## Updated at UTC 2026-08-01T17:45:21.046997

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-67352 7.6 0.00% 2 0 2026-08-01T13:17:05.860000 luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in
CVE-2026-67343 8.8 0.00% 2 0 2026-08-01T13:17:05.563000 ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the
CVE-2026-67342 9.8 0.00% 2 0 2026-08-01T13:17:05.417000 ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in
CVE-2026-67341 9.8 0.00% 2 0 2026-08-01T13:17:05.273000 ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks o
CVE-2026-67340 9.8 0.00% 4 0 2026-08-01T13:17:05.127000 ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host
CVE-2026-67336 8.7 0.00% 2 0 2026-08-01T13:17:04.557000 better-auth versions before 1.6.11 contain insecure cryptographic defaults in th
CVE-2026-16635 8.8 0.31% 2 0 2026-08-01T09:30:37 The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in a
CVE-2026-15964 9.8 0.49% 4 0 2026-08-01T09:30:37 The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication
CVE-2026-15368 None 0.14% 2 0 2026-08-01T09:30:36 The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind
CVE-2026-15262 None 0.15% 1 0 2026-08-01T09:30:36 The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape
CVE-2026-14561 None 0.14% 2 0 2026-08-01T09:30:36 The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does n
CVE-2026-64531 7.8 0.13% 1 2 2026-08-01T09:30:23 In the Linux kernel, the following vulnerability has been resolved: net: openvs
CVE-2026-16144 8.1 0.69% 2 0 2026-08-01T09:17:00.690000 The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vu
CVE-2026-15450 8.1 0.38% 2 0 2026-08-01T09:16:59.023000 The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable
CVE-2026-66066 0 1.70% 15 5 2026-08-01T08:16:30.147000 Action Pack is a framework for handling and responding to web requests. In versi
CVE-2026-15988 8.8 0.22% 2 0 2026-08-01T08:16:29.610000 The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPre
CVE-2026-3141 9.1 0.47% 4 1 2026-08-01T06:16:26.030000 The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file d
CVE-2026-20316 5.3 0.79% 14 0 2026-08-01T05:16:55.973000 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2026-17566 9.9 0.43% 2 0 2026-08-01T05:16:55.827000 pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by in
CVE-2026-15006 7.5 0.83% 4 0 2026-08-01T03:16:25.460000 The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email
CVE-2026-62246 8.5 0.27% 1 0 2026-08-01T00:17:17.480000 Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge,
CVE-2026-61536 7.5 0.30% 1 0 2026-07-31T23:17:25.930000 Banks generates meaningful LLM prompts using a simple template language. In vers
CVE-2026-44106 7.8 0.23% 2 0 2026-07-31T23:17:24.103000 A privilege escalation vulnerability in the init-script for user-applications al
CVE-2026-44101 9.8 0.40% 1 0 2026-07-31T23:17:23.970000 Due to missing authentication the CHARX OCPP Agent service allows an unauthentic
CVE-2026-44091 9.1 0.33% 1 0 2026-07-31T23:17:23.707000 An unauthenticated remote attacker can post a malicious ID to the MQTT Broker re
CVE-2026-68771 9.8 0.62% 3 0 2026-07-31T22:17:03.630000 ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrai
CVE-2026-53599 7.5 0.31% 1 0 2026-07-31T22:17:03.213000 REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_m
CVE-2026-68770 9.8 0.52% 3 0 2026-07-31T21:17:32.440000 sentence-transformers contains a security control bypass vulnerability that allo
CVE-2026-67207 8.8 0.30% 1 0 2026-07-31T20:16:54.253000 Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in Backu
CVE-2026-52855 9.9 0.27% 1 0 2026-07-31T20:16:51.173000 Wings is the server control plane for Pterodactyl, a free, open-source game serv
CVE-2026-18358 7.5 0.43% 2 0 2026-07-31T20:16:49.663000 A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux.
CVE-2026-52887 10.0 0.59% 2 0 2026-07-31T19:45:02 ## Summary `GET /api/myInAppChannels:list` accepts a structured `filter` query
CVE-2026-53510 8.1 0.40% 1 0 2026-07-31T19:38:26 ### Impact `Savon::Model` generated SOAP operation methods by interpolating ope
CVE-2026-53505 7.5 0.34% 2 0 2026-07-31T19:17:10.123000 Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0,
CVE-2026-18141 8.2 0.25% 1 0 2026-07-31T19:17:08.053000 A flaw was found in aap-gateway, a component of Ansible Automation Platform's Ev
CVE-2026-53500 8.2 0.29% 1 0 2026-07-31T18:36:05 ## Summary The `ALLOWED_SOURCES` configuration is meant to restrict which hosts
CVE-2026-17347 7.5 0.27% 1 0 2026-07-31T18:32:24 The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administr
CVE-2026-10685 7.6 0.18% 1 0 2026-07-31T18:17:09.510000 The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp()
CVE-2026-54725 9.6 0.32% 1 0 2026-07-31T17:45:04 ## Summary The vault-secrets-webhook reads the `vault.security.banzaicloud.io/v
CVE-2026-68500 7.5 0.38% 1 0 2026-07-31T16:52:41 ### Impact The shop payment webhook `POST /{_locale}/update-payment` (route
CVE-2026-6267 8.5 0.34% 2 0 2026-07-31T16:17:12.290000 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.
CVE-2026-68503 9.8 0.40% 1 0 2026-07-31T16:17:12.183000 LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framew
CVE-2026-66360 7.5 0.28% 1 0 2026-07-31T16:17:10.493000 The ISO Presentation layer contains a flaw in the handling of specific paramete
CVE-2026-63559 7.5 0.43% 1 0 2026-07-31T16:17:09.290000 An integer overflow in the UA_Variant arrayDimensions product computation in op
CVE-2026-18157 7.8 0.24% 1 0 2026-07-31T16:17:05.520000 A flaw was found in yggdrasil-worker-package-manager. A local attacker with exis
CVE-2026-15435 9.8 0.73% 3 0 2026-07-31T16:16:58.413000 IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.
CVE-2026-10079 8.5 0.17% 1 0 2026-07-31T16:16:57.167000 A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Wh
CVE-2026-17561 9.8 0.31% 4 0 2026-07-31T15:32:58 Improper Control of Generation of Code ('Code Injection') vulnerability in Innot
CVE-2026-63221 9.4 0.38% 1 0 2026-07-31T14:16:50.873000 CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query B
CVE-2026-63220 4.8 0.14% 1 0 2026-07-31T14:16:50.750000 CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, Incom
CVE-2026-11770 7.5 0.51% 1 0 2026-07-31T12:30:30 A flaw was found in 389 Directory Server. An unauthenticated remote attacker can
CVE-2026-15722 7.5 0.51% 1 0 2026-07-31T11:17:04.833000 A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). Th
CVE-2026-16236 8.8 0.63% 1 0 2026-07-31T09:31:30 The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Up
CVE-2026-65313 8.1 0.18% 1 0 2026-07-31T09:31:19 A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engin
CVE-2026-6102 7.8 0.09% 1 0 2026-07-31T04:17:24.730000 MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulner
CVE-2026-66803 10.0 0.49% 1 0 2026-07-31T04:17:24.520000 Improper access control in Azure Cosmos DB allows an unauthorized attacker to ex
CVE-2026-5490 8.8 0.48% 1 1 2026-07-31T04:17:24.013000 DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability a
CVE-2026-58066 9.8 0.21% 1 0 2026-07-31T04:17:23.877000 Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7,
CVE-2026-58043 7.5 0.14% 4 0 2026-07-31T04:17:23.737000 A flaw in Node.js Permission Model enforcement can over-grant filesystem access
CVE-2026-17543 0 0.39% 1 0 2026-07-31T04:16:48.350000 Improper escaping of backslashes in attacker-provided parameters would allow for
CVE-2026-12940 9.8 0.48% 1 0 2026-07-31T04:16:45.870000 IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote
CVE-2026-65423 8.8 0.60% 1 0 2026-07-31T00:30:29 An integer overflow in the UA_Variant arrayDimensions product computation in op
CVE-2026-66421 9.3 0.36% 1 0 2026-07-31T00:30:29 OpenClaw Dashboard contains a stored cross-site scripting vulnerability that all
CVE-2026-66420 8.8 0.17% 1 0 2026-07-31T00:30:29 MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass v
CVE-2026-18064 7.5 0.34% 1 0 2026-07-31T00:30:29 An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Healt
CVE-2026-63035 8.1 0.57% 1 0 2026-07-31T00:30:22 A heap use-after-free vulnerability in the TransferSubscriptions service in ope
CVE-2026-67206 8.8 0.44% 1 0 2026-07-30T21:31:57 Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileM
CVE-2026-67594 9.8 0.46% 1 0 2026-07-30T21:31:57 Spikster through commit e1cdf8c contains a missing authentication vulnerability
CVE-2026-66416 8.8 0.16% 1 0 2026-07-30T21:31:57 Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows u
CVE-2026-66415 8.5 0.28% 1 0 2026-07-30T21:31:57 Leantime 3.6.2 contains a server-side request forgery and local file inclusion v
CVE-2026-13435 9.9 0.29% 1 0 2026-07-30T21:31:56 IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vuln
CVE-2026-17657 8.3 0.36% 1 0 2026-07-30T21:31:32 Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a r
CVE-2026-18245 9.0 0.52% 1 0 2026-07-30T20:17:03.733000 Improper control of code generation in Amazon @aws-amplify/codegen-ui-react befo
CVE-2026-18140 7.5 0.44% 1 0 2026-07-30T20:17:03.400000 Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runti
CVE-2026-67432 7.5 0.44% 1 0 2026-07-30T19:30:33.710000 MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and cli
CVE-2026-62663 7.5 0.34% 1 0 2026-07-30T19:26:51.190000 Banks generates meaningful LLM prompts using a simple template language. In vers
CVE-2026-67437 7.5 0.35% 1 0 2026-07-30T19:21:23.297000 OliveTin gives access to predefined shell commands from a web interface. From 30
CVE-2026-16771 8.8 0.25% 1 0 2026-07-30T19:10:06.847000 In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to en
CVE-2026-28323 9.8 0.64% 3 0 2026-07-30T18:31:47 SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass
CVE-2026-9322 7.5 0.30% 1 0 2026-07-30T18:31:47 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv
CVE-2026-67595 8.1 0.42% 3 0 2026-07-30T16:45:00.353000 VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript p
CVE-2026-67428 8.5 0.34% 1 0 2026-07-30T16:41:25.650000 Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior
CVE-2026-56850 4.1 0.08% 1 0 2026-07-30T16:33:59.580000 A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key co
CVE-2026-44102 5.3 0.21% 1 0 2026-07-30T16:17:11.877000 An unauthenticated remote attacker can trigger a firmware update download via th
CVE-2026-47876 9.3 0.28% 3 0 2026-07-30T15:31:54 VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual
CVE-2026-59309 9.8 0.74% 2 0 2026-07-30T15:31:54 VMware vCenter contains an authentication bypass vulnerability in the VMware Dir
CVE-2026-59310 9.8 1.14% 2 0 2026-07-30T15:31:51 VMware vCenter contains a directory traversal vulnerability in the Syslog server
CVE-2026-1360 7.5 0.57% 1 0 2026-07-30T15:16:31.530000 The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untruste
CVE-2026-67429 10.0 0.49% 1 0 2026-07-30T14:46:44 ## Summary `image.download` fetches a URL and writes the response to disk. It d
CVE-2026-44108 9.8 0.46% 2 0 2026-07-30T14:31:21.447000 Due to a flaw in the execution order of scripts during shutdown, the firewall is
CVE-2026-44105 6.6 0.09% 1 0 2026-07-30T14:31:21.447000 The credentials for the local user "user-app" may be exposed in log files, poten
CVE-2026-44098 8.6 1.37% 1 0 2026-07-30T14:31:21.447000 This vulnerability allows an unauthenticated remote attacker with control over t
CVE-2026-44100 9.4 0.28% 1 0 2026-07-30T14:31:21.447000 The CHARX JupiCore service allows an unauthenticated remote attacker to reconfig
CVE-2026-44093 7.8 0.23% 1 0 2026-07-30T14:31:21.447000 A local privilege escalation vulnerability in the init-script for user-applicati
CVE-2026-5057 7.5 0.48% 1 0 2026-07-30T14:19:24.857000 ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability.
CVE-2026-5491 7.5 1.54% 1 0 2026-07-30T14:18:46.477000 DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnera
CVE-2026-15975 7.5 0.39% 1 0 2026-07-30T14:15:31.167000 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8
CVE-2026-14529 9.4 0.33% 2 0 2026-07-30T14:08:40.373000 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv
CVE-2026-14270 8.8 0.55% 1 0 2026-07-30T14:01:30.413000 The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCom
CVE-2026-18363 None 0.30% 1 0 2026-07-30T12:32:26 A logic vulnerability in the password reset token validation routine implemented
CVE-2026-64560 7.8 0.12% 1 0 2026-07-30T12:19:03.630000 In the Linux kernel, the following vulnerability has been resolved: posix-cpu-t
CVE-2026-44107 7.5 0.31% 2 0 2026-07-30T09:31:24 A reboot of the charging controller can be triggered via Modbus TCP without auth
CVE-2026-7849 9.8 0.42% 2 0 2026-07-30T09:31:24 Due to improper neutralization of special elements, an unauthenticated remote at
CVE-2026-44094 8.6 0.26% 1 0 2026-07-30T09:31:24 An unauthenticated remote attacker can enforce the system to fall back to a firm
CVE-2026-44090 9.8 0.40% 1 0 2026-07-30T09:31:24 Due to missing authentication, an unauthenticated remote attacker may access the
CVE-2026-44104 9.8 0.24% 1 0 2026-07-30T09:31:24 The firmware update process for the basemodule of the charging controller only v
CVE-2026-44095 7.8 0.23% 1 0 2026-07-30T09:31:24 A privilege escalation vulnerability in a script used for network configuration
CVE-2026-44103 5.3 0.24% 1 0 2026-07-30T09:31:24 An unauthenticated remote attacker can inject malicious firmware into the intern
CVE-2026-44092 9.1 0.38% 1 0 2026-07-30T09:31:24 An unauthenticated remote attacker can inject malicious input into the ModbusSer
CVE-2026-44096 7.8 0.23% 1 0 2026-07-30T09:31:18 A privilege escalation vulnerability in udhcpc allows a local user "charx-web" t
CVE-2026-44099 7.8 0.23% 1 0 2026-07-30T09:31:18 A privilege escalation vulnerability in the system configuration allows a low-pr
CVE-2026-44097 7.1 0.24% 1 0 2026-07-30T09:31:18 A low-privileged remote attacker with "operator" access can upload arbitrary fil
CVE-2026-58046 9.9 0.31% 1 0 2026-07-30T06:32:44 Improper neutralization in the Plesk XML-RPC API allows a remote authenticated l
CVE-2026-16610 9.8 0.58% 2 0 2026-07-30T06:32:44 The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to
CVE-2026-14356 8.8 0.27% 1 0 2026-07-30T06:32:43 The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in a
CVE-2026-48449 10.0 0.54% 3 0 2026-07-30T03:31:28 Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi
CVE-2026-48448 8.6 0.37% 1 0 2026-07-30T03:31:28 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia
CVE-2026-16727 None 0.09% 1 0 2026-07-30T03:31:28 Concurrent Execution using Shared Resource with Improper Synchronization (“Race
CVE-2026-5056 7.8 0.43% 1 0 2026-07-29T21:31:08 GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerabilit
CVE-2026-13308 8.1 0.57% 1 0 2026-07-29T21:31:08 Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Executi
CVE-2026-5487 7.5 1.54% 1 0 2026-07-29T21:31:07 DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnera
CVE-2026-67201 8.6 0.39% 1 0 2026-07-29T21:31:07 V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery
CVE-2026-61511 9.8 1.27% 2 6 2026-07-29T20:17:10.347000 vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vul
CVE-2026-67215 7.5 0.35% 1 0 2026-07-29T15:31:12 cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack ex
CVE-2026-65883 None 0.50% 1 1 2026-07-29T12:31:30 Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Ca
CVE-2026-18220 7.8 0.19% 1 1 2026-07-29T12:31:23 An out-of-bounds write vulnerability was found in the BFD library's DLX ELF back
CVE-2026-18197 None 0.27% 1 0 2026-07-29T09:31:36 Improper neutralization of input during web page generation ('cross-site scripti
CVE-2026-14512 9.8 0.54% 1 0 2026-07-28T21:31:44 IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-a
CVE-2026-16347 8.8 0.23% 2 0 2026-07-28T21:31:39 MikroTik RouterOS contains a weakness in its API authentication handling that la
CVE-2026-55390 7.5 0.36% 1 0 2026-07-28T21:26:42 ### Summary When generating models from an XML Schema (`--input-file-type xmlsc
CVE-2026-5674 8.8 0.12% 1 0 2026-07-28T18:33:47 A flaw was found in PipeWire, a multimedia server. This vulnerability allows an
CVE-2026-16812 10.0 0.88% 1 0 2026-07-27T21:31:22 VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may a
CVE-2026-63077 9.8 0.65% 4 1 2026-07-27T18:31:56 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe
CVE-2026-66013 None 0.39% 1 0 2026-07-25T12:31:47 OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the
CVE-2026-66373 7.5 0.47% 1 0 2026-07-25T03:30:55 Redis before 8.8.0, in the unusual case where an authenticated attacker can exec
CVE-2026-59952 None 0.52% 1 0 2026-07-24T16:14:33 ## Summary `valibot` 1.4.1 can throw a `TypeError` inside its `flatten()` helpe
CVE-2026-43499 7.8 0.73% 1 57 2026-07-24T15:33:29 In the Linux kernel, the following vulnerability has been resolved: rtmutex: Us
CVE-2026-21655 None 0.17% 1 0 2026-07-23T21:31:03 Deserialization of untrusted data vulnerability in Johnson Control victor on Win
CVE-2026-43503 8.8 0.34% 1 9 2026-07-23T11:10:00.120000 In the Linux kernel, the following vulnerability has been resolved: net: skbuff
CVE-2026-16232 9.1 69.97% 5 2 template 2026-07-22T21:32:05 An authentication bypass vulnerability in the Check Point SmartConsole login pro
CVE-2026-50522 9.8 75.76% 2 5 2026-07-22T21:31:51 Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CVE-2026-49176 7.8 0.47% 1 2 2026-07-22T16:17:28.753000 Improper privilege management in Windows WalletService allows an authorized atta
CVE-2026-20896 9.8 31.81% 2 6 2026-07-21T20:28:59 # Summary The Gitea Docker images ship an `app.ini` template that hard-codes:
CVE-2026-27771 8.2 43.07% 2 2 template 2026-07-17T19:04:38 ### CVE Description Gitea versions up to and including 1.26.1 have insufficient
CVE-2026-15352 7.5 0.43% 1 0 2026-07-16T21:30:45 A vulnerability exists in the Health & Safety (HS) application of NASA's Core Fl
CVE-2026-42530 8.1 3.68% 1 3 2026-07-16T12:17:51.630000 NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGI
CVE-2026-15409 10.0 78.44% 2 5 template 2026-07-16T05:16:18.293000 A Server-side request forgery (SSRF) vulnerability has been identified in the SM
CVE-2026-48319 9.1 32.29% 2 0 2026-07-14T21:32:32 ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted D
CVE-2026-15410 7.2 76.35% 2 3 2026-07-14T21:32:21 Post-authentication improper control of generation of code ('Code Injection') vu
CVE-2026-59726 10.0 0.48% 3 1 2026-07-10T19:15:15.780000 Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo
CVE-2026-56291 9.8 76.07% 2 4 template 2026-07-10T18:33:13 The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary
CVE-2026-58025 9.8 0.33% 1 1 2026-07-09T21:31:14 Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWik
CVE-2026-10702 4.3 0.72% 3 2 2026-06-30T03:36:54 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w
CVE-2026-42897 8.1 5.64% 6 1 2026-06-17T10:48:34.893000 Improper neutralization of input during web page generation ('cross-site scripti
CVE-2014-0160 7.5 100.00% 1 75 template 2026-06-17T00:02:24.467000 The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not p
CVE-2013-4786 7.5 78.57% 2 1 2026-06-16T23:57:53.617000 The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (R
CVE-2026-20079 10.0 37.67% 4 1 template 2026-03-04T18:32:03 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2025-15435 7.3 0.36% 1 0 2026-01-02T09:30:27 A flaw has been found in Yonyou KSOA 9.0. Affected by this vulnerability is an u
CVE-2023-37327 7.6 1.71% 2 0 2025-11-04T21:32:34 GStreamer FLAC File Parsing Integer Overflow Remote Code Execution Vulnerability
CVE-2026-63030 0 98.42% 2 72 template N/A
CVE-2026-60137 0 79.03% 2 46 N/A
CVE-2026-18420 0 0.00% 1 0 N/A
CVE-2026-62999 0 0.29% 1 0 N/A
CVE-2026-62261 0 0.00% 1 0 N/A
CVE-2026-62379 0 0.00% 1 0 N/A
CVE-2026-46648 0 0.00% 1 0 N/A
CVE-2026-46647 0 0.00% 1 0 N/A
CVE-2026-63223 0 0.49% 2 0 N/A
CVE-2026-63222 0 0.45% 1 0 N/A
CVE-2026-68502 0 0.53% 1 0 N/A
CVE-2026-58086 0 0.00% 1 0 N/A
CVE-2026-56846 0 0.00% 2 0 N/A
CVE-2026-56848 0 0.00% 4 0 N/A
CVE-2026-53921 0 0.00% 1 2 N/A

CVE-2026-67352
(7.6 HIGH)

EPSS: 0.00%

updated 2026-08-01T13:17:05.860000

2 posts

luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is rendered as raw HTML and executes JavaScript in the administrator's browser origin.

thehackerwire@mastodon.social at 2026-08-01T15:01:10.000Z ##

🟠 CVE-2026-67352 - High (7.6)

luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is ren...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-01T15:01:10.000Z ##

🟠 CVE-2026-67352 - High (7.6)

luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is ren...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67343
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-01T13:17:05.563000

2 posts

ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authenticated users to retrieve the arcadedb.ha.clusterToken value in cleartext. Attackers can use the leaked token with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate root and execute administrative actions including user creation, database operatio

thehackerwire@mastodon.social at 2026-08-01T15:00:59.000Z ##

🟠 CVE-2026-67343 - High (8.8)

ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authenticated users to retrieve the arcadedb.ha.clusterToken value in cleartext. Attackers can use the leaked token with X-Arcad...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-01T15:00:59.000Z ##

🟠 CVE-2026-67343 - High (8.8)

ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authenticated users to retrieve the arcadedb.ha.clusterToken value in cleartext. Attackers can use the leaked token with X-Arcad...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67342
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-01T13:17:05.417000

2 posts

ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify databases they are not authorized to use by directly calling affected endpoints with arbitrary database parameters.

thehackerwire@mastodon.social at 2026-08-01T15:00:24.000Z ##

🔴 CVE-2026-67342 - Critical (9.8)

ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify databases t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-01T15:00:24.000Z ##

🔴 CVE-2026-67342 - Critical (9.8)

ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify databases t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67341
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-01T13:17:05.273000

2 posts

ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, bypassing security controls intended to restrict scripting to administrators.

thehackerwire@mastodon.social at 2026-08-01T15:00:14.000Z ##

🔴 CVE-2026-67341 - Critical (9.8)

ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, by...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-01T15:00:14.000Z ##

🔴 CVE-2026-67341 - Critical (9.8)

ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, by...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67340
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-01T13:17:05.127000

4 posts

ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permission can create a JavaScript trigger that invokes java.lang.Runtime.getRuntime().exec() (or ProcessBuilder), achieving OS command execution when the trigger fires

thehackerwire@mastodon.social at 2026-08-01T15:00:03.000Z ##

🔴 CVE-2026-67340 - Critical (9.8)

ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permission can ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-01T13:30:26.249Z ##

CVE-2026-67340: CRITICAL RCE in ArcadeDB <26.7.2. Users w/ UPDATE_SCHEMA can exploit JavaScript triggers to run OS commands. Patch status pending — restrict permissions & audit triggers. Details: radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-01T15:00:03.000Z ##

🔴 CVE-2026-67340 - Critical (9.8)

ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permission can ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-01T13:30:26.000Z ##

CVE-2026-67340: CRITICAL RCE in ArcadeDB <26.7.2. Users w/ UPDATE_SCHEMA can exploit JavaScript triggers to run OS commands. Patch status pending — restrict permissions & audit triggers. Details: radar.offseq.com/threat/cve-20 #OffSeq #ArcadeDB #RCE #infosec

##

CVE-2026-67336
(8.7 HIGH)

EPSS: 0.00%

updated 2026-08-01T13:17:04.557000

2 posts

better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit algorithm negotiation to accept unsigned tokens or intercept authorization codes when PKCE plain is used instead of the required S256 method.

thehackerwire@mastodon.social at 2026-08-01T15:01:20.000Z ##

🟠 CVE-2026-67336 - High (8.7)

better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit algorithm negotiation to accept unsigned token...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-01T15:01:20.000Z ##

🟠 CVE-2026-67336 - High (8.7)

better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit algorithm negotiation to accept unsigned token...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16635
(8.8 HIGH)

EPSS: 0.31%

updated 2026-08-01T09:30:37

2 posts

The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value (`$lead[$feed->user_role_field_id]`) directly into `WP_User::set_role()` without any allowlist validation, capability comparison, or permission check to constrain whic

thehackerwire@mastodon.social at 2026-08-01T11:00:53.000Z ##

🟠 CVE-2026-16635 - High (8.8)

The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value (`$lead[$feed-...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-01T11:00:53.000Z ##

🟠 CVE-2026-16635 - High (8.8)

The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value (`$lead[$feed-...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15964
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-08-01T09:30:37

4 posts

The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — registered on `wp_ajax_nopriv_ssoprocess_ajax` and therefore reachable without authentication — accepting an attacker-supplied `email` parameter with the `setnewpassword` operation an

thehackerwire@mastodon.social at 2026-08-01T10:59:52.000Z ##

🔴 CVE-2026-15964 - Critical (9.8)

The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — registered on `wp_ajax_nopri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-01T10:30:25.737Z ##

CRITICAL: CVE-2026-15964 in britcoder Single Sign On For TNG <=2.0.0 lets unauthenticated attackers reset any WP user password via exposed AJAX. Full site takeover possible. Disable or restrict access now. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-01T10:59:52.000Z ##

🔴 CVE-2026-15964 - Critical (9.8)

The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — registered on `wp_ajax_nopri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-01T10:30:25.000Z ##

CRITICAL: CVE-2026-15964 in britcoder Single Sign On For TNG <=2.0.0 lets unauthenticated attackers reset any WP user password via exposed AJAX. Full site takeover possible. Disable or restrict access now. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE #Vuln

##

CVE-2026-15368(CVSS UNKNOWN)

EPSS: 0.14%

updated 2026-08-01T09:30:36

2 posts

The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic login performed after user registration to the newly created account, allowing unauthenticated attackers to obtain an authenticated session for an arbitrary existing user, including administrators, on sites using a supported but non-default configuration.

offseq at 2026-08-01T09:00:23.971Z ##

CVE-2026-15368: User Profile Builder WP plugin (CRITICAL) allows session hijack as any user — including admins — if using specific non-default configs. Review settings, restrict auto-login, and monitor for fixes. radar.offseq.com/threat/cve-20 🔒

##

offseq@infosec.exchange at 2026-08-01T09:00:23.000Z ##

CVE-2026-15368: User Profile Builder WP plugin (CRITICAL) allows session hijack as any user — including admins — if using specific non-default configs. Review settings, restrict auto-login, and monitor for fixes. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #CVE202615368 🔒

##

CVE-2026-15262(CVSS UNKNOWN)

EPSS: 0.15%

updated 2026-08-01T09:30:36

1 posts

The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fields values before outputting them in the WordPress admin list-table columns, allowing users with contributor-level access or above to store a payload that executes as JavaScript in the session of higher-privileged users who view the affected post-list screen.

killbait@mastodon.world at 2026-08-01T08:42:09.000Z ##

Linux Kernel Vulnerability Enables Privilege Escalation via Local Exploits

📰 Original title: CVE-2026-15262

🤖 IA: It's not clickbait ✅
👥 Users: It's not clickbait ✅

View full AI summary en.killbait.com/linux-kernel-v

#technology #cybersecurity #vulnerability #linux

##

CVE-2026-14561(CVSS UNKNOWN)

EPSS: 0.14%

updated 2026-08-01T09:30:36

2 posts

The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential, returning the code and a valid verification token in the response of an unauthenticated action, allowing unauthenticated attackers to log in as any user whose registered mobile number they know (including administrators) or to create arbitrary accounts.

offseq at 2026-08-01T07:30:25.039Z ##

CVE-2026-14561 | CRITICAL | Authora: Easy login with mobile number (WordPress <1.7.7) suffers from improper authentication — attackers can log in as any user if they know a mobile number. Restrict plugin endpoints & monitor logins. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-01T07:30:25.000Z ##

CVE-2026-14561 | CRITICAL | Authora: Easy login with mobile number (WordPress <1.7.7) suffers from improper authentication — attackers can log in as any user if they know a mobile number. Restrict plugin endpoints & monitor logins. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln

##

CVE-2026-64531
(7.8 HIGH)

EPSS: 0.13%

updated 2026-08-01T09:30:23

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16. Commit a1e64addf3ff ("net: openvswitch: remove misbehaving actions length check") allowed the total sw_flow_actions stream to grow beyond 64 KiB, which is valid, but also removed the last guar

2 repos

https://github.com/0xBlackash/CVE-2026-64531

https://github.com/mahfuzreham/OVSwrap-CVE-2026-64531-Mitigation-Tool

tugatech@masto.pt at 2026-07-31T09:36:37.000Z ##

Falha OVSwrap ameaça servidores Linux com acesso root e já tem exploit público. Uma vulnerabilidade crítica no kernel do Linux, batizada de OVSwrap (CVE-2026-64531), permite que utilizadores locais sem privilégios obtenham acesso total de root. 🚨

🔗 tugatech.com.pt/t88334-falha-o

#exploit #falha #linux #root 

##

CVE-2026-16144
(8.1 HIGH)

EPSS: 0.69%

updated 2026-08-01T09:17:00.690000

2 posts

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermalink' field value before it overwrites a trusted callable placeholder, allowing attacker-controlled strings to reach call_user_func() in _save_data(). This

thehackerwire@mastodon.social at 2026-08-01T11:00:42.000Z ##

🟠 CVE-2026-16144 - High (8.1)

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermal...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-01T11:00:42.000Z ##

🟠 CVE-2026-16144 - High (8.1)

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermal...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15450
(8.1 HIGH)

EPSS: 0.38%

updated 2026-08-01T09:16:59.023000

2 posts

The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 9.2.3. This is due to the delete_file() AJAX handler retrieving a file path from the database and passing it directly to unlink() with no validation (no realpath(), basename(), or allowlist check), combined with the insert_record() AJAX han

thehackerwire@mastodon.social at 2026-08-01T11:01:04.000Z ##

🟠 CVE-2026-15450 - High (8.1)

The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 9.2.3. This is due to the delete_file() AJAX handler retrieving a file path from th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-01T11:01:04.000Z ##

🟠 CVE-2026-15450 - High (8.1)

The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 9.2.3. This is due to the delete_file() AJAX handler retrieving a file path from th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66066
(0 None)

EPSS: 1.70%

updated 2026-08-01T08:16:30.147000

15 posts

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated a

5 repos

https://github.com/paveg/rails-activestorage-vips-audit

https://github.com/0xsha/KindaRails2Shell

https://github.com/Zer0SumGam3/CVE-2026-66066-POC

https://github.com/rails/rails-forensics-CVE-2026-66066

https://github.com/0xBlackash/CVE-2026-66066

undercodenews@mastodon.social at 2026-08-01T15:04:10.000Z ##

Critical Ruby on Rails Flaw CVE-2026-66066 Exposes Sensitive Files, Secret Keys, and the Hidden Risks Inside Modern Web Frameworks + Video

Introduction: A New Warning Sign for Web Application Security Modern web frameworks have transformed software development by making it faster and easier to build powerful applications. However, every additional feature, plugin, and integrated component also creates new security challenges. The discovery of CVE-2026-66066, a critical…

undercodenews.com/critical-rub

##

Analyst207@mastodon.social at 2026-08-01T14:54:41.000Z ##

Rails patches Active Storage flaw with RCE potential

A critical vulnerability in Rails' Active Storage, known as CVE-2026-66066, can allow an unauthenticated attacker to read sensitive files and potentially execute remote code, putting your application at risk. This flaw can be exploited under specific conditions, making it crucial to patch immediately.

osintsights.com/rails-patches-

#Rails #ActiveStorage #Cve202666066 #RemoteCodeExecution #FileUploadVulnerability

##

DailyCyberSecurity at 2026-08-01T10:18:30.243Z ##

CVE-2026-66066 (CVSS 9.5) enables Rails Active Storage RCE via libvips. A Metasploit module is now public. Upgrade Rails and rotate secrets.

securityonline.info/cve-2026-6

##

DailyCyberSecurity@infosec.exchange at 2026-08-01T10:18:30.000Z ##

CVE-2026-66066 (CVSS 9.5) enables Rails Active Storage RCE via libvips. A Metasploit module is now public. Upgrade Rails and rotate secrets.

#RubyOnRails #CVE202666066 #RCE #ActiveStorage #CyberSecurity #Metasploit

securityonline.info/cve-2026-6

##

flavorjones@ruby.social at 2026-07-31T01:01:12.000Z ##

RE: ruby.social/@flavorjones/11700

The Rails security team published attack details and -- more importantly -- tools and agent skills to run a forensic investigation to help you determine if you were exploited. Be careful out there.

discuss.rubyonrails.org/t/cve-

##

threatcodex@infosec.exchange at 2026-07-30T20:34:49.000Z ##

KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
#CVE_2026_66066
rapid7.com/blog/post/etr-kinda

##

AAKL@infosec.exchange at 2026-07-30T16:38:45.000Z ##

New.

Rapaid7: KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails rapid7.com/blog/post/etr-kinda @Rapid7Official

The related Ruby on Rails advisory was published yesterday: Possible arbitrary file read and remote code execution in Active Storage variant processing github.com/rails/rails/securit #infosec #vulnerability #Ruby

##

lobsters@mastodon.social at 2026-07-30T15:10:13.000Z ##

KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066) lobste.rs/s/kkobew #ruby #security
ethiack.com/info-hub/research/

##

_r_netsec@infosec.exchange at 2026-07-30T14:13:05.000Z ##

KindaRails2Shell: arbitrary file read to RCE in Rails Active Storage via libvips (CVE-2026-66066) ethiack.com/info-hub/research/

##

jbhall56@infosec.exchange at 2026-07-30T12:07:40.000Z ##

Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials, and API tokens. thehackernews.com/2026/07/crit

##

manyfold@3dp.chat at 2026-07-30T11:42:10.000Z ##

🚨 Manyfold v0.147.1 is out, with a security fix for #Rails CVE-2026-66066. Update your instances! 🚨

##

raul@mastodon.in4matics.cat at 2026-07-30T10:16:42.000Z ##

CVE-2026-66066: un atacant pot llegir fitxers del servidor Rails gràcies a Active Storage + libvips. secret_key_base, master.key, credencials de cloud — tot a l'abast. I després fer RCE amb les claus robades. 🎯

Parcheja a: activestorage 7.2.3.2 / 8.0.5.1 / 8.1.3.1 o libvips ≥ 8.13.0

Si encara uses libvips vell, posa VIPS_BLOCK_UNTRUSTED i resa.

#rails #cybersecurity #RCE #CVE

##

beyondmachines1@infosec.exchange at 2026-07-30T08:01:39.000Z ##

Critical Rails Active Storage Flaw Allows Unauthenticated Arbitrary File Read

Ruby on Rails patched a critical vulnerability (CVE-2026-66066) in Active Storage that allows unauthenticated attackers to read arbitrary server files and steal sensitive secrets.

**Update Rails immediately to a patched version (7.2.3.2, 8.0.5.1, or 8.1.3.1) and make sure libvips is upgraded to 8.13 or later. A public exploit is already available and attacks are expected soon. Because attackers may have already stolen your secrets, rotate every credential the app could access, including secret_key_base, the master key, database passwords, and all API tokens after patching.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

DailyCyberSecurity@infosec.exchange at 2026-07-30T03:01:51.000Z ##

A Rails Active Storage flaw, CVE-2026-66066 (CVSS 9.5), enables arbitrary file read and remote code execution. Patch Rails and rotate secrets now.

#RubyOnRails #ActiveStorage #CVE202666066 #RCE #libvips #InfoSec

securityonline.info/rails-cve-

##

christine@ruby.social at 2026-07-29T18:17:08.000Z ##

RE: christine-seeman.com/cve-2026-

Patch your #rails there's a new CVE out there specifically about active storage and if your app accepts image uploads.

#ruby #rubyonrails

##

CVE-2026-15988
(8.8 HIGH)

EPSS: 0.22%

updated 2026-08-01T08:16:29.610000

2 posts

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.5 This is due to missing or incorrect nonce validation on the reauth_for_authorize function. This makes it possible for unauthenticated attackers to create new administrator accounts with attacker-supplied credentials via a CSRF-ba

thehackerwire@mastodon.social at 2026-08-01T13:00:08.000Z ##

🟠 CVE-2026-15988 - High (8.8)

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.5 This is due to missing or incorrect nonce validation on the reauth_for_aut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-01T13:00:08.000Z ##

🟠 CVE-2026-15988 - High (8.8)

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.5 This is due to missing or incorrect nonce validation on the reauth_for_aut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-3141
(9.1 CRITICAL)

EPSS: 0.47%

updated 2026-08-01T06:16:26.030000

4 posts

The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This is due to the REST API route being registered without any authentication middleware in routes/rest/api.php. This makes it possible for unauthenticated attackers to

1 repos

https://github.com/Rat5ak/CVE-2026-31413-BPF-Container-Escape

thehackerwire@mastodon.social at 2026-08-01T13:00:18.000Z ##

🔴 CVE-2026-3141 - Critical (9.1)

The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This is due to t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-01T06:00:23.569Z ##

CVE-2026-3141 (CRITICAL, CVSS 9.1): wpwax FormGent for WordPress lets unauthenticated users delete arbitrary files via REST API. Linux servers risk full takeover if wp-config.php is deleted. Patch or restrict access now. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-01T13:00:18.000Z ##

🔴 CVE-2026-3141 - Critical (9.1)

The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This is due to t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-01T06:00:23.000Z ##

CVE-2026-3141 (CRITICAL, CVSS 9.1): wpwax FormGent for WordPress lets unauthenticated users delete arbitrary files via REST API. Linux servers risk full takeover if wp-config.php is deleted. Patch or restrict access now. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE20263141

##

CVE-2026-20316
(5.3 MEDIUM)

EPSS: 0.79%

updated 2026-08-01T05:16:55.973000

14 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged&nbsp;account. An attacker could exploit this vu

i_ball at 2026-08-01T14:55:34.473Z ##

What year is it?:

nvd.nist.gov/vuln/detail/CVE-2

##

i_ball@infosec.exchange at 2026-08-01T14:55:34.000Z ##

What year is it?:

nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-07-31T16:19:58.000Z ##

There are two new advisories from Cisco, one addressing a critical vulnerability that was first published on March 4:

CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi

The second is a high-severity vulnerability that was first published yesterday:

CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #vulnerability #Cisco

##

thecybermind@infosec.exchange at 2026-07-31T13:34:04.000Z ##

Executive alert: CVE-2026-20316 exposes Cisco Secure Firewall Management Center to active exploitation via hard-coded credentials. Review enterprise exposure metrics, zero-trust segmentation, and board-level risk mitigation strategies today. thecybermind.co/jily

##

oversecurity@mastodon.social at 2026-07-31T10:12:18.000Z ##

CVE-2026-20316 Zero-Day Actively Exploited, Cisco Releases Fix

Cisco has released security updates for an actively exploited zero-day vulnerability, CVE-2026-20316, affecting Cisco Secure FMC (Secure Firewall...

🔗️ [Thecyberexpress] link.is.it/FLOu9T

##

thecybermind@infosec.exchange at 2026-07-31T07:21:09.000Z ##

Critical advisory: CVE-2026-20316 exposes Cisco Secure Firewall Management Center to hard-coded credential abuse. Review active threat vectors, network access lockdowns, and system hardening playbooks to protect your perimeter. thecybermind.co/bkur

##

Bied@digitalhub.social at 2026-07-30T19:33:28.000Z ##

#Cisco - "We Never Learn". 🔥

Warum ein Konzern es noch immer notwendig findet eine #Backdoor in seine Produkte einzubauen ist mir völlig schleierhaft. 🙈

"Da CVE-2026-20316 bereits aktiv ausgenutzt wird, rät Cisco Administratoren, ihre FMC-Instanzen dringend zu aktualisieren."

"Gibt es Abhilfe?

"Die genannten Hotfix-Updates bessern auch bezüglich einer seit März bekannten kritischen Lücke (CVSS: 10) nach, mit der sich die Authentifizierung im Web-Interface von FMC umgehen lässt. Diese Lücke ist als CVE-2026-20079 registriert und verleiht Angreifern sogar einen direkten Root-Zugriff auf das zugrundeliegende Betriebssystem. "

Klar, eine Firewall ist ja nur zum Schutz der Kunden vorhanden, da kann man schon mal auch Kriminelle einladen, oder? 🤢

So eine persönliche Haftung des CEO und eine Strafe ab 5 % vom Konzernumsatz könnte möglicherweise zu einer Änderungen führen:

So stelle ich mir die Anweisung des CEO vor: 👍

"Ab sofort ist die Nutzung (auch während der Entwicklung) von Backdoors untersagt. Wer sich nicht daran hält wird fristlos entlassen und haftet für Schäden."

Und, natürlich sollte die Qualitätssicherung vorab prüfen ob die Entwickler sich auch daran halten. 😁

Es gibt erfahrene Spezialisten die gerne bei der Auswahl der Geräte helfen und für mehr Sicherheit sorgen. Einfach anfragen, dann weiß man mehr. 🙂

golem.de/news/kodierte-zugangs

#Backdoor

##

security_crawler_carl@infosec.exchange at 2026-07-30T11:45:32.000Z ##

🏆 New Achievement! Static Credentials, Static Fate!

RAID ALERT. RAID ALERT. Cisco Secure Firewall Management Center has a hardcoded low-privilege account baked right into the software — CVE-2026-20316 — and unauthenticated remote attackers are already using it to log in and harvest sensitive data. That's Phase One. Phase Two is the wipe: threat actors are chaining it with CVE-2026-20079, which hands them root access via arbitrary script execution. (1/2)

##

beyondmachines1@infosec.exchange at 2026-07-30T11:01:06.000Z ##

Cisco Patches Actively Exploited Hard-Coded Password in Secure Firewall Management Center

Cisco fixed a high-severity vulnerability (CVE-2026-20316) in Secure Firewall Management Center that allows unauthenticated remote attackers to log in using hard-coded credentials. CISA added the flaw to its KEV catalog following reports of zero-day exploitation targeting network security infrastructure.

**Make sure your Cisco Secure Firewall Management Center (FMC) is isolated from the internet and only reachable from trusted internal networks. Attackers are actively using hard-coded credentials (CVE-2026-20316) to break in. Apply Cisco's hotfix immediately (CISA requires it by August 1, 2026), and check your management logs for suspicious entries mentioning /var/tmp/license.tmp to spot any break-in.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

oversecurity@mastodon.social at 2026-07-29T22:20:25.000Z ##

Cisco warns of FMC static credential flaw exploited in zero-day attacks

Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was...

🔗️ [Bleepingcomputer] link.is.it/AKCr32

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T21:44:32.000Z ##

A Cisco FMC vulnerability, CVE-2026-20316, is exploited in the wild. Static credentials let attackers log in. CISA added it to KEV — patch now.

#Cisco #CVE202620316 #FMC #KEV #Vulnerability #InfoSec

securityonline.info/cisco-fmc-

##

secdb@infosec.exchange at 2026-07-29T21:00:20.000Z ##

🚨 [CISA-2026:0729] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-20316 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Management Center (FMC)
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260729 #cisa20260729 #cve_2026_20316 #cve202620316

##

cisakevtracker@mastodon.social at 2026-07-29T20:00:46.000Z ##

CVE ID: CVE-2026-20316
Vendor: Cisco
Product: Secure Firewall Management Center (FMC)
Date Added: 2026-07-29
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-07-29T17:36:00.000Z ##

New Cisco updates:

CRITICAL vulnerability, first released on March 4: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi

High severity: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability sec.cloudapps.cisco.com/securi

New informational advisory: Cisco Advance Notification for Publication of August 5, 2026, Security Advisories sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #vulnerability #Cisco

##

CVE-2026-17566
(9.9 CRITICAL)

EPSS: 0.43%

updated 2026-08-01T05:16:55.827000

2 posts

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (...) wrapper, create_import_export_job() (route POST /import_export/job/<sid>, gated only by the ordinary, commonly-granted tools_import_export_data permission)

hugovalters@mastodon.social at 2026-08-01T15:04:27.000Z ##

CVE-2026-17566 - Critical RCE in pgAdmin 4. Import/Export Data tool allows command injection via crafted SQL. CVSS 9.9. Unpatched - restrict access immediately. #CVE #pgAdmin #infosec

valtersit.com/cve/CVE-2026-175

##

thehackerwire@mastodon.social at 2026-07-31T17:00:30.000Z ##

🔴 CVE-2026-17566 - Critical (9.9)

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (...) wra...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15006
(7.5 HIGH)

EPSS: 0.83%

updated 2026-08-01T03:16:25.460000

4 posts

The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via the processAttachment function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

thehackerwire@mastodon.social at 2026-08-01T13:00:29.000Z ##

🟠 CVE-2026-15006 - High (7.5)

The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via the processAttachment function. This makes it p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-01T04:30:24.944Z ##

CVE-2026-15006: Bit integrations plugin ≤2.9.0 for WordPress has a HIGH severity path traversal flaw (CVSS 7.5). Unauthenticated attackers can read arbitrary server files. No patch yet — disable or restrict plugin. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-01T13:00:29.000Z ##

🟠 CVE-2026-15006 - High (7.5)

The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via the processAttachment function. This makes it p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-01T04:30:24.000Z ##

CVE-2026-15006: Bit integrations plugin ≤2.9.0 for WordPress has a HIGH severity path traversal flaw (CVSS 7.5). Unauthenticated attackers can read arbitrary server files. No patch yet — disable or restrict plugin. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln

##

CVE-2026-62246
(8.5 HIGH)

EPSS: 0.27%

updated 2026-08-01T00:17:17.480000

1 posts

Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() and GetDefaultDatastoreUsername(), allowing distinct tenants with colliding normalized identifiers to share control-plane state and read, modify, or dest

thehackerwire@mastodon.social at 2026-07-30T23:00:02.000Z ##

🟠 CVE-2026-62246 - High (8.5)

Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61536
(7.5 HIGH)

EPSS: 0.30%

updated 2026-07-31T23:17:25.930000

1 posts

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered body of {% completion %} blocks and later resolves their import_path field through importlib.import_module(...) + getattr(...) to obtain the callable that handles a tool call. There is no allowlist or sanitization on import_path, so any importable Py

thehackerwire@mastodon.social at 2026-07-30T20:00:25.000Z ##

🟠 CVE-2026-61536 - High (7.5)

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered body of {% completion %} blocks and later resolves their import_path field through importlib.impo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44106
(7.8 HIGH)

EPSS: 0.23%

updated 2026-07-31T23:17:24.103000

2 posts

A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

thehackerwire@mastodon.social at 2026-07-30T10:00:11.000Z ##

🟠 CVE-2026-44106 - High (7.8)

A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44101
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-07-31T23:17:23.970000

1 posts

Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44091
(9.1 CRITICAL)

EPSS: 0.33%

updated 2026-07-31T23:17:23.707000

1 posts

An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system configuration. This may lead to integrity and availability loss.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-68771
(9.8 CRITICAL)

EPSS: 0.62%

updated 2026-07-31T22:17:03.630000

3 posts

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. Attackers can upload a malicious shard_*.pkl file via the unauthenticated POST /upload/image endpoint and then queue a workflow graph via POST /prompt ref

hugovalters@mastodon.social at 2026-08-01T17:11:42.000Z ##

CVE-2026-68771 - Critical RCE in ComfyUI. Unsafe deserialization in LoadTrainingDataset. CVSS 9.8. No patch; stop using /upload/image and /prompt. #CVE #ComfyUI #infosec

valtersit.com/cve/CVE-2026-687

##

thehackerwire@mastodon.social at 2026-07-31T23:00:42.000Z ##

🔴 CVE-2026-68771 - Critical (9.8)

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. A...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-31T22:30:29.000Z ##

CVE-2026-68771: CRITICAL RCE in ComfyUI v0.23.0. Unauthenticated remote attackers can exploit unsafe pickle deserialization via /upload/image, leading to code execution as the process user. Restrict access & monitor endpoints. radar.offseq.com/threat/cve-20 #OffSeq #CVE202668771 #infosec

##

CVE-2026-53599
(7.5 HIGH)

EPSS: 0.31%

updated 2026-07-31T22:17:03.213000

1 posts

REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/mediapool.php lets an authenticated backend user with media[upload] permission upload a JPEG/PHP polyglot named shell.php.any.jpg, which web servers with multi-extension PHP handlers can execute as the web-server user. This issue is fixed in version 5.21.1

thehackerwire@mastodon.social at 2026-07-31T21:00:10.000Z ##

🟠 CVE-2026-53599 - High (7.5)

REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/mediapool.php lets an authenticated backend user with media[upload] permission upload a JPEG/PHP polygl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68770
(9.8 CRITICAL)

EPSS: 0.52%

updated 2026-07-31T21:17:32.440000

3 posts

sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, where the guard condition includes an 'or os.path.exists(model_name_or_path)' clause that satisfies the trust gate whenever the supplied path exists on the local files

offseq at 2026-08-01T00:00:35.281Z ##

CVE-2026-68770: Hugging Face sentence-transformers (all versions) impacted by CRITICAL code injection vuln. Local model dirs with malicious files can bypass trust_remote_code=False — arbitrary Python execution possible. Awaiting patch. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-01T00:00:35.000Z ##

CVE-2026-68770: Hugging Face sentence-transformers (all versions) impacted by CRITICAL code injection vuln. Local model dirs with malicious files can bypass trust_remote_code=False — arbitrary Python execution possible. Awaiting patch. radar.offseq.com/threat/cve-20 #OffSeq #CVE #AIsecurity

##

thehackerwire@mastodon.social at 2026-07-31T22:00:02.000Z ##

🔴 CVE-2026-68770 - Critical (9.8)

sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, where the guar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67207
(8.8 HIGH)

EPSS: 0.30%

updated 2026-07-31T20:16:54.253000

1 posts

Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users to access restricted backup functionality due to a PHP operator precedence flaw in the permission check expression. Attackers can exploit the incorrect evaluation of the access control expression to create, download, and restore backups without admin

thehackerwire@mastodon.social at 2026-07-30T21:00:17.000Z ##

🟠 CVE-2026-67207 - High (8.8)

Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users to access restricted backup functionality due to a PHP operator precedence flaw in the permission...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52855
(9.9 CRITICAL)

EPSS: 0.27%

updated 2026-07-31T20:16:51.173000

1 posts

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{config.token_id}}, and {{config.docker.registries}} from the full daemon configuration. This issue is fixed in version 1.12.3.

hugovalters@mastodon.social at 2026-08-01T11:04:52.000Z ##

CVE-2026-52855 - Critical SSTI in Wings (Pterodactyl). Low-priv user can read daemon config tokens via {{config.}} in egg templates. CVSS 9.9. Update to 1.12.3 immediately. #CVE #infosec #Pterodactyl

valtersit.com/cve/CVE-2026-528

##

CVE-2026-18358
(7.5 HIGH)

EPSS: 0.43%

updated 2026-07-31T20:16:49.663000

2 posts

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP listener. This can accumulate accepted sockets and pending routing-token operations

hugovalters@mastodon.social at 2026-08-01T12:08:40.000Z ##

CVE-2026-18358 - DoS in Gnome-Remote-Desktop on RHEL. Unauthenticated RDP flood exhausts resources, blocking legit sessions. CVSS 7.5. No patch yet; restrict RDP access. #CVE #infosec #Linux

valtersit.com/cve/CVE-2026-183

##

thehackerwire@mastodon.social at 2026-07-31T14:00:26.000Z ##

🟠 CVE-2026-18358 - High (7.5)

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote atta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52887
(10.0 CRITICAL)

EPSS: 0.59%

updated 2026-07-31T19:45:02

2 posts

## Summary `GET /api/myInAppChannels:list` accepts a structured `filter` query parameter. The handler for the `latestMsgReceiveTimestamp` field splices the `$lt` value directly into a `Sequelize.literal()` template string with no escape, type cast, or parameter binding. The action ACL is `loggedIn`, so any authenticated account reaches it. The default `auth-basic` authenticator ships `allowSignUp

offseq at 2026-08-01T01:30:26.673Z ##

CVE-2026-52887: @nocobase/plugin-notification-in-app-message <2.0.61 suffers CRITICAL SQL injection in /api/myInAppChannels:list, enabling RCE as PG superuser 🛡️. Patch to 2.0.61+, disable anonymous signup, restrict DB roles. radar.offseq.com/threat/plugin

##

offseq@infosec.exchange at 2026-08-01T01:30:26.000Z ##

CVE-2026-52887: @nocobase/plugin-notification-in-app-message <2.0.61 suffers CRITICAL SQL injection in /api/myInAppChannels:list, enabling RCE as PG superuser 🛡️. Patch to 2.0.61+, disable anonymous signup, restrict DB roles. radar.offseq.com/threat/plugin #OffSeq #CVE202652887 #AppSec

##

CVE-2026-53510
(8.1 HIGH)

EPSS: 0.40%

updated 2026-07-31T19:38:26

1 posts

### Impact `Savon::Model` generated SOAP operation methods by interpolating operation names into Ruby source passed to `module_eval`. An attacker who can control the operation names of a WSDL, can inject Ruby code that executes in the application process. This affects only the `.all_operations` class method provided by `Savon::Model` to automatically register all operations provided by the WSDL.

thehackerwire@mastodon.social at 2026-07-31T21:00:01.000Z ##

🟠 CVE-2026-53510 - High (8.1)

Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source passed to module_eval, allowing Ruby code execution in the application process. This issue is...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53505
(7.5 HIGH)

EPSS: 0.34%

updated 2026-07-31T19:17:10.123000

2 posts

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion(<value>) filter does not enforce an upper bound on <value> and runs in the post-transform phase. An attacker can trigger extremely large resizes (CPU/memory exhaustion) and cause denial of service. This issue is fixed in 7.8.0.

hugovalters@mastodon.social at 2026-08-01T14:11:07.000Z ##

CVE-2026-53505 - DoS in Thumbor. Unbounded proportion filter causes CPU/memory exhaustion. CVSS 7.5. Update to 7.8.0 immediately. #CVE #Thumbor #infosec

valtersit.com/cve/CVE-2026-535

##

thehackerwire@mastodon.social at 2026-07-31T23:00:51.000Z ##

🟠 CVE-2026-53505 - High (7.5)

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion() filter does not enforce an upper bound on and runs in the post-transform phase. An attacker can trigger extremely large resizes (CPU/me...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18141
(8.2 HIGH)

EPSS: 0.25%

updated 2026-07-31T19:17:08.053000

1 posts

A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by manipulating the event stream URL and forging the HTTP Subject header. The system also inadvertently discloses the expected certificate subject in error me

thehackerwire@mastodon.social at 2026-07-31T17:00:21.000Z ##

🟠 CVE-2026-18141 - High (8.2)

A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by ma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53500
(8.2 HIGH)

EPSS: 0.29%

updated 2026-07-31T18:36:05

1 posts

## Summary The `ALLOWED_SOURCES` configuration is meant to restrict which hosts Thumbor's HTTP loader may fetch images from. Plain-string entries in that list (the overwhelming majority of real-world and documented configurations) are passed directly to `re.match()` without escaping. Because `.` is a regex wildcard, every dot in a domain name becomes a bypass vector: `s.glbimg.com` silently match

thehackerwire@mastodon.social at 2026-07-31T23:01:00.000Z ##

🟠 CVE-2026-53500 - High (8.2)

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the allowlist. This issu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17347
(7.5 HIGH)

EPSS: 0.27%

updated 2026-07-31T18:32:24

1 posts

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implementation substituted the username directly into the command string and executed the result with subprocess.Popen(..., shell=True). Because the username can

thehackerwire@mastodon.social at 2026-07-31T17:00:41.000Z ##

🟠 CVE-2026-17347 - High (7.5)

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implement...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-10685
(7.6 HIGH)

EPSS: 0.18%

updated 2026-07-31T18:17:09.510000

1 posts

The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the application's params->subscribe() callback after it had already called params->notify(conn, params, NULL, 0). Per the public GATT API, a notify callback with NULL data is the documented signal that the subscription has terminated and the bt_gatt_subscribe_params struct may

offseq@infosec.exchange at 2026-07-31T15:30:25.000Z ##

Zephyr Bluetooth GATT client (versions 2.4.0 to <4.5.0) faces a HIGH severity use-after-free (CVE-2026-10685) in gatt_write_ccc_rsp(). Risk: memory corruption, crash, or attacker-driven flow. Patch pending — apply mitigations. radar.offseq.com/threat/cve-20 #OffSeq #Zephyr #Bluetooth #CVE

##

CVE-2026-54725
(9.6 CRITICAL)

EPSS: 0.32%

updated 2026-07-31T17:45:04

1 posts

## Summary The vault-secrets-webhook reads the `vault.security.banzaicloud.io/vault-addr` annotation from any ConfigMap or Secret being admitted and uses it as the Vault server address without any validation or allowlist. When a ConfigMap or Secret contains a value prefixed with `vault:`, the webhook's admission handler synchronously calls the Vault API at the attacker-supplied address from insid

offseq@infosec.exchange at 2026-07-31T19:30:25.000Z ##

bank-vaults vault-secrets-webhook is impacted by CVE-2026-54725 (CRITICAL, CVSS 9.6). SSRF flaw lets attackers exfiltrate ServiceAccount JWTs via attacker-controlled Vault addresses. Update to 1.23.1 ASAP. radar.offseq.com/threat/cve-20 #OffSeq #Kubernetes #SSRF #CloudSecurity

##

CVE-2026-68500
(7.5 HIGH)

EPSS: 0.38%

updated 2026-07-31T16:52:41

1 posts

### Impact The shop payment webhook `POST /{_locale}/update-payment` (route `sylius_mollie_shop_payment_webhook`) accepts two independent, attacker-controlled parameters: `id` (the Mollie payment ID, verified against Mollie's API) and `orderId` (the Sylius order ID, read directly from the database). The handler never verifies that the Mollie payment belongs to the referenced order. An

thehackerwire@mastodon.social at 2026-07-30T22:00:19.000Z ##

🟠 CVE-2026-68500 - High (7.5)

Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/update-payment payment webhook accepts attacker-controlled id and orderId parameters but doe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-6267
(8.5 HIGH)

EPSS: 0.34%

updated 2026-07-31T16:17:12.290000

2 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to insufficient access controls on internal request handling.

DailyCyberSecurity@infosec.exchange at 2026-07-30T03:11:14.000Z ##

The latest GitLab patch release fixes 13 vulnerabilities, including CVE-2026-6267, a high-severity data exposure flaw. Update self-managed GitLab now.

#GitLab #CVE20266267 #DevSecOps #Vulnerability #PatchNow #InfoSec

securityonline.info/gitlab-pat

##

thehackerwire@mastodon.social at 2026-07-29T20:59:50.000Z ##

🟠 CVE-2026-6267 - High (8.5)

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68503
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-07-31T16:17:12.183000

1 posts

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and core/payload_schema.py and passes them unchanged to lazyc2.py HTTP Basic authentication, allowing any network-reachable attacker who knows the defaults to authenticate to the C2 dashboard with operator-level access. This

thehackerwire@mastodon.social at 2026-07-30T22:00:38.000Z ##

🔴 CVE-2026-68503 - Critical (9.8)

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and core/payload_schema.py and passes them unchanged to lazyc2.py HTTP ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66360
(7.5 HIGH)

EPSS: 0.28%

updated 2026-07-31T16:17:10.493000

1 posts

The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A missing length check in the processing of the encoded presentation data allows an attacker controlled field with a zero length value to trigger a bounded heap over read. This condition occurs before MMS session establishment, a crafted TCP/102 connection attempt can trigger the

thehackerwire@mastodon.social at 2026-07-31T01:00:02.000Z ##

🟠 CVE-2026-66360 - High (7.5)

The ISO Presentation layer contains a flaw in the handling of specific
parameters during normal mode negotiation. A missing length check in the
processing of the encoded presentation data allows an attacker
controlled field with a zero length v...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63559
(7.5 HIGH)

EPSS: 0.43%

updated 2026-07-31T16:17:09.290000

1 posts

An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to read out-of-bounds heap memory, potentially disclosing sensitive information.

thehackerwire@mastodon.social at 2026-07-30T23:00:12.000Z ##

🟠 CVE-2026-63559 - High (7.5)

An integer overflow in the UA_Variant arrayDimensions product
computation in open62541 may allow a remote attacker to read
out-of-bounds heap memory, potentially disclosing sensitive information.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18157
(7.8 HIGH)

EPSS: 0.24%

updated 2026-07-31T16:17:05.520000

1 posts

A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen, to be misinterpreted as command options by apt-get. Successful exploitation could lead to remote code execution (RCE) with root privileges, enabling the

thehackerwire@mastodon.social at 2026-07-31T04:00:13.000Z ##

🟠 CVE-2026-18157 - High (7.8)

A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15435
(9.8 CRITICAL)

EPSS: 0.73%

updated 2026-07-31T16:16:58.413000

3 posts

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.

beyondmachines1 at 2026-08-01T09:01:03.653Z ##

IBM Patches Critical File Write and Command Injection Flaws in App Connect Enterprise

IBM fixed three vulnerabilities in App Connect Enterprise, including a critical path traversal flaw (CVE-2026-15435) that allows remote attackers to write arbitrary files and compromise systems. The updates also address OS command injection and unauthorized file read risks.

**If you run IBM App Connect Enterprise (versions 12.0.1.0–12.0.12.27 or 13.0.1.0–13.0.7.2), first make sure the system is isolated from the internet and reachable only from trusted networks. Then upgrade ASAP to v13 Fix Pack 13.0.8.0 or v12 Fix Pack 12.0.12.28.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-08-01T09:01:03.000Z ##

IBM Patches Critical File Write and Command Injection Flaws in App Connect Enterprise

IBM fixed three vulnerabilities in App Connect Enterprise, including a critical path traversal flaw (CVE-2026-15435) that allows remote attackers to write arbitrary files and compromise systems. The updates also address OS command injection and unauthorized file read risks.

**If you run IBM App Connect Enterprise (versions 12.0.1.0–12.0.12.27 or 13.0.1.0–13.0.7.2), first make sure the system is isolated from the internet and reachable only from trusted networks. Then upgrade ASAP to v13 Fix Pack 13.0.8.0 or v12 Fix Pack 12.0.12.28.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

phillip@social.lol at 2026-07-30T20:04:23.000Z ##

@nuintari I was curious how the results differed between Kagi and Startpage (and by proxy, Google) on this. Holy shit, @da_667 is right to be so upset.

Nothing on Startpage or Google’s first page is at all related. Ctrl + F for the CVE returns only the query in the search bar, and Google’s AI overview, which somehow has the right CVE and description, despite the fact that only one of its cited websites even mentions the actual CVE?

For their part, at least @kagihq has CVE Feed’s actual listing for CVE-2026-15435 as their second result, with Tenable and Feedly further down, but still on the first page of results. It’s still crazy that those aren’t the top three results and this should be better, but given how atrocious the competition is, at least it even found the right CVE at all

##

CVE-2026-10079
(8.5 HIGH)

EPSS: 0.17%

updated 2026-07-31T16:16:57.167000

1 posts

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to create Deployments can set this label to "null", causing ACS to treat the workload as having empty UID, name and labels and namespace "default". This bypas

thehackerwire@mastodon.social at 2026-07-31T12:00:33.000Z ##

🟠 CVE-2026-10079 - High (8.5)

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to cr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17561
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-07-31T15:32:58

4 posts

Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: before 6.4.108.

offseq at 2026-08-01T03:00:26.335Z ##

CVE-2026-17561: CRITICAL code injection vuln in Logsign SIEM <6.4.108 (CVSS 9.8). Allows unauthenticated RCE — full compromise possible. No patch confirmed. Restrict mgmt access pending fix. radar.offseq.com/threat/improp

##

offseq@infosec.exchange at 2026-08-01T03:00:26.000Z ##

CVE-2026-17561: CRITICAL code injection vuln in Logsign SIEM <6.4.108 (CVSS 9.8). Allows unauthenticated RCE — full compromise possible. No patch confirmed. Restrict mgmt access pending fix. radar.offseq.com/threat/improp #OffSeq #infosec #SIEM #vuln

##

thehackerwire@mastodon.social at 2026-07-31T14:00:16.000Z ##

🔴 CVE-2026-17561 - Critical (9.8)

Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection.

This issue affects Logsign SIEM: before 6.4.108.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-31T14:00:25.000Z ##

CVE-2026-17561: Logsign SIEM <6.4.108 faces CRITICAL code injection (CWE-94, CVSS 9.8). Exploitable remotely, no patch yet. Full system compromise possible. Monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE202617561 #SIEM #Vuln #BlueTeam

##

CVE-2026-63221
(9.4 CRITICAL)

EPSS: 0.38%

updated 2026-07-31T14:16:50.873000

1 posts

CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled condition values to be interpreted as SQL. This affects only the deleteBatch() code path. Regular delete() operations escape where() binds correctly. This issue is fixed i

AmmarSpaces@infosec.exchange at 2026-07-31T10:51:10.000Z ##

So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.

Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)

Did people still use CodeIgniter?

Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.

securityonline.info/codeignite

#cybersecurity #infosec #codeigniter #vulnerability

##

CVE-2026-63220
(4.8 MEDIUM)

EPSS: 0.14%

updated 2026-07-31T14:16:50.750000

1 posts

CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-Forwarded-Proto and Front-End-Https headers from any incoming request, allowing an attacker could spoof these headers and cause the application to incorrectly treat an HTTP request as secure. This may have impacted applications that rely on isSecure(), force_https(), forceGlobalSecu

AmmarSpaces@infosec.exchange at 2026-07-31T10:51:10.000Z ##

So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.

Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)

Did people still use CodeIgniter?

Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.

securityonline.info/codeignite

#cybersecurity #infosec #codeigniter #vulnerability

##

CVE-2026-11770
(7.5 HIGH)

EPSS: 0.51%

updated 2026-07-31T12:30:30

1 posts

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication

thehackerwire@mastodon.social at 2026-07-31T12:00:13.000Z ##

🟠 CVE-2026-11770 - High (7.5)

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15722
(7.5 HIGH)

EPSS: 0.51%

updated 2026-07-31T11:17:04.833000

1 posts

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a repl

thehackerwire@mastodon.social at 2026-07-31T12:00:23.000Z ##

🟠 CVE-2026-15722 - High (7.5)

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds chec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16236
(8.8 HIGH)

EPSS: 0.63%

updated 2026-07-31T09:31:30

1 posts

The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing file extension and content validation in the saveLiveImages() function combined with an insufficient authorization check on the get_keys() AJAX handler and a missing authentication check on the REST API import endpoint. This makes it possible for auth

hugovalters@mastodon.social at 2026-07-31T23:02:34.000Z ##

CVE-2026-16236 - Critical RCE in Realtyna Organic IDX WP plugin. Arbitrary file upload from subscriber-level. CVSS 8.8. No patch. Disable plugin now. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-162

##

CVE-2026-65313
(8.1 HIGH)

EPSS: 0.18%

updated 2026-07-31T09:31:19

1 posts

A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker with adjacent-network access who knows the password can gain VNC access to affected workstations.

thehackerwire@mastodon.social at 2026-07-31T14:00:39.000Z ##

🟠 CVE-2026-65313 - High (8.1)

A provisioning script used when installing HIPASE-250 (formerly 250
SCALA) engineering workstations sets a fixed, hard-coded x11vnc
password. Because the same credential is applied to every workstation
provisioned this way, an attacker with adjace...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-6102
(7.8 HIGH)

EPSS: 0.09%

updated 2026-07-31T04:17:24.730000

1 posts

MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MSI Center. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the NTIOLib_X64.sys driver. The issue

thehackerwire@mastodon.social at 2026-07-29T21:00:10.000Z ##

🟠 CVE-2026-6102 - High (7.8)

MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MSI Center. An attacker must first obtain the ability to execute...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66803
(10.0 CRITICAL)

EPSS: 0.49%

updated 2026-07-31T04:17:24.520000

1 posts

Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

offseq@infosec.exchange at 2026-07-31T01:30:24.000Z ##

Azure Cosmos DB suffers a CRITICAL improper access control vulnerability (CVE-2026-66803) allowing unauthorized remote code execution. No patch yet — restrict network access & monitor Microsoft advisories. radar.offseq.com/threat/improp #OffSeq #Azure #Vuln #CyberSecurity

##

CVE-2026-5490
(8.8 HIGH)

EPSS: 0.48%

updated 2026-07-31T04:17:24.013000

1 posts

DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of DriveLock. Authentication is required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 4568 by default. The issue results from the lack of proper validation of a user-supplied string befo

1 repos

https://github.com/HORKimhab/CVE-2026-54900

thehackerwire@mastodon.social at 2026-07-30T05:00:39.000Z ##

🟠 CVE-2026-5490 - High (8.8)

DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of DriveLock. Authentication is required to exploit this vulnerability.

The specific flaw exis...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58066
(9.8 CRITICAL)

EPSS: 0.21%

updated 2026-07-31T04:17:23.877000

1 posts

Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:Assertion. An attacker could submit a wrapped document carrying forged identity attributes alongside any valid signature made by the trusted IdP certificate, and log in as an arbitrary user.

thehackerwire@mastodon.social at 2026-07-30T07:00:31.000Z ##

🔴 CVE-2026-58066 - Critical (9.8)

Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:Assertion. An attacker could submit a wrapped docu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58043
(7.5 HIGH)

EPSS: 0.14%

updated 2026-07-31T04:17:23.737000

4 posts

A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**.

thehackerwire@mastodon.social at 2026-07-30T07:00:10.000Z ##

🟠 CVE-2026-58043 - High (7.5)

A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries.

Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T17:29:15.000Z ##

2026-07-29, Version 24.18.1 'Krypton' (LTS), @juanarbol

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:01.000Z ##

2026-07-29, Version 26.5.1 (Current), @RafaelGSS

This is a security release. Notable Changes (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:00.000Z ##

2026-07-29, Version 22.23.2 'Jod' (LTS), @marco-ippolito

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

CVE-2026-17543
(0 None)

EPSS: 0.39%

updated 2026-07-31T04:16:48.350000

1 posts

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

CVE-2026-12940
(9.8 CRITICAL)

EPSS: 0.48%

updated 2026-07-31T04:16:45.870000

1 posts

IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py where the DANGEROUS_ENV_VARS blocklist fails to include SHELLOPTS , BASHOPTS , and PS4 environment variables.

thehackerwire@mastodon.social at 2026-07-30T18:00:48.000Z ##

🔴 CVE-2026-12940 - Critical (9.8)

IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py whe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65423
(8.8 HIGH)

EPSS: 0.60%

updated 2026-07-31T00:30:29

1 posts

An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to trigger an out-of-bounds write.

thehackerwire@mastodon.social at 2026-07-31T04:00:36.000Z ##

🟠 CVE-2026-65423 - High (8.8)

An integer overflow in the UA_Variant arrayDimensions product
computation in open62541 may allow a remote attacker to trigger an
out-of-bounds write.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66421
(9.3 CRITICAL)

EPSS: 0.36%

updated 2026-07-31T00:30:29

1 posts

OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages processed through the sessions API. Attackers can craft a message containing inline event handler payloads such as an img tag with an onerror attribute with

thehackerwire@mastodon.social at 2026-07-31T01:00:25.000Z ##

🔴 CVE-2026-66421 - Critical (9.3)

OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages pro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66420
(8.8 HIGH)

EPSS: 0.17%

updated 2026-07-31T00:30:29

1 posts

MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the CheckWebServerOriginName() function within webserver.js when self-signed certificates are in use. Attackers can open cross-origin WebSocket connections to any of th

thehackerwire@mastodon.social at 2026-07-31T01:00:14.000Z ##

🟠 CVE-2026-66420 - High (8.8)

MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the CheckWebSer...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18064
(7.5 HIGH)

EPSS: 0.34%

updated 2026-07-31T00:30:29

1 posts

An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause the HS application to crash, resulting in a denial-of-service condition and processor reset.

thehackerwire@mastodon.social at 2026-07-30T23:00:23.000Z ##

🟠 CVE-2026-18064 - High (7.5)

An incomplete fix for CVE-2026-15352 in the NASA core Flight System
(cFS) Health and Safety (HS) application leaves a separate NULL pointer
dereference reachable in versions through 7.0.1. An attacker who can
trigger the affected command under ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63035
(8.1 HIGH)

EPSS: 0.57%

updated 2026-07-31T00:30:22

1 posts

A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code.

thehackerwire@mastodon.social at 2026-07-31T04:00:24.000Z ##

🟠 CVE-2026-63035 - High (8.1)

A heap use-after-free vulnerability in the TransferSubscriptions service
in open62541 may allow an authenticated attacker to cause a denial of
service or potentially execute arbitrary code.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67206
(8.8 HIGH)

EPSS: 0.44%

updated 2026-07-30T21:31:57

1 posts

Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file extension validation in the create_file() and save() functions. Attackers with the file_manager_mkfile capability can write malicious PHP content into the web-accessible FILES_DIR directory and trigger executio

thehackerwire@mastodon.social at 2026-07-30T21:00:08.000Z ##

🟠 CVE-2026-67206 - High (8.8)

Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file extension validation in the create_file() and save() func...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67594
(9.8 CRITICAL)

EPSS: 0.46%

updated 2026-07-30T21:31:57

1 posts

Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached CipiAuth middleware, which is registered but never applied to any route in the API routing configuration. Attackers can invoke approximately 50 unprotected API endpoints to enumerate and provision servers, reset root pass

thehackerwire@mastodon.social at 2026-07-30T20:59:58.000Z ##

🔴 CVE-2026-67594 - Critical (9.8)

Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached CipiAuth middleware, which is registered but never applied to any ro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66416
(8.8 HIGH)

EPSS: 0.16%

updated 2026-07-30T21:31:57

1 posts

Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform state-changing actions on behalf of authenticated users by excluding the Laravel VerifyCsrfToken middleware from the global middleware stack in app/Http/Kernel.php. Attackers can craft malicious pages delivered via phishing emails or malicious websites to trigger unauthorized POST, P

thehackerwire@mastodon.social at 2026-07-30T20:00:11.000Z ##

🟠 CVE-2026-66416 - High (8.8)

Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform state-changing actions on behalf of authenticated users by excluding the Laravel VerifyCsrfToken middleware from the global middlew...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66415
(8.5 HIGH)

EPSS: 0.28%

updated 2026-07-30T21:31:57

1 posts

Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal resources by passing unsanitized user-supplied filenames to file_get_contents() in the Blueprints::import() method without path validation. Attackers can submit crafted filenames containing URL wrappers or path traversal sequences through the JSON-RPC AP

thehackerwire@mastodon.social at 2026-07-30T20:00:00.000Z ##

🟠 CVE-2026-66415 - High (8.5)

Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal resources by passing unsanitized user-supplied filenames to file_get_contents() in the Blueprints::im...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13435
(9.9 CRITICAL)

EPSS: 0.29%

updated 2026-07-30T21:31:56

1 posts

IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.

thehackerwire@mastodon.social at 2026-07-30T20:01:35.000Z ##

🔴 CVE-2026-13435 - Critical (9.9)

IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17657
(8.3 HIGH)

EPSS: 0.36%

updated 2026-07-30T21:31:32

1 posts

Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

hrbrmstr@mastodon.social at 2026-07-31T12:22:30.000Z ##

Chrome CVE Report for the 2026-07-29 Stable channel: tbljrmp60k.joplinusercontent.c

Top vulnerability types: Inappropriate Implementation (34.5%), Insufficient Input Validation (19%), Use After Free (13.4%)

Most affected components: XR (36), Chrome for iOS (35), Input Handling (33), ANGLE Graphics (30)

Largest bounty: $36,000 — CVE-2026-17657 (Use after free in Navigation)

##

CVE-2026-18245
(9.0 CRITICAL)

EPSS: 0.52%

updated 2026-07-30T20:17:03.733000

1 posts

Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrary code in end-user browsers, developer machines, CI/CD environments, and server-side rendering contexts via crafted Studio component or theme schema values due to insufficient coverage and effectiveness of the input validation introduced for CVE-2025-

thehackerwire@mastodon.social at 2026-07-30T20:01:24.000Z ##

🔴 CVE-2026-18245 - Critical (9)

Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrary code in end-user browsers, developer machines, CI/CD environments, and server-side rendering con...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18140
(7.5 HIGH)

EPSS: 0.44%

updated 2026-07-30T20:17:03.400000

1 posts

Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes from every generated struct deserializer, might allow remote unauthenticated users to cause a denial of service (process abort via stack exhaustion) via a single small HTTP request containing deeply nested JSON to a smithy-rs generated server. To rem

thehackerwire@mastodon.social at 2026-07-30T20:01:11.000Z ##

🟠 CVE-2026-18140 - High (7.5)

Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes from every generated struct deserializer, might allow remote unauthenticated users to cause a denial...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67432
(7.5 HIGH)

EPSS: 0.44%

updated 2026-07-30T19:30:33.710000

1 posts

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem reads and parses an entire JSON-RPC POST body without a size limit, allowing an unauthenticated remote attacker to exhaust process memory. This issue is fixed in version 0.23.0.

thehackerwire@mastodon.social at 2026-07-29T21:00:00.000Z ##

🟠 CVE-2026-67432 - High (7.5)

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem reads and parses an entire JSON-RPC POST body without a size limit, allowing an ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62663
(7.5 HIGH)

EPSS: 0.34%

updated 2026-07-30T19:26:51.190000

1 posts

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filters (image, audio, video, document) in banks accept untrusted user input as file paths via Path(value) and pass them directly to open(file_path, "rb") without any path sanitization, canonicalization, or directory restriction. An attacker who controls template variables passed to

thehackerwire@mastodon.social at 2026-07-30T18:00:38.000Z ##

🟠 CVE-2026-62663 - High (7.5)

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filters (image, audio, video, document) in banks accept untrusted user input as file paths via Path(value) and pass them directly t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67437
(7.5 HIGH)

EPSS: 0.35%

updated 2026-07-30T19:21:23.297000

1 posts

OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_auth_oauth2.go OAuth2 login handler stores per-login state in the registeredStates map on every /oauth/login request without expiring, deleting, or bounding entries, allowing an unauthenticated attacker to exhaust memory and cause a denial of service. T

thehackerwire@mastodon.social at 2026-07-29T21:59:48.000Z ##

🟠 CVE-2026-67437 - High (7.5)

OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_auth_oauth2.go OAuth2 login handler stores per-login state in the registeredStates map on every /oau...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16771
(8.8 HIGH)

EPSS: 0.25%

updated 2026-07-30T19:10:06.847000

1 posts

In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management endpoints, relying solely on client‑side CSS/JavaScript gating that can be bypassed by any HTTP client. This allows unauthenticated attackers on the LAN to read sensitive configuration data, modify persistent device settings, or trigger backend diagno

CVE-2026-28323
(9.8 CRITICAL)

EPSS: 0.64%

updated 2026-07-30T18:31:47

3 posts

SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.

beyondmachines1 at 2026-08-01T08:01:04.472Z ##

SolarWinds Patches Critical SAML Bypass and pgAdmin4 RCE in Web Help Desk

SolarWinds released Web Help Desk 2026.2.1 to address eight vulnerabilities, including a critical SAML authentication bypass (CVE-2026-28323) and multiple remote code execution flaws in pgAdmin4.

**Update SolarWinds Web Help Desk to version 2026.2.1 ASAP to fix a critical authentication bypass and multiple remote code execution flaws that could give attackers full control of your help desk and connected databases. Before upgrading, switch from Servlet authentication to SAML 2.0 or HTTP Header authentication. If possible for your process, keep the platform isolated on trusted internal networks.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-08-01T08:01:04.000Z ##

SolarWinds Patches Critical SAML Bypass and pgAdmin4 RCE in Web Help Desk

SolarWinds released Web Help Desk 2026.2.1 to address eight vulnerabilities, including a critical SAML authentication bypass (CVE-2026-28323) and multiple remote code execution flaws in pgAdmin4.

**Update SolarWinds Web Help Desk to version 2026.2.1 ASAP to fix a critical authentication bypass and multiple remote code execution flaws that could give attackers full control of your help desk and connected databases. Before upgrading, switch from Servlet authentication to SAML 2.0 or HTTP Header authentication. If possible for your process, keep the platform isolated on trusted internal networks.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

DailyCyberSecurity@infosec.exchange at 2026-07-31T02:53:50.000Z ##

A SolarWinds Web Help Desk SAML authentication bypass, CVE-2026-28323, scores a critical CVSS 9.8. Update to 2026.2.1 to stay protected.

#SolarWinds #WebHelpDesk #CVE202628323 #SAML #InfoSec

securityonline.info/solarwinds

##

CVE-2026-9322
(7.5 HIGH)

EPSS: 0.30%

updated 2026-07-30T18:31:47

1 posts

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.

thehackerwire@mastodon.social at 2026-07-30T18:00:27.000Z ##

🟠 CVE-2026-9322 - High (7.5)

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67595
(8.1 HIGH)

EPSS: 0.42%

updated 2026-07-30T16:45:00.353000

3 posts

VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders the affected email template with JavaScript enabled. The payload establishes a WebSocket connection to a hardcoded command-and-control endpoint, install

DarkWebInformer@infosec.exchange at 2026-07-30T19:58:19.000Z ##

🚨 CVE-2026-67595: VaahCMS 2.0.0-2.3.4 contains malicious obfuscated JavaScript in an OTP email template that can connect to a C2 server, log passwords, scrape WhatsApp Web, and remotely alter pages.

Published: 2026-07-29

CVSS 4.0: 9.2
CVSS 3.1: 8.1
Exploitability Score: 2.2

Commit: github.com/webreinvent/vaahcms

##

offseq@infosec.exchange at 2026-07-30T00:00:36.000Z ##

CVE-2026-67595 (CRITICAL): VaahCMS 2.0.0 – 2.3.4 ships with malicious JS in OTP email templates. Enables C2, keylogging, WhatsApp scraping, and remote page control. Avoid JS-enabled viewing until patched. radar.offseq.com/threat/cve-20 #OffSeq #Infosec #CVE202667595 #VaahCMS

##

thehackerwire@mastodon.social at 2026-07-29T23:59:49.000Z ##

🟠 CVE-2026-67595 - High (8.1)

VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67428
(8.5 HIGH)

EPSS: 0.34%

updated 2026-07-30T16:41:25.650000

1 posts

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules including src/core/modules/third_party/developer/http/requests.py, core.api.http_get, core.api.http_post, graphql.query, graphql.mutation, monitor.http_check, communication.slack_send, notification.discord.send_message, notification.slack.send_message, notification.teams.send_message, a

thehackerwire@mastodon.social at 2026-07-29T20:00:14.000Z ##

🟠 CVE-2026-67428 - High (8.5)

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules including src/core/modules/third_party/developer/http/requests.py, core.api.http_get, core.api.http_post, graphql.query, graphql.mutat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56850
(4.1 MEDIUM)

EPSS: 0.08%

updated 2026-07-30T16:33:59.580000

1 posts

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:01.000Z ##

2026-07-29, Version 26.5.1 (Current), @RafaelGSS

This is a security release. Notable Changes (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX...

github.com/nodejs/node/release

#nodejs #javascript

##

CVE-2026-44102
(5.3 MEDIUM)

EPSS: 0.21%

updated 2026-07-30T16:17:11.877000

1 posts

An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid firmware file. This will cause the file to remain accessible for a short period before it is deleted due to improper locking during the cleanup process.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-47876
(9.3 CRITICAL)

EPSS: 0.28%

updated 2026-07-30T15:31:54

3 posts

VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.

security_crawler_carl at 2026-08-01T02:24:33.862Z ##

🏆 New Achievement! I'll Go Ahead And Escape Your VM For You!

Thank you for contacting VMware support. I see you've opened a ticket regarding CVE-2026-59309 and CVE-2026-59310, both scoring a casual 9.8 on vCenter, plus CVE-2026-47876, a 9.3-rated VMXNET3 guest-to-host escape. Per our knowledge base, I've gone ahead and granted attackers authentication bypass and full VM escape capabilities. Have you tried turning it off and not turning it back on? (1/2)

##

security_crawler_carl@infosec.exchange at 2026-08-01T02:24:33.000Z ##

🏆 New Achievement! I'll Go Ahead And Escape Your VM For You!

Thank you for contacting VMware support. I see you've opened a ticket regarding CVE-2026-59309 and CVE-2026-59310, both scoring a casual 9.8 on vCenter, plus CVE-2026-47876, a 9.3-rated VMXNET3 guest-to-host escape. Per our knowledge base, I've gone ahead and granted attackers authentication bypass and full VM escape capabilities. Have you tried turning it off and not turning it back on? (1/2)

##

offseq@infosec.exchange at 2026-07-30T13:30:31.000Z ##

CRITICAL vuln: CVE-2026-47876 in VMware Cloud Foundation (9.1.x.x/9.0.x.x/5.x) allows VM admin to execute code on host via VMXNET3 adapter. Restrict admin access, use other adapters if possible. Patch not yet available. radar.offseq.com/threat/cve-20 #OffSeq #VMware #InfoSec #CVE202647876

##

CVE-2026-59309
(9.8 CRITICAL)

EPSS: 0.74%

updated 2026-07-30T15:31:54

2 posts

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

security_crawler_carl at 2026-08-01T02:24:33.862Z ##

🏆 New Achievement! I'll Go Ahead And Escape Your VM For You!

Thank you for contacting VMware support. I see you've opened a ticket regarding CVE-2026-59309 and CVE-2026-59310, both scoring a casual 9.8 on vCenter, plus CVE-2026-47876, a 9.3-rated VMXNET3 guest-to-host escape. Per our knowledge base, I've gone ahead and granted attackers authentication bypass and full VM escape capabilities. Have you tried turning it off and not turning it back on? (1/2)

##

security_crawler_carl@infosec.exchange at 2026-08-01T02:24:33.000Z ##

🏆 New Achievement! I'll Go Ahead And Escape Your VM For You!

Thank you for contacting VMware support. I see you've opened a ticket regarding CVE-2026-59309 and CVE-2026-59310, both scoring a casual 9.8 on vCenter, plus CVE-2026-47876, a 9.3-rated VMXNET3 guest-to-host escape. Per our knowledge base, I've gone ahead and granted attackers authentication bypass and full VM escape capabilities. Have you tried turning it off and not turning it back on? (1/2)

##

CVE-2026-59310
(9.8 CRITICAL)

EPSS: 1.14%

updated 2026-07-30T15:31:51

2 posts

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

security_crawler_carl at 2026-08-01T02:24:33.862Z ##

🏆 New Achievement! I'll Go Ahead And Escape Your VM For You!

Thank you for contacting VMware support. I see you've opened a ticket regarding CVE-2026-59309 and CVE-2026-59310, both scoring a casual 9.8 on vCenter, plus CVE-2026-47876, a 9.3-rated VMXNET3 guest-to-host escape. Per our knowledge base, I've gone ahead and granted attackers authentication bypass and full VM escape capabilities. Have you tried turning it off and not turning it back on? (1/2)

##

security_crawler_carl@infosec.exchange at 2026-08-01T02:24:33.000Z ##

🏆 New Achievement! I'll Go Ahead And Escape Your VM For You!

Thank you for contacting VMware support. I see you've opened a ticket regarding CVE-2026-59309 and CVE-2026-59310, both scoring a casual 9.8 on vCenter, plus CVE-2026-47876, a 9.3-rated VMXNET3 guest-to-host escape. Per our knowledge base, I've gone ahead and granted attackers authentication bypass and full VM escape capabilities. Have you tried turning it off and not turning it back on? (1/2)

##

CVE-2026-1360
(7.5 HIGH)

EPSS: 0.57%

updated 2026-07-30T15:16:31.530000

1 posts

The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` parameter on user-controlled XProfile field data. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject ar

thehackerwire@mastodon.social at 2026-07-30T06:00:17.000Z ##

🟠 CVE-2026-1360 - High (7.5)

The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67429
(10.0 CRITICAL)

EPSS: 0.49%

updated 2026-07-30T14:46:44

1 posts

## Summary `image.download` fetches a URL and writes the response to disk. It does not use the central path guard (`validate_path_with_env_config`, which confines writes to `FLYTO_SANDBOX_DIR`); instead it confines the output to `output_dir`, but `output_dir` is itself a caller parameter. Since the attacker sets both the target and the base it is checked against, the check is meaningless, and att

thehackerwire@mastodon.social at 2026-07-29T20:00:25.000Z ##

🔴 CVE-2026-67429 - Critical (10)

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config and its FLYTO_SANDBOX_DIR confinem...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44108
(9.8 CRITICAL)

EPSS: 0.46%

updated 2026-07-30T14:31:21.447000

2 posts

Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to connect to these services, resulting in full system compromise.

thehackerwire@mastodon.social at 2026-07-30T10:00:30.000Z ##

🔴 CVE-2026-44108 - Critical (9.8)

Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an un...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44105
(6.6 MEDIUM)

EPSS: 0.09%

updated 2026-07-30T14:31:21.447000

1 posts

The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local attacker with access to the logs to authenticate via SSH as the limited user "user-app". Charging could be interrupted.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44098
(8.6 HIGH)

EPSS: 1.37%

updated 2026-07-30T14:31:21.447000

1 posts

This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44100
(9.4 CRITICAL)

EPSS: 0.28%

updated 2026-07-30T14:31:21.447000

1 posts

The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44093
(7.8 HIGH)

EPSS: 0.23%

updated 2026-07-30T14:31:21.447000

1 posts

A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-5057
(7.5 HIGH)

EPSS: 0.48%

updated 2026-07-30T14:19:24.857000

1 posts

ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ATEN Unizon. Authentication is not required to exploit this vulnerability. The specific flaw exists within the RpcProvider class. The issue results from the lack of authentication prior to allowing access to

thehackerwire@mastodon.social at 2026-07-30T02:00:44.000Z ##

🟠 CVE-2026-5057 - High (7.5)

ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ATEN Unizon. Authentication is not required to exploit ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5491
(7.5 HIGH)

EPSS: 1.54%

updated 2026-07-30T14:18:46.477000

1 posts

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 6067 by default. The issue results from the lack of proper validation of a us

thehackerwire@mastodon.social at 2026-07-30T02:00:18.000Z ##

🟠 CVE-2026-5491 - High (7.5)

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability.
...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15975
(7.5 HIGH)

EPSS: 0.39%

updated 2026-07-30T14:15:31.167000

1 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to insufficient resource throttling when processing merge request discussions.

thehackerwire@mastodon.social at 2026-07-30T05:00:49.000Z ##

🟠 CVE-2026-15975 - High (7.5)

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14529
(9.4 CRITICAL)

EPSS: 0.33%

updated 2026-07-30T14:08:40.373000

2 posts

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.

DailyCyberSecurity@infosec.exchange at 2026-07-31T01:02:48.000Z ##

Four IBM WebSphere vulnerabilities are fixed, including a 9.8 pre-auth RCE (CVE-2026-14512) and a 9.4 SSRF (CVE-2026-14529). Patch now.

#IBMWebSphere #CVE202614512 #SSRF #RCE #Vulnerability #InfoSec

securityonline.info/ibm-websph

##

offseq@infosec.exchange at 2026-07-30T06:00:24.000Z ##

CRITICAL SSRF vuln (CVE-2026-14529) in IBM WebSphere App Server 9.0, 8.5, and Liberty 17.0.0.3 – 26.0.0.8 if SIP (sipServlet-1.1) is enabled. Review SIP use, disable if possible. Details: radar.offseq.com/threat/ibm-we #OffSeq #IBM #WebSphere #SSRF #CVE202614529

##

CVE-2026-14270
(8.8 HIGH)

EPSS: 0.55%

updated 2026-07-30T14:01:30.413000

1 posts

The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing authorization and nonce validation in the eco_save_settings() function, which allows low-privileged authenticated users to modify the tc_eco_custom_file_types upload allowlist setting,

thehackerwire@mastodon.social at 2026-07-29T15:00:33.000Z ##

🟠 CVE-2026-14270 - High (8.8)

The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing authorization and nonce validati...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18363(CVSS UNKNOWN)

EPSS: 0.30%

updated 2026-07-30T12:32:26

1 posts

A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.8 and v1.18.4. During the password reset process, the application retrieves the timestamp associated with the provided token and checks whether the configured validity period has expired. Consequently, the expiry check is only performed if the timestamp lookup fails, allowing tok

offseq@infosec.exchange at 2026-07-30T12:00:27.000Z ##

CVE-2026-18363: osTicket <1.17.8 & <1.18.4 has a CRITICAL flaw (CVSS 9.1) in password reset logic — tokens can be reused, risking account takeover. Upgrade when patch is available, monitor resets, and restrict token access. radar.offseq.com/threat/cve-20 #OffSeq #osTicket #CVE202618363

##

CVE-2026-64560
(7.8 HIGH)

EPSS: 0.12%

updated 2026-07-30T12:19:03.630000

1 posts

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwoo decoded and reported a non-leader exec() related race which can result in an UAF: sys_timer_delete() exec() posix_cpu_timer_del() // Observes old leader p = pid_task(pid, pid_type); de_thread() switch_leader(); release

CVE-2026-44107
(7.5 HIGH)

EPSS: 0.31%

updated 2026-07-30T09:31:24

2 posts

A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.

thehackerwire@mastodon.social at 2026-07-30T10:00:21.000Z ##

🟠 CVE-2026-44107 - High (7.5)

A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Deni...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-7849
(9.8 CRITICAL)

EPSS: 0.42%

updated 2026-07-30T09:31:24

2 posts

Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root.

offseq@infosec.exchange at 2026-07-30T07:30:24.000Z ##

Phoenix Contact CHARX SEC-3150 v1.0.0 hit by CRITICAL (CVSS 9.3) command injection (CVE-2026-7849): unauthenticated remote attackers can execute root commands. No mitigation yet — restrict access! radar.offseq.com/threat/cve-20 #OffSeq #ICS #Vuln #CVE2026_7849

##

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44094
(8.6 HIGH)

EPSS: 0.26%

updated 2026-07-30T09:31:24

1 posts

An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configuration including default credentials. This could allow the attacker to gain SSH access to the system as an unprivileged user "user-app". Charging could be interrupted.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44090
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-07-30T09:31:24

1 posts

Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the device being fully compromised.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44104
(9.8 CRITICAL)

EPSS: 0.24%

updated 2026-07-30T09:31:24

1 posts

The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44095
(7.8 HIGH)

EPSS: 0.23%

updated 2026-07-30T09:31:24

1 posts

A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44103
(5.3 MEDIUM)

EPSS: 0.24%

updated 2026-07-30T09:31:24

1 posts

An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware updates without performing integrity or verification check. Successful exploitation may compromise the integrity of the affected device. This vulnerability could be used in chain with CVE-2026-44104.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44092
(9.1 CRITICAL)

EPSS: 0.38%

updated 2026-07-30T09:31:24

1 posts

An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44096
(7.8 HIGH)

EPSS: 0.23%

updated 2026-07-30T09:31:18

1 posts

A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compromise.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44099
(7.8 HIGH)

EPSS: 0.23%

updated 2026-07-30T09:31:18

1 posts

A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44097
(7.1 HIGH)

EPSS: 0.24%

updated 2026-07-30T09:31:18

1 posts

A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in persistent storage of attacker-controlled files and potentially exhausting resources, which might lead to Denial-of-Service.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-58046
(9.9 CRITICAL)

EPSS: 0.31%

updated 2026-07-30T06:32:44

1 posts

Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.

thehackerwire@mastodon.social at 2026-07-30T07:00:21.000Z ##

🔴 CVE-2026-58046 - Critical (9.9)

Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16610
(9.8 CRITICAL)

EPSS: 0.58%

updated 2026-07-30T06:32:44

2 posts

The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a publicly emitted nonce with no authentication check, CAPTCHA validation is bypassable by omitting an attacker-supplied key, and repeater row keys from cfgroup[input

thehackerwire@mastodon.social at 2026-07-30T06:00:07.000Z ##

🔴 CVE-2026-16610 - Critical (9.8)

The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a publicly em...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-30T04:30:24.000Z ##

CVE-2026-16610: ASE Pro plugin (≤8.9.0) for WordPress suffers CRITICAL RCE via recursive_html. Unauth attackers can execute code if [post_cf_form] is public. Update/disable plugin ASAP. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE2026_16610 #Security

##

CVE-2026-14356
(8.8 HIGH)

EPSS: 0.27%

updated 2026-07-30T06:32:43

1 posts

The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the email address and password of any WordPress user, including administrat

thehackerwire@mastodon.social at 2026-07-30T06:00:27.000Z ##

🟠 CVE-2026-14356 - High (8.8)

The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48449
(10.0 CRITICAL)

EPSS: 0.54%

updated 2026-07-30T03:31:28

3 posts

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Analyst207@mastodon.social at 2026-08-01T07:24:36.000Z ##

Adobe Patches CVSS 10.0 Flaw in Campaign Classic

Adobe has patched a critical flaw in Campaign Classic, a vulnerability rated 10.0 on the CVSS scale that could allow attackers to run malicious code without user interaction. This maximum-severity issue, tracked as CVE-2026-48449, enables arbitrary code execution with the privileges of the current user.

osintsights.com/adobe-patches-

#AdobeCampaignClassic #Cve202648449 #ArbitraryCodeExecution #IncorrectauthorizationFlaw #Cvss100

##

DailyCyberSecurity@infosec.exchange at 2026-07-31T02:41:48.000Z ##

Adobe Campaign Classic flaw CVE-2026-48449 scores a perfect CVSS 10.0 and allows arbitrary code execution. Update to build 9398 now.

#AdobeCampaignClassic #CVE202648449 #RCE #Adobe #InfoSec

securityonline.info/adobe-camp

##

thehackerwire@mastodon.social at 2026-07-30T04:00:14.000Z ##

🔴 CVE-2026-48449 - Critical (10)

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48448
(8.6 HIGH)

EPSS: 0.37%

updated 2026-07-30T03:31:28

1 posts

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to gain file system read access. Exploitation of this issue does not require user interaction. Scope is changed.

thehackerwire@mastodon.social at 2026-07-30T04:00:03.000Z ##

🟠 CVE-2026-48448 - High (8.6)

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to g...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16727(CVSS UNKNOWN)

EPSS: 0.09%

updated 2026-07-30T03:31:28

1 posts

Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows a local user to execute arbitrary code with elevated privileges via a crafted file replacement. Refer to the ' Security Update for ASUS Armoury Crate ' section on the ASUS Security Advisory for more information.

offseq@infosec.exchange at 2026-07-30T03:00:24.000Z ##

CVE-2026-16727 (HIGH): Race condition in ASUS Armoury Crate 5.4.1 lets local users escalate privileges via improper synchronization. No patch available. Limit local access & monitor systems. radar.offseq.com/threat/cve-20 #OffSeq #CVE202616727 #ASUS #Vuln

##

CVE-2026-5056
(7.8 HIGH)

EPSS: 0.43%

updated 2026-07-29T21:31:08

1 posts

GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of UncompressedFrameConfigBox

thehackerwire@mastodon.social at 2026-07-30T02:00:30.000Z ##

🟠 CVE-2026-5056 - High (7.8)

GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13308
(8.1 HIGH)

EPSS: 0.57%

updated 2026-07-29T21:31:08

1 posts

Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of WebSocket messages related to the OCPP service.

thehackerwire@mastodon.social at 2026-07-29T21:59:57.000Z ##

🟠 CVE-2026-13308 - High (8.1)

Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authen...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5487
(7.5 HIGH)

EPSS: 1.54%

updated 2026-07-29T21:31:07

1 posts

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 4568 by default. The issue results from the lack of proper validation of a us

thehackerwire@mastodon.social at 2026-07-30T05:00:28.000Z ##

🟠 CVE-2026-5487 - High (7.5)

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability.
...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67201
(8.6 HIGH)

EPSS: 0.39%

updated 2026-07-29T21:31:07

1 posts

V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows attackers to circumvent host-based allowlists by exploiting a parser differential between net.urllib and net.http. Attackers can craft a URL containing a backslash in the authority section such that net.urllib.parse() extracts the trusted host for allowlist validation while net.

thehackerwire@mastodon.social at 2026-07-29T20:00:35.000Z ##

🟠 CVE-2026-67201 - High (8.6)

V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows attackers to circumvent host-based allowlists by exploiting a parser differential between net.urllib and net.http. Attackers c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61511
(9.8 CRITICAL)

EPSS: 1.27%

updated 2026-07-29T20:17:10.347000

2 posts

vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style

6 repos

https://github.com/codeb0ssx/Ultimate-CVE-2026-61511

https://github.com/HORKimhab/CVE-2026-61511

https://github.com/tc4dy/CVE-2026-61511-PoC-Exploit

https://github.com/shootcannon/CVE-2026-61511

https://github.com/puj790201-lab/cve-2026-61511

https://github.com/webshellseo8/CVE-2026-61511-POC

cyberveille@mastobot.ping.moi at 2026-07-29T17:00:18.000Z ##

📢 RCE non authentifiée dans vBulletin ≤ 6.2.1 via la méthode runMaths() (CVE-2026-61511)
📝 ## 🔍 Contexte

Publié le 27 juillet 2026 sur le blog de recherche Karma(In)Security (karmainsecurity.com), cet article détaille une vulnérabilité critique d'exécut...
📖 cyberveille : cyberveille.ch/posts/2026-07-2
🌐 source : karmainsecurity.com/KIS-2026-13
#CVE_2026_61511 #IOC #Cyberveille

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T15:03:42.000Z ##

A critical vBulletin pre-auth RCE vulnerability, CVE-2026-61511, threatens unpatched forums. Learn how attackers exploit template math evaluation.

#vBulletin #CVE202661511 #RCE #Cybersecurity #Infosec

meterpreter.org/vbulletin-pre-

##

CVE-2026-67215
(7.5 HIGH)

EPSS: 0.35%

updated 2026-07-29T15:31:12

1 posts

cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operations grafts duplicated subtrees to amplify document depth beyond the parser's nesting limit: cJSON_Delete() recurses with no depth bound, and the cJSON

thehackerwire@mastodon.social at 2026-07-29T15:00:21.000Z ##

🟠 CVE-2026-67215 - High (7.5)

cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy oper...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65883(CVSS UNKNOWN)

EPSS: 0.50%

updated 2026-07-29T12:31:30

1 posts

Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.

1 repos

https://github.com/shinthink/CVE-2026-65883

AAKL@infosec.exchange at 2026-07-30T16:44:07.000Z ##

New. This is in reference to CVE-2026-65883.

VulnCheck: Aimy Captcha-Less Form Guard: The Anti-Bot Plugin That Hands Bots the Keys vulncheck.com/blog/aimy-captch @vulncheck #infosec #vulnerability

##

CVE-2026-18220
(7.8 HIGH)

EPSS: 0.19%

updated 2026-07-29T12:31:23

1 posts

An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled relocation type values (via ELF32_R_TYPE(r_info)) before indexing into the dlx_elf_howto_table[] array. The DLX relocation

1 repos

https://github.com/4D4J/objdump-Out-Of-Bounds-write

thehackerwire@mastodon.social at 2026-07-29T15:00:44.000Z ##

🟠 CVE-2026-18220 - High (7.8)

An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds ch...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18197(CVSS UNKNOWN)

EPSS: 0.27%

updated 2026-07-29T09:31:36

1 posts

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allows Cross-Site Scripting (XSS). This issue affects Link Library: before 7.9.4.

AAKL@infosec.exchange at 2026-07-29T17:53:33.000Z ##

New.

Tenable Research Advisories: CVE-2026-18197: Link Library - Reflected Cross-Site Scripting tenable.com/security/research/

From yesterday:

Coordinated “cyberattack” on Minnesota water utilities: What you need to know tenable.com/blog/coordinated-c @tenable #infosec #cyberattack #Minnesota #threatresearch

##

CVE-2026-14512
(9.8 CRITICAL)

EPSS: 0.54%

updated 2026-07-28T21:31:44

1 posts

IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.

CVE-2026-16347
(8.8 HIGH)

EPSS: 0.23%

updated 2026-07-28T21:31:39

2 posts

MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions, allowing repeated authentication failures to proceed without defensive response. In some versions, a fixed per-connection delay is present, but it can be bypass

DailyCyberSecurity at 2026-08-01T01:02:50.752Z ##

MikroTik RouterOS Flaw CVE-2026-16347 Helps Attackers Gain Unauthorized System Access

CVE-2026-16347 lets attackers brute-force MikroTik RouterOS logins for unauthorized system access. Rated CVSS 8.8, with no fix yet. Apply mitigations. TL;DR CISA warned of a brute-force weakness in MikroTik RouterOS and Cloud Hosted Router. Tracked as CVE-2026-16347, it scores a CVSS of 8.8. The flaw helps attackers guess passwords and gain unauthorized system access to admin services.

securityonline.info/mikrotik-r

##

DailyCyberSecurity@infosec.exchange at 2026-08-01T01:02:50.000Z ##

MikroTik RouterOS Flaw CVE-2026-16347 Helps Attackers Gain Unauthorized System Access

CVE-2026-16347 lets attackers brute-force MikroTik RouterOS logins for unauthorized system access. Rated CVSS 8.8, with no fix yet. Apply mitigations. #MikroTik #RouterOS #CVE202616347 #BruteForce #CISA #CyberSecurity TL;DR CISA warned of a brute-force weakness in MikroTik RouterOS and Cloud Hosted Router. Tracked as CVE-2026-16347, it scores a CVSS of 8.8. The flaw helps attackers guess passwords and gain unauthorized system access to admin services.

securityonline.info/mikrotik-r

##

CVE-2026-55390
(7.5 HIGH)

EPSS: 0.36%

updated 2026-07-28T21:26:42

1 posts

### Summary When generating models from an XML Schema (`--input-file-type xmlschema`), `datamodel-code-generator` resolves `<xs:include>`, `<xs:import>`, `<xs:redefine>`, and `<xs:override>` `schemaLocation` attributes against the source directory and reads the target with no restriction to the input/base directory. An attacker who controls the input XSD can read arbitrary files via `../` travers

hugovalters@mastodon.social at 2026-07-29T17:02:27.000Z ##

CVE-2026-55390 - High severity path traversal in datamodel-code-generator 0.59.0-0.62.0. Arbitrary local file read via XML schema imports. CVSS 7.5. Update to 0.62.0 immediately. #CVE #Python #infosec

valtersit.com/cve/CVE-2026-553

##

CVE-2026-5674
(8.8 HIGH)

EPSS: 0.12%

updated 2026-07-28T18:33:47

1 posts

A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.

CVE-2026-16812
(10.0 CRITICAL)

EPSS: 0.88%

updated 2026-07-27T21:31:22

1 posts

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intende

DailyCyberSecurity@infosec.exchange at 2026-07-30T02:16:35.000Z ##

Arista addresses CVE-2026-16812, a critical vulnerability in VeloCloud Orchestrator actively exploited to gain unauthenticated remote code execution.

#Arista #VeloCloud #Cybersecurity #CVE202616812 #RCE

meterpreter.org/arista-veloclo

##

CVE-2026-63077
(9.8 CRITICAL)

EPSS: 0.65%

updated 2026-07-27T18:31:56

4 posts

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

1 repos

https://github.com/unveiledhistory49/teamcity-cve-2026-63077-remediation

tugatech@masto.pt at 2026-07-31T09:45:10.000Z ##

JetBrains emitiu um aviso urgente sobre uma vulnerabilidade crítica no TeamCity que permite execução remota de código. A falha, classificada como CVE-2026-63077, pode ser explorada por atacantes para alcançar a execução remota de código nos sistemas vulneráveis.

🔗 tugatech.com.pt/t88336-jetbrai

#alerta #falha #teamcity 

##

offseq@infosec.exchange at 2026-07-31T00:00:37.000Z ##

CRITICAL: JetBrains TeamCity On-Premises (all versions) vulnerable to CVE-2026-63077 — auth bypass enables remote code execution via HTTPS. Patch to 2025.11.7/2026.1.3 or apply plugin for 2017.1+. TeamCity Cloud unaffected. radar.offseq.com/threat/jetbra
#OffSeq #Vuln #TeamCity #CVE202663077

##

oversecurity@mastodon.social at 2026-07-30T12:31:32.000Z ##

CVE-2026-63077 Exposes TeamCity Servers to Unauthenticated RCE

A critical security flaw affecting TeamCity On-Premises has prompted administrators to update their servers immediately after researchers disclosed...

🔗️ [Thecyberexpress] link.is.it/Uo0klI

##

DailyCyberSecurity@infosec.exchange at 2026-07-30T06:17:33.000Z ##

JetBrains patches critical TeamCity On-Premises vulnerability CVE-2026-63077 (CVSS 9.8), preventing unauthenticated remote code execution.

#TeamCity #JetBrains #CVE202663077 #Cybersecurity #CICD

meterpreter.org/teamcity-vulne

##

CVE-2026-66013(CVSS UNKNOWN)

EPSS: 0.39%

updated 2026-07-25T12:31:47

1 posts

OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. Attackers can overwrite push notification tokens and console metadata without authentication or ownership validation, redirecting notifications or denying delivery to legitimate consol

DailyCyberSecurity@infosec.exchange at 2026-07-31T01:39:37.000Z ##

An OpenRemote vulnerability, CVE-2026-66013 (CVSS 9.3), enables unauthenticated asset takeover. Full advisory details are now public. Patch to 1.26.2.

#OpenRemote #CVE202666013 #IoTSecurity #AssetTakeover

securityonline.info/openremote

##

CVE-2026-66373
(7.5 HIGH)

EPSS: 0.47%

updated 2026-07-25T03:30:55

1 posts

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.

CVE-2026-59952(CVSS UNKNOWN)

EPSS: 0.52%

updated 2026-07-24T16:14:33

1 posts

## Summary `valibot` 1.4.1 can throw a `TypeError` inside its `flatten()` helper when validation issues contain attacker-controlled object keys such as `toString`, `valueOf`, or `hasOwnProperty`. The issue is reachable through normal `record()` validation. `record()` intentionally filters `__proto__`, `prototype`, and `constructor`, but it still accepts other own keys that collide with inherited

offseq@infosec.exchange at 2026-07-30T01:30:28.000Z ##

CVE-2026-59952 | open-circle valibot <1.4.2 suffers from improper exception handling in flatten(), causing TypeErrors & potential DoS if attacker-controlled keys collide w/ Object.prototype methods. Severity: MEDIUM. Upgrade to 1.4.2+ radar.offseq.com/threat/cve-20 #OffSeq #Valibot #AppSec

##

CVE-2026-43499
(7.8 HIGH)

EPSS: 0.73%

updated 2026-07-24T15:33:29

1 posts

In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_requeue(). In the latter case waiter::task is not current, but remove_waiter() operates on current for the dequeue oper

57 repos

https://github.com/Wtrwx/smt878u-ionstack-poc

https://github.com/woshimaniubi8/CVE-2026-43499-root-KernelSU

https://github.com/Colorful-glassblock/duchamp-root

https://github.com/justsoman/CyberMeowfia-ace3

https://github.com/fusiondrive/CVE-2026-43499-S24U

https://github.com/MobiusM/CVE-2026-43499

https://github.com/ctn-Qvo/auto_extract_offsets

https://github.com/pubglite55/oppo-ghostlock

https://github.com/x-spy/CVE-2026-43499-popsicle

https://github.com/p2p3p/GhostLock-for-OnePlus

https://github.com/ayyy7128/CVE-2026-43499-jinghu

https://github.com/BuSung-dev/CVE-2026-43499-S25U

https://github.com/WitAqua-tools/Root-My-Device

https://github.com/datfooldive/ghostlock-emerald

https://github.com/0xBlackash/CVE-2026-43499

https://github.com/LuZe0y/pd2425-cve-2026-43499-config

https://github.com/PeronGH/ghostlock-selinux-disabler

https://github.com/Cxyofficial/x200-cve-2026-43499

https://github.com/joehquak/Mi8E5-Unlocker-by-CVE-2026-43499

https://github.com/sorrow404Null/CVE-2026-43499-RMX5200

https://github.com/Linuxoid-cn/Mi8E5-Unlocker-by-CVE-2026-43499

https://github.com/No-22-Github/UnPlus

https://github.com/qsvggff-spec/oppo-A5-PRO-5G-CVE-2026-43499

https://github.com/xianwan1314/CVE-2026-43499-Poc-Analysis

https://github.com/BuSung-dev/Root-My-Galaxy

https://github.com/dmcdtc/openvz-cve-patch-2026

https://github.com/dnlid/CVE-2026-43499

https://github.com/HYCQAQ/Logitech-G-Cloud-GhostLock-CVE-2026-43499

https://github.com/2932796375github/CVE-2026-43499_OPPO-MT6835

https://github.com/fancyzll/CVE-2026-43499_OPPO-MT6835

https://github.com/geecjdj/CVE-2026-43499

https://github.com/Petalrain224/CVE-2026-43499-Redmi-Turbo5

https://github.com/soralis0912/CVE-2026-43499-aristotle-apk

https://github.com/CatXiaoShi/cve-2026-43499

https://github.com/cuteaplane/GhostLock-for-OnePlus15T

https://github.com/soralis0912/CVE-2026-43499-pmg110-root

https://github.com/mumaosong/cve-2026-43499-CyberMeowfia

https://github.com/soralis0912/CVE-2026-43499-aristotle

https://github.com/Bailan766/rmx3888-cve-2026-43499-config

https://github.com/Bartixxx32/CVE-2026-43499-OnePlus15

https://github.com/inforcqb/CVE-2026-43499-pja110

https://github.com/soralis0912/CVE-2026-43499-warhol-root

https://github.com/HORKimhab/CVE-2026-43499

https://github.com/tc3650/CVE-2026-43499-armv7

https://github.com/Yakayna/SpringPeace

https://github.com/Thiasap/oppo-pgem10-ghostlock

https://github.com/onesmiledx/CVE-2026-43499

https://github.com/ctn-Qvo/CVE-2026-43499-so-build

https://github.com/Linuxoid-cn/CVE-2026-43499-Poc-Analysis

https://github.com/gagaltotal/CVE-2026-43499-PoC-Scanner

https://github.com/JoinChang/ghostlock-oneplus

https://github.com/Kananosa/CVE-2026-43499-For-Xiaomi-17T-chagall

https://github.com/NothingFumo/ghostlock-aresin

https://github.com/MiaPatsune/cve-2026-43499

https://github.com/caspy123/CVE-2026-43499

https://github.com/233laoliu/mt6985-CVE-2026-43499

https://github.com/CakesTwix/Android-CVE-2026-43499

JulianOliver@mastodon.social at 2026-07-31T01:30:52.000Z ##

Update Firefox, the Tor browser, and other derivatives if you are still running FF versions 147 through to 151.0.2.

Some interesting attacks exploiting CVE-2026-10702 are shoring up:

thehackernews.com/2026/07/rese

Note that thanks to Android's lazy sandbox,
this attack can be used as the entry point of a complete browser-to-kernel chain, giving the attacker root (CVE-2026-43499).

(Unclear if/how Firefox-ESR is affected)

#infosec

##

CVE-2026-21655(CVSS UNKNOWN)

EPSS: 0.17%

updated 2026-07-23T21:31:03

1 posts

Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586. This issue affects victor: from 2.9 before 3.0.

DailyCyberSecurity@infosec.exchange at 2026-07-29T14:30:41.000Z ##

A C-CURE 9000 vulnerability chain hits CVSS 9.6. CVE-2026-21655 allows remote code execution on Johnson Controls victor application servers.

#CCURE9000 #CVE202621655 #JohnsonControls #ICSSecurity

securityonline.info/c-cure-900

##

CVE-2026-43503
(8.8 HIGH)

EPSS: 0.34%

updated 2026-07-23T11:10:00.120000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail to propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()->flags when moving frags from source to destination. __pskb_copy_fclone() defers the rest of the shinfo metadata to skb_copy_header(

9 repos

https://github.com/SecureWithUmer/CVE-2026-43503

https://github.com/lieehrdiansyah12/CVE-2026-43503

https://github.com/rjt-gupta/page-cache-corruption-lpes

https://github.com/mooder1/dirtyclone-CVE-2026-43503

https://github.com/entra1337/DirtyClone

https://github.com/douglasmun/pagecache-lpe-containment-kit

https://github.com/gl1tch0x1/DirtyClone

https://github.com/0xBlackash/CVE-2026-43503

https://github.com/sec0x/CVE-2026-43503

DarkWebInformer@infosec.exchange at 2026-07-29T18:58:30.000Z ##

‼️ CVE-2026-43503: DirtyClone is a Linux kernel local privilege escalation (LPE) vulnerability caused by page-cache corruption.

PoC: github.com/entra1337/DirtyClone

##

CVE-2026-16232
(9.1 CRITICAL)

EPSS: 69.97%

updated 2026-07-22T21:32:05

5 posts

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server I

Nuclei template

2 repos

https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review

https://github.com/sfewer-r7/CVE-2026-16232

secdb at 2026-08-01T00:02:58.535Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

daniel1820815@infosec.exchange at 2026-07-30T07:47:53.000Z ##

From our Check Point Research Team:

July 2026 Security Update

Check Point has addressed CVE-2026-16232, an authentication bypass vulnerability in SmartConsole that is under active exploitation, affecting a handful of customers. The flaw allows remote attackers to bypass authentication and gain administrative access to Check Point management servers. Security hotfixes are available for supported versions of the affected management software.

blog.checkpoint.com/security/s

#CheckPoint #CheckPointSoftwareTechnologies #CVE202616232

##

obivan@infosec.exchange at 2026-07-29T17:57:51.000Z ##

Authentication bypass for Check Point Security Management Server and Multi-Domain Security Management Server github.com/sfewer-r7/CVE-2026-

##

AAKL@infosec.exchange at 2026-07-29T17:49:40.000Z ##

Rapid7, from yesterday: Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232) rapid7.com/blog/post/ra-check- @Rapid7Official #infosec #vulnerability #threatresearch

##

CVE-2026-50522
(9.8 CRITICAL)

EPSS: 75.76%

updated 2026-07-22T21:31:51

2 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

5 repos

https://github.com/HORKimhab/CVE-2026-50522

https://github.com/ChPratik/CVE-2026-50522

https://github.com/4minx/CVE-2026-50522

https://github.com/webshellseo8/CVE-2026-50522-Proof-of-Concept

https://github.com/darses/CVE-2026-50522

secdb at 2026-08-01T00:02:58.535Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-49176
(7.8 HIGH)

EPSS: 0.47%

updated 2026-07-22T16:17:28.753000

1 posts

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

2 repos

https://github.com/777erp/CVE-2026-49176_BOF

https://github.com/DavidCarliez/CVE-2026-49176_LPE_POC

DarkWebInformer@infosec.exchange at 2026-07-31T17:33:23.000Z ##

🚨 A Cobalt Strike BOF targeting CVE-2026-49176 adds another exploitation method for the CVSS 7.8 Windows WalletService local privilege escalation vulnerability.

GitHub: github.com/777erp/CVE-2026-491

The flaw can allow a standard user to execute commands with SYSTEM privileges on unpatched Windows systems.

##

CVE-2026-20896
(9.8 CRITICAL)

EPSS: 31.81%

updated 2026-07-21T20:28:59

2 posts

# Summary The Gitea Docker images ship an `app.ini` template that hard-codes: ``` REVERSE_PROXY_TRUSTED_PROXIES = * ``` The documented default for this setting, in `custom/conf/app.example.ini`, is `127.0.0.0/8,::1/128`, i.e. only loopback is trusted. When an admin enables `ENABLE_REVERSE_PROXY_AUTHENTICATION = true` to put Gitea behind an authenticating reverse proxy and leaves the trusted-pr

6 repos

https://github.com/XaocZenon/CVE-2026-20896

https://github.com/szybnev/cve-2026-20896-gitea-poc

https://github.com/Lite-os15/Lab-001-Gitea-CVE-2026-20896-

https://github.com/EQSTLab/CVE-2026-20896

https://github.com/kaleth4/CVE-2026-20896

https://github.com/rz1027/CVE-2026-20896

secdb at 2026-08-01T00:02:58.535Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-27771
(8.2 HIGH)

EPSS: 43.07%

updated 2026-07-17T19:04:38

2 posts

### CVE Description Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information. ### Summary A critical vulnerability has been discovered in Gitea. It was already reported via (security@gitea.io) from (dev@noscope.com), and submitted an encrypted report.

Nuclei template

2 repos

https://github.com/HORKimhab/CVE-2026-27771

https://github.com/portbuster1337/CVE-2026-27771

secdb at 2026-08-01T00:02:58.535Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-15352
(7.5 HIGH)

EPSS: 0.43%

updated 2026-07-16T21:30:45

1 posts

A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segmentation fault when processing a routine Housekeeping Telemetry request, leading to denial of service.

thehackerwire@mastodon.social at 2026-07-30T23:00:23.000Z ##

🟠 CVE-2026-18064 - High (7.5)

An incomplete fix for CVE-2026-15352 in the NASA core Flight System
(cFS) Health and Safety (HS) application leaves a separate NULL pointer
dereference reachable in versions through 7.0.1. An attacker who can
trigger the affected command under ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-42530
(8.1 HIGH)

EPSS: 3.68%

updated 2026-07-16T12:17:51.630000

1 posts

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers

3 repos

https://github.com/HORKimhab/CVE-2026-42530

https://github.com/v4ltonn/CVE-2026-42530

https://github.com/0xBlackash/CVE-2026-42530

CVE-2026-15409
(10.0 CRITICAL)

EPSS: 78.44%

updated 2026-07-16T05:16:18.293000

2 posts

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

Nuclei template

5 repos

https://github.com/tc4dy/CVE-2026-15409-15410-Framework

https://github.com/HORKimhab/CVE-2026-15409

https://github.com/0xBlackash/CVE-2026-15409

https://github.com/remmons-r7/rapid7-CVE-2026-15409

https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check

secdb at 2026-08-01T00:02:58.535Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-48319
(9.1 CRITICAL)

EPSS: 32.29%

updated 2026-07-14T21:32:32

2 posts

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

secdb at 2026-08-01T00:02:58.535Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-15410
(7.2 HIGH)

EPSS: 76.35%

updated 2026-07-14T21:32:21

2 posts

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

3 repos

https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check

https://github.com/HORKimhab/CVE-2026-15410

https://github.com/tc4dy/CVE-2026-15409-15410-Framework

secdb at 2026-08-01T00:02:58.535Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-59726
(10.0 CRITICAL)

EPSS: 0.48%

updated 2026-07-10T19:15:15.780000

3 posts

Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without authentication, allowing an unauthenticated network attacker to invoke tools/call to terminal_execute, obtain a shell in the bridge container, read provider API keys, and poison AgentDB learning-store patterns.

1 repos

https://github.com/HORKimhab/CVE-2026-59726

threatnoir@infosec.exchange at 2026-07-31T09:06:06.000Z ##

⚠️ CRITICAL: Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

CVE-2026-59726 in Ruflo AI orchestration platform allows unauthenticated remote code execution via an exposed Model Context Protocol bridge. Attackers can steal API keys, access user conversations, and corrupt AI memory without any credentials. Any organization running Ruflo is immediately exploita…

threatnoir.com/focus

#infosec #cybersecurity

##

beyondmachines1@infosec.exchange at 2026-07-31T09:01:05.000Z ##

Critical RufRoot Flaw Allows Full Takeover of Ruflo AI Agent Environments

Ruflo patched a CVSS 10.0 vulnerability (CVE-2026-59726) that allowed unauthenticated attackers to execute code and steal API keys via an exposed MCP bridge. The flaw, named RufRoot, also enabled AI memory poisoning that persists even after software updates.

**If you run Ruflo (formerly Claude Flow), first make sure your instances are isolated from the internet and reachable only from trusted networks, then update to version 3.16.3 immediately to fix the RufRoot flaw (CVE-2026-59726) and firewall ports 3001 and 27017 to block outside access from the local network. Because a simple update won't undo damage already done, rotate all your LLM provider API keys (OpenAI, Anthropic, etc.) and audit the AgentDB memory store for any malicious entries left behind by attackers.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

offseq@infosec.exchange at 2026-07-30T10:30:29.000Z ##

Ruflo <3.16.3 has a CRITICAL flaw (CVE-2026-59726): exposed /mcp endpoint allows unauth RCE in MCP bridge container. Attackers can spawn rogue AI swarms & steal API keys. Upgrade to 3.16.3 asap. radar.offseq.com/threat/critic #OffSeq #AIsecurity #infosec #CVE202659726

##

CVE-2026-56291
(9.8 CRITICAL)

EPSS: 76.07%

updated 2026-07-10T18:33:13

2 posts

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Nuclei template

4 repos

https://github.com/ChiefYoru/CVE-2026-56291_PoC

https://github.com/0xdenis77/CVE-2026-56291

https://github.com/rimbadirgantara/CVE-2026-56291.yaml

https://github.com/shinthink/CVE-2026-56291

secdb at 2026-08-01T00:02:58.535Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-58025
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-07-09T21:31:14

1 posts

Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Import/WikiImporter.Php, includes/Import/WikiRevision.Php, includes/Logging/LogEntryBase.Php. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

1 repos

https://github.com/shinthink/CVE-2026-58025

DarkWebInformer@infosec.exchange at 2026-07-30T19:21:53.000Z ##

🚨 PoC for CVE-2026-58025, a CVSS 9.8 MediaWiki deserialization flaw that could enable RCE through malicious log entry imports.

Exploitation requires import permissions. Upgrade to 1.43.9, 1.44.6, 1.45.4, or 1.46.0.

GitHub: github.com/shinthink/CVE-2026-

##

CVE-2026-10702
(4.3 MEDIUM)

EPSS: 0.72%

updated 2026-06-30T03:36:54

3 posts

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.

2 repos

https://github.com/raihants/cve-2026-10702

https://github.com/HORKimhab/CVE-2026-10702

DailyCyberSecurity@infosec.exchange at 2026-07-31T12:09:47.000Z ##

Firefox CVE-2026-10702 Exploit: Android Flaw Exposed

meterpreter.org/firefox-cve-20

##

JulianOliver@mastodon.social at 2026-07-31T01:30:52.000Z ##

Update Firefox, the Tor browser, and other derivatives if you are still running FF versions 147 through to 151.0.2.

Some interesting attacks exploiting CVE-2026-10702 are shoring up:

thehackernews.com/2026/07/rese

Note that thanks to Android's lazy sandbox,
this attack can be used as the entry point of a complete browser-to-kernel chain, giving the attacker root (CVE-2026-43499).

(Unclear if/how Firefox-ESR is affected)

#infosec

##

jbhall56@infosec.exchange at 2026-07-30T12:34:28.000Z ##

Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update. thehackernews.com/2026/07/rese

##

CVE-2026-42897
(8.1 HIGH)

EPSS: 5.64%

updated 2026-06-17T10:48:34.893000

6 posts

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

1 repos

https://github.com/atiilla/CVE-2026-42897

threatnoir@infosec.exchange at 2026-07-31T08:06:41.000Z ##

⚠️ CRITICAL: Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

Russian state-sponsored group Laundry Bear is actively exploiting a zero-day XSS vulnerability (CVE-2026-42897) in Exchange OWA to deploy OWAReaper backdoor. Targets include U.S. and European government entities and private sector organizations. Successful exploitation grants persistent mailbox acc…

threatnoir.com/focus

#infosec #cybersecurity

##

security_crawler_carl@infosec.exchange at 2026-07-30T20:06:31.000Z ##

🏆 New Achievement! Inbox: One New Backdoor (Unread)!

Conducting inventory audit of your Microsoft Exchange installation. Status: CVE-2026-42897, one cross-site scripting flaw in Outlook Web Access — present, unpatched, actively exploited. OWAReaper backdoor — installed, compliments of Laundry Bear (also filed under: Void Blizzard). Long-term mailbox access — granted, unauthorized, ongoing. Affected sectors listed: government, telecom, financial, hospitality, aerospace. (1/2)

##

security_crawler_carl@infosec.exchange at 2026-07-30T20:06:31.000Z ##

HTML sanitization — missing. Proofpoint's report — filed July 29, one week after the activity was detected.

Summary column: your email server is carrying significant negative-value assets. Patch CVE-2026-42897 immediately and audit OWA logs for suspicious JavaScript execution and unauthorized mailbox access.

Reward: A cursed Rusty Audit Clipboard. It changes nothing. The backdoor is still there.

#CyberSecurity #ZeroDay #Exchange #Ransomware #APT #AchievementUnlocked (2/2)

##

jbhall56@infosec.exchange at 2026-07-30T12:09:26.000Z ##

The activity, which began on July 22, 2026, involves the weaponization of CVE-2026-42897 (CVSS score: 8.1), a cross-site scripting (XSS) vulnerability in OWA. It was flagged by Microsoft as having been exploited in attacks as far back as May 2026. thehackernews.com/2026/07/russ

##

VirusBulletin@infosec.exchange at 2026-07-30T09:01:00.000Z ##

Proofpoint analyses a campaign from Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) exploiting Outlook CVE-2026-42897 and targeting US & European government entities, as well as the telecommunications, financial, hospitality & aerospace sectors. proofpoint.com/us/blog/threat-

##

AAKL@infosec.exchange at 2026-07-29T18:03:12.000Z ##

New.

"On 22 July 2026, one day prior to Proofpoint’s recent joint release with the NSA on Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear), the actor began a campaign abusing CVE-2026-42897, a cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA)."

Proofpoint: Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit proofpoint.com/us/blog/threat-

More:

The Record: Laundry Bear’s webmail hackers had more in store after February, report says therecord.media/russia-hackers @therecord_media @jwarminsky #infosec #threatresearch #Outlook #Microsoft

##

CVE-2014-0160
(7.5 HIGH)

EPSS: 100.00%

updated 2026-06-17T00:02:24.467000

1 posts

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

Nuclei template

75 repos

https://github.com/OffensivePython/HeartLeak

https://github.com/rouze-d/heartbleed

https://github.com/iSCInc/heartbleed

https://github.com/DisK0nn3cT/MaltegoHeartbleed

https://github.com/jdauphant/patch-openssl-CVE-2014-0160

https://github.com/GeeksXtreme/ssl-heartbleed.nse

https://github.com/proactiveRISK/heartbleed-extention

https://github.com/idkqh7/heatbleeding

https://github.com/marstornado/cve-2014-0160-Yunfeng-Jiang

https://github.com/SimoesCTT/CTT-HEARTBLEED-Temporal-Resonance-Memory-Leak-Exploit-Heartbleed-CVE-2014-0160

https://github.com/0xBlackash/CVE-2014-0160

https://github.com/h3x0v3rl0rd/CVE-2014-0160_Heartbleed

https://github.com/waqasjamal-zz/HeartBleed-Vulnerability-Checker

https://github.com/0xinf0/bleeding_onions

https://github.com/GardeniaWhite/fuzzing

https://github.com/anthophilee/A2SV--SSL-VUL-Scan

https://github.com/roganartu/heartbleedchecker-chrome

https://github.com/takeshixx/ssl-heartbleed.nse

https://github.com/artofscripting-zz/cmty-ssl-heartbleed-CVE-2014-0160-HTTP-HTTPS

https://github.com/tungduongNT/CVE-2014-0160.

https://github.com/yashfren/CVE-2014-0160-HeartBleed

https://github.com/PinkP4nther/Heartbleed_PoC

https://github.com/timsonner/cve-2014-0160-heartbleed

https://github.com/titanous/heartbleeder

https://github.com/FiloSottile/Heartbleed

https://github.com/WildfootW/CVE-2014-0160_OpenSSL_1.0.1f_Heartbleed

https://github.com/iwaffles/heartbleed-test.crx

https://github.com/sensepost/heartbleed-poc

https://github.com/Saymeis/HeartBleed

https://github.com/yryz/heartbleed.js

https://github.com/vortextube/ssl_scanner

https://github.com/tomdevman/heartbleed-bug

https://github.com/cheese-hub/heartbleed

https://github.com/cved-sources/cve-2014-0160

https://github.com/mozilla-services/Heartbleed

https://github.com/ingochris/heartpatch.us

https://github.com/Xyl2k/CVE-2014-0160-Chrome-Plugin

https://github.com/cbk914/heartbleed-checker

https://github.com/xlucas/heartbleed

https://github.com/belmind/heartbleed

https://github.com/musalbas/heartbleed-masstest

https://github.com/froyo75/Heartbleed_Dockerfile_with_Nginx

https://github.com/MrE-Fog/CVE-2014-0160-Chrome-Plugin

https://github.com/caiqiqi/OpenSSL-HeartBleed-CVE-2014-0160-PoC

https://github.com/hybridus/heartbleedscanner

https://github.com/DominikTo/bleed

https://github.com/undacmic/heartbleed-proof-of-concept

https://github.com/mpgn/heartbleed-PoC

https://github.com/a0726h77/heartbleed-test

https://github.com/22imer/CVE-2014-0160

https://github.com/indiw0rm/-Heartbleed-

https://github.com/hmlio/vaas-cve-2014-0160

https://github.com/cyphar/heartthreader

https://github.com/hreese/heartbleed-dtls

https://github.com/isgroup/openmagic

https://github.com/siddolo/knockbleed

https://github.com/obayesshelton/CVE-2014-0160-Scanner

https://github.com/zouguangxian/heartbleed

https://github.com/Lekensteyn/pacemaker

https://github.com/indrajeetmp11/Heartbleed-PoC-Exploit-Script

https://github.com/0x90/CVE-2014-0160

https://github.com/sammyfung/openssl-heartbleed-fix

https://github.com/einaros/heartbleed-tools

https://github.com/GuillermoEscobero/heartbleed

https://github.com/Shayhha/HeartbleedAttack

https://github.com/ArtemCyberLab/Project-Field-Analysis-and-Memory-Leak-Demonstration

https://github.com/amerine/coronary

https://github.com/Ryo-Soikutsu/Heartbleed

https://github.com/pierceoneill/bleeding-heart

https://github.com/fb1h2s/CVE-2014-0160

https://github.com/xanas/heartbleed.py

https://github.com/ThanHuuTuan/Heartexploit

https://github.com/victoriacfigueiredo/heartbleed-lab

https://github.com/pblittle/aws-suture

https://github.com/ice-security88/CVE-2014-0160

g0rb@infosec.exchange at 2026-07-29T17:09:54.000Z ##

Shodan-Query of the day:

asn:"AS59399" vuln:"cve-2014-0160"

#ThruntersAnonymous #shodansafari #yeet

##

CVE-2013-4786
(7.5 HIGH)

EPSS: 78.57%

updated 2026-06-16T23:57:53.617000

2 posts

The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC.

1 repos

https://github.com/fin3ss3g0d/CosmicRakp

marzlberger@neander.social at 2026-08-01T14:19:27.000Z ##

Also wirklich, niemand, wirklich niemand sollte ein #BMC ohne ein VPN/SSL frei ins Internet stellen! Das war schon 2004 fahrlässig.

@gborn : "Mehr als 24.000 Server mit BMC per #Schwachstelle CVE-2013-4786 gefährdet. .... Diese besteht wohl seit 2004 und kann den Password-Hash zur Authentifizierung leaken. Die Server wären dann per Internet öffentlich angreifbar, und die Passwort-Hashes sind in vielen Fällen knackbar"

borncity.com/blog/2026/08/01/m

#sicherheit #security

##

marzlberger@neander.social at 2026-08-01T14:19:27.000Z ##

Also wirklich, niemand, wirklich niemand sollte ein #BMC ohne ein VPN/SSL frei ins Internet stellen! Das war schon 2004 fahrlässig.

@gborn : "Mehr als 24.000 Server mit BMC per #Schwachstelle CVE-2013-4786 gefährdet. .... Diese besteht wohl seit 2004 und kann den Password-Hash zur Authentifizierung leaken. Die Server wären dann per Internet öffentlich angreifbar, und die Passwort-Hashes sind in vielen Fällen knackbar"

borncity.com/blog/2026/08/01/m

#sicherheit #security

##

CVE-2026-20079
(10.0 CRITICAL)

EPSS: 37.67%

updated 2026-03-04T18:32:03

4 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerab

Nuclei template

1 repos

https://github.com/0xBlackash/CVE-2026-20079

AAKL@infosec.exchange at 2026-07-31T16:19:58.000Z ##

There are two new advisories from Cisco, one addressing a critical vulnerability that was first published on March 4:

CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi

The second is a high-severity vulnerability that was first published yesterday:

CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #vulnerability #Cisco

##

Bied@digitalhub.social at 2026-07-30T19:33:28.000Z ##

#Cisco - "We Never Learn". 🔥

Warum ein Konzern es noch immer notwendig findet eine #Backdoor in seine Produkte einzubauen ist mir völlig schleierhaft. 🙈

"Da CVE-2026-20316 bereits aktiv ausgenutzt wird, rät Cisco Administratoren, ihre FMC-Instanzen dringend zu aktualisieren."

"Gibt es Abhilfe?

"Die genannten Hotfix-Updates bessern auch bezüglich einer seit März bekannten kritischen Lücke (CVSS: 10) nach, mit der sich die Authentifizierung im Web-Interface von FMC umgehen lässt. Diese Lücke ist als CVE-2026-20079 registriert und verleiht Angreifern sogar einen direkten Root-Zugriff auf das zugrundeliegende Betriebssystem. "

Klar, eine Firewall ist ja nur zum Schutz der Kunden vorhanden, da kann man schon mal auch Kriminelle einladen, oder? 🤢

So eine persönliche Haftung des CEO und eine Strafe ab 5 % vom Konzernumsatz könnte möglicherweise zu einer Änderungen führen:

So stelle ich mir die Anweisung des CEO vor: 👍

"Ab sofort ist die Nutzung (auch während der Entwicklung) von Backdoors untersagt. Wer sich nicht daran hält wird fristlos entlassen und haftet für Schäden."

Und, natürlich sollte die Qualitätssicherung vorab prüfen ob die Entwickler sich auch daran halten. 😁

Es gibt erfahrene Spezialisten die gerne bei der Auswahl der Geräte helfen und für mehr Sicherheit sorgen. Einfach anfragen, dann weiß man mehr. 🙂

golem.de/news/kodierte-zugangs

#Backdoor

##

security_crawler_carl@infosec.exchange at 2026-07-30T11:45:32.000Z ##

🏆 New Achievement! Static Credentials, Static Fate!

RAID ALERT. RAID ALERT. Cisco Secure Firewall Management Center has a hardcoded low-privilege account baked right into the software — CVE-2026-20316 — and unauthenticated remote attackers are already using it to log in and harvest sensitive data. That's Phase One. Phase Two is the wipe: threat actors are chaining it with CVE-2026-20079, which hands them root access via arbitrary script execution. (1/2)

##

AAKL@infosec.exchange at 2026-07-29T17:36:00.000Z ##

New Cisco updates:

CRITICAL vulnerability, first released on March 4: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi

High severity: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability sec.cloudapps.cisco.com/securi

New informational advisory: Cisco Advance Notification for Publication of August 5, 2026, Security Advisories sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #vulnerability #Cisco

##

CVE-2025-15435
(7.3 HIGH)

EPSS: 0.36%

updated 2026-01-02T09:30:27

1 posts

A flaw has been found in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksheet/work_update.jsp. This manipulation of the argument Report causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

jyasskin@hachyderm.io at 2026-07-30T18:14:29.000Z ##

@fugueish Was going to shill Kagi, but their first result is CVE-2025-15435 (i.e. wrong year). The second result is correct. Quotes don't uprank that second result for some reason. It's still the first day, so maybe their crawls aren't as aggressive?

##

CVE-2023-37327
(7.6 HIGH)

EPSS: 1.71%

updated 2025-11-04T21:32:34

2 posts

GStreamer FLAC File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of FLAC audio files. The issue

hugovalters@mastodon.social at 2026-07-30T05:55:09.000Z ##

@slomo No need for the hostility. The text summary might pull context from reference links mentioning 1.22.5, but our 'Patch Status' flag operates strictly on machine-readable data from the NVD API.
If you look at the official NVD record for CVE-2023-37327, the CPE configurations only map up to 1.22.4 and do not explicitly record the patched status. We explicitly do not accept vendor GitHub releases as evidence until they are validated by NVD.

##

slomo@toot.cat at 2026-07-29T19:32:02.000Z ##

@hugovalters Bullshit. Get your data updated and fix your website instead of spreading fud.

It's very funny that e.g. valtersit.com/cve/CVE-2023-373 claims to be "unpatched" and at the top says that it's fixed in 1.22.5, contains completely wrong information (just follow your own NVD link and compare: it's describing completely different issues), and a wrong patch for code that does not even exist in this shape in 1.22.5 or any other version.

Not enough that we have to deal with a flood of new issues reported thanks to LLMs, on top of that we also have to deal with clowns like you.

##

CVE-2026-63030
(0 None)

EPSS: 98.42%

2 posts

N/A

Nuclei template

72 repos

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

https://github.com/imXur/WordPress-CVE-2026-63030-Analysis

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/ekomsSavior/wp2shell

https://github.com/raphy76/wp2shell-poc-fulljs

https://github.com/michael-kanda/Wp2shell-ioc-scanner

https://github.com/0xWhoknows/wp2shell

https://github.com/yuag/wp2shell

https://github.com/0xh7ml/CVE-2026-63030

https://github.com/Industri4l-H3ll-Xpl0it3rs/CVE-2026-63030-WP2Shell

https://github.com/4minx/CVE-2026-63030

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/TomorrowX6/CVE-2026-63030-poc

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/0xjessie21/wp2shell-checker

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner

https://github.com/mhtsec/CVE-2026-63030

https://github.com/zeroc00I/CVE-2026-63030

https://github.com/administrator-01001/CVE-2026-63030

https://github.com/zi3lak/wp2shell_scanner

https://github.com/kulichr/wp2shell

https://github.com/0xsha/wp2shell

https://github.com/ChiefYoru/CVE-2026-63030_PoC

https://github.com/shinthink/CVE-2026-63030

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030

https://github.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t

https://github.com/0xBlackash/CVE-2026-63030

https://github.com/vulnquest58/PressVector

https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause

https://github.com/h4cd0c/wp2shell

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/ZenithGenius/wordpress-batch-rce-lab

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/ananay/wp2shell-lab

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/Icex0/wp2shell-poc

https://github.com/4B3R4M4-607D/CVE-2026-63030-POC

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/mrx-arafat/CVE-2026-63030-POC

https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030

https://github.com/fullhunt/wp2shell-scan

https://github.com/bahartanir/wp2shell-scanner

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/ikow/wp2shell

https://github.com/Crypto-Cat/wp2shell

https://github.com/47Cid/wp2shell-lab

https://github.com/Iqbalx7/wp2shell

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/NULL200OK/WP2Shell

https://github.com/ebrasha/abdal-cve-2026-63030

https://github.com/InstaWP/wp2shell-scan

https://github.com/dinosn/wp2shell-lab

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/attackercan/wp2shell-poc2

https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction

https://github.com/AkbarWiraN/holy-wp2shell

https://github.com/Lutfifakee-Project/wp2shell

https://github.com/Ch4120N/CVE-2026-63030

https://github.com/mverschu/CVE-2026-63030

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/c0gnit00/Wp2Shell

https://github.com/mcipekci/wp2shell

https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030

https://github.com/CybersecSpirit/CVE-2026-63030

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

https://github.com/gbrsh/CVE-2026-63030

https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137

https://github.com/securelayer7/WordPresShell

secdb at 2026-08-01T00:02:58.535Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-60137
(0 None)

EPSS: 79.03%

2 posts

N/A

46 repos

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

https://github.com/ebrasha/abdal-cve-2026-60137

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/ekomsSavior/wp2shell

https://github.com/michael-kanda/Wp2shell-ioc-scanner

https://github.com/0xWhoknows/wp2shell

https://github.com/yuag/wp2shell

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/0xjessie21/wp2shell-checker

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner

https://github.com/zi3lak/wp2shell_scanner

https://github.com/kulichr/wp2shell

https://github.com/0xsha/wp2shell

https://github.com/shinthink/CVE-2026-63030

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/vulnquest58/PressVector

https://github.com/h4cd0c/wp2shell

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/ananay/wp2shell-lab

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/Icex0/wp2shell-poc

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/bahartanir/wp2shell-scanner

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/ikow/wp2shell

https://github.com/Crypto-Cat/wp2shell

https://github.com/47Cid/wp2shell-lab

https://github.com/Iqbalx7/wp2shell

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/NULL200OK/WP2Shell

https://github.com/northsia/CVE-2026-60137-With-Skip-SSL

https://github.com/dinosn/wp2shell-lab

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction

https://github.com/AkbarWiraN/holy-wp2shell

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

https://github.com/mcipekci/wp2shell

https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030

https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137

https://github.com/securelayer7/WordPresShell

secdb at 2026-08-01T00:02:58.535Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-18420
(0 None)

EPSS: 0.00%

1 posts

N/A

offseq@infosec.exchange at 2026-07-31T21:00:29.000Z ##

CVE-2026-18420: CRITICAL RCE via prototype pollution in OpenSearch Dashboards TSVB plugin. Full system compromise possible. No patch yet — check AWS Security Bulletin, limit plugin access, monitor updates. radar.offseq.com/threat/cve-20 #OffSeq #OpenSearch #Infosec #RCE

##

CVE-2026-62999
(0 None)

EPSS: 0.29%

1 posts

N/A

thehackerwire@mastodon.social at 2026-07-31T20:59:51.000Z ##

🟠 CVE-2026-62999 - High (7.5)

Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-directory segments or encoded path separators in a template URL can match a configured trusted repository prefix before an HTTP serv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62261
(0 None)

EPSS: 0.00%

1 posts

N/A

DailyCyberSecurity@infosec.exchange at 2026-07-31T13:41:47.000Z ##

Four OpenAM vulnerabilities are fixed in 16.1.2. CVE-2026-62379 (CVSS 9.8) allows unauthenticated remote code execution; CVE-2026-62261 scores 9.9.

#OpenAM #RCE #IAM #CVE202662379

securityonline.info/openam-cve

##

CVE-2026-62379
(0 None)

EPSS: 0.00%

1 posts

N/A

DailyCyberSecurity@infosec.exchange at 2026-07-31T13:41:47.000Z ##

Four OpenAM vulnerabilities are fixed in 16.1.2. CVE-2026-62379 (CVSS 9.8) allows unauthenticated remote code execution; CVE-2026-62261 scores 9.9.

#OpenAM #RCE #IAM #CVE202662379

securityonline.info/openam-cve

##

CVE-2026-46648
(0 None)

EPSS: 0.00%

1 posts

N/A

moltenbit@infosec.exchange at 2026-07-31T12:33:17.000Z ##

two advisories i reported against globaleaks went public today. globaleaks is the whistleblowing platform a lot of ngos, newsrooms and public bodies run their leak sites on, so tenant separation is load bearing there.

CVE-2026-46648 (moderate): db_toggle_escrow runs three adjacent ORM updates. two of them are missing the User.tid == tid filter, so a non-root tenant admin disabling escrow wipes crypto_escrow_bkp2_key for every user on every tenant, while those tenants keep escrow nominally enabled. fixed in 5.0.94.

CVE-2026-46647 (low): /api/admin/network checked for internal user, not for admin, so any internal role on the root tenant could read and write network config. fixed in 5.0.93.

github.com/globaleaks/globalea and github.com/globaleaks/globalea

#GlobaLeaks #InfoSec #AppSec #Whistleblowing #Cybersecurity #security

##

CVE-2026-46647
(0 None)

EPSS: 0.00%

1 posts

N/A

moltenbit@infosec.exchange at 2026-07-31T12:33:17.000Z ##

two advisories i reported against globaleaks went public today. globaleaks is the whistleblowing platform a lot of ngos, newsrooms and public bodies run their leak sites on, so tenant separation is load bearing there.

CVE-2026-46648 (moderate): db_toggle_escrow runs three adjacent ORM updates. two of them are missing the User.tid == tid filter, so a non-root tenant admin disabling escrow wipes crypto_escrow_bkp2_key for every user on every tenant, while those tenants keep escrow nominally enabled. fixed in 5.0.94.

CVE-2026-46647 (low): /api/admin/network checked for internal user, not for admin, so any internal role on the root tenant could read and write network config. fixed in 5.0.93.

github.com/globaleaks/globalea and github.com/globaleaks/globalea

#GlobaLeaks #InfoSec #AppSec #Whistleblowing #Cybersecurity #security

##

CVE-2026-63223
(0 None)

EPSS: 0.49%

2 posts

N/A

AmmarSpaces@infosec.exchange at 2026-07-31T10:51:10.000Z ##

So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.

Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)

Did people still use CodeIgniter?

Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.

securityonline.info/codeignite

#cybersecurity #infosec #codeigniter #vulnerability

##

DailyCyberSecurity@infosec.exchange at 2026-07-31T09:19:52.000Z ##

CVE-2026-63223: CodeIgniter4 RCE Vulnerability Rated CVSS 9.8

securityonline.info/codeignite

##

CVE-2026-63222
(0 None)

EPSS: 0.45%

1 posts

N/A

AmmarSpaces@infosec.exchange at 2026-07-31T10:51:10.000Z ##

So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.

Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)

Did people still use CodeIgniter?

Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.

securityonline.info/codeignite

#cybersecurity #infosec #codeigniter #vulnerability

##

CVE-2026-68502
(0 None)

EPSS: 0.53%

1 posts

N/A

thehackerwire@mastodon.social at 2026-07-30T22:00:28.000Z ##

🔴 CVE-2026-68502 - Critical (9.8)

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.py registers an unauthenticated Socket.IO input event handler that dispatches data.get('value') to LazyOwnShell.one_cmd, reachi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58086
(0 None)

EPSS: 0.00%

1 posts

N/A

CVE-2026-56846
(0 None)

EPSS: 0.00%

2 posts

N/A

nodejs_release_watcher@kodesumber.com at 2026-07-29T17:29:15.000Z ##

2026-07-29, Version 24.18.1 'Krypton' (LTS), @juanarbol

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:00.000Z ##

2026-07-29, Version 22.23.2 'Jod' (LTS), @marco-ippolito

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

CVE-2026-56848
(0 None)

EPSS: 0.00%

4 posts

N/A

nodejs_release_watcher@kodesumber.com at 2026-07-29T17:29:15.000Z ##

2026-07-29, Version 24.18.1 'Krypton' (LTS), @juanarbol

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T15:30:05.000Z ##

Node.js patched 11 vulnerabilities in its July 2026 release. The high-severity bugs include a HTTP/2 use-after-free (CVE-2026-56848). Update now.

#NodeJS #CVE202656848 #HTTP2 #UseAfterFree #Vulnerability #InfoSec

securityonline.info/nodejs-jul

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:01.000Z ##

2026-07-29, Version 26.5.1 (Current), @RafaelGSS

This is a security release. Notable Changes (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:00.000Z ##

2026-07-29, Version 22.23.2 'Jod' (LTS), @marco-ippolito

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

Visit counter For Websites