##
Updated at UTC 2026-06-29T21:54:48.471913
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-13763 | 9.8 | 0.00% | 4 | 0 | 2026-06-29T21:16:43.300000 | Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer | |
| CVE-2026-13762 | 9.8 | 0.00% | 4 | 0 | 2026-06-29T21:16:43.183000 | Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF | |
| CVE-2026-48558 | 10.0 | 0.72% | 7 | 0 | 2026-06-29T20:17:38.077000 | SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an aut | |
| CVE-2026-22078 | 7.3 | 0.09% | 2 | 0 | 2026-06-29T19:07:03.733000 | Because O+ Connect's IPC service does not authenticate clients, external applica | |
| CVE-2025-2902 | 8.3 | 0.19% | 2 | 0 | 2026-06-29T18:52:40.497000 | Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual S | |
| CVE-2026-13500 | 7.3 | 0.31% | 1 | 0 | 2026-06-29T18:46:31.617000 | A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected is an unkn | |
| CVE-2026-57346 | 7.1 | 0.00% | 2 | 0 | 2026-06-29T18:39:20.080000 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') v | |
| CVE-2026-10083 | 7.5 | 0.16% | 1 | 0 | 2026-06-29T15:33:13 | The APCu Manager WordPress plugin before 4.5.0 does not escape APCu object-cache | |
| CVE-2026-46331 | 7.8 | 0.23% | 5 | 5 | 2026-06-29T15:32:00 | In the Linux kernel, the following vulnerability has been resolved: net/sched: | |
| CVE-2026-32833 | 8.8 | 1.34% | 1 | 0 | 2026-06-29T14:16:49.310000 | Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command i | |
| CVE-2026-13564 | 8.8 | 0.00% | 2 | 0 | 2026-06-29T12:31:51 | A vulnerability was found in Edimax EW-7478APC 1.04. Affected is the function fo | |
| CVE-2026-13553 | 7.3 | 0.00% | 1 | 0 | 2026-06-29T12:31:50 | A flaw has been found in itsourcecode Online Hotel Management System 1.0. Affect | |
| CVE-2026-13601 | 7.1 | 0.00% | 2 | 0 | 2026-06-29T12:31:50 | A flaw was found in Yelp due to an overly permissive Content Security Policy (CS | |
| CVE-2026-13539 | 8.8 | 0.47% | 2 | 0 | 2026-06-29T09:30:32 | A vulnerability was identified in Wavlink WL-NU516U1-A M16U1_V240425. The impact | |
| CVE-2026-13517 | 8.8 | 0.47% | 1 | 0 | 2026-06-29T03:30:58 | A flaw has been found in Tenda JD12L 16.03.53.23. The impacted element is the fu | |
| CVE-2026-13516 | 8.8 | 0.47% | 1 | 0 | 2026-06-29T00:31:46 | A vulnerability was detected in Tenda JD12L 16.03.53.23. The affected element is | |
| CVE-2026-13485 | 7.3 | 0.41% | 1 | 0 | 2026-06-28T12:30:28 | A vulnerability was found in SourceCodester Class and Exam Timetabling System 1. | |
| CVE-2026-55975 | 7.2 | 0.65% | 1 | 0 | 2026-06-27T00:30:34 | A vulnerability exists in H.View IP cameras that could allow an authenticated us | |
| CVE-2026-48769 | 9.9 | 0.00% | 1 | 0 | 2026-06-26T19:13:19 | ### Summary An arbitrary file write exists in the Incus client when a malicious | |
| CVE-2026-43503 | 8.8 | 0.13% | 4 | 8 | 2026-06-26T18:57:17.887000 | In the Linux kernel, the following vulnerability has been resolved: net: skbuff | |
| CVE-2026-48752 | 9.9 | 0.00% | 1 | 0 | 2026-06-26T18:46:32 | ### Summary A specially crafted image or instance backup can be used to read or | |
| CVE-2026-48750 | 9.9 | 0.00% | 1 | 0 | 2026-06-26T18:32:53 | ### Summary The `record-output` parameter of the `/instances/$name/exec` endpoi | |
| CVE-2026-48749 | 9.9 | 0.00% | 1 | 0 | 2026-06-26T18:31:23 | ### Summary A specially crafted image can be used to read or create/write arbit | |
| CVE-2026-20230 | 8.6 | 41.69% | 2 | 3 | 2026-06-25T21:31:23 | A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco U | |
| CVE-2026-12849 | 9.1 | 1.68% | 2 | 0 | 2026-06-25T14:02:35.347000 | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so funct | |
| CVE-2026-9776 | 7.5 | 1.58% | 2 | 0 | 2026-06-25T00:35:20 | ATEN Unizon writeFileToHttpServletResponse Directory Traversal Information Discl | |
| CVE-2026-55200 | 8.1 | 0.92% | 6 | 2 | 2026-06-24T18:33:40 | libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write | |
| CVE-2026-12851 | 9.1 | 1.68% | 2 | 0 | 2026-06-24T06:31:51 | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so funct | |
| CVE-2026-12850 | 9.1 | 1.72% | 2 | 0 | 2026-06-24T06:31:51 | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so funct | |
| CVE-2026-12486 | 9.1 | 1.72% | 2 | 0 | 2026-06-24T06:31:51 | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so funct | |
| CVE-2025-67038 | 9.8 | 1.13% | 1 | 1 | 2026-06-24T05:17:25.670000 | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module exec | |
| CVE-2026-56274 | 9.9 | 2.68% | 2 | 0 | 2026-06-23T15:32:37 | Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in t | |
| CVE-2026-11374 | 9.0 | 1.24% | 2 | 0 | 2026-06-23T09:32:28 | In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and | |
| CVE-2026-32315 | 5.5 | 2.90% | 2 | 0 | 2026-06-22T17:11:37 | # Security Advisory: World-Readable Configuration File Exposes Admin Password Ha | |
| CVE-2026-20127 | 10.0 | 57.79% | 2 | 8 | 2026-06-17T15:06:12.607000 | A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controlle | |
| CVE-2026-46529 | 0 | 0.56% | 2 | 1 | 2026-06-17T13:20:41.280000 | Atril Document Viewer is the default document reader of the MATE desktop environ | |
| CVE-2026-8037 | 9.6 | 1.87% | 2 | 0 | 2026-06-17T11:03:24.930000 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC | |
| CVE-2026-46215 | 7.8 | 0.13% | 2 | 1 | 2026-06-17T10:53:20.720000 | In the Linux kernel, the following vulnerability has been resolved: drm: Set ol | |
| CVE-2026-35273 | 9.8 | 92.33% | 1 | 4 | template | 2026-06-17T10:40:19.560000 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleS |
| CVE-2026-33825 | 7.8 | 6.75% | 2 | 5 | 2026-06-17T10:38:09.690000 | Insufficient granularity of access control in Microsoft Defender allows an autho | |
| CVE-2026-24418 | 6.5 | 0.36% | 2 | 2 | 2026-06-17T10:23:02.487000 | OpenSTAManager is an open source management software for technical assistance an | |
| CVE-2025-60727 | 7.8 | 0.49% | 1 | 0 | 2026-06-17T09:50:03.367000 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to | |
| CVE-2026-54157 | 9.0 | 1.78% | 2 | 0 | template | 2026-06-16T20:15:57 | ## Unauthenticated SSRF in /webapi/proxy allows anyone to proxy requests and inj |
| CVE-2026-20251 | 8.8 | 0.57% | 1 | 1 | 2026-06-10T18:31:53 | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk C | |
| CVE-2026-20245 | 7.8 | 9.92% | 2 | 3 | 2026-06-09T21:32:21 | A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vMa | |
| CVE-2026-46817 | 9.8 | 0.42% | 4 | 0 | 2026-05-29T18:31:20 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (compone | |
| CVE-2026-20182 | 10.0 | 87.69% | 2 | 3 | template | 2026-05-14T18:33:03 | May 2026: This security advisory provides the details and fix information for a |
| CVE-2026-6307 | 8.8 | 0.36% | 2 | 0 | 2026-04-15T21:30:19 | Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a re | |
| CVE-2026-24294 | 7.8 | 2.73% | 2 | 2 | 2026-03-27T21:32:39 | Improper authentication in Windows SMB Server allows an authorized attacker to e | |
| CVE-2026-3102 | 6.3 | 3.41% | 1 | 2 | 2026-02-26T21:32:34 | A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affe | |
| CVE-2026-28496 | 0 | 1.89% | 2 | 1 | template | N/A | |
| CVE-2026-54066 | 0 | 1.89% | 2 | 0 | template | N/A | |
| CVE-2026-50160 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-47220 | 0 | 0.46% | 2 | 0 | N/A | ||
| CVE-2026-47193 | 0 | 0.25% | 1 | 0 | N/A | ||
| CVE-2026-46386 | 0 | 0.27% | 1 | 0 | N/A | ||
| CVE-2026-49991 | 0 | 0.27% | 1 | 0 | N/A | ||
| CVE-2026-48751 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-48755 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-55621 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-55622 | 0 | 0.00% | 1 | 0 | N/A |
updated 2026-06-29T21:16:43.300000
4 posts
CVE-2026-13762/CVE-2026-13763 are not vulnerabilities and shouldn't have been assigned CVEs, fight me
CVE-2026-13762 and CVE-2026-13763 - Issue with HTTP/2 multi-frame request body inspection in AWS WAF
Bulletin ID: 2026-048-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/29/2026 11:15 PM PDT
Description:
AWS WAF is a web application firewall that monitors the HTTP(S) requests that are forwarded...
https://aws.amazon.com/security/security-bulletins/rss/2026-048-aws/
##CVE-2026-13762/CVE-2026-13763 are not vulnerabilities and shouldn't have been assigned CVEs, fight me
CVE-2026-13762 and CVE-2026-13763 - Issue with HTTP/2 multi-frame request body inspection in AWS WAF
Bulletin ID: 2026-048-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/29/2026 11:15 PM PDT
Description:
AWS WAF is a web application firewall that monitors the HTTP(S) requests that are forwarded...
https://aws.amazon.com/security/security-bulletins/rss/2026-048-aws/
##updated 2026-06-29T21:16:43.183000
4 posts
CVE-2026-13762/CVE-2026-13763 are not vulnerabilities and shouldn't have been assigned CVEs, fight me
CVE-2026-13762 and CVE-2026-13763 - Issue with HTTP/2 multi-frame request body inspection in AWS WAF
Bulletin ID: 2026-048-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/29/2026 11:15 PM PDT
Description:
AWS WAF is a web application firewall that monitors the HTTP(S) requests that are forwarded...
https://aws.amazon.com/security/security-bulletins/rss/2026-048-aws/
##CVE-2026-13762/CVE-2026-13763 are not vulnerabilities and shouldn't have been assigned CVEs, fight me
CVE-2026-13762 and CVE-2026-13763 - Issue with HTTP/2 multi-frame request body inspection in AWS WAF
Bulletin ID: 2026-048-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/29/2026 11:15 PM PDT
Description:
AWS WAF is a web application firewall that monitors the HTTP(S) requests that are forwarded...
https://aws.amazon.com/security/security-bulletins/rss/2026-048-aws/
##updated 2026-06-29T20:17:38.077000
7 posts
🚨 [CISA-2026:0629] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0629)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-48558 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48558)
- Name: SimpleHelp Authentication Bypass Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SimpleHelp
- Product: SimpleHelp
- Notes: https://simple-help.com/security/simplehelp-security-update-2026-05 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-48558
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260629 #cisa20260629 #cve_2026_48558 #cve202648558
##CVE ID: CVE-2026-48558
Vendor: SimpleHelp
Product: SimpleHelp
Date Added: 2026-06-29
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48558
Critical SimpleHelp flaw exploited to deploy new stealer malware
Hackers are exploiting a recently disclosed critical vulnerability (CVE-2026-48558) in SimpleHelp to deploy Djinn Stealer, a previously...
🔗️ [Bleepingcomputer] https://link.is.it/O1CzjD
##Hackers Exploit SimpleHelp Flaw to Deploy Djinn Stealer Malware
Hackers have found a way to exploit a flaw in SimpleHelp, using it as a trusted channel to deploy the Djinn Stealer malware and wreak havoc on managed systems. This critical vulnerability, CVE-2026-48558, allows attackers to create highly privileged accounts without authentication, putting thousands of systems at risk.
#Cve202648558 #Simplehelp #Oidc #DjinnStealer #MalwareOperations
##🚨 [CISA-2026:0629] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0629)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-48558 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48558)
- Name: SimpleHelp Authentication Bypass Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SimpleHelp
- Product: SimpleHelp
- Notes: https://simple-help.com/security/simplehelp-security-update-2026-05 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-48558
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260629 #cisa20260629 #cve_2026_48558 #cve202648558
##CVE ID: CVE-2026-48558
Vendor: SimpleHelp
Product: SimpleHelp
Date Added: 2026-06-29
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48558
Critical SimpleHelp flaw exploited to deploy new stealer malware
Hackers are exploiting a recently disclosed critical vulnerability (CVE-2026-48558) in SimpleHelp to deploy Djinn Stealer, a previously...
🔗️ [Bleepingcomputer] https://link.is.it/O1CzjD
##updated 2026-06-29T19:07:03.733000
2 posts
OPPO O+ Connect v16.0.33 is vulnerable (CVE-2026-22078, HIGH). Lack of IPC client authentication lets external apps escalate privileges — potential for sensitive actions. Patch unavailable. Monitor and restrict app permissions. #OffSeq #CVE202622078 #OPPO https://radar.offseq.com/threat/cve-2026-22078-cwe-266-incorrect-privilege-assignm-d3bb9a84f0ae01c1
##OPPO O+ Connect v16.0.33 is vulnerable (CVE-2026-22078, HIGH). Lack of IPC client authentication lets external apps escalate privileges — potential for sensitive actions. Patch unavailable. Monitor and restrict app permissions. #OffSeq #CVE202622078 #OPPO https://radar.offseq.com/threat/cve-2026-22078-cwe-266-incorrect-privilege-assignm-d3bb9a84f0ae01c1
##updated 2026-06-29T18:52:40.497000
2 posts
🟠 CVE-2025-2902 - High (8.3)
Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform.
This issue affects Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H: before DKCMAIN Ver. 93-07-26-xx/00, G...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-2902/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2025-2902 - High (8.3)
Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform.
This issue affects Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H: before DKCMAIN Ver. 93-07-26-xx/00, G...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-2902/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-06-29T18:46:31.617000
1 posts
CVE-2026-13500 - Code Injection in ANTLR4 up to 4.13.2. CVSS 7.3. Remote exploit public, vendor unresponsive. Mitigate immediately. #CVE #infosec #ANTLR
##updated 2026-06-29T18:39:20.080000
2 posts
Epiphyt Embed Privacy ≤1.12.3 is affected by CVE-2026-57346 (HIGH, CVSS 7.1): path traversal via improper pathname checks. Assess your deployments and watch for mitigations. https://radar.offseq.com/threat/cve-2026-57346-cwe-22-improper-limitation-of-a-pat-b3034ca61c60516d #OffSeq #CVE202657346 #Vuln #PathTraversal
##Epiphyt Embed Privacy ≤1.12.3 is affected by CVE-2026-57346 (HIGH, CVSS 7.1): path traversal via improper pathname checks. Assess your deployments and watch for mitigations. https://radar.offseq.com/threat/cve-2026-57346-cwe-22-improper-limitation-of-a-pat-b3034ca61c60516d #OffSeq #CVE202657346 #Vuln #PathTraversal
##updated 2026-06-29T15:33:13
1 posts
Stored XSS (CVE-2026-10083, HIGH) found in APCu Manager <4.5.0 for WordPress. Persistent object caching lets attackers inject JS via crafted cache keys, compromising admin sessions. Disable object caching or update plugin. https://radar.offseq.com/threat/cve-2026-10083-cwe-79-cross-site-scripting-xss-in--afabaed8bda5d811 #OffSeq #XSS #WordPress #Infosec
##updated 2026-06-29T15:32:00
5 posts
5 repos
https://github.com/douglasmun/pagecache-lpe-containment-kit
https://github.com/vulnquest58/dirtyclone-exploit
https://github.com/sgkdev/packet_edit_meme
📢 CVE-2026-46331 ' pedit COW ' : élévation de privilèges root dans le noyau Linux
📝 ## 🔍 Contexte
Source : The Hacker News, publiée le 26 juin 2026.
📖 cyberveille : https://cyberveille.ch/posts/2026-06-29-cve-2026-46331-pedit-cow-elevation-de-privileges-root-dans-le-noyau-linux/
🌐 source : https://thehackernews.com/2026/06/new-linux-pedit-cow-exploit-enables.html
#CVE_2026_46331 #IOC #Cyberveille
There's another #Linux page cache corruption bug making the rounds, assigned CVE-2026-46331. And again, I couldn't find a list of #kernel versions that include the fix. I wonder why? Anyway, here's the list:
7.1.x stable: 7.1
7.0.x stable: 7.0.13
6.18.x lts: 6.18.36
6.12.x lts: 6.12.94
"Sicherheitsforscher sind auf eine neue, pedit COW genannte, Schwachstelle CVE-2026-46331 gestoßen, es erlaubt, Speicherinhalte zu missbrauchen, um normalen Nutzern Root-Rechte zu verschaffen."
https://borncity.com/blog/2026/06/28/pedit-cow-linux-schwachstelle-cve-2026-46331-ermoeglicht-root/
##📢 CVE-2026-46331 ' pedit COW ' : élévation de privilèges root dans le noyau Linux
📝 ## 🔍 Contexte
Source : The Hacker News, publiée le 26 juin 2026.
📖 cyberveille : https://cyberveille.ch/posts/2026-06-29-cve-2026-46331-pedit-cow-elevation-de-privileges-root-dans-le-noyau-linux/
🌐 source : https://thehackernews.com/2026/06/new-linux-pedit-cow-exploit-enables.html
#CVE_2026_46331 #IOC #Cyberveille
There's another #Linux page cache corruption bug making the rounds, assigned CVE-2026-46331. And again, I couldn't find a list of #kernel versions that include the fix. I wonder why? Anyway, here's the list:
7.1.x stable: 7.1
7.0.x stable: 7.0.13
6.18.x lts: 6.18.36
6.12.x lts: 6.12.94
updated 2026-06-29T14:16:49.310000
1 posts
🟠 CVE-2026-32833 - High (8.8)
Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary commands by injecting shell metacharacters into the cbid.system.ntp.current POST parame...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-32833/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-06-29T12:31:51
2 posts
CVE-2026-13564: HIGH (CVSS 8.7) stack-based buffer overflow in Edimax EW-7478APC v1.04. Remote exploit via pppUserName; public PoC, no patch. Disable remote access or segment device. https://radar.offseq.com/threat/cve-2026-13564-stack-based-buffer-overflow-in-edim-026db0243354aebd #OffSeq #Vulnerability #IoTSecurity #CVE202613564
##CVE-2026-13564: HIGH (CVSS 8.7) stack-based buffer overflow in Edimax EW-7478APC v1.04. Remote exploit via pppUserName; public PoC, no patch. Disable remote access or segment device. https://radar.offseq.com/threat/cve-2026-13564-stack-based-buffer-overflow-in-edim-026db0243354aebd #OffSeq #Vulnerability #IoTSecurity #CVE202613564
##updated 2026-06-29T12:31:50
1 posts
CVE-2026-13553 - Unrestricted file upload in itsourcecode Online Hotel Management System 1.0 via controller.php. CVSS 7.3. Exploit published. No patch available. Restrict access or disable uploads immediately. #CVE #infosec #cybersecurity
##updated 2026-06-29T12:31:50
2 posts
CVE-2026-13601 (HIGH, CVSS 7.1) in Red Hat Enterprise Linux 10: Yelp’s help viewer can leak sensitive files via crafted Flatpak apps due to weak Content Security Policy. No patch yet — restrict untrusted Flatpaks. https://radar.offseq.com/threat/cve-2026-13601-protection-mechanism-failure-in-red-844c9044ecdb0d62 #OffSeq #Linux #Vuln #RedHat
##CVE-2026-13601 (HIGH, CVSS 7.1) in Red Hat Enterprise Linux 10: Yelp’s help viewer can leak sensitive files via crafted Flatpak apps due to weak Content Security Policy. No patch yet — restrict untrusted Flatpaks. https://radar.offseq.com/threat/cve-2026-13601-protection-mechanism-failure-in-red-844c9044ecdb0d62 #OffSeq #Linux #Vuln #RedHat
##updated 2026-06-29T09:30:32
2 posts
🟠 CVE-2026-13539 - High (8.8)
A vulnerability was identified in Wavlink WL-NU516U1-A M16U1_V240425. The impacted element is the function sub_407504 of the file /cgi-bin/wireless.cgi of the component POST Parameter Handler. Such manipulation of the argument Guest_ssid leads to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-13539/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-13539 - High (8.8)
A vulnerability was identified in Wavlink WL-NU516U1-A M16U1_V240425. The impacted element is the function sub_407504 of the file /cgi-bin/wireless.cgi of the component POST Parameter Handler. Such manipulation of the argument Guest_ssid leads to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-13539/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-06-29T03:30:58
1 posts
CVE-2026-13517: HIGH severity stack buffer overflow in Tenda JD12L (16.03.53.23). Exploitable remotely via security_5g argument in formWifiBasicSet. No patch yet — restrict access & monitor for threats. https://radar.offseq.com/threat/cve-2026-13517-stack-based-buffer-overflow-in-tend-004391078b4ed241 #OffSeq #Vulnerability #Infosec #RouterSecurity
##updated 2026-06-29T00:31:46
1 posts
Tenda JD12L routers (fw 16.03.53.23) face HIGH severity stack-based buffer overflow (CVE-2026-13516, CVSS 8.7). Remote code execution possible — exploit code is public. Restrict remote access, monitor endpoints. https://radar.offseq.com/threat/cve-2026-13516-stack-based-buffer-overflow-in-tend-c61568839c0ead88 #OffSeq #infosec #IoTSecurity #CVE
##updated 2026-06-28T12:30:28
1 posts
CVE-2026-13485 - SQLi in SourceCodester Class & Exam Timetabling System 1.0. Unpatched, exploit public. CVSS 7.3. Update or mitigate immediately. #CVE #infosec #cybersecurity
##updated 2026-06-27T00:30:34
1 posts
CVE-2026-55975 - Command Injection in H.View IP cameras. Authenticated users can exploit unsanitized XML fields for elevated command execution. CVSS 7.2. No patch available. Isolate affected devices immediately. #CVE #infosec #HView
##updated 2026-06-26T19:13:19
1 posts
The Incus team is pleased to announce the release of Incus 7.2!
It’s another pretty busy release for us with a varied set of new features across the board as well as the usual set of performance improvements and bugfixes.
[🖼 stgraber.org/wp-content/upload…]This fixes the following security issues:
rootfs/ symlink in malicious imageexec-output symlink in crafted imagetemplates/ symlink in malicious imageOn the feature front, the highlights for this release are:
The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:
https://www.youtube.com/watch?v=rcldqF6SpXA
You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/
And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus
Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.
Enjoy!
##updated 2026-06-26T18:57:17.887000
4 posts
8 repos
https://github.com/douglasmun/pagecache-lpe-containment-kit
https://github.com/gl1tch0x1/DirtyClone
https://github.com/aexdyhaxor/CVE-2026-43503-DirtyClone
https://github.com/SecureWithUmer/CVE-2026-43503
https://github.com/sec0x/CVE-2026-43503
https://github.com/mooder1/dirtyclone-CVE-2026-43503
‼️ CVE-2026-43503: Python PoC for DirtyClone, a Linux kernel LPE via page-cache corruption exploit
##📢 DirtyClone (CVE-2026-43503) : LPE Linux via corruption du page cache par IPsec
📝 ## 🔍 Contexte
Publié le 25 juin 2026 par les chercheurs Eddy Tsalolikhin et Or Peles de JFrog Security...
📖 cyberveille : https://cyberveille.ch/posts/2026-06-29-dirtyclone-cve-2026-43503-lpe-linux-via-corruption-du-page-cache-par-ipsec/
🌐 source : https://research.jfrog.com/post/dissecting-and-exploiting-linux-lpe-variant-dirtyclone-cve-2026-43503/
#CVE_2026_43284 #CVE_2026_43500 #Cyberveille
ANOTHER #Linux LPE: CVE-2026-43503
If only Linus wasn't so obsessed with calling #OpenBSD developers "masturbating monkeys" 18 years ago and actually took security seriously. 🤔
https://www.cnet.com/tech/tech-industry/torvalds-attacks-it-industry-security-circus-1/
##‼️ CVE-2026-43503: Python PoC for DirtyClone, a Linux kernel LPE via page-cache corruption exploit
##updated 2026-06-26T18:46:32
1 posts
The Incus team is pleased to announce the release of Incus 7.2!
It’s another pretty busy release for us with a varied set of new features across the board as well as the usual set of performance improvements and bugfixes.
[🖼 stgraber.org/wp-content/upload…]This fixes the following security issues:
rootfs/ symlink in malicious imageexec-output symlink in crafted imagetemplates/ symlink in malicious imageOn the feature front, the highlights for this release are:
The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:
https://www.youtube.com/watch?v=rcldqF6SpXA
You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/
And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus
Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.
Enjoy!
##updated 2026-06-26T18:32:53
1 posts
The Incus team is pleased to announce the release of Incus 7.2!
It’s another pretty busy release for us with a varied set of new features across the board as well as the usual set of performance improvements and bugfixes.
[🖼 stgraber.org/wp-content/upload…]This fixes the following security issues:
rootfs/ symlink in malicious imageexec-output symlink in crafted imagetemplates/ symlink in malicious imageOn the feature front, the highlights for this release are:
The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:
https://www.youtube.com/watch?v=rcldqF6SpXA
You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/
And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus
Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.
Enjoy!
##updated 2026-06-26T18:31:23
1 posts
The Incus team is pleased to announce the release of Incus 7.2!
It’s another pretty busy release for us with a varied set of new features across the board as well as the usual set of performance improvements and bugfixes.
[🖼 stgraber.org/wp-content/upload…]This fixes the following security issues:
rootfs/ symlink in malicious imageexec-output symlink in crafted imagetemplates/ symlink in malicious imageOn the feature front, the highlights for this release are:
The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:
https://www.youtube.com/watch?v=rcldqF6SpXA
You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/
And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus
Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.
Enjoy!
##updated 2026-06-25T21:31:23
2 posts
3 repos
https://github.com/HalilDeniz/CVE-2026-20230-Scanner
📰 Attackers Actively Exploit Critical Cisco Unified CM Flaw to Deploy Webshells
⚠️ ACTIVE EXPLOITATION: A critical SSRF flaw in Cisco Unified CM (CVE-2026-20230) is being used to drop webshells. Attackers are scanning from Tor. Disable the WebDialer service or patch immediately! #Cisco #CyberAttack #Infosec #SSRF
🌐 cyber[.]netsecops[.]io
##📰 Attackers Actively Exploit Critical Cisco Unified CM Flaw to Deploy Webshells
⚠️ ACTIVE EXPLOITATION: A critical SSRF flaw in Cisco Unified CM (CVE-2026-20230) is being used to drop webshells. Attackers are scanning from Tor. Disable the WebDialer service or patch immediately! #Cisco #CyberAttack #Infosec #SSRF
🌐 cyber[.]netsecops[.]io
##updated 2026-06-25T14:02:35.347000
2 posts
📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418
Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93
CISA KEVs:
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31
Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12
Top EPSS Score:
- CVE-2026-32315 - 2.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-32315)
- CVE-2026-56274 - 2.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56274)
- CVE-2026-28496 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-28496)
- CVE-2026-54066 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54066)
- CVE-2026-54157 - 1.78 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54157)
- CVE-2026-12486 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12486)
- CVE-2026-12850 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12850)
- CVE-2026-12849 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12849)
- CVE-2026-12851 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12851)
- CVE-2026-9776 - 1.58 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9776)
📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418
Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93
CISA KEVs:
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31
Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12
Top EPSS Score:
- CVE-2026-32315 - 2.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-32315)
- CVE-2026-56274 - 2.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56274)
- CVE-2026-28496 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-28496)
- CVE-2026-54066 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54066)
- CVE-2026-54157 - 1.78 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54157)
- CVE-2026-12486 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12486)
- CVE-2026-12850 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12850)
- CVE-2026-12849 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12849)
- CVE-2026-12851 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12851)
- CVE-2026-9776 - 1.58 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9776)
updated 2026-06-25T00:35:20
2 posts
📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418
Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93
CISA KEVs:
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31
Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12
Top EPSS Score:
- CVE-2026-32315 - 2.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-32315)
- CVE-2026-56274 - 2.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56274)
- CVE-2026-28496 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-28496)
- CVE-2026-54066 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54066)
- CVE-2026-54157 - 1.78 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54157)
- CVE-2026-12486 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12486)
- CVE-2026-12850 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12850)
- CVE-2026-12849 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12849)
- CVE-2026-12851 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12851)
- CVE-2026-9776 - 1.58 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9776)
📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418
Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93
CISA KEVs:
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31
Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12
Top EPSS Score:
- CVE-2026-32315 - 2.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-32315)
- CVE-2026-56274 - 2.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56274)
- CVE-2026-28496 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-28496)
- CVE-2026-54066 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54066)
- CVE-2026-54157 - 1.78 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54157)
- CVE-2026-12486 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12486)
- CVE-2026-12850 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12850)
- CVE-2026-12849 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12849)
- CVE-2026-12851 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12851)
- CVE-2026-9776 - 1.58 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9776)
updated 2026-06-24T18:33:40
6 posts
2 repos
Critical libssh2 vulnerability with a proof-of-concept exploit already published. curl, PHP and libgit2 are also affected.
https://nvd.nist.gov/vuln/detail/CVE-2026-55200
#ssh #Vulnerability #ITSecurity #curl
CVE-2026-55200: Öffentlicher Exploit-Code für libssh2-Schwachstelle veröffentlicht
##THE POSTHOLE
Monday, 29 June 2026 · Overnight Edition · Vol. 1 No. 201
MJD 61220.38
LEAD — HEALTH
Florida Hospitals Act Fast To Discharge Gun Victims — Especially if They’re Not Insured
-- KFF Health News
Uninsured patients made up about 1 in 4 of the more than 20,000 gunshot wound inpatient hospitalizations in Florida from 2018 to 2024, an analysis of state data by KFF Health News and The Trace found. They also had shorter hospital stays than those with any...
HEALTH
▸ She Struggled To Get a Lifesaving Drug Even After Insurers Vowed To Help
-- KFF Health News
Margaret Hvatum ended up in the hospital after her insurer denied coverage of a medicine she relies on to boost her immune...
INTERNATIONAL
▸ À gauche, les partis tentent d’étouffer en interne l’appel d’air insoumis
-- Mediapart
Craignant une hémorragie militante et des annonces en série d’un soutien à la candidature de Jean-Luc Mélenchon à la...
▸ Les saisonniers exposés aux pesticides, grands absents du débat public
-- Mediapart
▸ «Il y a eu comme une bascule»: en Île-de-France, les funérariums débordés par la canicule
-- Mediapart
NATIONAL
▸ Trump’s Sons Stand To Profit From The Critical Minerals Arms Race
-- Mother Jones
Donald Trump’s network of family businesses—and network of US government deals with those businesses—is mind-bogglingly wide. A...
▸ Trump’s Next ICE Pick: A Trooper Poised to Turn Local Cops Into Deportation Agents
-- Mother Jones
CULTURE & SPORT
▸ Dublin Pulls Off Comeback To Beat Galway In All-Ireland Quarterfinal
-- Defector
Dublin closed out a thrilling All-Ireland football quarterfinal weekend with a massive and penalty-aided comeback to beat Galway...
▸ Boots Ennis KO’s Zayas In Brooklyn Thriller
-- Defector
SECURITY
▸ Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw
-- The Hacker News
A public proof-of-concept is now out for CVE-2026-55200, a critical flaw in libssh2 that lets a malicious or compromised SSH...
#infosec #cybersecurity #posthole
IN BRIEF
• AI Tools Accelerates Coding, but Not Overall Software Delivery, GitLab Research Finds -- InfoQ
• Swift 6.4 Brings New Language Features and Swift Testing/XCTest Interop -- InfoQ
• AWS Previews FinOps Agent for Cost Analysis and Optimization -- InfoQ
• AWS Introduces Workload Credentials Provider for Automated Certificate and Secret... -- InfoQ
• Vercel Introduces Eve, an Open-Source Framework for Building AI Agents -- InfoQ
SECTIONS
Gaming Greatness: Marvel Tōkon: Fighting Souls Reveals Last 3 Playable Characters... #gaming
Tech Talk: [US Grid Constr...
libssh2 Flaw Exposes Clients to Code Execution Risk
A critical flaw in libssh2, known as CVE-2026-55200, can be exploited by a malicious SSH server to trigger memory corruption on a connecting client, with no credentials or user interaction required. This vulnerability can be easily triggered with a public proof-of-concept now available.
#Libssh2 #CodeExecution #Cve202655200 #Ssh #MemoryCorruption
##Critical libssh2 Memory Corruption Flaw Exposes Millions of SSH Clients to Potential Remote Code Execution + Video
Critical libssh2 Memory Corruption Flaw Exposes Millions of SSH Clients to Potential Remote Code Execution Introduction A newly disclosed vulnerability in libssh2 has sent a fresh warning across the cybersecurity industry, exposing a fundamental weakness inside one of the world's most widely embedded SSH client libraries. Tracked as CVE-2026-55200, the…
##Critical libssh2 vulnerability with a proof-of-concept exploit already published. curl, PHP and libgit2 are also affected.
https://nvd.nist.gov/vuln/detail/CVE-2026-55200
#ssh #Vulnerability #ITSecurity #curl
updated 2026-06-24T06:31:51
2 posts
📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418
Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93
CISA KEVs:
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31
Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12
Top EPSS Score:
- CVE-2026-32315 - 2.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-32315)
- CVE-2026-56274 - 2.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56274)
- CVE-2026-28496 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-28496)
- CVE-2026-54066 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54066)
- CVE-2026-54157 - 1.78 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54157)
- CVE-2026-12486 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12486)
- CVE-2026-12850 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12850)
- CVE-2026-12849 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12849)
- CVE-2026-12851 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12851)
- CVE-2026-9776 - 1.58 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9776)
📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418
Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93
CISA KEVs:
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31
Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12
Top EPSS Score:
- CVE-2026-32315 - 2.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-32315)
- CVE-2026-56274 - 2.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56274)
- CVE-2026-28496 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-28496)
- CVE-2026-54066 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54066)
- CVE-2026-54157 - 1.78 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54157)
- CVE-2026-12486 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12486)
- CVE-2026-12850 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12850)
- CVE-2026-12849 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12849)
- CVE-2026-12851 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12851)
- CVE-2026-9776 - 1.58 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9776)
updated 2026-06-24T06:31:51
2 posts
📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418
Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93
CISA KEVs:
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31
Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12
Top EPSS Score:
- CVE-2026-32315 - 2.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-32315)
- CVE-2026-56274 - 2.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56274)
- CVE-2026-28496 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-28496)
- CVE-2026-54066 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54066)
- CVE-2026-54157 - 1.78 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54157)
- CVE-2026-12486 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12486)
- CVE-2026-12850 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12850)
- CVE-2026-12849 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12849)
- CVE-2026-12851 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12851)
- CVE-2026-9776 - 1.58 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9776)
📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418
Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93
CISA KEVs:
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31
Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12
Top EPSS Score:
- CVE-2026-32315 - 2.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-32315)
- CVE-2026-56274 - 2.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56274)
- CVE-2026-28496 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-28496)
- CVE-2026-54066 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54066)
- CVE-2026-54157 - 1.78 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54157)
- CVE-2026-12486 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12486)
- CVE-2026-12850 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12850)
- CVE-2026-12849 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12849)
- CVE-2026-12851 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12851)
- CVE-2026-9776 - 1.58 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9776)
updated 2026-06-24T06:31:51
2 posts
📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418
Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93
CISA KEVs:
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31
Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12
Top EPSS Score:
- CVE-2026-32315 - 2.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-32315)
- CVE-2026-56274 - 2.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56274)
- CVE-2026-28496 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-28496)
- CVE-2026-54066 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54066)
- CVE-2026-54157 - 1.78 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54157)
- CVE-2026-12486 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12486)
- CVE-2026-12850 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12850)
- CVE-2026-12849 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12849)
- CVE-2026-12851 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12851)
- CVE-2026-9776 - 1.58 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9776)
📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418
Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93
CISA KEVs:
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31
Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12
Top EPSS Score:
- CVE-2026-32315 - 2.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-32315)
- CVE-2026-56274 - 2.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56274)
- CVE-2026-28496 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-28496)
- CVE-2026-54066 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54066)
- CVE-2026-54157 - 1.78 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54157)
- CVE-2026-12486 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12486)
- CVE-2026-12850 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12850)
- CVE-2026-12849 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12849)
- CVE-2026-12851 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12851)
- CVE-2026-9776 - 1.58 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9776)
updated 2026-06-24T05:17:25.670000
1 posts
1 repos
#Lantronix released new a bunch of new firmware, fixing both CVE-2025-67038 and the second actively exploited vulnerability without #CVE identifier.
I did not check all the firmware uploads nor do I have devices to actually test the fixed code, but from the looks of it this should all be good.
You can follow the discussion on #ifin : https://discourse.ifin.network/t/lantronix-openwrt-luci-attacks/625/5
##updated 2026-06-23T15:32:37
2 posts
📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418
Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93
CISA KEVs:
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31
Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12
Top EPSS Score:
- CVE-2026-32315 - 2.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-32315)
- CVE-2026-56274 - 2.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56274)
- CVE-2026-28496 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-28496)
- CVE-2026-54066 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54066)
- CVE-2026-54157 - 1.78 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54157)
- CVE-2026-12486 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12486)
- CVE-2026-12850 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12850)
- CVE-2026-12849 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12849)
- CVE-2026-12851 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12851)
- CVE-2026-9776 - 1.58 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9776)
📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418
Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93
CISA KEVs:
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31
Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12
Top EPSS Score:
- CVE-2026-32315 - 2.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-32315)
- CVE-2026-56274 - 2.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56274)
- CVE-2026-28496 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-28496)
- CVE-2026-54066 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54066)
- CVE-2026-54157 - 1.78 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54157)
- CVE-2026-12486 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12486)
- CVE-2026-12850 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12850)
- CVE-2026-12849 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12849)
- CVE-2026-12851 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12851)
- CVE-2026-9776 - 1.58 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9776)
updated 2026-06-23T09:32:28
2 posts
CVE-2026-11374: Account takeover vulnerability in ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus
#CVE_2026_11374 #ManageEngine
https://www.manageengine.com/products/self-service-password/advisory/CVE-2026-11374.html
CVE-2026-11374: Account takeover vulnerability in ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus
#CVE_2026_11374 #ManageEngine
https://www.manageengine.com/products/self-service-password/advisory/CVE-2026-11374.html
updated 2026-06-22T17:11:37
2 posts
📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418
Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93
CISA KEVs:
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31
Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12
Top EPSS Score:
- CVE-2026-32315 - 2.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-32315)
- CVE-2026-56274 - 2.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56274)
- CVE-2026-28496 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-28496)
- CVE-2026-54066 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54066)
- CVE-2026-54157 - 1.78 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54157)
- CVE-2026-12486 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12486)
- CVE-2026-12850 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12850)
- CVE-2026-12849 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12849)
- CVE-2026-12851 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12851)
- CVE-2026-9776 - 1.58 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9776)
📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418
Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93
CISA KEVs:
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31
Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12
Top EPSS Score:
- CVE-2026-32315 - 2.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-32315)
- CVE-2026-56274 - 2.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56274)
- CVE-2026-28496 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-28496)
- CVE-2026-54066 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54066)
- CVE-2026-54157 - 1.78 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54157)
- CVE-2026-12486 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12486)
- CVE-2026-12850 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12850)
- CVE-2026-12849 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12849)
- CVE-2026-12851 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12851)
- CVE-2026-9776 - 1.58 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9776)
updated 2026-06-17T15:06:12.607000
2 posts
8 repos
https://github.com/BugFor-Pings/CVE-2026-20127_EXP
https://github.com/0xBlackash/CVE-2026-20127
https://github.com/randeepajayasekara/CVE-2026-20127
https://github.com/gigachadusers/cve-2026-20127
https://github.com/yonathanpy/CVE-2026-20127-Cisco-SD-WAN-Preauth-RCE
https://github.com/abrahamsurf/sdwan-scanner-CVE-2026-20127
https://github.com/sfewer-r7/CVE-2026-20127
https://github.com/zerozenxlabs/CVE-2026-20127---Cisco-SD-WAN-Preauth-RCE
Exploitation started in March. Cisco disclosed in June. Patch landed June 10.
For roughly 2 months, whoever had working knowledge of CVE-2026-20245 used it _freely_. Defenders had no advisory, no patch, no signal.
Matei Badanoiu, our lead security researcher, put it plainly in Infosecurity Magazine:
""Whoever used this vulnerability had working knowledge of it in this period while defenders had none.""
🏴☠️ The exploitation path is specific: an attacker already holding netadmin privileges on Cisco Catalyst SD-WAN Manager could escalate to root via a crafted CSV upload through the request tenant-upload CLI command.
That prerequisite sounds like a meaningful bar - and it is - until you factor in that CVE-2026-20182 & CVE-2026-20127 (also recently disclosed Cisco flaws) may lower it *considerably*.
From root on the SD-WAN Manager control plane, an attacker can manipulate routing, alter policy enforcement, and reduce network visibility. The architectural placement is what makes root here different from root on a workstation.
The Mandiant (part of Google Cloud) report confirms what experienced practitioners already treat as a working assumption: for high-impact vulnerabilities, in-the-wild exploitation tends to run well ahead of any public disclosure.
If you're running Cisco Catalyst SD-WAN Manager: patch against Cisco's advisory, retain audit logs before upgrading, and review them for anomalous activity from netadmin-level accounts.
📍Read the full article by Kevin Poireault: https://www.infosecurity-magazine.com/news/cisco-vulnerability-exploited/
##Exploitation started in March. Cisco disclosed in June. Patch landed June 10.
For roughly 2 months, whoever had working knowledge of CVE-2026-20245 used it _freely_. Defenders had no advisory, no patch, no signal.
Matei Badanoiu, our lead security researcher, put it plainly in Infosecurity Magazine:
""Whoever used this vulnerability had working knowledge of it in this period while defenders had none.""
🏴☠️ The exploitation path is specific: an attacker already holding netadmin privileges on Cisco Catalyst SD-WAN Manager could escalate to root via a crafted CSV upload through the request tenant-upload CLI command.
That prerequisite sounds like a meaningful bar - and it is - until you factor in that CVE-2026-20182 & CVE-2026-20127 (also recently disclosed Cisco flaws) may lower it *considerably*.
From root on the SD-WAN Manager control plane, an attacker can manipulate routing, alter policy enforcement, and reduce network visibility. The architectural placement is what makes root here different from root on a workstation.
The Mandiant (part of Google Cloud) report confirms what experienced practitioners already treat as a working assumption: for high-impact vulnerabilities, in-the-wild exploitation tends to run well ahead of any public disclosure.
If you're running Cisco Catalyst SD-WAN Manager: patch against Cisco's advisory, retain audit logs before upgrading, and review them for anomalous activity from netadmin-level accounts.
📍Read the full article by Kevin Poireault: https://www.infosecurity-magazine.com/news/cisco-vulnerability-exploited/
##updated 2026-06-17T13:20:41.280000
2 posts
1 repos
Michael Catanzaro: Single-Click Code Execution Exploit for Evince, Atril, and Xreader
“CVE-2026-46529 is an argument injection vulnerability in Evince, Atril, and Xreader caused by missing shell quoting when composing a command line. The reporter, João Medeiros, has published a GitHub repo for the CVE and a blog post with the story of how he discovered the flaw and developed the exploit. (…)”
#RSSBridge via Planet GNOME
##Michael Catanzaro: Single-Click Code Execution Exploit for Evince, Atril, and Xreader
“CVE-2026-46529 is an argument injection vulnerability in Evince, Atril, and Xreader caused by missing shell quoting when composing a command line. The reporter, João Medeiros, has published a GitHub repo for the CVE and a blog post with the story of how he discovered the flaw and developed the exploit. (…)”
#RSSBridge via Planet GNOME
##updated 2026-06-17T11:03:24.930000
2 posts
Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037) - watchTowr Labs https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/
##Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037) - watchTowr Labs https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/
##updated 2026-06-17T10:53:20.720000
2 posts
1 repos
Unprivileged root via a use-after-free in DRM GEM change_handle (CVE-2026-46215) https://lobste.rs/s/hh5yyq #linux #security
https://cyberstan.co.uk/drm-lpe-linux/
Unprivileged root via a use-after-free in DRM GEM change_handle (CVE-2026-46215) https://lobste.rs/s/hh5yyq #linux #security
https://cyberstan.co.uk/drm-lpe-linux/
updated 2026-06-17T10:40:19.560000
1 posts
4 repos
https://github.com/ekomsSavior/POC_cve_2026_35273
https://github.com/0xBlackash/CVE-2026-35273
ShinyHunters Breach Exposes NAIC's Public Data
The National Association of Insurance Commissioners (NAIC) revealed that a breach exposed its public data after an unauthorized third party exploited a PeopleSoft vulnerability, identified as CVE-2026-35273, tied to the notorious ShinyHunters extortion group. This security issue allowed attackers to gain access to a portion of NAIC's IT systems, compromising…
##updated 2026-06-17T10:38:09.690000
2 posts
5 repos
https://github.com/Letlaka/redsun-bluehammer-undefend-detection-pack
https://github.com/0xBlackash/CVE-2026-33825
https://github.com/kaleth4/CVE-2026-33825
CVE-2026-33825 - Changed to Known Ransomware Status
Microsoft Defender Insufficient Granularity of Access Control VulnerabilityVendor: MicrosoftProduct: DefenderMicrosoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: June 29, 2026 at 20:00:35 UTCDate Added https://nvd.nist.gov/vuln/detail/CVE-2026-33825
##CVE-2026-33825 - Changed to Known Ransomware Status
Microsoft Defender Insufficient Granularity of Access Control VulnerabilityVendor: MicrosoftProduct: DefenderMicrosoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: June 29, 2026 at 20:00:35 UTCDate Added https://nvd.nist.gov/vuln/detail/CVE-2026-33825
##updated 2026-06-17T10:23:02.487000
2 posts
2 repos
‼️ CVE-2026-24418: OpenSTAManager v2.9.8 and earlier contain a critical Error-Based SQL Injection vulnerability in the bulk operations handler for the Scadenzario (Payment Schedule) module.
##‼️ CVE-2026-24418: OpenSTAManager v2.9.8 and earlier contain a critical Error-Based SQL Injection vulnerability in the bulk operations handler for the Scadenzario (Payment Schedule) module.
##updated 2026-06-17T09:50:03.367000
1 posts
Microsoft Patches Critical Excel Flaw That Could Let Attackers Take Over PCs Through Malicious Spreadsheets + Video
Microsoft has moved quickly to address a dangerous security vulnerability in Microsoft Excel that could allow cybercriminals to execute malicious code simply by convincing a victim to open a specially crafted spreadsheet. Tracked as CVE-2025-60727, the flaw affects multiple generations of Microsoft Office products and has been rated as a high-severity…
##updated 2026-06-16T20:15:57
2 posts
📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418
Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93
CISA KEVs:
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31
Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12
Top EPSS Score:
- CVE-2026-32315 - 2.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-32315)
- CVE-2026-56274 - 2.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56274)
- CVE-2026-28496 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-28496)
- CVE-2026-54066 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54066)
- CVE-2026-54157 - 1.78 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54157)
- CVE-2026-12486 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12486)
- CVE-2026-12850 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12850)
- CVE-2026-12849 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12849)
- CVE-2026-12851 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12851)
- CVE-2026-9776 - 1.58 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9776)
📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418
Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93
CISA KEVs:
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31
Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12
Top EPSS Score:
- CVE-2026-32315 - 2.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-32315)
- CVE-2026-56274 - 2.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56274)
- CVE-2026-28496 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-28496)
- CVE-2026-54066 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54066)
- CVE-2026-54157 - 1.78 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54157)
- CVE-2026-12486 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12486)
- CVE-2026-12850 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12850)
- CVE-2026-12849 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12849)
- CVE-2026-12851 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12851)
- CVE-2026-9776 - 1.58 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9776)
updated 2026-06-10T18:31:53
1 posts
1 repos
📢 CVE-2026-20251 : RCE via désérialisation jsonpickle dans Splunk Secure Gateway (CVSS 8.8)
📝 ## 🔍 Contexte
Publié le 29 juin 2026 sur GitHub par le chercheur **Fady Oueslati** (ReactiveZero Security Research), ce dépôt documente...
📖 cyberveille : https://cyberveille.ch/posts/2026-06-29-cve-2026-20251-rce-via-deserialisation-jsonpickle-dans-splunk-secure-gateway-cvss-8-8/
🌐 source : https://github.com/reactivezero/CVE-2026-20251
#CVE_2026_20251 #CVE_2026_20253 #Cyberveille
updated 2026-06-09T21:32:21
2 posts
3 repos
https://github.com/0xBlackash/CVE-2026-20245
https://github.com/HORKimhab/CVE-2026-20245
https://github.com/fevar54/CVE-2026-20245---Cisco-SD-WAN-Privilege-Escalation-Exploit
Exploitation started in March. Cisco disclosed in June. Patch landed June 10.
For roughly 2 months, whoever had working knowledge of CVE-2026-20245 used it _freely_. Defenders had no advisory, no patch, no signal.
Matei Badanoiu, our lead security researcher, put it plainly in Infosecurity Magazine:
""Whoever used this vulnerability had working knowledge of it in this period while defenders had none.""
🏴☠️ The exploitation path is specific: an attacker already holding netadmin privileges on Cisco Catalyst SD-WAN Manager could escalate to root via a crafted CSV upload through the request tenant-upload CLI command.
That prerequisite sounds like a meaningful bar - and it is - until you factor in that CVE-2026-20182 & CVE-2026-20127 (also recently disclosed Cisco flaws) may lower it *considerably*.
From root on the SD-WAN Manager control plane, an attacker can manipulate routing, alter policy enforcement, and reduce network visibility. The architectural placement is what makes root here different from root on a workstation.
The Mandiant (part of Google Cloud) report confirms what experienced practitioners already treat as a working assumption: for high-impact vulnerabilities, in-the-wild exploitation tends to run well ahead of any public disclosure.
If you're running Cisco Catalyst SD-WAN Manager: patch against Cisco's advisory, retain audit logs before upgrading, and review them for anomalous activity from netadmin-level accounts.
📍Read the full article by Kevin Poireault: https://www.infosecurity-magazine.com/news/cisco-vulnerability-exploited/
##Exploitation started in March. Cisco disclosed in June. Patch landed June 10.
For roughly 2 months, whoever had working knowledge of CVE-2026-20245 used it _freely_. Defenders had no advisory, no patch, no signal.
Matei Badanoiu, our lead security researcher, put it plainly in Infosecurity Magazine:
""Whoever used this vulnerability had working knowledge of it in this period while defenders had none.""
🏴☠️ The exploitation path is specific: an attacker already holding netadmin privileges on Cisco Catalyst SD-WAN Manager could escalate to root via a crafted CSV upload through the request tenant-upload CLI command.
That prerequisite sounds like a meaningful bar - and it is - until you factor in that CVE-2026-20182 & CVE-2026-20127 (also recently disclosed Cisco flaws) may lower it *considerably*.
From root on the SD-WAN Manager control plane, an attacker can manipulate routing, alter policy enforcement, and reduce network visibility. The architectural placement is what makes root here different from root on a workstation.
The Mandiant (part of Google Cloud) report confirms what experienced practitioners already treat as a working assumption: for high-impact vulnerabilities, in-the-wild exploitation tends to run well ahead of any public disclosure.
If you're running Cisco Catalyst SD-WAN Manager: patch against Cisco's advisory, retain audit logs before upgrading, and review them for anomalous activity from netadmin-level accounts.
📍Read the full article by Kevin Poireault: https://www.infosecurity-magazine.com/news/cisco-vulnerability-exploited/
##updated 2026-05-29T18:31:20
4 posts
Critical Oracle E-Business Suite Vulnerability Under Active Attack: Organizations Face Immediate Risk as Hackers Exploit CVE-2026-46817 + Video
Critical Oracle E-Business Suite Vulnerability Under Active Attack: Organizations Face Immediate Risk as Hackers Exploit CVE-2026-46817 Introduction: A Patch Released Too Late for Many Organizations The cybersecurity landscape has once again highlighted a familiar and costly lesson: releasing security patches is only half the…
##Hackers now exploit critical Oracle E-Business flaw in attacks
Attackers have begun exploiting a critical vulnerability (CVE-2026-46817) in the Oracle E-Business Suite (EBS) financial application, according to...
🔗️ [Bleepingcomputer] https://link.is.it/6jsPkq
##Hackers Exploit Oracle E-Business Flaw in Targeted Attacks
Hackers are actively exploiting a critical Oracle E-Business flaw, CVE-2026-46817, with a near-perfect CVSS score of 9.8, in targeted attacks, allowing for unauthenticated HTTP takeover. This alarming vulnerability has no known previous exploitation and no public proof-of-concept code exists, making it a high-risk threat.
#Cve202646817 #OracleEbusinessSuite #EmergingThreats #SupplyChain #ZeroDay
##Hackers now exploit critical Oracle E-Business flaw in attacks
Attackers have begun exploiting a critical vulnerability (CVE-2026-46817) in the Oracle E-Business Suite (EBS) financial application, according to...
🔗️ [Bleepingcomputer] https://link.is.it/6jsPkq
##updated 2026-05-14T18:33:03
2 posts
3 repos
https://github.com/Nxploited/CVE-2026-20182
Exploitation started in March. Cisco disclosed in June. Patch landed June 10.
For roughly 2 months, whoever had working knowledge of CVE-2026-20245 used it _freely_. Defenders had no advisory, no patch, no signal.
Matei Badanoiu, our lead security researcher, put it plainly in Infosecurity Magazine:
""Whoever used this vulnerability had working knowledge of it in this period while defenders had none.""
🏴☠️ The exploitation path is specific: an attacker already holding netadmin privileges on Cisco Catalyst SD-WAN Manager could escalate to root via a crafted CSV upload through the request tenant-upload CLI command.
That prerequisite sounds like a meaningful bar - and it is - until you factor in that CVE-2026-20182 & CVE-2026-20127 (also recently disclosed Cisco flaws) may lower it *considerably*.
From root on the SD-WAN Manager control plane, an attacker can manipulate routing, alter policy enforcement, and reduce network visibility. The architectural placement is what makes root here different from root on a workstation.
The Mandiant (part of Google Cloud) report confirms what experienced practitioners already treat as a working assumption: for high-impact vulnerabilities, in-the-wild exploitation tends to run well ahead of any public disclosure.
If you're running Cisco Catalyst SD-WAN Manager: patch against Cisco's advisory, retain audit logs before upgrading, and review them for anomalous activity from netadmin-level accounts.
📍Read the full article by Kevin Poireault: https://www.infosecurity-magazine.com/news/cisco-vulnerability-exploited/
##Exploitation started in March. Cisco disclosed in June. Patch landed June 10.
For roughly 2 months, whoever had working knowledge of CVE-2026-20245 used it _freely_. Defenders had no advisory, no patch, no signal.
Matei Badanoiu, our lead security researcher, put it plainly in Infosecurity Magazine:
""Whoever used this vulnerability had working knowledge of it in this period while defenders had none.""
🏴☠️ The exploitation path is specific: an attacker already holding netadmin privileges on Cisco Catalyst SD-WAN Manager could escalate to root via a crafted CSV upload through the request tenant-upload CLI command.
That prerequisite sounds like a meaningful bar - and it is - until you factor in that CVE-2026-20182 & CVE-2026-20127 (also recently disclosed Cisco flaws) may lower it *considerably*.
From root on the SD-WAN Manager control plane, an attacker can manipulate routing, alter policy enforcement, and reduce network visibility. The architectural placement is what makes root here different from root on a workstation.
The Mandiant (part of Google Cloud) report confirms what experienced practitioners already treat as a working assumption: for high-impact vulnerabilities, in-the-wild exploitation tends to run well ahead of any public disclosure.
If you're running Cisco Catalyst SD-WAN Manager: patch against Cisco's advisory, retain audit logs before upgrading, and review them for anomalous activity from netadmin-level accounts.
📍Read the full article by Kevin Poireault: https://www.infosecurity-magazine.com/news/cisco-vulnerability-exploited/
##updated 2026-04-15T21:30:19
2 posts
Longinus: 2 Boundaries in One Bug, Piercing Chrome’s Renderer and V8 Sandbox with a Single Vulnerability, CVE-2026-6307 https://lobste.rs/s/uaoe9y #security #web
https://nebusec.ai/research/v8-cve-2026-6307-writeup/
Longinus: 2 Boundaries in One Bug, Piercing Chrome’s Renderer and V8 Sandbox with a Single Vulnerability, CVE-2026-6307 https://lobste.rs/s/uaoe9y #security #web
https://nebusec.ai/research/v8-cve-2026-6307-writeup/
updated 2026-03-27T21:32:39
2 posts
2 repos
Researcher publicly disclosed an NTLM reflection bypass, CVE-2026-24294, with PoC exploit code. It gives SYSTEM on Windows Server 2025. Patch now.
#NTLM #NTLMReflection #CVE202624294 #Windows #PrivEsc #Cybersecurity #Infosec
##Researcher publicly disclosed an NTLM reflection bypass, CVE-2026-24294, with PoC exploit code. It gives SYSTEM on Windows Server 2025. Patch now.
#NTLM #NTLMReflection #CVE202624294 #Windows #PrivEsc #Cybersecurity #Infosec
##updated 2026-02-26T21:32:34
1 posts
2 repos
🛡️ Weekly CVE Roundup is here! We're highlighting a critical path traversal bypass in Node.js (CVE-2026-3102) and discussing why experimental features can be a liability in production. Stay ahead of the latest security trends. 🔒 Read more: https://cvedatabase.com/blog/weekly-cve-roundup-critical-node-js-permission-bypass-and-late-may-security-tren-2026-05-31 #NodeJS #CyberSecurity #CVE #Infosec #VulnerabilityManagement
##📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418
Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93
CISA KEVs:
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31
Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12
Top EPSS Score:
- CVE-2026-32315 - 2.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-32315)
- CVE-2026-56274 - 2.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56274)
- CVE-2026-28496 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-28496)
- CVE-2026-54066 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54066)
- CVE-2026-54157 - 1.78 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54157)
- CVE-2026-12486 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12486)
- CVE-2026-12850 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12850)
- CVE-2026-12849 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12849)
- CVE-2026-12851 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12851)
- CVE-2026-9776 - 1.58 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9776)
📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418
Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93
CISA KEVs:
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31
Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12
Top EPSS Score:
- CVE-2026-32315 - 2.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-32315)
- CVE-2026-56274 - 2.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56274)
- CVE-2026-28496 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-28496)
- CVE-2026-54066 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54066)
- CVE-2026-54157 - 1.78 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54157)
- CVE-2026-12486 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12486)
- CVE-2026-12850 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12850)
- CVE-2026-12849 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12849)
- CVE-2026-12851 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12851)
- CVE-2026-9776 - 1.58 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9776)
📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418
Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93
CISA KEVs:
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31
Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12
Top EPSS Score:
- CVE-2026-32315 - 2.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-32315)
- CVE-2026-56274 - 2.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56274)
- CVE-2026-28496 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-28496)
- CVE-2026-54066 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54066)
- CVE-2026-54157 - 1.78 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54157)
- CVE-2026-12486 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12486)
- CVE-2026-12850 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12850)
- CVE-2026-12849 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12849)
- CVE-2026-12851 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12851)
- CVE-2026-9776 - 1.58 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9776)
📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418
Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93
CISA KEVs:
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31
Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12
Top EPSS Score:
- CVE-2026-32315 - 2.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-32315)
- CVE-2026-56274 - 2.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56274)
- CVE-2026-28496 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-28496)
- CVE-2026-54066 - 1.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54066)
- CVE-2026-54157 - 1.78 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54157)
- CVE-2026-12486 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12486)
- CVE-2026-12850 - 1.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12850)
- CVE-2026-12849 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12849)
- CVE-2026-12851 - 1.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12851)
- CVE-2026-9776 - 1.58 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9776)
Critical 100 CVSS Flaw Lets Attackers Take Over Hoppscotch Servers in a Single Request + Video
A Silent Opening in the API Layer That Turned Into Full Server Compromise A devastating security vulnerability has been uncovered in the self-hosted version of Hoppscotch, exposing how a single overlooked validation rule can escalate into full system takeover. Assigned CVE-2026-50160 and rated CVSS 10.0, this flaw represents the highest severity class of vulnerability:…
##🟠 CVE-2026-47220 - High (7.5)
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, when the %REQUESTED_SERVER_NAME(X:Y)% is used in log format and host related options is specified, like HOST_FIRST, SNI_FIR...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47220/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-47220 - High (7.5)
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, when the %REQUESTED_SERVER_NAME(X:Y)% is used in log format and host related options is specified, like HOST_FIRST, SNI_FIR...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47220/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-47193 - High (7.5)
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historical field values without enforcing object and field visibility. This vulnerability is fixed in 17.3.3 ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47193/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-46386 - Critical (9.9)
OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key. Combined with cookies_serializer = :marshal, th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46386/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-49991 - Critical path traversal in RustFS. Authenticated users can write objects to other tenants' buckets via Snowball auto-extract, breaking isolation. CVSS 8.6. Unpatched. Mitigate immediately. #CVE #infosec #RustFS
##The Incus team is pleased to announce the release of Incus 7.2!
It’s another pretty busy release for us with a varied set of new features across the board as well as the usual set of performance improvements and bugfixes.
[🖼 stgraber.org/wp-content/upload…]This fixes the following security issues:
rootfs/ symlink in malicious imageexec-output symlink in crafted imagetemplates/ symlink in malicious imageOn the feature front, the highlights for this release are:
The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:
https://www.youtube.com/watch?v=rcldqF6SpXA
You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/
And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus
Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.
Enjoy!
##The Incus team is pleased to announce the release of Incus 7.2!
It’s another pretty busy release for us with a varied set of new features across the board as well as the usual set of performance improvements and bugfixes.
[🖼 stgraber.org/wp-content/upload…]This fixes the following security issues:
rootfs/ symlink in malicious imageexec-output symlink in crafted imagetemplates/ symlink in malicious imageOn the feature front, the highlights for this release are:
The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:
https://www.youtube.com/watch?v=rcldqF6SpXA
You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/
And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus
Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.
Enjoy!
##The Incus team is pleased to announce the release of Incus 7.2!
It’s another pretty busy release for us with a varied set of new features across the board as well as the usual set of performance improvements and bugfixes.
[🖼 stgraber.org/wp-content/upload…]This fixes the following security issues:
rootfs/ symlink in malicious imageexec-output symlink in crafted imagetemplates/ symlink in malicious imageOn the feature front, the highlights for this release are:
The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:
https://www.youtube.com/watch?v=rcldqF6SpXA
You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/
And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus
Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.
Enjoy!
##The Incus team is pleased to announce the release of Incus 7.2!
It’s another pretty busy release for us with a varied set of new features across the board as well as the usual set of performance improvements and bugfixes.
[🖼 stgraber.org/wp-content/upload…]This fixes the following security issues:
rootfs/ symlink in malicious imageexec-output symlink in crafted imagetemplates/ symlink in malicious imageOn the feature front, the highlights for this release are:
The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:
https://www.youtube.com/watch?v=rcldqF6SpXA
You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/
And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus
Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.
Enjoy!
##