## Updated at UTC 2026-08-06T14:54:06.803226

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-71315 8.2 0.00% 1 0 2026-08-06T14:16:43.987000 Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3
CVE-2026-18649 7.5 0.00% 1 0 2026-08-06T14:16:32.430000 A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and
CVE-2026-66733 7.5 0.00% 2 0 2026-08-06T13:18:21.947000 Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vul
CVE-2026-5430 10.0 0.00% 2 0 2026-08-06T13:18:21.283000 The JWT authentication mechanism accepts tokens signed with algorithms other tha
CVE-2026-1728 9.8 0.00% 2 0 2026-08-06T13:17:28.180000 Tokens issued to a low-privileged user are not sufficiently restricted, allowing
CVE-2026-15459 8.1 0.00% 2 0 2026-08-06T06:31:41 The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypa
CVE-2026-8478 8.8 0.00% 1 0 2026-08-06T05:17:11.987000 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject ar
CVE-2026-70482 8.1 0.34% 1 0 2026-08-06T05:17:07.240000 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI plat
CVE-2026-70431 8.8 0.00% 2 0 2026-08-06T05:17:06.537000 Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scriptin
CVE-2026-70426 9.0 0.00% 5 0 2026-08-06T05:17:05.850000 In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, incl
CVE-2026-63077 9.8 0.65% 9 1 2026-08-06T05:17:05.170000 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe
CVE-2026-44945 9.1 0.74% 1 0 2026-08-06T05:17:03.793000 A privilege escalation vulnerability exists in Rancher's impersonation middlewar
CVE-2026-20312 8.8 0.00% 1 0 2026-08-06T05:17:02.450000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20304 9.9 0.00% 1 0 2026-08-06T05:16:59.827000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20267 9.0 0.00% 1 0 2026-08-06T05:16:43.583000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-17633 8.5 0.00% 2 0 2026-08-06T05:16:40.457000 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacke
CVE-2026-18973 7.3 0.00% 1 0 2026-08-06T01:16:29.410000 A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The
CVE-2026-67869 7.5 0.00% 2 0 2026-08-06T00:31:38 Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to ca
CVE-2026-67863 7.5 0.00% 2 0 2026-08-06T00:31:29 In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredIt
CVE-2026-67531 0 0.00% 2 0 2026-08-06T00:16:53.733000 FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). P
CVE-2026-18970 7.3 0.00% 1 0 2026-08-06T00:16:53.060000 A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Plat
CVE-2026-71321 7.5 0.00% 2 0 2026-08-05T21:43:07 ### Impact The internal island renderer endpoint (`/__nuxt_island/...`) decodes
CVE-2026-70432 8.8 0.00% 2 0 2026-08-05T21:32:44 A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669
CVE-2026-60007 7.4 0.45% 1 0 2026-08-05T21:32:37 In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns
CVE-2026-70615 9.9 0.00% 1 0 2026-08-05T21:31:48 boringproxy through 0.10.0 contains a newline injection vulnerability that allow
CVE-2026-34966 7.6 0.00% 1 0 2026-08-05T21:31:47 Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that
CVE-2026-17624 8.5 0.00% 2 0 2026-08-05T21:31:46 IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.
CVE-2026-17632 8.8 0.00% 2 0 2026-08-05T21:31:46 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacke
CVE-2026-18485 7.8 0.00% 2 0 2026-08-05T21:31:46 There is a local privilege escalation vulnerability recently discovered in the N
CVE-2026-18411 8.1 0.00% 2 0 2026-08-05T21:31:46 The KARR Security System and SWDS dealer-installed automotive anti-theft systems
CVE-2026-17583 8.4 0.00% 2 1 2026-08-05T21:31:46 The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable
CVE-2026-69111 7.5 0.00% 1 0 2026-08-05T21:31:46 Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vu
CVE-2026-8183 7.7 0.00% 1 0 2026-08-05T21:31:39 IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.
CVE-2026-8182 8.8 0.00% 1 0 2026-08-05T21:31:39 IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet
CVE-2026-9201 8.8 0.00% 1 0 2026-08-05T21:31:39 IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to e
CVE-2026-9196 8.1 0.00% 1 0 2026-08-05T21:31:39 IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to e
CVE-2026-71320 8.1 0.00% 2 0 2026-08-05T21:29:56 ## Impact Nuxt server islands accept props via the `/__nuxt_island/` endpoint.
CVE-2026-71319 9.6 0.00% 4 0 2026-08-05T21:27:39 ### Impact Nuxt DevTools (development mode only) exposes a bidirectional RPC ch
CVE-2026-71316 7.5 0.00% 2 0 2026-08-05T21:14:34 ### Impact When a page is covered by `routeRules` `cache` / `swr` / `isr`, Nuxt
CVE-2026-71314 7.5 0.00% 1 0 2026-08-05T20:59:08 ### Impact An unauthenticated attacker can crash a Nuxt server that renders any
CVE-2026-71312 8.0 0.00% 1 0 2026-08-05T20:38:00 ## 1. Summary rclone interpolates remote SFTP paths into PowerShell hash comman
CVE-2026-70617 8.1 0.00% 1 0 2026-08-05T20:17:17.770000 Spacebar Server before commit dcfd910 contains a missing authorization vulnerabi
CVE-2026-15573 8.1 0.00% 1 0 2026-08-05T20:17:05.243000 A flaw was found in Keycloak's Authorization Services. The component responsible
CVE-2026-17566 9.9 0.43% 1 1 2026-08-05T20:00:10.473000 pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by in
CVE-2026-9077 8.5 0.00% 1 0 2026-08-05T19:17:45.807000 IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attac
CVE-2026-20310 9.1 0.00% 2 0 2026-08-05T18:31:49 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20313 7.7 0.00% 2 0 2026-08-05T18:31:49 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20303 9.9 0.00% 1 0 2026-08-05T18:31:48 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20272 9.8 0.00% 1 0 2026-08-05T18:31:45 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-45537 9.1 0.36% 1 0 2026-08-05T18:17:11.353000 OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versio
CVE-2026-20301 8.6 0.00% 2 0 2026-08-05T18:17:07.557000 A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referre
CVE-2026-18898 8.8 0.47% 1 0 2026-08-05T17:16:45.797000 A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. Thi
CVE-2026-71289 9.8 0.00% 1 0 2026-08-05T16:17:08.400000 The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implement
CVE-2026-71287 8.8 0.00% 1 0 2026-08-05T16:17:08.190000 Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER
CVE-2026-71285 8.1 0.00% 1 0 2026-08-05T16:17:07.967000 Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js
CVE-2026-67861 7.5 0.42% 1 0 2026-08-05T16:17:00.200000 An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a den
CVE-2026-67859 7.5 0.47% 1 0 2026-08-05T16:17:00.067000 Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to ca
CVE-2026-59913 7.8 0.11% 1 0 2026-08-05T15:44:27.057000 Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, co
CVE-2026-34486 9.8 81.16% 5 6 2026-08-05T15:33:26.557000 Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the f
CVE-2026-71294 7.6 0.00% 1 0 2026-08-05T15:32:29 Cotonti CMS's Comments plugin deserializes user-supplied data without restrictin
CVE-2026-67857 7.5 0.35% 1 0 2026-08-05T15:32:14 open62541 1.5.5 contains an out-of-bounds read in the client-side function respo
CVE-2026-9273 9.3 0.28% 1 0 2026-08-05T15:17:19.770000 The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restr
CVE-2026-70554 9.8 0.85% 1 0 2026-08-05T15:17:13.783000 MaxSite CMS contains a PHP object injection vulnerability that allows unauthenti
CVE-2026-70486 8.2 0.37% 1 0 2026-08-05T15:17:10.497000 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI plat
CVE-2026-67858 7.5 0.49% 1 0 2026-08-05T15:17:06.617000 Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery
CVE-2026-18895 8.8 0.57% 1 0 2026-08-05T15:16:45.587000 A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacte
CVE-2026-68981 7.5 0.32% 1 0 2026-08-05T14:59:30.577000 Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the appl
CVE-2026-68979 9.8 0.35% 1 0 2026-08-05T14:59:03.460000 Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API me
CVE-2026-48449 10.0 0.54% 1 0 2026-08-05T14:54:01.933000 Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi
CVE-2026-71214 9.8 0.34% 1 0 2026-08-05T14:17:14.103000 The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-serve
CVE-2026-71254 9.8 0.00% 1 0 2026-08-05T13:24:49.680000 nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-
CVE-2026-66747 9.8 0.00% 1 0 2026-08-05T12:31:36 Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS,
CVE-2026-4431 9.1 0.33% 1 0 2026-08-05T09:31:26 The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modi
CVE-2026-9198 9.8 17.05% 4 4 2026-08-05T05:17:15.823000 IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain
CVE-2026-6837 7.2 0.95% 1 0 2026-08-05T05:17:14.873000 A post-authentication command injection vulnerability in the "export-cgi" CGI pr
CVE-2026-66318 8.1 0.37% 1 0 2026-08-05T05:17:07.877000 Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorize
CVE-2026-58073 0 0.22% 3 0 2026-08-05T05:17:02.413000 A vulnerability in Veeam Service Provider Console allowing an unauthenticated at
CVE-2026-58072 0 0.38% 2 0 2026-08-05T05:17:01.967000 A vulnerability in Veeam Service Provider Console allowing arbitrary file write
CVE-2026-15307 8.8 0.54% 1 0 2026-08-05T05:16:46.480000 An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDja
CVE-2026-18897 8.8 0.57% 1 0 2026-08-05T03:30:28 A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. T
CVE-2026-70619 8.8 0.36% 1 0 2026-08-05T00:30:46 Odysseus before commit bf325f6 contains a missing authorization vulnerability th
CVE-2026-70553 9.8 0.88% 2 1 2026-08-04T21:30:37 MaxSite CMS contains a remote code execution vulnerability that allows unauthent
CVE-2026-69703 9.8 0.46% 1 0 2026-08-04T21:30:29 Atlas-Livre contains an improper access control vulnerability in the admin contr
CVE-2026-49435 9.8 0.77% 1 0 2026-08-04T21:30:28 Keysight IxChariot Endpoint and associated products contain a stack-based buffer
CVE-2026-18556 7.4 0.49% 4 1 2026-08-04T21:30:26 Authentication bypass using an alternate path or channel vulnerability in N-able
CVE-2026-15969 9.8 0.98% 1 0 2026-08-04T20:43:06.967000 SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via by
CVE-2026-70478 None 0.38% 1 0 2026-08-04T19:37:38 ### Summary The OAuth2 token refresh endpoint (`POST /api/v1/oauth2-credential/
CVE-2026-70477 None 0.44% 1 0 2026-08-04T19:29:28 -- ABSTRACT ------------------------------------- Trend Micro's Zero Day Initia
CVE-2026-18830 8.1 0.29% 1 0 2026-08-04T19:16:45.433000 Insufficient input validation in Amazon Bedrock AgentCore harness might allow an
CVE-2026-24254 9.8 0.45% 1 0 2026-08-04T18:31:37 NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topol
CVE-2026-64633 None 0.34% 1 1 2026-08-04T18:31:36 A vulnerability allowing remote unauthenticated code execution on the agent host
CVE-2026-15920 6.1 0.30% 1 0 2026-08-04T18:31:31 An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `djang
CVE-2026-24083 7.8 0.11% 1 0 2026-08-04T18:31:31 Memory Corruption while processing IOCTL device driver requests with invalid arg
CVE-2026-25292 7.6 0.16% 1 0 2026-08-04T18:31:31 Memory Corruption when processing untrusted user input in the fastboot command h
CVE-2026-69100 8.8 0.55% 1 0 2026-08-04T18:31:31 LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains
CVE-2026-69098 9.8 0.51% 1 1 2026-08-04T18:31:31 kotaemon through 0.12.0 contains an insecure deserialization vulnerability in th
CVE-2026-15958 9.3 0.20% 1 0 2026-08-04T18:16:45.220000 The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform
CVE-2026-69110 9.1 0.55% 1 0 2026-08-04T17:16:59.733000 OpenCode Studio before 2.4.4 contains a missing authentication vulnerability tha
CVE-2026-48323 10.0 0.62% 2 0 2026-08-04T17:16:55.413000 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia
CVE-2026-24084 7.5 0.23% 1 0 2026-08-04T17:16:52.453000 Weak configuration when UE does not verify the consistency of its additional sec
CVE-2026-48326 9.9 0.48% 1 0 2026-08-04T16:16:25.497000 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia
CVE-2026-18686 9.8 2.61% 1 0 2026-08-04T16:16:21.593000 A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected elem
CVE-2026-18577 8.1 4.10% 11 2 2026-08-04T15:33:20 An incomplete patch for CVE-2026-18556 allows for authentication bypass and acco
CVE-2026-69240 9.8 0.32% 1 0 2026-08-04T15:16:42.087000 Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with
CVE-2026-59639 0 0.17% 1 0 2026-08-04T14:50:12.360000 In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for Sig
CVE-2026-12816 0 0.16% 1 0 2026-08-04T14:50:12.360000 In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via len
CVE-2026-15721 9.8 0.23% 1 0 2026-08-04T14:16:30.620000 Cleartext storage of sensitive information vulnerability in Bilin Software and I
CVE-2026-14175 9.8 0.40% 2 0 2026-08-04T12:34:56 Unrestricted upload of file with dangerous type vulnerability in Bilin Software
CVE-2026-14804 9.1 0.30% 2 0 2026-08-04T12:34:56 Use of hard-coded cryptographic key vulnerability in Bilin Software and Informat
CVE-2026-18754 9.1 0.31% 1 0 2026-08-04T09:31:41 The product firmware contains an embedded, static RSA private key utilized by th
CVE-2026-9044 0 0.97% 1 0 2026-08-04T05:16:40.213000 An OS command injection vulnerability exists in the VPN module of TP-Link AXE75
CVE-2026-62354 None 0.26% 1 0 2026-08-04T00:35:57 Authorization handling for Parameter Context validation requests in Apache NiFi
CVE-2026-48333 9.8 0.47% 1 0 2026-08-04T00:35:01 Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi
CVE-2026-18684 9.8 2.03% 1 0 2026-08-04T00:35:01 A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affe
CVE-2026-48331 10.0 0.47% 1 0 2026-08-04T00:35:01 Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF)
CVE-2026-66310 7.7 0.40% 1 0 2026-08-04T00:35:01 External control of file name or path in Microsoft Edge for Android allows an un
CVE-2026-18685 9.8 1.99% 1 0 2026-08-04T00:35:01 A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Imp
CVE-2026-48330 10.0 0.68% 1 0 2026-08-04T00:35:01 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia
CVE-2026-66315 7.5 0.62% 1 0 2026-08-04T00:34:55 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacke
CVE-2026-59912 7.8 0.10% 1 0 2026-08-03T21:31:36 Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, co
CVE-2026-18108 9.8 0.22% 1 0 2026-08-03T20:17:14.513000 Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _ve
CVE-2026-18614 9.8 2.01% 1 0 2026-08-03T19:16:45.200000 A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the func
CVE-2026-18574 None 0.99% 1 0 2026-08-03T15:32:49 An authentication bypass vulnerability in Check Point Security Management Server
CVE-2026-33591 None 0.52% 1 0 2026-08-03T12:32:43 A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unaut
CVE-2026-5674 8.8 0.13% 1 0 2026-08-03T09:33:40 A flaw was found in PipeWire, a multimedia server. This vulnerability allows an
CVE-2026-8763 None 0.33% 1 1 2026-08-03T09:32:36 In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot
CVE-2026-12803 None 0.17% 1 0 2026-08-03T09:32:36 In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce w
CVE-2026-58062 None 0.20% 1 1 2026-08-03T09:32:36 In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without bi
CVE-2026-58061 None 0.21% 1 0 2026-08-03T09:32:36 In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to calle
CVE-2026-12569 9.8 30.20% 4 1 2026-08-01T05:16:55.023000 A critical remote code execution (RCE) vulnerability has been reported in PTC Wi
CVE-2026-58048 None 0.50% 1 2 2026-07-31T18:32:25 Improper preservation of SQL mode when renaming databases in cPanel allows exec
CVE-2026-12943 9.8 0.92% 1 0 2026-07-30T21:31:50 IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1
CVE-2026-51291 9.8 0.00% 1 0 2026-07-30T21:31:47 sqlite 3.41 is vulnerable to use after free in the json.c jsonCacheInsert functi
CVE-2026-67192 8.1 0.62% 1 0 2026-07-30T20:04:51.110000 Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overfl
CVE-2026-41709 2.7 0.38% 1 0 2026-07-30T19:07:59.843000 VMware ESX contains an insufficient logging vulnerability. A malicious administr
CVE-2026-66066 None 1.70% 3 7 2026-07-30T18:23:34 ### Impact In its default configuration, a Rails application that displays image
CVE-2026-47876 9.3 0.28% 1 0 2026-07-30T15:31:54 VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual
CVE-2026-59309 9.8 0.74% 1 0 2026-07-30T15:31:54 VMware vCenter contains an authentication bypass vulnerability in the VMware Dir
CVE-2026-59310 9.8 1.14% 1 0 2026-07-30T15:31:51 VMware vCenter contains a directory traversal vulnerability in the Syslog server
CVE-2026-41703 7.6 0.56% 1 0 2026-07-30T15:31:50 VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability.
CVE-2026-16498 10.0 0.33% 1 0 2026-07-30T14:08:23.057000 The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant cr
CVE-2026-20316 5.3 0.79% 1 0 2026-07-29T21:31:00 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2026-53264 7.8 0.21% 1 1 2026-07-29T21:30:47 In the Linux kernel, the following vulnerability has been resolved: net/sched:
CVE-2026-31431 7.8 94.55% 1 100 2026-07-28T14:54:01.770000 In the Linux kernel, the following vulnerability has been resolved: crypto: alg
CVE-2026-12495 0 0.16% 1 0 2026-07-28T08:17:14.187000 Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http
CVE-2026-39868 9.1 0.94% 2 0 2026-07-27T21:16:51.020000 This issue was addressed with improved input validation. This issue is fixed in
CVE-2026-50522 9.8 75.76% 1 5 2026-07-23T15:44:10.873000 Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CVE-2026-46300 7.8 7.01% 1 15 2026-07-23T11:10:00.120000 In the Linux kernel, the following vulnerability has been resolved: net: skbuff
CVE-2026-50343 7.8 3.50% 1 1 2026-07-22T16:17:42.747000 Improper privilege management in Microsoft Install Service allows an authorized
CVE-2026-15410 7.2 76.35% 2 3 2026-07-16T05:16:18.470000 Post-authentication improper control of generation of code ('Code Injection') vu
CVE-2026-15409 10.0 78.44% 2 6 2026-07-16T05:16:18.293000 A Server-side request forgery (SSRF) vulnerability has been identified in the SM
CVE-2026-54121 8.8 1.05% 1 12 2026-07-14T18:32:37 Improper authorization in Active Directory Certificate Services (AD CS) allows a
CVE-2026-43284 7.8 93.23% 1 44 2026-07-14T15:31:59 In the Linux kernel, the following vulnerability has been resolved: xfrm: esp:
CVE-2026-59726 10.0 0.48% 2 1 2026-07-10T19:15:15.780000 Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo
CVE-2026-46113 8.8 0.15% 1 0 2026-06-24T18:32:31 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: F
CVE-2026-50645 7.5 0.48% 1 0 2026-06-17T10:57:46.017000 There is no restriction on the amount of attachment headers that a message can c
CVE-2026-41679 10.0 1.97% 2 1 2026-06-17T10:46:59.450000 Paperclip is a Node.js server and React UI that orchestrates a team of AI agents
CVE-2025-58487 4.0 0.15% 2 0 2026-06-17T09:44:33.170000 Improper authorization in Samsung Account prior to version 15.5.01.1 allows loca
CVE-2025-58486 4.0 0.16% 4 0 2026-06-17T09:44:33.060000 Improper input validation in Samsung Account prior to version 15.5.01.1 allows l
CVE-2025-26399 9.8 88.33% 1 1 2026-06-17T09:01:42.407000 SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxP
CVE-2025-21079 7.1 0.41% 4 0 2026-06-17T08:42:34.123000 Improper input validation in Samsung Members prior to version 5.5.01.3 allows re
CVE-2023-32233 7.8 12.97% 1 7 2026-06-17T05:58:22.273000 In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when
CVE-2026-42897 8.1 70.31% 2 1 2026-05-15T18:30:32 Improper neutralization of input during web page generation ('cross-site scripti
CVE-2026-20079 10.0 37.67% 3 1 2026-03-04T18:32:03 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2013-4786 7.5 78.57% 2 1 2025-04-11T04:12:49 The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (R
CVE-2026-59774 0 0.00% 3 1 N/A
CVE-2026-15991 0 0.00% 2 0 N/A
CVE-2026-48168 0 0.00% 3 0 N/A
CVE-2026-18953 0 0.00% 2 0 N/A
CVE-2026-55524 0 0.00% 2 0 N/A
CVE-2026-55522 0 0.00% 2 0 N/A
CVE-2026-8446 0 0.00% 1 0 N/A
CVE-2026-53921 0 0.00% 1 2 N/A

CVE-2026-71315
(8.2 HIGH)

EPSS: 0.00%

updated 2026-08-06T14:16:43.987000

1 posts

Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules keys can fail to match case-folded lookups when router.options.sensitive is false and drop appMiddleware authorization gates. This is caused by an incomplete fix for CVE-2026-53721. This issue is fixed in 3.21.10 and 4.5.1.

thehackerwire@mastodon.social at 2026-08-05T21:59:59.000Z ##

🟠 CVE-2026-71315 - High (8.2)

Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules keys can fail to match case-folded lookups when router.options.sensitive is false and drop appMiddleware authorization gates. T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18649
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-06T14:16:32.430000

1 posts

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow wi

hugovalters@mastodon.social at 2026-08-06T12:02:08.000Z ##

CVE-2026-18649 - DoS in GStreamer via RTP depayloaders. Unbounded buffer growth from fragmented packets crashes process. CVSS 7.5. Unpatched - update or block RTP. #CVE #GStreamer #infosec

valtersit.com/cve/CVE-2026-186

##

CVE-2026-66733
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-06T13:18:21.947000

2 posts

Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enqueuePacket() that allows unauthenticated remote attackers to crash the server process by sending a crafted UDP packet with mUniquePacketID set to the maximum uint32 value. The mUniquePacketID field is read directly from the UDP wire-format packet header without bounds checking, cau

offseq at 2026-08-06T13:30:24.722Z ##

CVE-2026-66733: HIGH severity vuln in Eukaryot sonic3air ≤26.03.28.0. Crafted UDP packets can force unbounded memory allocation, crashing the server (DoS, no RCE). Patch unconfirmed — check vendor. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-06T13:30:24.000Z ##

CVE-2026-66733: HIGH severity vuln in Eukaryot sonic3air ≤26.03.28.0. Crafted UDP packets can force unbounded memory allocation, crashing the server (DoS, no RCE). Patch unconfirmed — check vendor. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #DoS #sonic3air

##

CVE-2026-5430
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-08-06T13:18:21.283000

2 posts

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of adm

offseq at 2026-08-06T09:00:30.096Z ##

WSO2 Universal Gateway v4.5.0 & 4.6.0 affected by CRITICAL CVE-2026-5430 (CVSS 10.0). Improper JWT validation enables account takeover. No patch yet — apply compensating controls. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-06T09:00:30.000Z ##

WSO2 Universal Gateway v4.5.0 & 4.6.0 affected by CRITICAL CVE-2026-5430 (CVSS 10.0). Improper JWT validation enables account takeover. No patch yet — apply compensating controls. radar.offseq.com/threat/cve-20 #OffSeq #WSO2 #JWT #Vulnerability

##

CVE-2026-1728
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-06T13:17:28.180000

2 posts

Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able

offseq at 2026-08-06T10:30:25.956Z ##

CVE-2026-1728 | CRITICAL: WSO2 API Manager (v4.0.0 – 4.6.0) has an improper privilege management flaw. Low-privileged user tokens can access admin REST APIs — possible admin account takeover. Patch status unknown. Restrict access & monitor. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-06T10:30:25.000Z ##

CVE-2026-1728 | CRITICAL: WSO2 API Manager (v4.0.0 – 4.6.0) has an improper privilege management flaw. Low-privileged user tokens can access admin REST APIs — possible admin account takeover. Patch status unknown. Restrict access & monitor. radar.offseq.com/threat/cve-20 #OffSeq #WSO2 #Vuln

##

CVE-2026-15459
(8.1 HIGH)

EPSS: 0.00%

updated 2026-08-06T06:31:41

2 posts

The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet connected to the WPMU DEV Hub — the default state after installation — the site API key that keys the WDP-AUTH request signature is empty, making the signature verified by validate_hash() trivially forgeable; version 5.0.0 additionally removed the replay

thehackerwire@mastodon.social at 2026-08-06T07:00:10.000Z ##

🟠 CVE-2026-15459 - High (8.1)

The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet connected to the WPMU DEV Hub — the default state after installation — the site API key that keys ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-06T07:00:10.000Z ##

🟠 CVE-2026-15459 - High (8.1)

The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet connected to the WPMU DEV Hub — the default state after installation — the site API key that keys ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8478
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-06T05:17:11.987000

1 posts

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.

thehackerwire@mastodon.social at 2026-08-05T20:00:27.000Z ##

🟠 CVE-2026-8478 - High (8.8)

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70482
(8.1 HIGH)

EPSS: 0.34%

updated 2026-08-06T05:17:07.240000

1 posts

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchange accepts a raw provider access token and validates it by calling the provider userinfo endpoint without confirming which OAuth client the token was issued to. Anyone holding an access token minted for any client regist

thehackerwire@mastodon.social at 2026-08-04T21:00:13.000Z ##

🟠 CVE-2026-70482 - High (8.1)

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchange accepts a raw provider access token and validates it by calling ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70431
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-06T05:17:06.537000

2 posts

Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugin, allowing attackers with Item/Create or Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM.

thehackerwire@mastodon.social at 2026-08-06T04:00:27.000Z ##

🟠 CVE-2026-70431 - High (8.8)

Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugin, allowing attackers with Item/Create or Item/Configure permission to execute arbitrary code in the context...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-06T04:00:27.000Z ##

🟠 CVE-2026-70431 - High (8.8)

Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugin, allowing attackers with Item/Create or Item/Configure permission to execute arbitrary code in the context...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70426
(9.0 CRITICAL)

EPSS: 0.00%

updated 2026-08-06T05:17:05.850000

5 posts

In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserialization implementation, allowing agent processes, code running on agents, and attackers with Agent/Connect permission to bypass the JEP-200 deserialization

undercodenews@mastodon.social at 2026-08-06T10:13:53.000Z ##

Critical Jenkins Vulnerability Exposes Build Controllers: CVE-2026-70426 Could Turn Trusted Automation Into an Attacker’s Gateway + Video

Introduction: The Hidden Risk Behind Modern Software Automation Jenkins has become one of the most important automation platforms in the software industry, powering continuous integration and continuous delivery (CI/CD) pipelines for organizations worldwide. From compiling applications to deploying cloud infrastructure, Jenkins…

undercodenews.com/critical-jen

##

thehackerwire@mastodon.social at 2026-08-06T04:00:16.000Z ##

🔴 CVE-2026-70426 - Critical (9)

In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserializa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity at 2026-08-06T01:06:12.886Z ##

Critical Jenkins vulnerability CVE-2026-70426 lets attackers bypass the JEP-200 filter and run code on the controller. Patch now.

securityonline.info/jenkins-cv

##

thehackerwire@mastodon.social at 2026-08-06T04:00:16.000Z ##

🔴 CVE-2026-70426 - Critical (9)

In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserializa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-08-06T01:06:12.000Z ##

Critical Jenkins vulnerability CVE-2026-70426 lets attackers bypass the JEP-200 filter and run code on the controller. Patch now.
#Jenkins #CVE202670426 #RCE #DevSecOps #Deserialization #CyberSecurity

securityonline.info/jenkins-cv

##

CVE-2026-63077
(9.8 CRITICAL)

EPSS: 0.65%

updated 2026-08-06T05:17:05.170000

9 posts

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

1 repos

https://github.com/unveiledhistory49/teamcity-cve-2026-63077-remediation

thecybermind at 2026-08-06T11:58:45.031Z ##

🚨 CSUITE THREAT ADVISORY: CISA confirms active exploitation of CVE-2026-63077 in JetBrains TeamCity. Unauthenticated RCE threatens core build pipelines & supply chain integrity. Get the executive governance, risk management, and compliance brief now: thecybermind.co/jvee

##

Analyst207@mastodon.social at 2026-08-06T08:36:23.000Z ##

CISA Warns of Active TeamCity Exploit

Warning: a critical vulnerability in JetBrains TeamCity (CVE-2026-63077) is being actively exploited in the wild, allowing unauthenticated attackers to execute malicious code remotely. This severe flaw has a CVSS score of 9.8, highlighting the urgent need for immediate action.

osintsights.com/cisa-warns-of-

#Teamcity #Cve202663077 #DeserializationVulnerability #RemoteCodeExecution #Cisa

##

allaboutsecurity@mastodon.social at 2026-08-06T06:23:50.000Z ##

CVE-2026-63077: CISA warnt vor aktiver Ausnutzung einer TeamCity-Sicherheitslücke

Angreifer können ohne Authentifizierung Schadcode auf dem Server ausführen.

all-about-security.de/cve-2026

#cybersecurity #cve #cisa #itsecurity #itsicherheit

##

DailyCyberSecurity at 2026-08-06T01:44:36.290Z ##

TeamCity vulnerability CVE-2026-63077 enables unauthenticated remote code execution. CISA added it to the KEV catalog amid active exploitation.

securityonline.info/teamcity-c

##

thecybermind@infosec.exchange at 2026-08-06T11:58:45.000Z ##

🚨 CSUITE THREAT ADVISORY: CISA confirms active exploitation of CVE-2026-63077 in JetBrains TeamCity. Unauthenticated RCE threatens core build pipelines & supply chain integrity. Get the executive governance, risk management, and compliance brief now: thecybermind.co/jvee

##

DailyCyberSecurity@infosec.exchange at 2026-08-06T01:44:36.000Z ##

TeamCity vulnerability CVE-2026-63077 enables unauthenticated remote code execution. CISA added it to the KEV catalog amid active exploitation.

#TeamCity #CVE202663077 #RCE #CISA #KEV #CyberSecurity

securityonline.info/teamcity-c

##

thecybermind@infosec.exchange at 2026-08-05T20:36:39.000Z ##

🚨 CISA KEV ALERT: CVE-2026-63077 exposes JetBrains TeamCity servers to unauthenticated RCE via untrusted deserialization. Active exploitation confirmed. Get the forensic breakdown, CrowdStrike CQL detection logic, and CI/CD hardening steps: thecybermind.co/oapr

##

secdb@infosec.exchange at 2026-08-05T19:00:10.000Z ##

🚨 [CISA-2026:0805] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-63077 (secdb.nttzen.cloud/cve/detail/)
- Name: JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JetBrains
- Product: TeamCity
- Notes: blog.jetbrains.com/teamcity/20; jetbrains.com/privacy-security ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260805 #cisa20260805 #cve_2026_63077 #cve202663077

##

cisakevtracker@mastodon.social at 2026-08-05T18:00:45.000Z ##

CVE ID: CVE-2026-63077
Vendor: JetBrains
Product: TeamCity
Date Added: 2026-08-05
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-44945
(9.1 CRITICAL)

EPSS: 0.74%

updated 2026-08-06T05:17:03.793000

1 posts

A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user global role can gain full administrative access to the Rancher control plane and transitively to all downstream clusters it manages. This issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.

offseq@infosec.exchange at 2026-08-05T10:30:25.000Z ##

SUSE Rancher CVE-2026-44945 (CRITICAL, CVSS 9.1): Privilege escalation flaw lets authenticated users with default global role gain full admin on Rancher & clusters. Restrict access & monitor pending patch. radar.offseq.com/threat/cve-20 #OffSeq #infosec #CVE202644945 #Kubernetes

##

CVE-2026-20312
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-06T05:17:02.450000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20312 are related to Cleartext storage of sensitive information

thehackerwire@mastodon.social at 2026-08-05T18:00:37.000Z ##

🟠 CVE-2026-20312 - High (8.8)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address mu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20304
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-08-06T05:16:59.827000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20304 are related to improper access control issues that are gr

CVE-2026-20267
(9.0 CRITICAL)

EPSS: 0.00%

updated 2026-08-06T05:16:43.583000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20267 are related to improper access control issues that ar

CVE-2026-17633
(8.5 HIGH)

EPSS: 0.00%

updated 2026-08-06T05:16:40.457000

2 posts

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection.

thehackerwire@mastodon.social at 2026-08-06T03:00:10.000Z ##

🟠 CVE-2026-17633 - High (8.5)

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-06T03:00:10.000Z ##

🟠 CVE-2026-17633 - High (8.5)

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18973
(7.3 HIGH)

EPSS: 0.00%

updated 2026-08-06T01:16:29.410000

1 posts

A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitize_proxy_url of the file server.py of the component extension_proxy Route. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early

hugovalters@mastodon.social at 2026-08-06T14:00:54.000Z ##

CVE-2026-18973 - SSRF in heshengtao super-agent-party ≤0.4.1. Unpatched, exploit public. CVSS 7.3. Update/block immediately. #CVE #infosec #cybersecurity

valtersit.com/cve/CVE-2026-189

##

CVE-2026-67869
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-06T00:31:38

2 posts

Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata

thehackerwire@mastodon.social at 2026-08-06T00:59:47.000Z ##

🟠 CVE-2026-67869 - High (7.5)

Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-06T00:59:47.000Z ##

🟠 CVE-2026-67869 - High (7.5)

Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67863
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-06T00:31:29

2 posts

In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish continues to use the current UA_Notification after a callback invokes UA_Server_deleteMonitoredItem for the current local MonitoredItem. This allows a remote attacker to cause a denial of service.

thehackerwire@mastodon.social at 2026-08-05T23:59:50.000Z ##

🟠 CVE-2026-67863 - High (7.5)

In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish continues to use the current UA_Notification after a callback invokes UA_Server_deleteMonitoredIte...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-05T23:59:50.000Z ##

🟠 CVE-2026-67863 - High (7.5)

In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish continues to use the current UA_Notification after a callback invokes UA_Server_deleteMonitoredIte...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67531
(0 None)

EPSS: 0.00%

updated 2026-08-06T00:16:53.733000

2 posts

FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host Zod schema instances to the script via getTool(), and because Zod v4 defines _zod as a non-configurable, non-writable own property, the ECMAScript Proxy invariants force the security membrane to hand back the raw host object, letting a script reach _z

offseq at 2026-08-06T00:00:39.359Z ##

CVE-2026-67531 (CRITICAL): agentfront frontmcp <1.5.7 suffers a code injection flaw enabling remote code execution and theft of secrets. Upgrade to v1.5.7+ ASAP. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-06T00:00:39.000Z ##

CVE-2026-67531 (CRITICAL): agentfront frontmcp <1.5.7 suffers a code injection flaw enabling remote code execution and theft of secrets. Upgrade to v1.5.7+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #RCE #InfoSec #CVE2026

##

CVE-2026-18970
(7.3 HIGH)

EPSS: 0.00%

updated 2026-08-06T00:16:53.060000

1 posts

A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. The affected element is an unknown function of the file /dm/dispatch/user/findAll. Executing a manipulation of the argument Name can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclos

hugovalters@mastodon.social at 2026-08-06T11:00:39.000Z ##

CVE-2026-18970 - SQLi in Command Dispatch Platform. Remote exploit via /dm/dispatch/user/findAll, CVSS 7.3. Unpatched, vendor unresponsive. Mitigate now. #CVE #infosec #cybersecurity

valtersit.com/cve/CVE-2026-189

##

CVE-2026-71321
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-05T21:43:07

2 posts

### Impact The internal island renderer endpoint (`/__nuxt_island/...`) decodes and hashes attacker-controlled request input before it validates the URL-resident hash. An unauthenticated `POST /__nuxt_island/<name>_<anything>.json` with a large JSON body (for example ~4.6 MB / 150k keys) is fully read, `destr`-parsed, and run through `ohash` before the request is rejected with a 400. Because Nitr

thehackerwire@mastodon.social at 2026-08-05T23:00:58.000Z ##

🟠 CVE-2026-71321 - High (7.5)

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island renderer endpoint `/__nuxt_island/...` decodes and hashes attacker-controlled JSON body input with destr and ohash before validati...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-05T23:00:58.000Z ##

🟠 CVE-2026-71321 - High (7.5)

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island renderer endpoint `/__nuxt_island/...` decodes and hashes attacker-controlled JSON body input with destr and ohash before validati...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70432
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-05T21:32:44

2 posts

A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute arbitrary code in the context of the Jenkins controller JVM.

thehackerwire@mastodon.social at 2026-08-06T07:00:32.000Z ##

🟠 CVE-2026-70432 - High (8.8)

A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute arbitrary code in the context of the Jenkins controller JVM.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-06T07:00:32.000Z ##

🟠 CVE-2026-70432 - High (8.8)

A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute arbitrary code in the context of the Jenkins controller JVM.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-60007
(7.4 HIGH)

EPSS: 0.45%

updated 2026-08-05T21:32:37

1 posts

In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's `Basic128Rsa15`-encrypted username token to use repeated unauthenticated `ActivateSession` requests as a padding oracle, recover the victim's password, and authenticate with

offseq@infosec.exchange at 2026-08-04T13:30:20.000Z ##

Eclipse Milo (0.6.0 – 1.1.4) faces a CRITICAL flaw (CVE-2026-60007): error messages in username-token RSA PKCS#1 v1.5 handling enable padding oracle attacks, risking password compromise. Patch status unclear. radar.offseq.com/threat/cve-20 #OffSeq #EclipseMilo #Vuln #Infosec

##

CVE-2026-70615
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-08-05T21:31:48

1 posts

boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH authorized_keys file by supplying a percent-encoded newline character in the domain parameter of the tunnel creation endpoint. Attackers can insert an unrestricted public key entry into authorize

thehackerwire@mastodon.social at 2026-08-05T20:59:59.000Z ##

🔴 CVE-2026-70615 - Critical (9.9)

boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH authorized_keys file by supplying a percen...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-34966
(7.6 HIGH)

EPSS: 0.00%

updated 2026-08-05T21:31:47

1 posts

Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get without a custom DialContext. Attackers can supply arbitrary URLs through release asset download URLs, pull-request patch URLs, or OAuth avatar endpoints

thehackerwire@mastodon.social at 2026-08-05T22:00:09.000Z ##

🟠 CVE-2026-34966 - High (7.6)

Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17624
(8.5 HIGH)

EPSS: 0.00%

updated 2026-08-05T21:31:46

2 posts

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of module imports.

thehackerwire@mastodon.social at 2026-08-06T04:00:05.000Z ##

🟠 CVE-2026-17624 - High (8.5)

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-06T04:00:05.000Z ##

🟠 CVE-2026-17624 - High (8.5)

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17632
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-05T21:31:46

2 posts

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based security scanning.

thehackerwire@mastodon.social at 2026-08-06T03:00:30.000Z ##

🟠 CVE-2026-17632 - High (8.8)

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based security scanning.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-06T03:00:30.000Z ##

🟠 CVE-2026-17632 - High (8.8)

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based security scanning.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18485
(7.8 HIGH)

EPSS: 0.00%

updated 2026-08-05T21:31:46

2 posts

There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver.  This may allow a local, authenticated user to escalate privileges and execute arbitrary code.  This vulnerability affects NI-PAL 26.3.1 and prior versions running on Microsoft Windows.

thehackerwire@mastodon.social at 2026-08-06T03:00:20.000Z ##

🟠 CVE-2026-18485 - High (7.8)

There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver.  This may allow a local, authenticated user to escalate privileges and execute arbitrary code.  This vulnerability affects NI-PAL 26.3.1 and p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-06T03:00:20.000Z ##

🟠 CVE-2026-18485 - High (7.8)

There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver.  This may allow a local, authenticated user to escalate privileges and execute arbitrary code.  This vulnerability affects NI-PAL 26.3.1 and p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18411
(8.1 HIGH)

EPSS: 0.00%

updated 2026-08-05T21:31:46

2 posts

The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. An attacker within Bluetooth range can leverage this weakness to issue unauthorized commands to the vehicle, potentially allowing unauthorized access to vehicle functions, including door unlocking and engine immobilization.

thehackerwire@mastodon.social at 2026-08-05T22:01:23.000Z ##

🟠 CVE-2026-18411 - High (8.1)

The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. An attacker within Bluetooth range can leverage this weakness to issue unauthorized commands to the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-05T22:01:23.000Z ##

🟠 CVE-2026-18411 - High (8.1)

The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. An attacker within Bluetooth range can leverage this weakness to issue unauthorized commands to the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17583
(8.4 HIGH)

EPSS: 0.00%

updated 2026-08-05T21:31:46

2 posts

The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes.

1 repos

https://github.com/HORKimhab/CVE-2026-17583

thehackerwire@mastodon.social at 2026-08-05T22:01:13.000Z ##

🟠 CVE-2026-17583 - High (8.4)

The affected

Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-05T22:01:13.000Z ##

🟠 CVE-2026-17583 - High (8.4)

The affected

Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-69111
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-05T21:31:46

1 posts

Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service components by sending a crafted HTTP GET request to the management server on port 9091. Attackers can exploit the unprotected /management/stop endpoint, which bypasses REST API authentication middleware, by supplying a 'role' parameter to shut down the proxy

thehackerwire@mastodon.social at 2026-08-05T21:00:18.000Z ##

🟠 CVE-2026-69111 - High (7.5)

Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service components by sending a crafted HTTP GET request to the management server on port 9091. Attackers can exp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8183
(7.7 HIGH)

EPSS: 0.00%

updated 2026-08-05T21:31:39

1 posts

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to v i ew arbitrary files on the system.

thehackerwire@mastodon.social at 2026-08-05T20:01:13.000Z ##

🟠 CVE-2026-8183 - High (7.7)

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote attacker to traverse directories on the system. An attacker could send a s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8182
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-05T21:31:39

1 posts

IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via 2 HTTP requests.

thehackerwire@mastodon.social at 2026-08-05T20:01:02.000Z ##

🟠 CVE-2026-8182 - High (8.8)

IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via 2 HTTP requests.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9201
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-05T21:31:39

1 posts

IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom component validation mechanism. When the optional hardening mode that restricts execution to trusted component templates is enabled, the application validates component code using a truncated SHA‑256 hash. Because the hash comparison relies on only a p

thehackerwire@mastodon.social at 2026-08-05T20:00:17.000Z ##

🟠 CVE-2026-9201 - High (8.8)

IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom component validation mechanism. When the optional hardening mode that restricts execution to truste...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9196
(8.1 HIGH)

EPSS: 0.00%

updated 2026-08-05T21:31:39

1 posts

IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLM‑generated components. The application executes model‑generated Python code in the backend during validation prior to user approval, which may allow an attacker to trigger side effects such as outbound network access, file system

thehackerwire@mastodon.social at 2026-08-05T20:00:08.000Z ##

🟠 CVE-2026-9196 - High (8.1)

IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLM‑generated components. The application executes model‑generated Python co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71320
(8.1 HIGH)

EPSS: 0.00%

updated 2026-08-05T21:29:56

2 posts

## Impact Nuxt server islands accept props via the `/__nuxt_island/` endpoint. When `vue.runtimeCompiler: true` is enabled (off by default) and the application has a server island component that forwards props into Vue's dynamic component resolution (`<component :is>`, `resolveDynamicComponent`, or `h()`), an attacker can inject a `template` key into the island props to achieve server-side remote

thehackerwire@mastodon.social at 2026-08-05T23:00:49.000Z ##

🟠 CVE-2026-71320 - High (8.1)

Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a template key through /__nuxt_island/ props into a dynamic component when `vue.runtimeCompiler: true` is enabled, causing temp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-05T23:00:49.000Z ##

🟠 CVE-2026-71320 - High (8.1)

Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a template key through /__nuxt_island/ props into a dynamic component when `vue.runtimeCompiler: true` is enabled, causing temp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71319
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-08-05T21:27:39

4 posts

### Impact Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the `nuxt:devtools:rpc` plugin. On affected versions the channel has no authentication: any client that can reach the Vite HMR endpoint (`ws://<host>:<port>/`, subprotocol `vite-hmr`) can call RPC methods, with no token, handshake, or origin check before the channel is established.

offseq at 2026-08-06T03:00:29.582Z ##

Nuxt DevTools <3.3.1 is affected by CVE-2026-71319 (CRITICAL). Unauthenticated Vite HMR WebSocket RPC lets attackers execute arbitrary code via updateOptions() & openInEditor(). Patch to 3.3.1 ASAP. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-05T23:00:39.000Z ##

🔴 CVE-2026-71319 - Critical (9.6)

Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin. On affected versions the channel h...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-06T03:00:29.000Z ##

Nuxt DevTools <3.3.1 is affected by CVE-2026-71319 (CRITICAL). Unauthenticated Vite HMR WebSocket RPC lets attackers execute arbitrary code via updateOptions() & openInEditor(). Patch to 3.3.1 ASAP. radar.offseq.com/threat/cve-20 #OffSeq #NuxtJS #CVE202671319 #infosec

##

thehackerwire@mastodon.social at 2026-08-05T23:00:39.000Z ##

🔴 CVE-2026-71319 - Critical (9.6)

Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin. On affected versions the channel h...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71316
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-05T21:14:34

2 posts

### Impact When a page is covered by `routeRules` `cache` / `swr` / `isr`, Nuxt enables runtime payload extraction and serves `/<page>/_payload.json`. On affected versions the renderer stored the SSR payload in the shared `cache:nuxt:payload` storage under a path-only key (no cookie, `authorization`, or `cache.varies` dimension) and, on a later payload request, returned the cached entry before ro

thehackerwire@mastodon.social at 2026-08-05T23:59:59.000Z ##

🟠 CVE-2026-71316 - High (7.5)

Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries for //_payload.json can be returned before route middleware and page guards because import.meta.prerender is not enforced, disc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-05T23:59:59.000Z ##

🟠 CVE-2026-71316 - High (7.5)

Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries for //_payload.json can be returned before route middleware and page guards because import.meta.prerender is not enforced, disc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71314
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-05T20:59:08

1 posts

### Impact An unauthenticated attacker can crash a Nuxt server that renders any island / server component containing a `v-for` over a prop (for example `v-for="n in count"` or a `<slot v-for>`). Because the island URL hash is a non-secret digest of the request, the attacker can compute a valid hash for arbitrary props and send the iterated prop as a large integer. The server then expands the `v-f

thehackerwire@mastodon.social at 2026-08-05T21:59:50.000Z ##

🟠 CVE-2026-71314 - High (7.5)

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated attacker can use a server island v-for prop, including vforToArray and , to trigger unbounded SSR memory allocation until MAX_VFOR_...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71312
(8.0 HIGH)

EPSS: 0.00%

updated 2026-08-05T20:38:00

1 posts

## 1. Summary rclone interpolates remote SFTP paths into PowerShell hash commands. Its quoting helper escapes only ASCII apostrophe, although PowerShell accepts four Unicode smart quotes as single-quote delimiters. An attacker-controlled filename can therefore terminate the intended path literal and append PowerShell statements executed as the victim's SSH account. ## 2. Affected Assets & Attack

thehackerwire@mastodon.social at 2026-08-05T22:01:04.000Z ##

🟠 CVE-2026-71312 - High (8)

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and quoteOrEscapeShellPath...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70617
(8.1 HIGH)

EPSS: 0.00%

updated 2026-08-05T20:17:17.770000

1 posts

Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group DM channels by sending a PUT request to the channels recipient endpoint without membership verification. Attackers can exploit the unguarded PUT /channels/{channel_id}/recipients/{user_id} handler to join private group DMs, read complete m

thehackerwire@mastodon.social at 2026-08-05T21:00:09.000Z ##

🟠 CVE-2026-70617 - High (8.1)

Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group DM channels by sending a PUT request to the channels recipient endpoint without member...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15573
(8.1 HIGH)

EPSS: 0.00%

updated 2026-08-05T20:17:05.243000

1 posts

A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into applying a less restrictive security policy than intended. This allows an authenticated

hugovalters@mastodon.social at 2026-08-05T23:02:48.000Z ##

CVE-2026-15573 - High severity auth bypass in Red Hat Keycloak. URI normalization flaw lets authenticated users bypass policies to access restricted areas. CVSS 8.1. Unpatched - update when available. #CVE #Keycloak #infosec

valtersit.com/cve/CVE-2026-155

##

CVE-2026-17566
(9.9 CRITICAL)

EPSS: 0.43%

updated 2026-08-05T20:00:10.473000

1 posts

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (...) wrapper, create_import_export_job() (route POST /import_export/job/<sid>, gated only by the ordinary, commonly-granted tools_import_export_data permission)

1 repos

https://github.com/HackSpeak/CVE-2026-17566

CVE-2026-9077
(8.5 HIGH)

EPSS: 0.00%

updated 2026-08-05T19:17:45.807000

1 posts

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files on the host system.

thehackerwire@mastodon.social at 2026-08-05T18:00:16.000Z ##

🟠 CVE-2026-9077 - High (8.5)

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files on the host system.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20310
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-08-05T18:31:49

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20310 are related to improper link resolution before file access i

thehackerwire@mastodon.social at 2026-08-06T08:00:19.000Z ##

🔴 CVE-2026-20310 - Critical (9.1)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address mu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-06T08:00:19.000Z ##

🔴 CVE-2026-20310 - Critical (9.1)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address mu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20313
(7.7 HIGH)

EPSS: 0.00%

updated 2026-08-05T18:31:49

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20313 are related to Improper link resolution before file access i

thehackerwire@mastodon.social at 2026-08-06T08:00:07.000Z ##

🟠 CVE-2026-20313 - High (7.7)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address mu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-06T08:00:07.000Z ##

🟠 CVE-2026-20313 - High (7.7)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address mu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20303
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-08-05T18:31:48

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20303 are related to improper input validation issues that are gro

CVE-2026-20272
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-05T18:31:45

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20272 are related to issues with improper neutralization of specia

CVE-2026-45537
(9.1 CRITICAL)

EPSS: 0.36%

updated 2026-08-05T18:17:11.353000

1 posts

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the construct_uri() function concatenates multiple URI components (protocol, username, domain, port, params) into a fixed 1024-byte global BSS buffer without any bounds checking. When a routing script calls construct_uri() with an attacker-controlled username, a combined component lengt

thehackerwire@mastodon.social at 2026-08-05T00:00:07.000Z ##

🔴 CVE-2026-45537 - Critical (9.1)

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the construct_uri() function concatenates multiple URI components (protocol, username, domain, port, params) into a fixed 1024-byte gl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20301
(8.6 HIGH)

EPSS: 0.00%

updated 2026-08-05T18:17:07.557000

2 posts

A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of malformed XMCP packets. An attacker could exploit this vulnerabil

thehackerwire@mastodon.social at 2026-08-06T08:00:51.000Z ##

🟠 CVE-2026-20301 - High (8.6)

A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-06T08:00:51.000Z ##

🟠 CVE-2026-20301 - High (8.6)

A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18898
(8.8 HIGH)

EPSS: 0.47%

updated 2026-08-05T17:16:45.797000

1 posts

A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the function strcpy of the file /goform/ConfigAdvideo. The manipulation of the argument timestart results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did n

thehackerwire@mastodon.social at 2026-08-05T06:00:05.000Z ##

🟠 CVE-2026-18898 - High (8.8)

A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the function strcpy of the file /goform/ConfigAdvideo. The manipulation of the argument timestart results in stack-based buffer overflow. The attack can be l...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71289
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-05T16:17:08.400000

1 posts

The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. "${ION_MGR_PORT:-8089}:8089/tcp") with cap_add: NET_ADMIN, NET_RAW, SYS_NICE, bypassing the CAM (Configuration and Access Manager) gateway that is otherwise the system's sole authentic

offseq@infosec.exchange at 2026-08-05T13:30:25.000Z ##

CVE-2026-71289 (CRITICAL, CVSS 9.8): NASA-AMMOS ANMS exposes amp-manager REST API w/ no auth. Remote attackers can control system & disrupt ops. Restrict access, avoid default configs, check vendor for patches. radar.offseq.com/threat/cve-20 #OffSeq #CVE #NASA #Infosec

##

CVE-2026-71287
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-05T16:17:08.190000

1 posts

Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex `preg_replace('/[^a-zA-Z0-9_().]/', '', $column)`. Because this allowlist retains letters, digits, underscore, parentheses, and dot (intended to support expressions like COUNT(id) and table.column), a payload such as `SLEEP(5)` passes through completely unmodified. The sanitized value is

thehackerwire@mastodon.social at 2026-08-05T14:00:30.000Z ##

🟠 CVE-2026-71287 - High (8.8)

Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex `preg_replace('/[^a-zA-Z0-9_().]/', '', $column)`. Because this allowlist retains letters, digits, underscore, parentheses, and dot (in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71285
(8.1 HIGH)

EPSS: 0.00%

updated 2026-08-05T16:17:07.967000

1 posts

Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo `siteId` value as a bare, unquoted JavaScript expression inside a <script> block rendered on every public status page: `_paq.push(['setSiteId', ${escapedSiteIdHTMLAttribute}]);`. The escaping pipeline used (jsesc with isScriptContext:true, then html-escaper.escape()) does not esc

thehackerwire@mastodon.social at 2026-08-05T14:00:20.000Z ##

🟠 CVE-2026-71285 - High (8.1)

Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo `siteId` value as a bare, unquoted JavaScript expression inside a block rendered on every public status page: `_paq.push(['set...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67861
(7.5 HIGH)

EPSS: 0.42%

updated 2026-08-05T16:17:00.200000

1 posts

An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component

thehackerwire@mastodon.social at 2026-08-05T00:00:17.000Z ##

🟠 CVE-2026-67861 - High (7.5)

An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67859
(7.5 HIGH)

EPSS: 0.47%

updated 2026-08-05T16:17:00.067000

1 posts

Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling.

thehackerwire@mastodon.social at 2026-08-04T23:00:19.000Z ##

🟠 CVE-2026-67859 - High (7.5)

Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59913
(7.8 HIGH)

EPSS: 0.11%

updated 2026-08-05T15:44:27.057000

1 posts

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

thehackerwire@mastodon.social at 2026-08-03T20:00:25.000Z ##

🟠 CVE-2026-59913 - High (7.8)

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-34486
(9.8 CRITICAL)

EPSS: 81.16%

updated 2026-08-05T15:33:26.557000

5 posts

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

6 repos

https://github.com/razureink/cve-2026-34486-tomcat_encrypt_bypass_reproduction

https://github.com/404-src/CVE-2026-34486

https://github.com/punitdarji/tomcat-cve-2026-34486

https://github.com/AirSkye/CVE-2026-34486-poc

https://github.com/anonmrc/CVE-2026-34486-e-Tomcat-Tribes

https://github.com/striga-ai/CVE-2026-34486

beyondmachines1 at 2026-08-06T11:01:31.170Z ##

CISA Reports Active Exploitation of Apache Tomcat RCE Vulnerability

CISA reports active exploitation of an Apache Tomcat vulnerability (CVE-2026-34486) to its KEV catalog after Chinese threat actors exploited a fail-open logic error in the EncryptInterceptor to achieve remote code execution.

**If you run Apache Tomcat with clustering enabled, upgrade ASAP to 9.0.117, 10.1.54, or 11.0.21 This flaw is being actively exploited and can give attackers full remote code execution on every node in the cluster. If you can't patch, make sure your cluster traffic ports are not reachable from the internet, check `server.xml` and `context.xml` to confirm EncryptInterceptor is active with no custom interceptors overriding it, and turn off plain HTTP in favour of HTTPS only.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-08-06T11:01:31.000Z ##

CISA Reports Active Exploitation of Apache Tomcat RCE Vulnerability

CISA reports active exploitation of an Apache Tomcat vulnerability (CVE-2026-34486) to its KEV catalog after Chinese threat actors exploited a fail-open logic error in the EncryptInterceptor to achieve remote code execution.

**If you run Apache Tomcat with clustering enabled, upgrade ASAP to 9.0.117, 10.1.54, or 11.0.21 This flaw is being actively exploited and can give attackers full remote code execution on every node in the cluster. If you can't patch, make sure your cluster traffic ports are not reachable from the internet, check `server.xml` and `context.xml` to confirm EncryptInterceptor is active with no custom interceptors overriding it, and turn off plain HTTP in favour of HTTPS only.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

thecybermind@infosec.exchange at 2026-08-05T11:47:47.000Z ##

🚨 CISA KEV ALERT: CVE-2026-34486 exposes Apache Tomcat installations to EncryptInterceptor bypasses and data interception. Active exploitation confirmed. Get the forensic breakdown, Splunk/KQL/Chronicle detection queries, and hardening steps: thecybermind.co/it1p

Top-of-the-Line LinkedIn Post

##

secdb@infosec.exchange at 2026-08-04T19:00:11.000Z ##

🚨 [CISA-2026:0804] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-18556 (secdb.nttzen.cloud/cve/detail/)
- Name: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: uptime.n-able.com/ ; status.n-able.com/2026/08/02/n ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34486 (secdb.nttzen.cloud/cve/detail/)
- Name: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Tomcat
- Notes: lists.apache.org/thread/9510k5 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9198 (secdb.nttzen.cloud/cve/detail/)
- Name: IBM Langflow Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: IBM
- Product: Langflow
- Notes: ibm.com/support/pages/node/727 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260804 #cisa20260804 #cve_2026_18556 #cve_2026_34486 #cve_2026_9198 #cve202618556 #cve202634486 #cve20269198

##

cisakevtracker@mastodon.social at 2026-08-04T18:01:07.000Z ##

CVE ID: CVE-2026-34486
Vendor: Apache
Product: Tomcat
Date Added: 2026-08-04
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-71294
(7.6 HIGH)

EPSS: 0.00%

updated 2026-08-05T15:32:29

1 posts

Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controllers/actions/CreateAction.php, a `ci` POST parameter obtained via `cot_import('ci', 'P', 'TXT')` (trim-only sanitization) is passed to `unserialize(base64_decode($ci))` with no `allowed_classes` restriction, reachable by any member with write access to

thehackerwire@mastodon.social at 2026-08-05T14:00:10.000Z ##

🟠 CVE-2026-71294 - High (7.6)

Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controllers/actions/CreateAction.php, a `ci` POST parameter obtained via `cot_import('ci', 'P', 'TXT')` (tr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67857
(7.5 HIGH)

EPSS: 0.35%

updated 2026-08-05T15:32:14

1 posts

open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.

thehackerwire@mastodon.social at 2026-08-05T00:00:27.000Z ##

🟠 CVE-2026-67857 - High (7.5)

open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9273
(9.3 CRITICAL)

EPSS: 0.28%

updated 2026-08-05T15:17:19.770000

1 posts

The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading to account takeover in all versions up to, and including, 4.0.0. This is due to the legacy lost-password handler rc_process_lost_password_form() consuming the attacker-controlled rc_redirect POST parameter into two unvalidated sinks in legacy/includes/

offseq@infosec.exchange at 2026-08-05T06:00:32.000Z ##

Kadence Memberships (stellarwp) ≤4.0.0 suffers CRITICAL vuln (CVE-2026-9273, CVSS 9.3): attackers can hijack any account by poisoning password reset links. Restrict reset features & monitor for patches. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #Security

##

CVE-2026-70554
(9.8 CRITICAL)

EPSS: 0.85%

updated 2026-08-05T15:17:13.783000

1 posts

MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers can craft a malicious serialized PHP object payload delivered in a single HTTP request to trigger magic methods during obje

offseq@infosec.exchange at 2026-08-05T00:00:36.000Z ##

MaxSite CMS 0.78 is vulnerable (CVE-2026-70554, CRITICAL): PHP object injection via maxsite_comuser cookie enables unauthenticated RCE. No patch available. Restrict access, deploy WAF, and monitor activity. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #CMS #PHP #RCE

##

CVE-2026-70486
(8.2 HIGH)

EPSS: 0.37%

updated 2026-08-05T15:17:10.497000

1 posts

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together with allow-scripts for HTML files served from the application origin. Any authenticated user with access to a configured terminal server could cause script in a previewed file to run in the Open Web

thehackerwire@mastodon.social at 2026-08-04T21:00:23.000Z ##

🟠 CVE-2026-70486 - High (8.2)

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together with allow-scripts for HTML files served from...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67858
(7.5 HIGH)

EPSS: 0.49%

updated 2026-08-05T15:17:06.617000

1 posts

Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. An unauthenticated remote attacker can send a RegisterServer or RegisterServer2 request containing many unique discoveryUrls. This allows remote attackers to cause a denial of service.

thehackerwire@mastodon.social at 2026-08-04T23:00:09.000Z ##

🟠 CVE-2026-67858 - High (7.5)

Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. An unauthenticated remote attacker can send a RegisterServer or RegisterServer2 requ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18895
(8.8 HIGH)

EPSS: 0.57%

updated 2026-08-05T15:16:45.587000

1 posts

A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulation of the argument cipher results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respon

thehackerwire@mastodon.social at 2026-08-05T06:00:15.000Z ##

🟠 CVE-2026-18895 - High (8.8)

A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulation of the argument cipher results in stack-based buffer overflow. It is possible to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68981
(7.5 HIGH)

EPSS: 0.32%

updated 2026-08-05T14:59:30.577000

1 posts

Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client to send crafted requests that could consume excessive amounts of memory. Upgrading to Apache NiFi 2.11.0 is the recommend

DailyCyberSecurity@infosec.exchange at 2026-08-04T01:52:18.000Z ##

Apache NiFi vulnerabilities, including CVE-2026-68979, CVE-2026-62354, and CVE-2026-68981, expose users to code execution and resource consumption.

#ApacheNiFi #CyberSecurity #Vulnerabilities #CVE #InfoSec

securityonline.info/apache-nif

##

CVE-2026-68979
(9.8 CRITICAL)

EPSS: 0.35%

updated 2026-08-05T14:59:03.460000

1 posts

Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing components, but framework authorization was limited to read and write privileges on the Parameter Context itself. As a result of the missing auth

DailyCyberSecurity@infosec.exchange at 2026-08-04T01:52:18.000Z ##

Apache NiFi vulnerabilities, including CVE-2026-68979, CVE-2026-62354, and CVE-2026-68981, expose users to code execution and resource consumption.

#ApacheNiFi #CyberSecurity #Vulnerabilities #CVE #InfoSec

securityonline.info/apache-nif

##

CVE-2026-48449
(10.0 CRITICAL)

EPSS: 0.54%

updated 2026-08-05T14:54:01.933000

1 posts

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

DailyCyberSecurity@infosec.exchange at 2026-08-03T15:02:08.000Z ##

Adobe fixes a CVSS 10 RCE in Campaign Classic (CVE-2026-48449) and eight critical flaws in Bridge. Update to build 9398 and Bridge 15.1.7 or 16.0.6 now.

#AdobeCampaign #CVE202648449 #AdobeBridge #CriticalPatch #RCE

securityexpress.info/adobe-cam

##

CVE-2026-71214
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-08-05T14:17:14.103000

1 posts

The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraSession(), which prefers a session_variables object taken directly from the client-supplied JSON request body over the Authorization header's JWT claims, with no verification that the request actually originated from Hasura. By setting {"session_variab

offseq@infosec.exchange at 2026-08-05T07:30:25.000Z ##

CVE-2026-71214: NASA-AMMOS plandev sequencing-server has a CRITICAL vuln (CVSS 9.8) — unauthenticated users can inject commands by spoofing session roles or using whitelisted endpoints. Patch urgently. More: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #NASA #CyberSec #CVSS

##

CVE-2026-71254
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-05T13:24:49.680000

1 posts

nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record() function (FC 0x14, Read File Record) in nanomodbus.c. The function validates that the total request size does not exceed 245 bytes and that each sub-request's record_length is at most 124, but it never validates the CUMULATIVE response size across all sub-requests before processing them.

offseq@infosec.exchange at 2026-08-05T12:00:26.000Z ##

CVE-2026-71254: CRITICAL out-of-bounds write in debevv nanoMODBUS (≤v1.23.0). Unauthenticated FC 0x14 requests can cause memory corruption, leading to DoS or RCE — especially on embedded targets. Patch/mitigate now. radar.offseq.com/threat/cve-20 #OffSeq #CVE #ICS #infosec

##

CVE-2026-66747
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-05T12:31:36

1 posts

Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP

catc0n@infosec.exchange at 2026-08-05T10:34:45.000Z ##

Today, VulnCheck is disclosing #ENDLESSDOORS, a phone-home implant CTO @albinolobster discovered in Zbtlink routers. ENDLESSDOORS starts automatically, runs with root privileges, and attempts to connect to command-and-control infrastructure roughly every 35 seconds. The backdoor ships by default across 20+ Zbtlink router models, which are white-labeled and sold on popular retail sites including Amazon, AliExpress, and Alibaba.

The implant and server implement no encryption or verification, meaning anyone along the network path can hijack the client-server communication and obtain a root shell on the device, regardless of the router's network position.

The VulnCheck CNA has assigned CVE-2026-66747 to track backdoored firmware versions; our blog also has guidance for defenders, including affected firmware images, hashes, network indicators, a YARA rule, and network signatures (Suricata / Snort).

vulncheck.com/blog/zbt-endless

##

CVE-2026-4431
(9.1 CRITICAL)

EPSS: 0.33%

updated 2026-08-05T09:31:26

1 posts

The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_post()` function in all versions up to, and including, 2.3.0. This is due to the `rbsm_submit_post` AJAX action being registered for unauthenticated users via `wp_ajax_nopriv_rbsm_submit_post` without any authorization checks when a `postId` parameter is

offseq@infosec.exchange at 2026-08-05T09:00:27.000Z ##

CVE-2026-4431: CRITICAL vuln in Easy Post Submission ≤2.3.0 for WordPress. Missing auth lets unauthenticated attackers modify or unpublish any post via AJAX. No patch yet — disable plugin if possible. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #CVE20264431

##

CVE-2026-9198
(9.8 CRITICAL)

EPSS: 17.05%

updated 2026-08-05T05:17:15.823000

4 posts

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments

4 repos

https://github.com/0xdak/CVE-2026-9198_exploit

https://github.com/rmhowe425/PoC-CVE-2026-9198

https://github.com/0xgh057r3c0n/CVE-2026-9198

https://github.com/ywh-jfellus/CVE-2026-9198

beyondmachines1@infosec.exchange at 2026-08-05T20:01:06.000Z ##

Actively Exploited IBM Langflow Vulnerability Allows Unauthenticated Remote Code Execution

IBM Langflow OSS injection vulnerability (CVE-2026-9198)is actively exploited. CISA has added the flaw to its Known Exploited Vulnerabilities catalog and requires immediate patching/

**If you run IBM Langflow OSS (versions 1.0.0 through 1.10.0), update to version 1.10.1 or later immediately. Attackers are already using this flaw to take over servers. If you can't update immediately, take the Langflow instance off the internet, and check your logs for unexpected superuser tokens or odd Python code being run.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

thecybermind@infosec.exchange at 2026-08-04T23:27:59.000Z ##

🚨 CISA KEV ALERT: CVE-2026-9198 identifies a critical unauthenticated code injection flaw in IBM Langflow allowing full RCE on default deployments. Active exploitation confirmed. Get the execution mechanics, CrowdStrike CQL detection, and compensating controls now: thecybermind.co/fi0v

##

secdb@infosec.exchange at 2026-08-04T19:00:11.000Z ##

🚨 [CISA-2026:0804] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-18556 (secdb.nttzen.cloud/cve/detail/)
- Name: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: uptime.n-able.com/ ; status.n-able.com/2026/08/02/n ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34486 (secdb.nttzen.cloud/cve/detail/)
- Name: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Tomcat
- Notes: lists.apache.org/thread/9510k5 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9198 (secdb.nttzen.cloud/cve/detail/)
- Name: IBM Langflow Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: IBM
- Product: Langflow
- Notes: ibm.com/support/pages/node/727 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260804 #cisa20260804 #cve_2026_18556 #cve_2026_34486 #cve_2026_9198 #cve202618556 #cve202634486 #cve20269198

##

cisakevtracker@mastodon.social at 2026-08-04T18:01:22.000Z ##

CVE ID: CVE-2026-9198
Vendor: IBM
Product: Langflow
Date Added: 2026-08-04
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-6837
(7.2 HIGH)

EPSS: 0.95%

updated 2026-08-05T05:17:14.873000

1 posts

A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

hugovalters@mastodon.social at 2026-08-04T14:06:53.000Z ##

CVE-2026-6837 - Post-auth command injection in Zyxel WAX650S export-cgi. Admin RCE. CVSS 7.2. Unpatched - restrict admin access now. #CVE #Zyxel #infosec

valtersit.com/cve/CVE-2026-683

##

CVE-2026-66318
(8.1 HIGH)

EPSS: 0.37%

updated 2026-08-05T05:17:07.877000

1 posts

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

thehackerwire@mastodon.social at 2026-08-04T01:00:05.000Z ##

🟠 CVE-2026-66318 - High (8.1)

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58073
(0 None)

EPSS: 0.22%

updated 2026-08-05T05:17:02.413000

3 posts

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.

beyondmachines1 at 2026-08-06T10:01:09.315Z ##

Veeam Patches Critical Credential Theft and RCE Flaws in Service Provider Console

Veeam patched four vulnerabilities in its Service Provider Console, including critical flaws (CVE-2026-58073 and CVE-2026-58072) that allow unauthenticated credential theft and remote code execution.

**If you run Veeam Service Provider Console version 9.2.1.33875 or any earlier version 9 build, upgrade to version 9.3.0.35057 ASAP. These flaws let attackers take over the console that controls all of your customers' backups. Make sure to lock down the management portal so it's only reachable from a small list of trusted IP addresses, not the open internet.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-08-06T10:01:09.000Z ##

Veeam Patches Critical Credential Theft and RCE Flaws in Service Provider Console

Veeam patched four vulnerabilities in its Service Provider Console, including critical flaws (CVE-2026-58073 and CVE-2026-58072) that allow unauthenticated credential theft and remote code execution.

**If you run Veeam Service Provider Console version 9.2.1.33875 or any earlier version 9 build, upgrade to version 9.3.0.35057 ASAP. These flaws let attackers take over the console that controls all of your customers' backups. Make sure to lock down the management portal so it's only reachable from a small list of trusted IP addresses, not the open internet.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

DailyCyberSecurity@infosec.exchange at 2026-08-04T15:46:09.000Z ##

A critical Veeam Service Provider Console flaw lets attackers steal agent credentials, while a second enables remote code execution. Update to 9.3 now.

#Veeam #VSPC #ServiceProviderConsole #CVE202658073 #RCE #RemoteCodeExecution #Vulnerability #MSP #CyberSecurity #InfoSec

securityonline.info/veeam-vspc

##

CVE-2026-58072
(0 None)

EPSS: 0.38%

updated 2026-08-05T05:17:01.967000

2 posts

A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution.

beyondmachines1 at 2026-08-06T10:01:09.315Z ##

Veeam Patches Critical Credential Theft and RCE Flaws in Service Provider Console

Veeam patched four vulnerabilities in its Service Provider Console, including critical flaws (CVE-2026-58073 and CVE-2026-58072) that allow unauthenticated credential theft and remote code execution.

**If you run Veeam Service Provider Console version 9.2.1.33875 or any earlier version 9 build, upgrade to version 9.3.0.35057 ASAP. These flaws let attackers take over the console that controls all of your customers' backups. Make sure to lock down the management portal so it's only reachable from a small list of trusted IP addresses, not the open internet.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-08-06T10:01:09.000Z ##

Veeam Patches Critical Credential Theft and RCE Flaws in Service Provider Console

Veeam patched four vulnerabilities in its Service Provider Console, including critical flaws (CVE-2026-58073 and CVE-2026-58072) that allow unauthenticated credential theft and remote code execution.

**If you run Veeam Service Provider Console version 9.2.1.33875 or any earlier version 9 build, upgrade to version 9.3.0.35057 ASAP. These flaws let attackers take over the console that controls all of your customers' backups. Make sure to lock down the management portal so it's only reachable from a small list of trusted IP addresses, not the open internet.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-15307
(8.8 HIGH)

EPSS: 0.54%

updated 2026-08-05T05:16:46.480000

1 posts

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by passing it to the `django.contrib.gis.gdal.GDALRaster` constructor. Any value used in a spatial lookup against a `GeometryField` or `RasterField` reaches this constructor, including untrusted input, for example a spatial-field filter subm

CVE-2026-18897
(8.8 HIGH)

EPSS: 0.57%

updated 2026-08-05T03:30:28

1 posts

A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempEntry. The manipulation of the argument tempName leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did no

thehackerwire@mastodon.social at 2026-08-05T06:00:24.000Z ##

🟠 CVE-2026-18897 - High (8.8)

A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempEntry. The manipulation of the argument tempName leads to stack-based buffer overflow. T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70619
(8.8 HIGH)

EPSS: 0.36%

updated 2026-08-05T00:30:46

1 posts

Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend configuration by invoking endpoint management routes that verify session authentication but omit the admin authorization guard. Attackers can supply an attacker-controlled URL to overwrite the embedding backend persisted in the endpoint con

thehackerwire@mastodon.social at 2026-08-04T22:59:59.000Z ##

🟠 CVE-2026-70619 - High (8.8)

Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend configuration by invoking endpoint management routes that verify session authentication...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70553
(9.8 CRITICAL)

EPSS: 0.88%

updated 2026-08-04T21:30:37

2 posts

MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install endpoint after installation is complete. Attackers can supply a malicious db_dbprefix value containing a single quote to break out of a PHP string literal in application/config/databa

1 repos

https://github.com/woshidashabi1126/CVE-2026-70553-PoC

offseq@infosec.exchange at 2026-08-05T01:30:32.000Z ##

CVE-2026-70553: CRITICAL RCE in MaxSite CMS 105.2 (CVSS 9.3). Attackers can inject PHP via POST to the install endpoint, gaining persistent code exec as www-data. Restrict endpoint & monitor traffic until patched. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE #websecurity #RCE

##

thehackerwire@mastodon.social at 2026-08-04T21:00:03.000Z ##

🔴 CVE-2026-70553 - Critical (9.8)

MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install endpoint after installation is...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-69703
(9.8 CRITICAL)

EPSS: 0.46%

updated 2026-08-04T21:30:29

1 posts

Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that ignore redirects. Attackers can invoke destructive admin actions such as record deletion by requesting controller endpoints with GET parameters like supp, because t

thehackerwire@mastodon.social at 2026-08-04T20:00:02.000Z ##

🔴 CVE-2026-69703 - Critical (9.8)

Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that ignore redi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49435
(9.8 CRITICAL)

EPSS: 0.77%

updated 2026-08-04T21:30:28

1 posts

Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with administrative privileges.

thehackerwire@mastodon.social at 2026-08-04T20:00:14.000Z ##

🔴 CVE-2026-49435 - Critical (9.8)

Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with administrative privileges.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18556
(7.4 HIGH)

EPSS: 0.49%

updated 2026-08-04T21:30:26

4 posts

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

1 repos

https://github.com/CreamyG31337/ncentral-compromise-ioc-triage

thecybermind@infosec.exchange at 2026-08-05T17:08:36.000Z ##

🚨 CISA KEV ALERT: CVE-2026-18556 exposes N-able N-central installations to authentication bypass via alternate channel paths. Active exploitation confirmed. Get the forensic breakdown, Splunk/KQL/Chronicle detection logic, and hardening guidance now: thecybermind.co/radr

##

secdb@infosec.exchange at 2026-08-04T19:00:11.000Z ##

🚨 [CISA-2026:0804] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-18556 (secdb.nttzen.cloud/cve/detail/)
- Name: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: uptime.n-able.com/ ; status.n-able.com/2026/08/02/n ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34486 (secdb.nttzen.cloud/cve/detail/)
- Name: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Tomcat
- Notes: lists.apache.org/thread/9510k5 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9198 (secdb.nttzen.cloud/cve/detail/)
- Name: IBM Langflow Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: IBM
- Product: Langflow
- Notes: ibm.com/support/pages/node/727 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260804 #cisa20260804 #cve_2026_18556 #cve_2026_34486 #cve_2026_9198 #cve202618556 #cve202634486 #cve20269198

##

cisakevtracker@mastodon.social at 2026-08-04T18:00:52.000Z ##

CVE ID: CVE-2026-18556
Vendor: N-able
Product: N-central
Date Added: 2026-08-04
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-08-04T14:33:24.000Z ##

CISA added this vulnerability to the catalogue yesterday, if you missed it:

CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability cve.org/CVERecord?id=CVE-2026-

Arctic Wolf: CVE-2026-18556 / CVE-2026-18577: N-able N-central Authentication Bypass Vulnerabilities Require Immediate Patching arcticwolf.com/resources/blog/ #infosec #vulnerability #CISA

##

CVE-2026-15969
(9.8 CRITICAL)

EPSS: 0.98%

updated 2026-08-04T20:43:06.967000

1 posts

SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle payloads.

DailyCyberSecurity@infosec.exchange at 2026-08-05T14:27:11.000Z ##

Six SGLang vulnerabilities include unauthenticated RCE via CVE-2026-15969, plus data and model-weight theft. No patch exists yet.

#SGLang #RCE #LLMSecurity #CVE202615969 #InfoSec

securityonline.info/sglang-vul

##

CVE-2026-70478(CVSS UNKNOWN)

EPSS: 0.38%

updated 2026-08-04T19:37:38

1 posts

### Summary The OAuth2 token refresh endpoint (`POST /api/v1/oauth2-credential/refresh/:credentialId`) is in `WHITELIST_URLS`, meaning it requires **no authentication**. It decrypts the stored credential (containing `clientId`, `clientSecret`, `refresh_token`), sends a refresh request to the configured OAuth provider, and returns the new `access_token` directly in the response body. ### Root Cau

offseq@infosec.exchange at 2026-08-05T03:00:25.000Z ##

FlowiseAI Flowise (<3.1.3) has a CRITICAL vuln (CVE-2026-70478): unauthenticated POST endpoint leaks refreshed OAuth tokens if credential ID is known. Upgrade to 3.1.3+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE202670478 #OAuth #infosec

##

CVE-2026-70477(CVSS UNKNOWN)

EPSS: 0.44%

updated 2026-08-04T19:29:28

1 posts

-- ABSTRACT ------------------------------------- Trend Micro's Zero Day Initiative has identified a vulnerability affecting the following products: Flowise - Flowise -- VULNERABILITY DETAILS ------------------------ * Version tested: 3.1.1 * Installer file: https://github.com/FlowiseAI/Flowise (npm install flowise@3.1.1) * Platform tested: Ubuntu 25.10 --- A prompt injection sent to a chatflo

offseq@infosec.exchange at 2026-08-05T04:30:25.000Z ##

FlowiseAI Flowise <3.1.3 is affected by CRITICAL CVE-2026-70477 (code injection, CVSS 9.5). Exploitation via CSV Agent node allows arbitrary Python execution. Patch to 3.1.3+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #Infosec #CVE #AppSec

##

CVE-2026-18830
(8.1 HIGH)

EPSS: 0.29%

updated 2026-08-04T19:16:45.433000

1 posts

Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this issue. No customer action is required.

awssecurityfeed@infosec.exchange at 2026-08-04T18:00:01.000Z ##

CVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation

Bulletin ID: 2026-073-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/04/2026 10:00 AM PDT
Description:
We have identified CVE-2026-18830 in the Amazon Bedrock AgentCore harness InvokeHarness API...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-24254
(9.8 CRITICAL)

EPSS: 0.45%

updated 2026-08-04T18:31:37

1 posts

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.

CVE-2026-64633(CVSS UNKNOWN)

EPSS: 0.34%

updated 2026-08-04T18:31:36

1 posts

A vulnerability allowing remote unauthenticated code execution on the agent host.

1 repos

https://github.com/tfawnies/CVE-2026-64633

CVE-2026-15920
(6.1 MEDIUM)

EPSS: 0.30%

updated 2026-08-04T18:31:31

1 posts

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating the URL. A value stored with an unsafe scheme is displayed as a link on changelist and read-only admin pages, which allows cross-site scripting against staff users who click the link. Exploitation req

CVE-2026-24083
(7.8 HIGH)

EPSS: 0.11%

updated 2026-08-04T18:31:31

1 posts

Memory Corruption while processing IOCTL device driver requests with invalid arguments.

thehackerwire@mastodon.social at 2026-08-04T17:01:12.000Z ##

🟠 CVE-2026-24083 - High (7.8)

Memory Corruption while processing IOCTL device driver requests with invalid arguments.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-25292
(7.6 HIGH)

EPSS: 0.16%

updated 2026-08-04T18:31:31

1 posts

Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.

thehackerwire@mastodon.social at 2026-08-04T17:01:01.000Z ##

🟠 CVE-2026-25292 - High (7.6)

Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-69100
(8.8 HIGH)

EPSS: 0.55%

updated 2026-08-04T18:31:31

1 posts

LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitelisting. Attackers can write or influence the script field via message template endpoints to execute arbitrary Groovy code and OS commands on the backend

thehackerwire@mastodon.social at 2026-08-04T17:00:15.000Z ##

🟠 CVE-2026-69100 - High (8.8)

LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitel...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-69098
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-08-04T18:31:31

1 posts

kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. Attackers can exploit this to override the __type__ field with subprocess.check_output and arbitrary arguments, achieving remote code execution with appli

1 repos

https://github.com/0xdak/CVE-2026-69098_exploit

thehackerwire@mastodon.social at 2026-08-04T17:00:04.000Z ##

🔴 CVE-2026-69098 - Critical (9.8)

kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. A...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15958
(9.3 CRITICAL)

EPSS: 0.20%

updated 2026-08-04T18:16:45.220000

1 posts

The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers for unauthenticated users, allowing an unauthenticated attacker to list, download and upload arbitrary files across the connected Dropbox account and to read the connected account and administrator email addresses.

offseq@infosec.exchange at 2026-08-04T07:30:25.000Z ##

CVE-2026-15958 (CRITICAL): Easy Integration for Dropbox <2.2.0 suffers from missing authorization, letting unauthenticated users manage Dropbox files and access account emails. Patch or disable plugin. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE #Security

##

CVE-2026-69110
(9.1 CRITICAL)

EPSS: 0.55%

updated 2026-08-04T17:16:59.733000

1 posts

OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints. Attackers can retrieve intermediate audio, video artifacts, and subtitles belonging to other users' jobs, and additionall

thehackerwire@mastodon.social at 2026-08-04T17:00:25.000Z ##

🔴 CVE-2026-69110 - Critical (9.1)

OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48323
(10.0 CRITICAL)

EPSS: 0.62%

updated 2026-08-04T17:16:55.413000

2 posts

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

offseq@infosec.exchange at 2026-08-04T04:30:24.000Z ##

Adobe Campaign Classic is impacted by CVE-2026-48323 (CRITICAL, CVSS 10). Improper neutralization in the template engine allows remote code execution — no user interaction needed. No patch yet. Monitor advisories: radar.offseq.com/threat/cve-20 #OffSeq #Adobe #Vuln #CVE202648323

##

thehackerwire@mastodon.social at 2026-08-04T00:00:03.000Z ##

🔴 CVE-2026-48323 - Critical (10)

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vul...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-24084
(7.5 HIGH)

EPSS: 0.23%

updated 2026-08-04T17:16:52.453000

1 posts

Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.

thehackerwire@mastodon.social at 2026-08-04T17:01:22.000Z ##

🟠 CVE-2026-24084 - High (7.5)

Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48326
(9.9 CRITICAL)

EPSS: 0.48%

updated 2026-08-04T16:16:25.497000

1 posts

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

thehackerwire@mastodon.social at 2026-08-04T00:00:13.000Z ##

🔴 CVE-2026-48326 - Critical (9.9)

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18686
(9.8 CRITICAL)

EPSS: 2.61%

updated 2026-08-04T16:16:21.593000

1 posts

A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web RPC Wrapper. Performing a manipulation results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of

offseq@infosec.exchange at 2026-08-04T01:30:25.000Z ##

CVE-2026-18686: CRITICAL command injection in GL.iNet GL-MT3000 (4.4.0 – 4.4.5). Remote, unauthenticated code execution possible — no patch yet. Limit admin interface exposure & monitor for abuse. radar.offseq.com/threat/cve-20 #OffSeq #CVE #RouterSecurity

##

CVE-2026-18577
(8.1 HIGH)

EPSS: 4.10%

updated 2026-08-04T15:33:20

11 posts

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

2 repos

https://github.com/CreamyG31337/ncentral-compromise-ioc-triage

https://github.com/HORKimhab/CVE-2026-18577

secdb@infosec.exchange at 2026-08-04T19:00:11.000Z ##

🚨 [CISA-2026:0804] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-18556 (secdb.nttzen.cloud/cve/detail/)
- Name: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: uptime.n-able.com/ ; status.n-able.com/2026/08/02/n ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34486 (secdb.nttzen.cloud/cve/detail/)
- Name: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Tomcat
- Notes: lists.apache.org/thread/9510k5 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9198 (secdb.nttzen.cloud/cve/detail/)
- Name: IBM Langflow Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: IBM
- Product: Langflow
- Notes: ibm.com/support/pages/node/727 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260804 #cisa20260804 #cve_2026_18556 #cve_2026_34486 #cve_2026_9198 #cve202618556 #cve202634486 #cve20269198

##

AAKL@infosec.exchange at 2026-08-04T15:28:21.000Z ##

New.

Rapid7: CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official #infosec #vulnerabiity

##

AAKL@infosec.exchange at 2026-08-04T14:33:24.000Z ##

CISA added this vulnerability to the catalogue yesterday, if you missed it:

CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability cve.org/CVERecord?id=CVE-2026-

Arctic Wolf: CVE-2026-18556 / CVE-2026-18577: N-able N-central Authentication Bypass Vulnerabilities Require Immediate Patching arcticwolf.com/resources/blog/ #infosec #vulnerability #CISA

##

youranonnewsirc@nerdculture.de at 2026-08-04T04:26:32.000Z ##

Geopolitical: Trump indicates ongoing talks with Iran for Strait of Hormuz reopening (Aug 3-4), though Tehran denies. Gaza operations persist.
Technology: SK hynix & Sandisk unveil HBF standard for AI memory (Aug 4). White House schedules AI safety talks (Aug 4).
Cybersecurity: CISA alerts to active exploitation of N-able N-central flaw (CVE-2026-18577) (Aug 3). Interpol: AI fuels over 55% of African cybercrime (Aug 3).
#AnonNews_irc #Cybersecurity #News

##

thecybermind@infosec.exchange at 2026-08-03T23:17:37.000Z ##

URGENT C-SUITE BRIEF: Active exploitation verified on CISA KEV for CVE-2026-18577 (N-able N-central). Executive leadership must oversee immediate patch deployment, supply chain auditing, and trust model revalidation to safeguard organizational assets. Full strategic analysis: thecybermind.co/0156

#CyberRisk

##

oversecurity@mastodon.social at 2026-08-03T22:39:19.000Z ##

N-able warns of N-central auth bypass flaw exploited in attacks

N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-...

🔗️ [Bleepingcomputer] link.is.it/tS9UYV

##

oversecurity@mastodon.social at 2026-08-03T22:38:32.000Z ##

N-able warns of N-central auth bypass flaw exploited in attacks

N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-...

🔗️ [Bleepingcomputer] bleepingcomputer.com/news/secu

##

thecybermind@infosec.exchange at 2026-08-03T22:06:53.000Z ##

ALERT: Active exploitation verified for CVE-2026-18577 in N-able N-central. Unauthenticated attackers can execute account takeovers via alternate path manipulation. Access our complete threat breakdown, SPL/KQL detection logic, and hardening guidance here: thecybermind.co/jily

#CyberSecurity #ThreatIntel

##

secdb@infosec.exchange at 2026-08-03T21:00:14.000Z ##

🚨 [CISA-2026:0803] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-18577 (secdb.nttzen.cloud/cve/detail/)
- Name: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: documentation.n-able.com/N-cen ; status.n-able.com/2026/08/02/n ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260803 #cisa20260803 #cve_2026_18577 #cve202618577

##

cisakevtracker@mastodon.social at 2026-08-03T19:00:49.000Z ##

CVE ID: CVE-2026-18577
Vendor: N-able
Product: N-central
Date Added: 2026-08-03
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

DailyCyberSecurity@infosec.exchange at 2026-08-03T16:25:47.000Z ##

CVE-2026-18577 is being exploited in the wild for N-central account takeover. An incomplete patch let attackers gain admin access. Update to 2026.3.1.7.

#Nable #Ncentral #CVE202618577 #AccountTakeover #RMM #CyberSecurity

securityonline.info/cve-2026-1

##

CVE-2026-69240
(9.8 CRITICAL)

EPSS: 0.32%

updated 2026-08-04T15:16:42.087000

1 posts

Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function defined in sql-string.js does not escape quotes if the value starts with TO_TIMESTAMP or TO_DATE. In the Oracle dialect, when val is a string and starts with TO_TIMESTAMP or TO_DATE, escape returns val directly instead of replacing single quotes. An attacke

thehackerwire@mastodon.social at 2026-08-03T22:00:08.000Z ##

🔴 CVE-2026-69240 - Critical (9.8)

Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function defined in sql-string.js does not escape quotes if the value starts with TO_TIMESTAMP or TO_DATE. In the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59639
(0 None)

EPSS: 0.17%

updated 2026-08-04T14:50:12.360000

1 posts

In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).

harrysintonen@infosec.exchange at 2026-08-04T09:28:16.000Z ##

Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:

- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.

bouncycastle.org/resources/new

#infosec #cybersecurity

##

CVE-2026-12816
(0 None)

EPSS: 0.16%

updated 2026-08-04T14:50:12.360000

1 posts

In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

harrysintonen@infosec.exchange at 2026-08-04T09:28:16.000Z ##

Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:

- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.

bouncycastle.org/resources/new

#infosec #cybersecurity

##

CVE-2026-15721
(9.8 CRITICAL)

EPSS: 0.23%

updated 2026-08-04T14:16:30.620000

1 posts

Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

thehackerwire@mastodon.social at 2026-08-04T13:00:22.000Z ##

🔴 CVE-2026-15721 - Critical (9.8)

Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection.

This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14175
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-08-04T12:34:56

2 posts

Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

thehackerwire@mastodon.social at 2026-08-04T13:00:33.000Z ##

🔴 CVE-2026-14175 - Critical (9.8)

Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server.

This issue affects HUMANIST Digital Human Resources: from...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-04T12:00:28.000Z ##

CVE-2026-14175 (CRITICAL, CVSS 9.8): HUMANIST Digital HR v26.0 has an unrestricted file upload flaw — attackers can deploy web shells for full compromise. No patch yet. Restrict uploads, monitor, and apply network controls. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #AppSec

##

CVE-2026-14804
(9.1 CRITICAL)

EPSS: 0.30%

updated 2026-08-04T12:34:56

2 posts

Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

thehackerwire@mastodon.social at 2026-08-04T13:00:08.000Z ##

🔴 CVE-2026-14804 - Critical (9.1)

Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable.

This issue affects HUMANIST Digital Human Resources: from ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-04T10:30:25.000Z ##

CVE-2026-14804: CRITICAL (CVSS 9.1) in HUMANIST Digital HR v26.0 🛡️ Hard-coded cryptographic key (CWE-321) allows data exposure & integrity loss. No official fix — limit access & track vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #CVE202614804

##

CVE-2026-18754
(9.1 CRITICAL)

EPSS: 0.31%

updated 2026-08-04T09:31:41

1 posts

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing.

offseq@infosec.exchange at 2026-08-04T09:00:29.000Z ##

CVE-2026-18754: GeoVision GV-AS1620 (GV-Cloud) v1.16 has a CRITICAL bug — static RSA key in firmware lets attackers decrypt HTTPS & spoof server. No fix yet; restrict access & watch for vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Cybersecurity #TLS

##

CVE-2026-9044
(0 None)

EPSS: 0.97%

updated 2026-08-04T05:16:40.213000

1 posts

An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. The issue arises from improper filtering of special characters.  Successful exploitation of this vulnerability may enable an attacker to

CVE-2026-62354(CVSS UNKNOWN)

EPSS: 0.26%

updated 2026-08-04T00:35:57

1 posts

Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read access to invoke predefined component validation methods with alternative settings. Apache NiFi installations that do not implement different levels of

DailyCyberSecurity@infosec.exchange at 2026-08-04T01:52:18.000Z ##

Apache NiFi vulnerabilities, including CVE-2026-68979, CVE-2026-62354, and CVE-2026-68981, expose users to code execution and resource consumption.

#ApacheNiFi #CyberSecurity #Vulnerabilities #CVE #InfoSec

securityonline.info/apache-nif

##

CVE-2026-48333
(9.8 CRITICAL)

EPSS: 0.47%

updated 2026-08-04T00:35:01

1 posts

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain elevated privileges. Exploitation of this issue does not require user interaction.

offseq@infosec.exchange at 2026-08-04T06:00:24.000Z ##

CVE-2026-48333 (CRITICAL, CVSS 9.8): Incorrect Authorization in Adobe Campaign Classic enables attackers to escalate privileges without user interaction. No patch info yet — monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #Adobe #Security #CVE202648333

##

CVE-2026-18684
(9.8 CRITICAL)

EPSS: 2.03%

updated 2026-08-04T00:35:01

1 posts

A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure and confir

offseq@infosec.exchange at 2026-08-04T03:00:29.000Z ##

CVE-2026-18684 | CRITICAL command injection in GL.iNet GL-MT3000 (fw 4.4.0 – 4.4.5) 🛡️ Remote attackers can execute commands — no patch yet. Restrict access and watch for vendor updates. Info: radar.offseq.com/threat/cve-20 #OffSeq #CVE202618684 #IoTSecurity

##

CVE-2026-48331
(10.0 CRITICAL)

EPSS: 0.47%

updated 2026-08-04T00:35:01

1 posts

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-66310
(7.7 HIGH)

EPSS: 0.40%

updated 2026-08-04T00:35:01

1 posts

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

thehackerwire@mastodon.social at 2026-08-04T01:00:15.000Z ##

🟠 CVE-2026-66310 - High (7.7)

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18685
(9.8 CRITICAL)

EPSS: 1.99%

updated 2026-08-04T00:35:01

1 posts

A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure and confirmed the existence of t

offseq@infosec.exchange at 2026-08-04T00:00:36.000Z ##

CVE-2026-18685: CRITICAL command injection in GL.iNet GL-MT3000 (4.4.0 – 4.4.5). Remote, unauthenticated RCE possible. No patch yet — restrict access & monitor for abuse. Details: radar.offseq.com/threat/cve-20 #OffSeq #vuln #IoT #infosec

##

CVE-2026-48330
(10.0 CRITICAL)

EPSS: 0.68%

updated 2026-08-04T00:35:01

1 posts

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially gaining elevated access or control over the application. Exploitation of this is

thehackerwire@mastodon.social at 2026-08-04T00:00:24.000Z ##

🔴 CVE-2026-48330 - Critical (10)

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could e...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66315
(7.5 HIGH)

EPSS: 0.62%

updated 2026-08-04T00:34:55

1 posts

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-08-04T01:00:25.000Z ##

🟠 CVE-2026-66315 - High (7.5)

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59912
(7.8 HIGH)

EPSS: 0.10%

updated 2026-08-03T21:31:36

1 posts

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and arbitrary code execution.

thehackerwire@mastodon.social at 2026-08-03T20:00:11.000Z ##

🟠 CVE-2026-59912 - High (7.8)

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18108
(9.8 CRITICAL)

EPSS: 0.22%

updated 2026-08-03T20:17:14.513000

1 posts

Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature. _verify_encrypted_assertion decrypts the EncryptedAssertion and returns it as verified when it carries no signature, via "return $xml unless $xpath->exists('dsig:Signature', $assert);". The signature check and the trus

hugovalters@mastodon.social at 2026-08-03T23:11:09.000Z ##

CVE-2026-18108 - Critical auth bypass in Perl Net::SAML2. Encrypted assertions without signatures accepted. CVSS 9.8. Upgrade to >=0.86 now. #CVE #Perl #infosec

valtersit.com/cve/cve-2026-181

##

CVE-2026-18614
(9.8 CRITICAL)

EPSS: 2.01%

updated 2026-08-03T19:16:45.200000

1 posts

A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure and conf

thehackerwire@mastodon.social at 2026-08-03T20:00:35.000Z ##

🔴 CVE-2026-18614 - Critical (9.8)

A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command injection...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18574(CVSS UNKNOWN)

EPSS: 0.99%

updated 2026-08-03T15:32:49

1 posts

An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered

CVE-2026-33591(CVSS UNKNOWN)

EPSS: 0.52%

updated 2026-08-03T12:32:43

1 posts

A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass security restriction using a specially crafted packet and retrieve a valid session token for the targeted account.

CVE-2026-5674
(8.8 HIGH)

EPSS: 0.13%

updated 2026-08-03T09:33:40

1 posts

A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.

jfkimmes@tinycyber.space at 2026-08-05T07:02:17.000Z ##

Simple Flatpak sandbox escape through pipewire:
1. Missing auth 2. Insecure default module loader

Vulns like these do not exist because devs lack the capability to look for them, but they lack the capacity.

I predict this class of issue will soon™️ cease to exist. LLM harnesses like the one used by Johann are getting productized at scale currently. The question is just how cheap can we make them and how quickly can we get them into CI pipelines.
embracethered.com/blog/posts/2

#AI #LLM #InfoSec

##

CVE-2026-8763(CVSS UNKNOWN)

EPSS: 0.33%

updated 2026-08-03T09:32:36

1 posts

In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

1 repos

https://github.com/xiaoqiMikko/bc-check

harrysintonen@infosec.exchange at 2026-08-04T09:28:16.000Z ##

Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:

- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.

bouncycastle.org/resources/new

#infosec #cybersecurity

##

CVE-2026-12803(CVSS UNKNOWN)

EPSS: 0.17%

updated 2026-08-03T09:32:36

1 posts

In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy Castle for Java LTS before 2.73.12.

harrysintonen@infosec.exchange at 2026-08-04T09:28:16.000Z ##

Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:

- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.

bouncycastle.org/resources/new

#infosec #cybersecurity

##

CVE-2026-58062(CVSS UNKNOWN)

EPSS: 0.20%

updated 2026-08-03T09:32:36

1 posts

In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

1 repos

https://github.com/xiaoqiMikko/bc-check

harrysintonen@infosec.exchange at 2026-08-04T09:28:16.000Z ##

Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:

- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.

bouncycastle.org/resources/new

#infosec #cybersecurity

##

CVE-2026-58061(CVSS UNKNOWN)

EPSS: 0.21%

updated 2026-08-03T09:32:36

1 posts

In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

harrysintonen@infosec.exchange at 2026-08-04T09:28:16.000Z ##

Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:

- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.

bouncycastle.org/resources/new

#infosec #cybersecurity

##

CVE-2026-12569
(9.8 CRITICAL)

EPSS: 30.20%

updated 2026-08-01T05:16:55.023000

4 posts

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

1 repos

https://github.com/west-wind/Threat-Hunting-With-Splunk

undercodenews@mastodon.social at 2026-08-06T09:32:19.000Z ##

Dark Web Ransomware Watch: Clop Claims Attack on Engineering Target Using CVE-2026-12569 to Steal Sensitive Data + Video

Introduction: A New Chapter in the Ransomware War Ransomware groups continue to evolve beyond simple file encryption, increasingly focusing on data theft, intellectual property harvesting, and exploitation of newly discovered vulnerabilities. A recent claim attributed to the notorious Clop ransomware operation suggests another targeted attack…

undercodenews.com/dark-web-ran

##

undercodenews@mastodon.social at 2026-08-06T05:42:03.000Z ##

Clop Ransomware Strikes Again: New Attack Exploits CVE-2026-12569 to Steal Database and Project Data + Video

A New Wave of Cyber Extortion Targets Critical Business Data The ransomware landscape continues to evolve as threat actors increasingly combine advanced exploitation techniques with aggressive data theft operations. A new incident linked to the Clop ransomware group highlights this growing danger, with reports indicating that attackers compromised a targeted…

undercodenews.com/clop-ransomw

##

undercodenews@mastodon.social at 2026-08-06T05:30:28.000Z ##

Clop Ransomware Exploits New Vulnerability to Target Enterprise Data, Raising Fresh Concerns Over Supply Chain Security + Video

A New Cybersecurity Threat Emerges Through CVE-2026-12569 The cybersecurity landscape continues to face a growing wave of sophisticated attacks as threat groups adapt their strategies around newly discovered vulnerabilities. The Clop ransomware operation has reportedly targeted an organization through CVE-2026-12569, claiming that it…

undercodenews.com/clop-ransomw

##

undercodenews@mastodon.social at 2026-08-06T04:23:02.000Z ##

Clop Ransomware Strikes Again: New Attack Exploits CVE-2026-12569 to Steal Sensitive Project and Software Data + Video

Introduction: A New Warning Sign in the Growing Ransomware War The ransomware landscape continues to evolve as cybercriminal groups become more aggressive, technically advanced, and focused on exploiting newly discovered vulnerabilities before organizations can fully defend their systems. A recent cybersecurity alert highlights another dangerous…

undercodenews.com/clop-ransomw

##

CVE-2026-58048(CVSS UNKNOWN)

EPSS: 0.50%

updated 2026-07-31T18:32:25

1 posts

Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

2 repos

https://github.com/imbas007/POC-CVE-2026-58048

https://github.com/tc4dy/CVE-2026-58048-PoC-Exploit

CVE-2026-12943
(9.8 CRITICAL)

EPSS: 0.92%

updated 2026-07-30T21:31:50

1 posts

IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.

DailyCyberSecurity@infosec.exchange at 2026-08-05T13:47:16.000Z ##

IBM critical vulnerabilities hit App Connect, Power HMC, and webMethods. CVE-2026-12943 lets attackers execute arbitrary commands at CVSS 9.8.

#IBM #CVE202612943 #RCE #InfoSec #VulnerabilityManagement

securityonline.info/ibm-critic

##

CVE-2026-51291
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-07-30T21:31:47

1 posts

sqlite 3.41 is vulnerable to use after free in the json.c jsonCacheInsert function of the JSON cache management module.

nyanbinary@infosec.exchange at 2026-08-03T18:39:18.000Z ##

Ok, the first one is absolutely it:

Furthermore, we deploy MLG-UAF to conduct large-scale security auditing on mainstream open-source software such as libtiff, LibRaw, SQLite, ImageMagick and Zephyr RTOS. In real-world industrial source code scanning, our framework successfully discovered 17 unique confirmed UAF vulnerabilities assigned with independent Common Vulnerabilities and Exposures (CVE) IDs (CVE-2026 series, RESERVED and not yet publicized), covering cross-functional kernel UAF, intra-procedural cache UAF, race-condition UAF and multimedia parsing UAF scenarios.Real CVE case studies on CVE-2026-51291 (SQLite JSON cache flaw) and CVE-2023-32233 (Linux netfilter kernel vulnerability) demonstrate that MLG-UAF can precisely capture the fixed free-then-use spatial topological fingerprint of UAF defects and accurately resolve ambiguous multi-level pointer aliasing, even under heavy control-flow obfuscation.

##

CVE-2026-67192
(8.1 HIGH)

EPSS: 0.62%

updated 2026-07-30T20:04:51.110000

1 posts

Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows unauthenticated attackers to corrupt stack memory by sending malformed SSH packets when a GCM cipher is negotiated. Attackers can craft packets with an unvalidated length field passed directly to the GCM decrypt function, overwriting the stack cookie and return address to potentially achiev

CVE-2026-41709
(2.7 LOW)

EPSS: 0.38%

updated 2026-07-30T19:07:59.843000

1 posts

VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged.

AAKL@infosec.exchange at 2026-08-04T14:53:52.000Z ##

New;

Broadcom has released advisories relating to several high and medium-severity vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

Nvidia:

CRITICAL: NVIDIA Dynamo - July 2026 nvidia.custhelp.com/app/answer

NVIDIA Triton Inference Server - June 2026 nvidia.custhelp.com/app/answer #Nvidia

Dell:

Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #Apache

Google:

This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) support.broadcom.com/web/ecx/s #google #infosec #vulnerability

##

CVE-2026-66066(CVSS UNKNOWN)

EPSS: 1.70%

updated 2026-07-30T18:23:34

3 posts

### Impact In its default configuration, a Rails application that displays image variants may allow an unauthenticated attacker to read arbitrary files from the server, including the process environment. That environment typically holds `secret_key_base` and often credentials for external systems, which may in turn allow escalation to remote code execution or lateral movement to those systems. ##

7 repos

https://github.com/paveg/rails-activestorage-vips-audit

https://github.com/Zer0SumGam3/CVE-2026-66066-POC

https://github.com/0xsha/KindaRails2Shell

https://github.com/0xBlackash/CVE-2026-66066

https://github.com/shinthink/CVE-2026-66066

https://github.com/rails/rails-forensics-CVE-2026-66066

https://github.com/HackSpeak/CVE-2026-66066

security_crawler_carl at 2026-08-06T02:29:26.123Z ##

🏆 New Achievement! Upload In Peace, Active Storage!

We are gathered here today to mourn Active Storage, the earnest, overly-trusting file-handling component of Ruby on Rails, taken from us by CVE-2026-66066, nicknamed "KindaRails2Shell." It lived as it worked: accepting everything without question, like a golden retriever at a buffet. (1/3)

##

security_crawler_carl@infosec.exchange at 2026-08-06T02:29:26.000Z ##

🏆 New Achievement! Upload In Peace, Active Storage!

We are gathered here today to mourn Active Storage, the earnest, overly-trusting file-handling component of Ruby on Rails, taken from us by CVE-2026-66066, nicknamed "KindaRails2Shell." It lived as it worked: accepting everything without question, like a golden retriever at a buffet. (1/3)

##

DailyCyberSecurity@infosec.exchange at 2026-08-04T07:28:39.000Z ##

A critical KindaRails2Shell Rails RCE flaw (CVE-2026-66066) in Active Storage exposes servers to secret theft and remote code execution via image uploads.

#RubyOnRails #KindaRails2Shell #CVE202666066 #Cybersecurity #WebSecurity

meterpreter.org/kindarails2she

##

CVE-2026-47876
(9.3 CRITICAL)

EPSS: 0.28%

updated 2026-07-30T15:31:54

1 posts

VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.

AAKL@infosec.exchange at 2026-08-04T14:53:52.000Z ##

New;

Broadcom has released advisories relating to several high and medium-severity vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

Nvidia:

CRITICAL: NVIDIA Dynamo - July 2026 nvidia.custhelp.com/app/answer

NVIDIA Triton Inference Server - June 2026 nvidia.custhelp.com/app/answer #Nvidia

Dell:

Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #Apache

Google:

This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) support.broadcom.com/web/ecx/s #google #infosec #vulnerability

##

CVE-2026-59309
(9.8 CRITICAL)

EPSS: 0.74%

updated 2026-07-30T15:31:54

1 posts

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

AAKL@infosec.exchange at 2026-08-04T14:53:52.000Z ##

New;

Broadcom has released advisories relating to several high and medium-severity vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

Nvidia:

CRITICAL: NVIDIA Dynamo - July 2026 nvidia.custhelp.com/app/answer

NVIDIA Triton Inference Server - June 2026 nvidia.custhelp.com/app/answer #Nvidia

Dell:

Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #Apache

Google:

This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) support.broadcom.com/web/ecx/s #google #infosec #vulnerability

##

CVE-2026-59310
(9.8 CRITICAL)

EPSS: 1.14%

updated 2026-07-30T15:31:51

1 posts

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

AAKL@infosec.exchange at 2026-08-04T14:53:52.000Z ##

New;

Broadcom has released advisories relating to several high and medium-severity vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

Nvidia:

CRITICAL: NVIDIA Dynamo - July 2026 nvidia.custhelp.com/app/answer

NVIDIA Triton Inference Server - June 2026 nvidia.custhelp.com/app/answer #Nvidia

Dell:

Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #Apache

Google:

This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) support.broadcom.com/web/ecx/s #google #infosec #vulnerability

##

CVE-2026-41703
(7.6 HIGH)

EPSS: 0.56%

updated 2026-07-30T15:31:50

1 posts

VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.

AAKL@infosec.exchange at 2026-08-04T14:53:52.000Z ##

New;

Broadcom has released advisories relating to several high and medium-severity vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

Nvidia:

CRITICAL: NVIDIA Dynamo - July 2026 nvidia.custhelp.com/app/answer

NVIDIA Triton Inference Server - June 2026 nvidia.custhelp.com/app/answer #Nvidia

Dell:

Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #Apache

Google:

This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) support.broadcom.com/web/ecx/s #google #infosec #vulnerability

##

CVE-2026-16498
(10.0 CRITICAL)

EPSS: 0.33%

updated 2026-07-30T14:08:23.057000

1 posts

The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform token to be used to execute tool calls on behalf of subsequent users. This vulnerability, CVE-2026-16498, is fixed in terraform-mcp-server 1.1.0.

CVE-2026-20316
(5.3 MEDIUM)

EPSS: 0.79%

updated 2026-07-29T21:31:00

1 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged&nbsp;account. An attacker could exploit this vuln

AAKL@infosec.exchange at 2026-08-05T15:17:35.000Z ##

Broadcom has addressed several vulnerabilities published yesterday, all of them ranked high-severity support.broadcom.com/web/ecx/s #Broadcom

Cisco has a new advisory for a critical vulnerability that was published yesterday:

CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

This addresses a vulnerability that was first published on July 29:

High: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

CVE-2026-53264
(7.8 HIGH)

EPSS: 0.21%

updated 2026-07-29T21:30:47

1 posts

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: use RCU with deferred freeing for action lifecycle When NEWTFILTER and DELFILTER are run concurrently it is possible to create a race with an associated action. Let's illustrate with CPU0 running NEWTFILTER and CPU1 running DELFILTER: 0: mutex_lock() <-- holds the idr lock 0: rcu_read_lock() 0: p = idr_f

1 repos

https://github.com/HORKimhab/CVE-2026-53264

DailyCyberSecurity@infosec.exchange at 2026-08-04T13:03:09.000Z ##

A Linux kernel vulnerability, CVE-2026-53264, lets a local user run arbitrary code via a net/sched use-after-free. A public PoC is now available.

#CVE202653264 #LinuxKernel #UseAfterFree #PrivilegeEscalation #InfoSec

securityonline.info/linux-kern

##

CVE-2026-31431
(7.8 HIGH)

EPSS: 94.55%

updated 2026-07-28T14:54:01.770000

1 posts

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just

100 repos

https://github.com/erlangparasu/mitigate_cve_2026_31431-sh

https://github.com/ben-slates/CVE-2026-31431-Exploit

https://github.com/M4xSec/CVE-2026-31431-RCE-Exploit

https://github.com/mym0us3r/COPY-FAIL-Detection-with-Wazuh-4.14.4

https://github.com/Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431

https://github.com/cyber-joker/copy-fail-python

https://github.com/Smarttfoxx/copyfail

https://github.com/bootsareme/copyfail-deconstructed

https://github.com/rootsecdev/cve_2026_31431

https://github.com/0xBlackash/CVE-2026-31431

https://github.com/Alfredooe/CVE-2026-31431

https://github.com/povzayd/CVE-2026-31431

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC

https://github.com/bigwario/copy-fail-CVE-2026-31431-C

https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit

https://github.com/AdityaBhatt3010/CVE-2026-31431

https://github.com/lonelyor/CVE-2026-31431-exp

https://github.com/TheMalwareGuardian/CVE-2026-31431

https://github.com/MrAriaNet/cPanel-Fix

https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag

https://github.com/desultory/CVE-2026-31431

https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe

https://github.com/insomnisec/Detections-CVE-2026-31431

https://github.com/Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail

https://github.com/rvzsec/CVE-2026-31431

https://github.com/yxdm02/CVE-2026-31431

https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit

https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431

https://github.com/cozystack/copy-fail-blocker

https://github.com/ncmprbll/copy-fail-rs

https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail

https://github.com/jbnetwork-git/copy-fail-check

https://github.com/luotian2/CVE-2026-31431

https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE

https://github.com/ExploitEoom/CVE-2026-31431

https://github.com/sec17br/CVE-2026-31431-Copy-Fail

https://github.com/kvakirsanov/CVE-2026-31431-live-process-code-injection

https://github.com/painoob/Copy-Fail-Exploit-CVE-2026-31431

https://github.com/mrunalp/block-copyfail

https://github.com/g1nt0n1x/copy-fail-CVE-2026-31431-shell

https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431

https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs

https://github.com/Juguitos/copy-fail

https://github.com/samanzamani/copy-fail-checker

https://github.com/kinryulabs/rootpacket-cve-2026-31431

https://github.com/Dabbleam/CVE-2026-31431-mitigation

https://github.com/SeanRickerd/cve-2026-31431

https://github.com/ZephrFish/CopyFail-CVE-2026-31431

https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script

https://github.com/1neptune/CopyFail

https://github.com/diemoeve/copyfail-rs

https://github.com/ErdemOzgen/copy-fail-cve-2026-31431

https://github.com/Boos4721/copyfail-rs

https://github.com/malwarekid/CVE-2026-31431

https://github.com/haydenjames/CVE-2026-31431-check

https://github.com/guiimoraes/CVE-2026-31431

https://github.com/adysec/cve-2026-31431

https://github.com/wgnet/wg.copyfail.patch

https://github.com/AliHzSec/CVE-2026-31431

https://github.com/KaraZajac/DIRTYFAIL

https://github.com/professional-slacker/alg_check

https://github.com/sgkdev/page_inject

https://github.com/kadir/copy-fail-CVE-2026-31431-IOC

https://github.com/mahdi13830510/CVE-2026-31431-mitigation-suite

https://github.com/yandex-cloud-examples/yc-mk8s-copy-fail-mitigation

https://github.com/pascal-gujer/CVE-2026-31431

https://github.com/H1d3r/copy-fail_LPE_Interactive

https://github.com/JuanBindez/CVE-2026-31431

https://github.com/0xShe/CVE-2026-31431

https://github.com/qi4L/CVE-2026-31431-Container-Escape

https://github.com/philfry/cve-2026-31431-ftrace

https://github.com/abdullaabdullazade/CVE-2026-31431

https://github.com/wuwu001/CVE-2026-31431-exploit

https://github.com/atgreen/block-copyfail

https://github.com/Shotafry/CopyFail-Exploits-CVE-2026-31431

https://github.com/novysodope/copy-fail-CVE-2026-31431-C

https://github.com/Sl4cK0TH/CVE-2026-31431-PoC

https://github.com/4xura/CVE-2026-31431-Copy-Fail

https://github.com/sgkdev/ptrace_may_dream

https://github.com/yuspring/cve-2026-31431-poc

https://github.com/MartinPham/copy-fail-CVE-2026-31431-php

https://github.com/pedromizz/copy-fail

https://github.com/XsanFlip/CVE-2026-31431-Patch

https://github.com/JnamerZ/CopyFail-CVE-2026-31431

https://github.com/xeloxa/copyfail-exploit

https://github.com/Iamliuxiaozhen/copy_fail

https://github.com/st4rburn/public-passwd

https://github.com/scriptzteam/Paranoid-Copy-Fail-CVE-2026-31431

https://github.com/b5null/CVE-2026-31431-C

https://github.com/cs8425/copy-fail-go

https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized

https://github.com/sammwyy/copyfail-rs

https://github.com/aestechno/cve-2026-31431-ansible

https://github.com/Xerxes-2/CVE-2026-31431-rs

https://github.com/wesmar/CVE-2026-31431

https://github.com/badsectorlabs/copyfail-go

https://github.com/tgies/copy-fail-c

https://github.com/theori-io/copy-fail-CVE-2026-31431

https://github.com/Huchangzhi/autorootlinux

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC

certvde@infosec.exchange at 2026-08-04T07:02:03.000Z ##

#OT #Advisory VDE-2026-072
Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI

The Linux kernel used in the IndustrialPI, 'linux-image-revpi-v8', prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.
#CVE CVE-2026-43284, CVE-2026-46300, CVE-2026-31431

certvde.com/en/advisories/vde-

#CSAF pilz.csaf-tp.certvde.com/.well

##

CVE-2026-12495
(0 None)

EPSS: 0.16%

updated 2026-07-28T08:17:14.187000

1 posts

Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys MB115-4G device's web interface. An unauthenticated attacker could exploit this vulnerability by sending a specially crafted request to the /cgi/login endpoint, causing memory corruption and the httpd process to crash, resulting in a denial of service for the web administration se

CVE-2026-39868
(9.1 CRITICAL)

EPSS: 0.94%

updated 2026-07-27T21:16:51.020000

2 posts

This issue was addressed with improved input validation. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.

CVE-2026-50522
(9.8 CRITICAL)

EPSS: 75.76%

updated 2026-07-23T15:44:10.873000

1 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

5 repos

https://github.com/webshellseo8/CVE-2026-50522-Proof-of-Concept

https://github.com/HORKimhab/CVE-2026-50522

https://github.com/darses/CVE-2026-50522

https://github.com/ChPratik/CVE-2026-50522

https://github.com/4minx/CVE-2026-50522

thecybermind@infosec.exchange at 2026-08-03T17:27:38.000Z ##

(CISA TS-SOC) CVE-2026-50522 – Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Severity: CRITICAL Impact Summary: An unauthorized attacker could exploit a deserialization vulnerability in Microsoft SharePoint to execute arbitrary code over a network....

thecybermind.co/2026/08/03/cis

##

certvde@infosec.exchange at 2026-08-04T07:02:03.000Z ##

#OT #Advisory VDE-2026-072
Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI

The Linux kernel used in the IndustrialPI, 'linux-image-revpi-v8', prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.
#CVE CVE-2026-43284, CVE-2026-46300, CVE-2026-31431

certvde.com/en/advisories/vde-

#CSAF pilz.csaf-tp.certvde.com/.well

##

CVE-2026-50343
(7.8 HIGH)

EPSS: 3.50%

updated 2026-07-22T16:17:42.747000

1 posts

Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.

1 repos

https://github.com/Rat5ak/CVE-2026-50343-InstallService-EoP

DailyCyberSecurity@infosec.exchange at 2026-08-04T13:03:56.000Z ##

Details and proof-of-concept exploit code for CVE-2026-50343 are now public. The Windows privilege escalation flaw hands standard users SYSTEM privileges.

#CVE202650343 #Windows #PrivilegeEscalation #LPE #InfoSec

securityonline.info/cve-2026-5

##

CVE-2026-15410
(7.2 HIGH)

EPSS: 76.35%

updated 2026-07-16T05:16:18.470000

2 posts

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

3 repos

https://github.com/tc4dy/CVE-2026-15409-15410-Framework

https://github.com/HORKimhab/CVE-2026-15410

https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check

ransomnews.online@bsky.brid.gy at 2026-08-06T09:24:25.000Z ##

🚨 INC Ransomware chains SonicWall zero-days for ransomware

The group exploited CVE-2026-15409 and CVE-2026-15410 to steal data and deploy ransomware.
🔗 read more: cyberscoop.com/inc-r...

#ransomNews #cybersecurity


Prolific ransomware group behi...

##

kev_Stalker@infosec.exchange at 2026-08-04T02:40:18.000Z ##

CVE-2026-15410 - Changed to Known Ransomware Status

SonicWall SMA1000 Appliances Code Injection VulnerabilityVendor: SonicWallProduct: SMA1000 AppliancesSonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-15409
(10.0 CRITICAL)

EPSS: 78.44%

updated 2026-07-16T05:16:18.293000

2 posts

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

6 repos

https://github.com/HORKimhab/CVE-2026-15409

https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check

https://github.com/Ch4120N/CVE-2026-15409

https://github.com/0xBlackash/CVE-2026-15409

https://github.com/tc4dy/CVE-2026-15409-15410-Framework

https://github.com/remmons-r7/rapid7-CVE-2026-15409

ransomnews.online@bsky.brid.gy at 2026-08-06T09:24:25.000Z ##

🚨 INC Ransomware chains SonicWall zero-days for ransomware

The group exploited CVE-2026-15409 and CVE-2026-15410 to steal data and deploy ransomware.
🔗 read more: cyberscoop.com/inc-r...

#ransomNews #cybersecurity


Prolific ransomware group behi...

##

kev_Stalker@infosec.exchange at 2026-08-04T02:35:33.000Z ##

CVE-2026-15409 - Changed to Known Ransomware Status

SonicWall SMA1000 Appliances Server-Side Request Forgery VulnerabilityVendor: SonicWallProduct: SMA1000 AppliancesSonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.Status changed from Unknown to Known for ransomware campaign usage.Flip nvd.nist.gov/vuln/detail/CVE-2

##

tugatech@masto.pt at 2026-08-03T16:30:24.000Z ##

A Microsoft acaba de corrigir a falha Certighost, que permitia a um utilizador com acessos básicos manipular o sistema de cadastro e obter um certificado válido em nome de um Controlador de Domínio, assumindo a gestão absoluta de uma rede Windows. A falha, classificada como de gravidade alta, foi corrigida com a CVE-2026-54121. 🛡️

🔗 tugatech.com.pt/t88505-microso

#controlo #falha #microsoft 

##

CVE-2026-43284
(7.8 HIGH)

EPSS: 93.23%

updated 2026-07-14T15:31:59

1 posts

In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first make a private copy. The IPv4/IPv6 datagram append paths did not set this flag when

44 repos

https://github.com/Aiyakami/rust_dirtyfrag

https://github.com/haydenjames/dirty-frag-check

https://github.com/RevyHub/CVE-2026-43284---DirtyFrag-Analysis-THM-

https://github.com/AK777177/Dirty-Frag-Analysis

https://github.com/lukeslp/redtail-ioc

https://github.com/0xlane/pagecache-guard

https://github.com/jayhutajulu1/CVE-2026-43284-DirtyFrag-PoC

https://github.com/millikanjohnl-blip/dirtyfrag-detection-rules

https://github.com/cumakurt/linuxpi

https://github.com/liamromanis101/DirtyFrag-Detector

https://github.com/krisiasty/vcheck

https://github.com/dixyes/dirtypatch

https://github.com/nonameuserosint-hue/DirtyFrag-go

https://github.com/DylanClaudio/Reporte-de-Escalada-de-Privilegios-Local-Dirty-Frag

https://github.com/aettern/copyfrag-fuse

https://github.com/LucasPDiniz/CVE-2026-43284

https://github.com/MadExploits/CVE-2026-46300

https://github.com/KaraZajac/DIRTYFAIL

https://github.com/XRSecCD/202605_dirty_frag

https://github.com/scriptzteam/Paranoid-Dirty-Frag-CVE-2026-43284

https://github.com/6abc/Copy-Fail-CVE-2026-31431-dirty-frag-CVE-2026-43284

https://github.com/metalx1993/dirtyfrag-patches

https://github.com/kuniyal08/Dirty-Frag-CVE-2026-43284

https://github.com/gagaltotal/CVE-2026-43284-CVE-2026-43500-scan

https://github.com/suominen/CVE-2026-43284

https://github.com/linnemanlabs/dirtyfrag-arm64

https://github.com/AtlasVector/Dirty-Frag-CVE-2026-43284

https://github.com/Percivalll/Dirty-Frag-Kubernetes-PoC

https://github.com/ChernStepanov/DirtyFrag-for-dummies

https://github.com/xd20111/CVE-2026-43284

https://github.com/ryan2929/CVE-2026-43284-

https://github.com/1neptune/DirtyFrag

https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag

https://github.com/grabesec/XCP_ng_CVE-2026-43284_tester

https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe

https://github.com/0xBlackash/CVE-2026-43284

https://github.com/nabhan-mohy/Dirty-Frag-Research-CVE-2026-43284-

https://github.com/g0thamRabb1t/CVE-2026-43284-dirtyfrag-detection

https://github.com/armircetaj/tetragon-dirtyfrag

https://github.com/t1ckprivate/CVE-2026-43284-Dirty-Frag

https://github.com/FrosterDL/CVE-2026-43284

https://github.com/mym0us3r/DIRTY-FRAG-Detection-with-Wazuh-4.14.4

https://github.com/attaattaatta/CVE-2026-43500

https://github.com/First-John/cve_2026_frag_family_fix

certvde@infosec.exchange at 2026-08-04T07:02:03.000Z ##

#OT #Advisory VDE-2026-072
Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI

The Linux kernel used in the IndustrialPI, 'linux-image-revpi-v8', prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.
#CVE CVE-2026-43284, CVE-2026-46300, CVE-2026-31431

certvde.com/en/advisories/vde-

#CSAF pilz.csaf-tp.certvde.com/.well

##

CVE-2026-59726
(10.0 CRITICAL)

EPSS: 0.48%

updated 2026-07-10T19:15:15.780000

2 posts

Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without authentication, allowing an unauthenticated network attacker to invoke tools/call to terminal_execute, obtain a shell in the bridge container, read provider API keys, and poison AgentDB learning-store patterns.

1 repos

https://github.com/HORKimhab/CVE-2026-59726

DailyCyberSecurity@infosec.exchange at 2026-08-04T12:32:47.000Z ##

RufRoot CVE-2026-59726: Unauthenticated RCE in Ruflo MCP Bridge Exposes AI Agent Keys

meterpreter.org/rufroot-cve-20

##

security_crawler_carl@infosec.exchange at 2026-08-04T07:04:17.000Z ##

🏆 New Achievement! RufRoot Has Entered The Arena!

PHASE ONE BEGINS. The challenger: CVE-2026-59726, alias RufRoot, a CVSS 10.0 critical flaw in the open-source AI agent platform Ruflo. Its special move — exploiting an exposed Model Context Protocol bridge to hand unauthenticated attackers full control of enterprise AI environments. No credentials required. No mercy shown. Noma Security surfaced this beast hiding in every Ruflo version before 3.16.3.

This is not a warm-up encounter. (1/2)

##

CVE-2026-46113
(8.8 HIGH)

EPSS: 0.15%

updated 2026-06-24T18:32:31

1 posts

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN The shadow MMU computes GFNs for direct shadow pages using sp->gfn plus the SPTE index. This assumption breaks for shadow paging if the guest page tables are modified between VM entries (similar to commit aad885e77496, "KVM: x86/mmu: Drop/zap existing present SPTE

sigint@fosstodon.org at 2026-08-05T23:45:08.000Z ##

🐧 SIGINT // Ubuntu Watch — 2026-08-06

A recurring KVM shadow paging bug enabling guest-to-host escape is a nightmare for anyone running multi-tenant VMs at home. Note it ships bundled with CVE-2026-46113, so patch both together or you are still exposed.

🔗 tuxcare.com/blog/januscape-exp

#Ubuntu #Linux #infosec

##

CVE-2026-50645
(7.5 HIGH)

EPSS: 0.48%

updated 2026-06-17T10:57:46.017000

1 posts

There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue by imposing a maximum default of 500 attachments per message.

EUVD_Bot@mastodon.social at 2026-08-06T12:01:14.000Z ##

🚨 EUVD-2026-53853

📊 Score: n/a
📦 Product: Apache CXF, Apache CXF, Apache CXF
🏢 Vendor: Apache Software Foundation
📅 Updated: 2026-08-06

📝 An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment headers. Users are recommended to upgrade to versions 4.2.3 or 4...

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2026-41679
(10.0 CRITICAL)

EPSS: 1.97%

updated 2026-06-17T10:46:59.450000

2 posts

Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in `authenticated` mode with default configuration. No user interaction, no credentials, just the target's address. The chain consists of six API calls

1 repos

https://github.com/bartfroklage/cve-2026-41679

offseq at 2026-08-06T12:00:26.632Z ##

CVE-2026-41679 | Paperclip AI platform CRITICAL vuln: auth bypass let attackers register, obtain API tokens, & run code as server. DNS rebinding risk in dev mode. Patch now. radar.offseq.com/threat/critic

##

offseq@infosec.exchange at 2026-08-06T12:00:26.000Z ##

CVE-2026-41679 | Paperclip AI platform CRITICAL vuln: auth bypass let attackers register, obtain API tokens, & run code as server. DNS rebinding risk in dev mode. Patch now. radar.offseq.com/threat/critic #OffSeq #CVE #Paperclip #vuln

##

CVE-2025-58487
(4.0 MEDIUM)

EPSS: 0.15%

updated 2026-06-17T09:44:33.170000

2 posts

Improper authorization in Samsung Account prior to version 15.5.01.1 allows local attacker to launch arbitrary activity with Samsung Account privilege.

threatnoir at 2026-08-06T10:06:38.582Z ##

⚠️ CRITICAL: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones

A three-stage exploit chain (CVE-2025-21079, CVE-2025-58486, CVE-2025-58487) chaining Samsung Members, Samsung Account, and Bixby achieves RCE and system-level access on Galaxy phones. Samsung patched in November/December 2025, but unpatched devices and those missing any of the three apps remain ex…

threatnoir.com/focus

🤖 AI generated summary

##

threatnoir@infosec.exchange at 2026-08-06T10:06:38.000Z ##

⚠️ CRITICAL: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones

A three-stage exploit chain (CVE-2025-21079, CVE-2025-58486, CVE-2025-58487) chaining Samsung Members, Samsung Account, and Bixby achieves RCE and system-level access on Galaxy phones. Samsung patched in November/December 2025, but unpatched devices and those missing any of the three apps remain ex…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

CVE-2025-58486
(4.0 MEDIUM)

EPSS: 0.16%

updated 2026-06-17T09:44:33.060000

4 posts

Improper input validation in Samsung Account prior to version 15.5.01.1 allows local attacker to execute arbitrary script.

threatnoir at 2026-08-06T10:06:38.582Z ##

⚠️ CRITICAL: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones

A three-stage exploit chain (CVE-2025-21079, CVE-2025-58486, CVE-2025-58487) chaining Samsung Members, Samsung Account, and Bixby achieves RCE and system-level access on Galaxy phones. Samsung patched in November/December 2025, but unpatched devices and those missing any of the three apps remain ex…

threatnoir.com/focus

🤖 AI generated summary

##

offseq at 2026-08-06T04:30:27.320Z ##

CRITICAL exploit chain affects Samsung Galaxy S25, S24, Flip 7: chained flaws in Samsung Members (CVE-2025-21079), Samsung Account (CVE-2025-58486/58487), and Bixby allow full remote system access. Patch now. radar.offseq.com/threat/how-a-

##

threatnoir@infosec.exchange at 2026-08-06T10:06:38.000Z ##

⚠️ CRITICAL: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones

A three-stage exploit chain (CVE-2025-21079, CVE-2025-58486, CVE-2025-58487) chaining Samsung Members, Samsung Account, and Bixby achieves RCE and system-level access on Galaxy phones. Samsung patched in November/December 2025, but unpatched devices and those missing any of the three apps remain ex…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

offseq@infosec.exchange at 2026-08-06T04:30:27.000Z ##

CRITICAL exploit chain affects Samsung Galaxy S25, S24, Flip 7: chained flaws in Samsung Members (CVE-2025-21079), Samsung Account (CVE-2025-58486/58487), and Bixby allow full remote system access. Patch now. radar.offseq.com/threat/how-a- #OffSeq #Samsung #Infosec #Vuln

##

CVE-2025-26399
(9.8 CRITICAL)

EPSS: 88.33%

updated 2026-06-17T09:01:42.407000

1 posts

SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.

1 repos

https://github.com/rxerium/CVE-2025-26399

kev_Stalker@infosec.exchange at 2026-08-05T02:59:14.000Z ##

CVE-2025-26399 - Changed to Known Ransomware Status

SolarWinds Web Help Desk Deserialization of Untrusted Data VulnerabilityVendor: SolarWindsProduct: Web Help DeskSolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 04, 2026 at 18:08:17 UTCDate nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2025-21079
(7.1 HIGH)

EPSS: 0.41%

updated 2026-06-17T08:42:34.123000

4 posts

Improper input validation in Samsung Members prior to version 5.5.01.3 allows remote attackers to connect arbitrary URL and launch arbitrary activity with Samsung Members privilege. User interaction is required for triggering this vulnerability.

threatnoir at 2026-08-06T10:06:38.582Z ##

⚠️ CRITICAL: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones

A three-stage exploit chain (CVE-2025-21079, CVE-2025-58486, CVE-2025-58487) chaining Samsung Members, Samsung Account, and Bixby achieves RCE and system-level access on Galaxy phones. Samsung patched in November/December 2025, but unpatched devices and those missing any of the three apps remain ex…

threatnoir.com/focus

🤖 AI generated summary

##

offseq at 2026-08-06T04:30:27.320Z ##

CRITICAL exploit chain affects Samsung Galaxy S25, S24, Flip 7: chained flaws in Samsung Members (CVE-2025-21079), Samsung Account (CVE-2025-58486/58487), and Bixby allow full remote system access. Patch now. radar.offseq.com/threat/how-a-

##

threatnoir@infosec.exchange at 2026-08-06T10:06:38.000Z ##

⚠️ CRITICAL: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones

A three-stage exploit chain (CVE-2025-21079, CVE-2025-58486, CVE-2025-58487) chaining Samsung Members, Samsung Account, and Bixby achieves RCE and system-level access on Galaxy phones. Samsung patched in November/December 2025, but unpatched devices and those missing any of the three apps remain ex…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

offseq@infosec.exchange at 2026-08-06T04:30:27.000Z ##

CRITICAL exploit chain affects Samsung Galaxy S25, S24, Flip 7: chained flaws in Samsung Members (CVE-2025-21079), Samsung Account (CVE-2025-58486/58487), and Bixby allow full remote system access. Patch now. radar.offseq.com/threat/how-a- #OffSeq #Samsung #Infosec #Vuln

##

CVE-2023-32233
(7.8 HIGH)

EPSS: 12.97%

updated 2026-06-17T05:58:22.273000

1 posts

In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled.

7 repos

https://github.com/RogelioPumajulca/TEST-CVE-2023-32233

https://github.com/Destawell/gemini-2.5-pro-nf-tables-red-teamin

https://github.com/void0red/CVE-2023-32233

https://github.com/oferchen/POC-CVE-2023-32233

https://github.com/Destawell/gemini-2.5-pro-nf-tables-red-teaming

https://github.com/PIDAN-HEIDASHUAI/CVE-2023-32233

https://github.com/Liuk3r/CVE-2023-32233

nyanbinary@infosec.exchange at 2026-08-03T18:39:18.000Z ##

Ok, the first one is absolutely it:

Furthermore, we deploy MLG-UAF to conduct large-scale security auditing on mainstream open-source software such as libtiff, LibRaw, SQLite, ImageMagick and Zephyr RTOS. In real-world industrial source code scanning, our framework successfully discovered 17 unique confirmed UAF vulnerabilities assigned with independent Common Vulnerabilities and Exposures (CVE) IDs (CVE-2026 series, RESERVED and not yet publicized), covering cross-functional kernel UAF, intra-procedural cache UAF, race-condition UAF and multimedia parsing UAF scenarios.Real CVE case studies on CVE-2026-51291 (SQLite JSON cache flaw) and CVE-2023-32233 (Linux netfilter kernel vulnerability) demonstrate that MLG-UAF can precisely capture the fixed free-then-use spatial topological fingerprint of UAF defects and accurately resolve ambiguous multi-level pointer aliasing, even under heavy control-flow obfuscation.

##

CVE-2026-42897
(8.1 HIGH)

EPSS: 70.31%

updated 2026-05-15T18:30:32

2 posts

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

1 repos

https://github.com/atiilla/CVE-2026-42897

oversecurity@mastodon.social at 2026-08-03T17:59:54.000Z ##

Falla in Outlook: apri un’e-mail e ti infettano, non servono più link o allegati

Il gruppo criminale filorusso TA488 sfrutta la CVE-2026-42897, falla XSS in Outlook Web Access, con un exploit half-click: basta aprire l'email per...

🔗️ [Cybersecurity360] link.is.it/ssYZlG

##

oversecurity@mastodon.social at 2026-08-03T17:59:52.000Z ##

Falla in Outlook: apri un’e-mail e ti infettano, non servono più link o allegati

Il gruppo criminale filorusso TA488 sfrutta la CVE-2026-42897, falla XSS in Outlook Web Access, con un exploit half-click: basta aprire l'email per...

🔗️ [Cybersecurity360] link.is.it/ssYZlG

##

CVE-2026-20079
(10.0 CRITICAL)

EPSS: 37.67%

updated 2026-03-04T18:32:03

3 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerab

1 repos

https://github.com/0xBlackash/CVE-2026-20079

offseq at 2026-08-06T07:30:27.034Z ##

CRITICAL vulnerabilities patched in Cisco SD-WAN, IOS XE, FMC, and IMC. FMC flaw (CVE-2026-20079, CVSS 10.0) allows remote root access; IMC PoC public. No active exploitation. Patch now: radar.offseq.com/threat/cisco-

##

offseq@infosec.exchange at 2026-08-06T07:30:27.000Z ##

CRITICAL vulnerabilities patched in Cisco SD-WAN, IOS XE, FMC, and IMC. FMC flaw (CVE-2026-20079, CVSS 10.0) allows remote root access; IMC PoC public. No active exploitation. Patch now: radar.offseq.com/threat/cisco- #OffSeq #Cisco #Vulnerability #PatchTuesday

##

AAKL@infosec.exchange at 2026-08-05T15:17:35.000Z ##

Broadcom has addressed several vulnerabilities published yesterday, all of them ranked high-severity support.broadcom.com/web/ecx/s #Broadcom

Cisco has a new advisory for a critical vulnerability that was published yesterday:

CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

This addresses a vulnerability that was first published on July 29:

High: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

CVE-2013-4786
(7.5 HIGH)

EPSS: 78.57%

updated 2025-04-11T04:12:49

2 posts

The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC.

1 repos

https://github.com/fin3ss3g0d/CosmicRakp

threatnoir@infosec.exchange at 2026-08-04T10:06:06.000Z ##

⚠️ CRITICAL: Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks

CVE-2013-4786 in IPMI 2.0 allows unauthenticated attackers to harvest password hashes from Baseboard Management Controllers via UDP 623, then crack them offline. Over 24,000 internet-exposed BMCs are vulnerable, and many run weak or predictable default credentials. Compromised BMCs give attackers d…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

DailyCyberSecurity@infosec.exchange at 2026-08-03T15:01:55.000Z ##

LAVA found 36,872 exposed BMCs leaking IPMI password hashes via CVE-2013-4786. Some are already exploited in the wild. Here is how to lock them down.

#BMC #IPMI #CVE20134786 #DataCenter #Supermicro #CyberSecurity

securityonline.info/exposed-bm

##

security_crawler_carl at 2026-08-06T10:06:40.445Z ##

🏆 New Achievement! Open Source, Open Season!

The court finds Gitea guilty of harboring CVE-2026-59774. The charges: permitting unauthenticated attackers to submit specially crafted Org-mode markup to a public repository and read arbitrary files from the server — with sentencing escalating, in certain configurations, to full remote code execution as the Gitea operating system user. No login required. No accomplices named. (1/2)

##

security_crawler_carl@infosec.exchange at 2026-08-06T10:06:40.000Z ##

🏆 New Achievement! Open Source, Open Season!

The court finds Gitea guilty of harboring CVE-2026-59774. The charges: permitting unauthenticated attackers to submit specially crafted Org-mode markup to a public repository and read arbitrary files from the server — with sentencing escalating, in certain configurations, to full remote code execution as the Gitea operating system user. No login required. No accomplices named. (1/2)

##

DailyCyberSecurity@infosec.exchange at 2026-08-04T07:54:14.000Z ##

Gitea Vulnerability CVE-2026-59774 Enables Unauthenticated Remote Code Execution

securityonline.info/gitea-vuln

##

CVE-2026-15991
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-06T07:00:21.000Z ##

🟠 CVE-2026-15991 - High (8.8)

The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-l...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-06T07:00:21.000Z ##

🟠 CVE-2026-15991 - High (8.8)

The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-l...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48168
(0 None)

EPSS: 0.00%

3 posts

N/A

offseq at 2026-08-06T06:00:27.264Z ##

PraisonAI <4.6.40 is affected by CVE-2026-48168 (CRITICAL, CVSS 10): Missing authorization lets attackers exploit GitHub Actions, execute arbitrary shell commands, and compromise repos. Patch to 4.6.40! radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-06T06:00:27.000Z ##

PraisonAI <4.6.40 is affected by CVE-2026-48168 (CRITICAL, CVSS 10): Missing authorization lets attackers exploit GitHub Actions, execute arbitrary shell commands, and compromise repos. Patch to 4.6.40! radar.offseq.com/threat/cve-20 #OffSeq #CVE202648168 #SecDevOps

##

thehackerwire@mastodon.social at 2026-08-05T20:01:23.000Z ##

🔴 CVE-2026-48168 - Critical (10)

PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection because it embeds an attacker-controlled pull request branch name into a Bash run: block without qu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18953
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-06T02:00:32.000Z ##

🟠 CVE-2026-18953 - High (8.6)

Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow a context-dependent actor to write arbitrary files outside the intended working directo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-06T02:00:32.000Z ##

🟠 CVE-2026-18953 - High (8.6)

Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow a context-dependent actor to write arbitrary files outside the intended working directo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55524
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-06T02:00:23.000Z ##

🟠 CVE-2026-55524 - High (7.5)

PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the initially supplied URL, allowing the protection to be bypassed so the tool connects to attacker-chosen internal destinatio...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-06T02:00:23.000Z ##

🟠 CVE-2026-55524 - High (7.5)

PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the initially supplied URL, allowing the protection to be bypassed so the tool connects to attacker-chosen internal destinatio...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55522
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-06T02:00:12.000Z ##

🟠 CVE-2026-55522 - High (7.8)

PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerable to code execution. Workflow._execute_include() implicitly imports...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-06T02:00:12.000Z ##

🟠 CVE-2026-55522 - High (7.8)

PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerable to code execution. Workflow._execute_include() implicitly imports...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8446
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-05T18:00:26.000Z ##

🟠 CVE-2026-8446 - High (7.5)

IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_composer_enabled=true (default) and projects are configured with auth_type=oauth .

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

hackmag@infosec.exchange at 2026-08-04T22:00:07.000Z ##

⚪️ OpenWrt Fixes Critical Vulnerability in DHCPv6 Server

🗨️ OpenWrt developers have released updates that fix a critical vulnerability in the DHCPv6 server. The flaw allowed an unauthenticated attacker to execute arbitrary code with root privileges and potentially fully compromise a vulnerable router. The issue, tracked as CVE-2026-53921 (CVSS…

🔗 hackmag.com/news/openwrt-patch

#news

##

Visit counter For Websites