##
Updated at UTC 2026-09-19T07:52:22.790255
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-93741 | 10.0 | 0.00% | 2 | 0 | 2026-09-19T06:16:30.557000 | A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affec | |
| CVE-2026-85889 | 10.0 | 0.49% | 6 | 0 | 2026-09-19T04:18:00.780000 | Missing authentication for critical function in Azure AI Foundry allows an unaut | |
| CVE-2026-92807 | 8.8 | 0.00% | 4 | 0 | 2026-09-19T03:17:17.723000 | The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitra | |
| CVE-2026-92229 | 9.1 | 0.00% | 4 | 0 | 2026-09-19T03:17:17.040000 | The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plug | |
| CVE-2026-89274 | 9.1 | 0.00% | 4 | 0 | 2026-09-19T03:17:16.587000 | The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Ex | |
| CVE-2026-87909 | 7.5 | 0.00% | 2 | 0 | 2026-09-19T03:17:15.853000 | The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execut | |
| CVE-2026-84434 | 9.8 | 0.00% | 2 | 0 | 2026-09-19T03:17:15.573000 | The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in | |
| CVE-2026-93739 | 9.9 | 0.00% | 2 | 0 | 2026-09-19T00:32:51 | A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impac | |
| CVE-2026-93740 | 10.0 | 0.00% | 2 | 0 | 2026-09-19T00:32:50 | A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected i | |
| CVE-2026-75885 | 9.3 | 0.00% | 4 | 0 | 2026-09-18T22:17:10.313000 | A flaw was found in the OpenShift console. Unauthenticated access to the `/api/d | |
| CVE-2026-93738 | 9.9 | 0.00% | 2 | 0 | 2026-09-18T21:32:44 | A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects th | |
| CVE-2026-88097 | 8.1 | 0.00% | 2 | 0 | 2026-09-18T21:32:43 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacke | |
| CVE-2026-93872 | 7.5 | 0.00% | 2 | 0 | 2026-09-18T21:32:42 | Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without al | |
| CVE-2026-93031 | 8.8 | 0.00% | 2 | 0 | 2026-09-18T21:32:41 | The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-B | |
| CVE-2026-93868 | 8.1 | 0.00% | 2 | 0 | 2026-09-18T21:32:41 | Cotonti through 1.0.0 derives password recovery validation tokens from md5(micro | |
| CVE-2026-93839 | 9.8 | 0.00% | 4 | 0 | 2026-09-18T21:32:40 | LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /p | |
| CVE-2026-84241 | 8.1 | 0.00% | 2 | 0 | 2026-09-18T21:32:40 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass securi | |
| CVE-2025-39682 | 7.1 | 0.51% | 2 | 1 | 2026-09-18T21:31:33 | In the Linux kernel, the following vulnerability has been resolved: tls: fix ha | |
| CVE-2026-93572 | 7.5 | 0.00% | 2 | 0 | 2026-09-18T21:18:48.020000 | A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker | |
| CVE-2026-57227 | 7.5 | 0.00% | 2 | 0 | 2026-09-18T21:17:01.217000 | Suricata is a network Intrusion Detection System, Intrusion Prevention System an | |
| CVE-2026-92953 | 10.0 | 0.34% | 2 | 0 | 2026-09-18T20:17:31.113000 | vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and Array | |
| CVE-2026-54767 | 9.1 | 0.43% | 2 | 0 | 2026-09-18T20:17:17.253000 | WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/soc | |
| CVE-2026-20329 | 9.9 | 0.45% | 2 | 0 | 2026-09-18T20:17:13.133000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-13639 | 9.8 | 0.51% | 2 | 0 | 2026-09-18T20:17:06.860000 | An insufficient entropy vulnerability in login logic in Synology DiskStation Man | |
| CVE-2026-92838 | 7.8 | 0.14% | 1 | 0 | 2026-09-18T19:41:42.593000 | A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop ap | |
| CVE-2026-15638 | 0 | 0.20% | 1 | 0 | 2026-09-18T19:34:36.657000 | An unauthenticated user with access to Secret Server could leverage a padding or | |
| CVE-2026-28197 | 8.8 | 0.00% | 2 | 0 | 2026-09-18T19:24:36.593000 | An authenticated, low-privileged user with access to the NetBackup Flex OS mana | |
| CVE-2026-86865 | 7.2 | 0.31% | 1 | 0 | 2026-09-18T19:19:49.643000 | Tanium addressed a SQL injection vulnerability in Asset. | |
| CVE-2026-54520 | 8.1 | 0.40% | 2 | 1 | 2026-09-18T19:16:42.680000 | AI Agent Automation is a modular AI agent workflow automation platform with sche | |
| CVE-2026-78428 | 8.0 | 0.24% | 2 | 0 | 2026-09-18T19:07:38.320000 | For users authenticated through SAML or OpenID Connect (OIDC), this vulnerabilit | |
| CVE-2026-93762 | 9.8 | 0.00% | 2 | 0 | 2026-09-18T19:05:01.127000 | Mongoid contains an unsafe reflection weakness in the query path used for embedd | |
| CVE-2026-93765 | 9.1 | 0.00% | 2 | 0 | 2026-09-18T19:05:01.127000 | Mongoid contains an unsafe reflection weakness in the document persistence layer | |
| CVE-2026-93752 | 7.5 | 0.00% | 2 | 0 | 2026-09-18T18:32:08 | CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclar | |
| CVE-2026-93761 | 7.5 | 0.00% | 2 | 0 | 2026-09-18T18:32:04 | An inefficient regular expression complexity issue in the in-memory query evalua | |
| CVE-2026-93759 | 8.6 | 0.00% | 2 | 0 | 2026-09-18T18:32:04 | Mongoid does not neutralize a string-typed query criterion supplied to its query | |
| CVE-2026-91149 | 7.5 | 0.00% | 2 | 0 | 2026-09-18T18:32:04 | A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this | |
| CVE-2026-93758 | 8.1 | 0.00% | 2 | 0 | 2026-09-18T18:32:02 | An insecure direct object reference in the nested attributes handling of the Mon | |
| CVE-2026-93687 | 7.5 | 0.00% | 2 | 0 | 2026-09-18T18:32:02 | braces through 3.0.3 contains a stack overflow vulnerability in the recursive AS | |
| CVE-2026-93753 | 7.5 | 0.00% | 2 | 0 | 2026-09-18T18:32:01 | deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the merg | |
| CVE-2026-93760 | 8.2 | 0.00% | 2 | 0 | 2026-09-18T18:31:58 | Mongoid does not restrict which query operators may come from caller-supplied fi | |
| CVE-2026-85497 | 9.8 | 0.00% | 2 | 0 | 2026-09-18T18:31:57 | CareCam CM2507 IP cameras store the device's root-account password using a fixed | |
| CVE-2026-84398 | 7.5 | 0.00% | 2 | 0 | 2026-09-18T18:31:54 | CM2507 IP cameras accept an empty password for a privileged account exposed thro | |
| CVE-2026-93606 | 10.0 | 0.00% | 2 | 0 | 2026-09-18T18:18:31.267000 | vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `Node | |
| CVE-2026-93597 | 7.7 | 0.00% | 2 | 0 | 2026-09-18T18:18:29.630000 | ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in th | |
| CVE-2026-67100 | 9.8 | 0.35% | 4 | 0 | 2026-09-18T18:17:11.110000 | HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tena | |
| CVE-2026-90999 | 9.8 | 0.22% | 3 | 0 | 2026-09-18T17:49:08.457000 | Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows | |
| CVE-2026-92943 | 8.1 | 0.27% | 2 | 0 | 2026-09-18T17:48:19.003000 | Improper validation of certificate with host mismatch in the MQTT client TLS con | |
| CVE-2026-61672 | 7.1 | 0.00% | 1 | 0 | 2026-09-18T17:16:58.537000 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0 | |
| CVE-2026-93688 | 7.5 | 0.00% | 2 | 0 | 2026-09-18T16:17:15.683000 | SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV tra | |
| CVE-2026-93374 | 9.6 | 0.27% | 2 | 0 | 2026-09-18T15:33:12 | Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 all | |
| CVE-2026-53266 | 8.8 | 0.12% | 4 | 0 | 2026-09-18T15:32:49 | In the Linux kernel, the following vulnerability has been resolved: netfilter: | |
| CVE-2026-93605 | 10.0 | 0.00% | 2 | 0 | 2026-09-18T15:32:25 | vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where t | |
| CVE-2026-93603 | 10.0 | 0.00% | 2 | 0 | 2026-09-18T15:32:25 | vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` | |
| CVE-2026-93592 | 7.5 | 0.00% | 2 | 0 | 2026-09-18T15:32:24 | vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the | |
| CVE-2026-93591 | 7.6 | 0.00% | 2 | 0 | 2026-09-18T15:32:24 | SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph | |
| CVE-2026-93491 | 7.5 | 0.00% | 2 | 0 | 2026-09-18T15:32:17 | A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker | |
| CVE-2026-87886 | 7.8 | 0.28% | 5 | 0 | 2026-09-18T15:32:10 | Local privilege escalation due to insecure file permissions. The following produ | |
| CVE-2025-39964 | 3.3 | 0.32% | 4 | 1 | 2026-09-18T15:31:06 | In the Linux kernel, the following vulnerability has been resolved: crypto: af_ | |
| CVE-2026-17086 | 8.8 | 0.89% | 2 | 0 | 2026-09-18T15:17:06.153000 | The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for | |
| CVE-2026-85410 | 8.1 | 0.31% | 2 | 0 | 2026-09-18T13:23:37.403000 | The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, | |
| CVE-2026-93450 | 7.5 | 0.66% | 2 | 0 | 2026-09-18T13:18:38.450000 | go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability | |
| CVE-2026-54671 | 8.8 | 0.41% | 2 | 0 | 2026-09-18T13:18:33.920000 | WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps I | |
| CVE-2026-28198 | 8.8 | 0.00% | 2 | 0 | 2026-09-18T12:31:28 | An authenticated, low-privileged user with access to the NetBackup Flex OS mana | |
| CVE-2026-6205 | 8.1 | 0.32% | 2 | 0 | 2026-09-18T09:31:21 | An external control of file name or path vulnerability in Upload API in Synology | |
| CVE-2026-13684 | 9.8 | 0.46% | 4 | 0 | 2026-09-18T09:31:20 | An improper encoding or escaping of output vulnerability in SCGI in Synology Dis | |
| CVE-2026-67101 | 9.3 | 0.27% | 2 | 0 | 2026-09-18T09:31:08 | HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF | |
| CVE-2026-18911 | 7.5 | 1.06% | 2 | 0 | 2026-09-18T06:32:11 | ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent a | |
| CVE-2026-18912 | 7.7 | 1.50% | 2 | 0 | 2026-09-18T06:32:11 | ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authent | |
| CVE-2026-20324 | 9.9 | 0.44% | 3 | 0 | 2026-09-18T04:17:37.867000 | A vulnerability in the sftunnel inter-device communication protocol of Cisco Sec | |
| CVE-2026-93456 | 8.2 | 0.15% | 2 | 0 | 2026-09-18T03:30:28 | django-page-cms through 2.0.13 exempts five admin mutation views from CSRF prote | |
| CVE-2026-93452 | 7.5 | 0.49% | 2 | 0 | 2026-09-18T00:31:21 | snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy. | |
| CVE-2026-70469 | 7.5 | 0.37% | 1 | 0 | 2026-09-17T21:32:42 | Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the appli | |
| CVE-2026-84858 | 8.8 | 0.68% | 1 | 0 | 2026-09-17T21:32:41 | ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote | |
| CVE-2026-92956 | 10.0 | 0.40% | 2 | 0 | 2026-09-17T20:18:59.730000 | vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a def | |
| CVE-2026-92946 | 10.0 | 0.59% | 2 | 0 | 2026-09-17T20:18:59.483000 | vm2 before 3.11.7 contains a remote code execution vulnerability when require.ex | |
| CVE-2026-92940 | 10.0 | 0.34% | 2 | 0 | 2026-09-17T20:18:59.213000 | vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAg | |
| CVE-2026-92919 | 8.1 | 0.38% | 2 | 0 | 2026-09-17T20:18:58.840000 | admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload h | |
| CVE-2026-89026 | 9.8 | 0.52% | 2 | 1 | 2026-09-17T20:18:52.037000 | The Issabel Framework, the web framework supporting Issabel PBX software, before | |
| CVE-2026-87976 | 0 | 0.39% | 1 | 0 | 2026-09-17T20:18:51.303000 | Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when | |
| CVE-2026-54692 | 7.8 | 0.14% | 2 | 0 | 2026-09-17T20:16:52.550000 | SAIL is a cross-platform library for loading and saving images with support for | |
| CVE-2026-73172 | 0 | 1.73% | 1 | 0 | 2026-09-17T19:16:55.587000 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele | |
| CVE-2026-86863 | 9.8 | 0.36% | 2 | 0 | 2026-09-17T18:32:03 | pgAdmin 4's Webserver authentication source is intended to accept an identity as | |
| CVE-2026-92957 | 9.9 | 0.49% | 2 | 0 | 2026-09-17T18:17:15.430000 | vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when e | |
| CVE-2026-92947 | 10.0 | 0.43% | 2 | 0 | 2026-09-17T16:18:34.667000 | vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing | |
| CVE-2026-79752 | 0 | 0.46% | 2 | 0 | 2026-09-17T16:17:44.693000 | CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, | |
| CVE-2026-92950 | 8.6 | 0.22% | 2 | 0 | 2026-09-17T15:32:35 | vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that a | |
| CVE-2026-92954 | 8.6 | 0.34% | 2 | 0 | 2026-09-17T15:32:28 | vm2 is a sandbox library for running untrusted JavaScript in Node.js. In version | |
| CVE-2026-92938 | 9.9 | 0.42% | 2 | 0 | 2026-09-17T15:32:28 | vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to c | |
| CVE-2026-92948 | 9.9 | 0.45% | 2 | 0 | 2026-09-17T15:32:27 | vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist b | |
| CVE-2026-92951 | 9.9 | 0.37% | 2 | 0 | 2026-09-17T15:32:26 | vm2 before 3.11.7 contains an incorrect authorization vulnerability in the exter | |
| CVE-2026-92935 | 9.0 | 0.50% | 2 | 0 | 2026-09-17T15:32:26 | vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and < | |
| CVE-2026-92944 | 9.8 | 0.58% | 2 | 0 | 2026-09-17T15:32:26 | vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Nod | |
| CVE-2026-92941 | 10.0 | 0.27% | 2 | 0 | 2026-09-17T15:32:26 | vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sand | |
| CVE-2026-92937 | 10.0 | 0.79% | 2 | 0 | 2026-09-17T15:32:23 | vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in | |
| CVE-2026-81481 | 7.5 | 0.53% | 2 | 0 | 2026-09-17T15:32:18 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Im | |
| CVE-2026-92955 | 10.0 | 0.62% | 2 | 0 | 2026-09-17T15:32:17 | vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows | |
| CVE-2026-92960 | 10.0 | 0.43% | 2 | 0 | 2026-09-17T15:17:01.170000 | vm2 before 3.11.6 fails to restrict access to os and dns builtins under the buil | |
| CVE-2026-92939 | 9.9 | 0.53% | 2 | 0 | 2026-09-17T15:17:00.650000 | vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM san | |
| CVE-2026-92934 | 9.0 | 0.74% | 2 | 0 | 2026-09-17T15:17:00.520000 | vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that a | |
| CVE-2026-92578 | 8.1 | 0.33% | 1 | 0 | 2026-09-17T15:16:58.247000 | WWBN AVideo through 29.0 contains an authentication bypass vulnerability where t | |
| CVE-2026-92918 | 8.8 | 0.35% | 2 | 0 | 2026-09-17T13:17:01.013000 | admin3 through 3.0.0 persists user session tokens in the audit log event body wh | |
| CVE-2026-76460 | 10.0 | 0.78% | 32 | 1 | 2026-09-17T12:46:31.670000 | A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an | |
| CVE-2026-92913 | 7.4 | 0.51% | 2 | 0 | 2026-09-17T12:18:30.290000 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptograp | |
| CVE-2026-20211 | 9.1 | 0.56% | 1 | 0 | 2026-09-17T12:17:25.350000 | A vulnerability in Cisco ISE could allow an authenticated, remote attacker to ex | |
| CVE-2026-20176 | 9.1 | 0.78% | 1 | 0 | 2026-09-17T12:17:25.200000 | A vulnerability in Cisco ISE could allow an authenticated, remote attacker to ex | |
| CVE-2026-15688 | None | 0.12% | 3 | 0 | 2026-09-17T09:33:03 | Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi | |
| CVE-2026-86320 | 7.8 | 0.22% | 2 | 0 | 2026-09-17T09:33:03 | A flaw was found in flatpak-builder where Git hooks are not disabled when applyi | |
| CVE-2026-87796 | 9.8 | 0.61% | 1 | 1 | 2026-09-17T06:30:45 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbit | |
| CVE-2026-92576 | 8.6 | 0.40% | 1 | 0 | 2026-09-17T00:31:25 | HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability | |
| CVE-2026-20332 | 9.9 | 0.30% | 2 | 0 | 2026-09-16T21:32:55 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-89082 | None | 0.51% | 2 | 0 | 2026-09-16T21:32:55 | HP has identified potential security vulnerabilities in the HP Advance software | |
| CVE-2026-20330 | 9.9 | 0.34% | 2 | 0 | 2026-09-16T21:32:50 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-20192 | 10.0 | 0.43% | 6 | 0 | 2026-09-16T21:32:50 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-20341 | 9.1 | 0.45% | 1 | 0 | 2026-09-16T21:32:50 | A vulnerability in the sftunnel inter-device communication protocol of Cisco Sec | |
| CVE-2026-87024 | 7.2 | 0.31% | 1 | 0 | 2026-09-16T21:32:47 | Tanium addressed a SQL injection vulnerability in Asset. | |
| CVE-2026-77179 | 0 | 0.16% | 8 | 1 | 2026-09-16T20:38:33.883000 | On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows | |
| CVE-2026-79994 | 0 | 0.11% | 3 | 0 | 2026-09-16T20:38:33.883000 | The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a | |
| CVE-2026-70416 | 10.0 | 0.91% | 1 | 0 | 2026-09-16T20:37:16.870000 | Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untru | |
| CVE-2026-78547 | 0 | 0.15% | 1 | 0 | 2026-09-16T19:16:15.097000 | Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows. T | |
| CVE-2026-20331 | 9.6 | 0.23% | 3 | 0 | 2026-09-16T18:32:09 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-20307 | 9.9 | 0.95% | 1 | 0 | 2026-09-16T18:32:09 | A vulnerability in the web-based management interface of Cisco ISE could allow a | |
| CVE-2026-92397 | 9.1 | 2.30% | 1 | 0 | 2026-09-16T18:32:09 | A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected | |
| CVE-2026-89775 | 9.3 | 0.17% | 1 | 0 | 2026-09-16T18:31:58 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: | |
| CVE-2026-61595 | 7.7 | 0.38% | 1 | 0 | 2026-09-16T15:32:15 | ### Impact `djust.tenants` isolation was enforced only on the HTTP path. The cur | |
| CVE-2026-91843 | 9.8 | 0.50% | 19 | 1 | 2026-09-16T15:31:14 | A stack overflow during the unauthenticated login process may allow an attacker | |
| CVE-2026-58704 | 8.0 | 0.21% | 22 | 0 | 2026-09-16T15:30:57 | In Cellular Modem, there is a possible permission bypass due to a logic error in | |
| CVE-2026-40854 | None | 0.30% | 1 | 0 | 2026-09-16T12:30:47 | WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability i | |
| CVE-2026-81642 | None | 0.52% | 4 | 1 | 2026-09-16T09:30:28 | In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in t | |
| CVE-2026-15640 | None | 0.28% | 1 | 0 | 2026-09-16T00:31:41 | Under certain conditions a valid SAML IdP response may be used to impersonate an | |
| CVE-2026-15639 | None | 0.39% | 1 | 0 | 2026-09-16T00:31:33 | An attacker can craft a malicious link that, if used by a legitimate user, may c | |
| CVE-2026-78175 | 8.8 | 0.59% | 2 | 0 | 2026-09-15T15:17:21.707000 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vul | |
| CVE-2026-39919 | 9.8 | 0.49% | 1 | 0 | 2026-09-15T15:17:14.723000 | Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability i | |
| CVE-2026-81915 | 0 | 0.42% | 1 | 0 | 2026-09-15T14:40:24.370000 | Concrete CMS below 9.5.3 does not perform an object-level authorization check wh | |
| CVE-2026-76461 | 9.8 | 2.01% | 5 | 4 | 2026-09-15T12:47:32.497000 | A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure | |
| CVE-2026-89491 | None | 0.21% | 1 | 0 | 2026-09-14T15:33:33 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: clus | |
| CVE-2026-89466 | 7.7 | 0.14% | 1 | 0 | 2026-09-14T15:33:32 | In the Linux kernel, the following vulnerability has been resolved: power: supp | |
| CVE-2026-89478 | 9.8 | 0.52% | 1 | 0 | 2026-09-14T15:32:26 | In the Linux kernel, the following vulnerability has been resolved: sctp: drop | |
| CVE-2026-89483 | 7.5 | 0.56% | 1 | 0 | 2026-09-14T15:32:26 | In the Linux kernel, the following vulnerability has been resolved: nvme: zero | |
| CVE-2026-89442 | 7.8 | 0.16% | 1 | 0 | 2026-09-14T15:32:24 | In the Linux kernel, the following vulnerability has been resolved: platform/x8 | |
| CVE-2026-80938 | None | 0.17% | 1 | 0 | 2026-09-14T15:32:20 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: | |
| CVE-2026-85706 | 10.0 | 14.56% | 1 | 13 | template | 2026-09-14T14:22:15.323000 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 |
| CVE-2026-89510 | 7.8 | 0.18% | 1 | 0 | 2026-09-14T13:19:07.537000 | In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: | |
| CVE-2026-89479 | 9.8 | 0.51% | 1 | 0 | 2026-09-14T13:19:04.457000 | In the Linux kernel, the following vulnerability has been resolved: sctp: stop | |
| CVE-2026-89474 | 0 | 0.17% | 1 | 0 | 2026-09-14T13:19:03.733000 | In the Linux kernel, the following vulnerability has been resolved: power: supp | |
| CVE-2026-89473 | 0 | 0.20% | 1 | 0 | 2026-09-14T13:19:03.620000 | In the Linux kernel, the following vulnerability has been resolved: power: supp | |
| CVE-2026-89460 | 0 | 0.17% | 1 | 0 | 2026-09-14T13:19:02.357000 | In the Linux kernel, the following vulnerability has been resolved: s390/cpum_c | |
| CVE-2026-89444 | 0 | 0.21% | 1 | 0 | 2026-09-14T13:19:01.690000 | In the Linux kernel, the following vulnerability has been resolved: platform/x8 | |
| CVE-2026-81005 | 0 | 0.18% | 2 | 0 | 2026-09-14T13:18:54.883000 | In the Linux kernel, the following vulnerability has been resolved: ipmi: si: F | |
| CVE-2026-81000 | 7.8 | 0.16% | 7 | 0 | 2026-09-14T13:18:54.210000 | In the Linux kernel, the following vulnerability has been resolved: net: tun: b | |
| CVE-2026-80982 | 7.8 | 0.16% | 1 | 0 | 2026-09-14T13:18:52.947000 | In the Linux kernel, the following vulnerability has been resolved: net/smc: fi | |
| CVE-2026-80967 | 8.4 | 0.18% | 1 | 0 | 2026-09-14T13:18:51.370000 | In the Linux kernel, the following vulnerability has been resolved: ALSA: pcxhr | |
| CVE-2026-80952 | 7.8 | 0.12% | 1 | 0 | 2026-09-14T13:18:50.710000 | In the Linux kernel, the following vulnerability has been resolved: i3c: master | |
| CVE-2026-80941 | 0 | 0.21% | 1 | 0 | 2026-09-14T13:18:50.160000 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88 | |
| CVE-2026-80939 | 0 | 0.17% | 1 | 0 | 2026-09-14T13:18:50.037000 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89 | |
| CVE-2026-90894 | 7.8 | 0.15% | 1 | 0 | 2026-09-14T12:31:44 | Parallels Desktop runs prl_disp_service as root. Local clients reach it on the w | |
| CVE-2026-89520 | 7.8 | 0.16% | 1 | 0 | 2026-09-13T09:33:29 | In the Linux kernel, the following vulnerability has been resolved: sched/core: | |
| CVE-2026-80954 | 7.8 | 0.15% | 1 | 0 | 2026-09-13T09:32:11 | In the Linux kernel, the following vulnerability has been resolved: i3c: Fix un | |
| CVE-2026-89492 | 9.8 | 0.60% | 1 | 0 | 2026-09-13T07:17:12.417000 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: vali | |
| CVE-2026-89452 | 8.4 | 0.18% | 1 | 0 | 2026-09-13T07:17:09.477000 | In the Linux kernel, the following vulnerability has been resolved: iommu/msm: | |
| CVE-2026-80953 | 8.4 | 0.18% | 1 | 0 | 2026-09-13T07:17:02.463000 | In the Linux kernel, the following vulnerability has been resolved: i3c: master | |
| CVE-2026-84869 | 9.9 | 0.69% | 1 | 0 | 2026-09-12T04:16:42.757000 | A condition in the ScreenConnect client may allow files to be transferred and ex | |
| CVE-2026-90467 | 4.0 | 0.23% | 1 | 0 | 2026-09-12T03:30:29 | aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by c | |
| CVE-2026-89529 | None | 0.19% | 1 | 0 | 2026-09-11T21:31:37 | In the Linux kernel, the following vulnerability has been resolved: svcrdma: Re | |
| CVE-2026-42016 | 8.1 | 0.89% | 1 | 0 | 2026-09-11T21:31:06 | JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a pri | |
| CVE-2026-89455 | 0 | 0.20% | 1 | 0 | 2026-09-11T20:19:26.220000 | In the Linux kernel, the following vulnerability has been resolved: PCI: plda: | |
| CVE-2026-89453 | 0 | 0.20% | 1 | 0 | 2026-09-11T20:19:25.967000 | In the Linux kernel, the following vulnerability has been resolved: iommu/amd: | |
| CVE-2026-0310 | 0 | 0.34% | 2 | 0 | 2026-09-11T04:17:13.060000 | A buffer overflow vulnerability in the XML processing functionality of Palo Alto | |
| CVE-2026-39113 | 4.0 | 0.21% | 1 | 1 | 2026-09-09T16:04:24.933000 | Buffer Overflow vulnerability in SQLite affected version source snapshots/builds | |
| CVE-2026-15534 | 5.7 | 0.17% | 1 | 0 | 2026-09-08T22:17:38.113000 | Perl versions through 5.45.1 have out-of-bounds heap reads and writes during reg | |
| CVE-2026-60004 | 9.8 | 86.78% | 1 | 10 | template | 2026-09-08T17:56:31 | ### Summary Gitea's `diffpatch` endpoint can be abused to install and execute a |
| CVE-2026-31431 | 7.8 | 99.91% | 1 | 100 | template | 2026-09-08T15:13:07.273000 | In the Linux kernel, the following vulnerability has been resolved: crypto: alg |
| CVE-2026-15315 | 8.8 | 0.30% | 3 | 1 | 2026-09-04T18:32:18 | Tapo C200 v5 contains an improper authentication vulnerability within the login | |
| CVE-2026-15316 | 6.5 | 0.23% | 4 | 1 | 2026-09-04T17:26:04.617000 | An improper input validation vulnerability in the configuration service for proc | |
| CVE-2026-80844 | 0 | 0.19% | 7 | 0 | 2026-09-04T16:18:13.023000 | In the Linux kernel, the following vulnerability has been resolved: xfrm: ah6: | |
| CVE-2026-13348 | None | 0.31% | 2 | 0 | 2026-09-01T15:31:17 | CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability | |
| CVE-2026-56209 | 7.1 | 0.35% | 1 | 0 | 2026-09-01T13:19:49.913000 | An arbitrary address write vulnerability was found in libaom, the reference AV1 | |
| CVE-2026-56210 | 7.1 | 0.31% | 1 | 0 | 2026-08-31T15:35:36 | A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 | |
| CVE-2026-56208 | 7.6 | 0.42% | 1 | 0 | 2026-08-31T15:34:31 | A heap buffer overflow vulnerability was found in libaom, the reference AV1 code | |
| CVE-2026-56211 | 7.1 | 0.48% | 1 | 0 | 2026-08-31T15:34:31 | A remote code execution vulnerability was found in libaom, the reference AV1 cod | |
| CVE-2026-18963 | 9.1 | 3.18% | 2 | 15 | 2026-08-28T22:53:42 | A flaw was found in the reset-credentials flow of the keycloak-services componen | |
| CVE-2026-56389 | 8.6 | 0.16% | 2 | 0 | 2026-08-24T18:32:30 | GNU Bison allows for an execution of an arbitrary program during HTML report gen | |
| CVE-2026-74469 | 8.8 | 0.47% | 7 | 0 | 2026-08-19T17:21:03.977000 | In the Linux kernel, the following vulnerability has been resolved: sctp: preve | |
| CVE-2026-68121 | 7.8 | 0.14% | 7 | 0 | 2026-08-19T17:20:29.553000 | In the Linux kernel, the following vulnerability has been resolved: pppoe: relo | |
| CVE-2026-59310 | 9.8 | 49.68% | 3 | 2 | 2026-08-18T18:32:52 | VMware vCenter contains a directory traversal vulnerability in the Syslog server | |
| CVE-2026-19487 | 5.3 | 0.42% | 1 | 0 | 2026-08-13T21:37:11 | Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression matc | |
| CVE-2026-5430 | 10.0 | 0.32% | 1 | 1 | 2026-08-06T09:30:40 | The JWT authentication mechanism accepts tokens signed with algorithms other tha | |
| CVE-2026-7646 | 6.5 | 0.30% | 2 | 5 | 2026-08-05T18:31:49 | IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from | |
| CVE-2026-15830 | 5.3 | 1.26% | 1 | 0 | 2026-08-04T18:31:31 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDja | |
| CVE-2026-13584 | None | 0.13% | 2 | 0 | 2026-08-04T06:32:37 | Improper Enforcement of Message Integrity During Transmission in a Communication | |
| CVE-2026-45659 | 8.8 | 76.08% | 1 | 2 | 2026-07-01T21:35:53 | Deserialization of untrusted data in Microsoft Office SharePoint allows an autho | |
| CVE-2026-58138 | 9.8 | 9.26% | 2 | 6 | template | 2026-06-30T21:31:51 | Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code ex |
| CVE-2026-8024 | 9.8 | 0.55% | 1 | 0 | 2026-06-22T17:47:16.070000 | A remote, unauthenticated attacker may exploit a deserialization of untrusted da | |
| CVE-2026-32746 | 9.8 | 23.67% | 3 | 8 | 2026-03-23T15:31:40 | telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMO | |
| CVE-2024-20260 | 8.6 | 0.59% | 1 | 0 | 2024-10-23T18:33:16 | A vulnerability in the VPN and management web servers of the Cisco Adaptive Secu | |
| CVE-2026-57228 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-63447 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-63446 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-63452 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-68928 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-71418 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-92708 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-72878 | 0 | 0.27% | 2 | 0 | N/A | ||
| CVE-2026-54670 | 0 | 0.55% | 2 | 0 | N/A | ||
| CVE-2026-54734 | 0 | 0.36% | 2 | 0 | N/A | ||
| CVE-2026-93426 | 0 | 0.37% | 2 | 0 | N/A | ||
| CVE-2026-54752 | 0 | 0.35% | 2 | 0 | N/A | ||
| CVE-2026-54716 | 0 | 0.32% | 2 | 0 | N/A | ||
| CVE-2026-54627 | 0 | 0.44% | 2 | 0 | N/A | ||
| CVE-2026-93337 | 0 | 0.15% | 2 | 0 | N/A | ||
| CVE-2026-85500 | 0 | 0.55% | 2 | 0 | N/A | ||
| CVE-2026-59347 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-59346 | 0 | 0.00% | 2 | 1 | N/A |
updated 2026-09-19T06:16:30.557000
2 posts
🔴 CVE-2026-93741 - Critical (10)
A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. It is possib...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93741/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-93741 - Critical (10)
A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. It is possib...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93741/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-19T04:18:00.780000
6 posts
If you missed this, Microsoft patched this vulnerability yesterday:
CVE-2026-85889: Azure AI Foundry Elevation of Privilege Vulnerability (new) https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85889
More:
The Hacker News: Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation https://thehackernews.com/2026/09/microsoft-patches-cvss-100-azure-ai.html @thehackernews #infosec #vulnerability #Microsoft #Azure
##Microsoft patched CVE-2026-85889 in Azure AI Foundry, a missing authentication for critical function flaw with CVSS 10.0 enabling unauthenticated remote privilege escalation. MSRC reports full mitigation, but the network-accessible, no-auth vector makes tenant privilege review and log auditing critical. #AzureSecurity #PrivilegeEscalation #AiSecurity
https://cyberworldops.eu/en/azure-ai-foundry-authentication-failure-earns-maximum-severity-cvss
##CVE-2026-85889 | CRITICAL flaw in Azure AI Foundry: missing authentication for a critical function (CVSS 10) allows remote privilege escalation. Microsoft patched this cloud vulnerability — verify your environment per MSRC: https://radar.offseq.com/threat/cve-2026-85889-cwe-306-missing-authentication-for-critical-function-in-microsoft-azure-ai-foundry-e4d903ee0861658f #OffSeq #Azure #Infosec #CVE202685889
##If you missed this, Microsoft patched this vulnerability yesterday:
CVE-2026-85889: Azure AI Foundry Elevation of Privilege Vulnerability (new) https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85889
More:
The Hacker News: Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation https://thehackernews.com/2026/09/microsoft-patches-cvss-100-azure-ai.html @thehackernews #infosec #vulnerability #Microsoft #Azure
##Microsoft patched CVE-2026-85889 in Azure AI Foundry, a missing authentication for critical function flaw with CVSS 10.0 enabling unauthenticated remote privilege escalation. MSRC reports full mitigation, but the network-accessible, no-auth vector makes tenant privilege review and log auditing critical. #AzureSecurity #PrivilegeEscalation #AiSecurity
https://cyberworldops.eu/en/azure-ai-foundry-authentication-failure-earns-maximum-severity-cvss
##CVE-2026-85889 | CRITICAL flaw in Azure AI Foundry: missing authentication for a critical function (CVSS 10) allows remote privilege escalation. Microsoft patched this cloud vulnerability — verify your environment per MSRC: https://radar.offseq.com/threat/cve-2026-85889-cwe-306-missing-authentication-for-critical-function-in-microsoft-azure-ai-foundry-e4d903ee0861658f #OffSeq #Azure #Infosec #CVE202685889
##updated 2026-09-19T03:17:17.723000
4 posts
🟠 CVE-2026-92807 - High (8.8)
The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via the `pdf_created_callback` shortcode attribute. The `eval_shortcode()` function copies any non-`...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92807/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-92807: HIGH severity (CVSS 8.8) code injection in pdfcrowd Save as PDF Plugin for WordPress (<=4.6.1). Contributor+ users can run arbitrary PHP — risking API credential leaks & server compromise. Restrict access, monitor for patch. https://radar.offseq.com/threat/cve-2026-92807-cwe-94-improper-control-of-generation-of-code-code-injection-in-pdfcrowd-save-as-pdf-bd60570e4aef57a5 #OffSeq #WordPress #Infosec
##🟠 CVE-2026-92807 - High (8.8)
The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via the `pdf_created_callback` shortcode attribute. The `eval_shortcode()` function copies any non-`...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92807/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-92807: HIGH severity (CVSS 8.8) code injection in pdfcrowd Save as PDF Plugin for WordPress (<=4.6.1). Contributor+ users can run arbitrary PHP — risking API credential leaks & server compromise. Restrict access, monitor for patch. https://radar.offseq.com/threat/cve-2026-92807-cwe-94-improper-control-of-generation-of-code-code-injection-in-pdfcrowd-save-as-pdf-bd60570e4aef57a5 #OffSeq #WordPress #Infosec
##updated 2026-09-19T03:17:17.040000
4 posts
🔴 CVE-2026-92229 - Critical (9.1)
The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92229/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-92229: CRITICAL code injection in wpmudev Forminator Forms plugin (≤1.57.2). Unauthenticated attackers can execute arbitrary shortcodes, risking full WordPress site compromise. Restrict or disable plugin now. https://radar.offseq.com/threat/cve-2026-92229-cwe-94-improper-control-of-generation-of-code-code-injection-in-wpmudev-forminator-8ac627c2b84841fc #OffSeq #WordPress #CVE202692229
##🔴 CVE-2026-92229 - Critical (9.1)
The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92229/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-92229: CRITICAL code injection in wpmudev Forminator Forms plugin (≤1.57.2). Unauthenticated attackers can execute arbitrary shortcodes, risking full WordPress site compromise. Restrict or disable plugin now. https://radar.offseq.com/threat/cve-2026-92229-cwe-94-improper-control-of-generation-of-code-code-injection-in-wpmudev-forminator-8ac627c2b84841fc #OffSeq #WordPress #CVE202692229
##updated 2026-09-19T03:17:16.587000
4 posts
🔴 CVE-2026-89274 - Critical (9.1)
The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()` on every...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89274/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##WP Recipe Maker <=10.8.1 hit by CVE-2026-89274: CRITICAL code injection via unsanitized shortcodes in comment ratings. Unauthenticated attackers can trigger arbitrary shortcode execution on recipe pages. Upgrade ASAP. https://radar.offseq.com/threat/cve-2026-89274-cwe-94-improper-control-of-generation-of-code-code-injection-in-brechtvds-wp-recipe-77a2426acb987f3a #OffSeq #WordPress #CVE202689274 #Infosec
##🔴 CVE-2026-89274 - Critical (9.1)
The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()` on every...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89274/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##WP Recipe Maker <=10.8.1 hit by CVE-2026-89274: CRITICAL code injection via unsanitized shortcodes in comment ratings. Unauthenticated attackers can trigger arbitrary shortcode execution on recipe pages. Upgrade ASAP. https://radar.offseq.com/threat/cve-2026-89274-cwe-94-improper-control-of-generation-of-code-code-injection-in-brechtvds-wp-recipe-77a2426acb987f3a #OffSeq #WordPress #CVE202689274 #Infosec
##updated 2026-09-19T03:17:15.853000
2 posts
🟠 CVE-2026-87909 - High (7.5)
The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMag...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87909/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-87909 - High (7.5)
The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMag...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87909/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-19T03:17:15.573000
2 posts
🔴 CVE-2026-84434 - Critical (9.8)
The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84434/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-84434 - Critical (9.8)
The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84434/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-19T00:32:51
2 posts
🔴 CVE-2026-93739 - Critical (9.9)
A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed fro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93739/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-93739 - Critical (9.9)
A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed fro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93739/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-19T00:32:50
2 posts
🔴 CVE-2026-93740 - Critical (10)
A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the at...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93740/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-93740 - Critical (10)
A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the at...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93740/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T22:17:10.313000
4 posts
CVE-2026-75885: CRITICAL SSRF & DoS in Red Hat OpenShift Container Platform 4. Unauthenticated access to /api/devfile/ endpoints can expose internal services & cause resource exhaustion. No fix yet — restrict access & monitor advisories. https://radar.offseq.com/threat/cve-2026-75885-server-side-request-forgery-ssrf-in-red-hat-red-hat-openshift-container-platform-4-7be62bac64620783 #OffSeq #OpenShift #SSRF
##🔴 CVE-2026-75885 - Critical (9.3)
A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75885/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-75885: CRITICAL SSRF & DoS in Red Hat OpenShift Container Platform 4. Unauthenticated access to /api/devfile/ endpoints can expose internal services & cause resource exhaustion. No fix yet — restrict access & monitor advisories. https://radar.offseq.com/threat/cve-2026-75885-server-side-request-forgery-ssrf-in-red-hat-red-hat-openshift-container-platform-4-7be62bac64620783 #OffSeq #OpenShift #SSRF
##🔴 CVE-2026-75885 - Critical (9.3)
A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75885/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:44
2 posts
🔴 CVE-2026-93738 - Critical (9.9)
A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possible to be ca...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93738/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-93738 - Critical (9.9)
A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possible to be ca...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93738/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:43
2 posts
🟠 CVE-2026-88097 - High (8.1)
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88097/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-88097 - High (8.1)
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88097/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:42
2 posts
🟠 CVE-2026-93872 - High (7.5)
Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93872/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93872 - High (7.5)
Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93872/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:41
2 posts
🟠 CVE-2026-93031 - High (8.8)
The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This i...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93031/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93031 - High (8.8)
The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This i...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93031/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:41
2 posts
🟠 CVE-2026-93868 - High (8.1)
Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the server Date...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93868/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93868 - High (8.1)
Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the server Date...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93868/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:40
4 posts
Go hack more LLM shit.
https://nvd.nist.gov/vuln/detail/cve-2026-93839
sev:CRIT 9.3 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
##LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers can disclose full user prompts routed to their socket, trigger denial of service by replacing legitimate nodes, or make the PD Master issue requests to internal network addresses.
🔴 CVE-2026-93839 - Critical (9.8)
LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers ca...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93839/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Go hack more LLM shit.
https://nvd.nist.gov/vuln/detail/cve-2026-93839
sev:CRIT 9.3 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
##LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers can disclose full user prompts routed to their socket, trigger denial of service by replacing legitimate nodes, or make the PD Master issue requests to internal network addresses.
🔴 CVE-2026-93839 - Critical (9.8)
LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers ca...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93839/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:40
2 posts
🟠 CVE-2026-84241 - High (8.1)
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84241/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84241 - High (8.1)
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84241/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:31:33
2 posts
1 repos
CVE ID: CVE-2025-39682
Vendor: Linux
Product: Kernel
Date Added: 2026-09-18
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39682
CVE ID: CVE-2025-39682
Vendor: Linux
Product: Kernel
Date Added: 2026-09-18
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39682
updated 2026-09-18T21:18:48.020000
2 posts
🟠 CVE-2026-93572 - High (7.5)
## Summary
`RedisArrayAggregator` recently added `maxElements` and `maxNestedArrayDepth` limits to fix public Redis resource-exhaustion advisories. The limits are independent, but the allocator remains eager: every positive nested RESP array he...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93572/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93572 - High (7.5)
## Summary
`RedisArrayAggregator` recently added `maxElements` and `maxNestedArrayDepth` limits to fix public Redis resource-exhaustion advisories. The limits are independent, but the allocator remains eager: every positive nested RESP array he...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93572/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:17:01.217000
2 posts
🟠 CVE-2026-57227 - High (7.5)
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.0 until 7.0.17 and 8.0.6, the MQTT parser in rust/src/mqtt/mqtt.rs permits repeated PUBREC or PUBREL messages to be appe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57227/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-57227 - High (7.5)
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.0 until 7.0.17 and 8.0.6, the MQTT parser in rust/src/mqtt/mqtt.rs permits repeated PUBREC or PUBREL messages to be appe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57227/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T20:17:31.113000
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-18T20:17:17.253000
2 posts
🔴 CVE-2026-54767 - Critical (9.1)
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded chave_correta value embedded...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54767/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-54767 - Critical (9.1)
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded chave_correta value embedded...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54767/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T20:17:13.133000
2 posts
Grab a coffee. Cisco has posted several advisories, one of them addressing a critical vulnerability that was first published on the 16th. More here https://sec.cloudapps.cisco.com/security/center/publicationListing.x
CRITICAL: CVE-2026-20329, CVE-2026-20330, and CVE-2026-20331: Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 @TalosSecurity #Cisco #vulnerability #infosec
##Grab a coffee. Cisco has posted several advisories, one of them addressing a critical vulnerability that was first published on the 16th. More here https://sec.cloudapps.cisco.com/security/center/publicationListing.x
CRITICAL: CVE-2026-20329, CVE-2026-20330, and CVE-2026-20331: Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 @TalosSecurity #Cisco #vulnerability #infosec
##updated 2026-09-18T20:17:06.860000
2 posts
Synology fixed 8 DSM vulnerabilities, including two critical unauthenticated flaws (CVE-2026-13684, CVE-2026-13639) on DiskStation Manager. Update now.
#Synology #DSM #NAS #CVE #Vulnerability #DiskStation #InfoSec #PatchNow #NetworkSecurity #DataStorage
##Synology fixed 8 DSM vulnerabilities, including two critical unauthenticated flaws (CVE-2026-13684, CVE-2026-13639) on DiskStation Manager. Update now.
#Synology #DSM #NAS #CVE #Vulnerability #DiskStation #InfoSec #PatchNow #NetworkSecurity #DataStorage
##updated 2026-09-18T19:41:42.593000
1 posts
CVE-2026-92838: HIGH severity DLL hijack in GeoVision GV-Remote E-map 18.3.1 🖥️. Local attackers can execute arbitrary code via unsafe DLL load paths. Restrict directory write access; check vendor guidance. https://radar.offseq.com/threat/cve-2026-92838-cwe-427-uncontrolled-search-path-element-in-geovision-inc-gv-remote-e-map-0688637b5de2fbea #OffSeq #Vuln #InfoSec #Windows
##updated 2026-09-18T19:34:36.657000
1 posts
Go hack more Secret Server shit.
https://delinea.com/security-advisories
##Authentication Bypass via SAML Response Manipulation - CVE-2026-15640
Reflected Cross-Site Scripting - CVE-2026-15639
Cryptographic Padding Oracle - CVE-2026-15638
updated 2026-09-18T19:24:36.593000
2 posts
🟠 CVE-2026-28197 - High (8.8)
An authenticated, low-privileged user with access to the NetBackup Flex
OS management shell could supply a specially crafted input to a
privileged administrative command, causing it to execute arbitrary code
with root-level permissions. Success...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-28197/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-28197 - High (8.8)
An authenticated, low-privileged user with access to the NetBackup Flex
OS management shell could supply a specially crafted input to a
privileged administrative command, causing it to execute arbitrary code
with root-level permissions. Success...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-28197/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T19:19:49.643000
1 posts
🟠 CVE-2026-86865 - High (8.8)
Tanium addressed a SQL injection vulnerability in Asset.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86865/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T19:16:42.680000
2 posts
1 repos
🟠 CVE-2026-54520 - High (8.1)
AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.path value...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54520/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-54520 - High (8.1)
AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.path value...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54520/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T19:07:38.320000
2 posts
🟠 CVE-2026-78428 - High (8)
For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78428/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-78428 - High (8)
For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78428/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T19:05:01.127000
2 posts
🔴 CVE-2026-93762 - Critical (9.8)
Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended d...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93762/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-93762 - Critical (9.8)
Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended d...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93762/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T19:05:01.127000
2 posts
🔴 CVE-2026-93765 - Critical (9.1)
Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal metho...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93765/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-93765 - Critical (9.1)
Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal metho...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93765/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T18:32:08
2 posts
🟠 CVE-2026-93752 - High (7.5)
CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names. Attackers can supply a stylesheet with a declaration named length to replace the internal counter a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93752/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93752 - High (7.5)
CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names. Attackers can supply a stylesheet with a declaration named length to replace the internal counter a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93752/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T18:32:04
2 posts
🟠 CVE-2026-93761 - High (7.5)
An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application process. Applications that place...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93761/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93761 - High (7.5)
An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application process. Applications that place...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93761/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T18:32:04
2 posts
🟠 CVE-2026-93759 - High (8.6)
Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application supplies as...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93759/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93759 - High (8.6)
Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application supplies as...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93759/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T18:32:04
2 posts
🟠 CVE-2026-91149 - High (7.5)
A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to create an unbounded number of de...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91149/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-91149 - High (7.5)
A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to create an unbounded number of de...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91149/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T18:32:02
2 posts
🟠 CVE-2026-93758 - High (8.1)
An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a request can ca...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93758/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93758 - High (8.1)
An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a request can ca...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93758/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T18:32:02
2 posts
🟠 CVE-2026-93687 - High (7.5)
braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate the Node.js proce...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93687/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93687 - High (7.5)
braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate the Node.js proce...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93687/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T18:32:01
2 posts
🟠 CVE-2026-93753 - High (7.5)
deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject at...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93753/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93753 - High (7.5)
deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject at...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93753/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T18:31:58
2 posts
🟠 CVE-2026-93760 - High (8.2)
Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter parameters in this way, a party...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93760/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93760 - High (8.2)
Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter parameters in this way, a party...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93760/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T18:31:57
2 posts
Oh look, yet another sev:CRIT CVE where the CVSS string doesn't match the description. Thanks, Doge.
sev:CRIT 9.3 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
##CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking. An attacker who obtains the firmware image or password database could recover the associated credential, which may also be reusable across other devices running the same firmware.
Oh look, yet another sev:CRIT CVE where the CVSS string doesn't match the description. Thanks, Doge.
sev:CRIT 9.3 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
##CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking. An attacker who obtains the firmware image or password database could recover the associated credential, which may also be reusable across other devices running the same firmware.
updated 2026-09-18T18:31:54
2 posts
🟠 CVE-2026-84398 - High (7.5)
CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-pr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84398/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84398 - High (7.5)
CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-pr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84398/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T18:18:31.267000
2 posts
RE: https://infosec.exchange/@cR0w/117287817060203283
But wait, there's more perfect 10s!
🥳
https://www.cve.org/CVERecord?id=CVE-2026-93603
RE: https://infosec.exchange/@cR0w/117287817060203283
But wait, there's more perfect 10s!
🥳
https://www.cve.org/CVERecord?id=CVE-2026-93603
updated 2026-09-18T18:18:29.630000
2 posts
🟠 CVE-2026-93597 - High (7.7)
ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands. Authenticated attackers can supply URLs resolving to NAT64, 6to4, or Teredo addresses embedding RFC 1918 or l...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93597/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93597 - High (7.7)
ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands. Authenticated attackers can supply URLs resolving to NAT64, 6to4, or Teredo addresses embedding RFC 1918 or l...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93597/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T18:17:11.110000
4 posts
HCL Software patched critical HCL BigFix vulnerabilities, including CVE-2026-67100 and CVE-2026-18963. Patch now to prevent total account takeovers.
#HCLBigFix #Cybersecurity #CVE202667100 #Vulnerability #InfoSec
##CVE-2026-67100: HCL BigFix Service Management v23 faces CRITICAL SQL injection & cross-tenant data exposure (CVSS 9.8). Authenticated attackers can access PII across orgs. No patch yet — restrict access & monitor logs. https://radar.offseq.com/threat/cve-2026-67100-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-dc5bf090924b31aa #OffSeq #Vuln #SQLi #Infosec
##HCL Software patched critical HCL BigFix vulnerabilities, including CVE-2026-67100 and CVE-2026-18963. Patch now to prevent total account takeovers.
#HCLBigFix #Cybersecurity #CVE202667100 #Vulnerability #InfoSec
##CVE-2026-67100: HCL BigFix Service Management v23 faces CRITICAL SQL injection & cross-tenant data exposure (CVSS 9.8). Authenticated attackers can access PII across orgs. No patch yet — restrict access & monitor logs. https://radar.offseq.com/threat/cve-2026-67100-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-dc5bf090924b31aa #OffSeq #Vuln #SQLi #Infosec
##updated 2026-09-18T17:49:08.457000
3 posts
PhantomFix: A fake bug to Sentry Seer gets a coding agent to run attacker code
CERT/CC는 Sentry Seer가 이슈를 코딩 에이전트에 자동으로 넘기도록 설정된 경우, 공개 DSN으로 제출한 조작된 오류 이벤트가 에이전트 프롬프트에 유입되는 취약점(CVE-2026-90999)을 공개했습니다. 공격자는 예외 메시지·스택 트레이스·breadcrumb 등 텔레메트리 필드를 이용해 가짜 버그 분석을 만들고, 코딩 에이전트가 공격자 제어 패키지를 내려받아 실행하도록 유도할 수 있습니다. 그 결과 PR 검토 이전에 연결된 저장소에 접근 가능한 에이전트 실행 환경에서 임의 코드 실행이 가능할 수 있습니다. 현재 공급업체 패치 정보는 없으므로 Seer의 자동 re...
##CVE-2026-90999: A fabricated Sentry bug report can make Seer's coding agent run attacker code https://agyn.io/blog/sentry-seer-autofix-vulnerability
##CVE-2026-90999: A fabricated Sentry bug report can make Seer's coding agent run attacker code https://agyn.io/blog/sentry-seer-autofix-vulnerability
##updated 2026-09-18T17:48:19.003000
2 posts
🟠 CVE-2026-92943 - High (8.1)
Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might allow an adversary-in-the-middle actor to impersonate the AWS IoT Core...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92943/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-92943 - High (8.1)
Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might allow an adversary-in-the-middle actor to impersonate the AWS IoT Core...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92943/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T17:16:58.537000
1 posts
CVE-2026-61672 - Policy bypass vulnerability in Capsule for Kubernetes allows metadata restriction evasion. CVSS 7.1. Update to 0.13.7 now. #CVE #Kubernetes #infosec
##updated 2026-09-18T16:17:15.683000
2 posts
🟠 CVE-2026-93688 - High (7.5)
SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation. Unauthenticated attackers can reach the decode engine's POST /gene...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93688/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93688 - High (7.5)
SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation. Unauthenticated attackers can reach the decode engine's POST /gene...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93688/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T15:33:12
2 posts
Google patched critical Google Chrome vulnerabilities. Update now to address multiple Google Chrome vulnerabilities like CVE-2026-93374 and stay secure.
#GoogleChrome #ChromeSecurity #CVE202693374 #BrowserSecurity #InfoSec
##Google patched critical Google Chrome vulnerabilities. Update now to address multiple Google Chrome vulnerabilities like CVE-2026-93374 and stay secure.
#GoogleChrome #ChromeSecurity #CVE202693374 #BrowserSecurity #InfoSec
##updated 2026-09-18T15:32:49
4 posts
New.
CISA Adds Two Known Exploited Vulnerabilities to Catalog.
CVE-2025-39964 Linux Kernel Race Condition Vulnerability https://www.cve.org/CVERecord?id=CVE-2025-39964
CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-53266 #CISA #Linux #infosec #vulnerability
##🚨 [CISA-2026:0918] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0918)
CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2025-39964 (https://secdb.nttzen.cloud/cve/detail/CVE-2025-39964)
- Name: Linux Kernel Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce; https://git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9; https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8; https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84; https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d; https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042; https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-39964
⚠️ CVE-2026-53266 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-53266)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87; https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b; https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0; https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b; https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093; https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d; https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5; https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53266
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260918 #cisa20260918 #cve_2025_39964 #cve_2026_53266 #cve202539964 #cve202653266
##New.
CISA Adds Two Known Exploited Vulnerabilities to Catalog.
CVE-2025-39964 Linux Kernel Race Condition Vulnerability https://www.cve.org/CVERecord?id=CVE-2025-39964
CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-53266 #CISA #Linux #infosec #vulnerability
##🚨 [CISA-2026:0918] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0918)
CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2025-39964 (https://secdb.nttzen.cloud/cve/detail/CVE-2025-39964)
- Name: Linux Kernel Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce; https://git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9; https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8; https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84; https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d; https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042; https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-39964
⚠️ CVE-2026-53266 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-53266)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87; https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b; https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0; https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b; https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093; https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d; https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5; https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53266
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260918 #cisa20260918 #cve_2025_39964 #cve_2026_53266 #cve202539964 #cve202653266
##updated 2026-09-18T15:32:25
2 posts
RE: https://infosec.exchange/@cR0w/117287817060203283
But wait, there's more perfect 10s!
🥳
https://www.cve.org/CVERecord?id=CVE-2026-93603
RE: https://infosec.exchange/@cR0w/117287817060203283
But wait, there's more perfect 10s!
🥳
https://www.cve.org/CVERecord?id=CVE-2026-93603
updated 2026-09-18T15:32:25
2 posts
RE: https://infosec.exchange/@cR0w/117287817060203283
But wait, there's more perfect 10s!
🥳
https://www.cve.org/CVERecord?id=CVE-2026-93603
RE: https://infosec.exchange/@cR0w/117287817060203283
But wait, there's more perfect 10s!
🥳
https://www.cve.org/CVERecord?id=CVE-2026-93603
updated 2026-09-18T15:32:24
2 posts
🟠 CVE-2026-93592 - High (7.5)
vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. A single request with a negative token...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93592/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93592 - High (7.5)
vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. A single request with a negative token...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93592/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T15:32:24
2 posts
🟠 CVE-2026-93591 - High (7.6)
SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values are concatenated raw into SQL string literals without escaping single quotes. A publish-mode reader or anonymous visitor can i...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93591/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93591 - High (7.6)
SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values are concatenated raw into SQL string literals without escaping single quotes. A publish-mode reader or anonymous visitor can i...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93591/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T15:32:17
2 posts
🟠 CVE-2026-93491 - High (7.5)
A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the methodOverflowQueue to grow without...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93491/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93491 - High (7.5)
A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the methodOverflowQueue to grow without...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93491/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T15:32:10
5 posts
🟠 New security advisory:
CVE-2026-87886 affects multiple systems.
• Impact: Significant security breach potential
• Risk: Unauthorized access or data exposure
• Mitigation: Apply patches within 24-48 hours
Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-87886-acronis-cpanel-plugin-root-escalation-exploited
by Yazoul AI
##📰 CISA Adds Actively Exploited Cisco and Acronis Flaws to KEV Catalog
CISA adds two actively exploited vulnerabilities to its KEV catalog: a critical Cisco ISE auth bypass (CVE-2026-76460) and an Acronis Backup flaw (CVE-2026-87886). Federal agencies must patch urgently. #CISA #KEV #PatchNow
##(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-87886 – Acronis Backup Incorrect Default Permissions Vulnerability
A strategic executive briefing detailing permission hardening, risk deliberation, and incident response frameworks for CVE-2026-87886 in Acronis Backup environments....
##Acronis Patches Actively Exploited Privilege Escalation Flaw in Hosting Plugins
Acronis patched a high-severity privilege escalation vulnerability (CVE-2026-87886) in its cPanel and Plesk backup plugins that attackers are actively exploiting in the wild. The flaw allows local users to gain root access by taking advantage of insecure file permissions.
**Check your Linux hosting servers for the Acronis backup plugin and update it to the latest version right now. Attackers are already using this flaw to gain root access, so do not wait for your next scheduled maintenance window.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/acronis-patches-actively-exploited-privilege-escalation-flaw-in-hosting-plugins-a-s-1-m-a/gD2P6Ple2L
CVE ID: CVE-2026-87886
Vendor: Acronis
Product: Backup
Date Added: 2026-09-16
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87886
updated 2026-09-18T15:31:06
4 posts
1 repos
New.
CISA Adds Two Known Exploited Vulnerabilities to Catalog.
CVE-2025-39964 Linux Kernel Race Condition Vulnerability https://www.cve.org/CVERecord?id=CVE-2025-39964
CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-53266 #CISA #Linux #infosec #vulnerability
##🚨 [CISA-2026:0918] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0918)
CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2025-39964 (https://secdb.nttzen.cloud/cve/detail/CVE-2025-39964)
- Name: Linux Kernel Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce; https://git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9; https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8; https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84; https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d; https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042; https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-39964
⚠️ CVE-2026-53266 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-53266)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87; https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b; https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0; https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b; https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093; https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d; https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5; https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53266
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260918 #cisa20260918 #cve_2025_39964 #cve_2026_53266 #cve202539964 #cve202653266
##New.
CISA Adds Two Known Exploited Vulnerabilities to Catalog.
CVE-2025-39964 Linux Kernel Race Condition Vulnerability https://www.cve.org/CVERecord?id=CVE-2025-39964
CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-53266 #CISA #Linux #infosec #vulnerability
##🚨 [CISA-2026:0918] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0918)
CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2025-39964 (https://secdb.nttzen.cloud/cve/detail/CVE-2025-39964)
- Name: Linux Kernel Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce; https://git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9; https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8; https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84; https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d; https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042; https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-39964
⚠️ CVE-2026-53266 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-53266)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87; https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b; https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0; https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b; https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093; https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d; https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5; https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53266
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260918 #cisa20260918 #cve_2025_39964 #cve_2026_53266 #cve202539964 #cve202653266
##updated 2026-09-18T15:17:06.153000
2 posts
🟠 CVE-2026-17086 - High (8.8)
The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input . This makes it possible for auth...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17086/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-17086 - High (8.8)
The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input . This makes it possible for auth...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17086/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T13:23:37.403000
2 posts
🟠 CVE-2026-85410 - High (8.1)
The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.2. This is due to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85410/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-85410 - High (8.1)
The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.2. This is due to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85410/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T13:18:38.450000
2 posts
🟠 CVE-2026-93450 - High (7.5)
go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attackers can submit deeply nested JSON documents to s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93450/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93450 - High (7.5)
go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attackers can submit deeply nested JSON documents to s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93450/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T13:18:33.920000
2 posts
🟠 CVE-2026-54671 - High (8.8)
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource array in web/controle/control.php, and verificarPermissao in web/dao/MiddlewareDAO.php treats that empty array as unconditional acc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54671/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-54671 - High (8.8)
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource array in web/controle/control.php, and verificarPermissao in web/dao/MiddlewareDAO.php treats that empty array as unconditional acc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54671/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T12:31:28
2 posts
🟠 CVE-2026-28198 - High (8.8)
An authenticated, low-privileged user with access to the NetBackup Flex
OS management shell could bypass the cryptographic signature
verification step of a privileged support command by supplying a
specially formed access credential. Successful...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-28198/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-28198 - High (8.8)
An authenticated, low-privileged user with access to the NetBackup Flex
OS management shell could bypass the cryptographic signature
verification step of a privileged support command by supplying a
specially formed access credential. Successful...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-28198/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T09:31:21
2 posts
🟠 CVE-2026-6205 - High (8.1)
An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and conduct den...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-6205/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-6205 - High (8.1)
An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and conduct den...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-6205/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T09:31:20
4 posts
🔴 CVE-2026-13684 - Critical (9.8)
An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-13684/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Synology fixed 8 DSM vulnerabilities, including two critical unauthenticated flaws (CVE-2026-13684, CVE-2026-13639) on DiskStation Manager. Update now.
#Synology #DSM #NAS #CVE #Vulnerability #DiskStation #InfoSec #PatchNow #NetworkSecurity #DataStorage
##🔴 CVE-2026-13684 - Critical (9.8)
An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-13684/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Synology fixed 8 DSM vulnerabilities, including two critical unauthenticated flaws (CVE-2026-13684, CVE-2026-13639) on DiskStation Manager. Update now.
#Synology #DSM #NAS #CVE #Vulnerability #DiskStation #InfoSec #PatchNow #NetworkSecurity #DataStorage
##updated 2026-09-18T09:31:08
2 posts
CVE-2026-67101: CRITICAL SSRF in HCL BigFix Service Management v23 (CVSS 9.3). Unauthenticated attackers can access internal systems. No patch yet — restrict service and monitor requests. https://radar.offseq.com/threat/cve-2026-67101-cwe-918-server-side-request-forgery-ssrf-in-hcl-software-hcl-bigfix-service-management-ca42c9cfa875105e #OffSeq #SSRF #Vuln #Infosec
##CVE-2026-67101: CRITICAL SSRF in HCL BigFix Service Management v23 (CVSS 9.3). Unauthenticated attackers can access internal systems. No patch yet — restrict service and monitor requests. https://radar.offseq.com/threat/cve-2026-67101-cwe-918-server-side-request-forgery-ssrf-in-hcl-software-hcl-bigfix-service-management-ca42c9cfa875105e #OffSeq #SSRF #Vuln #Infosec
##updated 2026-09-18T06:32:11
2 posts
🟠 CVE-2026-18911 - High (7.5)
ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18911/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18911 - High (7.5)
ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18911/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T06:32:11
2 posts
🟠 CVE-2026-18912 - High (7.7)
ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18912/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18912 - High (7.7)
ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18912/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T04:17:37.867000
3 posts
https://thecybersecguru.com/news/cisco-fmc-cve-2026-20324-sftunnel-root-rce/
##Cisco Secure Firewall Management Center Hit by Critical CVE-2026-20324 Root RCE Vulnerability + Video
A Critical Warning for Cisco Firewall Administrators A critical vulnerability in Cisco Secure Firewall Management Center (FMC) has raised concerns for organizations relying on Cisco infrastructure to manage and protect their networks. Tracked as CVE-2026-20324, the flaw carries a CVSS score of 9.9 and can allow an authenticated remote attacker to execute arbitrary…
##https://thecybersecguru.com/news/cisco-fmc-cve-2026-20324-sftunnel-root-rce/
##updated 2026-09-18T03:30:28
2 posts
🟠 CVE-2026-93456 - High (8.2)
django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify page content. Signed-in editors visiting a malicious page can be tricked into storing u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93456/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93456 - High (8.2)
django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify page content. Signed-in editors visiting a malicious page can be tricked into storing u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93456/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T00:31:21
2 posts
🟠 CVE-2026-93452 - High (7.5)
snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination buffer's rem...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93452/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93452 - High (7.5)
snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination buffer's rem...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93452/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-17T21:32:42
1 posts
Learn about recent Apache NiFi vulnerabilities (CVE-2026-87976, CVE-2026-70469) and Apache MyFaces flaws. Apply Apache security updates to prevent DoS attacks.
#ApacheNiFi #ApacheMyFaces #Vulnerability #CVE202687976 #Cybersecurity
##updated 2026-09-17T21:32:41
1 posts
New.
Cisco has advisories to address 13 critical vulnerabilities, among other lower-ranking flaws https://sec.cloudapps.cisco.com/security/center/publicationListing.x
This one is new, but there are others:
CRITICAL: CVE-2026-20176, CVE-2026-20211, and CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerabilities https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-se7bYU57
Broadcom:
Broadcom has a long list of advisories addressing at least two critical vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Tenable:
Tenable Research Advisories: CVE-2026-84858: ScadaLTS Multiple Vulnerabilities https://www.tenable.com/security/research/tra-2026-60
And if you missed this, Microsoft posted two advisories for Edge yesterday: https://msrc.microsoft.com/update-guide #Microsoft #infosec #Cisco #vulnerability
##updated 2026-09-17T20:18:59.730000
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T20:18:59.483000
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T20:18:59.213000
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T20:18:58.840000
2 posts
🟠 CVE-2026-92919 - High (8.1)
admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. Attackers can use dot-dot path segments in filenames to escape the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92919/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-92919 - High (8.1)
admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. Attackers can use dot-dot path segments in filenames to escape the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92919/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-17T20:18:52.037000
2 posts
1 repos
Shownotes:
LausivLoader analysis, or how to pass data between malware stages
https://isc.sans.edu/diary/LausivLoader%20analysis%2C%20or%20how%20to%20pass%20data%20between%20malware%20stages/33348
Issabel Framework Hard-coded JWT Key RCE CVE-2026-89026
AntennaPod | Anytime Player | Apple Podcasts | Castamatic | CurioCaster | Fountain | gPodder | Overcast | Pocket Casts | Podcast Addict | Podcast Guru | Podnews | Podverse | Truefans
Or Listen right here.
##Unauthenticated RCE in Issabel Framework (CVE-2026-89026) is being exploited in the wild. A hardcoded JWT secret in pbxapi/index.php allows token forgery and OS command execution as the Asterisk user, risking full PBX takeover. #Issabel #RemoteCodeExecution #InfoSec
https://cyberworldops.eu/en/one-shared-jwt-secret-exposes-issabel-pbx-servers-to-remote-command
##updated 2026-09-17T20:18:51.303000
1 posts
Learn about recent Apache NiFi vulnerabilities (CVE-2026-87976, CVE-2026-70469) and Apache MyFaces flaws. Apply Apache security updates to prevent DoS attacks.
#ApacheNiFi #ApacheMyFaces #Vulnerability #CVE202687976 #Cybersecurity
##updated 2026-09-17T20:16:52.550000
2 posts
🟠 CVE-2026-54692 - High (7.8)
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to 1.0.0, sail_codec_load_frame_v8_xbm() in src/sail-codecs/xbm/xbm.c allocates the decoded pixel buffer using the X11 one...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54692/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-54692 - High (7.8)
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to 1.0.0, sail_codec_load_frame_v8_xbm() in src/sail-codecs/xbm/xbm.c allocates the decoded pixel buffer using the X11 one...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54692/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-17T19:16:55.587000
1 posts
Advantech EKI-1242IEIMS (fw ≤1.06.01) suffers CRITICAL CVE-2026-73172: unauthenticated OS command injection via TCP 5058 enables remote root access. No patch yet — restrict device exposure & monitor traffic. Details: https://radar.offseq.com/threat/cve-2026-73172-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-273be6f3526b5b8e #OffSeq #ICS #CVE202673172 #infosec
##updated 2026-09-17T18:32:03
2 posts
A critical pgAdmin 4 authentication bypass (CVE-2026-86863) allows remote admin takeover. Patch this pgAdmin 4 authentication bypass vulnerability now.
#pgAdmin #PostgreSQL #CVE202686863 #AuthenticationBypass #Cybersecurity
##A critical pgAdmin 4 authentication bypass (CVE-2026-86863) allows remote admin takeover. Patch this pgAdmin 4 authentication bypass vulnerability now.
#pgAdmin #PostgreSQL #CVE202686863 #AuthenticationBypass #Cybersecurity
##updated 2026-09-17T18:17:15.430000
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T16:18:34.667000
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T16:17:44.693000
2 posts
CVE-2026-79752: CakePHP <4.5.12, 4.6.0-4.6.4, 5.0.0-5.1.8, 5.2.0-5.2.13, 5.3.0-5.3.6 FunctionsBuilder SQL injection risk! CRITICAL severity — patch ASAP or avoid user input in $dataType, $part, $unit. https://radar.offseq.com/threat/database-cakephp-multiple-methods-in-functionsbuilder-vulnerable-to-sql-injection-cve-2026-79752-16b04fe3ca4b5527 #OffSeq #CakePHP #SQLi #Infosec
##CVE-2026-79752: CakePHP <4.5.12, 4.6.0-4.6.4, 5.0.0-5.1.8, 5.2.0-5.2.13, 5.3.0-5.3.6 FunctionsBuilder SQL injection risk! CRITICAL severity — patch ASAP or avoid user input in $dataType, $part, $unit. https://radar.offseq.com/threat/database-cakephp-multiple-methods-in-functionsbuilder-vulnerable-to-sql-injection-cve-2026-79752-16b04fe3ca4b5527 #OffSeq #CakePHP #SQLi #Infosec
##updated 2026-09-17T15:32:35
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T15:32:28
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T15:32:28
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T15:32:27
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T15:32:26
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T15:32:26
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T15:32:26
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T15:32:26
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T15:32:23
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T15:32:18
2 posts
🟠 CVE-2026-81481 - High (7.5)
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81481/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81481 - High (7.5)
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81481/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-17T15:32:17
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T15:17:01.170000
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T15:17:00.650000
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T15:17:00.520000
2 posts
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."
https://www.cve.org/CVERecord?id=CVE-2026-92934
https://www.cve.org/CVERecord?id=CVE-2026-92935
https://www.cve.org/CVERecord?id=CVE-2026-92937
https://www.cve.org/CVERecord?id=CVE-2026-92938
https://www.cve.org/CVERecord?id=CVE-2026-92939
https://www.cve.org/CVERecord?id=CVE-2026-92940
https://www.cve.org/CVERecord?id=CVE-2026-92941
https://www.cve.org/CVERecord?id=CVE-2026-92944
https://www.cve.org/CVERecord?id=CVE-2026-92946
https://www.cve.org/CVERecord?id=CVE-2026-92947
https://www.cve.org/CVERecord?id=CVE-2026-92948
https://www.cve.org/CVERecord?id=CVE-2026-92950
https://www.cve.org/CVERecord?id=CVE-2026-92951
https://www.cve.org/CVERecord?id=CVE-2026-92953
https://www.cve.org/CVERecord?id=CVE-2026-92954
https://www.cve.org/CVERecord?id=CVE-2026-92955
https://www.cve.org/CVERecord?id=CVE-2026-92956
https://www.cve.org/CVERecord?id=CVE-2026-92957
https://www.cve.org/CVERecord?id=CVE-2026-92960
updated 2026-09-17T15:16:58.247000
1 posts
CVE-2026-92578: CRITICAL auth bypass in WWBN AVideo (≤29.0) allows attackers with stolen password hashes to log in as any user — no password needed. Patch pending — restrict hash access, monitor for abuse. https://radar.offseq.com/threat/cve-2026-92578-improper-authentication-in-wwbn-avideo-d660bbe72d13e3dc #OffSeq #CVE202692578 #authentication #infosec
##updated 2026-09-17T13:17:01.013000
2 posts
🟠 CVE-2026-92918 - High (8.8)
admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /logs endpoint to harvest session tokens and repla...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92918/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-92918 - High (8.8)
admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /logs endpoint to harvest session tokens and repla...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92918/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-17T12:46:31.670000
32 posts
1 repos
📰 Cisco ISE Zero-Day (CVSS 10.0) Under Active Attack, Bypasses Auth
Cisco warns of a critical (CVSS 10.0) zero-day in Identity Services Engine (ISE) actively exploited in the wild. The flaw, CVE-2026-76460, allows full authentication bypass. CISA added to KEV catalog. Patch immediately! #Cisco #ZeroDay #CyberSecurity
##Cisco ISE zero-day CVE-2026-76460 is being actively exploited.
The CVSS 10.0 flaw allows remote, unauthenticated attackers to bypass authentication and potentially execute commands with root privileges.
Cisco says there is no complete workaround and recommends upgrading immediately.
Read more here:
https://forum.hashpwn.net/post/16740
Noch ein Cisco Zero-Day (perfekte 10) unter Angriff
Ja, Cisco-Evangelisten müssen dieser Tage ganz stark sein. Kurz nach dem Desaster mit dem "sicheren" E-Mail-Gateway ist die nächste "Sicherheitslücke" aufgefallen, weil sie bereits angegriffen wird. CVE-2026-76460 hat eine perfekte 10 (von 10) als Risiko-Einstufung erhalten. Die "Sicherheitslücke" steckt in der Cisco Identity Services Engine (ISE). Wie der Name nahelegt, ist die Aufgabe dieser Funktion, Benutzer/innen zu identifizieren und dann für bestimmte Tätigkeiten zu autorisieren. Die Schwachstelle entsteht durch, ich zitiere: "... insufficient authentication control ... Weiterlesen:
#0day #backdoor #closedsource #exploits #hersteller #identität #sicherheit #UnplugTrump #zeroday #cisco
##Cisco ISE Vulnerability With CVSS 10.0 Score Under Active Attack
Cisco patched CVE-2026-76460, a critical Cisco Identity Services Engine (ISE) bug under active attack. CISA lists it as an exploited vulnerability.
🔗️ [Thecyberexpress] https://link.is.it/LOu95i
##「Cisco、ISE認証バイパスの新たなゼロデイ脆弱性(CVSS 10.0)が現在進行中の攻撃で悪用されていると警告 」: #TheHackerNews
「Ciscoは、Identity Services Engine(ISE)に影響を与える新たな最高レベルのセキュリティ脆弱性が発見され、現在悪用されていると警告した。
CVE-2026-76460 (CVSSスコア:10.0)として追跡されているこの脆弱性により 、認証されていないリモート攻撃者が認証を回避できる可能性がある。
「この脆弱性は、APIエンドポイントにおける認証制御の不備に起因するものです」とシスコは述べています。「攻撃者は、細工されたリクエストを影響を受けるAPIエンドポイントに送信することで、この脆弱性を悪用する可能性があります。攻撃が成功すると、攻撃者はWebベースの管理インターフェースを迂回して、影響を受けるデバイスへの不正アクセスを取得できる可能性があります。」 」
https://thehackernews.com/2026/09/cisco-warns-of-new-zero-day-ise-auth.html
##Cisco Discloses Second Actively Exploited Zero-Day Vulnerability
Cisco has disclosed a second actively exploited zero-day vulnerability, CVE-2026-76460, a maximum-severity flaw in its Identity Services Engine (ISE) that lets attackers bypass authentication and take full control of affected devices. This vulnerability is particularly alarming because it allows hackers to modify network access…
#ZeroDay #Cisco #IdentityServicesEngine #Cve202676460 #AuthenticationBypass
##Critical cybersecurity alerts issued as Check Point (CVE-2026-91843) and Cisco (CVE-2026-76460) disclose severe vulnerabilities, with Cisco's already exploited. Geopolitically, USCG/FBI investigate suspected foreign cyberattacks on two oil tankers; Iran reportedly targeted another in the Strait of Hormuz. Tech advances with OpenAI's 'Astra for Law' for legal AI workflows.
##⚠️ CRITICAL: Cisco alerts customers to second actively exploited zero-day in as many days
Cisco ISE zero-day CVE-2026-76460 is actively exploited in the wild. Remote attackers can bypass authentication, take full device control, modify network policies, and steal credentials. If you run ISE, this is a direct threat to your network perimeter and access controls.
🤖 AI generated summary
##Cisco ISE Faces a Critical Zero-Day Threat as CISA Adds CVE-2026-76460 to the KEV Catalog + Video
A Critical Warning for Cisco ISE Administrators A new Cisco security vulnerability has moved rapidly from a newly disclosed flaw to an active-exploitation concern. On September 16, 2026, Cisco disclosed CVE-2026-76460, a critical authentication-bypass vulnerability affecting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). Cisco…
##🔵 THREAT INTELLIGENCE
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
Vulnerability | CRITICAL
CVEs: CVE-2026-76460
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in...
Full analysis:
https://www.yazoul.net/news/article/cisco-warns-of-new-zero-day-ise-auth-bypass-cvss-10-0-exploited-in-active-attack
by Yazoul AI
##📰 CISA Adds Actively Exploited Cisco and Acronis Flaws to KEV Catalog
CISA adds two actively exploited vulnerabilities to its KEV catalog: a critical Cisco ISE auth bypass (CVE-2026-76460) and an Acronis Backup flaw (CVE-2026-87886). Federal agencies must patch urgently. #CISA #KEV #PatchNow
##📰 Cisco ISE Zero-Day (CVSS 10.0) Under Active Attack, Bypasses Auth
Cisco warns of a critical (CVSS 10.0) zero-day in Identity Services Engine (ISE) actively exploited in the wild. The flaw, CVE-2026-76460, allows full authentication bypass. CISA added to KEV catalog. Patch immediately! #Cisco #ZeroDay #CyberSecurity
##Cisco Discloses Zero-Day ISE Auth Bypass Under Active Exploitation
Cisco has uncovered a critical zero-day vulnerability, CVE-2026-76460, that lets hackers bypass authentication on its Identity Services Engine and Passive Identity Connector, and it's already being exploited by attackers. This flaw allows unauthorized access to affected devices with just a crafted request.
##Cisco Patches 21 Flaws in ISE Identity Infrastructure Including Actively Exploited Zero-Days
Cisco released a set of security updates for Identity Services Engine (ISE) addressing 21 vulnerabilities, including two critical authentication bypasses (CVE-2026-20192 and CVE-2026-76460) currently exploited by attackers to gain root access.
**Treat this as a top-priority emergency attackers are already using some of these flaws to take over identity servers. If you run Cisco ISE or ISE-PIC, first make sure the management interface is never reachable from the internet. Then patch ASAP to 3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7 or 3.5 P4. Check your access logs for strange accounts like "dummyuser". Assume a breach if you find anything weird.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/cisco-patches-21-flaws-in-ise-identity-infrastructure-including-actively-exploited-zero-days-e-2-9-l-x/gD2P6Ple2L
🔴 New security advisory:
CVE-2026-76460 affects multiple systems.
• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems
Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-76460-cisco-ise-auth-bypass-exploited-in-wild
by Yazoul AI
##Cisco ISE Under Attack: Critical CVE-2026-76460 Gives Attackers a Path to Root Access + Video
A Maximum-Severity Warning for Network Defenders Cisco has issued an urgent warning over active exploitation of a maximum-severity vulnerability in Cisco Identity Services Engine (ISE), a platform used by organizations to control and enforce access to corporate networks. The vulnerability, tracked as CVE-2026-76460, carries the highest possible CVSS score of 10.0 and has now…
##Cisco Discloses Active Exploitation of ISE Flaw
Cisco warns that a critical API vulnerability, CVE-2026-76460, is under active exploitation, allowing attackers to bypass security and gain unauthorized access to devices with a simple crafted request. This maximum-severity flaw scores a perfect 10.0 on the CVSS scale, making it a high-risk threat that demands immediate attention.
#Cve202676460 #ApiVulnerability #ActiveExploitation #Cisco #IseFlaw
##Cisco ISE zero-day CVE-2026-76460 is being actively exploited.
The CVSS 10.0 flaw allows remote, unauthenticated attackers to bypass authentication and potentially execute commands with root privileges.
Cisco says there is no complete workaround and recommends upgrading immediately.
Read more here:
https://forum.hashpwn.net/post/16740
Noch ein Cisco Zero-Day (perfekte 10) unter Angriff
Ja, Cisco-Evangelisten müssen dieser Tage ganz stark sein. Kurz nach dem Desaster mit dem "sicheren" E-Mail-Gateway ist die nächste "Sicherheitslücke" aufgefallen, weil sie bereits angegriffen wird. CVE-2026-76460 hat eine perfekte 10 (von 10) als Risiko-Einstufung erhalten. Die "Sicherheitslücke" steckt in der Cisco Identity Services Engine (ISE). Wie der Name nahelegt, ist die Aufgabe dieser Funktion, Benutzer/innen zu identifizieren und dann für bestimmte Tätigkeiten zu autorisieren. Die Schwachstelle entsteht durch, ich zitiere: "... insufficient authentication control ... Weiterlesen:
#0day #backdoor #closedsource #exploits #hersteller #identität #sicherheit #UnplugTrump #zeroday #cisco
##Cisco ISE Vulnerability With CVSS 10.0 Score Under Active Attack
Cisco patched CVE-2026-76460, a critical Cisco Identity Services Engine (ISE) bug under active attack. CISA lists it as an exploited vulnerability.
🔗️ [Thecyberexpress] https://link.is.it/LOu95i
##「Cisco、ISE認証バイパスの新たなゼロデイ脆弱性(CVSS 10.0)が現在進行中の攻撃で悪用されていると警告 」: #TheHackerNews
「Ciscoは、Identity Services Engine(ISE)に影響を与える新たな最高レベルのセキュリティ脆弱性が発見され、現在悪用されていると警告した。
CVE-2026-76460 (CVSSスコア:10.0)として追跡されているこの脆弱性により 、認証されていないリモート攻撃者が認証を回避できる可能性がある。
「この脆弱性は、APIエンドポイントにおける認証制御の不備に起因するものです」とシスコは述べています。「攻撃者は、細工されたリクエストを影響を受けるAPIエンドポイントに送信することで、この脆弱性を悪用する可能性があります。攻撃が成功すると、攻撃者はWebベースの管理インターフェースを迂回して、影響を受けるデバイスへの不正アクセスを取得できる可能性があります。」 」
https://thehackernews.com/2026/09/cisco-warns-of-new-zero-day-ise-auth.html
##Critical cybersecurity alerts issued as Check Point (CVE-2026-91843) and Cisco (CVE-2026-76460) disclose severe vulnerabilities, with Cisco's already exploited. Geopolitically, USCG/FBI investigate suspected foreign cyberattacks on two oil tankers; Iran reportedly targeted another in the Strait of Hormuz. Tech advances with OpenAI's 'Astra for Law' for legal AI workflows.
##⚠️ CRITICAL: Cisco alerts customers to second actively exploited zero-day in as many days
Cisco ISE zero-day CVE-2026-76460 is actively exploited in the wild. Remote attackers can bypass authentication, take full device control, modify network policies, and steal credentials. If you run ISE, this is a direct threat to your network perimeter and access controls.
🤖 AI generated summary
##Cisco Patches 21 Flaws in ISE Identity Infrastructure Including Actively Exploited Zero-Days
Cisco released a set of security updates for Identity Services Engine (ISE) addressing 21 vulnerabilities, including two critical authentication bypasses (CVE-2026-20192 and CVE-2026-76460) currently exploited by attackers to gain root access.
**Treat this as a top-priority emergency attackers are already using some of these flaws to take over identity servers. If you run Cisco ISE or ISE-PIC, first make sure the management interface is never reachable from the internet. Then patch ASAP to 3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7 or 3.5 P4. Check your access logs for strange accounts like "dummyuser". Assume a breach if you find anything weird.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/cisco-patches-21-flaws-in-ise-identity-infrastructure-including-actively-exploited-zero-days-e-2-9-l-x/gD2P6Ple2L
(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-76460 – Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
A strategic executive briefing detailing privileged API mitigation, network segmentation, and zero-trust verification frameworks for CVE-2026-76460 in Cisco ISE....
##CVE-2026-76460: CRITICAL auth bypass in Cisco ISE & ISE-PIC is actively exploited. Remote attackers can gain admin access via crafted API requests. Patch ISE 3.1 – 3.5 now — no workarounds. More: https://radar.offseq.com/threat/cisco-warns-of-max-severity-ise-zero-day-exploited-in-attacks-7c00b7de95d29289 #OffSeq #Cisco #ZeroDay #Vuln #Cybersecurity
##https://thecybersecguru.com/news/cisco-ise-cve-2026-76460-authentication-bypass/
##「Ciscoは、ISEのゼロデイ脆弱性が攻撃に悪用され、深刻な被害を受ける可能性があると警告している。 」: #BLEEPINGCOMPUTER
「シスコは、攻撃者が実際に悪用している、深刻度が最大レベルのアイデンティティサービスエンジンの脆弱性に対処するためのセキュリティアップデートをリリースしました。
Cisco ISEは、IT管理者がエンドポイント、ユーザー、およびデバイスのネットワークリソースへのアクセスを管理するために使用する集中型ポリシープラットフォームであり、多くの場合、ゼロトラストセキュリティモデルを適用しながら使用されます。
このセキュリティ上の欠陥( CVE-2026-76460 として追跡)により、リモートの攻撃者は、Cisco Identity Services Engine(ISE)およびCisco ISE Passive Identity Connector(ISE-PIC)のAPIの脆弱性を悪用することで、設定に関係なく認証を回避できます。 」
##CRITICAL auth bypass (CVE-2026-76460) in Cisco ISE & ISE-PIC is being actively exploited. Remote attackers gain root on management interface via crafted API calls. Patch ASAP — no workarounds except ACLs. Details: https://radar.offseq.com/threat/active-exploitation-triggers-emergency-patch-for-cisco-ise-zero-day-d5bd452a61e0a8f8 #OffSeq #Cisco #ZeroDay
##Cisco confirmed active exploitation of CVE-2026-76460, an authentication bypass in an ISE API endpoint. Unauthenticated remote access can lead to root compromise of ISE and ISE-PIC, now listed in CISA KEV. Patching and log review are urgent. #CiscoIse #AuthBypass #CisaKev
https://cyberworldops.eu/en/cisco-ise-api-authentication-flaw-opens-a-remote-path-to-root-access
##Patch your Cisco ISE. CVE-2026-76460 a perfect 10 and is EITW. 🥳
##The Cisco PSIRT is aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.
An exploited Cisco ISE vulnerability (CVE-2026-76460) allows remote root access. Patch this critical Cisco ISE vulnerability to secure networks.
##updated 2026-09-17T12:18:30.290000
2 posts
CVE-2026-92913 | WWBN AVideo (CRITICAL, CVSS 9.1): Weak random pairing codes + exposed microtime API = unauthenticated account takeover risk. No patch yet — restrict API access if possible. https://radar.offseq.com/threat/cve-2026-92913-use-of-insufficiently-random-values-in-wwbn-avideo-bdf60cd1a8224a92 #OffSeq #AVideo #CVE202692913 #AccountSecurity
##CVE-2026-92913 | WWBN AVideo (CRITICAL, CVSS 9.1): Weak random pairing codes + exposed microtime API = unauthenticated account takeover risk. No patch yet — restrict API access if possible. https://radar.offseq.com/threat/cve-2026-92913-use-of-insufficiently-random-values-in-wwbn-avideo-bdf60cd1a8224a92 #OffSeq #AVideo #CVE202692913 #AccountSecurity
##updated 2026-09-17T12:17:25.350000
1 posts
New.
Cisco has advisories to address 13 critical vulnerabilities, among other lower-ranking flaws https://sec.cloudapps.cisco.com/security/center/publicationListing.x
This one is new, but there are others:
CRITICAL: CVE-2026-20176, CVE-2026-20211, and CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerabilities https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-se7bYU57
Broadcom:
Broadcom has a long list of advisories addressing at least two critical vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Tenable:
Tenable Research Advisories: CVE-2026-84858: ScadaLTS Multiple Vulnerabilities https://www.tenable.com/security/research/tra-2026-60
And if you missed this, Microsoft posted two advisories for Edge yesterday: https://msrc.microsoft.com/update-guide #Microsoft #infosec #Cisco #vulnerability
##updated 2026-09-17T12:17:25.200000
1 posts
New.
Cisco has advisories to address 13 critical vulnerabilities, among other lower-ranking flaws https://sec.cloudapps.cisco.com/security/center/publicationListing.x
This one is new, but there are others:
CRITICAL: CVE-2026-20176, CVE-2026-20211, and CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerabilities https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-se7bYU57
Broadcom:
Broadcom has a long list of advisories addressing at least two critical vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Tenable:
Tenable Research Advisories: CVE-2026-84858: ScadaLTS Multiple Vulnerabilities https://www.tenable.com/security/research/tra-2026-60
And if you missed this, Microsoft posted two advisories for Edge yesterday: https://msrc.microsoft.com/update-guide #Microsoft #infosec #Cisco #vulnerability
##updated 2026-09-17T09:33:03
3 posts
Mitsubishi GX Works3 and bundled Motion Control Settings allow local bypass of block-password auth via in-memory patching (CVE-2026-15688). It matters because it breaks project protection for PLC logic, enabling undetected modification. #OtSecurity #PlcSecurity #VulnerabilityManagement
https://cyberworldops.eu/en/mitsubishi-engineering-tools-expose-control-programs-through-local
##Mitsubishi GX Works3 and bundled Motion Control Settings allow local bypass of block-password auth via in-memory patching (CVE-2026-15688). It matters because it breaks project protection for PLC logic, enabling undetected modification. #OtSecurity #PlcSecurity #VulnerabilityManagement
https://cyberworldops.eu/en/mitsubishi-engineering-tools-expose-control-programs-through-local
##CVE-2026-15688 | Mitsubishi Electric GX Works3 (CVSS 9.2, CRITICAL): Local attackers can bypass authentication by modifying memory, risking control program compromise. No fix yet — restrict local access. #OffSeq #ICS #CVE202615688 https://radar.offseq.com/threat/cve-2026-15688-cwe-303-incorrect-implementation-of-authentication-algorithm-in-mitsubishi-electric-b35e18a6ba962469
##updated 2026-09-17T09:33:03
2 posts
🟠 CVE-2026-86320 - High (7.8)
A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch hook can cause the hook to execute on the host ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86320/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86320 - High (7.8)
A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch hook can cause the hook to execute on the host ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86320/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-17T06:30:45
1 posts
1 repos
CVE-2026-87796 (CRITICAL, CVSS 9.8): sh1zen Multi Uploader for Gravity Forms ≤1.1.9 lets unauthenticated attackers upload arbitrary files, risking remote code execution. No patch yet — disable the plugin or restrict uploads. https://radar.offseq.com/threat/cve-2026-87796-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-sh1zen-multi-uploader-for-cfd4181d51e0b5e2 #OffSeq #WordPress #CVE #RCE
##updated 2026-09-17T00:31:25
1 posts
CRITICAL SSRF vuln (CVE-2026-92576) in HKUDS nanobot <0.3.0: Inadequate URL validation lets attackers access internal cloud metadata & services. Restrict WebFetchTool, monitor for suspicious requests. Patch status: unconfirmed. https://radar.offseq.com/threat/cve-2026-92576-server-side-request-forgery-ssrf-in-hkuds-nanobot-4673f42d188d2ce5 #OffSeq #infosec #CVE202692576
##updated 2026-09-16T21:32:55
2 posts
Cisco Patches 18 Critical and High-Severity Firewall Vulnerabilities, One Actively Exploited
Cisco released a massive security hardening update fixing 18 vulnerabilities in its Secure Firewall suite, including an actively exploited authentication bypass (CVE-2026-20332) and multiple critical remote code execution flaws.
**If you use Cisco Secure Firewall (ASA, FTD, or FMC), this is urgent. Patch now to the fixed versions Cisco lists. At least one flaw is already being exploited by attackers. Make sure the management interfaces are reachable only from your trusted internal network and never from the internet.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/cisco-patches-18-critical-and-high-severity-firewall-vulnerabilities-one-actively-exploited-3-v-t-c-t/gD2P6Ple2L
Cisco Patches 18 Critical and High-Severity Firewall Vulnerabilities, One Actively Exploited
Cisco released a massive security hardening update fixing 18 vulnerabilities in its Secure Firewall suite, including an actively exploited authentication bypass (CVE-2026-20332) and multiple critical remote code execution flaws.
**If you use Cisco Secure Firewall (ASA, FTD, or FMC), this is urgent. Patch now to the fixed versions Cisco lists. At least one flaw is already being exploited by attackers. Make sure the management interfaces are reachable only from your trusted internal network and never from the internet.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/cisco-patches-18-critical-and-high-severity-firewall-vulnerabilities-one-actively-exploited-3-v-t-c-t/gD2P6Ple2L
updated 2026-09-16T21:32:55
2 posts
HP released updates to fix critical HP Advance vulnerabilities (CVE-2026-89082). Patch these HP Advance vulnerabilities to stop remote code execution.
##HP released updates to fix critical HP Advance vulnerabilities (CVE-2026-89082). Patch these HP Advance vulnerabilities to stop remote code execution.
##updated 2026-09-16T21:32:50
2 posts
Grab a coffee. Cisco has posted several advisories, one of them addressing a critical vulnerability that was first published on the 16th. More here https://sec.cloudapps.cisco.com/security/center/publicationListing.x
CRITICAL: CVE-2026-20329, CVE-2026-20330, and CVE-2026-20331: Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 @TalosSecurity #Cisco #vulnerability #infosec
##Grab a coffee. Cisco has posted several advisories, one of them addressing a critical vulnerability that was first published on the 16th. More here https://sec.cloudapps.cisco.com/security/center/publicationListing.x
CRITICAL: CVE-2026-20329, CVE-2026-20330, and CVE-2026-20331: Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 @TalosSecurity #Cisco #vulnerability #infosec
##updated 2026-09-16T21:32:50
6 posts
Reward: You've received the Cursed Amulet of Maximum CVSS — it goes great with your existing collection of regrets.
https://www.ionix.io/threat-center/cve-2026-20192
#CyberSecurity #CVE #Cisco #CriticalVulnerability #AccessControl #PatchedOrPerish (3/3)
##🏆 New Achievement! Perfect Score, Perfect Doom!
Splendid news, brave adventurer! Your quest to secure the network is absolutely still possible — and to help you on your way, Cisco has gifted the world CVE-2026-20192, a shiny CVSS 10.0 access control bypass in Cisco Identity Services Engine and ISE Passive Identity Connector. Maximum score! Like a Tamagotchi dying the moment you crack the box open.
Cisco caught this one themselves during an internal review, which is the good news. (1/3)
##Cisco Patches 21 Flaws in ISE Identity Infrastructure Including Actively Exploited Zero-Days
Cisco released a set of security updates for Identity Services Engine (ISE) addressing 21 vulnerabilities, including two critical authentication bypasses (CVE-2026-20192 and CVE-2026-76460) currently exploited by attackers to gain root access.
**Treat this as a top-priority emergency attackers are already using some of these flaws to take over identity servers. If you run Cisco ISE or ISE-PIC, first make sure the management interface is never reachable from the internet. Then patch ASAP to 3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7 or 3.5 P4. Check your access logs for strange accounts like "dummyuser". Assume a breach if you find anything weird.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/cisco-patches-21-flaws-in-ise-identity-infrastructure-including-actively-exploited-zero-days-e-2-9-l-x/gD2P6Ple2L
Reward: You've received the Cursed Amulet of Maximum CVSS — it goes great with your existing collection of regrets.
https://www.ionix.io/threat-center/cve-2026-20192
#CyberSecurity #CVE #Cisco #CriticalVulnerability #AccessControl #PatchedOrPerish (3/3)
##🏆 New Achievement! Perfect Score, Perfect Doom!
Splendid news, brave adventurer! Your quest to secure the network is absolutely still possible — and to help you on your way, Cisco has gifted the world CVE-2026-20192, a shiny CVSS 10.0 access control bypass in Cisco Identity Services Engine and ISE Passive Identity Connector. Maximum score! Like a Tamagotchi dying the moment you crack the box open.
Cisco caught this one themselves during an internal review, which is the good news. (1/3)
##Cisco Patches 21 Flaws in ISE Identity Infrastructure Including Actively Exploited Zero-Days
Cisco released a set of security updates for Identity Services Engine (ISE) addressing 21 vulnerabilities, including two critical authentication bypasses (CVE-2026-20192 and CVE-2026-76460) currently exploited by attackers to gain root access.
**Treat this as a top-priority emergency attackers are already using some of these flaws to take over identity servers. If you run Cisco ISE or ISE-PIC, first make sure the management interface is never reachable from the internet. Then patch ASAP to 3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7 or 3.5 P4. Check your access logs for strange accounts like "dummyuser". Assume a breach if you find anything weird.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/cisco-patches-21-flaws-in-ise-identity-infrastructure-including-actively-exploited-zero-days-e-2-9-l-x/gD2P6Ple2L
updated 2026-09-16T21:32:50
1 posts
CVE-2026-20341: CRITICAL flaw in Cisco Secure FMC Software sftunnel protocol. Admin remote attackers can gain root via insecure deserialization. Limit admin access, monitor for abuse, and check for patch updates. https://radar.offseq.com/threat/a-vulnerability-in-the-sftunnel-inter-device-communication-protocol-of-cisco-secure-fmc-software-could-c3ce1a1e4096035e #OffSeq #Cisco #Infosec #Vulnerability
##updated 2026-09-16T21:32:47
1 posts
🟠 CVE-2026-87024 - High (7.5)
Tanium addressed a SQL injection vulnerability in Asset.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87024/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-16T20:38:33.883000
8 posts
1 repos
CVE-2026-77179: Docker's hypervisor for Mac compromised (Docker Desktop, Docker Sandboxes) https://www.accomplish.ai/blog/escaping-dockers-hypervisor/
##「Dockerサンドボックスの重大な脆弱性により、悪意のあるゲストコードがmacOSホストファイルを読み取り、変更することが可能になる。 」: #TheHackerNews
「Dockerは9月15日のセキュリティ発表 で、macOS上のDocker Sandboxes 仮想マシン内で実行されている悪意のあるコードが、 共有されているプロジェクトディレクトリから脱出し、ホスト上の他の場所にあるファイルを読み取ったり変更したりする可能性があると警告した 。
このエスケープ処理は、仮想マシンを実行するホストアカウントの権限で実行されます。この脆弱性( CVE-2026-77179 )は、深刻度が「重大」と評価されており、macOS 版のバージョン 0.28.0 から 0.42.0 まで(0.42.0 は含まない)に影響があり、 9 月 7 日にリリースされたバージョン 0.42.0 で修正されました。 」
https://thehackernews.com/2026/09/critical-docker-sandboxes-flaw-lets.html
##https://thecybersecguru.com/news/docker-sandboxes-cve-2026-77179-cve-2026-79994/
##Docker Flaw Lets Guest Code Read, Modify macOS Host Files
A newly discovered Docker flaw on macOS could allow malicious code in a virtual machine to break free from its sandbox and read or modify sensitive host files, potentially leading to code execution on the host. This vulnerability, tracked as CVE-2026-77179, leverages a weakness in the virtio-fs host server to gain unauthorized access.
#DockerFlaw #Macos #Cve202677179 #Containerization #VirtualMachine
##CVE-2026-77179: Docker's hypervisor for Mac compromised (Docker Desktop, Docker Sandboxes) https://www.accomplish.ai/blog/escaping-dockers-hypervisor/
##「Dockerサンドボックスの重大な脆弱性により、悪意のあるゲストコードがmacOSホストファイルを読み取り、変更することが可能になる。 」: #TheHackerNews
「Dockerは9月15日のセキュリティ発表 で、macOS上のDocker Sandboxes 仮想マシン内で実行されている悪意のあるコードが、 共有されているプロジェクトディレクトリから脱出し、ホスト上の他の場所にあるファイルを読み取ったり変更したりする可能性があると警告した 。
このエスケープ処理は、仮想マシンを実行するホストアカウントの権限で実行されます。この脆弱性( CVE-2026-77179 )は、深刻度が「重大」と評価されており、macOS 版のバージョン 0.28.0 から 0.42.0 まで(0.42.0 は含まない)に影響があり、 9 月 7 日にリリースされたバージョン 0.42.0 で修正されました。 」
https://thehackernews.com/2026/09/critical-docker-sandboxes-flaw-lets.html
##https://thecybersecguru.com/news/docker-sandboxes-cve-2026-77179-cve-2026-79994/
##Docker released an update for critical Docker Sandboxes vulnerabilities (CVE-2026-77179, CVE-2026-79994). Patch these Docker Sandboxes vulnerabilities today.
#Docker #DockerSandboxes #CVE202677179 #CVE202679994 #Cybersecurity
##updated 2026-09-16T20:38:33.883000
3 posts
https://thecybersecguru.com/news/docker-sandboxes-cve-2026-77179-cve-2026-79994/
##https://thecybersecguru.com/news/docker-sandboxes-cve-2026-77179-cve-2026-79994/
##Docker released an update for critical Docker Sandboxes vulnerabilities (CVE-2026-77179, CVE-2026-79994). Patch these Docker Sandboxes vulnerabilities today.
#Docker #DockerSandboxes #CVE202677179 #CVE202679994 #Cybersecurity
##updated 2026-09-16T20:37:16.870000
1 posts
🔴 CVE-2026-70416 - Critical (10)
Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70416/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-16T19:16:15.097000
1 posts
CVE-2026-78547: Out-of-bounds write in Citrix Workspace app for Windows. CVSS not yet assigned, no patch confirmed. Treat as urgent, update to 2603.11 CR or 2507.1 LTSR CU3 now. https://www.valtersit.com/cve/CVE-2026-78547/ #CVE #Citrix #infosec
##updated 2026-09-16T18:32:09
3 posts
Grab a coffee. Cisco has posted several advisories, one of them addressing a critical vulnerability that was first published on the 16th. More here https://sec.cloudapps.cisco.com/security/center/publicationListing.x
CRITICAL: CVE-2026-20329, CVE-2026-20330, and CVE-2026-20331: Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 @TalosSecurity #Cisco #vulnerability #infosec
##Grab a coffee. Cisco has posted several advisories, one of them addressing a critical vulnerability that was first published on the 16th. More here https://sec.cloudapps.cisco.com/security/center/publicationListing.x
CRITICAL: CVE-2026-20329, CVE-2026-20330, and CVE-2026-20331: Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 @TalosSecurity #Cisco #vulnerability #infosec
##@cR0w was just looking at those, lol. Don't sleep on this great advertisment of a CVE though: https://db.gcve.eu/vuln/cve-2026-20331
##updated 2026-09-16T18:32:09
1 posts
New.
Cisco has advisories to address 13 critical vulnerabilities, among other lower-ranking flaws https://sec.cloudapps.cisco.com/security/center/publicationListing.x
This one is new, but there are others:
CRITICAL: CVE-2026-20176, CVE-2026-20211, and CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerabilities https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-se7bYU57
Broadcom:
Broadcom has a long list of advisories addressing at least two critical vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Tenable:
Tenable Research Advisories: CVE-2026-84858: ScadaLTS Multiple Vulnerabilities https://www.tenable.com/security/research/tra-2026-60
And if you missed this, Microsoft posted two advisories for Edge yesterday: https://msrc.microsoft.com/update-guide #Microsoft #infosec #Cisco #vulnerability
##updated 2026-09-16T18:32:09
1 posts
🔴 CVE-2026-92397 - Critical (9.1)
A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. Such manipulation of the argument data.url leads to os comma...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92397/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-16T18:31:58
1 posts
A critical KVM guest escape (CVE-2026-89775) enables an LPE to gain root on Linux hosts. Patch this KVM guest escape vulnerability now.
##updated 2026-09-16T15:32:15
1 posts
🟠 CVE-2026-61595 - High (7.7)
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.tenants` isolation was enforced only on the HTTP path. The current tenant was stored in `threading.local(...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61595/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-16T15:31:14
19 posts
1 repos
Two companion curses arrived earlier: an auth bypass in August and a heap overflow in VPN certificate decoding in September.
INVENTORY PENALTY: Your management plane is now haunted. Patch Check Point Security Management Server immediately to close CVE-2026-91843 and its critical siblings.
Reward: You've received the Debuffed Robe of Five Failures — Armor Class: negative five. The "found internally, no exploitation detected" enchantment is fading fast. (2/3)
##🏆 New Achievement! Stack Overflow, Stack Underdelivery!
ITEM ACQUIRED: Cursed Login Request (very long username, -9.8 integrity, equips in zero hands). Check Point's Security Management Server has taken its fifth critical unauthenticated hit since July — CVE-2026-91843, a 9.8-rated stack overflow in the login handler that lets attackers execute code as root before a single password is checked. Censys confirms the trigger: just send a comically oversized username. (1/3)
##📰 Check Point Patches Critical RCE Flaw in Management Servers
Check Point patches critical RCE flaw (CVE-2026-91843, CVSS 9.8) in Security Management Servers. Unauthenticated attackers can gain root access via a long username. LivePatch is available. Restrict trusted client access now! #CyberSecurity #CheckPoin...
##Check Point Security Mgmt & Log Server face CRITICAL stack buffer overflow (CVE-2026-91843). Remote, unauthenticated RCE as root possible. Patch now or restrict access, monitor for 'Username too long' login failures. https://radar.offseq.com/threat/new-check-point-flaw-lets-hackers-execute-code-with-root-privileges-00056aa571ef0004 #OffSeq #CheckPoint #Vuln #RCE
##Check Point Management Servers Face Critical Root-Level Remote Code Execution Risk
A Dangerous New Flaw Puts Security Management Systems in the Spotlight A critical vulnerability in Check Point Software Technologies security management products has raised fresh concerns for organizations that rely on centralized systems to control firewalls, collect security logs, and administer enterprise networks. Tracked as CVE-2026-91843, the flaw can potentially allow an…
##Check Point Flaw Enables Hackers to Execute Code with Root Privileges
A critical flaw in Check Point's Security Management Server has been discovered, leaving all deployments vulnerable to hackers who can exploit it to execute code with root privileges, putting the entire firewall estate at risk. This severe vulnerability, tracked as CVE-2026-91843, requires immediate…
#CheckPoint #Cve202691843 #FirewallVulnerability #RootPrivilegeEscalation #SecurityManagementServer
##Critical Check Point Management Flaw Allows Unauthenticated Remote Root Access
Check Point issued an patch for a critical stack overflow vulnerability (CVE-2026-91843) in its Security Management and Log Servers that allows unauthenticated attackers to gain root-level code execution.
**If you run Check Point Security Management or Log Servers, make sure they are never reachable from the internet and restrict the Trusted Clients setting so only specific, known admin IP addresses can connect (use a VPN for remote access). Then apply the LivePatch fix released on September 16, 2026 to every management and log server, confirm it installed with `cplp list`, and check your logs for "Administrator failed to log in: Username too long" to spot attempted attacks.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/critical-check-point-management-flaw-allows-unauthenticated-remote-root-access-9-x-m-8-o/gD2P6Ple2L
Critical Check Point Vulnerability CVE-2026-91843 Exposes Management Servers to Unauthenticated Root-Level Remote Code Execution + Video
Critical Check Point Vulnerability CVE-2026-91843 Exposes Management Servers to Unauthenticated Root-Level Remote Code Execution A Critical Warning for Check Point Administrators A newly disclosed critical vulnerability in Check Point Security Management and Log Servers could allow a remote, unauthenticated attacker to execute…
##Check Point Security Mgmt & Log Server hit by CRITICAL RCE (CVE-2026-91843) via unauthenticated login. No active exploitation yet. Patch ASAP. Tanium (SQLi, RCE) & Kaspersky (Redis) also patched. https://radar.offseq.com/threat/check-point-kaspersky-tanium-patch-product-vulnerabilities-ae8c3757ea9b181a #OffSeq #Vulnerability #RCE #PatchNow
##Critical cybersecurity alerts issued as Check Point (CVE-2026-91843) and Cisco (CVE-2026-76460) disclose severe vulnerabilities, with Cisco's already exploited. Geopolitically, USCG/FBI investigate suspected foreign cyberattacks on two oil tankers; Iran reportedly targeted another in the Strait of Hormuz. Tech advances with OpenAI's 'Astra for Law' for legal AI workflows.
##Two companion curses arrived earlier: an auth bypass in August and a heap overflow in VPN certificate decoding in September.
INVENTORY PENALTY: Your management plane is now haunted. Patch Check Point Security Management Server immediately to close CVE-2026-91843 and its critical siblings.
Reward: You've received the Debuffed Robe of Five Failures — Armor Class: negative five. The "found internally, no exploitation detected" enchantment is fading fast. (2/3)
##🏆 New Achievement! Stack Overflow, Stack Underdelivery!
ITEM ACQUIRED: Cursed Login Request (very long username, -9.8 integrity, equips in zero hands). Check Point's Security Management Server has taken its fifth critical unauthenticated hit since July — CVE-2026-91843, a 9.8-rated stack overflow in the login handler that lets attackers execute code as root before a single password is checked. Censys confirms the trigger: just send a comically oversized username. (1/3)
##Check Point Security Mgmt & Log Server face CRITICAL stack buffer overflow (CVE-2026-91843). Remote, unauthenticated RCE as root possible. Patch now or restrict access, monitor for 'Username too long' login failures. https://radar.offseq.com/threat/new-check-point-flaw-lets-hackers-execute-code-with-root-privileges-00056aa571ef0004 #OffSeq #CheckPoint #Vuln #RCE
##Critical Check Point Management Flaw Allows Unauthenticated Remote Root Access
Check Point issued an patch for a critical stack overflow vulnerability (CVE-2026-91843) in its Security Management and Log Servers that allows unauthenticated attackers to gain root-level code execution.
**If you run Check Point Security Management or Log Servers, make sure they are never reachable from the internet and restrict the Trusted Clients setting so only specific, known admin IP addresses can connect (use a VPN for remote access). Then apply the LivePatch fix released on September 16, 2026 to every management and log server, confirm it installed with `cplp list`, and check your logs for "Administrator failed to log in: Username too long" to spot attempted attacks.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/critical-check-point-management-flaw-allows-unauthenticated-remote-root-access-9-x-m-8-o/gD2P6Ple2L
Check Point Security Mgmt & Log Server hit by CRITICAL RCE (CVE-2026-91843) via unauthenticated login. No active exploitation yet. Patch ASAP. Tanium (SQLi, RCE) & Kaspersky (Redis) also patched. https://radar.offseq.com/threat/check-point-kaspersky-tanium-patch-product-vulnerabilities-ae8c3757ea9b181a #OffSeq #Vulnerability #RCE #PatchNow
##Critical cybersecurity alerts issued as Check Point (CVE-2026-91843) and Cisco (CVE-2026-76460) disclose severe vulnerabilities, with Cisco's already exploited. Geopolitically, USCG/FBI investigate suspected foreign cyberattacks on two oil tankers; Iran reportedly targeted another in the Strait of Hormuz. Tech advances with OpenAI's 'Astra for Law' for legal AI workflows.
##🚨New Censys Advisory: CVE-2026-91843
A critical (CVSS 9.8) unauthenticated RCE affects Check Point Quantum Security Management and Log Servers.
Censys observes 3,836 hosts globally exposing the management/log server role. This is total product presence, not a confirmed-vulnerable count.
No public PoC or confirmed exploitation has been reported as of publication. Check Point has released patches for supported versions via LivePatch.
Read the analysis and remediation details: https://censys.com/advisory/cve-2026-91843/
##🚨 Please read this important update from Check Point:
CVE-2026-91843 - Stack overflow in login process to the Security Management and Log Servers
https://support.checkpoint.com/results/sk/sk1000155
#CheckPoint #CheckPointsoftwareTechnologies #CVE #CVE202691843
##Check Point fixed a critical Check Point login flaw (CVE-2026-91843). Patch this Check Point login flaw now to block unauthenticated remote root takeovers.
#CheckPoint #Cybersecurity #CVE202691843 #InfoSec #Vulnerability
##updated 2026-09-16T15:30:57
22 posts
📢 [VULN] Google confirme un piratage des Pixel via une faille du modem - CVE-2026-58704
Google a confirmé que ses smartphones Pixel ont été piratés à la suite d’attaques ciblées exploitant une faille de type zero-day dans le modem. La faille de sécurité, qui a pour identifiant CVE-2026-58704, permet une élévation de privilèges sans aucune interaction de l’utilisateur et bénéficie désormais d’un…
🔗 https://kulturegeek.fr/news-359668/google-confirme-piratage-pixel-via-faille-modem
💬 discussion : https://infosec.pub/post/52458473
#ZeroDay #CVE #Cyberveille
Google sieht Hinweise auf eine begrenzte, gezielte Ausnutzung von
CVE-2026-58704 auf Pixel-Geräten. Die Schwachstelle steckt im Modem
und ermöglicht eine Rechteausweitung. Der September-Patchlevel
2026-09-05 behebt die Lücke.
https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01
##Google Pixel Zero-Day Warning: CVE-2026-58704 Exploited in Targeted Attacks + Video
Google Pixel Zero-Day Warning: CVE-2026-58704 Exploited in Targeted Attacks A Silent Pixel Attack Has Triggered a New Security Warning Google Pixel users are facing a serious security warning after Google disclosed that a high-severity vulnerability in the cellular modem may have already been exploited in limited, targeted attacks. Tracked as CVE-2026-58704, the flaw involves a…
##🚨 Google confirms Pixel phones targeted in zero-click zero-day attacks
Google has patched CVE-2026-58704, a high-severity vulnerability in Pixel phones' cellular modem that the company says was already under "limited, targeted exploitation."
⠀
The flaw is caused by a logic error that can allow an attacker to bypass permission checks and escalate privileges beyond the modem's isolated environment.
⠀
Most importantly, exploitation requires no interaction from the victim.
No malicious link needs to be clicked and no file needs to be opened, making it a zero-click attack.
⠀
Google has not disclosed:
• Who carried out the attacks
• How many Pixel owners were targeted
• How the victims were selected
• What tools or spyware may have been deployed
⠀
CISA has added CVE-2026-58704 to its Known Exploited Vulnerabilities catalog and set a September 19 remediation deadline for affected federal systems.
⠀
Google says Pixel devices with the September 5, 2026 security patch level or later are protected.
Pixel owners should update their devices immediately.
##Google Pixel phones pwned in zero-click attacks
Google Pixel 휴대폰의 셀룰러 모뎀에서 권한 검증을 우회하고 권한 상승을 가능하게 하는 제로데이 취약점 CVE-2026-58704가 제한적 표적 공격에 악용된 정황이 공개됐다. 사용자 상호작용이 필요 없는 zero-click 공격이 가능하며, 이런 유형은 상용 스파이웨어 기반 표적 감시에 자주 활용된다. Google은 패치를 배포했고, CISA는 이 취약점을 KEV 카탈로그에 추가하며 미국 연방기관에 9월 19일까지 패치하도록 지시했다. AI 개발 자체와 직접 관련되지는 않지만, Android 기기를...
##Google Patches Pixel Modem Zero-Day Exploited in Targeted Attacks
Google's September 2026 update for Pixel devices fixes 110 vulnerabilities, including a high-severity modem flaw (CVE-2026-58704) that attackers are actively exploiting to escalate privileges without user interaction.
**Update your Pixel devices to the September 2026 patch level ASAP to block an active modem exploit and patch a huge set of issues.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/google-patches-pixel-modem-zero-day-exploited-in-targeted-attacks-w-p-u-q-l/gD2P6Ple2L
Google sieht Hinweise auf eine begrenzte, gezielte Ausnutzung von
CVE-2026-58704 auf Pixel-Geräten. Die Schwachstelle steckt im Modem
und ermöglicht eine Rechteausweitung. Der September-Patchlevel
2026-09-05 behebt die Lücke.
https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01
##🚨 Google confirms Pixel phones targeted in zero-click zero-day attacks
Google has patched CVE-2026-58704, a high-severity vulnerability in Pixel phones' cellular modem that the company says was already under "limited, targeted exploitation."
⠀
The flaw is caused by a logic error that can allow an attacker to bypass permission checks and escalate privileges beyond the modem's isolated environment.
⠀
Most importantly, exploitation requires no interaction from the victim.
No malicious link needs to be clicked and no file needs to be opened, making it a zero-click attack.
⠀
Google has not disclosed:
• Who carried out the attacks
• How many Pixel owners were targeted
• How the victims were selected
• What tools or spyware may have been deployed
⠀
CISA has added CVE-2026-58704 to its Known Exploited Vulnerabilities catalog and set a September 19 remediation deadline for affected federal systems.
⠀
Google says Pixel devices with the September 5, 2026 security patch level or later are protected.
Pixel owners should update their devices immediately.
##Google Patches Pixel Modem Zero-Day Exploited in Targeted Attacks
Google's September 2026 update for Pixel devices fixes 110 vulnerabilities, including a high-severity modem flaw (CVE-2026-58704) that attackers are actively exploiting to escalate privileges without user interaction.
**Update your Pixel devices to the September 2026 patch level ASAP to block an active modem exploit and patch a huge set of issues.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/google-patches-pixel-modem-zero-day-exploited-in-targeted-attacks-w-p-u-q-l/gD2P6Ple2L
「Google Pixel端末がゼロクリック攻撃でハッキングされる
/CISAは連邦政府機関に対し、パッチ適用にわずか3日間しか猶予を与えていない。 」: #TheRegister
「Googleと米国政府は、Pixelスマートフォンの携帯モデムに存在するゼロデイ脆弱性を悪用した攻撃者が、権限チェックを回避し、ユーザーの操作なしに権限を昇格できると警告した。この脆弱性は、アップデートを行うことで既に修正されている。
Googleは 火曜日に、 CVE-2026-58704 として追跡されているこの重大な脆弱性 を公表し 、その際、このセキュリティホールが「限定的かつ標的を絞った悪用を受けている可能性がある」と警告した。つまり、Googleが問題を修正する前に、悪意のある人物がこのバグを発見し、悪用していたということだ。」
##「Google、限定的な標的型攻撃の兆候が見られる中、Pixelモデムの脆弱性を修正 」: #TheHackerNews
「Googleは、 明らかにした。 同社のPixel Cellular Modemに存在する深刻なセキュリティ上の欠陥が、実際に悪用されていることを
(CVSSスコア:8.0)として追跡されているこの脆弱性は CVE-2026-58704 、権限昇格の欠陥です。
によると、「セルラーモデムには、コードの論理エラーにより権限がバイパスされる可能性がある」とのことです NIST(米国国立標準技術研究所)の国家脆弱性データベース(NVD)に掲載されているバグの説明 。「これにより、追加の実行権限を必要とせずに、リモート(近接/隣接)での権限昇格が可能になる可能性がある。悪用にはユーザーの操作は不要である。」 」
https://thehackernews.com/2026/09/google-patches-pixel-modem-flaw-amid.html
##Google confirmed a Pixel modem zero-day (CVE-2026-58704) exploited in a zero-click spyware attack to escape the modem sandbox. Update now.
#Pixel #ZeroDay #CVE202658704 #Google #Spyware #ZeroClick #CyberSecurity
https://securityexpress.info/pixel-modem-zero-day/?utm_source=mastodon&utm_medium=jetpack_social
##(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-58704 – Google Pixel Improper Authorization Vulnerability
A strategic executive briefing detailing governance, risk mitigation, and compliance frameworks for CVE-2026-58704 on Google Pixel mobile devices....
##Google and CISA warned that an actively exploited zero-day vulnerability (CVE-2026-58704) affecting Pixel cellular modems.
This allows attackers to silently bypass permission checks and escalate privileges with no user interaction!
It was quickly added to CISA's Known Exploited Vulnerabilities (KEV) catalog [1.2.1, 1.5.1].
Would be an excellent idea for Pixel owners to ownload and apply the September Android OS patches ASAP!
##(CISA TS-MAN) The Cyber Mind TSUITE Brief: CVE-2026-58704 – Google Pixel Improper Authorization Vulnerability
Actionable threat intelligence and end-to-end hardening strategies for CVE-2026-58704, addressing improper authorization flaws in Google Pixel cellular modems....
##Google patched CVE-2026-58704, a high-severity Pixel Cellular Modem privilege-escalation flaw reportedly exploited in limited, targeted attacks. Its addition to CISA’s KEV Catalog underscores the need to prioritize affected device updates. #ZeroDay #MobileSecurity #ThreatIntelligence
https://cyberworldops.eu/en/google-patches-pixel-modem-zero-day-exploited-in-targeted-attacks
##New.
Press release: New CISA Guidance Helps Critical Infrastructure Detect, Observe and Impede Malicious Cyber Activity https://www.cisa.gov/news-events/news/new-cisa-guidance-helps-critical-infrastructure-detect-observe-and-impede-malicious-cyber-activity
The guide: Using Cyber Decoys to Strengthen Detection and Response https://www.cisa.gov/resources-tools/resources/using-cyber-decoys-strengthen-detection-and-response
CISA has also added one vulnerability to the catalogue.
CVE-2026-58704: Google Pixel Improper Authorization Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-58704 #Google #infosec #vulnerability #CISA
##🏆 New Achievement! Tutorial: Learning to Live With Being Actively Exploited!
Welcome to the Mandatory Pixel Debuff Sequence. Before you proceed, please note that CVE-2026-58704 has been equipped to your device without your consent. This is a zero-day — that means the tutorial boss was already in your pocket before the level loaded. (1/3)
##🚨 [CISA-2026:0916] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0916)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-58704 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-58704)
- Name: Google Pixel Improper Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Pixel
- Notes: https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-58704
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260916 #cisa20260916 #cve_2026_58704 #cve202658704
##If you've got a Google Pixel cell phone, do a system patch immediately. There is an active vulnerability that allows the hacker to take control of your device with no user interaction. It is being actively used in the wild.
##Google corrige falha zero-day em telemóveis Pixel com atualização que resolve 110 vulnerabilidades. A falha, identificada como CVE-2026-58704, está a ser explorada em ataques direcionados de alcance limitado. 📱
##CVE ID: CVE-2026-58704
Vendor: Google
Product: Pixel
Date Added: 2026-09-16
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-58704
updated 2026-09-16T12:30:47
1 posts
Vulnerabilities in a 5g router from T-Mobile, the company known for its security?! I'm shocked. Shocked! Well, not that shocked.
##updated 2026-09-16T09:30:28
4 posts
1 repos
Critical Unbound DNSSEC Flaw Opens a Dangerous Path to Remote Code Execution + Video
Critical Unbound DNSSEC Flaw Could Turn a Malicious DNS Zone Into a Remote Code Execution Gateway A Critical Weakness Hidden Inside DNS Validation A critical security flaw in the Unbound DNS resolver has placed organizations running older versions under serious patching pressure. Tracked as CVE-2026-81642, the vulnerability is a heap buffer overflow in Unbound's DNSSEC validation…
##NLnet Labs Unbound before 1.26.1 contains heap overflow CVE-2026-81642 in the DNSSEC validator via crafted DNSKEY with compression pointer into RDATA. Any resolver induced to query a malicious zone risks crash or potential RCE, exposing core DNS infrastructure. #Unbound #DnsSec #HeapOverflow
https://cyberworldops.eu/en/unbound-dnssec-heap-overflow-puts-vulnerable-resolvers-at-risk-of
##Unbound DNSSEC Validator Flaw Enables Remote Code Execution
A critical flaw in the Unbound DNSSEC Validator, known as CVE-2026-81642, allows attackers to trigger a heap overflow, potentially enabling remote code execution on vulnerable systems. This vulnerability affects all Unbound DNS resolver releases before 1.26.1, putting countless systems at risk.
#DnssecValidatorFlaw #RemoteCodeExecution #Cve202681642 #Unbound #HeapOverflow
##NLnet Labs Unbound before 1.26.1 contains heap overflow CVE-2026-81642 in the DNSSEC validator via crafted DNSKEY with compression pointer into RDATA. Any resolver induced to query a malicious zone risks crash or potential RCE, exposing core DNS infrastructure. #Unbound #DnsSec #HeapOverflow
https://cyberworldops.eu/en/unbound-dnssec-heap-overflow-puts-vulnerable-resolvers-at-risk-of
##updated 2026-09-16T00:31:41
1 posts
Go hack more Secret Server shit.
https://delinea.com/security-advisories
##Authentication Bypass via SAML Response Manipulation - CVE-2026-15640
Reflected Cross-Site Scripting - CVE-2026-15639
Cryptographic Padding Oracle - CVE-2026-15638
updated 2026-09-16T00:31:33
1 posts
Go hack more Secret Server shit.
https://delinea.com/security-advisories
##Authentication Bypass via SAML Response Manipulation - CVE-2026-15640
Reflected Cross-Site Scripting - CVE-2026-15639
Cryptographic Padding Oracle - CVE-2026-15638
updated 2026-09-15T15:17:21.707000
2 posts
https://thecybersecguru.com/news/cve-2026-78175-tutor-lms-rce/
##https://thecybersecguru.com/news/cve-2026-78175-tutor-lms-rce/
##updated 2026-09-15T15:17:14.723000
1 posts
A Ghostscript buffer overflow enables unauthenticated remote code execution. Patch this Ghostscript buffer overflow flaw (CVE-2026-39919) immediately.
#Ghostscript #CVE202639919 #RemoteCodeExecution #Cybersecurity #InfoSec
##updated 2026-09-15T14:40:24.370000
1 posts
CVE-2026-81915 Concrete CMS below 9.5.3: broken object-level authz lets any dashboard user edit Page Types outside their scope. CVSS N/A, patch status unknown. Update immediately. https://www.valtersit.com/cve/CVE-2026-81915/ #CVE #infosec #ConcreteCMS
##updated 2026-09-15T12:47:32.497000
5 posts
4 repos
https://github.com/HORKimhab/CVE-2026-76461
https://github.com/S3v3n-JG/CVE-2026-76461
⚪️ Cisco Secure Email Gateway Appliances Can Be Hacked with a Malicious Email
🗨️ Cisco researchers have fixed a critical vulnerability in Secure Email Gateway, a gateway designed to protect email from malicious messages. Ironically, to compromise the gateway itself, an attacker only had to send a specially crafted email through it. The vulnerability…
##Cisco Zero-Day wird aktiv angegriffen
Mal was neues - ach nein, Hintertüren bei Cisco sind ja gar nicht neu, sondern schon fast Gewohnheit. Am Montag hat die Firma ihre Kunden informiert, dass im Secure Email Gateway (SEG) eine Sicherheitslücke steckt, die bereits aktiv angegriffen wird. Dabei ist gleichgültig, ob das SEG auf eigener Hardware (Appliance) läuft oder als virtuelle Maschine oder Cloud-Dienst. Auch die Konfiguration des SEG macht keinen Unterschied. Das muss man sich mal auf der Zunge zergehen lassen: Das SEG, das vor schädlichen E-Mails schützen soll, kann durch genau solche angegriffen werden! Die Sicherheitslücke CVE-2026-76461 ... Weiterlesen:
https://www.pc-fluesterer.info/wordpress/2026/09/17/cisco-zero-day-wird-aktiv-angegriffen/
#0day #backdoor #closedsource #email #exploits #hersteller #sicherheit #UnplugTrump #zeroday #cisco
##⚪️ Cisco Secure Email Gateway Appliances Can Be Hacked with a Malicious Email
🗨️ Cisco researchers have fixed a critical vulnerability in Secure Email Gateway, a gateway designed to protect email from malicious messages. Ironically, to compromise the gateway itself, an attacker only had to send a specially crafted email through it. The vulnerability…
##🏆 New Achievement! Root Access? We'll Get That Escalated for You!
Your ticket has been received. We see you're experiencing an issue where an unauthenticated attacker is executing arbitrary commands with root privileges on your Cisco Secure Email Gateway via CVE-2026-76461. Great news: we've reproduced the bug! It's the email parsing in Cisco AsyncOS — sending a specially crafted email with malicious SQL statements is all it takes. (1/3)
##Recent developments include Cisco patching a critical zero-day (CVE-2026-76461) in its Secure Email Gateway, which was actively exploited for root command execution. Geopolitically, China warned against weaponizing space after the US confirmed orbital weapon deployments. In technology, debates continue on AI safety versus national competitive advantage, with US Speaker Johnson rejecting development pauses.
##updated 2026-09-14T15:33:33
1 posts
CVE-2026-89491 Linux kernel ocfs2 flaw: sleep while holding o2hb_live_lock in o2hb_region_pin(). CVSS N/A, patch status unknown. Update immediately. https://www.valtersit.com/cve/CVE-2026-89491/ #CVE #Linux #infosec
##updated 2026-09-14T15:33:32
1 posts
CVE-2026-89466 Linux kernel qcom_battmgr: unterminated firmware strings leak adjacent memory to userspace. CVSS N/A, patch unknown. Update now. https://www.valtersit.com/cve/CVE-2026-89466/ #CVE #infosec #Linux
##updated 2026-09-14T15:32:26
1 posts
CVE-2026-89478 Linux kernel sctp use-after-free via ASCONF DEL-IP. CVSS N/A, unpatched. Patch or restrict SCTP now. https://www.valtersit.com/cve/CVE-2026-89478/ #CVE #infosec #Linux
##updated 2026-09-14T15:32:26
1 posts
CVE-2026-89483 Linux kernel nvme discard: uninitialized page read leaks 4080 bytes of stale kernel memory to devices. CVSS N/A, patch status unknown. Update kernel now if you run nvme. https://www.valtersit.com/cve/CVE-2026-89483/ #CVE #Linux #infosec
##updated 2026-09-14T15:32:24
1 posts
CVE-2026-89442: out-of-bounds access in the Linux kernel ISST driver lets a bad socket ID index past sst_inst[]. No CVSS or patch yet. Treat as unpatched, restrict ioctl access. Details: https://www.valtersit.com/cve/CVE-2026-89442/ #CVE #Linux #infosec
##updated 2026-09-14T15:32:20
1 posts
CVE-2026-80938 Linux kernel mt7615 wifi deadlock in suspend path, MAC work vs mutex. No CVSS or patch yet. Watch for fixes. https://www.valtersit.com/cve/CVE-2026-80938/ #CVE #Linux #infosec
##updated 2026-09-14T14:22:15.323000
1 posts
13 repos
https://github.com/gagaltotal/CVE-2026-85706-gitlab-poc
https://github.com/gabrielunknown/CVE-2026-85706
https://github.com/0xenesbayram/cve-2026-85706
https://github.com/brigadeops32/CVE-2026-85706
https://github.com/jithinkrishnanrs/gitlab-cve-2026-85706-ioc
https://github.com/ynsmroztas/GitLabSniper
https://github.com/FlowerWitch/CVE-2026-85706_docker_exp
https://github.com/0xlyvio/cve-2026-85706-poc-exploit-gitlab
https://github.com/mhtsec/CVE-2026-85706
https://github.com/solivaquaant/CVE-2026-85706
https://github.com/guneykabel/cve-2026-85706
GitLab CVE-2026-85706: unauth arbitrary file read, exploited in the wild, now on CISA KEV. Patch
19.3.2 / 19.2.6 / 19.1.8.
The 10.0 is about the read. The damage is the credentials inside the files, and a commits API
reads history, so secrets you deleted are still there.
Patch, hunt, THEN rotate. Rotating on a readable server hands over the new keys.
blog.relayshield.net/a-file-read-bug-is-a-credential-theft-bug
#GitLab #infosec #DevSecOps
updated 2026-09-14T13:19:07.537000
1 posts
CVE-2026-89510 Linux kernel RDMA/cxgb4 use-after-free in c4iw_remove, reg_work frees device while registration work still runs. No CVSS, no patch yet. Update your kernel now. https://www.valtersit.com/cve/CVE-2026-89510/ #CVE #infosec #Linux
##updated 2026-09-14T13:19:04.457000
1 posts
CVE-2026-89479 Linux kernel SCTP use-after-free, unpatched, no CVSS assigned. Crafted packet can free an association mid-processing. Patch status unclear, so track kernel updates now. Details: https://www.valtersit.com/cve/CVE-2026-89479/ #CVE #Linux #infosec
##updated 2026-09-14T13:19:03.733000
1 posts
CVE-2026-89474 Linux kernel bq256xx use-after-free in power supply driver, USB work can run after charger freed. No CVSS, no patch yet. Audit and update kernel now. https://www.valtersit.com/cve/CVE-2026-89474/ #CVE #infosec #LinuxKernel
##updated 2026-09-14T13:19:03.620000
1 posts
CVE-2026-89473 Linux kernel bq25890 driver ref leak on probe fail or detach, causing resource exhaustion. No CVSS, no patch yet. Update when vendor fix lands. https://www.valtersit.com/cve/CVE-2026-89473/ #CVE #Linux #infosec
##updated 2026-09-14T13:19:02.357000
1 posts
CVE-2026-89460: Linux kernel s390 cpum_cf crash on CPU hotplug, DoS risk. CVSS N/A, patch status unknown. Audit and update now. https://www.valtersit.com/cve/CVE-2026-89460/ #CVE #Linux #infosec
##updated 2026-09-14T13:19:01.690000
1 posts
CVE-2026-89444 Linux kernel dell-wmi-sysman leaks plaintext BIOS admin password to kernel log. CVSS N/A, patch status unknown. Update now. https://www.valtersit.com/cve/CVE-2026-89444/ #CVE #Linux #infosec
##updated 2026-09-14T13:18:54.883000
2 posts
@hugovalters Thanks for flagging CVE-2026-81005. This NULL pointer dereference in ipmi_si is nasty — BMC failure during Get Device ID shouldn't crash the kernel. Mitigation: disable ipmi_si module if BMC is unresponsive (modprobe -r ipmi_si) or ensure ipmi_si.force_kipmi=0 to avoid kernel thread hang. Patch backports likely in stable kernel queue. #infosec #Linux #CVE
##CVE-2026-81005 Linux kernel NULL pointer dereference in ipmi_si after failed SMI registration. CVSS N/A. Unpatched. A BMC that fails Get Device ID can crash the kernel. Patch now. https://www.valtersit.com/cve/CVE-2026-81005/ #CVE #Linux #infosec
##updated 2026-09-14T13:18:54.210000
7 posts
Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk. #LinuxSecurity #PrivilegeEscalation #KernelSecurity
https://cyberworldops.eu/en/four-public-linux-kernel-exploits-put-unpatched-hosts-at-risk-of-local
##A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, DiagSpill
Linux 커널에서 일반 로컬 사용자를 root로 승격할 수 있는 4개 취약점 DirtyAH6(CVE-2026-80844), TUNderflow(CVE-2026-81000), PPPoEject(CVE-2026-68121), DiagSpill(CVE-2026-74469)가 공개됐다. 취약점들은 네트워크 서브시스템의 오래된 메모리 손상 문제이며, DiagSpill은 별도 capability나 비특권 사용자 네임스페이스 없이도 조건 충족 시 LPE가 가능하고 컨테이너 호스트 탈출 가능성도 있다. 수정은 Linux stable 5.10.270,...
##Ouep, vendredi vuln assisté is back : le kernel Linux, toujours la cible préférée du branding CVE 🐧
DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121) et DiagSpill (CVE-2026-74469) permettent, dans les configurations adaptées, à un utilisateur local non privilégié d'obtenir root.
Bugs présents dans le kernel depuis 10 à 21 ans.
Risque pas uniforme : les trois premières nécessitent des user namespaces non privilégiés + des fonctionnalités réseau particulières (AH6/XFRM, TUN/TAP, PPPoE).
DiagSpill est directement accessible sans capability, MAIS nécessite SCTP + sctp_diag.
Pas de RCE distante générique, mais nuance à connaître pour les passerelles : DirtyAH6 peut causer un DoS distant sur un routeur IPv6 faisant de l'AH en mode transport (root distant obtenu en labo par l'auteur, via grooming côté cible--> jugé "extrêmement difficile").
DiagSpill a aussi un vecteur DoS distant si ASCONF/ADD-IP + SCTP-AUTH (ou addip_noauth_enable=1) sont actifs-->désactivés par défaut.
➡️ À surveiller en priorité : systèmes multi-utilisateurs, conteneurs, hôtes TUN/TAP, PPPoE, XFRM/AH6 ou SCTP.
🔎 Analyse complète
👇
https://heyitsas.im/posts/lpe-quartet/
:debian:
👇
DirtyAH6 corrigé sur Bookworm-security, encore vulnérable sur Trixie.
TUNderflow corrigée uniquement dans sid
PPPoEject et DiagSpill corrigés sur Bookworm-security et Trixie.
⬇️
DirtyAH6 — CVE-2026-80844
Debian Security Tracker
TUNderflow — CVE-2026-81000
Debian Security Tracker
PPPoEject — CVE-2026-68121
Debian Security Tracker
DiagSpill — CVE-2026-74469
Debian Security Tracker
PoCs 👀
👇
DirtyAH6 — CVE-2026-80844 : https://github.com/manizada/DirtyAH6
TUNderflow — CVE-2026-81000 : https://github.com/manizada/TUNderflow
PPPoEject — CVE-2026-68121 : https://github.com/manizada/PPPoEject
DiagSpill — CVE-2026-74469 : https://github.com/manizada/DiagSpill
It's Friday, and we have 4 more local privilege escalation vulnerabilities disclosed for the Linux kernel:
- DirtyAH6 (CVE-2026-80844)
- TUNderflow (CVE-2026-81000)
- PPPoEject (CVE-2026-68121)
- DiagSpill (CVE-2026-74469)
"The underlying bugs have been around for 10-21 years. The first three LPEs require either unprivileged user namespaces or specific CAPs; DiagSpill does not."
https://www.openwall.com/lists/oss-security/2026/09/18/3
https://heyitsas.im/posts/lpe-quartet/
#CVE_2026_80844 #CVE_2026_81000 #CVE_2026_68121 #CVE_2026_74469
##Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk. #LinuxSecurity #PrivilegeEscalation #KernelSecurity
https://cyberworldops.eu/en/four-public-linux-kernel-exploits-put-unpatched-hosts-at-risk-of-local
##Ouep, vendredi vuln assisté is back : le kernel Linux, toujours la cible préférée du branding CVE 🐧
DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121) et DiagSpill (CVE-2026-74469) permettent, dans les configurations adaptées, à un utilisateur local non privilégié d'obtenir root.
Bugs présents dans le kernel depuis 10 à 21 ans.
Risque pas uniforme : les trois premières nécessitent des user namespaces non privilégiés + des fonctionnalités réseau particulières (AH6/XFRM, TUN/TAP, PPPoE).
DiagSpill est directement accessible sans capability, MAIS nécessite SCTP + sctp_diag.
Pas de RCE distante générique, mais nuance à connaître pour les passerelles : DirtyAH6 peut causer un DoS distant sur un routeur IPv6 faisant de l'AH en mode transport (root distant obtenu en labo par l'auteur, via grooming côté cible--> jugé "extrêmement difficile").
DiagSpill a aussi un vecteur DoS distant si ASCONF/ADD-IP + SCTP-AUTH (ou addip_noauth_enable=1) sont actifs-->désactivés par défaut.
➡️ À surveiller en priorité : systèmes multi-utilisateurs, conteneurs, hôtes TUN/TAP, PPPoE, XFRM/AH6 ou SCTP.
🔎 Analyse complète
👇
https://heyitsas.im/posts/lpe-quartet/
:debian:
👇
DirtyAH6 corrigé sur Bookworm-security, encore vulnérable sur Trixie.
TUNderflow corrigée uniquement dans sid
PPPoEject et DiagSpill corrigés sur Bookworm-security et Trixie.
⬇️
DirtyAH6 — CVE-2026-80844
Debian Security Tracker
TUNderflow — CVE-2026-81000
Debian Security Tracker
PPPoEject — CVE-2026-68121
Debian Security Tracker
DiagSpill — CVE-2026-74469
Debian Security Tracker
PoCs 👀
👇
DirtyAH6 — CVE-2026-80844 : https://github.com/manizada/DirtyAH6
TUNderflow — CVE-2026-81000 : https://github.com/manizada/TUNderflow
PPPoEject — CVE-2026-68121 : https://github.com/manizada/PPPoEject
DiagSpill — CVE-2026-74469 : https://github.com/manizada/DiagSpill
It's Friday, and we have 4 more local privilege escalation vulnerabilities disclosed for the Linux kernel:
- DirtyAH6 (CVE-2026-80844)
- TUNderflow (CVE-2026-81000)
- PPPoEject (CVE-2026-68121)
- DiagSpill (CVE-2026-74469)
"The underlying bugs have been around for 10-21 years. The first three LPEs require either unprivileged user namespaces or specific CAPs; DiagSpill does not."
https://www.openwall.com/lists/oss-security/2026/09/18/3
https://heyitsas.im/posts/lpe-quartet/
#CVE_2026_80844 #CVE_2026_81000 #CVE_2026_68121 #CVE_2026_74469
##updated 2026-09-14T13:18:52.947000
1 posts
CVE-2026-80982 Linux net/smc use-after-free in smc_rx_pipe_buf_release(), patch status unknown, CVSS not assigned. Unpatched kernel race can crash or corrupt memory. Update immediately. https://www.valtersit.com/cve/CVE-2026-80982/ #CVE #Linux #infosec
##updated 2026-09-14T13:18:51.370000
1 posts
CVE-2026-80967 Linux ALSA pcxhr: mutexes initialized after threaded IRQ request, risking uninitialized lock state during probe. Patch status unknown. Update your kernel now. https://www.valtersit.com/cve/CVE-2026-80967/ #CVE #infosec #Linux
##updated 2026-09-14T13:18:50.710000
1 posts
CVE-2026-80952 Linux kernel i3c UAF and info leak in device unregister path, CVSS N/A, patch status unknown. Assume unpatched. Patch now: https://www.valtersit.com/cve/CVE-2026-80952/ #CVE #infosec #Linux
##updated 2026-09-14T13:18:50.160000
1 posts
CVE-2026-80941 Linux rtw88 wifi driver memory leak in rtw_txq_push_skb error path. No CVSS or patch confirmed yet. Update your kernel as soon as fixes land. https://www.valtersit.com/cve/CVE-2026-80941/ #CVE #Linux #infosec
##updated 2026-09-14T13:18:50.037000
1 posts
CVE-2026-80939 Linux rtw89 PCI wifi driver can panic arm64 systems with SError on warm reboot due to rfkill polling with no shutdown callback. No CVSS assigned, patch status unknown. Apply kernel updates when https://www.valtersit.com/cve/CVE-2026-80939/ #CVE #Linux #infosec
##updated 2026-09-14T12:31:44
1 posts
New Parallels Desktop Flaw Lets Local Users Seize Root Control of Macs
A newly documented security flaw in Parallels Desktop, identified as CVE-2026-90894 and nicknamed "ParaShells," could let any local account on
🔗️ [Thecyberexpress] https://link.is.it/XRBHSO
##updated 2026-09-13T09:33:29
1 posts
CVE-2026-89520 Linux kernel core-sched race lets __sched_core_flip rebind rq_lockp mid-selection. No CVSS, no patch yet. Update to latest stable kernel when fixed. https://www.valtersit.com/cve/CVE-2026-89520/ #CVE #Linux #infosec
##updated 2026-09-13T09:32:11
1 posts
CVE-2026-80954 Linux kernel i3c unlocked dev->desc dereference, unpatched, CVSS N/A. Patch now if you run i3c. https://www.valtersit.com/cve/CVE-2026-80954/ #CVE #infosec #Linux
##updated 2026-09-13T07:17:12.417000
1 posts
CVE-2026-89492 Linux kernel ocfs2 out-of-bounds access via unchecked directory-index entry counts. No CVSS or patch yet. Treat as unpatched and update immediately if ocfs2 is in use. https://www.valtersit.com/cve/CVE-2026-89492/ #CVE #infosec #Linux
##updated 2026-09-13T07:17:09.477000
1 posts
CVE-2026-89452 Linux kernel iommu/msm probe failure leaves a dangling list entry, risking use-after-free on later list walks. No CVSS score and no patch yet. Track it and update the kernel as soon as a fix https://www.valtersit.com/cve/CVE-2026-89452/ #CVE #LinuxKernel #infosec
##updated 2026-09-13T07:17:02.463000
1 posts
CVE-2026-80953 Linux i3c adi driver inits lock after enabling IRQ, risking race and memory corruption. CVSS N/A, unpatched. Patch or mitigate now. https://www.valtersit.com/cve/CVE-2026-80953/ #CVE #Linux #infosec
##updated 2026-09-12T04:16:42.757000
1 posts
(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-84869 – ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
C-Suite threat intelligence and mitigation protocols for CVE-2026-84869, addressing active exploitation vectors within enterprise ConnectWise environments....
##updated 2026-09-12T03:30:29
1 posts
CVE-2026-90467 aiosmtplib before 5.1.3: ESMTP parameter injection via MAIL FROM/RCPT TO, forged auth and forced notifications. CVSS 4.0, no patch confirmed. Update to 5.1.3+ now. https://www.valtersit.com/cve/CVE-2026-90467/ #CVE #infosec #cybersecurity
##updated 2026-09-11T21:31:37
1 posts
CVE-2026-89529 Linux kernel svcrdma: unvalidated Read segment lengths allow oversized allocation. No CVSS yet, patch status unknown. Update your kernel now: https://www.valtersit.com/cve/CVE-2026-89529/ #CVE #infosec #Linux
##updated 2026-09-11T21:31:06
1 posts
(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-42016 – JFrog Artifactory Incorrect Authorization Vulnerability
C-Suite threat intelligence for CVE-2026-42016, covering OAuth scope validation, lateral movement detection, and repository hardening across JFrog Artifactory instances....
##updated 2026-09-11T20:19:26.220000
1 posts
CVE-2026-89455 Linux kernel PCI plda use-after-free during IRQ teardown. No CVSS or patch yet. Audit and update affected systems. https://www.valtersit.com/cve/CVE-2026-89455/ #CVE #Linux #infosec
##updated 2026-09-11T20:19:25.967000
1 posts
CVE-2026-89453 Linux kernel iommu/amd PPR fault handling leaks PCI device references. Unpatched. Patch now https://www.valtersit.com/cve/CVE-2026-89453/ #CVE #infosec #Linux
##updated 2026-09-11T04:17:13.060000
2 posts
@badsamurai CVE-2026-0310 go brrrrrr
##@badsamurai CVE-2026-0310 go brrrrrr
##updated 2026-09-09T16:04:24.933000
1 posts
1 repos
aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3
perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38
sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0
セキュリティ対応なのでお早めに。
##updated 2026-09-08T22:17:38.113000
1 posts
aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3
perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38
sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0
セキュリティ対応なのでお早めに。
##updated 2026-09-08T17:56:31
1 posts
10 repos
https://github.com/shinthink/CVE-2026-60004
https://github.com/HORKimhab/CVE-2026-60004
https://github.com/gagaltotal/CVE-2026-60004-poc-gitea
https://github.com/imbas007/CVE-2026-60004-POC
https://github.com/HackSpeak/CVE-2026-60004
https://github.com/0xBlackash/CVE-2026-60004
https://github.com/EQSTLab/CVE-2026-60004
https://github.com/erberkan/CVE-2026-60004-PoC
📢 Red Heron exploite CVE-2026-60004 dans Gitea pour déployer un rootkit Linux inédit
L'Acronis Threat Research Unit (TRU) a publié le 13 septembre 2026 une analyse détaillée d'une campagne multinationale menée par un acteur malveillant sinophone qu'ils suivent sous le nom Red Heron. La découverte initiale remonte au 4 août 2026, lorsque TRU a…
📖 cyberveille : https://cyberveille.ch/posts/2026-09-17-red-heron-exploite-cve-2026-60004-dans-gitea-pour-deployer-un-rootkit-linux-inedit/
🌐 source : https://www.acronis.com/en/tru/posts/red-heron-exploits-gitea-n-day-flaw-in-multinational-campaign-exposing-new-linux-rootkit/
🟢 vérification factuelle haute
#RedHeron #RootkitLinux #Cyberveille
updated 2026-09-08T15:13:07.273000
1 posts
100 repos
https://github.com/ben-slates/CVE-2026-31431-Exploit
https://github.com/wesmar/CVE-2026-31431
https://github.com/pyroceper/copy-fail-CVE-2026-31431
https://github.com/Boos4721/copyfail-rs
https://github.com/erlangparasu/mitigate_cve_2026_31431-sh
https://github.com/mahdi13830510/CVE-2026-31431-mitigation-suite
https://github.com/Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail
https://github.com/insomnisec/Detections-CVE-2026-31431
https://github.com/Smarttfoxx/copyfail
https://github.com/sgkdev/page_inject
https://github.com/desultory/CVE-2026-31431
https://github.com/Juguitos/copy-fail
https://github.com/4xura/CVE-2026-31431-Copy-Fail
https://github.com/bigwario/copy-fail-CVE-2026-31431-C
https://github.com/Huchangzhi/autorootlinux
https://github.com/badsectorlabs/copyfail-go
https://github.com/philfry/cve-2026-31431-ftrace
https://github.com/ErdemOzgen/copy-fail-cve-2026-31431
https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe
https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script
https://github.com/aestechno/cve-2026-31431-ansible
https://github.com/cozystack/copy-fail-blocker
https://github.com/KaraZajac/DIRTYFAIL
https://github.com/theori-io/copy-fail-CVE-2026-31431
https://github.com/xeloxa/copyfail-exploit
https://github.com/kinryulabs/rootpacket-cve-2026-31431
https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431
https://github.com/painoob/Copy-Fail-Exploit-CVE-2026-31431
https://github.com/nisec-eric/cve-2026-31431
https://github.com/b5null/CVE-2026-31431-C
https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs
https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit
https://github.com/povzayd/CVE-2026-31431
https://github.com/mrunalp/block-copyfail
https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag
https://github.com/diemoeve/copyfail-rs
https://github.com/ExploitEoom/CVE-2026-31431
https://github.com/wuwu001/CVE-2026-31431-exploit
https://github.com/TheMalwareGuardian/CVE-2026-31431
https://github.com/samanzamani/copy-fail-checker
https://github.com/JuanBindez/CVE-2026-31431
https://github.com/SeanRickerd/cve-2026-31431
https://github.com/wgnet/wg.copyfail.patch
https://github.com/qi4L/CVE-2026-31431-Container-Escape
https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431
https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE
https://github.com/tgies/copy-fail-c
https://github.com/ZephrFish/CopyFail-CVE-2026-31431
https://github.com/Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431
https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC
https://github.com/ncmprbll/copy-fail-rs
https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized
https://github.com/Dabbleam/CVE-2026-31431-mitigation
https://github.com/Sl4cK0TH/CVE-2026-31431-PoC
https://github.com/AliHzSec/CVE-2026-31431
https://github.com/rvzsec/CVE-2026-31431
https://github.com/yuspring/cve-2026-31431-poc
https://github.com/M4xSec/CVE-2026-31431-RCE-Exploit
https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit
https://github.com/Alfredooe/CVE-2026-31431
https://github.com/0xBlackash/CVE-2026-31431
https://github.com/scriptzteam/Paranoid-Copy-Fail-CVE-2026-31431
https://github.com/haydenjames/CVE-2026-31431-check
https://github.com/yandex-cloud-examples/yc-mk8s-copy-fail-mitigation
https://github.com/sgkdev/ptrace_may_dream
https://github.com/Qengineering/RK35xx-CopyFail-Hotfix
https://github.com/g1nt0n1x/copy-fail-CVE-2026-31431-shell
https://github.com/mym0us3r/COPY-FAIL-Detection-with-Wazuh-4.14.4
https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC
https://github.com/Shotafry/CopyFail-Exploits-CVE-2026-31431
https://github.com/JnamerZ/CopyFail-CVE-2026-31431
https://github.com/pedromizz/copy-fail
https://github.com/lonelyor/CVE-2026-31431-exp
https://github.com/Iamliuxiaozhen/copy_fail
https://github.com/rootsecdev/cve_2026_31431
https://github.com/bootsareme/copyfail-deconstructed
https://github.com/adampielak/CVE-2026-31431_SCA_WAZUH
https://github.com/gagaltotal/cve-2026-31431-copy-fail
https://github.com/malwarekid/CVE-2026-31431
https://github.com/kadir/copy-fail-CVE-2026-31431-IOC
https://github.com/jbnetwork-git/copy-fail-check
https://github.com/sammwyy/copyfail-rs
https://github.com/Xerxes-2/CVE-2026-31431-rs
https://github.com/luotian2/CVE-2026-31431
https://github.com/cs8425/copy-fail-go
https://github.com/MartinPham/copy-fail-CVE-2026-31431-php
https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail
https://github.com/guiimoraes/CVE-2026-31431
https://github.com/atgreen/block-copyfail
https://github.com/sudoytang/copyfail-arm64
https://github.com/XsanFlip/CVE-2026-31431-Patch
https://github.com/MrAriaNet/cPanel-Fix
https://github.com/sec17br/CVE-2026-31431-Copy-Fail
https://github.com/cyber-joker/copy-fail-python
https://github.com/novysodope/copy-fail-CVE-2026-31431-C
https://github.com/0xShe/CVE-2026-31431
https://github.com/pascal-gujer/CVE-2026-31431
https://github.com/abdelkabirouadoukou/CVE-2026-31431-Analysis-and-Fix
https://github.com/hans362/CVE-2026-31431-Copy-Fail-Container-Escape
When the Red Light Goes On: How We Responded to the Linux Kernel 0-Day
Linux 커널의 공개 PoC 로컬 권한 상승 취약점 CVE-2026-31431("Copy Fail")이 Ubuntu 24.04에서 비권한 사용자로부터 root 획득까지 가능하다고 보고됐다. 원인은 Crypto User API의 AF_ALG 경로에서 `algif_aead` 모듈에 도달 가능한 out-of-bounds write이며, 웹 애플리케이션 침해가 호스트 전체 침해로 확대될 수 있어 멀티테넌트 서버와 컨테이너 노드 운영자에게 특히 중요하다. 패치가 배포되기 전에는 `algif_aead`를 언로드하고 modprobe 설정으로 재로딩을 차단하는 방식으로 공...
##updated 2026-09-04T18:32:18
3 posts
1 repos
TP-Link Patches Critical Flaws in Tapo Surveillance Cameras
TP-Link patched multiple vulnerabilities in its Tapo C200 and C120 cameras, including an authentication bypass (CVE-2026-15315) and a denial-of-service flaw (CVE-2026-15316), while a third critical vulnerability remains under investigation.
**Update your Tapo camera firmware to version V5_1.4.6 ASAP, and check for new updates for the most severe issue that's still not patched. And move all smart cameras to a separate guest network to keep your main computers safe if a device is hacked.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/tp-link-patches-critical-flaws-in-tapo-surveillance-cameras-w-h-9-n-b/gD2P6Ple2L
TP-Link Patches Critical Flaws in Tapo Surveillance Cameras
TP-Link patched multiple vulnerabilities in its Tapo C200 and C120 cameras, including an authentication bypass (CVE-2026-15315) and a denial-of-service flaw (CVE-2026-15316), while a third critical vulnerability remains under investigation.
**Update your Tapo camera firmware to version V5_1.4.6 ASAP, and check for new updates for the most severe issue that's still not patched. And move all smart cameras to a separate guest network to keep your main computers safe if a device is hacked.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/tp-link-patches-critical-flaws-in-tapo-surveillance-cameras-w-h-9-n-b/gD2P6Ple2L
In case you didn't have enough problems with cameras, here's another one.
OPSWAT, posted yesterday: Authentication Bypass and DoS Vulnerabilities: OPSWAT Discovers CVE-2026-15315 & CVE-2026-15316 in TP-Link Tapo Cameras https://www.opswat.com/blog/authentication-bypass-and-dos-vulnerabilities-opswat-discovers-cve-2026-15315-cve-2026-15316-in-tp-link-tapo-cameras
More:
Infosecurity-Magazine: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping https://www.infosecurity-magazine.com/news/zeroday-tplink-cameras/ #infosec #vulnerability #spyware #zeroday #threatresearch
##updated 2026-09-04T17:26:04.617000
4 posts
1 repos
TP-Link Patches Critical Flaws in Tapo Surveillance Cameras
TP-Link patched multiple vulnerabilities in its Tapo C200 and C120 cameras, including an authentication bypass (CVE-2026-15315) and a denial-of-service flaw (CVE-2026-15316), while a third critical vulnerability remains under investigation.
**Update your Tapo camera firmware to version V5_1.4.6 ASAP, and check for new updates for the most severe issue that's still not patched. And move all smart cameras to a separate guest network to keep your main computers safe if a device is hacked.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/tp-link-patches-critical-flaws-in-tapo-surveillance-cameras-w-h-9-n-b/gD2P6Ple2L
TP-Link Patches Critical Flaws in Tapo Surveillance Cameras
TP-Link patched multiple vulnerabilities in its Tapo C200 and C120 cameras, including an authentication bypass (CVE-2026-15315) and a denial-of-service flaw (CVE-2026-15316), while a third critical vulnerability remains under investigation.
**Update your Tapo camera firmware to version V5_1.4.6 ASAP, and check for new updates for the most severe issue that's still not patched. And move all smart cameras to a separate guest network to keep your main computers safe if a device is hacked.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/tp-link-patches-critical-flaws-in-tapo-surveillance-cameras-w-h-9-n-b/gD2P6Ple2L
In case you didn't have enough problems with cameras, here's another one.
OPSWAT, posted yesterday: Authentication Bypass and DoS Vulnerabilities: OPSWAT Discovers CVE-2026-15315 & CVE-2026-15316 in TP-Link Tapo Cameras https://www.opswat.com/blog/authentication-bypass-and-dos-vulnerabilities-opswat-discovers-cve-2026-15315-cve-2026-15316-in-tp-link-tapo-cameras
More:
Infosecurity-Magazine: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping https://www.infosecurity-magazine.com/news/zeroday-tplink-cameras/ #infosec #vulnerability #spyware #zeroday #threatresearch
##CVE-2026-15316 throws in a denial-of-service against the onboarding flow as a bonus gift with purchase.
Perhaps you'd like our Extended Vulnerability Warranty? Only $49.99. Or — and hear me out — you could just update your Tapo C200 to firmware V5_1.4.6, released August 18, for the remarkable price of free.
Reward: You've received a slightly-used Tin Foil Lens Cap. Refurbished. Non-returnable.
https://www.infosecurity-magazine.com/news/zeroday-tplink-cameras
#ZeroDay #CyberSecurity (2/2)
##updated 2026-09-04T16:18:13.023000
7 posts
Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk. #LinuxSecurity #PrivilegeEscalation #KernelSecurity
https://cyberworldops.eu/en/four-public-linux-kernel-exploits-put-unpatched-hosts-at-risk-of-local
##A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, DiagSpill
Linux 커널에서 일반 로컬 사용자를 root로 승격할 수 있는 4개 취약점 DirtyAH6(CVE-2026-80844), TUNderflow(CVE-2026-81000), PPPoEject(CVE-2026-68121), DiagSpill(CVE-2026-74469)가 공개됐다. 취약점들은 네트워크 서브시스템의 오래된 메모리 손상 문제이며, DiagSpill은 별도 capability나 비특권 사용자 네임스페이스 없이도 조건 충족 시 LPE가 가능하고 컨테이너 호스트 탈출 가능성도 있다. 수정은 Linux stable 5.10.270,...
##Ouep, vendredi vuln assisté is back : le kernel Linux, toujours la cible préférée du branding CVE 🐧
DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121) et DiagSpill (CVE-2026-74469) permettent, dans les configurations adaptées, à un utilisateur local non privilégié d'obtenir root.
Bugs présents dans le kernel depuis 10 à 21 ans.
Risque pas uniforme : les trois premières nécessitent des user namespaces non privilégiés + des fonctionnalités réseau particulières (AH6/XFRM, TUN/TAP, PPPoE).
DiagSpill est directement accessible sans capability, MAIS nécessite SCTP + sctp_diag.
Pas de RCE distante générique, mais nuance à connaître pour les passerelles : DirtyAH6 peut causer un DoS distant sur un routeur IPv6 faisant de l'AH en mode transport (root distant obtenu en labo par l'auteur, via grooming côté cible--> jugé "extrêmement difficile").
DiagSpill a aussi un vecteur DoS distant si ASCONF/ADD-IP + SCTP-AUTH (ou addip_noauth_enable=1) sont actifs-->désactivés par défaut.
➡️ À surveiller en priorité : systèmes multi-utilisateurs, conteneurs, hôtes TUN/TAP, PPPoE, XFRM/AH6 ou SCTP.
🔎 Analyse complète
👇
https://heyitsas.im/posts/lpe-quartet/
:debian:
👇
DirtyAH6 corrigé sur Bookworm-security, encore vulnérable sur Trixie.
TUNderflow corrigée uniquement dans sid
PPPoEject et DiagSpill corrigés sur Bookworm-security et Trixie.
⬇️
DirtyAH6 — CVE-2026-80844
Debian Security Tracker
TUNderflow — CVE-2026-81000
Debian Security Tracker
PPPoEject — CVE-2026-68121
Debian Security Tracker
DiagSpill — CVE-2026-74469
Debian Security Tracker
PoCs 👀
👇
DirtyAH6 — CVE-2026-80844 : https://github.com/manizada/DirtyAH6
TUNderflow — CVE-2026-81000 : https://github.com/manizada/TUNderflow
PPPoEject — CVE-2026-68121 : https://github.com/manizada/PPPoEject
DiagSpill — CVE-2026-74469 : https://github.com/manizada/DiagSpill
It's Friday, and we have 4 more local privilege escalation vulnerabilities disclosed for the Linux kernel:
- DirtyAH6 (CVE-2026-80844)
- TUNderflow (CVE-2026-81000)
- PPPoEject (CVE-2026-68121)
- DiagSpill (CVE-2026-74469)
"The underlying bugs have been around for 10-21 years. The first three LPEs require either unprivileged user namespaces or specific CAPs; DiagSpill does not."
https://www.openwall.com/lists/oss-security/2026/09/18/3
https://heyitsas.im/posts/lpe-quartet/
#CVE_2026_80844 #CVE_2026_81000 #CVE_2026_68121 #CVE_2026_74469
##Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk. #LinuxSecurity #PrivilegeEscalation #KernelSecurity
https://cyberworldops.eu/en/four-public-linux-kernel-exploits-put-unpatched-hosts-at-risk-of-local
##Ouep, vendredi vuln assisté is back : le kernel Linux, toujours la cible préférée du branding CVE 🐧
DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121) et DiagSpill (CVE-2026-74469) permettent, dans les configurations adaptées, à un utilisateur local non privilégié d'obtenir root.
Bugs présents dans le kernel depuis 10 à 21 ans.
Risque pas uniforme : les trois premières nécessitent des user namespaces non privilégiés + des fonctionnalités réseau particulières (AH6/XFRM, TUN/TAP, PPPoE).
DiagSpill est directement accessible sans capability, MAIS nécessite SCTP + sctp_diag.
Pas de RCE distante générique, mais nuance à connaître pour les passerelles : DirtyAH6 peut causer un DoS distant sur un routeur IPv6 faisant de l'AH en mode transport (root distant obtenu en labo par l'auteur, via grooming côté cible--> jugé "extrêmement difficile").
DiagSpill a aussi un vecteur DoS distant si ASCONF/ADD-IP + SCTP-AUTH (ou addip_noauth_enable=1) sont actifs-->désactivés par défaut.
➡️ À surveiller en priorité : systèmes multi-utilisateurs, conteneurs, hôtes TUN/TAP, PPPoE, XFRM/AH6 ou SCTP.
🔎 Analyse complète
👇
https://heyitsas.im/posts/lpe-quartet/
:debian:
👇
DirtyAH6 corrigé sur Bookworm-security, encore vulnérable sur Trixie.
TUNderflow corrigée uniquement dans sid
PPPoEject et DiagSpill corrigés sur Bookworm-security et Trixie.
⬇️
DirtyAH6 — CVE-2026-80844
Debian Security Tracker
TUNderflow — CVE-2026-81000
Debian Security Tracker
PPPoEject — CVE-2026-68121
Debian Security Tracker
DiagSpill — CVE-2026-74469
Debian Security Tracker
PoCs 👀
👇
DirtyAH6 — CVE-2026-80844 : https://github.com/manizada/DirtyAH6
TUNderflow — CVE-2026-81000 : https://github.com/manizada/TUNderflow
PPPoEject — CVE-2026-68121 : https://github.com/manizada/PPPoEject
DiagSpill — CVE-2026-74469 : https://github.com/manizada/DiagSpill
It's Friday, and we have 4 more local privilege escalation vulnerabilities disclosed for the Linux kernel:
- DirtyAH6 (CVE-2026-80844)
- TUNderflow (CVE-2026-81000)
- PPPoEject (CVE-2026-68121)
- DiagSpill (CVE-2026-74469)
"The underlying bugs have been around for 10-21 years. The first three LPEs require either unprivileged user namespaces or specific CAPs; DiagSpill does not."
https://www.openwall.com/lists/oss-security/2026/09/18/3
https://heyitsas.im/posts/lpe-quartet/
#CVE_2026_80844 #CVE_2026_81000 #CVE_2026_68121 #CVE_2026_74469
##updated 2026-09-01T15:31:17
2 posts
Schneider Electric disclosed CVE-2026-13348 (CWE-307) in PowerChute Serial Shutdown, allowing unrestricted authentication attempts. Successful brute-forcing enables account takeover with impact on UPS management and operational continuity. #SchneiderElectric #PowerChute #BruteForce
https://cyberworldops.eu/en/powerchute-authentication-flaw-opens-the-door-to-unlimited-login
##Schneider Electric disclosed CVE-2026-13348 (CWE-307) in PowerChute Serial Shutdown, allowing unrestricted authentication attempts. Successful brute-forcing enables account takeover with impact on UPS management and operational continuity. #SchneiderElectric #PowerChute #BruteForce
https://cyberworldops.eu/en/powerchute-authentication-flaw-opens-the-door-to-unlimited-login
##updated 2026-09-01T13:19:49.913000
1 posts
aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3
perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38
sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0
セキュリティ対応なのでお早めに。
##updated 2026-08-31T15:35:36
1 posts
aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3
perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38
sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0
セキュリティ対応なのでお早めに。
##updated 2026-08-31T15:34:31
1 posts
aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3
perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38
sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0
セキュリティ対応なのでお早めに。
##updated 2026-08-31T15:34:31
1 posts
aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3
perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38
sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0
セキュリティ対応なのでお早めに。
##updated 2026-08-28T22:53:42
2 posts
15 repos
https://github.com/ynsmroztas/KeySniper
https://github.com/BlackHatExploitation/Exploit-For-CVE-2026-18963
https://github.com/0xlyvio/CVE-2026-18963-keycloak
https://github.com/prot0tw/Keycloak_CVE-2026-18963_PoC
https://github.com/T0w0T/POC-CVE-2026-18963
https://github.com/kyos-public/keycloak-cve-2026-18963-hunt
https://github.com/debugactiveprocess/CVE-2026-18963
https://github.com/Snizi/CVE-2026-18963-Exploit
https://github.com/minh3102011/CVE-2026-18963_analyst
https://github.com/alt3kx/CVE-2026-18963
https://github.com/EQSTLab/CVE-2026-18963
https://github.com/gman0x00/keycloak-CVE-2026-18963
https://github.com/M4xSec/My-Exploits
HCL Software patched critical HCL BigFix vulnerabilities, including CVE-2026-67100 and CVE-2026-18963. Patch now to prevent total account takeovers.
#HCLBigFix #Cybersecurity #CVE202667100 #Vulnerability #InfoSec
##HCL Software patched critical HCL BigFix vulnerabilities, including CVE-2026-67100 and CVE-2026-18963. Patch now to prevent total account takeovers.
#HCLBigFix #Cybersecurity #CVE202667100 #Vulnerability #InfoSec
##updated 2026-08-24T18:32:30
2 posts
bison (2:3.8.2+dfsg-1ubuntu0.24.04.1)
CVE-2026-56389へのセキュリティ対応。
セキュリティ対応なのでお早めに。
##bison (2:3.8.2+dfsg-1ubuntu0.24.04.1)
CVE-2026-56389へのセキュリティ対応。
セキュリティ対応なのでお早めに。
##updated 2026-08-19T17:21:03.977000
7 posts
Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk. #LinuxSecurity #PrivilegeEscalation #KernelSecurity
https://cyberworldops.eu/en/four-public-linux-kernel-exploits-put-unpatched-hosts-at-risk-of-local
##A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, DiagSpill
Linux 커널에서 일반 로컬 사용자를 root로 승격할 수 있는 4개 취약점 DirtyAH6(CVE-2026-80844), TUNderflow(CVE-2026-81000), PPPoEject(CVE-2026-68121), DiagSpill(CVE-2026-74469)가 공개됐다. 취약점들은 네트워크 서브시스템의 오래된 메모리 손상 문제이며, DiagSpill은 별도 capability나 비특권 사용자 네임스페이스 없이도 조건 충족 시 LPE가 가능하고 컨테이너 호스트 탈출 가능성도 있다. 수정은 Linux stable 5.10.270,...
##Ouep, vendredi vuln assisté is back : le kernel Linux, toujours la cible préférée du branding CVE 🐧
DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121) et DiagSpill (CVE-2026-74469) permettent, dans les configurations adaptées, à un utilisateur local non privilégié d'obtenir root.
Bugs présents dans le kernel depuis 10 à 21 ans.
Risque pas uniforme : les trois premières nécessitent des user namespaces non privilégiés + des fonctionnalités réseau particulières (AH6/XFRM, TUN/TAP, PPPoE).
DiagSpill est directement accessible sans capability, MAIS nécessite SCTP + sctp_diag.
Pas de RCE distante générique, mais nuance à connaître pour les passerelles : DirtyAH6 peut causer un DoS distant sur un routeur IPv6 faisant de l'AH en mode transport (root distant obtenu en labo par l'auteur, via grooming côté cible--> jugé "extrêmement difficile").
DiagSpill a aussi un vecteur DoS distant si ASCONF/ADD-IP + SCTP-AUTH (ou addip_noauth_enable=1) sont actifs-->désactivés par défaut.
➡️ À surveiller en priorité : systèmes multi-utilisateurs, conteneurs, hôtes TUN/TAP, PPPoE, XFRM/AH6 ou SCTP.
🔎 Analyse complète
👇
https://heyitsas.im/posts/lpe-quartet/
:debian:
👇
DirtyAH6 corrigé sur Bookworm-security, encore vulnérable sur Trixie.
TUNderflow corrigée uniquement dans sid
PPPoEject et DiagSpill corrigés sur Bookworm-security et Trixie.
⬇️
DirtyAH6 — CVE-2026-80844
Debian Security Tracker
TUNderflow — CVE-2026-81000
Debian Security Tracker
PPPoEject — CVE-2026-68121
Debian Security Tracker
DiagSpill — CVE-2026-74469
Debian Security Tracker
PoCs 👀
👇
DirtyAH6 — CVE-2026-80844 : https://github.com/manizada/DirtyAH6
TUNderflow — CVE-2026-81000 : https://github.com/manizada/TUNderflow
PPPoEject — CVE-2026-68121 : https://github.com/manizada/PPPoEject
DiagSpill — CVE-2026-74469 : https://github.com/manizada/DiagSpill
It's Friday, and we have 4 more local privilege escalation vulnerabilities disclosed for the Linux kernel:
- DirtyAH6 (CVE-2026-80844)
- TUNderflow (CVE-2026-81000)
- PPPoEject (CVE-2026-68121)
- DiagSpill (CVE-2026-74469)
"The underlying bugs have been around for 10-21 years. The first three LPEs require either unprivileged user namespaces or specific CAPs; DiagSpill does not."
https://www.openwall.com/lists/oss-security/2026/09/18/3
https://heyitsas.im/posts/lpe-quartet/
#CVE_2026_80844 #CVE_2026_81000 #CVE_2026_68121 #CVE_2026_74469
##Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk. #LinuxSecurity #PrivilegeEscalation #KernelSecurity
https://cyberworldops.eu/en/four-public-linux-kernel-exploits-put-unpatched-hosts-at-risk-of-local
##Ouep, vendredi vuln assisté is back : le kernel Linux, toujours la cible préférée du branding CVE 🐧
DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121) et DiagSpill (CVE-2026-74469) permettent, dans les configurations adaptées, à un utilisateur local non privilégié d'obtenir root.
Bugs présents dans le kernel depuis 10 à 21 ans.
Risque pas uniforme : les trois premières nécessitent des user namespaces non privilégiés + des fonctionnalités réseau particulières (AH6/XFRM, TUN/TAP, PPPoE).
DiagSpill est directement accessible sans capability, MAIS nécessite SCTP + sctp_diag.
Pas de RCE distante générique, mais nuance à connaître pour les passerelles : DirtyAH6 peut causer un DoS distant sur un routeur IPv6 faisant de l'AH en mode transport (root distant obtenu en labo par l'auteur, via grooming côté cible--> jugé "extrêmement difficile").
DiagSpill a aussi un vecteur DoS distant si ASCONF/ADD-IP + SCTP-AUTH (ou addip_noauth_enable=1) sont actifs-->désactivés par défaut.
➡️ À surveiller en priorité : systèmes multi-utilisateurs, conteneurs, hôtes TUN/TAP, PPPoE, XFRM/AH6 ou SCTP.
🔎 Analyse complète
👇
https://heyitsas.im/posts/lpe-quartet/
:debian:
👇
DirtyAH6 corrigé sur Bookworm-security, encore vulnérable sur Trixie.
TUNderflow corrigée uniquement dans sid
PPPoEject et DiagSpill corrigés sur Bookworm-security et Trixie.
⬇️
DirtyAH6 — CVE-2026-80844
Debian Security Tracker
TUNderflow — CVE-2026-81000
Debian Security Tracker
PPPoEject — CVE-2026-68121
Debian Security Tracker
DiagSpill — CVE-2026-74469
Debian Security Tracker
PoCs 👀
👇
DirtyAH6 — CVE-2026-80844 : https://github.com/manizada/DirtyAH6
TUNderflow — CVE-2026-81000 : https://github.com/manizada/TUNderflow
PPPoEject — CVE-2026-68121 : https://github.com/manizada/PPPoEject
DiagSpill — CVE-2026-74469 : https://github.com/manizada/DiagSpill
It's Friday, and we have 4 more local privilege escalation vulnerabilities disclosed for the Linux kernel:
- DirtyAH6 (CVE-2026-80844)
- TUNderflow (CVE-2026-81000)
- PPPoEject (CVE-2026-68121)
- DiagSpill (CVE-2026-74469)
"The underlying bugs have been around for 10-21 years. The first three LPEs require either unprivileged user namespaces or specific CAPs; DiagSpill does not."
https://www.openwall.com/lists/oss-security/2026/09/18/3
https://heyitsas.im/posts/lpe-quartet/
#CVE_2026_80844 #CVE_2026_81000 #CVE_2026_68121 #CVE_2026_74469
##updated 2026-08-19T17:20:29.553000
7 posts
Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk. #LinuxSecurity #PrivilegeEscalation #KernelSecurity
https://cyberworldops.eu/en/four-public-linux-kernel-exploits-put-unpatched-hosts-at-risk-of-local
##A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, DiagSpill
Linux 커널에서 일반 로컬 사용자를 root로 승격할 수 있는 4개 취약점 DirtyAH6(CVE-2026-80844), TUNderflow(CVE-2026-81000), PPPoEject(CVE-2026-68121), DiagSpill(CVE-2026-74469)가 공개됐다. 취약점들은 네트워크 서브시스템의 오래된 메모리 손상 문제이며, DiagSpill은 별도 capability나 비특권 사용자 네임스페이스 없이도 조건 충족 시 LPE가 가능하고 컨테이너 호스트 탈출 가능성도 있다. 수정은 Linux stable 5.10.270,...
##Ouep, vendredi vuln assisté is back : le kernel Linux, toujours la cible préférée du branding CVE 🐧
DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121) et DiagSpill (CVE-2026-74469) permettent, dans les configurations adaptées, à un utilisateur local non privilégié d'obtenir root.
Bugs présents dans le kernel depuis 10 à 21 ans.
Risque pas uniforme : les trois premières nécessitent des user namespaces non privilégiés + des fonctionnalités réseau particulières (AH6/XFRM, TUN/TAP, PPPoE).
DiagSpill est directement accessible sans capability, MAIS nécessite SCTP + sctp_diag.
Pas de RCE distante générique, mais nuance à connaître pour les passerelles : DirtyAH6 peut causer un DoS distant sur un routeur IPv6 faisant de l'AH en mode transport (root distant obtenu en labo par l'auteur, via grooming côté cible--> jugé "extrêmement difficile").
DiagSpill a aussi un vecteur DoS distant si ASCONF/ADD-IP + SCTP-AUTH (ou addip_noauth_enable=1) sont actifs-->désactivés par défaut.
➡️ À surveiller en priorité : systèmes multi-utilisateurs, conteneurs, hôtes TUN/TAP, PPPoE, XFRM/AH6 ou SCTP.
🔎 Analyse complète
👇
https://heyitsas.im/posts/lpe-quartet/
:debian:
👇
DirtyAH6 corrigé sur Bookworm-security, encore vulnérable sur Trixie.
TUNderflow corrigée uniquement dans sid
PPPoEject et DiagSpill corrigés sur Bookworm-security et Trixie.
⬇️
DirtyAH6 — CVE-2026-80844
Debian Security Tracker
TUNderflow — CVE-2026-81000
Debian Security Tracker
PPPoEject — CVE-2026-68121
Debian Security Tracker
DiagSpill — CVE-2026-74469
Debian Security Tracker
PoCs 👀
👇
DirtyAH6 — CVE-2026-80844 : https://github.com/manizada/DirtyAH6
TUNderflow — CVE-2026-81000 : https://github.com/manizada/TUNderflow
PPPoEject — CVE-2026-68121 : https://github.com/manizada/PPPoEject
DiagSpill — CVE-2026-74469 : https://github.com/manizada/DiagSpill
It's Friday, and we have 4 more local privilege escalation vulnerabilities disclosed for the Linux kernel:
- DirtyAH6 (CVE-2026-80844)
- TUNderflow (CVE-2026-81000)
- PPPoEject (CVE-2026-68121)
- DiagSpill (CVE-2026-74469)
"The underlying bugs have been around for 10-21 years. The first three LPEs require either unprivileged user namespaces or specific CAPs; DiagSpill does not."
https://www.openwall.com/lists/oss-security/2026/09/18/3
https://heyitsas.im/posts/lpe-quartet/
#CVE_2026_80844 #CVE_2026_81000 #CVE_2026_68121 #CVE_2026_74469
##Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk. #LinuxSecurity #PrivilegeEscalation #KernelSecurity
https://cyberworldops.eu/en/four-public-linux-kernel-exploits-put-unpatched-hosts-at-risk-of-local
##Ouep, vendredi vuln assisté is back : le kernel Linux, toujours la cible préférée du branding CVE 🐧
DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121) et DiagSpill (CVE-2026-74469) permettent, dans les configurations adaptées, à un utilisateur local non privilégié d'obtenir root.
Bugs présents dans le kernel depuis 10 à 21 ans.
Risque pas uniforme : les trois premières nécessitent des user namespaces non privilégiés + des fonctionnalités réseau particulières (AH6/XFRM, TUN/TAP, PPPoE).
DiagSpill est directement accessible sans capability, MAIS nécessite SCTP + sctp_diag.
Pas de RCE distante générique, mais nuance à connaître pour les passerelles : DirtyAH6 peut causer un DoS distant sur un routeur IPv6 faisant de l'AH en mode transport (root distant obtenu en labo par l'auteur, via grooming côté cible--> jugé "extrêmement difficile").
DiagSpill a aussi un vecteur DoS distant si ASCONF/ADD-IP + SCTP-AUTH (ou addip_noauth_enable=1) sont actifs-->désactivés par défaut.
➡️ À surveiller en priorité : systèmes multi-utilisateurs, conteneurs, hôtes TUN/TAP, PPPoE, XFRM/AH6 ou SCTP.
🔎 Analyse complète
👇
https://heyitsas.im/posts/lpe-quartet/
:debian:
👇
DirtyAH6 corrigé sur Bookworm-security, encore vulnérable sur Trixie.
TUNderflow corrigée uniquement dans sid
PPPoEject et DiagSpill corrigés sur Bookworm-security et Trixie.
⬇️
DirtyAH6 — CVE-2026-80844
Debian Security Tracker
TUNderflow — CVE-2026-81000
Debian Security Tracker
PPPoEject — CVE-2026-68121
Debian Security Tracker
DiagSpill — CVE-2026-74469
Debian Security Tracker
PoCs 👀
👇
DirtyAH6 — CVE-2026-80844 : https://github.com/manizada/DirtyAH6
TUNderflow — CVE-2026-81000 : https://github.com/manizada/TUNderflow
PPPoEject — CVE-2026-68121 : https://github.com/manizada/PPPoEject
DiagSpill — CVE-2026-74469 : https://github.com/manizada/DiagSpill
It's Friday, and we have 4 more local privilege escalation vulnerabilities disclosed for the Linux kernel:
- DirtyAH6 (CVE-2026-80844)
- TUNderflow (CVE-2026-81000)
- PPPoEject (CVE-2026-68121)
- DiagSpill (CVE-2026-74469)
"The underlying bugs have been around for 10-21 years. The first three LPEs require either unprivileged user namespaces or specific CAPs; DiagSpill does not."
https://www.openwall.com/lists/oss-security/2026/09/18/3
https://heyitsas.im/posts/lpe-quartet/
#CVE_2026_80844 #CVE_2026_81000 #CVE_2026_68121 #CVE_2026_74469
##updated 2026-08-18T18:32:52
3 posts
2 repos
Oracle's quarterly release fixed 800+ flaws, none flagged as exploited. Meanwhile CVE-2026-59310, an unauthenticated directory traversal in the VMware vCenter Syslog server patched in July, is now in ransomware hands after...
##Discover how ransomware gangs actively exploit the critical VMware vCenter flaw, CVE-2026-59310. Learn about the swift weaponization and severe infrastructure risks.
##Discover how ransomware gangs actively exploit the critical VMware vCenter flaw, CVE-2026-59310. Learn about the swift weaponization and severe infrastructure risks.
##updated 2026-08-13T21:37:11
1 posts
aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3
perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38
sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0
セキュリティ対応なのでお早めに。
##updated 2026-08-06T09:30:40
1 posts
1 repos
WSO2 Warns of Active Exploitation Targeting Critical Authentication Bypass
WSO2 is warning of active exploitation of a critical authentication bypass vulnerability (CVE-2026-5430) that allows attackers to take over administrative accounts and steal sensitive API credentials. The flaw affects multiple middleware products and has been targeted in the wild since mid-September 2026.
**If you run WSO2 API Manager, API Control Plane, Traffic Manager, or Universal Gateway, check for affected versions and patch immediately to the latest update level from WSO2. If you are using open source version apply the public GitHub fix. Attackers are already using forged tokens to gain full admin access.
After patching, assume your secrets were exposed and rotate all API keys, backend credentials, consumer keys, and application secrets, and check your logs for suspicious access since September 13, 2026.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/wso2-warns-of-active-exploitation-targeting-critical-authentication-bypass-6-5-6-k-k/gD2P6Ple2L
updated 2026-08-05T18:31:49
2 posts
5 repos
https://github.com/S3v3n-JG/CVE-2026-76461
https://github.com/fevar54/CVE-2026-76461-Detection-Kit-
https://github.com/S3v3n-JG/CVE-2026-76460
⚪️ Cisco Secure Email Gateway Appliances Can Be Hacked with a Malicious Email
🗨️ Cisco researchers have fixed a critical vulnerability in Secure Email Gateway, a gateway designed to protect email from malicious messages. Ironically, to compromise the gateway itself, an attacker only had to send a specially crafted email through it. The vulnerability…
##⚪️ Cisco Secure Email Gateway Appliances Can Be Hacked with a Malicious Email
🗨️ Cisco researchers have fixed a critical vulnerability in Secure Email Gateway, a gateway designed to protect email from malicious messages. Ironically, to compromise the gateway itself, an attacker only had to send a specially crafted email through it. The vulnerability…
##updated 2026-08-04T18:31:31
1 posts
[Django Fellow Reports] Django Fellow Report - Jacob
Jacob reviewed six Django pull requests and authored changes covering GEOS 3.10 support removal and expanded WKT depth-check coverage related to CVE-2026-15830.
https://forum.djangoproject.com/t/django-fellow-report-jacob-2026/43851/39
updated 2026-08-04T06:32:37
2 posts
Mitsubishi Electric CC-Link IE TSN is affected by CVE-2026-13584, CWE-924 message integrity failure. An adjacent attacker can inject crafted packets under timing conditions to tamper with OT traffic. It matters for ICS integrity and safety assumptions on trusted segments. #IcsSecurity #OtSecurity #MessageIntegrity
https://cyberworldops.eu/en/mitsubishi-protocol-flaw-exposes-industrial-control-traffic-to-on
##Mitsubishi Electric CC-Link IE TSN is affected by CVE-2026-13584, CWE-924 message integrity failure. An adjacent attacker can inject crafted packets under timing conditions to tamper with OT traffic. It matters for ICS integrity and safety assumptions on trusted segments. #IcsSecurity #OtSecurity #MessageIntegrity
https://cyberworldops.eu/en/mitsubishi-protocol-flaw-exposes-industrial-control-traffic-to-on
##updated 2026-07-01T21:35:53
1 posts
2 repos
CVE-2026-45659: SharePoint Authenticated Deserialization RCE
#CVE_2026_45659
https://blog.securelayer7.net/cve-2026-45659-sharepoint-deserialization-rce/
updated 2026-06-30T21:31:51
2 posts
6 repos
https://github.com/BiiTts/CVE-2026-58138-Conductor-Unauth-RCE
https://github.com/seqra/cve-2026-58138
https://github.com/0xgh057r3c0n/CVE-2026-58138
https://github.com/Procjevt/CVE-2026-58138
Orkes Conductor 3.21.21 through before 3.30.2 is affected by CVE-2026-58138, an unauthenticated RCE via malicious workflow definitions using inline JS/Python. Exposed APIs allow arbitrary OS command execution with host-level impact. Patch to 3.30.2 and restrict exposure. #OrkesConductor #RemoteCodeExecution #ThreatIntel
https://cyberworldops.eu/en/exposed-orkes-conductor-apis-turn-workflow-scripts-into-root-level
##Orkes Conductor 3.21.21 through before 3.30.2 is affected by CVE-2026-58138, an unauthenticated RCE via malicious workflow definitions using inline JS/Python. Exposed APIs allow arbitrary OS command execution with host-level impact. Patch to 3.30.2 and restrict exposure. #OrkesConductor #RemoteCodeExecution #ThreatIntel
https://cyberworldops.eu/en/exposed-orkes-conductor-apis-turn-workflow-scripts-into-root-level
##updated 2026-06-22T17:47:16.070000
1 posts
🔄 CSAF advisory updated (version 3.0.0)
VDE-2026-051
iba: Deserialization vulnerability in ibaPDA and ibaDatCoordinator
CVE-2026-8024
Changes: Corrected all CPE numbers and vendor name of all products.
HTML: https://certvde.com/en/advisories/VDE-2026-051
CSAF JSON: https://iba.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-051.json
updated 2026-03-23T15:31:40
3 posts
8 repos
https://github.com/chosenonehacks/CVE-2026-32746
https://github.com/ekomsSavior/telnet_scan
https://github.com/danindiana/cve-2026-32746-mitigation
https://github.com/MonkeySeC-sys/Kangaroo
https://github.com/duduLiu8787/CVE-2026-32746-Exploit
https://github.com/kaleth4/CVE-2026-32746
https://github.com/watchtowrlabs/watchtowr-vs-telnetd-CVE-2026-32746
A 32-year-old bug walks into a Telnet server
Link: https://labs.watchtowr.com/a-32-year-old-bug-walks-into-a-telnet-server-gnu-inetutils-telnetd-cve-2026-32746/
Discussion: https://news.ycombinator.com/item?id=49721291
😂 Oh, look, a bug older than some of you on this site! GNU #inetutils just realized their #Telnet server had a 32-year-old #exploit hiding like a dusty family heirloom. Who knew pre-auth RCE could double as a boomer joke? 🧐🔍
https://labs.watchtowr.com/a-32-year-old-bug-walks-into-a-telnet-server-gnu-inetutils-telnetd-cve-2026-32746/ #bugreport #cybersecurity #humor #technews #HackerNews #ngated
A 32-year-old bug walks into a Telnet server
Comments: https://news.ycombinator.com/item?id=49721291
#HackerNews #bugfix #cybersecurity #Telnet #server #technology #vulnerabilities #GNU #inetutils
##updated 2024-10-23T18:33:16
1 posts
Nice of Cisco to finally publish CVE-2024-20260 now that we're almost in 3Q2026.
##🟠 CVE-2026-57228 - High (8.2)
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.13 until 7.0.17, the SMTP MIME quoted-printable decoder in src/util-decode-mime.c can read one byte past a heap buffer w...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57228/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-57228 - High (8.2)
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.13 until 7.0.17, the SMTP MIME quoted-printable decoder in src/util-decode-mime.c can read one byte past a heap buffer w...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57228/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-63447 - High (7.5)
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.5 until 8.0.6, the FTP parser in src/app-layer-ftp.c can continue allocating transactions after app-layer.protocols.ftp....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63447/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-63447 - High (7.5)
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.5 until 8.0.6, the FTP parser in src/app-layer-ftp.c can continue allocating transactions after app-layer.protocols.ftp....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63447/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-63446 - High (7.5)
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, AppLayerParserSetTransactionInspectId() in src/app-layer-parser.c uses an inverted guard and marks only a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63446/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-63446 - High (7.5)
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, AppLayerParserSetTransactionInspectId() in src/app-layer-parser.c uses an inverted guard and marks only a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63446/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-63452 - High (7.5)
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the HTTP/1 parser limits decompression work per transaction but does not limit how many small brotli comp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63452/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-63452 - High (7.5)
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the HTTP/1 parser limits decompression work per transaction but does not limit how many small brotli comp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63452/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-68928 - High (8.6)
Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a binding permission, and src/plugins...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68928/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-68928 - High (8.6)
Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a binding permission, and src/plugins...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68928/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-71418 - High (7.5)
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, DNS-over-HTTP/2 processing in rust/src/http2/http2.rs retains previously processed HTTP/2 DATA frame cont...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71418/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-71418 - High (7.5)
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, DNS-over-HTTP/2 processing in rust/src/http2/http2.rs retains previously processed HTTP/2 DATA frame cont...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71418/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-92708 - High (7.5)
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. In versions 5.1.0 through 5.9.2, stringify and uneval functions serialize a typed array by emitting its entire backing Arr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92708/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-92708 - High (7.5)
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. In versions 5.1.0 through 5.9.2, stringify and uneval functions serialize a typed array by emitting its entire backing Arr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92708/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##A critical Dokploy OS command injection flaw (CVE-2026-72878) exposes servers to root takeover via backups. Patch this Dokploy OS command injection now.
#Dokploy #CommandInjection #CVE202672878 #Cybersecurity #PaaS
##A critical Dokploy OS command injection flaw (CVE-2026-72878) exposes servers to root takeover via backups. Patch this Dokploy OS command injection now.
#Dokploy #CommandInjection #CVE202672878 #Cybersecurity #PaaS
##🔴 CVE-2026-54670 - Critical (9.1)
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and metodo values without a complete controller and meth...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54670/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-54670 - Critical (9.1)
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and metodo values without a complete controller and meth...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54670/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-54734 - Critical (10)
Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the resulting domain or path segment. A malicious ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54734/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-54734 - Critical (10)
Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the resulting domain or path segment. A malicious ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54734/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93426 - High (8.5)
SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or higher can embed backticks and quotes in field names ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93426/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93426 - High (8.5)
SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or higher can embed backticks and quotes in field names ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93426/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-54752 - Critical (9.6)
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the read_pickle_d...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54752/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-54752 - Critical (9.6)
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the read_pickle_d...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54752/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-54716 - High (7.5)
Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earlier, a POST request to /sources_to_targets containing an exclude_polygons ring formed by three collinear points can cause unboun...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54716/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-54716 - High (7.5)
Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earlier, a POST request to /sources_to_targets containing an exclude_polygons ring formed by three collinear points can cause unboun...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54716/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-54627 - Critical (9.8)
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_private_sail_pixel_format() in src/sail-codecs/psd/helpers.c resolves a one-channel PSD in Bitmap col...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54627/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-54627 - Critical (9.8)
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_private_sail_pixel_format() in src/sail-codecs/psd/helpers.c resolves a one-channel PSD in Bitmap col...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54627/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93337 - High (7.8)
NetworkManager-l2tp contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd directives by supplying mru or mtu property values containing trailing non-numeric co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93337/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93337 - High (7.8)
NetworkManager-l2tp contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd directives by supplying mru or mtu property values containing trailing non-numeric co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93337/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-85500: team-alembic ash_authentication (4.3.8 – 4.15.0, 5.0.0-rc.14) suffers a CRITICAL auth bypass — unconfirmed users may gain sessions, defeating email confirmation. Patch urgently. https://radar.offseq.com/threat/cve-2026-85500-cwe-305-authentication-bypass-by-primary-weakness-in-team-alembic-ashauthentication-cb315bb57ae7fd92 #OffSeq #Vuln #CVE202685500 #AshAuthentication
##CVE-2026-85500: team-alembic ash_authentication (4.3.8 – 4.15.0, 5.0.0-rc.14) suffers a CRITICAL auth bypass — unconfirmed users may gain sessions, defeating email confirmation. Patch urgently. https://radar.offseq.com/threat/cve-2026-85500-cwe-305-authentication-bypass-by-primary-weakness-in-team-alembic-ashauthentication-cb315bb57ae7fd92 #OffSeq #Vuln #CVE202685500 #AshAuthentication
##VMware łata poważne błędy w Workstation i Fusion. Można wyskoczyć z maszyny wirtualnej i wykonać kod na hoście
Broadcom poinformował o załataniu dwóch poważnych błędów w popularnych produktach VMware Workstation oraz VMware Fusion. W określonych warunkach ich wykorzystanie mogło doprowadzić do ucieczki z maszyny wirtualnej oraz wykonanie kodu bezpośrednio na hoście. TLDR: Podatności otrzymały identyfikatory CVE-2026-59346 (CVSS 9.3) oraz CVE-2026-59347 (CVSS 8.1). Pierwsza z nich to błąd typu...
##VMware łata poważne błędy w Workstation i Fusion. Można wyskoczyć z maszyny wirtualnej i wykonać kod na hoście
Broadcom poinformował o załataniu dwóch poważnych błędów w popularnych produktach VMware Workstation oraz VMware Fusion. W określonych warunkach ich wykorzystanie mogło doprowadzić do ucieczki z maszyny wirtualnej oraz wykonanie kodu bezpośrednio na hoście. TLDR: Podatności otrzymały identyfikatory CVE-2026-59346 (CVSS 9.3) oraz CVE-2026-59347 (CVSS 8.1). Pierwsza z nich to błąd typu...
##VMware łata poważne błędy w Workstation i Fusion. Można wyskoczyć z maszyny wirtualnej i wykonać kod na hoście
Broadcom poinformował o załataniu dwóch poważnych błędów w popularnych produktach VMware Workstation oraz VMware Fusion. W określonych warunkach ich wykorzystanie mogło doprowadzić do ucieczki z maszyny wirtualnej oraz wykonanie kodu bezpośrednio na hoście. TLDR: Podatności otrzymały identyfikatory CVE-2026-59346 (CVSS 9.3) oraz CVE-2026-59347 (CVSS 8.1). Pierwsza z nich to błąd typu...
##VMware łata poważne błędy w Workstation i Fusion. Można wyskoczyć z maszyny wirtualnej i wykonać kod na hoście
Broadcom poinformował o załataniu dwóch poważnych błędów w popularnych produktach VMware Workstation oraz VMware Fusion. W określonych warunkach ich wykorzystanie mogło doprowadzić do ucieczki z maszyny wirtualnej oraz wykonanie kodu bezpośrednio na hoście. TLDR: Podatności otrzymały identyfikatory CVE-2026-59346 (CVSS 9.3) oraz CVE-2026-59347 (CVSS 8.1). Pierwsza z nich to błąd typu...
##