## Updated at UTC 2026-08-12T10:00:27.259094

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2025-41771 4.3 0.00% 2 0 2026-08-12T08:17:12.130000 An authenticated attacker with low privileges can access an endpoint in the cont
CVE-2025-41770 7.5 0.00% 2 0 2026-08-12T08:17:11.910000 An unauthenticated denial-of-service vulnerability in the device's PLCnext Engin
CVE-2025-41769 9.8 0.00% 2 0 2026-08-12T08:17:11.590000 The device's PROFINET service is affected by a buffer overflow vulnerability tha
CVE-2026-66659 9.3 0.00% 2 0 2026-08-12T06:31:00 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CVE-2026-64954 8.2 0.00% 2 0 2026-08-12T06:30:49 Velociraptor allows scheduling new collections via VQL queries in notebooks. For
CVE-2026-68820 7.0 0.00% 20 0 2026-08-12T05:19:45.527000 Use after free in Windows Ancillary Function Driver for WinSock allows an author
CVE-2026-66147 9.4 0.00% 2 0 2026-08-12T05:19:32.523000 An unauthenticated command injection vulnerability was identified in the GMS Dis
CVE-2026-62832 7.8 0.00% 1 0 2026-08-12T05:18:51.970000 Improper link resolution before file access ('link following') in Windows User P
CVE-2026-58641 7.8 0.00% 1 0 2026-08-12T05:17:57.853000 Integer overflow or wraparound in .NET allows an unauthorized attacker to elevat
CVE-2026-58243 8.8 0.31% 1 0 2026-08-12T05:17:57.427000 SAP ABAP Development Tools does not perform necessary authorization checks for c
CVE-2026-58231 10.0 0.00% 4 0 2026-08-12T05:17:56.963000 SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authent
CVE-2026-34265 9.8 0.44% 5 0 2026-08-12T05:17:46.207000 SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to expl
CVE-2026-20349 8.6 0.00% 13 0 2026-08-12T05:17:44.330000 A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall A
CVE-2026-73122 7.7 0.00% 2 0 2026-08-12T03:31:23 A flaw was found in the multicloud-operators-channel component of Red Hat Advanc
CVE-2026-6484 8.2 0.00% 2 0 2026-08-12T03:31:23 In an UEFI, Lack of verified boot to certain FV may cause arbitrary code executi
CVE-2026-72526 9.9 0.00% 4 0 2026-08-12T03:31:18 A flaw was found in the multicloud-integrations component. The Application propa
CVE-2026-70398 9.6 0.00% 4 0 2026-08-12T03:31:17 A flaw was found in multicloud-integrations, a component of Red Hat Advanced Clu
CVE-2026-18961 8.1 0.00% 2 0 2026-08-12T03:16:42.807000 The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by Ventr
CVE-2026-68067 9.8 0.00% 4 0 2026-08-12T00:31:23 The login endpoint on the Mira cloud API accepts any format-valid string in the
CVE-2026-67568 9.1 0.00% 4 0 2026-08-12T00:31:23 The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access
CVE-2026-66875 8.8 0.00% 2 0 2026-08-12T00:31:23 In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote u
CVE-2026-19556 None 0.00% 2 0 2026-08-12T00:31:18 Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote a
CVE-2026-19560 None 0.00% 2 0 2026-08-12T00:31:11 Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remot
CVE-2026-73249 7.5 0.00% 2 0 2026-08-11T22:19:05.687000 calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoi
CVE-2026-73247 8.6 0.00% 2 0 2026-08-11T22:19:05.417000 Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, K
CVE-2026-15562 7.5 0.35% 1 0 2026-08-11T21:33:39 A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who
CVE-2026-18948 9.9 0.69% 2 0 2026-08-11T21:33:39 A flaw was found in Feast. The system improperly deserializes user-defined funct
CVE-2026-18951 8.8 0.65% 1 0 2026-08-11T21:33:39 A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training op
CVE-2026-18950 8.8 0.40% 1 0 2026-08-11T21:33:39 A flaw was found in odh-dashboard. An authenticated user of the dashboard can ex
CVE-2026-18947 8.5 0.49% 1 0 2026-08-11T21:33:35 A flaw was found in Feast. An authorization bypass vulnerability exists in the /
CVE-2026-16985 8.8 0.19% 1 0 2026-08-11T21:32:30 The Squeeze WordPress plugin before 1.7.12 does not validate the file type or e
CVE-2026-10579 9.8 0.39% 1 0 2026-08-11T21:17:24.910000 A flaw was found in Picketlink Federation SAML; the unsolcited response handler
CVE-2026-73234 7.8 0.00% 1 0 2026-08-11T20:18:48.833000 FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to
CVE-2026-73232 7.5 0.00% 1 0 2026-08-11T20:18:48.543000 ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious
CVE-2026-73226 8.8 0.00% 1 0 2026-08-11T20:18:48.007000 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ft
CVE-2026-18949 8.8 0.40% 1 0 2026-08-11T19:17:31.520000 A flaw was found in odh-dashboard. This vulnerability allows an attacker, who ha
CVE-2026-62901 7.5 0.00% 1 0 2026-08-11T18:53:58 ## Executive summary Microsoft is releasing this security advisory to provide i
CVE-2026-18786 8.8 0.19% 1 0 2026-08-11T18:31:45 The CheckView WordPress plugin before 2.3.2 does not restrict its REST API auth
CVE-2026-53414 6.5 0.00% 1 0 2026-08-11T18:30:54 Missing bounds check in the annotator function of Zoom Clients allows buffer ove
CVE-2026-53413 8.3 0.00% 1 0 2026-08-11T18:30:54 Missing bounds check in the annotator function of Zoom Clients allows buffer ove
CVE-2026-56721 8.8 0.00% 1 0 2026-08-11T18:30:54 CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerabil
CVE-2026-67180 8.4 0.00% 1 0 2026-08-11T18:30:53 Google Turbinia allows arbitrary command execution via worker tasks. An attacker
CVE-2026-13738 None 0.00% 1 0 2026-08-11T18:30:43 CommServe contained an authorization bypass vulnerability affecting a limited se
CVE-2026-73079 8.5 0.00% 1 0 2026-08-11T17:19:15.747000 Sub2API is an AI API gateway platform designed to distribute and manage API quot
CVE-2026-71217 7.5 0.33% 1 0 2026-08-11T17:19:12.937000 A flaw was found in iperf3. A remote attacker can exploit this vulnerability by
CVE-2026-53415 8.3 0.00% 1 0 2026-08-11T17:18:03.250000 Use after Free in the annotator function of Zoom Clients may allow a meeting par
CVE-2026-19516 9.1 0.23% 1 0 2026-08-11T17:17:48.383000 A caller-supplied X-Grafana-URL request header controls the destination of mcp-g
CVE-2026-72903 8.1 0.31% 1 0 2026-08-11T16:17:37.360000 Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1
CVE-2026-67179 7.8 0.00% 1 0 2026-08-11T16:17:34.113000 Genkit does not properly validate host request headers. Any host on the develope
CVE-2026-73080 9.3 0.00% 1 0 2026-08-11T15:58:24 ### Impact `VolumeServer.FetchAndWriteNeedle` fetches a caller-supplied remote e
CVE-2026-58115 10.0 0.00% 2 0 2026-08-11T15:32:40 A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1
CVE-2026-18972 9.6 0.00% 1 0 2026-08-11T15:32:40 An authenticated attacker can spoof another GUI user's identity by sending their
CVE-2026-72922 8.2 0.00% 1 0 2026-08-11T15:17:38.350000 AutoGPT is a workflow automation platform for creating, deploying, and managing
CVE-2026-72864 9.9 0.27% 1 0 2026-08-11T15:17:36.393000 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13,
CVE-2026-44758 9.1 0.51% 4 0 2026-08-11T15:17:29.603000 SAP Manufacturing Integration and Intelligence (MII) allows an attacker with hig
CVE-2026-46670 9.8 0.00% 1 0 template 2026-08-11T14:17:13.863000 YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthentic
CVE-2026-72693 7.8 0.10% 1 0 2026-08-11T09:32:42 `openvt -u` is intended to identify the owner of the current VT and then execute
CVE-2026-19425 9.8 0.47% 1 0 2026-08-11T06:31:25 Travel Agency Management System developed by Win Men Intermational has a SQL Inj
CVE-2026-13716 9.1 0.56% 1 0 2026-08-11T06:31:25 Path traversal in server import and admin file upload in Crafty Controller. Allo
CVE-2026-44763 7.6 0.28% 1 0 2026-08-11T03:32:04 SAP Manufacturing Integration and Intelligence allows a privileged attacker to e
CVE-2026-66763 7.9 0.13% 1 0 2026-08-11T03:32:04 SAP BusinessObjects Business Intelligence Platform stores certain sensitive cred
CVE-2026-8917 None 0.11% 1 0 2026-08-11T03:31:59 Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and
CVE-2026-8718 8.4 0.12% 1 0 2026-08-10T23:16:51.587000 tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tl
CVE-2026-73030 8.1 0.38% 1 0 2026-08-10T21:32:15 unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulne
CVE-2026-63622 7.8 0.13% 1 0 2026-08-10T21:32:08 A flaw was found in libvirt. A local attacker, specifically a process running as
CVE-2026-72886 9.9 0.36% 1 0 2026-08-10T20:17:35.423000 Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until
CVE-2026-72730 8.7 0.24% 1 0 2026-08-10T19:17:33.807000 Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 20
CVE-2026-72689 7.5 0.32% 1 0 2026-08-10T19:17:33.103000 A broken object-level authorization vulnerability in OpenSignLabs opensignserver
CVE-2026-71576 8.5 0.12% 1 0 2026-08-10T18:32:24 A flaw was found in multicluster-global-hub. The manager component improperly va
CVE-2026-19381 7.8 0.11% 2 0 2026-08-10T18:17:42.733000 A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2
CVE-2026-66738 8.8 0.40% 1 0 2026-08-10T17:17:35.557000 SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed inst
CVE-2026-19387 7.6 0.24% 1 0 2026-08-10T17:17:30.323000 A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-
CVE-2026-72691 7.5 0.39% 1 0 2026-08-10T15:33:59 An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.
CVE-2026-63106 9.8 0.29% 1 0 2026-08-10T15:33:59 ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerabil
CVE-2026-13206 9.8 1.27% 1 0 2026-08-10T15:33:42 Improper neutralization of special elements used in an OS command ('OS command i
CVE-2026-18933 7.2 0.28% 1 0 2026-08-10T12:17:14.430000 The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the
CVE-2026-19389 7.1 0.24% 1 0 2026-08-10T03:31:01 Multiple integer overflow and underflow vulnerabilities were found in the GStrea
CVE-2026-15534 0 0.20% 1 0 2026-08-09T22:16:30.373000 Perl versions through 5.45.1 have out-of-bounds heap reads and writes during reg
CVE-2026-64564 9.8 0.48% 4 4 2026-08-09T06:31:34 In the Linux kernel, the following vulnerability has been resolved: sctp: don't
CVE-2026-71993 9.8 1.35% 1 0 2026-08-09T00:31:13 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-5857 8.1 0.53% 1 0 2026-08-08T03:16:46.377000 Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c se
CVE-2026-64638 0 0.77% 2 20 template 2026-08-07T19:18:51.610000 WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login s
CVE-2026-67687 8.8 0.53% 1 1 2026-08-07T18:32:48 Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to
CVE-2026-20339 7.5 0.33% 1 0 2026-08-07T18:31:54 A vulnerability in the PESpin file format parser of ClamAV could allow an unauth
CVE-2026-20338 7.5 0.33% 5 0 2026-08-07T18:31:53 A vulnerability in the zip archive parser of ClamAV could allow an unauthenticat
CVE-2026-20337 7.5 0.36% 5 0 2026-08-07T18:31:52 A vulnerability in the zip archive parser of ClamAV could allow an unauthenticat
CVE-2026-67621 7.6 0.27% 1 0 2026-08-07T18:31:42 Flowise through 3.1.4 contains a missing authorization vulnerability that allows
CVE-2026-70628 7.8 0.15% 1 0 2026-08-07T18:31:42 FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer
CVE-2026-15733 9.8 3.90% 1 0 2026-08-07T18:31:37 A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 a
CVE-2026-8037 9.6 99.31% 2 2 template 2026-08-07T18:31:36 OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC
CVE-2026-67422 7.5 0.58% 1 0 2026-08-07T18:26:08 ### Summary Four inline processors in pymdown-extensions contain regular expres
CVE-2026-67622 9.9 0.25% 1 0 2026-08-07T18:17:21.357000 Flowise through 3.1.4 contains an insecure direct object reference vulnerability
CVE-2026-67688 9.8 0.59% 1 0 2026-08-07T16:17:27.400000 ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload
CVE-2026-67689 9.8 0.69% 1 1 2026-08-07T15:34:17 SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execut
CVE-2026-5855 7.5 0.54% 1 0 2026-08-07T00:31:27 Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c
CVE-2026-53984 9.1 0.38% 1 0 2026-08-07T00:31:26 Ground Station prior to 0.6.0 contains an unauthenticated database-destruction a
CVE-2026-53983 8.6 0.33% 1 0 2026-08-07T00:31:26 Ground Station prior to 0.6.0 contains an unauthenticated blind server-side requ
CVE-2026-64665 8.1 0.31% 1 0 2026-08-06T19:25:06 ### Impact When OAuth login is enabled with a provider that does not guarantee
CVE-2026-10090 9.9 0.25% 1 0 2026-08-06T15:37:22.093000 A flaw was found in the Application Subscription controller (multicluster-operat
CVE-2026-19036 7.2 2.47% 1 0 2026-08-06T15:32:48 A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the
CVE-2026-19034 7.2 2.47% 1 0 2026-08-06T12:31:21 A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vuln
CVE-2026-19035 7.2 2.47% 1 0 2026-08-06T12:31:21 A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issu
CVE-2026-34966 7.6 0.31% 2 0 2026-08-05T21:31:47 Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that
CVE-2026-63077 9.8 10.72% 2 4 template 2026-08-05T18:32:31 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe
CVE-2026-70374 8.8 0.97% 1 0 2026-08-05T15:32:14 HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-
CVE-2026-18900 7.2 2.38% 1 0 2026-08-05T15:16:46.037000 A weakness has been identified in H3C NX15 V100R017. This impacts the function f
CVE-2026-71249 6.1 0.15% 1 0 2026-08-05T12:31:36 299Ko's public contact form (plugin/contact/controllers/ContactController.php, h
CVE-2026-55739 8.3 0.27% 1 0 2026-08-05T09:31:26 Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense po
CVE-2026-18902 7.2 2.38% 1 0 2026-08-05T06:30:32 A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerabilit
CVE-2026-18814 7.2 2.71% 1 0 2026-08-05T00:30:41 A vulnerability was found in H3C NX15 V100R017. This impacts the function reload
CVE-2026-18686 9.8 2.61% 1 0 2026-08-04T16:16:21.593000 A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected elem
CVE-2026-18577 8.1 4.10% 3 3 2026-08-04T14:27:12.530000 An incomplete patch for CVE-2026-18556 allows for authentication bypass and acco
CVE-2026-18601 9.8 2.38% 1 0 2026-08-03T20:17:16.310000 A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the fun
CVE-2026-17656 9.6 0.40% 1 0 2026-07-30T21:32:37 Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote
CVE-2026-17650 8.3 0.35% 1 0 2026-07-30T21:31:31 Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a
CVE-2026-64560 7.8 0.12% 2 1 2026-07-30T12:32:18 In the Linux kernel, the following vulnerability has been resolved: posix-cpu-t
CVE-2026-64747 7.8 0.14% 2 1 2026-07-28T15:32:12 A buffer overflow was addressed with improved size validation. This issue is fix
CVE-2026-59765 None 0.00% 2 0 2026-07-21T21:55:32 ### Summary Gitea has robust SSRF protection via `hostmatcher.NewDialContext()`
CVE-2026-53361 7.1 0.13% 3 1 2026-07-18T09:32:17 In the Linux kernel, the following vulnerability has been resolved: af_unix: Se
CVE-2026-55040 9.1 1.63% 8 2 2026-07-14T18:32:38 Weak authentication in Microsoft Office SharePoint allows an unauthorized attack
CVE-2026-31431 7.8 99.91% 1 100 template 2026-07-14T15:32:55 In the Linux kernel, the following vulnerability has been resolved: crypto: alg
CVE-2026-12879 0 0.19% 1 0 2026-07-09T16:39:17.737000 An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apige
CVE-2026-50656 7.8 10.75% 8 3 2026-07-09T00:17:26.607000 Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect
CVE-2026-45659 8.8 9.12% 2 2 2026-07-01T21:35:53 Deserialization of untrusted data in Microsoft Office SharePoint allows an autho
CVE-2026-43074 7.8 0.48% 1 1 2026-06-17T10:48:53.150000 In the Linux kernel, the following vulnerability has been resolved: eventpoll:
CVE-1999-1587 0 0.95% 1 0 2026-06-16T21:50:46.783000 /usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, a
CVE-2026-34486 7.5 82.93% 1 6 template 2026-06-08T23:28:56 Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the f
CVE-2026-48048 7.5 0.36% 1 0 2026-05-26T20:17:03 ### Impact XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insuffici
CVE-2026-27912 8.0 0.24% 1 2 2026-04-14T18:30:50 Improper authorization in Windows Kerberos allows an authorized attacker to elev
CVE-2003-0190 None 76.75% 1 0 2026-03-22T05:08:29 OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediat
CVE-2025-7771 None 6.83% 1 12 2025-08-06T12:31:25 ThrottleStop.sys, a legitimate driver, exposes two IOCTL interfaces that allow a
CVE-2026-44772 0 0.00% 2 0 N/A
CVE-2026-72915 0 0.28% 3 0 N/A
CVE-2026-72916 0 0.36% 2 0 N/A
CVE-2026-72914 0 0.45% 3 0 N/A
CVE-2026-12234 0 0.00% 2 0 N/A
CVE-2026-48765 0 0.00% 3 0 N/A
CVE-2026-73246 0 0.00% 2 0 N/A
CVE-2026-48763 0 0.00% 1 0 N/A
CVE-2026-55676 0 0.00% 1 0 N/A
CVE-2026-72898 0 0.69% 2 0 template N/A
CVE-2026-73231 0 0.00% 1 0 N/A
CVE-2026-73225 0 0.00% 1 0 N/A
CVE-2026-73224 0 0.00% 1 0 N/A
CVE-2026-73069 0 0.00% 1 0 N/A
CVE-2026-72921 0 0.00% 1 0 N/A
CVE-2026-72920 0 0.00% 1 0 N/A
CVE-2026-17106 0 0.00% 1 2 N/A
CVE-2026-44945 0 0.30% 1 0 N/A
CVE-2026-48161 0 0.42% 1 0 N/A
CVE-2026-72911 0 0.38% 1 0 N/A
CVE-2026-72901 0 0.63% 1 0 N/A
CVE-2026-72883 0 0.40% 1 0 N/A
CVE-2026-72872 0 0.37% 1 0 N/A
CVE-2026-72871 0 0.29% 1 0 N/A
CVE-2026-47754 0 0.34% 1 0 N/A
CVE-2026-5423 0 0.34% 1 0 N/A
CVE-2026-60137 0 73.10% 1 52 N/A
CVE-2026-63030 0 95.60% 1 81 template N/A
CVE-2026-48085 0 0.55% 1 0 N/A
CVE-2026-63637 0 0.24% 1 0 N/A

CVE-2025-41771
(4.3 MEDIUM)

EPSS: 0.00%

updated 2026-08-12T08:17:12.130000

2 posts

An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the system’s notification functionality.

certvde at 2026-08-12T08:07:13.931Z ##

VDE-2025-056
Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware

This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.
CVE-2025-41769, CVE-2025-41770, CVE-2025-41771

certvde.com/en/advisories/vde-

phoenixcontact.csaf-tp.certvde

##

certvde@infosec.exchange at 2026-08-12T08:07:13.000Z ##

#OT #Advisory VDE-2025-056
Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware

This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.
#CVE CVE-2025-41769, CVE-2025-41770, CVE-2025-41771

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2025-41770
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-12T08:17:11.910000

2 posts

An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted.

certvde at 2026-08-12T08:07:13.931Z ##

VDE-2025-056
Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware

This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.
CVE-2025-41769, CVE-2025-41770, CVE-2025-41771

certvde.com/en/advisories/vde-

phoenixcontact.csaf-tp.certvde

##

certvde@infosec.exchange at 2026-08-12T08:07:13.000Z ##

#OT #Advisory VDE-2025-056
Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware

This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.
#CVE CVE-2025-41769, CVE-2025-41770, CVE-2025-41771

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2025-41769
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-12T08:17:11.590000

2 posts

The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.

certvde at 2026-08-12T08:07:13.931Z ##

VDE-2025-056
Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware

This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.
CVE-2025-41769, CVE-2025-41770, CVE-2025-41771

certvde.com/en/advisories/vde-

phoenixcontact.csaf-tp.certvde

##

certvde@infosec.exchange at 2026-08-12T08:07:13.000Z ##

#OT #Advisory VDE-2025-056
Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware

This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.
#CVE CVE-2025-41769, CVE-2025-41770, CVE-2025-41771

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-66659
(9.3 CRITICAL)

EPSS: 0.00%

updated 2026-08-12T06:31:00

2 posts

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Injection. This issue affects Tablesome Table: from n/a through 1.2.9.

offseq at 2026-08-12T07:30:27.118Z ##

CVE-2026-66659: CRITICAL SQL Injection (CVSS 9.3) in Essekia Tablesome Table ≤1.2.9. Allows unauth’d blind SQLi & data disclosure. No patch yet — monitor vendor updates. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-12T07:30:27.000Z ##

CVE-2026-66659: CRITICAL SQL Injection (CVSS 9.3) in Essekia Tablesome Table ≤1.2.9. Allows unauth’d blind SQLi & data disclosure. No patch yet — monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #SQLInjection #Vuln #Infosec

##

CVE-2026-64954
(8.2 HIGH)

EPSS: 0.00%

updated 2026-08-12T06:30:49

2 posts

Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider. This allows a user who can run arbitrary VQL (usually with the "analyst" role) to launch new collections (usually requires the "inve

thehackerwire@mastodon.social at 2026-08-12T06:00:25.000Z ##

🟠 CVE-2026-64954 - High (8.2)

Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the auth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T06:00:25.000Z ##

🟠 CVE-2026-64954 - High (8.2)

Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the auth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68820
(7.0 HIGH)

EPSS: 0.00%

updated 2026-08-12T05:19:45.527000

20 posts

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

offseq at 2026-08-12T09:00:32.200Z ##

CVE-2026-68820: CRITICAL Windows afd.sys zero-day exploited by Lazarus Group for SYSTEM access in defense/aerospace. Patch released 2026-08-11. Prioritize updates & check for ForestTiger/Troy backdoors. radar.offseq.com/threat/fresh-

##

VirusBulletin at 2026-08-12T08:50:09.841Z ##

Check Point researchers look into the latest variant of the Operation Dream Job campaign where the threat actor exploited CVE-2026-68820, a zero-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of Lazarus’s kernel-mode rootkit FudModule. research.checkpoint.com/2026/s

##

thecybermind at 2026-08-12T08:49:26.242Z ##

🚨 THREAT ALERT: CISA adds CVE-2026-68820 (Windows WinSock AFD Use-After-Free) to the KEV catalog due to active exploitation. Local attackers can elevate privileges to system level. Access our TSUITE brief with CrowdStrike CQL telemetry queries: thecybermind.co/jily

##

ottoto2017@prattohome.com at 2026-08-12T06:07:08.000Z ##

「Microsoft 製品の脆弱性対策について(2026年8月)」: #IPA

「 2026年8月12日(日本時間)に Microsoft 製品に関するセキュリティ更新プログラム(月例)が公表されています。
これらの脆弱性を悪用された場合、アプリケーションプログラムが異常終了する、攻撃者によってパソコンを制御される、といった様々な被害が発生するおそれがあります。

この内 CVE-2026-68820 の脆弱性について、Microsoft 社では悪用の事実を確認済みと公表しており、今後被害が拡大するおそれがあるため、至急、セキュリティ更新プログラムを適用してください。 」

ipa.go.jp/security/security-al

#prattohome

##

sayzard@mastodon.sayzard.org at 2026-08-12T05:46:34.000Z ##

Bugs in MS' Patch Tuesday release and NK's Lazarus has hit one already

Microsoft의 2026년 8월 Patch Tuesday는 421개 취약점을 수정했으며, 그중 Windows WinSock Ancillary Function Driver(afd.sys)의 use-after-free 취약점 CVE-2026-68820은 Lazarus 그룹이 패치 전 실제 공격에 사용한 제로데이다. 로컬 인증 사용자가 경쟁 조건을 유발해 사용자 상호작용 없이 SYSTEM 권한 코드 실행을...

theregister.com/security/2026/

##

ottoto2017@prattohome.com at 2026-08-12T04:51:43.000Z ##

「マイクロソフトは、現在攻撃を受けているWindowsドライバーのゼロデイ脆弱性を含む398件の脆弱性を修正した。 」: #TheHackerNews

「マイクロソフトは火曜日に月例のセキュリティアップデートを公開したが、修正された脆弱性の1つが既に攻撃に悪用されている。

このバグは、ネットワークソケット操作を処理するWindowsカーネルの中核ドライバに存在します。既にマシン上でコードを実行している攻撃者は、このバグを利用してSYSTEM権限に昇格できます。このパッチが最初にリリースされます。

この脆弱性は CVE-2026-68820 (CVSSスコア:7.0)として追跡されており、今月のリリースでマイクロソフトが現在悪用されていると警告している唯一の脆弱性です。悪用は、ドライバーの競合状態をトリガーすることによって行われます。マイクロソフトは、この悪用を行った組織を公表していません。」

thehackernews.com/2026/08/micr

#prattohome

##

sayzard@mastodon.sayzard.org at 2026-08-12T03:43:20.000Z ##

Microsoft Plugs Nearly 400 Security Holes

Microsoft가 8월 Patch Tuesday에서 Windows 및 지원 소프트웨어의 취약점 최소 398건을 수정했으며, 이 중 42건은 원격 코드 실행 등으로 이어질 수 있는 Critical 등급이다. 이미 악용 중인 CVE-2026-68820은 거의 모든 Windows 엔드포인트의 소켓 연결에 관여하는 afd.sys의 권한 상승 취약점으로, 초기 침투 후 시스템 장악 체인에 사용될 수 있다. 또한 Windows User Profile Service의 CVE-2026-62832는 공개된 LegacyHive 이슈와 연관 가능성이 있으며 악용 가능성이 높은 것으로...

krebsonsecurity.com/2026/08/mi

##

DailyCyberSecurity at 2026-08-12T02:44:48.174Z ##

Lazarus exploited a Windows zero-day (CVE-2026-68820) in Operation Dream Job to hit defense firms with fake job offers and a new backdoor.

securityonline.info/lazarus-ze

##

DailyCyberSecurity at 2026-08-12T02:21:44.193Z ##

Microsoft August 2026 Patch Tuesday fixes 421 flaws, including CVE-2026-68820, a WinSock zero-day exploited in the wild, plus two disclosed bugs.

securityonline.info/microsoft-

##

sayzard@mastodon.sayzard.org at 2026-08-12T00:40:40.000Z ##

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

Microsoft의 2026년 8월 Patch Tuesday는 총 400개 취약점(치명적 42개 포함)을 수정하며, 원격 코드 실행 110개와 권한 상승 176개가 포함된다. 특히 CVE-2026-68820은 Windows AFD.sys(WinSock Ancillary Function Driver)의 use-after-free 기반 로컬 권한 상승 취약점으로, Lazarus가 FudModule 커널 루트킷 배포에 실제 악용한 정황이 보고됐다. 공개된 Windows...

bleepingcomputer.com/news/micr

##

offseq@infosec.exchange at 2026-08-12T09:00:32.000Z ##

CVE-2026-68820: CRITICAL Windows afd.sys zero-day exploited by Lazarus Group for SYSTEM access in defense/aerospace. Patch released 2026-08-11. Prioritize updates & check for ForestTiger/Troy backdoors. radar.offseq.com/threat/fresh- #OffSeq #ZeroDay #Windows #Cybersecurity

##

VirusBulletin@infosec.exchange at 2026-08-12T08:50:09.000Z ##

Check Point researchers look into the latest variant of the Operation Dream Job campaign where the threat actor exploited CVE-2026-68820, a zero-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of Lazarus’s kernel-mode rootkit FudModule. research.checkpoint.com/2026/s

##

thecybermind@infosec.exchange at 2026-08-12T08:49:26.000Z ##

🚨 THREAT ALERT: CISA adds CVE-2026-68820 (Windows WinSock AFD Use-After-Free) to the KEV catalog due to active exploitation. Local attackers can elevate privileges to system level. Access our TSUITE brief with CrowdStrike CQL telemetry queries: thecybermind.co/jily

#CyberSecurity

##

ottoto2017@prattohome.com at 2026-08-12T06:07:08.000Z ##

「Microsoft 製品の脆弱性対策について(2026年8月)」: #IPA

「 2026年8月12日(日本時間)に Microsoft 製品に関するセキュリティ更新プログラム(月例)が公表されています。
これらの脆弱性を悪用された場合、アプリケーションプログラムが異常終了する、攻撃者によってパソコンを制御される、といった様々な被害が発生するおそれがあります。

この内 CVE-2026-68820 の脆弱性について、Microsoft 社では悪用の事実を確認済みと公表しており、今後被害が拡大するおそれがあるため、至急、セキュリティ更新プログラムを適用してください。 」

ipa.go.jp/security/security-al

#prattohome

##

ottoto2017@prattohome.com at 2026-08-12T04:51:43.000Z ##

「マイクロソフトは、現在攻撃を受けているWindowsドライバーのゼロデイ脆弱性を含む398件の脆弱性を修正した。 」: #TheHackerNews

「マイクロソフトは火曜日に月例のセキュリティアップデートを公開したが、修正された脆弱性の1つが既に攻撃に悪用されている。

このバグは、ネットワークソケット操作を処理するWindowsカーネルの中核ドライバに存在します。既にマシン上でコードを実行している攻撃者は、このバグを利用してSYSTEM権限に昇格できます。このパッチが最初にリリースされます。

この脆弱性は CVE-2026-68820 (CVSSスコア:7.0)として追跡されており、今月のリリースでマイクロソフトが現在悪用されていると警告している唯一の脆弱性です。悪用は、ドライバーの競合状態をトリガーすることによって行われます。マイクロソフトは、この悪用を行った組織を公表していません。」

thehackernews.com/2026/08/micr

#prattohome

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T02:44:48.000Z ##

Lazarus exploited a Windows zero-day (CVE-2026-68820) in Operation Dream Job to hit defense firms with fake job offers and a new backdoor.

#Lazarus #ZeroDay #CVE202668820 #OperationDreamJob #Cybersecurity #DPRK #FudModule #DefenseSector

securityonline.info/lazarus-ze

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T02:21:44.000Z ##

Microsoft August 2026 Patch Tuesday fixes 421 flaws, including CVE-2026-68820, a WinSock zero-day exploited in the wild, plus two disclosed bugs.

#PatchTuesday #Microsoft #ZeroDay #CVE #WindowsSecurity #InfoSec

securityonline.info/microsoft-

##

secdb@infosec.exchange at 2026-08-11T21:00:13.000Z ##

🚨 [CISA-2026:0811] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-20349 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-68820 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows Ancillary Function Driver for WinSock
- Notes: portal.msrc.microsoft.com/en-U ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-72898 (secdb.nttzen.cloud/cve/detail/)
- Name: Metabase SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Metabase
- Product: Metabase
- Notes: metabase.com/blog/security-upd ; github.com/metabase/metabase/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260811 #cisa20260811 #cve_2026_20349 #cve_2026_68820 #cve_2026_72898 #cve202620349 #cve202668820 #cve202672898

##

cyberworldops@infosec.exchange at 2026-08-11T20:10:00.000Z ##

Microsoft Patch Tuesday August 2026 patches 421 CVEs including CVE-2026-68820, an actively exploited use-after-free in the kernel driver afd.sys that grants SYSTEM-level privileges. Attacks are ongoing and no operational details have been disclosed yet. Prioritize patching on exposed systems.

#PatchTuesday #ZeroDay #VulnerabilityManagement #Microsoft

cyberworldops.eu/en/microsoft-

##

cisakevtracker@mastodon.social at 2026-08-11T20:01:05.000Z ##

CVE ID: CVE-2026-68820
Vendor: Microsoft
Product: Windows Ancillary Function Driver for WinSock
Date Added: 2026-08-11
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-66147
(9.4 CRITICAL)

EPSS: 0.00%

updated 2026-08-12T05:19:32.523000

2 posts

An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.

DailyCyberSecurity at 2026-08-12T00:45:54.822Z ##

SonicWall patched a critical GMS vulnerability, CVE-2026-66147 (CVSS 9.4), enabling unauthenticated remote code execution. Update to 9.5.2 now.

securityonline.info/sonicwall-

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T00:45:54.000Z ##

SonicWall patched a critical GMS vulnerability, CVE-2026-66147 (CVSS 9.4), enabling unauthenticated remote code execution. Update to 9.5.2 now.

#SonicWall #CVE #RCE #GMS #EmailSecurity #InfoSec

securityonline.info/sonicwall-

##

CVE-2026-62832
(7.8 HIGH)

EPSS: 0.00%

updated 2026-08-12T05:18:51.970000

1 posts

Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.

sayzard@mastodon.sayzard.org at 2026-08-12T03:43:20.000Z ##

Microsoft Plugs Nearly 400 Security Holes

Microsoft가 8월 Patch Tuesday에서 Windows 및 지원 소프트웨어의 취약점 최소 398건을 수정했으며, 이 중 42건은 원격 코드 실행 등으로 이어질 수 있는 Critical 등급이다. 이미 악용 중인 CVE-2026-68820은 거의 모든 Windows 엔드포인트의 소켓 연결에 관여하는 afd.sys의 권한 상승 취약점으로, 초기 침투 후 시스템 장악 체인에 사용될 수 있다. 또한 Windows User Profile Service의 CVE-2026-62832는 공개된 LegacyHive 이슈와 연관 가능성이 있으며 악용 가능성이 높은 것으로...

krebsonsecurity.com/2026/08/mi

##

CVE-2026-58641
(7.8 HIGH)

EPSS: 0.00%

updated 2026-08-12T05:17:57.853000

1 posts

Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.

us@newsbeep.org at 2026-08-11T23:40:13.000Z ##

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

Tag
CVE ID
CVE Title
Severity
.NET
CVE-2026-58641
.NET Elevation of Privilege Vulnerability
Important
.NET
CVE-2026-62901
.NET Denial…
#NewsBeep #News #US #USA #UnitedStates #UnitedStatesOfAmerica #Technology
newsbeep.com/us/810540/

##

CVE-2026-58243
(8.8 HIGH)

EPSS: 0.31%

updated 2026-08-12T05:17:57.427000

1 posts

SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could allow the attacker to read sensitive data, modify application data, and disrupt access for legitimate users, resulting in high impact on confidentiality

thehackerwire@mastodon.social at 2026-08-11T02:00:11.000Z ##

🟠 CVE-2026-58243 - High (8.8)

SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58231
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-08-12T05:17:56.963000

4 posts

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

undercodenews@mastodon.social at 2026-08-12T08:29:46.000Z ##

SAP Issues Emergency-Grade Patch for CVSS 100 Commerce Cloud Flaw That Could Enable Unauthenticated Code Execution + Video

A Critical Warning for SAP Enterprise Customers A maximum-severity vulnerability in SAP Commerce Cloud has put enterprise e-commerce environments under renewed security pressure. The newly identified flaw, tracked as CVE-2026-58231, carries the highest possible CVSS score of 10.0 and could allow an unauthenticated attacker to execute arbitrary code…

undercodenews.com/sap-issues-e

##

beyondmachines1 at 2026-08-12T08:01:15.265Z ##

SAP August 2026 Patch Day Fixes Critical Code Injection and Memory Corruption Flaws

SAP's August 2026 Security Patch Day addresses 31 vulnerabilities, including a critical CVSS 10.0 authentication bypass in Commerce Cloud and code injection flaws in Manufacturing Integration and Intelligence. These vulnerabilities allow remote attackers to execute arbitrary commands and gain unauthorized access to internal enterprise systems.

**If you run SAP products, especially Manufacturing Integration and Intelligence (MII) read the advisory in detail. First make sure these systems are isolated from the internet where possible and reachable only from trusted internal networks. Then apply SAP's August 2026 security notes ASAP starting with the critical fixes for Commerce Cloud (CVE-2026-58231) and MII (CVE-2026-44772, CVE-2026-44758), followed by the ABAP Platform patch (CVE-2026-34265).**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-08-12T08:01:15.000Z ##

SAP August 2026 Patch Day Fixes Critical Code Injection and Memory Corruption Flaws

SAP's August 2026 Security Patch Day addresses 31 vulnerabilities, including a critical CVSS 10.0 authentication bypass in Commerce Cloud and code injection flaws in Manufacturing Integration and Intelligence. These vulnerabilities allow remote attackers to execute arbitrary commands and gain unauthorized access to internal enterprise systems.

**If you run SAP products, especially Manufacturing Integration and Intelligence (MII) read the advisory in detail. First make sure these systems are isolated from the internet where possible and reachable only from trusted internal networks. Then apply SAP's August 2026 security notes ASAP starting with the critical fixes for Commerce Cloud (CVE-2026-58231) and MII (CVE-2026-44772, CVE-2026-44758), followed by the ABAP Platform patch (CVE-2026-34265).**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

DailyCyberSecurity@infosec.exchange at 2026-08-11T12:43:35.000Z ##

SAP August 2026 Patch Day fixes CVE-2026-58231 (CVSS 10.0) and code injection RCE flaws scoring 9.9 and 9.8 across Commerce Cloud and NetWeaver.

#SAP #CVE #RCE #PatchTuesday #NetWeaver #InfoSec

securityonline.info/sap-august

##

CVE-2026-34265
(9.8 CRITICAL)

EPSS: 0.44%

updated 2026-08-12T05:17:46.207000

5 posts

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the system, leading to a high impact on the confidentiality, integrity, and availability of the application.

beyondmachines1 at 2026-08-12T08:01:15.265Z ##

SAP August 2026 Patch Day Fixes Critical Code Injection and Memory Corruption Flaws

SAP's August 2026 Security Patch Day addresses 31 vulnerabilities, including a critical CVSS 10.0 authentication bypass in Commerce Cloud and code injection flaws in Manufacturing Integration and Intelligence. These vulnerabilities allow remote attackers to execute arbitrary commands and gain unauthorized access to internal enterprise systems.

**If you run SAP products, especially Manufacturing Integration and Intelligence (MII) read the advisory in detail. First make sure these systems are isolated from the internet where possible and reachable only from trusted internal networks. Then apply SAP's August 2026 security notes ASAP starting with the critical fixes for Commerce Cloud (CVE-2026-58231) and MII (CVE-2026-44772, CVE-2026-44758), followed by the ABAP Platform patch (CVE-2026-34265).**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-08-12T08:01:15.000Z ##

SAP August 2026 Patch Day Fixes Critical Code Injection and Memory Corruption Flaws

SAP's August 2026 Security Patch Day addresses 31 vulnerabilities, including a critical CVSS 10.0 authentication bypass in Commerce Cloud and code injection flaws in Manufacturing Integration and Intelligence. These vulnerabilities allow remote attackers to execute arbitrary commands and gain unauthorized access to internal enterprise systems.

**If you run SAP products, especially Manufacturing Integration and Intelligence (MII) read the advisory in detail. First make sure these systems are isolated from the internet where possible and reachable only from trusted internal networks. Then apply SAP's August 2026 security notes ASAP starting with the critical fixes for Commerce Cloud (CVE-2026-58231) and MII (CVE-2026-44772, CVE-2026-44758), followed by the ABAP Platform patch (CVE-2026-34265).**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

se38@nrw.social at 2026-08-11T06:42:28.000Z ##

Time to patch your Kernel...
CVSS v3.0 Base Score: 9,8 / 10

3714806 - [CVE-2026-34265] Memory Corruption vulnerability in Application Server #ABAP for #SAP NetWeaver and ABAP Platform

me.sap.com/notes/3714806

##

thehackerwire@mastodon.social at 2026-08-11T03:00:26.000Z ##

🔴 CVE-2026-34265 - Critical (9.8)

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the sy...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-11T03:00:27.000Z ##

CVE-2026-34265: CRITICAL out-of-bounds write in SAP NetWeaver & ABAP Platform (CVSS 9.8) allows unauthenticated memory corruption. No patch yet — restrict access & monitor SAP advisories for updates. radar.offseq.com/threat/cve-20 #OffSeq #SAP #Vuln #Cybersecurity

##

CVE-2026-20349
(8.6 HIGH)

EPSS: 0.00%

updated 2026-08-12T05:17:44.330000

13 posts

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to insufficient error checking when processin

Analyst207@mastodon.social at 2026-08-12T08:04:38.000Z ##

Cisco ASA and FTD Flaw Exploited in Wild, Triggers Remote DoS

A high-severity vulnerability in Cisco Secure Firewall ASA and FTD software, known as CVE-2026-20349, is being actively exploited in the wild, allowing attackers to trigger a remote denial-of-service condition with a simple crafted HTTP request. This flaw, with a CVSS score of 8.6, can cause affected devices to reload, leaving networks…

osintsights.com/cisco-asa-and-

#CiscoAsa #Ftd #Cve202620349 #RemoteDos #VulnerabilityExploitation

##

thecybermind at 2026-08-12T07:44:11.997Z ##

🚨 THREAT ALERT: CISA adds CVE-2026-20349 (Cisco ASA/FTD Heap Inspection DoS) to the KEV catalog due to active exploitation. Unauthenticated remote actors can crash perimeter firewalls. Read our full TSUITE brief with SPL, KQL, AQL & Chronicle queries: thecybermind.co/jily

##

undercodenews@mastodon.social at 2026-08-12T06:59:20.000Z ##

Cisco Firewalls Under Pressure: CVE-2026-20349 Exposes a Dangerous Zero-Day Risk While Sandworm-Linked Hackers Weaponize Fake IT Jobs + Video

Introduction: Two Different Attacks, One Bigger Warning Cybersecurity defenders are facing a familiar but increasingly dangerous pattern: attackers do not need to break through every security control if they can find one exposed edge device or convince one trusted employee to install the wrong software. On August 12, 2026, two…

undercodenews.com/cisco-firewa

##

undercodenews@mastodon.social at 2026-08-12T06:58:48.000Z ##

Cisco Secure Firewall Under Active Attack: High-Severity CVE-2026-20349 Puts ASA and FTD Devices on Immediate Patch Alert + Video

A New Warning Has Turned a Firewall Bug Into an Active Security Emergency A firewall is supposed to be the wall between an organization and the hostile internet. When that wall can be forced to restart remotely, without authentication, the problem is no longer a theoretical weakness hidden inside a security scanner. It becomes an operational…

undercodenews.com/cisco-secure

##

ottoto2017@prattohome.com at 2026-08-12T05:39:38.000Z ##

「Ciscoは、ASAおよびFTD VPNの脆弱性が悪用され、デバイスがクラッシュする可能性があると警告している。 」: #BLEEPINGCOMPUTER

「シスコは、Secure Firewall ASAおよびThreat Defense(FTD)ソフトウェアに存在する深刻なサービス拒否攻撃の脆弱性が、影響を受けるデバイスをリモートからクラッシュさせる攻撃で積極的に悪用されていると警告している。

CVE-2026-20349として追跡されているこの脆弱性は、深刻度スコアが8.6であり、特定のリモートアクセスサービスが有効になっているCisco Secure Firewall Adaptive Security Appliance(ASA)またはSecure Firewall Threat Defense(FTD)ソフトウェアを実行しているデバイスに影響を与えます。

シスコは本日公開したセキュリティ勧告の中で、この脆弱性はHTTPリクエスト処理時のエラーチェックが不十分なことに起因すると述べた。 」

bleepingcomputer.com/news/secu

#prattohome

##

DailyCyberSecurity at 2026-08-12T00:37:09.921Z ##

Cisco confirms CVE-2026-20349, a Cisco ASA and FTD VPN vulnerability (CVSS 8.6), is exploited in the wild to crash firewalls. Patch now.

securityonline.info/cisco-asa-

##

thecybermind@infosec.exchange at 2026-08-12T07:44:11.000Z ##

🚨 THREAT ALERT: CISA adds CVE-2026-20349 (Cisco ASA/FTD Heap Inspection DoS) to the KEV catalog due to active exploitation. Unauthenticated remote actors can crash perimeter firewalls. Read our full TSUITE brief with SPL, KQL, AQL & Chronicle queries: thecybermind.co/jily

#CyberSecurity

##

ottoto2017@prattohome.com at 2026-08-12T05:39:38.000Z ##

「Ciscoは、ASAおよびFTD VPNの脆弱性が悪用され、デバイスがクラッシュする可能性があると警告している。 」: #BLEEPINGCOMPUTER

「シスコは、Secure Firewall ASAおよびThreat Defense(FTD)ソフトウェアに存在する深刻なサービス拒否攻撃の脆弱性が、影響を受けるデバイスをリモートからクラッシュさせる攻撃で積極的に悪用されていると警告している。

CVE-2026-20349として追跡されているこの脆弱性は、深刻度スコアが8.6であり、特定のリモートアクセスサービスが有効になっているCisco Secure Firewall Adaptive Security Appliance(ASA)またはSecure Firewall Threat Defense(FTD)ソフトウェアを実行しているデバイスに影響を与えます。

シスコは本日公開したセキュリティ勧告の中で、この脆弱性はHTTPリクエスト処理時のエラーチェックが不十分なことに起因すると述べた。 」

bleepingcomputer.com/news/secu

#prattohome

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T00:37:09.000Z ##

Cisco confirms CVE-2026-20349, a Cisco ASA and FTD VPN vulnerability (CVSS 8.6), is exploited in the wild to crash firewalls. Patch now.

#Cisco #CVE #DoS #FirewallSecurity #VPN #InfoSec

securityonline.info/cisco-asa-

##

secdb@infosec.exchange at 2026-08-11T21:00:13.000Z ##

🚨 [CISA-2026:0811] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-20349 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-68820 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows Ancillary Function Driver for WinSock
- Notes: portal.msrc.microsoft.com/en-U ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-72898 (secdb.nttzen.cloud/cve/detail/)
- Name: Metabase SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Metabase
- Product: Metabase
- Notes: metabase.com/blog/security-upd ; github.com/metabase/metabase/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260811 #cisa20260811 #cve_2026_20349 #cve_2026_68820 #cve_2026_72898 #cve202620349 #cve202668820 #cve202672898

##

Xavier@infosec.exchange at 2026-08-11T20:18:44.000Z ##

This is being actively exploited. CVE-2026-20349. Patch now. Like right now. #infosec #vpn #cisco #cve
bleepingcomputer.com/news/secu

##

cisakevtracker@mastodon.social at 2026-08-11T20:00:49.000Z ##

CVE ID: CVE-2026-20349
Vendor: Cisco
Product: Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
Date Added: 2026-08-11
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-08-11T17:11:08.000Z ##

Broadcom has several new advisories that include two critical vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

CISA:

Industrial vulnerability: Johnson Controls C-CURE 9000 and Victor application server (Update A) cisa.gov/news-events/ics-advis

Blog post: Cyber Storm X: 20 Years of Readiness, Resilience, and Real‑World Impact cisa.gov/news-events/news/cybe #CISA

Cisco:

High-severity: CVE-2026-20349: Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco

Yesterday:

Tenable Research Advisories:

Medium-severity: CVE-2026-12879: Google Cloud Platform (GCP) Apigee Cross-Tenant Data Exfiltration via Confused Deputy tenable.com/security/research/ #infosec #Google #vulnerability

##

CVE-2026-73122
(7.7 HIGH)

EPSS: 0.00%

updated 2026-08-12T03:31:23

2 posts

A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically, the agent can read all Secrets and ConfigMaps within any Channel namespace on the hub, potentially exposing credentials for other tenants' Git and Helm

thehackerwire@mastodon.social at 2026-08-12T06:00:48.000Z ##

🟠 CVE-2026-73122 - High (7.7)

A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T06:00:48.000Z ##

🟠 CVE-2026-73122 - High (7.7)

A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-6484
(8.2 HIGH)

EPSS: 0.00%

updated 2026-08-12T03:31:23

2 posts

In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.

thehackerwire@mastodon.social at 2026-08-12T01:59:50.000Z ##

🟠 CVE-2026-6484 - High (8.2)

In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T01:59:50.000Z ##

🟠 CVE-2026-6484 - High (8.2)

In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72526
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-08-12T03:31:18

4 posts

A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary managed clusters. This can force ArgoCD on the spoke clusters to synchronize attac

offseq at 2026-08-12T04:30:27.162Z ##

CVE-2026-72526 (CRITICAL, CVSS 9.9) in Red Hat Advanced Cluster Management for Kubernetes 2 lets low-priv hub users escalate to cluster-admin on managed clusters. No official fix. Restrict Application creation permissions now. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-12T04:00:39.000Z ##

🔴 CVE-2026-72526 - Critical (9.9)

A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to creat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-12T04:30:27.000Z ##

CVE-2026-72526 (CRITICAL, CVSS 9.9) in Red Hat Advanced Cluster Management for Kubernetes 2 lets low-priv hub users escalate to cluster-admin on managed clusters. No official fix. Restrict Application creation permissions now. radar.offseq.com/threat/cve-20 #OffSeq #RedHat #Kubernetes #CVE2026_72526

##

thehackerwire@mastodon.social at 2026-08-12T04:00:39.000Z ##

🔴 CVE-2026-72526 - Critical (9.9)

A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to creat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70398
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-08-12T03:31:17

4 posts

A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a tenant can redirect sensitive spoke cluster bearer tokens from secure locations to a namespace they control. This unauthorized access to tokens can lead to

thehackerwire@mastodon.social at 2026-08-12T04:00:28.000Z ##

🔴 CVE-2026-70398 - Critical (9.6)

A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a te...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-12T03:00:23.878Z ##

CRITICAL CVE-2026-70398 in Red Hat Advanced Cluster Management for Kubernetes 2: Authenticated tenants can redirect bearer tokens via GitOpsCluster controller. No official fix. Restrict privileges & monitor activity. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-12T04:00:28.000Z ##

🔴 CVE-2026-70398 - Critical (9.6)

A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a te...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-12T03:00:23.000Z ##

CRITICAL CVE-2026-70398 in Red Hat Advanced Cluster Management for Kubernetes 2: Authenticated tenants can redirect bearer tokens via GitOpsCluster controller. No official fix. Restrict privileges & monitor activity. radar.offseq.com/threat/cve-20 #OffSeq #Kubernetes #RedHat #CVE202670398

##

CVE-2026-18961
(8.1 HIGH)

EPSS: 0.00%

updated 2026-08-12T03:16:42.807000

2 posts

The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the plugin trusting the unverified email field returned by Spotify's /v1/me endpoint as proof of mailbox ownership — Generic::normalize_common() copies this valu

thehackerwire@mastodon.social at 2026-08-12T04:00:18.000Z ##

🟠 CVE-2026-18961 - High (8.1)

The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the pl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T04:00:18.000Z ##

🟠 CVE-2026-18961 - High (8.1)

The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the pl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68067
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-12T00:31:23

4 posts

The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings.

offseq at 2026-08-12T01:30:25.242Z ##

Mira Firmware v1.7.1.47 has a CRITICAL auth bug (CVE-2026-68067): login accepts any valid-format password, exposing hormone records. No patch yet; restrict access & monitor accounts. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-12T00:01:04.000Z ##

🔴 CVE-2026-68067 - Critical (9.8)

The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud acc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-12T01:30:25.000Z ##

Mira Firmware v1.7.1.47 has a CRITICAL auth bug (CVE-2026-68067): login accepts any valid-format password, exposing hormone records. No patch yet; restrict access & monitor accounts. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #IoTSecurity #CVE202668067

##

thehackerwire@mastodon.social at 2026-08-12T00:01:04.000Z ##

🔴 CVE-2026-68067 - Critical (9.8)

The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud acc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67568
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-08-12T00:31:23

4 posts

The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of health information.

thehackerwire@mastodon.social at 2026-08-12T00:01:26.000Z ##

🔴 CVE-2026-67568 - Critical (9.1)

The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of health information.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-12T00:00:38.878Z ##

CVE-2026-67568 (CRITICAL, CVSS 9.3) in Mira Firmware 1.7.1.47: Hard-coded credentials let remote attackers read/write sensitive health data. No patch yet — restrict network access & monitor logs. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-12T00:01:26.000Z ##

🔴 CVE-2026-67568 - Critical (9.1)

The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of health information.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-12T00:00:38.000Z ##

CVE-2026-67568 (CRITICAL, CVSS 9.3) in Mira Firmware 1.7.1.47: Hard-coded credentials let remote attackers read/write sensitive health data. No patch yet — restrict network access & monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #CVE202667568 #infosec #medtech #vuln

##

CVE-2026-66875
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-12T00:31:23

2 posts

In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measurements in cleartext, cause a denial-of-service via malformed or undocumented command opcodes, and passively track the user via a static random BLE address

thehackerwire@mastodon.social at 2026-08-12T00:01:15.000Z ##

🟠 CVE-2026-66875 - High (8.8)

In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measur...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T00:01:15.000Z ##

🟠 CVE-2026-66875 - High (8.8)

In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measur...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19556(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-08-12T00:31:18

2 posts

Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

DailyCyberSecurity at 2026-08-12T03:45:23.321Z ##

Google's new Chrome security update patches 5 high-severity use-after-free bugs, including CVE-2026-19556 and CVE-2026-19560. Update now.

securityonline.info/chrome-use

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T03:45:23.000Z ##

Google's new Chrome security update patches 5 high-severity use-after-free bugs, including CVE-2026-19556 and CVE-2026-19560. Update now.

#Chrome #Google #UseAfterFree #CVE #BrowserSecurity #PatchNow #Cybersecurity

securityonline.info/chrome-use

##

CVE-2026-19560(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-08-12T00:31:11

2 posts

Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

DailyCyberSecurity at 2026-08-12T03:45:23.321Z ##

Google's new Chrome security update patches 5 high-severity use-after-free bugs, including CVE-2026-19556 and CVE-2026-19560. Update now.

securityonline.info/chrome-use

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T03:45:23.000Z ##

Google's new Chrome security update patches 5 high-severity use-after-free bugs, including CVE-2026-19556 and CVE-2026-19560. Update now.

#Chrome #Google #UseAfterFree #CVE #BrowserSecurity #PatchNow #Cybersecurity

securityonline.info/chrome-use

##

CVE-2026-73249
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-11T22:19:05.687000

2 posts

calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{library_id}/{book_id}/{fmt} in src/calibre/srv/books.py omits needs_db_write=True, causing Router.dispatch() to skip ctx.check_for_write_access() before update_annotations() passes attacker-controlled JSON to db.merge_annotations_for_book(), which allows a readonly user or an anonymous

thehackerwire@mastodon.social at 2026-08-12T00:00:22.000Z ##

🟠 CVE-2026-73249 - High (7.5)

calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{library_id}/{book_id}/{fmt} in src/calibre/srv/books.py omits needs_db_write=True, causing Router.dispatch() to skip ctx.check_for_wr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T00:00:22.000Z ##

🟠 CVE-2026-73249 - High (7.5)

calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{library_id}/{book_id}/{fmt} in src/calibre/srv/books.py omits needs_db_write=True, causing Router.dispatch() to skip ctx.check_for_wr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73247
(8.6 HIGH)

EPSS: 0.00%

updated 2026-08-11T22:19:05.417000

2 posts

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/functions/HttpFunction.java passes the user-controlled http() uri argument to URI.create() and the server-side HTTP client without restricting private, loopback, or link-local destinations, allowing an unauthenticated attacker to import and execute a flow that ac

thehackerwire@mastodon.social at 2026-08-12T00:00:12.000Z ##

🟠 CVE-2026-73247 - High (8.6)

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/functions/HttpFunction.java passes the user-controlled http() uri argument to URI.create() and the server-side...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T00:00:12.000Z ##

🟠 CVE-2026-73247 - High (8.6)

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/functions/HttpFunction.java passes the user-controlled http() uri argument to URI.create() and the server-side...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15562
(7.5 HIGH)

EPSS: 0.35%

updated 2026-08-11T21:33:39

1 posts

A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-remoting handshake can cause OOM errors that degrade requests server-wide, leading to denial of service.

thehackerwire@mastodon.social at 2026-08-11T10:00:39.000Z ##

🟠 CVE-2026-15562 - High (7.5)

A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-remoting handshake can cause OOM errors that degrade requests server-wide, leading to denial of ser...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18948
(9.9 CRITICAL)

EPSS: 0.69%

updated 2026-08-11T21:33:39

2 posts

A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious UDF, leading to unauthenticated arbitrary code execution on the feature server in default configurations. An authenticated attacker can also achieve arbitrary code execution on the regis

offseq@infosec.exchange at 2026-08-11T04:30:24.000Z ##

CVE-2026-18948: CRITICAL in RHOAI Feast — unsafe UDF deserialization allows unauth RCE on feature-server. Auth attackers can bypass auth to run code on registry-server. Mitigate by enforcing `auth.type: kubernetes`. radar.offseq.com/threat/cve-20 #OffSeq #RedHat #CVE #infosec

##

thehackerwire@mastodon.social at 2026-08-10T22:01:31.000Z ##

🔴 CVE-2026-18948 - Critical (9.9)

A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious UDF, leading to unauthenticated a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18951
(8.8 HIGH)

EPSS: 0.65%

updated 2026-08-11T21:33:39

1 posts

A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with `edit ClusterRole` permissions in a namespace to create, modify, and delete `TrainJobs`. When combined with a separate vulnerability (TRN-01) that permits arbitrar

thehackerwire@mastodon.social at 2026-08-10T23:01:06.000Z ##

🟠 CVE-2026-18951 - High (8.8)

A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with `edit Clus...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18950
(8.8 HIGH)

EPSS: 0.40%

updated 2026-08-11T21:33:39

1 posts

A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The system does not properly validate the `roleRef` field, allowing a user to specify an arbitrary role, including highly privileged ones like `cluster-admin`. This can lead to privilege escalation, where an attacker gains unauthorized elevated access withi

thehackerwire@mastodon.social at 2026-08-10T23:00:55.000Z ##

🟠 CVE-2026-18950 - High (8.8)

A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The system does not properly validate the `roleRef` field, allowing a user to specify an arbitrary role,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18947
(8.5 HIGH)

EPSS: 0.49%

updated 2026-08-11T21:33:35

1 posts

A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental endpoints. By sending a specially crafted request that omits the feature_views field, an attacker can bypass intended permission checks. This allows an unauthenticated remote attacker, or any authenticated user, to trigger a full re-materialization of all feature views. The cons

thehackerwire@mastodon.social at 2026-08-10T22:01:20.000Z ##

🟠 CVE-2026-18947 - High (8.5)

A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental endpoints. By sending a specially crafted request that omits the feature_views field, an attacker can bypass intended permissi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16985
(8.8 HIGH)

EPSS: 0.19%

updated 2026-08-11T21:32:30

1 posts

The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data written by one of its attachment-update actions, allowing users with the upload_files capability (Author and above) to write an executable PHP file into the uploads directory and achieve remote code execution.

offseq@infosec.exchange at 2026-08-10T09:00:24.000Z ##

CVE-2026-16985: Squeeze WP plugin <1.7.12 has a CRITICAL vuln — users with upload_files can upload PHP files, enabling remote code execution. Restrict permissions, monitor uploads, and check for updates. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE2026_16985 #infosec

##

CVE-2026-10579
(9.8 CRITICAL)

EPSS: 0.39%

updated 2026-08-11T21:17:24.910000

1 posts

A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws.

offseq@infosec.exchange at 2026-08-11T10:30:30.000Z ##

Red Hat JBoss EAP 7 hit by CVE-2026-10579 (CRITICAL, CVSS 9.8): SAML handler flaw lets unauthenticated attackers forge access as any user. Patch available — apply ASAP. Full details: radar.offseq.com/threat/cve-20 #OffSeq #RedHat #Vuln #CVE202610579

##

CVE-2026-73234
(7.8 HIGH)

EPSS: 0.00%

updated 2026-08-11T20:18:48.833000

1 posts

FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, PropertyFileIncluded::Restore() in src/App/PropertyFile.cpp concatenates an attacker-controlled file or data attribute from Document.xml with the document transient path without rejecting directory components, absolute paths, or parent traversal. A crafted .FCStd archive with a matching FileIncluded XML attribut

thehackerwire@mastodon.social at 2026-08-11T21:00:33.000Z ##

🟠 CVE-2026-73234 - High (7.8)

FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, PropertyFileIncluded::Restore() in src/App/PropertyFile.cpp concatenates an attacker-controlled file or data attribute from Document.xml with the document trans...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73232
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-11T20:18:48.543000

1 posts

ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory denial of service because the response size guard in pkg/runner/simple.go checks only the compressed Content-Length while io.ReadAll reads gzip, brotli, deflate, transparently decompressed, or chunked response bodies without a decompressed-size bound. This issue is fixed in vers

thehackerwire@mastodon.social at 2026-08-11T21:00:15.000Z ##

🟠 CVE-2026-73232 - High (7.5)

ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory denial of service because the response size guard in pkg/runner/simple.go checks only the compressed Content-Length while io.R...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73226
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-11T20:18:48.007000

1 posts

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm allows an authenticated WebSocket client to invoke unintended internal functions through client-controlled func values in upgrade-func in src/app/server/dispatch-center.js and handleFs in src/app/server/fs.js, exposing Upgrade and fsExport methods that can execute commands, open fi

thehackerwire@mastodon.social at 2026-08-11T20:00:34.000Z ##

🟠 CVE-2026-73226 - High (8.8)

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm allows an authenticated WebSocket client to invoke unintended internal functions through client-controlled func values in upgrade...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18949
(8.8 HIGH)

EPSS: 0.40%

updated 2026-08-11T19:17:31.520000

1 posts

A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions granted to the SA. This enables the attacker to escalate their privileges to cluster-administrator level, gain access to sensitive data like credentials and keys across the entire cluster, and disrupt multi-tenant isolation.

thehackerwire@mastodon.social at 2026-08-10T23:00:44.000Z ##

🟠 CVE-2026-18949 - High (8.8)

A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions granted to the SA. This enables the attacker to escalate their privileges...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62901
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-11T18:53:58

1 posts

## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in System.Net.WebSockets. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network. ## Announcement Announceme

us@newsbeep.org at 2026-08-11T23:40:13.000Z ##

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

Tag
CVE ID
CVE Title
Severity
.NET
CVE-2026-58641
.NET Elevation of Privilege Vulnerability
Important
.NET
CVE-2026-62901
.NET Denial…
#NewsBeep #News #US #USA #UnitedStates #UnitedStatesOfAmerica #Technology
newsbeep.com/us/810540/

##

CVE-2026-18786
(8.8 HIGH)

EPSS: 0.19%

updated 2026-08-11T18:31:45

1 posts

The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and unconditionally discards the authentication error raised for any request whose URI merely contains a CheckView WordPress plugin before 2.3.2-specific string, making it possible for unauthenticated attackers to bypass the REST nonce check and perform any REST action available to

offseq@infosec.exchange at 2026-08-10T07:30:27.000Z ##

CVE-2026-18786: CRITICAL auth bypass in CheckView WP plugin ≤2.0.29. Attackers can exploit REST API via crafted links to perform admin actions if an admin clicks. Restrict plugin REST API & avoid suspicious links. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202618786

##

CVE-2026-53414
(6.5 MEDIUM)

EPSS: 0.00%

updated 2026-08-11T18:30:54

1 posts

Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access.

571906@ap.podcastindex.org at 2026-08-12T02:00:02.000Z ##

New Episode: SANS Stormcast Wednesday, August 12th, 2026: Microsoft Patch Tuesday; Zoom Vulnerabilities; Mozilla Revokes Key; Rogue Inflight Wifi

Shownotes:

Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20August%202026/33236
Zoom Vulnerablities CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415
https://a.security/blog/asecurity-zoomsday
Mozilla Revokes

Transcript

AntennaPod | Anytime Player | Apple Podcasts | Castamatic | CurioCaster | Fountain | gPodder | Overcast | Pocket Casts | Podcast Addict | Podcast Guru | Podnews | Podverse | Truefans

Or Listen right here.

##

CVE-2026-53413
(8.3 HIGH)

EPSS: 0.00%

updated 2026-08-11T18:30:54

1 posts

Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access.

571906@ap.podcastindex.org at 2026-08-12T02:00:02.000Z ##

New Episode: SANS Stormcast Wednesday, August 12th, 2026: Microsoft Patch Tuesday; Zoom Vulnerabilities; Mozilla Revokes Key; Rogue Inflight Wifi

Shownotes:

Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20August%202026/33236
Zoom Vulnerablities CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415
https://a.security/blog/asecurity-zoomsday
Mozilla Revokes

Transcript

AntennaPod | Anytime Player | Apple Podcasts | Castamatic | CurioCaster | Fountain | gPodder | Overcast | Pocket Casts | Podcast Addict | Podcast Guru | Podnews | Podverse | Truefans

Or Listen right here.

##

CVE-2026-56721
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-11T18:30:54

1 posts

CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference (IDOR) that allows authenticated low-privileged attackers to overwrite any user's credentials by exploiting a parameter confusion flaw between the authorization filter and action body in the UsersController. Attackers can send a PATCH request to the updated_ajax endpoint setting

thehackerwire@mastodon.social at 2026-08-11T17:01:48.000Z ##

🟠 CVE-2026-56721 - High (8.8)

CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference (IDOR) that allows authenticated low-privileged attackers to overwrite any user's credentials by exploiting a parameter confus...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67180
(8.4 HIGH)

EPSS: 0.00%

updated 2026-08-11T18:30:53

1 posts

Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evidence path/name obtains code execution on the worker fleet. Fixed on 2026-07-10.

thehackerwire@mastodon.social at 2026-08-11T17:01:35.000Z ##

🟠 CVE-2026-67180 - High (8.4)

Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evidence path/name obtains code execution on the worker fleet. Fixed on 2026-07-10.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13738(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-08-11T18:30:43

1 posts

CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.

offseq@infosec.exchange at 2026-08-11T12:00:31.000Z ##

CVE-2026-13738 (CRITICAL, CVSS 9.2) affects Commvault Cloud CommServe: authorization bypass enables unauthorized command execution. Affects v11.36.0 – 11.46.0. Upgrade all components. radar.offseq.com/threat/cve-20 #OffSeq #CVE #CloudSecurity #SysAdmin

##

CVE-2026-73079
(8.5 HIGH)

EPSS: 0.00%

updated 2026-08-11T17:19:15.747000

1 posts

Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0.1.135, to 0.1.168, platform API keys issued to tenants are exchanged for upstream requests made with shared provider accounts (ChatGPT/Codex OAuth, OpenAI platform keys, or an operator-configured base URL) that belong to the operator, not to the caller. The `POST /responses/*sub

thehackerwire@mastodon.social at 2026-08-11T17:00:18.000Z ##

🟠 CVE-2026-73079 - High (8.5)

Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0.1.135, to 0.1.168, platform API keys issued to tenants are exchanged for upstream requests made with shared provider accounts ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71217
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-11T17:19:12.937000

1 posts

A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper input validation can lead to excessive stream and thread creation, as well as large buffer allocations, causing resource exhaustion. Consequently, this can

thehackerwire@mastodon.social at 2026-08-11T10:00:13.000Z ##

🟠 CVE-2026-71217 - High (7.5)

A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper inp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53415
(8.3 HIGH)

EPSS: 0.00%

updated 2026-08-11T17:18:03.250000

1 posts

Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access.

571906@ap.podcastindex.org at 2026-08-12T02:00:02.000Z ##

New Episode: SANS Stormcast Wednesday, August 12th, 2026: Microsoft Patch Tuesday; Zoom Vulnerabilities; Mozilla Revokes Key; Rogue Inflight Wifi

Shownotes:

Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20August%202026/33236
Zoom Vulnerablities CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415
https://a.security/blog/asecurity-zoomsday
Mozilla Revokes

Transcript

AntennaPod | Anytime Player | Apple Podcasts | Castamatic | CurioCaster | Fountain | gPodder | Overcast | Pocket Casts | Podcast Addict | Podcast Guru | Podnews | Podverse | Truefans

Or Listen right here.

##

CVE-2026-19516
(9.1 CRITICAL)

EPSS: 0.23%

updated 2026-08-11T17:17:48.383000

1 posts

A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the caller also choose the HTTP method, path, and body. Because the destination is not restricted to the configured Grafana instance, a caller can direct requests at internal, loopback, and link-local network services (including metadata endpoints) and r

offseq@infosec.exchange at 2026-08-11T06:00:25.000Z ##

Grafana MCP Server hit by CRITICAL SSRF (CVE-2026-19516, CVSS 9.1) via X-Grafana-URL header. Attackers can access internal endpoints and metadata. Restrict access & monitor usage until patch available. radar.offseq.com/threat/cve-20 #OffSeq #Grafana #SSRF #Vuln

##

CVE-2026-72903
(8.1 HIGH)

EPSS: 0.31%

updated 2026-08-11T16:17:37.360000

1 posts

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal filename through entry.name. In tabby-ssh/src/session/sftp.ts, SFTPSession.readdir() and _makeFile() use POSIX path processing that preserves the backslashes as ordinary filename characters. In tabby-ssh/src/components/sftpPanel.component.ts, downloadFold

thehackerwire@mastodon.social at 2026-08-10T22:00:28.000Z ##

🟠 CVE-2026-72903 - High (8.1)

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal filename through entry.name. In tabby-ssh/src/session/sftp.ts, SFTPSession.readdir() and _makeFile() u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67179
(7.8 HIGH)

EPSS: 0.00%

updated 2026-08-11T16:17:34.113000

1 posts

Genkit does not properly validate host request headers. Any host on the developer's network, and any website the developer visits (via DNS rebinding), can reach POST /api/runAction on the Dev UI server (default port 4000) and execute any registered Genkit action and read the result. Fixed on 2026-06-18.

thehackerwire@mastodon.social at 2026-08-11T17:01:23.000Z ##

🟠 CVE-2026-67179 - High (7.8)

Genkit does not properly validate host request headers. Any host on the developer's network, and any website the developer visits (via DNS rebinding), can reach POST /api/runAction on the Dev UI server (default port 4000) and execute any registere...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73080
(9.3 CRITICAL)

EPSS: 0.00%

updated 2026-08-11T15:58:24

1 posts

### Impact `VolumeServer.FetchAndWriteNeedle` fetches a caller-supplied remote endpoint and writes the response into a needle. Before 4.24 this RPC performed no authentication and no validation of the target, so anyone able to reach a volume server's gRPC port could coerce the server into issuing requests to arbitrary hosts — including loopback, link-local, RFC 1918, and cloud metadata endpoints s

thehackerwire@mastodon.social at 2026-08-11T17:00:34.000Z ##

🔴 CVE-2026-73080 - Critical (9.3)

SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a caller-supplied remote endpoint through weed/remote_storage/s3/s3_storage_client.go and writes the response i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58115
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-08-11T15:32:40

2 posts

A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attack

DailyCyberSecurity at 2026-08-12T07:32:31.690Z ##

CVE-2026-58115 is a CVSS 10 flaw letting unauthenticated attackers run code on SIMATIC IoT2050 via Node-RED. Siemens urges an immediate update.

securityonline.info/simatic-io

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T07:32:31.000Z ##

CVE-2026-58115 is a CVSS 10 flaw letting unauthenticated attackers run code on SIMATIC IoT2050 via Node-RED. Siemens urges an immediate update.

#CVE202658115 #Siemens #NodeRED #RCE #SIMATIC #ICS #Cybersecurity

securityonline.info/simatic-io

##

CVE-2026-18972
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-08-11T15:32:40

1 posts

An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator.

offseq@infosec.exchange at 2026-08-11T13:30:32.000Z ##

CVE-2026-18972 (CRITICAL): Rapid7 Velociraptor <0.77.2 lets low-priv users escalate to admin by spoofing 'Grpc-Metadata-USER' header — full account takeover. No patch yet. Restrict GUI access, monitor requests. radar.offseq.com/threat/cve-20 #OffSeq #Velociraptor #CVE202618972

##

CVE-2026-72922
(8.2 HIGH)

EPSS: 0.00%

updated 2026-08-11T15:17:38.350000

1 posts

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.70, AutoGPT's autogpt_platform/backend/backend/api/features/integrations/router.py webhook_ingress_generic route selected get_webhook_manager(provider) from the untrusted provider URL segment without verifying webhook.provider, allowing a request to /compass/webho

thehackerwire@mastodon.social at 2026-08-11T16:01:34.000Z ##

🟠 CVE-2026-72922 - High (8.2)

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.70, AutoGPT's autogpt_platform/backend/backend/api/features/integrations/router.py webhook_ingress_generic rout...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72864
(9.9 CRITICAL)

EPSS: 0.27%

updated 2026-08-11T15:17:36.393000

1 posts

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-terminal in apps/dokploy/server/wss/docker-container-terminal.ts authenticates with validateRequest but does not authorize the attacker-controlled containerId against the caller's role, organization, or service access before passing it to `docker exec`, allowing any authenticated

thehackerwire@mastodon.social at 2026-08-10T20:00:44.000Z ##

🔴 CVE-2026-72864 - Critical (9.9)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-terminal in apps/dokploy/server/wss/docker-container-terminal.ts authenticates with validateRequest but does not authorize the a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44758
(9.1 CRITICAL)

EPSS: 0.51%

updated 2026-08-11T15:17:29.603000

4 posts

SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system, resulting in high impact on confidentiality, integrity, and availability

beyondmachines1 at 2026-08-12T08:01:15.265Z ##

SAP August 2026 Patch Day Fixes Critical Code Injection and Memory Corruption Flaws

SAP's August 2026 Security Patch Day addresses 31 vulnerabilities, including a critical CVSS 10.0 authentication bypass in Commerce Cloud and code injection flaws in Manufacturing Integration and Intelligence. These vulnerabilities allow remote attackers to execute arbitrary commands and gain unauthorized access to internal enterprise systems.

**If you run SAP products, especially Manufacturing Integration and Intelligence (MII) read the advisory in detail. First make sure these systems are isolated from the internet where possible and reachable only from trusted internal networks. Then apply SAP's August 2026 security notes ASAP starting with the critical fixes for Commerce Cloud (CVE-2026-58231) and MII (CVE-2026-44772, CVE-2026-44758), followed by the ABAP Platform patch (CVE-2026-34265).**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-08-12T08:01:15.000Z ##

SAP August 2026 Patch Day Fixes Critical Code Injection and Memory Corruption Flaws

SAP's August 2026 Security Patch Day addresses 31 vulnerabilities, including a critical CVSS 10.0 authentication bypass in Commerce Cloud and code injection flaws in Manufacturing Integration and Intelligence. These vulnerabilities allow remote attackers to execute arbitrary commands and gain unauthorized access to internal enterprise systems.

**If you run SAP products, especially Manufacturing Integration and Intelligence (MII) read the advisory in detail. First make sure these systems are isolated from the internet where possible and reachable only from trusted internal networks. Then apply SAP's August 2026 security notes ASAP starting with the critical fixes for Commerce Cloud (CVE-2026-58231) and MII (CVE-2026-44772, CVE-2026-44758), followed by the ABAP Platform patch (CVE-2026-34265).**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

thehackerwire@mastodon.social at 2026-08-11T03:00:35.000Z ##

🔴 CVE-2026-44758 - Critical (9.1)

SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-11T01:30:29.000Z ##

SAP MII 15.5 is exposed to CRITICAL code injection (CVE-2026-44758, CVSS 9.1). High-privilege users could execute arbitrary OS commands. No patch yet — restrict access & monitor for code injection. radar.offseq.com/threat/cve-20 #OffSeq #SAP #Infosec #CVE202644758

##

CVE-2026-46670
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-11T14:17:13.863000

1 posts

YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a default YesWiki install to inject arbitrary SQL into an `INSERT` statement and read the full database, including `yeswiki_users.password` hashes. Version 4.6.4 fixes the issue.

Nuclei template

Matchbook3469@mastodon.social at 2026-08-12T08:02:20.000Z ##

🔴 New security advisory:

CVE-2026-46670 affects multiple systems.

• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#InfoSec #SecurityPatching #HackerNews

##

CVE-2026-72693
(7.8 HIGH)

EPSS: 0.10%

updated 2026-08-11T09:32:42

1 posts

`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on `stat("/proc/<pid>/fd/0")`. `stat()` on `/proc/<pid>/fd/0` follows the symlink to the underlying TTY device node. As a result, `buf.st_uid` reflects the owner of the TTY node

thehackerwire@mastodon.social at 2026-08-11T10:00:27.000Z ##

🟠 CVE-2026-72693 - High (7.8)

`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on `stat("/proc//fd/0")`....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19425
(9.8 CRITICAL)

EPSS: 0.47%

updated 2026-08-11T06:31:25

1 posts

Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.

offseq@infosec.exchange at 2026-08-11T09:00:26.000Z ##

Win Men Intermational Travel Agency Management System has a CRITICAL SQL Injection flaw (CVE-2026-19425, CVSS 9.8). Unauthenticated attackers may fully compromise databases. No patch yet: restrict access & monitor for SQLi. radar.offseq.com/threat/cve-20 #OffSeq #CVE202619425 #SQLInjection #InfoSec

##

CVE-2026-13716
(9.1 CRITICAL)

EPSS: 0.56%

updated 2026-08-11T06:31:25

1 posts

Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution.

offseq@infosec.exchange at 2026-08-11T07:30:28.000Z ##

CRITICAL path traversal (CVE-2026-13716, CVSS 9.1) found in Crafty Controller v4.4.0 (Arcadia). Authenticated attackers can upload files to arbitrary paths, risking RCE. Restrict admin/file upload access & monitor activity. Details: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #CVE202613716

##

CVE-2026-44763
(7.6 HIGH)

EPSS: 0.28%

updated 2026-08-11T03:32:04

1 posts

SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and depends on conditions outside the attacker�s control. Successful exploitation could allow files to be written outside the i

thehackerwire@mastodon.social at 2026-08-11T03:00:45.000Z ##

🟠 CVE-2026-44763 - High (7.6)

SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66763
(7.9 HIGH)

EPSS: 0.13%

updated 2026-08-11T03:32:04

1 posts

SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects and decrypt the stored credentials. Successful exploitation could allow the attacker to obtain sensitive authentication data and modify protected inform

thehackerwire@mastodon.social at 2026-08-11T02:00:02.000Z ##

🟠 CVE-2026-66763 - High (7.9)

SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8917(CVSS UNKNOWN)

EPSS: 0.11%

updated 2026-08-11T03:31:59

1 posts

Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to write a specific value to an arbitrary memory address, potentially leading to privilege escalation. Refer to the '  Security Update for ASUS GPU Tweak III, GPU Tweak II, AI Suite 3, and Armoury Crate Security Bulletin   ' section on the ASUS Security Advisory fo

AAKL@infosec.exchange at 2026-08-11T19:02:36.000Z ##

Asus posted an advisory today. Scroll down for the full list:

CVE-2026-8917: Security Update for ASUS GPU Tweak III, GPU Tweak II, AI Suite 3, and Armoury Crate Security Bulletin asus.com/security-advisory/

PC Gamer: It's time to update Asus Armoury Crate and several other Asus software tools again, as another high severity security vulnerability has been discovered pcgamer.com/software/security/ #infosec #vulnerability #Asus

##

CVE-2026-8718
(8.4 HIGH)

EPSS: 0.12%

updated 2026-08-10T23:16:51.587000

1 posts

tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied optval directly to mbedtls_ssl_get_peer_cid() without verifying the buffer was at least MBEDTLS_SSL_CID_OUT_LEN_MAX (default 32) bytes. mbedtls_ssl_get_peer_cid() copies the peer-negotiated DTLS Connection ID (length 1..MBEDTLS_

thehackerwire@mastodon.social at 2026-08-10T23:59:54.000Z ##

🟠 CVE-2026-8718 - High (8.4)

tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied optval directly to mbedtls_ssl_get_peer_cid() without verifying the buffer ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73030
(8.1 HIGH)

EPSS: 0.38%

updated 2026-08-10T21:32:15

1 posts

unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers can supply malicious tar archives with symlink members or traversal sequences to write files to arbitrary filesystem locations accessible to the process.

thehackerwire@mastodon.social at 2026-08-10T22:00:06.000Z ##

🟠 CVE-2026-73030 - High (8.1)

unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63622
(7.8 HIGH)

EPSS: 0.13%

updated 2026-08-10T21:32:08

1 posts

A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtpm` state directory, the attacker could trick the root-level libvirt daemon into changing the ownership of an arbitrary file to the `swtpm` user. This allows for

thehackerwire@mastodon.social at 2026-08-10T22:01:09.000Z ##

🟠 CVE-2026-63622 - High (7.8)

A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtpm` state...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72886
(9.9 CRITICAL)

EPSS: 0.36%

updated 2026-08-10T20:17:35.423000

1 posts

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/api/routers/schedule.ts derive serviceId from applicationId or composeId and execute the owner/admin host-schedule gate only in the alternative branch, allowing a member with access to one application to attach its applicationId to a dokploy-server sc

thehackerwire@mastodon.social at 2026-08-10T21:00:20.000Z ##

🔴 CVE-2026-72886 - Critical (9.9)

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/api/routers/schedule.ts derive serviceId from applicationId or composeId and execute the owner/adm...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72730
(8.7 HIGH)

EPSS: 0.24%

updated 2026-08-10T19:17:33.807000

1 posts

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Editor rendered a chat-transcript username as HTML, allowing stored cross-site scripting. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.

thehackerwire@mastodon.social at 2026-08-10T17:59:51.000Z ##

🟠 CVE-2026-72730 - High (8.7)

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Editor rendered a chat-transcript username as HTML, allowing stored cross-site scripting. This issue is fixed in versions 2026.1.6,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72689
(7.5 HIGH)

EPSS: 0.32%

updated 2026-08-10T19:17:33.103000

1 posts

A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read complete contract records via the getDocument Parse cloud function. The function fetches documents using useMasterKey, bypassing the object ACL, and returns full records including sender and signer PII and a pre-signed document download URL whenever the

thehackerwire@mastodon.social at 2026-08-10T16:00:43.000Z ##

🟠 CVE-2026-72689 - High (7.5)

A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read complete contract records via the getDocument Parse cloud function. The function fetches documents us...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71576
(8.5 HIGH)

EPSS: 0.12%

updated 2026-08-10T18:32:24

1 posts

A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming CloudEvents on Kafka status topics. A remote attacker, after compromising a managed hub and obtaining its Kafka client certificate, can manipulate the self-asserted source identity. This allows the attacker to falsify or delete critical data, such as compliance, inventory, and cl

thehackerwire@mastodon.social at 2026-08-10T18:00:01.000Z ##

🟠 CVE-2026-71576 - High (8.5)

A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming CloudEvents on Kafka status topics. A remote attacker, after compromising a managed hub and obtaining its Kafka client certific...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19381
(7.8 HIGH)

EPSS: 0.11%

updated 2026-08-10T18:17:42.733000

2 posts

A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performing a manipulation results in improper privilege management. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. The vendor was contacted e

thehackerwire@mastodon.social at 2026-08-10T01:59:49.000Z ##

🟠 CVE-2026-19381 - High (7.8)

A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performing a manipulation results in improper privilege m...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-10T01:30:28.000Z ##

Kingston FURY CTRL RGB Control Software v2.0.65.0 hit by HIGH severity vuln (CVE-2026-19381, CVSS 8.5). Local attackers can escalate privileges via NTIOLib_KSFX.sys. Exploit code is public; no patch yet. Restrict local access, monitor systems. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Kingston

##

CVE-2026-66738
(8.8 HIGH)

EPSS: 0.40%

updated 2026-08-10T17:17:35.557000

1 posts

SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-typed user input, which bypasses input sanitization and allows the value to break out of an internal quoted string context when evaluated as PHP. An authenticated attacker with at minimum editor (redacteur) privileges can submit a single crafted GET reque

thehackerwire@mastodon.social at 2026-08-10T17:00:14.000Z ##

🔴 CVE-2026-66738 - Critical (9.8)

SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-typed user input, which bypasses input sanitization and allows the value to break out of an internal q...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19387
(7.6 HIGH)

EPSS: 0.24%

updated 2026-08-10T17:17:30.323000

1 posts

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to application crash, denial of service, memory corruption, or potentially arbitrary code ex

thehackerwire@mastodon.social at 2026-08-10T03:59:51.000Z ##

🟠 CVE-2026-19387 - High (7.6)

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72691
(7.5 HIGH)

EPSS: 0.39%

updated 2026-08-10T15:33:59

1 posts

An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to mint MASTER_KEY-signed file access tokens for arbitrary stored files via the getsignedurl Parse cloud function. The function skips its isAuthenticated check whenever any docId parameter is supplied, even one corresponding to no real document, allowing the authentication

thehackerwire@mastodon.social at 2026-08-10T16:00:57.000Z ##

🟠 CVE-2026-72691 - High (7.5)

An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to mint MASTER_KEY-signed file access tokens for arbitrary stored files via the getsignedurl Parse cloud function. The f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63106
(9.8 CRITICAL)

EPSS: 0.29%

updated 2026-08-10T15:33:59

1 posts

ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the products endpoint is concatenated directly into a MySQL HAVING clause without parameterization in ProductController.php. Attackers can perform time-based blind SQL injection through the unsanitized rating parameter to extract the full database contents,

thehackerwire@mastodon.social at 2026-08-10T16:00:32.000Z ##

🔴 CVE-2026-63106 - Critical (9.8)

ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the products endpoint is concatenated directly into a MySQL HAVING clause without parameterization in Pr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13206
(9.8 CRITICAL)

EPSS: 1.27%

updated 2026-08-10T15:33:42

1 posts

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networks WAH7601 allows OS Command Injection. This issue affects WAH7601: through 20072026.

offseq@infosec.exchange at 2026-08-10T13:30:24.000Z ##

CVE-2026-13206: CRITICAL OS command injection in Zyxel WAH7601 (≤20072026). Remote, unauthenticated code execution possible — no patch yet. Restrict access & monitor vendor updates. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE #Zyxel #Vuln #InfoSec

##

CVE-2026-18933
(7.2 HIGH)

EPSS: 0.28%

updated 2026-08-10T12:17:14.430000

1 posts

The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-privileged user (current_user_can('manage_downloads')) to upload arbitrary files via download-add.php with no extension or MIME-type validation of any kind - no wp_check_filetype_and_ext, no validate_file, and no extension blocklist exist anywhere in the upload handler.

nyanbinary@infosec.exchange at 2026-08-11T14:38:03.000Z ##

Or this one - does that links actually document the vulnerability?

nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-19389
(7.1 HIGH)

EPSS: 0.24%

updated 2026-08-10T03:31:01

1 posts

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information

offseq@infosec.exchange at 2026-08-10T04:30:27.000Z ##

GStreamer gst-plugins-ugly (asfdemux) in Red Hat Enterprise Linux 10 is affected by CVE-2026-19389 (HIGH, CVSS 7.1). Parsing crafted ASF/WMV/WMA files may lead to DoS or info leaks. No patch yet — avoid untrusted media. radar.offseq.com/threat/cve-20 #OffSeq #Linux #CVE #GStreamer

##

CVE-2026-15534
(0 None)

EPSS: 0.20%

updated 2026-08-09T22:16:30.373000

1 posts

Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the sig

offseq@infosec.exchange at 2026-08-10T03:00:24.000Z ##

CVE-2026-15534: HIGH severity in LEONT perl (≤5.45.1) — Integer overflow in regex engine can cause heap corruption or crashes when large inputs and crafted patterns are processed. Avoid risky patterns until patched. radar.offseq.com/threat/cve-20 #OffSeq #Perl #Vuln #AppSec

##

CVE-2026-64564
(9.8 CRITICAL)

EPSS: 0.48%

updated 2026-08-09T06:31:34

4 posts

In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv()). For an ASCONF located through its Address Parameter by __sctp_rcv_asconf_lookup(), that cached transport corresponds

4 repos

https://github.com/HackSpeak/CVE-2026-64564

https://github.com/yandex-cloud-examples/yc-mk8s-sctphantom-mitigation

https://github.com/suominen/sctphantom

https://github.com/ethanolgolf/CVE-2026-64564

tugatech@masto.pt at 2026-08-11T10:46:33.000Z ##

Falha com 18 anos no Linux entrega controlo máximo de administrador. Uma falha de segurança identificada como CVE-2026-64564 permite que utilizadores com acesso local prévio escalarem privilégios até atingirem o estatuto máximo no sistema operativo. 🚨

🔗 tugatech.com.pt/t88893-falha-c

#administrador #controlo #entrega #falha #linux 

##

linuxse@friendica.helvetet.eu at 2026-08-10T05:40:52.000Z ## En 18 år gammal sårbarhet i Linuxkärnans SCTP-kod kan ge lokala angripare fullständig rootåtkomst. Säkerhetsforskarna bakom upptäckten har även visat att felet under vissa förutsättningar kan användas för att ta sig ur en container och angripa värdsystemet. Sårbarheten har fått namnet SCTPhantom och registrerats som CVE-2026-64564. Den finns i Linuxkärnans stöd för nätverksprotokollet SCTP och […]
SCTPhantom – 18 år gammal Linux-bugg kan ge angripare rootåtkomst ##

DailyCyberSecurity@infosec.exchange at 2026-08-10T01:55:44.000Z ##

CVE-2026-64564: SCTP Flaw Enables Container Escape

securityonline.info/sctp-uaf-c

##

beyondmachines1@infosec.exchange at 2026-08-09T14:01:06.000Z ##

SCTPhantom: 18-Year-Old Linux Kernel Flaw Allows Root Access and Container Escape

A use-after-free vulnerability in the Linux SCTP implementation (CVE-2026-64564) allows local attackers to gain root privileges and escape containers. The flaw has existed since 2008 and affects most major Linux distributions.

**If you run Linux (Debian, Ubuntu, RHEL, Rocky) on servers, containers or workstations, install the latest kernel update from your distribution vendor and reboot. The fix for CVE-2026-64564 only takes effect after the restart. If you don't use SCTP, also switch the module off (add both blacklist sctp and install sctp /bin/false to /etc/modprobe.d/sctp.conf, refresh the initramfs, and confirm with lsmod | grep sctp that nothing comes back).**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-71993
(9.8 CRITICAL)

EPSS: 1.35%

updated 2026-08-09T00:31:13

1 posts

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system.

offseq@infosec.exchange at 2026-08-10T00:00:36.000Z ##

MSI Radix AXE6600 (firmware v781521) is affected by CVE-2026-71993 (CVSS 9.8): CRITICAL command injection in openvpn via macfilter allows remote root access. Restrict management access & monitor activity. Details: radar.offseq.com/threat/msi-ra #OffSeq #Vuln #RouterSecurity #CVE2026_71993

##

CVE-2026-5857
(8.1 HIGH)

EPSS: 0.53%

updated 2026-08-08T03:16:46.377000

1 posts

Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag set. On the next TCP segment, tcp_input() re-invokes the parser with topic_received==0, and the persisted topic_len_received==1 skips the length-reading block containing the guard, fall

thehackerwire@mastodon.social at 2026-08-10T02:00:37.000Z ##

🟠 CVE-2026-5857 - High (8.1)

Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag set. On the next TCP segment, tc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

decio@infosec.exchange at 2026-08-10T08:17:55.000Z ##

Dans la suite de wp2shell, encore une jolie chaîne WordPress : #XSS2Shell — CVE-2026-64638.

Au départ, on a “juste” une Reflected XSS pré-auth sur wp-login.php.

Sauf qu’en la chaînant avec plusieurs briques déjà présentes dans WordPress, on arrive à quelque chose de beaucoup moins sympa :

XSS → contexte admin → Application Password → REST API → upload de plugin → RCE 🐚

⚠️ À noter quand même : ce n’est pas du pre-auth zero-click.
Il faut qu’un admin déjà connecté clique sur un lien contrôlé par l’attaquant.

Encore un bon rappel : une “simple XSS” peut devenir franchement méchante une fois mise dans la bonne chaîne.

🩹 Corrigé dans WordPress 7.0.3.
👇
wordpress.org/news/2026/08/wor

En cas de doute sur une exploitation passée : petit coup d’œil aux Application Passwords, aux plugins récemment ajoutés et aux fichiers PHP inhabituels.

"XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)"
👇
pwn.ai/blog/xss2shell

#WordPress #XSS2Shell #CyberVeille

##

campuscodi@mastodon.social at 2026-08-09T19:57:58.000Z ##

Another one of those WordPress pre-auth RCEs

This one's named XSS2Shell, CVE-2026-64638, found with AI, patched in v7.0.3, released on Thursday

pwn.ai/blog/xss2shell

##

CVE-2026-67687
(8.8 HIGH)

EPSS: 0.53%

updated 2026-08-07T18:32:48

1 posts

Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleController.java and system/user/update endpoint in UserController.java

1 repos

https://github.com/qflksheep/CVE-2026-67687-ICS-Park-Smart-Park-Management-System-v2.0

thehackerwire@mastodon.social at 2026-08-09T14:59:50.000Z ##

🟠 CVE-2026-67687 - High (8.8)

Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleController.java and system/user/update endpoint in UserController.java

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20339
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-07T18:31:54

1 posts

A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an integer overflow. An attacker could exploit this

AAKL@infosec.exchange at 2026-08-10T16:26:02.000Z ##

New.

CISA: Gunra Ransomware Advisory cisa.gov/news-events/cybersecu

Cisco:

Advisory for a high-severity vulnerability first published on August 7:

CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #CISA #ransomware #cybercrime #vulnerability

##

CVE-2026-20338
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-07T18:31:53

5 posts

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to ca

ottoto2017@prattohome.com at 2026-08-12T05:43:02.000Z ##

「Cisco社、ClamAVの深刻な脆弱性と公開されているエクスプロイトについて警告 」: #BLEEPINGCOMPUTER

「Ciscoは、Secure Endpoint Connectorに影響を与える2つの深刻な脆弱性について警告を発した。これらの脆弱性により、攻撃者はサービス拒否(DoS)攻撃においてClamAVのスキャンプロセスをクラッシュさせることができる。

これらのセキュリティ上の欠陥( CVE-2026-20337 および CVE-2026-20338 として追跡)は、マルウェアのファイルスキャンに使用されるオープンソースかつクロスプラットフォームのエンジンであるClamAV(Clam AntiVirus)のZIPアーカイブパーサーで発見されました。

シスコが金曜日に発表した勧告によると、これら2つの脆弱性はそれぞれ不適切な境界チェックとメモリ処理に起因するものであり、認証されていないリモート攻撃者によって悪用される可能性がある。 」

bleepingcomputer.com/news/secu

#prattohome

##

ottoto2017@prattohome.com at 2026-08-12T05:43:02.000Z ##

「Cisco社、ClamAVの深刻な脆弱性と公開されているエクスプロイトについて警告 」: #BLEEPINGCOMPUTER

「Ciscoは、Secure Endpoint Connectorに影響を与える2つの深刻な脆弱性について警告を発した。これらの脆弱性により、攻撃者はサービス拒否(DoS)攻撃においてClamAVのスキャンプロセスをクラッシュさせることができる。

これらのセキュリティ上の欠陥( CVE-2026-20337 および CVE-2026-20338 として追跡)は、マルウェアのファイルスキャンに使用されるオープンソースかつクロスプラットフォームのエンジンであるClamAV(Clam AntiVirus)のZIPアーカイブパーサーで発見されました。

シスコが金曜日に発表した勧告によると、これら2つの脆弱性はそれぞれ不適切な境界チェックとメモリ処理に起因するものであり、認証されていないリモート攻撃者によって悪用される可能性がある。 」

bleepingcomputer.com/news/secu

#prattohome

##

jbhall56@infosec.exchange at 2026-08-11T13:59:35.000Z ##

The security flaws (tracked as CVE-2026-20337 and CVE-2026-20338) were found in the ZIP archive parser of ClamAV (Clam AntiVirus), the open-source and cross-platform engine used to scan files for malware. bleepingcomputer.com/news/secu

##

cyberworldops@infosec.exchange at 2026-08-10T20:10:00.000Z ##

Cisco disclosed seven high-severity vulnerabilities in ClamAV, the open-source antivirus engine used in Secure Endpoint Connector across Windows, macOS, and Linux. Two of the flaws (CVE-2026-20337 and CVE-2026-20338) already have public proof-of-concept exploits, elevating the risk. The vulnerabilities can trigger denial-of-service conditions.

#ClamAV #Cisco #CVE #InfoSec

cyberworldops.eu/en/cisco-repo

##

AAKL@infosec.exchange at 2026-08-10T16:26:02.000Z ##

New.

CISA: Gunra Ransomware Advisory cisa.gov/news-events/cybersecu

Cisco:

Advisory for a high-severity vulnerability first published on August 7:

CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #CISA #ransomware #cybercrime #vulnerability

##

CVE-2026-20337
(7.5 HIGH)

EPSS: 0.36%

updated 2026-08-07T18:31:52

5 posts

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A success

ottoto2017@prattohome.com at 2026-08-12T05:43:02.000Z ##

「Cisco社、ClamAVの深刻な脆弱性と公開されているエクスプロイトについて警告 」: #BLEEPINGCOMPUTER

「Ciscoは、Secure Endpoint Connectorに影響を与える2つの深刻な脆弱性について警告を発した。これらの脆弱性により、攻撃者はサービス拒否(DoS)攻撃においてClamAVのスキャンプロセスをクラッシュさせることができる。

これらのセキュリティ上の欠陥( CVE-2026-20337 および CVE-2026-20338 として追跡)は、マルウェアのファイルスキャンに使用されるオープンソースかつクロスプラットフォームのエンジンであるClamAV(Clam AntiVirus)のZIPアーカイブパーサーで発見されました。

シスコが金曜日に発表した勧告によると、これら2つの脆弱性はそれぞれ不適切な境界チェックとメモリ処理に起因するものであり、認証されていないリモート攻撃者によって悪用される可能性がある。 」

bleepingcomputer.com/news/secu

#prattohome

##

ottoto2017@prattohome.com at 2026-08-12T05:43:02.000Z ##

「Cisco社、ClamAVの深刻な脆弱性と公開されているエクスプロイトについて警告 」: #BLEEPINGCOMPUTER

「Ciscoは、Secure Endpoint Connectorに影響を与える2つの深刻な脆弱性について警告を発した。これらの脆弱性により、攻撃者はサービス拒否(DoS)攻撃においてClamAVのスキャンプロセスをクラッシュさせることができる。

これらのセキュリティ上の欠陥( CVE-2026-20337 および CVE-2026-20338 として追跡)は、マルウェアのファイルスキャンに使用されるオープンソースかつクロスプラットフォームのエンジンであるClamAV(Clam AntiVirus)のZIPアーカイブパーサーで発見されました。

シスコが金曜日に発表した勧告によると、これら2つの脆弱性はそれぞれ不適切な境界チェックとメモリ処理に起因するものであり、認証されていないリモート攻撃者によって悪用される可能性がある。 」

bleepingcomputer.com/news/secu

#prattohome

##

jbhall56@infosec.exchange at 2026-08-11T13:59:35.000Z ##

The security flaws (tracked as CVE-2026-20337 and CVE-2026-20338) were found in the ZIP archive parser of ClamAV (Clam AntiVirus), the open-source and cross-platform engine used to scan files for malware. bleepingcomputer.com/news/secu

##

cyberworldops@infosec.exchange at 2026-08-10T20:10:00.000Z ##

Cisco disclosed seven high-severity vulnerabilities in ClamAV, the open-source antivirus engine used in Secure Endpoint Connector across Windows, macOS, and Linux. Two of the flaws (CVE-2026-20337 and CVE-2026-20338) already have public proof-of-concept exploits, elevating the risk. The vulnerabilities can trigger denial-of-service conditions.

#ClamAV #Cisco #CVE #InfoSec

cyberworldops.eu/en/cisco-repo

##

AAKL@infosec.exchange at 2026-08-10T16:26:02.000Z ##

New.

CISA: Gunra Ransomware Advisory cisa.gov/news-events/cybersecu

Cisco:

Advisory for a high-severity vulnerability first published on August 7:

CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #CISA #ransomware #cybercrime #vulnerability

##

CVE-2026-67621
(7.6 HIGH)

EPSS: 0.27%

updated 2026-08-07T18:31:42

1 posts

Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permissions can send direct HTTP requests to the upsert and refresh document store routes to trigger document ingestion, refresh vector database contents, con

thehackerwire@mastodon.social at 2026-08-09T15:59:50.000Z ##

🟠 CVE-2026-67621 - High (7.6)

Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70628
(7.8 HIGH)

EPSS: 0.15%

updated 2026-08-07T18:31:42

1 posts

FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expression to wrap to INT_MIN, bypassing the PARSE_BUF_SIZE comparison and invoking memcpy() with attacker-c

thehackerwire@mastodon.social at 2026-08-09T14:00:12.000Z ##

🟠 CVE-2026-70628 - High (7.8)

FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15733
(9.8 CRITICAL)

EPSS: 3.90%

updated 2026-08-07T18:31:37

1 posts

A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attackers to execute arbitrary commands as root.

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-8037
(9.6 CRITICAL)

EPSS: 99.31%

updated 2026-08-07T18:31:36

2 posts

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

Nuclei template

2 repos

https://github.com/Caster-chen/CVE-2026-8037-POC

https://github.com/HORKimhab/CVE-2026-8037

thecybermind@infosec.exchange at 2026-08-10T14:09:10.000Z ##

🚨 CRITICAL THREAT ALERT: CVE-2026-8037 is under active exploitation per CISA KEV. Progress LoadMaster appliances face remote command injection risks. Secure your perimeter with our strategic C-Suite breakdown covering technical indicators, backdoor mechanics, and hardening protocols.
thecybermind.co/2j7b

##

threatnoir@infosec.exchange at 2026-08-10T12:06:17.000Z ##

⚠️ CRITICAL: CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability

Progress Kemp LoadMaster has a critical RCE vulnerability (CVE-2026-8037) that allows unauthenticated attackers to execute arbitrary commands. Active exploitation started around June 29. Any organization running affected LoadMaster versions needs to patch immediately or risk full appliance compromi…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

CVE-2026-67422
(7.5 HIGH)

EPSS: 0.58%

updated 2026-08-07T18:26:08

1 posts

### Summary Four inline processors in pymdown-extensions contain regular expressions with exponential backtracking. A single untrusted Markdown line under 50 bytes drives `markdown.markdown()` into unbounded CPU on the rendering thread (seconds at ~45 bytes, growing exponentially with each added character). All four fire in the extension's **default configuration** and are reachable through the d

thehackerwire@mastodon.social at 2026-08-10T01:00:00.000Z ##

🟠 CVE-2026-67422 - High (7.5)

pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclink) use regular expressions whose content groups can partition a run...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67622
(9.9 CRITICAL)

EPSS: 0.25%

updated 2026-08-07T18:17:21.357000

1 posts

Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID to Assistants endpoints without workspace ownership verification. Attackers can enumerate cross-workspace assistant metadata, retrieve file and vector s

thehackerwire@mastodon.social at 2026-08-10T00:59:51.000Z ##

🔴 CVE-2026-67622 - Critical (9.9)

Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67688
(9.8 CRITICAL)

EPSS: 0.59%

updated 2026-08-07T16:17:27.400000

1 posts

ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker to execute arbitrary code.

thehackerwire@mastodon.social at 2026-08-09T14:59:59.000Z ##

🔴 CVE-2026-67688 - Critical (9.8)

ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker to execute arbitrary code.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67689
(9.8 CRITICAL)

EPSS: 0.69%

updated 2026-08-07T15:34:17

1 posts

SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated list endpoints

1 repos

https://github.com/qflksheep/CVE-2026-67689-FineAdmin.Mvc-vulnerability

thehackerwire@mastodon.social at 2026-08-09T15:00:09.000Z ##

🔴 CVE-2026-67689 - Critical (9.8)

SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated list endpoints

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5855
(7.5 HIGH)

EPSS: 0.54%

updated 2026-08-07T00:31:27

1 posts

Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer length argument and reads up to six bytes from the input buffer with no bounds check. The caller in lwm2m-engine.c iterates while there is at least one byte remaining, so a crafted CoAP WRITE to any LwM2M endpoint whose final TLV supplies exactly one byte triggers up to five out-of-bo

thehackerwire@mastodon.social at 2026-08-10T02:00:26.000Z ##

🟠 CVE-2026-5855 - High (7.5)

Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer length argument and reads up to six bytes from the input buffer with no bounds check. The caller in lwm2m-engine.c iterates while th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53984
(9.1 CRITICAL)

EPSS: 0.38%

updated 2026-08-07T00:31:26

1 posts

Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauthenticated network peer to wipe or replace the entire SQLite database by sending a single full_restore command with a caller-supplied SQL blob. Attackers can connect to the Socket.IO server on port 700

thehackerwire@mastodon.social at 2026-08-10T02:59:59.000Z ##

🔴 CVE-2026-53984 - Critical (9.1)

Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauthenticated network peer to wipe or replace the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53983
(8.6 HIGH)

EPSS: 0.33%

updated 2026-08-07T00:31:26

1 posts

Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital-source configuration path that allows any unauthenticated Socket.IO client to cause the ground-station process to issue outbound HTTP requests to attacker-chosen destinations. Attackers can connect to the Socket.IO server on port 7000 without credentials due to disabled authenti

thehackerwire@mastodon.social at 2026-08-10T02:59:50.000Z ##

🟠 CVE-2026-53983 - High (8.6)

Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital-source configuration path that allows any unauthenticated Socket.IO client to cause the ground-station process to issue outb...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64665
(8.1 HIGH)

EPSS: 0.31%

updated 2026-08-06T19:25:06

1 posts

### Impact When OAuth login is enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an existing user — potentially including a super admin — without their password. Exploitation requires OAuth to be explicitly enabled with such a provider. ### Patches Fixed in 5.74.1 and 6.24.0. ### Workarounds Only enable OAuth with providers

thehackerwire@mastodon.social at 2026-08-10T01:00:10.000Z ##

🟠 CVE-2026-64665 - High (8.1)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an exist...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-10090
(9.9 CRITICAL)

EPSS: 0.25%

updated 2026-08-06T15:37:22.093000

1 posts

A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM hub namespace can create a Channel resource pointing to a Helm repository they control and a Subscription resource referencing it. The app-subscription controller fetches and applies t

CVE-2026-19036
(7.2 HIGH)

EPSS: 2.47%

updated 2026-08-06T15:32:48

1 posts

A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulation of the argument ppp_custom results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. This project is superseded by FreshTomato.

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-19034
(7.2 HIGH)

EPSS: 2.47%

updated 2026-08-06T12:31:21

1 posts

A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function new_qoslimit_stop of the file /tmp/qoslimittc_stop.sh. Executing a manipulation of the argument wan_iface can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This project is superseded by FreshTomato.

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-19035
(7.2 HIGH)

EPSS: 2.47%

updated 2026-08-06T12:31:21

1 posts

A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The manipulation of the argument new_qoslimit_enable leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used. This project is superseded by FreshTomato.

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-34966
(7.6 HIGH)

EPSS: 0.31%

updated 2026-08-05T21:31:47

2 posts

Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get without a custom DialContext. Attackers can supply arbitrary URLs through release asset download URLs, pull-request patch URLs, or OAuth avatar endpoints

nyanbinary@infosec.exchange at 2026-08-11T16:58:03.000Z ##

ACTUALLY...

CVE-2026-34966 -> github.com/go-gitea/gitea/secu -> CVE-2026-59765

... did they double assign without retraction?

##

nyanbinary@infosec.exchange at 2026-08-11T16:53:26.000Z ##

motherf... nvd.nist.gov/vuln/detail/cve-2

Why is this a vulncheck CVE, gitea got their own CNA!

##

CVE-2026-63077
(9.8 CRITICAL)

EPSS: 10.72%

updated 2026-08-05T18:32:31

2 posts

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Nuclei template

4 repos

https://github.com/AnggaTechI/CVE-2026-63077

https://github.com/BoredHackerBlog/teamcity-CVE-2026-63077-pcap

https://github.com/sfewer-r7/CVE-2026-63077

https://github.com/unveiledhistory49/teamcity-cve-2026-63077-remediation

CVE-2026-70374
(8.8 HIGH)

EPSS: 0.97%

updated 2026-08-05T15:32:14

1 posts

HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail generation routine. Media.generateThumbnail() in src/Server/Entity/Resource/Media.js builds a temporary file path as 'thumbnail' + Path.extname(filename) and passes it, unescaped, into a shell command executed via AppService.exec() ('convert ' + tempFile + ...). The MIME-type filter in

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-18900
(7.2 HIGH)

EPSS: 2.38%

updated 2026-08-05T15:16:46.037000

1 posts

A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file /api/esps of the component Backend RPC. This manipulation of the argument File causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure.

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-71249
(6.1 MEDIUM)

EPSS: 0.15%

updated 2026-08-05T12:31:36

1 posts

299Ko's public contact form (plugin/contact/controllers/ContactController.php, home()) sets raw POST field values (name, firstname, email, message) into the page template with no sanitization. The template engine's variable output function (common/Template.php, _show_var()) echoes values with no htmlspecialchars() call, and the sink template (contact.tpl) outputs these values unescaped into an HTM

CVE-2026-55739
(8.3 HIGH)

EPSS: 0.27%

updated 2026-08-05T09:31:26

1 posts

Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability check and $user->hasCompany($model->company_id). CustomerPolicy's view/update/delete methods omit the company-ownership check entirely, checking only the blanket ability. Route-model-bound customer lookups and the bulk Customer::deleteCustomers() method are similarly unscoped (self

nyanbinary@infosec.exchange at 2026-08-11T14:43:29.000Z ##

Like, please read this: cve.org/ResourcesSupport/AllRe

And then tell me that this CVE nvd.nist.gov/vuln/detail/CVE-2 is sufficiently documented by the one and only reference github.com/crater-invoice-inc/ , the landing page for a project that has not had a release in 4 years (years before the vulnerability was presumably assigned)

##

CVE-2026-18902
(7.2 HIGH)

EPSS: 2.38%

updated 2026-08-05T06:30:32

1 posts

A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerability is the function esps.wan.repeater.set/repeaterproc of the file /api/esps. Performing a manipulation of the argument my2P4key results in command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure.

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-18814
(7.2 HIGH)

EPSS: 2.71%

updated 2026-08-05T00:30:41

1 posts

A vulnerability was found in H3C NX15 V100R017. This impacts the function reload.reload_config of the file /api/esps. The manipulation results in command injection. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure.

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-18686
(9.8 CRITICAL)

EPSS: 2.61%

updated 2026-08-04T16:16:21.593000

1 posts

A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web RPC Wrapper. Performing a manipulation results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-18577
(8.1 HIGH)

EPSS: 4.10%

updated 2026-08-04T14:27:12.530000

3 posts

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

3 repos

https://github.com/CreamyG31337/ncentral-compromise-ioc-triage

https://github.com/HORKimhab/CVE-2026-18577

https://github.com/Yash-Dalvee/stormencryptor-ncentral-defense

blog@insicurezzadigitale.com at 2026-08-11T12:21:10.000Z ##

StormEncryptor: come l’ex affiliato Medusa Storm-1175 ha trasformato N-central in un launchpad ransomware

Microsoft attribuisce a Storm-1175, gruppo legato alla Cina e già affiliato Medusa, lo sfruttamento della falla CVE-2026-18577 in N-able N-central per distribuire il nuovo ransomware StormEncryptor a cascata su decine di MSP e relativi clienti.

insicurezzadigitale.com/storme

##

security_crawler_carl@infosec.exchange at 2026-08-11T04:22:58.000Z ##

Like a fighting-game boss mid-match suddenly swapping movesets, it exploited CVE-2026-18577, an authentication-bypass zero-day in N-able's N-central RMM tool, to get inside.

N-able dropped a hotfix on August 2 — patch to build 2026.3.1.7 immediately, and hunt for rogue svchost.exe files in user Documents folders, a Cloudflared service, or suspicious inbound connections listed in the advisory.

Reward: You've received the Cursed Badge of the Late Patcher — equip it at your peril. (2/2)

##

cyberworldops@infosec.exchange at 2026-08-10T14:20:00.000Z ##

Storm-1175, a China-nexus financially motivated threat actor, is distributing the StormEncryptor ransomware by exploiting a critical zero-day in ConnectWise N-central (CVE-2026-18577). First exploitation was detected July 31, with ransomware deployment beginning August 2. Targeting MSPs amplifies downstream impact across hundreds of managed clients.

#Storm1175 #Ransomware #Ncentral #MSPSecurity

cyberworldops.eu/en/storm-1175

##

CVE-2026-18601
(9.8 CRITICAL)

EPSS: 2.38%

updated 2026-08-03T20:17:16.310000

1 posts

A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. Performing a manipulation of the argument filename results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-17656
(9.6 CRITICAL)

EPSS: 0.40%

updated 2026-07-30T21:32:37

1 posts

Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

security_crawler_carl@infosec.exchange at 2026-08-10T03:03:06.000Z ##

🏆 New Achievement! Three Hundred and Seventy Reasons to Click Update!

Here, in its natural habitat, the unpatched browser clings stubbornly to an older Chrome build while the predator closes in. Google released Chrome 151 on July 28, 2026, correcting 370 vulnerabilities in a single migration — seven rated critical, spanning CVE-2026-17650 through CVE-2026-17656, with another 71 rated high severity. Naturalists observe this is among the largest single-release security drops of the year. (1/2)

##

CVE-2026-17650
(8.3 HIGH)

EPSS: 0.35%

updated 2026-07-30T21:31:31

1 posts

Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

security_crawler_carl@infosec.exchange at 2026-08-10T03:03:06.000Z ##

🏆 New Achievement! Three Hundred and Seventy Reasons to Click Update!

Here, in its natural habitat, the unpatched browser clings stubbornly to an older Chrome build while the predator closes in. Google released Chrome 151 on July 28, 2026, correcting 370 vulnerabilities in a single migration — seven rated critical, spanning CVE-2026-17650 through CVE-2026-17656, with another 71 rated high severity. Naturalists observe this is among the largest single-release security drops of the year. (1/2)

##

CVE-2026-64560
(7.8 HIGH)

EPSS: 0.12%

updated 2026-07-30T12:32:18

2 posts

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwoo decoded and reported a non-leader exec() related race which can result in an UAF: sys_timer_delete() exec() posix_cpu_timer_del() // Observes old leader p = pid_task(pid, pid_type); de_thread() switch_leader(); release

1 repos

https://github.com/villager1314/CVE-2026-64560-Analysis

DailyCyberSecurity at 2026-08-12T01:02:34.386Z ##

CVE-2026-64560: Linux Kernel CPU Timer Use-After-Free Gives a Root Shell, PoC Exploit Code Publicly Disclosed

securityonline.info/linux-kern

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T01:02:34.000Z ##

CVE-2026-64560: Linux Kernel CPU Timer Use-After-Free Gives a Root Shell, PoC Exploit Code Publicly Disclosed

securityonline.info/linux-kern

##

CVE-2026-64747
(7.8 HIGH)

EPSS: 0.14%

updated 2026-07-28T15:32:12

2 posts

A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to execute arbitrary code with kernel privileges.

1 repos

https://github.com/jiuyi155/agxprobe

Mndell@mastodon.social at 2026-08-12T05:57:41.000Z ##

@jurjen_heeck @malwaretech it might be not so much agentic yet. There is however a growing number of CVE’s with AI, like CVE-2026-64747 and the early release by Apple recently of multiple fixes as a result reuters.com/business/apple-say

##

Mndell@mastodon.social at 2026-08-12T05:57:41.000Z ##

@jurjen_heeck @malwaretech it might be not so much agentic yet. There is however a growing number of CVE’s with AI, like CVE-2026-64747 and the early release by Apple recently of multiple fixes as a result reuters.com/business/apple-say

##

CVE-2026-59765(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-07-21T21:55:32

2 posts

### Summary Gitea has robust SSRF protection via `hostmatcher.NewDialContext()` for webhook and migration clone URLs, which validates resolved IPs at the TCP dial level. However, three code paths use raw `http.Get()` (Go's `DefaultClient`) which completely bypasses this protection, enabling SSRF to internal services and local file read via the `file://` scheme. ### Vulnerable Code **File: `modu

nyanbinary@infosec.exchange at 2026-08-11T16:58:40.000Z ##

wait, the CVE-2026-59765 doesn't exist? wtf

##

nyanbinary@infosec.exchange at 2026-08-11T16:58:03.000Z ##

ACTUALLY...

CVE-2026-34966 -> github.com/go-gitea/gitea/secu -> CVE-2026-59765

... did they double assign without retraction?

##

CVE-2026-53361
(7.1 HIGH)

EPSS: 0.13%

updated 2026-07-18T09:32:17

3 posts

In the Linux kernel, the following vulnerability has been resolved: af_unix: Set gc_in_progress to true in unix_gc(). Igor Ushakov reported that unix_gc() could run with gc_in_progress being false if the work is scheduled while running: Thread 1 Thread 2 Thread 3 -------- -------- -------- unix_schedule_gc()

1 repos

https://github.com/sgkdev/bad_garbage

sayzard@mastodon.sayzard.org at 2026-08-12T07:41:56.000Z ##

CVE-2026-53361 AF_Unix GC vs. MSG_PEEK use-after-free container escape

공개 PoC 저장소는 Linux 커널 AF_UNIX 소켓 가비지 컬렉터와 `MSG_PEEK`의 경쟁 조건으로 발생하는 use-after-free(CVE-2026-53361)를 이용해 비권한 사용자 권한 상승 및 컨테이너 탈출이 가능하다고 주장합니다. 핵심은 GC가 순환 참조 소켓을 수집하는 동안 `MSG_PEEK`가 획득한 참조를 정확히 반영하지 못해, 살아 있는 소켓과 연결된 `sk_buff`가 해제되는 문제입니다. 저장소는 Debian trixie, RHEL/CentOS Stream 10, Ubuntu 24.04 HWE 등의 특정 커널 빌드가 영향을 받는다고 열거하며, Linux 6...

github.com/sgkdev/bad_garbage

##

CuratedHackerNews@mastodon.social at 2026-08-12T06:39:04.000Z ##

CVE-2026-53361 AF_Unix GC vs. MSG_PEEK use-after-free container escape

github.com/sgkdev/bad_garbage

#github

##

CuratedHackerNews@mastodon.social at 2026-08-12T06:39:04.000Z ##

CVE-2026-53361 AF_Unix GC vs. MSG_PEEK use-after-free container escape

github.com/sgkdev/bad_garbage

#github

##

CVE-2026-55040
(9.1 CRITICAL)

EPSS: 1.63%

updated 2026-07-14T18:32:38

8 posts

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

2 repos

https://github.com/sfewer-r7/CVE-2026-55040

https://github.com/l0ggg/CVE-2026-55040

cyberworldops at 2026-08-12T06:20:01.341Z ##

Researchers disclosed a full unauthenticated RCE chain in Microsoft SharePoint, tracked as CVE-2026-55040 (CVSS 9.1). The flaw in the authentication pipeline allows an attacker to impersonate any user, including admins, using only the target's AD SID or UPN. No credentials required.

cyberworldops.eu/en/sharepoint

##

DailyCyberSecurity at 2026-08-12T06:14:46.899Z ##

Rapid7 published full details and a PoC for CVE-2026-55040, a critical SharePoint authentication bypass that forges JWT tokens. Patch now.

securityonline.info/sharepoint

##

ottoto2017@prattohome.com at 2026-08-12T04:55:06.000Z ##

「研究者らが、認証不要のリモートコード実行(RCE)を実現するAI支援型SharePointエクスプロイトチェーンを公開 」: #TheHackerNews

「セキュリティ研究者らは、有効なアカウントを持たずに、管理者を含むあらゆるユーザーとしてMicrosoft SharePointサーバーに侵入する方法を発見した。この発見に大きく貢献したのが、AIエージェントを用いた作業だった。

CVE-2026-55040 (CVSS 9.1)として追跡されているこの脆弱性は 、SharePoint Server Subscription Edition、SharePoint Server 2019、およびSharePoint Server 2016に影響します。マイクロソフトの影響を受ける製品リストには、これら3つのオンプレミス版のみが含まれており、SharePoint Onlineは含まれていません。

この攻撃手法は、認証されていないリモート攻撃者が、選択したユーザーの身元を偽装することを可能にします。 」

thehackernews.com/2026/08/rese

#prattohome

##

cyberworldops@infosec.exchange at 2026-08-12T06:20:01.000Z ##

Researchers disclosed a full unauthenticated RCE chain in Microsoft SharePoint, tracked as CVE-2026-55040 (CVSS 9.1). The flaw in the authentication pipeline allows an attacker to impersonate any user, including admins, using only the target's AD SID or UPN. No credentials required.

#SharePointRCE #UnauthenticatedExploit #CVE2026 #CriticalVulnerability

cyberworldops.eu/en/sharepoint

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T06:14:46.000Z ##

Rapid7 published full details and a PoC for CVE-2026-55040, a critical SharePoint authentication bypass that forges JWT tokens. Patch now.

#CVE202655040 #SharePoint #AuthenticationBypass #JWT #Rapid7 #PoC #Cybersecurity

securityonline.info/sharepoint

##

ottoto2017@prattohome.com at 2026-08-12T04:55:06.000Z ##

「研究者らが、認証不要のリモートコード実行(RCE)を実現するAI支援型SharePointエクスプロイトチェーンを公開 」: #TheHackerNews

「セキュリティ研究者らは、有効なアカウントを持たずに、管理者を含むあらゆるユーザーとしてMicrosoft SharePointサーバーに侵入する方法を発見した。この発見に大きく貢献したのが、AIエージェントを用いた作業だった。

CVE-2026-55040 (CVSS 9.1)として追跡されているこの脆弱性は 、SharePoint Server Subscription Edition、SharePoint Server 2019、およびSharePoint Server 2016に影響します。マイクロソフトの影響を受ける製品リストには、これら3つのオンプレミス版のみが含まれており、SharePoint Onlineは含まれていません。

この攻撃手法は、認証されていないリモート攻撃者が、選択したユーザーの身元を偽装することを可能にします。 」

thehackernews.com/2026/08/rese

#prattohome

##

AAKL@infosec.exchange at 2026-08-11T17:25:10.000Z ##

New.

Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040) rapid7.com/blog/post/ra-micros @Rapid7Official #Microsoft #infosec #threatresearch #SharePoint #vulnerability

##

obivan@infosec.exchange at 2026-08-11T13:37:38.000Z ##

Microsoft SharePoint JWT Authentication Bypass (CVE-2026-55040) github.com/sfewer-r7/CVE-2026-

##

CVE-2026-31431
(7.8 HIGH)

EPSS: 99.91%

updated 2026-07-14T15:32:55

1 posts

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just

Nuclei template

100 repos

https://github.com/novysodope/copy-fail-CVE-2026-31431-C

https://github.com/haydenjames/CVE-2026-31431-check

https://github.com/XsanFlip/CVE-2026-31431-Patch

https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized

https://github.com/hans362/CVE-2026-31431-Copy-Fail-Container-Escape

https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs

https://github.com/KaraZajac/DIRTYFAIL

https://github.com/sgkdev/ptrace_may_dream

https://github.com/lonelyor/CVE-2026-31431-exp

https://github.com/g1nt0n1x/copy-fail-CVE-2026-31431-shell

https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag

https://github.com/diemoeve/copyfail-rs

https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431

https://github.com/wesmar/CVE-2026-31431

https://github.com/gagaltotal/cve-2026-31431-copy-fail

https://github.com/mym0us3r/COPY-FAIL-Detection-with-Wazuh-4.14.4

https://github.com/ncmprbll/copy-fail-rs

https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit

https://github.com/cozystack/copy-fail-blocker

https://github.com/adampielak/CVE-2026-31431_SCA_WAZUH

https://github.com/pascal-gujer/CVE-2026-31431

https://github.com/kvakirsanov/CVE-2026-31431-live-process-code-injection

https://github.com/samanzamani/copy-fail-checker

https://github.com/insomnisec/Detections-CVE-2026-31431

https://github.com/Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431

https://github.com/ErdemOzgen/copy-fail-cve-2026-31431

https://github.com/theori-io/copy-fail-CVE-2026-31431

https://github.com/yandex-cloud-examples/yc-mk8s-copy-fail-mitigation

https://github.com/Shotafry/CopyFail-Exploits-CVE-2026-31431

https://github.com/pedromizz/copy-fail

https://github.com/Smarttfoxx/copyfail

https://github.com/painoob/Copy-Fail-Exploit-CVE-2026-31431

https://github.com/cyber-joker/copy-fail-python

https://github.com/qi4L/CVE-2026-31431-Container-Escape

https://github.com/wgnet/wg.copyfail.patch

https://github.com/desultory/CVE-2026-31431

https://github.com/M4xSec/CVE-2026-31431-RCE-Exploit

https://github.com/ZephrFish/CopyFail-CVE-2026-31431

https://github.com/yuspring/cve-2026-31431-poc

https://github.com/mahdi13830510/CVE-2026-31431-mitigation-suite

https://github.com/Alfredooe/CVE-2026-31431

https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe

https://github.com/kinryulabs/rootpacket-cve-2026-31431

https://github.com/Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail

https://github.com/rootsecdev/cve_2026_31431

https://github.com/rvzsec/CVE-2026-31431

https://github.com/b5null/CVE-2026-31431-C

https://github.com/AliHzSec/CVE-2026-31431

https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script

https://github.com/Qengineering/RK35xx-CopyFail-Hotfix

https://github.com/MrAriaNet/cPanel-Fix

https://github.com/ExploitEoom/CVE-2026-31431

https://github.com/0xShe/CVE-2026-31431

https://github.com/st4rburn/public-passwd

https://github.com/guiimoraes/CVE-2026-31431

https://github.com/abdullaabdullazade/CVE-2026-31431

https://github.com/badsectorlabs/copyfail-go

https://github.com/TheMalwareGuardian/CVE-2026-31431

https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail

https://github.com/bigwario/copy-fail-CVE-2026-31431-C

https://github.com/ben-slates/CVE-2026-31431-Exploit

https://github.com/xeloxa/copyfail-exploit

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC

https://github.com/jbnetwork-git/copy-fail-check

https://github.com/Xerxes-2/CVE-2026-31431-rs

https://github.com/atgreen/block-copyfail

https://github.com/Sl4cK0TH/CVE-2026-31431-PoC

https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC

https://github.com/AdityaBhatt3010/CVE-2026-31431

https://github.com/scriptzteam/Paranoid-Copy-Fail-CVE-2026-31431

https://github.com/4xura/CVE-2026-31431-Copy-Fail

https://github.com/cs8425/copy-fail-go

https://github.com/luotian2/CVE-2026-31431

https://github.com/sgkdev/page_inject

https://github.com/bootsareme/copyfail-deconstructed

https://github.com/Boos4721/copyfail-rs

https://github.com/Dabbleam/CVE-2026-31431-mitigation

https://github.com/adysec/cve-2026-31431

https://github.com/sammwyy/copyfail-rs

https://github.com/erlangparasu/mitigate_cve_2026_31431-sh

https://github.com/sec17br/CVE-2026-31431-Copy-Fail

https://github.com/Huchangzhi/autorootlinux

https://github.com/mrunalp/block-copyfail

https://github.com/aestechno/cve-2026-31431-ansible

https://github.com/Juguitos/copy-fail

https://github.com/kadir/copy-fail-CVE-2026-31431-IOC

https://github.com/philfry/cve-2026-31431-ftrace

https://github.com/povzayd/CVE-2026-31431

https://github.com/wuwu001/CVE-2026-31431-exploit

https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE

https://github.com/Iamliuxiaozhen/copy_fail

https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431

https://github.com/JuanBindez/CVE-2026-31431

https://github.com/malwarekid/CVE-2026-31431

https://github.com/JnamerZ/CopyFail-CVE-2026-31431

https://github.com/MartinPham/copy-fail-CVE-2026-31431-php

https://github.com/SeanRickerd/cve-2026-31431

https://github.com/0xBlackash/CVE-2026-31431

https://github.com/tgies/copy-fail-c

sigint@fosstodon.org at 2026-08-11T23:45:08.000Z ##

🐧 SIGINT // Ubuntu Watch — 2026-08-12

A 732-byte script reportedly roots any Linux since 2017 via a logic flaw, not memory corruption. If accurate this hits every homelab box and container host regardless of distro. Patch fast, verify your kernel version against the advisory.

🔗 bugcrowd.com/blog/what-we-know

#Ubuntu #Linux #infosec

##

CVE-2026-12879
(0 None)

EPSS: 0.19%

updated 2026-07-09T16:39:17.737000

1 posts

An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google Cloud Platform allows an authenticated attacker to exfiltrate cross-tenant data. This vulnerability was patched on 12 June 2026 on the Apigee Servers, and no customer action is needed.

AAKL@infosec.exchange at 2026-08-11T17:11:08.000Z ##

Broadcom has several new advisories that include two critical vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

CISA:

Industrial vulnerability: Johnson Controls C-CURE 9000 and Victor application server (Update A) cisa.gov/news-events/ics-advis

Blog post: Cyber Storm X: 20 Years of Readiness, Resilience, and Real‑World Impact cisa.gov/news-events/news/cybe #CISA

Cisco:

High-severity: CVE-2026-20349: Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco

Yesterday:

Tenable Research Advisories:

Medium-severity: CVE-2026-12879: Google Cloud Platform (GCP) Apigee Cross-Tenant Data Exfiltration via Confused Deputy tenable.com/security/research/ #infosec #Google #vulnerability

##

CVE-2026-50656
(7.8 HIGH)

EPSS: 10.75%

updated 2026-07-09T00:17:26.607000

8 posts

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;RoguePlanet &quot;.

3 repos

https://github.com/HORKimhab/CVE-2026-50656

https://github.com/g0thamRabb1t/CVE-2026-50656-rogueplanet-validation

https://github.com/0xBlackash/CVE-2026-50656

cyberworldops at 2026-08-12T08:10:01.208Z ##

A proof-of-concept for ShieldBreak has been disclosed, showing how to bypass the patch Microsoft issued for CVE-2026-50656 (RoguePlanet). The flaw targets SYSTEM-level privilege escalation on Windows systems protected by Microsoft Defender.

cyberworldops.eu/en/shieldbrea

##

teezeh@ieji.de at 2026-08-12T05:27:04.000Z ##

„Microsoft hat mit dem August 2026-Patchday zwar einige Sicherheitskorrekturen ausgeliefert. Aber die RoguePlanet genannte Schwachstelle (CVE-2026-50656) soll nicht ausreichend abgeschwächt worden sein. Der als Nightmare Eclipse agierende Sicherheitsforscher hat einen ShieldBreak genannten Proof of Concept (PoC) veröffentlicht.“

borncity.com/blog/2026/08/12/s

##

DailyCyberSecurity at 2026-08-12T04:24:39.796Z ##

A public PoC named ShieldBreak bypasses Microsoft's CVE-2026-50656 patch, enabling Windows Defender privilege escalation to SYSTEM.

securityonline.info/shieldbrea

##

cyberworldops@infosec.exchange at 2026-08-12T08:10:01.000Z ##

A proof-of-concept for ShieldBreak has been disclosed, showing how to bypass the patch Microsoft issued for CVE-2026-50656 (RoguePlanet). The flaw targets SYSTEM-level privilege escalation on Windows systems protected by Microsoft Defender.

#ShieldBreak #CVE202650656 #PrivilegeEscalation #MicrosoftDefender

cyberworldops.eu/en/shieldbrea

##

teezeh@ieji.de at 2026-08-12T05:27:04.000Z ##

„Microsoft hat mit dem August 2026-Patchday zwar einige Sicherheitskorrekturen ausgeliefert. Aber die RoguePlanet genannte Schwachstelle (CVE-2026-50656) soll nicht ausreichend abgeschwächt worden sein. Der als Nightmare Eclipse agierende Sicherheitsforscher hat einen ShieldBreak genannten Proof of Concept (PoC) veröffentlicht.“

borncity.com/blog/2026/08/12/s

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T04:24:39.000Z ##

A public PoC named ShieldBreak bypasses Microsoft's CVE-2026-50656 patch, enabling Windows Defender privilege escalation to SYSTEM.

#ShieldBreak #CVE202650656 #WindowsDefender #PrivilegeEscalation #PoC #RoguePlanet #Cybersecurity

securityonline.info/shieldbrea

##

AmmarSpaces@infosec.exchange at 2026-08-11T21:36:43.000Z ##

On another news NightmareEclipse (the goat?) returned with a new PoC, after Microsoft failed to fully patch RoguePlanet (CVE-2026-50656), the current PoC only made for latest Windows 11 release, but they said that Windows 10 also still vulnerable. And yeah, it works even after the latest update

github.com/MSNightmare/ShieldB

#cybersecurity #infosec #zeroday #vulnerability #windows #nightmareEclipse

##

DarkWebInformer@infosec.exchange at 2026-08-11T19:57:18.000Z ##

🚨Nightmare Eclipse has released a new zero-day PoC called ShieldBreak

Per the security researcher: "Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass."

GitHub: github.com/MSNightmare/ShieldB

##

CVE-2026-45659
(8.8 HIGH)

EPSS: 9.12%

updated 2026-07-01T21:35:53

2 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

2 repos

https://github.com/HORKimhab/CVE-2026-45659

https://github.com/WismanSec/sharepoint-2026-poc

cyberworldops@infosec.exchange at 2026-08-11T16:10:00.000Z ##

CISA has confirmed active ransomware exploitation of CVE-2026-45659, a remote code execution flaw in Microsoft SharePoint. The vulnerability was added to the Known Exploited Vulnerabilities catalog on July 1st with a mandatory 3-day remediation deadline for federal agencies.

#SharePoint #Ransomware #CISA #CVE202645659

cyberworldops.eu/en/sharepoint

##

kev_Stalker@infosec.exchange at 2026-08-11T09:26:34.000Z ##

CVE-2026-45659 - Changed to Known Ransomware Status

Microsoft SharePoint Server Deserialization of Untrusted Data VulnerabilityVendor: MicrosoftProduct: SharePoint ServerMicrosoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 10, 2026 at 17:08:17 UTCDate nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-43074
(7.8 HIGH)

EPSS: 0.48%

updated 2026-06-17T10:48:53.150000

1 posts

In the Linux kernel, the following vulnerability has been resolved: eventpoll: defer struct eventpoll free to RCU grace period In certain situations, ep_free() in eventpoll.c will kfree the epi->ep eventpoll struct while it still being used by another concurrent thread. Defer the kfree() to an RCU callback to prevent UAF.

1 repos

https://github.com/PeronGH/badepoll-selinux-disabler

DailyCyberSecurity@infosec.exchange at 2026-08-10T12:56:45.000Z ##

CVE-2026-43074: Linux Kernel eventpoll Use-After-Free Gives a Root Shell, PoC Exploit Code Publicly Disclosed

securityonline.info/linux-kern

##

CVE-1999-1587
(0 None)

EPSS: 0.95%

updated 2026-06-16T21:50:46.783000

1 posts

/usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, allows local users to view the environment variables and values of arbitrary processes via the -e option.

raptor@infosec.exchange at 2026-08-11T09:06:33.000Z ##

Finally, to close out our short #GitHub tour, a few vintage repositories 🍷 that have aged into historical curiosities and are now (mostly) harmless. Still worth a look as a learning resource, for humans and AI alike 🤖

github.com/0xdea/exploits - a collection of my public exploits from CVE-1999-1587 onwards
github.com/0xdea/shellcode - a small collection of my shellcode samples
github.com/0xdea/advisories - my public advisories starting from CAN-2003-0190, err..., CVE-2003-0190 up until today

Thanks for following along, and enjoy your summer break! ☀️

##

CVE-2026-34486
(7.5 HIGH)

EPSS: 82.93%

updated 2026-06-08T23:28:56

1 posts

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

Nuclei template

6 repos

https://github.com/anonmrc/CVE-2026-34486-e-Tomcat-Tribes

https://github.com/striga-ai/CVE-2026-34486

https://github.com/razureink/cve-2026-34486-tomcat_encrypt_bypass_reproduction

https://github.com/AirSkye/CVE-2026-34486-poc

https://github.com/punitdarji/tomcat-cve-2026-34486

https://github.com/404-src/CVE-2026-34486

thecybermind@infosec.exchange at 2026-08-10T18:21:57.000Z ##

🚨 CRITICAL THREAT ALERT: CVE-2026-34486 in Apache Tomcat is under active CISA KEV exploitation. Missing encryption allows intercept of sensitive corporate data. Review our strategic C-Suite brief on technical vectors, persistence checks, and endpoint hardening to protect your data streams. thecybermind.co/6dk1

##

CVE-2026-48048
(7.5 HIGH)

EPSS: 0.36%

updated 2026-05-26T20:17:03

1 posts

### Impact XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient and with slightly modified parameters to the `LiveTableResults`, it is still possible to discover password hashes one bit at a time, so with 768 requests, the full password salt and hash can be retrieved of a user. ### Patches The check for password (and email properties) has been adjusted in XWiki 18.0.0RC1, 17.1

thehackerwire@mastodon.social at 2026-08-10T17:00:34.000Z ##

🟠 CVE-2026-48048 - High (7.5)

XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Starting with version 6.2.1 and prior to versions 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17, with slightly modified parameters to t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-27912
(8.0 HIGH)

EPSS: 0.24%

updated 2026-04-14T18:30:50

1 posts

Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.

2 repos

https://github.com/Semperis-Community/ResetNightmare

https://github.com/mihat2/ResetNightmare-impacket

CVE-2003-0190(CVSS UNKNOWN)

EPSS: 76.75%

updated 2026-03-22T05:08:29

1 posts

OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.

raptor@infosec.exchange at 2026-08-11T09:06:33.000Z ##

Finally, to close out our short #GitHub tour, a few vintage repositories 🍷 that have aged into historical curiosities and are now (mostly) harmless. Still worth a look as a learning resource, for humans and AI alike 🤖

github.com/0xdea/exploits - a collection of my public exploits from CVE-1999-1587 onwards
github.com/0xdea/shellcode - a small collection of my shellcode samples
github.com/0xdea/advisories - my public advisories starting from CAN-2003-0190, err..., CVE-2003-0190 up until today

Thanks for following along, and enjoy your summer break! ☀️

##

CVE-2025-7771(CVSS UNKNOWN)

EPSS: 6.83%

updated 2025-08-06T12:31:25

1 posts

ThrottleStop.sys, a legitimate driver, exposes two IOCTL interfaces that allow arbitrary read and write access to physical memory via the MmMapIoSpace function. This insecure implementation can be exploited by a malicious user-mode application to patch the running Windows kernel and invoke arbitrary kernel functions with ring-0 privileges. The vulnerability enables local attackers to execute arbit

12 repos

https://github.com/Gabriel-Lacorte/CVE-2025-7771

https://github.com/enessakircolak/CVE-2025-7771

https://github.com/AmrHuss/throttlestop-exploit-rw

https://github.com/I3r1h0n/Sigurd

https://github.com/mein-0/cve-2025-7771

https://github.com/lzty/CVE-2025-7771

https://github.com/v31l0x1/ThrottleStopPPL

https://github.com/xM0kht4r/CVE-2025-7771

https://github.com/Demoo1337/ThrottleStop

https://github.com/DeathShotXD/0xKern3lCrush

https://github.com/D4rkks/CVE-2025-7771-Vulnerability-Exploration

https://github.com/fxrstor/ThrottleStopPoC

obivan@infosec.exchange at 2026-08-11T15:13:19.000Z ##

CVE-2025-7771 — ThrottleStop.sys Arbitrary Physical Memory R/W github.com/enessakircolak/CVE-

##

CVE-2026-44772
(0 None)

EPSS: 0.00%

2 posts

N/A

beyondmachines1 at 2026-08-12T08:01:15.265Z ##

SAP August 2026 Patch Day Fixes Critical Code Injection and Memory Corruption Flaws

SAP's August 2026 Security Patch Day addresses 31 vulnerabilities, including a critical CVSS 10.0 authentication bypass in Commerce Cloud and code injection flaws in Manufacturing Integration and Intelligence. These vulnerabilities allow remote attackers to execute arbitrary commands and gain unauthorized access to internal enterprise systems.

**If you run SAP products, especially Manufacturing Integration and Intelligence (MII) read the advisory in detail. First make sure these systems are isolated from the internet where possible and reachable only from trusted internal networks. Then apply SAP's August 2026 security notes ASAP starting with the critical fixes for Commerce Cloud (CVE-2026-58231) and MII (CVE-2026-44772, CVE-2026-44758), followed by the ABAP Platform patch (CVE-2026-34265).**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-08-12T08:01:15.000Z ##

SAP August 2026 Patch Day Fixes Critical Code Injection and Memory Corruption Flaws

SAP's August 2026 Security Patch Day addresses 31 vulnerabilities, including a critical CVSS 10.0 authentication bypass in Commerce Cloud and code injection flaws in Manufacturing Integration and Intelligence. These vulnerabilities allow remote attackers to execute arbitrary commands and gain unauthorized access to internal enterprise systems.

**If you run SAP products, especially Manufacturing Integration and Intelligence (MII) read the advisory in detail. First make sure these systems are isolated from the internet where possible and reachable only from trusted internal networks. Then apply SAP's August 2026 security notes ASAP starting with the critical fixes for Commerce Cloud (CVE-2026-58231) and MII (CVE-2026-44772, CVE-2026-44758), followed by the ABAP Platform patch (CVE-2026-34265).**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-72915
(0 None)

EPSS: 0.28%

3 posts

N/A

harald@mementomori.social at 2026-08-12T06:12:19.000Z ##

Vulnerabilities in #Mastodon
URL: github.com/mastodon/mastodon/s
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5
CVEs: CVE-2026-72914, CVE-2026-72915, CVE-2026-72916
See also:
- github.com/mastodon/mastodon/s
- github.com/mastodon/mastodon/s

CVE-2026-72914 (CVSS: 7.5): A Mastodon statistics endpoint intended for
instance administrators was checking for the appropriate permissions before
returning the results, but not before computing them, allowing anyone to issue
potentially expensive requests.

CVE-2026-72915 (CVSS: 7.5): Mastodon versions 4.6.0 to 4.6.4 allow any
logged-in local user to access personally-identifying information about other
local-users due to an incorrect access control validation.

CVE-2026-72916 (CVSS: 6.3): By nature, Mastodon performs a lot of outbound
requests to user-provided domains. Mastodon however has some protection
mechanism to disallow requests to local IP addresses (unless specified in
ALLOWED_PRIVATE_ADDRESSES) to avoid the “confused deputy” problem. The list of
disallowed IP address ranges was lacking the IPv4-compatible IPv6 address
range that can be used to reach local IP addresses on specific configurations.

##

harald@mementomori.social at 2026-08-12T06:12:19.000Z ##

Vulnerabilities in #Mastodon
URL: github.com/mastodon/mastodon/s
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5
CVEs: CVE-2026-72914, CVE-2026-72915, CVE-2026-72916
See also:
- github.com/mastodon/mastodon/s
- github.com/mastodon/mastodon/s

CVE-2026-72914 (CVSS: 7.5): A Mastodon statistics endpoint intended for
instance administrators was checking for the appropriate permissions before
returning the results, but not before computing them, allowing anyone to issue
potentially expensive requests.

CVE-2026-72915 (CVSS: 7.5): Mastodon versions 4.6.0 to 4.6.4 allow any
logged-in local user to access personally-identifying information about other
local-users due to an incorrect access control validation.

CVE-2026-72916 (CVSS: 6.3): By nature, Mastodon performs a lot of outbound
requests to user-provided domains. Mastodon however has some protection
mechanism to disallow requests to local IP addresses (unless specified in
ALLOWED_PRIVATE_ADDRESSES) to avoid the “confused deputy” problem. The list of
disallowed IP address ranges was lacking the IPv4-compatible IPv6 address
range that can be used to reach local IP addresses on specific configurations.

##

thehackerwire@mastodon.social at 2026-08-10T22:59:58.000Z ##

🟠 CVE-2026-72915 - High (7.5)

Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta.1, any logged-in local user could use the show action in app/controllers/admin/collections_controller.rb to access personally ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72916
(0 None)

EPSS: 0.36%

2 posts

N/A

harald@mementomori.social at 2026-08-12T06:12:19.000Z ##

Vulnerabilities in #Mastodon
URL: github.com/mastodon/mastodon/s
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5
CVEs: CVE-2026-72914, CVE-2026-72915, CVE-2026-72916
See also:
- github.com/mastodon/mastodon/s
- github.com/mastodon/mastodon/s

CVE-2026-72914 (CVSS: 7.5): A Mastodon statistics endpoint intended for
instance administrators was checking for the appropriate permissions before
returning the results, but not before computing them, allowing anyone to issue
potentially expensive requests.

CVE-2026-72915 (CVSS: 7.5): Mastodon versions 4.6.0 to 4.6.4 allow any
logged-in local user to access personally-identifying information about other
local-users due to an incorrect access control validation.

CVE-2026-72916 (CVSS: 6.3): By nature, Mastodon performs a lot of outbound
requests to user-provided domains. Mastodon however has some protection
mechanism to disallow requests to local IP addresses (unless specified in
ALLOWED_PRIVATE_ADDRESSES) to avoid the “confused deputy” problem. The list of
disallowed IP address ranges was lacking the IPv4-compatible IPv6 address
range that can be used to reach local IP addresses on specific configurations.

##

harald@mementomori.social at 2026-08-12T06:12:19.000Z ##

Vulnerabilities in #Mastodon
URL: github.com/mastodon/mastodon/s
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5
CVEs: CVE-2026-72914, CVE-2026-72915, CVE-2026-72916
See also:
- github.com/mastodon/mastodon/s
- github.com/mastodon/mastodon/s

CVE-2026-72914 (CVSS: 7.5): A Mastodon statistics endpoint intended for
instance administrators was checking for the appropriate permissions before
returning the results, but not before computing them, allowing anyone to issue
potentially expensive requests.

CVE-2026-72915 (CVSS: 7.5): Mastodon versions 4.6.0 to 4.6.4 allow any
logged-in local user to access personally-identifying information about other
local-users due to an incorrect access control validation.

CVE-2026-72916 (CVSS: 6.3): By nature, Mastodon performs a lot of outbound
requests to user-provided domains. Mastodon however has some protection
mechanism to disallow requests to local IP addresses (unless specified in
ALLOWED_PRIVATE_ADDRESSES) to avoid the “confused deputy” problem. The list of
disallowed IP address ranges was lacking the IPv4-compatible IPv6 address
range that can be used to reach local IP addresses on specific configurations.

##

CVE-2026-72914
(0 None)

EPSS: 0.45%

3 posts

N/A

harald@mementomori.social at 2026-08-12T06:12:19.000Z ##

Vulnerabilities in #Mastodon
URL: github.com/mastodon/mastodon/s
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5
CVEs: CVE-2026-72914, CVE-2026-72915, CVE-2026-72916
See also:
- github.com/mastodon/mastodon/s
- github.com/mastodon/mastodon/s

CVE-2026-72914 (CVSS: 7.5): A Mastodon statistics endpoint intended for
instance administrators was checking for the appropriate permissions before
returning the results, but not before computing them, allowing anyone to issue
potentially expensive requests.

CVE-2026-72915 (CVSS: 7.5): Mastodon versions 4.6.0 to 4.6.4 allow any
logged-in local user to access personally-identifying information about other
local-users due to an incorrect access control validation.

CVE-2026-72916 (CVSS: 6.3): By nature, Mastodon performs a lot of outbound
requests to user-provided domains. Mastodon however has some protection
mechanism to disallow requests to local IP addresses (unless specified in
ALLOWED_PRIVATE_ADDRESSES) to avoid the “confused deputy” problem. The list of
disallowed IP address ranges was lacking the IPv4-compatible IPv6 address
range that can be used to reach local IP addresses on specific configurations.

##

harald@mementomori.social at 2026-08-12T06:12:19.000Z ##

Vulnerabilities in #Mastodon
URL: github.com/mastodon/mastodon/s
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5
CVEs: CVE-2026-72914, CVE-2026-72915, CVE-2026-72916
See also:
- github.com/mastodon/mastodon/s
- github.com/mastodon/mastodon/s

CVE-2026-72914 (CVSS: 7.5): A Mastodon statistics endpoint intended for
instance administrators was checking for the appropriate permissions before
returning the results, but not before computing them, allowing anyone to issue
potentially expensive requests.

CVE-2026-72915 (CVSS: 7.5): Mastodon versions 4.6.0 to 4.6.4 allow any
logged-in local user to access personally-identifying information about other
local-users due to an incorrect access control validation.

CVE-2026-72916 (CVSS: 6.3): By nature, Mastodon performs a lot of outbound
requests to user-provided domains. Mastodon however has some protection
mechanism to disallow requests to local IP addresses (unless specified in
ALLOWED_PRIVATE_ADDRESSES) to avoid the “confused deputy” problem. The list of
disallowed IP address ranges was lacking the IPv4-compatible IPv6 address
range that can be used to reach local IP addresses on specific configurations.

##

thehackerwire@mastodon.social at 2026-08-10T22:59:48.000Z ##

🟠 CVE-2026-72914 - High (7.5)

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, the administrative statistics endpoints handled by Api::V1::Admin::MeasuresController and Api::V1::Admin::RetentionContro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12234
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-12T06:00:36.000Z ##

🟠 CVE-2026-12234 - High (7.8)

The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsock_recvmsg() in subsys/net/lib/sockets/sockets.c snapshot the caller-supplied struct net_msghdr into a kernel-side copy with k_usermode_from_copy(), but then re-read the still-li...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T06:00:36.000Z ##

🟠 CVE-2026-12234 - High (7.8)

The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsock_recvmsg() in subsys/net/lib/sockets/sockets.c snapshot the caller-supplied struct net_msghdr into a kernel-side copy with k_usermode_from_copy(), but then re-read the still-li...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48765
(0 None)

EPSS: 0.00%

3 posts

N/A

offseq at 2026-08-12T06:00:27.764Z ##

CVE-2026-48765 (CRITICAL, CVSS 9.9): TypeBot.io <3.17.0 suffers from an auth bypass, letting read collaborators hijack OAuth credentials across workspaces. Upgrade to 3.17.0+ ASAP. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-12T06:00:27.000Z ##

CVE-2026-48765 (CRITICAL, CVSS 9.9): TypeBot.io <3.17.0 suffers from an auth bypass, letting read collaborators hijack OAuth credentials across workspaces. Upgrade to 3.17.0+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE202648765 #TypeBot #OAuth #Security

##

thehackerwire@mastodon.social at 2026-08-11T22:01:20.000Z ##

🔴 CVE-2026-48765 - Critical (9.9)

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from a readable bot configuration and then overwrite that credential through `handleUpdateOAuthCredent...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73246
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-12T00:00:02.000Z ##

🟠 CVE-2026-73246 - High (7.5)

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kestra/worker/endpoint/WorkerEndpoint.java serves GET /worker without authentication and serializes the complete live Task object, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T00:00:02.000Z ##

🟠 CVE-2026-73246 - High (7.5)

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kestra/worker/endpoint/WorkerEndpoint.java serves GET /worker without authentication and serializes the complete live Task object, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48763
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-11T22:00:20.000Z ##

🟠 CVE-2026-48763 - High (8.2)

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-url` that accepts an attacker-controlled `filePath` and returns a presigned...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55676
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-11T22:00:10.000Z ##

🟠 CVE-2026-55676 - High (8.8)

Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and stores them in a directory served by the same nginx and php-fpm instance. The allow-list that s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72898
(0 None)

EPSS: 0.69%

2 posts

N/A

Nuclei template

secdb@infosec.exchange at 2026-08-11T21:00:13.000Z ##

🚨 [CISA-2026:0811] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-20349 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-68820 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows Ancillary Function Driver for WinSock
- Notes: portal.msrc.microsoft.com/en-U ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-72898 (secdb.nttzen.cloud/cve/detail/)
- Name: Metabase SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Metabase
- Product: Metabase
- Notes: metabase.com/blog/security-upd ; github.com/metabase/metabase/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260811 #cisa20260811 #cve_2026_20349 #cve_2026_68820 #cve_2026_72898 #cve202620349 #cve202668820 #cve202672898

##

cisakevtracker@mastodon.social at 2026-08-11T20:01:25.000Z ##

CVE ID: CVE-2026-72898
Vendor: Metabase
Product: Metabase
Date Added: 2026-08-11
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-73231
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-11T21:00:03.000Z ##

🟠 CVE-2026-73231 - High (7.8)

Faker generates massive amounts of fake data in the browser and Node.js. Prior to 10.5.0, the faker.helpers.fake method in src/modules/helpers/eval.ts allows attacker-controlled fake templates to access the Function constructor through fakeEval.re...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73225
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-11T20:00:22.000Z ##

🟠 CVE-2026-73225 - High (8.1)

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to write attacker-controlled content outside the selected download directory because recurs...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73224
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-11T20:00:08.000Z ##

🟠 CVE-2026-73224 - High (8.8)

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to execute arbitrary commands when a user downloads a crafted folder and invokes Properties...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73069
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-11T17:00:46.000Z ##

🔴 CVE-2026-73069 - Critical (9.1)

Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace administrator with the DATA_MODEL permission to supply settings.asExpression for the system TS_VECTOR field searchVector through ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72921
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-11T16:01:19.000Z ##

🟠 CVE-2026-72921 - High (8.1)

SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.HasPrefix on raw path strings, so a filer JWT scoped to /tenant1 also authorized sibling paths suc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72920
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-11T16:01:00.000Z ##

🔴 CVE-2026-72920 - Critical (9.8)

SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the filer gRPC ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

_r_netsec@infosec.exchange at 2026-08-11T15:43:04.000Z ##

CopyEscape: Container-to-host arbitrary file write via docker cp (CVE-2026-17106) imperva.com/blog/copyescape-ta

##

CVE-2026-44945
(0 None)

EPSS: 0.30%

1 posts

N/A

DailyCyberSecurity@infosec.exchange at 2026-08-11T01:03:45.000Z ##

CVE-2026-44945: Rancher Cross-Cluster Impersonation Flaw Enables Full Privilege Escalation, Rated CVSS 9.1

securityonline.info/rancher-pr

##

CVE-2026-48161
(0 None)

EPSS: 0.42%

1 posts

N/A

offseq@infosec.exchange at 2026-08-11T00:00:34.000Z ##

CVE-2026-48161 | CRITICAL: dai-shi react18-use had malicious postinstall script — RCE on dev machines via npm install. Not in npm registry, but local checkouts may be compromised. Rotate creds & reimage if affected. radar.offseq.com/threat/cve-20 #OffSeq #SupplyChain #CVE #npm #infosec

##

CVE-2026-72911
(0 None)

EPSS: 0.38%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T22:00:16.000Z ##

🔴 CVE-2026-72911 - Critical (9.9)

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py render s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72901
(0 None)

EPSS: 0.63%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T21:00:31.000Z ##

🔴 CVE-2026-72901 - Critical (9.9)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-privilege member to execute arbitrary commands on the control-plane host because the volumeName field accepted by volumeBackup.cre...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72883
(0 None)

EPSS: 0.40%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T21:00:09.000Z ##

🟠 CVE-2026-72883 - High (8.8)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handlers in apps/dokploy/server/wss/terminal.ts, apps/dokploy/server/wss/docker-container-terminal.ts, apps/dokploy/server/wss/docker-container-logs.ts,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72872
(0 None)

EPSS: 0.37%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T20:00:30.000Z ##

🔴 CVE-2026-72872 - Critical (9.9)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider stores bitbucketOwner and bitbucketRepository without validation and cloneBitbucketRepository in packages/server/src/utils/providers...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72871
(0 None)

EPSS: 0.29%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T20:00:08.000Z ##

🟠 CVE-2026-72871 - High (7.5)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/github/setup route in apps/dokploy/pages/api/providers/github/setup.ts trusts gh_init organizationId and userId values from the sta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47754
(0 None)

EPSS: 0.34%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T17:00:24.000Z ##

🔴 CVE-2026-47754 - Critical (9.3)

Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19.1 and all 1.x versions contain an unauthenticated path traversal in the `archiveEntryName` parameter of the `action=read` endp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5423
(0 None)

EPSS: 0.34%

1 posts

N/A

CVE-2026-60137
(0 None)

EPSS: 73.10%

1 posts

N/A

52 repos

https://github.com/yuag/wp2shell

https://github.com/AdarshThakur14777-cyber/CVE-2026-60137

https://github.com/Icex0/wp2shell-poc

https://github.com/ikow/wp2shell

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/g0d150ne/WP2Shell

https://github.com/mcipekci/wp2shell

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/ananay/wp2shell-lab

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/vulnquest58/PressVector

https://github.com/kulichr/wp2shell

https://github.com/securelayer7/WordPresShell

https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/ebrasha/abdal-cve-2026-60137

https://github.com/47Cid/wp2shell-lab

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

https://github.com/0xWhoknows/wp2shell

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/AkbarWiraN/holy-wp2shell

https://github.com/0xsha/wp2shell

https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/johnlodan/wp2shell-rce

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/Iqbalx7/wp2shell

https://github.com/dinosn/wp2shell-lab

https://github.com/northsia/CVE-2026-60137-With-Skip-SSL

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/h4cd0c/wp2shell

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/bahartanir/wp2shell-scanner

https://github.com/M4xSec/wp2shell-Exploit-Waf-Bypass

https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137

https://github.com/sowarma/wp2shell-PoC

https://github.com/Crypto-Cat/wp2shell

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

https://github.com/0xjessie21/wp2shell-checker

https://github.com/AbdullahMaqbool22/CVE-2026-60137-WordPress-Core-SQL-Injection-PoC

https://github.com/NULL200OK/WP2Shell

https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030

https://github.com/shinthink/CVE-2026-63030

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/ekomsSavior/wp2shell

https://github.com/zi3lak/wp2shell_scanner

https://github.com/michael-kanda/Wp2shell-ioc-scanner

bstnbuck@infosec.exchange at 2026-08-10T12:30:00.000Z ##

A #Wordpress site belonging to an friend (I’m not the admin...) was successfully hacked using #wp2shell (17.07.2026; CVE-2026-63030 + CVE-2026-60137), just 5 days after the first exploit published (20.07.). Another 5 days later, the website was abused for SEO spamming and for hosting phishing…

If you haven't already, update your Wordpress (preferably yesterday…; >=v7.0.2 or >= 6.9.5) and also enable automatic updates for themes and plug-ins!

I found several PHP backdoors/webshells (see @abuse_ch Malware Bazaar and #VirusTotal (hashes below)). Interestingly, not every sample was detected by the #YARA rules from @cyb3rops and github.com/ruppde/yara_rules.

tl;dr #wp2shell is being actively exploited, patch immediately and enable automatic updates.

Hashes:
1093b4045b45a8498d146e31788c25769f992056c8ffc582b5d8c06598598966
05e3884a478d3bc8fd7285dabb74107422f1615d2d7f80df9b8438d4beb663da
bb9136494a546368e7c9b6252c2e1c5af9327c07947908a9ba6fdd78fb4bf4cf
1e7ca9074cc2eca8d366022629f665d9ffaa79e0621bb579bf5aabe681cb07e8
8ebaf3ba0be7b62269aaf333cfaf66c1dea6e8ee495a917691beb550b4bbf0ab
e3fb920aa70c7ad5c67b4d9b8e60954f5e0c1a07c0eba09505816b966f4d1a3c
165e94c87ef17389c8de25ba2a6c31b348e3c916dab89d0dd3708156414f3de5
b55cf5af8b57e9d56c69d00e023e2384c7eb184614c2a2a283062ebeaf4a26c6
a46230a1638b9b341d15a640ead1b885548c1d1e5a149657e8e315540a068be8
7918f29993383e579ef33bd0d8e766fd2ce047dce83bac51efb5fe17578b6cdf
ae9ee9db7c41e04c531298782b908766c769a899aa92df3f64f4a83baa77ad09

##

CVE-2026-63030
(0 None)

EPSS: 95.60%

1 posts

N/A

Nuclei template

81 repos

https://github.com/yuag/wp2shell

https://github.com/g0d150ne/WP2Shell

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/gbrsh/CVE-2026-63030

https://github.com/47Cid/wp2shell-lab

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause

https://github.com/AkbarWiraN/holy-wp2shell

https://github.com/AnggaTechI/CVE-2026-63030

https://github.com/administrator-01001/CVE-2026-63030

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/dinosn/wp2shell-lab

https://github.com/mrx-arafat/CVE-2026-63030-POC

https://github.com/h4cd0c/wp2shell

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t

https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137

https://github.com/sowarma/wp2shell-PoC

https://github.com/CybersecSpirit/CVE-2026-63030

https://github.com/raphy76/wp2shell-poc-fulljs

https://github.com/michael-kanda/Wp2shell-ioc-scanner

https://github.com/Lutfifakee-Project/wp2shell

https://github.com/Icex0/wp2shell-poc

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/c0gnit00/Wp2Shell

https://github.com/x-znn/CVE-2026-63030

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/attackercan/wp2shell-poc2

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/InstaWP/wp2shell-scan

https://github.com/4B3R4M4-607D/CVE-2026-63030-POC

https://github.com/ChiefYoru/CVE-2026-63030_PoC

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/Industri4l-H3ll-Xpl0it3rs/CVE-2026-63030-WP2Shell

https://github.com/rechandra/wp2exp-2026

https://github.com/TomorrowX6/CVE-2026-63030-poc

https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030

https://github.com/NULL200OK/WP2Shell

https://github.com/shinthink/CVE-2026-63030

https://github.com/4minx/CVE-2026-63030

https://github.com/ekomsSavior/wp2shell

https://github.com/ikow/wp2shell

https://github.com/mcipekci/wp2shell

https://github.com/ananay/wp2shell-lab

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/minwunn/wp2shell-CVE-2026-63030

https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner

https://github.com/Procjevt/CVE-2026-63030

https://github.com/mhtsec/CVE-2026-63030

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction

https://github.com/Iqbalx7/wp2shell

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030

https://github.com/zeroc00I/CVE-2026-63030

https://github.com/0xBlackash/CVE-2026-63030

https://github.com/vulnquest58/PressVector

https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030

https://github.com/imXur/WordPress-CVE-2026-63030-Analysis

https://github.com/kulichr/wp2shell

https://github.com/securelayer7/WordPresShell

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/0xWhoknows/wp2shell

https://github.com/0xsha/wp2shell

https://github.com/ebrasha/abdal-cve-2026-63030

https://github.com/johnlodan/wp2shell-rce

https://github.com/fullhunt/wp2shell-scan

https://github.com/mverschu/CVE-2026-63030

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/0xh7ml/CVE-2026-63030

https://github.com/ZenithGenius/wordpress-batch-rce-lab

https://github.com/Ch4120N/CVE-2026-63030

https://github.com/bahartanir/wp2shell-scanner

https://github.com/M4xSec/wp2shell-Exploit-Waf-Bypass

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

https://github.com/Crypto-Cat/wp2shell

https://github.com/0xjessie21/wp2shell-checker

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/zi3lak/wp2shell_scanner

bstnbuck@infosec.exchange at 2026-08-10T12:30:00.000Z ##

A #Wordpress site belonging to an friend (I’m not the admin...) was successfully hacked using #wp2shell (17.07.2026; CVE-2026-63030 + CVE-2026-60137), just 5 days after the first exploit published (20.07.). Another 5 days later, the website was abused for SEO spamming and for hosting phishing…

If you haven't already, update your Wordpress (preferably yesterday…; >=v7.0.2 or >= 6.9.5) and also enable automatic updates for themes and plug-ins!

I found several PHP backdoors/webshells (see @abuse_ch Malware Bazaar and #VirusTotal (hashes below)). Interestingly, not every sample was detected by the #YARA rules from @cyb3rops and github.com/ruppde/yara_rules.

tl;dr #wp2shell is being actively exploited, patch immediately and enable automatic updates.

Hashes:
1093b4045b45a8498d146e31788c25769f992056c8ffc582b5d8c06598598966
05e3884a478d3bc8fd7285dabb74107422f1615d2d7f80df9b8438d4beb663da
bb9136494a546368e7c9b6252c2e1c5af9327c07947908a9ba6fdd78fb4bf4cf
1e7ca9074cc2eca8d366022629f665d9ffaa79e0621bb579bf5aabe681cb07e8
8ebaf3ba0be7b62269aaf333cfaf66c1dea6e8ee495a917691beb550b4bbf0ab
e3fb920aa70c7ad5c67b4d9b8e60954f5e0c1a07c0eba09505816b966f4d1a3c
165e94c87ef17389c8de25ba2a6c31b348e3c916dab89d0dd3708156414f3de5
b55cf5af8b57e9d56c69d00e023e2384c7eb184614c2a2a283062ebeaf4a26c6
a46230a1638b9b341d15a640ead1b885548c1d1e5a149657e8e315540a068be8
7918f29993383e579ef33bd0d8e766fd2ce047dce83bac51efb5fe17578b6cdf
ae9ee9db7c41e04c531298782b908766c769a899aa92df3f64f4a83baa77ad09

##

CVE-2026-48085
(0 None)

EPSS: 0.55%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T03:00:08.000Z ##

🔴 CVE-2026-48085 - Critical (9.8)

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provisioned OpenReception instance accepts unauthenticated POST requests to `/setup/create-admin-account` a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63637
(0 None)

EPSS: 0.24%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T02:00:16.000Z ##

🟠 CVE-2026-63637 - High (8.6)

Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.go passes regexp filter strings into generated DQL without quoting or validating the /pattern/flags form, allowing crafted Grap...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites