##
Updated at UTC 2026-08-10T10:18:35.240854
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-18786 | 0 | 0.00% | 2 | 0 | 2026-08-10T07:16:50.487000 | The CheckView WordPress plugin before 2.3.2 does not restrict its REST API auth | |
| CVE-2026-16985 | 0 | 0.00% | 2 | 0 | 2026-08-10T07:16:48.380000 | The Squeeze WordPress plugin before 1.7.12 does not validate the file type or e | |
| CVE-2026-19389 | 7.1 | 0.00% | 2 | 0 | 2026-08-10T03:16:40.380000 | Multiple integer overflow and underflow vulnerabilities were found in the GStrea | |
| CVE-2026-19387 | 7.6 | 0.00% | 2 | 0 | 2026-08-10T03:16:40.223000 | A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins- | |
| CVE-2026-19381 | 7.8 | 0.00% | 4 | 0 | 2026-08-10T01:16:48.367000 | A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2 | |
| CVE-2026-15534 | 0 | 0.00% | 2 | 0 | 2026-08-09T22:16:30.373000 | Perl versions through 5.45.1 have out-of-bounds heap reads and writes during reg | |
| CVE-2026-19348 | 9.8 | 0.00% | 4 | 0 | 2026-08-09T12:32:52 | A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea | |
| CVE-2026-19346 | 8.8 | 0.00% | 2 | 0 | 2026-08-09T10:17:10.567000 | A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects | |
| CVE-2026-19341 | 8.8 | 0.44% | 1 | 0 | 2026-08-09T09:30:29 | A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-17030 | |
| CVE-2026-19195 | 7.8 | 0.11% | 2 | 1 | 2026-08-09T06:32:38 | A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affec | |
| CVE-2026-10595 | 7.5 | 0.49% | 1 | 0 | 2026-08-09T06:31:42 | A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specific | |
| CVE-2026-15038 | None | 0.19% | 1 | 1 | 2026-08-09T06:31:36 | The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify th | |
| CVE-2026-64561 | 8.8 | 0.12% | 3 | 6 | 2026-08-09T06:31:34 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: C | |
| CVE-2026-19193 | 7.8 | 0.11% | 2 | 1 | 2026-08-09T06:19:12.620000 | A flaw has been found in Jiangmin Antivirus 21. Impacted is the function Message | |
| CVE-2026-64564 | 9.8 | 0.48% | 10 | 3 | 2026-08-09T04:17:43.283000 | In the Linux kernel, the following vulnerability has been resolved: sctp: don't | |
| CVE-2026-71993 | 9.8 | 1.35% | 4 | 0 | 2026-08-09T00:31:13 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71986 | 9.8 | 1.35% | 3 | 0 | 2026-08-09T00:31:13 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71990 | 9.8 | 1.35% | 2 | 0 | 2026-08-09T00:31:13 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71992 | 9.8 | 1.35% | 2 | 0 | 2026-08-09T00:31:13 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71985 | 9.8 | 1.35% | 1 | 0 | 2026-08-09T00:31:13 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71984 | 9.8 | 1.35% | 1 | 0 | 2026-08-09T00:31:13 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71987 | 9.8 | 1.35% | 4 | 0 | 2026-08-09T00:31:07 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71988 | 9.8 | 1.35% | 3 | 0 | 2026-08-09T00:31:07 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71991 | 9.8 | 1.35% | 2 | 0 | 2026-08-09T00:16:48.270000 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71989 | 9.8 | 1.35% | 2 | 0 | 2026-08-09T00:16:47.953000 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71983 | 9.8 | 1.62% | 1 | 0 | 2026-08-08T23:16:56.967000 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71953 | 9.8 | 2.09% | 1 | 0 | 2026-08-08T18:30:30 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1 | |
| CVE-2026-71955 | 9.8 | 2.13% | 1 | 0 | 2026-08-08T18:30:30 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2 | |
| CVE-2026-71954 | 9.8 | 2.13% | 1 | 0 | 2026-08-08T18:30:30 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1 | |
| CVE-2026-71950 | 9.8 | 2.09% | 2 | 0 | 2026-08-08T18:30:29 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1 | |
| CVE-2026-71945 | 9.8 | 2.09% | 1 | 0 | 2026-08-08T18:30:29 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1 | |
| CVE-2026-71944 | 9.8 | 2.09% | 1 | 0 | 2026-08-08T18:30:29 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1 | |
| CVE-2026-71952 | 9.8 | 2.09% | 1 | 0 | 2026-08-08T18:30:29 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1 | |
| CVE-2026-71948 | 9.8 | 2.09% | 1 | 0 | 2026-08-08T18:30:29 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1 | |
| CVE-2026-71957 | 9.8 | 0.59% | 1 | 0 | 2026-08-08T18:30:29 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2 | |
| CVE-2026-71956 | 9.8 | 1.74% | 1 | 0 | 2026-08-08T18:30:29 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2 | |
| CVE-2026-42170 | 7.8 | 0.19% | 1 | 0 | 2026-08-08T18:30:29 | A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Su | |
| CVE-2026-71946 | 9.8 | 2.09% | 1 | 0 | 2026-08-08T18:30:25 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1 | |
| CVE-2026-71958 | 9.8 | 0.56% | 1 | 0 | 2026-08-08T18:16:56.783000 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2 | |
| CVE-2026-71951 | 9.8 | 2.09% | 1 | 0 | 2026-08-08T18:16:55.907000 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1 | |
| CVE-2026-71949 | 9.8 | 2.09% | 1 | 0 | 2026-08-08T18:16:55.660000 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1 | |
| CVE-2026-71947 | 9.8 | 2.09% | 2 | 0 | 2026-08-08T18:16:55.410000 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1 | |
| CVE-2026-67620 | 7.7 | 0.43% | 1 | 1 | 2026-08-08T16:16:49.420000 | Flowise through 3.1.4 contains a server-side request forgery vulnerability in th | |
| CVE-2026-14526 | 9.8 | 0.61% | 3 | 0 | 2026-08-08T09:30:28 | The AI Copilot – Content Generator plugin for WordPress is vulnerable to authori | |
| CVE-2026-16948 | None | 0.13% | 1 | 0 | 2026-08-08T09:30:28 | The Solace Extra WordPress plugin before 1.6.1 does not perform capability check | |
| CVE-2026-16955 | 0 | 0.16% | 1 | 0 | 2026-08-08T07:17:11.440000 | The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied | |
| CVE-2026-16594 | 0 | 0.14% | 1 | 0 | 2026-08-08T07:17:10.910000 | The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorizatio | |
| CVE-2026-8037 | 9.6 | 99.31% | 5 | 2 | template | 2026-08-08T05:17:10.403000 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC |
| CVE-2026-56793 | 7.7 | 0.31% | 2 | 0 | 2026-08-08T05:17:09.880000 | Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Im | |
| CVE-2026-71851 | 9.0 | 0.32% | 2 | 0 | 2026-08-08T04:17:55.850000 | crypto-js is a JavaScript library of crypto standards. Versions of crypto-js pri | |
| CVE-2026-71560 | 9.1 | 0.55% | 1 | 0 | 2026-08-08T03:32:14 | Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue | |
| CVE-2026-71558 | 9.8 | 0.71% | 1 | 0 | 2026-08-08T03:32:14 | Heap type confusion vulnerability in Apache Fory C++ deserialization. This issu | |
| CVE-2026-70558 | 9.8 | 0.60% | 2 | 0 | 2026-08-08T03:16:46.910000 | Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied pa | |
| CVE-2026-5857 | 8.1 | 0.53% | 2 | 0 | 2026-08-08T03:16:46.377000 | Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c se | |
| CVE-2026-19192 | 7.8 | 0.11% | 1 | 0 | 2026-08-08T03:16:45.610000 | A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affec | |
| CVE-2026-52878 | 7.5 | 0.28% | 1 | 0 | 2026-08-07T23:17:04.593000 | Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1 | |
| CVE-2026-46409 | 9.6 | 0.36% | 1 | 0 | 2026-08-07T23:17:03.243000 | OpenYak is a local-first agent runtime for reliable tool-using models, with a de | |
| CVE-2026-48170 | 9.1 | 0.25% | 3 | 0 | 2026-08-07T22:16:59.170000 | `scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs p | |
| CVE-2026-16258 | 9.8 | 0.47% | 1 | 0 | 2026-08-07T21:31:37 | The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deseri | |
| CVE-2026-16263 | 8.8 | 0.34% | 1 | 0 | 2026-08-07T21:31:36 | The WP Maps WordPress plugin before 4.9.7 does not perform a capability check i | |
| CVE-2025-63235 | 7.5 | 0.32% | 1 | 0 | 2026-08-07T21:30:40 | In sol commit 373d848 (2024-12-12), the broker does not fully release resources | |
| CVE-2026-15972 | 7.5 | 0.39% | 1 | 0 | 2026-08-07T21:30:40 | Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerab | |
| CVE-2026-64636 | 7.7 | 0.21% | 1 | 0 | 2026-08-07T21:30:37 | An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Win | |
| CVE-2026-15215 | 8.8 | 0.35% | 1 | 0 | 2026-08-07T21:30:33 | The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify | |
| CVE-2026-16041 | 7.5 | 0.21% | 1 | 0 | 2026-08-07T21:30:33 | The MStore API WordPress plugin before 4.21.0 does not perform authorization or | |
| CVE-2026-50540 | 9.6 | 0.38% | 1 | 0 | 2026-08-07T21:17:28.827000 | Kata Containers is an open source project focusing on a standard implementation | |
| CVE-2026-19082 | 7.5 | 0.29% | 1 | 0 | 2026-08-07T21:17:27.317000 | Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap byte | |
| CVE-2026-48169 | 8.8 | 0.26% | 1 | 0 | 2026-08-07T21:16:58 | ### Summary The PraisonAI Platform API has two authorization failures that toge | |
| CVE-2026-48039 | 9.1 | 0.34% | 2 | 0 | 2026-08-07T19:29:59 | # Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token | Fi | |
| CVE-2026-50481 | 9.9 | 0.46% | 2 | 0 | 2026-08-07T19:29:09.813000 | Modification of assumed-immutable data (maid) in Azure Active Directory allows a | |
| CVE-2026-64638 | 0 | 0.77% | 10 | 19 | template | 2026-08-07T19:18:51.610000 | WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login s |
| CVE-2026-20346 | 7.5 | 0.33% | 1 | 0 | 2026-08-07T19:17:41.360000 | A vulnerability in the PDF file format parser of ClamAV could allow an unauthent | |
| CVE-2026-16262 | 7.5 | 0.16% | 1 | 0 | 2026-08-07T19:17:37.053000 | The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its O | |
| CVE-2026-16038 | 9.1 | 0.24% | 1 | 0 | 2026-08-07T19:17:36.110000 | The MStore API WordPress plugin before 4.21.0 does not verify the payment with | |
| CVE-2026-15361 | 8.1 | 0.22% | 1 | 0 | 2026-08-07T19:17:35.543000 | The Content Views WordPress plugin before 4.5 does not perform a capability che | |
| CVE-2026-59118 | 9.3 | 0.39% | 1 | 0 | 2026-08-07T19:06:49.530000 | Improper authorization in Microsoft Power Apps allows an unauthorized attacker t | |
| CVE-2026-16030 | 8.1 | 0.23% | 2 | 0 | 2026-08-07T18:32:49 | The MStore API WordPress plugin before 4.21.0 does not correctly verify the cry | |
| CVE-2026-71559 | 7.5 | 0.59% | 1 | 0 | 2026-08-07T18:32:49 | Deserialization of Untrusted Data vulnerability in the Go implementation of Apac | |
| CVE-2026-67688 | 9.8 | 0.59% | 2 | 0 | 2026-08-07T18:32:48 | ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload | |
| CVE-2026-67687 | 8.8 | 0.53% | 2 | 1 | 2026-08-07T18:32:48 | Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to | |
| CVE-2026-70634 | 8.1 | 0.41% | 2 | 0 | 2026-08-07T18:32:48 | TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds r | |
| CVE-2026-14943 | 7.5 | 0.26% | 1 | 0 | 2026-08-07T18:32:48 | The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial | |
| CVE-2026-14205 | 9.8 | 0.27% | 1 | 0 | 2026-08-07T18:32:48 | The WP Events Manager WordPress plugin before 2.2.5 does not validate the reques | |
| CVE-2026-64637 | 9.9 | 0.23% | 2 | 0 | 2026-08-07T18:31:57 | Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows | |
| CVE-2026-20339 | 7.5 | 0.33% | 2 | 0 | 2026-08-07T18:31:54 | A vulnerability in the PESpin file format parser of ClamAV could allow an unauth | |
| CVE-2026-20348 | 7.5 | 0.33% | 1 | 0 | 2026-08-07T18:31:54 | A vulnerability in the XAR file format parser of ClamAV could allow an unauthent | |
| CVE-2026-20345 | 7.5 | 0.33% | 1 | 0 | 2026-08-07T18:31:54 | A vulnerability in the GPT file format parser of ClamAV could allow an unauthent | |
| CVE-2026-20338 | 7.5 | 0.33% | 2 | 0 | 2026-08-07T18:31:53 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticat | |
| CVE-2026-20347 | 7.5 | 0.33% | 1 | 0 | 2026-08-07T18:31:53 | A vulnerability in the Mach-O file format parser of ClamAV could allow an unauth | |
| CVE-2026-68772 | 8.0 | 0.40% | 1 | 0 | 2026-08-07T18:31:53 | ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMa | |
| CVE-2026-20337 | 7.5 | 0.36% | 3 | 0 | 2026-08-07T18:31:52 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticat | |
| CVE-2026-67621 | 7.6 | 0.27% | 2 | 0 | 2026-08-07T18:31:42 | Flowise through 3.1.4 contains a missing authorization vulnerability that allows | |
| CVE-2026-70628 | 7.8 | 0.15% | 2 | 0 | 2026-08-07T18:31:42 | FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer | |
| CVE-2026-70632 | 7.8 | 0.21% | 2 | 0 | 2026-08-07T18:31:42 | FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds | |
| CVE-2026-67622 | 9.9 | 0.25% | 2 | 0 | 2026-08-07T18:31:41 | Flowise through 3.1.4 contains an insecure direct object reference vulnerability | |
| CVE-2026-15733 | 9.8 | 3.90% | 2 | 0 | 2026-08-07T18:31:37 | A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 a | |
| CVE-2026-67422 | 7.5 | 0.58% | 2 | 0 | 2026-08-07T18:26:08 | ### Summary Four inline processors in pymdown-extensions contain regular expres | |
| CVE-2026-53984 | 9.1 | 0.38% | 2 | 0 | 2026-08-07T18:17:18.960000 | Ground Station prior to 0.6.0 contains an unauthenticated database-destruction a | |
| CVE-2026-45198 | 7.8 | 0.12% | 2 | 0 | 2026-08-07T18:17:14.827000 | Kernel software from a non-secure operating system on a platform with Trusted Ex | |
| CVE-2026-14365 | 9.8 | 0.31% | 2 | 0 | 2026-08-07T18:17:07.753000 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress i | |
| CVE-2026-65667 | 10.0 | 0.44% | 1 | 0 | 2026-08-07T18:11:23.330000 | Missing authorization in Microsoft Teams allows an unauthorized attacker to elev | |
| CVE-2026-50515 | 9.9 | 0.91% | 2 | 0 | 2026-08-07T18:05:55.493000 | Deserialization of untrusted data in Azure Service Bus allows an authorized atta | |
| CVE-2026-5855 | 7.5 | 0.54% | 2 | 0 | 2026-08-07T17:17:05.047000 | Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c | |
| CVE-2026-9169 | 8.8 | 0.14% | 1 | 0 | 2026-08-07T16:17:28.807000 | DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows a | |
| CVE-2026-53983 | 8.6 | 0.33% | 2 | 0 | 2026-08-07T16:17:25.673000 | Ground Station prior to 0.6.0 contains an unauthenticated blind server-side requ | |
| CVE-2026-49007 | 7.5 | 0.34% | 1 | 0 | 2026-08-07T16:17:25.380000 | By accessing unencrypted information in the device firmware, an attacker can obt | |
| CVE-2026-48085 | 9.8 | 0.55% | 2 | 0 | 2026-08-07T16:17:24.773000 | OpenReception's appointment booking software provides an end-to-end encrypted ap | |
| CVE-2026-67689 | 9.8 | 0.69% | 2 | 1 | 2026-08-07T15:34:17 | SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execut | |
| CVE-2026-19264 | 9.8 | 0.63% | 1 | 1 | 2026-08-07T15:33:32 | Postiz is an open-source social media scheduling tool. The route that serves loc | |
| CVE-2026-54212 | 0 | 0.47% | 1 | 0 | 2026-08-07T15:17:01.830000 | Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint | |
| CVE-2026-15816 | 7.5 | 0.25% | 1 | 0 | 2026-08-07T12:32:06 | A flaw was found in dracut. The die() error-handling function writes its message | |
| CVE-2026-54213 | None | 0.45% | 1 | 0 | 2026-08-07T12:32:06 | Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality tha | |
| CVE-2026-54211 | None | 0.41% | 1 | 0 | 2026-08-07T12:32:00 | Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_ | |
| CVE-2026-14364 | 9.8 | 0.29% | 2 | 0 | 2026-08-07T06:30:34 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress i | |
| CVE-2026-19191 | 7.8 | 0.11% | 1 | 0 | 2026-08-07T06:30:26 | A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. T | |
| CVE-2026-19190 | 7.8 | 0.14% | 2 | 0 | 2026-08-07T06:30:25 | A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an | |
| CVE-2026-65400 | 7.1 | 0.30% | 1 | 0 | 2026-08-07T03:31:32 | An authentication issue was addressed with improved state management. This issue | |
| CVE-2026-19189 | 7.8 | 0.11% | 2 | 0 | 2026-08-07T03:30:38 | A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected | |
| CVE-2026-63508 | 10.0 | 0.44% | 2 | 0 | 2026-08-07T00:31:33 | Missing authentication for critical function in Microsoft Planetary Computer Pro | |
| CVE-2026-62873 | 9.8 | 0.34% | 1 | 0 | 2026-08-07T00:31:33 | Improper verification of cryptographic signature in Microsoft 365 Admin Center a | |
| CVE-2026-49163 | 8.8 | 0.62% | 2 | 0 | 2026-08-07T00:31:28 | Improper limitation of a pathname to a restricted directory ('path traversal') i | |
| CVE-2026-56161 | 9.6 | 0.38% | 2 | 0 | 2026-08-07T00:31:28 | Improper access control in Azure Logic Apps allows an authorized attacker to dis | |
| CVE-2026-59115 | 9.9 | 0.64% | 1 | 0 | 2026-08-07T00:31:28 | '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an autho | |
| CVE-2026-70559 | 7.5 | 0.33% | 2 | 1 | 2026-08-07T00:31:27 | Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carri | |
| CVE-2026-56162 | 10.0 | 0.48% | 3 | 0 | 2026-08-07T00:31:27 | Improper authentication in Azure SQL Database allows an unauthorized attacker to | |
| CVE-2026-62836 | 8.7 | 0.36% | 1 | 0 | 2026-08-07T00:31:27 | Improper restriction of communication channel to intended endpoints in Azure SQL | |
| CVE-2026-16633 | None | 0.00% | 1 | 0 | 2026-08-06T21:12:27 | ### Impact If PDF.js is used to load a malicious PDF, and PDF.js is configured | |
| CVE-2026-64665 | 8.1 | 0.31% | 2 | 0 | 2026-08-06T19:25:06 | ### Impact When OAuth login is enabled with a provider that does not guarantee | |
| CVE-2026-19036 | 7.2 | 2.47% | 2 | 0 | 2026-08-06T15:32:48 | A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the | |
| CVE-2026-19034 | 7.2 | 2.47% | 2 | 0 | 2026-08-06T12:31:21 | A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vuln | |
| CVE-2026-19035 | 7.2 | 2.47% | 2 | 0 | 2026-08-06T12:31:21 | A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issu | |
| CVE-2026-5430 | 10.0 | 0.22% | 1 | 0 | 2026-08-06T09:30:40 | The JWT authentication mechanism accepts tokens signed with algorithms other tha | |
| CVE-2026-17650 | 8.3 | 0.35% | 2 | 0 | 2026-08-06T00:36:25.360000 | Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a | |
| CVE-2026-17656 | 9.6 | 0.40% | 2 | 0 | 2026-08-06T00:30:24.850000 | Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote | |
| CVE-2026-63077 | 9.8 | 1.01% | 2 | 4 | template | 2026-08-05T18:32:31 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe |
| CVE-2026-70374 | 8.8 | 2.52% | 2 | 0 | 2026-08-05T15:32:14 | HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE- | |
| CVE-2026-66747 | 9.8 | 0.58% | 1 | 0 | 2026-08-05T15:17:04.690000 | Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, | |
| CVE-2026-18902 | 7.2 | 2.38% | 2 | 0 | 2026-08-05T06:30:32 | A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerabilit | |
| CVE-2026-18900 | 7.2 | 2.38% | 2 | 0 | 2026-08-05T06:30:31 | A weakness has been identified in H3C NX15 V100R017. This impacts the function f | |
| CVE-2026-18814 | 7.2 | 2.71% | 2 | 0 | 2026-08-05T00:30:41 | A vulnerability was found in H3C NX15 V100R017. This impacts the function reload | |
| CVE-2026-9198 | 9.8 | 17.05% | 1 | 4 | 2026-08-04T21:30:25 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain | |
| CVE-2026-64633 | None | 0.34% | 1 | 1 | 2026-08-04T18:31:36 | A vulnerability allowing remote unauthenticated code execution on the agent host | |
| CVE-2026-18577 | 8.1 | 4.10% | 1 | 2 | 2026-08-04T15:33:20 | An incomplete patch for CVE-2026-18556 allows for authentication bypass and acco | |
| CVE-2026-29146 | 7.5 | 6.26% | 1 | 0 | 2026-08-04T13:18:02.797000 | Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default | |
| CVE-2024-49039 | 8.8 | 13.72% | 1 | 2 | 2026-08-04T05:16:30.980000 | Windows Task Scheduler Elevation of Privilege Vulnerability | |
| CVE-2026-18686 | 9.8 | 2.61% | 2 | 0 | 2026-08-04T00:35:01 | A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected elem | |
| CVE-2026-18601 | 9.8 | 2.38% | 2 | 0 | 2026-08-03T15:32:55 | A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the fun | |
| CVE-2026-64531 | 7.8 | 0.13% | 1 | 4 | 2026-08-01T09:30:23 | In the Linux kernel, the following vulnerability has been resolved: net: openvs | |
| CVE-2026-28323 | 9.8 | 0.64% | 1 | 0 | 2026-07-30T18:31:47 | SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass | |
| CVE-2026-64560 | 7.8 | 0.12% | 3 | 1 | 2026-07-30T12:19:03.630000 | In the Linux kernel, the following vulnerability has been resolved: posix-cpu-t | |
| CVE-2025-68260 | 7.8 | 0.16% | 1 | 0 | 2026-07-30T06:33:30 | In the Linux kernel, the following vulnerability has been resolved: rust_binder | |
| CVE-2026-60206 | 9.9 | 0.49% | 1 | 4 | 2026-07-28T14:14:37.463000 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware | |
| CVE-2025-68686 | 5.9 | 1.26% | 1 | 0 | 2026-07-28T05:17:04.113000 | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE | |
| CVE-2026-60667 | 7.4 | 0.33% | 1 | 0 | 2026-07-24T21:32:15 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle | |
| CVE-2026-65535 | 4.3 | 0.18% | 1 | 0 | 2026-07-23T14:17:59.510000 | Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions. | |
| CVE-2026-34348 | 6.5 | 0.71% | 1 | 0 | 2026-07-14T18:31:58 | Protection mechanism failure in Windows Event Logging Service allows an authoriz | |
| CVE-2026-0288 | 7.5 | 0.84% | 1 | 0 | 2026-07-10T15:45:17.463000 | Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (T | |
| CVE-2025-8088 | 8.8 | 94.55% | 1 | 31 | 2026-06-17T10:06:17.243000 | A path traversal vulnerability affecting the Windows version of WinRAR allows th | |
| CVE-2024-43451 | 6.5 | 81.82% | 1 | 2 | 2026-06-17T07:51:04.273000 | NTLM Hash Disclosure Spoofing Vulnerability | |
| CVE-2024-38193 | 7.8 | 27.56% | 1 | 1 | 2026-06-17T07:39:39.247000 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerabili | |
| CVE-2024-38178 | 7.5 | 41.38% | 1 | 0 | 2026-06-17T07:39:37.397000 | Scripting Engine Memory Corruption Vulnerability | |
| CVE-2024-36971 | 7.8 | 2.70% | 1 | 1 | 2026-06-17T07:37:30.630000 | In the Linux kernel, the following vulnerability has been resolved: net: fix __ | |
| CVE-2026-52880 | 7.5 | 0.29% | 1 | 0 | 2026-06-09T18:40:45 | ### Summary The Klever seednode REST API starts a Gin engine with `Engine.Run(r | |
| CVE-2026-52879 | 7.5 | 0.29% | 1 | 0 | 2026-06-09T18:40:42 | ### Summary `networkMessenger.directMessageHandler` in `network/p2p/libp2p/netM | |
| CVE-2026-34486 | 7.5 | 81.16% | 1 | 6 | 2026-06-08T23:28:56 | Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the f | |
| CVE-2026-47249 | 7.5 | 0.28% | 1 | 0 | 2026-06-05T15:27:42 | ### Summary A connected peer can send a compressed `RequestDataType_HashArrayTyp | |
| CVE-2026-28299 | 8.2 | 0.49% | 1 | 0 | 2026-06-02T21:30:50 | SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerab | |
| CVE-2026-20685 | 6.5 | 0.19% | 1 | 1 | 2026-05-18T18:31:37 | An attacker in a privileged network position may be able to leak sensitive infor | |
| CVE-2026-41679 | 10.0 | 2.95% | 1 | 1 | 2026-04-27T16:19:05 | ## Summary An unauthenticated attacker can achieve full remote code execution o | |
| CVE-2024-23692 | 9.8 | 99.47% | 1 | 14 | 2025-10-22T00:34:06 | Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a t | |
| CVE-2025-42999 | 9.1 | 11.28% | 1 | 1 | 2025-10-22T00:33:19 | SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged | |
| CVE-2025-36852 | None | 0.20% | 1 | 0 | 2025-10-14T19:17:03 | A critical security vulnerability exists in remote cache extensions for common b | |
| CVE-2021-26708 | 7.0 | 1.60% | 1 | 3 | 2023-11-18T05:04:48 | A local privilege escalation was discovered in the Linux kernel before 5.10.13. | |
| CVE-2015-6609 | None | 2.17% | 1 | 0 | 2023-01-27T05:08:18 | libutils in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote | |
| CVE-2026-63637 | 0 | 0.24% | 2 | 0 | N/A | ||
| CVE-2026-62296 | 0 | 0.28% | 2 | 0 | N/A | ||
| CVE-2026-60004 | 0 | 0.00% | 1 | 8 | template | N/A | |
| CVE-2026-48097 | 0 | 0.27% | 1 | 0 | N/A | ||
| CVE-2026-65819 | 0 | 0.37% | 1 | 0 | N/A | ||
| CVE-2026-48026 | 0 | 0.22% | 1 | 0 | N/A | ||
| CVE-2026-48120 | 0 | 0.14% | 1 | 0 | N/A | ||
| CVE-2026-62295 | 0 | 0.28% | 1 | 0 | N/A | ||
| CVE-2026-61808 | 0 | 0.34% | 1 | 0 | N/A | ||
| CVE-2026-33691 | 0 | 3.58% | 1 | 0 | N/A | ||
| CVE-2026-48024 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-48162 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-49441 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-18576 | 0 | 0.00% | 1 | 0 | N/A |
updated 2026-08-10T07:16:50.487000
2 posts
CVE-2026-18786: CRITICAL auth bypass in CheckView WP plugin ≤2.0.29. Attackers can exploit REST API via crafted links to perform admin actions if an admin clicks. Restrict plugin REST API & avoid suspicious links. https://radar.offseq.com/threat/cve-2026-18786-cwe-287-improper-authentication-in-checkview-8f35dcb91728f992 #OffSeq #WordPress #CVE202618786
##CVE-2026-18786: CRITICAL auth bypass in CheckView WP plugin ≤2.0.29. Attackers can exploit REST API via crafted links to perform admin actions if an admin clicks. Restrict plugin REST API & avoid suspicious links. https://radar.offseq.com/threat/cve-2026-18786-cwe-287-improper-authentication-in-checkview-8f35dcb91728f992 #OffSeq #WordPress #CVE202618786
##updated 2026-08-10T07:16:48.380000
2 posts
CVE-2026-16985: Squeeze WP plugin <1.7.12 has a CRITICAL vuln — users with upload_files can upload PHP files, enabling remote code execution. Restrict permissions, monitor uploads, and check for updates. https://radar.offseq.com/threat/cve-2026-16985-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-squeeze-a1de64d348b6591f #OffSeq #WordPress #CVE2026_16985 #infosec
##CVE-2026-16985: Squeeze WP plugin <1.7.12 has a CRITICAL vuln — users with upload_files can upload PHP files, enabling remote code execution. Restrict permissions, monitor uploads, and check for updates. https://radar.offseq.com/threat/cve-2026-16985-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-squeeze-a1de64d348b6591f #OffSeq #WordPress #CVE2026_16985 #infosec
##updated 2026-08-10T03:16:40.380000
2 posts
GStreamer gst-plugins-ugly (asfdemux) in Red Hat Enterprise Linux 10 is affected by CVE-2026-19389 (HIGH, CVSS 7.1). Parsing crafted ASF/WMV/WMA files may lead to DoS or info leaks. No patch yet — avoid untrusted media. https://radar.offseq.com/threat/cve-2026-19389-integer-overflow-or-wraparound-in-red-hat-red-hat-enterprise-linux-10-8bd45ea7a574114c #OffSeq #Linux #CVE #GStreamer
##GStreamer gst-plugins-ugly (asfdemux) in Red Hat Enterprise Linux 10 is affected by CVE-2026-19389 (HIGH, CVSS 7.1). Parsing crafted ASF/WMV/WMA files may lead to DoS or info leaks. No patch yet — avoid untrusted media. https://radar.offseq.com/threat/cve-2026-19389-integer-overflow-or-wraparound-in-red-hat-red-hat-enterprise-linux-10-8bd45ea7a574114c #OffSeq #Linux #CVE #GStreamer
##updated 2026-08-10T03:16:40.223000
2 posts
🟠 CVE-2026-19387 - High (7.6)
A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to ca...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19387/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19387 - High (7.6)
A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to ca...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19387/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-10T01:16:48.367000
4 posts
🟠 CVE-2026-19381 - High (7.8)
A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performing a manipulation results in improper privilege m...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19381/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Kingston FURY CTRL RGB Control Software v2.0.65.0 hit by HIGH severity vuln (CVE-2026-19381, CVSS 8.5). Local attackers can escalate privileges via NTIOLib_KSFX.sys. Exploit code is public; no patch yet. Restrict local access, monitor systems. https://radar.offseq.com/threat/cve-2026-19381-improper-privilege-management-in-kingston-fury-ctrl-rgb-control-software-9a62169aad70214d #OffSeq #Vuln #Kingston
##🟠 CVE-2026-19381 - High (7.8)
A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performing a manipulation results in improper privilege m...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19381/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Kingston FURY CTRL RGB Control Software v2.0.65.0 hit by HIGH severity vuln (CVE-2026-19381, CVSS 8.5). Local attackers can escalate privileges via NTIOLib_KSFX.sys. Exploit code is public; no patch yet. Restrict local access, monitor systems. https://radar.offseq.com/threat/cve-2026-19381-improper-privilege-management-in-kingston-fury-ctrl-rgb-control-software-9a62169aad70214d #OffSeq #Vuln #Kingston
##updated 2026-08-09T22:16:30.373000
2 posts
CVE-2026-15534: HIGH severity in LEONT perl (≤5.45.1) — Integer overflow in regex engine can cause heap corruption or crashes when large inputs and crafted patterns are processed. Avoid risky patterns until patched. https://radar.offseq.com/threat/cve-2026-15534-cwe-190-integer-overflow-or-wraparound-in-leont-perl-b58a44fbf0b93abe #OffSeq #Perl #Vuln #AppSec
##CVE-2026-15534: HIGH severity in LEONT perl (≤5.45.1) — Integer overflow in regex engine can cause heap corruption or crashes when large inputs and crafted patterns are processed. Avoid risky patterns until patched. https://radar.offseq.com/threat/cve-2026-15534-cwe-190-integer-overflow-or-wraparound-in-leont-perl-b58a44fbf0b93abe #OffSeq #Perl #Vuln #AppSec
##updated 2026-08-09T12:32:52
4 posts
🔴 CVE-2026-19348 - Critical (9.8)
A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation of t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19348/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-19348 in Shenzhen Aitemi M300 Wi-Fi Repeater: CRITICAL command injection via /protocol.csp (enable, name, mac). Public exploit code out; no patch yet. Restrict access & monitor traffic. https://radar.offseq.com/threat/cve-2026-19348-command-injection-in-shenzhen-aitemi-m300-wi-fi-repeater-50170c9de7b315c0 #OffSeq #CVE202619348 #IoTSecurity
##🔴 CVE-2026-19348 - Critical (9.8)
A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation of t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19348/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-19348 in Shenzhen Aitemi M300 Wi-Fi Repeater: CRITICAL command injection via /protocol.csp (enable, name, mac). Public exploit code out; no patch yet. Restrict access & monitor traffic. https://radar.offseq.com/threat/cve-2026-19348-command-injection-in-shenzhen-aitemi-m300-wi-fi-repeater-50170c9de7b315c0 #OffSeq #CVE202619348 #IoTSecurity
##updated 2026-08-09T10:17:10.567000
2 posts
🟠 CVE-2026-19346 - High (8.8)
A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection. The attack can be initiated remotely....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19346/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19346 - High (8.8)
A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection. The attack can be initiated remotely....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19346/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T09:30:29
1 posts
🟠 CVE-2026-19341 - High (8.8)
A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/pptpSrvGlobalConfig. Such manipulation of the argument EncryptionMode leads to stack-based buffer overflow. The...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19341/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T06:32:38
2 posts
1 repos
🟠 CVE-2026-19195 - High (7.8)
A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in the library ZyArk.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19195/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19195 - High (7.8)
A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in the library ZyArk.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19195/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T06:31:42
1 posts
🟠 CVE-2026-10595 - High (7.5)
A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises from the improper handling of user-controlled path input, which is dir...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10595/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T06:31:36
1 posts
1 repos
CVE-2026-15038 (CRITICAL): InfiniteWP Client <1.13.6 has improper authentication in WordPress Multisite. Allows unauthenticated takeover & potential RCE. Restrict endpoint, monitor activity, upgrade ASAP. https://radar.offseq.com/threat/cve-2026-15038-cwe-287-improper-authentication-in-infinitewp-client-58f162c29ea9006c #OffSeq #WordPress #Vuln #BlueTeam
##updated 2026-08-09T06:31:34
3 posts
6 repos
https://github.com/Aoripus-LTD/Zapscape-Fix
https://github.com/aarif450/aarif450.github.io
https://github.com/aarif450/Zapscape
https://github.com/chuzhongyun/CVE-2026-64561-Kernel-Fix
Instale já a correção para vulnerabilidade em máquinas virtuais
Se você usa Proxmox ou apenas tem um VPS, atualize já seu sistema. O problema permite o escape de máquinas virtuais e acesso à máquina física.
Se usa Debian, saiu o kernel 6.12.101-1 que corrige o problema. O Proxmox também já lançou atualização mesmo para quem não é assinante com o kernel 7.0.14-9.
:debian: https://security-tracker.debian.org/tracker/CVE-2026-64561
:xp_secure_server: https://forum.proxmox.com/threads/proxmox-and-cve-2026-64561.185571/
:xp_sys_info: https://www.cve.org/CVERecord?id=CVE-2026-64561
:github: https://github.com/V4bel/Zapscape
A new Linux Kernel KVM vulnerability threatens cloud servers with virtual machine escape risks. Learn about CVE-2026-64561 and secure your host machine now.
#LinuxKernel #KVMVulnerability #CVE202664561 #CloudSecurity #VMescape
##「Zapscape KVMの新たな脆弱性により、特権を持つL1ゲストコードがLinuxホストに漏洩する可能性 」: #TheHackerNews
「Linuxカーネルの新たな脆弱性「Zapscape」 により、L1ゲスト仮想マシン(VM)内でカーネル権限を持つ攻撃者がKVM分離を回避し、ホスト上でコードを実行できる可能性があります。このリスクは、ネストされた仮想化が信頼できないゲストに公開されている場合に発生します。
この脆弱性は CVE-2026-64561 として追跡されており、ネストされたゲストメモリ変換に使用されるシャドウページテーブルを管理するKVM/x86のシャドウメモリ管理ユニット(MMU)に影響を与えます。
このバグを明らかにしたセキュリティ研究者の キム・ヒョヌ氏 は、実証されたエクスプロイト経路によって、カーネル権限、つまりroot権限でホスト上でコマンドを実行できると述べた。 」
https://thehackernews.com/2026/08/new-zapscape-kvm-flaw-could-let.html
##updated 2026-08-09T06:19:12.620000
2 posts
1 repos
🟠 CVE-2026-19193 - High (7.8)
A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of the component Minifilter Port. Executing a manipulation can lead to improper access controls. The attack needs to be launch...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19193/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19193 - High (7.8)
A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of the component Minifilter Port. Executing a manipulation can lead to improper access controls. The attack needs to be launch...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19193/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T04:17:43.283000
10 posts
3 repos
https://github.com/suominen/sctphantom
CVE-2026-64564: SCTP Flaw Enables Container Escape
##SCTPhantom: 18-Year-Old Linux Kernel Flaw Allows Root Access and Container Escape
A use-after-free vulnerability in the Linux SCTP implementation (CVE-2026-64564) allows local attackers to gain root privileges and escape containers. The flaw has existed since 2008 and affects most major Linux distributions.
**If you run Linux (Debian, Ubuntu, RHEL, Rocky) on servers, containers or workstations, install the latest kernel update from your distribution vendor and reboot. The fix for CVE-2026-64564 only takes effect after the restart. If you don't use SCTP, also switch the module off (add both blacklist sctp and install sctp /bin/false to /etc/modprobe.d/sctp.conf, refresh the initramfs, and confirm with lsmod | grep sctp that nothing comes back).**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/sctphantom-18-year-old-linux-kernel-flaw-allows-root-access-and-container-escape-f-i-j-g-0/gD2P6Ple2L
🏆 New Achievement! SCTPhantom Menace: Eighteen Years In The Making!
ERROR: Kernel identity verification module returned incorrect value. Duration of incorrect value: eighteen years. Tencent researchers have confirmed CVE-2026-64564, a use-after-free in Linux's SCTP networking code, allows local users to escalate to root and escape containers entirely. The bug checks a delete request against the packet's source address, then acts on a different one. The kernel trusted the wrong address. (1/2)
##CVE-2026-64564: SCTP Flaw Enables Container Escape
##SCTPhantom: 18-Year-Old Linux Kernel Flaw Allows Root Access and Container Escape
A use-after-free vulnerability in the Linux SCTP implementation (CVE-2026-64564) allows local attackers to gain root privileges and escape containers. The flaw has existed since 2008 and affects most major Linux distributions.
**If you run Linux (Debian, Ubuntu, RHEL, Rocky) on servers, containers or workstations, install the latest kernel update from your distribution vendor and reboot. The fix for CVE-2026-64564 only takes effect after the restart. If you don't use SCTP, also switch the module off (add both blacklist sctp and install sctp /bin/false to /etc/modprobe.d/sctp.conf, refresh the initramfs, and confirm with lsmod | grep sctp that nothing comes back).**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/sctphantom-18-year-old-linux-kernel-flaw-allows-root-access-and-container-escape-f-i-j-g-0/gD2P6Ple2L
🏆 New Achievement! SCTPhantom Menace: Eighteen Years In The Making!
ERROR: Kernel identity verification module returned incorrect value. Duration of incorrect value: eighteen years. Tencent researchers have confirmed CVE-2026-64564, a use-after-free in Linux's SCTP networking code, allows local users to escalate to root and escape containers entirely. The bug checks a delete request against the packet's source address, then acts on a different one. The kernel trusted the wrong address. (1/2)
##「18年前のLinux SCTPの脆弱性により、ローカルユーザーがroot権限を取得し、コンテナから脱出できる可能性 」: #TheHackerNews
「LinuxのSCTPネットワークコードに存在する解放済みメモリ使用のバグを悪用すると、ホスト上で完全なroot権限を取得できる可能性がある。Tencentの研究者らは、このバグを利用してコンテナから脱出し、その下にあるマシンにアクセスしたと述べている。
この脆弱性は2008年から存在していました。修正版は既にリリースされており、8月3日にリリースされた安定版カーネル7.1.6、6.18.42、6.12.101、6.6.148で修正されています。SCTP接続可能な古いカーネルを使用しているユーザーはアップデートしてください。
CVE-2026-64564 として追跡され 、 発見者によってSCTPhantom と名付けられたこの脆弱性は、カーネルCVEチームが割り当てた2日後の8月6日に公表された。 」
https://thehackernews.com/2026/08/18-year-old-linux-sctp-flaw-could-let.html
##SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free · Tencent Zhuque Lab https://matrix.tencent.com/en/2026/08/06/sctphantom-CVE-2026-64564
##updated 2026-08-09T00:31:13
4 posts
MSI Radix AXE6600 (firmware v781521) is affected by CVE-2026-71993 (CVSS 9.8): CRITICAL command injection in openvpn via macfilter allows remote root access. Restrict management access & monitor activity. Details: https://radar.offseq.com/threat/msi-radix-axe6600-router-firmware-version-v781521-contains-a-command-injection-vulnerability-in-the-776e96041d2257c7 #OffSeq #Vuln #RouterSecurity #CVE2026_71993
##MSI Radix AXE6600 (firmware v781521) is affected by CVE-2026-71993 (CVSS 9.8): CRITICAL command injection in openvpn via macfilter allows remote root access. Restrict management access & monitor activity. Details: https://radar.offseq.com/threat/msi-radix-axe6600-router-firmware-version-v781521-contains-a-command-injection-vulnerability-in-the-776e96041d2257c7 #OffSeq #Vuln #RouterSecurity #CVE2026_71993
##MSI Radix AXE6600 v781521 suffers CRITICAL CVE-2026-71993 (CVSS 9.3): OS Command Injection via macfilter allows remote root access. Restrict remote access & monitor openvpn/macfilter activity. Details: https://radar.offseq.com/threat/cve-2026-71993-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-d8e25db330470f39 #OffSeq #CVE #RouterSecurity #Infosec
##🔴 CVE-2026-71993 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71993/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T00:31:13
3 posts
MSI Radix AXE6600 (v781521) is affected by CVE-2026-71986 (CRITICAL) — OS command injection in dmz function allows remote root access. No patch yet, monitor vendor updates. https://radar.offseq.com/threat/cve-2026-71986-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-a197b90333b0f1d8 #OffSeq #CVE #Infosec #RouterSecurity
##MSI Radix AXE6600 (v781521) is affected by CVE-2026-71986 (CRITICAL) — OS command injection in dmz function allows remote root access. No patch yet, monitor vendor updates. https://radar.offseq.com/threat/cve-2026-71986-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-a197b90333b0f1d8 #OffSeq #CVE #Infosec #RouterSecurity
##🔴 CVE-2026-71986 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71986/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T00:31:13
2 posts
MSI Radix AXE6600 (v781521) hit by CRITICAL OS command injection (CVE-2026-71990, CVSS 9.3). Remote attackers can gain root via SSH config. No patch yet — restrict SSH access & monitor for updates. https://radar.offseq.com/threat/cve-2026-71990-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-0b56ced622becfdc #OffSeq #CVE #infosec #router
##🔴 CVE-2026-71990 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can expl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71990/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T00:31:13
2 posts
MSI Radix AXE6600 routers (v781521) affected by CRITICAL OS command injection (CVE-2026-71992, CVSS 9.3). Remote attackers can execute root commands — no auth needed. Restrict access, monitor logs. No patch yet. https://radar.offseq.com/threat/cve-2026-71992-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-20f0be0f1615528d #OffSeq #CVE202671992 #RouterSecurity
##🔴 CVE-2026-71992 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71992/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T00:31:13
1 posts
🔴 CVE-2026-71985 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71985/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T00:31:13
1 posts
🔴 CVE-2026-71984 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the urlfilter function ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71984/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T00:31:07
4 posts
CVE-2026-71987 - Critical unpatched RCE in MSI Radix AXE6600 routers via command injection in alg function. CVSS 9.8. Full root access possible. Update immediately or isolate devices. #CVE #MSI #infosec
##CVE-2026-71987: MSI Radix AXE6600 (v781521) suffers from a CRITICAL OS command injection vulnerability (CVSS 9.3). Remote, unauthenticated code execution possible with root privileges. Restrict device access and monitor! https://radar.offseq.com/threat/cve-2026-71987-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-46b78b0439cf6545 #OffSeq #CVE202671987 #Infosec #RouterSecurity
##CVE-2026-71987: MSI Radix AXE6600 (v781521) suffers from a CRITICAL OS command injection vulnerability (CVSS 9.3). Remote, unauthenticated code execution possible with root privileges. Restrict device access and monitor! https://radar.offseq.com/threat/cve-2026-71987-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-46b78b0439cf6545 #OffSeq #CVE202671987 #Infosec #RouterSecurity
##🔴 CVE-2026-71987 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71987/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T00:31:07
3 posts
MSI Radix AXE6600 (v781521) hit by CRITICAL OS command injection (CVE-2026-71988, CVSS 9.3). Remote attackers can gain root via portFw/alg — full device takeover possible. Patch status unconfirmed. More: https://radar.offseq.com/threat/cve-2026-71988-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-8fa920b8dd663be3 #OffSeq #CVE202671988 #Infosec #RouterSecurity
##MSI Radix AXE6600 (v781521) hit by CRITICAL OS command injection (CVE-2026-71988, CVSS 9.3). Remote attackers can gain root via portFw/alg — full device takeover possible. Patch status unconfirmed. More: https://radar.offseq.com/threat/cve-2026-71988-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-8fa920b8dd663be3 #OffSeq #CVE202671988 #Infosec #RouterSecurity
##🔴 CVE-2026-71988 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71988/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T00:16:48.270000
2 posts
🔴 CVE-2026-71991 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can e...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71991/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##MSI Radix AXE6600 routers (v781521) affected by CRITICAL CVE-2026-71991 🛡️. OS command injection via TelnetSSH enables remote root access. Restrict Telnet, segment devices, monitor for vendor fixes. https://radar.offseq.com/threat/cve-2026-71991-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-73b9d5ae919f36d2 #OffSeq #CVE202671991 #RouterSecurity
##updated 2026-08-09T00:16:47.953000
2 posts
MSI Radix AXE6600 routers (v781521) impacted by CVE-2026-71989: CRITICAL OS command injection (CVSS 9.3) in porTrigger/alg enables unauthenticated root command execution. Patch status unknown. Details: https://radar.offseq.com/threat/cve-2026-71989-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-0ff15d6b83145a7e #OffSeq #Vuln #CVE202671989 #RouterSecurity
##🔴 CVE-2026-71989 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability thr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71989/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T23:16:56.967000
1 posts
🔴 CVE-2026-71983 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through the pin2g, pin5g, or pin6g parame...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71983/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:30
1 posts
🔴 CVE-2026-71953 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary malicious commands into the ntpSe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71953/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:30
1 posts
🔴 CVE-2026-71955 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, ta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71955/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:30
1 posts
🔴 CVE-2026-71954 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71954/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:29
2 posts
CVE-2026-71950 - Critical RCE in D-Link DWR-M961. Command injection in formSmsManage, root access. CVSS 9.8. Unpatched. Disable remote access immediately. #CVE #DLink #infosec
##🔴 CVE-2026-71950 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject arbitrary malicious commands into the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71950/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:29
1 posts
🔴 CVE-2026-71945 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can inject arbitrary malicious comma...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71945/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:29
1 posts
🔴 CVE-2026-71944 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can inject arbitrary malicious comma...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71944/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:29
1 posts
🔴 CVE-2026-71952 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbitrary malicious commands int...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71952/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:29
1 posts
🔴 CVE-2026-71948 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71948/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:29
1 posts
🔴 CVE-2026-71957 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71957/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:29
1 posts
🔴 CVE-2026-71956 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst fiel...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71956/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:29
1 posts
🟠 CVE-2026-42170 - High (7.8)
A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS file declares a D3D9 pixel format but sets a lower bits-per-pixel (bpp) value in the header, the loader allocates an undersized ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-42170/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:25
1 posts
🔴 CVE-2026-71946 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71946/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:16:56.783000
1 posts
🔴 CVE-2026-71958 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71958/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:16:55.907000
1 posts
🔴 CVE-2026-71951 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject arbitrary malicious commands into the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71951/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:16:55.660000
1 posts
🔴 CVE-2026-71949 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject arbitrary malicious commands into the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71949/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:16:55.410000
2 posts
CVE-2026-71947 - Critical command injection in D-Link DWR-M961 routers. Remote attackers can execute arbitrary commands as root via /boafrm/formTracerouteDiagnosticRun. CVSS 9.8. No patch available - isolate affected devices now. #CVE #DLink #infosec
##🔴 CVE-2026-71947 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can inject arbitrary malicious com...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71947/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T16:16:49.420000
1 posts
1 repos
🟠 CVE-2026-67620 - High (7.7)
Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba Cloud meta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67620/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T09:30:28
3 posts
CVE-2026-14526 - Critical auth bypass in AI Copilot WordPress plugin. Unauthenticated attackers can create admin accounts and take over sites. CVSS 9.8. Unpatched. Disable plugin now. #CVE #WordPress #infosec
##CVE-2026-14526: AI Copilot – Content Generator <=1.5.6 has a CRITICAL auth bypass. Unauth attackers can create WordPress admin users via an exposed nonce, leading to site takeover. Disable [aiwu-form]/chatbot & check for vendor patch. https://radar.offseq.com/threat/cve-2026-14526-cwe-269-improper-privilege-management-in-wupsales-ai-copilot-content-generator-735a53bb0d60cd45 #OffSeq #CVE202614526 #WordPress
##🔴 CVE-2026-14526 - Critical (9.8)
The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This make...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14526/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T09:30:28
1 posts
CVE-2026-16948 | HIGH severity in Solace Extra WP plugin <1.6.1: Missing capability checks on AJAX actions lets Subscribers change site settings & delete imported content. Patch status unknown — tighten role permissions. https://radar.offseq.com/threat/cve-2026-16948-cwe-284-improper-access-control-in-solace-extra-5877e08458999aac #OffSeq #WordPress #CVE2026_16948
##updated 2026-08-08T07:17:11.440000
1 posts
CVE-2026-16955: HIGH severity path traversal in AI Engine WP plugin <3.6.6. Subscribers can read arbitrary files if public API is enabled. Restrict API & admin privileges. Await patch. https://radar.offseq.com/threat/cve-2026-16955-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-ai-72905be644e71053 #OffSeq #WordPress #CVE2026_16955 #Security
##updated 2026-08-08T07:17:10.910000
1 posts
CVE-2026-16594: WP Directory Kit <1.5.5 has a HIGH severity info exposure flaw. Any authenticated user (even Subscribers) can access API keys/secrets due to missing authorization on AJAX action. Restrict user roles & monitor logs. https://radar.offseq.com/threat/cve-2026-16594-cwe-200-information-exposure-in-wp-directory-kit-3d8a39f4c5fd7c8a #OffSeq #WordPress #CVE
##updated 2026-08-08T05:17:10.403000
5 posts
2 repos
📰 CISA Adds Progress Kemp LoadMaster Flaw to KEV Catalog After Exploits
🚨 CISA KEV ALERT: A critical command injection flaw in Progress Kemp LoadMaster (CVE-2026-8037, CVSS 9.6) is actively exploited. Unauthenticated attackers can gain full control. Federal agencies must patch by Aug 10. #CVE #CISA #KEV #PatchNow
##CRITICAL THREAT ALERT: Active exploitation of CVE-2026-8037 in Progress LoadMaster allows unauthenticated RCE via command injection. Securing your perimeter requires immediate SIEM detection updates and access restrictions. Review our full TSUITE analysis: https://thecybermind.co/5yde
##🚨 [CISA-2026:0807] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-8037 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8037)
- Name: Progress LoadMaster Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Progress
- Product: LoadMaster
- Notes: https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8037
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260807 #cisa20260807 #cve_2026_8037 #cve20268037
##CVE ID: CVE-2026-8037
Vendor: Progress
Product: LoadMaster
Date Added: 2026-08-07
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8037
CISA has added one vulnerability to the KEV catalogue:
CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-8037 #CISA
Cisco:
NEW: CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26 #Cisco
Palo Alto:
CRITICAL, NEW: CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent https://security.paloaltonetworks.com/CVE-2026-0288
Microsoft:
Several updates for a slew of vulnerabilities were posted today on the Microsoft Update Guide: https://msrc.microsoft.com/update-guide/ #Microsoft
Google:
New: Chrome Dev for Android Update https://chromereleases.googleblog.com/ #Google #Chrome
Broadcom:
One new advisory for a high-severity vulnerability that was first published on July 23 https://support.broadcom.com/web/ecx/security-advisory
Posted yesterday:
Apple security updates https://support.apple.com/en-us/100100 #Apple
AMD: Safe RET Interrupt Vulnerability https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7061.html #AMD
Dell:
CRITICAL, last updated yesterday: Dell PowerMaxOS, Dell PowerMax EEM, Dell Unisphere for PowerMax, Dell Solutions Enabler Security Update for Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000483543/dsa-2026-272-dell-powermaxos-dell-powermax-eem-dell-unisphere-for-powermax-dell-unisphere-for-powermax-virtualappliance-dell-unisphere-360-dell-solutionsenabler-and-dell-solutionsenabler-virtualappliance-security-update-for-multiple-vulnerabilities #Dell #infosec #vulnerability #Java #SQL
##updated 2026-08-08T05:17:09.880000
2 posts
CVE-2026-56793 - High-severity improper authentication in Dell OpenManage Server Administrator (<11.1.0.2). Remote unauthenticated attackers can gain unauthorized access. CVSS 7.7. Update immediately. #CVE #Dell #infosec
##🟠 CVE-2026-56793 - High (7.7)
Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56793/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T04:17:55.850000
2 posts
CVE-2026-71851 (CRITICAL, CVSS 9): brix crypto-js <4.0.0 uses weak RNG in WordArray.random(), risking private key recovery in wallet apps using BIP39. Upgrade to 4.0.0+ now. https://radar.offseq.com/threat/cve-2026-71851-cwe-331-insufficient-entropy-in-brix-crypto-js-e5283f6c465bd95e #OffSeq #CryptoJS #InfoSec #Vulnerability
##🔴 CVE-2026-71851 - Critical (9)
crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded from Math....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71851/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T03:32:14
1 posts
🔴 CVE-2026-71560 - Critical (9.1)
Out-of-bounds Read vulnerability in Apache Fory C++ deserialization.
This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-b...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71560/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T03:32:14
1 posts
🔴 CVE-2026-71558 - Critical (9.8)
Heap type confusion vulnerability in Apache Fory C++ deserialization.
This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserializat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71558/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T03:16:46.910000
2 posts
🔴 CVE-2026-70558 - Critical (9.8)
Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and /download/** is excluded from the Sa-Token...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70558/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-70558 - Critical (9.8)
Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and /download/** is excluded from the Sa-Token...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70558/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T03:16:46.377000
2 posts
🟠 CVE-2026-5857 - High (8.1)
Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag set. On the next TCP segment, tc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-5857/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-5857 - High (8.1)
Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag set. On the next TCP segment, tc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-5857/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T03:16:45.610000
1 posts
🟠 CVE-2026-19192 - High (7.8)
A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C:\DeepCool\resources\service\x64\DeepCoolDisplayService.exe. Performing a manipulation results in improper access controls. The...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19192/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T23:17:04.593000
1 posts
🟠 CVE-2026-52878 - High (7.5)
Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a nil-pointer panic triggered by a protobuf Transaction whose embedded RawData sub-message is omitted. This omission causes RawD...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52878/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T23:17:03.243000
1 posts
🔴 CVE-2026-46409 - Critical (9.6)
OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:` (commonly 19141) without server-side Origin validat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46409/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T22:16:59.170000
3 posts
CVE-2026-48170 - Critical prototype pollution in scim-patch <0.9.1. Attacker-controlled SCIM PATCH can pollute Object.prototype process-wide. CVSS 9.1. Unpatched - update immediately. #CVE #NodeJS #infosec
##CVE-2026-48170 (CRITICAL, CVSS 9.1): Prototype pollution in scim-patch <0.9.1 lets attackers alter Object.prototype globally in Node.js. Upgrade to 0.9.1+ or freeze prototypes for mitigation. https://radar.offseq.com/threat/cve-2026-48170-cwe-1321-improperly-controlled-modification-of-object-prototype-attributes-prototype-1a8d5ec623a7b014 #OffSeq #CVE202648170 #NodeJS #InfoSec
##🔴 CVE-2026-48170 - Critical (9.1)
`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH operation whose `value` object contains a key like `"__proto__.someProp"`. After one such patch,
`Object.prototype.somePr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48170/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T21:31:37
1 posts
🔴 CVE-2026-16258 - Critical (9.8)
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Searc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16258/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T21:31:36
1 posts
🟠 CVE-2026-16263 - High (8.8)
The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a Subscriber account to includ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16263/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T21:30:40
1 posts
🟠 CVE-2025-63235 - High (7.5)
In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CONNECT packets. When clients send invalid CONNECT packets - either due to repeated attempts or failed authentication - the server...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-63235/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T21:30:40
1 posts
🟠 CVE-2026-15972 - High (7.5)
Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC listeners. A remote attacker may exhaust agent file descriptors...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15972/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T21:30:37
1 posts
🟠 CVE-2026-64636 - High (7.7)
An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64636/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T21:30:33
1 posts
🟠 CVE-2026-15215 - High (8.8)
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protecte...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15215/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T21:30:33
1 posts
🟠 CVE-2026-16041 - High (7.5)
The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chose...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16041/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T21:17:28.827000
1 posts
🔴 CVE-2026-50540 - Critical (9.6)
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalidated config...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50540/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T21:17:27.317000
1 posts
🟠 CVE-2026-19082 - High (7.5)
Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags.
copy_string_tags() computes an ASCII EXIF tag's length as `entry->size - 1` to strip ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19082/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T21:16:58
1 posts
🟠 CVE-2026-48169 - High (8.8)
PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace isolation. The service layer for issues and projects performs global primary-key lookups w...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48169/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T19:29:59
2 posts
pipeboard-co meta-ads-mcp (<1.0.109) affected by CRITICAL auth bypass (CVE-2026-48039). Unauthenticated requests can access tools & leak access tokens via error responses. Patch to 1.0.109+ ASAP. https://radar.offseq.com/threat/cve-2026-48039-cwe-287-improper-authentication-in-pipeboard-co-meta-ads-mcp-cda3b9551f498ab7 #OffSeq #CVE202648039 #infosec #vuln
##🔴 CVE-2026-48039 - Critical (9.1)
Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streamable HTTP r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48039/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T19:29:09.813000
2 posts
🔴 CVE-2026-50481 - Critical (9.9)
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50481/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-50481 - Critical (9.9)
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50481/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T19:18:51.610000
10 posts
19 repos
https://github.com/0xlipon/xss2shell
https://github.com/jendmaoul/XSS2Shell-CVE-2026-64638
https://github.com/Dungsocool/CVE-2026-64638
https://github.com/ZSecur1ty/XSS2Shell-CVE-2026-64638
https://github.com/renzi25031469/CVE-2026-64638-WordPress-Core-XSS2Shell
https://github.com/imbas007/CVE-2026-64638-POC
https://github.com/wordsec/XSS2Shell
https://github.com/mohwahyudi/poc-CVE-2026-64638-
https://github.com/tc4dy/CVE-2026-64638-PoC-Exploit
https://github.com/HackSpeak/CVE-2026-64638
https://github.com/5yu4n/CVE-2026-64638
https://github.com/eh-amish/CVE-2026-64638-XSS-to-Shell-PoC
https://github.com/4minx/CVE-2026-64638
https://github.com/686f6c61/POC-WP-XSS2Shell-CVE-2026-64638
https://github.com/Boreas37/CVE-2026-64638-PoC-XSS2Shell-
https://github.com/yogaGymn/XSS2Shell-CVE-2026-64638
https://github.com/HORKimhab/CVE-2026-64638
https://github.com/0xBlackash/CVE-2026-64638
https://github.com/MR-LeonardoGomes/XSS2Shell-CVE-2026-64638
Dans la suite de wp2shell, encore une jolie chaîne WordPress : #XSS2Shell — CVE-2026-64638.
Au départ, on a “juste” une Reflected XSS pré-auth sur wp-login.php.
Sauf qu’en la chaînant avec plusieurs briques déjà présentes dans WordPress, on arrive à quelque chose de beaucoup moins sympa :
XSS → contexte admin → Application Password → REST API → upload de plugin → RCE 🐚
⚠️ À noter quand même : ce n’est pas du pre-auth zero-click.
Il faut qu’un admin déjà connecté clique sur un lien contrôlé par l’attaquant.
Encore un bon rappel : une “simple XSS” peut devenir franchement méchante une fois mise dans la bonne chaîne.
🩹 Corrigé dans WordPress 7.0.3.
👇
https://wordpress.org/news/2026/08/wordpress-7-0-3-release/
En cas de doute sur une exploitation passée : petit coup d’œil aux Application Passwords, aux plugins récemment ajoutés et aux fichiers PHP inhabituels.
"XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)"
👇
https://pwn.ai/blog/xss2shell
Another one of those WordPress pre-auth RCEs
This one's named XSS2Shell, CVE-2026-64638, found with AI, patched in v7.0.3, released on Thursday
##Dans la suite de wp2shell, encore une jolie chaîne WordPress : #XSS2Shell — CVE-2026-64638.
Au départ, on a “juste” une Reflected XSS pré-auth sur wp-login.php.
Sauf qu’en la chaînant avec plusieurs briques déjà présentes dans WordPress, on arrive à quelque chose de beaucoup moins sympa :
XSS → contexte admin → Application Password → REST API → upload de plugin → RCE 🐚
⚠️ À noter quand même : ce n’est pas du pre-auth zero-click.
Il faut qu’un admin déjà connecté clique sur un lien contrôlé par l’attaquant.
Encore un bon rappel : une “simple XSS” peut devenir franchement méchante une fois mise dans la bonne chaîne.
🩹 Corrigé dans WordPress 7.0.3.
👇
https://wordpress.org/news/2026/08/wordpress-7-0-3-release/
En cas de doute sur une exploitation passée : petit coup d’œil aux Application Passwords, aux plugins récemment ajoutés et aux fichiers PHP inhabituels.
"XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)"
👇
https://pwn.ai/blog/xss2shell
Another one of those WordPress pre-auth RCEs
This one's named XSS2Shell, CVE-2026-64638, found with AI, patched in v7.0.3, released on Thursday
##🚨 XSS2shell (CVE-2026-64638) has been identified as a notable vulnerability.
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim.
This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.
Discovered and responsibly disclosed by the team at pwn.ai.
ℹ️ Additional details on ZEN SecDB https://secdb.nttzen.cloud/updates/267dffcb-04e8-4ba6-9c9e-2305d1d11b59/xss2shell-vulnerability
#infosec #xss2shell #wordpress #xss #rce
#nttdata #zen #secdb
WordPress RCE. Every version ever released (except the latest, 7.0.3). 500+ million sites. 43% of the Internet-facing sites. Hacker's paradise.
"XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)":
##「WordPressの事前認証における新たなXSS脆弱性によりPHPコードの実行につながる可能性あり - 早急に修正を! 」: #TheHackerNews
「WordPressは、ログイン画面に存在する、認証前のリフレクテッドクロスサイトスクリプティング(XSS)の脆弱性を修正しました。この脆弱性は、コンテンツ管理システムのすべてのバージョンに影響を与えます。pwn.aiは、ログインした管理者が攻撃者によって制御されたページを操作する際に、この脆弱性がサーバー上でPHPコードの実行に連鎖的に繋がる仕組みを実証しました。
CVE-2026-64638 (CVSSスコア:8.9)として追跡されている この深刻な脆弱性は、攻撃者に特別な権限を必要としません。 」
https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html
##"XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)"
https://pwn.ai/blog/xss2shell
🚨 WordPress patches XSS2Shell flaw that could lead to server code execution
CVE-2026-64638 is a CVSS 8.9 pre-authentication XSS vulnerability in the WordPress login screen.
The XSS itself requires no account. Researchers at pwn.ai demonstrated how it can be chained against a logged-in administrator to reach PHP code execution after social engineering the admin into interacting with an attacker-controlled page.
A successful chain could potentially allow attackers to:
• Create API credentials
• Gain authenticated REST access
• Upload malicious plugin files
• Execute PHP on the server
• Access WordPress secrets and database credentials
WordPress 7.0.3 fixes the flaw, with patches backported through the 4.7 branch.
NHS England says exploitation is likely following the release of technical details and a PoC.
WordPress has not reported confirmed exploitation in the wild as of August 7.
Update immediately.
##updated 2026-08-07T19:17:41.360000
1 posts
🟠 CVE-2026-20346 - High (7.5)
A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device.
This vulnerability ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20346/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T19:17:37.053000
1 posts
🟠 CVE-2026-16262 - High (7.5)
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16262/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T19:17:36.110000
1 posts
🔴 CVE-2026-16038 - Critical (9.1)
The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order ful...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16038/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T19:17:35.543000
1 posts
🟠 CVE-2026-15361 - High (8.1)
The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscrib...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15361/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T19:06:49.530000
1 posts
🔴 CVE-2026-59118 - Critical (9.3)
Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59118/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:32:49
2 posts
🟠 CVE-2026-16030 - High (8.1)
The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16030/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##MStore API WordPress plugin (<4.21.0) hit by CRITICAL vuln (CVE-2026-16030): improper phone token checks enable account takeover, incl. admins. Restrict endpoints & monitor logins until patched. https://radar.offseq.com/threat/cve-2026-16030-cwe-287-improper-authentication-in-mstore-api-799def1fc3890a44 #OffSeq #WordPress #CVE2026_16030 #Vuln
##updated 2026-08-07T18:32:49
1 posts
🟠 CVE-2026-71559 - High (7.5)
Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic.
This issue aff...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71559/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:32:48
2 posts
🔴 CVE-2026-67688 - Critical (9.8)
ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker to execute arbitrary code.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67688/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-67688 - Critical (9.8)
ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker to execute arbitrary code.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67688/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:32:48
2 posts
1 repos
https://github.com/qflksheep/CVE-2026-67687-ICS-Park-Smart-Park-Management-System-v2.0
🟠 CVE-2026-67687 - High (8.8)
Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleController.java and system/user/update endpoint in UserController.java
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67687/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67687 - High (8.8)
Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleController.java and system/user/update endpoint in UserController.java
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67687/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:32:48
2 posts
🟠 CVE-2026-70634 - High (8.1)
TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compression/algorithms/dictionary.c). The forward path validates the decoded index; the reverse path us...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70634/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-70634 - High (8.1)
TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compression/algorithms/dictionary.c). The forward path validates the decoded index; the reverse path us...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70634/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:32:48
1 posts
🟠 CVE-2026-14943 - High (7.5)
The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API access to authenticated users when a specific option is enabled, allowing unauthenticated visitors ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14943/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:32:48
1 posts
🔴 CVE-2026-14205 - Critical (9.8)
The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed book...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14205/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:31:57
2 posts
🔴 CVE-2026-64637 - Critical (9.9)
Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64637/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-64637 (CRITICAL, CVSS 9.9): WebPros Plesk <18.0.80 allows authenticated resellers to escalate privileges to root via XML-RPC API. Patch not confirmed — restrict access, monitor API use. https://radar.offseq.com/threat/cve-2026-64637-cwe-269-improper-privilege-management-in-webpros-plesk-ea44a21d820141d3 #OffSeq #Plesk #Vuln #PrivilegeEscalation
##updated 2026-08-07T18:31:54
2 posts
🟠 CVE-2026-20339 - High (7.5)
A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device.
This vulnerabili...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20339/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CISA has added one vulnerability to the KEV catalogue:
CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-8037 #CISA
Cisco:
NEW: CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26 #Cisco
Palo Alto:
CRITICAL, NEW: CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent https://security.paloaltonetworks.com/CVE-2026-0288
Microsoft:
Several updates for a slew of vulnerabilities were posted today on the Microsoft Update Guide: https://msrc.microsoft.com/update-guide/ #Microsoft
Google:
New: Chrome Dev for Android Update https://chromereleases.googleblog.com/ #Google #Chrome
Broadcom:
One new advisory for a high-severity vulnerability that was first published on July 23 https://support.broadcom.com/web/ecx/security-advisory
Posted yesterday:
Apple security updates https://support.apple.com/en-us/100100 #Apple
AMD: Safe RET Interrupt Vulnerability https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7061.html #AMD
Dell:
CRITICAL, last updated yesterday: Dell PowerMaxOS, Dell PowerMax EEM, Dell Unisphere for PowerMax, Dell Solutions Enabler Security Update for Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000483543/dsa-2026-272-dell-powermaxos-dell-powermax-eem-dell-unisphere-for-powermax-dell-unisphere-for-powermax-virtualappliance-dell-unisphere-360-dell-solutionsenabler-and-dell-solutionsenabler-virtualappliance-security-update-for-multiple-vulnerabilities #Dell #infosec #vulnerability #Java #SQL
##updated 2026-08-07T18:31:54
1 posts
🟠 CVE-2026-20348 - High (7.5)
A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device.
This vulnerability ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20348/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:31:54
1 posts
🟠 CVE-2026-20345 - High (7.5)
A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device.
This vulnerability ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20345/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:31:53
2 posts
🟠 CVE-2026-20338 - High (7.5)
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper memory handling when processing content in zip files durin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20338/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CISA has added one vulnerability to the KEV catalogue:
CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-8037 #CISA
Cisco:
NEW: CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26 #Cisco
Palo Alto:
CRITICAL, NEW: CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent https://security.paloaltonetworks.com/CVE-2026-0288
Microsoft:
Several updates for a slew of vulnerabilities were posted today on the Microsoft Update Guide: https://msrc.microsoft.com/update-guide/ #Microsoft
Google:
New: Chrome Dev for Android Update https://chromereleases.googleblog.com/ #Google #Chrome
Broadcom:
One new advisory for a high-severity vulnerability that was first published on July 23 https://support.broadcom.com/web/ecx/security-advisory
Posted yesterday:
Apple security updates https://support.apple.com/en-us/100100 #Apple
AMD: Safe RET Interrupt Vulnerability https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7061.html #AMD
Dell:
CRITICAL, last updated yesterday: Dell PowerMaxOS, Dell PowerMax EEM, Dell Unisphere for PowerMax, Dell Solutions Enabler Security Update for Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000483543/dsa-2026-272-dell-powermaxos-dell-powermax-eem-dell-unisphere-for-powermax-dell-unisphere-for-powermax-virtualappliance-dell-unisphere-360-dell-solutionsenabler-and-dell-solutionsenabler-virtualappliance-security-update-for-multiple-vulnerabilities #Dell #infosec #vulnerability #Java #SQL
##updated 2026-08-07T18:31:53
1 posts
🟠 CVE-2026-20347 - High (7.5)
A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device.
This vulnerabili...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20347/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:31:53
1 posts
🟠 CVE-2026-68772 - High (8)
ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by planting a malicious pickle file. Attackers can re...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68772/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:31:52
3 posts
CVE-2026-20337 - Memory corruption in ClamAV ZIP parsing, out-of-bounds write DoS. CVSS 7.5. Unpatched. Update or mitigate immediately. #CVE #Cisco #infosec
##🟠 CVE-2026-20337 - High (7.5)
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper boundary checks for content in zip files during scanning, ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20337/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CISA has added one vulnerability to the KEV catalogue:
CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-8037 #CISA
Cisco:
NEW: CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26 #Cisco
Palo Alto:
CRITICAL, NEW: CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent https://security.paloaltonetworks.com/CVE-2026-0288
Microsoft:
Several updates for a slew of vulnerabilities were posted today on the Microsoft Update Guide: https://msrc.microsoft.com/update-guide/ #Microsoft
Google:
New: Chrome Dev for Android Update https://chromereleases.googleblog.com/ #Google #Chrome
Broadcom:
One new advisory for a high-severity vulnerability that was first published on July 23 https://support.broadcom.com/web/ecx/security-advisory
Posted yesterday:
Apple security updates https://support.apple.com/en-us/100100 #Apple
AMD: Safe RET Interrupt Vulnerability https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7061.html #AMD
Dell:
CRITICAL, last updated yesterday: Dell PowerMaxOS, Dell PowerMax EEM, Dell Unisphere for PowerMax, Dell Solutions Enabler Security Update for Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000483543/dsa-2026-272-dell-powermaxos-dell-powermax-eem-dell-unisphere-for-powermax-dell-unisphere-for-powermax-virtualappliance-dell-unisphere-360-dell-solutionsenabler-and-dell-solutionsenabler-virtualappliance-security-update-for-multiple-vulnerabilities #Dell #infosec #vulnerability #Java #SQL
##updated 2026-08-07T18:31:42
2 posts
🟠 CVE-2026-67621 - High (7.6)
Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67621/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67621 - High (7.6)
Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67621/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:31:42
2 posts
🟠 CVE-2026-70628 - High (7.8)
FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70628/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-70628 - High (7.8)
FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70628/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:31:42
2 posts
🟠 CVE-2026-70632 - High (7.8)
FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stre...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70632/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-70632 - High (7.8)
FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stre...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70632/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:31:41
2 posts
🔴 CVE-2026-67622 - Critical (9.9)
Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67622/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-67622 - Critical (9.9)
Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67622/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:31:37
2 posts
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
updated 2026-08-07T18:26:08
2 posts
🟠 CVE-2026-67422 - High (7.5)
pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclink) use regular expressions whose content groups can partition a run...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67422/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67422 - High (7.5)
pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclink) use regular expressions whose content groups can partition a run...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67422/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:17:18.960000
2 posts
🔴 CVE-2026-53984 - Critical (9.1)
Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauthenticated network peer to wipe or replace the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53984/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-53984 - Critical (9.1)
Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauthenticated network peer to wipe or replace the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53984/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:17:14.827000
2 posts
🟠 CVE-2026-45198 - High (7.8)
Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause GPU Firmware to boot up using data from non-secure memory.
The GPU thread of control (Firmware) uses a pointer from non-secur...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45198/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-45198 - High (7.8)
Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause GPU Firmware to boot up using data from non-secure memory.
The GPU thread of control (Firmware) uses a pointer from non-secur...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45198/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:17:07.753000
2 posts
🔴 CVE-2026-14365 - Critical (9.8)
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perfo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14365/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-14365 - Critical (9.8)
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perfo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14365/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:11:23.330000
1 posts
If you missed these yesterday.
"Three of the issues, CVE-2026-63508, CVE-2026-56162, and CVE-2026-65667, have a maximum severity rating of 10/10."
Security Week: Microsoft, Apple Release Fresh Security Updates https://www.securityweek.com/microsoft-apple-release-fresh-security-updates/ #Microsoft #Apple #infosec #vylnerability #Apple
##updated 2026-08-07T18:05:55.493000
2 posts
🔴 CVE-2026-50515 - Critical (9.9)
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50515/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-50515 - Critical (9.9)
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50515/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T17:17:05.047000
2 posts
🟠 CVE-2026-5855 - High (7.5)
Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer length argument and reads up to six bytes from the input buffer with no bounds check. The caller in lwm2m-engine.c iterates while th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-5855/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-5855 - High (7.5)
Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer length argument and reads up to six bytes from the input buffer with no bounds check. The caller in lwm2m-engine.c iterates while th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-5855/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T16:17:28.807000
1 posts
🟠 CVE-2026-9169 - High (8.8)
DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by placing a malicious DLL in a user-controlled directory listed in the PATH en...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9169/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T16:17:25.673000
2 posts
🟠 CVE-2026-53983 - High (8.6)
Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital-source configuration path that allows any unauthenticated Socket.IO client to cause the ground-station process to issue outb...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53983/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-53983 - High (8.6)
Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital-source configuration path that allows any unauthenticated Socket.IO client to cause the ground-station process to issue outb...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53983/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T16:17:25.380000
1 posts
🟠 CVE-2026-49007 - High (7.5)
By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for the device's web interface.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49007/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T16:17:24.773000
2 posts
🔴 CVE-2026-48085 - Critical (9.8)
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provisioned OpenReception instance accepts unauthenticated POST requests to `/setup/create-admin-account` a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48085/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-48085 - Critical (9.8)
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provisioned OpenReception instance accepts unauthenticated POST requests to `/setup/create-admin-account` a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48085/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T15:34:17
2 posts
1 repos
https://github.com/qflksheep/CVE-2026-67689-FineAdmin.Mvc-vulnerability
🔴 CVE-2026-67689 - Critical (9.8)
SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated list endpoints
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67689/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-67689 - Critical (9.8)
SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated list endpoints
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67689/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T15:33:32
1 posts
1 repos
🔴 CVE-2026-19264 - Critical (9.8)
Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that directory, and t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19264/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T15:17:01.830000
1 posts
CVE-2026-54212: CRITICAL buffer overflow in Tobit TeamDavid Webbox API (≤ Rollout 524). Crafted JSON lets unauthenticated attackers crash servers; RCE possible if combined with other flaws. Restrict API, monitor activity. https://radar.offseq.com/threat/cve-2026-54212-cwe-787-out-of-bounds-write-in-tobit-laboratories-ag-teamdavid-2e946f5b4b7b0ab5 #OffSeq #CVE #bufferOverflow #infosec
##updated 2026-08-07T12:32:06
1 posts
🟠 CVE-2026-15816 - High (7.5)
A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH opt...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15816/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T12:32:06
1 posts
CVE-2026-54213: CRITICAL improper access control in Tobit TeamDavid Webbox — public /internalRestart endpoint lets remote attackers trigger persistent DoS by shutting down servers. No patch yet. Restrict access & monitor. https://radar.offseq.com/threat/cve-2026-54213-cwe-284-improper-access-control-in-tobit-laboratories-ag-teamdavid-7d00f2efd17d315b #OffSeq #Cybersecurity #Vuln
##updated 2026-08-07T12:32:00
1 posts
Tobit TeamDavid (Webbox ≤ Rollout 524) hit by CRITICAL buffer overflow (CVE-2026-54211). Authenticated attackers can crash servers; possible RCE if stack canary is disclosed. Restrict access & monitor. No patch yet. https://radar.offseq.com/threat/cve-2026-54211-cwe-787-out-of-bounds-write-in-tobit-laboratories-ag-teamdavid-dd683c887b0f0b7a #OffSeq #Vulnerability #InfoSec
##updated 2026-08-07T06:30:34
2 posts
🔴 CVE-2026-14364 - Critical (9.8)
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the plugin not properly validatin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14364/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-14364 - Critical (9.8)
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the plugin not properly validatin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14364/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T06:30:26
1 posts
🟠 CVE-2026-19191 - High (7.8)
A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code of the file C:\Program Files\StableBit\DrivePool\DrivePool.Service.exe of the component DrivePoolService. Such manipulation lead...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19191/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T06:30:25
2 posts
🟠 CVE-2026-19190 - High (7.8)
A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Files (x86)\StableBit\Scanner\Service\Scanner.Service.exe of the component ScannerService. This manipulation causes permission iss...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19190/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19190 - High (7.8)
A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Files (x86)\StableBit\Scanner\Service\Scanner.Service.exe of the component ScannerService. This manipulation causes permission iss...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19190/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T03:31:32
1 posts
Whoa, macOS Sequoia 15.7.9 changes:
> An attacker on the network may be able to authenticate to Screen Sharing without valid credentials
https://xcancel.com/calif_io/status/2086022794840793454
> If Screen Sharing is enabled, any network attacker can exploit the bug to log in as any account, without knowing the password.
Good thing it requires screen sharing to be enabled though.
CVE-2026-65400
##updated 2026-08-07T03:30:38
2 posts
🟠 CVE-2026-19189 - High (7.8)
A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functionality in the library C:\Windows\System32\drivers\scdemu.sys of the component Kernel Driver. The manipulation results in improper ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19189/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19189 - High (7.8)
A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functionality in the library C:\Windows\System32\drivers\scdemu.sys of the component Kernel Driver. The manipulation results in improper ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19189/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T00:31:33
2 posts
If you missed these yesterday.
"Three of the issues, CVE-2026-63508, CVE-2026-56162, and CVE-2026-65667, have a maximum severity rating of 10/10."
Security Week: Microsoft, Apple Release Fresh Security Updates https://www.securityweek.com/microsoft-apple-release-fresh-security-updates/ #Microsoft #Apple #infosec #vylnerability #Apple
##CVE-2026-63508 (CRITICAL, CVSS 10): Microsoft Planetary Computer Pro (GeoCatalog) suffers from missing authentication, enabling remote privilege escalation. Immediate patching recommended. Details: https://radar.offseq.com/threat/cve-2026-63508-cwe-306-missing-authentication-for-critical-function-in-microsoft-microsoft-planetary-431bf04580187f39 #OffSeq #Vuln #Microsoft #Infosec
##updated 2026-08-07T00:31:33
1 posts
CVE-2026-62873 (CRITICAL, CVSS 9.8) affects Microsoft 365 Admin Center: Improper cryptographic signature checks allow privilege escalation over the network. Microsoft has issued a fix — confirm your environment is patched. https://radar.offseq.com/threat/cve-2026-62873-cwe-347-improper-verification-of-cryptographic-signature-in-microsoft-microsoft-365-5fad3518811d36c2 #OffSeq #Microsoft365 #Vuln
##updated 2026-08-07T00:31:28
2 posts
🟠 CVE-2026-49163 - High (8.8)
Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49163/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-49163 - High (8.8)
Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49163/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T00:31:28
2 posts
🔴 CVE-2026-56161 - Critical (9.6)
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56161/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-56161 - Critical (9.6)
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56161/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T00:31:28
1 posts
🔴 CVE-2026-59115 - Critical (9.9)
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59115/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T00:31:27
2 posts
1 repos
🟠 CVE-2026-70559 - High (7.5)
Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation that short-circuits the class-level @SaCheckLogin, so the Sa-Token interceptor lets the request through with no session or role ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70559/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-70559 - High (7.5)
Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation that short-circuits the class-level @SaCheckLogin, so the Sa-Token interceptor lets the request through with no session or role ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70559/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T00:31:27
3 posts
🔴 CVE-2026-56162 - Critical (10)
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56162/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-56162 - Critical (10)
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56162/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##If you missed these yesterday.
"Three of the issues, CVE-2026-63508, CVE-2026-56162, and CVE-2026-65667, have a maximum severity rating of 10/10."
Security Week: Microsoft, Apple Release Fresh Security Updates https://www.securityweek.com/microsoft-apple-release-fresh-security-updates/ #Microsoft #Apple #infosec #vylnerability #Apple
##updated 2026-08-07T00:31:27
1 posts
🟠 CVE-2026-62836 - High (8.7)
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62836/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T21:12:27
1 posts
Vulnerability in ngx-extended-pdf-viewer (HIGH): Bundled pdf.js exposes XFA (enabled by default), risking JS execution via malicious PDFs (CVE-2026-16633). Update to 29.0.0-rc.3 or disable XFA for mitigation. https://radar.offseq.com/threat/ngx-extended-pdf-viewer-bundles-a-version-of-pdfjs-vulnerable-to-cve-2026-16633-3a7320cdbeb0cda3 #OffSeq #Vulnerability #PDF #Infosec
##updated 2026-08-06T19:25:06
2 posts
🟠 CVE-2026-64665 - High (8.1)
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an exist...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64665/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-64665 - High (8.1)
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an exist...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64665/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T15:32:48
2 posts
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
updated 2026-08-06T12:31:21
2 posts
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
updated 2026-08-06T12:31:21
2 posts
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
updated 2026-08-06T09:30:40
1 posts
WSO2 patched four critical account takeover flaws, including CVE-2026-5430 at CVSS 10 via JWT auth bypass. Details and fixes inside.
##updated 2026-08-06T00:36:25.360000
2 posts
🏆 New Achievement! Three Hundred and Seventy Reasons to Click Update!
Here, in its natural habitat, the unpatched browser clings stubbornly to an older Chrome build while the predator closes in. Google released Chrome 151 on July 28, 2026, correcting 370 vulnerabilities in a single migration — seven rated critical, spanning CVE-2026-17650 through CVE-2026-17656, with another 71 rated high severity. Naturalists observe this is among the largest single-release security drops of the year. (1/2)
##🏆 New Achievement! Three Hundred and Seventy Reasons to Click Update!
Here, in its natural habitat, the unpatched browser clings stubbornly to an older Chrome build while the predator closes in. Google released Chrome 151 on July 28, 2026, correcting 370 vulnerabilities in a single migration — seven rated critical, spanning CVE-2026-17650 through CVE-2026-17656, with another 71 rated high severity. Naturalists observe this is among the largest single-release security drops of the year. (1/2)
##updated 2026-08-06T00:30:24.850000
2 posts
🏆 New Achievement! Three Hundred and Seventy Reasons to Click Update!
Here, in its natural habitat, the unpatched browser clings stubbornly to an older Chrome build while the predator closes in. Google released Chrome 151 on July 28, 2026, correcting 370 vulnerabilities in a single migration — seven rated critical, spanning CVE-2026-17650 through CVE-2026-17656, with another 71 rated high severity. Naturalists observe this is among the largest single-release security drops of the year. (1/2)
##🏆 New Achievement! Three Hundred and Seventy Reasons to Click Update!
Here, in its natural habitat, the unpatched browser clings stubbornly to an older Chrome build while the predator closes in. Google released Chrome 151 on July 28, 2026, correcting 370 vulnerabilities in a single migration — seven rated critical, spanning CVE-2026-17650 through CVE-2026-17656, with another 71 rated high severity. Naturalists observe this is among the largest single-release security drops of the year. (1/2)
##updated 2026-08-05T18:32:31
2 posts
4 repos
https://github.com/sfewer-r7/CVE-2026-63077
https://github.com/unveiledhistory49/teamcity-cve-2026-63077-remediation
https://github.com/AnggaTechI/CVE-2026-63077
https://github.com/BoredHackerBlog/teamcity-CVE-2026-63077-pcap
CVE-2026-63077: TeamCity RCE Exploited in the Wild
##CVE-2026-63077: TeamCity RCE Exploited in the Wild
##updated 2026-08-05T15:32:14
2 posts
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
updated 2026-08-05T15:17:04.690000
1 posts
CVE-2026-66747: a Zbtlink router backdoor named ENDLESSDOORS gives unauthenticated remote code execution as root. No fix exists. CVSS 9.8.
#Zbtlink #RouterBackdoor #CVE #IoT #CyberSecurity
https://securityonline.info/zbtlink-router-backdoor/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-08-05T06:30:32
2 posts
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
updated 2026-08-05T06:30:31
2 posts
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
updated 2026-08-05T00:30:41
2 posts
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
updated 2026-08-04T21:30:25
1 posts
4 repos
https://github.com/rmhowe425/PoC-CVE-2026-9198
https://github.com/0xdak/CVE-2026-9198_exploit
🏆 New Achievement! Patch Notes From Hell!
Version 2026.08 changelog: ADDED — Chinese-speaking threat actor manually planting reverse shells on Apache Tomcat servers via CVE-2026-34486, itself an incomplete fix for the 9.8-rated CVE-2026-29146. ADDED — unauthenticated admin account hijacking on N-able's N-central via CVE-2026-18576. ADDED — critical 9.8-rated remote code execution at root on IBM Langflow via CVE-2026-9198. (1/2)
##updated 2026-08-04T18:31:36
1 posts
1 repos
Veeam ONE Patches Critical Remote Code Execution and SQL Injection Flaws
Veeam ONE version 13 contains six vulnerabilities, including a CVSS 10.0 critical remote code execution flaw and a high-severity SQL injection bug. These vulnerabilities allow unauthenticated attackers to take over agent hosts, read arbitrary files, and extract sensitive database information.
**If you run Veeam ONE version 13, update it to build 13.1.0.7034. One of these flaws (CVE-2026-64633) lets an attacker take over the system remotely without any login or clicks from you. While you're at it, make sure Veeam ONE is only reachable from your trusted admin network, not from the internet or the general user network.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/veeam-one-patches-critical-remote-code-execution-and-sql-injection-flaws-q-a-8-7-1/gD2P6Ple2L
updated 2026-08-04T15:33:20
1 posts
2 repos
https://github.com/CreamyG31337/ncentral-compromise-ioc-triage
⚠️ N-central auth bypass exploited in attacks
CVE-2026-18577 enables admin takeover; N-able issued an urgent hotfix.
🔗 read more: www.bleepingcomputer...
#ransomNews #cybersecurity
N-able warns of N-central auth...
updated 2026-08-04T13:18:02.797000
1 posts
🏆 New Achievement! Patch Notes From Hell!
Version 2026.08 changelog: ADDED — Chinese-speaking threat actor manually planting reverse shells on Apache Tomcat servers via CVE-2026-34486, itself an incomplete fix for the 9.8-rated CVE-2026-29146. ADDED — unauthenticated admin account hijacking on N-able's N-central via CVE-2026-18576. ADDED — critical 9.8-rated remote code execution at root on IBM Langflow via CVE-2026-9198. (1/2)
##updated 2026-08-04T05:16:30.980000
1 posts
2 repos
https://github.com/je5442804/WPTaskScheduler_CVE-2024-49039
https://github.com/razureink/cve-2024-49039-task_scheduler_eop_reproduction
[1/4]
Most impactful security incidents and vulnerabilities reported in the last ≈ 30 days (up to 2024‑09‑03)
1
• CVE‑2024‑49039
• Windows Task Scheduler (TaskScheduler service)
• Privilege‑escalation: a low‑privileged AppContainer can break out and invoke privileged RPC functions. CVSS ≈ 8.8; actively exploited by ransomware groups.
• All supported Windows 10/11 and Server 2019/2022 builds released before the 2024‑09‑03 patch.
• <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49039>
2
• CVE‑2024‑43451
• Microsoft Windows NTLMv2 authentication (hash handling)
• Remote attacker can force a file‑open that leaks the user’s NTLMv2 hash, enabling pass‑the‑hash attacks. CVSS ≈ 8.1; directly compromises credential confidentiality.
• All supported Windows 10/11 and Server editions up to build 22631 (pre‑2024‑09‑03).
• <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43451>
3
• CVE‑2024‑38193
• Windows Ancillary Function Driver for WinSock (AFD)
• Unspecified kernel flaw that grants SYSTEM privileges to a local attacker. CVSS ≈ 8.5; part of the “privilege‑escalation” wave in the networking stack.
• Windows 10 22H2, Windows 11 and Server 2022 before 2024‑09‑03.
• <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38193>
4
• CVE‑2024‑38178
• Windows Scripting Engine (JScript/VBScript)
• Memory‑corruption bug that enables remote code execution via a crafted URL, bypassing same‑origin protections. CVSS ≈ 8.6; network‑reachable RCE.
• All supported Windows 10/11 and Server releases prior to 2024‑09‑03.
• <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38178>
5
• CVE‑2024‑36971
• Android kernel (Linux)
• Remote‑code‑execution via use‑after‑free/heap overflow in the core OS. CVSS ≈ 9.0; affects billions of smartphones and can be weaponised by ransomware.
• Android 13 & 14 builds with kernel ≤ 5.15.112 before September 2024 patch.
• <https://nvd.nist.gov/vuln/detail/CVE-2024-36971>
updated 2026-08-04T00:35:01
2 posts
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
updated 2026-08-03T15:32:55
2 posts
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
updated 2026-08-01T09:30:23
1 posts
4 repos
https://github.com/suominen/ovswrap
https://github.com/HackSpeak/CVE-2026-64531
https://github.com/mahfuzreham/OVSwrap-CVE-2026-64531-Mitigation-Tool
🐧 SIGINT // Ubuntu Watch — 2026-08-10
CVE-2026-64531 hits hosts even if they never touch OVS, with a public PoC across ~800 builds. Local privesc to root on any container or VM host running the module means patch now, not next maintenance window.
🔗 https://thehackernews.com/2026/08/new-ovswrap-linux-kernel-flaw-lets.html
##updated 2026-07-30T18:31:47
1 posts
This post is from yesterday.
Note: Arctic Wolf will sell your data without consent. You need to scroll to the bottom and opt out of being sold to unscrupulous third-parties.
Arctic Wolf: SolarWinds Web Help Desk Vulnerabilities: CVE-2026-28323 and CVE-2026-28299 https://arcticwolf.com/resources/blog/cve-2026-28323-and-cve-2026-28299/ #infosec #vulnerability #privacy
##updated 2026-07-30T12:19:03.630000
3 posts
1 repos
🚨 Tails has released an emergency security update: Tails 7.10.1, patching critical flaws that could enable privilege escalation and potentially deanonymize users. It fixes CVE-2026-64560 (Linux kernel) and multiple Expat XML library issues. 🔐➡️ https://cyberinsider.com/tails-emergency-update-fixes-flaws-that-could-deanonymize-users/ #Tails #Tor #Cybersecurity #Privacy #SecurityUpdate
##Tails 7.10.1 patches CVE-2026-64560, a Linux kernel race condition letting a compromised Tor Browser gain root and deanonymize users via a malicious website.
#Tails #CVE202664560 #LinuxKernel #TorBrowser #Deanonymization #PrivilegeEscalation #AnonymityOS #TailsOS
##Tails 7.10.1 patches CVE-2026-64560 in the Linux kernel and expat library flaws that could let attackers deanonymize users and gain admin privileges.
#Tails #Linux #Privacy #CVE202664560 #Cybersecurity #AnonymousOS
##updated 2026-07-30T06:33:30
1 posts
For one, Rust is vibecoded now. There are Claude commits in it and probably more than GitHub is willing to tell me.
Two, users try to rewrite everything to Rust when there is no point. When Rust was no longer experimental in Linux it caused CVEs (CVE-2025-68260).
Three, Rust projects can take 10 seconds to compile or 20 minutes.
Four, it uses LLVM and that's bloated and vibecoded now.
Five, I generally just don't like it either. I prefer C and some other similar langs much more.
updated 2026-07-28T14:14:37.463000
1 posts
4 repos
https://github.com/Debajyoti0-0/CVE-2026-60206
https://github.com/tc4dy/CVE-2026-60206-PoC-Exploit
🔬 The best bytes of #science & #tech across the #fediverse
“Interesting Git repos of the week:Detection:* github․com/Yamato-Security/WELA - improve your Windows loggingBugs:* github․com/timb-machine-mirrors/imbas007-POC-CVE-2026-60206 - popping WebLogic via SAMLExploitat…”
https://infosec.exchange/@timb_machine/117060183912935232
🤖 via RSS feed. Not an endorsement.
##updated 2026-07-28T05:17:04.113000
1 posts
Hackers bypass patch using new FortiOS vulnerability
An actively exploited #vulnerability in #FortiOS allows for the bypass of a previous protection mechanism against manipulated symbolic links. Affected systems should be updated and checked for prior compromise.
Sensitive information on potentially compromised #FortiGate systems running FortiOS with SSL-VPN enabled may be at risk.
##updated 2026-07-24T21:32:15
1 posts
@da_667 oh the number of times my sleep deprived brain tried to understand how the text in front of me relates to the CVE I thought to analyse *UNTIL I FIGURED THE SEARCH RESULTS WERE BORKED AND CVE-2026-60667 IS IN FACT NOT THE CVE I WAS ORIGINALLY LOOKING FOR* gave me serious PTSD.
Relieved to see I'm not the dumbo after all.
##updated 2026-07-23T14:17:59.510000
1 posts
updated 2026-07-14T18:31:58
1 posts
@adamshostack @gsuberland the main vulnerability is CVE-2026-34348. As I understood, a signature of sign-in is stored in event log, which can be replayed and used for impersonation, as there is no validation of reused signatures in Entra ID.
##updated 2026-07-10T15:45:17.463000
1 posts
CISA has added one vulnerability to the KEV catalogue:
CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-8037 #CISA
Cisco:
NEW: CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26 #Cisco
Palo Alto:
CRITICAL, NEW: CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent https://security.paloaltonetworks.com/CVE-2026-0288
Microsoft:
Several updates for a slew of vulnerabilities were posted today on the Microsoft Update Guide: https://msrc.microsoft.com/update-guide/ #Microsoft
Google:
New: Chrome Dev for Android Update https://chromereleases.googleblog.com/ #Google #Chrome
Broadcom:
One new advisory for a high-severity vulnerability that was first published on July 23 https://support.broadcom.com/web/ecx/security-advisory
Posted yesterday:
Apple security updates https://support.apple.com/en-us/100100 #Apple
AMD: Safe RET Interrupt Vulnerability https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7061.html #AMD
Dell:
CRITICAL, last updated yesterday: Dell PowerMaxOS, Dell PowerMax EEM, Dell Unisphere for PowerMax, Dell Solutions Enabler Security Update for Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000483543/dsa-2026-272-dell-powermaxos-dell-powermax-eem-dell-unisphere-for-powermax-dell-unisphere-for-powermax-virtualappliance-dell-unisphere-360-dell-solutionsenabler-and-dell-solutionsenabler-virtualappliance-security-update-for-multiple-vulnerabilities #Dell #infosec #vulnerability #Java #SQL
##updated 2026-06-17T10:06:17.243000
1 posts
31 repos
https://github.com/nuky-alt/CVE-2025-8088
https://github.com/pentestfunctions/CVE-2025-8088-Multi-Document
https://github.com/sxyrxyy/CVE-2025-8088-WinRAR-Proof-of-Concept-PoC-Exploit-
https://github.com/pentestfunctions/best-CVE-2025-8088
https://github.com/walidpyh/CVE-2025-8088
https://github.com/nhattanhh/CVE-2025-8088
https://github.com/jordan922/CVE-2025-8088
https://github.com/AdityaBhatt3010/CVE-2025-8088-WinRAR-Zero-Day-Path-Traversal
https://github.com/Lewis-Ricardo/Amaranth-Project
https://github.com/lennertdefauw/CVE-2025-8088
https://github.com/travisbgreen/cve-2025-8088
https://github.com/papcaii2004/CVE-2025-8088-WinRAR-builder
https://github.com/IsmaelCosma/CVE-2025-8088
https://github.com/pexlexity/WinRAR-CVE-2025-8088-Path-Traversal-PoC
https://github.com/ghostn4444/CVE-2025-8088
https://github.com/hexsecteam/CVE-2025-8088-Winrar-Tool
https://github.com/Syrins/CVE-2025-8088-Winrar-Tool-Gui
https://github.com/Shinkirou789/Cve-2025-8088-WinRar-vulnerability
https://github.com/xi0onamdev/WinRAR-CVE-2025-8088-Exploitation-Toolkit
https://github.com/aldisakti2/CVE-2025-8088-BUILDER-Winrar-Tool
https://github.com/techcorp/CVE-2025-8088-Exploit
https://github.com/undefined-name12/CVE-2025-8088-Winrar
https://github.com/ilhamrzr/RAR-Anomaly-Inspector
https://github.com/pescada-dev/-CVE-2025-8088
https://github.com/kitsuneshade/WinRAR-Exploit-Tool---Rust-Edition
https://github.com/starfallreverie/winrar-exploit
https://github.com/onlytoxi/CVE-2025-8088-Winrar-Tool
https://github.com/shaheeryasirofficial/CVE-2025-8088
https://github.com/0xAbolfazl/CVE-2025-8088-WinRAR-PathTraversal-PoC
CVE-2025-8088 - Changed to Known Ransomware Status
RARLAB WinRAR Path Traversal VulnerabilityVendor: RARLABProduct: WinRARRARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 06, 2026 at 14:08:17 UTCDate https://nvd.nist.gov/vuln/detail/CVE-2025-8088
##updated 2026-06-17T07:51:04.273000
1 posts
2 repos
https://github.com/RonF98/CVE-2024-43451-POC
https://github.com/razureink/cve-2024-43451-ntlm_hash_disclosure_reproduction
[1/4]
Most impactful security incidents and vulnerabilities reported in the last ≈ 30 days (up to 2024‑09‑03)
1
• CVE‑2024‑49039
• Windows Task Scheduler (TaskScheduler service)
• Privilege‑escalation: a low‑privileged AppContainer can break out and invoke privileged RPC functions. CVSS ≈ 8.8; actively exploited by ransomware groups.
• All supported Windows 10/11 and Server 2019/2022 builds released before the 2024‑09‑03 patch.
• <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49039>
2
• CVE‑2024‑43451
• Microsoft Windows NTLMv2 authentication (hash handling)
• Remote attacker can force a file‑open that leaks the user’s NTLMv2 hash, enabling pass‑the‑hash attacks. CVSS ≈ 8.1; directly compromises credential confidentiality.
• All supported Windows 10/11 and Server editions up to build 22631 (pre‑2024‑09‑03).
• <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43451>
3
• CVE‑2024‑38193
• Windows Ancillary Function Driver for WinSock (AFD)
• Unspecified kernel flaw that grants SYSTEM privileges to a local attacker. CVSS ≈ 8.5; part of the “privilege‑escalation” wave in the networking stack.
• Windows 10 22H2, Windows 11 and Server 2022 before 2024‑09‑03.
• <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38193>
4
• CVE‑2024‑38178
• Windows Scripting Engine (JScript/VBScript)
• Memory‑corruption bug that enables remote code execution via a crafted URL, bypassing same‑origin protections. CVSS ≈ 8.6; network‑reachable RCE.
• All supported Windows 10/11 and Server releases prior to 2024‑09‑03.
• <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38178>
5
• CVE‑2024‑36971
• Android kernel (Linux)
• Remote‑code‑execution via use‑after‑free/heap overflow in the core OS. CVSS ≈ 9.0; affects billions of smartphones and can be weaponised by ransomware.
• Android 13 & 14 builds with kernel ≤ 5.15.112 before September 2024 patch.
• <https://nvd.nist.gov/vuln/detail/CVE-2024-36971>
updated 2026-06-17T07:39:39.247000
1 posts
1 repos
[1/4]
Most impactful security incidents and vulnerabilities reported in the last ≈ 30 days (up to 2024‑09‑03)
1
• CVE‑2024‑49039
• Windows Task Scheduler (TaskScheduler service)
• Privilege‑escalation: a low‑privileged AppContainer can break out and invoke privileged RPC functions. CVSS ≈ 8.8; actively exploited by ransomware groups.
• All supported Windows 10/11 and Server 2019/2022 builds released before the 2024‑09‑03 patch.
• <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49039>
2
• CVE‑2024‑43451
• Microsoft Windows NTLMv2 authentication (hash handling)
• Remote attacker can force a file‑open that leaks the user’s NTLMv2 hash, enabling pass‑the‑hash attacks. CVSS ≈ 8.1; directly compromises credential confidentiality.
• All supported Windows 10/11 and Server editions up to build 22631 (pre‑2024‑09‑03).
• <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43451>
3
• CVE‑2024‑38193
• Windows Ancillary Function Driver for WinSock (AFD)
• Unspecified kernel flaw that grants SYSTEM privileges to a local attacker. CVSS ≈ 8.5; part of the “privilege‑escalation” wave in the networking stack.
• Windows 10 22H2, Windows 11 and Server 2022 before 2024‑09‑03.
• <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38193>
4
• CVE‑2024‑38178
• Windows Scripting Engine (JScript/VBScript)
• Memory‑corruption bug that enables remote code execution via a crafted URL, bypassing same‑origin protections. CVSS ≈ 8.6; network‑reachable RCE.
• All supported Windows 10/11 and Server releases prior to 2024‑09‑03.
• <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38178>
5
• CVE‑2024‑36971
• Android kernel (Linux)
• Remote‑code‑execution via use‑after‑free/heap overflow in the core OS. CVSS ≈ 9.0; affects billions of smartphones and can be weaponised by ransomware.
• Android 13 & 14 builds with kernel ≤ 5.15.112 before September 2024 patch.
• <https://nvd.nist.gov/vuln/detail/CVE-2024-36971>
updated 2026-06-17T07:39:37.397000
1 posts
[1/4]
Most impactful security incidents and vulnerabilities reported in the last ≈ 30 days (up to 2024‑09‑03)
1
• CVE‑2024‑49039
• Windows Task Scheduler (TaskScheduler service)
• Privilege‑escalation: a low‑privileged AppContainer can break out and invoke privileged RPC functions. CVSS ≈ 8.8; actively exploited by ransomware groups.
• All supported Windows 10/11 and Server 2019/2022 builds released before the 2024‑09‑03 patch.
• <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49039>
2
• CVE‑2024‑43451
• Microsoft Windows NTLMv2 authentication (hash handling)
• Remote attacker can force a file‑open that leaks the user’s NTLMv2 hash, enabling pass‑the‑hash attacks. CVSS ≈ 8.1; directly compromises credential confidentiality.
• All supported Windows 10/11 and Server editions up to build 22631 (pre‑2024‑09‑03).
• <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43451>
3
• CVE‑2024‑38193
• Windows Ancillary Function Driver for WinSock (AFD)
• Unspecified kernel flaw that grants SYSTEM privileges to a local attacker. CVSS ≈ 8.5; part of the “privilege‑escalation” wave in the networking stack.
• Windows 10 22H2, Windows 11 and Server 2022 before 2024‑09‑03.
• <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38193>
4
• CVE‑2024‑38178
• Windows Scripting Engine (JScript/VBScript)
• Memory‑corruption bug that enables remote code execution via a crafted URL, bypassing same‑origin protections. CVSS ≈ 8.6; network‑reachable RCE.
• All supported Windows 10/11 and Server releases prior to 2024‑09‑03.
• <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38178>
5
• CVE‑2024‑36971
• Android kernel (Linux)
• Remote‑code‑execution via use‑after‑free/heap overflow in the core OS. CVSS ≈ 9.0; affects billions of smartphones and can be weaponised by ransomware.
• Android 13 & 14 builds with kernel ≤ 5.15.112 before September 2024 patch.
• <https://nvd.nist.gov/vuln/detail/CVE-2024-36971>
updated 2026-06-17T07:37:30.630000
1 posts
1 repos
[1/4]
Most impactful security incidents and vulnerabilities reported in the last ≈ 30 days (up to 2024‑09‑03)
1
• CVE‑2024‑49039
• Windows Task Scheduler (TaskScheduler service)
• Privilege‑escalation: a low‑privileged AppContainer can break out and invoke privileged RPC functions. CVSS ≈ 8.8; actively exploited by ransomware groups.
• All supported Windows 10/11 and Server 2019/2022 builds released before the 2024‑09‑03 patch.
• <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49039>
2
• CVE‑2024‑43451
• Microsoft Windows NTLMv2 authentication (hash handling)
• Remote attacker can force a file‑open that leaks the user’s NTLMv2 hash, enabling pass‑the‑hash attacks. CVSS ≈ 8.1; directly compromises credential confidentiality.
• All supported Windows 10/11 and Server editions up to build 22631 (pre‑2024‑09‑03).
• <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43451>
3
• CVE‑2024‑38193
• Windows Ancillary Function Driver for WinSock (AFD)
• Unspecified kernel flaw that grants SYSTEM privileges to a local attacker. CVSS ≈ 8.5; part of the “privilege‑escalation” wave in the networking stack.
• Windows 10 22H2, Windows 11 and Server 2022 before 2024‑09‑03.
• <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38193>
4
• CVE‑2024‑38178
• Windows Scripting Engine (JScript/VBScript)
• Memory‑corruption bug that enables remote code execution via a crafted URL, bypassing same‑origin protections. CVSS ≈ 8.6; network‑reachable RCE.
• All supported Windows 10/11 and Server releases prior to 2024‑09‑03.
• <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38178>
5
• CVE‑2024‑36971
• Android kernel (Linux)
• Remote‑code‑execution via use‑after‑free/heap overflow in the core OS. CVSS ≈ 9.0; affects billions of smartphones and can be weaponised by ransomware.
• Android 13 & 14 builds with kernel ≤ 5.15.112 before September 2024 patch.
• <https://nvd.nist.gov/vuln/detail/CVE-2024-36971>
updated 2026-06-09T18:40:45
1 posts
🟠 CVE-2026-52880 - High (7.5)
Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely triggerable denial of service. Both REST APIs are started with the Gin Engine.Run convenience method, which serv...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52880/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-06-09T18:40:42
1 posts
🟠 CVE-2026-52879 - High (7.5)
Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-message ingress handler spawns a new goroutine for every incoming direct message before the processor-level antiflood layer makes a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52879/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-06-08T23:28:56
1 posts
6 repos
https://github.com/404-src/CVE-2026-34486
https://github.com/anonmrc/CVE-2026-34486-e-Tomcat-Tribes
https://github.com/razureink/cve-2026-34486-tomcat_encrypt_bypass_reproduction
https://github.com/AirSkye/CVE-2026-34486-poc
🏆 New Achievement! Patch Notes From Hell!
Version 2026.08 changelog: ADDED — Chinese-speaking threat actor manually planting reverse shells on Apache Tomcat servers via CVE-2026-34486, itself an incomplete fix for the 9.8-rated CVE-2026-29146. ADDED — unauthenticated admin account hijacking on N-able's N-central via CVE-2026-18576. ADDED — critical 9.8-rated remote code execution at root on IBM Langflow via CVE-2026-9198. (1/2)
##updated 2026-06-05T15:27:42
1 posts
🟠 CVE-2026-47249 - High (7.5)
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling logic is vulnerable to hash-array amplification. A connected peer can send a compressed RequestDataType_HashArrayType direct r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47249/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-06-02T21:30:50
1 posts
This post is from yesterday.
Note: Arctic Wolf will sell your data without consent. You need to scroll to the bottom and opt out of being sold to unscrupulous third-parties.
Arctic Wolf: SolarWinds Web Help Desk Vulnerabilities: CVE-2026-28323 and CVE-2026-28299 https://arcticwolf.com/resources/blog/cve-2026-28323-and-cve-2026-28299/ #infosec #vulnerability #privacy
##updated 2026-05-18T18:31:37
1 posts
1 repos
Beyond Prompt Injection: Hacking Apple's Private Cloud Compute
Sentry Applied Research Center 연구자가 Apple Private Cloud Compute(PCC)의 부팅 프로세스 `darwin-init`에서 발생하는 경로 순회 취약점 CVE-2026-20685를 공개했다. 악성 tar 기반 cryptex의 엔트리 경로를 검증 없이 추출하는 문제로, 공격자는 PCC 노드의 영속 데이터 볼륨(`/var/db`)에 root 권한으로 파일을 쓸 수 있다. 연구 환경(VRE)에서 공격자는 이 쓰기 권한을 이용해 `splunkloggingd` 설정을 변조하...
https://blog.sentry.security/beyond-prompt-injection-hacking-apples-private-cloud-compute/
##updated 2026-04-27T16:19:05
1 posts
1 repos
Vuln critica (CVSS 10.0) a Paperclip, orquestracio d'agents d'IA
CVE-2026-41679: RCE via bypass d'autenticacio. Registrar-se sense verificar email, aconseguir token d'API persistent, i importar un .paperclip.yaml malicios que executa comandes al servidor
Tambe afecta el mode local_trusted: DNS rebinding des del navegador executa comandes al PC del dev.
Actualitza ja.
https://blog.elhacker.net/2026/08/vulnerabilidades-criticas-de-paperclip.html
##updated 2025-10-22T00:34:06
1 posts
14 repos
https://github.com/verylazytech/CVE-2024-23692
https://github.com/jakabakos/CVE-2024-23692-RCE-in-Rejetto-HFS
https://github.com/vanboomqi/CVE-2024-23692
https://github.com/pradeepboo/Rejetto-HFS-2.x-RCE-CVE-2024-23692
https://github.com/WanLiChangChengWanLiChang/CVE-2024-23692-RCE
https://github.com/NingXin2002/HFS2.3_poc
https://github.com/Mr-r00t11/CVE-2024-23692
https://github.com/999gawkboyy/CVE-2024-23692_Exploit
https://github.com/0x20c/CVE-2024-23692-EXP
https://github.com/sandimfz/CVE-2024-23692
https://github.com/Tupler/CVE-2024-23692-exp
https://github.com/wgetnz/hfs2
CVE-2024-23692 - Changed to Known Ransomware Status
Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine VulnerabilityVendor: RejettoProduct: HTTP File ServerRejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted https://nvd.nist.gov/vuln/detail/CVE-2024-23692
##updated 2025-10-22T00:33:19
1 posts
1 repos
https://github.com/Onapsis/Onapsis-Mandiant-CVE-2025-31324-Vuln-Compromise-Assessment
CVE-2025-42999 - Changed to Known Ransomware Status
SAP NetWeaver Deserialization VulnerabilityVendor: SAPProduct: NetWeaverSAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host system by deserializing untrusted or malicious content.Status changed from Unknown to Known for ransomware campaign https://nvd.nist.gov/vuln/detail/CVE-2025-42999
##updated 2025-10-14T19:17:03
1 posts
This bothers me.
Nx v1 was released in 2018, yet https://nx.dev/blog/cve-2025-36852-critical-cache-poisoning-vulnerability-creep (CREEP) was only discovered in 2025 (and is, disingenuously, described as a "race condition", which it is not - it's just inappropriate use of shared resources without trust boundaries).
##updated 2023-11-18T05:04:48
1 posts
3 repos
https://github.com/azpema/CVE-2021-26708
⚪️ Four Bytes of Power: How I Found the CVE-2021-26708 Vulnerability in the Linux Kernel
🗨️ In January 2021, I discovered and fixed five vulnerabilities in the Linux kernel’s virtual socket (vsock) implementation, collectively tracked as CVE-2021-26708. In this article, I will show how they can be used to compromise the entire operating system while bypassing the platform’s security mec…
##updated 2023-01-27T05:08:18
1 posts
The paper has a table listing the patches they're inaccurately claiming are missing in GrapheneOS. They claim the ones marked as green were manually verified to be missing. The first patch listed in the table is CVE-2015-6609, which we reported to Google in 2015.
https://source.android.com/docs/security/bulletin/2015-11-01#acknowledgements
##🟠 CVE-2026-63637 - High (8.6)
Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.go passes regexp filter strings into generated DQL without quoting or validating the /pattern/flags form, allowing crafted Grap...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63637/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-63637 - High (8.6)
Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.go passes regexp filter strings into generated DQL without quoting or validating the /pattern/flags form, allowing crafted Grap...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63637/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-62296 - DoS in HAPI FHIR via deeply nested XHTML. Unbounded recursion crashes parser threads. CVSS 7.5. Fixed in 6.9.11. Update now. #CVE #HAPI #infosec
##🟠 CVE-2026-62296 - High (7.5)
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, XhtmlParser.java imposes no maximum element nesting depth, so a deeply nested text.div narrative triggers unbounded recursion...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62296/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##1 posts
8 repos
https://github.com/Sachinart/CVE-2026-60004-gitea-0day
https://github.com/HORKimhab/CVE-2026-60004
https://github.com/EQSTLab/CVE-2026-60004
https://github.com/gagaltotal/CVE-2026-60004-poc-gitea
https://github.com/shinthink/CVE-2026-60004
https://github.com/0xBlackash/CVE-2026-60004
Welp. My Forgejo instance got popped by CVE-2026-60004. Hooray for RCE 🙃
My two screw-ups were
1. I pinned it to v13 "for stability" forever ago, then forgot about it.
2. I accidentally left sign-ups enabled.
Grabbed the seemingly obfuscated payload script from the attacker's server. Looks like it hits a different IP and grabs one of three different binaries depending on the victim's CPU architecture. You best believe I'm grabbing those too
Will probably write a blog post on what I find, but I'll at least post updates here, too
##🟠 CVE-2026-48097 - High (7.8)
NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 have a command execution vulnerability due to unsafe use of `shell=True` with commands that rely on executa...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48097/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-65819 - High (7.5)
gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-controlled lengths, counts, or offsets before validating them against packet buffers, allowing a crafted packet decoded through De...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65819/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-48026 - High (8.7)
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI renders markdown files from repository objects withou...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48026/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-48120 - High (8.6)
Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell commands being executed by simply opening a file. Ka...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48120/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-62295 - High (7.5)
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in org.hl7.fhir.utilities.json.parser.JsonParser enforces no maximum nesting depth for arrays or obje...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62295/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-61808 - Critical (9.8)
LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an unauthenticated network attacker to read indexed ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61808/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🚨 [CISA-2026:0807] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-8037 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8037)
- Name: Progress LoadMaster Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Progress
- Product: LoadMaster
- Notes: https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8037
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260807 #cisa20260807 #cve_2026_8037 #cve20268037
##three critical (9.1) advisories for wazuh i reported were published today. same trust assumption broken in three places: the cluster fernet key authenticates membership, and the cluster protocol then lets that peer pick filesystem paths.
CVE-2026-49441: the peer-supplied metadata key in process_files_from_worker is used directly as the destination path. write etc/ossec.conf, root rce via wazuh-logcollector.
CVE-2026-48024: same function, merged-file branch. traversal in the merged header name and in merge_type.
CVE-2026-48162: the DAPI tmp_file field is joined to WAZUH_PATH with os.path.join and shipped back to the peer. absolute paths win, so it reads anything the wazuh user can open. grab private_key.pem, forge ES512 admin jwts offline. survives cluster key rotation, since the jwt keypair is a different scope.
patched in 4.14.6.
https://github.com/wazuh/wazuh/security/advisories/GHSA-3v57-hgvj-3vj2
https://github.com/wazuh/wazuh/security/advisories/GHSA-gh4h-fx78-q8xc
https://github.com/wazuh/wazuh/security/advisories/GHSA-r6f5-h662-8ffc
#Wazuh #InfoSec #CVE #SIEM #ResponsibleDisclosure #CyberSecurity
##three critical (9.1) advisories for wazuh i reported were published today. same trust assumption broken in three places: the cluster fernet key authenticates membership, and the cluster protocol then lets that peer pick filesystem paths.
CVE-2026-49441: the peer-supplied metadata key in process_files_from_worker is used directly as the destination path. write etc/ossec.conf, root rce via wazuh-logcollector.
CVE-2026-48024: same function, merged-file branch. traversal in the merged header name and in merge_type.
CVE-2026-48162: the DAPI tmp_file field is joined to WAZUH_PATH with os.path.join and shipped back to the peer. absolute paths win, so it reads anything the wazuh user can open. grab private_key.pem, forge ES512 admin jwts offline. survives cluster key rotation, since the jwt keypair is a different scope.
patched in 4.14.6.
https://github.com/wazuh/wazuh/security/advisories/GHSA-3v57-hgvj-3vj2
https://github.com/wazuh/wazuh/security/advisories/GHSA-gh4h-fx78-q8xc
https://github.com/wazuh/wazuh/security/advisories/GHSA-r6f5-h662-8ffc
#Wazuh #InfoSec #CVE #SIEM #ResponsibleDisclosure #CyberSecurity
##three critical (9.1) advisories for wazuh i reported were published today. same trust assumption broken in three places: the cluster fernet key authenticates membership, and the cluster protocol then lets that peer pick filesystem paths.
CVE-2026-49441: the peer-supplied metadata key in process_files_from_worker is used directly as the destination path. write etc/ossec.conf, root rce via wazuh-logcollector.
CVE-2026-48024: same function, merged-file branch. traversal in the merged header name and in merge_type.
CVE-2026-48162: the DAPI tmp_file field is joined to WAZUH_PATH with os.path.join and shipped back to the peer. absolute paths win, so it reads anything the wazuh user can open. grab private_key.pem, forge ES512 admin jwts offline. survives cluster key rotation, since the jwt keypair is a different scope.
patched in 4.14.6.
https://github.com/wazuh/wazuh/security/advisories/GHSA-3v57-hgvj-3vj2
https://github.com/wazuh/wazuh/security/advisories/GHSA-gh4h-fx78-q8xc
https://github.com/wazuh/wazuh/security/advisories/GHSA-r6f5-h662-8ffc
#Wazuh #InfoSec #CVE #SIEM #ResponsibleDisclosure #CyberSecurity
##🏆 New Achievement! Patch Notes From Hell!
Version 2026.08 changelog: ADDED — Chinese-speaking threat actor manually planting reverse shells on Apache Tomcat servers via CVE-2026-34486, itself an incomplete fix for the 9.8-rated CVE-2026-29146. ADDED — unauthenticated admin account hijacking on N-able's N-central via CVE-2026-18576. ADDED — critical 9.8-rated remote code execution at root on IBM Langflow via CVE-2026-9198. (1/2)
##