 CVE-2026-100575 - High (8.8)

OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages. Disallowed participants can trigger Slack agents and access tools and data granted to those agents by bypassing configured sender p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-26T04:30:25.000Z ##

CVE-2026-100575 | HIGH severity | OpenClaw Slack (<2026.8.1): Missing authorization in multi-person DMs lets unauthorized users trigger Slack agents and access restricted tools/data. Patch to 2026.8.1+ now. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Infosec #Slack

##

CVE-2026-100570
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-26T03:17:04.177000

1 posts

OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 allow an untrusted workspace .env file to set the CLOUDSDK_PYTHON_ARGS environment variable. When an operator starts OpenClaw in attacker-controlled workspace content and then runs the Gmail setup flow, that value is inherited when gcloud is launched, and the gcloud launcher passes it as arguments to the trusted Python interpre

thehackerwire@mastodon.social at 2026-09-26T06:32:36.000Z ##

🟠 CVE-2026-100570 - High (7.8)

OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and &lt; 2026.8.1 allow an untrusted workspace .env file to set the CLOUDSDK_PYTHON_ARGS environment variable. When an operator starts OpenClaw in attacker-controlled workspace content and th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100561
(8.0 HIGH)

EPSS: 0.25%

updated 2026-09-26T03:17:02.987000

1 posts

OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain an approval-bypass flaw in the exec approval policy: the policy could trust a command-running wrapper without inspecting the command carried in its arguments. After an operator allowlisted or permanently approved a benign wrapper invocation, a later agent turn could substitute an arbitrary inner command and execute it w

thehackerwire@mastodon.social at 2026-09-26T07:01:05.000Z ##

🟠 CVE-2026-100561 - High (8)

OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and &lt; 2026.8.1 contain an approval-bypass flaw in the exec approval policy: the policy could trust a command-running wrapper without inspecting the command carried in its arguments. After ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100558
(7.5 HIGH)

EPSS: 0.28%

updated 2026-09-26T03:17:02.533000

1 posts

OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in the Gateway listener that allows unauthenticated clients to retain response sockets by sending WebSocket upgrade requests without matching connection semantics. Attackers can repeatedly send malformed upgrade requests to exhaust listener resources and cause denial of service without consuming the WebSocket pre-auth co

thehackerwire@mastodon.social at 2026-09-26T06:45:27.000Z ##

🟠 CVE-2026-100558 - High (7.5)

OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in the Gateway listener that allows unauthenticated clients to retain response sockets by sending WebSocket upgrade requests without matching connection semantics. Attac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100544
(8.8 HIGH)

EPSS: 0.25%

updated 2026-09-26T03:17:00.440000

1 posts

openclaw's @openclaw/voice-call package before 2026.8.1 launches the configured agent for classic inbound voice calls without propagating the caller's identity or non-owner status. As a result, owner-only tool filtering can fail open and expose the agent's normal tool authority to a remote caller. A caller who is admitted by the configured inbound-call policy (open, pairing, or allowlist) on a dep

thehackerwire@mastodon.social at 2026-09-26T07:15:40.000Z ##

🟠 CVE-2026-100544 - High (8.8)

openclaw's @OpenClaw/voice-call package before 2026.8.1 launches the configured agent for classic inbound voice calls without propagating the caller's identity or non-owner status. As a result, owner-only tool filtering can fail open and expose th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100541
(7.5 HIGH)

EPSS: 0.30%

updated 2026-09-26T03:16:59.987000

1 posts

OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 lowercase complete Matrix user IDs — including historical localparts and the case-sensitive server-name portion — when deriving the OpenClaw authorization identity. As a result, distinct authenticated Matrix accounts can normalize to the same authorization identity. A Matrix participant controlling a c

thehackerwire@mastodon.social at 2026-09-26T07:30:48.000Z ##

🟠 CVE-2026-100541 - High (7.5)

OpenClaw's Matrix integration (npm package @OpenClaw/matrix) versions >= 2026.2.2 and &lt; 2026.8.1 lowercase complete Matrix user IDs — including historical localparts and the case-sensitive server-name portion — when deriving the OpenClaw au...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100382(CVSS UNKNOWN)

EPSS: 0.95%

updated 2026-09-26T00:32:22

2 posts

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Foundation Mediawiki - ExternalData Extension allows OS Command Injection. This issue affects Mediawiki - ExternalData Extension: from * before 3.7.

1 repos

https://github.com/nth347/mediawiki-CVE-2026-100382

offseq@infosec.exchange at 2026-09-26T09:00:23.000Z ##

Mediawiki ExternalData Extension <3.7 has a CRITICAL OS Command Injection vuln (CVE-2026-100382). Unauthenticated attackers could run arbitrary OS commands. No exploits yet. Restrict access, monitor activity. radar.offseq.com/threat/improp #OffSeq #CVE2026100382 #Mediawiki #Security

##

offseq@infosec.exchange at 2026-09-26T00:00:36.000Z ##

CVE-2026-100382 (CRITICAL, CVSS 10): Wikimedia Mediawiki ExternalData Extension (<3.7) suffers OS Command Injection. Remote, unauthenticated code execution is possible. Restrict access & monitor systems. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE2026100382 #infosec #Mediawiki

##

CVE-2026-96795
(8.8 HIGH)

EPSS: 0.30%

updated 2026-09-25T23:16:55.020000

1 posts

Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py accepts an authenticated user's columns POST parameter, takes field_tuple[1], interpolates it into dynamic_fn_str as Python source, and passes the generated function definition to exec(). A crafted string that remains valid under ast.literal_eval can inject Python syntax into a defa

thehackerwire@mastodon.social at 2026-09-25T23:46:00.000Z ##

🟠 CVE-2026-96795 - High (8.8)

Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py accepts an authenticated user's columns POST parameter, takes field_tuple[1], interpolates it into dynamic_fn_str as Python source...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-57443
(7.5 HIGH)

EPSS: 0.57%

updated 2026-09-25T21:48:04

1 posts

### Summary The AetherBrowser API server (`scripts/aetherbrowser/api_server.py`) exposes the `POST /api/ops/check-email` endpoint without any authentication. Any remote attacker can call this endpoint and trigger execution of the `email_reader.py` subprocess, which connects to configured ProtonMail or Gmail accounts via IMAP and returns email metadata (sender, subject, body snippet) in the JSON r

thehackerwire@mastodon.social at 2026-09-25T23:46:39.000Z ##

🟠 CVE-2026-57443 - High (7.5)

SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 and prior to version 4.2.1, the AetherBrowser API server (`scripts/aetherbrowser/api_server.py`) exposes the `POST /api/ops/check-email` endpoint wit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100368
(8.4 HIGH)

EPSS: 0.58%

updated 2026-09-25T21:41:49

1 posts

### Impact An OS command injection vulnerability exists in the PowerShell and Cmd shell wrappers provided by the `CliInvoke.Specializations` package (the `PowershellProcessInvoker`/`CmdProcessInvoker` invokers, and the `UsePowerShell`/`UseCmd` middleware in v3 pre-release versions). The wrappers re-run a caller-supplied target and arguments inside a shell command (`pwsh -Command ...` / `cmd /c ..

thehackerwire@mastodon.social at 2026-09-26T03:17:23.000Z ##

🟠 CVE-2026-100368 - High (8.4)

CliInvoke is a .NET library for invoking command-line programs, and its `CliInvoke.Specializations` packages provide specialized wrappers for shells such as PowerShell and Windows Command Prompt. `CliInvoke.Specializations` versions 2.2.0 through ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100369
(8.4 HIGH)

EPSS: 0.36%

updated 2026-09-25T21:41:37

1 posts

### Impact An argument-injection vulnerability exists in the `CliInvoke` package's runner factory: `RunnerProcessFactory` on the 2.x line and `RunnerConfigurationFactory` on the 3.x line. The factory joins the runner arguments, the caller's target, and the caller's arguments into a single `ProcessStartInfo.Arguments` string and hands it to the OS. The OS command-line parser re-tokenizes the strin

thehackerwire@mastodon.social at 2026-09-26T03:17:05.000Z ##

🟠 CVE-2026-100369 - High (8.4)

CliInvoke and its formerly named `AlastairLundy.CliInvoke` package are .NET libraries for invoking command-line programs and wrapping executable processes. `CliInvoke` versions 2.0.0 through 2.8.4, 2.9.0 through 2.9.3, 2.10.0 through 2.10.4, and 3...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100390
(7.4 HIGH)

EPSS: 0.29%

updated 2026-09-25T21:33:12

1 posts

Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their source IP and bypass authorization provider IP-based access controls.

offseq@infosec.exchange at 2026-09-26T01:30:25.000Z ##

CRITICAL vuln: CVE-2026-100390 in tobychui zoraxy (3.2.3 – 3.3.4). IPv6 parsing flaw lets attackers bypass IP-based controls via spoofed X-Forwarded-For headers. Restrict IPv6 or XFF reliance until patch. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026100390 #infosec

##

CVE-2026-10758
(7.5 HIGH)

EPSS: 0.33%

updated 2026-09-25T21:33:12

1 posts

Esri LERC is an open-source image or raster format which supports rapid encoding and decoding for any pixel type. A Heap based Out-of-Bounds Write via Integer Overflow in LERC versions 4.1.0 and earlier may allow a remote, unauthenticated attacker who can pass specifically crafted attacker controlled imagery to an application that uses LERC to crash the application, leading to a denial of service.

thehackerwire@mastodon.social at 2026-09-25T23:46:31.000Z ##

🟠 CVE-2026-10758 - High (7.5)

Esri LERC is an open-source image or raster format which supports rapid encoding and decoding for any pixel type. A Heap based Out-of-Bounds Write via Integer Overflow in LERC versions 4.1.0 and earlier may allow a remote, unauthenticated attacker...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100389
(8.1 HIGH)

EPSS: 0.57%

updated 2026-09-25T21:33:11

2 posts

GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible upload/ticket directory and executed when accessed.

offseq@infosec.exchange at 2026-09-26T10:30:24.000Z ##

GestSup <3.2.61 is vulnerable to CRITICAL RCE (CVE-2026-100389) via IMAP connector. Attackers can send PHP attachments to monitored mailboxes, leading to system compromise. Upgrade to 3.2.61+ ASAP. radar.offseq.com/threat/gestsu #OffSeq #Infosec #RCE #GestSup

##

thehackerwire@mastodon.social at 2026-09-26T00:02:02.000Z ##

🟠 CVE-2026-100389 - High (8.1)

GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100391
(8.2 HIGH)

EPSS: 0.31%

updated 2026-09-25T21:33:11

1 posts

MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing and incomplete destination validation in the d query parameter. Remote attackers can supply arbitrary internal URLs including loopback and cloud metadata endpoints to read full responses from the proxy server.

thehackerwire@mastodon.social at 2026-09-26T00:02:12.000Z ##

🟠 CVE-2026-100391 - High (8.2)

MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing and incomplete destination validation in the d query parameter. Remote attackers can supply arbitrary internal URLs including lo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97063
(9.1 CRITICAL)

EPSS: 0.29%

updated 2026-09-25T21:33:06

1 posts

X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners. Attackers can request codes using known mobile numbers or email addresses, read them from responses, and authenticate as victims via POST /sys/emailOrMobileLogin/login to hijack accounts.

thehackerwire@mastodon.social at 2026-09-26T07:45:31.000Z ##

🔴 CVE-2026-97063 - Critical (9.1)

X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners. Attackers can request codes using known mobile numbers ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100208
(7.5 HIGH)

EPSS: 0.35%

updated 2026-09-25T21:33:06

1 posts

Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-09-26T07:45:22.000Z ##

🟠 CVE-2026-100208 - High (7.5)

Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5267
(7.5 HIGH)

EPSS: 0.36%

updated 2026-09-25T21:17:23.633000

1 posts

Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication. An unauthenticated attacker with network access to the affected service could access the event stream and potentially obtain sensitive information.

thehackerwire@mastodon.social at 2026-09-26T03:17:14.000Z ##

🟠 CVE-2026-5267 - High (7.5)

Ciena Navigator Network
Control Suite (NCS) contains an information exposure vulnerability in an
event-streaming API that does not properly enforce authentication. An
unauthenticated attacker with network access to the affected service could
acces...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100387
(8.1 HIGH)

EPSS: 0.32%

updated 2026-09-25T21:17:22.163000

1 posts

pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that allows authenticated database users to read adjacent heap memory. Attackers can supply crafted pcpatch values with attacker-controlled size fields to copy heap memory into stored patches for exfiltration or crash the PostgreSQL backend.

thehackerwire@mastodon.social at 2026-09-26T00:01:53.000Z ##

🟠 CVE-2026-100387 - High (8.1)

pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that allows authenticated database users to read adjacent heap memory. Attackers can supply crafted pcpatch values with attacker-c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92161
(9.8 CRITICAL)

EPSS: 0.27%

updated 2026-09-25T20:31:30

1 posts

### Impact An unauthenticated account takeover vulnerability exists in `fof/oauth` when the Discord OAuth provider is enabled. Discord allows an account to use an unverified email address when its phone number has been verified. During OAuth authentication, Discord may return that email address with `"verified": false`. Affected versions of `fof/oauth` did not validate this flag and passed the

thehackerwire@mastodon.social at 2026-09-26T08:30:36.000Z ##

🔴 CVE-2026-92161 - Critical (9.8)

FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7.4 and 2.0.0-beta.4, the Discord OAuth provider does not check the verified field returned for an OAuth email before passing th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97064
(9.1 CRITICAL)

EPSS: 0.30%

updated 2026-09-25T19:17:59.427000

1 posts

X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submitting the public master code to the emailOrMobileLogin endpoint with a known email or mobile number.

thehackerwire@mastodon.social at 2026-09-26T07:45:39.000Z ##

🔴 CVE-2026-97064 - Critical (9.1)

X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submitting the public master code to the emailOrMobileL...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67279
(6.5 MEDIUM)

EPSS: 1.03%

updated 2026-09-25T18:32:21

5 posts

RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support

3 repos

https://github.com/HackSpeak/CVE-2026-67279

https://github.com/tc4dy/CVE-2026-67279-86060-Toolkit

https://github.com/gagaltotal/CVE-2026-mikrotik-poc

netsecio@mastodon.social at 2026-09-27T13:41:31.000Z ##

📰 CISA Adds SharePoint, MikroTik Bugs to Known Exploited List

CISA adds two actively exploited vulnerabilities to its KEV catalog: a SharePoint RCE (CVE-2026-65660) and a MikroTik RouterOS flaw (CVE-2026-67279). Federal agencies must patch by Sep 28. Prioritize remediation now! #CyberSecurity #PatchNow #CISA

🔗 cyber.netsecops.io/articles/ci

##

AAKL@infosec.exchange at 2026-09-25T17:13:12.000Z ##

CISA has updated the catalogue.

- CVE-2026-65660: Microsoft SharePoint Code Injection Vulnerability cisa.gov/known-exploited-vulne

- CVE-2026-67279: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability cve.org/CVERecord?id=CVE-2026-

Yesterday:

- CVE-2026-71362: Adobe Commerce and Magento Incorrect Authorization Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-5430: WSO2 Multiple Products Path Traversal Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability #Microsoft #Adobe

##

secdb@infosec.exchange at 2026-09-25T17:00:12.000Z ##

🚨 [CISA-2026:0925] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-65660 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft SharePoint Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SharePoint
- Notes: msrc.microsoft.com/update-guid ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-67279 (secdb.nttzen.cloud/cve/detail/)
- Name: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: mikrotik.com/supportsec/septem ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260925 #cisa20260925 #cve_2026_65660 #cve_2026_67279 #cve202665660 #cve202667279

##

cisakevtracker@mastodon.social at 2026-09-25T16:00:58.000Z ##

CVE ID: CVE-2026-67279
Vendor: MikroTik
Product: RouterOS
Date Added: 2026-09-25
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cR0w@infosec.exchange at 2026-09-25T15:32:09.000Z ##

cisa.gov/news-events/alerts/20

  • CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability

  • CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

##

CVE-2026-65660
(6.5 MEDIUM)

EPSS: 2.10%

updated 2026-09-25T18:32:20

8 posts

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

2 repos

https://github.com/ShadowForge-Cyber/CVE-2026-65660-Poc

https://github.com/HORKimhab/CVE-2026-65660

undercodenews@mastodon.social at 2026-09-27T14:16:01.000Z ##

Microsoft SharePoint Exploit and Citrix NetScaler Zero-Days Put Enterprise Systems on High Alert + Video

Microsoft SharePoint Vulnerability Is Now Being Exploited Microsoft SharePoint vulnerability CVE-2026-65660 has reportedly moved from disclosure into active exploitation, creating a serious security concern for organizations running affected SharePoint environments. The vulnerability reportedly allows a low-privilege authenticated attacker to achieve remote code…

undercodenews.com/microsoft-sh

##

netsecio@mastodon.social at 2026-09-27T13:41:31.000Z ##

📰 CISA Adds SharePoint, MikroTik Bugs to Known Exploited List

CISA adds two actively exploited vulnerabilities to its KEV catalog: a SharePoint RCE (CVE-2026-65660) and a MikroTik RouterOS flaw (CVE-2026-67279). Federal agencies must patch by Sep 28. Prioritize remediation now! #CyberSecurity #PatchNow #CISA

🔗 cyber.netsecops.io/articles/ci

##

AAKL@infosec.exchange at 2026-09-25T17:13:12.000Z ##

CISA has updated the catalogue.

- CVE-2026-65660: Microsoft SharePoint Code Injection Vulnerability cisa.gov/known-exploited-vulne

- CVE-2026-67279: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability cve.org/CVERecord?id=CVE-2026-

Yesterday:

- CVE-2026-71362: Adobe Commerce and Magento Incorrect Authorization Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-5430: WSO2 Multiple Products Path Traversal Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability #Microsoft #Adobe

##

secdb@infosec.exchange at 2026-09-25T17:00:12.000Z ##

🚨 [CISA-2026:0925] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-65660 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft SharePoint Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SharePoint
- Notes: msrc.microsoft.com/update-guid ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-67279 (secdb.nttzen.cloud/cve/detail/)
- Name: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: mikrotik.com/supportsec/septem ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260925 #cisa20260925 #cve_2026_65660 #cve_2026_67279 #cve202665660 #cve202667279

##

cisakevtracker@mastodon.social at 2026-09-25T16:01:14.000Z ##

CVE ID: CVE-2026-65660
Vendor: Microsoft
Product: SharePoint
Date Added: 2026-09-25
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cR0w@infosec.exchange at 2026-09-25T15:32:09.000Z ##

cisa.gov/news-events/alerts/20

  • CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability

  • CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

##

cR0w@infosec.exchange at 2026-09-25T14:24:26.000Z ##

Go hunt on your SharePoint shit.

blog.previdian.com/cve-2026-65

Update September 25th, 2026: The exploitation creates a webshell backdoor named: "/_layouts/15/sphealth.aspx"

##

DailyCyberSecurity@infosec.exchange at 2026-09-25T08:15:27.000Z ##

An exploited SharePoint RCE vulnerability is under attack. Technical details for this SharePoint RCE vulnerability are public. Patch CVE-2026-65660 now.

#SharePoint #CVE202665660 #RCE #Cybersecurity #Infosec #ZeroDay

securityonline.info/exploited-

##

CVE-2026-91841
(7.8 HIGH)

EPSS: 0.19%

updated 2026-09-25T18:31:36

1 posts

A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by injecting a newline character into the CA-File path. This manipulation allows the user to execute arbitrary commands as the root user, leading to local privilege escalation.

thehackerwire@mastodon.social at 2026-09-26T08:15:22.000Z ##

🟠 CVE-2026-91841 - High (7.8)

A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by injecting a newline character into the CA-File path. This manipulation allows the user to execute arbitrary comma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91839
(7.8 HIGH)

EPSS: 0.20%

updated 2026-09-25T18:31:36

1 posts

A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection profile credentials. A local unprivileged user can exploit this by crafting a malicious VPN profile to inject additional configuration directives. This can lead to arbitrary code execution with root p

thehackerwire@mastodon.social at 2026-09-26T08:00:36.000Z ##

🟠 CVE-2026-91839 - High (7.8)

A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection profile credentials. A local unprivileged user ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91838
(7.8 HIGH)

EPSS: 0.10%

updated 2026-09-25T18:31:36

1 posts

A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacters, into VPN connection profile fields such as CA certificate or proxy settings. These unescaped characters are then processed by the `pppd` daemon, which runs with root privileges, allowing the attacke

thehackerwire@mastodon.social at 2026-09-26T08:00:27.000Z ##

🟠 CVE-2026-91838 - High (7.8)

A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacters, into VPN connection profile fields such as CA...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89032
(7.7 HIGH)

EPSS: 0.27%

updated 2026-09-25T18:31:35

1 posts

BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that allows authenticated users to read other tenants' cached responses by exploiting a metadata key mismatch between _get_semantic_cache_tenant_scope() and _get_metadata_variable_name(). Attackers holding a valid virtual key can submit semantically similar prompts on affected routes su

thehackerwire@mastodon.social at 2026-09-26T08:15:39.000Z ##

🟠 CVE-2026-89032 - High (7.7)

BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that allows authenticated users to read other tenants' cached responses by exploiting a metadata key mismatch between _get_semantic_ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94445
(8.8 HIGH)

EPSS: 0.36%

updated 2026-09-25T18:31:35

1 posts

A malicious txtar could escape the intended execution context and force arbitrary writes to the playground host's trusted filesystem. Disjointly, one of the three possible paths to invoke go vet on the playground host did not correctly restrict the execution environment. This permitted a Go process to make a read for an environment configuration file rooted in the playground host's $HOME. To

thehackerwire@mastodon.social at 2026-09-26T08:15:30.000Z ##

🟠 CVE-2026-94445 - High (8.8)

A malicious txtar could escape the intended execution context and force arbitrary writes to the playground host's trusted filesystem.

Disjointly, one of the three possible paths to invoke go vet on the playground host did not correctly restri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91837
(7.8 HIGH)

EPSS: 0.14%

updated 2026-09-25T17:17:18.983000

1 posts

A flaw was found in NetworkManager-iodine, the iodine VPN plugin for NetworkManager. A local unprivileged user can exploit a vulnerability in how the 'nameserver' setting is processed when establishing an iodine VPN connection. By embedding shell metacharacters (special characters that can execute commands) in the 'nameserver' value, an attacker can inject and execute arbitrary commands. These com

thehackerwire@mastodon.social at 2026-09-26T08:30:27.000Z ##

🟠 CVE-2026-91837 - High (7.8)

A flaw was found in NetworkManager-iodine, the iodine VPN plugin for NetworkManager. A local unprivileged user can exploit a vulnerability in how the 'nameserver' setting is processed when establishing an iodine VPN connection. By embedding shell ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92609
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-09-25T15:32:40

1 posts

Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.

DailyCyberSecurity@infosec.exchange at 2026-09-25T13:21:02.000Z ##

New Apache Qpid Broker-J vulnerabilities, including CVE-2026-92609, CVE-2026-92573, and CVE-2026-92564, expose brokers to DoS. Patch immediately.

#ApacheQpid #CVE202692609 #CVE202692573 #AMQP #Cybersecurity #Infosec

securityonline.info/apache-qpi

##

CVE-2026-61825
(8.7 HIGH)

EPSS: 0.22%

updated 2026-09-25T15:00:45

1 posts

### Impact The vulnerability allows an attacker to bypass the HTML sanitizer by using the `data-html-content` attribute in the content of a `SharpEditorFormField`. ### Patches The field must now explicitly configure `SharpFormEditorField::RAW_HTML` in the toolbar to keep this behavior. **When using the `RAW_HTML` button, the application using `code16/sharp` must sanitize manually the content co

thehackerwire@mastodon.social at 2026-09-25T06:16:51.000Z ##

🟠 CVE-2026-61825 - High (8.7)

code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulnerability in `SharpEditorFormField`: attacker-controlled content bearing the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97818
(8.6 HIGH)

EPSS: 0.32%

updated 2026-09-25T14:17:26.837000

1 posts

phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php.

thehackerwire@mastodon.social at 2026-09-25T05:31:07.000Z ##

🟠 CVE-2026-97818 - High (8.6)

phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92573
(6.5 MEDIUM)

EPSS: 0.29%

updated 2026-09-25T14:17:22.150000

1 posts

Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message delivery, message conversion and HTTP management JSON rendering allows authenticated message producers to exhaust memory and disrupt broker availability via processing without a decompressed-output limit. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recomme

DailyCyberSecurity@infosec.exchange at 2026-09-25T13:21:02.000Z ##

New Apache Qpid Broker-J vulnerabilities, including CVE-2026-92609, CVE-2026-92573, and CVE-2026-92564, expose brokers to DoS. Patch immediately.

#ApacheQpid #CVE202692609 #CVE202692573 #AMQP #Cybersecurity #Infosec

securityonline.info/apache-qpi

##

CVE-2026-89426
(8.8 HIGH)

EPSS: 0.47%

updated 2026-09-25T14:17:21.750000

1 posts

The Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.6.1.0. This is due to the `maybe_update_user_role()` function reading the target role directly from an attacker-controlled Gravity Forms entry field — configured via the feed's `user_role_field_id` — and passing it to `WP_User::set_role()`

thehackerwire@mastodon.social at 2026-09-25T08:17:43.000Z ##

🟠 CVE-2026-89426 - High (8.8)

The Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.6.1.0. This is due to the `maybe_update_user_role()` function reading the target rol...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97433
(8.2 HIGH)

EPSS: 0.32%

updated 2026-09-25T13:17:26.930000

1 posts

In the Linux kernel, the following vulnerability has been resolved: nvme: validate FDP configuration descriptor sizes Validate descriptor sizes while walking the FDP configurations log so dsze == 0 or a descriptor past the log end cannot cause unbounded iteration or reads past the buffer.

thehackerwire@mastodon.social at 2026-09-25T06:31:37.000Z ##

🟠 CVE-2026-97433 - High (8.2)

In the Linux kernel, the following vulnerability has been resolved:

nvme: validate FDP configuration descriptor sizes

Validate descriptor sizes while walking the FDP configurations log so
dsze == 0 or a descriptor past the log end cannot cause u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14281
(9.8 CRITICAL)

EPSS: 0.53%

updated 2026-09-25T13:08:26.930000

1 posts

The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.6. This is due to missing permission enforcement on the publicly accessible REST route `POST /wp-json/wawp/v1/signup/<op>` and the absence of a key allowlist in the `finish_registration_logic` function, which

3 repos

https://github.com/murrez/CVE-2026-14281

https://github.com/langz337/CVE-2026-14281

https://github.com/abatsakidis/CVE-2026-14281-check

offseq@infosec.exchange at 2026-09-25T07:30:24.000Z ##

CVE-2026-14281 (CVSS 9.8, CRITICAL) in 101gen Automation Web Platform – Notifications & OTP for WooCommerce (<=4.8.6) allows unauthenticated admin account creation and OTP bypass via REST API. Disable plugin or restrict endpoints now! radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202614281

##

CVE-2026-71362
(9.1 CRITICAL)

EPSS: 87.51%

updated 2026-09-25T12:53:15.757000

1 posts

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

1 repos

https://github.com/dinosn/cve-2026-71362-magento-lab

AAKL@infosec.exchange at 2026-09-25T17:13:12.000Z ##

CISA has updated the catalogue.

- CVE-2026-65660: Microsoft SharePoint Code Injection Vulnerability cisa.gov/known-exploited-vulne

- CVE-2026-67279: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability cve.org/CVERecord?id=CVE-2026-

Yesterday:

- CVE-2026-71362: Adobe Commerce and Magento Incorrect Authorization Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-5430: WSO2 Multiple Products Path Traversal Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability #Microsoft #Adobe

##

CVE-2026-92564(CVSS UNKNOWN)

EPSS: 0.19%

updated 2026-09-25T09:31:16

1 posts

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.

DailyCyberSecurity@infosec.exchange at 2026-09-25T13:21:02.000Z ##

New Apache Qpid Broker-J vulnerabilities, including CVE-2026-92609, CVE-2026-92573, and CVE-2026-92564, expose brokers to DoS. Patch immediately.

#ApacheQpid #CVE202692609 #CVE202692573 #AMQP #Cybersecurity #Infosec

securityonline.info/apache-qpi

##

CVE-2026-89406
(7.5 HIGH)

EPSS: 0.39%

updated 2026-09-25T09:31:16

1 posts

The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized disclosure of private gallery contents in versions up to, and including, 3.0.1. This is due to the Modula_Meta::add_metas() function being hooked to wp_head on every frontend request and looking up any post via get_post( $_GET['modula_gallery_id'] ) without verifying the gallery's post_status o

thehackerwire@mastodon.social at 2026-09-25T08:17:25.000Z ##

🟠 CVE-2026-89406 - High (7.5)

The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized disclosure of private gallery contents in versions up to, and including, 3.0.1. This is due to the Modula_Meta::add_metas() function being h...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93399
(9.1 CRITICAL)

EPSS: 0.37%

updated 2026-09-25T09:31:15

2 posts

The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and 'bookly_rollback_order' AJAX actions. This is due to the 'bookly_get_form_id' handler blindly storing the attacker-controlled 'order_id' from the submitted form_data into a new booking session,

2 repos

https://github.com/murrez/CVE-2026-93399

https://github.com/josemour8/CVE-2026-93399

offseq@infosec.exchange at 2026-09-25T10:30:25.000Z ##

CVE-2026-93399 (CRITICAL): Bookly WordPress plugin (≤28.2) lets unauth'd attackers enumerate, access, and delete bookings via auth bypass in AJAX actions. No patch. Restrict plugin endpoints & monitor for abuse. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #Cybersecurity

##

thehackerwire@mastodon.social at 2026-09-25T07:18:04.000Z ##

🔴 CVE-2026-93399 - Critical (9.1)

The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and 'bookly_rollback_order' AJAX actions. Thi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19804
(8.8 HIGH)

EPSS: 1.04%

updated 2026-09-25T09:31:15

1 posts

The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 260814 via the 'first_name' parameter parameter. This is due to insufficient sanitization of the first_name parameter via esc_refs(), which strips only regex backreferences and not PHP tag

thehackerwire@mastodon.social at 2026-09-25T08:17:16.000Z ##

🟠 CVE-2026-19804 - High (8.8)

The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 260814 via the 'first_name' param...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92713
(8.1 HIGH)

EPSS: 0.27%

updated 2026-09-25T09:31:15

1 posts

The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_image function in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers, with author-level access and above, to delete arbitrary files on the server. The path restriction to wp-content/uploa

thehackerwire@mastodon.social at 2026-09-25T08:17:07.000Z ##

🟠 CVE-2026-92713 - High (8.1)

The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_image function in all versions up to, and including, 3.0.2. This makes it ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89055
(9.1 CRITICAL)

EPSS: 0.39%

updated 2026-09-25T09:31:14

2 posts

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete arbitrary attachments from the Media Library — including administrator-owned product

1 repos

https://github.com/murrez/CVE-2026-89055

offseq@infosec.exchange at 2026-09-25T12:00:26.000Z ##

CVE-2026-89055 (CRITICAL, CVSS 9.1): Customer Reviews for WooCommerce <=5.120.0 lets unauthenticated attackers delete arbitrary media via public review-form links. Restrict link access, monitor suspicious review activity. radar.offseq.com/threat/cve-20 #OffSeq #CVE202689055 #WordPress #Infosec

##

thehackerwire@mastodon.social at 2026-09-25T07:18:13.000Z ##

🔴 CVE-2026-89055 - Critical (9.1)

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This ma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62062
(8.8 HIGH)

EPSS: 0.13%

updated 2026-09-25T09:31:05

2 posts

Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This issue affects Elementor Website Builder: from n/a through 4.3.1.

1 repos

https://github.com/abraxas/CVE-2026-62062

guru@thecybersecguru.com at 2026-09-26T17:58:21.000Z ##

Critical Elementor CSRF Flaw Exposes 2 Million WordPress Sites to Full Takeover

Elementor CVE-2026-62062 is a CVSS 8.8 CSRF flaw affecting versions 4.3.0 and 4.3.1. Update to 4.3.2 to block the attack

thecybersecguru.com/news/eleme

##

thehackerwire@mastodon.social at 2026-09-25T07:18:22.000Z ##

🟠 CVE-2026-62062 - High (8.8)

Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery.

This issue affects Elementor Website Builder: from n/a through 4.3.1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97428
(7.7 HIGH)

EPSS: 0.14%

updated 2026-09-25T06:31:36

1 posts

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: harden FRU PIA parsing with bounded helpers Replace the open-coded TLV walk with fru_pia_advance() and fru_pia_copy_field() helpers that bound every read by the actual EEPROM data length, preventing out-of-bounds reads on truncated or malformed FRU data.

thehackerwire@mastodon.social at 2026-09-25T06:31:46.000Z ##

🟠 CVE-2026-97428 - High (7.7)

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: harden FRU PIA parsing with bounded helpers

Replace the open-coded TLV walk with fru_pia_advance()
and fru_pia_copy_field() helpers that bound every read
by the actu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97444
(7.7 HIGH)

EPSS: 0.14%

updated 2026-09-25T06:31:36

1 posts

In the Linux kernel, the following vulnerability has been resolved: ACPICA: add boundary checks in two places Add boundary checks in acpi_ps_get_next_namestring() and acpi_ps_peek_opcode() to prevent out-of-bounds access.

thehackerwire@mastodon.social at 2026-09-25T06:16:28.000Z ##

🟠 CVE-2026-97444 - High (7.7)

In the Linux kernel, the following vulnerability has been resolved:

ACPICA: add boundary checks in two places

Add boundary checks in acpi_ps_get_next_namestring() and
acpi_ps_peek_opcode() to prevent out-of-bounds access.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97450
(8.4 HIGH)

EPSS: 0.14%

updated 2026-09-25T06:31:35

1 posts

In the Linux kernel, the following vulnerability has been resolved: ACPICA: validate handler object type in two places ACPICA: validate handler object type in acpi_ev_has_default_handler() and acpi_ev_find_region_handler().

thehackerwire@mastodon.social at 2026-09-25T06:01:44.000Z ##

🟠 CVE-2026-97450 - High (8.4)

In the Linux kernel, the following vulnerability has been resolved:

ACPICA: validate handler object type in two places

ACPICA: validate handler object type in acpi_ev_has_default_handler()
and acpi_ev_find_region_handler().

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97448
(7.7 HIGH)

EPSS: 0.14%

updated 2026-09-25T06:31:35

1 posts

In the Linux kernel, the following vulnerability has been resolved: ACPICA: Add validation for node in acpi_ns_build_normalized_path() Add validation for node in acpi_ns_build_normalized_path() to prevent use-after-free vulnerabilities.

thehackerwire@mastodon.social at 2026-09-25T05:48:59.000Z ##

🟠 CVE-2026-97448 - High (7.7)

In the Linux kernel, the following vulnerability has been resolved:

ACPICA: Add validation for node in acpi_ns_build_normalized_path()

Add validation for node in acpi_ns_build_normalized_path()
to prevent use-after-free vulnerabilities.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97509
(8.8 HIGH)

EPSS: 0.24%

updated 2026-09-25T06:31:35

1 posts

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Keep XDomain reference during the lifetime of a service This is needed because we release the service ID in tb_service_release() and the ID array is owned by the parent XDomain.

thehackerwire@mastodon.social at 2026-09-25T05:46:16.000Z ##

🟠 CVE-2026-97509 - High (8.8)

In the Linux kernel, the following vulnerability has been resolved:

thunderbolt: Keep XDomain reference during the lifetime of a service

This is needed because we release the service ID in tb_service_release()
and the ID array is owned by the pa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97508
(7.5 HIGH)

EPSS: 0.21%

updated 2026-09-25T06:31:35

1 posts

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Set tb->root_switch to NULL when domain is stopped Similarly what we do with the firmware connection manager. This makes tb_xdp_handle_request() return error to the remote host. However, we need to make sure we keep the uuid alive so that we can reply until the whole domain is released.

thehackerwire@mastodon.social at 2026-09-25T05:46:07.000Z ##

🟠 CVE-2026-97508 - High (7.5)

In the Linux kernel, the following vulnerability has been resolved:

thunderbolt: Set tb->root_switch to NULL when domain is stopped

Similarly what we do with the firmware connection manager. This makes
tb_xdp_handle_request() return error to the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97445
(7.7 HIGH)

EPSS: 0.15%

updated 2026-09-25T06:31:34

1 posts

In the Linux kernel, the following vulnerability has been resolved: ACPICA: Enhance buffer validation in acpi_ut_walk_aml_resources() Enhance buffer validation in acpi_ut_walk_aml_resources() to prevent buffer overflows.

thehackerwire@mastodon.social at 2026-09-25T06:31:28.000Z ##

🟠 CVE-2026-97445 - High (7.7)

In the Linux kernel, the following vulnerability has been resolved:

ACPICA: Enhance buffer validation in acpi_ut_walk_aml_resources()

Enhance buffer validation in acpi_ut_walk_aml_resources() to prevent
buffer overflows.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97442
(8.8 HIGH)

EPSS: 0.24%

updated 2026-09-25T06:31:34

1 posts

In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi In certain cases, hardware might provide packets with a length greater than the maximum native Wi-Fi header length. This can lead to accessing and modifying fields in the header within the ath11k_dp_rx_h_undecap_nwifi() function for the DP_RX_DECAP_TYPE_NATIVE

thehackerwire@mastodon.social at 2026-09-25T06:03:54.000Z ##

🟠 CVE-2026-97442 - High (8.8)

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi

In certain cases, hardware might provide packets with a
length greater than the maximum native Wi-Fi header...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97452
(8.4 HIGH)

EPSS: 0.14%

updated 2026-09-25T06:31:34

1 posts

In the Linux kernel, the following vulnerability has been resolved: ACPICA: Prevent adding invalid references Prevent adding references for local, argument, and debug objects in acpi_ut_copy_simple_object().

thehackerwire@mastodon.social at 2026-09-25T06:02:03.000Z ##

🟠 CVE-2026-97452 - High (8.4)

In the Linux kernel, the following vulnerability has been resolved:

ACPICA: Prevent adding invalid references

Prevent adding references for local, argument, and debug objects
in acpi_ut_copy_simple_object().

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97478
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-25T06:31:34

1 posts

In the Linux kernel, the following vulnerability has been resolved: virt: acrn: Fix irqfd use-after-free during eventfd shutdown acrn_irqfd_deassign() and the eventfd EPOLLHUP wakeup can race and free the same struct hsm_irqfd: CPU0 CPU1 ---- ---- eventfd_release() wake_up_poll(EPOLLHUP) hsm_irqfd_wakeup() q

thehackerwire@mastodon.social at 2026-09-25T05:48:50.000Z ##

🟠 CVE-2026-97478 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

virt: acrn: Fix irqfd use-after-free during eventfd shutdown

acrn_irqfd_deassign() and the eventfd EPOLLHUP wakeup can race and free
the same struct hsm_irqfd:

CPU0 ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97454
(7.7 HIGH)

EPSS: 0.14%

updated 2026-09-25T06:31:19

1 posts

In the Linux kernel, the following vulnerability has been resolved: ACPICA: add boundary checks in acpi_ps_get_next_field() Add boundary checks in acpi_ps_get_next_field() to prevent out-of-bounds access.

thehackerwire@mastodon.social at 2026-09-25T06:03:37.000Z ##

🟠 CVE-2026-97454 - High (7.7)

In the Linux kernel, the following vulnerability has been resolved:

ACPICA: add boundary checks in acpi_ps_get_next_field()

Add boundary checks in acpi_ps_get_next_field() to prevent out-of-bounds
access.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97513
(7.8 HIGH)

EPSS: 0.11%

updated 2026-09-25T05:17:07.540000

1 posts

In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Release m2m_ctx after Instance Removed from List Possible use after free if IRQ thread manages to obtain spinlock between m2m_ctx release and wave5_release function removing stream instance from list of active instances. The IRQ thread looks for the m2m_ctx which is freed so null pointer dereference oc

thehackerwire@mastodon.social at 2026-09-25T05:45:57.000Z ##

🟠 CVE-2026-97513 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

media: chips-media: wave5: Release m2m_ctx after Instance Removed from List

Possible use after free if IRQ thread manages to obtain spinlock between
m2m_ctx release and wave5_re...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97497
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-25T05:17:07.180000

1 posts

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Check bounds for allocate_sdma_queue restore_sdma_id allocate_sdma_queue has an option where the sdma queue id can be specified (used by CRIU). We weren't bounds-checking that value. Confirm it's less than the maximum number of queues.

thehackerwire@mastodon.social at 2026-09-25T05:48:41.000Z ##

🟠 CVE-2026-97497 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: Check bounds for allocate_sdma_queue restore_sdma_id

allocate_sdma_queue has an option where the sdma queue id can be
specified (used by CRIU). We weren't bounds-che...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97455
(8.4 HIGH)

EPSS: 0.14%

updated 2026-09-25T05:17:06.673000

1 posts

In the Linux kernel, the following vulnerability has been resolved: ACPICA: Fix use-after-free in acpi_ds_terminate_control_method() Fix use-after-free issue in acpi_ds_terminate_control_method() by clearing references to method locals and arguments.

thehackerwire@mastodon.social at 2026-09-25T06:03:46.000Z ##

🟠 CVE-2026-97455 - High (8.4)

In the Linux kernel, the following vulnerability has been resolved:

ACPICA: Fix use-after-free in acpi_ds_terminate_control_method()

Fix use-after-free issue in acpi_ds_terminate_control_method() by
clearing references to method locals and argum...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97451
(8.4 HIGH)

EPSS: 0.14%

updated 2026-09-25T05:17:06.323000

1 posts

In the Linux kernel, the following vulnerability has been resolved: ACPICA: Fix integer overflow in acpi_ex_opcode_3A_1T_1R() (mid_op) Add overflow check for Index + Length to prevent integer overflow when calculating the truncation length. This prevents negative size parameter being passed to memcpy().

thehackerwire@mastodon.social at 2026-09-25T06:01:53.000Z ##

🟠 CVE-2026-97451 - High (8.4)

In the Linux kernel, the following vulnerability has been resolved:

ACPICA: Fix integer overflow in acpi_ex_opcode_3A_1T_1R() (mid_op)

Add overflow check for Index + Length to prevent integer overflow
when calculating the truncation length. This...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89078
(9.9 CRITICAL)

EPSS: 0.36%

updated 2026-09-25T04:17:48.843000

1 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to a double free issue when parsing a specially crafted regular expression in a CI/CD configuration.

beyondmachines1@infosec.exchange at 2026-09-26T10:01:12.000Z ##

GitLab Patches Critical Regex Flaws Allowing Remote Code Execution

GitLab released emergency patches for 11 vulnerabilities, including two critical regex-related flaws (CVE-2026-89078 and CVE-2026-93577) that allow authenticated attackers to execute arbitrary code on self-managed servers.

**If you run your own GitLab server, update it to version 19.4.1, 19.3.3, or 19.2.7. Two critical flaws allow any logged-in user take over the whole server. After updating, check your .gitlab-ci.yml files for new or strange-looking regular expressions, and review who has access to your projects in case someone already tried to exploit this. GitLab.com and GitLab Dedicated users don't need to do anything.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-48842
(8.1 HIGH)

EPSS: 0.89%

updated 2026-09-25T04:17:35.357000

3 posts

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

2 repos

https://github.com/murrez/CVE-2026-48842

https://github.com/4minx/CVE-2026-48842

DarkWebInformer@infosec.exchange at 2026-09-25T18:36:27.000Z ##

🚨 Roundcube SQL injection flaw actively exploited months after patches were released

The Canadian Centre for Cyber Security has warned that CVE-2026-48842, a high-severity vulnerability in Roundcube Webmail, is being exploited in the wild.
⠀
Roundcube is an open-source webmail application that lets people access email through a browser.

The flaw affects its virtuser_query plugin and allows SQL injection before authentication.
⠀
Key details:

• CVSS score: 8.1
• No attacker credentials required
• No user interaction required
• Affects Roundcube 1.6.x before 1.6.16 and 1.7.x before 1.7.1
⠀
Roundcube released the original fixes on May 24, 2026. Canada added the exploitation warning to its advisory on September 21, citing open-source reporting.

The advisory does not identify the attackers, victims or scale of exploitation.
⠀
Administrators should update affected installations promptly. Newer security releases, 1.6.19 and 1.7.4, also address additional vulnerabilities.

Source: cyber.gc.ca/en/alerts-advisori

##

cyberworldops@infosec.exchange at 2026-09-25T11:10:01.000Z ##

Canadian Centre for Cyber Security warns CVE-2026-48842, a pre-auth SQL injection in Roundcube Webmail virtuser_query plugin, is actively exploited. Unauthenticated preg_replace escape bypass affects 1.6.x before 1.6.16 and 1.7.x before 1.7.1, enabling backend DB compromise. #Roundcube #SqlInjection #InfoSec

cyberworldops.eu/en/active-rou

##

DailyCyberSecurity@infosec.exchange at 2026-09-25T09:57:33.000Z ##

Learn how hackers are exploiting the CVE-2026-48842 Roundcube SQL injection vulnerability. Understand the risk and how to patch your webmail server immediately.

#Roundcube #CyberSecurity #SQLInjection #DataBreach #TechNews

meterpreter.org/roundcube-webm

##

CVE-2026-81473
(8.1 HIGH)

EPSS: 0.09%

updated 2026-09-24T21:32:59

1 posts

Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

thehackerwire@mastodon.social at 2026-09-25T05:31:57.000Z ##

🟠 CVE-2026-81473 - High (8.1)

Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89325
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-24T21:32:58

1 posts

An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as SYSTEM via a planted executable resolved from the machine PATH. Assessment content at or below version 0.0.261.0 included a check that invoked the `code` command without a fully qualified path from a process running as SYSTEM. The

thehackerwire@mastodon.social at 2026-09-25T05:16:37.000Z ##

🟠 CVE-2026-89325 - High (7.8)

An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as SYSTEM via a planted executable resolved from the machine PATH.

Assessment con...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13248
(8.8 HIGH)

EPSS: 0.44%

updated 2026-09-24T21:32:57

1 posts

An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows an authenticated user with access to the admin or itadmin account to submit commands written in the Intermec Fingerprint programming language directly to the printer ’s internal

thehackerwire@mastodon.social at 2026-09-25T06:46:16.000Z ##

🟠 CVE-2026-13248 - High (8.8)

An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows an authenticated use...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13249
(9.8 CRITICAL)

EPSS: 0.57%

updated 2026-09-24T21:32:57

1 posts

An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker controlled files without requiring authentication. An attacker could potentially exploit this vulnerability, leading to the execution of malicious files and commands. Honeywell also recommends updati

1 repos

https://github.com/murrez/CVE-2026-13249

thehackerwire@mastodon.social at 2026-09-25T06:17:09.000Z ##

🔴 CVE-2026-13249 - Critical (9.8)

An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker controlled files without requiring authenticatio...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81455
(8.6 HIGH)

EPSS: 0.26%

updated 2026-09-24T21:32:57

1 posts

Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

thehackerwire@mastodon.social at 2026-09-25T05:31:48.000Z ##

🟠 CVE-2026-81455 - High (8.6)

Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unautho...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5430
(10.0 CRITICAL)

EPSS: 0.59%

updated 2026-09-24T21:32:26

3 posts

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of adm

2 repos

https://github.com/abraxas/CVE-2026-5430

https://github.com/HORKimhab/CVE-2026-5430

gtronix@infosec.exchange at 2026-09-25T18:01:28.000Z ##

"CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks"

"[...] The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2."

bleepingcomputer.com/news/secu

#Cybersecurity

##

AAKL@infosec.exchange at 2026-09-25T17:13:12.000Z ##

CISA has updated the catalogue.

- CVE-2026-65660: Microsoft SharePoint Code Injection Vulnerability cisa.gov/known-exploited-vulne

- CVE-2026-67279: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability cve.org/CVERecord?id=CVE-2026-

Yesterday:

- CVE-2026-71362: Adobe Commerce and Magento Incorrect Authorization Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-5430: WSO2 Multiple Products Path Traversal Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability #Microsoft #Adobe

##

thecybermind@infosec.exchange at 2026-09-25T13:00:16.000Z ##

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-5430 – WSO2 Multiple Products Path Traversal Vulnerability

Analyze the technical mechanics of CVE-2026-5430 with our WSO2 TSUITE brief, covering directory traversal vectors, unrestricted file uploads, and endpoint hardening....

thecybermind.co/bg2r

##

CVE-2026-28324
(9.8 CRITICAL)

EPSS: 0.65%

updated 2026-09-24T21:00:46.893000

1 posts

SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected.

DailyCyberSecurity@infosec.exchange at 2026-09-26T02:59:37.000Z ##

SolarWinds Critical Vulnerability: RCE Flaw Patched

#SolarWinds #Vulnerability #Cybersecurity #CVE202628324 #InfoSec A monitoring system engineered to oversee corporate infrastructure can inadvertently pave the way for an attacker to breach the network. SolarWinds has rectified a critical vulnerability within Observability Self-Hosted that permitted unauthenticated remote code execution. Tracked as CVE-2026-28324, this flaw achieved a staggering CVSS severity score of 9.8 out of 10. Exploitation requires neither system privileges nor user interaction, and the attack complexity is deemed low.

dailytechnow.com/solarwinds-cr

##

CVE-2026-61816
(7.5 HIGH)

EPSS: 0.39%

updated 2026-09-24T19:45:08

1 posts

### Impact An uncontrolled resource consumption / algorithmic complexity vulnerability affecting any application that parses untrusted email with this library. Three independent parsing paths are super-linear in cost, so a byte-size cap on the caller side does **not** bound the work done. A crafted message under 2 MB can consume seconds of CPU or hundreds of megabytes to multiple gigabytes of m

thehackerwire@mastodon.social at 2026-09-25T08:02:07.000Z ##

🟠 CVE-2026-61816 - High (7.5)

zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading messages in Internet Message Format RFC 822. Starting in version 2.0.0 and prior to version 3.0.6 and 4.0.2, an uncontrolled resour...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61741
(9.3 CRITICAL)

EPSS: 0.29%

updated 2026-09-24T19:35:18

1 posts

http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. These decoders used a `javax.xml.parsers.SAXParserFactory` obtained from `SAXParserFactory.newInstance` without any security configuration. With the JDK's default settings, the parser resolves DOCTYPE declarations, external general and parameter entities, and external DTDs. An application that u

thehackerwire@mastodon.social at 2026-09-25T08:02:17.000Z ##

🔴 CVE-2026-61741 - Critical (9.3)

http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. Prior to versions 0.24.1 and 1.0.0-M39, these decoders used a `javax.xml.parsers.SAXParserFactory` obtained from `SAXParserFactory.newInstance` w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75907
(7.5 HIGH)

EPSS: 0.36%

updated 2026-09-24T19:17:16.220000

1 posts

The door access control on a Norwegian Cruise Line asset grants entry based only on the credential's static 7-byte UID stored on an NTAG212 NFC chip. A UID is a manufacturer serial number sent in the clear on every read and is not intended to be secret or to authenticate the holder. Validating on the UID of the NTAG212 NFC chip alone is identification, not authentication, and the credential has no

CVE-2026-57440
(7.5 HIGH)

EPSS: 0.26%

updated 2026-09-24T19:17:14.630000

1 posts

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with $wgEmbedVideoRequireConsent disabled (not the default), the urls for videos are passed into an iframe src attribute without sanitization. When given a malformed url or id, the src attribute can be escap

thehackerwire@mastodon.social at 2026-09-25T06:17:01.000Z ##

🟠 CVE-2026-57440 - High (7.5)

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with $wgEmbedVideoRequireConsent disabled (not the def...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-95985
(8.8 HIGH)

EPSS: 0.14%

updated 2026-09-24T18:31:48

1 posts

The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message can cause agent modifications to auto-loaded global configuration paths. We recommend you upgrade to Kiro IDE version 1.0.242 or later. U

thehackerwire@mastodon.social at 2026-09-25T06:46:24.000Z ##

🟠 CVE-2026-95985 - High (8.8)

The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85057
(8.7 HIGH)

EPSS: 0.39%

updated 2026-09-24T18:19:34

1 posts

### Summary A vulnerability in ZITADEL Actions V1 allows an organization Action author to read files from the ZITADEL host filesystem through the JavaScript `require()` module loader. On common self-hosted deployments this can be chained to steal bootstrap credentials (including the Login Client PAT) and escalate from a single-tenant organization owner to instance administrator. ### Impact ZITA

thehackerwire@mastodon.social at 2026-09-25T07:02:02.000Z ##

🟠 CVE-2026-85057 - High (8.7)

ZITADEL is an open source identity management platform. From 3.0.0 until 3.4.13 and 4.16.1, ZITADEL Actions V1 enables the goja Node-compatible require() registry without restricting its filesystem source loader. An organization Action author with...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85056
(8.2 HIGH)

EPSS: 0.29%

updated 2026-09-24T18:19:04.180000

1 posts

ZITADEL is an open source identity management platform. From 4.0.0 until 4.16.1, ZITADEL Login V2 creates a browser session after password verification and can reuse that session for a later authentication request without verifying a user's enrolled TOTP, OTP, or U2F second factor. When the MFA step is abandoned and login starts again, session-validity checks require MFA only when the organization

thehackerwire@mastodon.social at 2026-09-25T06:46:34.000Z ##

🟠 CVE-2026-85056 - High (8.2)

ZITADEL is an open source identity management platform. From 4.0.0 until 4.16.1, ZITADEL Login V2 creates a browser session after password verification and can reuse that session for a later authentication request without verifying a user's enroll...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61782
(7.5 HIGH)

EPSS: 0.36%

updated 2026-09-24T18:17:16.333000

1 posts

Rsdoctor is a build analyzer tailored for projects built with Rspack. Prior to version 1.5.16, the default Rsdoctor report HTTP server started by `@rsdoctor/rspack-plugin` binds to all network interfaces (`0.0.0.0`) and serves a `POST /api/data/key` endpoint with no authentication and wildcard CORS (`Access-Control-Allow-Origin: *`). Any network-adjacent or remote attacker can send a single unauth

thehackerwire@mastodon.social at 2026-09-25T08:02:26.000Z ##

🟠 CVE-2026-61782 - High (7.5)

Rsdoctor is a build analyzer tailored for projects built with Rspack. Prior to version 1.5.16, the default Rsdoctor report HTTP server started by `@rsdoctor/rspack-plugin` binds to all network interfaces (`0.0.0.0`) and serves a `POST /api/data/ke...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93577
(9.9 CRITICAL)

EPSS: 0.43%

updated 2026-09-24T00:30:34

1 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to an integer overflow issue when compiling a specially crafted regular expression in a CI/CD configuration.

beyondmachines1@infosec.exchange at 2026-09-26T10:01:12.000Z ##

GitLab Patches Critical Regex Flaws Allowing Remote Code Execution

GitLab released emergency patches for 11 vulnerabilities, including two critical regex-related flaws (CVE-2026-89078 and CVE-2026-93577) that allow authenticated attackers to execute arbitrary code on self-managed servers.

**If you run your own GitLab server, update it to version 19.4.1, 19.3.3, or 19.2.7. Two critical flaws allow any logged-in user take over the whole server. After updating, check your .gitlab-ci.yml files for new or strange-looking regular expressions, and review who has access to your projects in case someone already tried to exploit this. GitLab.com and GitLab Dedicated users don't need to do anything.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-94127
(9.8 CRITICAL)

EPSS: 2.23%

updated 2026-09-22T21:31:17

2 posts

When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software version

2 repos

https://github.com/watchtowrlabs/watchTowr-vs-f5-bigip-PreAuth-RCE-CVE-2026-94127

https://github.com/FurkanKAYAPINAR/CVE-2026-94127

DailyCyberSecurity@infosec.exchange at 2026-09-25T12:53:34.000Z ##

Discover the critical F5 BIG-IP zero-day vulnerability CVE-2026-94127. Learn why CISA demands immediate patching for this actively exploited APM flaw.

#F5BIGIP #ZeroDay #CISA #CyberSecurity #TechNews

meterpreter.org/f5-big-ip-zero

##

ulldma@infosec.exchange at 2026-09-25T12:46:04.000Z ##

Love the energy 😅

>Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)

labs.watchtowr.com/is-this-a-j

##

CVE-2026-93616
(9.8 CRITICAL)

EPSS: 19.65%

updated 2026-09-22T21:31:15

1 posts

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

1 repos

https://github.com/WadesWeaponShed/CVE-2026-93616_Checks

thecybermind@infosec.exchange at 2026-09-26T12:27:03.000Z ##

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-93616 – Check Point Multiple Products Path Traversal Vulnerability

Analyze the technical mechanics of CVE-2026-93616 with our Check Point TSUITE brief, covering management server path traversal, remote code execution, and endpoint hardening....

thecybermind.co/1yot

##

CVE-2026-85102
(9.8 CRITICAL)

EPSS: 0.99%

updated 2026-09-22T21:30:40

1 posts

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

thecybermind@infosec.exchange at 2026-09-26T10:59:17.000Z ##

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-85102 – Check Point Multiple Products Improper Certificate Validation Vulnerability

Analyze the technical mechanics of CVE-2026-85102 with our Check Point TSUITE brief, covering VPN certificate trust validation bypass, multi-platform SIEM queries, and gateway hardening....

thecybermind.co/x9a1

##

CVE-2026-93854
(0 None)

EPSS: 0.41%

updated 2026-09-22T19:56:19.073000

1 posts

In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id} and DELETE /v2/leases/{lease_id}). The policy authorize() wrapper attempts to load the target lease to build the authorization target from its owner, but it looks up the lease under the keyword "lease_id" whereas the controller methods name

hugovalters@mastodon.social at 2026-09-27T06:10:02.000Z ##

CVE-2026-93854: OpenStack Blazar before 17.0.1 lets any authenticated user update or delete leases they do not own due to a broken authorization lookup. No CVSS or patch yet. Restrict Blazar API access now. valtersit.com/cve/CVE-2026-938 #CVE #infosec #OpenStack

##

CVE-2026-93579
(6.5 MEDIUM)

EPSS: 0.58%

updated 2026-09-22T18:34:29

1 posts

A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, such as NUL, Line Feed, and Carriage Return, into HTTP/2 header field values due to insufficient validation. When these values cross an HTTP/2 to HTTP/1.1 translation boundary, they can be exploited for request smuggling, header injection, or response splitting. This could lead to

hugovalters@mastodon.social at 2026-09-27T12:20:39.000Z ##

CVE-2026-93579: Netty HTTP/2 header validation flaw enables request smuggling and header injection via NUL/LF/CR chars. CVSS 6.5, no patch yet. Audit your HTTP/2 proxies. valtersit.com/cve/CVE-2026-935 #CVE #infosec #Netty

##

CVE-2026-93871
(5.4 MEDIUM)

EPSS: 0.27%

updated 2026-09-18T21:32:44

1 posts

Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or edit permissions to store redirects to arbitrary external hosts. Attackers can craft pages on trusted domains that redirect visitors to malicious sites for phishing attacks without administrative privileges.

hugovalters@mastodon.social at 2026-09-27T03:00:07.000Z ##

CVE-2026-93871 Cotonti through 1.0.0 open redirect lets authenticated page editors store redirects to malicious hosts for phishing. CVSS 5.4, no patch yet. Restrict page permissions now. valtersit.com/cve/CVE-2026-938 #CVE #infosec #cybersecurity

##

CVE-2026-82890
(5.9 MEDIUM)

EPSS: 0.32%

updated 2026-09-18T21:32:36

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary JavaScript code due to improper neutralization of input during web page generation.

hugovalters@mastodon.social at 2026-09-27T14:00:25.000Z ##

CVE-2026-82890 IBM Guardium Data Protection 12.2 allows remote authenticated attackers to execute arbitrary JavaScript via improper input neutralization. CVSS 5.9, patch status unknown. Review and update immediately. valtersit.com/cve/CVE-2026-828 #CVE #infosec #IBM

##

hugovalters@mastodon.social at 2026-09-27T14:00:25.000Z ##

CVE-2026-82890 IBM Guardium Data Protection 12.2 allows remote authenticated attackers to execute arbitrary JavaScript via improper input neutralization. CVSS 5.9, patch status unknown. Review and update immediately. valtersit.com/cve/CVE-2026-828 #CVE #infosec #IBM

##

CVE-2026-11722
(4.8 MEDIUM)

EPSS: 0.18%

updated 2026-09-18T21:32:27

1 posts

IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.

hugovalters@mastodon.social at 2026-09-27T04:30:42.000Z ##

CVE-2026-11722: IBM WebSphere HTTP request smuggling, CVSS 4.8, patch status unknown. Update immediately. valtersit.com/cve/CVE-2026-117 #CVE #infosec #IBM

##

CVE-2026-93432
(6.1 MEDIUM)

EPSS: 0.42%

updated 2026-09-18T20:17:32.267000

1 posts

A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails to pass the parent template's content type information. This bypasses standard escaping mechanisms, allowing untrusted data to be output as raw, unescaped text. This vulnerability can lead to Cross-Site Scripting (XSS) and JSON Injection, potentially allowing a remote attacker t

hugovalters@mastodon.social at 2026-09-27T01:10:16.000Z ##

CVE-2026-93432: Quarkus Qute XSS/JSON injection via eval sub-templates. CVSS 6.1, no patch yet. Audit your templates and watch for updates. valtersit.com/cve/CVE-2026-934 #CVE #infosec #Quarkus

##

CVE-2026-93751
(6.5 MEDIUM)

EPSS: 0.40%

updated 2026-09-18T18:32:05

1 posts

uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass platform decoder validation and inject path traversal or CRLF sequences that downstream consumers process without filtering.

hugovalters@mastodon.social at 2026-09-27T09:11:04.000Z ##

CVE-2026-93751 uri-js path traversal via improper UTF-8 decoding, CVSS 6.5, no patch yet. Update dependencies immediately. valtersit.com/cve/CVE-2026-937 #CVE #infosec #cybersecurity

##

CVE-2026-77608
(6.1 MEDIUM)

EPSS: 0.26%

updated 2026-09-18T16:42:52

1 posts

#### Failure mode The `value` parameter was reflected back into rendered output and error messaging paths without enough output-context encoding. #### Remediation - The form value is escaped before it is placed back into the input field. - Derived error messages are also escaped before being rendered into HTML. #### Maintenance note Do not treat error text as trusted just because it originate

hugovalters@mastodon.social at 2026-09-27T10:50:23.000Z ##

CVE-2026-77608 Semantic MediaWiki reflected XSS before 7.2.0, CVSS 6.1, no patch confirmed. Update to 7.2.0 now. valtersit.com/cve/CVE-2026-776 #CVE #infosec #MediaWiki

##

CVE-2025-39964
(3.3 LOW)

EPSS: 1.00%

updated 2026-09-18T15:31:06

2 posts

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates

2 repos

https://github.com/n1k0oowang/CVE-2025-39964_EXP

https://github.com/suominen/CVE-2025-39964

sayzard@mastodon.sayzard.org at 2026-09-27T07:40:08.000Z ##

I Found a $113,337 Af_alg Linux Local Privilege Escalation Before Copy Fail

CVE-2025-39964는 Linux 커널 AF_ALG의 공유 소켓 동시 `sendmsg()` 처리에서 발생하는 레이스 컨디션으로, `ctx->merge`와 scatterlist 상태 불일치가 `sg[-1]` 접근으로 이어진다. 연구자는 선행 힙 객체의 제어 가능한 메타데이터를 이용해 usercopy 오라클과 임의 커널 쓰기를 만들고, `core_pattern` 덮어쓰기를 통해 일반 사용자 권한 상승 및 Docker 컨테이너 탈출을 시연했다. 취약한 코드는 약 2011년부터 존재했으며, 업스트림 수정은 동일 AF...

idnsec.com/research/linux-loca

##

ibu_ipop@burnout.cafe at 2026-09-26T07:52:12.000Z ##

Linux kernel flaw enables root and container escape A 14-year-old bug in the AF_ALG cryptographic socket interface, tracked as CVE-2025-39964, allows unprivileged local users to gain root and escape Docker containers. The issue is a race condition in concurrent sendmsg() operations that can be turned into out-of-bounds memory access and an arbitrary kernel write. The vulnerable code dates to Linux 2.6.38

cyberpress.org/14-year-old-lin

##

CVE-2026-91843
(9.8 CRITICAL)

EPSS: 0.52%

updated 2026-09-16T15:31:14

1 posts

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

1 repos

https://github.com/HORKimhab/CVE-2026-91843

daniel1820815@infosec.exchange at 2026-09-25T08:36:01.000Z ##

CVE-2026-91843 Fix

Check Point has released a fix for CVE-2026-91843, a critical vulnerability affecting Security Management and Log Servers. The flaw, rated CVSS 9.8, stems from a stack overflow in the login process and can allow unauthenticated remote attackers to execute code as root on affected R80 through R82 systems.

support.checkpoint.com/results

#CVE #CVE202691843

##

CVE-2026-0310
(0 None)

EPSS: 0.37%

updated 2026-09-11T04:17:13.060000

2 posts

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls. The security risk posed by this issue is minimiz

CVE-2026-55074(CVSS UNKNOWN)

EPSS: 0.44%

updated 2026-08-13T15:58:54

2 posts

Through version 1.3.0, the jailexec connection plugin's put_file resolved a transfer's destination to a path on the jail host (<jail filesystem root> + <destination>) and ran mkdir -p and mv there as root on the host. Those commands follow symbolic links, and the path was operated on outside the jail, so a symlink existing inside the jail was followed by the host-side, root-privileged mv. A party

Larvitz@burningboard.net at 2026-09-27T09:38:25.000Z ##

For almost a year, my Ansible connection plugin for FreeBSD jails had a jail escape.

A symlink inside a jail, a root-owned mv on the host, and every file transfer could land wherever the jail wanted. Rejecting ".." didn't help at all.

Now it's CVE-2026-55074. Here's the bug, the fix, and what disclosing it looks like when the project has one maintainer.

blog.hofstede.it/my-ansible-pl

#FreeBSD #Ansible #InfoSec #CVE #Jails #OpenSource #Security #SysAdmin

##

Larvitz@burningboard.net at 2026-09-27T09:38:25.000Z ##

For almost a year, my Ansible connection plugin for FreeBSD jails had a jail escape.

A symlink inside a jail, a root-owned mv on the host, and every file transfer could land wherever the jail wanted. Rejecting ".." didn't help at all.

Now it's CVE-2026-55074. Here's the bug, the fix, and what disclosing it looks like when the project has one maintainer.

blog.hofstede.it/my-ansible-pl

#FreeBSD #Ansible #InfoSec #CVE #Jails #OpenSource #Security #SysAdmin

##

netsecio@mastodon.social at 2026-09-27T13:41:20.000Z ##

📰 CISA: Ransomware Gangs Actively Exploiting Critical TeamCity RCE Flaw

CISA confirms ransomware gangs are exploiting a critical RCE flaw (CVE-2026-63077, CVSS 9.8) in JetBrains TeamCity. Unauthenticated attackers can take over CI/CD servers. Patch now! #Ransomware #CVE #TeamCity #SupplyChain

🔗 cyber.netsecops.io/articles/ci

##

CVE-2026-39808
(9.8 CRITICAL)

EPSS: 47.36%

updated 2026-07-16T18:32:24

1 posts

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

6 repos

https://github.com/samu-delucas/CVE-2026-39808

https://github.com/error-inside/CVE-2026-39808

https://github.com/HORKimhab/CVE-2026-39808

https://github.com/ynsmroztas/FortiSandbox-RCE-Exploit-CVE-2026-39808

https://github.com/Lechansky/CVE-2026-39808

https://github.com/0xBlackash/CVE-2026-39808

AAKL@infosec.exchange at 2026-09-25T17:30:37.000Z ##

If you missed this, Fortinet posted advisories for two critical vulnerabilities yesterday - CVE-2026-39813 and CVE-2026-39808 app.opencve.io/cve/?vendor=for #infosec #Fortinet #vulnerability

##

CVE-2026-44661
(4.7 MEDIUM)

EPSS: 0.20%

updated 2026-06-17T10:51:12.463000

1 posts

python-utcp is the python implementation of UTCP. Prior to 1.1.3, the utcp-http plugin is vulnerable to a blind Server-Side Request Forgery (SSRF) caused by a trust-boundary inconsistency between manual discovery and tool invocation. register_manual() validates the discovery URL against an HTTPS / loopback allowlist, but call_tool() and call_tool_streaming() reuse the resolved tool_call_template.u

EUVD_Bot@mastodon.social at 2026-09-27T18:01:07.000Z ##

🚨 EUVD-2026-87986

📊 Score: 2.3/10 (CVSS v3.1)
📦 Product: python-utcp
🏢 Vendor: universal-tool-calling-protocol
📅 Updated: 2026-09-27

📝 utcp-gql before 1.1.1 and utcp-websocket before 1.1.1 contain server-side request forgery vulnerabilities due to incomplete application of CVE-2026-44661 fixes. The GraphQL plugin uses a vulnerable prefix check allowing bypass URL...

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2026-0257
(9.1 CRITICAL)

EPSS: 96.38%

updated 2026-06-17T10:10:37.953000

1 posts

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

Nuclei template

8 repos

https://github.com/tushargurav28/CVE-2026-0257

https://github.com/HORKimhab/CVE-2026-0257

https://github.com/0xBlackash/CVE-2026-0257

https://github.com/sfewer-r7/CVE-2026-0257

https://github.com/Mr-Robot-LP/CVE-2026-0257

https://github.com/grayxploit/CVE-2026-0257

https://github.com/Ez4rd1x1/CVE-2026-0257

https://github.com/akashsingh0454/CVE-2026-0257-PoC

japancyberwatch@infosec.exchange at 2026-09-25T10:08:42.000Z ##

Japan's Digital Agency was breached through a VPN flaw that was public before the attack. Data on ~246,000 officials and contractors may be exposed.

The agency won't name the product. Japanese researcher piyolog points to CVE-2026-0257 (PAN-OS GlobalProtect), added to CISA KEV on May 29. Detection to disclosure: eleven weeks, with no CVE or IOCs in the notice.

Our take on patching by CVSS, "zero trust" as a label, and Japan's disclosure culture:
japancyberwatch.com/articles/j

#infosec #Japan #DataBreach #VulnerabilityManagement #PaloAlto

##

CVE-2026-35273
(9.8 CRITICAL)

EPSS: 9.44%

updated 2026-06-12T18:31:50

4 posts

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of Peopl

4 repos

https://github.com/12hrformat/CVE-2026-35273-POC

https://github.com/0xBlackash/CVE-2026-35273

https://github.com/ekomsSavior/POC_cve_2026_35273

https://github.com/HORKimhab/CVE-2026-35273

youranonnewsirc@nerdculture.de at 2026-09-27T04:26:17.000Z ##

Cybersecurity: ShinyHunters exploit a critical Oracle PeopleSoft flaw (CVE-2026-35273), bypassing WAFs and deploying SIDEEYE backdoor across sectors. Geopolitics/Tech: President Trump rejects AI regulation, prioritizing innovation despite global concerns (Sept 26, 2026).

#Cybersecurity #AnonNews_irc #News

##

youranonnewsirc@nerdculture.de at 2026-09-27T04:26:17.000Z ##

Cybersecurity: ShinyHunters exploit a critical Oracle PeopleSoft flaw (CVE-2026-35273), bypassing WAFs and deploying SIDEEYE backdoor across sectors. Geopolitics/Tech: President Trump rejects AI regulation, prioritizing innovation despite global concerns (Sept 26, 2026).

#Cybersecurity #AnonNews_irc #News

##

cyberworldops@infosec.exchange at 2026-09-26T14:40:01.000Z ##

Google reports active exploitation of CVE-2026-35273 in Oracle PeopleSoft PeopleTools by UNC6240, linked to ShinyHunters. Encoded requests evade WAF rules to deploy JSP webshells via the Environment Management Hub, enabling persistent access. Prioritize patching and compromise hunting. #OracleSecurity #PeopleSoft #ThreatIntel

cyberworldops.eu/en/encoded-re

##

DarkWebInformer@infosec.exchange at 2026-09-25T23:44:38.000Z ##

🚨 ShinyHunters resumes mass exploitation of critical Oracle PeopleSoft flaw using simple WAF bypass.

Mandiant and Google Threat Intelligence Group have identified renewed mass exploitation of CVE-2026-35273 by UNC6240, also known as ShinyHunters.
⠀
The critical vulnerability allows unauthenticated remote code execution in Oracle PeopleSoft PeopleTools and carries a CVSS score of 9.8.

Oracle released an emergency patch on June 10.
⠀
The new campaign targets organizations that attempted to mitigate the flaw using web application firewall rules but did not install the patch.

ShinyHunters bypassed rules blocking the vulnerable /PSEMHUB/ endpoint by encoding a single character and sending requests to /%50SEMHUB/.
⠀
Google says web shells were deployed on dozens of systems worldwide across:

• Higher education
• Technology
• IT services
• Healthcare
• Agriculture
• Transportation
• Government
⠀
The actors deployed web shells, the SIDEEYE backdoor, Neo-reGeorg tunneling tools and MeshAgent for persistent remote access.

Around one-quarter of the observed commands executed with root or SYSTEM privileges.
⠀
Organizations running PeopleSoft should patch immediately, disable or remove the Environment Management Hub where possible and investigate encoded variants of /PSEMHUB/ in access logs.

WAF rules alone are not sufficient.

##

CVE-2026-32996(CVSS UNKNOWN)

EPSS: 0.17%

updated 2026-05-28T06:31:09

1 posts

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

1 repos

https://github.com/suce0155/CVE-2026-32996

CVE-2026-42608(CVSS UNKNOWN)

EPSS: 0.52%

updated 2026-05-13T13:52:36

1 posts

# Vulnerability Report: Grav CMS Unauthenticated Path Traversal & Arbitrary File Write **[ZERO-DAY] Unauthenticated Path Traversal leading to Arbitrary Directory Creation and Configuration Injection** ## Summary Grav CMS (v1.7.49.5 and latest development source) is vulnerable to a Zero-Day Path Traversal vulnerability within the FormFlash core component. By manipulating the session_id (passed a

Analyst207@mastodon.social at 2026-09-25T21:19:23.000Z ##

ShinyHunters Exploits Grav CMS Flaw to Breach Clop Leak Site

The Grav CMS flaw, tracked as CVE-2026-42608, was exploited by ShinyHunters to breach the Clop gang's leak site, and the vulnerability has since been patched in Grav's 2.0 and 1.7 branches. Grav confirmed the legitimacy of the flaw and the threat actor's description, and has implemented a fix to prevent further attacks.

osintsights.com/shinyhunters-e

#Shinyhunters #GravCms #Cve202642608 #PathTraversal #Clop

##

CVE-2026-39813
(9.8 CRITICAL)

EPSS: 0.72%

updated 2026-04-14T18:30:41

1 posts

A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via <insert attack vector here>

2 repos

https://github.com/0xBlackash/CVE-2026-39813

https://github.com/HORKimhab/CVE-2026-39813

AAKL@infosec.exchange at 2026-09-25T17:30:37.000Z ##

If you missed this, Fortinet posted advisories for two critical vulnerabilities yesterday - CVE-2026-39813 and CVE-2026-39808 app.opencve.io/cve/?vendor=for #infosec #Fortinet #vulnerability

##

CVE-2025-13032
(9.9 CRITICAL)

EPSS: 0.25%

updated 2025-11-11T18:30:23

7 posts

Double fetch in sandbox kernel driver in Avast/AVG Antivirus <25.3  on windows allows local attacker to escalate privelages via pool overflow.

hackersnews@mastodon.cesium.pw at 2026-09-25T19:30:07.000Z ##

CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2
news.ycombinator.com/item?id=4

#hackernews #tech

##

hn100@social.lansky.name at 2026-09-25T18:30:08.000Z ##

CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2

Link: safateam.com/intelligence-hub/
Discussion: news.ycombinator.com/item?id=4

##

_r_netsec@infosec.exchange at 2026-09-25T14:58:04.000Z ##

CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2 safateam.com/intelligence-hub/

##

hn50@social.lansky.name at 2026-09-25T10:30:09.000Z ##

CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2

Link: safateam.com/intelligence-hub/
Discussion: news.ycombinator.com/item?id=4

##

zer0@infosec.exchange at 2026-09-25T09:02:44.000Z ##

CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2 | safateam.com/intelligence-hub/

##

newsycombinator@framapiaf.org at 2026-09-25T08:00:36.000Z ##

CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2
Link: safateam.com/intelligence-hub/
Comments: news.ycombinator.com/item?id=4

##

h4ckernews@mastodon.social at 2026-09-25T07:18:10.000Z ##

CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2

safateam.com/intelligence-hub/

Comments: news.ycombinator.com/item?id=4

#HackerNews #CVE2025 #CVE #AvastAntivirus #CyberSecurity #Vulnerability #Research

##

CVE-2026-61722
(0 None)

EPSS: 0.20%

1 posts

N/A

hugovalters@mastodon.social at 2026-09-27T17:00:27.000Z ##

CVE-2026-61722 FluidSynth 2.5.0-2.5.6: crafted DLS file triggers integer overflow in the native parser, bypassing chunk-size checks and causing a denial of service through massive out-of-bounds iterations. CVSS 6.8. Patch to valtersit.com/cve/CVE-2026-617 #CVE #infosec #FluidSynth

##

CVE-2026-85271
(0 None)

EPSS: 0.35%

1 posts

N/A

hugovalters@mastodon.social at 2026-09-27T15:30:10.000Z ##

CVE-2026-85271 Open edX: unsanitized discussion titles let enrolled students inject CSS-capable markup into notification emails. CVSS 6.1. No patch yet. Restrict enrollment or filter post_title. Details: valtersit.com/cve/CVE-2026-852 #CVE #infosec #OpenEdX

##

rswebsols@mastodon.social at 2026-09-27T14:11:21.000Z ##

CVE-2026-87902: Severe Security Flaw in WordPress #wordpress

WordPress users urgently: CVE-2026-87902 is a severe remote code execution vulnerability that could allow arbitrary code on vulnerable sites. WordPress patched version 7.1.2 and later, but exploitation began within hours of disclosure. Update now to mitigate risk across all affected versions (4.7.0–7.1.1). Learn more and protect your site: ift.tt/OPqJ7NS

Source: ift.tt/OPqJ7NS | Image: ift.tt/xzLj2U6

##

netsecio@mastodon.social at 2026-09-27T13:41:28.000Z ##

📰 Critical WordPress Path Traversal Flaw Actively Exploited (CVE-2026-87902)

🚨 CRITICAL VULNERABILITY: WordPress Core is being actively exploited via CVE-2026-87902 (CVSS 9.2). The unauthenticated path traversal flaw can lead to RCE. Affects versions 4.7.0-7.1.1. Update to 7.1.2 immediately! #WordPress #CVE #CyberSecurity #P...

🔗 cyber.netsecops.io/articles/cr

##

rhudaur@flipboard.com at 2026-09-25T21:01:15.000Z ##

WordPress Patch Became Exploit Blueprint: CVE-2026-87902 Webshells Hit 350K Sites
techtimes.com/articles/328042/

Posted into Cybersecurity Today @cybersecurity-today-rhudaur

##

cisakevtracker@mastodon.social at 2026-09-25T20:00:51.000Z ##

CVE ID: CVE-2026-87902
Vendor: WordPress
Product: Core
Date Added: 2026-09-25
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-76654
(0 None)

EPSS: 0.00%

1 posts

N/A

mastokukei@social.josko.org at 2026-09-27T09:01:44.000Z ##

Scheme (Skate), Atari Jaguar OS (JagOS), ESP32 Linux support, and Arduino libraries.
- **Security vulnerabilities**: CVE-2026-76654, CVE-2026-2270, and a 14-year-old Linux kernel bug (AF_ALG).
- **Web development**: CSS features (scroll-driven animations, anchor positioning), Django, WordPress updates. [2/2]

##

CVE-2026-2270
(0 None)

EPSS: 0.00%

1 posts

N/A

mastokukei@social.josko.org at 2026-09-27T09:01:44.000Z ##

Scheme (Skate), Atari Jaguar OS (JagOS), ESP32 Linux support, and Arduino libraries.
- **Security vulnerabilities**: CVE-2026-76654, CVE-2026-2270, and a 14-year-old Linux kernel bug (AF_ALG).
- **Web development**: CSS features (scroll-driven animations, anchor positioning), Django, WordPress updates. [2/2]

##

CVE-2026-76902
(0 None)

EPSS: 0.27%

1 posts

N/A

hugovalters@mastodon.social at 2026-09-27T07:40:02.000Z ##

CVE-2026-76902 CordysCRM IDOR: unauthenticated attackers can download other orgs' files via predictable IDs. CVSS 5. No patch yet. Update to 1.7.4+ valtersit.com/cve/CVE-2026-769 #CVE #infosec

##

CVE-2026-57229
(0 None)

EPSS: 0.41%

1 posts

N/A

hugovalters@mastodon.social at 2026-09-27T04:40:01.000Z ##

CVE-2026-57229 Suricata SMTP MIME parser state leak lets crafted mail evade file.data, file.name and URL detections. CVSS 5.3, no patch yet. Isolate or review SMTP MIME decoding now. valtersit.com/cve/CVE-2026-572 #CVE #Suricata #infosec

##

CVE-2026-61720
(0 None)

EPSS: 0.18%

1 posts

N/A

hugovalters@mastodon.social at 2026-09-27T04:00:37.000Z ##

CVE-2026-61720 FluidSynth SF2 parser DoS: zero-sized DMOD chunk wraps count to UINT_MAX, triggering billions of allocations and memory exhaustion. CVSS 6.2. Patched in 2.5.6, no workaround. Update now. valtersit.com/cve/CVE-2026-617 #CVE #infosec #FluidSynth

##

CVE-2026-91765
(0 None)

EPSS: 0.52%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-25T23:46:21.000Z ##

🟠 CVE-2026-91765 - High (7.5)

cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements to any SoapServer endpoint, exhaust the stack an...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93676
(0 None)

EPSS: 0.14%

1 posts

N/A

linuxmint_hun@mastodon.social at 2026-09-25T16:16:05.000Z ##

Megjelent a Flatpak 1.18.3: biztonsági függőségek és regressziós javítások érkeztek – kezelik a CVE-2026-87766 és CVE-2026-93676 sebezhetőségeket. Gondoltad volna, hogy az 1.18.2 okozott build-regressziók SELinuxos rendszereken problémát, és téged érinthetnek? Kíváncsi vagy, javult-e a subsandbox és a bundle-telepítési stabilitás a te setupodon?

linuxmint.hu/hir/2026/09/megje

#Flatpak #Bubblewrap #xdg-dbus-proxy #CVE2026 #SELinux #Linux #Runtime #FlatpakRelease #Security #Bugfix

##

CVE-2026-87766
(0 None)

EPSS: 0.15%

1 posts

N/A

linuxmint_hun@mastodon.social at 2026-09-25T16:16:05.000Z ##

Megjelent a Flatpak 1.18.3: biztonsági függőségek és regressziós javítások érkeztek – kezelik a CVE-2026-87766 és CVE-2026-93676 sebezhetőségeket. Gondoltad volna, hogy az 1.18.2 okozott build-regressziók SELinuxos rendszereken problémát, és téged érinthetnek? Kíváncsi vagy, javult-e a subsandbox és a bundle-telepítési stabilitás a te setupodon?

linuxmint.hu/hir/2026/09/megje

#Flatpak #Bubblewrap #xdg-dbus-proxy #CVE2026 #SELinux #Linux #Runtime #FlatpakRelease #Security #Bugfix

##

CVE-2026-100000
(0 None)

EPSS: 0.00%

1 posts

N/A

bagder@mastodon.social at 2026-09-25T13:29:46.000Z ##

"the kernel.org CNA has CVE-2026-100000 reserved"

🍾

/ @gregkh

##

CVE-2026-63645
(0 None)

EPSS: 0.33%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-25T07:02:21.000Z ##

🟠 CVE-2026-63645 - High (7.5)

OpenObserve is a cloud-native observability platform. Prior to 0.90.3, OpenObserve registers the /config/runtime endpoint without authentication and serializes the complete server configuration after applying the hide_sensitive_fields keyword filt...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71540
(0 None)

EPSS: 0.35%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-25T07:02:11.000Z ##

🟠 CVE-2026-71540 - High (7.5)

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. From 3.9.0 until 4.14.7, wazuh-clusterd in framework/wazuh/core/cluster/common.py allocates a payload buffer using the size decl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77294
(0 None)

EPSS: 0.31%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-25T05:32:05.000Z ##

🟠 CVE-2026-77294 - High (8.1)

TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an authenticated user to store an attacker-controlled llm_base_url through the settings API when the LLM_PARSING feature is enabled. Write permission to the target trip instance i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-96749
(0 None)

EPSS: 0.13%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-25T05:16:29.000Z ##

🟠 CVE-2026-96749 - High (8.4)

An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusually large amount of caller-supplied data. Size arithmetic is performed in a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites