## Updated at UTC 2026-08-11T09:42:56.189666

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-18951 8.8 0.00% 2 0 2026-08-11T06:31:19 A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training op
CVE-2026-18950 8.8 0.00% 2 0 2026-08-11T06:31:19 A flaw was found in odh-dashboard. An authenticated user of the dashboard can ex
CVE-2026-18949 8.8 0.00% 2 0 2026-08-11T06:31:19 A flaw was found in odh-dashboard. This vulnerability allows an attacker, who ha
CVE-2026-18947 8.5 0.00% 2 0 2026-08-11T06:31:19 A flaw was found in Feast. An authorization bypass vulnerability exists in the /
CVE-2026-19516 9.1 0.00% 2 0 2026-08-11T06:17:13.433000 A caller-supplied X-Grafana-URL request header controls the destination of mcp-g
CVE-2026-13716 9.1 0.00% 2 0 2026-08-11T06:17:12.870000 Path traversal in server import and admin file upload in Crafty Controller. Allo
CVE-2026-19425 9.8 0.00% 2 0 2026-08-11T05:17:14.680000 Travel Agency Management System developed by Win Men Intermational has a SQL Inj
CVE-2026-18948 9.9 0.00% 4 0 2026-08-11T05:17:13.793000 A flaw was found in Feast. The system improperly deserializes user-defined funct
CVE-2026-71983 9.8 1.62% 1 0 2026-08-11T03:18:01.180000 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71949 9.8 2.09% 1 0 2026-08-11T03:18:00.893000 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71944 9.8 2.09% 1 0 2026-08-11T03:18:00.770000 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-14526 9.8 0.61% 2 0 2026-08-11T02:16:49.880000 The AI Copilot – Content Generator plugin for WordPress is vulnerable to authori
CVE-2026-66763 7.9 0.00% 2 0 2026-08-11T01:17:23 SAP BusinessObjects Business Intelligence Platform stores certain sensitive cred
CVE-2026-58243 8.8 0.00% 2 0 2026-08-11T01:17:22.160000 SAP ABAP Development Tools does not perform necessary authorization checks for c
CVE-2026-44763 7.6 0.00% 2 0 2026-08-11T01:17:20.930000 SAP Manufacturing Integration and Intelligence allows a privileged attacker to e
CVE-2026-44758 9.1 0.00% 4 0 2026-08-11T01:17:20.670000 SAP Manufacturing Integration and Intelligence (MII) allows an attacker with hig
CVE-2026-34265 9.8 0.00% 6 0 2026-08-11T01:17:20.240000 SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to expl
CVE-2026-73030 8.1 0.00% 2 0 2026-08-10T21:32:15 unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulne
CVE-2026-63622 7.8 0.00% 2 0 2026-08-10T21:32:08 A flaw was found in libvirt. A local attacker, specifically a process running as
CVE-2026-16594 7.5 0.14% 1 0 2026-08-10T21:31:59 The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorizatio
CVE-2026-8037 9.6 99.31% 2 2 template 2026-08-10T20:19:44.760000 OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC
CVE-2026-15038 9.8 0.19% 1 1 2026-08-10T20:17:26.803000 The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify th
CVE-2026-72730 8.7 0.00% 1 0 2026-08-10T19:17:33.807000 Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 20
CVE-2026-72691 7.5 0.00% 1 0 2026-08-10T19:17:33.320000 An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.
CVE-2026-66738 8.8 0.00% 2 0 2026-08-10T18:32:17 SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed inst
CVE-2026-19389 7.1 0.24% 1 0 2026-08-10T18:17:42.883000 Multiple integer overflow and underflow vulnerabilities were found in the GStrea
CVE-2026-10595 7.5 0.49% 1 0 2026-08-10T18:17:38.870000 A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specific
CVE-2026-71955 9.8 2.13% 1 0 2026-08-10T17:17:36.333000 D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2
CVE-2026-71576 8.5 0.00% 1 0 2026-08-10T17:17:36.060000 A flaw was found in multicluster-global-hub. The manager component improperly va
CVE-2026-19341 8.8 0.44% 1 0 2026-08-10T16:19:29.797000 A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-17030
CVE-2026-72689 7.5 0.00% 1 0 2026-08-10T15:33:59 A broken object-level authorization vulnerability in OpenSignLabs opensignserver
CVE-2026-63106 9.8 0.00% 1 0 2026-08-10T15:33:59 ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerabil
CVE-2026-13206 9.8 0.00% 1 0 2026-08-10T15:33:42 Improper neutralization of special elements used in an OS command ('OS command i
CVE-2026-71989 9.8 1.35% 2 0 2026-08-10T15:17:44.397000 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71948 9.8 2.09% 1 0 2026-08-10T14:17:26.467000 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-67620 7.7 0.43% 1 1 2026-08-10T14:17:26.107000 Flowise through 3.1.4 contains a server-side request forgery vulnerability in th
CVE-2026-18786 None 0.19% 1 0 2026-08-10T09:31:28 The CheckView WordPress plugin before 2.3.2 does not restrict its REST API auth
CVE-2026-16985 None 0.19% 1 0 2026-08-10T09:31:27 The Squeeze WordPress plugin before 1.7.12 does not validate the file type or e
CVE-2026-19381 7.8 0.11% 2 0 2026-08-10T03:31:08 A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2
CVE-2026-19387 7.6 0.24% 1 0 2026-08-10T03:31:01 A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-
CVE-2026-15534 0 0.20% 1 0 2026-08-09T22:16:30.373000 Perl versions through 5.45.1 have out-of-bounds heap reads and writes during reg
CVE-2026-19348 9.8 2.46% 2 0 2026-08-09T12:32:52 A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea
CVE-2026-19346 8.8 2.22% 1 0 2026-08-09T12:32:46 A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects
CVE-2026-19195 7.8 0.11% 1 1 2026-08-09T06:32:38 A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affec
CVE-2026-19193 7.8 0.11% 1 1 2026-08-09T06:32:38 A flaw has been found in Jiangmin Antivirus 21. Impacted is the function Message
CVE-2026-64564 9.8 0.48% 6 3 2026-08-09T04:17:43.283000 In the Linux kernel, the following vulnerability has been resolved: sctp: don't
CVE-2026-71993 9.8 1.35% 3 0 2026-08-09T00:31:13 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71986 9.8 1.35% 2 0 2026-08-09T00:31:13 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71992 9.8 1.35% 2 0 2026-08-09T00:31:13 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71984 9.8 1.35% 1 0 2026-08-09T00:31:13 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71987 9.8 1.35% 2 0 2026-08-09T00:31:07 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71988 9.8 1.35% 2 0 2026-08-09T00:31:07 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71991 9.8 1.35% 2 0 2026-08-09T00:31:07 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71990 9.8 1.35% 2 0 2026-08-09T00:16:48.130000 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71985 9.8 1.35% 1 0 2026-08-09T00:16:47.360000 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71953 9.8 2.09% 1 0 2026-08-08T18:30:30 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71958 9.8 0.56% 1 0 2026-08-08T18:30:30 D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2
CVE-2026-71954 9.8 2.13% 1 0 2026-08-08T18:30:30 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71947 9.8 2.09% 1 0 2026-08-08T18:30:29 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71945 9.8 2.09% 1 0 2026-08-08T18:30:29 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71952 9.8 2.09% 1 0 2026-08-08T18:30:29 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71951 9.8 2.09% 1 0 2026-08-08T18:30:29 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71950 9.8 2.09% 1 0 2026-08-08T18:30:29 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71957 9.8 0.59% 1 0 2026-08-08T18:30:29 D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2
CVE-2026-42170 7.8 0.19% 1 0 2026-08-08T18:30:29 A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Su
CVE-2026-71946 9.8 2.09% 1 0 2026-08-08T18:30:25 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71956 9.8 1.74% 1 0 2026-08-08T18:16:56.503000 D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2
CVE-2026-16948 None 0.13% 1 0 2026-08-08T09:30:28 The Solace Extra WordPress plugin before 1.6.1 does not perform capability check
CVE-2026-16955 None 0.16% 1 0 2026-08-08T09:30:28 The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied
CVE-2026-71560 9.1 0.55% 1 0 2026-08-08T03:32:14 Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue
CVE-2026-5857 8.1 0.53% 1 0 2026-08-08T03:16:46.377000 Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c se
CVE-2026-71558 9.8 0.71% 1 0 2026-08-08T00:52:49.367000 Heap type confusion vulnerability in Apache Fory C++ deserialization. This issu
CVE-2026-20347 7.5 0.33% 1 0 2026-08-07T22:16:58.003000 A vulnerability in the Mach-O file format parser of ClamAV could allow an unauth
CVE-2026-20339 7.5 0.33% 2 0 2026-08-07T22:16:57.707000 A vulnerability in the PESpin file format parser of ClamAV could allow an unauth
CVE-2026-15361 8.1 0.22% 1 0 2026-08-07T21:31:36 The Content Views WordPress plugin before 4.5 does not perform a capability che
CVE-2026-16263 8.8 0.34% 1 0 2026-08-07T21:31:36 The WP Maps WordPress plugin before 4.9.7 does not perform a capability check i
CVE-2026-15972 7.5 0.39% 1 0 2026-08-07T21:30:40 Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerab
CVE-2026-64636 7.7 0.21% 1 0 2026-08-07T21:30:37 An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Win
CVE-2026-16262 7.5 0.16% 1 0 2026-08-07T21:30:34 The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its O
CVE-2026-19082 7.5 0.29% 1 0 2026-08-07T21:17:27.317000 Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap byte
CVE-2026-48097 7.8 0.27% 1 0 2026-08-07T20:16:51.893000 NexTor IP Changer is a command-line tool that leverages the Tor network to perio
CVE-2025-63235 7.5 0.32% 1 0 2026-08-07T20:16:49.087000 In sol commit 373d848 (2024-12-12), the broker does not fully release resources
CVE-2026-48039 9.1 0.34% 2 0 2026-08-07T19:29:59 # Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token | Fi
CVE-2026-50481 9.9 0.46% 1 0 2026-08-07T19:29:09.813000 Modification of assumed-immutable data (maid) in Azure Active Directory allows a
CVE-2026-56161 9.6 0.38% 1 0 2026-08-07T19:28:41.040000 Improper access control in Azure Logic Apps allows an authorized attacker to dis
CVE-2026-64638 0 0.77% 7 20 template 2026-08-07T19:18:51.610000 WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login s
CVE-2026-64637 9.9 0.23% 2 0 2026-08-07T19:18:51.483000 Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows
CVE-2026-20346 7.5 0.33% 1 0 2026-08-07T19:17:41.360000 A vulnerability in the PDF file format parser of ClamAV could allow an unauthent
CVE-2026-16258 9.8 0.47% 1 0 2026-08-07T19:17:36.727000 The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deseri
CVE-2026-16041 7.5 0.21% 1 0 2026-08-07T19:17:36.343000 The MStore API WordPress plugin before 4.21.0 does not perform authorization or
CVE-2026-16038 9.1 0.24% 1 0 2026-08-07T19:17:36.110000 The MStore API WordPress plugin before 4.21.0 does not verify the payment with
CVE-2026-15215 8.8 0.35% 1 0 2026-08-07T19:17:34.677000 The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify
CVE-2026-71851 9.0 0.32% 2 0 2026-08-07T18:50:37 ### Summary `CryptoJS.lib.WordArray.random()` in affected versions is not a cry
CVE-2026-16030 8.1 0.23% 1 0 2026-08-07T18:32:49 The MStore API WordPress plugin before 4.21.0 does not correctly verify the cry
CVE-2026-71559 7.5 0.59% 1 0 2026-08-07T18:32:49 Deserialization of Untrusted Data vulnerability in the Go implementation of Apac
CVE-2026-67688 9.8 0.59% 1 0 2026-08-07T18:32:48 ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload
CVE-2026-45198 7.8 0.12% 1 0 2026-08-07T18:32:48 Kernel software from a non-secure operating system on a platform with Trusted Ex
CVE-2026-20348 7.5 0.33% 1 0 2026-08-07T18:31:54 A vulnerability in the XAR file format parser of ClamAV could allow an unauthent
CVE-2026-20345 7.5 0.33% 1 0 2026-08-07T18:31:54 A vulnerability in the GPT file format parser of ClamAV could allow an unauthent
CVE-2026-20338 7.5 0.33% 4 0 2026-08-07T18:31:53 A vulnerability in the zip archive parser of ClamAV could allow an unauthenticat
CVE-2026-68772 8.0 0.40% 1 0 2026-08-07T18:31:53 ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMa
CVE-2026-20337 7.5 0.36% 5 0 2026-08-07T18:31:52 A vulnerability in the zip archive parser of ClamAV could allow an unauthenticat
CVE-2026-70628 7.8 0.15% 1 0 2026-08-07T18:31:42 FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer
CVE-2026-67422 7.5 0.58% 1 0 2026-08-07T18:26:08 ### Summary Four inline processors in pymdown-extensions contain regular expres
CVE-2026-70634 8.1 0.41% 1 0 2026-08-07T18:17:22.580000 TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds r
CVE-2026-70632 7.8 0.21% 1 0 2026-08-07T18:17:22.307000 FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds
CVE-2026-67622 9.9 0.25% 1 0 2026-08-07T18:17:21.357000 Flowise through 3.1.4 contains an insecure direct object reference vulnerability
CVE-2026-67621 7.6 0.27% 1 0 2026-08-07T18:17:21.223000 Flowise through 3.1.4 contains a missing authorization vulnerability that allows
CVE-2026-64665 8.1 0.31% 1 0 2026-08-07T18:17:20.827000 Statamic is a Laravel and Git powered content management system (CMS). Prior to
CVE-2026-15733 9.8 3.90% 1 0 2026-08-07T18:17:08.840000 A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 a
CVE-2026-14943 7.5 0.26% 1 0 2026-08-07T18:17:08.120000 The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial
CVE-2026-14365 9.8 0.31% 1 0 2026-08-07T18:17:07.753000 The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress i
CVE-2026-14364 9.8 0.29% 1 0 2026-08-07T18:17:07.627000 The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress i
CVE-2026-14205 9.8 0.27% 1 0 2026-08-07T18:17:07.073000 The WP Events Manager WordPress plugin before 2.2.5 does not validate the reques
CVE-2026-50515 9.9 0.91% 1 0 2026-08-07T18:05:55.493000 Deserialization of untrusted data in Azure Service Bus allows an authorized atta
CVE-2026-70559 7.5 0.33% 1 1 2026-08-07T17:17:07.733000 Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carri
CVE-2026-5855 7.5 0.54% 1 0 2026-08-07T17:17:05.047000 Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c
CVE-2026-67687 8.8 0.53% 1 1 2026-08-07T16:17:27.217000 Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to
CVE-2026-19189 7.8 0.11% 1 0 2026-08-07T16:17:23.463000 A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected
CVE-2026-67689 9.8 0.69% 1 1 2026-08-07T15:34:17 SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execut
CVE-2026-49007 7.5 0.34% 1 0 2026-08-07T09:32:04 By accessing unencrypted information in the device firmware, an attacker can obt
CVE-2026-19192 7.8 0.11% 1 0 2026-08-07T06:30:27 A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affec
CVE-2026-19191 7.8 0.11% 1 0 2026-08-07T06:30:26 A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. T
CVE-2026-19190 7.8 0.14% 1 0 2026-08-07T06:30:25 A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an
CVE-2026-65400 7.1 0.30% 2 0 2026-08-07T03:31:32 An authentication issue was addressed with improved state management. This issue
CVE-2026-49163 8.8 0.62% 1 0 2026-08-07T00:31:28 Improper limitation of a pathname to a restricted directory ('path traversal') i
CVE-2026-70558 9.8 0.60% 1 0 2026-08-07T00:31:27 Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied pa
CVE-2026-56162 10.0 0.48% 1 0 2026-08-07T00:31:27 Improper authentication in Azure SQL Database allows an unauthorized attacker to
CVE-2026-53984 9.1 0.38% 1 0 2026-08-07T00:31:26 Ground Station prior to 0.6.0 contains an unauthenticated database-destruction a
CVE-2026-53983 8.6 0.33% 1 0 2026-08-07T00:31:26 Ground Station prior to 0.6.0 contains an unauthenticated blind server-side requ
CVE-2026-19036 7.2 2.47% 1 0 2026-08-06T22:16:51.977000 A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the
CVE-2026-19035 7.2 2.47% 1 0 2026-08-06T16:16:40.753000 A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issu
CVE-2026-10090 9.9 0.25% 1 0 2026-08-06T15:37:22.093000 A flaw was found in the Application Subscription controller (multicluster-operat
CVE-2026-19034 7.2 2.47% 1 0 2026-08-06T12:31:21 A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vuln
CVE-2026-44945 9.1 0.30% 2 0 2026-08-06T05:17:03.793000 A privilege escalation vulnerability exists in Rancher's impersonation middlewar
CVE-2026-17650 8.3 0.35% 1 0 2026-08-06T00:36:25.360000 Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a
CVE-2026-63077 9.8 10.72% 2 4 template 2026-08-05T18:32:31 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe
CVE-2026-70374 8.8 2.52% 1 0 2026-08-05T15:32:14 HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-
CVE-2026-18902 7.2 2.38% 1 0 2026-08-05T14:17:04.910000 A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerabilit
CVE-2026-18900 7.2 2.38% 1 0 2026-08-05T06:30:31 A weakness has been identified in H3C NX15 V100R017. This impacts the function f
CVE-2026-18814 7.2 2.71% 1 0 2026-08-05T00:30:41 A vulnerability was found in H3C NX15 V100R017. This impacts the function reload
CVE-2026-18577 8.1 4.10% 5 3 2026-08-04T14:27:12.530000 An incomplete patch for CVE-2026-18556 allows for authentication bypass and acco
CVE-2026-18686 9.8 2.61% 1 0 2026-08-04T00:35:01 A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected elem
CVE-2026-18601 9.8 2.38% 1 0 2026-08-03T15:32:55 A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the fun
CVE-2026-33591 0 0.52% 1 0 2026-08-03T12:16:26.317000 A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unaut
CVE-2026-64542 0 0.17% 1 0 2026-08-03T10:16:32.820000 In the Linux kernel, the following vulnerability has been resolved: ipv6: ndisc
CVE-2026-17656 9.6 0.40% 1 0 2026-07-30T21:32:37 Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote
CVE-2026-64560 7.8 0.12% 1 1 2026-07-30T12:19:03.630000 In the Linux kernel, the following vulnerability has been resolved: posix-cpu-t
CVE-2026-60206 9.9 0.49% 1 4 2026-07-28T14:14:37.463000 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware
CVE-2026-15903 8.8 0.31% 1 0 2026-07-24T15:33:44 Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allo
CVE-2026-65535 4.3 0.18% 1 0 2026-07-23T14:17:59.510000 Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.
CVE-2026-63030 9.8 95.60% 1 81 template 2026-07-22T23:10:00.110000 WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API ba
CVE-2026-56155 7.8 2.33% 1 0 2026-07-14T21:32:52 Insufficient granularity of access control in Active Directory Federation Servic
CVE-2026-34348 6.5 0.71% 1 1 2026-07-14T18:31:58 Protection mechanism failure in Windows Event Logging Service allows an authoriz
CVE-2026-43074 7.8 0.48% 1 1 2026-06-17T10:48:53.150000 In the Linux kernel, the following vulnerability has been resolved: eventpoll:
CVE-2026-25166 7.8 1.63% 1 0 2026-06-17T10:24:13.150000 Deserialization of untrusted data in Windows System Image Manager allows an auth
CVE-2020-11069 8.0 0.70% 1 0 2026-06-17T02:48:59.070000 In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discove
CVE-2003-0190 0 76.75% 2 0 2026-06-16T22:01:43.273000 OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediat
CVE-1999-1587 0 0.95% 2 0 2026-06-16T21:50:46.783000 /usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, a
CVE-2026-34486 7.5 81.16% 1 6 template 2026-06-08T23:28:56 Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the f
CVE-2026-48048 7.5 0.00% 1 0 2026-05-26T20:17:03 ### Impact XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insuffici
CVE-2021-26708 7.0 1.60% 1 3 2023-11-18T05:04:48 A local privilege escalation was discovered in the Linux kernel before 5.10.13.
CVE-2015-6609 None 2.17% 1 0 2023-01-27T05:08:18 libutils in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote
CVE-2026-62737 0 0.00% 1 0 N/A
CVE-2026-60004 0 0.00% 2 8 template N/A
CVE-2026-48161 0 0.00% 2 0 N/A
CVE-2026-8718 0 0.00% 2 0 N/A
CVE-2026-72915 0 0.00% 2 0 N/A
CVE-2026-72914 0 0.00% 2 0 N/A
CVE-2026-72903 0 0.00% 2 0 N/A
CVE-2026-72911 0 0.00% 2 0 N/A
CVE-2026-72901 0 0.00% 2 0 N/A
CVE-2026-72886 0 0.00% 2 0 N/A
CVE-2026-72883 0 0.00% 2 0 N/A
CVE-2026-45628 0 0.23% 1 0 N/A
CVE-2026-72864 0 0.00% 2 0 N/A
CVE-2026-72872 0 0.00% 2 0 N/A
CVE-2026-72871 0 0.00% 2 0 N/A
CVE-2026-47754 0 0.00% 1 0 N/A
CVE-2026-5423 0 0.34% 1 0 N/A
CVE-2026-60137 0 73.10% 1 52 N/A
CVE-2026-48085 0 0.55% 1 0 N/A
CVE-2026-63637 0 0.24% 1 0 N/A

CVE-2026-18951
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-11T06:31:19

2 posts

A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with `edit ClusterRole` permissions in a namespace to create, modify, and delete `TrainJobs`. When combined with a separate vulnerability (TRN-01) that permits arbitrar

thehackerwire@mastodon.social at 2026-08-10T23:01:06.000Z ##

🟠 CVE-2026-18951 - High (8.8)

A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with `edit Clus...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-10T23:01:06.000Z ##

🟠 CVE-2026-18951 - High (8.8)

A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with `edit Clus...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18950
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-11T06:31:19

2 posts

A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The system does not properly validate the `roleRef` field, allowing a user to specify an arbitrary role, including highly privileged ones like `cluster-admin`. This can lead to privilege escalation, where an attacker gains unauthorized elevated access withi

thehackerwire@mastodon.social at 2026-08-10T23:00:55.000Z ##

🟠 CVE-2026-18950 - High (8.8)

A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The system does not properly validate the `roleRef` field, allowing a user to specify an arbitrary role,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-10T23:00:55.000Z ##

🟠 CVE-2026-18950 - High (8.8)

A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The system does not properly validate the `roleRef` field, allowing a user to specify an arbitrary role,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18949
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-11T06:31:19

2 posts

A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions granted to the SA. This enables the attacker to escalate their privileges to cluster-administrator level, gain access to sensitive data like credentials and keys across the entire cluster, and disrupt multi-tenant isolation.

thehackerwire@mastodon.social at 2026-08-10T23:00:44.000Z ##

🟠 CVE-2026-18949 - High (8.8)

A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions granted to the SA. This enables the attacker to escalate their privileges...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-10T23:00:44.000Z ##

🟠 CVE-2026-18949 - High (8.8)

A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions granted to the SA. This enables the attacker to escalate their privileges...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18947
(8.5 HIGH)

EPSS: 0.00%

updated 2026-08-11T06:31:19

2 posts

A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental endpoints. By sending a specially crafted request that omits the feature_views field, an attacker can bypass intended permission checks. This allows an unauthenticated remote attacker, or any authenticated user, to trigger a full re-materialization of all feature views. The cons

thehackerwire@mastodon.social at 2026-08-10T22:01:20.000Z ##

🟠 CVE-2026-18947 - High (8.5)

A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental endpoints. By sending a specially crafted request that omits the feature_views field, an attacker can bypass intended permissi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-10T22:01:20.000Z ##

🟠 CVE-2026-18947 - High (8.5)

A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental endpoints. By sending a specially crafted request that omits the feature_views field, an attacker can bypass intended permissi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19516
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-08-11T06:17:13.433000

2 posts

A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the caller also choose the HTTP method, path, and body. Because the destination is not restricted to the configured Grafana instance, a caller can direct requests at internal, loopback, and link-local network services (including metadata endpoints) and r

offseq at 2026-08-11T06:00:25.873Z ##

Grafana MCP Server hit by CRITICAL SSRF (CVE-2026-19516, CVSS 9.1) via X-Grafana-URL header. Attackers can access internal endpoints and metadata. Restrict access & monitor usage until patch available. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-11T06:00:25.000Z ##

Grafana MCP Server hit by CRITICAL SSRF (CVE-2026-19516, CVSS 9.1) via X-Grafana-URL header. Attackers can access internal endpoints and metadata. Restrict access & monitor usage until patch available. radar.offseq.com/threat/cve-20 #OffSeq #Grafana #SSRF #Vuln

##

CVE-2026-13716
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-08-11T06:17:12.870000

2 posts

Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution.

offseq at 2026-08-11T07:30:28.028Z ##

CRITICAL path traversal (CVE-2026-13716, CVSS 9.1) found in Crafty Controller v4.4.0 (Arcadia). Authenticated attackers can upload files to arbitrary paths, risking RCE. Restrict admin/file upload access & monitor activity. Details: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-11T07:30:28.000Z ##

CRITICAL path traversal (CVE-2026-13716, CVSS 9.1) found in Crafty Controller v4.4.0 (Arcadia). Authenticated attackers can upload files to arbitrary paths, risking RCE. Restrict admin/file upload access & monitor activity. Details: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #CVE202613716

##

CVE-2026-19425
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-11T05:17:14.680000

2 posts

Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.

offseq at 2026-08-11T09:00:26.412Z ##

Win Men Intermational Travel Agency Management System has a CRITICAL SQL Injection flaw (CVE-2026-19425, CVSS 9.8). Unauthenticated attackers may fully compromise databases. No patch yet: restrict access & monitor for SQLi. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-11T09:00:26.000Z ##

Win Men Intermational Travel Agency Management System has a CRITICAL SQL Injection flaw (CVE-2026-19425, CVSS 9.8). Unauthenticated attackers may fully compromise databases. No patch yet: restrict access & monitor for SQLi. radar.offseq.com/threat/cve-20 #OffSeq #CVE202619425 #SQLInjection #InfoSec

##

CVE-2026-18948
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-08-11T05:17:13.793000

4 posts

A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious UDF, leading to unauthenticated arbitrary code execution on the feature server in default configurations. An authenticated attacker can also achieve arbitrary code execution on the regis

offseq at 2026-08-11T04:30:24.830Z ##

CVE-2026-18948: CRITICAL in RHOAI Feast — unsafe UDF deserialization allows unauth RCE on feature-server. Auth attackers can bypass auth to run code on registry-server. Mitigate by enforcing `auth.type: kubernetes`. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-10T22:01:31.000Z ##

🔴 CVE-2026-18948 - Critical (9.9)

A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious UDF, leading to unauthenticated a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-11T04:30:24.000Z ##

CVE-2026-18948: CRITICAL in RHOAI Feast — unsafe UDF deserialization allows unauth RCE on feature-server. Auth attackers can bypass auth to run code on registry-server. Mitigate by enforcing `auth.type: kubernetes`. radar.offseq.com/threat/cve-20 #OffSeq #RedHat #CVE #infosec

##

thehackerwire@mastodon.social at 2026-08-10T22:01:31.000Z ##

🔴 CVE-2026-18948 - Critical (9.9)

A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious UDF, leading to unauthenticated a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71983
(9.8 CRITICAL)

EPSS: 1.62%

updated 2026-08-11T03:18:01.180000

1 posts

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through the pin2g, pin5g, or pin6g parameters. Attackers can exploit these unsanitized parameters to execute arbitrary commands on the affected device and obtain root privileges.

thehackerwire@mastodon.social at 2026-08-08T23:59:57.000Z ##

🔴 CVE-2026-71983 - Critical (9.8)

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through the pin2g, pin5g, or pin6g parame...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71949
(9.8 CRITICAL)

EPSS: 2.09%

updated 2026-08-11T03:18:00.893000

1 posts

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject arbitrary malicious commands into the ussdValue and selectMenuValue fields, resulting in command execution with root privileges.

thehackerwire@mastodon.social at 2026-08-09T02:01:05.000Z ##

🔴 CVE-2026-71949 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject arbitrary malicious commands into the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71944
(9.8 CRITICAL)

EPSS: 2.09%

updated 2026-08-11T03:18:00.770000

1 posts

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges.

thehackerwire@mastodon.social at 2026-08-09T07:00:02.000Z ##

🔴 CVE-2026-71944 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can inject arbitrary malicious comma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14526
(9.8 CRITICAL)

EPSS: 0.61%

updated 2026-08-11T02:16:49.880000

2 posts

The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to create a new administrator-level user account and achieve full site takeover by saving and executing a malic

offseq@infosec.exchange at 2026-08-08T13:30:27.000Z ##

CVE-2026-14526: AI Copilot – Content Generator <=1.5.6 has a CRITICAL auth bypass. Unauth attackers can create WordPress admin users via an exposed nonce, leading to site takeover. Disable [aiwu-form]/chatbot & check for vendor patch. radar.offseq.com/threat/cve-20 #OffSeq #CVE202614526 #WordPress

##

thehackerwire@mastodon.social at 2026-08-08T08:00:29.000Z ##

🔴 CVE-2026-14526 - Critical (9.8)

The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This make...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66763
(7.9 HIGH)

EPSS: 0.00%

updated 2026-08-11T01:17:23

2 posts

SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects and decrypt the stored credentials. Successful exploitation could allow the attacker to obtain sensitive authentication data and modify protected inform

thehackerwire@mastodon.social at 2026-08-11T02:00:02.000Z ##

🟠 CVE-2026-66763 - High (7.9)

SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-11T02:00:02.000Z ##

🟠 CVE-2026-66763 - High (7.9)

SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58243
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-11T01:17:22.160000

2 posts

SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could allow the attacker to read sensitive data, modify application data, and disrupt access for legitimate users, resulting in high impact on confidentiality

thehackerwire@mastodon.social at 2026-08-11T02:00:11.000Z ##

🟠 CVE-2026-58243 - High (8.8)

SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-11T02:00:11.000Z ##

🟠 CVE-2026-58243 - High (8.8)

SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44763
(7.6 HIGH)

EPSS: 0.00%

updated 2026-08-11T01:17:20.930000

2 posts

SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and depends on conditions outside the attacker�s control. Successful exploitation could allow files to be written outside the i

thehackerwire@mastodon.social at 2026-08-11T03:00:45.000Z ##

🟠 CVE-2026-44763 - High (7.6)

SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-11T03:00:45.000Z ##

🟠 CVE-2026-44763 - High (7.6)

SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44758
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-08-11T01:17:20.670000

4 posts

SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system, resulting in high impact on confidentiality, integrity, and availability

thehackerwire@mastodon.social at 2026-08-11T03:00:35.000Z ##

🔴 CVE-2026-44758 - Critical (9.1)

SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-11T01:30:29.060Z ##

SAP MII 15.5 is exposed to CRITICAL code injection (CVE-2026-44758, CVSS 9.1). High-privilege users could execute arbitrary OS commands. No patch yet — restrict access & monitor for code injection. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-11T03:00:35.000Z ##

🔴 CVE-2026-44758 - Critical (9.1)

SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-11T01:30:29.000Z ##

SAP MII 15.5 is exposed to CRITICAL code injection (CVE-2026-44758, CVSS 9.1). High-privilege users could execute arbitrary OS commands. No patch yet — restrict access & monitor for code injection. radar.offseq.com/threat/cve-20 #OffSeq #SAP #Infosec #CVE202644758

##

CVE-2026-34265
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-11T01:17:20.240000

6 posts

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the system, leading to a high impact on the confidentiality, integrity, and availability of the application.

se38@nrw.social at 2026-08-11T06:42:28.000Z ##

Time to patch your Kernel...
CVSS v3.0 Base Score: 9,8 / 10

3714806 - [CVE-2026-34265] Memory Corruption vulnerability in Application Server #ABAP for #SAP NetWeaver and ABAP Platform

me.sap.com/notes/3714806

##

thehackerwire@mastodon.social at 2026-08-11T03:00:26.000Z ##

🔴 CVE-2026-34265 - Critical (9.8)

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the sy...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-11T03:00:27.601Z ##

CVE-2026-34265: CRITICAL out-of-bounds write in SAP NetWeaver & ABAP Platform (CVSS 9.8) allows unauthenticated memory corruption. No patch yet — restrict access & monitor SAP advisories for updates. radar.offseq.com/threat/cve-20

##

se38@nrw.social at 2026-08-11T06:42:28.000Z ##

Time to patch your Kernel...
CVSS v3.0 Base Score: 9,8 / 10

3714806 - [CVE-2026-34265] Memory Corruption vulnerability in Application Server #ABAP for #SAP NetWeaver and ABAP Platform

me.sap.com/notes/3714806

##

thehackerwire@mastodon.social at 2026-08-11T03:00:26.000Z ##

🔴 CVE-2026-34265 - Critical (9.8)

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the sy...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-11T03:00:27.000Z ##

CVE-2026-34265: CRITICAL out-of-bounds write in SAP NetWeaver & ABAP Platform (CVSS 9.8) allows unauthenticated memory corruption. No patch yet — restrict access & monitor SAP advisories for updates. radar.offseq.com/threat/cve-20 #OffSeq #SAP #Vuln #Cybersecurity

##

CVE-2026-73030
(8.1 HIGH)

EPSS: 0.00%

updated 2026-08-10T21:32:15

2 posts

unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers can supply malicious tar archives with symlink members or traversal sequences to write files to arbitrary filesystem locations accessible to the process.

thehackerwire@mastodon.social at 2026-08-10T22:00:06.000Z ##

🟠 CVE-2026-73030 - High (8.1)

unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-10T22:00:06.000Z ##

🟠 CVE-2026-73030 - High (8.1)

unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63622
(7.8 HIGH)

EPSS: 0.00%

updated 2026-08-10T21:32:08

2 posts

A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtpm` state directory, the attacker could trick the root-level libvirt daemon into changing the ownership of an arbitrary file to the `swtpm` user. This allows for

thehackerwire@mastodon.social at 2026-08-10T22:01:09.000Z ##

🟠 CVE-2026-63622 - High (7.8)

A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtpm` state...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-10T22:01:09.000Z ##

🟠 CVE-2026-63622 - High (7.8)

A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtpm` state...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16594
(7.5 HIGH)

EPSS: 0.14%

updated 2026-08-10T21:31:59

1 posts

The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the WP Directory Kit WordPress plugin before 1.5.5 settings including sensitive API keys and secrets.

offseq@infosec.exchange at 2026-08-08T10:30:23.000Z ##

CVE-2026-16594: WP Directory Kit <1.5.5 has a HIGH severity info exposure flaw. Any authenticated user (even Subscribers) can access API keys/secrets due to missing authorization on AJAX action. Restrict user roles & monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE

##

CVE-2026-8037
(9.6 CRITICAL)

EPSS: 99.31%

updated 2026-08-10T20:19:44.760000

2 posts

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

Nuclei template

2 repos

https://github.com/HORKimhab/CVE-2026-8037

https://github.com/Caster-chen/CVE-2026-8037-POC

thecybermind@infosec.exchange at 2026-08-10T14:09:10.000Z ##

🚨 CRITICAL THREAT ALERT: CVE-2026-8037 is under active exploitation per CISA KEV. Progress LoadMaster appliances face remote command injection risks. Secure your perimeter with our strategic C-Suite breakdown covering technical indicators, backdoor mechanics, and hardening protocols.
thecybermind.co/2j7b

##

threatnoir@infosec.exchange at 2026-08-10T12:06:17.000Z ##

⚠️ CRITICAL: CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability

Progress Kemp LoadMaster has a critical RCE vulnerability (CVE-2026-8037) that allows unauthenticated attackers to execute arbitrary commands. Active exploitation started around June 29. Any organization running affected LoadMaster versions needs to patch immediately or risk full appliance compromi…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

CVE-2026-15038
(9.8 CRITICAL)

EPSS: 0.19%

updated 2026-08-10T20:17:26.803000

1 posts

The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key, hijack an administrator session, and take over the entire network, leading to remote code execution.

1 repos

https://github.com/Polosss/By-Poloss..-..CVE-2026-15038-POC

offseq@infosec.exchange at 2026-08-09T07:30:24.000Z ##

CVE-2026-15038 (CRITICAL): InfiniteWP Client <1.13.6 has improper authentication in WordPress Multisite. Allows unauthenticated takeover & potential RCE. Restrict endpoint, monitor activity, upgrade ASAP. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #BlueTeam

##

CVE-2026-72730
(8.7 HIGH)

EPSS: 0.00%

updated 2026-08-10T19:17:33.807000

1 posts

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Editor rendered a chat-transcript username as HTML, allowing stored cross-site scripting. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.

thehackerwire@mastodon.social at 2026-08-10T17:59:51.000Z ##

🟠 CVE-2026-72730 - High (8.7)

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Editor rendered a chat-transcript username as HTML, allowing stored cross-site scripting. This issue is fixed in versions 2026.1.6,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72691
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-10T19:17:33.320000

1 posts

An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to mint MASTER_KEY-signed file access tokens for arbitrary stored files via the getsignedurl Parse cloud function. The function skips its isAuthenticated check whenever any docId parameter is supplied, even one corresponding to no real document, allowing the authentication

thehackerwire@mastodon.social at 2026-08-10T16:00:57.000Z ##

🟠 CVE-2026-72691 - High (7.5)

An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to mint MASTER_KEY-signed file access tokens for arbitrary stored files via the getsignedurl Parse cloud function. The f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66738
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-10T18:32:17

2 posts

SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-typed user input, which bypasses input sanitization and allows the value to break out of an internal quoted string context when evaluated as PHP. An authenticated attacker with at minimum editor (redacteur) privileges can submit a single crafted GET reque

hugovalters@mastodon.social at 2026-08-10T23:01:49.000Z ##

CVE-2026-66738 - Critical code injection in SPIP <4.4.18 via SQLite nav endpoint. Auth'd editors can RCE. CVSS 9.8. Unpatched - update/isolate now. #CVE #SPIP #infosec

valtersit.com/cve/CVE-2026-667

##

thehackerwire@mastodon.social at 2026-08-10T17:00:14.000Z ##

🔴 CVE-2026-66738 - Critical (9.8)

SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-typed user input, which bypasses input sanitization and allows the value to break out of an internal q...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19389
(7.1 HIGH)

EPSS: 0.24%

updated 2026-08-10T18:17:42.883000

1 posts

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information

offseq@infosec.exchange at 2026-08-10T04:30:27.000Z ##

GStreamer gst-plugins-ugly (asfdemux) in Red Hat Enterprise Linux 10 is affected by CVE-2026-19389 (HIGH, CVSS 7.1). Parsing crafted ASF/WMV/WMA files may lead to DoS or info leaks. No patch yet — avoid untrusted media. radar.offseq.com/threat/cve-20 #OffSeq #Linux #CVE #GStreamer

##

CVE-2026-10595
(7.5 HIGH)

EPSS: 0.49%

updated 2026-08-10T18:17:38.870000

1 posts

A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises from the improper handling of user-controlled path input, which is directly joined into a filesystem path without sanitization or containment checks. URL-encoded dot-dot sequences (`%2e%2e`) bypass Starlette's built-in path

thehackerwire@mastodon.social at 2026-08-09T05:00:00.000Z ##

🟠 CVE-2026-10595 - High (7.5)

A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises from the improper handling of user-controlled path input, which is dir...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71955
(9.8 CRITICAL)

EPSS: 2.13%

updated 2026-08-10T17:17:36.333000

1 posts

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, targetAPSsid, peerPin, and peerRptPin fields, resulting in command execution with root privileges.

thehackerwire@mastodon.social at 2026-08-09T00:01:03.000Z ##

🔴 CVE-2026-71955 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, ta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71576
(8.5 HIGH)

EPSS: 0.00%

updated 2026-08-10T17:17:36.060000

1 posts

A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming CloudEvents on Kafka status topics. A remote attacker, after compromising a managed hub and obtaining its Kafka client certificate, can manipulate the self-asserted source identity. This allows the attacker to falsify or delete critical data, such as compliance, inventory, and cl

thehackerwire@mastodon.social at 2026-08-10T18:00:01.000Z ##

🟠 CVE-2026-71576 - High (8.5)

A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming CloudEvents on Kafka status topics. A remote attacker, after compromising a managed hub and obtaining its Kafka client certific...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19341
(8.8 HIGH)

EPSS: 0.44%

updated 2026-08-10T16:19:29.797000

1 posts

A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/pptpSrvGlobalConfig. Such manipulation of the argument EncryptionMode leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did n

thehackerwire@mastodon.social at 2026-08-09T08:00:02.000Z ##

🟠 CVE-2026-19341 - High (8.8)

A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/pptpSrvGlobalConfig. Such manipulation of the argument EncryptionMode leads to stack-based buffer overflow. The...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72689
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-10T15:33:59

1 posts

A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read complete contract records via the getDocument Parse cloud function. The function fetches documents using useMasterKey, bypassing the object ACL, and returns full records including sender and signer PII and a pre-signed document download URL whenever the

thehackerwire@mastodon.social at 2026-08-10T16:00:43.000Z ##

🟠 CVE-2026-72689 - High (7.5)

A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read complete contract records via the getDocument Parse cloud function. The function fetches documents us...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63106
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-10T15:33:59

1 posts

ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the products endpoint is concatenated directly into a MySQL HAVING clause without parameterization in ProductController.php. Attackers can perform time-based blind SQL injection through the unsanitized rating parameter to extract the full database contents,

thehackerwire@mastodon.social at 2026-08-10T16:00:32.000Z ##

🔴 CVE-2026-63106 - Critical (9.8)

ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the products endpoint is concatenated directly into a MySQL HAVING clause without parameterization in Pr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13206
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-10T15:33:42

1 posts

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networks WAH7601 allows OS Command Injection. This issue affects WAH7601: through 20072026.

offseq@infosec.exchange at 2026-08-10T13:30:24.000Z ##

CVE-2026-13206: CRITICAL OS command injection in Zyxel WAH7601 (≤20072026). Remote, unauthenticated code execution possible — no patch yet. Restrict access & monitor vendor updates. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE #Zyxel #Vuln #InfoSec

##

CVE-2026-71989
(9.8 CRITICAL)

EPSS: 1.35%

updated 2026-08-10T15:17:44.397000

2 posts

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.

offseq@infosec.exchange at 2026-08-09T06:00:26.000Z ##

MSI Radix AXE6600 routers (v781521) impacted by CVE-2026-71989: CRITICAL OS command injection (CVSS 9.3) in porTrigger/alg enables unauthenticated root command execution. Patch status unknown. Details: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #CVE202671989 #RouterSecurity

##

thehackerwire@mastodon.social at 2026-08-09T02:00:55.000Z ##

🔴 CVE-2026-71989 - Critical (9.8)

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability thr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71948
(9.8 CRITICAL)

EPSS: 2.09%

updated 2026-08-10T14:17:26.467000

1 posts

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges.

thehackerwire@mastodon.social at 2026-08-09T00:01:13.000Z ##

🔴 CVE-2026-71948 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67620
(7.7 HIGH)

EPSS: 0.43%

updated 2026-08-10T14:17:26.107000

1 posts

Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba Cloud metadata endpoint 100.100.100.200, allowing authenticated attackers to force the server to issue arbitrary GET requests to cloud instance metadata services.

1 repos

https://github.com/abdugafforov-bobur/CVE-2026-67620-poc

thehackerwire@mastodon.social at 2026-08-08T17:00:03.000Z ##

🟠 CVE-2026-67620 - High (7.7)

Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba Cloud meta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18786(CVSS UNKNOWN)

EPSS: 0.19%

updated 2026-08-10T09:31:28

1 posts

The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and unconditionally discards the authentication error raised for any request whose URI merely contains a CheckView WordPress plugin before 2.3.2-specific string, making it possible for unauthenticated attackers to bypass the REST nonce check and perform any REST action available to

offseq@infosec.exchange at 2026-08-10T07:30:27.000Z ##

CVE-2026-18786: CRITICAL auth bypass in CheckView WP plugin ≤2.0.29. Attackers can exploit REST API via crafted links to perform admin actions if an admin clicks. Restrict plugin REST API & avoid suspicious links. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202618786

##

CVE-2026-16985(CVSS UNKNOWN)

EPSS: 0.19%

updated 2026-08-10T09:31:27

1 posts

The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data written by one of its attachment-update actions, allowing users with the upload_files capability (Author and above) to write an executable PHP file into the uploads directory and achieve remote code execution.

offseq@infosec.exchange at 2026-08-10T09:00:24.000Z ##

CVE-2026-16985: Squeeze WP plugin <1.7.12 has a CRITICAL vuln — users with upload_files can upload PHP files, enabling remote code execution. Restrict permissions, monitor uploads, and check for updates. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE2026_16985 #infosec

##

CVE-2026-19381
(7.8 HIGH)

EPSS: 0.11%

updated 2026-08-10T03:31:08

2 posts

A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performing a manipulation results in improper privilege management. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. The vendor was contacted e

thehackerwire@mastodon.social at 2026-08-10T01:59:49.000Z ##

🟠 CVE-2026-19381 - High (7.8)

A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performing a manipulation results in improper privilege m...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-10T01:30:28.000Z ##

Kingston FURY CTRL RGB Control Software v2.0.65.0 hit by HIGH severity vuln (CVE-2026-19381, CVSS 8.5). Local attackers can escalate privileges via NTIOLib_KSFX.sys. Exploit code is public; no patch yet. Restrict local access, monitor systems. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Kingston

##

CVE-2026-19387
(7.6 HIGH)

EPSS: 0.24%

updated 2026-08-10T03:31:01

1 posts

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to application crash, denial of service, memory corruption, or potentially arbitrary code ex

thehackerwire@mastodon.social at 2026-08-10T03:59:51.000Z ##

🟠 CVE-2026-19387 - High (7.6)

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15534
(0 None)

EPSS: 0.20%

updated 2026-08-09T22:16:30.373000

1 posts

Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the sig

offseq@infosec.exchange at 2026-08-10T03:00:24.000Z ##

CVE-2026-15534: HIGH severity in LEONT perl (≤5.45.1) — Integer overflow in regex engine can cause heap corruption or crashes when large inputs and crafted patterns are processed. Avoid risky patterns until patched. radar.offseq.com/threat/cve-20 #OffSeq #Perl #Vuln #AppSec

##

CVE-2026-19348
(9.8 CRITICAL)

EPSS: 2.46%

updated 2026-08-09T12:32:52

2 posts

A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation of the argument enable/name/mac results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be us

thehackerwire@mastodon.social at 2026-08-09T12:00:26.000Z ##

🔴 CVE-2026-19348 - Critical (9.8)

A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation of t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-09T12:00:24.000Z ##

CVE-2026-19348 in Shenzhen Aitemi M300 Wi-Fi Repeater: CRITICAL command injection via /protocol.csp (enable, name, mac). Public exploit code out; no patch yet. Restrict access & monitor traffic. radar.offseq.com/threat/cve-20 #OffSeq #CVE202619348 #IoTSecurity

##

CVE-2026-19346
(8.8 HIGH)

EPSS: 2.22%

updated 2026-08-09T12:32:46

1 posts

A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.

thehackerwire@mastodon.social at 2026-08-09T11:00:17.000Z ##

🟠 CVE-2026-19346 - High (8.8)

A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection. The attack can be initiated remotely....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19195
(7.8 HIGH)

EPSS: 0.11%

updated 2026-08-09T06:32:38

1 posts

A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in the library ZyArk.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be performed locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond

1 repos

https://github.com/patrickt2017/CVE-2026-19195-PoC

thehackerwire@mastodon.social at 2026-08-09T08:00:56.000Z ##

🟠 CVE-2026-19195 - High (7.8)

A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in the library ZyArk.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19193
(7.8 HIGH)

EPSS: 0.11%

updated 2026-08-09T06:32:38

1 posts

A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of the component Minifilter Port. Executing a manipulation can lead to improper access controls. The attack needs to be launched locally. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

1 repos

https://github.com/patrickt2017/CVE-2026-19193-PoC

thehackerwire@mastodon.social at 2026-08-09T08:00:40.000Z ##

🟠 CVE-2026-19193 - High (7.8)

A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of the component Minifilter Port. Executing a manipulation can lead to improper access controls. The attack needs to be launch...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64564
(9.8 CRITICAL)

EPSS: 0.48%

updated 2026-08-09T04:17:43.283000

6 posts

In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv()). For an ASCONF located through its Address Parameter by __sctp_rcv_asconf_lookup(), that cached transport corresponds

3 repos

https://github.com/suominen/sctphantom

https://github.com/ethanolgolf/CVE-2026-64564

https://github.com/HackSpeak/CVE-2026-64564

linuxse@friendica.helvetet.eu at 2026-08-10T05:40:52.000Z ## En 18 år gammal sårbarhet i Linuxkärnans SCTP-kod kan ge lokala angripare fullständig rootåtkomst. Säkerhetsforskarna bakom upptäckten har även visat att felet under vissa förutsättningar kan användas för att ta sig ur en container och angripa värdsystemet. Sårbarheten har fått namnet SCTPhantom och registrerats som CVE-2026-64564. Den finns i Linuxkärnans stöd för nätverksprotokollet SCTP och […]
SCTPhantom – 18 år gammal Linux-bugg kan ge angripare rootåtkomst ##

DailyCyberSecurity@infosec.exchange at 2026-08-10T01:55:44.000Z ##

CVE-2026-64564: SCTP Flaw Enables Container Escape

securityonline.info/sctp-uaf-c

##

beyondmachines1@infosec.exchange at 2026-08-09T14:01:06.000Z ##

SCTPhantom: 18-Year-Old Linux Kernel Flaw Allows Root Access and Container Escape

A use-after-free vulnerability in the Linux SCTP implementation (CVE-2026-64564) allows local attackers to gain root privileges and escape containers. The flaw has existed since 2008 and affects most major Linux distributions.

**If you run Linux (Debian, Ubuntu, RHEL, Rocky) on servers, containers or workstations, install the latest kernel update from your distribution vendor and reboot. The fix for CVE-2026-64564 only takes effect after the restart. If you don't use SCTP, also switch the module off (add both blacklist sctp and install sctp /bin/false to /etc/modprobe.d/sctp.conf, refresh the initramfs, and confirm with lsmod | grep sctp that nothing comes back).**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

security_crawler_carl@infosec.exchange at 2026-08-09T09:05:59.000Z ##

🏆 New Achievement! SCTPhantom Menace: Eighteen Years In The Making!

ERROR: Kernel identity verification module returned incorrect value. Duration of incorrect value: eighteen years. Tencent researchers have confirmed CVE-2026-64564, a use-after-free in Linux's SCTP networking code, allows local users to escalate to root and escape containers entirely. The bug checks a delete request against the packet's source address, then acts on a different one. The kernel trusted the wrong address. (1/2)

##

ottoto2017@prattohome.com at 2026-08-08T07:27:58.000Z ##

「18年前のLinux SCTPの脆弱性により、ローカルユーザーがroot権限を取得し、コンテナから脱出できる可能性 」: #TheHackerNews

「LinuxのSCTPネットワークコードに存在する解放済みメモリ使用のバグを悪用すると、ホスト上で完全なroot権限を取得できる可能性がある。Tencentの研究者らは、このバグを利用してコンテナから脱出し、その下にあるマシンにアクセスしたと述べている。

この脆弱性は2008年から存在していました。修正版は既にリリースされており、8月3日にリリースされた安定版カーネル7.1.6、6.18.42、6.12.101、6.6.148で修正されています。SCTP接続可能な古いカーネルを使用しているユーザーはアップデートしてください。

CVE-2026-64564 として追跡され 、 発見者によってSCTPhantom と名付けられたこの脆弱性は、カーネルCVEチームが割り当てた2日後の8月6日に公表された。 」

thehackernews.com/2026/08/18-y

#prattohome

##

_r_netsec@infosec.exchange at 2026-08-08T02:28:05.000Z ##

SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free · Tencent Zhuque Lab matrix.tencent.com/en/2026/08/

##

CVE-2026-71993
(9.8 CRITICAL)

EPSS: 1.35%

updated 2026-08-09T00:31:13

3 posts

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system.

offseq@infosec.exchange at 2026-08-10T00:00:36.000Z ##

MSI Radix AXE6600 (firmware v781521) is affected by CVE-2026-71993 (CVSS 9.8): CRITICAL command injection in openvpn via macfilter allows remote root access. Restrict management access & monitor activity. Details: radar.offseq.com/threat/msi-ra #OffSeq #Vuln #RouterSecurity #CVE2026_71993

##

offseq@infosec.exchange at 2026-08-09T01:30:28.000Z ##

MSI Radix AXE6600 v781521 suffers CRITICAL CVE-2026-71993 (CVSS 9.3): OS Command Injection via macfilter allows remote root access. Restrict remote access & monitor openvpn/macfilter activity. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE #RouterSecurity #Infosec

##

thehackerwire@mastodon.social at 2026-08-09T01:00:57.000Z ##

🔴 CVE-2026-71993 - Critical (9.8)

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71986
(9.8 CRITICAL)

EPSS: 1.35%

updated 2026-08-09T00:31:13

2 posts

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the dmz function to execute malicious commands and obtain root privileges on the underlying system.

offseq@infosec.exchange at 2026-08-09T13:30:10.000Z ##

MSI Radix AXE6600 (v781521) is affected by CVE-2026-71986 (CRITICAL) — OS command injection in dmz function allows remote root access. No patch yet, monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Infosec #RouterSecurity

##

thehackerwire@mastodon.social at 2026-08-09T01:59:56.000Z ##

🔴 CVE-2026-71986 - Critical (9.8)

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71992
(9.8 CRITICAL)

EPSS: 1.35%

updated 2026-08-09T00:31:13

2 posts

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system.

offseq@infosec.exchange at 2026-08-09T03:00:23.000Z ##

MSI Radix AXE6600 routers (v781521) affected by CRITICAL OS command injection (CVE-2026-71992, CVSS 9.3). Remote attackers can execute root commands — no auth needed. Restrict access, monitor logs. No patch yet. radar.offseq.com/threat/cve-20 #OffSeq #CVE202671992 #RouterSecurity

##

thehackerwire@mastodon.social at 2026-08-09T01:00:21.000Z ##

🔴 CVE-2026-71992 - Critical (9.8)

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71984
(9.8 CRITICAL)

EPSS: 1.35%

updated 2026-08-09T00:31:13

1 posts

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the urlfilter function to inject malicious commands and obtain root privileges on the underlying system.

thehackerwire@mastodon.social at 2026-08-09T01:01:07.000Z ##

🔴 CVE-2026-71984 - Critical (9.8)

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the urlfilter function ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71987
(9.8 CRITICAL)

EPSS: 1.35%

updated 2026-08-09T00:31:07

2 posts

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.

offseq@infosec.exchange at 2026-08-09T10:30:26.000Z ##

CVE-2026-71987: MSI Radix AXE6600 (v781521) suffers from a CRITICAL OS command injection vulnerability (CVSS 9.3). Remote, unauthenticated code execution possible with root privileges. Restrict device access and monitor! radar.offseq.com/threat/cve-20 #OffSeq #CVE202671987 #Infosec #RouterSecurity

##

thehackerwire@mastodon.social at 2026-08-09T02:00:06.000Z ##

🔴 CVE-2026-71987 - Critical (9.8)

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71988
(9.8 CRITICAL)

EPSS: 1.35%

updated 2026-08-09T00:31:07

2 posts

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.

offseq@infosec.exchange at 2026-08-09T09:00:23.000Z ##

MSI Radix AXE6600 (v781521) hit by CRITICAL OS command injection (CVE-2026-71988, CVSS 9.3). Remote attackers can gain root via portFw/alg — full device takeover possible. Patch status unconfirmed. More: radar.offseq.com/threat/cve-20 #OffSeq #CVE202671988 #Infosec #RouterSecurity

##

thehackerwire@mastodon.social at 2026-08-09T02:00:18.000Z ##

🔴 CVE-2026-71988 - Critical (9.8)

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71991
(9.8 CRITICAL)

EPSS: 1.35%

updated 2026-08-09T00:31:07

2 posts

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the Telnet configuration interface to inject malicious commands and obtain root privileges on the underlying system.

thehackerwire@mastodon.social at 2026-08-09T01:00:10.000Z ##

🔴 CVE-2026-71991 - Critical (9.8)

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can e...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-09T00:00:35.000Z ##

MSI Radix AXE6600 routers (v781521) affected by CRITICAL CVE-2026-71991 🛡️. OS command injection via TelnetSSH enables remote root access. Restrict Telnet, segment devices, monitor for vendor fixes. radar.offseq.com/threat/cve-20 #OffSeq #CVE202671991 #RouterSecurity

##

CVE-2026-71990
(9.8 CRITICAL)

EPSS: 1.35%

updated 2026-08-09T00:16:48.130000

2 posts

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the SSH configuration interface to inject malicious commands and obtain root privileges on the underlying system.

offseq@infosec.exchange at 2026-08-09T04:30:25.000Z ##

MSI Radix AXE6600 (v781521) hit by CRITICAL OS command injection (CVE-2026-71990, CVSS 9.3). Remote attackers can gain root via SSH config. No patch yet — restrict SSH access & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE #infosec #router

##

thehackerwire@mastodon.social at 2026-08-09T01:00:00.000Z ##

🔴 CVE-2026-71990 - Critical (9.8)

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can expl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71985
(9.8 CRITICAL)

EPSS: 1.35%

updated 2026-08-09T00:16:47.360000

1 posts

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the accesscontrol function to execute malicious commands and obtain root privileges on the underlying system.

thehackerwire@mastodon.social at 2026-08-09T01:01:18.000Z ##

🔴 CVE-2026-71985 - Critical (9.8)

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71953
(9.8 CRITICAL)

EPSS: 2.09%

updated 2026-08-08T18:30:30

1 posts

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary malicious commands into the ntpServerIp1 field, resulting in command execution with root privileges.

thehackerwire@mastodon.social at 2026-08-09T05:00:52.000Z ##

🔴 CVE-2026-71953 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary malicious commands into the ntpSe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71958
(9.8 CRITICAL)

EPSS: 0.56%

updated 2026-08-08T18:30:30

1 posts

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username fields and execute arbitrary commands by crafting a specific payload, or cause the device to crash.

thehackerwire@mastodon.social at 2026-08-09T00:00:53.000Z ##

🔴 CVE-2026-71958 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71954
(9.8 CRITICAL)

EPSS: 2.13%

updated 2026-08-08T18:30:30

1 posts

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the tunnelid and sessionid fields, resulting in command execution with root privileges.

thehackerwire@mastodon.social at 2026-08-08T18:00:44.000Z ##

🔴 CVE-2026-71954 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71947
(9.8 CRITICAL)

EPSS: 2.09%

updated 2026-08-08T18:30:29

1 posts

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host and ipVer fields, resulting in command execution with root privileges.

thehackerwire@mastodon.social at 2026-08-09T08:00:29.000Z ##

🔴 CVE-2026-71947 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can inject arbitrary malicious com...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71945
(9.8 CRITICAL)

EPSS: 2.09%

updated 2026-08-08T18:30:29

1 posts

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges.

thehackerwire@mastodon.social at 2026-08-09T07:00:13.000Z ##

🔴 CVE-2026-71945 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can inject arbitrary malicious comma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71952
(9.8 CRITICAL)

EPSS: 2.09%

updated 2026-08-08T18:30:29

1 posts

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbitrary malicious commands into the oldPIn field, resulting in command execution with root privileges.

thehackerwire@mastodon.social at 2026-08-09T05:00:41.000Z ##

🔴 CVE-2026-71952 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbitrary malicious commands int...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71951
(9.8 CRITICAL)

EPSS: 2.09%

updated 2026-08-08T18:30:29

1 posts

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject arbitrary malicious commands into the IMEI_value field, resulting in command execution with root privileges.

thehackerwire@mastodon.social at 2026-08-09T05:00:28.000Z ##

🔴 CVE-2026-71951 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject arbitrary malicious commands into the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71950
(9.8 CRITICAL)

EPSS: 2.09%

updated 2026-08-08T18:30:29

1 posts

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject arbitrary malicious commands into the action_value field, resulting in command execution with root privileges.

thehackerwire@mastodon.social at 2026-08-09T02:01:16.000Z ##

🔴 CVE-2026-71950 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject arbitrary malicious commands into the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71957
(9.8 CRITICAL)

EPSS: 0.59%

updated 2026-08-08T18:30:29

1 posts

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by crafting a specific payload, or cause the device to crash.

thehackerwire@mastodon.social at 2026-08-09T00:00:19.000Z ##

🔴 CVE-2026-71957 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-42170
(7.8 HIGH)

EPSS: 0.19%

updated 2026-08-08T18:30:29

1 posts

A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS file declares a D3D9 pixel format but sets a lower bits-per-pixel (bpp) value in the header, the loader allocates an undersized heap buffer. Subsequent pixel data consumption at the real format's stride causes a write past the heap buffer boundary, leading to heap metadata corrupt

thehackerwire@mastodon.social at 2026-08-08T16:59:53.000Z ##

🟠 CVE-2026-42170 - High (7.8)

A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS file declares a D3D9 pixel format but sets a lower bits-per-pixel (bpp) value in the header, the loader allocates an undersized ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71946
(9.8 CRITICAL)

EPSS: 2.09%

updated 2026-08-08T18:30:25

1 posts

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges.

thehackerwire@mastodon.social at 2026-08-09T07:00:23.000Z ##

🔴 CVE-2026-71946 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71956
(9.8 CRITICAL)

EPSS: 1.74%

updated 2026-08-08T18:16:56.503000

1 posts

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst field, resulting in command execution with root privileges.

thehackerwire@mastodon.social at 2026-08-09T00:00:07.000Z ##

🔴 CVE-2026-71956 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst fiel...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16948(CVSS UNKNOWN)

EPSS: 0.13%

updated 2026-08-08T09:30:28

1 posts

The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects them on admin pages reachable by low-privileged users, allowing users with a role as low as Subscriber to modify site-wide presentation settings and delete imported site-builder content.

offseq@infosec.exchange at 2026-08-08T09:00:24.000Z ##

CVE-2026-16948 | HIGH severity in Solace Extra WP plugin <1.6.1: Missing capability checks on AJAX actions lets Subscribers change site settings & delete imported content. Patch status unknown — tighten role permissions. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE2026_16948

##

CVE-2026-16955(CVSS UNKNOWN)

EPSS: 0.16%

updated 2026-08-08T09:30:28

1 posts

The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwarding the contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host. Reaching the issue at subscriber level requires a non-default public API feature to be enabled; otherwise the same issue is

offseq@infosec.exchange at 2026-08-08T07:30:23.000Z ##

CVE-2026-16955: HIGH severity path traversal in AI Engine WP plugin <3.6.6. Subscribers can read arbitrary files if public API is enabled. Restrict API & admin privileges. Await patch. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE2026_16955 #Security

##

CVE-2026-71560
(9.1 CRITICAL)

EPSS: 0.55%

updated 2026-08-08T03:32:14

1 posts

Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-bounds heap read in the tagged integer fast-path deserializer, potentially causing information disclosure or denial of service. Users are recommended to

thehackerwire@mastodon.social at 2026-08-08T12:00:46.000Z ##

🔴 CVE-2026-71560 - Critical (9.1)

Out-of-bounds Read vulnerability in Apache Fory C++ deserialization.

This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-b...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5857
(8.1 HIGH)

EPSS: 0.53%

updated 2026-08-08T03:16:46.377000

1 posts

Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag set. On the next TCP segment, tcp_input() re-invokes the parser with topic_received==0, and the persisted topic_len_received==1 skips the length-reading block containing the guard, fall

thehackerwire@mastodon.social at 2026-08-10T02:00:37.000Z ##

🟠 CVE-2026-5857 - High (8.1)

Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag set. On the next TCP segment, tc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71558
(9.8 CRITICAL)

EPSS: 0.71%

updated 2026-08-08T00:52:49.367000

1 posts

Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization, causing an object of an incompatible type to be treated as the declared base type. This may result in undefined behavior and potentially lead to den

thehackerwire@mastodon.social at 2026-08-08T11:00:28.000Z ##

🔴 CVE-2026-71558 - Critical (9.8)

Heap type confusion vulnerability in Apache Fory C++ deserialization.

This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserializat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20347
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-07T22:16:58.003000

1 posts

A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in Mach-O files during scanning, which may result in an out-of-bounds buffer read. An attacker could ex

thehackerwire@mastodon.social at 2026-08-08T10:00:12.000Z ##

🟠 CVE-2026-20347 - High (7.5)

A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device.

This vulnerabili...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20339
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-07T22:16:57.707000

2 posts

A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an integer overflow. An attacker could exploit thi

AAKL@infosec.exchange at 2026-08-10T16:26:02.000Z ##

New.

CISA: Gunra Ransomware Advisory cisa.gov/news-events/cybersecu

Cisco:

Advisory for a high-severity vulnerability first published on August 7:

CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #CISA #ransomware #cybercrime #vulnerability

##

thehackerwire@mastodon.social at 2026-08-08T11:00:18.000Z ##

🟠 CVE-2026-20339 - High (7.5)

A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device.

This vulnerabili...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15361
(8.1 HIGH)

EPSS: 0.22%

updated 2026-08-07T21:31:36

1 posts

The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscribers, to perform SQL injection attacks.

thehackerwire@mastodon.social at 2026-08-08T15:00:13.000Z ##

🟠 CVE-2026-15361 - High (8.1)

The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscrib...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16263
(8.8 HIGH)

EPSS: 0.34%

updated 2026-08-07T21:31:36

1 posts

The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a Subscriber account to include and execute arbitrary existing local PHP files on the server.

thehackerwire@mastodon.social at 2026-08-08T14:59:52.000Z ##

🟠 CVE-2026-16263 - High (8.8)

The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a Subscriber account to includ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15972
(7.5 HIGH)

EPSS: 0.39%

updated 2026-08-07T21:30:40

1 posts

Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC listeners. A remote attacker may exhaust agent file descriptors, goroutines, and memory by opening many incomplete connections, potentially preventing legitimate clients from connecting. This vulnerability, CVE-2026-

thehackerwire@mastodon.social at 2026-08-08T03:00:14.000Z ##

🟠 CVE-2026-15972 - High (7.5)

Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC listeners. A remote attacker may exhaust agent file descriptors...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64636
(7.7 HIGH)

EPSS: 0.21%

updated 2026-08-07T21:30:37

1 posts

An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.

thehackerwire@mastodon.social at 2026-08-08T07:00:58.000Z ##

🟠 CVE-2026-64636 - High (7.7)

An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16262
(7.5 HIGH)

EPSS: 0.16%

updated 2026-08-07T21:30:34

1 posts

The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that the victim's subsequent activity is stored under and readable by the attacker.

thehackerwire@mastodon.social at 2026-08-08T13:00:10.000Z ##

🟠 CVE-2026-16262 - High (7.5)

The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19082
(7.5 HIGH)

EPSS: 0.29%

updated 2026-08-07T21:17:27.317000

1 posts

Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags. copy_string_tags() computes an ASCII EXIF tag's length as `entry->size - 1` to strip the trailing NUL. A zero-count ASCII entry sets `entry->size` to 0, and the derived length reaches i_tags_add() as -1, which is interpreted as a request

thehackerwire@mastodon.social at 2026-08-08T08:00:50.000Z ##

🟠 CVE-2026-19082 - High (7.5)

Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags.

copy_string_tags() computes an ASCII EXIF tag's length as `entry->size - 1` to strip ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48097
(7.8 HIGH)

EPSS: 0.27%

updated 2026-08-07T20:16:51.893000

1 posts

NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 have a command execution vulnerability due to unsafe use of `shell=True` with commands that rely on executable resolution through the `PATH` environment variable. An attacker controlling the execution environment can place malicious executables such as sudo ea

thehackerwire@mastodon.social at 2026-08-08T07:00:27.000Z ##

🟠 CVE-2026-48097 - High (7.8)

NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 have a command execution vulnerability due to unsafe use of `shell=True` with commands that rely on executa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-63235
(7.5 HIGH)

EPSS: 0.32%

updated 2026-08-07T20:16:49.087000

1 posts

In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CONNECT packets. When clients send invalid CONNECT packets - either due to repeated attempts or failed authentication - the server may silently drop the connection or send a CONNACK but fail to close the session or deallocate internal resources. This behavior allows an attacker to c

thehackerwire@mastodon.social at 2026-08-08T07:00:48.000Z ##

🟠 CVE-2025-63235 - High (7.5)

In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CONNECT packets. When clients send invalid CONNECT packets - either due to repeated attempts or failed authentication - the server...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48039
(9.1 CRITICAL)

EPSS: 0.34%

updated 2026-08-07T19:29:59

2 posts

# Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token | Field | Value | | ---------------- | ----- | | Repository | pipeboard-co/meta-ads-mcp | | Affected version | ≤ 1.0.101 (commit 496c988 ~ 7d14226); Versions 1.0.102–1.0.105 lack git tags, so patch status is unconfirmed. | | Vulnerability | CWE-287 — Improper Authentication | | Severity | Critic

offseq@infosec.exchange at 2026-08-08T03:00:24.000Z ##

pipeboard-co meta-ads-mcp (<1.0.109) affected by CRITICAL auth bypass (CVE-2026-48039). Unauthenticated requests can access tools & leak access tokens via error responses. Patch to 1.0.109+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE202648039 #infosec #vuln

##

thehackerwire@mastodon.social at 2026-08-08T03:00:04.000Z ##

🔴 CVE-2026-48039 - Critical (9.1)

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streamable HTTP r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-50481
(9.9 CRITICAL)

EPSS: 0.46%

updated 2026-08-07T19:29:09.813000

1 posts

Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

thehackerwire@mastodon.social at 2026-08-09T12:59:55.000Z ##

🔴 CVE-2026-50481 - Critical (9.9)

Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56161
(9.6 CRITICAL)

EPSS: 0.38%

updated 2026-08-07T19:28:41.040000

1 posts

Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.

thehackerwire@mastodon.social at 2026-08-09T11:00:47.000Z ##

🔴 CVE-2026-56161 - Critical (9.6)

Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

rswebsols@mastodon.social at 2026-08-11T08:21:39.000Z ##

CVE-2026-64638: Severe Pre-Authentication XSS Flaw in WordPress Permits Remote Code Execution – Immediate Update to Version 7.0.3 #wordpress #programming

CVE-2026-64638 poses a serious pre-authentication XSS risk in WordPress that can lead to remote code execution. Immediate update to WordPress 7.0.3 is essential. Read the full incident overview and mitigation steps in our latest post: ift.tt/ghG2K8Z

Source: ift.tt/ghG2K8Z | Image: ift.tt/zle32Oa

##

decio@infosec.exchange at 2026-08-10T08:17:55.000Z ##

Dans la suite de wp2shell, encore une jolie chaîne WordPress : #XSS2Shell — CVE-2026-64638.

Au départ, on a “juste” une Reflected XSS pré-auth sur wp-login.php.

Sauf qu’en la chaînant avec plusieurs briques déjà présentes dans WordPress, on arrive à quelque chose de beaucoup moins sympa :

XSS → contexte admin → Application Password → REST API → upload de plugin → RCE 🐚

⚠️ À noter quand même : ce n’est pas du pre-auth zero-click.
Il faut qu’un admin déjà connecté clique sur un lien contrôlé par l’attaquant.

Encore un bon rappel : une “simple XSS” peut devenir franchement méchante une fois mise dans la bonne chaîne.

🩹 Corrigé dans WordPress 7.0.3.
👇
wordpress.org/news/2026/08/wor

En cas de doute sur une exploitation passée : petit coup d’œil aux Application Passwords, aux plugins récemment ajoutés et aux fichiers PHP inhabituels.

"XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)"
👇
pwn.ai/blog/xss2shell

#WordPress #XSS2Shell #CyberVeille

##

campuscodi@mastodon.social at 2026-08-09T19:57:58.000Z ##

Another one of those WordPress pre-auth RCEs

This one's named XSS2Shell, CVE-2026-64638, found with AI, patched in v7.0.3, released on Thursday

pwn.ai/blog/xss2shell

##

secdb@infosec.exchange at 2026-08-08T15:46:32.000Z ##

🚨 XSS2shell (CVE-2026-64638) has been identified as a notable vulnerability.

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.

Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim.

This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.

Discovered and responsibly disclosed by the team at pwn.ai.

ℹ️ Additional details on ZEN SecDB secdb.nttzen.cloud/updates/267

#infosec #xss2shell #wordpress #xss #rce
#nttdata #zen #secdb

##

bontchev@infosec.exchange at 2026-08-08T13:13:07.000Z ##

WordPress RCE. Every version ever released (except the latest, 7.0.3). 500+ million sites. 43% of the Internet-facing sites. Hacker's paradise.

"XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)":

pwn.ai/blog/xss2shell

##

ottoto2017@prattohome.com at 2026-08-08T06:19:36.000Z ##

「WordPressの事前認証における新たなXSS脆弱性によりPHPコードの実行につながる可能性あり - 早急に修正を! 」: #TheHackerNews

「WordPressは、ログイン画面に存在する、認証前のリフレクテッドクロスサイトスクリプティング(XSS)の脆弱性を修正しました。この脆弱性は、コンテンツ管理システムのすべてのバージョンに影響を与えます。pwn.aiは、ログインした管理者が攻撃者によって制御されたページを操作する際に、この脆弱性がサーバー上でPHPコードの実行に連鎖的に繋がる仕組みを実証しました。

CVE-2026-64638 (CVSSスコア:8.9)として追跡されている この深刻な脆弱性は、攻撃者に特別な権限を必要としません。 」

thehackernews.com/2026/08/new-

#prattohome

##

modrobert@infosec.exchange at 2026-08-08T03:04:41.000Z ##

"XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)"
pwn.ai/blog/xss2shell

##

CVE-2026-64637
(9.9 CRITICAL)

EPSS: 0.23%

updated 2026-08-07T19:18:51.483000

2 posts

Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.

thehackerwire@mastodon.social at 2026-08-08T08:00:39.000Z ##

🔴 CVE-2026-64637 - Critical (9.9)

Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-08T06:00:24.000Z ##

CVE-2026-64637 (CRITICAL, CVSS 9.9): WebPros Plesk <18.0.80 allows authenticated resellers to escalate privileges to root via XML-RPC API. Patch not confirmed — restrict access, monitor API use. radar.offseq.com/threat/cve-20 #OffSeq #Plesk #Vuln #PrivilegeEscalation

##

CVE-2026-20346
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-07T19:17:41.360000

1 posts

A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PDF files during scanning, which may result in an out-of-bounds buffer read. An attacker could exploit

thehackerwire@mastodon.social at 2026-08-08T09:00:57.000Z ##

🟠 CVE-2026-20346 - High (7.5)

A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device.

This vulnerability ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16258
(9.8 CRITICAL)

EPSS: 0.47%

updated 2026-08-07T19:17:36.727000

1 posts

The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before 4.14.5 or , this can be leveraged to achieve Remote Code Execution.

thehackerwire@mastodon.social at 2026-08-08T13:00:00.000Z ##

🔴 CVE-2026-16258 - Critical (9.8)

The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Searc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16041
(7.5 HIGH)

EPSS: 0.21%

updated 2026-08-07T19:17:36.343000

1 posts

The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star rating on stores configured to accept reviews only from verified owners.

thehackerwire@mastodon.social at 2026-08-08T12:59:50.000Z ##

🟠 CVE-2026-16041 - High (7.5)

The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chose...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16038
(9.1 CRITICAL)

EPSS: 0.24%

updated 2026-08-07T19:17:36.110000

1 posts

The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and obtain goods or services for free.

thehackerwire@mastodon.social at 2026-08-08T16:00:02.000Z ##

🔴 CVE-2026-16038 - Critical (9.1)

The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order ful...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15215
(8.8 HIGH)

EPSS: 0.35%

updated 2026-08-07T19:17:34.677000

1 posts

The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack Subscriptions for WooCommerce WordPress plugin before 2.0.1-management capabilities) t

thehackerwire@mastodon.social at 2026-08-08T15:00:03.000Z ##

🟠 CVE-2026-15215 - High (8.8)

The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protecte...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71851
(9.0 None)

EPSS: 0.32%

updated 2026-08-07T18:50:37

2 posts

### Summary `CryptoJS.lib.WordArray.random()` in affected versions is not a cryptographically secure random number generator. Nominal requests for 128 or 256 bits of entropy produce effective search spaces of approximately 2^39 and 2^47 possibilities — small enough to enumerate on commodity hardware. Coinspect's [Ill Bloom](https://www.coinspect.com/blog/ill-bloom-investigation/) investigation c

offseq@infosec.exchange at 2026-08-08T04:30:25.000Z ##

CVE-2026-71851 (CRITICAL, CVSS 9): brix crypto-js <4.0.0 uses weak RNG in WordArray.random(), risking private key recovery in wallet apps using BIP39. Upgrade to 4.0.0+ now. radar.offseq.com/threat/cve-20 #OffSeq #CryptoJS #InfoSec #Vulnerability

##

thehackerwire@mastodon.social at 2026-08-08T03:00:24.000Z ##

🔴 CVE-2026-71851 - Critical (9)

crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded from Math....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16030
(8.1 HIGH)

EPSS: 0.23%

updated 2026-08-07T18:32:49

1 posts

The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts.

thehackerwire@mastodon.social at 2026-08-08T15:59:53.000Z ##

🟠 CVE-2026-16030 - High (8.1)

The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71559
(7.5 HIGH)

EPSS: 0.59%

updated 2026-08-07T18:32:49

1 posts

Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This issue affects Apache Fory: from 0.16.0 before 1.5.0.  Users of other language implementations are not affected. Users are recommended to upgrade to version 1.5.0

thehackerwire@mastodon.social at 2026-08-08T12:00:29.000Z ##

🟠 CVE-2026-71559 - High (7.5)

Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic.

This issue aff...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67688
(9.8 CRITICAL)

EPSS: 0.59%

updated 2026-08-07T18:32:48

1 posts

ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker to execute arbitrary code.

thehackerwire@mastodon.social at 2026-08-09T14:59:59.000Z ##

🔴 CVE-2026-67688 - Critical (9.8)

ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker to execute arbitrary code.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45198
(7.8 HIGH)

EPSS: 0.12%

updated 2026-08-07T18:32:48

1 posts

Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause GPU Firmware to boot up using data from non-secure memory. The GPU thread of control (Firmware) uses a pointer from non-secure memory belonging to the Rich Execution Environment (REE) when saving or retrieving internal data between the tightly coupled private memory to main mem

thehackerwire@mastodon.social at 2026-08-09T10:00:10.000Z ##

🟠 CVE-2026-45198 - High (7.8)

Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause GPU Firmware to boot up using data from non-secure memory.

The GPU thread of control (Firmware) uses a pointer from non-secur...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20348
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-07T18:31:54

1 posts

A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in XAR files during scanning. An attacker could exploit this vulnerability by submitting a crafted file that

thehackerwire@mastodon.social at 2026-08-08T10:00:28.000Z ##

🟠 CVE-2026-20348 - High (7.5)

A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device.

This vulnerability ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20345
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-07T18:31:54

1 posts

A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device. This vulnerability is due to improper handling of an endian conversion operation, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerabil

thehackerwire@mastodon.social at 2026-08-08T09:00:42.000Z ##

🟠 CVE-2026-20345 - High (7.5)

A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device.

This vulnerability ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20338
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-07T18:31:53

4 posts

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to ca

cyberworldops at 2026-08-10T20:10:00.845Z ##

Cisco disclosed seven high-severity vulnerabilities in ClamAV, the open-source antivirus engine used in Secure Endpoint Connector across Windows, macOS, and Linux. Two of the flaws (CVE-2026-20337 and CVE-2026-20338) already have public proof-of-concept exploits, elevating the risk. The vulnerabilities can trigger denial-of-service conditions.

cyberworldops.eu/en/cisco-repo

##

cyberworldops@infosec.exchange at 2026-08-10T20:10:00.000Z ##

Cisco disclosed seven high-severity vulnerabilities in ClamAV, the open-source antivirus engine used in Secure Endpoint Connector across Windows, macOS, and Linux. Two of the flaws (CVE-2026-20337 and CVE-2026-20338) already have public proof-of-concept exploits, elevating the risk. The vulnerabilities can trigger denial-of-service conditions.

#ClamAV #Cisco #CVE #InfoSec

cyberworldops.eu/en/cisco-repo

##

AAKL@infosec.exchange at 2026-08-10T16:26:02.000Z ##

New.

CISA: Gunra Ransomware Advisory cisa.gov/news-events/cybersecu

Cisco:

Advisory for a high-severity vulnerability first published on August 7:

CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #CISA #ransomware #cybercrime #vulnerability

##

thehackerwire@mastodon.social at 2026-08-08T11:00:08.000Z ##

🟠 CVE-2026-20338 - High (7.5)

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.

This vulnerability is due to improper memory handling when processing content in zip files durin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68772
(8.0 HIGH)

EPSS: 0.40%

updated 2026-08-07T18:31:53

1 posts

ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by planting a malicious pickle file. Attackers can replace a stored artifact.pkl file with a crafted cloudpickle payload containing a malicious __reduce__ method, which executes arbitrary system commands wh

thehackerwire@mastodon.social at 2026-08-08T09:00:31.000Z ##

🟠 CVE-2026-68772 - High (8)

ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by planting a malicious pickle file. Attackers can re...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20337
(7.5 HIGH)

EPSS: 0.36%

updated 2026-08-07T18:31:52

5 posts

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A success

cyberworldops at 2026-08-10T20:10:00.845Z ##

Cisco disclosed seven high-severity vulnerabilities in ClamAV, the open-source antivirus engine used in Secure Endpoint Connector across Windows, macOS, and Linux. Two of the flaws (CVE-2026-20337 and CVE-2026-20338) already have public proof-of-concept exploits, elevating the risk. The vulnerabilities can trigger denial-of-service conditions.

cyberworldops.eu/en/cisco-repo

##

cyberworldops@infosec.exchange at 2026-08-10T20:10:00.000Z ##

Cisco disclosed seven high-severity vulnerabilities in ClamAV, the open-source antivirus engine used in Secure Endpoint Connector across Windows, macOS, and Linux. Two of the flaws (CVE-2026-20337 and CVE-2026-20338) already have public proof-of-concept exploits, elevating the risk. The vulnerabilities can trigger denial-of-service conditions.

#ClamAV #Cisco #CVE #InfoSec

cyberworldops.eu/en/cisco-repo

##

AAKL@infosec.exchange at 2026-08-10T16:26:02.000Z ##

New.

CISA: Gunra Ransomware Advisory cisa.gov/news-events/cybersecu

Cisco:

Advisory for a high-severity vulnerability first published on August 7:

CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #CISA #ransomware #cybercrime #vulnerability

##

hugovalters@mastodon.social at 2026-08-08T14:02:58.000Z ##

CVE-2026-20337 - Memory corruption in ClamAV ZIP parsing, out-of-bounds write DoS. CVSS 7.5. Unpatched. Update or mitigate immediately. #CVE #Cisco #infosec

valtersit.com/cve/CVE-2026-203

##

thehackerwire@mastodon.social at 2026-08-08T10:00:41.000Z ##

🟠 CVE-2026-20337 - High (7.5)

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.

This vulnerability is due to improper boundary checks for content in zip files during scanning, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70628
(7.8 HIGH)

EPSS: 0.15%

updated 2026-08-07T18:31:42

1 posts

FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expression to wrap to INT_MIN, bypassing the PARSE_BUF_SIZE comparison and invoking memcpy() with attacker-c

thehackerwire@mastodon.social at 2026-08-09T14:00:12.000Z ##

🟠 CVE-2026-70628 - High (7.8)

FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67422
(7.5 HIGH)

EPSS: 0.58%

updated 2026-08-07T18:26:08

1 posts

### Summary Four inline processors in pymdown-extensions contain regular expressions with exponential backtracking. A single untrusted Markdown line under 50 bytes drives `markdown.markdown()` into unbounded CPU on the rendering thread (seconds at ~45 bytes, growing exponentially with each added character). All four fire in the extension's **default configuration** and are reachable through the d

thehackerwire@mastodon.social at 2026-08-10T01:00:00.000Z ##

🟠 CVE-2026-67422 - High (7.5)

pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclink) use regular expressions whose content groups can partition a run...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70634
(8.1 HIGH)

EPSS: 0.41%

updated 2026-08-07T18:17:22.580000

1 posts

TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compression/algorithms/dictionary.c). The forward path validates the decoded index; the reverse path uses an assertion compiled out of release builds, leaving the 64-bit Simple8b index unvalidated and the read offset attacker-controlled. Attackers with DML

thehackerwire@mastodon.social at 2026-08-09T13:00:15.000Z ##

🟠 CVE-2026-70634 - High (8.1)

TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compression/algorithms/dictionary.c). The forward path validates the decoded index; the reverse path us...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70632
(7.8 HIGH)

EPSS: 0.21%

updated 2026-08-07T18:17:22.307000

1 posts

FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing

thehackerwire@mastodon.social at 2026-08-09T13:00:05.000Z ##

🟠 CVE-2026-70632 - High (7.8)

FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stre...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67622
(9.9 CRITICAL)

EPSS: 0.25%

updated 2026-08-07T18:17:21.357000

1 posts

Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID to Assistants endpoints without workspace ownership verification. Attackers can enumerate cross-workspace assistant metadata, retrieve file and vector s

thehackerwire@mastodon.social at 2026-08-10T00:59:51.000Z ##

🔴 CVE-2026-67622 - Critical (9.9)

Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67621
(7.6 HIGH)

EPSS: 0.27%

updated 2026-08-07T18:17:21.223000

1 posts

Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permissions can send direct HTTP requests to the upsert and refresh document store routes to trigger document ingestion, refresh vector database contents, con

thehackerwire@mastodon.social at 2026-08-09T15:59:50.000Z ##

🟠 CVE-2026-67621 - High (7.6)

Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64665
(8.1 HIGH)

EPSS: 0.31%

updated 2026-08-07T18:17:20.827000

1 posts

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an existing user, potentially including a super admin, without knowing that user's password, because the application matched OAuth identities to accounts by emai

thehackerwire@mastodon.social at 2026-08-10T01:00:10.000Z ##

🟠 CVE-2026-64665 - High (8.1)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an exist...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15733
(9.8 CRITICAL)

EPSS: 3.90%

updated 2026-08-07T18:17:08.840000

1 posts

A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attackers to execute arbitrary commands as root.

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-14943
(7.5 HIGH)

EPSS: 0.26%

updated 2026-08-07T18:17:08.120000

1 posts

The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API access to authenticated users when a specific option is enabled, allowing unauthenticated visitors to bypass the sitewide password gate and read otherwise-protected content and account identifiers via the REST API. This re-introduces a previously-fixed i

thehackerwire@mastodon.social at 2026-08-08T17:00:37.000Z ##

🟠 CVE-2026-14943 - High (7.5)

The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API access to authenticated users when a specific option is enabled, allowing unauthenticated visitors ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14365
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-08-07T18:17:07.753000

1 posts

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to change the password of arbitrary user accounts, including administrators, which can b

thehackerwire@mastodon.social at 2026-08-09T09:00:10.000Z ##

🔴 CVE-2026-14365 - Critical (9.8)

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perfo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14364
(9.8 CRITICAL)

EPSS: 0.29%

updated 2026-08-07T18:17:07.627000

1 posts

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the plugin not properly validating a user's identity before resetting their password. This makes it possible for unauthenticated attackers to reset the password of arbitrary user accounts,

thehackerwire@mastodon.social at 2026-08-09T08:59:59.000Z ##

🔴 CVE-2026-14364 - Critical (9.8)

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the plugin not properly validatin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14205
(9.8 CRITICAL)

EPSS: 0.27%

updated 2026-08-07T18:17:07.073000

1 posts

The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without making a payment.

thehackerwire@mastodon.social at 2026-08-08T16:00:12.000Z ##

🔴 CVE-2026-14205 - Critical (9.8)

The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed book...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-50515
(9.9 CRITICAL)

EPSS: 0.91%

updated 2026-08-07T18:05:55.493000

1 posts

Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-08-09T10:00:32.000Z ##

🔴 CVE-2026-50515 - Critical (9.9)

Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70559
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-07T17:17:07.733000

1 posts

Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation that short-circuits the class-level @SaCheckLogin, so the Sa-Token interceptor lets the request through with no session or role check. Any remote unauthenticated caller who can reach the Dinky HTTP port (8888 by default) receives the full live system configuration (54 entries on a

1 repos

https://github.com/codeb0ssx/CVE-2026-70559-PoC

thehackerwire@mastodon.social at 2026-08-09T14:00:02.000Z ##

🟠 CVE-2026-70559 - High (7.5)

Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation that short-circuits the class-level @SaCheckLogin, so the Sa-Token interceptor lets the request through with no session or role ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5855
(7.5 HIGH)

EPSS: 0.54%

updated 2026-08-07T17:17:05.047000

1 posts

Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer length argument and reads up to six bytes from the input buffer with no bounds check. The caller in lwm2m-engine.c iterates while there is at least one byte remaining, so a crafted CoAP WRITE to any LwM2M endpoint whose final TLV supplies exactly one byte triggers up to five out-of-bo

thehackerwire@mastodon.social at 2026-08-10T02:00:26.000Z ##

🟠 CVE-2026-5855 - High (7.5)

Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer length argument and reads up to six bytes from the input buffer with no bounds check. The caller in lwm2m-engine.c iterates while th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67687
(8.8 HIGH)

EPSS: 0.53%

updated 2026-08-07T16:17:27.217000

1 posts

Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleController.java and system/user/update endpoint in UserController.java

1 repos

https://github.com/qflksheep/CVE-2026-67687-ICS-Park-Smart-Park-Management-System-v2.0

thehackerwire@mastodon.social at 2026-08-09T14:59:50.000Z ##

🟠 CVE-2026-67687 - High (8.8)

Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleController.java and system/user/update endpoint in UserController.java

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19189
(7.8 HIGH)

EPSS: 0.11%

updated 2026-08-07T16:17:23.463000

1 posts

A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functionality in the library C:\Windows\System32\drivers\scdemu.sys of the component Kernel Driver. The manipulation results in improper privilege management. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The vendor

thehackerwire@mastodon.social at 2026-08-09T10:00:21.000Z ##

🟠 CVE-2026-19189 - High (7.8)

A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functionality in the library C:\Windows\System32\drivers\scdemu.sys of the component Kernel Driver. The manipulation results in improper ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67689
(9.8 CRITICAL)

EPSS: 0.69%

updated 2026-08-07T15:34:17

1 posts

SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated list endpoints

1 repos

https://github.com/qflksheep/CVE-2026-67689-FineAdmin.Mvc-vulnerability

thehackerwire@mastodon.social at 2026-08-09T15:00:09.000Z ##

🔴 CVE-2026-67689 - Critical (9.8)

SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated list endpoints

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49007
(7.5 HIGH)

EPSS: 0.34%

updated 2026-08-07T09:32:04

1 posts

By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for the device's web interface.

thehackerwire@mastodon.social at 2026-08-08T12:00:57.000Z ##

🟠 CVE-2026-49007 - High (7.5)

By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for the device's web interface.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19192
(7.8 HIGH)

EPSS: 0.11%

updated 2026-08-07T06:30:27

1 posts

A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C:\DeepCool\resources\service\x64\DeepCoolDisplayService.exe. Performing a manipulation results in improper access controls. The attack must be initiated from a local position. The exploit is now public and may be used.

thehackerwire@mastodon.social at 2026-08-08T17:00:57.000Z ##

🟠 CVE-2026-19192 - High (7.8)

A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C:\DeepCool\resources\service\x64\DeepCoolDisplayService.exe. Performing a manipulation results in improper access controls. The...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19191
(7.8 HIGH)

EPSS: 0.11%

updated 2026-08-07T06:30:26

1 posts

A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code of the file C:\Program Files\StableBit\DrivePool\DrivePool.Service.exe of the component DrivePoolService. Such manipulation leads to permission issues. The attack must be carried out locally. The exploit has been disclosed publicly and may be used.

thehackerwire@mastodon.social at 2026-08-08T17:00:47.000Z ##

🟠 CVE-2026-19191 - High (7.8)

A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code of the file C:\Program Files\StableBit\DrivePool\DrivePool.Service.exe of the component DrivePoolService. Such manipulation lead...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19190
(7.8 HIGH)

EPSS: 0.14%

updated 2026-08-07T06:30:25

1 posts

A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Files (x86)\StableBit\Scanner\Service\Scanner.Service.exe of the component ScannerService. This manipulation causes permission issues. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks.

thehackerwire@mastodon.social at 2026-08-09T09:00:20.000Z ##

🟠 CVE-2026-19190 - High (7.8)

A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Files (x86)\StableBit\Scanner\Service\Scanner.Service.exe of the component ScannerService. This manipulation causes permission iss...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65400
(7.1 HIGH)

EPSS: 0.30%

updated 2026-08-07T03:31:32

2 posts

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

sayzard@mastodon.sayzard.org at 2026-08-10T20:42:09.000Z ##

CVE-2026-65400: Apple macOS Screen Sharing authentication bypass

Apple이 macOS Tahoe 26.6.1에서 Screen Sharing 인증 우회 취약점(CVE-2026-65400)을 수정했다. 동일 네트워크의 공격자가 유효한 자격 증명 없이 Screen Sharing에 인증할 수 있어 원격 화면 접근 및 세션 탈취 위험으로 이어질 수 있다. 근본 원인은 인증 상태 관리 문제이며, Apple은 개선된 state management로 이를 해결했다고 밝혔다. macOS Tahoe 사용 조직은 26.6.1 업데이트를 우선 적용하고, 패치 전에는 Screen Sharing 노출을 제한하는 것이 권장된다.

support.apple.com/en-us/148170

#macos #security #authentication #screensharing #cve

##

nicd@masto.ahlcode.fi at 2026-08-08T21:51:23.000Z ##

Whoa, macOS Sequoia 15.7.9 changes:

> An attacker on the network may be able to authenticate to Screen Sharing without valid credentials

xcancel.com/calif_io/status/20

> If Screen Sharing is enabled, any network attacker can exploit the bug to log in as any account, without knowing the password.

Good thing it requires screen sharing to be enabled though.

CVE-2026-65400

##

CVE-2026-49163
(8.8 HIGH)

EPSS: 0.62%

updated 2026-08-07T00:31:28

1 posts

Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.

thehackerwire@mastodon.social at 2026-08-09T11:01:06.000Z ##

🟠 CVE-2026-49163 - High (8.8)

Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70558
(9.8 CRITICAL)

EPSS: 0.60%

updated 2026-08-07T00:31:27

1 posts

Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and /download/** is excluded from the Sa-Token interceptor, so the only guard is a header equality check against a dinkyToken value whose default (efda1551-7958-4e0f-80a8-dfd107df3e38) is hardcoded i

thehackerwire@mastodon.social at 2026-08-09T13:59:52.000Z ##

🔴 CVE-2026-70558 - Critical (9.8)

Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and /download/** is excluded from the Sa-Token...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56162
(10.0 CRITICAL)

EPSS: 0.48%

updated 2026-08-07T00:31:27

1 posts

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

thehackerwire@mastodon.social at 2026-08-09T11:00:57.000Z ##

🔴 CVE-2026-56162 - Critical (10)

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53984
(9.1 CRITICAL)

EPSS: 0.38%

updated 2026-08-07T00:31:26

1 posts

Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauthenticated network peer to wipe or replace the entire SQLite database by sending a single full_restore command with a caller-supplied SQL blob. Attackers can connect to the Socket.IO server on port 700

thehackerwire@mastodon.social at 2026-08-10T02:59:59.000Z ##

🔴 CVE-2026-53984 - Critical (9.1)

Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauthenticated network peer to wipe or replace the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53983
(8.6 HIGH)

EPSS: 0.33%

updated 2026-08-07T00:31:26

1 posts

Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital-source configuration path that allows any unauthenticated Socket.IO client to cause the ground-station process to issue outbound HTTP requests to attacker-chosen destinations. Attackers can connect to the Socket.IO server on port 7000 without credentials due to disabled authenti

thehackerwire@mastodon.social at 2026-08-10T02:59:50.000Z ##

🟠 CVE-2026-53983 - High (8.6)

Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital-source configuration path that allows any unauthenticated Socket.IO client to cause the ground-station process to issue outb...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19036
(7.2 HIGH)

EPSS: 2.47%

updated 2026-08-06T22:16:51.977000

1 posts

A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulation of the argument ppp_custom results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. This project is superseded by FreshTomato.

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-19035
(7.2 HIGH)

EPSS: 2.47%

updated 2026-08-06T16:16:40.753000

1 posts

A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The manipulation of the argument new_qoslimit_enable leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used. This project is superseded by FreshTomato.

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-10090
(9.9 CRITICAL)

EPSS: 0.25%

updated 2026-08-06T15:37:22.093000

1 posts

A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM hub namespace can create a Channel resource pointing to a Helm repository they control and a Subscription resource referencing it. The app-subscription controller fetches and applies t

CVE-2026-19034
(7.2 HIGH)

EPSS: 2.47%

updated 2026-08-06T12:31:21

1 posts

A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function new_qoslimit_stop of the file /tmp/qoslimittc_stop.sh. Executing a manipulation of the argument wan_iface can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This project is superseded by FreshTomato.

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-44945
(9.1 CRITICAL)

EPSS: 0.30%

updated 2026-08-06T05:17:03.793000

2 posts

A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user global role can gain full administrative access to the Rancher control plane and transitively to all downstream clusters it manages. This issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.

DailyCyberSecurity at 2026-08-11T01:03:45.326Z ##

CVE-2026-44945: Rancher Cross-Cluster Impersonation Flaw Enables Full Privilege Escalation, Rated CVSS 9.1

securityonline.info/rancher-pr

##

DailyCyberSecurity@infosec.exchange at 2026-08-11T01:03:45.000Z ##

CVE-2026-44945: Rancher Cross-Cluster Impersonation Flaw Enables Full Privilege Escalation, Rated CVSS 9.1

securityonline.info/rancher-pr

##

CVE-2026-17650
(8.3 HIGH)

EPSS: 0.35%

updated 2026-08-06T00:36:25.360000

1 posts

Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

security_crawler_carl@infosec.exchange at 2026-08-10T03:03:06.000Z ##

🏆 New Achievement! Three Hundred and Seventy Reasons to Click Update!

Here, in its natural habitat, the unpatched browser clings stubbornly to an older Chrome build while the predator closes in. Google released Chrome 151 on July 28, 2026, correcting 370 vulnerabilities in a single migration — seven rated critical, spanning CVE-2026-17650 through CVE-2026-17656, with another 71 rated high severity. Naturalists observe this is among the largest single-release security drops of the year. (1/2)

##

CVE-2026-63077
(9.8 CRITICAL)

EPSS: 10.72%

updated 2026-08-05T18:32:31

2 posts

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Nuclei template

4 repos

https://github.com/AnggaTechI/CVE-2026-63077

https://github.com/unveiledhistory49/teamcity-cve-2026-63077-remediation

https://github.com/sfewer-r7/CVE-2026-63077

https://github.com/BoredHackerBlog/teamcity-CVE-2026-63077-pcap

CVE-2026-70374
(8.8 HIGH)

EPSS: 2.52%

updated 2026-08-05T15:32:14

1 posts

HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail generation routine. Media.generateThumbnail() in src/Server/Entity/Resource/Media.js builds a temporary file path as 'thumbnail' + Path.extname(filename) and passes it, unescaped, into a shell command executed via AppService.exec() ('convert ' + tempFile + ...). The MIME-type filter in

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-18902
(7.2 HIGH)

EPSS: 2.38%

updated 2026-08-05T14:17:04.910000

1 posts

A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerability is the function esps.wan.repeater.set/repeaterproc of the file /api/esps. Performing a manipulation of the argument my2P4key results in command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure.

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-18900
(7.2 HIGH)

EPSS: 2.38%

updated 2026-08-05T06:30:31

1 posts

A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file /api/esps of the component Backend RPC. This manipulation of the argument File causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure.

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-18814
(7.2 HIGH)

EPSS: 2.71%

updated 2026-08-05T00:30:41

1 posts

A vulnerability was found in H3C NX15 V100R017. This impacts the function reload.reload_config of the file /api/esps. The manipulation results in command injection. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure.

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-18577
(8.1 HIGH)

EPSS: 4.10%

updated 2026-08-04T14:27:12.530000

5 posts

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

3 repos

https://github.com/HORKimhab/CVE-2026-18577

https://github.com/Yash-Dalvee/stormencryptor-ncentral-defense

https://github.com/CreamyG31337/ncentral-compromise-ioc-triage

security_crawler_carl at 2026-08-11T04:22:58.887Z ##

Like a fighting-game boss mid-match suddenly swapping movesets, it exploited CVE-2026-18577, an authentication-bypass zero-day in N-able's N-central RMM tool, to get inside.

N-able dropped a hotfix on August 2 — patch to build 2026.3.1.7 immediately, and hunt for rogue svchost.exe files in user Documents folders, a Cloudflared service, or suspicious inbound connections listed in the advisory.

Reward: You've received the Cursed Badge of the Late Patcher — equip it at your peril. (2/2)

##

cyberveille@mastobot.ping.moi at 2026-08-10T19:30:05.000Z ##

📢 Storm-1175 déploie StormEncryptor, un nouveau ransomware exploitant CVE-2026-18577

📰 Source : GBHackers / Microsoft Threat Intelligence — Date de publication : 8 août 2026 🎯 Contexte général Microsoft Threat Intelligence a identifié une nouvelle campagne de ransomware attribuée à l'acteur financièrement motivé Storm-1175, active depuis le 2…

📖 cyberveille : cyberveille.ch/posts/2026-08-1
🌐 source : gbhackers.com/storm-1175-launc
🟡 vérification factuelle moyenne
#Storm1175 #StormEncryptor #Cyberveille

##

security_crawler_carl@infosec.exchange at 2026-08-11T04:22:58.000Z ##

Like a fighting-game boss mid-match suddenly swapping movesets, it exploited CVE-2026-18577, an authentication-bypass zero-day in N-able's N-central RMM tool, to get inside.

N-able dropped a hotfix on August 2 — patch to build 2026.3.1.7 immediately, and hunt for rogue svchost.exe files in user Documents folders, a Cloudflared service, or suspicious inbound connections listed in the advisory.

Reward: You've received the Cursed Badge of the Late Patcher — equip it at your peril. (2/2)

##

cyberworldops@infosec.exchange at 2026-08-10T14:20:00.000Z ##

Storm-1175, a China-nexus financially motivated threat actor, is distributing the StormEncryptor ransomware by exploiting a critical zero-day in ConnectWise N-central (CVE-2026-18577). First exploitation was detected July 31, with ransomware deployment beginning August 2. Targeting MSPs amplifies downstream impact across hundreds of managed clients.

#Storm1175 #Ransomware #Ncentral #MSPSecurity

cyberworldops.eu/en/storm-1175

##

ransomnews.online@bsky.brid.gy at 2026-08-08T07:37:08.000Z ##

⚠️ N-central auth bypass exploited in attacks

CVE-2026-18577 enables admin takeover; N-able issued an urgent hotfix.
🔗 read more: www.bleepingcomputer...

#ransomNews #cybersecurity


N-able warns of N-central auth...

##

CVE-2026-18686
(9.8 CRITICAL)

EPSS: 2.61%

updated 2026-08-04T00:35:01

1 posts

A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web RPC Wrapper. Performing a manipulation results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-18601
(9.8 CRITICAL)

EPSS: 2.38%

updated 2026-08-03T15:32:55

1 posts

A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. Performing a manipulation of the argument filename results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-33591
(0 None)

EPSS: 0.52%

updated 2026-08-03T12:16:26.317000

1 posts

A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass security restriction using a specially crafted packet and retrieve a valid session token for the targeted account.

cyberveille@mastobot.ping.moi at 2026-08-11T00:30:06.000Z ##

📢 CVE-2026-33591 : contournement d'authentification critique dans WAPT Server de Tranquil IT

🔍 Nature de la vulnérabilité La faille CVE-2026-33591 réside dans le mécanisme d'authentification de WAPT Server. Un attaquant distant non authentifié peut envoyer un paquet spécialement conçu pour contourner une restriction de sécurité et récupérer un jeton…

📖 cyberveille : cyberveille.ch/posts/2026-08-1
🌐 source : it-connect.fr/wapt-server-cve-
🟡 vérification factuelle moyenne
#TranquilIT #WAPTServer #Cyberveille

##

CVE-2026-64542
(0 None)

EPSS: 0.17%

updated 2026-08-03T10:16:32.820000

1 posts

In the Linux kernel, the following vulnerability has been resolved: ipv6: ndisc: fix NULL deref in accept_untracked_na() accept_untracked_na() re-fetches the inet6_dev with __in6_dev_get(dev) and dereferences idev->cnf.accept_untracked_na without a NULL check, even though its only caller ndisc_recv_na() already fetched and NULL-checked idev for the same device. Both reads of dev->ip6_ptr run in

sigint@fosstodon.org at 2026-08-10T23:45:07.000Z ##

🐧 SIGINT // Ubuntu Watch — 2026-08-11

A namespace-scoped IPv6 race that panics the host is a real problem for anyone running containers or LXC with unprivileged users. Check your kernel version before you trust that isolation boundary.

🔗 windowsforum.com/security-aler

#Ubuntu #Linux #infosec

##

CVE-2026-17656
(9.6 CRITICAL)

EPSS: 0.40%

updated 2026-07-30T21:32:37

1 posts

Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

security_crawler_carl@infosec.exchange at 2026-08-10T03:03:06.000Z ##

🏆 New Achievement! Three Hundred and Seventy Reasons to Click Update!

Here, in its natural habitat, the unpatched browser clings stubbornly to an older Chrome build while the predator closes in. Google released Chrome 151 on July 28, 2026, correcting 370 vulnerabilities in a single migration — seven rated critical, spanning CVE-2026-17650 through CVE-2026-17656, with another 71 rated high severity. Naturalists observe this is among the largest single-release security drops of the year. (1/2)

##

CVE-2026-64560
(7.8 HIGH)

EPSS: 0.12%

updated 2026-07-30T12:19:03.630000

1 posts

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwoo decoded and reported a non-leader exec() related race which can result in an UAF: sys_timer_delete() exec() posix_cpu_timer_del() // Observes old leader p = pid_task(pid, pid_type); de_thread() switch_leader(); release

1 repos

https://github.com/villager1314/CVE-2026-64560-Analysis

nemo@mas.to at 2026-08-08T11:54:34.000Z ##

🚨 Tails has released an emergency security update: Tails 7.10.1, patching critical flaws that could enable privilege escalation and potentially deanonymize users. It fixes CVE-2026-64560 (Linux kernel) and multiple Expat XML library issues. 🔐➡️ cyberinsider.com/tails-emergen #Tails #Tor #Cybersecurity #Privacy #SecurityUpdate

##

CVE-2026-60206
(9.9 CRITICAL)

EPSS: 0.49%

updated 2026-07-28T14:14:37.463000

1 posts

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SAML to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significa

4 repos

https://github.com/imbas007/POC-CVE-2026-60206

https://github.com/Debajyoti0-0/CVE-2026-60206

https://github.com/tc4dy/CVE-2026-60206-PoC-Exploit

https://github.com/0xBlackash/CVE-2026-60206

bitsontape@privacysafe.social at 2026-08-09T07:20:04.000Z ##

🔬 The best bytes of #science & #tech across the #fediverse

“Interesting Git repos of the week:Detection:* github․com/Yamato-Security/WELA - improve your Windows loggingBugs:* github․com/timb-machine-mirrors/imbas007-POC-CVE-2026-60206 - popping WebLogic via SAMLExploitat…”

infosec.exchange/@timb_machine

🤖 via RSS feed. Not an endorsement.

##

CVE-2026-15903
(8.8 HIGH)

EPSS: 0.31%

updated 2026-07-24T15:33:44

1 posts

Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

sayzard@mastodon.sayzard.org at 2026-08-10T19:38:50.000Z ##

GPT 5.6 Cyber

OpenAI가 승인된 보안 연구자용 Daybreak Red를 통해 사이버보안 특화 모델 GPT-5.6-Cyber를 공개했다. 이 모델은 GPT-5.6 Sol 기반으로 취약점 탐색, 익스플로잇 체인 검증, 보안 테스트 등 고위험 이중용도 작업에서 거절률을 낮추고 성능을 높이도록 학습됐으며, 내부 완료율 평가에서 95.0%를 기록했다고 밝혔다. OpenAI는 V8에서 메모리 손상 및 힙 샌드박스 탈출로 이어질 수 있는 취약점 체인을 찾아 Google에 책임 공개했고, CVE-2026-15903으로 수정됐다고 설명했다. 보안팀에는 취약점 조사·PoC 검증·보고서 작성 자동화의 생산성 향상 가능성이 크지만, 모델 접근...

openai.com/index/expanding-day

##

CVE-2026-65535
(4.3 MEDIUM)

EPSS: 0.18%

updated 2026-07-23T14:17:59.510000

1 posts

Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.

dan@discuss.systems at 2026-08-08T02:15:49.000Z ##

CVE-2026-65535: Ranch Overflow

##

CVE-2026-63030
(9.8 CRITICAL)

EPSS: 95.60%

updated 2026-07-22T23:10:00.110000

1 posts

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

Nuclei template

81 repos

https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030

https://github.com/M4xSec/wp2shell-Exploit-Waf-Bypass

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/securelayer7/WordPresShell

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

https://github.com/mrx-arafat/CVE-2026-63030-POC

https://github.com/bahartanir/wp2shell-scanner

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

https://github.com/4minx/CVE-2026-63030

https://github.com/AnggaTechI/CVE-2026-63030

https://github.com/mcipekci/wp2shell

https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/minwunn/wp2shell-CVE-2026-63030

https://github.com/zi3lak/wp2shell_scanner

https://github.com/gbrsh/CVE-2026-63030

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/dinosn/wp2shell-lab

https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner

https://github.com/Industri4l-H3ll-Xpl0it3rs/CVE-2026-63030-WP2Shell

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/x-znn/CVE-2026-63030

https://github.com/ananay/wp2shell-lab

https://github.com/Lutfifakee-Project/wp2shell

https://github.com/CybersecSpirit/CVE-2026-63030

https://github.com/Ch4120N/CVE-2026-63030

https://github.com/sowarma/wp2shell-PoC

https://github.com/zeroc00I/CVE-2026-63030

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

https://github.com/g0d150ne/WP2Shell

https://github.com/ekomsSavior/wp2shell

https://github.com/kulichr/wp2shell

https://github.com/0xWhoknows/wp2shell

https://github.com/vulnquest58/PressVector

https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/michael-kanda/Wp2shell-ioc-scanner

https://github.com/attackercan/wp2shell-poc2

https://github.com/ikow/wp2shell

https://github.com/0xBlackash/CVE-2026-63030

https://github.com/NULL200OK/WP2Shell

https://github.com/fullhunt/wp2shell-scan

https://github.com/yuag/wp2shell

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/h4cd0c/wp2shell

https://github.com/4B3R4M4-607D/CVE-2026-63030-POC

https://github.com/InstaWP/wp2shell-scan

https://github.com/Procjevt/CVE-2026-63030

https://github.com/Crypto-Cat/wp2shell

https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause

https://github.com/47Cid/wp2shell-lab

https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction

https://github.com/johnlodan/wp2shell-rce

https://github.com/0xh7ml/CVE-2026-63030

https://github.com/imXur/WordPress-CVE-2026-63030-Analysis

https://github.com/administrator-01001/CVE-2026-63030

https://github.com/0xjessie21/wp2shell-checker

https://github.com/shinthink/CVE-2026-63030

https://github.com/Icex0/wp2shell-poc

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/ebrasha/abdal-cve-2026-63030

https://github.com/ChiefYoru/CVE-2026-63030_PoC

https://github.com/raphy76/wp2shell-poc-fulljs

https://github.com/ZenithGenius/wordpress-batch-rce-lab

https://github.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t

https://github.com/mverschu/CVE-2026-63030

https://github.com/Iqbalx7/wp2shell

https://github.com/mhtsec/CVE-2026-63030

https://github.com/0xsha/wp2shell

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/rechandra/wp2exp-2026

https://github.com/c0gnit00/Wp2Shell

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/TomorrowX6/CVE-2026-63030-poc

https://github.com/AkbarWiraN/holy-wp2shell

https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030

bstnbuck@infosec.exchange at 2026-08-10T12:30:00.000Z ##

A #Wordpress site belonging to an friend (I’m not the admin...) was successfully hacked using #wp2shell (17.07.2026; CVE-2026-63030 + CVE-2026-60137), just 5 days after the first exploit published (20.07.). Another 5 days later, the website was abused for SEO spamming and for hosting phishing…

If you haven't already, update your Wordpress (preferably yesterday…; >=v7.0.2 or >= 6.9.5) and also enable automatic updates for themes and plug-ins!

I found several PHP backdoors/webshells (see @abuse_ch Malware Bazaar and #VirusTotal (hashes below)). Interestingly, not every sample was detected by the #YARA rules from @cyb3rops and github.com/ruppde/yara_rules.

tl;dr #wp2shell is being actively exploited, patch immediately and enable automatic updates.

Hashes:
1093b4045b45a8498d146e31788c25769f992056c8ffc582b5d8c06598598966
05e3884a478d3bc8fd7285dabb74107422f1615d2d7f80df9b8438d4beb663da
bb9136494a546368e7c9b6252c2e1c5af9327c07947908a9ba6fdd78fb4bf4cf
1e7ca9074cc2eca8d366022629f665d9ffaa79e0621bb579bf5aabe681cb07e8
8ebaf3ba0be7b62269aaf333cfaf66c1dea6e8ee495a917691beb550b4bbf0ab
e3fb920aa70c7ad5c67b4d9b8e60954f5e0c1a07c0eba09505816b966f4d1a3c
165e94c87ef17389c8de25ba2a6c31b348e3c916dab89d0dd3708156414f3de5
b55cf5af8b57e9d56c69d00e023e2384c7eb184614c2a2a283062ebeaf4a26c6
a46230a1638b9b341d15a640ead1b885548c1d1e5a149657e8e315540a068be8
7918f29993383e579ef33bd0d8e766fd2ce047dce83bac51efb5fe17578b6cdf
ae9ee9db7c41e04c531298782b908766c769a899aa92df3f64f4a83baa77ad09

##

CVE-2026-56155
(7.8 HIGH)

EPSS: 2.33%

updated 2026-07-14T21:32:52

1 posts

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

CVE-2026-34348
(6.5 MEDIUM)

EPSS: 0.71%

updated 2026-07-14T18:31:58

1 posts

Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.

1 repos

https://github.com/HORKimhab/CVE-2026-34348

obivan@infosec.exchange at 2026-08-08T16:23:05.000Z ##

@adamshostack @gsuberland the main vulnerability is CVE-2026-34348. As I understood, a signature of sign-in is stored in event log, which can be replayed and used for impersonation, as there is no validation of reused signatures in Entra ID.

##

CVE-2026-43074
(7.8 HIGH)

EPSS: 0.48%

updated 2026-06-17T10:48:53.150000

1 posts

In the Linux kernel, the following vulnerability has been resolved: eventpoll: defer struct eventpoll free to RCU grace period In certain situations, ep_free() in eventpoll.c will kfree the epi->ep eventpoll struct while it still being used by another concurrent thread. Defer the kfree() to an RCU callback to prevent UAF.

1 repos

https://github.com/PeronGH/badepoll-selinux-disabler

DailyCyberSecurity@infosec.exchange at 2026-08-10T12:56:45.000Z ##

CVE-2026-43074: Linux Kernel eventpoll Use-After-Free Gives a Root Shell, PoC Exploit Code Publicly Disclosed

securityonline.info/linux-kern

##

CVE-2026-25166
(7.8 HIGH)

EPSS: 1.63%

updated 2026-06-17T10:24:13.150000

1 posts

Deserialization of untrusted data in Windows System Image Manager allows an authorized attacker to execute code locally.

cyberveille@mastobot.ping.moi at 2026-08-11T00:30:06.000Z ##

📢 CVE-2026-25166 : Désérialisation non sécurisée dans imgmgr.exe permet de contourner Windows Application Control

🔍 Contexte : Le 2 avril 2026, la société australienne dotSec publie une analyse technique détaillant la découverte et la divulgation responsable à Microsoft d'une vulnérabilité de désérialisation non sécurisée dans un binaire du…

📖 cyberveille : cyberveille.ch/posts/2026-08-1
🌐 source : dotsec.com/insecure-deserialis
🟡 vérification factuelle moyenne
#WindowsADK #YsoserialNet #Cyberveille

##

CVE-2020-11069
(8.0 HIGH)

EPSS: 0.70%

updated 2026-06-17T02:48:59.070000

1 posts

In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discovered that the backend user interface and install tool are vulnerable to a same-site request forgery. A backend user can be tricked into interacting with a malicious resource an attacker previously managed to upload to the web server. Scripts are then executed with the privileges of the victims' user session. In a worst-

EUVD_Bot@mastodon.social at 2026-08-11T08:00:22.000Z ##

🚨 EUVD-2026-55971

📊 Score: 7.3/10 (CVSS v3.1)
📦 Product: TYPO3 CMS, TYPO3 CMS
🏢 Vendor: TYPO3
📅 Updated: 2026-08-11

📝 The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 news.typo3.com/security/adviso ( CVE-2020-11069 cve.org/CVERecord ) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving t...

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2003-0190
(0 None)

EPSS: 76.75%

updated 2026-06-16T22:01:43.273000

2 posts

OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.

raptor at 2026-08-11T09:06:33.378Z ##

Finally, to close out our short tour, a few vintage repositories 🍷 that have aged into historical curiosities and are now (mostly) harmless. Still worth a look as a learning resource, for humans and AI alike 🤖

github.com/0xdea/exploits - a collection of my public exploits from CVE-1999-1587 onwards
github.com/0xdea/shellcode - a small collection of my shellcode samples
github.com/0xdea/advisories - my public advisories starting from CAN-2003-0190, err..., CVE-2003-0190 up until today

Thanks for following along, and enjoy your summer break! ☀️

##

raptor@infosec.exchange at 2026-08-11T09:06:33.000Z ##

Finally, to close out our short #GitHub tour, a few vintage repositories 🍷 that have aged into historical curiosities and are now (mostly) harmless. Still worth a look as a learning resource, for humans and AI alike 🤖

github.com/0xdea/exploits - a collection of my public exploits from CVE-1999-1587 onwards
github.com/0xdea/shellcode - a small collection of my shellcode samples
github.com/0xdea/advisories - my public advisories starting from CAN-2003-0190, err..., CVE-2003-0190 up until today

Thanks for following along, and enjoy your summer break! ☀️

##

CVE-1999-1587
(0 None)

EPSS: 0.95%

updated 2026-06-16T21:50:46.783000

2 posts

/usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, allows local users to view the environment variables and values of arbitrary processes via the -e option.

raptor at 2026-08-11T09:06:33.378Z ##

Finally, to close out our short tour, a few vintage repositories 🍷 that have aged into historical curiosities and are now (mostly) harmless. Still worth a look as a learning resource, for humans and AI alike 🤖

github.com/0xdea/exploits - a collection of my public exploits from CVE-1999-1587 onwards
github.com/0xdea/shellcode - a small collection of my shellcode samples
github.com/0xdea/advisories - my public advisories starting from CAN-2003-0190, err..., CVE-2003-0190 up until today

Thanks for following along, and enjoy your summer break! ☀️

##

raptor@infosec.exchange at 2026-08-11T09:06:33.000Z ##

Finally, to close out our short #GitHub tour, a few vintage repositories 🍷 that have aged into historical curiosities and are now (mostly) harmless. Still worth a look as a learning resource, for humans and AI alike 🤖

github.com/0xdea/exploits - a collection of my public exploits from CVE-1999-1587 onwards
github.com/0xdea/shellcode - a small collection of my shellcode samples
github.com/0xdea/advisories - my public advisories starting from CAN-2003-0190, err..., CVE-2003-0190 up until today

Thanks for following along, and enjoy your summer break! ☀️

##

CVE-2026-34486
(7.5 HIGH)

EPSS: 81.16%

updated 2026-06-08T23:28:56

1 posts

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

Nuclei template

6 repos

https://github.com/striga-ai/CVE-2026-34486

https://github.com/punitdarji/tomcat-cve-2026-34486

https://github.com/AirSkye/CVE-2026-34486-poc

https://github.com/404-src/CVE-2026-34486

https://github.com/razureink/cve-2026-34486-tomcat_encrypt_bypass_reproduction

https://github.com/anonmrc/CVE-2026-34486-e-Tomcat-Tribes

thecybermind@infosec.exchange at 2026-08-10T18:21:57.000Z ##

🚨 CRITICAL THREAT ALERT: CVE-2026-34486 in Apache Tomcat is under active CISA KEV exploitation. Missing encryption allows intercept of sensitive corporate data. Review our strategic C-Suite brief on technical vectors, persistence checks, and endpoint hardening to protect your data streams. thecybermind.co/6dk1

##

CVE-2026-48048
(7.5 HIGH)

EPSS: 0.00%

updated 2026-05-26T20:17:03

1 posts

### Impact XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient and with slightly modified parameters to the `LiveTableResults`, it is still possible to discover password hashes one bit at a time, so with 768 requests, the full password salt and hash can be retrieved of a user. ### Patches The check for password (and email properties) has been adjusted in XWiki 18.0.0RC1, 17.1

thehackerwire@mastodon.social at 2026-08-10T17:00:34.000Z ##

🟠 CVE-2026-48048 - High (7.5)

XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Starting with version 6.2.1 and prior to versions 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17, with slightly modified parameters to t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2021-26708
(7.0 None)

EPSS: 1.60%

updated 2023-11-18T05:04:48

1 posts

A local privilege escalation was discovered in the Linux kernel before 5.10.13. Multiple race conditions in the AF_VSOCK implementation are caused by wrong locking in net/vmw_vsock/af_vsock.c. The race conditions were implicitly introduced in the commits that added VSOCK multi-transport support.

3 repos

https://github.com/kungaocode/vulnerability-analysis-

https://github.com/azpema/CVE-2021-26708

https://github.com/jordan9001/vsock_poc

hackmag@infosec.exchange at 2026-08-09T00:30:10.000Z ##

⚪️ Four Bytes of Power: How I Found the CVE-2021-26708 Vulnerability in the Linux Kernel

🗨️ In January 2021, I discovered and fixed five vulnerabilities in the Linux kernel’s virtual socket (vsock) implementation, collectively tracked as CVE-2021-26708. In this article, I will show how they can be used to compromise the entire operating system while bypassing the platform’s security mec…

🔗 hackmag.com/unix/linux-core-cv

#unix

##

CVE-2015-6609(CVSS UNKNOWN)

EPSS: 2.17%

updated 2023-01-27T05:08:18

1 posts

libutils in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted audio file, aka internal bug 22953624.

GrapheneOS@grapheneos.social at 2026-08-08T15:04:04.000Z ##

The paper has a table listing the patches they're inaccurately claiming are missing in GrapheneOS. They claim the ones marked as green were manually verified to be missing. The first patch listed in the table is CVE-2015-6609, which we reported to Google in 2015.

source.android.com/docs/securi

##

CVE-2026-62737
(0 None)

EPSS: 0.00%

1 posts

N/A

guru@thecybersecguru.com at 2026-08-11T08:14:00.000Z ##

CVE-2026-62737: Windows 11 Kernel Zero-Day via NDIS KLoader and ExecutionContext.sys

CVE-2026-62737 is a Windows 11 kernel zero-day involving NDIS KLoader and ExecutionContext.sys. Analyze the ACL bypass, task injection and controlled kernel RIP

thecybersecguru.com/news/cve-2

##

sayzard@mastodon.sayzard.org at 2026-08-11T01:42:21.000Z ##

My Homelab Got Hacked – A Postmortem

Forgejo v13(EOL) 인스턴스가 Gitea 계열의 diffpatch 엔드포인트 RCE 취약점(CVE-2026-60004)으로 침해된 실제 사후 분석이다. 공격자는 공개 회원가입을 통해 저장소와 악성 Git hook을 만들고, diffpatch 요청을 자동화해 원격 셸 실행 후 아키텍처별 크립토마이너를 내려받았다. 핵심 IOC는 `/api/v1/repos/<USER>/<REPO>/diffpatch`에 대한 반복 POST, 공격자 IP의 후속 다운로드 요청, 비정상적인 Forgejo 컨테이너 CPU 사용률이다. 운영 측면에서는 EOL 이미지 태그 고정과 업데이트 감시 누락이 직접 원인이었으며, Forgejo/Gitea 배포 환경은...

phunky.cafe/my-homelab-got-hac

##

phillip@social.lol at 2026-08-08T19:01:48.000Z ##

Welp. My Forgejo instance got popped by CVE-2026-60004. Hooray for RCE 🙃

My two screw-ups were
1. I pinned it to v13 "for stability" forever ago, then forgot about it.
2. I accidentally left sign-ups enabled.

Grabbed the seemingly obfuscated payload script from the attacker's server. Looks like it hits a different IP and grabs one of three different binaries depending on the victim's CPU architecture. You best believe I'm grabbing those too

Will probably write a blog post on what I find, but I'll at least post updates here, too

Edit:
The postmortem is done!
social.lol/@phillip/1170725452

#Homelab #SelfHosted #PatchYourShit #Forgejo

##

CVE-2026-48161
(0 None)

EPSS: 0.00%

2 posts

N/A

offseq at 2026-08-11T00:00:34.610Z ##

CVE-2026-48161 | CRITICAL: dai-shi react18-use had malicious postinstall script — RCE on dev machines via npm install. Not in npm registry, but local checkouts may be compromised. Rotate creds & reimage if affected. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-11T00:00:34.000Z ##

CVE-2026-48161 | CRITICAL: dai-shi react18-use had malicious postinstall script — RCE on dev machines via npm install. Not in npm registry, but local checkouts may be compromised. Rotate creds & reimage if affected. radar.offseq.com/threat/cve-20 #OffSeq #SupplyChain #CVE #npm #infosec

##

CVE-2026-8718
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T23:59:54.000Z ##

🟠 CVE-2026-8718 - High (8.4)

tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied optval directly to mbedtls_ssl_get_peer_cid() without verifying the buffer ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-10T23:59:54.000Z ##

🟠 CVE-2026-8718 - High (8.4)

tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied optval directly to mbedtls_ssl_get_peer_cid() without verifying the buffer ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72915
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T22:59:58.000Z ##

🟠 CVE-2026-72915 - High (7.5)

Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta.1, any logged-in local user could use the show action in app/controllers/admin/collections_controller.rb to access personally ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-10T22:59:58.000Z ##

🟠 CVE-2026-72915 - High (7.5)

Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta.1, any logged-in local user could use the show action in app/controllers/admin/collections_controller.rb to access personally ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72914
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T22:59:48.000Z ##

🟠 CVE-2026-72914 - High (7.5)

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, the administrative statistics endpoints handled by Api::V1::Admin::MeasuresController and Api::V1::Admin::RetentionContro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-10T22:59:48.000Z ##

🟠 CVE-2026-72914 - High (7.5)

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, the administrative statistics endpoints handled by Api::V1::Admin::MeasuresController and Api::V1::Admin::RetentionContro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72903
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T22:00:28.000Z ##

🟠 CVE-2026-72903 - High (8.1)

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal filename through entry.name. In tabby-ssh/src/session/sftp.ts, SFTPSession.readdir() and _makeFile() u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-10T22:00:28.000Z ##

🟠 CVE-2026-72903 - High (8.1)

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal filename through entry.name. In tabby-ssh/src/session/sftp.ts, SFTPSession.readdir() and _makeFile() u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72911
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T22:00:16.000Z ##

🔴 CVE-2026-72911 - Critical (9.9)

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py render s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-10T22:00:16.000Z ##

🔴 CVE-2026-72911 - Critical (9.9)

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py render s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72901
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T21:00:31.000Z ##

🔴 CVE-2026-72901 - Critical (9.9)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-privilege member to execute arbitrary commands on the control-plane host because the volumeName field accepted by volumeBackup.cre...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-10T21:00:31.000Z ##

🔴 CVE-2026-72901 - Critical (9.9)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-privilege member to execute arbitrary commands on the control-plane host because the volumeName field accepted by volumeBackup.cre...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72886
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T21:00:20.000Z ##

🔴 CVE-2026-72886 - Critical (9.9)

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/api/routers/schedule.ts derive serviceId from applicationId or composeId and execute the owner/adm...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-10T21:00:20.000Z ##

🔴 CVE-2026-72886 - Critical (9.9)

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/api/routers/schedule.ts derive serviceId from applicationId or composeId and execute the owner/adm...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72883
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T21:00:09.000Z ##

🟠 CVE-2026-72883 - High (8.8)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handlers in apps/dokploy/server/wss/terminal.ts, apps/dokploy/server/wss/docker-container-terminal.ts, apps/dokploy/server/wss/docker-container-logs.ts,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-10T21:00:09.000Z ##

🟠 CVE-2026-72883 - High (8.8)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handlers in apps/dokploy/server/wss/terminal.ts, apps/dokploy/server/wss/docker-container-terminal.ts, apps/dokploy/server/wss/docker-container-logs.ts,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45628
(0 None)

EPSS: 0.23%

1 posts

N/A

EUVD_Bot@mastodon.social at 2026-08-10T20:02:02.000Z ##

🚨 EUVD-2026-55725

📊 Score: 9.9/10 (CVSS v3.1)
📦 Product: dokploy
🏢 Vendor: Dokploy
📅 Updated: 2026-08-10

📝 Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-45628 leaves packages/server/src/db/schema/compose.ts branch fields without server-side validation, allowing a direct compose.update req...

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2026-72864
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T20:00:44.000Z ##

🔴 CVE-2026-72864 - Critical (9.9)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-terminal in apps/dokploy/server/wss/docker-container-terminal.ts authenticates with validateRequest but does not authorize the a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-10T20:00:44.000Z ##

🔴 CVE-2026-72864 - Critical (9.9)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-terminal in apps/dokploy/server/wss/docker-container-terminal.ts authenticates with validateRequest but does not authorize the a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72872
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T20:00:30.000Z ##

🔴 CVE-2026-72872 - Critical (9.9)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider stores bitbucketOwner and bitbucketRepository without validation and cloneBitbucketRepository in packages/server/src/utils/providers...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-10T20:00:30.000Z ##

🔴 CVE-2026-72872 - Critical (9.9)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider stores bitbucketOwner and bitbucketRepository without validation and cloneBitbucketRepository in packages/server/src/utils/providers...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72871
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T20:00:08.000Z ##

🟠 CVE-2026-72871 - High (7.5)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/github/setup route in apps/dokploy/pages/api/providers/github/setup.ts trusts gh_init organizationId and userId values from the sta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-10T20:00:08.000Z ##

🟠 CVE-2026-72871 - High (7.5)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/github/setup route in apps/dokploy/pages/api/providers/github/setup.ts trusts gh_init organizationId and userId values from the sta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47754
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T17:00:24.000Z ##

🔴 CVE-2026-47754 - Critical (9.3)

Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19.1 and all 1.x versions contain an unauthenticated path traversal in the `archiveEntryName` parameter of the `action=read` endp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5423
(0 None)

EPSS: 0.34%

1 posts

N/A

CVE-2026-60137
(0 None)

EPSS: 73.10%

1 posts

N/A

52 repos

https://github.com/Crypto-Cat/wp2shell

https://github.com/ekomsSavior/wp2shell

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/kulichr/wp2shell

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/0xWhoknows/wp2shell

https://github.com/47Cid/wp2shell-lab

https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction

https://github.com/AdarshThakur14777-cyber/CVE-2026-60137

https://github.com/M4xSec/wp2shell-Exploit-Waf-Bypass

https://github.com/johnlodan/wp2shell-rce

https://github.com/zi3lak/wp2shell_scanner

https://github.com/vulnquest58/PressVector

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030

https://github.com/0xjessie21/wp2shell-checker

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/dinosn/wp2shell-lab

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/AbdullahMaqbool22/CVE-2026-60137-WordPress-Core-SQL-Injection-PoC

https://github.com/michael-kanda/Wp2shell-ioc-scanner

https://github.com/securelayer7/WordPresShell

https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/shinthink/CVE-2026-63030

https://github.com/Icex0/wp2shell-poc

https://github.com/ikow/wp2shell

https://github.com/ananay/wp2shell-lab

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

https://github.com/bahartanir/wp2shell-scanner

https://github.com/NULL200OK/WP2Shell

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

https://github.com/yuag/wp2shell

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/sowarma/wp2shell-PoC

https://github.com/northsia/CVE-2026-60137-With-Skip-SSL

https://github.com/h4cd0c/wp2shell

https://github.com/mcipekci/wp2shell

https://github.com/Iqbalx7/wp2shell

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/0xsha/wp2shell

https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137

https://github.com/ebrasha/abdal-cve-2026-60137

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/g0d150ne/WP2Shell

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/AkbarWiraN/holy-wp2shell

bstnbuck@infosec.exchange at 2026-08-10T12:30:00.000Z ##

A #Wordpress site belonging to an friend (I’m not the admin...) was successfully hacked using #wp2shell (17.07.2026; CVE-2026-63030 + CVE-2026-60137), just 5 days after the first exploit published (20.07.). Another 5 days later, the website was abused for SEO spamming and for hosting phishing…

If you haven't already, update your Wordpress (preferably yesterday…; >=v7.0.2 or >= 6.9.5) and also enable automatic updates for themes and plug-ins!

I found several PHP backdoors/webshells (see @abuse_ch Malware Bazaar and #VirusTotal (hashes below)). Interestingly, not every sample was detected by the #YARA rules from @cyb3rops and github.com/ruppde/yara_rules.

tl;dr #wp2shell is being actively exploited, patch immediately and enable automatic updates.

Hashes:
1093b4045b45a8498d146e31788c25769f992056c8ffc582b5d8c06598598966
05e3884a478d3bc8fd7285dabb74107422f1615d2d7f80df9b8438d4beb663da
bb9136494a546368e7c9b6252c2e1c5af9327c07947908a9ba6fdd78fb4bf4cf
1e7ca9074cc2eca8d366022629f665d9ffaa79e0621bb579bf5aabe681cb07e8
8ebaf3ba0be7b62269aaf333cfaf66c1dea6e8ee495a917691beb550b4bbf0ab
e3fb920aa70c7ad5c67b4d9b8e60954f5e0c1a07c0eba09505816b966f4d1a3c
165e94c87ef17389c8de25ba2a6c31b348e3c916dab89d0dd3708156414f3de5
b55cf5af8b57e9d56c69d00e023e2384c7eb184614c2a2a283062ebeaf4a26c6
a46230a1638b9b341d15a640ead1b885548c1d1e5a149657e8e315540a068be8
7918f29993383e579ef33bd0d8e766fd2ce047dce83bac51efb5fe17578b6cdf
ae9ee9db7c41e04c531298782b908766c769a899aa92df3f64f4a83baa77ad09

##

CVE-2026-48085
(0 None)

EPSS: 0.55%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T03:00:08.000Z ##

🔴 CVE-2026-48085 - Critical (9.8)

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provisioned OpenReception instance accepts unauthenticated POST requests to `/setup/create-admin-account` a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63637
(0 None)

EPSS: 0.24%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T02:00:16.000Z ##

🟠 CVE-2026-63637 - High (8.6)

Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.go passes regexp filter strings into generated DQL without quoting or validating the /pattern/flags form, allowing crafted Grap...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites