##
Updated at UTC 2026-09-15T05:19:40.595100
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-87719 | 9.9 | 0.61% | 1 | 0 | 2026-09-15T04:18:19.173000 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 bef | |
| CVE-2026-76461 | 9.8 | 0.00% | 16 | 0 | 2026-09-15T04:18:15.100000 | A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure | |
| CVE-2026-76440 | 9.8 | 0.00% | 2 | 0 | 2026-09-15T04:18:12.660000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-90493 | 8.8 | 0.11% | 2 | 0 | 2026-09-15T03:31:31 | A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build | |
| CVE-2026-90847 | 9.1 | 0.00% | 2 | 0 | 2026-09-15T03:30:30 | A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element i | |
| CVE-2026-91771 | 8.8 | 0.00% | 2 | 0 | 2026-09-15T02:16:49.680000 | Weights & Biases wandb before 0.29.0 fails to validate the file name from server | |
| CVE-2026-91200 | 8.8 | 0.00% | 2 | 0 | 2026-09-15T00:31:22 | DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry n | |
| CVE-2026-12944 | 9.6 | 0.00% | 4 | 0 | 2026-09-15T00:31:21 | IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary P | |
| CVE-2026-91144 | 7.5 | 0.00% | 2 | 0 | 2026-09-15T00:31:21 | ZFile through 5.0.5 fails to validate requested file paths against a share link' | |
| CVE-2026-82028 | 8.8 | 0.00% | 2 | 0 | 2026-09-14T21:31:46 | Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale- | |
| CVE-2026-89023 | 8.6 | 0.00% | 2 | 0 | 2026-09-14T21:31:42 | ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missin | |
| CVE-2026-53713 | 9.1 | 0.00% | 2 | 0 | 2026-09-14T21:17:12.520000 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone | |
| CVE-2026-88793 | 8.8 | 0.28% | 2 | 0 | 2026-09-14T21:10:17.423000 | The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any author | |
| CVE-2026-85129 | 8.8 | 0.26% | 2 | 0 | 2026-09-14T21:10:17.423000 | The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or vali | |
| CVE-2026-77005 | 9.6 | 0.30% | 1 | 0 | 2026-09-14T21:10:17.423000 | The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a u | |
| CVE-2026-80494 | 8.6 | 0.32% | 1 | 0 | 2026-09-14T21:10:17.423000 | The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-suppli | |
| CVE-2026-82845 | 9.9 | 0.35% | 1 | 0 | 2026-09-14T21:10:17.423000 | The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied | |
| CVE-2026-87888 | 8.0 | 0.23% | 1 | 0 | 2026-09-14T21:10:17.423000 | The YayPricing WordPress plugin before 3.5.7 does not perform an authorization | |
| CVE-2026-85681 | 9.8 | 0.28% | 2 | 0 | 2026-09-14T21:10:17.423000 | The WP Component WordPress plugin through 2.2.4 does not have any capability or | |
| CVE-2026-90537 | 8.2 | 0.21% | 1 | 0 | 2026-09-14T21:03:01.800000 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a m | |
| CVE-2026-78330 | 9.8 | 0.00% | 2 | 0 | 2026-09-14T20:58:48.430000 | Incorrect privilege assignment vulnerability in Apache Syncope. When the config | |
| CVE-2026-90606 | 9.9 | 0.49% | 6 | 0 | 2026-09-14T20:56:48.220000 | A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046 | |
| CVE-2026-90680 | 9.9 | 0.51% | 2 | 0 | 2026-09-14T20:56:48.220000 | A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The im | |
| CVE-2026-90605 | 9.9 | 0.47% | 2 | 0 | 2026-09-14T20:56:48.220000 | A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulne | |
| CVE-2026-90510 | 8.3 | 0.29% | 2 | 0 | 2026-09-14T20:56:48.220000 | A security vulnerability has been detected in dromara orion-visor up to 2.5.7. T | |
| CVE-2026-78006 | 9.8 | 0.78% | 3 | 2 | 2026-09-14T20:16:52.847000 | The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execut | |
| CVE-2026-65838 | 8.2 | 0.00% | 2 | 0 | 2026-09-14T20:16:49.103000 | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0. | |
| CVE-2026-57126 | 8.5 | 0.00% | 2 | 0 | 2026-09-14T20:16:48.440000 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, Spider | |
| CVE-2026-91080 | 7.5 | 0.00% | 2 | 0 | 2026-09-14T19:18:14.500000 | webhook through 2.8.3 reads the entire request body into memory before evaluatin | |
| CVE-2026-90768 | 8.1 | 0.24% | 2 | 0 | 2026-09-14T19:18:08.653000 | CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpo | |
| CVE-2026-90668 | 7.5 | 0.33% | 2 | 0 | 2026-09-14T19:18:08.107000 | The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the | |
| CVE-2026-91079 | 8.5 | 0.00% | 2 | 0 | 2026-09-14T18:31:35 | Huly Platform through 0.7.426 contains a server-side request forgery vulnerabili | |
| CVE-2026-90946 | 7.5 | 0.00% | 2 | 0 | 2026-09-14T18:31:29 | DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerabili | |
| CVE-2026-85921 | 8.2 | 0.00% | 2 | 0 | 2026-09-14T18:31:29 | Double free in Windows Secure Kernel Mode allows an authorized attacker to eleva | |
| CVE-2026-76441 | 9.8 | 0.00% | 2 | 0 | 2026-09-14T18:31:29 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-20353 | 9.8 | 0.00% | 2 | 0 | 2026-09-14T18:31:22 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-90945 | 9.8 | 0.00% | 4 | 0 | 2026-09-14T18:20:29.030000 | Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing | |
| CVE-2026-90777 | 8.8 | 0.51% | 2 | 0 | 2026-09-14T18:20:26.223000 | ESPnet before 202609 deserializes pretrained model checkpoints using torch.load | |
| CVE-2026-90772 | 7.6 | 0.21% | 2 | 0 | 2026-09-14T18:20:25.707000 | Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptio | |
| CVE-2026-59178 | 9.8 | 0.00% | 2 | 0 | 2026-09-14T18:08:58 | ## Summary The dashboard reads its authentication credentials from `$ESPHOME_US | |
| CVE-2026-90648 | 0 | 0.15% | 1 | 0 | 2026-09-14T17:17:55.827000 | wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situatio | |
| CVE-2026-78159 | 9.8 | 0.76% | 3 | 0 | 2026-09-14T17:17:51.410000 | The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execut | |
| CVE-2026-89697 | 9.1 | 0.60% | 2 | 0 | 2026-09-14T15:33:39 | In the Linux kernel, the following vulnerability has been resolved: nfsd: add f | |
| CVE-2026-89704 | 7.5 | 0.44% | 2 | 0 | 2026-09-14T15:33:38 | In the Linux kernel, the following vulnerability has been resolved: nfsd: sampl | |
| CVE-2026-89461 | None | 0.20% | 1 | 0 | 2026-09-14T15:33:29 | In the Linux kernel, the following vulnerability has been resolved: power: supp | |
| CVE-2026-80970 | None | 0.19% | 1 | 0 | 2026-09-14T15:33:27 | In the Linux kernel, the following vulnerability has been resolved: ALSA: FCP: | |
| CVE-2026-80912 | None | 0.16% | 1 | 0 | 2026-09-14T15:33:22 | In the Linux kernel, the following vulnerability has been resolved: selinux: re | |
| CVE-2026-12258 | None | 0.00% | 2 | 0 | 2026-09-14T15:32:42 | Inadequate access control in Hiperdino’s REST v1.0 API. The public endpoint ‘cus | |
| CVE-2026-88802 | 7.5 | 0.23% | 2 | 0 | 2026-09-14T15:32:39 | The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events | |
| CVE-2026-81648 | 10.0 | 0.28% | 2 | 0 | 2026-09-14T15:32:38 | The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an | |
| CVE-2026-74933 | 8.8 | 0.27% | 2 | 0 | 2026-09-14T15:32:38 | The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisatio | |
| CVE-2026-89736 | 7.8 | 0.12% | 2 | 0 | 2026-09-14T15:32:36 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget | |
| CVE-2026-89750 | 7.8 | 0.16% | 2 | 0 | 2026-09-14T15:32:36 | In the Linux kernel, the following vulnerability has been resolved: tracing/use | |
| CVE-2026-89744 | 8.4 | 0.14% | 2 | 0 | 2026-09-14T15:32:36 | In the Linux kernel, the following vulnerability has been resolved: device prop | |
| CVE-2026-89706 | 7.5 | 0.44% | 2 | 0 | 2026-09-14T15:32:35 | In the Linux kernel, the following vulnerability has been resolved: nfsd: Reset | |
| CVE-2026-43502 | 7.8 | 0.12% | 2 | 1 | 2026-09-14T15:32:07 | In the Linux kernel, the following vulnerability has been resolved: net/rds: ha | |
| CVE-2026-90919 | 9.8 | 0.00% | 2 | 0 | 2026-09-14T15:17:13.630000 | LightLLM through 1.2.0 contains a remote code execution vulnerability in the Con | |
| CVE-2026-85706 | 10.0 | 11.12% | 27 | 12 | template | 2026-09-14T14:22:15.323000 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 |
| CVE-2026-73324 | 4.3 | 0.33% | 3 | 0 | 2026-09-14T14:17:08.940000 | Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memor | |
| CVE-2026-16482 | 7.5 | 0.34% | 1 | 0 | 2026-09-14T13:51:41.830000 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulner | |
| CVE-2026-89746 | 7.8 | 0.16% | 2 | 0 | 2026-09-14T13:19:23.350000 | In the Linux kernel, the following vulnerability has been resolved: tracing: Fi | |
| CVE-2026-89696 | 7.5 | 0.67% | 2 | 0 | 2026-09-14T13:19:19.897000 | In the Linux kernel, the following vulnerability has been resolved: nfsd: block | |
| CVE-2026-89684 | 7.5 | 0.45% | 2 | 0 | 2026-09-14T13:19:19.610000 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix c | |
| CVE-2026-89504 | 8.4 | 0.14% | 1 | 0 | 2026-09-14T13:19:07.210000 | In the Linux kernel, the following vulnerability has been resolved: regulator: | |
| CVE-2026-89488 | 7.8 | 0.12% | 1 | 0 | 2026-09-14T13:19:05.627000 | In the Linux kernel, the following vulnerability has been resolved: openvswitch | |
| CVE-2026-90703 | 9.1 | 0.00% | 2 | 0 | 2026-09-14T12:31:44 | A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element i | |
| CVE-2026-90607 | 9.9 | 0.47% | 4 | 0 | 2026-09-14T03:30:29 | A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is | |
| CVE-2026-90608 | 9.9 | 0.80% | 4 | 0 | 2026-09-14T03:30:29 | A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected elemen | |
| CVE-2026-33963 | 7.5 | 0.11% | 2 | 0 | 2026-09-14T03:30:29 | An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, | |
| CVE-2026-31278 | 7.7 | 0.15% | 3 | 1 | 2026-09-14T03:30:22 | An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 be | |
| CVE-2026-23789 | 7.8 | 0.11% | 2 | 0 | 2026-09-14T02:17:13.397000 | An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processo | |
| CVE-2026-81578 | 9.8 | 1.62% | 1 | 2 | 2026-09-14T00:16:56.207000 | An improper access control vulnerability exists in the web management interface | |
| CVE-2026-37008 | 8.1 | 0.13% | 2 | 0 | 2026-09-13T21:31:54 | CrewAI before fb2323b offers a Python blocklist approach that operates at the wr | |
| CVE-2026-29811 | 7.7 | 0.25% | 2 | 0 | 2026-09-13T21:31:53 | CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second dom | |
| CVE-2026-90783 | 7.8 | 0.14% | 2 | 0 | 2026-09-13T15:30:28 | MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib l | |
| CVE-2026-90775 | 6.5 | 0.34% | 2 | 0 | 2026-09-13T12:31:19 | PostGIS address_standardizer through 3.7.0 fails to validate the Weight paramete | |
| CVE-2026-90779 | 7.5 | 0.56% | 2 | 0 | 2026-09-13T12:31:19 | SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthH | |
| CVE-2026-90778 | 7.5 | 0.63% | 2 | 0 | 2026-09-13T12:31:19 | SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() fu | |
| CVE-2026-90776 | 7.5 | 0.48% | 2 | 0 | 2026-09-13T12:31:19 | Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vul | |
| CVE-2026-90780 | 7.5 | 0.63% | 2 | 0 | 2026-09-13T12:31:19 | SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() | |
| CVE-2026-90769 | 7.7 | 0.26% | 2 | 0 | 2026-09-13T12:31:19 | Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sou | |
| CVE-2026-90774 | 7.5 | 0.38% | 2 | 0 | 2026-09-13T12:31:19 | rustypaste before 0.18.1 validates the destination path before applying the opti | |
| CVE-2026-90770 | 8.8 | 0.72% | 2 | 0 | 2026-09-13T12:31:12 | Spug through 3.4.0 contains a remote code execution vulnerability in the ping_ch | |
| CVE-2026-90561 | 8.7 | 0.24% | 4 | 0 | 2026-09-13T12:31:11 | Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross- | |
| CVE-2026-89080 | 7.5 | 0.20% | 2 | 0 | 2026-09-13T12:31:10 | The Really Simple Security WordPress plugin before 9.8.1 does not prevent an un | |
| CVE-2026-86406 | 7.5 | 0.19% | 2 | 0 | 2026-09-13T12:31:09 | The User Registration & Membership WordPress plugin before 5.2.8 does not check | |
| CVE-2026-90562 | 8.1 | 0.42% | 4 | 0 | 2026-09-13T11:17:00.780000 | LangBot before 4.10.11 generates password recovery keys with only 24 bits of ent | |
| CVE-2026-89687 | 7.5 | 0.47% | 2 | 0 | 2026-09-13T09:33:34 | In the Linux kernel, the following vulnerability has been resolved: nfsd: ensur | |
| CVE-2026-89692 | 7.5 | 0.43% | 2 | 0 | 2026-09-13T09:33:34 | In the Linux kernel, the following vulnerability has been resolved: nfsd: clear | |
| CVE-2026-89690 | 7.8 | 0.16% | 2 | 0 | 2026-09-13T09:33:34 | In the Linux kernel, the following vulnerability has been resolved: nfsd: defer | |
| CVE-2026-89764 | 7.8 | 0.14% | 1 | 0 | 2026-09-13T09:33:34 | In the Linux kernel, the following vulnerability has been resolved: rust: devre | |
| CVE-2026-89763 | 7.8 | 0.11% | 1 | 0 | 2026-09-13T09:33:34 | In the Linux kernel, the following vulnerability has been resolved: KEYS: trust | |
| CVE-2026-89688 | 9.8 | 0.61% | 2 | 0 | 2026-09-13T09:33:31 | In the Linux kernel, the following vulnerability has been resolved: nfsd: drop | |
| CVE-2026-89612 | 9.8 | 0.55% | 2 | 0 | 2026-09-13T09:33:31 | In the Linux kernel, the following vulnerability has been resolved: ntfs: rejec | |
| CVE-2026-89695 | 7.5 | 0.49% | 2 | 0 | 2026-09-13T09:33:31 | In the Linux kernel, the following vulnerability has been resolved: nfsd: cap d | |
| CVE-2026-89689 | 9.8 | 0.60% | 2 | 0 | 2026-09-13T09:33:30 | In the Linux kernel, the following vulnerability has been resolved: nfsd: don't | |
| CVE-2026-80980 | 9.8 | 0.60% | 1 | 0 | 2026-09-13T09:33:21 | In the Linux kernel, the following vulnerability has been resolved: net/smc: st | |
| CVE-2026-89747 | 7.8 | 0.16% | 2 | 0 | 2026-09-13T09:32:30 | In the Linux kernel, the following vulnerability has been resolved: tracing: Fi | |
| CVE-2026-89758 | 7.8 | 0.14% | 2 | 0 | 2026-09-13T09:32:30 | In the Linux kernel, the following vulnerability has been resolved: mm/mempolic | |
| CVE-2026-89754 | 7.8 | 0.12% | 1 | 0 | 2026-09-13T09:32:30 | In the Linux kernel, the following vulnerability has been resolved: mm/pagewalk | |
| CVE-2026-89762 | 7.8 | 0.12% | 1 | 0 | 2026-09-13T09:32:30 | In the Linux kernel, the following vulnerability has been resolved: apparmor: f | |
| CVE-2026-89761 | 7.8 | 0.12% | 1 | 0 | 2026-09-13T09:32:30 | In the Linux kernel, the following vulnerability has been resolved: apparmor: f | |
| CVE-2026-89760 | 7.8 | 0.11% | 1 | 0 | 2026-09-13T09:32:30 | In the Linux kernel, the following vulnerability has been resolved: mm, swap: d | |
| CVE-2026-89685 | 7.5 | 0.43% | 2 | 0 | 2026-09-13T09:32:28 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix c | |
| CVE-2026-89682 | 8.1 | 0.40% | 2 | 0 | 2026-09-13T09:32:28 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix f | |
| CVE-2026-89613 | 9.8 | 0.55% | 2 | 0 | 2026-09-13T09:32:24 | In the Linux kernel, the following vulnerability has been resolved: ntfs: rejec | |
| CVE-2026-89771 | 7.8 | 0.12% | 1 | 0 | 2026-09-13T07:17:41.310000 | In the Linux kernel, the following vulnerability has been resolved: ring-buffer | |
| CVE-2026-89767 | 7.8 | 0.15% | 1 | 0 | 2026-09-13T07:17:41.050000 | In the Linux kernel, the following vulnerability has been resolved: ovl: fix do | |
| CVE-2026-89755 | 7.8 | 0.14% | 1 | 0 | 2026-09-13T07:17:39.983000 | In the Linux kernel, the following vulnerability has been resolved: mm/migrate_ | |
| CVE-2026-89748 | 7.8 | 0.15% | 2 | 0 | 2026-09-13T07:17:39.493000 | In the Linux kernel, the following vulnerability has been resolved: tracing: Fi | |
| CVE-2026-89686 | 9.8 | 0.67% | 2 | 0 | 2026-09-13T07:17:34.367000 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix B | |
| CVE-2026-89611 | 9.8 | 0.38% | 2 | 0 | 2026-09-13T07:17:26.617000 | In the Linux kernel, the following vulnerability has been resolved: ntfs: valid | |
| CVE-2026-89499 | 7.8 | 0.12% | 1 | 0 | 2026-09-13T07:17:13.100000 | In the Linux kernel, the following vulnerability has been resolved: ring-buffer | |
| CVE-2026-81006 | 7.8 | 0.13% | 2 | 0 | 2026-09-13T07:17:07.273000 | In the Linux kernel, the following vulnerability has been resolved: ipmi: Remov | |
| CVE-2026-80947 | 7.8 | 0.16% | 1 | 0 | 2026-09-13T07:17:01.960000 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtl8x | |
| CVE-2026-90678 | 7.5 | 0.52% | 1 | 0 | 2026-09-13T06:33:11 | An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3 | |
| CVE-2026-90651 | 8.1 | 0.19% | 2 | 0 | 2026-09-13T00:31:26 | Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0 | |
| CVE-2026-90647 | 7.4 | 0.14% | 1 | 0 | 2026-09-12T23:17:01.490000 | ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows con | |
| CVE-2026-90616 | 7.4 | 0.17% | 1 | 0 | 2026-09-12T21:31:19 | In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read an | |
| CVE-2026-84171 | 9.8 | 0.37% | 2 | 0 | 2026-09-12T18:31:29 | The WP images upload on piclect WordPress plugin through 1.0 does not validate t | |
| CVE-2026-75800 | 9.8 | 0.42% | 1 | 0 | 2026-09-12T18:31:28 | The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signatu | |
| CVE-2026-77006 | 9.6 | 0.18% | 1 | 0 | 2026-09-12T18:31:28 | The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-sup | |
| CVE-2026-84047 | 8.6 | 0.26% | 1 | 0 | 2026-09-12T18:31:28 | The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize | |
| CVE-2026-87842 | 7.5 | 0.29% | 1 | 0 | 2026-09-12T18:31:28 | The Zonify WordPress plugin before 1.0.5 does not perform any capability or aut | |
| CVE-2026-90558 | 9.8 | 0.51% | 2 | 0 | 2026-09-12T18:30:33 | sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attri | |
| CVE-2026-90560 | 8.2 | 0.34% | 1 | 0 | 2026-09-12T18:30:33 | zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerabi | |
| CVE-2026-90559 | 7.5 | 0.35% | 1 | 0 | 2026-09-12T18:30:33 | snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Sn | |
| CVE-2026-90556 | 7.8 | 0.14% | 1 | 0 | 2026-09-12T18:30:33 | Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() | |
| CVE-2026-81742 | 8.8 | 0.28% | 1 | 0 | 2026-09-12T18:30:22 | The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any author | |
| CVE-2026-87759 | 8.8 | 0.23% | 1 | 0 | 2026-09-12T18:30:22 | The Add User Autocomplete WordPress plugin before 1.2 does not perform any capab | |
| CVE-2026-84099 | 8.1 | 0.27% | 1 | 0 | 2026-09-12T18:30:22 | The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthen | |
| CVE-2026-81402 | 9.8 | 0.45% | 1 | 0 | 2026-09-12T18:30:21 | The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability c | |
| CVE-2026-80491 | 8.6 | 0.32% | 1 | 0 | 2026-09-12T18:30:21 | The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and esc | |
| CVE-2026-90553 | 7.8 | 0.21% | 1 | 0 | 2026-09-12T15:31:56 | vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOn | |
| CVE-2026-15451 | 8.8 | 0.25% | 1 | 0 | 2026-09-12T15:31:49 | The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privile | |
| CVE-2026-78175 | 8.8 | 0.59% | 1 | 0 | 2026-09-12T09:33:41 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vul | |
| CVE-2026-85200 | 7.5 | 0.76% | 1 | 0 | 2026-09-12T09:33:36 | The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all | |
| CVE-2026-84869 | 9.9 | 0.69% | 9 | 0 | 2026-09-12T04:16:42.757000 | A condition in the ScreenConnect client may allow files to be transferred and ex | |
| CVE-2026-42018 | 7.5 | 0.92% | 3 | 1 | 2026-09-11T21:32:08 | JFrog Artifactory could return an internal anonymous-user token to an unauthenti | |
| CVE-2026-89517 | None | 0.20% | 1 | 0 | 2026-09-11T21:31:37 | In the Linux kernel, the following vulnerability has been resolved: sched_ext: | |
| CVE-2026-89447 | None | 0.18% | 1 | 0 | 2026-09-11T21:31:32 | In the Linux kernel, the following vulnerability has been resolved: iommufd: Av | |
| CVE-2026-80974 | None | 0.20% | 1 | 0 | 2026-09-11T21:31:22 | In the Linux kernel, the following vulnerability has been resolved: mfd: sm501: | |
| CVE-2026-42016 | 8.1 | 0.89% | 5 | 0 | 2026-09-11T21:31:06 | JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a pri | |
| CVE-2026-89502 | 0 | 0.20% | 1 | 0 | 2026-09-11T20:19:32.423000 | In the Linux kernel, the following vulnerability has been resolved: ring-buffer | |
| CVE-2026-89010 | 9.8 | 2.85% | 2 | 0 | 2026-09-11T15:32:49 | WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 cont | |
| CVE-2026-86060 | 9.8 | 1.02% | 2 | 1 | 2026-09-11T15:32:27 | RouterOS contains an argument-handling flaw in the SSH login path involving user | |
| CVE-2026-17176 | 0 | 3.59% | 2 | 0 | 2026-09-11T15:21:12.850000 | An OS command injection vulnerability in the TDDP module of Deco BE11000 allows | |
| CVE-2026-87020 | 8.1 | 0.56% | 2 | 0 | 2026-09-11T15:17:06.937000 | An integer overflow in a specified pitch and buffer-size computation leads to a | |
| CVE-2026-82079 | 8.4 | 0.16% | 2 | 0 | 2026-09-11T03:31:25 | A stack-based buffer overflow vulnerability in the Nintendo Switch local wireles | |
| CVE-2026-65638 | 0 | 3.20% | 3 | 0 | 2026-09-10T19:54:25.810000 | Improper escaping of a request URL in ConfigServer Security & Firewall allows a | |
| CVE-2026-81467 | 9.8 | 3.84% | 2 | 0 | 2026-09-10T18:33:04 | Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutraliza | |
| CVE-2026-81468 | 9.1 | 2.28% | 2 | 0 | 2026-09-10T18:33:03 | Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutraliza | |
| CVE-2026-19490 | 9.8 | 5.60% | 2 | 2 | 2026-09-10T15:33:58 | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: f | |
| CVE-2025-25249 | 8.1 | 2.40% | 3 | 0 | 2026-09-10T12:47:59.933000 | A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6 | |
| CVE-2026-50894 | 9.8 | 0.48% | 1 | 0 | 2026-09-09T21:32:24 | easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous T | |
| CVE-2026-20079 | 10.0 | 75.75% | 3 | 3 | 2026-09-09T21:31:33 | A vulnerability in the web interface of Cisco Secure Firewall Management Center | |
| CVE-2026-85102 | 9.8 | 0.33% | 8 | 0 | 2026-09-09T15:35:15 | Improper certificate trust validation during VPN negotiation in Check Point Quan | |
| CVE-2026-85103 | 9.8 | 0.36% | 8 | 0 | 2026-09-09T15:35:15 | A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unau | |
| CVE-2026-56711 | 8.8 | 0.30% | 3 | 0 | 2026-09-09T15:35:15 | VLC media player computes the size of a picture buffer with 32-bit arithmetic an | |
| CVE-2026-87827 | None | 1.07% | 2 | 0 | 2026-09-09T12:32:22 | Certain KGUARD DVR devices running vulnerable firmware expose a system command e | |
| CVE-2026-86218 | 9.8 | 0.74% | 3 | 2 | 2026-09-09T05:18:19.490000 | N-central is vulnerable to a pre-auth remote code execution This issue affects N | |
| CVE-2026-85880 | 7.8 | 0.57% | 2 | 0 | 2026-09-09T05:18:19.193000 | Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elev | |
| CVE-2026-81963 | 7.8 | 0.63% | 2 | 0 | 2026-09-09T05:18:17.173000 | Improper link resolution before file access ('link following') in Windows Update | |
| CVE-2026-75650 | 10.0 | 2.15% | 2 | 5 | 2026-09-08T21:33:09 | Adobe Commerce is affected by an Improper Neutralization of Special Elements Use | |
| CVE-2026-69730 | 9.8 | 1.05% | 1 | 0 | 2026-09-08T18:33:07 | Use after free in Windows DNS allows an unauthorized attacker to execute code ov | |
| CVE-2026-13297 | 7.5 | 0.25% | 1 | 0 | 2026-09-08T18:32:45 | IBM Verify Identity Access Advanced Access Control may be vulnerable to an infor | |
| CVE-2026-60004 | 9.8 | 86.78% | 4 | 10 | 2026-09-08T17:56:31 | ### Summary Gitea's `diffpatch` endpoint can be abused to install and execute a | |
| CVE-2026-12744 | 9.8 | 2.17% | 2 | 0 | 2026-09-08T15:32:04 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM bef | |
| CVE-2026-12745 | 9.8 | 2.09% | 2 | 0 | 2026-09-08T15:32:04 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM bef | |
| CVE-2026-78488 | 6.5 | 3.25% | 2 | 0 | 2026-09-07T15:34:02 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application | |
| CVE-2026-79697 | 9.9 | 3.35% | 2 | 0 | 2026-09-07T09:31:46 | A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-661 | |
| CVE-2026-80897 | None | 0.17% | 1 | 0 | 2026-09-04T18:31:46 | In the Linux kernel, the following vulnerability has been resolved: netfs: rele | |
| CVE-2026-80904 | None | 0.16% | 1 | 0 | 2026-09-04T18:31:46 | In the Linux kernel, the following vulnerability has been resolved: net/tls: Fa | |
| CVE-2026-85636 | 5.3 | 0.43% | 1 | 0 | 2026-09-04T18:31:46 | A vulnerability was identified in jofpin trape 1.0.0. Affected by this vulnerabi | |
| CVE-2026-17273 | 6.5 | 0.35% | 1 | 0 | 2026-09-04T18:31:40 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to caus | |
| CVE-2026-16693 | 4.4 | 0.13% | 1 | 0 | 2026-09-04T18:31:40 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obta | |
| CVE-2026-18073 | 4.4 | 0.10% | 1 | 0 | 2026-09-04T18:31:31 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to injec | |
| CVE-2026-20212 | 9.8 | 0.53% | 1 | 1 | 2026-09-02T18:32:26 | A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switc | |
| CVE-2026-83549 | 7.8 | 8.51% | 1 | 2 | 2026-09-02T18:32:06 | Post-authentication Improper Neutralization of Special Elements used in an OS Co | |
| CVE-2026-83548 | 10.0 | 4.67% | 1 | 3 | 2026-09-02T18:32:06 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Pla | |
| CVE-2026-82329 | 9.8 | 7.67% | 1 | 7 | 2026-09-02T18:31:57 | JFrog Artifactory contains an authentication weakness that, under default config | |
| CVE-2026-82078 | 9.1 | 1.69% | 1 | 2 | 2026-08-31T21:31:56 | An unsafe dynamic class loading vulnerability exists in the database connection | |
| CVE-2026-82448 | 9.8 | 0.41% | 2 | 0 | 2026-08-29T15:30:20 | Shinobi before commit 5a76c74f contains a hardcoded connection key in the child | |
| CVE-2026-56368 | 3.7 | 0.26% | 2 | 0 | 2026-08-26T20:48:48 | A memory leak vulnerability exists in multiple coders that write raw pixel data | |
| CVE-2026-59310 | 9.8 | 45.88% | 1 | 2 | 2026-08-18T18:32:52 | VMware vCenter contains a directory traversal vulnerability in the Syslog server | |
| CVE-2021-44228 | 10.0 | 100.00% | 1 | 100 | template | 2026-08-11T19:33:44.513000 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12 |
| CVE-2026-62721 | 7.8 | 0.38% | 2 | 0 | 2026-08-11T18:31:23 | Insufficient granularity of access control in User-Mode Power Service (UMPS) all | |
| CVE-2026-61511 | 9.8 | 70.77% | 3 | 5 | 2026-08-07T06:31:24 | vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vul | |
| CVE-2026-62946 | 5.1 | 0.09% | 2 | 0 | 2026-08-03T16:19:22.763000 | ImageMagick is free and open-source software used for editing and manipulating d | |
| CVE-2026-46331 | 7.8 | 0.58% | 2 | 14 | 2026-07-23T12:33:27 | In the Linux kernel, the following vulnerability has been resolved: net/sched: | |
| CVE-2026-49176 | 7.8 | 0.47% | 2 | 2 | 2026-07-22T16:17:28.753000 | Improper privilege management in Windows WalletService allows an authorized atta | |
| CVE-2026-57130 | 8.1 | 0.00% | 2 | 0 | 2026-07-20T21:26:50 | ## Summary The email search tool in `src/praisonai-agents/praisonaiagents/tools | |
| CVE-2026-57129 | 7.5 | 0.00% | 2 | 0 | 2026-07-20T21:26:30 | ## Summary The MentionsParser in `src/praisonai-agents/praisonaiagents/tools/me | |
| CVE-2026-61866 | 2.9 | 0.19% | 2 | 0 | 2026-07-16T03:01:45.513000 | ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG enco | |
| CVE-2026-61864 | 2.9 | 0.10% | 2 | 0 | 2026-07-15T18:20:21.237000 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in color transf | |
| CVE-2026-61865 | 2.9 | 0.10% | 2 | 0 | 2026-07-15T18:20:21.237000 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the hough li | |
| CVE-2026-61863 | 2.9 | 0.19% | 2 | 0 | 2026-07-15T12:32:05 | ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in | |
| CVE-2026-50458 | 7.8 | 0.26% | 2 | 0 | 2026-07-14T18:32:25 | Use after free in Microsoft Brokering File System allows an authorized attacker | |
| CVE-2026-61857 | 3.7 | 0.27% | 2 | 0 | 2026-07-13T22:11:46.303000 | ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused | |
| CVE-2026-61870 | 2.9 | 0.19% | 2 | 0 | 2026-07-11T15:30:30 | ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF enc | |
| CVE-2026-61465 | 3.3 | 0.17% | 2 | 0 | 2026-07-11T15:30:29 | ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed mem | |
| CVE-2026-56366 | 3.3 | 0.17% | 2 | 0 | 2026-07-10T15:31:48 | ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META rea | |
| CVE-2026-56373 | 3.7 | 0.23% | 2 | 0 | 2026-07-10T15:31:48 | ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB d | |
| CVE-2026-57239 | 8.2 | 0.17% | 2 | 1 | 2026-07-09T15:33:27 | The user-controllable executable files will be directly executed by high-privile | |
| CVE-2026-56379 | None | 0.88% | 2 | 0 | 2026-06-30T03:38:15 | ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerabi | |
| CVE-2026-56370 | 3.3 | 0.12% | 2 | 0 | 2026-06-24T13:10:05 | When the `connected-components:*` define specifies an invalid index and out of b | |
| CVE-2026-56371 | None | 0.26% | 2 | 0 | 2026-06-23T15:32:48 | ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c | |
| CVE-2026-56378 | 3.7 | 0.22% | 2 | 0 | 2026-06-21T15:31:31 | ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bo | |
| CVE-2026-39987 | 9.8 | 98.95% | 1 | 25 | 2026-06-17T10:42:51.460000 | marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE | |
| CVE-2026-2275 | 9.6 | 0.44% | 2 | 0 | 2026-06-17T10:30:42.313000 | The CrewAI CodeInterpreter tool falls back to SandboxPython when it cannot reach | |
| CVE-2026-28993 | 5.5 | 0.12% | 2 | 0 | 2026-06-17T10:29:27.873000 | This issue was addressed by adding an additional prompt for user consent. This i | |
| CVE-2024-1813 | 9.8 | 1.22% | 2 | 1 | 2026-06-17T07:05:03.993000 | The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection | |
| CVE-2026-4986 | 5.3 | 0.20% | 2 | 2 | 2026-06-09T15:33:16 | The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity o | |
| CVE-2026-39364 | None | 2.00% | 5 | 0 | template | 2026-04-07T22:16:19 | ### Summary The contents of files that are specified by [`server.fs.deny`](http |
| CVE-2026-4201 | 7.3 | 0.28% | 2 | 0 | 2026-03-16T15:30:57 | A weakness has been identified in glowxq glowxq-oj up to 6f7c723090472057252040f | |
| CVE-2025-31125 | 5.3 | 58.46% | 2 | 7 | template | 2026-01-22T21:47:41 | ### Summary The contents of arbitrary files can be returned to the browser. ## |
| CVE-2025-30208 | 5.3 | 74.97% | 2 | 23 | template | 2025-03-25T14:00:04 | ### Summary The contents of arbitrary files can be returned to the browser. ### |
| CVE-2024-45811 | 5.3 | 1.06% | 2 | 0 | 2024-09-19T18:34:34 | ### Summary The contents of arbitrary files can be returned to the browser. ### | |
| CVE-2024-3094 | 10.0 | 85.97% | 1 | 89 | 2024-03-29T18:30:50 | Malicious code was discovered in the upstream tarballs of xz, starting with vers | |
| CVE-2026-73496 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-72898 | 0 | 94.22% | 1 | 9 | N/A | ||
| CVE-2026-51990 | 0 | 0.00% | 10 | 1 | N/A | ||
| CVE-2026-61797 | 0 | 0.00% | 1 | 1 | N/A | ||
| CVE-2026-89049 | 0 | 0.36% | 1 | 0 | N/A | ||
| CVE-2026-63030 | 0 | 97.27% | 3 | 85 | N/A | ||
| CVE-2026-15891 | 0 | 0.34% | 2 | 0 | N/A | ||
| CVE-2026-53761 | 0 | 0.34% | 1 | 0 | N/A |
updated 2026-09-15T04:18:19.173000
1 posts
CVE-2026-87719 GitLab EE: authed Duo Chat user can leak Advanced Search configs and credentials via crafted GraphQL subscription, CVSS 9.9. No patch confirmed. Update now.
https://www.valtersit.com/cve/CVE-2026-87719/
#CVE #GitLab #infosec
updated 2026-09-15T04:18:15.100000
16 posts
CRITICAL (CVSS 9.8): CVE-2026-76461 in Cisco AsyncOS for Secure Email Gateway lets unauthenticated attackers execute commands as root via crafted emails. Patch status unknown — monitor Cisco’s updates. https://radar.offseq.com/threat/a-vulnerability-in-the-email-parsing-of-cisco-asyncos-software-for-cisco-secure-email-gateway-could-a5a1b3247d786df4 #OffSeq #Cisco #Vulnerability #EmailSecurity
##CVE-2026-76461 (CVSS 9.8) is a Cisco Secure Email Gateway vulnerability exploited in the wild. SQL injection grants root command execution. Patch now.
#Cisco #EmailSecurity #CVE202676461 #SQLInjection #RCE #ExploitedInTheWild #AsyncOS #InfoSec #PatchNow #RootAccess
##No one else seems to have noticed the Cisco exploited zero-day:
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability
##🚨 [CISA-2026:0914] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0914)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-76461 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76461)
- Name: Cisco Secure Email Gateway SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Email Gateway
- Notes: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-76461
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260914 #cisa20260914 #cve_2026_76461 #cve202676461
##CRITICAL CISA KEV ALERT: CVE-2026-76461 targets Cisco Secure Email Gateway via SQL injection, granting root-level RCE. Active exploitation verified. Access our TSUITE brief for SIEM queries and hardening steps to secure your email perimeter.
##CVE ID: CVE-2026-76461
Vendor: Cisco
Product: Secure Email Gateway
Date Added: 2026-09-14
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76461
Welcome to Monday and two new advisories from Cisco.
CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm
CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
Two more critical vulnerabilities on the 9th and the 11th https://sec.cloudapps.cisco.com/security/center/publicationListing.x @TalosSecurity #Cisco #infosec #vulnerability
##ayy lmao Cisco CVE-2026-76461
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
##In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability.
CRITICAL (CVSS 9.8): CVE-2026-76461 in Cisco AsyncOS for Secure Email Gateway lets unauthenticated attackers execute commands as root via crafted emails. Patch status unknown — monitor Cisco’s updates. https://radar.offseq.com/threat/a-vulnerability-in-the-email-parsing-of-cisco-asyncos-software-for-cisco-secure-email-gateway-could-a5a1b3247d786df4 #OffSeq #Cisco #Vulnerability #EmailSecurity
##CVE-2026-76461 (CVSS 9.8) is a Cisco Secure Email Gateway vulnerability exploited in the wild. SQL injection grants root command execution. Patch now.
#Cisco #EmailSecurity #CVE202676461 #SQLInjection #RCE #ExploitedInTheWild #AsyncOS #InfoSec #PatchNow #RootAccess
##Since no one seems to have noticed the Cisco exploited zero-day:
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability
##🚨 [CISA-2026:0914] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0914)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-76461 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76461)
- Name: Cisco Secure Email Gateway SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Email Gateway
- Notes: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-76461
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260914 #cisa20260914 #cve_2026_76461 #cve202676461
##CRITICAL CISA KEV ALERT: CVE-2026-76461 targets Cisco Secure Email Gateway via SQL injection, granting root-level RCE. Active exploitation verified. Access our TSUITE brief for SIEM queries and hardening steps to secure your email perimeter.
##CVE ID: CVE-2026-76461
Vendor: Cisco
Product: Secure Email Gateway
Date Added: 2026-09-14
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76461
Welcome to Monday and two new advisories from Cisco.
CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm
CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
Two more critical vulnerabilities on the 9th and the 11th https://sec.cloudapps.cisco.com/security/center/publicationListing.x @TalosSecurity #Cisco #infosec #vulnerability
##ayy lmao Cisco CVE-2026-76461
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
##In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability.
updated 2026-09-15T04:18:12.660000
2 posts
Welcome to Monday and two new advisories from Cisco.
CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm
CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
Two more critical vulnerabilities on the 9th and the 11th https://sec.cloudapps.cisco.com/security/center/publicationListing.x @TalosSecurity #Cisco #infosec #vulnerability
##Welcome to Monday and two new advisories from Cisco.
CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm
CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
Two more critical vulnerabilities on the 9th and the 11th https://sec.cloudapps.cisco.com/security/center/publicationListing.x @TalosSecurity #Cisco #infosec #vulnerability
##updated 2026-09-15T03:31:31
2 posts
🟠 CVE-2026-90493 - High (8.8)
A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper access controls...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90493/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Tonec Internet Download Manager <=6.42.63 hit by CRITICAL vuln (CVE-2026-90493) in idmwfp.sys — improper access controls enable local privilege escalation. Public exploit code, no patch yet. Restrict local access & monitor. https://radar.offseq.com/threat/cve-2026-90493-improper-access-controls-in-tonec-internet-download-manager-a788ce95502ef3ad #OffSeq #CVE202690493 #Vuln #Cybersecurity
##updated 2026-09-15T03:30:30
2 posts
EFM ipTIME C200E v1.094 suffers CRITICAL OS command injection (CVE-2026-90847, CVSS 9.4) via iux_set.cgi. Remotely exploitable, public exploit available. Restrict device access and monitor. https://radar.offseq.com/threat/cve-2026-90847-os-command-injection-in-efm-iptime-c200e-1c30057b126bbbf4 #OffSeq #Vulnerability #IoTSecurity #CVE
##EFM ipTIME C200E v1.094 suffers CRITICAL OS command injection (CVE-2026-90847, CVSS 9.4) via iux_set.cgi. Remotely exploitable, public exploit available. Restrict device access and monitor. https://radar.offseq.com/threat/cve-2026-90847-os-command-injection-in-efm-iptime-c200e-1c30057b126bbbf4 #OffSeq #Vulnerability #IoTSecurity #CVE
##updated 2026-09-15T02:16:49.680000
2 posts
🟠 CVE-2026-91771 - High (8.8)
Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download function, allowing path traversal attacks. Attackers controlling the backend can supply file names with directory traversal sequences t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91771/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-91771 - High (8.8)
Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download function, allowing path traversal attacks. Attackers controlling the backend can supply file names with directory traversal sequences t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91771/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T00:31:22
2 posts
🟠 CVE-2026-91200 - High (8.8)
DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attackers operating a malicious container can stream tar entries with traversal sequences to write arbitrary files on the developer w...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91200/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-91200 - High (8.8)
DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attackers operating a malicious container can stream tar entries with traversal sequences to write arbitrary files on the developer w...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91200/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T00:31:21
4 posts
CVE-2026-12944 (CRITICAL, CVSS 9.6) affects IBM Langflow OSS 1.0.0 – 1.10.0. Attackers can execute arbitrary Python as root via SSRF, steal AWS creds, and move laterally. Patch is available — validate remediation. https://radar.offseq.com/threat/cve-2026-12944-cwe-918-server-side-request-forgery-ssrf-in-ibm-langflow-oss-98110564771040c9 #OffSeq #SSRF #IBM #CloudSecurity
##🔴 CVE-2026-12944 - Critical (9.6)
IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12944/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-12944 (CRITICAL, CVSS 9.6) affects IBM Langflow OSS 1.0.0 – 1.10.0. Attackers can execute arbitrary Python as root via SSRF, steal AWS creds, and move laterally. Patch is available — validate remediation. https://radar.offseq.com/threat/cve-2026-12944-cwe-918-server-side-request-forgery-ssrf-in-ibm-langflow-oss-98110564771040c9 #OffSeq #SSRF #IBM #CloudSecurity
##🔴 CVE-2026-12944 - Critical (9.6)
IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12944/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T00:31:21
2 posts
🟠 CVE-2026-91144 - High (7.5)
ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the shared ba...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91144/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-91144 - High (7.5)
ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the shared ba...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91144/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T21:31:46
2 posts
🟠 CVE-2026-82028 - High (8.8)
Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API services that allows authenticated attackers to inject arbitrary SQL by supplying a malicious format query parameter that is interp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82028/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82028 - High (8.8)
Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API services that allows authenticated attackers to inject arbitrary SQL by supplying a malicious format query parameter that is interp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82028/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T21:31:42
2 posts
🟠 CVE-2026-89023 - High (8.6)
ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its REST API endpoints that allows unauthenticated attackers to access and manipulate protected resources. Attackers can retrieve stor...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89023/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89023 - High (8.6)
ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its REST API endpoints that allows unauthenticated attackers to access and manipulate protected resources. Attackers can retrieve stor...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89023/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T21:17:12.520000
2 posts
🔴 CVE-2026-53713 - Critical (9.1)
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, to_absolute_normalized_path in internal/gatewayapi/luavalidator/security.lua does not collapse redu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53713/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-53713 - Critical (9.1)
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, to_absolute_normalized_path in internal/gatewayapi/luavalidator/security.lua does not collapse redu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53713/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T21:10:17.423000
2 posts
🟠 CVE-2026-88793 - High (8.8)
The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it prints on every front-end page, and does not escape the stored data before rendering it, allowing ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88793/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-88793 - High (8.8)
The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it prints on every front-end page, and does not escape the stored data before rendering it, allowing ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88793/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T21:10:17.423000
2 posts
🟠 CVE-2026-85129 - High (8.8)
The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85129/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-85129 - High (8.8)
The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85129/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T21:10:17.423000
1 posts
🔴 CVE-2026-77005 - Critical (9.6)
The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber,...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77005/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T21:10:17.423000
1 posts
🟠 CVE-2026-80494 - High (8.6)
The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrar...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80494/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T21:10:17.423000
1 posts
🔴 CVE-2026-82845 - Critical (9.9)
The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82845/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T21:10:17.423000
1 posts
🟠 CVE-2026-87888 - High (8)
The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administra...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87888/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T21:10:17.423000
2 posts
🔴 CVE-2026-85681 - Critical (9.8)
The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users, and it takes both the option name and the option value from the request, allowing unaut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85681/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-85681 (CRITICAL): WP Component plugin ≤2.2.4 allows unauthenticated option overwrites, risking full WordPress site takeover. Single-site installs are exposed. Check vendor advisory for mitigation steps: https://radar.offseq.com/threat/cve-2026-85681-cwe-269-improper-privilege-management-in-wp-component-ee74cec7c7b526ed #OffSeq #WordPress #Vuln #BlueTeam
##updated 2026-09-14T21:03:01.800000
1 posts
🟠 CVE-2026-90537 - High (8.2)
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to access scheduler email jobs by providing a site-wide...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90537/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T20:58:48.430000
2 posts
CVE-2026-78330 | CRITICAL: Apache Syncope vuln allows admin escalation if JWKS is exposed and JWT auth used. Affects 3.0.0-M0 – 3.0.16, 4.0.0-M0 – 4.0.7, 4.1.0-M0 – 4.1.2. Upgrade to 4.0.8/4.1.3 to mitigate. Details: https://radar.offseq.com/threat/incorrect-privilege-assignment-vulnerability-in-apache-syncope-cve-2026-78330-b2c023a1d947f76b #OffSeq #Vulnerability #ApacheSyncope
##CVE-2026-78330 | CRITICAL: Apache Syncope vuln allows admin escalation if JWKS is exposed and JWT auth used. Affects 3.0.0-M0 – 3.0.16, 4.0.0-M0 – 4.0.7, 4.1.0-M0 – 4.1.2. Upgrade to 4.0.8/4.1.3 to mitigate. Details: https://radar.offseq.com/threat/incorrect-privilege-assignment-vulnerability-in-apache-syncope-cve-2026-78330-b2c023a1d947f76b #OffSeq #Vulnerability #ApacheSyncope
##updated 2026-09-14T20:56:48.220000
6 posts
CVE-2026-90606: HIGH-severity buffer overflow in Totolink A3002MU Hh-B20211125.1046 (boa/formIpv6Setup). Public exploit disclosed. RCE or DoS possible. Restrict access & monitor IPv6 setup. No patch yet. https://radar.offseq.com/threat/a-security-vulnerability-has-been-detected-in-totolink-a3002mu-hh-b202111251046-cve-2026-90606-6a6dad4a128a1845 #OffSeq #Vuln #IoTSecurity #BufferOverflow
##🔴 CVE-2026-90606 - Critical (9.9)
A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to buffer ov...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90606/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-90606: CRITICAL buffer overflow in Totolink A3002MU (Hh-B20211125.1046). Remote attackers can exploit static_ipv6 in /boafrm/formIpv6Setup. Exploit is public — review device exposure now. https://radar.offseq.com/threat/cve-2026-90606-buffer-overflow-in-totolink-a3002mu-ff1e560ec5dedad6 #OffSeq #CVE202690606 #RouterSecurity #NetSec
##CVE-2026-90606: HIGH-severity buffer overflow in Totolink A3002MU Hh-B20211125.1046 (boa/formIpv6Setup). Public exploit disclosed. RCE or DoS possible. Restrict access & monitor IPv6 setup. No patch yet. https://radar.offseq.com/threat/a-security-vulnerability-has-been-detected-in-totolink-a3002mu-hh-b202111251046-cve-2026-90606-6a6dad4a128a1845 #OffSeq #Vuln #IoTSecurity #BufferOverflow
##🔴 CVE-2026-90606 - Critical (9.9)
A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to buffer ov...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90606/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-90606: CRITICAL buffer overflow in Totolink A3002MU (Hh-B20211125.1046). Remote attackers can exploit static_ipv6 in /boafrm/formIpv6Setup. Exploit is public — review device exposure now. https://radar.offseq.com/threat/cve-2026-90606-buffer-overflow-in-totolink-a3002mu-ff1e560ec5dedad6 #OffSeq #CVE202690606 #RouterSecurity #NetSec
##updated 2026-09-14T20:56:48.220000
2 posts
🔴 CVE-2026-90680 - Critical (9.9)
A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gateway re...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90680/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-90680 - Critical (9.9)
A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gateway re...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90680/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T20:56:48.220000
2 posts
🔴 CVE-2026-90605 - Critical (9.9)
A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overf...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90605/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-90605 - Critical (9.9)
A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overf...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90605/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T20:56:48.220000
2 posts
🟠 CVE-2026-90510 - High (8.3)
A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/org/drom...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90510/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-90510 - High (8.3)
A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/org/drom...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90510/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T20:16:52.847000
3 posts
2 repos
CVE-2026-78006: The Events Calendar plugin ≤6.17.4 has a CRITICAL RCE flaw. Unauthenticated attackers can run code via comment handling — disable event comments until patched. Review vendor advisories. https://radar.offseq.com/threat/the-the-events-calendar-plugin-for-wordpress-is-vulnerable-to-remote-code-execution-in-all-versions-up-6446d1c8dfcb6a24 #OffSeq #WordPress #CVE202678006 #RCE
##CVE-2026-78006: CRITICAL RCE in The Events Calendar plugin (<=6.17.4) for WordPress. Unauthenticated attackers can exploit comments to run code on the server. Disable event comments now & check for patches. https://radar.offseq.com/threat/cve-2026-78006-cwe-502-deserialization-of-untrusted-data-in-stellarwp-the-events-calendar-efa20e86741ba4b3 #OffSeq #WordPress #RCE #Vuln
##🔴 CVE-2026-78006 - Critical (9.8)
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78006/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T20:16:49.103000
2 posts
🟠 CVE-2026-65838 - High (8.2)
Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass a deny-on-...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65838/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-65838 - High (8.2)
Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass a deny-on-...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65838/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T20:16:48.440000
2 posts
🟠 CVE-2026-57126 - High (8.5)
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _host_is_blocked, which checks literal host encodings but does not resolve DNS names before scrape_page, crawl, extract_links, extract_text, ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57126/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-57126 - High (8.5)
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _host_is_blocked, which checks literal host encodings but does not resolve DNS names before scrape_page, crawl, extract_links, extract_text, ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57126/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T19:18:14.500000
2 posts
🟠 CVE-2026-91080 - High (7.5)
webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies. Attackers can send multi-gigabyte request bodies with invalid signat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91080/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-91080 - High (7.5)
webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies. Attackers can send multi-gigabyte request bodies with invalid signat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91080/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T19:18:08.653000
2 posts
🟠 CVE-2026-90768 - High (8.1)
CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete analyses submitted by other users. Attackers can enumerate all tasks in the system and delete arbitrary analyses ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90768/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-90768 - High (8.1)
CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete analyses submitted by other users. Attackers can enumerate all tasks in the system and delete arbitrary analyses ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90768/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T19:18:08.107000
2 posts
The UnrealIRCd security issue from yesterday was assigned CVE-2026-90668. Admins on older versions could apply a hot-patch to fix the issue without restart.
We have been doing that at UnrealIRCd for more than 20 years now, so I wrote a story on my personal blog about how effective it is, and the times it did not work: https://www.vulnscan.org/why-hot-patching-is-awesome/
##🟠 CVE-2026-90668 - High (7.5)
The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackers to cause a denial of service (memory consumption and unresponsive server) via an HTTP request with an unl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90668/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T18:31:35
2 posts
🟠 CVE-2026-91079 - High (8.5)
Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply arbitrary URLs to the print endpoint, which Puppeteer ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91079/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-91079 - High (8.5)
Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply arbitrary URLs to the print endpoint, which Puppeteer ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91079/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T18:31:29
2 posts
🟠 CVE-2026-90946 - High (7.5)
DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment. Attackers can supply arbitrary directory paths to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90946/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-90946 - High (7.5)
DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment. Attackers can supply arbitrary directory paths to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90946/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T18:31:29
2 posts
Looks like Microsoft has a couple of new flaws.
NEW and CRITICAL: CVE-2026-85921: Windows Secure Kernel Mode Elevation of Privilege Vulnerabilityhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85921
NEW and CRITICAL: CVE-2026-85921: Windows Secure Kernel Mode Elevation of Privilege Vulnerability New https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85921 #infosec #Microsoft #vulnerability #Windows
##Looks like Microsoft has a couple of new flaws.
NEW and CRITICAL: CVE-2026-85921: Windows Secure Kernel Mode Elevation of Privilege Vulnerabilityhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85921
NEW and CRITICAL: CVE-2026-85921: Windows Secure Kernel Mode Elevation of Privilege Vulnerability New https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85921 #infosec #Microsoft #vulnerability #Windows
##updated 2026-09-14T18:31:29
2 posts
Welcome to Monday and two new advisories from Cisco.
CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm
CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
Two more critical vulnerabilities on the 9th and the 11th https://sec.cloudapps.cisco.com/security/center/publicationListing.x @TalosSecurity #Cisco #infosec #vulnerability
##Welcome to Monday and two new advisories from Cisco.
CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm
CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
Two more critical vulnerabilities on the 9th and the 11th https://sec.cloudapps.cisco.com/security/center/publicationListing.x @TalosSecurity #Cisco #infosec #vulnerability
##updated 2026-09-14T18:31:22
2 posts
Welcome to Monday and two new advisories from Cisco.
CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm
CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
Two more critical vulnerabilities on the 9th and the 11th https://sec.cloudapps.cisco.com/security/center/publicationListing.x @TalosSecurity #Cisco #infosec #vulnerability
##Welcome to Monday and two new advisories from Cisco.
CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm
CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
Two more critical vulnerabilities on the 9th and the 11th https://sec.cloudapps.cisco.com/security/center/publicationListing.x @TalosSecurity #Cisco #infosec #vulnerability
##updated 2026-09-14T18:20:29.030000
4 posts
🔴 CVE-2026-90945 - Critical (9.8)
Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90945/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Go fuck with some crawlers.
https://nvd.nist.gov/vuln/detail/cve-2026-90945
##Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and execute code on worker nodes.
🔴 CVE-2026-90945 - Critical (9.8)
Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90945/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Go fuck with some crawlers.
https://nvd.nist.gov/vuln/detail/cve-2026-90945
##Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and execute code on worker nodes.
updated 2026-09-14T18:20:26.223000
2 posts
🟠 CVE-2026-90777 - High (8.8)
ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files that execute code during deseri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90777/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-90777 - High (8.8)
ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files that execute code during deseri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90777/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T18:20:25.707000
2 posts
🟠 CVE-2026-90772 - High (7.6)
Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerror handlers...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90772/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-90772 - High (7.6)
Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerror handlers...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90772/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T18:08:58
2 posts
🔴 CVE-2026-59178 - Critical (9.8)
ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the dashboard reads its authentication credentials from `$ESPHOME_USERNAME` and `$ESPHOME_PASSWORD`. Earlier versions, and the legac...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59178/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-59178 - Critical (9.8)
ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the dashboard reads its authentication credentials from `$ESPHOME_USERNAME` and `$ESPHOME_PASSWORD`. Earlier versions, and the legac...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59178/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T17:17:55.827000
1 posts
CVE-2026-90648: HIGH severity vuln in wasm2c (WebAssembly wabt <=1.0.41). Unchecked calloc() return enables sandbox escape & code exec if allocation fails — mainly on 32-bit/memory-limited systems. Patch status pending. https://radar.offseq.com/threat/cve-2026-90648-cwe-252-unchecked-return-value-in-webassembly-wabt-365471fbebafc772 #OffSeq #WebAssembly #CVE202690648
##updated 2026-09-14T17:17:51.410000
3 posts
CVE-2026-78159: The Events Calendar <=6.17.3 for WordPress has a CRITICAL RCE flaw via parse_array(). Unauthenticated code execution if comments on tribe_events posts are enabled. Disable comments as interim mitigation. https://radar.offseq.com/threat/the-the-events-calendar-plugin-for-wordpress-is-vulnerable-to-remote-code-execution-in-all-versions-up-1ecd7d8aa73f934d #OffSeq #WordPress #RCE #CVE202678159
##CVE-2026-78159: CRITICAL RCE in The Events Calendar (<=6.17.3). Unauthenticated attackers can run arbitrary code via crafted comments. Disable comments on tribe_events posts to mitigate. CVSS 9.8. Details: https://radar.offseq.com/threat/cve-2026-78159-cwe-94-improper-control-of-generation-of-code-code-injection-in-stellarwp-the-events-c0d168b99a9315ff #OffSeq #WordPress #Infosec #RCE
##🔴 CVE-2026-78159 - Critical (9.8)
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-arr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78159/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T15:33:39
2 posts
🔴 CVE-2026-89697 - Critical (9.1)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr()
The BOTH_TIME_SET branch calls fh_verify() early so setattr_prepare()
can inspect the dentry. This ca...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89697/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-89697 - Critical (9.1)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr()
The BOTH_TIME_SET branch calls fh_verify() early so setattr_prepare()
can inspect the dentry. This ca...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89697/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T15:33:38
2 posts
🟠 CVE-2026-89704 - High (7.5)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: sample writeback error cursor before async COPY loop
_nfsd_copy_file_range() samples dst->f_wb_err into "since"
after the copy loop, then uses it to detect writeback error...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89704/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89704 - High (7.5)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: sample writeback error cursor before async COPY loop
_nfsd_copy_file_range() samples dst->f_wb_err into "since"
after the copy loop, then uses it to detect writeback error...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89704/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T15:33:29
1 posts
CVE-2026-89461 Linux kernel max17040 power supply race on suspend. Work callback can keep running and requeue itself after suspend, causing use-after-suspend. No CVSS, still unpatched. Update kernel when fix lands. #CVE #Linux https://www.valtersit.com/cve/CVE-2026-89461/
##updated 2026-09-14T15:33:27
1 posts
CVE-2026-80970 Linux kernel ALSA FCP ioctl leaks uninitialised kmalloc memory to userspace via copy_to_user. Info disclosure, no CVSS or patch yet. Patch or restrict ioctl access. https://www.valtersit.com/cve/CVE-2026-80970/ #CVE #infosec #Linux
##updated 2026-09-14T15:33:22
1 posts
CVE-2026-80912: Linux kernel SELinux flaw—a NULL deref via an unclaimed class value can crash the system. CVSS: N/A, unpatched. If you run SELinux, review your policy and wait for the fix. Patch ASAP when available. https://www.valtersit.com/cve/CVE-2026-80912/ #CVE #Linux #infos
##updated 2026-09-14T15:32:42
2 posts
Hiperdino REST API v1.0 (CVE-2026-12258) has a CRITICAL info disclosure flaw (CVSS 9.2): attackers with a static bearer token can enumerate user contact info via the 'customer/check' endpoint. No patch yet. Restrict token access & monitor usage. https://radar.offseq.com/threat/cve-2026-12258-cwe-284-improper-access-control-in-hiperdino-rest-api-827f2edf6294f9bd #OffSeq #infosec #APIsecurity
##Hiperdino REST API v1.0 (CVE-2026-12258) has a CRITICAL info disclosure flaw (CVSS 9.2): attackers with a static bearer token can enumerate user contact info via the 'customer/check' endpoint. No patch yet. Restrict token access & monitor usage. https://radar.offseq.com/threat/cve-2026-12258-cwe-284-improper-access-control-in-hiperdino-rest-api-827f2edf6294f9bd #OffSeq #infosec #APIsecurity
##updated 2026-09-14T15:32:39
2 posts
🟠 CVE-2026-88802 - High (7.5)
The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88802/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-88802 - High (7.5)
The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88802/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T15:32:38
2 posts
🔴 CVE-2026-81648 - Critical (10)
The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81648/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-81648 - Critical (10)
The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81648/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T15:32:38
2 posts
🟠 CVE-2026-74933 - High (8.8)
The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and in...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74933/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-74933 - High (8.8)
The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and in...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74933/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T15:32:36
2 posts
🟠 CVE-2026-89736 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: u_audio: Fix use-after-free on sound card disconnect
g_audio_cleanup() invokes snd_card_free_when_closed() to initiate sound
card teardown and immediately frees the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89736/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89736 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: u_audio: Fix use-after-free on sound card disconnect
g_audio_cleanup() invokes snd_card_free_when_closed() to initiate sound
card teardown and immediately frees the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89736/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T15:32:36
2 posts
🟠 CVE-2026-89750 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
tracing/user_events: Clear copied tracing state before fork duplication
dup_task_struct() copies user_event_mm from the parent into the child,
without grabbing a reference to it...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89750/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89750 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
tracing/user_events: Clear copied tracing state before fork duplication
dup_task_struct() copies user_event_mm from the parent into the child,
without grabbing a reference to it...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89750/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T15:32:36
2 posts
🟠 CVE-2026-89744 - High (8.4)
In the Linux kernel, the following vulnerability has been resolved:
device property: fix infinite loop in fwnode_for_each_child_node()
When iterate over children of a fwnode that has a secondary fwnode,
fwnode_get_next_child_node() can enter an ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89744/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89744 - High (8.4)
In the Linux kernel, the following vulnerability has been resolved:
device property: fix infinite loop in fwnode_for_each_child_node()
When iterate over children of a fwnode that has a secondary fwnode,
fwnode_get_next_child_node() can enter an ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89744/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T15:32:35
2 posts
🟠 CVE-2026-89706 - High (7.5)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: Reset write verifier when async COPY writeback fails
Async COPY captures nn->writeverf at request time and reports it to
the client via CB_OFFLOAD after the worker kthread...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89706/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89706 - High (7.5)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: Reset write verifier when async COPY writeback fails
Async COPY captures nn->writeverf at request time and reports it to
the client via CB_OFFLOAD after the worker kthread...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89706/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T15:32:07
2 posts
1 repos
🚨 ZcopyReaper (CVE-2026-43502) has been identified as a notable vulnerability.
In the Linux kernel, the following vulnerability has been resolved:
net/rds: handle zerocopy send cleanup before the message is queued
A zerocopy send can fail after user pages have been pinned but before
the message is attached to the sending socket.
The purge path currently infers zerocopy state from rm->m_rs, so an
unqueued message can be cleaned up as if it owned normal payload pages.
However, zerocopy ownership is really determined by the presence of
op_mmp_znotifier, regardless of whether the message has reached the
socket queue.
Capture op_mmp_znotifier up front in rds_message_purge() and use it as
the cleanup discriminator. If the message is already associated with a
socket, keep the existing completion path. Otherwise, drop the pinned
page accounting directly and release the notifier before putting the
payload pages.
This keeps early send failure cleanup consistent with the zerocopy
lifetime rules without changing the normal queued completion path.
ℹ️ Additional information on ZEN SecDB 👉 https://secdb.nttzen.cloud/cve/detail/CVE-2026-43502
#Infosec #ZcopyReaper #Linux #Kernel #LPE #CVE202643502
#NTTData #ZEN #SecDB
🚨 ZcopyReaper (CVE-2026-43502) has been identified as a notable vulnerability.
In the Linux kernel, the following vulnerability has been resolved:
net/rds: handle zerocopy send cleanup before the message is queued
A zerocopy send can fail after user pages have been pinned but before
the message is attached to the sending socket.
The purge path currently infers zerocopy state from rm->m_rs, so an
unqueued message can be cleaned up as if it owned normal payload pages.
However, zerocopy ownership is really determined by the presence of
op_mmp_znotifier, regardless of whether the message has reached the
socket queue.
Capture op_mmp_znotifier up front in rds_message_purge() and use it as
the cleanup discriminator. If the message is already associated with a
socket, keep the existing completion path. Otherwise, drop the pinned
page accounting directly and release the notifier before putting the
payload pages.
This keeps early send failure cleanup consistent with the zerocopy
lifetime rules without changing the normal queued completion path.
ℹ️ Additional information on ZEN SecDB 👉 https://secdb.nttzen.cloud/cve/detail/CVE-2026-43502
#Infosec #ZcopyReaper #Linux #Kernel #LPE #CVE202643502
#NTTData #ZEN #SecDB
updated 2026-09-14T15:17:13.630000
2 posts
CVE-2026-90919: ModelTC LightLLM <=1.2.0 faces CRITICAL RCE risk. Unauthenticated /visual_register WebSocket lets attackers send malicious pickle data, leading to code execution. Patch or restrict access fast. https://radar.offseq.com/threat/cve-2026-90919-deserialization-of-untrusted-data-in-modeltc-lightllm-99a91583cd9500c2 #OffSeq #CVE202690919 #RCE #LightLLM
##CVE-2026-90919: ModelTC LightLLM <=1.2.0 faces CRITICAL RCE risk. Unauthenticated /visual_register WebSocket lets attackers send malicious pickle data, leading to code execution. Patch or restrict access fast. https://radar.offseq.com/threat/cve-2026-90919-deserialization-of-untrusted-data-in-modeltc-lightllm-99a91583cd9500c2 #OffSeq #CVE202690919 #RCE #LightLLM
##updated 2026-09-14T14:22:15.323000
27 posts
12 repos
https://github.com/ynsmroztas/GitLabSniper
https://github.com/0xenesbayram/cve-2026-85706
https://github.com/0xlyvio/cve-2026-85706-poc-exploit-gitlab
https://github.com/gagaltotal/CVE-2026-85706-gitlab-poc
https://github.com/solivaquaant/CVE-2026-85706
https://github.com/plur1bu5/gitread
https://github.com/guneykabel/cve-2026-85706
https://github.com/jithinkrishnanrs/gitlab-cve-2026-85706-ioc
https://github.com/mhtsec/CVE-2026-85706
https://github.com/gabrielunknown/CVE-2026-85706
⚪️ Developers Urge Immediate Fix for Critical GitLab Vulnerability
🗨️ GitLab engineers have released patches for the critical CVE-2026-85706 vulnerability, which received the maximum CVSS score of 10 and allows an unauthenticated attacker to read arbitrary files on a server. Security researchers warn that attackers began attempting to exploit the…
##CRITICAL CISA KEV ALERT: CVE-2026-85706 targets GitLab CE/EE via path traversal in the repository commits API. Active exploitation verified. Access our TSUITE brief for SIEM detection queries and compensating controls to protect your CI/CD pipeline and isolate your secrets.
##GitLab CVE-2026-85706: A Critical Zero-Authentication Flaw Is Now Being Exploited in the Wild + Video
GitLab CVE-2026-85706: A Critical Zero-Authentication Flaw Is Now Being Exploited in the Wild Introduction: A GitLab Warning That Security Teams Cannot Ignore A critical GitLab vulnerability has rapidly moved from a newly patched security issue to an active exploitation concern. Tracked as CVE-2026-85706, the flaw carries the maximum CVSS score of 10.0 and affects…
##New.
Rapid7: CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-85706-critical-gitlab-path-traversal-exploited-in-the-wild/ @Rapid7Official #infosec #GitLab #vulnerability
##⚠️GitLab : CVE-2026-85706 est activement exploitée.
Une faille critique de traversée de répertoires permet à un attaquant non authentifié de lire des fichiers arbitraires sur le serveur.
Encore une vulnérabilité qui prend des chemins de traverse…
../../../../etc/ :dumpster_fire_gif: 👀
-->GitLab auto-hébergé exposé sur Internet : mise à jour rapide recommandée.
Correctifs : 19.1.8, 19.2.6 et 19.3.2.
La faille a déjà rejoint le catalogue KEV de la CISA, et ça commence clairement à renifler autour : watchTowr et plusieurs honeypots ont déjà vu passer des tentatives de probing.
Onyphe recense une bonne centaine d’instances vulnérables en CH aujourd'hui...
##CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild
#CVE_2026_85706
https://www.rapid7.com/blog/post/etr-cve-2026-85706-critical-gitlab-path-traversal-exploited-in-the-wild/
GitLab Faces a Critical Security Emergency as CVE-2026-85706 Enters the CISA Exploited Vulnerabilities List + Video
Introduction: A GitLab Warning That Administrators Cannot Afford to Ignore A maximum-severity vulnerability in self-hosted GitLab installations has moved from a serious security concern to an urgent patching priority after researchers detected apparent exploitation attempts in the wild. The flaw, tracked as CVE-2026-85706, can allow an unauthenticated…
##Recent reports confirm a critical GitLab zero-day (CVE-2026-85706) exploited within 24 hours, alongside new EU Cyber Resilience Act mandates for 24-hour vulnerability reporting. Operational technology (OT) sectors face emerging ransomware threats. Meanwhile, leading AI developers advocate for a slowdown in development due to safety concerns, prompting market shifts. Geopolitically, the BRICS summit addressed rising global tensions and the "weaponization of technology."
##GitLab Flaw Exploited in Wild, Prompting Urgent Patch Push
A critical GitLab bug, CVE-2026-85706, is under active exploitation, putting sensitive files at risk of exposure due to a path traversal vulnerability that allows unauthenticated users to access arbitrary files. GitLab has urgently pushed a patch to fix the flaw, affecting versions CE/EE 18.7 to 19.3.2.
#Gitlab #Cve202685706 #PathTraversal #VulnerabilityExploitation #EmergingThreats
##📢 [VULN] GitLab : mise à jour de sécurité critique CVE-2026-85706
GitLab a publié le 10 septembre des mises à jour de sécurité. Ce patch critique concerne les versions enterprise et communautaire. Les versions 19.3.2, 19.2.8 et 19.1.8 corrigent un important bug et plusieurs failles de sécurité. GitLab recommande la mise à jour.
🔗 https://www.programmez.com/actualites/gitlab-mise-jour-de-securite-critique-40109
💬 discussion : https://infosec.pub/post/52275402
#CVE #Cyberveille
CVE-2026-85706 GitLab CE/EE: unauthenticated arbitrary file read via commits API, CVSS 10. Affects 18.7 up to 19.1.8, 19.2.6, 19.3.2. No patch confirmed yet, restrict access now. https://www.valtersit.com/cve/CVE-2026-85706/ #CVE #GitLab #infosec
##Hackers Exploit GitLab Flaw in Active Attacks
Hackers are actively exploiting a critical GitLab flaw, CVE-2026-85706, that allows them to read sensitive information like credentials and secrets with just a single HTTP request. This vulnerability enables attackers to access arbitrary files, potentially exposing long-lived secrets and confidential data.
#Gitlab #Cve202685706 #PathTraversal #VulnerabilityExploitation #EmergingThreats
##📰 GitLab Patches Critical CVSS 10.0 Path Traversal Vulnerability
GitLab releases emergency patches for a critical CVSS 10.0 path traversal flaw (CVE-2026-85706). Unauthenticated attackers can read arbitrary files. Active scanning detected. Upgrade self-managed instances NOW. #GitLab #CVE #CyberSecurity #PatchNow
##GitLab CVE-2026-85706: Critical CVSS 100 Flaw Is Already Being Probed in the Wild + Video
GitLab CVE-2026-85706: Critical CVSS 10.0 Path Traversal Flaw Puts Sensitive Files at Risk A Maximum-Severity Warning for GitLab Administrators A dangerous new GitLab vulnerability has moved from disclosure to real-world reconnaissance with remarkable speed. Tracked as CVE-2026-85706, the flaw carries the maximum CVSS score of 10.0 and affects the repository commits API in…
##⚪️ Developers Urge Immediate Fix for Critical GitLab Vulnerability
🗨️ GitLab engineers have released patches for the critical CVE-2026-85706 vulnerability, which received the maximum CVSS score of 10 and allows an unauthenticated attacker to read arbitrary files on a server. Security researchers warn that attackers began attempting to exploit the…
##CRITICAL CISA KEV ALERT: CVE-2026-85706 targets GitLab CE/EE via path traversal in the repository commits API. Active exploitation verified. Access our TSUITE brief for SIEM detection queries and compensating controls to protect your CI/CD pipeline and isolate your secrets.
##New.
Rapid7: CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-85706-critical-gitlab-path-traversal-exploited-in-the-wild/ @Rapid7Official #infosec #GitLab #vulnerability
##⚠️GitLab : CVE-2026-85706 est activement exploitée.
Une faille critique de traversée de répertoires permet à un attaquant non authentifié de lire des fichiers arbitraires sur le serveur.
Encore une vulnérabilité qui prend des chemins de traverse…
../../../../etc/ :dumpster_fire_gif: 👀
-->GitLab auto-hébergé exposé sur Internet : mise à jour rapide recommandée.
Correctifs : 19.1.8, 19.2.6 et 19.3.2.
La faille a déjà rejoint le catalogue KEV de la CISA, et ça commence clairement à renifler autour : watchTowr et plusieurs honeypots ont déjà vu passer des tentatives de probing.
Onyphe recense une bonne centaine d’instances vulnérables en CH aujourd'hui...
##CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild
#CVE_2026_85706
https://www.rapid7.com/blog/post/etr-cve-2026-85706-critical-gitlab-path-traversal-exploited-in-the-wild/
Recent reports confirm a critical GitLab zero-day (CVE-2026-85706) exploited within 24 hours, alongside new EU Cyber Resilience Act mandates for 24-hour vulnerability reporting. Operational technology (OT) sectors face emerging ransomware threats. Meanwhile, leading AI developers advocate for a slowdown in development due to safety concerns, prompting market shifts. Geopolitically, the BRICS summit addressed rising global tensions and the "weaponization of technology."
##2026-W37 — Weekly Threat Roundup
🤖 AI is no longer just a defender's tool: state-sponsored groups and criminals weaponized Claude, ChatGPT, and OpenAI agents to automate exploitation, rebuild malware, and generate one million personalized phishing emails in three days.
🔓 GitLab's CVSS 10.0 path traversal flaw (CVE-2026-85706) wa…
https://threatnoir.com/weekly/2026-w37
#infosec #cybersecurity #threatintel
🤖 AI generated summary
##GitLab CVE-2026-85706 is a maximum-severity path traversal in the repository commits API enabling unauthenticated arbitrary file read on self-managed servers. CISA added it to KEV with a three-day deadline, signaling active exploitation risk. Patch immediately and review for anomalous access to credentials and secrets. #GitLab #CisaKev #InfoSec
https://cyberworldops.eu/en/gitlab-path-traversal-flaw-enters-cisa-kev-with-three-day-patch
##That is a faster turnaround than most people's pizza delivery.
Patch GitLab immediately to remediate CVE-2026-85706 — your self-managed server is the featured product in someone else's highlight reel.
Reward: Complimentary sponsorship credit from Deferred Maintenance Inc. Your inaction keeps them in business.
https://www.securityweek.com/gitlab-vulnerability-exploited-one-day-after-disclosure/
#GitLab #CyberSecurity #ZeroDay #PathTraversal #CVE #PatchedOrPerish (2/2)
##🏆 New Achievement! Speed-Run Sponsored by Your Unpatched GitLab!
This achievement is brought to you by Deferred Maintenance Inc. — when you absolutely, positively need unauthenticated strangers reading every file on your server within a single HTTP request. CVE-2026-85706 scored a perfect ten out of ten on the CVSS scale, because some bugs don't do half measures. GitLab dropped patches on a Thursday. By Friday, WatchTowr was already watching wild exploitation probes roll in. One day. (1/2)
##📰 GitLab Patches Critical CVSS 10.0 Path Traversal Vulnerability
GitLab releases emergency patches for a critical CVSS 10.0 path traversal flaw (CVE-2026-85706). Unauthenticated attackers can read arbitrary files. Active scanning detected. Upgrade self-managed instances NOW. #GitLab #CVE #CyberSecurity #PatchNow
##🚨 Detection for the actively exploited GitLab vulnerability tagged as CVE-2026-85706 (CVSS 10.0) available here:
https://github.com/projectdiscovery/nuclei-templates/pull/17231/changes
PoC for unauthenticated arbitrary file read on Gitlab https://github.com/guneykabel/cve-2026-85706
##updated 2026-09-14T14:17:08.940000
3 posts
VLC Media Player Flaws Allow Heap Corruption and Sensitive Data Disclosure
VideoLAN reports two vulnerabilities in VLC Media Player (CVE-2026-56711 and CVE-2026-73324) that allow attackers to corrupt heap memory or leak sensitive data via crafted PNG files and RTSP streams.
**If you use VLC Media Player (any version from 3.0.0 to 3.0.23), update it to the latest patched version as soon as VideoLAN releases it. Until you've updated, don't open media files, playlists, or RTSP streaming links that come from people or websites you don't know and trust.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/vlc-media-player-flaws-allow-heap-corruption-and-sensitive-data-disclosure-6-k-q-2-9/gD2P6Ple2L
VLC Media Player Flaws Allow Heap Corruption and Sensitive Data Disclosure
VideoLAN reports two vulnerabilities in VLC Media Player (CVE-2026-56711 and CVE-2026-73324) that allow attackers to corrupt heap memory or leak sensitive data via crafted PNG files and RTSP streams.
**If you use VLC Media Player (any version from 3.0.0 to 3.0.23), update it to the latest patched version as soon as VideoLAN releases it. Until you've updated, don't open media files, playlists, or RTSP streaming links that come from people or websites you don't know and trust.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/vlc-media-player-flaws-allow-heap-corruption-and-sensitive-data-disclosure-6-k-q-2-9/gD2P6Ple2L
https://thecybersecguru.com/news/vlc-media-player-vulnerabilities-cve-2026-56711-cve-2026-73324/
##updated 2026-09-14T13:51:41.830000
1 posts
🟠 CVE-2026-16482 - High (7.5)
The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'compare' parameter in all versions up to, and including, 4.7.11 due to insufficient escaping on the user supplied param...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16482/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T13:19:23.350000
2 posts
🟠 CVE-2026-89746 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
tracing: Fix use-after-free with same-name named triggers
When two hist triggers on different events are registered with the same
name=, the second one reuses the first as named...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89746/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89746 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
tracing: Fix use-after-free with same-name named triggers
When two hist triggers on different events are registered with the same
name=, the second one reuses the first as named...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89746/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T13:19:19.897000
2 posts
🟠 CVE-2026-89696 - High (7.5)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref
When CONFIG_NFSD_V4_2_INTER_SSC is enabled, nfsd4_putfh() can return
success with fh_dentry and fh_export bo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89696/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89696 - High (7.5)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref
When CONFIG_NFSD_V4_2_INTER_SSC is enabled, nfsd4_putfh() can return
success with fh_dentry and fh_export bo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89696/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T13:19:19.610000
2 posts
🟠 CVE-2026-89684 - High (7.5)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix cpntf publish race in nfs4_init_cp_state
nfs4_alloc_init_cpntf_state() published the new cpntf entry into the
s2s_cp_stateids IDR (with cs_type set) in one s2s_cp_lock...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89684/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89684 - High (7.5)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix cpntf publish race in nfs4_init_cp_state
nfs4_alloc_init_cpntf_state() published the new cpntf entry into the
s2s_cp_stateids IDR (with cs_type set) in one s2s_cp_lock...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89684/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T13:19:07.210000
1 posts
CVE-2026-89504 Linux kernel regulator as3722 use-after-free via premature of_node_put, dangling of_node pointer. CVSS N/A, no patch yet. Audit your kernels and apply fixes as soon as they land. https://www.valtersit.com/cve/CVE-2026-89504/ #CVE #Linux #infosec
##updated 2026-09-14T13:19:05.627000
1 posts
CVE-2026-89488: use-after-free in Linux openvswitch CT limit teardown. Unprivileged user can trigger slab-UAF in ovs_ct_execute(). CVSS N/A, no patch yet. Update immediately. https://www.valtersit.com/cve/CVE-2026-89488/ #CVE #Linux #infosec
##updated 2026-09-14T12:31:44
2 posts
D-Link DWR-M921 v1.1.52 is vulnerable to CRITICAL OS command injection (CVE-2026-90703, CVSS 9.4). No patch yet, public exploit out. Restrict access & monitor logs. Details: https://radar.offseq.com/threat/cve-2026-90703-os-command-injection-in-d-link-dwr-m921-f9739a3ef4495656 #OffSeq #CVE #RouterSecurity #Infosec
##D-Link DWR-M921 v1.1.52 is vulnerable to CRITICAL OS command injection (CVE-2026-90703, CVSS 9.4). No patch yet, public exploit out. Restrict access & monitor logs. Details: https://radar.offseq.com/threat/cve-2026-90703-os-command-injection-in-d-link-dwr-m921-f9739a3ef4495656 #OffSeq #CVE #RouterSecurity #Infosec
##updated 2026-09-14T03:30:29
4 posts
🔴 CVE-2026-90607 - Critical (9.9)
A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow. The atta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90607/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Totolink A3002MU routers hit by CRITICAL (CVSS 9.4) buffer overflow (CVE-2026-90607) in formNewSchedule. Public exploit code available. Restrict remote access & monitor systems until a patch is released. https://radar.offseq.com/threat/cve-2026-90607-buffer-overflow-in-totolink-a3002mu-f5be31acbfac3e1f #OffSeq #CVE202690607 #RouterSecurity #Infosec
##🔴 CVE-2026-90607 - Critical (9.9)
A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow. The atta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90607/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Totolink A3002MU routers hit by CRITICAL (CVSS 9.4) buffer overflow (CVE-2026-90607) in formNewSchedule. Public exploit code available. Restrict remote access & monitor systems until a patch is released. https://radar.offseq.com/threat/cve-2026-90607-buffer-overflow-in-totolink-a3002mu-f5be31acbfac3e1f #OffSeq #CVE202690607 #RouterSecurity #Infosec
##updated 2026-09-14T03:30:29
4 posts
🔴 CVE-2026-90608 - Critical (9.9)
A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It is possible...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90608/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-90608: Totolink A3002MU routers have a CRITICAL buffer overflow (CVSS 9.4) in /boafrm/formPortFw. Exploit code is public; RCE possible. No patch — restrict external access & monitor vendor updates. https://radar.offseq.com/threat/cve-2026-90608-buffer-overflow-in-totolink-a3002mu-43328ea907451224 #OffSeq #CVE202690608 #RouterSecurity
##🔴 CVE-2026-90608 - Critical (9.9)
A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It is possible...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90608/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-90608: Totolink A3002MU routers have a CRITICAL buffer overflow (CVSS 9.4) in /boafrm/formPortFw. Exploit code is public; RCE possible. No patch — restrict external access & monitor vendor updates. https://radar.offseq.com/threat/cve-2026-90608-buffer-overflow-in-totolink-a3002mu-43328ea907451224 #OffSeq #CVE202690608 #RouterSecurity
##updated 2026-09-14T03:30:29
2 posts
🟠 CVE-2026-33963 - High (7.5)
An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs when a malformed message is sent to the camera driver, causing a denial of service.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-33963/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-33963 - High (7.5)
An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs when a malformed message is sent to the camera driver, causing a denial of service.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-33963/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T03:30:22
3 posts
1 repos
🟠 New security advisory:
CVE-2026-31278 affects multiple systems.
• Impact: Significant security breach potential
• Risk: Unauthorized access or data exposure
• Mitigation: Apply patches within 24-48 hours
Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-31278-biostar-2-leaks-ad-service-credentials-poc
by Yazoul AI
##🟠 CVE-2026-31278 - High (7.7)
An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-31278/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-31278 - High (7.7)
An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-31278/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T02:17:13.397000
2 posts
🟠 CVE-2026-23789 - High (7.8)
An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC encoder driv...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-23789/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-23789 - High (7.8)
An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC encoder driv...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-23789/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T00:16:56.207000
1 posts
2 repos
PaperCut Attacker (Russian Linked) Uses AI Agents to Compromise 440 Instances
러시아어권으로 추정되는 공격자가 PaperCut NG/MF의 인증 우회·RCE 체인(CVE-2026-81578, CVE-2026-82078)을 악용해 48개국 395개 조직의 최소 440개 인스턴스를 침해한 것으로 보고됐다. 공격자는 OpenAI Codex, DeepSeek 모델, Hindsight의 지속 메모리, AionUi 멀티 에이전트 작업 공간을 결합해 취약점 분석부터 익스플로잇 수정, 표적 분류, 재시도, AD 정찰까지 자동화했으며, 실제 공격 개시 후 2...
https://www.swapupdate.in/papercut-attacker-uses-hundreds-of-ai-agents-to-compromise-440-instances/
##updated 2026-09-13T21:31:54
2 posts
🟠 CVE-2026-37008 - High (8.1)
CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete obj...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-37008/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-37008 - High (8.1)
CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete obj...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-37008/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T21:31:53
2 posts
🟠 CVE-2026-29811 - High (7.7)
CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-29811/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-29811 - High (7.7)
CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-29811/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T15:30:28
2 posts
🟠 CVE-2026-90783 - High (7.8)
MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an unde...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90783/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-90783 - High (7.8)
MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an unde...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90783/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T12:31:19
2 posts
CVE-2026-90775: HIGH severity vuln in PostGIS address_standardizer (≤3.7.0) allows out-of-bounds read via unvalidated Weight parameter, crashing PostgreSQL backend (DoS). Patch status pending — monitor vendor updates. https://radar.offseq.com/threat/cve-2026-90775-out-of-bounds-read-in-postgis-addressstandardizer-b09887107f7082c5 #OffSeq #PostGIS #Vuln
##CVE-2026-90775: HIGH severity vuln in PostGIS address_standardizer (≤3.7.0) allows out-of-bounds read via unvalidated Weight parameter, crashing PostgreSQL backend (DoS). Patch status pending — monitor vendor updates. https://radar.offseq.com/threat/cve-2026-90775-out-of-bounds-read-in-postgis-addressstandardizer-b09887107f7082c5 #OffSeq #PostGIS #Vuln
##updated 2026-09-13T12:31:19
2 posts
🟠 CVE-2026-90779 - High (7.5)
SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to corrupt th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90779/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-90779 - High (7.5)
SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to corrupt th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90779/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T12:31:19
2 posts
🟠 CVE-2026-90778 - High (7.5)
SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversized tag para...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90778/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-90778 - High (7.5)
SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversized tag para...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90778/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T12:31:19
2 posts
🟠 CVE-2026-90776 - High (7.5)
Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separated atoms...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90776/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-90776 - High (7.5)
Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separated atoms...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90776/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T12:31:19
2 posts
🟠 CVE-2026-90780 - High (7.5)
SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes. Unauthenticated remote attackers can send crafted SIP messages ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90780/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-90780 - High (7.5)
SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes. Unauthenticated remote attackers can send crafted SIP messages ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90780/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T12:31:19
2 posts
🟠 CVE-2026-90769 - High (7.7)
Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata, internal ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90769/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-90769 - High (7.7)
Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata, internal ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90769/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T12:31:19
2 posts
🟠 CVE-2026-90774 - High (7.5)
rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path traversal sequences in the filename header to write f...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90774/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-90774 - High (7.5)
rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path traversal sequences in the filename header to write f...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90774/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T12:31:12
2 posts
🟠 CVE-2026-90770 - High (8.8)
Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation. Authenticated users with monitor permissions can inject...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90770/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-90770 - High (8.8)
Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation. Authenticated users with monitor permissions can inject...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90770/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T12:31:11
4 posts
Strapi 4.x – 4.26.2 & 5.x<5.48.1: CRITICAL stored XSS (CVE-2026-90561, CVSS 8.7) in WYSIWYG preview lets Author roles execute malicious scripts in higher-privileged sessions. Restrict roles & monitor vendor updates. https://radar.offseq.com/threat/strapi-versions-4x-through-4262-and-5x-before-5481-contain-a-stored-cross-site-scripting-vulnerability-e05bee9fce842336 #OffSeq #Strapi #XSS #Infosec
##🟠 CVE-2026-90561 - High (8.7)
Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich text. An Author-role user can store malicious s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90561/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Strapi 4.x – 4.26.2 & 5.x<5.48.1: CRITICAL stored XSS (CVE-2026-90561, CVSS 8.7) in WYSIWYG preview lets Author roles execute malicious scripts in higher-privileged sessions. Restrict roles & monitor vendor updates. https://radar.offseq.com/threat/strapi-versions-4x-through-4262-and-5x-before-5481-contain-a-stored-cross-site-scripting-vulnerability-e05bee9fce842336 #OffSeq #Strapi #XSS #Infosec
##🟠 CVE-2026-90561 - High (8.7)
Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich text. An Author-role user can store malicious s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90561/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T12:31:10
2 posts
🟠 CVE-2026-89080 - High (7.5)
The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the sec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89080/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89080 - High (7.5)
The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the sec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89080/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T12:31:09
2 posts
🟠 CVE-2026-86406 - High (7.5)
The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated user such ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86406/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86406 - High (7.5)
The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated user such ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86406/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T11:17:00.780000
4 posts
🟠 CVE-2026-90562 - High (8.1)
LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through con...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90562/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##LangBot <4.10.11 is affected by CRITICAL CVE-2026-90562: password reset keys generated with only 24 bits of entropy & no rate limiting let attackers brute-force admin resets. Upgrade to 4.10.11+! https://radar.offseq.com/threat/cve-2026-90562-insufficient-entropy-in-langbot-app-langbot-e9a2899a1e2d1fa5 #OffSeq #CVE202690562 #infosec #AppSec
##🟠 CVE-2026-90562 - High (8.1)
LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through con...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90562/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##LangBot <4.10.11 is affected by CRITICAL CVE-2026-90562: password reset keys generated with only 24 bits of entropy & no rate limiting let attackers brute-force admin resets. Upgrade to 4.10.11+! https://radar.offseq.com/threat/cve-2026-90562-insufficient-entropy-in-langbot-app-langbot-e9a2899a1e2d1fa5 #OffSeq #CVE202690562 #infosec #AppSec
##updated 2026-09-13T09:33:34
2 posts
🟠 CVE-2026-89687 - High (7.5)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file
->atomic_open is permitted to return success without actually opening
the file. It indicates this by calling ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89687/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89687 - High (7.5)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file
->atomic_open is permitted to return success without actually opening
the file. It indicates this by calling ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89687/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T09:33:34
2 posts
🟠 CVE-2026-89692 - High (7.5)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: clear CALLBACK_RUNNING on failed delegation recall queue
nfsd_break_one_deleg() sets NFSD4_CALLBACK_RUNNING via test_and_set_bit
at entry to serialize recall work, then ca...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89692/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89692 - High (7.5)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: clear CALLBACK_RUNNING on failed delegation recall queue
nfsd_break_one_deleg() sets NFSD4_CALLBACK_RUNNING via test_and_set_bit
at entry to serialize recall work, then ca...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89692/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T09:33:34
2 posts
🟠 CVE-2026-89690 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: defer vfree of compound ops to fix rpc_status UAF
The rpc_status netlink dumpit walks every in-flight svc_rqst under
rcu_read_lock and, for NFSv4 requests, reads opnums ou...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89690/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89690 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: defer vfree of compound ops to fix rpc_status UAF
The rpc_status netlink dumpit walks every in-flight svc_rqst under
rcu_read_lock and, for NFSv4 requests, reads opnums ou...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89690/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T09:33:34
1 posts
🟠 CVE-2026-89764 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
rust: devres: fix race between concurrent revokers
There is a potential race condition when two paths try to revoke a
Devres concurrently.
The driver core's devres_release_all(...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89764/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T09:33:34
1 posts
🟠 CVE-2026-89763 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
KEYS: trusted: Fix TPM teardown ordering
trusted_tpm_exit() drops the TPM chip reference and frees the digest
array before unregistering the trusted key type. key_type_lookup()
...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89763/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T09:33:31
2 posts
🔴 CVE-2026-89688 - Critical (9.8)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: drop the stateid, not the stateowner, on seqid_op replay retry
In nfs4_preprocess_seqid_op() the stateid is obtained from
nfsd4_lookup_stateid(), which holds a reference o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89688/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-89688 - Critical (9.8)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: drop the stateid, not the stateowner, on seqid_op replay retry
In nfs4_preprocess_seqid_op() the stateid is obtained from
nfsd4_lookup_stateid(), which holds a reference o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89688/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T09:33:31
2 posts
🔴 CVE-2026-89612 - Critical (9.8)
In the Linux kernel, the following vulnerability has been resolved:
ntfs: reject invalid MFT LCNs from boot sector
The NTFS boot sector stores the MFT and MFTMirr locations as unsigned
64-bit LCNs, but parse_ntfs_boot_sector() decoded them into ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89612/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-89612 - Critical (9.8)
In the Linux kernel, the following vulnerability has been resolved:
ntfs: reject invalid MFT LCNs from boot sector
The NTFS boot sector stores the MFT and MFTMirr locations as unsigned
64-bit LCNs, but parse_ntfs_boot_sector() decoded them into ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89612/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T09:33:31
2 posts
🟠 CVE-2026-89695 - High (7.5)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: cap decoded POSIX ACL count to bound sort cost
nfsd4_decode_posixacl() reads a u32 entry count off the wire and passes
it straight to posix_acl_alloc() and sort_pacl_range...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89695/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89695 - High (7.5)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: cap decoded POSIX ACL count to bound sort cost
nfsd4_decode_posixacl() reads a u32 entry count off the wire and passes
it straight to posix_acl_alloc() and sort_pacl_range...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89695/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T09:33:30
2 posts
🔴 CVE-2026-89689 - Critical (9.8)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: don't free session slots that are still in use
nfsd4_sequence() can free the very slot it is currently processing.
When the session shrinker has reduced se_target_maxslots...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89689/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-89689 - Critical (9.8)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: don't free session slots that are still in use
nfsd4_sequence() can free the very slot it is currently processing.
When the session shrinker has reduced se_target_maxslots...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89689/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T09:33:21
1 posts
CVE-2026-80980 Linux kernel net/smc bitfield race - killed, freed, out_of_sync share one byte without a common lock, a data race that can corrupt connection state. CVSS N/A, patch status unknown/unpatched. Audit https://www.valtersit.com/cve/CVE-2026-80980/ #CVE #Linux #infosec
##updated 2026-09-13T09:32:30
2 posts
🟠 CVE-2026-89747 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
tracing: Fix use-after-free in trace_pipe read on sub-buffer order change
Writing to buffer_subbuf_size_kb calls ring_buffer_subbuf_order_set(),
which frees every sub-buffer of ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89747/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89747 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
tracing: Fix use-after-free in trace_pipe read on sub-buffer order change
Writing to buffer_subbuf_size_kb calls ring_buffer_subbuf_order_set(),
which frees every sub-buffer of ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89747/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T09:32:30
2 posts
🟠 CVE-2026-89758 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
mm/mempolicy: skip non-present PMDs when queueing folios
Patch series "mm: handle device-private PMDs in walk callbacks", v3.
Since commit 368076f52ebe ("mm/huge_memory: add de...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89758/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89758 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
mm/mempolicy: skip non-present PMDs when queueing folios
Patch series "mm: handle device-private PMDs in walk callbacks", v3.
Since commit 368076f52ebe ("mm/huge_memory: add de...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89758/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T09:32:30
1 posts
🟠 CVE-2026-89754 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
mm/pagewalk: fix stale walk->action escaping walk_pmd_range()
If ->pmd_entry() sets walk->action = ACTION_AGAIN, the pmd_none() check is
retried. The PMD entry may be cleared a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89754/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T09:32:30
1 posts
🟠 CVE-2026-89762 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
apparmor: fix cred UAF caused by begin_current_label_crit_section()
AppArmor's begin_current_label_crit_section() is a scary function called
from lots of LSM hooks (in particula...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89762/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T09:32:30
1 posts
🟠 CVE-2026-89761 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
apparmor: fix out-of-bounds write when null terminating a label vec
aa_vec_unique() null terminates at vec[n - dups] when VEC_FLAG_TERMINATE
is passed. If the components are all...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89761/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T09:32:30
1 posts
🟠 CVE-2026-89760 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
mm, swap: don't free a hibernation slot that is in the swap cache
A slot with a folio in the swap cache is freed when the folio leaves the
cache, not when its count drops. swap...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89760/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T09:32:28
2 posts
🟠 CVE-2026-89685 - High (7.5)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix clock domain mismatch in clients_still_reclaiming()
clients_still_reclaiming() computes a deadline from nn->boot_time
(CLOCK_REALTIME, ~1.7 billion) but compares it ag...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89685/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89685 - High (7.5)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix clock domain mismatch in clients_still_reclaiming()
clients_still_reclaiming() computes a deadline from nn->boot_time
(CLOCK_REALTIME, ~1.7 billion) but compares it ag...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89685/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T09:32:28
2 posts
🟠 CVE-2026-89682 - High (8.1)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix fcache_disposal UAF by inlining dispose state into nfsd_net
nfsd_file_dispose_list_delayed() defers fput() to nfsd service threads
via a per-net freeme queue, preventi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89682/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89682 - High (8.1)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix fcache_disposal UAF by inlining dispose state into nfsd_net
nfsd_file_dispose_list_delayed() defers fput() to nfsd service threads
via a per-net freeme queue, preventi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89682/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T09:32:24
2 posts
🔴 CVE-2026-89613 - Critical (9.8)
In the Linux kernel, the following vulnerability has been resolved:
ntfs: reject invalid empty mapping pairs
Reject an attribute with empty mapping pairs if it has inconsistent
highest VCN and size.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89613/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-89613 - Critical (9.8)
In the Linux kernel, the following vulnerability has been resolved:
ntfs: reject invalid empty mapping pairs
Reject an attribute with empty mapping pairs if it has inconsistent
highest VCN and size.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89613/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T07:17:41.310000
1 posts
🟠 CVE-2026-89771 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
ring-buffer: Fix subbuf resize race with ring buffer readers
trace_buffer subbuf_size is read lockless in ring_buffer_read_page() and
ring_buffer_read_start(), while it can simu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89771/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T07:17:41.050000
1 posts
🟠 CVE-2026-89767 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
ovl: fix double end_creating() on the casefold-mismatch path
ovl_create_real() releases the new dentry twice when the casefold
consistency check fails. The S_IFDIR branch calls...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89767/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T07:17:39.983000
1 posts
🟠 CVE-2026-89755 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
mm/migrate_device: clear stale mapping after freeing swapcache
__migrate_device_pages() reads the folio mapping before calling
folio_free_swap(). When folio_free_swap() succeed...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89755/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T07:17:39.493000
2 posts
🟠 CVE-2026-89748 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
tracing: Fix retry exhaustion in simple ring buffer reader swap
simple_ring_buffer_swap_reader_page() starts with retry set to 8 and
post-decrements it only after a failed link ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89748/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89748 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
tracing: Fix retry exhaustion in simple ring buffer reader swap
simple_ring_buffer_swap_reader_page() starts with retry set to 8 and
post-decrements it only after a failed link ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89748/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T07:17:34.367000
2 posts
🔴 CVE-2026-89686 - Critical (9.8)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke
nfsd4_alloc_layout_stateid reads fp->fi_deleg_file without holding
fi_lock when the parent stateid is ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89686/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-89686 - Critical (9.8)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke
nfsd4_alloc_layout_stateid reads fp->fi_deleg_file without holding
fi_lock when the parent stateid is ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89686/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T07:17:26.617000
2 posts
🔴 CVE-2026-89611 - Critical (9.8)
In the Linux kernel, the following vulnerability has been resolved:
ntfs: validate non-resident attribute offsets
ntfs_attr_update_meta() shifts the attribute name when converting between
non-sparse and sparse attributes. Converting to sparse al...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89611/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-89611 - Critical (9.8)
In the Linux kernel, the following vulnerability has been resolved:
ntfs: validate non-resident attribute offsets
ntfs_attr_update_meta() shifts the attribute name when converting between
non-sparse and sparse attributes. Converting to sparse al...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89611/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T07:17:13.100000
1 posts
CVE-2026-89499 Linux kernel ring-buffer flaw: failed remote page swap corrupts reader state, risking kernel crash or memory corruption during event storms. No CVSS or patch yet. Track it and apply updates as https://www.valtersit.com/cve/CVE-2026-89499/ #CVE #Linux #infosec
##updated 2026-09-13T07:17:07.273000
2 posts
CVE-2026-81006 Linux kernel ipmi: failed registration leaves sysfs files on freed memory, risking use-after-free. CVSS N/A, patch status unknown. Update your kernel now. https://www.valtersit.com/cve/CVE-2026-81006/ #CVE #Linux #infosec
##CVE-2026-81006 Linux kernel ipmi: failed registration leaves sysfs files on freed memory, risking use-after-free. CVSS N/A, patch status unknown. Update your kernel now. https://www.valtersit.com/cve/CVE-2026-81006/ #CVE #Linux #infosec
##updated 2026-09-13T07:17:01.960000
1 posts
CVE-2026-80947 Linux kernel rtl8xxxu wifi driver use-after-free on stop, triggered via RX path. CVSS N/A, no patch yet. Update your kernel now. https://www.valtersit.com/cve/CVE-2026-80947/ #CVE #Linux #infosec
##updated 2026-09-13T06:33:11
1 posts
🟠 CVE-2026-90678 - High (7.5)
An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3 frontend: HAProxy must be built with QUIC support and configured with a QUIC bind listener, and the affected traffic must reac...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90678/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T00:31:26
2 posts
CVE-2026-90651 | HIGH severity in Socket Socket Firewall <2.0.0: TLS certs not validated by default — MITM risk. Set api_ssl_verify and upstream_ssl_verify to true & patch configs or upgrade to 2.0.0+. https://radar.offseq.com/threat/cve-2026-90651-cwe-295-improper-certificate-validation-in-socket-socket-firewall-a5dfe1c95649d9c6 #OffSeq #vuln #infosec #supplychain
##🟠 CVE-2026-90651 - High (8.1)
Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the api_ssl_verify and upstream_ssl_verify configuration keys are omitted from socket.yml, the generated ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90651/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-12T23:17:01.490000
1 posts
CVE-2026-90647 (CRITICAL, CVSS 9.1) affects Kalkitech ASE2000 V2 (2.35 – 2.37): improper TLS certificate validation in IEC 60870-5-104 enables MitM attacks. No patch confirmed. Restrict access & monitor. https://radar.offseq.com/threat/cve-2026-90647-cwe-295-improper-certificate-validation-in-kalkitech-ase2000-v2-communication-test-set-2a292ef0f6b1257f #OffSeq #ICS #CVE202690647 #TLS
##updated 2026-09-12T21:31:19
1 posts
CVE-2026-90616: Flatpak <1.18.1 has a HIGH severity vuln — malicious sandboxed apps can use symlinks to gain arbitrary read/write host access, risking code execution. Update to 1.18.1+ now. https://radar.offseq.com/threat/in-flatpak-before-1181-a-malicious-sandboxed-app-can-obtain-arbitrary-read-and-write-access-to-files-4ccb40754f32d716 #OffSeq #Flatpak #Linux #Security
##updated 2026-09-12T18:31:29
2 posts
🔴 CVE-2026-84171 - Critical (9.8)
The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84171/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##WP images upload on piclect (≤1.0) suffers from CRITICAL CVE-2026-84171: Unauthenticated attackers can upload arbitrary files, risking code execution. Restrict uploads & monitor activity until a fix is released. https://radar.offseq.com/threat/cve-2026-84171-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-wp-images-upload-on-piclect-1bdb1fa95a2cb1f8 #OffSeq #WordPress #CVE202684171 #Vuln
##updated 2026-09-12T18:31:28
1 posts
🔴 CVE-2026-75800 - Critical (9.8)
The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as wel...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75800/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-12T18:31:28
1 posts
🔴 CVE-2026-77006 - Critical (9.6)
The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77006/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-12T18:31:28
1 posts
🟠 CVE-2026-84047 - High (8.6)
The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84047/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-12T18:31:28
1 posts
🟠 CVE-2026-87842 - High (7.5)
The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retrieve it and authenticate to the site owner's linked...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87842/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-12T18:30:33
2 posts
CVE-2026-90558: CRITICAL stack buffer overflow in irontec sngrep (<=1.8.4). Malicious SIP headers can crash or allow code execution. Patch status pending — filter untrusted SIP traffic. https://radar.offseq.com/threat/cve-2026-90558-stack-based-buffer-overflow-in-irontec-sngrep-f0d23a6d23082198 #OffSeq #CVE202690558 #vuln #SIPrisk
##🔴 CVE-2026-90558 - Critical (9.8)
sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other hea...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90558/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-12T18:30:33
1 posts
🟠 CVE-2026-90560 - High (8.2)
zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90560/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-12T18:30:33
1 posts
🟠 CVE-2026-90559 - High (7.5)
snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never validated against decompressed size. Attackers can supply valid compressed data th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90559/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-12T18:30:33
1 posts
🟠 CVE-2026-90556 - High (7.8)
Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that write p...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90556/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-12T18:30:22
1 posts
🟠 CVE-2026-81742 - High (8.8)
The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated users to i...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81742/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-12T18:30:22
1 posts
🟠 CVE-2026-87759 - High (8.8)
The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pending site-membership invitation carrying a caller-supplied role, allowing any authenticated user, such as a subscriber, to gr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87759/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-12T18:30:22
1 posts
🟠 CVE-2026-84099 - High (8.1)
The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84099/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-12T18:30:21
1 posts
🔴 CVE-2026-81402 - Critical (9.8)
The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, to a web-ac...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81402/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-12T18:30:21
1 posts
🟠 CVE-2026-80491 - High (8.6)
The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80491/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-12T15:31:56
1 posts
🟠 CVE-2026-90553 - High (7.8)
vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90553/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-12T15:31:49
1 posts
🟠 CVE-2026-15451 - High (8.8)
The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.39. This is due to a mass assignment vulnerability in the 'add_sub_account_user' function that passes the raw 'user...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15451/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-12T09:33:41
1 posts
🟠 CVE-2026-78175 - High (8.8)
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJAX handl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78175/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-12T09:33:36
1 posts
🟠 CVE-2026-85200 - High (7.5)
The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function. This makes it possible for unauthenticated attackers to include and ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85200/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-12T04:16:42.757000
9 posts
🏆 New Achievement! The Help Desk Has Turned Against You!
PHASE ONE: ConnectWise ScreenConnect, your trusted remote support companion, enters the arena. PHASE TWO: CVE-2026-84869 awakens — CVSS 9.9, the kind of score that makes sysadmins physically leave their bodies. PHASE THREE: the worm-like propagation begins, chaining active remote sessions into unauthorized file transfers and full remote code execution. Huntress confirmed real-world exploitation. (1/2)
##ConnectWise ScreenConnect Flaw Turns Remote Support Into a Worm-Like Attack Engine + Video
A Critical Vulnerability With a Dangerous Twist ConnectWise has rushed out an emergency security update for its ScreenConnect remote access and support platform after a critical vulnerability was exploited in real-world attacks. Tracked as CVE-2026-84869 and rated 9.9 out of 10, the flaw is particularly dangerous because attackers can potentially abuse an active remote session to…
##CRITICAL CISA KEV ALERT: CVE-2026-84869 targets ConnectWise ScreenConnect with unauthorized file transfer and RCE. Active exploitation verified. Access our TSUITE brief for Splunk, Sentinel, QRadar queries, and endpoint hardening steps to protect your environment. https://thecybermind.co/g5ob
##ConnectWise patched CVE-2026-84869, a critical ScreenConnect authorization flaw allowing file transfer and execution via active sessions. Huntress reports worm-like exploitation since August 20. It enables lateral spread without host confirmation, requiring immediate patching and session review. #ScreenConnect #CyberSecurity #InfoSec
https://cyberworldops.eu/en/critical-screenconnect-flaw-fuels-worm-like-attacks-through-active
##ConnectWise ScreenConnect CRITICAL vuln (CVE-2026-84869) exploited in worm-like attacks — unauthorized file transfer & execution via remote sessions in versions <26.6.5. Patch to 26.6.5 now or disable TransferFiles. https://radar.offseq.com/threat/connectwise-patches-screenconnect-vulnerability-exploited-in-worm-like-attacks-c3e27ae69aeeacb1 #OffSeq #Cybersecurity #Vuln #CISA
##🏆 New Achievement! The Help Desk Has Turned Against You!
PHASE ONE: ConnectWise ScreenConnect, your trusted remote support companion, enters the arena. PHASE TWO: CVE-2026-84869 awakens — CVSS 9.9, the kind of score that makes sysadmins physically leave their bodies. PHASE THREE: the worm-like propagation begins, chaining active remote sessions into unauthorized file transfers and full remote code execution. Huntress confirmed real-world exploitation. (1/2)
##CRITICAL CISA KEV ALERT: CVE-2026-84869 targets ConnectWise ScreenConnect with unauthorized file transfer and RCE. Active exploitation verified. Access our TSUITE brief for Splunk, Sentinel, QRadar queries, and endpoint hardening steps to protect your environment. https://thecybermind.co/g5ob
##ConnectWise patched CVE-2026-84869, a critical ScreenConnect authorization flaw allowing file transfer and execution via active sessions. Huntress reports worm-like exploitation since August 20. It enables lateral spread without host confirmation, requiring immediate patching and session review. #ScreenConnect #CyberSecurity #InfoSec
https://cyberworldops.eu/en/critical-screenconnect-flaw-fuels-worm-like-attacks-through-active
##ConnectWise ScreenConnect CRITICAL vuln (CVE-2026-84869) exploited in worm-like attacks — unauthorized file transfer & execution via remote sessions in versions <26.6.5. Patch to 26.6.5 now or disable TransferFiles. https://radar.offseq.com/threat/connectwise-patches-screenconnect-vulnerability-exploited-in-worm-like-attacks-c3e27ae69aeeacb1 #OffSeq #Cybersecurity #Vuln #CISA
##updated 2026-09-11T21:32:08
3 posts
1 repos
Artifactory: In-the-Wild Exploitation of CVE-2026-42016,CVE-2026-42018
Wiz Research는 JFrog Artifactory의 CVE-2026-42016, CVE-2026-42018, CVE-2026-82329가 실제 환경에서 활발히 악용되고 있음을 확인했다. 공격자는 익명 사용자 토큰 노출과 토큰 스코프 검증 결함을 연쇄해 인증 없이 관리자 권한 토큰을 획득하거나, CVE-2026-82329의 인증 우회로 직접 관리자 권한을 얻을 수 있다. 침해 후에는 지속성 관리자 계정 생성, Groovy 플러그인을 통한 서버 명령 실행, 클러스...
##CRITICAL SOC ALERT: CVE-2026-42018 exposes JFrog Artifactory via improper auth and token leakage. Active KEV exploitation verified. Access our TSUITE brief for Splunk, Sentinel, QRadar queries, and endpoint hardening steps to neutralize attacker persistence. https://thecybermind.co/9t6b
##CRITICAL CISA KEV ALERT: CVE-2026-42018 targets JFrog Artifactory via improper auth and token leakage. Active exploitation verified. Access our CSUITE Brief for technical execution vectors, asset integrity rules, and endpoint hardening steps to protect your enterprise perimeter. https://thecybermind.co/22sa
##updated 2026-09-11T21:31:37
1 posts
CVE-2026-89517 Linux kernel: sched_ext rq->core_pick corruption under core scheduling. CVSS N/A, patch status unknown. Kernel memory corruption risk. Patch now if a fix lands. https://www.valtersit.com/cve/CVE-2026-89517/ #CVE #Linux #infosec
##updated 2026-09-11T21:31:32
1 posts
CVE-2026-89447 Linux kernel iommufd flaw: internal accesses skip the matching put during unmap, risking a refcount/lock imbalance. No CVSS yet, patch status unknown. Patch or update now. https://www.valtersit.com/cve/CVE-2026-89447/ #CVE #Linux #infosec
##updated 2026-09-11T21:31:22
1 posts
CVE-2026-80974 Linux kernel sm501 mfd driver leaks memory on device removal. No CVSS assigned, patch status unknown. Update your kernel when a fix lands. Details: https://www.valtersit.com/cve/CVE-2026-80974/ #CVE #Linux #infosec
##updated 2026-09-11T21:31:06
5 posts
CRITICAL CISA KEV ALERT: CVE-2026-42016 targets JFrog Artifactory via incorrect authorization and token scope flaws. Active exploitation verified. Access our TSUITE brief for Splunk, Sentinel, QRadar queries, and endpoint hardening steps to secure your software pipelines.
##📢 Exploitation active de trois vulnérabilités critiques dans JFrog Artifactory
🔍 Contexte : Le 10 septembre 2026, Wiz Research publie une analyse technique détaillant l'exploitation active en conditions réelles de trois vulnérabilités critiques et de haute sévérité affectant JFrog Artifactory.
📖 cyberveille : https://cyberveille.ch/posts/2026-09-14-exploitation-active-de-trois-vulnerabilites-critiques-dans-jfrog-artifactory/
🌐 source : https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201
🟢 vérification factuelle haute
#JFrogArtifactory #ExploitationActive #Cyberveille
Artifactory: In-the-Wild Exploitation of CVE-2026-42016,CVE-2026-42018
Wiz Research는 JFrog Artifactory의 CVE-2026-42016, CVE-2026-42018, CVE-2026-82329가 실제 환경에서 활발히 악용되고 있음을 확인했다. 공격자는 익명 사용자 토큰 노출과 토큰 스코프 검증 결함을 연쇄해 인증 없이 관리자 권한 토큰을 획득하거나, CVE-2026-82329의 인증 우회로 직접 관리자 권한을 얻을 수 있다. 침해 후에는 지속성 관리자 계정 생성, Groovy 플러그인을 통한 서버 명령 실행, 클러스...
##🔵 THREAT INTELLIGENCE
CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
Vulnerability | CRITICAL
CVEs: CVE-2026-42016
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise...
Full analysis:
https://www.yazoul.net/news/article/cisa-adds-5-actively-exploited-artifactory-screenconnect-and-routeros-flaws-to-k
by Yazoul AI
##CRITICAL CISA KEV ALERT: CVE-2026-42016 targets JFrog Artifactory via incorrect authorization and token scope flaws. Active exploitation verified. Access our TSUITE brief for Splunk, Sentinel, QRadar queries, and endpoint hardening steps to secure your software pipelines.
##updated 2026-09-11T20:19:32.423000
1 posts
CVE-2026-89502 Linux kernel ring-buffer memory flaw. Patch status unknown, no CVSS yet. Update your kernels immediately. https://www.valtersit.com/cve/CVE-2026-89502/ #CVE #infosec #Linux
##updated 2026-09-11T15:32:49
2 posts
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
updated 2026-09-11T15:32:27
2 posts
1 repos
CRITICAL CISA KEV ALERT: CVE-2026-86060 targets MikroTik RouterOS via improper argument delimiter neutralization and command injection. Active exploitation verified. Access our TSUITE brief for hardening steps and network segmentation protocols to secure your perimeter.
##CRITICAL CISA KEV ALERT: CVE-2026-86060 targets MikroTik RouterOS via improper argument delimiter neutralization and command injection. Active exploitation verified. Access our TSUITE brief for hardening steps and network segmentation protocols to secure your perimeter.
##updated 2026-09-11T15:21:12.850000
2 posts
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
updated 2026-09-11T15:17:06.937000
2 posts
Orthanc DICOM Server is affected by CVE-2026-87020, an integer overflow in image pitch calculation enabling authenticated heap out-of-bounds write via malicious PNG. It matters for clinical environments where exploitation risks service disruption and imaging integrity. #OrthancServer #DicomSecurity #HeapCorruption
https://cyberworldops.eu/en/orthanc-dicom-server-flaw-allows-authenticated-attackers-to-corrupt
##Orthanc DICOM Server is affected by CVE-2026-87020, an integer overflow in image pitch calculation enabling authenticated heap out-of-bounds write via malicious PNG. It matters for clinical environments where exploitation risks service disruption and imaging integrity. #OrthancServer #DicomSecurity #HeapCorruption
https://cyberworldops.eu/en/orthanc-dicom-server-flaw-allows-authenticated-attackers-to-corrupt
##updated 2026-09-11T03:31:25
2 posts
Discover the dangerous Nintendo Switch QR code vulnerability (CVE-2026-82079) allowing hackers to execute code. Learn how system update 23.0.0 fixes it.
#NintendoSwitch #CyberSecurity #CVE202682079 #QRCode #Vulnerability
##Discover the dangerous Nintendo Switch QR code vulnerability (CVE-2026-82079) allowing hackers to execute code. Learn how system update 23.0.0 fixes it.
#NintendoSwitch #CyberSecurity #CVE202682079 #QRCode #Vulnerability
##updated 2026-09-10T19:54:25.810000
3 posts
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
Critical ConfigServer Firewall Flaw Allows Unauthenticated Remote Command Execution
ConfigServer Security & Firewall (CSF) patched a critical shell injection vulnerability (CVE-2026-65638) in its MESSENGER service that allows unauthenticated remote code execution.
**If you run ConfigServer Security & Firewall (CSF) on your Linux or cPanel/WHM servers, update to version 16.30 right away (on cPanel systems run `yum clean all` then `/scripts/update-packages`) to close CVE-2026-65638. If you can't update immediately, turn the vulnerable feature off by setting `MESSENGER = 0` in `/etc/csf/csf.conf`, restart with `systemctl restart csf lfd`. Then check your logs for any unexpected commands run under the CSF service account.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/critical-configserver-firewall-flaw-allows-unauthenticated-remote-command-execution-b-r-4-6-3/gD2P6Ple2L
updated 2026-09-10T18:33:04
2 posts
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
updated 2026-09-10T18:33:03
2 posts
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
updated 2026-09-10T15:33:58
2 posts
2 repos
Detecting and Weaponizing NetScaler
Citrix NetScaler ADC/Gateway의 SAML 처리 인증 우회 취약점 CVE-2026-19490(CVSS 9.3)이 공개됐다. 공격자는 인증 없이 특수한 RelayState 길이를 이용해 사후 로그인 처리 경로로 진입할 수 있으며, 구성에 따라 서비스 크래시(약 45초), 내부망 프록시 접근, 장비 root 명령 실행까지 이어질 수 있다. SAML이 설정된 Gateway·AAA 가상 서버가 주 대상이며, 특히 전역 VPN 기본 권한이 ALLOW이면 익명 세션이 내부 리소스에 접근할 위험이 커진다. 13.1-63.21 또는 14.1-7...
https://bishopfox.com/blog/mind-the-config-detecting-and-weaponizing-netscaler-cve-2026-19490
##¿Seguimos confiando demasiado?
Anderson hablaba de confianza en seguridad informática a comienzos de los años 70.
Más de cincuenta años después tenemos Cloud, SaaS, Zero Trust, MFA, PAM, EDR y tecnologías que en aquella época hubieran parecido ciencia ficción.
Entonces me hice una pregunta:
¿El problema también cambió?
En lugar de buscar la respuesta en otro paper, decidí mirar algunas vulnerabilidades recientes:
CVE-2026-20079
CVE-2026-19490
CVE-2025-25249
CVE-2026-20212
Authentication bypass, problemas de memoria, componentes de infraestructura...
Vulnerabilidades técnicamente muy diferentes.
Pero hay una pregunta interesante que podemos hacerle a cada una:
¿Qué tuvo que asumir el sistema para que esa vulnerabilidad pudiera existir?
De eso hablaremos próximamente
¿Seguimos confiando demasiado? —
De Anderson a la Inteligencia Artificial
updated 2026-09-10T12:47:59.933000
3 posts
Discover how the PivotC2 FortiGate RAT uses CVE-2025-25249 exploitation to harvest credentials and tunnel traffic across corporate network environments.
#PivotC2 #FortiGate #Malware #Cybercrime #CVE202525249
http://securityonline.info/pivotc2-fortigate-rat/?utm_source=mastodon&utm_medium=jetpack_social
##¿Seguimos confiando demasiado?
Anderson hablaba de confianza en seguridad informática a comienzos de los años 70.
Más de cincuenta años después tenemos Cloud, SaaS, Zero Trust, MFA, PAM, EDR y tecnologías que en aquella época hubieran parecido ciencia ficción.
Entonces me hice una pregunta:
¿El problema también cambió?
En lugar de buscar la respuesta en otro paper, decidí mirar algunas vulnerabilidades recientes:
CVE-2026-20079
CVE-2026-19490
CVE-2025-25249
CVE-2026-20212
Authentication bypass, problemas de memoria, componentes de infraestructura...
Vulnerabilidades técnicamente muy diferentes.
Pero hay una pregunta interesante que podemos hacerle a cada una:
¿Qué tuvo que asumir el sistema para que esa vulnerabilidad pudiera existir?
De eso hablaremos próximamente
¿Seguimos confiando demasiado? —
De Anderson a la Inteligencia Artificial
Discover how the PivotC2 FortiGate RAT uses CVE-2025-25249 exploitation to harvest credentials and tunnel traffic across corporate network environments.
#PivotC2 #FortiGate #Malware #Cybercrime #CVE202525249
http://securityonline.info/pivotc2-fortigate-rat/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-09-09T21:32:24
1 posts
CVE-2026-50894: Unrestricted file upload in easyadmin v2.0.2.2 enables authenticated RCE and full server takeover. CVSS not scored, but impact is critical. If you use easyadmin, restrict access and audit uploads now. Patch https://www.valtersit.com/cve/CVE-2026-50894/
##updated 2026-09-09T21:31:33
3 posts
3 repos
https://github.com/CyberAuth/CVE-2026-20079
🔎 NEXUS8 WEEKLY DIGEST · 💥 EXPLOIT
Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks
Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. The vulnerability…
Also tracked this week: Hackers exploit Sangoma Switchvox flaw to deploy reverse… · Microsoft Plugs Nearly 1,000…
##¿Seguimos confiando demasiado?
Anderson hablaba de confianza en seguridad informática a comienzos de los años 70.
Más de cincuenta años después tenemos Cloud, SaaS, Zero Trust, MFA, PAM, EDR y tecnologías que en aquella época hubieran parecido ciencia ficción.
Entonces me hice una pregunta:
¿El problema también cambió?
En lugar de buscar la respuesta en otro paper, decidí mirar algunas vulnerabilidades recientes:
CVE-2026-20079
CVE-2026-19490
CVE-2025-25249
CVE-2026-20212
Authentication bypass, problemas de memoria, componentes de infraestructura...
Vulnerabilidades técnicamente muy diferentes.
Pero hay una pregunta interesante que podemos hacerle a cada una:
¿Qué tuvo que asumir el sistema para que esa vulnerabilidad pudiera existir?
De eso hablaremos próximamente
¿Seguimos confiando demasiado? —
De Anderson a la Inteligencia Artificial
🔎 NEXUS8 WEEKLY DIGEST · 💥 EXPLOIT
Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks
Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. The vulnerability…
Also tracked this week: Hackers exploit Sangoma Switchvox flaw to deploy reverse… · Microsoft Plugs Nearly 1,000…
##updated 2026-09-09T15:35:15
8 posts
Critical Check Point VPN Flaws Put Organizations on High Alert as Exploitation Threat Looms + Video
Introduction: A Dangerous Warning for Internet-Facing VPNs A new cybersecurity warning from the Netherlands’ National Cyber Security Center (NCSC) is putting organizations using Check Point VPN technology on notice. Two critical vulnerabilities, CVE-2026-85102 and CVE-2026-85103, have received a near-maximum CVSS score of 9.8, and security officials believe large-scale…
##⚠️ CRITICAL: Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
Two critical remote code execution vulnerabilities in Check Point VPN (CVE-2026-85102 and CVE-2026-85103) are facing imminent exploitation. Any organization running affected Check Point VPN appliances is at immediate risk of full system compromise. Unpatched instances are likely to be targeted with…
🤖 AI generated summary
##📰 Check Point patches two critical 9.8 CVSS flaws in VPN products
Check Point patches two critical 9.8 CVSS vulnerabilities (CVE-2026-85102, CVE-2026-85103) in its VPN products. Flaws could allow unauthenticated RCE. Admins are urged to apply hotfixes immediately. #CyberSecurity #Vulnerability #VPN #PatchNow
##https://thecybersecguru.com/news/check-point-vpn-cve-2026-85102-cve-2026-85103/
##⚠️ CRITICAL: Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
Two critical remote code execution vulnerabilities in Check Point VPN (CVE-2026-85102 and CVE-2026-85103) are facing imminent exploitation. Any organization running affected Check Point VPN appliances is at immediate risk of full system compromise. Unpatched instances are likely to be targeted with…
🤖 AI generated summary
##https://thecybersecguru.com/news/check-point-vpn-cve-2026-85102-cve-2026-85103/
##@cyberwald Bevor man hier einen Hersteller zu CVEs verurteilt, sollte man vielleicht tiefer recherchieren und dazu ein paar Fakten hinzufügen.
Beide Schwachstellen wurden intern entdeckt und bis zur Veröffentlichung gab es keine Hinweise darauf, dass sie in freier Wildbahn ausgenutzt wurden. Weiterhin gab es zu jedem CVE direkt entsprechende Anweisungen und Patches:
Darüber hinaus gibt es mittlerweile die Funktion Check Point Live Patch (CPLP), welches ein im Betriebssystem Gaia enthaltener Dienst zur Bereitstellung von Abwehrmaßnahmen ist. Es schließt kritische Schwachstellen im laufenden Betrieb durch gezielte In-Memory-Korrekturen (Live-Patches). -> https://support.checkpoint.com/results/sk/sk185114
#CheckPoint #CheckpointsoftwareTechnologies
#CheckPointsw
#CVE #CVE202685102 #CVE202685103
Er zijn 2 kritieke kwetsbaarheden in Check Point VPN-producten, met de kenmerken CVE-2026-85102 en CVE-2026-85103. Het gaat om 2 ernstige kwetsbaarheden met een CVSS-score van 9,8. Het NCSC beoordeelt de kans op misbruik en de mogelijke schade als hoog en verwacht dat er snel pogingen tot misbruik zullen plaatsvinden, het advies is dan ook om de updates zo snel mogelijk te installeren.
Translated by LibreWolf:
##There are 2 critical vulnerabilities in Check Point VPN products, with the characteristics CVE-2026-85102 and CVE-2026-85103. This concerns 2 serious vulnerabilities with a CVSS score of 9.8. The NCSC assesses the risk of abuse and possible damage as high and expects that attempts at abuse will take place quickly, so the advice is to install the updates as quickly as possible.
updated 2026-09-09T15:35:15
8 posts
Critical Check Point VPN Flaws Put Organizations on High Alert as Exploitation Threat Looms + Video
Introduction: A Dangerous Warning for Internet-Facing VPNs A new cybersecurity warning from the Netherlands’ National Cyber Security Center (NCSC) is putting organizations using Check Point VPN technology on notice. Two critical vulnerabilities, CVE-2026-85102 and CVE-2026-85103, have received a near-maximum CVSS score of 9.8, and security officials believe large-scale…
##⚠️ CRITICAL: Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
Two critical remote code execution vulnerabilities in Check Point VPN (CVE-2026-85102 and CVE-2026-85103) are facing imminent exploitation. Any organization running affected Check Point VPN appliances is at immediate risk of full system compromise. Unpatched instances are likely to be targeted with…
🤖 AI generated summary
##📰 Check Point patches two critical 9.8 CVSS flaws in VPN products
Check Point patches two critical 9.8 CVSS vulnerabilities (CVE-2026-85102, CVE-2026-85103) in its VPN products. Flaws could allow unauthenticated RCE. Admins are urged to apply hotfixes immediately. #CyberSecurity #Vulnerability #VPN #PatchNow
##https://thecybersecguru.com/news/check-point-vpn-cve-2026-85102-cve-2026-85103/
##⚠️ CRITICAL: Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
Two critical remote code execution vulnerabilities in Check Point VPN (CVE-2026-85102 and CVE-2026-85103) are facing imminent exploitation. Any organization running affected Check Point VPN appliances is at immediate risk of full system compromise. Unpatched instances are likely to be targeted with…
🤖 AI generated summary
##https://thecybersecguru.com/news/check-point-vpn-cve-2026-85102-cve-2026-85103/
##@cyberwald Bevor man hier einen Hersteller zu CVEs verurteilt, sollte man vielleicht tiefer recherchieren und dazu ein paar Fakten hinzufügen.
Beide Schwachstellen wurden intern entdeckt und bis zur Veröffentlichung gab es keine Hinweise darauf, dass sie in freier Wildbahn ausgenutzt wurden. Weiterhin gab es zu jedem CVE direkt entsprechende Anweisungen und Patches:
Darüber hinaus gibt es mittlerweile die Funktion Check Point Live Patch (CPLP), welches ein im Betriebssystem Gaia enthaltener Dienst zur Bereitstellung von Abwehrmaßnahmen ist. Es schließt kritische Schwachstellen im laufenden Betrieb durch gezielte In-Memory-Korrekturen (Live-Patches). -> https://support.checkpoint.com/results/sk/sk185114
#CheckPoint #CheckpointsoftwareTechnologies
#CheckPointsw
#CVE #CVE202685102 #CVE202685103
Er zijn 2 kritieke kwetsbaarheden in Check Point VPN-producten, met de kenmerken CVE-2026-85102 en CVE-2026-85103. Het gaat om 2 ernstige kwetsbaarheden met een CVSS-score van 9,8. Het NCSC beoordeelt de kans op misbruik en de mogelijke schade als hoog en verwacht dat er snel pogingen tot misbruik zullen plaatsvinden, het advies is dan ook om de updates zo snel mogelijk te installeren.
Translated by LibreWolf:
##There are 2 critical vulnerabilities in Check Point VPN products, with the characteristics CVE-2026-85102 and CVE-2026-85103. This concerns 2 serious vulnerabilities with a CVSS score of 9.8. The NCSC assesses the risk of abuse and possible damage as high and expects that attempts at abuse will take place quickly, so the advice is to install the updates as quickly as possible.
updated 2026-09-09T15:35:15
3 posts
VLC Media Player Flaws Allow Heap Corruption and Sensitive Data Disclosure
VideoLAN reports two vulnerabilities in VLC Media Player (CVE-2026-56711 and CVE-2026-73324) that allow attackers to corrupt heap memory or leak sensitive data via crafted PNG files and RTSP streams.
**If you use VLC Media Player (any version from 3.0.0 to 3.0.23), update it to the latest patched version as soon as VideoLAN releases it. Until you've updated, don't open media files, playlists, or RTSP streaming links that come from people or websites you don't know and trust.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/vlc-media-player-flaws-allow-heap-corruption-and-sensitive-data-disclosure-6-k-q-2-9/gD2P6Ple2L
VLC Media Player Flaws Allow Heap Corruption and Sensitive Data Disclosure
VideoLAN reports two vulnerabilities in VLC Media Player (CVE-2026-56711 and CVE-2026-73324) that allow attackers to corrupt heap memory or leak sensitive data via crafted PNG files and RTSP streams.
**If you use VLC Media Player (any version from 3.0.0 to 3.0.23), update it to the latest patched version as soon as VideoLAN releases it. Until you've updated, don't open media files, playlists, or RTSP streaming links that come from people or websites you don't know and trust.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/vlc-media-player-flaws-allow-heap-corruption-and-sensitive-data-disclosure-6-k-q-2-9/gD2P6Ple2L
https://thecybersecguru.com/news/vlc-media-player-vulnerabilities-cve-2026-56711-cve-2026-73324/
##updated 2026-09-09T12:32:22
2 posts
CVE-2026-87827 (CVSS 10) is a KGUARD DVR vulnerability exploited by the Mirai botnet for unauthenticated RCE and complete device compromise.
#KGUARD #DVR #CVE202687827 #Mirai #Botnet #IoTSecurity #RCE #DDoS #ExploitedInTheWild #InfoSec
##CVE-2026-87827 (CVSS 10) is a KGUARD DVR vulnerability exploited by the Mirai botnet for unauthenticated RCE and complete device compromise.
#KGUARD #DVR #CVE202687827 #Mirai #Botnet #IoTSecurity #RCE #DDoS #ExploitedInTheWild #InfoSec
##updated 2026-09-09T05:18:19.490000
3 posts
2 repos
https://github.com/HORKimhab/CVE-2026-86218
https://github.com/jithinkrishnanrs/CVE-2026-86218-N-central-IOC-Toolkit
CVE-2026-86218, a CVSS 10 N-central vulnerability, is exploited in the wild for remote code execution. A public Metasploit PoC is out. Patch now.
##CVE-2026-86218, a CVSS 10 N-central vulnerability, is exploited in the wild for remote code execution. A public Metasploit PoC is out. Patch now.
##CVE-2026-86218: Active Exploitation of N-able N-central: Critical Pre-Auth Remote Code Execution (RCE) Vulnerability
#N_central #CVE_2026_86218
https://arcticwolf.com/resources/blog/cve-2026-86218/
updated 2026-09-09T05:18:19.193000
2 posts
Microsoft's September 2026 Patch Tuesday addressed a record 974 vulnerabilities, including two actively exploited zero-days (CVE-2026-85880, CVE-2026-81963) allowing privilege escalation. Anthropic also revealed Russia-linked cyber-espionage groups are using Claude AI for hacking operations targeting government and defense organizations. Geopolitically, China is hosting a defense forum amid rising regional tensions over Taiwan and the South China Sea. In technology, OpenAI delayed its IPO beyond 2026, advocating for a global AI development slowdown.
##Microsoft's September 2026 Patch Tuesday addressed a record 974 vulnerabilities, including two actively exploited zero-days (CVE-2026-85880, CVE-2026-81963) allowing privilege escalation. Anthropic also revealed Russia-linked cyber-espionage groups are using Claude AI for hacking operations targeting government and defense organizations. Geopolitically, China is hosting a defense forum amid rising regional tensions over Taiwan and the South China Sea. In technology, OpenAI delayed its IPO beyond 2026, advocating for a global AI development slowdown.
##updated 2026-09-09T05:18:17.173000
2 posts
Microsoft's September 2026 Patch Tuesday addressed a record 974 vulnerabilities, including two actively exploited zero-days (CVE-2026-85880, CVE-2026-81963) allowing privilege escalation. Anthropic also revealed Russia-linked cyber-espionage groups are using Claude AI for hacking operations targeting government and defense organizations. Geopolitically, China is hosting a defense forum amid rising regional tensions over Taiwan and the South China Sea. In technology, OpenAI delayed its IPO beyond 2026, advocating for a global AI development slowdown.
##Microsoft's September 2026 Patch Tuesday addressed a record 974 vulnerabilities, including two actively exploited zero-days (CVE-2026-85880, CVE-2026-81963) allowing privilege escalation. Anthropic also revealed Russia-linked cyber-espionage groups are using Claude AI for hacking operations targeting government and defense organizations. Geopolitically, China is hosting a defense forum amid rising regional tensions over Taiwan and the South China Sea. In technology, OpenAI delayed its IPO beyond 2026, advocating for a global AI development slowdown.
##updated 2026-09-08T21:33:09
2 posts
5 repos
https://github.com/disrex-group/stylesmuggler-adobe-patches-mageos
https://github.com/jithinkrishnanrs/stylesmuggler-ioc-toolkit
https://github.com/disrex-group/stylesmuggler-adobe-patches
https://github.com/fortbridge/stylesmuggler
https://github.com/dinosn/cve-2026-75650-magento-validation-lab
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
updated 2026-09-08T18:33:07
1 posts
https://www.cve.org/CVERecord?id=CVE-2026-69730
Windows DNS server RCE
updated 2026-09-08T18:32:45
1 posts
CVE-2026-13297: IBM Verify Identity Access (AAC) risks info disclosure. CVSS N/A, patch status unknown. If you use it, audit exposure now. Details: https://www.valtersit.com/cve/CVE-2026-13297/ #CVE #infosec #IBM
##updated 2026-09-08T17:56:31
4 posts
10 repos
https://github.com/0xBlackash/CVE-2026-60004
https://github.com/EQSTLab/CVE-2026-60004
https://github.com/erberkan/CVE-2026-60004-PoC
https://github.com/HORKimhab/CVE-2026-60004
https://github.com/fevar54/cve-2026-60004
https://github.com/imbas007/CVE-2026-60004-POC
https://github.com/Sachinart/CVE-2026-60004-gitea-0day
https://github.com/gagaltotal/CVE-2026-60004-poc-gitea
Red Heron exploited CVE-2026-60004, a critical Gitea RCE, to compromise 13 organizations after scanning 1,386 exposed instances. Exposed dev platforms offer direct access to code and lateral movement. Patch, restrict exposure and review logs. #GiteaSecurity #ThreatIntel #SupplyChain
https://cyberworldops.eu/en/red-heron-exploits-critical-gitea-rce-to-breach-13-organizations
##⚪️ Over 8,300 Gitea Servers Vulnerable to Remote Code Execution
🗨️ Researchers at The Shadowserver Foundation warn that more than 8,300 internet-exposed Gitea instances remain unprotected against the critical CVE-2026-60004 vulnerability. The flaw is already being exploited in real-world attacks and allows arbitrary commands to be executed on vulnerable servers.…
##Red Heron exploited CVE-2026-60004, a critical Gitea RCE, to compromise 13 organizations after scanning 1,386 exposed instances. Exposed dev platforms offer direct access to code and lateral movement. Patch, restrict exposure and review logs. #GiteaSecurity #ThreatIntel #SupplyChain
https://cyberworldops.eu/en/red-heron-exploits-critical-gitea-rce-to-breach-13-organizations
##⚪️ Over 8,300 Gitea Servers Vulnerable to Remote Code Execution
🗨️ Researchers at The Shadowserver Foundation warn that more than 8,300 internet-exposed Gitea instances remain unprotected against the critical CVE-2026-60004 vulnerability. The flaw is already being exploited in real-world attacks and allows arbitrary commands to be executed on vulnerable servers.…
##updated 2026-09-08T15:32:04
2 posts
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
updated 2026-09-08T15:32:04
2 posts
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
updated 2026-09-07T15:34:02
2 posts
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
updated 2026-09-07T09:31:46
2 posts
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
updated 2026-09-04T18:31:46
1 posts
CVE-2026-80897 - Linux kernel netfs flaw leaves readahead folio refs held on iterator prep failure, risking memory exhaustion. CVSS N/A. Currently unpatched. If you run a kernel with netfs, monitor for updates and test mitigations. https://www.valtersit.com/cve/CVE-2026-80897/
##updated 2026-09-04T18:31:46
1 posts
CVE-2026-80904 Linux kernel TLS flaw: failed async decrypt can bypass splice_read check, breaking connection authentication. CVSS N/A, unpatched. If you rely on kernel TLS splicing, audit exposure now. Update once fix lands. https://www.valtersit.com/cve/CVE-2026-80904/ #CVE #inf
##updated 2026-09-04T18:31:46
1 posts
CVE-2026-85636: Missing authentication in Trape 1.0.0 (core/stats.py Login Endpoint). Remote exploit is public; project unpatched and unresponsive. CVSS 5.3. If you run Trape, assume compromise and isolate now. Details: https://www.valtersit.com/cve/CVE-2026-85636/ #CVE #infosec
##updated 2026-09-04T18:31:40
1 posts
CVE-2026-17273: IBM i (7.3-7.6) flaw lets authenticated remote users trigger DoS via NULL pointer deref. CVSS 6.5. Unpatched—assume risk. Isolate admin access & monitor logs. Details: https://www.valtersit.com/cve/CVE-2026-17273/ Patch when available. #CVE #IBM #cybersecurity
##updated 2026-09-04T18:31:40
1 posts
CVE-2026-16693: IBM i 7.3-7.6 flaw lets authenticated remote users grab sensitive data via hardcoded crypto constants to obfuscate keys. CVSS 4.4. No patch yet. Mitigate: restrict access, monitor logs. Details: https://www.valtersit.com/cve/CVE-2026-16693/ #CVE #IBM #infosec
##updated 2026-09-04T18:31:31
1 posts
CVE-2026-18073 IBM i 7.3-7.6: local authenticated attacker can inject parameters into a CL command (improper input neutralization). CVSS 4.4. No patch yet—assume risk. Restrict local access & monitor. Details: https://www.valtersit.com/cve/CVE-2026-18073/ #CVE #IBM #infosec
##updated 2026-09-02T18:32:26
1 posts
1 repos
¿Seguimos confiando demasiado?
Anderson hablaba de confianza en seguridad informática a comienzos de los años 70.
Más de cincuenta años después tenemos Cloud, SaaS, Zero Trust, MFA, PAM, EDR y tecnologías que en aquella época hubieran parecido ciencia ficción.
Entonces me hice una pregunta:
¿El problema también cambió?
En lugar de buscar la respuesta en otro paper, decidí mirar algunas vulnerabilidades recientes:
CVE-2026-20079
CVE-2026-19490
CVE-2025-25249
CVE-2026-20212
Authentication bypass, problemas de memoria, componentes de infraestructura...
Vulnerabilidades técnicamente muy diferentes.
Pero hay una pregunta interesante que podemos hacerle a cada una:
¿Qué tuvo que asumir el sistema para que esa vulnerabilidad pudiera existir?
De eso hablaremos próximamente
¿Seguimos confiando demasiado? —
De Anderson a la Inteligencia Artificial
updated 2026-09-02T18:32:06
1 posts
2 repos
📢 SonicWall SMA1000 : module Metasploit pour chaîne RCE non authentifiée (CVE-2026-83548 + CVE-2026-83549)
Ce pull request Metasploit (PR #21883) documente l'intégration d'un module d'exploitation complet pour une chaîne de vulnérabilités zero-day affectant les appliances SonicWall Secure Mobile Access 1000 (SMA1000), divulguée début septembre 2026 comme…
📖 cyberveille : https://cyberveille.ch/posts/2026-09-14-sonicwall-sma1000-module-metasploit-pour-chaine-rce-non-authentifiee-cve-2026-83548-cve-2026-83549/
🌐 source : https://github.com/rapid7/metasploit-framework/pull/21883
🟡 vérification factuelle moyenne
#Metasploit #RCE #Cyberveille
updated 2026-09-02T18:32:06
1 posts
3 repos
https://github.com/xoessie/CVE-2026-83548-SonicWall-SMA1000-Analysis
📢 SonicWall SMA1000 : module Metasploit pour chaîne RCE non authentifiée (CVE-2026-83548 + CVE-2026-83549)
Ce pull request Metasploit (PR #21883) documente l'intégration d'un module d'exploitation complet pour une chaîne de vulnérabilités zero-day affectant les appliances SonicWall Secure Mobile Access 1000 (SMA1000), divulguée début septembre 2026 comme…
📖 cyberveille : https://cyberveille.ch/posts/2026-09-14-sonicwall-sma1000-module-metasploit-pour-chaine-rce-non-authentifiee-cve-2026-83548-cve-2026-83549/
🌐 source : https://github.com/rapid7/metasploit-framework/pull/21883
🟡 vérification factuelle moyenne
#Metasploit #RCE #Cyberveille
updated 2026-09-02T18:31:57
1 posts
7 repos
https://github.com/0xCyp1337/CVE-2026-82329
https://github.com/dinosn/cve-2026-82329-jfrog-artifactory
https://github.com/realalexandergeorgiev/artifactory-CVE-2026-82329-poc.py
https://github.com/0xTerror/CVE-2026-82329-JFrog-Artifactory-
https://github.com/ynsmroztas/CVE-2026-82329-JFrog-Artifactory-Auth-Bypass
Artifactory: In-the-Wild Exploitation of CVE-2026-42016,CVE-2026-42018
Wiz Research는 JFrog Artifactory의 CVE-2026-42016, CVE-2026-42018, CVE-2026-82329가 실제 환경에서 활발히 악용되고 있음을 확인했다. 공격자는 익명 사용자 토큰 노출과 토큰 스코프 검증 결함을 연쇄해 인증 없이 관리자 권한 토큰을 획득하거나, CVE-2026-82329의 인증 우회로 직접 관리자 권한을 얻을 수 있다. 침해 후에는 지속성 관리자 계정 생성, Groovy 플러그인을 통한 서버 명령 실행, 클러스...
##updated 2026-08-31T21:31:56
1 posts
2 repos
PaperCut Attacker (Russian Linked) Uses AI Agents to Compromise 440 Instances
러시아어권으로 추정되는 공격자가 PaperCut NG/MF의 인증 우회·RCE 체인(CVE-2026-81578, CVE-2026-82078)을 악용해 48개국 395개 조직의 최소 440개 인스턴스를 침해한 것으로 보고됐다. 공격자는 OpenAI Codex, DeepSeek 모델, Hindsight의 지속 메모리, AionUi 멀티 에이전트 작업 공간을 결합해 취약점 분석부터 익스플로잇 수정, 표적 분류, 재시도, AD 정찰까지 자동화했으며, 실제 공격 개시 후 2...
https://www.swapupdate.in/papercut-attacker-uses-hundreds-of-ai-agents-to-compromise-440-instances/
##updated 2026-08-29T15:30:20
2 posts
A critical Shinobi vulnerability (CVE-2026-82448) uses a hardcoded child node key to reach the camera database unauthenticated. Patch and lock port 8288.
#Shinobi #CVE202682448 #CCTV #Vulnerability #HardcodedKey #CyberSecurity #InfoSec
##A critical Shinobi vulnerability (CVE-2026-82448) uses a hardcoded child node key to reach the camera database unauthenticated. Patch and lock port 8288.
#Shinobi #CVE202682448 #CCTV #Vulnerability #HardcodedKey #CyberSecurity #InfoSec
##updated 2026-08-26T20:48:48
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-08-18T18:32:52
1 posts
2 repos
CVE-2026-59310 - Changed to Known Ransomware Status
Broadcom VMware vCenter Path Traversal VulnerabilityVendor: BroadcomProduct: VMware vCenterBroadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 11, 2026 at 16:08:17 UTCDate Added to KEV: https://nvd.nist.gov/vuln/detail/CVE-2026-59310
##updated 2026-08-11T19:33:44.513000
1 posts
100 repos
https://github.com/bigsizeme/Log4j-check
https://github.com/leonjza/log4jpwn
https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce
https://github.com/puzzlepeaches/Log4jUnifi
https://github.com/1lann/log4shelldetect
https://github.com/0xDexter0us/Log4J-Scanner
https://github.com/dtact/divd-2021-00038--log4j-scanner
https://github.com/lucab85/log4j-cve-2021-44228
https://github.com/puzzlepeaches/Log4jHorizon
https://github.com/back2root/log4shell-rex
https://github.com/CrackerCat/CVE-2021-44228-Log4j-Payloads
https://github.com/AlexandreHeroux/Fix-CVE-2021-44228
https://github.com/CreeperHost/Log4jPatcher
https://github.com/wortell/log4j
https://github.com/yahoo/check-log4j
https://github.com/lfama/log4j_checker
https://github.com/mr-r3b00t/CVE-2021-44228
https://github.com/roxas-tan/CVE-2021-44228
https://github.com/infiniroot/nginx-mitigate-log4shell
https://github.com/alexbakker/log4shell-tools
https://github.com/qingtengyun/cve-2021-44228-qingteng-patch
https://github.com/Kadantte/CVE-2021-44228-poc
https://github.com/0xInfection/LogMePwn
https://github.com/mzlogin/CVE-2021-44228-Demo
https://github.com/NorthwaveSecurity/log4jcheck
https://github.com/Jeromeyoung/log4j2burpscanner
https://github.com/jas502n/Log4j2-CVE-2021-44228
https://github.com/TaroballzChen/CVE-2021-44228-log4jVulnScanner-metasploit
https://github.com/NS-Sp4ce/Vm4J
https://github.com/sunnyvale-it/CVE-2021-44228-PoC
https://github.com/LiveOverflow/log4shell
https://github.com/HynekPetrak/log4shell-finder
https://github.com/fox-it/log4j-finder
https://github.com/hackinghippo/log4shell_ioc_ips
https://github.com/momos1337/Log4j-RCE
https://github.com/Adikso/minecraft-log4j-honeypot
https://github.com/BinaryDefense/log4j-honeypot-flask
https://github.com/corretto/hotpatch-for-apache-log4j2
https://github.com/future-client/CVE-2021-44228
https://github.com/simonis/Log4jPatch
https://github.com/pedrohavay/exploit-CVE-2021-44228
https://github.com/corelight/cve-2021-44228
https://github.com/twseptian/spring-boot-log4j-cve-2021-44228-docker-lab
https://github.com/nu11secur1ty/CVE-2021-44228-VULN-APP
https://github.com/CodeShield-Security/Log4JShell-Bytecode-Detector
https://github.com/claranet/ansible-role-log4shell
https://github.com/nccgroup/log4j-jndi-be-gone
https://github.com/NCSC-NL/log4shell
https://github.com/Puliczek/CVE-2021-44228-PoC-log4j-bypass-words
https://github.com/puzzlepeaches/Log4jCenter
https://github.com/thecyberneh/Log4j-RCE-Exploiter
https://github.com/justakazh/Log4j-CVE-2021-44228
https://github.com/greymd/CVE-2021-44228
https://github.com/christophetd/log4shell-vulnerable-app
https://github.com/MalwareTech/Log4jTools
https://github.com/Malwar3Ninja/Exploitation-of-Log4j2-CVE-2021-44228
https://github.com/CERTCC/CVE-2021-44228_scanner
https://github.com/ssl/scan4log4j
https://github.com/Diverto/nse-log4shell
https://github.com/mufeedvh/log4jail
https://github.com/kozmer/log4j-shell-poc
https://github.com/logpresso/CVE-2021-44228-Scanner
https://github.com/mubix/CVE-2021-44228-Log4Shell-Hashes
https://github.com/darkarnium/Log4j-CVE-Detect
https://github.com/dwisiswant0/look4jar
https://github.com/mr-vill4in/log4j-fuzzer
https://github.com/faisalfs10x/Log4j2-CVE-2021-44228-revshell
https://github.com/RedDrip7/Log4Shell_CVE-2021-44228_related_attacks_IOCs
https://github.com/r3kind1e/Log4Shell-obfuscated-payloads-generator
https://github.com/toramanemre/apache-solr-log4j-CVE-2021-44228
https://github.com/KosmX/CVE-2021-44228-example
https://github.com/blake-fm/vcenter-log4j
https://github.com/cyberxml/log4j-poc
https://github.com/alexandre-lavoie/python-log4rce
https://github.com/boundaryx/cloudrasp-log4j2
https://github.com/rubo77/log4j_checker_beta
https://github.com/takito1812/log4j-detect
https://github.com/qingtengyun/cve-2021-44228-qingteng-online-patch
https://github.com/stripe/log4j-remediation-tools
https://github.com/giterlizzi/nmap-log4shell
https://github.com/irgoncalves/f5-waf-enforce-sig-CVE-2021-44228
https://github.com/aws-samples/kubernetes-log4j-cve-2021-44228-node-agent
https://github.com/thomaspatzke/Log4Pot
https://github.com/fireeye/CVE-2021-44228
https://github.com/tippexs/nginx-njs-waf-cve2021-44228
https://github.com/kubearmor/log4j-CVE-2021-44228
https://github.com/sec13b/CVE-2021-44228-POC
https://github.com/f0ng/log4j2burpscanner
https://github.com/irgoncalves/f5-waf-quick-patch-cve-2021-44228
https://github.com/Azeemering/CVE-2021-44228-DFIR-Notes
https://github.com/Nanitor/log4fix
https://github.com/fullhunt/log4j-scan
https://github.com/Labout/log4shell-rmi-poc
https://github.com/HyCraftHD/Log4J-RCE-Proof-Of-Concept
https://github.com/DragonSurvivalEU/RCE
https://github.com/mergebase/log4j-detector
https://github.com/toramanemre/log4j-rce-detect-waf-bypass
https://github.com/marcourbano/CVE-2021-44228
GET /api/cve/CVE-2021-44228 returns CVSS, CPEs, affected vendors, and known exploits in one call. No scraping, no joins. Docs: https://www.valtersit.com/cve/pricing/
##updated 2026-08-11T18:31:23
2 posts
Microsoft today released an out of band update that includes a security update to a vulnerability they first patched in August. I guess the first patch didn't work broadly enough or introduced more flaws (or both). According to MS, though, there aren't any signs this vulnerability is actively being exploited. MS just says "The CVE was updated with links to security updates for Windows 11, version 26H1, 25H2, and 24H2 to address a missed fix."
https://msrc.microsoft.com/update-guide/advisory/CVE-2026-62721
##Microsoft today released an out of band update that includes a security update to a vulnerability they first patched in August. I guess the first patch didn't work broadly enough or introduced more flaws (or both). According to MS, though, there aren't any signs this vulnerability is actively being exploited. MS just says "The CVE was updated with links to security updates for Windows 11, version 26H1, 25H2, and 24H2 to address a missed fix."
https://msrc.microsoft.com/update-guide/advisory/CVE-2026-62721
##updated 2026-08-07T06:31:24
3 posts
5 repos
https://github.com/puj790201-lab/cve-2026-61511
https://github.com/shootcannon/CVE-2026-61511
https://github.com/HORKimhab/CVE-2026-61511
Critical vBulletin Pre-Authentication RCE Flaw Puts Internet-Facing Forums at Serious Risk of Full Server Takeover
Introduction A newly disclosed critical vulnerability in vBulletin has turned ordinary forum traffic into a potentially dangerous attack path. Tracked as CVE-2026-61511, the flaw can allow an unauthenticated remote attacker to execute arbitrary PHP code on affected servers, meaning an attacker may not need an administrator account, stolen credentials, or…
##[CVE-2026-61511] vBulletin <= 6.2.1 (runMaths) Pre-Auth RCE Vulnerability https://karmainsecurity.com/KIS-2026-13
##[CVE-2026-61511] vBulletin <= 6.2.1 (runMaths) Pre-Auth RCE Vulnerability https://karmainsecurity.com/KIS-2026-13
##updated 2026-08-03T16:19:22.763000
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-07-23T12:33:27
2 posts
14 repos
https://github.com/g0thamRabb1t/CVE-2026-46331-pedit-COW-detection
https://github.com/sgkdev/packet_edit_meme
https://github.com/V0IDNETWORK/CVE-2026-46331
https://github.com/HORKimhab/CVE-2026-46331
https://github.com/douglasmun/pagecache-lpe-containment-kit
https://github.com/MarwahHadi/CVE-2026-46331-pedit-cow
https://github.com/Quaerendir/cve-2026-46331-audit
https://github.com/nawalacheker1/CVE-2026-46331
https://github.com/vulnquest58/dirtyclone-exploit
https://github.com/0xBlackash/CVE-2026-46331
https://github.com/rjt-gupta/page-cache-corruption-lpes
https://github.com/yanxinwu946/CVE-2026-46331
Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331 https://www.accomplish.ai/blog/sharedroot-escaping-claude-cowork-sandbox/
##Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331 https://www.accomplish.ai/blog/sharedroot-escaping-claude-cowork-sandbox/
##updated 2026-07-22T16:17:28.753000
2 posts
2 repos
Writeup & POC: CVE-2026-49176 Windows WalletService to SYSTEM (LPE) https://davidcarliez.github.io/blog/cve-2026-49176-walletservice-to-system/
##Writeup & POC: CVE-2026-49176 Windows WalletService to SYSTEM (LPE) https://davidcarliez.github.io/blog/cve-2026-49176-walletservice-to-system/
##updated 2026-07-20T21:26:50
2 posts
🟠 CVE-2026-57130 - High (8.1)
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/email_tools.py interpolates LLM-controlled from_addr, subject, and query values directly into quoted IMAP SEARCH criteria. Embedde...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57130/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-57130 - High (8.1)
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/email_tools.py interpolates LLM-controlled from_addr, subject, and query values directly into quoted IMAP SEARCH criteria. Embedde...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57130/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-20T21:26:30
2 posts
🟠 CVE-2026-57129 - High (7.5)
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, MentionsParser._process_file_mention accepts file-mention values and falls back from workspace-relative resolution to Path(file_path) without traversal, symlink, or workspac...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57129/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-57129 - High (7.5)
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, MentionsParser._process_file_mention accepts file-mention values and falls back from workspace-relative resolution to Path(file_path) without traversal, symlink, or workspac...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57129/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-16T03:01:45.513000
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-07-15T18:20:21.237000
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-07-15T18:20:21.237000
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-07-15T12:32:05
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-07-14T18:32:25
2 posts
CVE-2026-50458: Finding a UAF in the Windows Brokering File System https://rotcee.github.io/posts/CVE-2026-50458-finding-a-UAF-in-windows-brokering-file-system/
##CVE-2026-50458: Finding a UAF in the Windows Brokering File System https://rotcee.github.io/posts/CVE-2026-50458-finding-a-UAF-in-windows-brokering-file-system/
##updated 2026-07-13T22:11:46.303000
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-07-11T15:30:30
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-07-11T15:30:29
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-07-10T15:31:48
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-07-10T15:31:48
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-07-09T15:33:27
2 posts
1 repos
Escalating All The Privileges With Foxit PDF Reader (CVE-2026–57239) https://blog.paradoxis.nl/escalating-all-the-privileges-with-foxit-pdf-reader-cve-2026-57239-582a78b60492
##Escalating All The Privileges With Foxit PDF Reader (CVE-2026–57239) https://blog.paradoxis.nl/escalating-all-the-privileges-with-foxit-pdf-reader-cve-2026-57239-582a78b60492
##updated 2026-06-30T03:38:15
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-06-24T13:10:05
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-06-23T15:32:48
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-06-21T15:31:31
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-06-17T10:42:51.460000
1 posts
25 repos
https://github.com/dodeepsink/CVE-2026-39987.py
https://github.com/keraattin/CVE-2026-39987
https://github.com/julichaan/CVE-2026-39987_POC
https://github.com/Clara-M-Grossl/Exploit-Marimo
https://github.com/0xdeadroot/CVE-2026-39987-marimo-rce
https://github.com/jasonbernier/CVE-2026-39987
https://github.com/HORKimhab/CVE-2026-39987
https://github.com/fevar54/marimo_CVE-2026-39987_RCE_PoC
https://github.com/M3PH1569/CVE-2026-39987-POC
https://github.com/alreadyClosed/CVE-2026-39987
https://github.com/MADA0L/CVE-2026-39987-Poc
https://github.com/mki9/CVE-2026-39987_exploit
https://github.com/gbuyssens/CVE-2026-39987
https://github.com/iapetus12/cohort-htb
https://github.com/vanhari/CVE-2026-39987
https://github.com/K3ysTr0K3R/CVE-2026-39987
https://github.com/0xBlackash/CVE-2026-39987
https://github.com/Ghxstsec/CVE-2026-39987
https://github.com/stapat1245/CVE-2026-39987-PoC
https://github.com/Wind010/CVE-2026-39987_PoC
https://github.com/Nxploited/CVE-2026-39987
https://github.com/h3raklez/CVE-2026-39987
https://github.com/rootdirective-sec/CVE-2026-39987-Lab
https://github.com/Dhiaelhak-Rached/CVE-2026-39987-lab-or-marimo-cve-lab
Human Exploits Marimo Flaw to Breach SSH Bastion Host in 8 Seconds
In just 8 seconds, a human attacker exploited a vulnerability in Marimo notebooks to breach an SSH bastion host, showcasing the alarming speed and ease of lateral movement within compromised systems. This lightning-fast breach was achieved without the aid of AI tools, highlighting the severity of the CVE-2026-39987 flaw.
#Marimo #Cve202639987 #SshBastionHost #RemoteCodeExecution #Preauthentication
##updated 2026-06-17T10:30:42.313000
2 posts
🟠 CVE-2026-37008 - High (8.1)
CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete obj...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-37008/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-37008 - High (8.1)
CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete obj...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-37008/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-06-17T10:29:27.873000
2 posts
Sequoia 15.7.7 broke a critical shortcut I use. Terra says "Apple’s Shortcuts security fix for CVE-2026-28993,"
It doesn't always fail, just most of the time.
It feels like I run into something of this nature every day now.
##Sequoia 15.7.7 broke a critical shortcut I use. Terra says "Apple’s Shortcuts security fix for CVE-2026-28993,"
It doesn't always fail, just most of the time.
It feels like I run into something of this nature every day now.
##updated 2026-06-17T07:05:03.993000
2 posts
1 repos
Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813) https://mobeta.fr/simple-job-board-unauth-rce-cve-2024-1813/
##Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813) https://mobeta.fr/simple-job-board-unauth-rce-cve-2024-1813/
##updated 2026-06-09T15:33:16
2 posts
2 repos
I was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986) https://blog.himanshuanand.com/2026/07/reporter-11-10-people-found-the-wpforms-paypal-bug-before-me-cve-2026-4986/
##I was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986) https://blog.himanshuanand.com/2026/07/reporter-11-10-people-found-the-wpforms-paypal-bug-before-me-cve-2026-4986/
##updated 2026-04-07T22:16:19
5 posts
The Vite development server vulnerability CVE-2026-39364 is exploited in mass scanning for credential harvesting. F5 Labs logged 32,000 events. Patch now.
#Vite #CVE202639364 #CloudSecurity #CredentialHarvesting #F5Labs #DevSecOps #FileDisclosure #InfoSec #AWS #MassScanning
##F5 observed mass scanning of exposed Vite dev servers exploiting CVE-2026-39364 and older flaws CVE-2025-30208, CVE-2025-31125, CVE-2024-45811. Stolen AWS/Azure credentials and deployment configs enable full cloud compromise, so isolate dev servers and rotate secrets. #Vite #CloudSecurity #ThreatIntelligence
https://cyberworldops.eu/en/hackers-scan-exposed-vite-servers-for-aws-azure-and-deployment-secrets
##Hackers Are Mass-Scanning Exposed Vite Servers to Steal AWS, Azure and Terraform Secrets + Video
A New Warning for Developers Modern web development depends heavily on fast local development environments, but convenience can become dangerous when those environments are accidentally exposed to the public internet. A new mass-scanning campaign is reportedly targeting exposed Vite development servers, abusing CVE-2026-39364 to access sensitive files and potentially…
##The Vite development server vulnerability CVE-2026-39364 is exploited in mass scanning for credential harvesting. F5 Labs logged 32,000 events. Patch now.
#Vite #CVE202639364 #CloudSecurity #CredentialHarvesting #F5Labs #DevSecOps #FileDisclosure #InfoSec #AWS #MassScanning
##F5 observed mass scanning of exposed Vite dev servers exploiting CVE-2026-39364 and older flaws CVE-2025-30208, CVE-2025-31125, CVE-2024-45811. Stolen AWS/Azure credentials and deployment configs enable full cloud compromise, so isolate dev servers and rotate secrets. #Vite #CloudSecurity #ThreatIntelligence
https://cyberworldops.eu/en/hackers-scan-exposed-vite-servers-for-aws-azure-and-deployment-secrets
##updated 2026-03-16T15:30:57
2 posts
📢 Exploitation active de trois vulnérabilités critiques dans JFrog Artifactory
🔍 Contexte : Le 10 septembre 2026, Wiz Research publie une analyse technique détaillant l'exploitation active en conditions réelles de trois vulnérabilités critiques et de haute sévérité affectant JFrog Artifactory.
📖 cyberveille : https://cyberveille.ch/posts/2026-09-14-exploitation-active-de-trois-vulnerabilites-critiques-dans-jfrog-artifactory/
🌐 source : https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201
🟢 vérification factuelle haute
#JFrogArtifactory #ExploitationActive #Cyberveille
Artifactory: In-the-Wild Exploitation of CVE-2026-42016,CVE-2026-42018
Wiz Research는 JFrog Artifactory의 CVE-2026-42016, CVE-2026-42018, CVE-2026-82329가 실제 환경에서 활발히 악용되고 있음을 확인했다. 공격자는 익명 사용자 토큰 노출과 토큰 스코프 검증 결함을 연쇄해 인증 없이 관리자 권한 토큰을 획득하거나, CVE-2026-82329의 인증 우회로 직접 관리자 권한을 얻을 수 있다. 침해 후에는 지속성 관리자 계정 생성, Groovy 플러그인을 통한 서버 명령 실행, 클러스...
##updated 2026-01-22T21:47:41
2 posts
7 repos
https://github.com/xuemian168/CVE-2025-30208
https://github.com/0xgh057r3c0n/CVE-2025-31125
https://github.com/jackieya/ViteVulScan
https://github.com/harshgupptaa/Path-Transversal-CVE-2025-31125-
https://github.com/nkuty/CVE-2025-30208-31125-31486-32395
F5 observed mass scanning of exposed Vite dev servers exploiting CVE-2026-39364 and older flaws CVE-2025-30208, CVE-2025-31125, CVE-2024-45811. Stolen AWS/Azure credentials and deployment configs enable full cloud compromise, so isolate dev servers and rotate secrets. #Vite #CloudSecurity #ThreatIntelligence
https://cyberworldops.eu/en/hackers-scan-exposed-vite-servers-for-aws-azure-and-deployment-secrets
##F5 observed mass scanning of exposed Vite dev servers exploiting CVE-2026-39364 and older flaws CVE-2025-30208, CVE-2025-31125, CVE-2024-45811. Stolen AWS/Azure credentials and deployment configs enable full cloud compromise, so isolate dev servers and rotate secrets. #Vite #CloudSecurity #ThreatIntelligence
https://cyberworldops.eu/en/hackers-scan-exposed-vite-servers-for-aws-azure-and-deployment-secrets
##updated 2025-03-25T14:00:04
2 posts
23 repos
https://github.com/lilil3333/Vite-CVE-2025-30208-EXP
https://github.com/HaGsec/CVE-2025-30208
https://github.com/nkuty/CVE-2025-30208-31125-31486-32395
https://github.com/keklick1337/CVE-2025-30208-ViteVulnScanner
https://github.com/4m3rr0r/CVE-2025-30208-PoC
https://github.com/cc3305/CVE-2025-30208
https://github.com/marino-admin/Vite-CVE-2025-30208-Scanner
https://github.com/0xshaheen/CVE-2025-30208
https://github.com/iSee857/CVE-2025-30208-PoC
https://github.com/On1onss/CVE-2025-30208
https://github.com/xuemian168/CVE-2025-30208
https://github.com/imbas007/CVE-2025-30208-template
https://github.com/ThumpBo/CVE-2025-30208-EXP
https://github.com/jackieya/ViteVulScan
https://github.com/Lusensec/CVE-2025-30208
https://github.com/ThemeHackers/CVE-2025-30208
https://github.com/r0ngy40/CVE-2025-30208-Series
https://github.com/TH-SecForge/CVE-2025-30208
https://github.com/MiclelsonCN/CVE-2025-30208_POC
https://github.com/sumeet-darekar/CVE-2025-30208
https://github.com/HazaVVIP/CVE-2025-30208
F5 observed mass scanning of exposed Vite dev servers exploiting CVE-2026-39364 and older flaws CVE-2025-30208, CVE-2025-31125, CVE-2024-45811. Stolen AWS/Azure credentials and deployment configs enable full cloud compromise, so isolate dev servers and rotate secrets. #Vite #CloudSecurity #ThreatIntelligence
https://cyberworldops.eu/en/hackers-scan-exposed-vite-servers-for-aws-azure-and-deployment-secrets
##F5 observed mass scanning of exposed Vite dev servers exploiting CVE-2026-39364 and older flaws CVE-2025-30208, CVE-2025-31125, CVE-2024-45811. Stolen AWS/Azure credentials and deployment configs enable full cloud compromise, so isolate dev servers and rotate secrets. #Vite #CloudSecurity #ThreatIntelligence
https://cyberworldops.eu/en/hackers-scan-exposed-vite-servers-for-aws-azure-and-deployment-secrets
##updated 2024-09-19T18:34:34
2 posts
F5 observed mass scanning of exposed Vite dev servers exploiting CVE-2026-39364 and older flaws CVE-2025-30208, CVE-2025-31125, CVE-2024-45811. Stolen AWS/Azure credentials and deployment configs enable full cloud compromise, so isolate dev servers and rotate secrets. #Vite #CloudSecurity #ThreatIntelligence
https://cyberworldops.eu/en/hackers-scan-exposed-vite-servers-for-aws-azure-and-deployment-secrets
##F5 observed mass scanning of exposed Vite dev servers exploiting CVE-2026-39364 and older flaws CVE-2025-30208, CVE-2025-31125, CVE-2024-45811. Stolen AWS/Azure credentials and deployment configs enable full cloud compromise, so isolate dev servers and rotate secrets. #Vite #CloudSecurity #ThreatIntelligence
https://cyberworldops.eu/en/hackers-scan-exposed-vite-servers-for-aws-azure-and-deployment-secrets
##updated 2024-03-29T18:30:50
1 posts
89 repos
https://github.com/bioless/xz_cve-2024-3094_detection
https://github.com/Ava-Vispilio/CVE-2024-3094
https://github.com/Horizon-Software-Development/CVE-2024-3094
https://github.com/neuralinhibitor/xzwhy
https://github.com/hackura/xz-cve-2024-3094
https://github.com/hackingetico21/revisaxzutils
https://github.com/shefirot/CVE-2024-3094
https://github.com/felipecosta09/cve-2024-3094
https://github.com/ykhurshudyan-blip/CVE-2024-3094
https://github.com/Juul/xz-backdoor-scan
https://github.com/vesjolyjd/Kaspersky_CVE-2024-3094
https://github.com/weltregie/liblzma-scan
https://github.com/ElinaNotElina/cve-2024-3094-analysis
https://github.com/valeriot30/cve-2024-3094
https://github.com/nnatsopoulos/xz-backdoor-research
https://github.com/przemoc/xz-backdoor-links
https://github.com/gensecaihq/CVE-2024-3094-Vulnerability-Checker-Fixer
https://github.com/mhicairo-hue/cs50-cybersecurity-final-project
https://github.com/FabioBaroni/CVE-2024-3094-checker
https://github.com/stevehenderson/lab_xz_backdoor
https://github.com/M1lo25/CS50FinalProject
https://github.com/Yuma-Tsushima07/CVE-2024-3094
https://github.com/mightysai1997/CVE-2024-3094-info
https://github.com/iheb2b/CVE-2024-3094-Checker
https://github.com/namegabevictoire01-sys/cs50-cybersecurity-final-project
https://github.com/galacticquest/cve-2024-3094-detect
https://github.com/KaminaDuck/ansible-CVE-2024-3094
https://github.com/been22426/CVE-2024-3094
https://github.com/ashwani95/CVE-2024-3094
https://github.com/harekrishnarai/xz-utils-vuln-checker
https://github.com/hazemkya/CVE-2024-3094-checker
https://github.com/ScrimForever/CVE-2024-3094
https://github.com/mrk336/CVE-2024-3094
https://github.com/dah4k/CVE-2024-3094
https://github.com/Preacher98/Report-XZ-Utils-CVE-2024-3094
https://github.com/x-cmd-build/xz
https://github.com/Simplifi-ED/CVE-2024-3094-patcher
https://github.com/lypd0/CVE-2024-3094-Vulnerabity-Checker
https://github.com/robertdebock/ansible-playbook-cve-2024-3094
https://github.com/Ikram124/CVE-2024-3094-analysis
https://github.com/gustavorobertux/CVE-2024-3094
https://github.com/michalAshurov/writeup-CVE-2024-3094
https://github.com/amlweems/xzbot
https://github.com/ackemed/detectar_cve-2024-3094
https://github.com/0xlane/xz-cve-2024-3094
https://github.com/robertdebock/ansible-role-cve_2024_3094
https://github.com/zpxlz/CVE-2024-3094
https://github.com/encikayelwhitehat-glitch/CVE-2024-3094
https://github.com/hariskhalil555000-sketch/What-utility-does-CVE-2024-3094-refer-to-
https://github.com/robertdfrench/ifuncd-up
https://github.com/devjanger/CVE-2024-3094-XZ-Backdoor-Detector
https://github.com/24Owais/threat-intel-cve-2024-3094
https://github.com/AndreaCicca/Sicurezza-Informatica-Presentazione
https://github.com/jfrog/cve-2024-3094-tools
https://github.com/brinhosa/CVE-2024-3094-One-Liner
https://github.com/BOSE122/CVE-2024-3094
https://github.com/OpensourceICTSolutions/xz_utils-CVE-2024-3094
https://github.com/Mustafa1986/CVE-2024-3094
https://github.com/spidygal/CVE-2024-3094-Nmap-NSE-script
https://github.com/ThomRgn/xzutils_backdoor_obfuscation
https://github.com/bsekercioglu/cve2024-3094-Checker
https://github.com/h3raklez/CVE-2024-3094
https://github.com/Fractal-Tess/CVE-2024-3094
https://github.com/r0binak/xzk8s
https://github.com/jbnetwork-git/CVE-2024-3094-XZ-Utils-Check
https://github.com/byinarie/CVE-2024-3094-info
https://github.com/MagpieRYL/CVE-2024-3094-backdoor-env-container
https://github.com/Titus-soc/-CVE-2024-3094-Vulnerability-Checker-Fixer-Public
https://github.com/laxmikumari615/Linux---Security---Detect-and-Mitigate-CVE-2024-3094
https://github.com/Security-Phoenix-demo/CVE-2024-3094-fix-exploits
https://github.com/extracoding-dozen/CVE-2024-3094
https://github.com/Dermot-lab/TryHack
https://github.com/HackerHermanos/CVE-2024-3094_xz_check
https://github.com/Bella-Bc/xz-backdoor-CVE-2024-3094-Check
https://github.com/0xBlackash/CVE-2024-3094
https://github.com/MrBUGLF/XZ-Utils_CVE-2024-3094
https://github.com/vnchk1/sec_review_cve-2024-3094
https://github.com/emirkmo/xz-backdoor-github
https://github.com/mightysai1997/CVE-2024-3094
https://github.com/lockness-Ko/xz-vulnerable-honeypot
https://github.com/mesutgungor/xz-backdoor-vulnerability
https://github.com/badsectorlabs/ludus_xz_backdoor
https://github.com/teyhouse/CVE-2024-3094
https://github.com/wgetnz/CVE-2024-3094-check
https://github.com/pentestfunctions/CVE-2024-3094
https://github.com/fevar54/Detectar-Backdoor-en-liblzma-de-XZ-utils-CVE-2024-3094-
https://github.com/TheTorjanCaptain/CVE-2024-3094-Checker
Get CVE and exploit intel into your pipeline with one call. Metered, no seat licenses.
curl https://valtersit.com/api/cve/CVE-2024-3094
Pricing at https://www.valtersit.com/cve/pricing/
🟠 CVE-2026-73496 - High (7.7)
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src/mcp_atlas...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73496/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73496 - High (7.7)
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src/mcp_atlas...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73496/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##1 posts
9 repos
https://github.com/4minx/CVE-2026-72898
https://github.com/ubitquity/Metabase-Setup-Endpoint-SQLi-Fix
https://github.com/Franc-Zar/CVE-2026-72898-safe-detection
https://github.com/VuxNx/CVE-2026-72898
https://github.com/d-maggipinto/CVE-2026-72898-metabase-sqli
https://github.com/EQSTLab/CVE-2026-72898
https://github.com/0xBlackash/CVE-2026-72898
📰 Mathspace Breach Affects 1M Users via Metabase Flaw
Education platform Mathspace discloses a data breach affecting over 1 million users. Attackers exploited a known SQL injection flaw (CVE-2026-72898) in a self-hosted Metabase instance to access user PII. #DataBreach #CyberSecurity #EdTech #Metabase
##UNC3569 is exploiting CVE-2026-51990 in Tencent Sogou Input Method for Windows. A crafted sgbiz:// URL enables one-click SYSTEM-level code execution and GrayRabbit backdoor deployment. Widespread IME deployment makes this a high-priority patch and detection target. #SogouFlaw #GrayRabbit #ThreatIntel
https://cyberworldops.eu/en/tencent-sogou-input-flaw-exploited-for-one-click-system-level-code
##⚠️🐰 Tencent flaw deploys GrayRabbit
CVE-2026-51990 enables RCE through Sogou Input Method; fixed in version 16.3.
##Defend against the CVE-2026-51990 Sogou exploit. Discover how hackers use this one-click flaw to drop backdoors and how to secure your systems today.
#CVE202651990 #SogouInputMethod #CyberSecurity #UNC3569 #InfoSec #EndpointSecurity #ThreatIntel
##🏆 New Achievement! One Click to the Food Chain Bottom!
Here, in the wild habitat of Windows enterprise environments, we observe the Sogou Input Method — a text entry tool installed by millions — standing perfectly still as UNC3569, a China-aligned espionage group, approaches from the brush. CVE-2026-51990 is a critical one-click remote code execution flaw exploiting an unsandboxed Chromium chain. The creature does not run. It simply... accepts the GrayRabbit backdoor. (1/2)
##Hackers exploit Tencent app flaw to deploy GrayRabbit malware
Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method...
🔗️ [Bleepingcomputer] https://link.is.it/DXBwPD
##Hackers exploit Tencent app flaw to deploy GrayRabbit malware
Hackers are actively exploiting a critical flaw in Tencent's Sogou Input Method for Windows, using a clever one-click trick to deploy the GrayRabbit backdoor; researchers warn that this vulnerability, tracked as CVE-2026-51990, is being used to deliver malware to unsuspecting victims.
#GrayrabbitMalware #Tencent #Cve202651990 #RemoteCodeExecution #Windows
##UNC3569 is exploiting CVE-2026-51990 in Tencent Sogou Input Method for Windows. A crafted sgbiz:// URL enables one-click SYSTEM-level code execution and GrayRabbit backdoor deployment. Widespread IME deployment makes this a high-priority patch and detection target. #SogouFlaw #GrayRabbit #ThreatIntel
https://cyberworldops.eu/en/tencent-sogou-input-flaw-exploited-for-one-click-system-level-code
##Defend against the CVE-2026-51990 Sogou exploit. Discover how hackers use this one-click flaw to drop backdoors and how to secure your systems today.
#CVE202651990 #SogouInputMethod #CyberSecurity #UNC3569 #InfoSec #EndpointSecurity #ThreatIntel
##🏆 New Achievement! One Click to the Food Chain Bottom!
Here, in the wild habitat of Windows enterprise environments, we observe the Sogou Input Method — a text entry tool installed by millions — standing perfectly still as UNC3569, a China-aligned espionage group, approaches from the brush. CVE-2026-51990 is a critical one-click remote code execution flaw exploiting an unsandboxed Chromium chain. The creature does not run. It simply... accepts the GrayRabbit backdoor. (1/2)
##Hackers exploit Tencent app flaw to deploy GrayRabbit malware
Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method...
🔗️ [Bleepingcomputer] https://link.is.it/DXBwPD
##Critical AWS Systems Manager Flaw Could Turn EC2 Instances Into Credential Theft Gateways
Introduction: A Trusted AWS Tool With a Dangerous Blind Spot A critical vulnerability in the AWS Systems Manager Agent has exposed a particularly dangerous weakness in cloud environments: an attacker who already has authorized Session Manager access may be able to turn an EC2 instance into a bridge toward services that were supposed to be unreachable. Tracked as CVE-2026-89049,…
##3 posts
85 repos
https://github.com/johnlodan/wp2shell-rce
https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc
https://github.com/InstaWP/wp2shell-scan
https://github.com/JohenLastGen-JLG/wp2shell
https://github.com/mhassani97/cve-2026-63030-lab
https://github.com/Procjevt/CVE-2026-63030
https://github.com/Icex0/wp2shell-poc
https://github.com/DeadExpl0it/wp2shell-poc
https://github.com/Iqbalx7/wp2shell
https://github.com/hidden-investigations/wp2shell-scanner
https://github.com/Senanfurkan/wordpress-cve-2026-63030
https://github.com/Madelleimproved411/wp-to-code
https://github.com/Ch4120N/CVE-2026-63030
https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner
https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction
https://github.com/AnggaTechI/CVE-2026-63030
https://github.com/ikow/wp2shell
https://github.com/TomorrowX6/CVE-2026-63030-poc
https://github.com/NULL200OK/WP2Shell
https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause
https://github.com/Industri4l-H3ll-Xpl0it3rs/CVE-2026-63030-WP2Shell
https://github.com/ananay/wp2shell-lab
https://github.com/0xWhoknows/wp2shell
https://github.com/kulichr/wp2shell
https://github.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t
https://github.com/mcipekci/wp2shell
https://github.com/raphy76/wp2shell-poc-fulljs
https://github.com/SentinelXofficial/sxwp2shell
https://github.com/0xjessie21/wp2shell-checker
https://github.com/Colere-Sys/wp2shell-poc
https://github.com/mverschu/CVE-2026-63030
https://github.com/47Cid/wp2shell-lab
https://github.com/ivanesk315/CVE-2026-60137-and-CVE-2026-63030
https://github.com/Crypto-Cat/wp2shell
https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress
https://github.com/zeroc00I/CVE-2026-63030
https://github.com/michael-kanda/Wp2shell-ioc-scanner
https://github.com/mrx-arafat/CVE-2026-63030-POC
https://github.com/Lutfifakee-Project/wp2shell
https://github.com/fullhunt/wp2shell-scan
https://github.com/h4cd0c/wp2shell
https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell
https://github.com/yuag/wp2shell
https://github.com/x-znn/CVE-2026-63030
https://github.com/4B3R4M4-607D/CVE-2026-63030-POC
https://github.com/Sec-Dan/WP2Shell-Scanner
https://github.com/securelayer7/WordPresShell
https://github.com/imXur/WordPress-CVE-2026-63030-Analysis
https://github.com/mhtsec/CVE-2026-63030
https://github.com/CybersecSpirit/CVE-2026-63030
https://github.com/administrator-01001/CVE-2026-63030
https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner
https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030
https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC
https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin
https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137
https://github.com/c0gnit00/Wp2Shell
https://github.com/HackingLZ/wp2shell_stock_chain
https://github.com/dinosn/wp2shell-lab
https://github.com/zi3lak/wp2shell_scanner
https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN
https://github.com/shinthink/CVE-2026-63030
https://github.com/Lukols-Dev/wp-cve-2026-63030-check
https://github.com/gbrsh/CVE-2026-63030
https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030
https://github.com/codeb0ssx/Ultimate-wp2shell
https://github.com/own2pwn-fr/wp2shell-detect
https://github.com/ZenithGenius/wordpress-batch-rce-lab
https://github.com/TranDongA3/POC-CVE-2026-63030-CVE-2026-60137-
https://github.com/g0d150ne/WP2Shell
https://github.com/sowarma/wp2shell-PoC
https://github.com/AkbarWiraN/holy-wp2shell
https://github.com/bahartanir/wp2shell-scanner
https://github.com/ZephrFish/wp2shell-scanner
https://github.com/4minx/CVE-2026-63030
https://github.com/0xBlackash/CVE-2026-63030
https://github.com/0xsha/wp2shell
https://github.com/vulnquest58/PressVector
https://github.com/ChiefYoru/CVE-2026-63030_PoC
https://github.com/ekomsSavior/wp2shell
https://github.com/ebrasha/abdal-cve-2026-63030
https://github.com/M4xSec/wp2shell-Exploit-Waf-Bypass
https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030
Browsing through my webserver logs to see what the internet brings me today and I come across:
user_agent: cve-2026-63030/1.0
Nice when the attack bot tells you exactly what it's after.
This came from 85.239.151.0/24 registered under "Aeza International LTD". Turns out this company is under international sanctions. Looking up AS19318, this netblock seems to be managed by Interserver, Inc, US.
##wp2shell (CVE-2026-63030): Pre-Auth RCE Chain in WordPress Core - Analysis and Open-Source Scanner https://fullhunt.io/blog/2026/07/17/wp2shell-wordpress-core-pre-auth-rce-cve-2026-63030.html
##wp2shell (CVE-2026-63030): Pre-Auth RCE Chain in WordPress Core - Analysis and Open-Source Scanner https://fullhunt.io/blog/2026/07/17/wp2shell-wordpress-core-pre-auth-rce-cve-2026-63030.html
##🟠 CVE-2026-15891 - High (7.5)
The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&client->gateways, gw, next) but discarded the result....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15891/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-15891 - High (7.5)
The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&client->gateways, gw, next) but discarded the result....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15891/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-53761: Authentication bypass in Frappe CRM via logged invitation keys, affecting versions before 1.73.0. CVSS N/A, but unpatched installs are at risk of unauthorized access. Patch immediately! Details: https://www.valtersit.com/cve/CVE-2026-53761/ #CVE #cybersecurity #Fr
##