## Updated at UTC 2026-10-09T17:25:06.159921

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-105281 7.5 0.00% 2 0 2026-10-09T16:41:53.540000 The internal data publisher on openPDC accepts network connections without authe
CVE-2026-100730 9.8 0.00% 2 0 2026-10-09T16:41:53.540000 A service console interface on openPDC and openHistorian deserializes a client-s
CVE-2026-107806 0 0.00% 2 0 2026-10-09T16:38:57.820000 Nginx UI is a web user interface for the Nginx web server. From 2.3.8 until 2.5.
CVE-2026-88131 9.8 0.84% 4 0 2026-10-09T16:35:35.900000 Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized
CVE-2026-77900 9.8 0.49% 3 0 2026-10-09T16:35:35.900000 Missing authentication for critical function in Azure App Service allows an unau
CVE-2026-83943 8.7 0.38% 2 0 2026-10-09T16:35:35.900000 Exposure of sensitive information to an unauthorized actor in Azure API Center a
CVE-2026-83947 7.7 0.37% 2 0 2026-10-09T16:35:35.900000 Missing authorization in Azure Event Grid allows an authorized attacker to perfo
CVE-2026-69435 9.6 0.39% 3 0 2026-10-09T16:35:35.900000 Missing authorization in Azure SRE Agent allows an authorized attacker to elevat
CVE-2026-84058 8.1 0.36% 1 0 2026-10-09T16:35:35.900000 IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer over
CVE-2026-84875 7.5 0.42% 1 0 2026-10-09T16:35:35.900000 IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker
CVE-2026-103413 8.8 0.00% 2 0 2026-10-09T16:33:39.007000 Improper input validation vulnerability in Apache Camel Karavan. When a deplo
CVE-2026-103412 8.8 0.00% 2 0 2026-10-09T16:33:39.007000 Improper limitation of a pathname to a restricted directory ('path traversal') v
CVE-2026-19482 8.8 0.41% 1 0 2026-10-09T16:17:28.053000 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-105436 8.8 0.25% 1 0 2026-10-09T16:17:21.427000 Deserialization of Untrusted Data vulnerability in MainWP MainWP Child mainwp-ch
CVE-2026-86405 9.8 0.00% 2 0 2026-10-09T15:31:30 Improper verification of cryptographic signature vulnerability in Sipay Electron
CVE-2026-107406 None 0.41% 15 3 2026-10-09T15:31:27 Memory overflow vulnerability leading to Remote Code Execution or Denial of Serv
CVE-2026-82344 8.1 0.38% 1 0 2026-10-09T15:17:16.183000 IBM Guardium Data Protection 12.0, 12.1 is vulnerable to a heap-based buffer ove
CVE-2016-3081 8.1 94.51% 3 0 2026-10-09T14:43:05.703000 Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when
CVE-2026-78406 9.8 0.50% 1 0 2026-10-09T14:25:39.773000 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-79842 9.1 0.33% 2 0 2026-10-09T14:17:23.533000 An authentication bypass vulnerability exists in HPE Intelligent Management Cent
CVE-2026-76459 9.8 0.28% 1 0 2026-10-09T14:17:22.427000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-18740 8.8 0.34% 1 0 2026-10-09T14:17:21.017000 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-19491 9.1 0.36% 1 0 2026-10-09T14:15:26.720000 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-19493 7.5 0.36% 1 0 2026-10-09T14:15:19.050000 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-94503 10.0 0.00% 2 0 2026-10-09T12:31:48 Unrestricted Upload of File with Dangerous Type vulnerability in PX-lab Zombify
CVE-2026-93947 9.3 0.00% 2 0 2026-10-09T12:31:48 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CVE-2026-107303 7.6 0.26% 1 0 2026-10-09T12:17:07.987000 JHipster is a development platform to quickly generate, develop, and deploy mode
CVE-2026-107510 9.1 0.29% 1 0 2026-10-09T09:31:04 An authenticated high privilege user can inject arguments in troubleshooting com
CVE-2026-76268 9.8 0.40% 2 0 2026-10-09T04:18:12.730000 In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user w
CVE-2026-15762 9.8 0.52% 1 0 2026-10-09T04:18:09.937000 IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.
CVE-2026-14502 9.8 0.39% 1 0 2026-10-09T04:18:06.343000 IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.
CVE-2026-96207 10.0 0.48% 3 0 2026-10-09T00:31:56 Improper certificate validation in Microsoft Partner Center allows an unauthoriz
CVE-2026-94510 9.9 0.40% 3 0 2026-10-09T00:31:56 Authorization bypass through user-controlled key in Microsoft Bookings allows an
CVE-2026-84057 8.1 0.36% 1 0 2026-10-09T00:31:56 IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to e
CVE-2026-84035 8.1 0.37% 1 0 2026-10-09T00:31:56 IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker
CVE-2026-84249 9.8 0.41% 1 0 2026-10-09T00:31:56 IBM Guardium Data Protection 12.2, and 12.2.2 could allow a remote attacker to e
CVE-2026-89091 8.8 0.48% 1 0 2026-10-09T00:31:56 A flaw was found in ansible-core. When installing a collection with `ansible-gal
CVE-2026-107701 8.2 0.33% 1 0 2026-10-08T21:35:53.890000 dot-access through 1.0.0 contains a prototype pollution vulnerability that allow
CVE-2026-105110 9.8 2.79% 1 0 2026-10-08T21:35:53.890000 OS Command Injection in the login.xgi CGI endpoint in Iskratel Innbox GPON ONT d
CVE-2026-107376 8.2 0.45% 1 0 2026-10-08T21:34:48.800000 webonyx graphql-php is a PHP implementation of the GraphQL specification. Prior
CVE-2026-95210 9.1 0.23% 1 0 2026-10-08T21:33:42.423000 Improper certificate validation in gnutls v3.8.13 causes the application to acce
CVE-2026-104078 7.8 0.29% 1 0 2026-10-08T21:33:42.423000 Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bun
CVE-2026-16823 9.1 0.36% 1 0 2026-10-08T21:33:42 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-78401 9.8 0.57% 1 0 2026-10-08T21:33:42 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-17189 8.2 0.14% 1 0 2026-10-08T21:33:41 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-16916 9.1 0.42% 1 0 2026-10-08T21:33:41 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-19494 8.1 0.32% 1 0 2026-10-08T21:33:41 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-84275 7.5 0.35% 1 0 2026-10-08T21:33:34 IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the GIM fil
CVE-2026-107704 9.8 1.66% 1 0 2026-10-08T21:33:34 The image_optimizer Ruby gem 1.3.0 through 1.9.0 contains an OS command injectio
CVE-2026-11318 7.8 0.19% 1 1 2026-10-08T21:33:33 Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com.
CVE-2026-107703 9.8 1.85% 1 0 2026-10-08T21:33:33 @enmaso/node-convert through 1.0.0 contains an OS command injection vulnerabilit
CVE-2026-107699 9.8 1.47% 1 0 2026-10-08T21:33:33 ppt2png through 0.0.6 contains an OS command injection vulnerability that allows
CVE-2026-107700 9.8 0.50% 1 0 2026-10-08T21:33:33 dot-access 0.0.3 through 1.0.0 contains a code injection vulnerability that allo
CVE-2026-107782 7.8 0.11% 1 0 2026-10-08T21:33:32 System Informer before 4.0.26241.138 contains an incorrect authorization vulnera
CVE-2026-84244 9.3 0.22% 1 0 2026-10-08T21:33:28 IBM Guardium Data Protection 12.2 IBM Security Guardium Data Protection is vulne
CVE-2026-84276 7.5 0.33% 1 0 2026-10-08T21:33:26 IBM Guardium Data Protection 12.2.2 is affected by a denial-of-service vulnerabi
CVE-2026-76281 5.3 0.21% 1 0 2026-10-08T21:33:09 Improper Access Control. Splunk addressed multiple internally identified vulnera
CVE-2026-107779 9.8 0.54% 1 0 2026-10-08T21:27:15.010000 Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains
CVE-2026-62252 9.8 0.65% 1 0 2026-10-08T21:09:00.643000 Homer is open source telecom observability software. Prior to version 11.0.283,
CVE-2026-107206 9.4 0.58% 1 0 2026-10-08T21:07:19.997000 LMCache through 0.5.5 contains a missing authentication vulnerability in the mul
CVE-2026-107204 9.8 0.77% 1 0 2026-10-08T21:07:19.997000 LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerab
CVE-2026-107333 8.1 0.98% 1 0 2026-10-08T21:03:43.847000 Malcolm's nginx based reverse proxy contains a URL path normalization inconsiste
CVE-2026-107217 7.5 0.34% 1 0 2026-10-08T20:33:41.757000 Excelize is a Go language library for reading and writing Microsoft Excel spread
CVE-2026-107216 7.5 0.31% 1 0 2026-10-08T20:33:41.757000 Excelize is a Go language library for reading and writing Microsoft Excel spread
CVE-2026-107215 7.5 0.22% 1 0 2026-10-08T20:33:41.757000 Excelize is a Go language library for reading and writing Microsoft Excel spread
CVE-2026-107383 7.5 0.39% 1 0 2026-10-08T20:25:00.647000 MariaDB Connector/Node.js is used to connect applications developed on Node.js t
CVE-2026-107322 7.8 0.13% 1 0 2026-10-08T20:17:31.590000 An incomplete list of disallowed inputs in Amazon Agent Plugins for AWS database
CVE-2026-20362 7.2 0.47% 3 0 2026-10-08T20:08:45.857000 A vulnerability in the web-based management interface of Cisco Finesse could all
CVE-2026-76467 7.5 0.25% 2 0 2026-10-08T20:08:45.857000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76463 8.8 0.14% 2 0 2026-10-08T20:08:45.857000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76456 8.6 0.28% 1 0 2026-10-08T20:08:45.857000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76454 9.1 0.58% 1 0 2026-10-08T20:08:45.857000 A vulnerability in the Cisco Smart Licensing Utility API of Cisco License On-Pre
CVE-2026-76453 8.8 0.34% 1 0 2026-10-08T20:08:45.857000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76457 8.6 0.28% 1 0 2026-10-08T20:08:45.857000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76482 10.0 0.20% 2 0 2026-10-08T20:08:45.857000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76472 8.8 0.12% 1 0 2026-10-08T20:08:45.857000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76470 8.8 0.18% 1 0 2026-10-08T20:08:45.857000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76486 9.8 0.51% 1 0 2026-10-08T20:08:45.857000 A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) fe
CVE-2026-76501 9.8 0.51% 1 0 2026-10-08T20:08:45.857000 A vulnerability in the Segment Routing over IPv6 (SRv6) Operation, Administratio
CVE-2026-107384 8.1 0.45% 1 0 2026-10-08T19:42:25 ### Description With the non-default permitSetMultiParamEntries option enabled,
CVE-2015-5477 7.5 91.81% 3 8 2026-10-08T18:32:53 named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote
CVE-2015-3306 10.0 98.03% 3 18 2026-10-08T18:32:52 The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write t
CVE-2021-3199 9.8 14.55% 3 0 2026-10-08T18:32:52 Directory traversal with remote code execution can occur in /upload in ONLYOFFIC
CVE-2026-104077 7.8 0.35% 1 0 2026-10-08T18:32:31 Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability th
CVE-2026-107377 7.5 0.45% 1 0 2026-10-08T17:58:02 ## Summary When processing an attacker-controlled Protobuf schema, vulnerable v
CVE-2026-107375 8.8 0.34% 1 0 2026-10-08T17:40:37 # SQL Injection in the `sort` Parameter of JHipster-Generated Reactive (WebFlux
CVE-2026-107302 7.5 0.43% 1 0 2026-10-08T17:40:11 ### Impact A truncated `map32` header causes an out-of-bounds buffer read and t
CVE-2026-107300 7.5 0.43% 1 0 2026-10-08T17:40:07 ### Impact The streaming decoder recursively invokes itself for every complete
CVE-2026-107352 7.7 0.20% 1 0 2026-10-08T17:26:22.830000 Missing authorization checks in Amazon Athena engine version 3 request handling
CVE-2026-92414 0 0.62% 1 0 2026-10-08T17:26:22.830000 : Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabb
CVE-2026-95606 9.8 0.33% 2 0 2026-10-08T17:24:31.040000 Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Ev
CVE-2026-107295 7.6 0.16% 1 0 2026-10-08T17:16:37 ### Summary The Pydantic AI development web chat UI (`Agent.to_web()`, `clai we
CVE-2026-107212 7.5 0.34% 1 0 2026-10-08T16:50:14 ### Summary A worksheet whose `<row r="...">` number is far past Excel's 1,048,
CVE-2026-107214 7.5 0.27% 1 0 2026-10-08T16:31:32 ### Summary Any file whose first 8 bytes are the OLE compound-file signature (`
CVE-2026-71895 7.1 0.22% 1 0 2026-10-08T15:33:58 An authorization vulnerability in Apache DolphinScheduler allows authenticated n
CVE-2026-9209 9.8 0.69% 1 1 2026-10-08T15:33:16 mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulne
CVE-2026-93017 7.7 0.21% 1 0 2026-10-08T15:33:15 The `insights-operator-gather` ClusterRole grants the operator's service account
CVE-2026-14992 9.8 0.31% 1 0 2026-10-08T15:33:11 IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.
CVE-2026-14497 8.1 0.59% 1 0 2026-10-08T15:33:10 IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.
CVE-2026-16340 9.8 0.49% 2 0 2026-10-08T15:33:05 IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.
CVE-2026-71896 6.5 0.26% 1 0 2026-10-08T15:32:55 An authorization vulnerability in Apache DolphinScheduler allows authenticated u
CVE-2026-12260 None 0.23% 1 0 2026-10-08T09:32:03 SQL injection in the NetBoard CRM demo platform; specifically, the vulnerable co
CVE-2026-107459 9.8 1.47% 1 0 2026-10-08T06:31:28 The SecuShare Pro developed by Openfind has an OS Command Injection vulnerabilit
CVE-2026-17609 9.1 0.31% 1 0 2026-10-08T06:31:27 The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to
CVE-2025-64393 0 0.36% 3 0 2026-10-08T04:16:55.397000 This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execu
CVE-2026-107161 7.5 0.24% 1 0 2026-10-07T21:33:37 A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge(
CVE-2026-76266 7.7 0.12% 1 0 2026-10-07T21:33:30 In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15 on Linux
CVE-2026-107219 7.5 0.34% 1 0 2026-10-07T20:23:23 Opening a file whose first eight bytes are the OLE magic number sends excelize d
CVE-2026-76471 9.8 0.52% 3 0 2026-10-07T18:32:21 A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an una
CVE-2026-76465 9.8 0.45% 3 0 2026-10-07T18:32:21 A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) fea
CVE-2026-76485 9.8 0.51% 3 0 2026-10-07T18:32:21 A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) fe
CVE-2026-76458 8.6 0.28% 1 0 2026-10-07T18:32:21 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76483 9.1 0.22% 1 0 2026-10-07T18:32:21 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-96335 7.5 0.20% 1 0 2026-10-07T18:32:21 Missing Authorization vulnerability in WPMU DEV Forminator allows Exploiting Inc
CVE-2026-76480 9.8 0.33% 1 0 2026-10-07T18:32:21 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76499 9.8 0.31% 1 0 2026-10-07T18:32:21 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76498 9.8 0.30% 1 0 2026-10-07T18:32:21 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76484 8.8 0.28% 1 0 2026-10-07T18:32:21 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-95534 8.8 0.29% 1 0 2026-10-07T18:32:21 Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited
CVE-2026-95605 9.3 0.25% 1 0 2026-10-07T18:32:21 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CVE-2026-76464 9.6 0.19% 2 0 2026-10-07T18:32:20 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76455 9.8 0.28% 2 0 2026-10-07T18:32:20 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76468 8.2 0.23% 1 0 2026-10-07T18:32:20 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20328 9.1 0.52% 2 0 2026-10-07T18:32:14 A vulnerability in the web-based management interface of Cisco License On-Prem,
CVE-2026-76500 9.8 0.33% 1 0 2026-10-07T18:32:14 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-107205 8.6 0.39% 1 0 2026-10-07T18:32:14 LMCache through 0.5.5 contains a missing authentication vulnerability in the mul
CVE-2026-106510 7.7 0.44% 1 0 2026-10-07T18:17:16.660000 Backstage is an open framework for building developer portals. Prior to 1.14.6,
CVE-2026-104286 9.8 2.20% 1 2 2026-10-07T18:17:15.240000 An improper limitation of a pathname to a restricted directory ('path traversal'
CVE-2026-106501 9.6 0.47% 1 0 2026-10-07T17:16:49.597000 Backstage is an open framework for building developer portals. Prior to 3.3.1, 3
CVE-2026-102255 10.0 0.48% 11 0 2026-10-07T16:17:32.440000 A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Pla
CVE-2026-62251 8.1 0.34% 1 0 2026-10-07T16:13:09 ### Summary The `V4StatisticsQuery` handler passes the user-supplied `rawquery`
CVE-2026-62253 9.8 0.42% 1 0 2026-10-07T16:11:59 ### Summary Both JWT middleware functions (`JWTMiddleware` and `JWTMiddlewareV4`
CVE-2026-62176 9.1 0.46% 1 0 2026-10-07T16:05:54 ### Summary The `deploy/api.py` module generates Python server code by directly
CVE-2026-83540 0 0.34% 1 0 2026-10-07T16:02:27.613000 When password or public key authentication is used with the Windows port of wolf
CVE-2026-59346 9.3 0.26% 2 1 2026-10-07T15:58:17.433000 VMware Workstation and Fusion contain an integer-overflow vulnerability. A malic
CVE-2026-106558 8.8 0.47% 1 0 2026-10-07T15:52:18.453000 Backstage is an open framework for building developer portals. Prior to 1.14.8,
CVE-2026-77214 8.2 0.55% 1 0 2026-10-07T15:32:08 libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in
CVE-2026-107181 8.1 0.34% 2 0 2026-10-07T15:32:07 Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnera
CVE-2026-21589 None 1.77% 14 10 2026-10-07T15:31:33 h3. Summary This is a vulnerability in Bitbucket Data Center, Confluence Data C
CVE-2026-105192 9.8 0.48% 4 1 2026-10-07T12:31:58 LMCache multiprocess mode, also called distributed mode, opens an unauthenticate
CVE-2026-91140 9.6 1.92% 1 0 2026-10-07T04:18:10.610000 An OS command injection vulnerability in the shell-based temporary-file cleanup
CVE-2026-16516 None 0.15% 1 0 2026-10-07T03:30:31 wolfSSH does not validate that the ECDSA curve identifier in a KEXDH_REPLY host
CVE-2026-79820 9.0 0.27% 1 0 2026-10-06T15:15:48.310000 A remote user validation failure vulnerability exists in HPE Integrated Lights-O
CVE-2026-105134 10.0 1.84% 6 1 2026-10-06T15:04:52.637000 A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects
CVE-2026-105133 7.3 0.38% 6 0 2026-10-06T15:04:52.637000 A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the fu
CVE-2026-88779 7.5 0.59% 1 2 2026-10-05T15:33:23 Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: b
CVE-2026-73551 5.3 0.53% 1 0 2026-10-05T14:06:32.380000 Envoy is an open source edge and service proxy designed for cloud-native applica
CVE-2026-53359 8.8 0.98% 1 7 2026-10-03T12:32:07 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: F
CVE-2026-88771 9.8 1.08% 2 14 2026-09-29T04:18:01.603000 Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetSc
CVE-2026-94572 0 0.53% 1 0 2026-09-24T23:19:22.677000 In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate
CVE-2026-61747 4.3 0.34% 1 0 2026-09-23T18:30:42.573000 InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the /ap
CVE-2026-79316 7.6 0.32% 1 0 2026-09-22T20:00:03.713000 An improper access control vulnerability exists in x-ui 0.3.2. Any authenticated
CVE-2026-88745 6.1 0.25% 1 0 2026-09-22T18:34:31 EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables attackers to upload a
CVE-2026-93836 7.2 0.24% 1 0 2026-09-22T09:31:18 The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to St
CVE-2026-94504 7.2 0.41% 1 0 2026-09-22T09:31:17 Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it wit
CVE-2026-94414 5.4 0.38% 1 0 2026-09-21T21:32:00 jshERP through 3.6 is missing an authorization check on the POST /userBusiness/u
CVE-2026-87491 8.8 3.14% 1 2 2026-09-21T13:17:11.283000 Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remo
CVE-2026-93485 7.1 0.38% 1 4 2026-09-18T06:32:17 Improper neutralization of input during web page generation ('cross-site scripti
CVE-2026-0310 0 0.37% 2 0 2026-09-11T04:17:13.060000 A buffer overflow vulnerability in the XML processing functionality of Palo Alto
CVE-2026-80093 7.0 0.32% 2 0 2026-09-09T00:31:34 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized at
CVE-2026-85046 8.8 48.88% 1 8 2026-09-06T03:30:24 Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote at
CVE-2026-48710 6.5 7.06% 2 5 2026-08-28T18:31:00 ### Summary In affected versions, the HTTP `Host` request header was not validat
CVE-2026-47483 8.2 0.55% 1 0 2026-07-28T17:16:45.823000 NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pp
CVE-2025-41738 7.5 0.39% 1 0 2026-06-17T09:23:03.883000 An unauthenticated remote attacker may cause the visualisation server of the COD
CVE-2025-41691 7.5 0.55% 1 0 2026-06-17T09:22:58.030000 An unauthenticated remote attacker may trigger a NULL pointer dereference in the
CVE-2026-10520 10.0 99.91% 2 9 template 2026-06-11T21:31:50 An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6
CVE-2026-23870 7.5 1.53% 1 2 2026-05-11T14:50:21 ## Impact A denial of service vulnerability could be triggered by sending speci
CVE-2025-41739 5.9 0.35% 1 0 2025-12-01T12:30:34 An unauthenticated remote attacker, who beats a race condition, can exploit a fl
CVE-2025-47818 2.2 0.24% 2 0 2025-10-24T18:32:04 Flock Safety Gunshot Detection devices before 1.3 have a hard-coded password for
CVE-2024-50623 8.8 98.61% 2 4 template 2025-10-22T00:34:15 In Cleo Harmony before 5.8.0.20, VLTrader before 5.8.0.20, and LexiCom before 5.
CVE-2025-41659 8.3 0.22% 1 0 2025-08-04T09:30:34 A low-privileged attacker can remotely access the PKI folder of the CODESYS Cont
CVE-2023-22894 7.5 3.43% 3 2 2023-11-07T05:05:45 ### Summary Strapi through 4.7.1 allows unauthenticated attackers to discover s
CVE-2026-72898 0 19.05% 3 10 N/A
CVE-2026-106433 0 0.27% 1 0 N/A
CVE-2026-107332 0 0.10% 1 0 N/A
CVE-2026-77459 0 0.00% 1 0 N/A
CVE-2026-103059 0 0.28% 1 0 N/A
CVE-2026-101027 0 0.17% 1 0 N/A

CVE-2026-105281
(7.5 HIGH)

EPSS: 0.00%

updated 2026-10-09T16:41:53.540000

2 posts

The internal data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and retrieve the complete device and measurement topology of the system.

DailyCyberSecurity at 2026-10-09T16:05:45.643Z ##

Fix critical openPDC openHistorian vulnerabilities like CVE-2026-100730 and CVE-2026-105281. CISA urges patching these severe RCE flaws immediately.

securityonline.info/openpdc-op

##

DailyCyberSecurity@infosec.exchange at 2026-10-09T16:05:45.000Z ##

Fix critical openPDC openHistorian vulnerabilities like CVE-2026-100730 and CVE-2026-105281. CISA urges patching these severe RCE flaws immediately.

#openPDC #openHistorian #CyberSecurity #Vulnerability #CISA

securityonline.info/openpdc-op

##

CVE-2026-100730
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-09T16:41:53.540000

2 posts

A service console interface on openPDC and openHistorian deserializes a client-supplied data structure. On systems using Windows Authentication, an attacker must already be authenticated to reach this function; on systems without Windows Authentication, this is reachable by an unauthenticated network attacker. This allows an attacker to trigger deserialization of an arbitrary object graph, which c

DailyCyberSecurity at 2026-10-09T16:05:45.643Z ##

Fix critical openPDC openHistorian vulnerabilities like CVE-2026-100730 and CVE-2026-105281. CISA urges patching these severe RCE flaws immediately.

securityonline.info/openpdc-op

##

DailyCyberSecurity@infosec.exchange at 2026-10-09T16:05:45.000Z ##

Fix critical openPDC openHistorian vulnerabilities like CVE-2026-100730 and CVE-2026-105281. CISA urges patching these severe RCE flaws immediately.

#openPDC #openHistorian #CyberSecurity #Vulnerability #CISA

securityonline.info/openpdc-op

##

CVE-2026-107806
(0 None)

EPSS: 0.00%

updated 2026-10-09T16:38:57.820000

2 posts

Nginx UI is a web user interface for the Nginx web server. From 2.3.8 until 2.5.0, an authenticated administrator with an active secure session can submit attacker-controlled portable backup key material and a matching manifest to POST /api/restore. The restore flow trusts the supplied key, decrypts attacker-controlled contents, and replaces the live app.ini, including protected nginx command sett

DailyCyberSecurity at 2026-10-09T16:23:53.249Z ##

A critical Nginx UI RCE vulnerability (CVE-2026-107806) is publicly disclosed with PoC exploit code. Admins must patch now to prevent system takeover.

securityonline.info/nginx-ui-r

##

DailyCyberSecurity@infosec.exchange at 2026-10-09T16:23:53.000Z ##

A critical Nginx UI RCE vulnerability (CVE-2026-107806) is publicly disclosed with PoC exploit code. Admins must patch now to prevent system takeover.

#NginxUI #RCE #Vulnerability #CVE2026107806 #CyberSecurity

securityonline.info/nginx-ui-r

##

CVE-2026-88131
(9.8 CRITICAL)

EPSS: 0.84%

updated 2026-10-09T16:35:35.900000

4 posts

Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized attacker to execute code over a network.

ssvc at 2026-10-09T14:45:52.819Z ##

Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.

  1. msrc.microsoft.com/update-guid (10.0 critical)
  2. msrc.microsoft.com/update-guid (9.9 critical)
  3. msrc.microsoft.com/update-guid (9.8 critical)
  4. msrc.microsoft.com/update-guid (9.8 critical)
  5. msrc.microsoft.com/update-guid (9.6 critical)
  6. msrc.microsoft.com/update-guid (8.7 high)
  7. msrc.microsoft.com/update-guid (7.7 high)

##

hugovalters@mastodon.social at 2026-10-09T11:10:38.000Z ##

CVE-2026-88131 - Critical RCE in Microsoft Dataverse via insecure deserialization. CVSS 9.8. Unpatched vulnerability. Mitigate immediately. #CVE #Microsoft #infosec

valtersit.com/cve/CVE-2026-881

##

ssvc@infosec.exchange at 2026-10-09T14:45:52.000Z ##

Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.

  1. msrc.microsoft.com/update-guid (10.0 critical)
  2. msrc.microsoft.com/update-guid (9.9 critical)
  3. msrc.microsoft.com/update-guid (9.8 critical)
  4. msrc.microsoft.com/update-guid (9.8 critical)
  5. msrc.microsoft.com/update-guid (9.6 critical)
  6. msrc.microsoft.com/update-guid (8.7 high)
  7. msrc.microsoft.com/update-guid (7.7 high)

#microsoft #CVE

##

offseq@infosec.exchange at 2026-10-09T03:00:24.000Z ##

Microsoft Dataverse is affected by CVE-2026-88131 (CRITICAL, CVSS 9.8): deserialization of untrusted data allows unauthenticated RCE. Patch available — apply ASAP! radar.offseq.com/threat/cve-20 #OffSeq #CVE202688131 #Microsoft #RCE #Infosec

##

CVE-2026-77900
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-10-09T16:35:35.900000

3 posts

Missing authentication for critical function in Azure App Service allows an unauthorized attacker to execute code over a network.

ssvc at 2026-10-09T14:45:52.819Z ##

Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.

  1. msrc.microsoft.com/update-guid (10.0 critical)
  2. msrc.microsoft.com/update-guid (9.9 critical)
  3. msrc.microsoft.com/update-guid (9.8 critical)
  4. msrc.microsoft.com/update-guid (9.8 critical)
  5. msrc.microsoft.com/update-guid (9.6 critical)
  6. msrc.microsoft.com/update-guid (8.7 high)
  7. msrc.microsoft.com/update-guid (7.7 high)

##

ssvc@infosec.exchange at 2026-10-09T14:45:52.000Z ##

Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.

  1. msrc.microsoft.com/update-guid (10.0 critical)
  2. msrc.microsoft.com/update-guid (9.9 critical)
  3. msrc.microsoft.com/update-guid (9.8 critical)
  4. msrc.microsoft.com/update-guid (9.8 critical)
  5. msrc.microsoft.com/update-guid (9.6 critical)
  6. msrc.microsoft.com/update-guid (8.7 high)
  7. msrc.microsoft.com/update-guid (7.7 high)

#microsoft #CVE

##

offseq@infosec.exchange at 2026-10-09T04:30:25.000Z ##

Microsoft Azure App Service for Linux hit by CVE-2026-77900 (CRITICAL, CVSS 9.8): missing authentication enables unauthenticated remote code execution. Patch released — update now. radar.offseq.com/threat/cve-20 #OffSeq #Azure #CVE202677900 #Infosec #CloudSecurity

##

CVE-2026-83943
(8.7 HIGH)

EPSS: 0.38%

updated 2026-10-09T16:35:35.900000

2 posts

Exposure of sensitive information to an unauthorized actor in Azure API Center allows an unauthorized attacker to disclose information over a network.

ssvc at 2026-10-09T14:45:52.819Z ##

Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.

  1. msrc.microsoft.com/update-guid (10.0 critical)
  2. msrc.microsoft.com/update-guid (9.9 critical)
  3. msrc.microsoft.com/update-guid (9.8 critical)
  4. msrc.microsoft.com/update-guid (9.8 critical)
  5. msrc.microsoft.com/update-guid (9.6 critical)
  6. msrc.microsoft.com/update-guid (8.7 high)
  7. msrc.microsoft.com/update-guid (7.7 high)

##

ssvc@infosec.exchange at 2026-10-09T14:45:52.000Z ##

Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.

  1. msrc.microsoft.com/update-guid (10.0 critical)
  2. msrc.microsoft.com/update-guid (9.9 critical)
  3. msrc.microsoft.com/update-guid (9.8 critical)
  4. msrc.microsoft.com/update-guid (9.8 critical)
  5. msrc.microsoft.com/update-guid (9.6 critical)
  6. msrc.microsoft.com/update-guid (8.7 high)
  7. msrc.microsoft.com/update-guid (7.7 high)

#microsoft #CVE

##

CVE-2026-83947
(7.7 HIGH)

EPSS: 0.37%

updated 2026-10-09T16:35:35.900000

2 posts

Missing authorization in Azure Event Grid allows an authorized attacker to perform spoofing over a network.

ssvc at 2026-10-09T14:45:52.819Z ##

Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.

  1. msrc.microsoft.com/update-guid (10.0 critical)
  2. msrc.microsoft.com/update-guid (9.9 critical)
  3. msrc.microsoft.com/update-guid (9.8 critical)
  4. msrc.microsoft.com/update-guid (9.8 critical)
  5. msrc.microsoft.com/update-guid (9.6 critical)
  6. msrc.microsoft.com/update-guid (8.7 high)
  7. msrc.microsoft.com/update-guid (7.7 high)

##

ssvc@infosec.exchange at 2026-10-09T14:45:52.000Z ##

Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.

  1. msrc.microsoft.com/update-guid (10.0 critical)
  2. msrc.microsoft.com/update-guid (9.9 critical)
  3. msrc.microsoft.com/update-guid (9.8 critical)
  4. msrc.microsoft.com/update-guid (9.8 critical)
  5. msrc.microsoft.com/update-guid (9.6 critical)
  6. msrc.microsoft.com/update-guid (8.7 high)
  7. msrc.microsoft.com/update-guid (7.7 high)

#microsoft #CVE

##

CVE-2026-69435
(9.6 CRITICAL)

EPSS: 0.39%

updated 2026-10-09T16:35:35.900000

3 posts

Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.

ssvc at 2026-10-09T14:45:52.819Z ##

Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.

  1. msrc.microsoft.com/update-guid (10.0 critical)
  2. msrc.microsoft.com/update-guid (9.9 critical)
  3. msrc.microsoft.com/update-guid (9.8 critical)
  4. msrc.microsoft.com/update-guid (9.8 critical)
  5. msrc.microsoft.com/update-guid (9.6 critical)
  6. msrc.microsoft.com/update-guid (8.7 high)
  7. msrc.microsoft.com/update-guid (7.7 high)

##

ssvc@infosec.exchange at 2026-10-09T14:45:52.000Z ##

Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.

  1. msrc.microsoft.com/update-guid (10.0 critical)
  2. msrc.microsoft.com/update-guid (9.9 critical)
  3. msrc.microsoft.com/update-guid (9.8 critical)
  4. msrc.microsoft.com/update-guid (9.8 critical)
  5. msrc.microsoft.com/update-guid (9.6 critical)
  6. msrc.microsoft.com/update-guid (8.7 high)
  7. msrc.microsoft.com/update-guid (7.7 high)

#microsoft #CVE

##

offseq@infosec.exchange at 2026-10-09T07:30:24.000Z ##

CVE-2026-69435: CRITICAL SSRF (CVSS 9.6) in Microsoft Azure SRE Agent. Missing authorization controls let authorized attackers escalate privileges, risking confidentiality & integrity. Microsoft has issued a fix. radar.offseq.com/threat/cve-20 #OffSeq #Azure #SSRF #Infosec

##

CVE-2026-84058
(8.1 HIGH)

EPSS: 0.36%

updated 2026-10-09T16:35:35.900000

1 posts

IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer overrun in the TDS (Microsoft SQL Server) PRELOGIN packet decoder. A remote attacker who can send a specially crafted TDS PRELOGIN packet to a network monitored by an IBM Guardium Collector may cause a denial of service or potentially execute arbitrary code on the Collector appliance.

thehackerwire@mastodon.social at 2026-10-08T22:32:22.000Z ##

🟠 CVE-2026-84058 - High (8.1)

IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer overrun in the TDS (Microsoft SQL Server) PRELOGIN packet decoder. A remote attacker who can send a specially crafted TDS PRELOGIN packet to a network monitored by an IBM...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84875
(7.5 HIGH)

EPSS: 0.42%

updated 2026-10-09T16:35:35.900000

1 posts

IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a buffer overflow.

thehackerwire@mastodon.social at 2026-10-08T22:31:07.000Z ##

🟠 CVE-2026-84875 - High (7.5)

IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a buffer overflow.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103413
(8.8 HIGH)

EPSS: 0.00%

updated 2026-10-09T16:33:39.007000

2 posts

Improper input validation vulnerability in Apache Camel Karavan. When a deployment was started, Karavan unmarshalled a project's `kubernetes.yaml` and applied every resource it contained to the cluster without restricting the resource kinds, without rejecting security-sensitive pod options, and without pinning the target namespace. An authenticated user of any role could therefore have Karavan

DailyCyberSecurity at 2026-10-09T16:13:23.846Z ##

Discover how critical Apache Camel Karavan vulnerabilities (CVE-2026-103413 and CVE-2026-103412) allow code execution. Update to version 4.22.1 now.

securityonline.info/apache-cam

##

DailyCyberSecurity@infosec.exchange at 2026-10-09T16:13:23.000Z ##

Discover how critical Apache Camel Karavan vulnerabilities (CVE-2026-103413 and CVE-2026-103412) allow code execution. Update to version 4.22.1 now.

#ApacheCamel #CyberSecurity #Vulnerability #CVE2026103413 #CVE2026103412

securityonline.info/apache-cam

##

CVE-2026-103412
(8.8 HIGH)

EPSS: 0.00%

updated 2026-10-09T16:33:39.007000

2 posts

Improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Apache Camel Karavan. A project file name supplied through the project file API was used verbatim as a path segment when the project was written to the working copy for a Git commit, so a name containing `../` sequences caused the file content to be written outside the project directory, to any locat

DailyCyberSecurity at 2026-10-09T16:13:23.846Z ##

Discover how critical Apache Camel Karavan vulnerabilities (CVE-2026-103413 and CVE-2026-103412) allow code execution. Update to version 4.22.1 now.

securityonline.info/apache-cam

##

DailyCyberSecurity@infosec.exchange at 2026-10-09T16:13:23.000Z ##

Discover how critical Apache Camel Karavan vulnerabilities (CVE-2026-103413 and CVE-2026-103412) allow code execution. Update to version 4.22.1 now.

#ApacheCamel #CyberSecurity #Vulnerability #CVE2026103413 #CVE2026103412

securityonline.info/apache-cam

##

CVE-2026-19482
(8.8 HIGH)

EPSS: 0.41%

updated 2026-10-09T16:17:28.053000

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of command arguments.

thehackerwire@mastodon.social at 2026-10-08T22:00:59.000Z ##

🟠 CVE-2026-19482 - High (8.8)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of command arguments.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105436
(8.8 HIGH)

EPSS: 0.25%

updated 2026-10-09T16:17:21.427000

1 posts

Deserialization of Untrusted Data vulnerability in MainWP MainWP Child mainwp-child allows Object Injection.This issue affects MainWP Child: from n/a through 6.2.1.

thehackerwire@mastodon.social at 2026-10-08T17:30:39.000Z ##

🟠 CVE-2026-105436 - High (8.8)

Deserialization of Untrusted Data vulnerability in MainWP MainWP Child mainwp-child allows Object Injection.This issue affects MainWP Child: from n/a through 6.2.1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86405
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-09T15:31:30

2 posts

Improper verification of cryptographic signature vulnerability in Sipay Electronic Money and Payment Services Inc. PrestaShop Virtual POS Module allows Signature Spoofing by Improper Validation. This issue affects PrestaShop Virtual POS Module: from 26.8.1 before 26.9.1.

offseq at 2026-10-09T13:30:29.626Z ##

CVE-2026-86405 (CRITICAL, CVSS 9.8) in Sipay PrestaShop Virtual POS Module (26.8.1 – 26.9.1): Improper cryptographic signature checks allow spoofing & data tampering. Patch not confirmed — monitor vendor. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-10-09T13:30:29.000Z ##

CVE-2026-86405 (CRITICAL, CVSS 9.8) in Sipay PrestaShop Virtual POS Module (26.8.1 – 26.9.1): Improper cryptographic signature checks allow spoofing & data tampering. Patch not confirmed — monitor vendor. radar.offseq.com/threat/cve-20 #OffSeq #CVE #vuln #cybersecurity

##

CVE-2026-107406(CVSS UNKNOWN)

EPSS: 0.41%

updated 2026-10-09T15:31:27

15 posts

Memory overflow vulnerability leading to Remote Code Execution or Denial of Service Vulnerability in NetScaler ADC. NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP, subject to the following version-specific requirements:   * For the following versions: Applicable only when configured as a SAML IdP: * NetScaler ADC and NetScaler Gateway between 14.1-73.37

3 repos

https://github.com/ApexBreach/CVE-2026-107406-Poc

https://github.com/techupdate24/citrix-netscaler-rce-cve-2026-107406

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

jbhall56 at 2026-10-09T14:40:50.583Z ##

CVE-2026-107406 affects NetScaler ADC and NetScaler Gateway and can lead to remote code execution (RCE) or denial of service (DoS). It carries a CVSS v4.0 score of 9.5. theregister.com/security/2026/

##

hacksgr@mastodon.social at 2026-10-09T10:55:03.000Z ##

Citrix has released fixes for CVE-2026-107406, a memory overflow flaw in NetScaler ADC and NetScaler Gateway.

Under specific configurations, it could allow remote code execution or denial of service.

The issue requires NetScaler to be configured as a SAML identity provider or service provider; affected releases vary by role and product branch.

It is rated 9.5/10.

There is no evidence the flaw has been exploited in real-world…

en.hacks.gr/i-citrix-diorthone

#Citrix #NetScaler #CVE2026107406 #SAML

##

Analyst207@mastodon.social at 2026-10-09T10:34:19.000Z ##

Citrix Patches Flaw That Enables RCE in SAML Deployments

Citrix has patched a critical vulnerability, CVE-2026-107406, with a near-perfect score of 9.5, that could allow devastating remote code execution or denial-of-service attacks in SAML deployments. The flaw can be triggered under specific configuration conditions when NetScaler instances are set up as a SAML identity provider or service provider.

osintsights.com/citrix-patches

#RemoteCodeExecution #Cve2026107406 #Citrix #Saml #Netscaler

##

thecybersecguru@mastox.eu at 2026-10-09T09:46:02.000Z ##

🚨 CRITICAL CITRIX NETSCALER FLAW: CVSS 9.5

CVE-2026-107406 could let attackers achieve REMOTE CODE EXECUTION or crash NetScaler ADC & Gateway appliances through a memory overflow in SAML processing.

⚠️ No workaround
🔐 SAML configurations are affected
🛠️ Patches are available

Citrix says it has no evidence of exploitation of this specific flaw so far. Don’t wait to patch.

Affected versions, detection commands & fixed builds 👇
thecybersecguru.com/uncategori

#CyberSecurity #Citrix #ZeroDay #InfoSec

##

guru@thecybersecguru.com at 2026-10-09T09:41:43.000Z ##

Citrix Patches Critical NetScaler Memory Overflow Flaw (CVSS 9.5) That Enables Remote Code Execution in SAML Deployments

Citrix patches CVE-2026-107406, a critical NetScaler memory overflow flaw rated CVSS 9.5 that can enable remote code execution or denial of service

thecybersecguru.com/exploits/c

##

tugatech@masto.pt at 2026-10-09T09:33:45.000Z ##

Citrix emitiu um aviso urgente para corrigir uma vulnerabilidade crítica nas soluções de rede NetScaler ADC e plataformas de acesso remoto NetScaler Gateway. A falha, identificada como CVE-2026-107406, permite a execução remota de código arbitrário ou negação de serviço. 🚨

🔗 tugatech.com.pt/t92412-citrix-

#alerta #falha 

##

jbhall56@infosec.exchange at 2026-10-09T14:40:50.000Z ##

CVE-2026-107406 affects NetScaler ADC and NetScaler Gateway and can lead to remote code execution (RCE) or denial of service (DoS). It carries a CVSS v4.0 score of 9.5. theregister.com/security/2026/

##

guru@thecybersecguru.com at 2026-10-09T09:41:43.000Z ##

Citrix Patches Critical NetScaler Memory Overflow Flaw (CVSS 9.5) That Enables Remote Code Execution in SAML Deployments

Citrix patches CVE-2026-107406, a critical NetScaler memory overflow flaw rated CVSS 9.5 that can enable remote code execution or denial of service

thecybersecguru.com/uncategori

##

tugatech@masto.pt at 2026-10-09T09:33:45.000Z ##

Citrix emitiu um aviso urgente para corrigir uma vulnerabilidade crítica nas soluções de rede NetScaler ADC e plataformas de acesso remoto NetScaler Gateway. A falha, identificada como CVE-2026-107406, permite a execução remota de código arbitrário ou negação de serviço. 🚨

🔗 tugatech.com.pt/t92412-citrix-

#alerta #falha 

##

cyberworldops@infosec.exchange at 2026-10-09T09:20:27.000Z ##

Citrix NetScaler instances with SAML enabled are affected by CVE-2026-107406, which can cause remote code execution and crash. Exposed ADC and Gateway systems risk takeover or service disruption, so patching and log review for malicious SAML requests is critical. #NetScaler #Citrix #PatchManagement

cyberworldops.eu/en/netscaler-

##

DailyCyberSecurity@infosec.exchange at 2026-10-09T01:39:17.000Z ##

Critical Citrix NetScaler vulnerability CVE-2026-107406 (CVSS 9.5) can lead to RCE on SAML-configured ADC and Gateway. Upgrade now.

#Citrix #NetScaler #NetScalerGateway #CVE2026107406 #SAML #RCE #PatchNow #Vulnerability

securityonline.info/citrix-net

##

ssvc@infosec.exchange at 2026-10-08T23:55:22.000Z ##

I thought it was a Sunday because Citrix posted another yet another NetScaler security advisory:

CVE-2026-107406 (9.5 critical) pre-auth memory overflow > RCE or DoS

As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability.

support.citrix.com/external/ar
community.citrix.com/techzone-

#citrix #netscaler #cve

##

GossiTheDog@cyberplace.social at 2026-10-08T22:07:42.000Z ##

There’s yet another Citrix Netscaler vuln (new patch today) which allows unauth RCE - CVE-2026-107406

Same attack surface (SAML) as two of the other vulns exploited in the wild during the past month.

##

Creek__@cyberplace.social at 2026-10-08T21:09:21.000Z ##

@GossiTheDog community.citrix.com/techzone-

They did it again :D

##

ifin@infosec.exchange at 2026-10-08T21:09:58.000Z ##

I'm tired, boss.

A new #Citrix CVE affecting SAML IdP/SP-configured devices is out.

ifin.network/t/cve-2026-107406

#ThreatIntel #ThreatIntelligence #IFIN

##

CVE-2026-82344
(8.1 HIGH)

EPSS: 0.38%

updated 2026-10-09T15:17:16.183000

1 posts

IBM Guardium Data Protection 12.0, 12.1 is vulnerable to a heap-based buffer overflow in the S-TAP TrafficTap TDS login reassembly functionality. An unauthenticated remote attacker can send crafted TDS login fragments that exceed the fixed-size reassembly buffer, potentially resulting in denial of service or arbitrary code execution on the affected system.

thehackerwire@mastodon.social at 2026-10-08T21:00:48.000Z ##

🟠 CVE-2026-82344 - High (8.1)

IBM Guardium Data Protection 12.0, 12.1 is vulnerable to a heap-based buffer overflow in the S-TAP TrafficTap TDS login reassembly functionality. An unauthenticated remote attacker can send crafted TDS login fragments that exceed the fixed-size r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2016-3081
(8.1 HIGH)

EPSS: 94.51%

updated 2026-10-09T14:43:05.703000

3 posts

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.

hacksgr@mastodon.social at 2026-10-09T13:39:03.000Z ##

CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog after their use by China-linked Flax Typhoon: ProFTPD (CVE-2015-3306), ONLYOFFICE Docs (CVE-2021-3199), Strapi (CVE-2023-22894), Apache Struts (CVE-2016-3081) and ISC BIND (CVE-2015-5477).

The wider operations targeted eight vulnerabilities to gain initial access to organizations and remove sensitive data.

US federal agencies must install require…

en.hacks.gr/i-cisa-prosthetei-

#FlaxTyphoon #ProFTPD #ONLYOFFICE #ISC_BIND

##

secdb@infosec.exchange at 2026-10-08T19:00:11.000Z ##

🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3306 (secdb.nttzen.cloud/cve/detail/)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: proftpd.org/ ; lists.debian.org/debian-securi ; lists.opensuse.org/archives/li ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5477 (secdb.nttzen.cloud/cve/detail/)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: web.archive.org/web/2015072901 ; access.redhat.com/errata/RHSA-; supportportal.juniper.net/s/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2016-3081 (secdb.nttzen.cloud/cve/detail/)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: cwiki.apache.org/confluence/di ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-3199 (secdb.nttzen.cloud/cve/detail/)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; github.com/ONLYOFFICE/Document ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2023-22894 (secdb.nttzen.cloud/cve/detail/)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: strapi.io/blog/security-disclo ; github.com/strapi/strapi/relea ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261008 #cisa20261008 #cve_2015_3306 #cve_2015_5477 #cve_2016_3081 #cve_2021_3199 #cve_2023_22894 #cve20153306 #cve20155477 #cve20163081 #cve20213199 #cve202322894

##

cisakevtracker@mastodon.social at 2026-10-08T18:01:13.000Z ##

CVE ID: CVE-2016-3081
Vendor: Apache
Product: Struts
Date Added: 2026-10-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-78406
(9.8 CRITICAL)

EPSS: 0.50%

updated 2026-10-09T14:25:39.773000

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

thehackerwire@mastodon.social at 2026-10-08T21:31:12.000Z ##

🔴 CVE-2026-78406 - Critical (9.8)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79842
(9.1 CRITICAL)

EPSS: 0.33%

updated 2026-10-09T14:17:23.533000

2 posts

An authentication bypass vulnerability exists in HPE Intelligent Management Center (iMC) prior to v7.3 E0713

DailyCyberSecurity@infosec.exchange at 2026-10-09T01:53:05.000Z ##

HPE fixes a critical HPE iLO 7 vulnerability, CVE-2026-79820, and iMC authentication bypass CVE-2026-79842. Update iLO to 1.25.01 now.

#HPE #iLO #iMC #CVE202679820 #CVE202679842 #AuthBypass #ServerSecurity #Vulnerability

securityonline.info/hpe-ilo-7-

##

thehackerwire@mastodon.social at 2026-10-08T21:31:21.000Z ##

🔴 CVE-2026-79842 - Critical (9.1)

An authentication bypass vulnerability exists in HPE Intelligent Management Center (iMC) prior to v7.3 E0713

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76459
(9.8 CRITICAL)

EPSS: 0.28%

updated 2026-10-09T14:17:22.427000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76459 are related to out-of-bounds write issues that are grouped under

thehackerwire@mastodon.social at 2026-10-07T19:46:33.000Z ##

🟠 CVE-2026-76459 - High (8.8)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18740
(8.8 HIGH)

EPSS: 0.34%

updated 2026-10-09T14:17:21.017000

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to perform unauthorized actions due to argument injection.

thehackerwire@mastodon.social at 2026-10-08T22:00:48.000Z ##

🟠 CVE-2026-18740 - High (8.8)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to perform unauthorized actions due to argument injection.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19491
(9.1 CRITICAL)

EPSS: 0.36%

updated 2026-10-09T14:15:26.720000

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to bypass authentication due to improper authentication.

thehackerwire@mastodon.social at 2026-10-08T21:46:00.000Z ##

🔴 CVE-2026-19491 - Critical (9.1)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to bypass authentication due to improper authentication.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19493
(7.5 HIGH)

EPSS: 0.36%

updated 2026-10-09T14:15:19.050000

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to perform an arbitrary file write due to path traversal.

thehackerwire@mastodon.social at 2026-10-08T21:46:09.000Z ##

🟠 CVE-2026-19493 - High (7.5)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to perform an arbitrary file write due to path traversal.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94503
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-10-09T12:31:48

2 posts

Unrestricted Upload of File with Dangerous Type vulnerability in PX-lab Zombify zombify allows Upload a Web Shell to a Web Server.This issue affects Zombify: from n/a through 1.7.7.

offseq at 2026-10-09T12:00:32.541Z ##

PX-lab Zombify ≤1.7.7 is affected by CVE-2026-94503 (CRITICAL, CVSS 10): unrestricted upload of dangerous files enables remote code execution. No patch yet — restrict uploads & monitor for updates. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-10-09T12:00:32.000Z ##

PX-lab Zombify ≤1.7.7 is affected by CVE-2026-94503 (CRITICAL, CVSS 10): unrestricted upload of dangerous files enables remote code execution. No patch yet — restrict uploads & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE202694503 #WebSecurity #Infosec

##

CVE-2026-93947
(9.3 CRITICAL)

EPSS: 0.00%

updated 2026-10-09T12:31:48

2 posts

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shinetheme Traveler traveler allows Blind SQL Injection.This issue affects Traveler: from n/a through 3.2.9.

offseq at 2026-10-09T10:30:25.136Z ##

CVE-2026-93947: CRITICAL SQL Injection in Shinetheme Traveler (0 – 3.2.9). Blind SQLi risk — attackers may access sensitive DB data. Patch when available & monitor your systems. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-10-09T10:30:25.000Z ##

CVE-2026-93947: CRITICAL SQL Injection in Shinetheme Traveler (0 – 3.2.9). Blind SQLi risk — attackers may access sensitive DB data. Patch when available & monitor your systems. radar.offseq.com/threat/cve-20 #OffSeq #CVE202693947 #SQLInjection #InfoSec

##

CVE-2026-107303
(7.6 HIGH)

EPSS: 0.26%

updated 2026-10-09T12:17:07.987000

1 posts

JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures. Prior to generator-jhipster 9.4.0 and react-jhipster 1.1.0, generated applications can persist attacker-controlled Blob data and companion ContentType values, return them through generated REST endpoints, and pass them to the generated openFile helper in generators/cl

thehackerwire@mastodon.social at 2026-10-08T18:46:09.000Z ##

🟠 CVE-2026-107303 - High (7.6)

JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures. Prior to generator-jhipster 9.4.0 and react-jhipster 1.1.0, generated applications can persist attacker-controlled ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107510
(9.1 CRITICAL)

EPSS: 0.29%

updated 2026-10-09T09:31:04

1 posts

An authenticated high privilege user can inject arguments in troubleshooting commands resulting in privilege escalation.

offseq@infosec.exchange at 2026-10-08T10:30:26.000Z ##

CVE-2026-107510: CRITICAL vuln in Infoblox NIOS 9.0.x – 9.1.0. Auth'd high-priv users can escalate privileges via argument injection. Restrict admin access & watch for vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #Infosec #CVE2026107510

##

CVE-2026-76268
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-10-09T04:18:12.730000

2 posts

In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with network access to the Patroni Representational State Transfer (REST) Application Programming Interface (API) on a search head cluster member could execute attacker-controlled operating-system commands. The vulnerability is possible because this interface does not require authentication for critical configuration op

DailyCyberSecurity@infosec.exchange at 2026-10-08T01:56:26.000Z ##

Splunk fixes 22 Splunk Enterprise vulnerabilities, including critical Patroni API flaw CVE-2026-76268 and CVE-2026-76281. Upgrade to 10.4.3 now.

#Splunk #SplunkEnterprise #SIEM #CVE202676268 #CVE202676281 #RCE #PatchNow #Vulnerability

securityonline.info/splunk-ent

##

thehackerwire@mastodon.social at 2026-10-07T21:31:08.000Z ##

🔴 CVE-2026-76268 - Critical (9.8)

In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with network access to the Patroni Representational State Transfer (REST) Application Programming Interface (API) on a search head cluster member could execute attacker...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15762
(9.8 CRITICAL)

EPSS: 0.52%

updated 2026-10-09T04:18:09.937000

1 posts

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.

CVE-2026-14502
(9.8 CRITICAL)

EPSS: 0.39%

updated 2026-10-09T04:18:06.343000

1 posts

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to obtain administrative access due to failure to reject empty passwords during LDAP authentication.

thehackerwire@mastodon.social at 2026-10-08T20:16:38.000Z ##

🔴 CVE-2026-14502 - Critical (9.8)

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to obtain administrative access due to failure to reject empty passwords during LDAP a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-96207
(10.0 CRITICAL)

EPSS: 0.48%

updated 2026-10-09T00:31:56

3 posts

Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.

ssvc at 2026-10-09T14:45:52.819Z ##

Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.

  1. msrc.microsoft.com/update-guid (10.0 critical)
  2. msrc.microsoft.com/update-guid (9.9 critical)
  3. msrc.microsoft.com/update-guid (9.8 critical)
  4. msrc.microsoft.com/update-guid (9.8 critical)
  5. msrc.microsoft.com/update-guid (9.6 critical)
  6. msrc.microsoft.com/update-guid (8.7 high)
  7. msrc.microsoft.com/update-guid (7.7 high)

##

ssvc@infosec.exchange at 2026-10-09T14:45:52.000Z ##

Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.

  1. msrc.microsoft.com/update-guid (10.0 critical)
  2. msrc.microsoft.com/update-guid (9.9 critical)
  3. msrc.microsoft.com/update-guid (9.8 critical)
  4. msrc.microsoft.com/update-guid (9.8 critical)
  5. msrc.microsoft.com/update-guid (9.6 critical)
  6. msrc.microsoft.com/update-guid (8.7 high)
  7. msrc.microsoft.com/update-guid (7.7 high)

#microsoft #CVE

##

offseq@infosec.exchange at 2026-10-09T00:00:41.000Z ##

CVE-2026-96207 (CRITICAL, CVSS 10) affects Microsoft Partner Center: improper certificate validation (CWE-295) allows remote privilege escalation. Patch available — apply ASAP. No public exploits seen. radar.offseq.com/threat/cve-20 #OffSeq #Microsoft #CVE202696207 #Infosec

##

CVE-2026-94510
(9.9 CRITICAL)

EPSS: 0.40%

updated 2026-10-09T00:31:56

3 posts

Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network.

ssvc at 2026-10-09T14:45:52.819Z ##

Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.

  1. msrc.microsoft.com/update-guid (10.0 critical)
  2. msrc.microsoft.com/update-guid (9.9 critical)
  3. msrc.microsoft.com/update-guid (9.8 critical)
  4. msrc.microsoft.com/update-guid (9.8 critical)
  5. msrc.microsoft.com/update-guid (9.6 critical)
  6. msrc.microsoft.com/update-guid (8.7 high)
  7. msrc.microsoft.com/update-guid (7.7 high)

##

ssvc@infosec.exchange at 2026-10-09T14:45:52.000Z ##

Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.

  1. msrc.microsoft.com/update-guid (10.0 critical)
  2. msrc.microsoft.com/update-guid (9.9 critical)
  3. msrc.microsoft.com/update-guid (9.8 critical)
  4. msrc.microsoft.com/update-guid (9.8 critical)
  5. msrc.microsoft.com/update-guid (9.6 critical)
  6. msrc.microsoft.com/update-guid (8.7 high)
  7. msrc.microsoft.com/update-guid (7.7 high)

#microsoft #CVE

##

offseq@infosec.exchange at 2026-10-09T01:30:26.000Z ##

CVE-2026-94510 (CRITICAL, CVSS 9.9) in Microsoft Bookings enables remote privilege escalation via authorization bypass (CWE-639). Apply the official Microsoft patch now: radar.offseq.com/threat/cve-20 #OffSeq #Microsoft #Vuln #CVE #Infosec

##

CVE-2026-84057
(8.1 HIGH)

EPSS: 0.36%

updated 2026-10-09T00:31:56

1 posts

IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

thehackerwire@mastodon.social at 2026-10-08T22:32:13.000Z ##

🟠 CVE-2026-84057 - High (8.1)

IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84035
(8.1 HIGH)

EPSS: 0.37%

updated 2026-10-09T00:31:56

1 posts

IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.

thehackerwire@mastodon.social at 2026-10-08T22:32:04.000Z ##

🟠 CVE-2026-84035 - High (8.1)

IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84249
(9.8 CRITICAL)

EPSS: 0.41%

updated 2026-10-09T00:31:56

1 posts

IBM Guardium Data Protection 12.2, and 12.2.2 could allow a remote attacker to execute arbitrary management operations due to missing authentication for critical function.

thehackerwire@mastodon.social at 2026-10-08T22:30:58.000Z ##

🔴 CVE-2026-84249 - Critical (9.8)

IBM Guardium Data Protection 12.2, and 12.2.2 could allow a remote attacker to execute arbitrary management operations due to missing authentication for critical function.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89091
(8.8 HIGH)

EPSS: 0.48%

updated 2026-10-09T00:31:56

1 posts

A flaw was found in ansible-core. When installing a collection with `ansible-galaxy collection install`, the archive extractor validates member paths using lexical path normalisation (os.path.abspath) instead of resolving symbolic links (os.path.realpath), and it performs no containment check on symlink-typed directory members before creating them. A crafted collection tarball can chain symlink di

thehackerwire@mastodon.social at 2026-10-08T22:30:49.000Z ##

🟠 CVE-2026-89091 - High (8.8)

A flaw was found in ansible-core. When installing a collection with
`ansible-galaxy collection install`, the archive extractor validates member
paths using lexical path normalisation (os.path.abspath) instead of resolving
symbolic links (os.path.r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107701
(8.2 HIGH)

EPSS: 0.33%

updated 2026-10-08T21:35:53.890000

1 posts

dot-access through 1.0.0 contains a prototype pollution vulnerability that allows attackers to modify Object.prototype by supplying a crafted dotted path to set(). Attackers controlling the path, such as through user-supplied field names, can use __proto__ segments to inject properties into all objects, altering authorization flags and option defaults or crashing the process.

thehackerwire@mastodon.social at 2026-10-08T19:31:00.000Z ##

🟠 CVE-2026-107701 - High (8.2)

dot-access through 1.0.0 contains a prototype pollution vulnerability that allows attackers to modify Object.prototype by supplying a crafted dotted path to set(). Attackers controlling the path, such as through user-supplied field names, can use ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105110
(9.8 CRITICAL)

EPSS: 2.79%

updated 2026-10-08T21:35:53.890000

1 posts

OS Command Injection in the login.xgi CGI endpoint in Iskratel Innbox GPON ONT devices allows an unauthenticated remote attacker to execute arbitrary commands as root via the CLI parameter.

offseq@infosec.exchange at 2026-10-08T12:00:26.000Z ##

CVE-2026-105110 (CRITICAL, CVSS 9.8): Iskratel Innbox GPON ONT devices have an OS command injection flaw in login.xgi. Remote, unauthenticated code execution as root possible. Restrict access & monitor until patch. radar.offseq.com/threat/cve-20 #OffSeq #infosec #zeroday #vuln

##

CVE-2026-107376
(8.2 HIGH)

EPSS: 0.45%

updated 2026-10-08T21:34:48.800000

1 posts

webonyx graphql-php is a PHP implementation of the GraphQL specification. Prior to 15.32.3, GraphQL\Language\Parser performs recursive descent without a recursion limit in parseSelectionSet, parseValueLiteral, and parseTypeReference. A remote attacker can submit deeply nested selection sets, object or list values, or list types that exhaust the PHP process stack during pre-validation parsing, befo

thehackerwire@mastodon.social at 2026-10-08T18:30:24.000Z ##

🟠 CVE-2026-107376 - High (8.2)

webonyx graphql-php is a PHP implementation of the GraphQL specification. Prior to 15.32.3, GraphQL\Language\Parser performs recursive descent without a recursion limit in parseSelectionSet, parseValueLiteral, and parseTypeReference. A remote atta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-95210
(9.1 CRITICAL)

EPSS: 0.23%

updated 2026-10-08T21:33:42.423000

1 posts

Improper certificate validation in gnutls v3.8.13 causes the application to accept certificates containing invalid extensions.

thehackerwire@mastodon.social at 2026-10-08T19:46:45.000Z ##

🔴 CVE-2026-95210 - Critical (9.1)

Improper certificate validation in gnutls v3.8.13 causes the application to accept certificates containing invalid extensions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104078
(7.8 HIGH)

EPSS: 0.29%

updated 2026-10-08T21:33:42.423000

1 posts

Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute arbitrary code by embedding a crafted \href value with a TAB byte in the URL scheme, causing filterURL to produce an empty protocol that bypasses the configured safeProtocols restrictions. Attackers can craft a note containing a malicious MathJax formul

thehackerwire@mastodon.social at 2026-10-08T17:31:54.000Z ##

🟠 CVE-2026-104078 - High (7.8)

Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute arbitrary code by embedding a crafted \href value with a TAB byte in the URL scheme, causing filterU...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16823
(9.1 CRITICAL)

EPSS: 0.36%

updated 2026-10-08T21:33:42

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to bypass security restrictions due to improper authentication.

thehackerwire@mastodon.social at 2026-10-08T21:47:11.000Z ##

🔴 CVE-2026-16823 - Critical (9.1)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to bypass security restrictions due to improper authentication.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78401
(9.8 CRITICAL)

EPSS: 0.57%

updated 2026-10-08T21:33:42

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

thehackerwire@mastodon.social at 2026-10-08T21:31:03.000Z ##

🔴 CVE-2026-78401 - Critical (9.8)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17189
(8.2 HIGH)

EPSS: 0.14%

updated 2026-10-08T21:33:41

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session

thehackerwire@mastodon.social at 2026-10-08T21:47:28.000Z ##

🟠 CVE-2026-17189 - High (8.2)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI thus alt...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16916
(9.1 CRITICAL)

EPSS: 0.42%

updated 2026-10-08T21:33:41

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to execute arbitrary code due to a protection mechanism failure.

thehackerwire@mastodon.social at 2026-10-08T21:47:19.000Z ##

🔴 CVE-2026-16916 - Critical (9.1)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to execute arbitrary code due to a protection mechanism failure.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19494
(8.1 HIGH)

EPSS: 0.32%

updated 2026-10-08T21:33:41

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication.

thehackerwire@mastodon.social at 2026-10-08T21:46:18.000Z ##

🟠 CVE-2026-19494 - High (8.1)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84275
(7.5 HIGH)

EPSS: 0.35%

updated 2026-10-08T21:33:34

1 posts

IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the GIM file-upload functionality. An unauthenticated attacker could exploit this vulnerability to write arbitrary files to the Collector.

thehackerwire@mastodon.social at 2026-10-08T21:00:39.000Z ##

🟠 CVE-2026-84275 - High (7.5)

IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the GIM file-upload functionality. An unauthenticated attacker could exploit this vulnerability to write arbitrary files to the Collector.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107704
(9.8 CRITICAL)

EPSS: 1.66%

updated 2026-10-08T21:33:34

1 posts

The image_optimizer Ruby gem 1.3.0 through 1.9.0 contains an OS command injection vulnerability in ImageOptimizer#identify_format that allows attackers to execute commands by supplying a crafted image path when the identify option is enabled. Attackers controlling the path, such as an uploaded file name, can append shell metacharacters like ';' that are executed via Ruby backticks with the Ruby pr

thehackerwire@mastodon.social at 2026-10-08T19:31:57.000Z ##

🔴 CVE-2026-107704 - Critical (9.8)

The image_optimizer Ruby gem 1.3.0 through 1.9.0 contains an OS command injection vulnerability in ImageOptimizer#identify_format that allows attackers to execute commands by supplying a crafted image path when the identify option is enabled. Atta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-11318
(7.8 HIGH)

EPSS: 0.19%

updated 2026-10-08T21:33:33

1 posts

Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com.deskin.service.installer XPC service that allows local unprivileged attackers to execute arbitrary installer packages as root by connecting to the root-owned service without authentication. Attackers can invoke the privileged installer method to run an attacker-supplied installer, achieving full root compromise of the

1 repos

https://github.com/Cr0wld3r/CVE-2026-11318

thehackerwire@mastodon.social at 2026-10-08T22:01:39.000Z ##

🟠 CVE-2026-11318 - High (7.8)

Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com.deskin.service.installer XPC service that allows local unprivileged attackers to execute arbitrary installer packages as root by connecting to the root-owned service w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107703
(9.8 CRITICAL)

EPSS: 1.85%

updated 2026-10-08T21:33:33

1 posts

@enmaso/node-convert through 1.0.0 contains an OS command injection vulnerability in convert.js that allows attackers to execute shell commands via unsanitized filepath and convertTo arguments. Attackers can inject shell metacharacters or a single quote into the ImageMagick command run by child_process.exec() to execute operating system commands with Node.js process privileges.

thehackerwire@mastodon.social at 2026-10-08T19:31:48.000Z ##

🔴 CVE-2026-107703 - Critical (9.8)

@enmaso/node-convert through 1.0.0 contains an OS command injection vulnerability in convert.js that allows attackers to execute shell commands via unsanitized filepath and convertTo arguments. Attackers can inject shell metacharacters or a single...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107699
(9.8 CRITICAL)

EPSS: 1.47%

updated 2026-10-08T21:33:33

1 posts

ppt2png through 0.0.6 contains an OS command injection vulnerability that allows attackers to execute operating system commands by supplying unsanitized input or output path arguments. Attackers can append shell metacharacters such as ';' to file names passed to child_process.exec() in ppt2png.js, running commands with Node.js process privileges.

thehackerwire@mastodon.social at 2026-10-08T19:32:08.000Z ##

🔴 CVE-2026-107699 - Critical (9.8)

ppt2png through 0.0.6 contains an OS command injection vulnerability that allows attackers to execute operating system commands by supplying unsanitized input or output path arguments. Attackers can append shell metacharacters such as ';' to file ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107700
(9.8 CRITICAL)

EPSS: 0.50%

updated 2026-10-08T21:33:33

1 posts

dot-access 0.0.3 through 1.0.0 contains a code injection vulnerability that allows remote attackers to execute JavaScript by supplying crafted paths to get(). The path is concatenated into a new Function body in index.js, so attackers can reach constructor.constructor to load child_process and run operating system commands in the Node.js process.

thehackerwire@mastodon.social at 2026-10-08T19:30:51.000Z ##

🔴 CVE-2026-107700 - Critical (9.8)

dot-access 0.0.3 through 1.0.0 contains a code injection vulnerability that allows remote attackers to execute JavaScript by supplying crafted paths to get(). The path is concatenated into a new Function body in index.js, so attackers can reach co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107782
(7.8 HIGH)

EPSS: 0.11%

updated 2026-10-08T21:33:32

1 posts

System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc helper that allows local attackers to reach privileged APIs by connecting from any Authenticode-signed process. Attackers can load code into a Microsoft-signed host like rundll32.exe, connect to SiSvcApiPort, and call PhSvcApiCreateService to execute code as SYSTEM.

thehackerwire@mastodon.social at 2026-10-08T22:01:27.000Z ##

🟠 CVE-2026-107782 - High (7.8)

System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc helper that allows local attackers to reach privileged APIs by connecting from any Authenticode-signed process. Attackers can load code into a Micr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84244
(9.3 CRITICAL)

EPSS: 0.22%

updated 2026-10-08T21:33:28

1 posts

IBM Guardium Data Protection 12.2 IBM Security Guardium Data Protection is vulnerable to stored cross-site scripting (XSS) in the Quick Search results grid. An unauthenticated attacker who can influence monitored database traffic could execute malicious script in the browser of an authenticated Guardium user.

thehackerwire@mastodon.social at 2026-10-08T21:00:57.000Z ##

🔴 CVE-2026-84244 - Critical (9.3)

IBM Guardium Data Protection 12.2 IBM Security Guardium Data Protection is vulnerable to stored cross-site scripting (XSS) in the Quick Search results grid. An unauthenticated attacker who can influence monitored database traffic could execute mal...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84276
(7.5 HIGH)

EPSS: 0.33%

updated 2026-10-08T21:33:26

1 posts

IBM Guardium Data Protection 12.2.2 is affected by a denial-of-service vulnerability in the edge-controller. An unauthenticated remote attacker with network access to the edge-controller gRPC service can provide malformed task data that triggers an unchecked type assertion, causing the edge-controller process to terminate unexpectedly.

thehackerwire@mastodon.social at 2026-10-08T19:30:41.000Z ##

🟠 CVE-2026-84276 - High (7.5)

IBM Guardium Data Protection 12.2.2 is affected by a denial-of-service vulnerability in the edge-controller. An unauthenticated remote attacker with network access to the edge-controller gRPC service can provide malformed task data that triggers a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76281
(5.3 MEDIUM)

EPSS: 0.21%

updated 2026-10-08T21:33:09

1 posts

Improper Access Control. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information.

CVE-2026-107779
(9.8 CRITICAL)

EPSS: 0.54%

updated 2026-10-08T21:27:15.010000

1 posts

Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a missing authentication vulnerability in bundled xxl-job-admin JobInfoController endpoints annotated with @PermissionLimit(limit = false). Unauthenticated attackers can POST GLUE_SHELL, GLUE_PYTHON, or GLUE_POWERSHELL jobs with attacker-supplied glueSource to /jobinfo/addAndStart, executing commands on the executor ho

thehackerwire@mastodon.social at 2026-10-08T22:01:47.000Z ##

🔴 CVE-2026-107779 - Critical (9.8)

Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a missing authentication vulnerability in bundled xxl-job-admin JobInfoController endpoints annotated with @PermissionLimit(limit = false). Unauthenticated attackers c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62252
(9.8 CRITICAL)

EPSS: 0.65%

updated 2026-10-08T21:09:00.643000

1 posts

Homer is open source telecom observability software. Prior to version 11.0.283, on every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an `admin` account with the password `sipcapture` (stored as a legacy SHA-256 hex hash). There is no first-login forced-change mechanism. Any attacker who reaches the login endpoint immediately gains full administ

thehackerwire@mastodon.social at 2026-10-07T21:16:12.000Z ##

🔴 CVE-2026-62252 - Critical (9.8)

Homer is open source telecom observability software. Prior to version 11.0.283, on every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an `admin` account with the password `sipcapture` (stored as...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107206
(9.4 CRITICAL)

EPSS: 0.58%

updated 2026-10-08T21:07:19.997000

1 posts

LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess mode HTTP server that allows remote unauthenticated attackers to access management endpoints listening on all interfaces by default. Attackers can read environment credentials via GET /env and configuration via GET /config, clear caches, delete cache objects, and modify tenant quotas to evict other tenants' c

thehackerwire@mastodon.social at 2026-10-07T16:49:47.000Z ##

🔴 CVE-2026-107206 - Critical (9.4)

LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess mode HTTP server that allows remote unauthenticated attackers to access management endpoints listening on all interfaces by default. Attackers can read envir...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107204
(9.8 CRITICAL)

EPSS: 0.77%

updated 2026-10-08T21:07:19.997000

1 posts

LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run_script endpoint. Attackers can recover real builtins through the injected FastAPI app object, bypassing the guarded __import__, to import os and run operating system commands as the LMCache process.

thehackerwire@mastodon.social at 2026-10-07T16:49:30.000Z ##

🔴 CVE-2026-107204 - Critical (9.8)

LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run_script endpoint. Attackers can recover real builtins through the injected Fast...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107333
(8.1 HIGH)

EPSS: 0.98%

updated 2026-10-08T21:03:43.847000

1 posts

Malcolm's nginx based reverse proxy contains a URL path normalization inconsistency between its Lua based role-based access control (RBAC) authorization layer and nginx's own request routing logic. An authenticated user can craft a specially formatted request path to bypass role-based restrictions and reach administrative or role gated endpoints they should not have access to. This affects all res

thehackerwire@mastodon.social at 2026-10-08T18:46:18.000Z ##

🟠 CVE-2026-107333 - High (8.1)

Malcolm's nginx based reverse proxy contains a URL path normalization inconsistency between its Lua based role-based access control (RBAC) authorization layer and nginx's own request routing logic. An authenticated user can craft a specially forma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107217
(7.5 HIGH)

EPSS: 0.34%

updated 2026-10-08T20:33:41.757000

1 posts

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.0.0 to 2.11.0 in github.com/xuri/excelize/v2 and from 1.1.0 to 1.4.1 in github.com/xuri/excelize, ColumnNameToNumber accumulates a bijective base-26 value in int64 without detecting overflow, allowing an invalid long column name to wrap to zero with no error. ColumnNameToNumber accepts the overflowing na

thehackerwire@mastodon.social at 2026-10-07T19:45:50.000Z ##

🟠 CVE-2026-107217 - High (7.5)

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.0.0 to 2.11.0 in github.com/xuri/excelize/v2 and from 1.1.0 to 1.4.1 in github.com/xuri/excelize, ColumnNameToNumber accumulates a bijective base-26 val...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107216
(7.5 HIGH)

EPSS: 0.31%

updated 2026-10-08T20:33:41.757000

1 posts

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.1 to 2.11.0, ANCHORARRAY recursively calls the exported CalcCellValue function, creating a fresh calculation context at each cycle and bypassing in-flight and iteration controls. ANCHORARRAY calls CalcCellValue instead of cellResolver, so each recursive hop receives a new calcContext and loses cycle st

thehackerwire@mastodon.social at 2026-10-07T19:00:45.000Z ##

🟠 CVE-2026-107216 - High (7.5)

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.1 to 2.11.0, ANCHORARRAY recursively calls the exported CalcCellValue function, creating a fresh calculation context at each cycle and bypassing in-fl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107215
(7.5 HIGH)

EPSS: 0.22%

updated 2026-10-08T20:33:41.757000

1 posts

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, extractPart allocates a byte slice directly from an attacker-controlled CFB directory-entry size before validating the sector chain or size domain. extractPart trusts the CFB directory entry streamSize for EncryptionInfo and EncryptedPackage allocations before validating the stream. When a

thehackerwire@mastodon.social at 2026-10-07T18:31:02.000Z ##

🟠 CVE-2026-107215 - High (7.5)

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, extractPart allocates a byte slice directly from an attacker-controlled CFB directory-entry size before validating the sector chain or si...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107383
(7.5 HIGH)

EPSS: 0.39%

updated 2026-10-08T20:25:00.647000

1 posts

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4, the GeoJSON Polygon and MultiPolygon binary encoders size a Buffer.allocUnsafe() allocation from each ring's numeric length before confirming that the ring is an array. A malformed non-array ring can therefore reserve bytes that the writing loop sk

thehackerwire@mastodon.social at 2026-10-08T19:45:45.000Z ##

🟠 CVE-2026-107383 - High (7.5)

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4, the GeoJSON Polygon and MultiPolygon binary encoders size a Buffer.allocUnsafe() allocation fro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107322
(7.8 HIGH)

EPSS: 0.13%

updated 2026-10-08T20:17:31.590000

1 posts

An incomplete list of disallowed inputs in Amazon Agent Plugins for AWS databases-on-aws plugin before 1.7.1 might allow a remote unauthenticated actor to execute arbitrary operating system commands on the host running the helper via a crafted database command value introduced in the agent context. To remediate this issue, users should upgrade to databases-on-aws plugin version 1.7.1 or later a

thehackerwire@mastodon.social at 2026-10-08T19:46:37.000Z ##

🟠 CVE-2026-107322 - High (7.8)

An incomplete list of disallowed inputs in Amazon Agent Plugins for AWS databases-on-aws plugin before 1.7.1 might allow a remote unauthenticated actor to execute arbitrary operating system commands on the host running the helper via a crafted dat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20362
(7.2 HIGH)

EPSS: 0.47%

updated 2026-10-08T20:08:45.857000

3 posts

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successfu

sans_isc@infosec.exchange at 2026-10-09T07:55:30.000Z ##

SANS Stormcast Friday, October 9th, 2026: AI Agent Forensics; AI-Assisted Attack on South Korean Banks; IDN Typosquatting; Cisco Finesse SSRF (CVE-2026-20362)
isc.sans.edu/podcastdetail/101

##

DailyCyberSecurity@infosec.exchange at 2026-10-08T02:26:40.000Z ##

A Cisco Finesse vulnerability, SSRF flaw CVE-2026-20362, has been publicly disclosed. Fixes arrive in early 2027, with no workarounds.

#Cisco #CiscoFinesse #ContactCenter #CVE202620362 #SSRF #Horizon3 #UnifiedCCX #Vulnerability

securityonline.info/cisco-fine

##

ssvc@infosec.exchange at 2026-10-07T16:17:37.000Z ##

There are 14 Cisco security advisories that came out today. sec.cloudapps.cisco.com/securi

A lot of 9.8 and even 10.0 across multiple products. While there's no mention of exploitation, there's zero-day disclosure pre-patch for Cisco Finesse Server-Side Request Forgery Vulnerability CVE-2026-20362 (7.2)

The Cisco PSIRT is aware that a public announcement is available for the vulnerability that is described in this advisory.

sec.cloudapps.cisco.com/securi

#cisco #CVE

##

CVE-2026-76467
(7.5 HIGH)

EPSS: 0.25%

updated 2026-10-08T20:08:45.857000

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76467 are related to issues concerning improper control of a resou

AAKL@infosec.exchange at 2026-10-08T15:52:31.000Z ##

Two more Cisco advisories today addressing critical vulnerabilities:

- CVE-2026-76471: Cisco NX-OS Software NX-API Remote Code Execution Vulnerability sec.cloudapps.cisco.com/securi

- CVE-2026-76463, CVE-2026-76464, and CVE-2026-76467: Cisco Meraki Security Hardening Release: October 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #Cisco #vulnerability

##

thehackerwire@mastodon.social at 2026-10-07T19:15:55.000Z ##

🟠 CVE-2026-76467 - High (7.5)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses mult...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76463
(8.8 HIGH)

EPSS: 0.14%

updated 2026-10-08T20:08:45.857000

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76463 are related to improper access control issues that are group

AAKL@infosec.exchange at 2026-10-08T15:52:31.000Z ##

Two more Cisco advisories today addressing critical vulnerabilities:

- CVE-2026-76471: Cisco NX-OS Software NX-API Remote Code Execution Vulnerability sec.cloudapps.cisco.com/securi

- CVE-2026-76463, CVE-2026-76464, and CVE-2026-76467: Cisco Meraki Security Hardening Release: October 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #Cisco #vulnerability

##

thehackerwire@mastodon.social at 2026-10-07T19:46:43.000Z ##

🟠 CVE-2026-76463 - High (8.8)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses mult...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76456
(8.6 HIGH)

EPSS: 0.28%

updated 2026-10-08T20:08:45.857000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76456 are related to improper input validation of special elements used

thehackerwire@mastodon.social at 2026-10-07T20:45:56.000Z ##

🟠 CVE-2026-76456 - High (8.6)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76454
(9.1 CRITICAL)

EPSS: 0.58%

updated 2026-10-08T20:08:45.857000

1 posts

A vulnerability in the Cisco Smart Licensing Utility API of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to write arbitrary files to the system or cause a DoS condition on an affected application. This vulnerability is due to improper input validation and a lack of authentication in the management API. An att

thehackerwire@mastodon.social at 2026-10-07T20:15:50.000Z ##

🔴 CVE-2026-76454 - Critical (9.1)

A vulnerability in the Cisco Smart Licensing Utility API of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to write arbitrary files to the system or cause a DoS c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76453
(8.8 HIGH)

EPSS: 0.34%

updated 2026-10-08T20:08:45.857000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76453 are related to improper neutralization issues that are grouped un

thehackerwire@mastodon.social at 2026-10-07T20:15:40.000Z ##

🟠 CVE-2026-76453 - High (8.8)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76457
(8.6 HIGH)

EPSS: 0.28%

updated 2026-10-08T20:08:45.857000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76457 are related to out-of-bounds read issues that are grouped under t

thehackerwire@mastodon.social at 2026-10-07T19:16:13.000Z ##

🟠 CVE-2026-76457 - High (8.6)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76482
(10.0 CRITICAL)

EPSS: 0.20%

updated 2026-10-08T20:08:45.857000

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-202

thehackerwire@mastodon.social at 2026-10-07T18:17:30.000Z ##

🔴 CVE-2026-76482 - Critical (10)

As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-10-07T17:36:18.000Z ##

Cisco License On-Prem vulnerabilities include CVSS 10 flaw CVE-2026-76482 and password reset bug CVE-2026-20328. APIC and Meraki also patched.

#Cisco #SmartLicensing #APIC #Meraki #CVE202676482 #CVE202620328 #PatchNow #Vulnerability

securityonline.info/cisco-lice

##

CVE-2026-76472
(8.8 HIGH)

EPSS: 0.12%

updated 2026-10-08T20:08:45.857000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-76472 are related to issues with improper neutralization of special elemen

thehackerwire@mastodon.social at 2026-10-07T18:17:11.000Z ##

🟠 CVE-2026-76472 - High (8.8)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multipl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76470
(8.8 HIGH)

EPSS: 0.18%

updated 2026-10-08T20:08:45.857000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76470 are related to incorrect calculation issues that are grouped

thehackerwire@mastodon.social at 2026-10-07T18:15:52.000Z ##

🟠 CVE-2026-76470 - High (8.8)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses mult...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76486
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-10-08T20:08:45.857000

1 posts

A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a Denial-of-Service (DoS) on an affected device. This vulnerability is due to improper input validation of IP traffic when the NGOAM feature is enabled. An attacker c

thehackerwire@mastodon.social at 2026-10-07T17:30:50.000Z ##

🔴 CVE-2026-76486 - Critical (9.8)

A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a Denial-of-Serv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76501
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-10-08T20:08:45.857000

1 posts

A vulnerability in the Segment Routing over IPv6 (SRv6) Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) on an affected device. This vulnerability is due to improper input validation of IP traffic when the NGOAM and SR

thehackerwire@mastodon.social at 2026-10-07T17:22:00.000Z ##

🔴 CVE-2026-76501 - Critical (9.8)

A vulnerability in the Segment Routing over IPv6 (SRv6) Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privilege...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107384
(8.1 HIGH)

EPSS: 0.45%

updated 2026-10-08T19:42:25

1 posts

### Description With the non-default permitSetMultiParamEntries option enabled, an object passed as a query parameter is expanded into a SET clause, each key becoming a column name. The three code paths implementing that expansion built the backtick-quoted identifier by hand and wrote the key out unescaped, while only the value was escaped. A key containing a backtick therefore closed the identif

thehackerwire@mastodon.social at 2026-10-08T19:45:55.000Z ##

🟠 CVE-2026-107384 - High (8.1)

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. From 3.2.0 until 3.2.5, 3.3.4, 3.4.7, and 3.5.4, applications that enable permitSetMultiParamEntries can pass objects whose keys are exp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2015-5477
(7.5 HIGH)

EPSS: 91.81%

updated 2026-10-08T18:32:53

3 posts

named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.

8 repos

https://github.com/xycloops123/TKEY-remote-DoS-vulnerability-exploit

https://github.com/hmlio/vaas-cve-2015-5477

https://github.com/elceef/tkeypoc

https://github.com/ilanyu/cve-2015-5477

https://github.com/knqyf263/cve-2015-5477

https://github.com/likekabin/ShareDoc_cve-2015-5477

https://github.com/robertdavidgraham/cve-2015-5477

https://github.com/tintinweb/pub

hacksgr@mastodon.social at 2026-10-09T13:39:03.000Z ##

CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog after their use by China-linked Flax Typhoon: ProFTPD (CVE-2015-3306), ONLYOFFICE Docs (CVE-2021-3199), Strapi (CVE-2023-22894), Apache Struts (CVE-2016-3081) and ISC BIND (CVE-2015-5477).

The wider operations targeted eight vulnerabilities to gain initial access to organizations and remove sensitive data.

US federal agencies must install require…

en.hacks.gr/i-cisa-prosthetei-

#FlaxTyphoon #ProFTPD #ONLYOFFICE #ISC_BIND

##

secdb@infosec.exchange at 2026-10-08T19:00:11.000Z ##

🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3306 (secdb.nttzen.cloud/cve/detail/)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: proftpd.org/ ; lists.debian.org/debian-securi ; lists.opensuse.org/archives/li ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5477 (secdb.nttzen.cloud/cve/detail/)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: web.archive.org/web/2015072901 ; access.redhat.com/errata/RHSA-; supportportal.juniper.net/s/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2016-3081 (secdb.nttzen.cloud/cve/detail/)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: cwiki.apache.org/confluence/di ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-3199 (secdb.nttzen.cloud/cve/detail/)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; github.com/ONLYOFFICE/Document ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2023-22894 (secdb.nttzen.cloud/cve/detail/)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: strapi.io/blog/security-disclo ; github.com/strapi/strapi/relea ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261008 #cisa20261008 #cve_2015_3306 #cve_2015_5477 #cve_2016_3081 #cve_2021_3199 #cve_2023_22894 #cve20153306 #cve20155477 #cve20163081 #cve20213199 #cve202322894

##

cisakevtracker@mastodon.social at 2026-10-08T18:00:57.000Z ##

CVE ID: CVE-2015-5477
Vendor: ISC
Product: BIND
Date Added: 2026-10-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

hacksgr@mastodon.social at 2026-10-09T13:39:03.000Z ##

CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog after their use by China-linked Flax Typhoon: ProFTPD (CVE-2015-3306), ONLYOFFICE Docs (CVE-2021-3199), Strapi (CVE-2023-22894), Apache Struts (CVE-2016-3081) and ISC BIND (CVE-2015-5477).

The wider operations targeted eight vulnerabilities to gain initial access to organizations and remove sensitive data.

US federal agencies must install require…

en.hacks.gr/i-cisa-prosthetei-

#FlaxTyphoon #ProFTPD #ONLYOFFICE #ISC_BIND

##

secdb@infosec.exchange at 2026-10-08T19:00:11.000Z ##

🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3306 (secdb.nttzen.cloud/cve/detail/)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: proftpd.org/ ; lists.debian.org/debian-securi ; lists.opensuse.org/archives/li ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5477 (secdb.nttzen.cloud/cve/detail/)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: web.archive.org/web/2015072901 ; access.redhat.com/errata/RHSA-; supportportal.juniper.net/s/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2016-3081 (secdb.nttzen.cloud/cve/detail/)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: cwiki.apache.org/confluence/di ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-3199 (secdb.nttzen.cloud/cve/detail/)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; github.com/ONLYOFFICE/Document ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2023-22894 (secdb.nttzen.cloud/cve/detail/)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: strapi.io/blog/security-disclo ; github.com/strapi/strapi/relea ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261008 #cisa20261008 #cve_2015_3306 #cve_2015_5477 #cve_2016_3081 #cve_2021_3199 #cve_2023_22894 #cve20153306 #cve20155477 #cve20163081 #cve20213199 #cve202322894

##

cisakevtracker@mastodon.social at 2026-10-08T18:02:00.000Z ##

CVE ID: CVE-2015-3306
Vendor: ProFTPD
Product: ProFTPD
Date Added: 2026-10-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2021-3199
(9.8 CRITICAL)

EPSS: 14.55%

updated 2026-10-08T18:32:52

3 posts

Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.

hacksgr@mastodon.social at 2026-10-09T13:39:03.000Z ##

CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog after their use by China-linked Flax Typhoon: ProFTPD (CVE-2015-3306), ONLYOFFICE Docs (CVE-2021-3199), Strapi (CVE-2023-22894), Apache Struts (CVE-2016-3081) and ISC BIND (CVE-2015-5477).

The wider operations targeted eight vulnerabilities to gain initial access to organizations and remove sensitive data.

US federal agencies must install require…

en.hacks.gr/i-cisa-prosthetei-

#FlaxTyphoon #ProFTPD #ONLYOFFICE #ISC_BIND

##

secdb@infosec.exchange at 2026-10-08T19:00:11.000Z ##

🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3306 (secdb.nttzen.cloud/cve/detail/)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: proftpd.org/ ; lists.debian.org/debian-securi ; lists.opensuse.org/archives/li ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5477 (secdb.nttzen.cloud/cve/detail/)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: web.archive.org/web/2015072901 ; access.redhat.com/errata/RHSA-; supportportal.juniper.net/s/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2016-3081 (secdb.nttzen.cloud/cve/detail/)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: cwiki.apache.org/confluence/di ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-3199 (secdb.nttzen.cloud/cve/detail/)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; github.com/ONLYOFFICE/Document ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2023-22894 (secdb.nttzen.cloud/cve/detail/)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: strapi.io/blog/security-disclo ; github.com/strapi/strapi/relea ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261008 #cisa20261008 #cve_2015_3306 #cve_2015_5477 #cve_2016_3081 #cve_2021_3199 #cve_2023_22894 #cve20153306 #cve20155477 #cve20163081 #cve20213199 #cve202322894

##

cisakevtracker@mastodon.social at 2026-10-08T18:01:44.000Z ##

CVE ID: CVE-2021-3199
Vendor: ONLYOFFICE
Product: Docs
Date Added: 2026-10-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-104077
(7.8 HIGH)

EPSS: 0.35%

updated 2026-10-08T18:32:31

1 posts

Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability that allows attackers to craft malicious Markdown notes exploiting insufficient sanitization of the data-background-iframe attribute, which bypasses DOMPurify and is processed by the bundled Reveal.js 4.3.1 within the Slides core plugin, allowing a javascript: URL to execute in the resulting background iframe. Because No

thehackerwire@mastodon.social at 2026-10-08T17:31:44.000Z ##

🟠 CVE-2026-104077 - High (7.8)

Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability that allows attackers to craft malicious Markdown notes exploiting insufficient sanitization of the data-background-iframe attribute, which bypasses DOMPurify and is pro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107377
(7.5 HIGH)

EPSS: 0.45%

updated 2026-10-08T17:58:02

1 posts

## Summary When processing an attacker-controlled Protobuf schema, vulnerable versions of `datamodel-code-generator` could write a generated weak-import stub outside the intended `__weak_imports__` temporary directory. Absolute import paths and relative paths containing `..` could escape this directory. An attacker could create directories and new files at locations writable by the process. Rela

thehackerwire@mastodon.social at 2026-10-08T18:30:33.000Z ##

🟠 CVE-2026-107377 - High (7.5)

datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.81.0, an attacker-controlled Protobuf schema can supply absolute or parent-directory paths captured by WEAK_IMPORT_PATTERN and consumed by _write_mi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107375
(8.8 HIGH)

EPSS: 0.34%

updated 2026-10-08T17:40:37

1 posts

# SQL Injection in the `sort` Parameter of JHipster-Generated Reactive (WebFlux + R2DBC) Applications - **Product**: jhipster/generator-jhipster (npm package `generator-jhipster`) - **Affected versions**: v7.0.0 through v9.2.0 - **Component**: generated reactive-application code, template `EntityManager_reactive.java.ejs` - **Report date**: 2026-08-29 --- ## 1. Summary Every reactive (Spring

thehackerwire@mastodon.social at 2026-10-08T18:30:43.000Z ##

🟠 CVE-2026-107375 - High (8.8)

JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures. From 7.0.0 until 9.4.0, reactive applications generated with Spring WebFlux, Spring Data R2DBC, and a SQL database ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107302
(7.5 HIGH)

EPSS: 0.43%

updated 2026-10-08T17:40:11

1 posts

### Impact A truncated `map32` header causes an out-of-bounds buffer read and throws `RangeError` instead of `IncompleteBufferError`. Applications that rely on `IncompleteBufferError` to wait for additional bytes may terminate a request, stream, or worker unexpectedly. No adjacent memory is disclosed because the buffer implementation checks bounds. ### Patches The decoder now validates the comp

thehackerwire@mastodon.social at 2026-10-08T18:46:00.000Z ##

🟠 CVE-2026-107302 - High (7.5)

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the decoder reads the four-byte length of a map32 value before validating that the complete five-byte header is available. A truncated map32 header therefore caus...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107300
(7.5 HIGH)

EPSS: 0.43%

updated 2026-10-08T17:40:07

1 posts

### Impact The streaming decoder recursively invokes itself for every complete value remaining in a chunk. A single chunk containing many small valid MessagePack values can exhaust the JavaScript call stack and interrupt the process or stream. ### Patches The streaming decoder now drains concatenated values iteratively with constant call-stack depth. ### Workarounds Limit the number of Messag

thehackerwire@mastodon.social at 2026-10-08T17:30:20.000Z ##

🟠 CVE-2026-107300 - High (7.5)

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invokes itself for each complete MessagePack value remaining in a chunk. A remote peer can send one chunk containing many small ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107352
(7.7 HIGH)

EPSS: 0.20%

updated 2026-10-08T17:26:22.830000

1 posts

Missing authorization checks in Amazon Athena engine version 3 request handling could have allowed an authenticated user to read limited query metadata (AWS account identifiers and SQL statement text) from other AWS accounts. Query results, credentials, and Amazon S3 data were not affected. AWS remediated the issue on September 1, 2026, and has confirmed no customer metadata was accessed. No custo

thehackerwire@mastodon.social at 2026-10-07T21:31:18.000Z ##

🟠 CVE-2026-107352 - High (7.7)

Missing authorization checks in Amazon Athena engine version 3 request handling could have allowed an authenticated user to read limited query metadata (AWS account identifiers and SQL statement text) from other AWS accounts. Query results, creden...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92414
(0 None)

EPSS: 0.62%

updated 2026-10-08T17:26:22.830000

1 posts

: Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit. Jackrabbit WebDAV server attaches a cached authenticated session on any Lock-Token/TransactionId/SubscriptionId/If-header field token match with no credential check. This issue affects Apache Jackrabbit: from 2.23.0 through 2.23.5, from 2.22.0 through 2.22.4, from 2.20.0 through 2.20.17. Users ar

CVE-2026-95606
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-10-08T17:24:31.040000

2 posts

Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Events Calendar allows Object Injection. This issue affects The Events Calendar: from n/a through 6.17.4.

offseq@infosec.exchange at 2026-10-08T00:00:35.000Z ##

CVE-2026-95606: CRITICAL deserialization of untrusted data in The Events Calendar (<=6.17.4) enables remote object injection & code execution. No patch confirmed — review vendor advisory. radar.offseq.com/threat/deseri #OffSeq #WordPress #Vulnerability #CVE202695606

##

thehackerwire@mastodon.social at 2026-10-07T17:20:46.000Z ##

🔴 CVE-2026-95606 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Events Calendar allows Object Injection.

This issue affects The Events Calendar: from n/a through 6.17.4.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107295
(7.6 HIGH)

EPSS: 0.16%

updated 2026-10-08T17:16:37

1 posts

### Summary The Pydantic AI development web chat UI (`Agent.to_web()`, `clai web`) did not check the content type of requests to its chat endpoint. This allowed a website visited by a developer to submit a request to a chat UI running on that developer's machine, causing the served agent to run and to execute its tools with the privileges and credentials of the local process. Binding the web UI

thehackerwire@mastodon.social at 2026-10-08T17:30:30.000Z ##

🟠 CVE-2026-107295 - High (7.6)

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 1.107.4 and 2.28.0, the Agent.to_web() and clai web development chat endpoint has missing request content-type validation. A webs...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107212
(7.5 HIGH)

EPSS: 0.34%

updated 2026-10-08T16:50:14

1 posts

### Summary A worksheet whose `<row r="...">` number is far past Excel's 1,048,576-row limit makes `File.GetRows` and the `Rows` iterator loop once for every missing row. The row limit is checked in `Rows.Next`, but not in `Rows.Columns`, which also reads `<row>` elements. A 1.5 KB file with `<row r="231999999999940">` after an ordinary first row keeps `GetRows` busy for an estimated 11 days (abo

thehackerwire@mastodon.social at 2026-10-07T19:00:55.000Z ##

🟠 CVE-2026-107212 - High (7.5)

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, Rows.Columns accepts a look-ahead row number above TotalRows without applying the limit enforced by Rows.Next. File.GetRows relies on Row...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107214
(7.5 HIGH)

EPSS: 0.27%

updated 2026-10-08T16:31:32

1 posts

### Summary Any file whose first 8 bytes are the OLE compound-file signature (`D0 CF 11 E0 A1 B1 1A E1`) is routed by `OpenFile`/`OpenReader`/`OpenBytes` → `openReaderAt` → `Decrypt`. The version dispatch only guarantees `len(EncryptionInfo) >= 4` before handing attacker-controlled `EncryptionInfo`/`EncryptedPackage` buffers to `standardDecrypt`/`agileDecrypt`, and no callee validates structure.

thehackerwire@mastodon.social at 2026-10-07T18:30:53.000Z ##

🟠 CVE-2026-107214 - High (7.5)

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, the decryption dispatch performs insufficient structural and parameter validation before standard and agile decryptors slice, index, allo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71895
(7.1 HIGH)

EPSS: 0.22%

updated 2026-10-08T15:33:58

1 posts

An authorization vulnerability in Apache DolphinScheduler allows authenticated non-admin users to retrieve Kubernetes configuration data intended for administrator-managed cluster configuration. The exposed kubeconfig data contains credentials that may allow users to authenticate directly to the Kubernetes API outside DolphinScheduler. The impact depends on the permissions granted to the disclo

CVE-2026-9209
(9.8 CRITICAL)

EPSS: 0.69%

updated 2026-10-08T15:33:16

1 posts

mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the backing Sybase SQL Anywhere database using DBA/sysadmin privileges with no server-side authentication enforced beyond a client-side sessionStorage flag. Attacke

1 repos

https://github.com/MS-0x404/CVE-2026-92099

thehackerwire@mastodon.social at 2026-10-08T17:32:03.000Z ##

🔴 CVE-2026-9209 - Critical (9.8)

mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the backing...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93017
(7.7 HIGH)

EPSS: 0.21%

updated 2026-10-08T15:33:15

1 posts

The `insights-operator-gather` ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or resourceNames restriction — therefore, access to every secret in every namespace in the cluster. Ref: https://github.com/openshift/insights-operator/blob/8f15e3157ff09f54ab22801f5b21da35a195cc6d/manifests/03-clusterrole.yaml#L368-L373 ``` - apiGroups:

thehackerwire@mastodon.social at 2026-10-08T19:46:54.000Z ##

🟠 CVE-2026-93017 - High (7.7)

The `insights-operator-gather` ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or resourceNames restriction — therefore, access to every secret in every namespace in the cluster.

...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14992
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-10-08T15:33:11

1 posts

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 vulnerable to buffer overflow.

thehackerwire@mastodon.social at 2026-10-08T20:16:18.000Z ##

🔴 CVE-2026-14992 - Critical (9.8)

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 vulnerable to buffer overflow.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14497
(8.1 HIGH)

EPSS: 0.59%

updated 2026-10-08T15:33:10

1 posts

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote authenticated attacker to bypass security restrictions due to improper verification of cryptographic signatures.

thehackerwire@mastodon.social at 2026-10-08T20:16:28.000Z ##

🟠 CVE-2026-14497 - High (8.1)

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote authenticated attacker to bypass security restrictions due to improper verification of cryptogr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16340
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-10-08T15:33:05

2 posts

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write in the RFC2047 encoded-word parser.

DailyCyberSecurity@infosec.exchange at 2026-10-08T14:43:26.000Z ##

IBM fixes 23 IBM DataPower Gateway vulnerabilities, including critical RCE flaws CVE-2026-15762 and CVE-2026-16340. Upgrade to 11.0.0.3 now.

#IBM #DataPower #APIGateway #CVE202615762 #CVE202616340 #CVE202614990 #RCE #Vulnerability

securityonline.info/ibm-datapo

##

offseq@infosec.exchange at 2026-10-08T13:30:12.000Z ##

CVE-2026-16340 (CRITICAL, CVSS 9.8): IBM DataPower Gateway 10.5.0.0 – 10.5.0.22, 10.6.0.0 – 10.6.0.10, 10.6.1 – 10.6.6, 11.0.0.0 – 11.0.0.2 vulnerable to remote code execution via out-of-bounds write. Patch priority high. radar.offseq.com/threat/cve-20 #OffSeq #IBM #Vuln #Cybersecurity

##

CVE-2026-71896
(6.5 MEDIUM)

EPSS: 0.26%

updated 2026-10-08T15:32:55

1 posts

An authorization vulnerability in Apache DolphinScheduler allows authenticated users to retrieve other users' account information through the /dolphinscheduler/users/list-all endpoint without the required permissions. The endpoint fails to enforce the necessary authorization checks before returning user account information. As a result, an authenticated user can access account information they

CVE-2026-12260(CVSS UNKNOWN)

EPSS: 0.23%

updated 2026-10-08T09:32:03

1 posts

SQL injection in the NetBoard CRM demo platform; specifically, the vulnerable component is the ‘user-name’ POST parameter in the ‘/module/auth/recovery.php’ endpoint. The parameter is vulnerable to blind attacks based on Boolean, error, time-based and UNION techniques. Exploitation allows attackers to extract confidential information (such as the version and type of backend used), alter data or fu

offseq@infosec.exchange at 2026-10-08T09:00:27.000Z ##

CVE-2026-12260: CRITICAL SQL injection in NetBoard CRM Demo (user-name param in /module/auth/recovery.php). Exploitable via multiple SQLi techniques — data theft or CRM compromise possible. Mitigation needed now. radar.offseq.com/threat/cve-20 #OffSeq #SQLi #NetBoardCRM #CVE202612260

##

CVE-2026-107459
(9.8 CRITICAL)

EPSS: 1.47%

updated 2026-10-08T06:31:28

1 posts

The SecuShare Pro developed by Openfind has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.

offseq@infosec.exchange at 2026-10-08T07:30:25.000Z ##

Openfind SecuShare Pro v4 is affected by CVE-2026-107459 (CRITICAL, CVSS 9.3) — unauthenticated OS command injection allows remote code execution. No patch yet; restrict access and monitor activity. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Vuln

##

CVE-2026-17609
(9.1 CRITICAL)

EPSS: 0.31%

updated 2026-10-08T06:31:27

1 posts

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 6.3.316 via the submit_form function. This is due to insufficient validation of attacker-controlled JSON field declarations against the actual form schema, combined with a non-effective ABSPATH guard that dirname() trivially bypasses by stripping the t

offseq@infosec.exchange at 2026-10-08T06:00:26.000Z ##

CRITICAL: CVE-2026-17609 in Super Forms – Drag & Drop Form Builder (<=6.3.316) lets unauthenticated attackers recursively delete server directories if 'Delete files after form submissions' is enabled. Disable it! radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #Infosec

##

CVE-2025-64393
(0 None)

EPSS: 0.36%

updated 2026-10-08T04:16:55.397000

3 posts

This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execute arbitrary code as SYSTEM on the backup server.

security_crawler_carl@infosec.exchange at 2026-10-09T09:22:31.000Z ##

🏆 New Achievement! The Keys to the Vault Were Under the Mat!

Magnificent. Truly, someone looked at a backup server — the one room that holds the skeleton keys to your entire infrastructure — and said, let's let low-privileged users knock it over. CVE-2025-64393 is a critical remote code execution flaw in Veeam Backup & Replication version 12, and it hands full control of the backup server to anyone with the Backup Viewer role. (1/3)

##

beyondmachines1@infosec.exchange at 2026-10-09T09:01:49.000Z ##

Veeam Patches Critical Remote Code Execution Flaw in Backup & Replication Software

Veeam patched four vulnerabilities in Backup & Replication version 12, including a critical RCE flaw (CVE-2025-64393) that allows low-privileged users to take control of the backup server.

**If you use Veeam Backup & Replication version 12, update ASAP to 12.3.2 P4 (build 12.3.2.4934). Review and remove the Backup Viewer role from anyone who doesn't really need it, and keep your backup servers isolated from the rest of the network.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

ssvc@infosec.exchange at 2026-10-07T16:43:15.000Z ##

Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2 P4 from 10/6

CVE-2025-64393 (9.4 critical) low-privileged RCE

veeam.com/kb4934

#veeam #cve

##

CVE-2026-107161
(7.5 HIGH)

EPSS: 0.24%

updated 2026-10-07T21:33:37

1 posts

A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-

thehackerwire@mastodon.social at 2026-10-07T20:45:34.000Z ##

🟠 CVE-2026-107161 - High (7.5)

A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76266
(7.7 HIGH)

EPSS: 0.12%

updated 2026-10-07T21:33:30

1 posts

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15 on Linux, a local user who can run commands as the user account running Splunk Enterprise could cause an affected Linux package upgrade to run attacker-controlled operating-system commands with root privileges. The vulnerability is possible because the Linux package maintainer script trusts existing Splunk Enterprise installat

thehackerwire@mastodon.social at 2026-10-07T21:30:58.000Z ##

🟠 CVE-2026-76266 - High (7.7)

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15 on Linux, a local user who can run commands as the user account running Splunk Enterprise could cause an affected Linux package upgrade to run attacker-controlled operating-sy...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107219
(7.5 HIGH)

EPSS: 0.34%

updated 2026-10-07T20:23:23

1 posts

Opening a file whose first eight bytes are the OLE magic number sends excelize down the decryption path whether or not the caller set a password, or supports encrypted workbooks at all. `openReaderAt` (excelize.go:198-215) branches on the header alone, and `agileDecrypt` calls `convertPasswdToKey` before the verifier hash is checked, so the key-derivation loop runs `spinCount` times regardless. `

thehackerwire@mastodon.social at 2026-10-07T19:45:41.000Z ##

🟠 CVE-2026-107219 - High (7.5)

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, agile decryption accepts an attacker-controlled spinCount and performs that many password-key derivation iterations before verifier valid...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76471
(9.8 CRITICAL)

EPSS: 0.52%

updated 2026-10-07T18:32:21

3 posts

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device.&nbsp; The vulnerability is due to insufficient input validation of data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP req

AAKL@infosec.exchange at 2026-10-08T15:52:31.000Z ##

Two more Cisco advisories today addressing critical vulnerabilities:

- CVE-2026-76471: Cisco NX-OS Software NX-API Remote Code Execution Vulnerability sec.cloudapps.cisco.com/securi

- CVE-2026-76463, CVE-2026-76464, and CVE-2026-76467: Cisco Meraki Security Hardening Release: October 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #Cisco #vulnerability

##

thehackerwire@mastodon.social at 2026-10-07T18:16:02.000Z ##

🔴 CVE-2026-76471 - Critical (9.8)

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device.&nbsp;

The vulnerabi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-10-07T17:26:58.000Z ##

Cisco NX-OS vulnerabilities fixed, including critical NX-API RCE flaw CVE-2026-76471 and CVE-2026-76455, across Nexus, MDS and UCS gear. Patch now.

#Cisco #NXOS #Nexus #CVE202676471 #CVE202676455 #RCE #NetworkSecurity #Vulnerability

securityonline.info/cisco-nx-o

##

CVE-2026-76465
(9.8 CRITICAL)

EPSS: 0.45%

updated 2026-10-07T18:32:21

3 posts

A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute arbitrary code with&nbsp;root privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper validation

offseq@infosec.exchange at 2026-10-08T03:00:24.000Z ##

CVE-2026-76465 (CRITICAL, CVSS 9.8) in Cisco NX-OS for Nexus 3000/9000: Remote, unauthenticated attackers can gain root or cause DoS via crafted MPLS echo-requests. Patch status unknown — check Cisco advisories. radar.offseq.com/threat/a-vuln #OffSeq #Cisco #Vulnerability #CVE202676465

##

thehackerwire@mastodon.social at 2026-10-07T19:02:10.000Z ##

🔴 CVE-2026-76465 - Critical (9.8)

A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute arbit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-10-07T17:18:30.000Z ##

Four critical Cisco Nexus vulnerabilities, including CVE-2026-76485 and CVE-2026-76465 (CVSS 9.8), allow root RCE on NX-OS switches. Patch now.

#Cisco #Nexus #NXOS #CVE202676485 #CVE202676465 #RCE #NetworkSecurity #Vulnerability

securityonline.info/cisco-nexu

##

CVE-2026-76485
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-10-07T18:32:21

3 posts

A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a Denial-of-Service (DoS) on an affected device. This vulnerability is due to improper input validation of IP traffic when the NGOAM feature is enabled. An attacker cou

offseq@infosec.exchange at 2026-10-08T01:30:25.000Z ##

CVE-2026-76485: CRITICAL (CVSS 9.8) vulnerability in Cisco NX-OS NGOAM allows remote code execution or DoS via crafted packets. Disable NGOAM if unused. Awaiting official patch. Details: radar.offseq.com/threat/a-vuln #OffSeq #Cisco #CVE202676485 #Infosec

##

thehackerwire@mastodon.social at 2026-10-07T17:22:20.000Z ##

🔴 CVE-2026-76485 - Critical (9.8)

A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a Denial-of-Serv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-10-07T17:18:30.000Z ##

Four critical Cisco Nexus vulnerabilities, including CVE-2026-76485 and CVE-2026-76465 (CVSS 9.8), allow root RCE on NX-OS switches. Patch now.

#Cisco #Nexus #NXOS #CVE202676485 #CVE202676465 #RCE #NetworkSecurity #Vulnerability

securityonline.info/cisco-nexu

##

CVE-2026-76458
(8.6 HIGH)

EPSS: 0.28%

updated 2026-10-07T18:32:21

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76458 are related to improper handling of exceptional conditions issues t

thehackerwire@mastodon.social at 2026-10-07T19:46:24.000Z ##

🟠 CVE-2026-76458 - High (8.6)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76483
(9.1 CRITICAL)

EPSS: 0.22%

updated 2026-10-07T18:32:21

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. &nbsp; The vulnerabilities tracked by CV

thehackerwire@mastodon.social at 2026-10-07T19:01:36.000Z ##

🔴 CVE-2026-76483 - Critical (9.1)

As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-96335
(7.5 HIGH)

EPSS: 0.20%

updated 2026-10-07T18:32:21

1 posts

Missing Authorization vulnerability in WPMU DEV Forminator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Forminator: from n/a through 1.57.2.

thehackerwire@mastodon.social at 2026-10-07T18:30:42.000Z ##

🟠 CVE-2026-96335 - High (7.5)

Missing Authorization vulnerability in WPMU DEV Forminator allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects Forminator: from n/a through 1.57.2.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76480
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-10-07T18:32:21

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-

thehackerwire@mastodon.social at 2026-10-07T18:17:20.000Z ##

🔴 CVE-2026-76480 - Critical (9.8)

As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76499
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-10-07T18:32:21

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76499 are related to improper

thehackerwire@mastodon.social at 2026-10-07T17:31:09.000Z ##

🔴 CVE-2026-76499 - Critical (9.8)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in softwar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76498
(9.8 CRITICAL)

EPSS: 0.30%

updated 2026-10-07T18:32:21

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76498 are related to improper

thehackerwire@mastodon.social at 2026-10-07T17:31:00.000Z ##

🔴 CVE-2026-76498 - Critical (9.8)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in softwar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76484
(8.8 HIGH)

EPSS: 0.28%

updated 2026-10-07T18:32:21

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-

thehackerwire@mastodon.social at 2026-10-07T17:22:11.000Z ##

🟠 CVE-2026-76484 - High (8.8)

As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-95534
(8.8 HIGH)

EPSS: 0.29%

updated 2026-10-07T18:32:21

1 posts

Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Object Injection. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.19.

thehackerwire@mastodon.social at 2026-10-07T17:20:55.000Z ##

🟠 CVE-2026-95534 - High (8.8)

Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Object Injection.

This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-95605
(9.3 CRITICAL)

EPSS: 0.25%

updated 2026-10-07T18:32:21

1 posts

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Passionate Programmer Peter WP Data Access allows Blind SQL Injection. This issue affects WP Data Access: from n/a through 5.5.82.

thehackerwire@mastodon.social at 2026-10-07T17:20:37.000Z ##

🔴 CVE-2026-95605 - Critical (9.3)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Passionate Programmer Peter WP Data Access allows Blind SQL Injection.

This issue affects WP Data Access: from n/a through 5.5.82.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76464
(9.6 CRITICAL)

EPSS: 0.19%

updated 2026-10-07T18:32:20

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by this CVE-2026-76464 are related to buffer management issues that are grouped

AAKL@infosec.exchange at 2026-10-08T15:52:31.000Z ##

Two more Cisco advisories today addressing critical vulnerabilities:

- CVE-2026-76471: Cisco NX-OS Software NX-API Remote Code Execution Vulnerability sec.cloudapps.cisco.com/securi

- CVE-2026-76463, CVE-2026-76464, and CVE-2026-76467: Cisco Meraki Security Hardening Release: October 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #Cisco #vulnerability

##

thehackerwire@mastodon.social at 2026-10-07T19:01:48.000Z ##

🔴 CVE-2026-76464 - Critical (9.6)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses mult...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76455
(9.8 CRITICAL)

EPSS: 0.28%

updated 2026-10-07T18:32:20

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76455 are related to improper access control issues that are grouped unde

thehackerwire@mastodon.social at 2026-10-07T20:16:00.000Z ##

🔴 CVE-2026-76455 - Critical (9.8)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-10-07T17:26:58.000Z ##

Cisco NX-OS vulnerabilities fixed, including critical NX-API RCE flaw CVE-2026-76471 and CVE-2026-76455, across Nexus, MDS and UCS gear. Patch now.

#Cisco #NXOS #Nexus #CVE202676471 #CVE202676455 #RCE #NetworkSecurity #Vulnerability

securityonline.info/cisco-nx-o

##

CVE-2026-76468
(8.2 HIGH)

EPSS: 0.23%

updated 2026-10-07T18:32:20

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76468 are related to improper input validation that are grouped unde

thehackerwire@mastodon.social at 2026-10-07T19:16:04.000Z ##

🟠 CVE-2026-76468 - High (8.2)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses mult...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20328
(9.1 CRITICAL)

EPSS: 0.52%

updated 2026-10-07T18:32:14

2 posts

A vulnerability in the web-based management interface of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to gain unauthorized access to an affected application. This vulnerability is due to improper checks during the password reset process. An attacker could exploit this vulnerability by sending a malicious reques

thehackerwire@mastodon.social at 2026-10-07T21:16:31.000Z ##

🔴 CVE-2026-20328 - Critical (9.1)

A vulnerability in the web-based management interface of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to gain unauthorized access to an affected application.

...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-10-07T17:36:18.000Z ##

Cisco License On-Prem vulnerabilities include CVSS 10 flaw CVE-2026-76482 and password reset bug CVE-2026-20328. APIC and Meraki also patched.

#Cisco #SmartLicensing #APIC #Meraki #CVE202676482 #CVE202620328 #PatchNow #Vulnerability

securityonline.info/cisco-lice

##

CVE-2026-76500
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-10-07T18:32:14

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. &nbsp; The vulnerabilities tracked by CVE-2026-76500 are related to is

thehackerwire@mastodon.social at 2026-10-07T18:15:43.000Z ##

🔴 CVE-2026-76500 - Critical (9.8)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in softwar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107205
(8.6 HIGH)

EPSS: 0.39%

updated 2026-10-07T18:32:14

1 posts

LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess coordinator that allows remote unauthenticated attackers to access its HTTP fleet control API listening on all interfaces by default. Attackers can register or deregister instances via /instances, overwrite quotas via /quota endpoints, inject events via /events, and enumerate /directory/keys to disrupt cachin

thehackerwire@mastodon.social at 2026-10-07T16:49:38.000Z ##

🟠 CVE-2026-107205 - High (8.6)

LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess coordinator that allows remote unauthenticated attackers to access its HTTP fleet control API listening on all interfaces by default. Attackers can register ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-106510
(7.7 HIGH)

EPSS: 0.44%

updated 2026-10-07T18:17:16.660000

1 posts

Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by remote code execution via crafted markdown_extensions in techdocs mkdocs.yml. An authenticated user who can register catalog entities can provide a crafted mkdocs.yml causing arbitrary OS command execution on the TechDocs build host when the docs are built. Thi

thehackerwire@mastodon.social at 2026-10-07T17:05:36.000Z ##

🟠 CVE-2026-106510 - High (7.7)

Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by remote code execution via crafted markdown_extensions in techdocs mkdocs.yml. An authenticated user who can ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104286
(9.8 CRITICAL)

EPSS: 2.20%

updated 2026-10-07T18:17:15.240000

1 posts

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

2 repos

https://github.com/techupdate24/fortimail-zero-day-cve-2026-104286

https://github.com/ShadowForge-Cyber/CVE-2026-104286-POC

PC_Fluesterer@social.tchncs.de at 2026-10-09T15:12:33.000Z ##

Schon wieder: Citrix, Fortinet, wer noch?

Fangen wir chronologisch an. Bereits am 1. Oktober hat Fortinet seine Kunden vor einer neuen Zero-Day Sicherheitslücke im "sicheren" E-Mail-Gateway FortiMail gewarnt, die bereits für Angriffe ausgenutzt wird. Die "Sicherheitslücke" CVE-2026-104286 (Risiko 9,8 von 10) kann durch speziell gedrechselte (crafted) Anfragen ausgenutzt werden. Der Angreifer kann dann eigene Dateien in das angegriffene System schreiben, was ihn zum ausführen eigenen Programmcodes befähigt.

Citrix fällt wieder einmal auf. Nur eine gute Woche nach den letzten Flicken gegen gefährliche - und bereits für Angriffe ausgenutzte - ... Weiterlesen:

pc-fluesterer.info/wordpress/2

#0day #closedsource #cybercrime #email #exploits #hersteller #politik #sicherheit #UnplugTrump #vorbeugen

##

CVE-2026-106501
(9.6 CRITICAL)

EPSS: 0.47%

updated 2026-10-07T17:16:49.597000

1 posts

Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensitive information exposure in scaffolder. An authenticated Backstage user who can read another user's Scaffolder task may receive internal execution data. In deployments where that data contains credentials for an external servic

offseq@infosec.exchange at 2026-10-08T04:30:25.000Z ##

CVE-2026-106501: @backstage/plugin-scaffolder-backend CRITICAL vuln (CVSS 9.6) allows authenticated users to access other users’ task data, incl. credentials. Patch to 4.1.0 now. Restrict task read perms as interim measure. radar.offseq.com/threat/plugin #OffSeq #Backstage #Vuln

##

CVE-2026-102255
(10.0 CRITICAL)

EPSS: 0.48%

updated 2026-10-07T16:17:32.440000

11 posts

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.

sayzard@mastodon.sayzard.org at 2026-10-09T16:45:36.000Z ##

Max severity SonicWall SMA1000 flaw now exploited in attacks

SonicWall SMA1000 원격접속 게이트웨이의 최대 심각도 취약점 CVE-2026-102255가 패치 공개 3일 만에 실제 공격 시도에 악용되고 있다. 인증되지 않은 원격 공격자는 WorkPlace/Extraweb 인터페이스의 조작된 OPTIONS 요청을 통해 내부 CouchDB(127.0.0.1:5984)에 도달하고, SSRF 방식으로 승인되지 않은 내부 작업을 수행할 수 있다. 인터넷에 노출된 SMA1000 인스턴스가 400개 이상 관측되며, 이 장비는 기업·MSSP·...

bleepingcomputer.com/news/secu

##

oversecurity@mastodon.social at 2026-10-09T13:51:04.000Z ##

Max severity SonicWall SMA1000 flaw now exploited in attacks

Attackers are exploiting a maximum-severity vulnerability in SonicWall SMA1000 appliances (CVE-2026-102255) that was patched on Tuesday, three days...

🔗️ [Bleepingcomputer] link.is.it/pvDc7j

##

jbhall56 at 2026-10-09T13:41:19.854Z ##

Tracked as CVE-2026-102255, the flaw affects the Appliance WorkPlace interface on SMA1000 6210, 7210, and 8200v models, but does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls. bleepingcomputer.com/news/secu

##

Analyst207@mastodon.social at 2026-10-09T13:02:56.000Z ##

SonicWall SMA1000 flaw exploited in targeted attacks

A critical vulnerability, CVE-2026-102255, in SonicWall SMA1000 appliances is being exploited in targeted attacks, putting sensitive internal functionality at risk. This maximum-severity flaw allows remote attackers to manipulate the appliance and perform unauthorized operations.

osintsights.com/sonicwall-sma1

#Sonicwall #Sma1000 #Cve2026102255 #VulnerabilityExploitation #RemoteCodeExecution

##

DailyCyberSecurity at 2026-10-09T10:55:44.246Z ##

Attackers target a critical SonicWall SMA1000 vulnerability in the wild. Apply vendor hotfixes to secure remote access gateways against CVE-2026-102255.

securityonline.info/sonicwall-

##

oversecurity@mastodon.social at 2026-10-09T13:51:04.000Z ##

Max severity SonicWall SMA1000 flaw now exploited in attacks

Attackers are exploiting a maximum-severity vulnerability in SonicWall SMA1000 appliances (CVE-2026-102255) that was patched on Tuesday, three days...

🔗️ [Bleepingcomputer] link.is.it/pvDc7j

##

jbhall56@infosec.exchange at 2026-10-09T13:41:19.000Z ##

Tracked as CVE-2026-102255, the flaw affects the Appliance WorkPlace interface on SMA1000 6210, 7210, and 8200v models, but does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls. bleepingcomputer.com/news/secu

##

DailyCyberSecurity@infosec.exchange at 2026-10-09T10:55:44.000Z ##

Attackers target a critical SonicWall SMA1000 vulnerability in the wild. Apply vendor hotfixes to secure remote access gateways against CVE-2026-102255.

#SonicWall #CVE2026102255 #CyberSecurity #InfoSec #SSRF

securityonline.info/sonicwall-

##

beyondmachines1@infosec.exchange at 2026-10-08T14:01:49.000Z ##

SonicWall Patches Critical Pre-Auth SSRF in SMA 1000 Series Appliances

SonicWall patched four vulnerabilities in its SMA 1000 series appliances, including a critical pre-authentication SSRF (CVE-2026-102255) with a CVSS score of 10.0. The flaws allow unauthenticated attackers to access internal services and authenticated users to execute arbitrary code.

**If you use SonicWall SMA 1000 series appliances (SMA 6210, SMA 7210 or SMA 8200v), update them ASAP to firmware 12.4.3-03670 or 12.5.0-03082 or newer. Make sure the management console is reachable only from trusted internal networks, and check the appliance logs for unusual activity, since these gateways are a favorite entry point for ransomware groups.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

censys@infosec.exchange at 2026-10-07T21:02:33.000Z ##

🚨 Rapid Response: SonicWall has patched a critical CVSS 10.0 pre-authentication SSRF in SMA1000 appliances (CVE-2026-102255).

Censys detects 5,966 Internet-exposed hosts and 39,310 web properties running SMA1000/Secure Mobile Access after excluding honeypot-labeled systems. This indicates product presence, not confirmed-vulnerable systems.

Full Censys ARC advisory: censys.com/advisory/cve-2026-1

#CensysARC #SonicWall #Vulnerability #CyberSecurity

##

ifin@infosec.exchange at 2026-10-07T18:39:28.000Z ##

Chat, is it bad if your zero-trust VPN device forwards network requests without auth? Asking for thousands of friends.

SonicWall SMA1000 devices have a SSRF vulnerability that needs patching.

ifin.network/t/cve-2026-102255

#IFIN #ThreatIntel #ThreatIntelligence

##

CVE-2026-62251
(8.1 HIGH)

EPSS: 0.34%

updated 2026-10-07T16:13:09

1 posts

### Summary The `V4StatisticsQuery` handler passes the user-supplied `rawquery` field directly to DuckDB without calling the `sqlvalidator.ValidateRawSQL` function used throughout the rest of the codebase. Any authenticated user can execute arbitrary SQL statements against all data accessible through the FlightSQL service. ### Details **`coordinator/handlers/statistics_v4.go` lines 74-107** — `V4

thehackerwire@mastodon.social at 2026-10-07T20:46:14.000Z ##

🟠 CVE-2026-62251 - High (8.1)

Homer is open source telecom observability software. Prior to version 11.0.283, the `V4StatisticsQuery` handler passes the user-supplied `rawquery` field directly to DuckDB without calling the `sqlvalidator.ValidateRawSQL` function used throughout...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62253
(9.8 CRITICAL)

EPSS: 0.42%

updated 2026-10-07T16:11:59

1 posts

### Summary Both JWT middleware functions (`JWTMiddleware` and `JWTMiddlewareV4`) immediately return `next(c)` when `jwtSecret == ""`. The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under `/api/v1`, `/api/v3`, and `/api/v4` are completely unauthenticated. ### Details **`coordinator/handlers/auth.go` lines 298-304:** ```go func (h *Auth) JWTMiddl

thehackerwire@mastodon.social at 2026-10-07T21:16:22.000Z ##

🔴 CVE-2026-62253 - Critical (9.8)

Homer is open source telecom observability software. Prior to version 11.0.283, both JWT middleware functions (`JWTMiddleware` and `JWTMiddlewareV4`) immediately return `next(c)` when `jwtSecret == ""`. The JWT secret defaults to an empty string. ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62176
(9.1 CRITICAL)

EPSS: 0.46%

updated 2026-10-07T16:05:54

1 posts

### Summary The `deploy/api.py` module generates Python server code by directly interpolating the `agents_file` parameter into an f-string that is then written to a file and executed via `subprocess.Popen()`. An attacker who controls the `agents_file` value (via CLI argument, configuration, or upstream API) can inject arbitrary Python code. ### Details `src/praisonai/praisonai/deploy/api.py` (li

thehackerwire@mastodon.social at 2026-10-07T20:46:05.000Z ##

🔴 CVE-2026-62176 - Critical (9.1)

PraisonAI is a multi-agent teams system. Prior to version 4.6.78, the `deploy/api.py` module generates Python server code by directly interpolating the `agents_file` parameter into an f-string that is then written to a file and executed via `subpr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-83540
(0 None)

EPSS: 0.34%

updated 2026-10-07T16:02:27.613000

1 posts

When password or public key authentication is used with the Windows port of wolfSSHd, the Windows logon token acquired for one authenticated connection is not released before a token is acquired for a subsequent connection, resulting in user login poisoning between connections. A less privileged user with a valid account on the server can exploit this to force a login as a more privileged user. Th

CVE-2026-59346
(9.3 CRITICAL)

EPSS: 0.26%

updated 2026-10-07T15:58:17.433000

2 posts

VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Affected versions: - VMware Workstation: 25H2, 26H1 (fixed in 26H1u1) - VMware Fusion: 25H2, 26H1 (fixed in 26H1u1)

1 repos

https://github.com/0xCyberstan/CVE-2026-59346-POC

guru@thecybersecguru.com at 2026-10-08T18:05:42.000Z ##

PoC Released for Critical VMware VMXNET3 Integer Overflow Flaw Enabling Guest-to-Host Code Execution (CVE-2026-59346)

CVE-2026-59346 affects VMware VMXNET3 and enables guest-to-host memory corruption. A public PoC crashes vmware-vmx. Patch Workstation and Fusion now

thecybersecguru.com/exploits/c

##

DailyCyberSecurity@infosec.exchange at 2026-10-08T02:17:27.000Z ##

A VMware VMXNET3 vulnerability, CVE-2026-59346 (CVSS 9.3), allows VM escape. Full details and PoC exploit code are now public. Patch to 26H1u1.

#VMware #VMXNET3 #CVE202659346 #VMEscape #Virtualization #Broadcom #PoC #Vulnerability

securityonline.info/vmware-vmx

##

CVE-2026-106558
(8.8 HIGH)

EPSS: 0.47%

updated 2026-10-07T15:52:18.453000

1 posts

Backstage is an open framework for building developer portals. Prior to 1.14.8, 1.15.6, and 2.0.1, the @backstage/plugin-techdocs-node package improperly validated mapping-style markdown_extensions configuration. An authenticated attacker who can register or influence an SCM-backed documentation source may bypass TechDocs sanitization and cause Python objects to be imported and instantiated in the

thehackerwire@mastodon.social at 2026-10-07T17:05:26.000Z ##

🟠 CVE-2026-106558 - High (8.8)

Backstage is an open framework for building developer portals. Prior to 1.14.8, 1.15.6, and 2.0.1, the @backstage/plugin-techdocs-node package improperly validated mapping-style markdown_extensions configuration. An authenticated attacker who can ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77214
(8.2 HIGH)

EPSS: 0.55%

updated 2026-10-07T15:32:08

1 posts

libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching t

thehackerwire@mastodon.social at 2026-10-07T17:05:14.000Z ##

🟠 CVE-2026-77214 - High (8.2)

libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated b...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107181
(8.1 HIGH)

EPSS: 0.34%

updated 2026-10-07T15:32:07

2 posts

Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the interpret: scheme handler to upload local files, including tdata session keys, to an attacker channel, enabling account takeover.

hacksgr@mastodon.social at 2026-10-09T10:04:05.000Z ##

Telegram Desktop’s CVE-2026-107181 affects versions before 7.2.9.

A specially crafted link opened outside Telegram could allow local-file theft; account takeover was possible if no local lock code was enabled.

Links opened inside Telegram were not affected.

The demonstrated attack used Windows and was not shown on macOS or Linux.

It also depended on specific group auto-download and invitation settings.

Te…

en.hacks.gr/provlima-sto-teleg

#TelegramDesktop #CVE2026107181 #FileTheft #AccountSecurity

##

DailyCyberSecurity@infosec.exchange at 2026-10-09T02:09:46.000Z ##

A critical Telegram Desktop account takeover vulnerability (CVE-2026-107181) exposes users to session hijacking. Exploit details and PoC are now public.

#Telegram #Cybersecurity #CVE2026107181 #AccountTakeover #PoC

securityonline.info/telegram-d

##

CVE-2026-21589(CVSS UNKNOWN)

EPSS: 1.77%

updated 2026-10-07T15:31:33

14 posts

h3. Summary This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires p

10 repos

https://github.com/murrez/CVE-2026-21589

https://github.com/watchtowrlabs/watchTowr-vs-Atlassian-CVE-2026-21589

https://github.com/MarcusProgram/CVE-2026-21589

https://github.com/renzi25031469/CVE-2026-21589

https://github.com/rxsklife/CVE-2026-21589

https://github.com/0xBlackash/CVE-2026-21589

https://github.com/BimBoxH4/CVE-2026-21589

https://github.com/ynsmroztas/AtlasSniper

https://github.com/tc4dy/CVE-2026-21589-PoC-Exploit

https://github.com/aduli198/CVE-2026-21589

DailyCyberSecurity at 2026-10-09T12:56:36.009Z ##

Hackers rapidly exploit the Atlassian vulnerability CVE-2026-21589. Learn how this critical flaw compromises Jira, Confluence, and Bitbucket security.

meterpreter.org/atlassian-cve-

##

DailyCyberSecurity@infosec.exchange at 2026-10-09T12:56:36.000Z ##

Hackers rapidly exploit the Atlassian vulnerability CVE-2026-21589. Learn how this critical flaw compromises Jira, Confluence, and Bitbucket security.

#Atlassian #CVE202621589 #CyberSecurity #Jira #TechNews

meterpreter.org/atlassian-cve-

##

patrickcmiller@infosec.exchange at 2026-10-09T03:12:00.000Z ##

You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589) labs.watchtowr.com/you-wont-he

##

linuxmint_hun@mastodon.social at 2026-10-08T17:13:07.000Z ##

CVE-2026-21589 kritikus arbitrary file access hiba érinti több Atlassian Data Center terméket (Jira, Confluence, Bitbucket) és bejelentkezés nélkül hozzáférhetők lehetnek fájlok. Van internetre kitett példányod, ami veszélyben lehet, aggódsz? A végleges megoldás a frissítés; ideiglenes WAF/Tomcat RewriteValve mitigációk lehetségesek.

linuxmint.hu/hir/2026/10/kriti

#Atlassian #CVE202621589 #Jira #Confluence #Bitbucket #DataCenter #WAF #Tomcat #kiberbiztonság #infosec

##

jschauma@mstdn.social at 2026-10-08T16:58:05.000Z ##

Oh, Atlassian, never change! 😭

"CVE-2026-21589 - Arbitrary File Access Vulnerability impacts Multiple Products"

CVSS Score 9.3, so, you know, you better "Test that your rule blocks .. immediately adjacent to /".

APT /../../../../../../etc/passwd strikes again.

confluence.atlassian.com/secur

##

beyondmachines1@infosec.exchange at 2026-10-08T12:01:49.000Z ##

Atlassian Patches Critical File Access Flaw Exploited in the Wild

Atlassian released emergency patches for a critical arbitrary file access vulnerability (CVE-2026-21589) affecting eight Data Center products, which attackers are actively exploiting to gain administrator privileges.

**If you run self-hosted Atlassian Data Center or Server products (Jira, Confluence, Bitbucket, Bamboo, Crowd, Crucible/Fisheye), apply Atlassian's security update immediately, because this flaw is being actively exploited to steal passwords and take over admin accounts. If you can't patch, remove the instance from the public internet now, then check your logs for access attempts to WEB-INF or crowd.properties. Change any Crowd credentials that may have been exposed.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

benzogaga33@mamot.fr at 2026-10-08T09:40:04.000Z ##

Atlassian : une faille critique permet de lire des fichiers sur Jira, Confluence et Bitbucket it-connect.fr/atlassian-cve-20 #ActuCybersécurité #Cybersécurité #Vulnérabilité

##

threatnoir@infosec.exchange at 2026-10-08T08:07:02.000Z ##

⚠️ CRITICAL: Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details

A critical arbitrary file access vulnerability (CVE-2026-21589) in Atlassian Data Center products is under active exploitation as of public disclosure. Threat actors attempted exploitation within two hours of details going public, with potential access to credentials and sensitive files. All Atlass…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

censys@infosec.exchange at 2026-10-07T20:15:13.000Z ##

🚨 Rapid Response: CVE-2026-21589 (CVSS 9.3) is a critical arbitrary file access vulnerability affecting eight Atlassian Data Center products, including Confluence, Jira, Bitbucket, and Bamboo.

Censys currently detects 95,366 Internet-facing hosts and 431,502 web properties running affected products after excluding assets labeled as honeypots. This is product exposure, not a confirmed-vulnerable count.
Atlassian has released fixes for all eight products.

Full Censys ARC advisory: censys.com/advisory/cve-2026-2

#CensysARC #Atlassian #Cybersecurity #Vulnerability

##

threatcodex@infosec.exchange at 2026-10-07T16:50:50.000Z ##

Scans for Atlassian vulnerablity (CVE-2026-21589)
#CVE_2026_21589
isc.sans.edu/diary/rss/33406

##

youranonnewsirc@nerdculture.de at 2026-10-07T16:26:28.000Z ##

Recent developments include the US evacuating B-1 bombers from the UK due to an Iranian threat, while Hamas is reportedly plotting attacks in Gaza for October 7th. In cybersecurity, ASOS experienced a cloud breach via its Snowflake platform, and active exploitation of a critical Atlassian flaw (CVE-2026-21589) has begun. An FBI breach was also linked to a contractor error. Microsoft is hosting an AI-focused Surface event today.

#Cybersecurity #Geopolitics #TechNews

##

cyberworldops@infosec.exchange at 2026-10-07T15:45:24.000Z ##

Unauthenticated arbitrary file access in eight self-hosted Atlassian families (CVE-2026-21589) is seeing active probing after public PoC release. Exploitation requires exact file path and is limited to web root, without directory listing. Data Center operators should patch and reduce exposure promptly. #Atlassian #DataCenter #ThreatIntel

cyberworldops.eu/en/public-exp

##

sans_isc@infosec.exchange at 2026-10-07T15:01:52.000Z ##

Scans for Atlassian vulnerablity (CVE-2026-21589) isc.sans.edu/diary/33406

##

oversecurity@mastodon.social at 2026-10-07T14:50:53.000Z ##

Atlassian Warns of Critical Flaw Affecting Eight Self-Managed Products

Atlassian's CVE-2026-21589 lets unauthenticated attackers read files in Confluence and seven other Data Center products.

🔗️ [Thecyberexpress] link.is.it/gJ99W6

##

CVE-2026-105192
(9.8 CRITICAL)

EPSS: 0.48%

updated 2026-10-07T12:31:58

4 posts

LMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and share KV cache blocks. Messages on that socket are msgpack. Extension code 1 is passed to DeviceIPCWrapper.Deserialize, which calls pickle.loads, while the server is still decoding request arguments and before the handler runs. A single unauthenticated ZMQ DEALER mes

1 repos

https://github.com/rxsklife/CVE-2026-105192

DailyCyberSecurity at 2026-10-09T11:54:44.597Z ##

Explore the critical LMCache vulnerability CVE-2026-105192. Learn how insecure ZeroMQ configurations and Python pickle deserialization lead to RCE attacks.

meterpreter.org/critical-lmcac

##

DailyCyberSecurity@infosec.exchange at 2026-10-09T11:54:44.000Z ##

Explore the critical LMCache vulnerability CVE-2026-105192. Learn how insecure ZeroMQ configurations and Python pickle deserialization lead to RCE attacks.

#LMCache #CVE2026105192 #CyberSecurity #TechNews #ZeroMQ

meterpreter.org/critical-lmcac

##

beyondmachines1@infosec.exchange at 2026-10-08T09:01:49.000Z ##

Unpatched Critical RCE Vulnerability in LMCache Exposes LLM Infrastructure to Remote Takeover

LMCache suffers from a critical unpatched vulnerability (CVE-2026-105192) that allows unauthenticated attackers to execute arbitrary code with root privileges via malicious ZeroMQ messages. The flaw stems from the unsafe use of Python's pickle library for data deserialization in the platform's multiprocess mode.

**If you run LMCache in multiprocess mode (versions 0.3.9 through 0.5.5), be aware that your system is critically vulnerable and there is no fix yet. Make sure its port is reachable only from localhost or a trusted internal network. Also update vLLM to version 0.30.0 or later, so a single bad request can't crash your AI service for everyone.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

cyberworldops@infosec.exchange at 2026-10-07T20:40:08.000Z ##

LMCache multiprocess mode is affected by CVE-2026-105192, an unauthenticated RCE via pickle deserialization over ZeroMQ, rated CVSS 9.8. Localhost binding by default limits exposure, but any reachable instance allows full process compromise. Prioritize network restriction and patching. #LmCache #RemoteCodeExecution #PickleDeserialization

cyberworldops.eu/en/lmcache-di

##

CVE-2026-91140
(9.6 CRITICAL)

EPSS: 1.92%

updated 2026-10-07T04:18:10.610000

1 posts

An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user invokes the generator.

beyondmachines1@infosec.exchange at 2026-10-08T10:01:49.000Z ##

Progress Software Fixes Critical Command Injection Flaw in DataDirect ARC GenAI Agents

Progress Software patched a critical command injection vulnerability (CVE-2026-91140) in its DataDirect ARC GenAI Agents that allowed attackers to execute code via malicious OpenAPI filenames.

**If you use Progress DataDirect ARC GenAI agents (the ARCGenAI-Generator or ARCGenAI-EntityGen files), update ASAP by pulling the latest version 2.1 files from GitHub. If you've recently fed it any OpenAPI or Swagger files from outside sources, check your developer machines and CI/CD pipelines for unexpected files or changes. From now on treat every external spec file as untrusted.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-16516(CVSS UNKNOWN)

EPSS: 0.15%

updated 2026-10-07T03:30:31

1 posts

wolfSSH does not validate that the ECDSA curve identifier in a KEXDH_REPLY host key blob matches the algorithm negotiated during key exchange. In ParseECCPubKey() (src/internal.c), the blob's algorithm string is used to derive the curve via NameToId/wcPrimeForId without checking against the negotiated ssh->handshake->pubKeyId, and the RFC 5656 curve identifier string is discarded via GetSkip() rat

CVE-2026-79820
(9.0 CRITICAL)

EPSS: 0.27%

updated 2026-10-06T15:15:48.310000

1 posts

A remote user validation failure vulnerability exists in HPE Integrated Lights-Out (iLO) 7 firmware.

CVE-2026-105134
(10.0 CRITICAL)

EPSS: 1.84%

updated 2026-10-06T15:04:52.637000

6 posts

A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 10.3.4 is able to resolve

1 repos

https://github.com/RayanAlmulhim/CVE-2026-105134-lab

hacksgr@mastodon.social at 2026-10-09T16:02:02.000Z ##

Unknown attackers are exploiting two AhsayCBS backup-software flaws: CVE-2026-105133 (CVSS v4 5.5) and CVE-2026-105134 (9.3).

Used together, they can bypass authentication and allow commands on affected systems.

Huntress says attempts began on Oct.

7; by Oct.

8, five organizations were estimated to be affected.

After gaining access, attackers installed XMRig for cryptocurrency mining, disguised as “edge.exe.” Patch in…

en.hacks.gr/agnostoi-parakampt

#AhsayCBS #CVE2026105133 #CVE2026105134 #XMRig

##

ssvc at 2026-10-09T14:55:27.780Z ##

Huntress is reporting AhsayCBS CVE-2026-105133 and CVE-2026-105134 exploitation to drop web shells and XMRig cryptominer:

Huntress is seeing these two vulnerabilities being chained together in order to gain access to targeted systems.

huntress.com/blog/ahsaycbs-fla

##

Analyst207@mastodon.social at 2026-10-09T14:35:07.000Z ##

AhsayCBS Flaws Exploited to Deploy XMRig Miners

Hackers are exploiting weaknesses in AhsayCBS to spread XMRig cryptominers, using clever tactics like disguising malware as Microsoft Edge. They gain access by chaining two recently disclosed vulnerabilities, CVE-2026-105133 and CVE-2026-105134.

osintsights.com/ahsaycbs-flaws

#CryptocurrencyMining #XmrigMiners #Cve2026105133 #Cve2026105134 #Ahsaycbs

##

beyondmachines1 at 2026-10-09T11:01:49.167Z ##

Threat Actors Chain AhsayCBS Vulnerabilities to Deploy Webshells and Cryptominers

Threat actors are chaining two vulnerabilities in AhsayCBS (CVE-2026-105133 and CVE-2026-105134) to bypass authentication and gain remote code execution on backup servers.

**If you run AhsayCBS (any version up to and including 10.3.4), be aware it's actively exploited with no patch available. Immediately make sure that the management console is off the internet and allow access only from trusted IPs or over VPN. Then check for signs of compromise, such as unusual processes started by cbssvcX64.exe. If you find any, fully re-image the server from a clean backup.**

beyondmachines.net/event_detai

##

ssvc@infosec.exchange at 2026-10-09T14:55:27.000Z ##

Huntress is reporting AhsayCBS CVE-2026-105133 and CVE-2026-105134 exploitation to drop web shells and XMRig cryptominer:

Huntress is seeing these two vulnerabilities being chained together in order to gain access to targeted systems.

huntress.com/blog/ahsaycbs-fla

#threatintel #ahsayCBS #CVE #eitw #IOC

##

beyondmachines1@infosec.exchange at 2026-10-09T11:01:49.000Z ##

Threat Actors Chain AhsayCBS Vulnerabilities to Deploy Webshells and Cryptominers

Threat actors are chaining two vulnerabilities in AhsayCBS (CVE-2026-105133 and CVE-2026-105134) to bypass authentication and gain remote code execution on backup servers.

**If you run AhsayCBS (any version up to and including 10.3.4), be aware it's actively exploited with no patch available. Immediately make sure that the management console is off the internet and allow access only from trusted IPs or over VPN. Then check for signs of compromise, such as unusual processes started by cbssvcX64.exe. If you find any, fully re-image the server from a clean backup.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2026-105133
(7.3 HIGH)

EPSS: 0.38%

updated 2026-10-06T15:04:52.637000

6 posts

A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file com/ahsay/obs/api/ApiStructsAction.java of the component API. Performing a manipulation of the argument random results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 10.3.4 is able to mitigate thi

hacksgr@mastodon.social at 2026-10-09T16:02:02.000Z ##

Unknown attackers are exploiting two AhsayCBS backup-software flaws: CVE-2026-105133 (CVSS v4 5.5) and CVE-2026-105134 (9.3).

Used together, they can bypass authentication and allow commands on affected systems.

Huntress says attempts began on Oct.

7; by Oct.

8, five organizations were estimated to be affected.

After gaining access, attackers installed XMRig for cryptocurrency mining, disguised as “edge.exe.” Patch in…

en.hacks.gr/agnostoi-parakampt

#AhsayCBS #CVE2026105133 #CVE2026105134 #XMRig

##

ssvc at 2026-10-09T14:55:27.780Z ##

Huntress is reporting AhsayCBS CVE-2026-105133 and CVE-2026-105134 exploitation to drop web shells and XMRig cryptominer:

Huntress is seeing these two vulnerabilities being chained together in order to gain access to targeted systems.

huntress.com/blog/ahsaycbs-fla

##

Analyst207@mastodon.social at 2026-10-09T14:35:07.000Z ##

AhsayCBS Flaws Exploited to Deploy XMRig Miners

Hackers are exploiting weaknesses in AhsayCBS to spread XMRig cryptominers, using clever tactics like disguising malware as Microsoft Edge. They gain access by chaining two recently disclosed vulnerabilities, CVE-2026-105133 and CVE-2026-105134.

osintsights.com/ahsaycbs-flaws

#CryptocurrencyMining #XmrigMiners #Cve2026105133 #Cve2026105134 #Ahsaycbs

##

beyondmachines1 at 2026-10-09T11:01:49.167Z ##

Threat Actors Chain AhsayCBS Vulnerabilities to Deploy Webshells and Cryptominers

Threat actors are chaining two vulnerabilities in AhsayCBS (CVE-2026-105133 and CVE-2026-105134) to bypass authentication and gain remote code execution on backup servers.

**If you run AhsayCBS (any version up to and including 10.3.4), be aware it's actively exploited with no patch available. Immediately make sure that the management console is off the internet and allow access only from trusted IPs or over VPN. Then check for signs of compromise, such as unusual processes started by cbssvcX64.exe. If you find any, fully re-image the server from a clean backup.**

beyondmachines.net/event_detai

##

ssvc@infosec.exchange at 2026-10-09T14:55:27.000Z ##

Huntress is reporting AhsayCBS CVE-2026-105133 and CVE-2026-105134 exploitation to drop web shells and XMRig cryptominer:

Huntress is seeing these two vulnerabilities being chained together in order to gain access to targeted systems.

huntress.com/blog/ahsaycbs-fla

#threatintel #ahsayCBS #CVE #eitw #IOC

##

beyondmachines1@infosec.exchange at 2026-10-09T11:01:49.000Z ##

Threat Actors Chain AhsayCBS Vulnerabilities to Deploy Webshells and Cryptominers

Threat actors are chaining two vulnerabilities in AhsayCBS (CVE-2026-105133 and CVE-2026-105134) to bypass authentication and gain remote code execution on backup servers.

**If you run AhsayCBS (any version up to and including 10.3.4), be aware it's actively exploited with no patch available. Immediately make sure that the management console is off the internet and allow access only from trusted IPs or over VPN. Then check for signs of compromise, such as unusual processes started by cbssvcX64.exe. If you find any, fully re-image the server from a clean backup.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2026-88779
(7.5 HIGH)

EPSS: 0.59%

updated 2026-10-05T15:33:23

1 posts

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.

2 repos

https://github.com/orjanj/netscaler_threat_hunt_helper

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

cyberveille@mastobot.ping.moi at 2026-10-09T13:00:20.000Z ##

📢 Zero-day Citrix NetScaler CVE-2026-88779 exploité activement, correctifs disponibles

📰 Source : The Hacker News (Ravie Lakshmanan) — Date : 5 octobre 2026 🔍 Contexte Citrix a publié des mises à jour de sécurité pour corriger une vulnérabilité de haute sévérité affectant NetScaler ADC et NetScaler Gateway, activement exploitée dans le cadre d'attaques…

📖 cyberveille : cyberveille.ch/posts/2026-10-0
🌐 source : thehackernews.com/2026/10/new-
🟡 vérification factuelle moyenne
#Citrix #NetScaler #Cyberveille

##

CVE-2026-73551
(5.3 MEDIUM)

EPSS: 0.53%

updated 2026-10-05T14:06:32.380000

1 posts

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's URL normalization does not recognize dot and dotdot path segments when they carry semicolon parameters. A request such as /user/..;foo=bar/admin is therefore not canonicalized to /admin even when path normalization is enabled. If an upstream interprets the se

hugovalters@mastodon.social at 2026-10-09T13:00:21.000Z ##

CVE-2026-73551 Envoy path normalization bypass lets /user/..;foo=bar/admin reach /admin uncanonicalized. CVSS 5.3. Patch to 1.36.10, 1.37.6, 1.38.4 or 1.39.1 now. valtersit.com/cve/CVE-2026-735 #Envoy #infosec #CVE

##

CVE-2026-53359
(8.8 HIGH)

EPSS: 0.98%

updated 2026-10-03T12:32:07

1 posts

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due to unexpected GFN") fixed a shadow paging mismatch between stored and computed GFNs; the bug could be triggered by changing a PDE mapping from outside the guest, and then deleting a memslot. Th

7 repos

https://github.com/suominen/januscape

https://github.com/HORKimhab/CVE-2026-53359

https://github.com/ndouglas-cloudsmith/CVE-2026-53359

https://github.com/0xBlackash/CVE-2026-53359

https://github.com/chuzhongyun/CVE-2026-53359-Kernel-Fix

https://github.com/Aoripus-LTD/Januscape-Hotfix

https://github.com/xj2268-TA/KVM-Januscape

bontchev@infosec.exchange at 2026-10-09T05:37:07.000Z ##

@GossiTheDog Meanwhile I've updated my Citrix honeypot to handle CVE-2026-88771 - but so far have seen absolutely no attacks. I'll run some tests later today to check if it doesn't miss them due to some kind of bug.

Visualization (empty so far):

pandora.nlcv.bas.bg/grafana/d/

##

GossiTheDog@cyberplace.social at 2026-10-08T16:55:50.000Z ##

Watchtowr have a good look at pray and spray #PitScaler exploitation. This isn’t the initial exploitation - their timeline should expand back to September 4th for that.

Also they make a good point re the latest SAML bug - by using it to DoS, it causes attacker commands in the logs to process immediately post reboot with PitScaler vuln. Not covered in blog: Attackers are actually doing this, they’re preloading the logs using the username field for failed logins.

watchtowr.com/intelligence/pos

##

CVE-2026-94572
(0 None)

EPSS: 0.53%

updated 2026-09-24T23:19:22.677000

1 posts

In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The value is written verbatim into the HAProxy configuration generated on the amphora, and thus an authenticated project member who owns a TLS-enabled load balancer can embed a newline and inject arbitrary HAProxy configuration directives. Only deployment

hugovalters@mastodon.social at 2026-10-08T03:30:20.000Z ##

CVE-2026-94572: OpenStack Octavia Amphora driver config injection, CVSS 8.5. Authenticated project members can inject HAProxy directives via tls_ciphers. Patch is under review, hold off yet. Details: valtersit.com/cve/CVE-2026-945 #CVE #OpenStack #infosec

##

CVE-2026-61747
(4.3 MEDIUM)

EPSS: 0.34%

updated 2026-09-23T18:30:42.573000

1 posts

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the /api/importer/row/ and /api/importer/mapping/ endpoints do not scope DataImportRow and DataImportColumnMap querysets to the owner of the associated DataImportSession. Any authenticated user, including an account with no assigned roles, can supply another user's import session identifier and retrieve that session's row_dat

hugovalters@mastodon.social at 2026-10-09T14:40:02.000Z ##

CVE-2026-61747: InvenTree API endpoints leak other users' import data to any authenticated account. CVSS 4.3. No fix live yet, patch under review. Audit access now. valtersit.com/cve/CVE-2026-617 #CVE #infosec #cybersecurity

##

CVE-2026-79316
(7.6 HIGH)

EPSS: 0.32%

updated 2026-09-22T20:00:03.713000

1 posts

An improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can modify the xray configuration template through the settings interface and trigger a panel restart, causing the xray management gRPC service, which is bound to loopback by default, to be regenerated and bound to non-loopback addresses. This expands the reachable surface of the management interface beyond

hugovalters@mastodon.social at 2026-10-09T16:10:03.000Z ##

CVE-2026-79316 x-ui 0.3.2 improper access control lets any panel user rebind the xray gRPC service to non-loopback, exposing the management interface. CVSS 7.6, no patch yet. Restrict panel access and watch for updates. valtersit.com/cve/CVE-2026-793 #CVE #infosec #xui

##

CVE-2026-88745
(6.1 MEDIUM)

EPSS: 0.25%

updated 2026-09-22T18:34:31

1 posts

EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables attackers to upload a malicious shell.

hugovalters@mastodon.social at 2026-10-09T09:50:02.000Z ##

CVE-2026-88745 EMLOG-Pro XSS (CVSS 6.1) lets attackers upload a malicious shell. No patch yet. Audit and isolate affected instances. valtersit.com/cve/CVE-2026-887 #CVE #infosec

##

CVE-2026-93836
(7.2 HIGH)

EPSS: 0.24%

updated 2026-09-22T09:31:18

1 posts

The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qty' parameter in all versions up to, and including, 8.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The float c

CVE-2026-94504
(7.2 HIGH)

EPSS: 0.41%

updated 2026-09-22T09:31:17

1 posts

Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct submission URL, the script runs in the WordPress admin origin.

CVE-2026-94414
(5.4 MEDIUM)

EPSS: 0.38%

updated 2026-09-21T21:32:00

1 posts

jshERP through 3.6 is missing an authorization check on the POST /userBusiness/updateBtnStr endpoint that allows authenticated users to modify role button-permission definitions. Attackers can supply arbitrary roleId and btnStr parameters to overwrite button-permission configurations for any role in the tenant without privilege validation.

hugovalters@mastodon.social at 2026-10-09T11:30:03.000Z ##

CVE-2026-94414 jshERP through 3.6 misses an authz check on POST /userBusiness/updateBtnStr, letting any authenticated user rewrite role button-permission configs across the tenant. CVSS 5.4, patch status unknown. Review valtersit.com/cve/CVE-2026-944 #CVE #infosec #cybersecurity

##

CVE-2026-87491
(8.8 HIGH)

EPSS: 3.14%

updated 2026-09-21T13:17:11.283000

1 posts

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

2 repos

https://github.com/SneakyNachos/CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass.

https://github.com/SneakyNachos/CVE-2026-87491-and-CVE-2026-85046-the-bagel-fell-off-the-counter

CVE-2026-93485
(7.1 HIGH)

EPSS: 0.38%

updated 2026-09-18T06:32:17

1 posts

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through 6.5.10; 6.4 through 6.4.10; 6.3 through 6.3.10; 6.2 through 6.2.11; 6.1 through 6.1.1

4 repos

https://github.com/686f6c61/POC-WP-CORE-CVE-2026-93485

https://github.com/DeathShotXD/Comment2Shell

https://github.com/0xBlackash/CVE-2026-93485

https://github.com/HORKimhab/CVE-2026-93485

sekurakbot@mastodon.com.pl at 2026-10-09T07:35:00.000Z ##

Ataki na strony WordPress chwilę po wydaniu poprawki

17 września 2026 r. WordPress wydał wersję 7.1.1, w której załatano dwie podatności – kojarzone jako Click2Shell i Comment2Shell (CVE-2026-93485). To jednak dopiero początek historii. Kilka dni później – 22 września – wydano wersję 7.1.2 łatającą kolejną podatność. Atakujący nie czekali jednak na publikację jej szczegółów – wszystko wskazuje na...

#WBiegu #Podatność #Rce #Wordpress

sekurak.pl/ataki-na-strony-wor

##

CVE-2026-0310
(0 None)

EPSS: 0.37%

updated 2026-09-11T04:17:13.060000

2 posts

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls. The security risk posed by this issue is minimiz

AAKL at 2026-10-09T16:15:10.087Z ##

Palo Alto has a a long list of advisories, addressing at least two critical vulnerabilities, among others: security.paloaltonetworks.com/

CRITICAL: CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing security.paloaltonetworks.com/

CRITICAL: PAN-SA-2026-0012 Chromium: Monthly Vulnerability Update (September 2026) security.paloaltonetworks.com/

- Tenable Research Advisories:

HIGH: Hermes Agent - PKCE Session Takeover via Redirect-URI Parser Confusion tenable.com/security/research/

There are also two WordPress vulnerabilities and a few others here tenable.com/security/research

- Microsoft:

In case you missed this, Microsoft posted quite a few patches yesterday msrc.microsoft.com/update-guide

##

AAKL@infosec.exchange at 2026-10-09T16:15:10.000Z ##

Palo Alto has a a long list of advisories, addressing at least two critical vulnerabilities, among others: security.paloaltonetworks.com/

CRITICAL: CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing security.paloaltonetworks.com/

CRITICAL: PAN-SA-2026-0012 Chromium: Monthly Vulnerability Update (September 2026) security.paloaltonetworks.com/

- Tenable Research Advisories:

HIGH: Hermes Agent - PKCE Session Takeover via Redirect-URI Parser Confusion tenable.com/security/research/

There are also two WordPress vulnerabilities and a few others here tenable.com/security/research #WorPress

- Microsoft:

In case you missed this, Microsoft posted quite a few patches yesterday msrc.microsoft.com/update-guide #infosec #vulnerability #Microsofot #Azure #Linux

##

CVE-2026-80093
(7.0 None)

EPSS: 0.32%

updated 2026-09-09T00:31:34

2 posts

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

DailyCyberSecurity at 2026-10-09T13:15:49.761Z ##

Discover the details of the Windows Cloud Files Driver vulnerability, CVE-2026-80093. Learn how this flaw in cldflt.sys affects kernel privileges.

meterpreter.org/windows-cloud-

##

DailyCyberSecurity@infosec.exchange at 2026-10-09T13:15:49.000Z ##

Discover the details of the Windows Cloud Files Driver vulnerability, CVE-2026-80093. Learn how this flaw in cldflt.sys affects kernel privileges.

#WindowsSecurity #CVE202680093 #CyberSecurity #Microsoft #TechNews

meterpreter.org/windows-cloud-

##

CVE-2026-48710
(6.5 MEDIUM)

EPSS: 7.06%

updated 2026-08-28T18:31:00

2 posts

### Summary In affected versions, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions

5 repos

https://github.com/xtremebeing/starlette-host-header-lab

https://github.com/sb-ox/repro-OXDEV-77637-uv-workspace

https://github.com/Bhanunamikaze/BadHost-CVE-2026-48710-Exploit

https://github.com/eris-ths/supply-chain-guard

https://github.com/CuteeCat/CVE-2026-48710

x41sec at 2026-10-09T14:05:54.092Z ##

We have published our writeup about the discovery and details of the vulnerability (CVE-2026-48710) at x41-dsec.de/lab/research/2026/

##

x41sec@infosec.exchange at 2026-10-09T14:05:54.000Z ##

We have published our writeup about the discovery and details of the #BadHost vulnerability (CVE-2026-48710) at x41-dsec.de/lab/research/2026/

##

CVE-2026-47483
(8.2 HIGH)

EPSS: 0.55%

updated 2026-07-28T17:16:45.823000

1 posts

NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption by submitting concurrent unauthenticated profiling requests. A successful exploit of this vulnerability might lead to denial of service and information disclosure.

_r_netsec@infosec.exchange at 2026-10-08T22:03:21.000Z ##

How We Found Thousands of Exposed NVIDIA GPUs and a Way to Disrupt Them (CVE-2026-47483) lava.security/research/cve-202

##

CVE-2025-41738
(7.5 HIGH)

EPSS: 0.39%

updated 2026-06-17T09:23:03.883000

1 posts

An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.

certvde@infosec.exchange at 2026-10-08T06:42:39.000Z ##

🔒 New CSAF advisory published

VDE-2026-105
KEB Automation: Multiple Vulnerabilities in COMBIVIS Control Runtime
CVE-2025-41659, CVE-2025-41691, CVE-2025-41739, CVE-2025-41738

The Docker-based COMBIVIS Control Runtime service is affected by several vulnerabilities in CODESYS Runtime Toolkit 3.5.21.10. These vulnerabilities are…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: keb-automation.csaf-tp.certvde

#OT #Advisory

##

CVE-2025-41691
(7.5 HIGH)

EPSS: 0.55%

updated 2026-06-17T09:22:58.030000

1 posts

An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime systems by sending specially crafted communication requests, potentially leading to a denial-of-service (DoS) condition.

certvde@infosec.exchange at 2026-10-08T06:42:39.000Z ##

🔒 New CSAF advisory published

VDE-2026-105
KEB Automation: Multiple Vulnerabilities in COMBIVIS Control Runtime
CVE-2025-41659, CVE-2025-41691, CVE-2025-41739, CVE-2025-41738

The Docker-based COMBIVIS Control Runtime service is affected by several vulnerabilities in CODESYS Runtime Toolkit 3.5.21.10. These vulnerabilities are…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: keb-automation.csaf-tp.certvde

#OT #Advisory

##

security_crawler_carl@infosec.exchange at 2026-10-07T20:29:36.000Z ##

Patch Ivanti Sentry against CVE-2026-10520 and scan your environment for PoeLLM infections before the next stanza drops.

Reward: You've received a Tattered Broadside of Suspicious Verse. We recommend not parsing it.

theregister.com/security/2026/

#Malware #CyberSecurity #Ivanti #ZeroDay #APT #PatchedOrPerish (3/3)

##

security_crawler_carl@infosec.exchange at 2026-10-07T20:29:36.000Z ##

It locates its command-and-control server not through conventional means, but by parsing poetry — extracting keywords, converting them to numbers via a hard-coded dictionary, and silently pivoting to wherever the operator rewrites the verse. Keats never had this kind of reach.

The compromised host, much like the lesser-spotted migratory waterfowl before a storm, immediately began scanning for further vulnerable devices. CVE-2026-10520 is the wound; the poem is the leash. (2/3)

##

CVE-2026-23870
(7.5 HIGH)

EPSS: 1.53%

updated 2026-05-11T14:50:21

1 posts

## Impact A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to out-of-memory exceptions or excessive CPU usage. We recommend updating immediately. The vulnerability exists in versions 19.0.0 through 19.0.5, 19.1.0 through 19.1.6, and 19.2.0 through 19.2.5 of: [react-server-dom-webpack](https://www.npmjs

2 repos

https://github.com/dwisiswant0/next-16.2.4-pocs

https://github.com/emresandikci/nextjs-cve-2026-23870-checker

sayzard@mastodon.sayzard.org at 2026-10-09T13:46:20.000Z ##

CVE-2026-23870: A Single Post Freezes Any Next.js Server

CVE-2026-23870은 React Server Actions의 multipart/form-data 역직렬화 과정에서 `$K` 참조마다 전체 폼 필드를 다시 순회해 발생하는 O(n²) CPU 소모 취약점이다. 공격자는 공개된 Server Action ID를 이용해 약 900KB 크기의 POST 하나로 Node.js 이벤트 루프를 수 초~수십 초간 점유시켜, 인증 전에도 Next.js 서버에 서비스 거부를 유발할 수 있다. React 19.0.6, 19.1.7, 19.2.6에서 필드를 요청당 한 번만 순회하도록 수정됐으며, 취약한 React 19 기반 Next...

simonkoeck.com/writeups/react-

##

CVE-2025-41739
(5.9 MEDIUM)

EPSS: 0.35%

updated 2025-12-01T12:30:34

1 posts

An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the CODESYS Control runtime system on Linux and QNX to trigger an out-of-bounds read via crafted socket communication, potentially causing a denial of service.

certvde@infosec.exchange at 2026-10-08T06:42:39.000Z ##

🔒 New CSAF advisory published

VDE-2026-105
KEB Automation: Multiple Vulnerabilities in COMBIVIS Control Runtime
CVE-2025-41659, CVE-2025-41691, CVE-2025-41739, CVE-2025-41738

The Docker-based COMBIVIS Control Runtime service is affected by several vulnerabilities in CODESYS Runtime Toolkit 3.5.21.10. These vulnerabilities are…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: keb-automation.csaf-tp.certvde

#OT #Advisory

##

CVE-2025-47818
(2.2 LOW)

EPSS: 0.24%

updated 2025-10-24T18:32:04

2 posts

Flock Safety Gunshot Detection devices before 1.3 have a hard-coded password for a connection.

olearysec at 2026-10-09T14:11:02.200Z ##

@briankrebs Every Flock CVE in existence (CVE-2025-47818 through -47824) came through MITRE off Jon Gaines' 2025 research, before Flock had any say in the numbering. The "outside parties requesting CVE IDs before a fix is ready" line reads like a reference to that.

As for who decides what's a bug, they've answered in writing. The new VDP gives Flock 120 days to publish, with an exception for anything it deems a "material safety risk to law enforcement or the public." Their advisories page lists nothing, two weeks after a pentest write-up with 2 criticals and 7 highs that Flock says needed no customer action, which is exactly the kind of finding a vendor CNA can decline to number. So yes, Flock decides now. The criteria just live on a legal page instead of a press release.

##

olearysec@infosec.exchange at 2026-10-09T14:11:02.000Z ##

@briankrebs Every Flock CVE in existence (CVE-2025-47818 through -47824) came through MITRE off Jon Gaines' 2025 research, before Flock had any say in the numbering. The "outside parties requesting CVE IDs before a fix is ready" line reads like a reference to that.

As for who decides what's a bug, they've answered in writing. The new VDP gives Flock 120 days to publish, with an exception for anything it deems a "material safety risk to law enforcement or the public." Their advisories page lists nothing, two weeks after a pentest write-up with 2 criticals and 7 highs that Flock says needed no customer action, which is exactly the kind of finding a vendor CNA can decline to number. So yes, Flock decides now. The criteria just live on a legal page instead of a press release.

##

CVE-2024-50623
(8.8 HIGH)

EPSS: 98.61%

updated 2025-10-22T00:34:15

2 posts

In Cleo Harmony before 5.8.0.20, VLTrader before 5.8.0.20, and LexiCom before 5.8.0.20, there is a JavaScript Injection vulnerability.

Nuclei template

4 repos

https://github.com/iSee857/Cleo-CVE-2024-50623-PoC

https://github.com/watchtowrlabs/CVE-2024-50623

https://github.com/congdong007/CVE-2024-50623-poc

https://github.com/verylazytech/CVE-2024-50623

security_crawler_carl@infosec.exchange at 2026-10-08T11:29:04.000Z ##

The verdict on whether Aon was actually breached, encrypted, or exfiltrated remains, as of October 7, 2026, unconfirmed. The court is unimpressed by this lack of closure.

Sentencing is pending, but the docket is clear: patch your Cleo managed file-transfer software against CVE-2024-50623 immediately or await your own summons.

Reward: You've received a Subpoena of Moderate Urgency. It is not transferable.

shattered.io/aon-ransomware-cv

#Ransomware #Cleo (2/2)

##

security_crawler_carl@infosec.exchange at 2026-10-08T11:29:04.000Z ##

🏆 New Achievement! Exhibit A: Two-Year-Old Bug, Still Loaded!

The court finds as follows. Aon, insurance and risk-advisory colossus, stands named in connection with the Termite ransomware group's exploitation of CVE-2024-50623, a vulnerability in Cleo's managed file-transfer software that has been kicking around since 2024. Rescana and BleepingComputer raised the charges. (1/2)

##

CVE-2025-41659
(8.3 HIGH)

EPSS: 0.22%

updated 2025-08-04T09:30:34

1 posts

A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys. This allows sensitive data to be extracted or to accept certificates as trusted. Although all services remain available, only unencrypted communication is possible if the certificates are deleted.

certvde@infosec.exchange at 2026-10-08T06:42:39.000Z ##

🔒 New CSAF advisory published

VDE-2026-105
KEB Automation: Multiple Vulnerabilities in COMBIVIS Control Runtime
CVE-2025-41659, CVE-2025-41691, CVE-2025-41739, CVE-2025-41738

The Docker-based COMBIVIS Control Runtime service is affected by several vulnerabilities in CODESYS Runtime Toolkit 3.5.21.10. These vulnerabilities are…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: keb-automation.csaf-tp.certvde

#OT #Advisory

##

CVE-2023-22894
(7.5 HIGH)

EPSS: 3.43%

updated 2023-11-07T05:05:45

3 posts

### Summary Strapi through 4.7.1 allows unauthenticated attackers to discover sensitive user details for Strapi administrators and API users. ### Details Strapi through 4.7.1 allows unauthenticated attackers to discover sensitive user details for Strapi administrators and API users. The unauthenticated attacker can filter users by columns that contain sensitive information and infer the values

2 repos

https://github.com/maxntv/CVE-2023-22894-PoC

https://github.com/Saboor-Hakimi/CVE-2023-22894

hacksgr@mastodon.social at 2026-10-09T13:39:03.000Z ##

CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog after their use by China-linked Flax Typhoon: ProFTPD (CVE-2015-3306), ONLYOFFICE Docs (CVE-2021-3199), Strapi (CVE-2023-22894), Apache Struts (CVE-2016-3081) and ISC BIND (CVE-2015-5477).

The wider operations targeted eight vulnerabilities to gain initial access to organizations and remove sensitive data.

US federal agencies must install require…

en.hacks.gr/i-cisa-prosthetei-

#FlaxTyphoon #ProFTPD #ONLYOFFICE #ISC_BIND

##

secdb@infosec.exchange at 2026-10-08T19:00:11.000Z ##

🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3306 (secdb.nttzen.cloud/cve/detail/)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: proftpd.org/ ; lists.debian.org/debian-securi ; lists.opensuse.org/archives/li ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5477 (secdb.nttzen.cloud/cve/detail/)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: web.archive.org/web/2015072901 ; access.redhat.com/errata/RHSA-; supportportal.juniper.net/s/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2016-3081 (secdb.nttzen.cloud/cve/detail/)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: cwiki.apache.org/confluence/di ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-3199 (secdb.nttzen.cloud/cve/detail/)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; github.com/ONLYOFFICE/Document ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2023-22894 (secdb.nttzen.cloud/cve/detail/)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: strapi.io/blog/security-disclo ; github.com/strapi/strapi/relea ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261008 #cisa20261008 #cve_2015_3306 #cve_2015_5477 #cve_2016_3081 #cve_2021_3199 #cve_2023_22894 #cve20153306 #cve20155477 #cve20163081 #cve20213199 #cve202322894

##

cisakevtracker@mastodon.social at 2026-10-08T18:01:28.000Z ##

CVE ID: CVE-2023-22894
Vendor: Strapi
Product: Strapi
Date Added: 2026-10-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

kaito834@infosec.exchange at 2026-10-08T23:15:40.000Z ##

直近で相次いでいる国内組織における不正アクセスに関する注意喚起 jpcert.or.jp/m/at/2026/at26003 2026-10-08
JPCERT/CCに寄せられた情報などでは:
ケースA:...既知の脆弱性を探索し攻撃試行するもの
ケースB:API経由での不正な操作
ケースC:MetabaseのSQLインジェクションの脆弱性(CVE-2026-72898)

ケースBの場合:
(a)一般公開しているスマートフォンアプリを解析しAPIのエンドポイントやキーを特定する
(b)本来画面操作では実行できない内部APIに対する攻撃
(c)他のシステムの侵害で窃取したAPIキーを使用する

##

japancyberwatch@infosec.exchange at 2026-10-08T11:28:03.000Z ##

JPCERT/CC has issued a warning on the wave of data breaches at Japanese organizations since around September.

Not one shared flaw. Three patterns:
- Scanning each target for known vulns and exposed config/backup files
- Internal API abuse, with endpoints and keys pulled from public smartphone apps
- Metabase SQLi (CVE-2026-72898)

Attacker IPs published. Macnica counts 119 similar breaches in Japan this year, 81 since July.

japancyberwatch.com/articles/j

#cybersecurity #APIsecurity #Japan #infosec

##

mayaeh@taruntarun.net at 2026-10-08T04:50:00.000Z ##

Xユーザーのconnect24hさん: 「JPCERTさん.ありがとうございます!
全CSIRTが感謝!

不審な送信元IPアドレス
- 3.112.252[.]14
- 54.95.112[.]6
- 69.10.51[.]162
- 172.86.91[.]7
- 210.149.87[.]120

User-Agentの例
- curl/7.88.1
- python-requests/2.34.2
- Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0 Safari/537.36

ケースC:MetabaseのSQLインジェクションの脆弱性(CVE-2026-72898) / X
x.com/connect24h/status/210803

##

CVE-2026-106433
(0 None)

EPSS: 0.27%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-08T19:46:04.000Z ##

🟠 CVE-2026-106433 - High (8.8)

Improper state management in MongoDB libmongocrypt can cause provider-specific data to be treated as an incompatible type when cleaning up a key document containing duplicate masterKey fields. An authenticated actor who can modify key vault docume...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107332
(0 None)

EPSS: 0.10%

1 posts

N/A

awssecurityfeed@infosec.exchange at 2026-10-08T17:45:00.000Z ##

CVE-2026-107332 - Insecure default file permissions on cached credentials in AWS Toolkit for Visual Studio Code

Bulletin ID: 2026-129-AWS

Scope: AWS

Content Type: Important (requires attention)

Publication Date: 10/08/2026 10:30 PM PDT
Description:
AWS Toolkit for Visual Studio Code is an open source extension that lets developers ...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-77459
(0 None)

EPSS: 0.00%

1 posts

N/A

CVE-2026-103059
(0 None)

EPSS: 0.28%

1 posts

N/A

CVE-2026-101027
(0 None)

EPSS: 0.17%

1 posts

N/A

Visit counter For Websites