## Updated at UTC 2026-10-08T20:26:52.638354

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-95210 9.1 0.00% 2 0 2026-10-08T19:20:52.957000 Improper certificate validation in gnutls v3.8.13 causes the application to acce
CVE-2026-107704 9.8 0.00% 2 0 2026-10-08T19:17:02.897000 The image_optimizer Ruby gem 1.3.0 through 1.9.0 contains an OS command injectio
CVE-2026-107703 9.8 0.00% 2 0 2026-10-08T19:17:02.720000 @enmaso/node-convert through 1.0.0 contains an OS command injection vulnerabilit
CVE-2026-107701 8.2 0.00% 2 0 2026-10-08T19:17:02.403000 dot-access through 1.0.0 contains a prototype pollution vulnerability that allow
CVE-2026-107700 9.8 0.00% 2 0 2026-10-08T19:17:02.213000 dot-access 0.0.3 through 1.0.0 contains a code injection vulnerability that allo
CVE-2026-107699 9.8 0.00% 2 0 2026-10-08T19:17:01.853000 ppt2png through 0.0.6 contains an OS command injection vulnerability that allows
CVE-2026-107384 8.1 0.00% 2 0 2026-10-08T19:17:00.990000 MariaDB Connector/Node.js is used to connect applications developed on Node.js t
CVE-2026-107383 7.5 0.00% 2 0 2026-10-08T19:17:00.783000 MariaDB Connector/Node.js is used to connect applications developed on Node.js t
CVE-2026-107376 8.2 0.00% 2 0 2026-10-08T19:17:00.327000 webonyx graphql-php is a PHP implementation of the GraphQL specification. Prior
CVE-2026-107322 7.8 0.00% 2 0 2026-10-08T19:16:59.857000 An incomplete list of disallowed inputs in Amazon Agent Plugins for AWS database
CVE-2026-106433 8.8 0.00% 2 0 2026-10-08T19:16:59.233000 Improper state management in MongoDB libmongocrypt can cause provider-specific d
CVE-2015-3306 10.0 96.75% 5 18 template 2026-10-08T18:32:52 The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write t
CVE-2021-3199 9.8 8.21% 5 0 2026-10-08T18:32:52 Directory traversal with remote code execution can occur in /upload in ONLYOFFIC
CVE-2026-107333 8.1 0.00% 2 0 2026-10-08T18:32:39 Malcolm's nginx based reverse proxy contains a URL path normalization inconsiste
CVE-2026-104077 7.8 0.00% 2 0 2026-10-08T18:32:31 Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability th
CVE-2026-93674 9.8 0.76% 1 1 2026-10-08T18:29:00.377000 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute a
CVE-2026-9209 9.8 0.00% 2 1 2026-10-08T18:18:33.757000 mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulne
CVE-2026-15762 9.8 0.00% 1 0 2026-10-08T18:17:27.660000 IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.
CVE-2026-107303 7.6 0.00% 2 0 2026-10-08T18:17:19.277000 JHipster is a development platform to quickly generate, develop, and deploy mode
CVE-2026-107302 7.5 0.00% 2 0 2026-10-08T18:17:19.100000 msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.
CVE-2026-107300 7.5 0.00% 2 0 2026-10-08T18:17:17.697000 msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.
CVE-2026-104078 7.8 0.00% 2 0 2026-10-08T18:17:13.277000 Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bun
CVE-2015-5477 7.5 91.28% 5 8 2026-10-08T18:17:11.250000 named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote
CVE-2026-107377 7.5 0.00% 2 0 2026-10-08T17:58:02 ## Summary When processing an attacker-controlled Protobuf schema, vulnerable v
CVE-2026-106446 9.8 0.64% 1 0 2026-10-08T17:52:34 ## Summary `Handlebars.compile()` and `Handlebars.precompile()` accept a pre-pa
CVE-2026-107375 8.8 0.00% 2 0 2026-10-08T17:40:37 # SQL Injection in the `sort` Parameter of JHipster-Generated Reactive (WebFlux
CVE-2026-107352 7.7 0.20% 1 0 2026-10-08T17:26:22.830000 Missing authorization checks in Amazon Athena engine version 3 request handling
CVE-2026-71895 7.1 0.17% 1 0 2026-10-08T17:25:38.450000 An authorization vulnerability in Apache DolphinScheduler allows authenticated n
CVE-2026-71896 6.5 0.16% 1 0 2026-10-08T17:25:38.450000 An authorization vulnerability in Apache DolphinScheduler allows authenticated u
CVE-2026-95534 8.8 0.29% 1 0 2026-10-08T17:24:31.040000 Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited
CVE-2026-105436 8.8 0.00% 2 0 2026-10-08T17:24:11.230000 Deserialization of Untrusted Data vulnerability in MainWP MainWP Child mainwp-ch
CVE-2026-105110 9.8 2.79% 1 0 2026-10-08T17:17:12 OS Command Injection in the login.xgi CGI endpoint in Iskratel Innbox GPON ONT d
CVE-2026-107295 7.6 0.00% 2 0 2026-10-08T17:16:37 ### Summary The Pydantic AI development web chat UI (`Agent.to_web()`, `clai we
CVE-2026-107215 7.5 0.22% 1 0 2026-10-08T16:31:27 ### Summary `extractPart` allocates directly from the mscfb directory-entry siz
CVE-2026-107216 7.5 0.31% 1 0 2026-10-08T16:31:23 ### Summary `ANCHORARRAY` (calc.go:15137 on current master) evaluates each cell
CVE-2026-76472 8.8 0.12% 1 0 2026-10-08T16:17:43.130000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76458 8.6 0.28% 1 0 2026-10-08T16:17:42.737000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-16340 9.8 0.00% 2 0 2026-10-08T15:33:05 IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.
CVE-2026-93017 7.7 0.00% 2 0 2026-10-08T15:17:56.950000 The `insights-operator-gather` ClusterRole grants the operator's service account
CVE-2026-107510 9.1 0.00% 1 0 2026-10-08T15:17:43.183000 An authenticated high privilege user can inject arguments in troubleshooting com
CVE-2026-76485 9.8 0.51% 3 0 2026-10-08T13:17:19.953000 A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) fe
CVE-2026-106197 9.6 0.40% 1 0 2026-10-08T13:03:34.193000 Use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remo
CVE-2026-12260 None 0.23% 1 0 2026-10-08T09:32:03 SQL injection in the NetBoard CRM demo platform; specifically, the vulnerable co
CVE-2026-107459 9.8 1.47% 1 0 2026-10-08T06:31:28 The SecuShare Pro developed by Openfind has an OS Command Injection vulnerabilit
CVE-2026-17609 9.1 0.31% 1 0 2026-10-08T06:31:27 The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to
CVE-2026-79806 7.8 0.10% 1 0 2026-10-08T04:17:50.280000 A privilege escalation vulnerability in the ClearPass Policy Manager OnGuard Lin
CVE-2026-79803 8.8 0.80% 1 0 2026-10-08T04:17:49.827000 A command injection vulnerability exists in the API of ClearPass Policy Manager.
CVE-2026-79800 8.8 0.62% 1 0 2026-10-08T04:17:43.710000 An authenticated path traversal vulnerability exists in the command line interfa
CVE-2026-79798 9.9 0.34% 1 0 2026-10-08T04:17:43.317000 SQL injection vulnerabilities in the web-based management interface of ClearPass
CVE-2026-79796 9.8 0.46% 1 0 2026-10-08T04:17:42.980000 Vulnerabilities have been identified in the affected interface of ClearPass Poli
CVE-2026-76480 9.8 0.33% 1 0 2026-10-08T04:17:34.733000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76471 9.8 0.52% 3 0 2026-10-08T04:17:34.533000 A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an una
CVE-2026-76465 9.8 0.45% 3 0 2026-10-08T04:17:34.377000 A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) fea
CVE-2026-19386 0 0.19% 1 0 2026-10-08T04:17:19.810000 A stack-based buffer overflow in the ASUS router modules allows an authenticated
CVE-2026-76281 None 0.15% 1 0 2026-10-07T21:33:38 Improper Access Control. Splunk addressed multiple internally identified vulnera
CVE-2026-76268 9.8 0.40% 2 0 2026-10-07T21:33:30 In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user w
CVE-2026-76266 7.7 0.12% 1 0 2026-10-07T21:33:30 In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15 on Linux
CVE-2026-79802 8.8 1.19% 1 0 2026-10-07T21:33:24 A command injection vulnerability exists in the client software of ClearPass Pol
CVE-2026-79801 9.8 0.32% 1 0 2026-10-07T21:33:24 A missing integrity verification vulnerability in the client agent software of H
CVE-2026-79799 8.8 0.33% 1 0 2026-10-07T21:33:24 A vulnerability in the web-based management interface of ClearPass Policy Manage
CVE-2026-79797 8.8 0.27% 1 0 2026-10-07T21:33:24 An improper access control vulnerability exists in the Android client applicatio
CVE-2026-79808 7.8 0.11% 1 0 2026-10-07T21:33:24 A buffer overflow vulnerability exists in the OnGuard agent of ClearPass Policy
CVE-2026-79807 7.8 0.08% 1 0 2026-10-07T21:33:24 A missing integrity verification vulnerability in the Windows client software fo
CVE-2026-79805 9.8 0.43% 1 0 2026-10-07T21:33:24 An authenticated path traversal vulnerability exists in ClearPass Policy Manager
CVE-2026-76744 9.8 0.51% 1 0 2026-10-07T21:33:23 Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Succes
CVE-2026-76750 9.8 0.54% 1 0 2026-10-07T21:33:23 Deserialization of untrusted data vulnerabilities exist in the web interface of
CVE-2026-105857 10.0 0.43% 1 0 2026-10-07T20:28:48 ## Impact A vulnerability in `@payloadcms/plugin-form-builder` in versions < 3.
CVE-2026-106115 7.5 0.35% 1 0 2026-10-07T20:24:49 ### Summary The TIFF CCITT Group 4 (T6) encoder writes beyond its logical compr
CVE-2026-106112 7.5 0.35% 1 0 2026-10-07T20:24:38 ### Summary When ICC conversion is enabled, a malformed embedded ICC LUT16 prof
CVE-2026-106113 7.5 0.35% 1 0 2026-10-07T20:24:24 ### Summary `SixLabors.ImageSharp` can terminate a process when an application
CVE-2026-107217 7.5 0.34% 1 0 2026-10-07T20:23:32 ### Summary `ColumnNameToNumber` (lib.go:220-237) accumulates the bijective bas
CVE-2026-20362 7.2 0.47% 2 0 2026-10-07T20:17:12.390000 A vulnerability in the web-based management interface of Cisco Finesse could all
CVE-2026-107219 7.5 0.34% 1 0 2026-10-07T20:17:11.450000 Excelize is a Go language library for reading and writing Microsoft Excel spread
CVE-2026-107214 7.5 0.27% 1 0 2026-10-07T20:17:11.320000 Excelize is a Go language library for reading and writing Microsoft Excel spread
CVE-2026-107161 7.5 0.24% 1 0 2026-10-07T20:17:10.977000 A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge(
CVE-2026-76498 9.8 0.30% 1 0 2026-10-07T19:17:41.153000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76470 8.8 0.18% 1 0 2026-10-07T19:17:40.830000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76456 8.6 0.28% 1 0 2026-10-07T19:17:40.127000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-14911 0 0.32% 2 0 2026-10-07T19:17:35.867000 Improper Neutralization of Input During Web Page Generation (“Cross-site Scripti
CVE-2026-107104 0 0.42% 1 0 2026-10-07T19:17:33.483000 This vulnerability exists in the ERP system due to unsafe deserialization of use
CVE-2026-102255 10.0 0.48% 5 0 2026-10-07T18:33:12 A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Pla
CVE-2026-95606 9.8 0.33% 2 0 2026-10-07T18:32:21 Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Ev
CVE-2026-76453 8.8 0.34% 1 0 2026-10-07T18:32:21 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76457 8.6 0.28% 1 0 2026-10-07T18:32:21 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76483 9.1 0.22% 1 0 2026-10-07T18:32:21 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-96335 7.5 0.20% 1 0 2026-10-07T18:32:21 Missing Authorization vulnerability in WPMU DEV Forminator allows Exploiting Inc
CVE-2026-76499 9.8 0.31% 1 0 2026-10-07T18:32:21 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76486 9.8 0.51% 1 0 2026-10-07T18:32:21 A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) fe
CVE-2026-76484 8.8 0.28% 1 0 2026-10-07T18:32:21 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-95605 9.3 0.25% 1 0 2026-10-07T18:32:21 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CVE-2026-76464 9.6 0.19% 2 0 2026-10-07T18:32:20 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76467 7.5 0.25% 2 0 2026-10-07T18:32:20 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76463 8.8 0.14% 2 0 2026-10-07T18:32:20 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76455 9.8 0.28% 2 0 2026-10-07T18:32:20 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76459 8.8 0.28% 1 0 2026-10-07T18:32:20 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76482 10.0 0.20% 2 0 2026-10-07T18:32:20 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20328 9.1 0.52% 2 0 2026-10-07T18:32:14 A vulnerability in the web-based management interface of Cisco License On-Prem,
CVE-2026-76500 9.8 0.33% 1 0 2026-10-07T18:32:14 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76501 9.8 0.51% 1 0 2026-10-07T18:32:14 A vulnerability in the Segment Routing over IPv6 (SRv6) Operation, Administratio
CVE-2026-107206 9.4 0.58% 1 0 2026-10-07T18:32:14 LMCache through 0.5.5 contains a missing authentication vulnerability in the mul
CVE-2026-107205 8.6 0.39% 1 0 2026-10-07T18:32:14 LMCache through 0.5.5 contains a missing authentication vulnerability in the mul
CVE-2026-92414 None 0.62% 1 0 2026-10-07T18:32:14 : Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabb
CVE-2026-96408 9.4 0.64% 1 0 2026-10-07T18:17:32.210000 A code injection vulnerability exists in the upgrade script of Movable Type, whi
CVE-2026-107212 7.5 0.34% 1 0 2026-10-07T18:17:18.670000 Excelize is a Go language library for reading and writing Microsoft Excel spread
CVE-2026-105192 9.8 0.48% 3 1 2026-10-07T18:17:15.427000 LMCache multiprocess mode, also called distributed mode, opens an unauthenticate
CVE-2026-104286 9.8 2.20% 1 2 2026-10-07T18:17:15.240000 An improper limitation of a pathname to a restricted directory ('path traversal'
CVE-2026-106441 7.8 0.17% 1 0 2026-10-07T18:03:56 ## Summary Hydra passed its Python logging configuration to `logging.config.dic
CVE-2026-106510 7.7 0.44% 1 0 2026-10-07T18:03:25 ### Impact An authenticated user who can register catalog entities can provide
CVE-2026-102489 9.8 1.26% 1 2 2026-10-07T18:03:07.387000 Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability tha
CVE-2026-76468 8.2 0.23% 1 0 2026-10-07T17:16:59.680000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76454 9.1 0.58% 1 0 2026-10-07T17:16:57.363000 A vulnerability in the Cisco Smart Licensing Utility API of Cisco License On-Pre
CVE-2026-62253 9.8 0.42% 1 0 2026-10-07T17:16:56.627000 Homer is open source telecom observability software. Prior to version 11.0.283,
CVE-2026-62176 9.1 0.46% 1 0 2026-10-07T17:16:56.153000 PraisonAI is a multi-agent teams system. Prior to version 4.6.78, the `deploy/ap
CVE-2026-107204 9.8 0.77% 1 0 2026-10-07T17:16:53.657000 LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerab
CVE-2026-106501 9.6 0.47% 1 0 2026-10-07T17:16:49.597000 Backstage is an open framework for building developer portals. Prior to 3.3.1, 3
CVE-2026-106118 7.5 0.60% 1 0 2026-10-07T16:18:57 ## Summary When decoding a tiled TIFF with fax compression (T4/T6/MH), `DecodeT
CVE-2026-106117 7.5 0.43% 1 0 2026-10-07T16:18:52 ## Summary When decoding a fax-compressed strip TIFF (Compression=3 / Group 3 1
CVE-2026-101027 7.7 0.17% 1 0 2026-10-07T16:17:31.953000 When `[migrations] ALLOWED_DOMAINS` was configured, a hostname matching the allo
CVE-2026-62251 8.1 0.34% 1 0 2026-10-07T16:13:09 ### Summary The `V4StatisticsQuery` handler passes the user-supplied `rawquery`
CVE-2026-62252 9.8 0.65% 1 0 2026-10-07T16:12:03 ### Summary On every fresh Homer deployment using internal authentication, the b
CVE-2026-16516 0 0.15% 2 0 2026-10-07T16:02:27.613000 wolfSSH does not validate that the ECDSA curve identifier in a KEXDH_REPLY host
CVE-2026-77214 8.2 0.55% 1 0 2026-10-07T15:57:20.793000 libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in
CVE-2026-106558 8.8 0.47% 1 0 2026-10-07T15:52:18.453000 Backstage is an open framework for building developer portals. Prior to 1.14.8,
CVE-2026-21589 None 1.77% 20 10 template 2026-10-07T15:31:33 h3. Summary This is a vulnerability in Bitbucket Data Center, Confluence Data C
CVE-2026-106442 7.8 0.16% 1 0 2026-10-07T15:17:11.900000 Hydra is a framework for elegantly configuring complex applications. From 1.3.4
CVE-2026-103059 9.1 0.28% 1 0 2026-10-07T15:16:56.737000 When Gitea's built-in SSH server is enabled (`START_SSH_SERVER = true`), the pre
CVE-2026-106445 0 0.41% 1 0 2026-10-07T13:58:29.527000 Handlebars provides the power necessary to let users build semantic templates. F
CVE-2026-102159 9.8 0.36% 1 0 2026-10-07T13:38:48.657000 An access-control flaw in the CV-CUE backend may allow an unauthenticated networ
CVE-2025-64393 None 0.36% 2 0 2026-10-07T09:32:29 This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execu
CVE-2026-59346 9.3 0.26% 3 1 2026-10-07T06:33:08 VMware Workstation and Fusion contain an integer-overflow vulnerability. A malic
CVE-2026-19572 None 0.37% 1 0 2026-10-07T06:33:01 A security vulnerability has been identified in FlexNet Publisher lmadmin. The v
CVE-2026-91140 9.6 1.92% 1 0 2026-10-07T04:18:10.610000 An OS command injection vulnerability in the shell-based temporary-file cleanup
CVE-2026-101207 8.8 1.66% 1 0 2026-10-07T04:17:38.120000 Dell OpenManage Integration with Microsoft Windows Admin Center, versions prior
CVE-2026-83540 None 0.34% 1 0 2026-10-07T03:30:31 When password or public key authentication is used with the Windows port of wolf
CVE-2026-105324 None 0.65% 1 0 2026-10-07T03:30:23 An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an
CVE-2026-86361 8.2 0.14% 1 0 2026-10-06T21:31:59 Dell System Update, versions prior to 2.3.0.0, contains an Incorrect Permission
CVE-2026-103007 7.2 0.34% 1 0 2026-10-06T21:31:57 Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalat
CVE-2026-102406 8.8 0.35% 1 0 2026-10-06T21:31:55 Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana could lead
CVE-2026-86362 8.2 0.13% 1 0 2026-10-06T21:31:53 Dell System Update, versions prior to 2.3.0.0, contains an Improper Access Contr
CVE-2026-106382 9.6 0.40% 2 0 2026-10-06T21:31:51 Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a r
CVE-2026-104073 7.6 0.28% 1 0 2026-10-06T21:31:41 NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vuln
CVE-2026-86360 9.6 0.63% 1 0 2026-10-06T20:17:34.090000 Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation o
CVE-2026-106443 8.8 0.69% 1 0 2026-10-06T20:17:26.023000 WeasyPrint helps web developers to create PDF documents. Prior to 70.0, the imag
CVE-2026-106440 7.8 0.27% 1 0 2026-10-06T20:03:40.690000 Hydra is a framework for elegantly configuring complex applications. From 1.2.0
CVE-2026-106110 7.5 0.35% 1 0 2026-10-06T20:03:40.690000 ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Grou
CVE-2026-105859 9.8 0.35% 1 0 2026-10-06T20:03:40.690000 Payload is a free and open source headless content management system. In version
CVE-2026-105858 8.1 0.48% 1 0 2026-10-06T20:03:40.690000 Payload is a free and open source headless content management system. In version
CVE-2026-63697 7.6 0.29% 1 0 2026-10-06T19:58:37.060000 Dell System Update, versions prior to 2.3.0.0, contains an Improper Certificate
CVE-2026-104070 9.8 0.57% 2 0 2026-10-06T18:31:38 The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulner
CVE-2026-105796 8.8 0.90% 1 0 2026-10-06T16:00:36.547000 Kiota is an OpenAPI based HTTP Client code generator. From 0.5.0 until 1.35.0, K
CVE-2026-104850 7.5 0.18% 1 0 2026-10-06T15:35:44 ### Summary In affected versions, the SDK's OAuth client let the MCP server deci
CVE-2026-63688 10.0 0.79% 1 0 2026-10-06T15:32:11 Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Miss
CVE-2026-63277 0 0.14% 1 1 2026-10-06T15:03:59.427000 LibreOffice Calc can link a cell range to an external data source, and the link
CVE-2026-88779 7.5 0.59% 2 2 2026-10-05T15:33:23 Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: b
CVE-2026-50572 5.9 0.68% 1 0 2026-10-05T14:12:02.027000 Envoy is an open source edge and service proxy designed for cloud-native applica
CVE-2026-48521 5.9 0.74% 1 0 2026-10-05T14:09:45.933000 Envoy is an open source edge and service proxy designed for cloud-native applica
CVE-2026-53359 8.8 0.98% 1 7 2026-10-03T12:32:07 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: F
CVE-2026-96940 8.8 0.50% 1 1 2026-10-02T21:32:13 Weak authorization in Microsoft Exchange Server allows an authenticated attacker
CVE-2026-90970 9.9 0.94% 1 1 2026-10-02T18:44:11.270000 GitLab has remediated a vulnerability in the GitLab AI Gateway component affecti
CVE-2026-88772 8.1 1.30% 1 8 2026-09-28T12:32:09 Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue
CVE-2026-88771 9.8 1.08% 3 14 2026-09-28T12:32:08 Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetSc
CVE-2026-91166 5.7 0.22% 1 0 2026-09-24T23:19:21.613000 Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.2
CVE-2026-93836 7.2 0.24% 1 0 2026-09-22T09:31:18 The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to St
CVE-2026-94504 7.2 0.41% 1 0 2026-09-22T09:31:17 Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it wit
CVE-2026-94572 None 0.53% 1 0 2026-09-21T21:32:02 In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate
CVE-2026-87491 8.8 3.14% 1 2 2026-09-09T21:31:35 Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remo
CVE-2026-85046 8.8 48.88% 1 8 2026-09-06T03:30:24 Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote at
CVE-2026-68508 7.8 0.46% 1 0 2026-08-21T20:57:32 ## Summary `hydra.utils.instantiate()` resolves and calls Python objects from c
CVE-2026-47483 8.2 0.55% 1 0 2026-07-28T18:33:11 NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pp
CVE-2025-54769 8.8 3.33% 1 2 2026-06-17T09:40:40.793000 An authenticated, read-only user can upload a file and perform a directory trave
CVE-2025-41739 5.9 0.35% 1 0 2026-06-17T09:23:04.017000 An unauthenticated remote attacker, who beats a race condition, can exploit a fl
CVE-2025-41738 7.5 0.39% 1 0 2026-06-17T09:23:03.883000 An unauthenticated remote attacker may cause the visualisation server of the COD
CVE-2025-41659 8.3 0.22% 1 0 2026-06-17T09:22:54.780000 A low-privileged attacker can remotely access the PKI folder of the CODESYS Cont
CVE-2026-10520 10.0 99.91% 2 9 template 2026-06-11T21:31:50 An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6
CVE-2024-50623 8.8 98.61% 2 4 template 2025-10-22T00:34:15 In Cleo Harmony before 5.8.0.20, VLTrader before 5.8.0.20, and LexiCom before 5.
CVE-2021-26085 5.3 99.94% 1 2 template 2025-10-22T00:33:23 Affected versions of Atlassian Confluence Server allow remote attackers to view
CVE-2025-41691 7.5 0.55% 1 0 2025-08-04T09:30:34 An unauthenticated remote attacker may trigger a NULL pointer dereference in the
CVE-2023-22894 7.5 1.66% 4 2 2023-11-07T05:05:45 ### Summary Strapi through 4.7.1 allows unauthenticated attackers to discover s
CVE-2016-3081 8.1 93.35% 5 0 template 2023-11-01T19:47:30 Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when
CVE-2026-84276 0 0.00% 2 0 N/A
CVE-2026-107332 0 0.00% 2 0 N/A
CVE-2026-72898 0 19.05% 1 10 template N/A
CVE-2026-77459 0 0.00% 1 0 N/A
CVE-2026-103416 0 0.21% 1 0 N/A
CVE-2026-105797 0 0.56% 1 0 N/A
CVE-2026-105793 0 0.86% 1 0 N/A
CVE-2026-61744 0 0.51% 1 0 N/A

CVE-2026-95210
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-10-08T19:20:52.957000

2 posts

Improper certificate validation in gnutls v3.8.13 causes the application to accept certificates containing invalid extensions.

thehackerwire@mastodon.social at 2026-10-08T19:46:45.000Z ##

🔴 CVE-2026-95210 - Critical (9.1)

Improper certificate validation in gnutls v3.8.13 causes the application to accept certificates containing invalid extensions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-08T19:46:45.000Z ##

🔴 CVE-2026-95210 - Critical (9.1)

Improper certificate validation in gnutls v3.8.13 causes the application to accept certificates containing invalid extensions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107704
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-08T19:17:02.897000

2 posts

The image_optimizer Ruby gem 1.3.0 through 1.9.0 contains an OS command injection vulnerability in ImageOptimizer#identify_format that allows attackers to execute commands by supplying a crafted image path when the identify option is enabled. Attackers controlling the path, such as an uploaded file name, can append shell metacharacters like ';' that are executed via Ruby backticks with the Ruby pr

thehackerwire@mastodon.social at 2026-10-08T19:31:57.000Z ##

🔴 CVE-2026-107704 - Critical (9.8)

The image_optimizer Ruby gem 1.3.0 through 1.9.0 contains an OS command injection vulnerability in ImageOptimizer#identify_format that allows attackers to execute commands by supplying a crafted image path when the identify option is enabled. Atta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-08T19:31:57.000Z ##

🔴 CVE-2026-107704 - Critical (9.8)

The image_optimizer Ruby gem 1.3.0 through 1.9.0 contains an OS command injection vulnerability in ImageOptimizer#identify_format that allows attackers to execute commands by supplying a crafted image path when the identify option is enabled. Atta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107703
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-08T19:17:02.720000

2 posts

@enmaso/node-convert through 1.0.0 contains an OS command injection vulnerability in convert.js that allows attackers to execute shell commands via unsanitized filepath and convertTo arguments. Attackers can inject shell metacharacters or a single quote into the ImageMagick command run by child_process.exec() to execute operating system commands with Node.js process privileges.

thehackerwire@mastodon.social at 2026-10-08T19:31:48.000Z ##

🔴 CVE-2026-107703 - Critical (9.8)

@enmaso/node-convert through 1.0.0 contains an OS command injection vulnerability in convert.js that allows attackers to execute shell commands via unsanitized filepath and convertTo arguments. Attackers can inject shell metacharacters or a single...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-08T19:31:48.000Z ##

🔴 CVE-2026-107703 - Critical (9.8)

@enmaso/node-convert through 1.0.0 contains an OS command injection vulnerability in convert.js that allows attackers to execute shell commands via unsanitized filepath and convertTo arguments. Attackers can inject shell metacharacters or a single...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107701
(8.2 HIGH)

EPSS: 0.00%

updated 2026-10-08T19:17:02.403000

2 posts

dot-access through 1.0.0 contains a prototype pollution vulnerability that allows attackers to modify Object.prototype by supplying a crafted dotted path to set(). Attackers controlling the path, such as through user-supplied field names, can use __proto__ segments to inject properties into all objects, altering authorization flags and option defaults or crashing the process.

thehackerwire@mastodon.social at 2026-10-08T19:31:00.000Z ##

🟠 CVE-2026-107701 - High (8.2)

dot-access through 1.0.0 contains a prototype pollution vulnerability that allows attackers to modify Object.prototype by supplying a crafted dotted path to set(). Attackers controlling the path, such as through user-supplied field names, can use ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-08T19:31:00.000Z ##

🟠 CVE-2026-107701 - High (8.2)

dot-access through 1.0.0 contains a prototype pollution vulnerability that allows attackers to modify Object.prototype by supplying a crafted dotted path to set(). Attackers controlling the path, such as through user-supplied field names, can use ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107700
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-08T19:17:02.213000

2 posts

dot-access 0.0.3 through 1.0.0 contains a code injection vulnerability that allows remote attackers to execute JavaScript by supplying crafted paths to get(). The path is concatenated into a new Function body in index.js, so attackers can reach constructor.constructor to load child_process and run operating system commands in the Node.js process.

thehackerwire@mastodon.social at 2026-10-08T19:30:51.000Z ##

🔴 CVE-2026-107700 - Critical (9.8)

dot-access 0.0.3 through 1.0.0 contains a code injection vulnerability that allows remote attackers to execute JavaScript by supplying crafted paths to get(). The path is concatenated into a new Function body in index.js, so attackers can reach co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-08T19:30:51.000Z ##

🔴 CVE-2026-107700 - Critical (9.8)

dot-access 0.0.3 through 1.0.0 contains a code injection vulnerability that allows remote attackers to execute JavaScript by supplying crafted paths to get(). The path is concatenated into a new Function body in index.js, so attackers can reach co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107699
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-08T19:17:01.853000

2 posts

ppt2png through 0.0.6 contains an OS command injection vulnerability that allows attackers to execute operating system commands by supplying unsanitized input or output path arguments. Attackers can append shell metacharacters such as ';' to file names passed to child_process.exec() in ppt2png.js, running commands with Node.js process privileges.

thehackerwire@mastodon.social at 2026-10-08T19:32:08.000Z ##

🔴 CVE-2026-107699 - Critical (9.8)

ppt2png through 0.0.6 contains an OS command injection vulnerability that allows attackers to execute operating system commands by supplying unsanitized input or output path arguments. Attackers can append shell metacharacters such as ';' to file ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-08T19:32:08.000Z ##

🔴 CVE-2026-107699 - Critical (9.8)

ppt2png through 0.0.6 contains an OS command injection vulnerability that allows attackers to execute operating system commands by supplying unsanitized input or output path arguments. Attackers can append shell metacharacters such as ';' to file ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107384
(8.1 HIGH)

EPSS: 0.00%

updated 2026-10-08T19:17:00.990000

2 posts

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. From 3.2.0 until 3.2.5, 3.3.4, 3.4.7, and 3.5.4, applications that enable permitSetMultiParamEntries can pass objects whose keys are expanded into a SQL SET clause without being processed by escapeId. An attacker-controlled key containing a backtick can close the quoted identifier and cau

thehackerwire@mastodon.social at 2026-10-08T19:45:55.000Z ##

🟠 CVE-2026-107384 - High (8.1)

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. From 3.2.0 until 3.2.5, 3.3.4, 3.4.7, and 3.5.4, applications that enable permitSetMultiParamEntries can pass objects whose keys are exp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-08T19:45:55.000Z ##

🟠 CVE-2026-107384 - High (8.1)

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. From 3.2.0 until 3.2.5, 3.3.4, 3.4.7, and 3.5.4, applications that enable permitSetMultiParamEntries can pass objects whose keys are exp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107383
(7.5 HIGH)

EPSS: 0.00%

updated 2026-10-08T19:17:00.783000

2 posts

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4, the GeoJSON Polygon and MultiPolygon binary encoders size a Buffer.allocUnsafe() allocation from each ring's numeric length before confirming that the ring is an array. A malformed non-array ring can therefore reserve bytes that the writing loop sk

thehackerwire@mastodon.social at 2026-10-08T19:45:45.000Z ##

🟠 CVE-2026-107383 - High (7.5)

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4, the GeoJSON Polygon and MultiPolygon binary encoders size a Buffer.allocUnsafe() allocation fro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-08T19:45:45.000Z ##

🟠 CVE-2026-107383 - High (7.5)

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4, the GeoJSON Polygon and MultiPolygon binary encoders size a Buffer.allocUnsafe() allocation fro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107376
(8.2 HIGH)

EPSS: 0.00%

updated 2026-10-08T19:17:00.327000

2 posts

webonyx graphql-php is a PHP implementation of the GraphQL specification. Prior to 15.32.3, GraphQL\Language\Parser performs recursive descent without a recursion limit in parseSelectionSet, parseValueLiteral, and parseTypeReference. A remote attacker can submit deeply nested selection sets, object or list values, or list types that exhaust the PHP process stack during pre-validation parsing, befo

thehackerwire@mastodon.social at 2026-10-08T18:30:24.000Z ##

🟠 CVE-2026-107376 - High (8.2)

webonyx graphql-php is a PHP implementation of the GraphQL specification. Prior to 15.32.3, GraphQL\Language\Parser performs recursive descent without a recursion limit in parseSelectionSet, parseValueLiteral, and parseTypeReference. A remote atta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-08T18:30:24.000Z ##

🟠 CVE-2026-107376 - High (8.2)

webonyx graphql-php is a PHP implementation of the GraphQL specification. Prior to 15.32.3, GraphQL\Language\Parser performs recursive descent without a recursion limit in parseSelectionSet, parseValueLiteral, and parseTypeReference. A remote atta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107322
(7.8 HIGH)

EPSS: 0.00%

updated 2026-10-08T19:16:59.857000

2 posts

An incomplete list of disallowed inputs in Amazon Agent Plugins for AWS databases-on-aws plugin before 1.7.1 might allow a remote unauthenticated actor to execute arbitrary operating system commands on the host running the helper via a crafted database command value introduced in the agent context. To remediate this issue, users should upgrade to databases-on-aws plugin version 1.7.1 or later a

thehackerwire@mastodon.social at 2026-10-08T19:46:37.000Z ##

🟠 CVE-2026-107322 - High (7.8)

An incomplete list of disallowed inputs in Amazon Agent Plugins for AWS databases-on-aws plugin before 1.7.1 might allow a remote unauthenticated actor to execute arbitrary operating system commands on the host running the helper via a crafted dat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-08T19:46:37.000Z ##

🟠 CVE-2026-107322 - High (7.8)

An incomplete list of disallowed inputs in Amazon Agent Plugins for AWS databases-on-aws plugin before 1.7.1 might allow a remote unauthenticated actor to execute arbitrary operating system commands on the host running the helper via a crafted dat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-106433
(8.8 HIGH)

EPSS: 0.00%

updated 2026-10-08T19:16:59.233000

2 posts

Improper state management in MongoDB libmongocrypt can cause provider-specific data to be treated as an incompatible type when cleaning up a key document containing duplicate masterKey fields. An authenticated actor who can modify key vault documents, or a server that returns such a key document, can cause invalid memory access and invalid frees in the client process. This can terminate the applic

thehackerwire@mastodon.social at 2026-10-08T19:46:04.000Z ##

🟠 CVE-2026-106433 - High (8.8)

Improper state management in MongoDB libmongocrypt can cause provider-specific data to be treated as an incompatible type when cleaning up a key document containing duplicate masterKey fields. An authenticated actor who can modify key vault docume...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-08T19:46:04.000Z ##

🟠 CVE-2026-106433 - High (8.8)

Improper state management in MongoDB libmongocrypt can cause provider-specific data to be treated as an incompatible type when cleaning up a key document containing duplicate masterKey fields. An authenticated actor who can modify key vault docume...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

ninjaintelgroup@mastodon.social at 2026-10-08T19:16:11.000Z ##

🚨 NEW on CISA KEV — exploited in the wild

🛡 ProFTPD ProFTPD
ProFTPD Improper Access Control Vulnerability
CVE: CVE-2015-3306 · patch by 2026-10-11

ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.

🔗 ninjasignal.ninja/intel/cve/CV
#cybersecurity #KEV #CVE #infosec

##

secdb at 2026-10-08T19:00:11.504Z ##

🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3306 (secdb.nttzen.cloud/cve/detail/)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: proftpd.org/ ; lists.debian.org/debian-securi ; lists.opensuse.org/archives/li ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5477 (secdb.nttzen.cloud/cve/detail/)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: web.archive.org/web/2015072901 ; access.redhat.com/errata/RHSA-; supportportal.juniper.net/s/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2016-3081 (secdb.nttzen.cloud/cve/detail/)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: cwiki.apache.org/confluence/di ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-3199 (secdb.nttzen.cloud/cve/detail/)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; github.com/ONLYOFFICE/Document ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2023-22894 (secdb.nttzen.cloud/cve/detail/)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: strapi.io/blog/security-disclo ; github.com/strapi/strapi/relea ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-10-08T18:02:00.000Z ##

CVE ID: CVE-2015-3306
Vendor: ProFTPD
Product: ProFTPD
Date Added: 2026-10-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-10-08T19:00:11.000Z ##

🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3306 (secdb.nttzen.cloud/cve/detail/)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: proftpd.org/ ; lists.debian.org/debian-securi ; lists.opensuse.org/archives/li ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5477 (secdb.nttzen.cloud/cve/detail/)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: web.archive.org/web/2015072901 ; access.redhat.com/errata/RHSA-; supportportal.juniper.net/s/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2016-3081 (secdb.nttzen.cloud/cve/detail/)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: cwiki.apache.org/confluence/di ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-3199 (secdb.nttzen.cloud/cve/detail/)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; github.com/ONLYOFFICE/Document ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2023-22894 (secdb.nttzen.cloud/cve/detail/)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: strapi.io/blog/security-disclo ; github.com/strapi/strapi/relea ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261008 #cisa20261008 #cve_2015_3306 #cve_2015_5477 #cve_2016_3081 #cve_2021_3199 #cve_2023_22894 #cve20153306 #cve20155477 #cve20163081 #cve20213199 #cve202322894

##

cisakevtracker@mastodon.social at 2026-10-08T18:02:00.000Z ##

CVE ID: CVE-2015-3306
Vendor: ProFTPD
Product: ProFTPD
Date Added: 2026-10-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2021-3199
(9.8 CRITICAL)

EPSS: 8.21%

updated 2026-10-08T18:32:52

5 posts

Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.

ninjaintelgroup@mastodon.social at 2026-10-08T19:16:00.000Z ##

🚨 NEW on CISA KEV — exploited in the wild

🛡 ONLYOFFICE Docs
ONLYOFFICE Docs Server Path Traversal Vulnerability
CVE: CVE-2021-3199 · patch by 2026-10-11

ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution.

🔗 ninjasignal.ninja/intel/cve/CV
#cybersecurity #KEV #CVE #infosec

##

secdb at 2026-10-08T19:00:11.504Z ##

🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3306 (secdb.nttzen.cloud/cve/detail/)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: proftpd.org/ ; lists.debian.org/debian-securi ; lists.opensuse.org/archives/li ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5477 (secdb.nttzen.cloud/cve/detail/)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: web.archive.org/web/2015072901 ; access.redhat.com/errata/RHSA-; supportportal.juniper.net/s/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2016-3081 (secdb.nttzen.cloud/cve/detail/)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: cwiki.apache.org/confluence/di ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-3199 (secdb.nttzen.cloud/cve/detail/)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; github.com/ONLYOFFICE/Document ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2023-22894 (secdb.nttzen.cloud/cve/detail/)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: strapi.io/blog/security-disclo ; github.com/strapi/strapi/relea ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-10-08T18:01:44.000Z ##

CVE ID: CVE-2021-3199
Vendor: ONLYOFFICE
Product: Docs
Date Added: 2026-10-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-10-08T19:00:11.000Z ##

🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3306 (secdb.nttzen.cloud/cve/detail/)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: proftpd.org/ ; lists.debian.org/debian-securi ; lists.opensuse.org/archives/li ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5477 (secdb.nttzen.cloud/cve/detail/)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: web.archive.org/web/2015072901 ; access.redhat.com/errata/RHSA-; supportportal.juniper.net/s/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2016-3081 (secdb.nttzen.cloud/cve/detail/)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: cwiki.apache.org/confluence/di ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-3199 (secdb.nttzen.cloud/cve/detail/)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; github.com/ONLYOFFICE/Document ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2023-22894 (secdb.nttzen.cloud/cve/detail/)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: strapi.io/blog/security-disclo ; github.com/strapi/strapi/relea ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261008 #cisa20261008 #cve_2015_3306 #cve_2015_5477 #cve_2016_3081 #cve_2021_3199 #cve_2023_22894 #cve20153306 #cve20155477 #cve20163081 #cve20213199 #cve202322894

##

cisakevtracker@mastodon.social at 2026-10-08T18:01:44.000Z ##

CVE ID: CVE-2021-3199
Vendor: ONLYOFFICE
Product: Docs
Date Added: 2026-10-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-107333
(8.1 HIGH)

EPSS: 0.00%

updated 2026-10-08T18:32:39

2 posts

Malcolm's nginx based reverse proxy contains a URL path normalization inconsistency between its Lua based role-based access control (RBAC) authorization layer and nginx's own request routing logic. An authenticated user can craft a specially formatted request path to bypass role-based restrictions and reach administrative or role gated endpoints they should not have access to. This affects all res

thehackerwire@mastodon.social at 2026-10-08T18:46:18.000Z ##

🟠 CVE-2026-107333 - High (8.1)

Malcolm's nginx based reverse proxy contains a URL path normalization inconsistency between its Lua based role-based access control (RBAC) authorization layer and nginx's own request routing logic. An authenticated user can craft a specially forma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-08T18:46:18.000Z ##

🟠 CVE-2026-107333 - High (8.1)

Malcolm's nginx based reverse proxy contains a URL path normalization inconsistency between its Lua based role-based access control (RBAC) authorization layer and nginx's own request routing logic. An authenticated user can craft a specially forma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104077
(7.8 HIGH)

EPSS: 0.00%

updated 2026-10-08T18:32:31

2 posts

Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability that allows attackers to craft malicious Markdown notes exploiting insufficient sanitization of the data-background-iframe attribute, which bypasses DOMPurify and is processed by the bundled Reveal.js 4.3.1 within the Slides core plugin, allowing a javascript: URL to execute in the resulting background iframe. Because No

thehackerwire@mastodon.social at 2026-10-08T17:31:44.000Z ##

🟠 CVE-2026-104077 - High (7.8)

Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability that allows attackers to craft malicious Markdown notes exploiting insufficient sanitization of the data-background-iframe attribute, which bypasses DOMPurify and is pro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-08T17:31:44.000Z ##

🟠 CVE-2026-104077 - High (7.8)

Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability that allows attackers to craft malicious Markdown notes exploiting insufficient sanitization of the data-background-iframe attribute, which bypasses DOMPurify and is pro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93674
(9.8 CRITICAL)

EPSS: 0.76%

updated 2026-10-08T18:29:00.377000

1 posts

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

1 repos

https://github.com/rmhowe425/POC-CVE-2026-93674

offseq@infosec.exchange at 2026-10-07T01:30:24.000Z ##

IBM Langflow OSS v1.0.0 – 1.12.2 is affected by CRITICAL code injection (CVE-2026-93674, CVSS 9.8). Remote code exec possible via improper OS command neutralization. No patch yet — restrict network access & monitor activity. radar.offseq.com/threat/cve-20 #OffSeq #IBM #Vuln #AppSec

##

CVE-2026-9209
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-08T18:18:33.757000

2 posts

mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the backing Sybase SQL Anywhere database using DBA/sysadmin privileges with no server-side authentication enforced beyond a client-side sessionStorage flag. Attacke

1 repos

https://github.com/MS-0x404/CVE-2026-92099

thehackerwire@mastodon.social at 2026-10-08T17:32:03.000Z ##

🔴 CVE-2026-9209 - Critical (9.8)

mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the backing...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-08T17:32:03.000Z ##

🔴 CVE-2026-9209 - Critical (9.8)

mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the backing...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15762
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-08T18:17:27.660000

1 posts

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.

CVE-2026-107303
(7.6 HIGH)

EPSS: 0.00%

updated 2026-10-08T18:17:19.277000

2 posts

JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures. Prior to generator-jhipster 9.4.0 and react-jhipster 1.1.0, generated applications can persist attacker-controlled Blob data and companion ContentType values, return them through generated REST endpoints, and pass them to the generated openFile helper in generators/cl

thehackerwire@mastodon.social at 2026-10-08T18:46:09.000Z ##

🟠 CVE-2026-107303 - High (7.6)

JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures. Prior to generator-jhipster 9.4.0 and react-jhipster 1.1.0, generated applications can persist attacker-controlled ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-08T18:46:09.000Z ##

🟠 CVE-2026-107303 - High (7.6)

JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures. Prior to generator-jhipster 9.4.0 and react-jhipster 1.1.0, generated applications can persist attacker-controlled ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107302
(7.5 HIGH)

EPSS: 0.00%

updated 2026-10-08T18:17:19.100000

2 posts

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the decoder reads the four-byte length of a map32 value before validating that the complete five-byte header is available. A truncated map32 header therefore causes a checked out-of-bounds buffer read and throws RangeError instead of IncompleteBufferError, which can unexpectedly terminate a request, stream, or wor

thehackerwire@mastodon.social at 2026-10-08T18:46:00.000Z ##

🟠 CVE-2026-107302 - High (7.5)

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the decoder reads the four-byte length of a map32 value before validating that the complete five-byte header is available. A truncated map32 header therefore caus...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-08T18:46:00.000Z ##

🟠 CVE-2026-107302 - High (7.5)

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the decoder reads the four-byte length of a map32 value before validating that the complete five-byte header is available. A truncated map32 header therefore caus...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107300
(7.5 HIGH)

EPSS: 0.00%

updated 2026-10-08T18:17:17.697000

2 posts

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invokes itself for each complete MessagePack value remaining in a chunk. A remote peer can send one chunk containing many small valid values, causing recursion proportional to the value count, exhausting the JavaScript call stack, and interrupting the process or stream. This issue

thehackerwire@mastodon.social at 2026-10-08T17:30:20.000Z ##

🟠 CVE-2026-107300 - High (7.5)

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invokes itself for each complete MessagePack value remaining in a chunk. A remote peer can send one chunk containing many small ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-08T17:30:20.000Z ##

🟠 CVE-2026-107300 - High (7.5)

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invokes itself for each complete MessagePack value remaining in a chunk. A remote peer can send one chunk containing many small ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104078
(7.8 HIGH)

EPSS: 0.00%

updated 2026-10-08T18:17:13.277000

2 posts

Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute arbitrary code by embedding a crafted \href value with a TAB byte in the URL scheme, causing filterURL to produce an empty protocol that bypasses the configured safeProtocols restrictions. Attackers can craft a note containing a malicious MathJax formul

thehackerwire@mastodon.social at 2026-10-08T17:31:54.000Z ##

🟠 CVE-2026-104078 - High (7.8)

Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute arbitrary code by embedding a crafted \href value with a TAB byte in the URL scheme, causing filterU...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-08T17:31:54.000Z ##

🟠 CVE-2026-104078 - High (7.8)

Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute arbitrary code by embedding a crafted \href value with a TAB byte in the URL scheme, causing filterU...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2015-5477
(7.5 HIGH)

EPSS: 91.28%

updated 2026-10-08T18:17:11.250000

5 posts

named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.

8 repos

https://github.com/knqyf263/cve-2015-5477

https://github.com/xycloops123/TKEY-remote-DoS-vulnerability-exploit

https://github.com/likekabin/ShareDoc_cve-2015-5477

https://github.com/ilanyu/cve-2015-5477

https://github.com/tintinweb/pub

https://github.com/elceef/tkeypoc

https://github.com/hmlio/vaas-cve-2015-5477

https://github.com/robertdavidgraham/cve-2015-5477

ninjaintelgroup@mastodon.social at 2026-10-08T19:15:19.000Z ##

🚨 NEW on CISA KEV — exploited in the wild

🛡 ISC BIND
ISC BIND Data Processing Errors Vulnerability
CVE: CVE-2015-5477 · patch by 2026-10-11

ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries.

🔗 ninjasignal.ninja/intel/cve/CV
#cybersecurity #KEV #CVE #infosec

##

secdb at 2026-10-08T19:00:11.504Z ##

🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3306 (secdb.nttzen.cloud/cve/detail/)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: proftpd.org/ ; lists.debian.org/debian-securi ; lists.opensuse.org/archives/li ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5477 (secdb.nttzen.cloud/cve/detail/)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: web.archive.org/web/2015072901 ; access.redhat.com/errata/RHSA-; supportportal.juniper.net/s/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2016-3081 (secdb.nttzen.cloud/cve/detail/)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: cwiki.apache.org/confluence/di ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-3199 (secdb.nttzen.cloud/cve/detail/)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; github.com/ONLYOFFICE/Document ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2023-22894 (secdb.nttzen.cloud/cve/detail/)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: strapi.io/blog/security-disclo ; github.com/strapi/strapi/relea ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-10-08T18:00:57.000Z ##

CVE ID: CVE-2015-5477
Vendor: ISC
Product: BIND
Date Added: 2026-10-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-10-08T19:00:11.000Z ##

🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3306 (secdb.nttzen.cloud/cve/detail/)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: proftpd.org/ ; lists.debian.org/debian-securi ; lists.opensuse.org/archives/li ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5477 (secdb.nttzen.cloud/cve/detail/)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: web.archive.org/web/2015072901 ; access.redhat.com/errata/RHSA-; supportportal.juniper.net/s/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2016-3081 (secdb.nttzen.cloud/cve/detail/)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: cwiki.apache.org/confluence/di ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-3199 (secdb.nttzen.cloud/cve/detail/)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; github.com/ONLYOFFICE/Document ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2023-22894 (secdb.nttzen.cloud/cve/detail/)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: strapi.io/blog/security-disclo ; github.com/strapi/strapi/relea ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261008 #cisa20261008 #cve_2015_3306 #cve_2015_5477 #cve_2016_3081 #cve_2021_3199 #cve_2023_22894 #cve20153306 #cve20155477 #cve20163081 #cve20213199 #cve202322894

##

cisakevtracker@mastodon.social at 2026-10-08T18:00:57.000Z ##

CVE ID: CVE-2015-5477
Vendor: ISC
Product: BIND
Date Added: 2026-10-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-107377
(7.5 HIGH)

EPSS: 0.00%

updated 2026-10-08T17:58:02

2 posts

## Summary When processing an attacker-controlled Protobuf schema, vulnerable versions of `datamodel-code-generator` could write a generated weak-import stub outside the intended `__weak_imports__` temporary directory. Absolute import paths and relative paths containing `..` could escape this directory. An attacker could create directories and new files at locations writable by the process. Rela

thehackerwire@mastodon.social at 2026-10-08T18:30:33.000Z ##

🟠 CVE-2026-107377 - High (7.5)

datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.81.0, an attacker-controlled Protobuf schema can supply absolute or parent-directory paths captured by WEAK_IMPORT_PATTERN and consumed by _write_mi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-08T18:30:33.000Z ##

🟠 CVE-2026-107377 - High (7.5)

datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.81.0, an attacker-controlled Protobuf schema can supply absolute or parent-directory paths captured by WEAK_IMPORT_PATTERN and consumed by _write_mi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-106446
(9.8 CRITICAL)

EPSS: 0.64%

updated 2026-10-08T17:52:34

1 posts

## Summary `Handlebars.compile()` and `Handlebars.precompile()` accept a pre-parsed AST as well as a template string. Handlebars 4.7.9 added validation for such ASTs. It only checks values on `PathExpression`, `NumberLiteral` and `BooleanLiteral` nodes, and the compiler still writes several other AST values into the generated JavaScript unchecked. If an application passes an untrusted object to

CVE-2026-107375
(8.8 HIGH)

EPSS: 0.00%

updated 2026-10-08T17:40:37

2 posts

# SQL Injection in the `sort` Parameter of JHipster-Generated Reactive (WebFlux + R2DBC) Applications - **Product**: jhipster/generator-jhipster (npm package `generator-jhipster`) - **Affected versions**: v7.0.0 through v9.2.0 - **Component**: generated reactive-application code, template `EntityManager_reactive.java.ejs` - **Report date**: 2026-08-29 --- ## 1. Summary Every reactive (Spring

thehackerwire@mastodon.social at 2026-10-08T18:30:43.000Z ##

🟠 CVE-2026-107375 - High (8.8)

JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures. From 7.0.0 until 9.4.0, reactive applications generated with Spring WebFlux, Spring Data R2DBC, and a SQL database ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-08T18:30:43.000Z ##

🟠 CVE-2026-107375 - High (8.8)

JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures. From 7.0.0 until 9.4.0, reactive applications generated with Spring WebFlux, Spring Data R2DBC, and a SQL database ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107352
(7.7 HIGH)

EPSS: 0.20%

updated 2026-10-08T17:26:22.830000

1 posts

Missing authorization checks in Amazon Athena engine version 3 request handling could have allowed an authenticated user to read limited query metadata (AWS account identifiers and SQL statement text) from other AWS accounts. Query results, credentials, and Amazon S3 data were not affected. AWS remediated the issue on September 1, 2026, and has confirmed no customer metadata was accessed. No custo

thehackerwire@mastodon.social at 2026-10-07T21:31:18.000Z ##

🟠 CVE-2026-107352 - High (7.7)

Missing authorization checks in Amazon Athena engine version 3 request handling could have allowed an authenticated user to read limited query metadata (AWS account identifiers and SQL statement text) from other AWS accounts. Query results, creden...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71895
(7.1 HIGH)

EPSS: 0.17%

updated 2026-10-08T17:25:38.450000

1 posts

An authorization vulnerability in Apache DolphinScheduler allows authenticated non-admin users to retrieve Kubernetes configuration data intended for administrator-managed cluster configuration. The exposed kubeconfig data contains credentials that may allow users to authenticate directly to the Kubernetes API outside DolphinScheduler. The impact depends on the permissions granted to the disclo

CVE-2026-71896
(6.5 MEDIUM)

EPSS: 0.16%

updated 2026-10-08T17:25:38.450000

1 posts

An authorization vulnerability in Apache DolphinScheduler allows authenticated users to retrieve other users' account information through the /dolphinscheduler/users/list-all endpoint without the required permissions. The endpoint fails to enforce the necessary authorization checks before returning user account information. As a result, an authenticated user can access account information they

CVE-2026-95534
(8.8 HIGH)

EPSS: 0.29%

updated 2026-10-08T17:24:31.040000

1 posts

Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Object Injection. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.19.

thehackerwire@mastodon.social at 2026-10-07T17:20:55.000Z ##

🟠 CVE-2026-95534 - High (8.8)

Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Object Injection.

This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105436
(8.8 HIGH)

EPSS: 0.00%

updated 2026-10-08T17:24:11.230000

2 posts

Deserialization of Untrusted Data vulnerability in MainWP MainWP Child mainwp-child allows Object Injection.This issue affects MainWP Child: from n/a through 6.2.1.

thehackerwire@mastodon.social at 2026-10-08T17:30:39.000Z ##

🟠 CVE-2026-105436 - High (8.8)

Deserialization of Untrusted Data vulnerability in MainWP MainWP Child mainwp-child allows Object Injection.This issue affects MainWP Child: from n/a through 6.2.1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-08T17:30:39.000Z ##

🟠 CVE-2026-105436 - High (8.8)

Deserialization of Untrusted Data vulnerability in MainWP MainWP Child mainwp-child allows Object Injection.This issue affects MainWP Child: from n/a through 6.2.1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105110
(9.8 CRITICAL)

EPSS: 2.79%

updated 2026-10-08T17:17:12

1 posts

OS Command Injection in the login.xgi CGI endpoint in Iskratel Innbox GPON ONT devices allows an unauthenticated remote attacker to execute arbitrary commands as root via the CLI parameter.

offseq@infosec.exchange at 2026-10-08T12:00:26.000Z ##

CVE-2026-105110 (CRITICAL, CVSS 9.8): Iskratel Innbox GPON ONT devices have an OS command injection flaw in login.xgi. Remote, unauthenticated code execution as root possible. Restrict access & monitor until patch. radar.offseq.com/threat/cve-20 #OffSeq #infosec #zeroday #vuln

##

CVE-2026-107295
(7.6 HIGH)

EPSS: 0.00%

updated 2026-10-08T17:16:37

2 posts

### Summary The Pydantic AI development web chat UI (`Agent.to_web()`, `clai web`) did not check the content type of requests to its chat endpoint. This allowed a website visited by a developer to submit a request to a chat UI running on that developer's machine, causing the served agent to run and to execute its tools with the privileges and credentials of the local process. Binding the web UI

thehackerwire@mastodon.social at 2026-10-08T17:30:30.000Z ##

🟠 CVE-2026-107295 - High (7.6)

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 1.107.4 and 2.28.0, the Agent.to_web() and clai web development chat endpoint has missing request content-type validation. A webs...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-08T17:30:30.000Z ##

🟠 CVE-2026-107295 - High (7.6)

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 1.107.4 and 2.28.0, the Agent.to_web() and clai web development chat endpoint has missing request content-type validation. A webs...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107215
(7.5 HIGH)

EPSS: 0.22%

updated 2026-10-08T16:31:27

1 posts

### Summary `extractPart` allocates directly from the mscfb directory-entry size with no clamping (`crypt.go:198`, same missing bound at `crypt.go:204`): ```go buf := make([]byte, entry.Size) ``` `entry.Size` is the raw `streamSize` field from the attacker-controlled CFB directory entry (mscfb v1.0.8 `fixFile`, `file.go:109-120`: full uint64 → int64 for major version 4, low uint32 for v3). mscf

thehackerwire@mastodon.social at 2026-10-07T18:31:02.000Z ##

🟠 CVE-2026-107215 - High (7.5)

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, extractPart allocates a byte slice directly from an attacker-controlled CFB directory-entry size before validating the sector chain or si...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107216
(7.5 HIGH)

EPSS: 0.31%

updated 2026-10-08T16:31:23

1 posts

### Summary `ANCHORARRAY` (calc.go:15137 on current master) evaluates each cell of the referenced spill range by calling the **exported** `CalcCellValue`, which unconditionally constructs a fresh `calcContext` — fresh entry marker, fresh iterations map, full `MaxCalcIterations` budget (calc.go:896-900). The circular-reference control only exists **within one context**: the entry-exclusion marker

thehackerwire@mastodon.social at 2026-10-07T19:00:45.000Z ##

🟠 CVE-2026-107216 - High (7.5)

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.1 to 2.11.0, ANCHORARRAY recursively calls the exported CalcCellValue function, creating a fresh calculation context at each cycle and bypassing in-fl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76472
(8.8 HIGH)

EPSS: 0.12%

updated 2026-10-08T16:17:43.130000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-76472 are related to issues with improper neutralization of special elemen

thehackerwire@mastodon.social at 2026-10-07T18:17:11.000Z ##

🟠 CVE-2026-76472 - High (8.8)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multipl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76458
(8.6 HIGH)

EPSS: 0.28%

updated 2026-10-08T16:17:42.737000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76458 are related to improper handling of exceptional conditions issues

thehackerwire@mastodon.social at 2026-10-07T19:46:24.000Z ##

🟠 CVE-2026-76458 - High (8.6)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16340
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-08T15:33:05

2 posts

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write in the RFC2047 encoded-word parser.

DailyCyberSecurity@infosec.exchange at 2026-10-08T14:43:26.000Z ##

IBM fixes 23 IBM DataPower Gateway vulnerabilities, including critical RCE flaws CVE-2026-15762 and CVE-2026-16340. Upgrade to 11.0.0.3 now.

#IBM #DataPower #APIGateway #CVE202615762 #CVE202616340 #CVE202614990 #RCE #Vulnerability

securityonline.info/ibm-datapo

##

offseq@infosec.exchange at 2026-10-08T13:30:12.000Z ##

CVE-2026-16340 (CRITICAL, CVSS 9.8): IBM DataPower Gateway 10.5.0.0 – 10.5.0.22, 10.6.0.0 – 10.6.0.10, 10.6.1 – 10.6.6, 11.0.0.0 – 11.0.0.2 vulnerable to remote code execution via out-of-bounds write. Patch priority high. radar.offseq.com/threat/cve-20 #OffSeq #IBM #Vuln #Cybersecurity

##

CVE-2026-93017
(7.7 HIGH)

EPSS: 0.00%

updated 2026-10-08T15:17:56.950000

2 posts

The `insights-operator-gather` ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or resourceNames restriction — therefore, access to every secret in every namespace in the cluster. Ref: https://github.com/openshift/insights-operator/blob/8f15e3157ff09f54ab22801f5b21da35a195cc6d/manifests/03-clusterrole.yaml#L368-L373 ``` - apiGroups:

thehackerwire@mastodon.social at 2026-10-08T19:46:54.000Z ##

🟠 CVE-2026-93017 - High (7.7)

The `insights-operator-gather` ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or resourceNames restriction — therefore, access to every secret in every namespace in the cluster.

...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-08T19:46:54.000Z ##

🟠 CVE-2026-93017 - High (7.7)

The `insights-operator-gather` ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or resourceNames restriction — therefore, access to every secret in every namespace in the cluster.

...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107510
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-10-08T15:17:43.183000

1 posts

An authenticated high privilege user can inject arguments in troubleshooting commands resulting in privilege escalation.

offseq@infosec.exchange at 2026-10-08T10:30:26.000Z ##

CVE-2026-107510: CRITICAL vuln in Infoblox NIOS 9.0.x – 9.1.0. Auth'd high-priv users can escalate privileges via argument injection. Restrict admin access & watch for vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #Infosec #CVE2026107510

##

CVE-2026-76485
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-10-08T13:17:19.953000

3 posts

A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a Denial-of-Service (DoS) on an affected device. This vulnerability is due to improper input validation of IP traffic when the NGOAM feature is enabled. An attacker c

offseq@infosec.exchange at 2026-10-08T01:30:25.000Z ##

CVE-2026-76485: CRITICAL (CVSS 9.8) vulnerability in Cisco NX-OS NGOAM allows remote code execution or DoS via crafted packets. Disable NGOAM if unused. Awaiting official patch. Details: radar.offseq.com/threat/a-vuln #OffSeq #Cisco #CVE202676485 #Infosec

##

thehackerwire@mastodon.social at 2026-10-07T17:22:20.000Z ##

🔴 CVE-2026-76485 - Critical (9.8)

A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a Denial-of-Serv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-10-07T17:18:30.000Z ##

Four critical Cisco Nexus vulnerabilities, including CVE-2026-76485 and CVE-2026-76465 (CVSS 9.8), allow root RCE on NX-OS switches. Patch now.

#Cisco #Nexus #NXOS #CVE202676485 #CVE202676465 #RCE #NetworkSecurity #Vulnerability

securityonline.info/cisco-nexu

##

CVE-2026-106197
(9.6 CRITICAL)

EPSS: 0.40%

updated 2026-10-08T13:03:34.193000

1 posts

Use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-12260(CVSS UNKNOWN)

EPSS: 0.23%

updated 2026-10-08T09:32:03

1 posts

SQL injection in the NetBoard CRM demo platform; specifically, the vulnerable component is the ‘user-name’ POST parameter in the ‘/module/auth/recovery.php’ endpoint. The parameter is vulnerable to blind attacks based on Boolean, error, time-based and UNION techniques. Exploitation allows attackers to extract confidential information (such as the version and type of backend used), alter data or fu

offseq@infosec.exchange at 2026-10-08T09:00:27.000Z ##

CVE-2026-12260: CRITICAL SQL injection in NetBoard CRM Demo (user-name param in /module/auth/recovery.php). Exploitable via multiple SQLi techniques — data theft or CRM compromise possible. Mitigation needed now. radar.offseq.com/threat/cve-20 #OffSeq #SQLi #NetBoardCRM #CVE202612260

##

CVE-2026-107459
(9.8 CRITICAL)

EPSS: 1.47%

updated 2026-10-08T06:31:28

1 posts

The SecuShare Pro developed by Openfind has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.

offseq@infosec.exchange at 2026-10-08T07:30:25.000Z ##

Openfind SecuShare Pro v4 is affected by CVE-2026-107459 (CRITICAL, CVSS 9.3) — unauthenticated OS command injection allows remote code execution. No patch yet; restrict access and monitor activity. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Vuln

##

CVE-2026-17609
(9.1 CRITICAL)

EPSS: 0.31%

updated 2026-10-08T06:31:27

1 posts

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 6.3.316 via the submit_form function. This is due to insufficient validation of attacker-controlled JSON field declarations against the actual form schema, combined with a non-effective ABSPATH guard that dirname() trivially bypasses by stripping the t

offseq@infosec.exchange at 2026-10-08T06:00:26.000Z ##

CRITICAL: CVE-2026-17609 in Super Forms – Drag & Drop Form Builder (<=6.3.316) lets unauthenticated attackers recursively delete server directories if 'Delete files after form submissions' is enabled. Disable it! radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #Infosec

##

CVE-2026-79806
(7.8 HIGH)

EPSS: 0.10%

updated 2026-10-08T04:17:50.280000

1 posts

A privilege escalation vulnerability in the ClearPass Policy Manager OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges. A successful exploit allows a malicious user to escalate to root privileges on the affected Linux client.

thehackerwire@mastodon.social at 2026-10-06T20:30:57.000Z ##

🟠 CVE-2026-79806 - High (7.8)

A privilege escalation vulnerability in the ClearPass Policy Manager OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges. A successful exploit allows a malicious user to escalate to root privileges ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79803
(8.8 HIGH)

EPSS: 0.80%

updated 2026-10-08T04:17:49.827000

1 posts

A command injection vulnerability exists in the API of ClearPass Policy Manager. Successful exploitation could allow an authenticated remote attacker to escalate privileges and gain administrative control of the affected system.

thehackerwire@mastodon.social at 2026-10-06T21:01:30.000Z ##

🟠 CVE-2026-79803 - High (8.8)

A command injection vulnerability exists in the API of ClearPass Policy Manager. Successful exploitation could allow an authenticated remote attacker to escalate privileges and gain administrative control of the affected system.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79800
(8.8 HIGH)

EPSS: 0.62%

updated 2026-10-08T04:17:43.710000

1 posts

An authenticated path traversal vulnerability exists in the command line interface of ClearPass Policy Manager. Successful exploitation could allow a low-privileged authenticated remote attacker to execute arbitrary code with elevated privileges on the underlying operating system.

thehackerwire@mastodon.social at 2026-10-06T20:46:00.000Z ##

🟠 CVE-2026-79800 - High (8.8)

An authenticated path traversal vulnerability exists in the command line interface of ClearPass Policy Manager. Successful exploitation could allow a low-privileged authenticated remote attacker to execute arbitrary code with elevated privileges o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79798
(9.9 CRITICAL)

EPSS: 0.34%

updated 2026-10-08T04:17:43.317000

1 posts

SQL injection vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow a low-privileged authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands.

thehackerwire@mastodon.social at 2026-10-06T20:45:42.000Z ##

🔴 CVE-2026-79798 - Critical (9.9)

SQL injection vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow a low-privileged authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful e...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79796
(9.8 CRITICAL)

EPSS: 0.46%

updated 2026-10-08T04:17:42.980000

1 posts

Vulnerabilities have been identified in the affected interface of ClearPass Policy Manager that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain unauthorized access to the affected system.

thehackerwire@mastodon.social at 2026-10-06T20:31:54.000Z ##

🔴 CVE-2026-79796 - Critical (9.8)

Vulnerabilities have been identified in the affected interface of ClearPass Policy Manager that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76480
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-10-08T04:17:34.733000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-202

thehackerwire@mastodon.social at 2026-10-07T18:17:20.000Z ##

🔴 CVE-2026-76480 - Critical (9.8)

As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76471
(9.8 CRITICAL)

EPSS: 0.52%

updated 2026-10-08T04:17:34.533000

3 posts

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device.&nbsp; The vulnerability is due to insufficient input validation of data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP r

AAKL@infosec.exchange at 2026-10-08T15:52:31.000Z ##

Two more Cisco advisories today addressing critical vulnerabilities:

- CVE-2026-76471: Cisco NX-OS Software NX-API Remote Code Execution Vulnerability sec.cloudapps.cisco.com/securi

- CVE-2026-76463, CVE-2026-76464, and CVE-2026-76467: Cisco Meraki Security Hardening Release: October 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #Cisco #vulnerability

##

thehackerwire@mastodon.social at 2026-10-07T18:16:02.000Z ##

🔴 CVE-2026-76471 - Critical (9.8)

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device.&nbsp;

The vulnerabi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-10-07T17:26:58.000Z ##

Cisco NX-OS vulnerabilities fixed, including critical NX-API RCE flaw CVE-2026-76471 and CVE-2026-76455, across Nexus, MDS and UCS gear. Patch now.

#Cisco #NXOS #Nexus #CVE202676471 #CVE202676455 #RCE #NetworkSecurity #Vulnerability

securityonline.info/cisco-nx-o

##

CVE-2026-76465
(9.8 CRITICAL)

EPSS: 0.45%

updated 2026-10-08T04:17:34.377000

3 posts

A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute arbitrary code with&nbsp;root privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper validati

offseq@infosec.exchange at 2026-10-08T03:00:24.000Z ##

CVE-2026-76465 (CRITICAL, CVSS 9.8) in Cisco NX-OS for Nexus 3000/9000: Remote, unauthenticated attackers can gain root or cause DoS via crafted MPLS echo-requests. Patch status unknown — check Cisco advisories. radar.offseq.com/threat/a-vuln #OffSeq #Cisco #Vulnerability #CVE202676465

##

thehackerwire@mastodon.social at 2026-10-07T19:02:10.000Z ##

🔴 CVE-2026-76465 - Critical (9.8)

A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute arbit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-10-07T17:18:30.000Z ##

Four critical Cisco Nexus vulnerabilities, including CVE-2026-76485 and CVE-2026-76465 (CVSS 9.8), allow root RCE on NX-OS switches. Patch now.

#Cisco #Nexus #NXOS #CVE202676485 #CVE202676465 #RCE #NetworkSecurity #Vulnerability

securityonline.info/cisco-nexu

##

CVE-2026-19386
(0 None)

EPSS: 0.19%

updated 2026-10-08T04:17:19.810000

1 posts

A stack-based buffer overflow in the ASUS router modules allows an authenticated nearby user to execute arbitrary code via a crafted configuration file upload that exceeds the expected buffer size.Refer to the ' Security Update for ASUS Router Firmware  ' section on the ASUS Security Advisory for more information.

CVE-2026-76281(CVSS UNKNOWN)

EPSS: 0.15%

updated 2026-10-07T21:33:38

1 posts

Improper Access Control. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information.

CVE-2026-76268
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-10-07T21:33:30

2 posts

In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with network access to the Patroni Representational State Transfer (REST) Application Programming Interface (API) on a search head cluster member could execute attacker-controlled operating-system commands. The vulnerability is possible because this interface does not require authentication for critical configuration op

DailyCyberSecurity@infosec.exchange at 2026-10-08T01:56:26.000Z ##

Splunk fixes 22 Splunk Enterprise vulnerabilities, including critical Patroni API flaw CVE-2026-76268 and CVE-2026-76281. Upgrade to 10.4.3 now.

#Splunk #SplunkEnterprise #SIEM #CVE202676268 #CVE202676281 #RCE #PatchNow #Vulnerability

securityonline.info/splunk-ent

##

thehackerwire@mastodon.social at 2026-10-07T21:31:08.000Z ##

🔴 CVE-2026-76268 - Critical (9.8)

In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with network access to the Patroni Representational State Transfer (REST) Application Programming Interface (API) on a search head cluster member could execute attacker...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76266
(7.7 HIGH)

EPSS: 0.12%

updated 2026-10-07T21:33:30

1 posts

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15 on Linux, a local user who can run commands as the user account running Splunk Enterprise could cause an affected Linux package upgrade to run attacker-controlled operating-system commands with root privileges. The vulnerability is possible because the Linux package maintainer script trusts existing Splunk Enterprise installat

thehackerwire@mastodon.social at 2026-10-07T21:30:58.000Z ##

🟠 CVE-2026-76266 - High (7.7)

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15 on Linux, a local user who can run commands as the user account running Splunk Enterprise could cause an affected Linux package upgrade to run attacker-controlled operating-sy...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79802
(8.8 HIGH)

EPSS: 1.19%

updated 2026-10-07T21:33:24

1 posts

A command injection vulnerability exists in the client software of ClearPass Policy Manager. Successful exploitation could allow an attacker who is able to supply crafted input to the affected software to execute arbitrary commands with elevated privileges on the affected host.

thehackerwire@mastodon.social at 2026-10-06T21:01:20.000Z ##

🟠 CVE-2026-79802 - High (8.8)

A command injection vulnerability exists in the client software of ClearPass Policy Manager. Successful exploitation could allow an attacker who is able to supply crafted input to the affected software to execute arbitrary commands with elevated p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79801
(9.8 CRITICAL)

EPSS: 0.32%

updated 2026-10-07T21:33:24

1 posts

A missing integrity verification vulnerability in the client agent software of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to introduce untrusted code. Successful exploitation could allow an attacker to execute arbitrary code on the affected client system.

thehackerwire@mastodon.social at 2026-10-06T21:01:11.000Z ##

🔴 CVE-2026-79801 - Critical (9.8)

A missing integrity verification vulnerability in the client agent software of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to introduce untrusted code. Successful exploitation could allow an attacker to e...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79799
(8.8 HIGH)

EPSS: 0.33%

updated 2026-10-07T21:33:24

1 posts

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.

thehackerwire@mastodon.social at 2026-10-06T20:45:51.000Z ##

🟠 CVE-2026-79799 - High (8.8)

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful ex...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79797
(8.8 HIGH)

EPSS: 0.27%

updated 2026-10-07T21:33:24

1 posts

An improper access control vulnerability exists in the Android client application for HPE Networking ClearPass Policy Manager, where application functionality may be invoked by untrusted sources. Successful exploitation could allow an unauthenticated remote attacker, with user interaction, to obtain sensitive information from the affected user.

thehackerwire@mastodon.social at 2026-10-06T20:32:03.000Z ##

🟠 CVE-2026-79797 - High (8.8)

An improper access control vulnerability exists in the Android client application for HPE Networking ClearPass Policy Manager, where application functionality may be invoked by untrusted sources. Successful exploitation could allow an unauthentica...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79808
(7.8 HIGH)

EPSS: 0.11%

updated 2026-10-07T21:33:24

1 posts

A buffer overflow vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow an authenticated local user to execute arbitrary code with elevated privileges on the affected host or to disrupt the availability of the affected service.

thehackerwire@mastodon.social at 2026-10-06T20:31:45.000Z ##

🟠 CVE-2026-79808 - High (7.8)

A buffer overflow vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow an authenticated local user to execute arbitrary code with elevated privileges on the affected host or to disrupt the avai...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79807
(7.8 HIGH)

EPSS: 0.08%

updated 2026-10-07T21:33:24

1 posts

A missing integrity verification vulnerability in the Windows client software for ClearPass Policy Manager could allow malicious users on a local instance to elevate their user privileges. A successful exploit could allow these users to execute attacker-supplied code with elevated privileges on the local system.

thehackerwire@mastodon.social at 2026-10-06T20:31:06.000Z ##

🟠 CVE-2026-79807 - High (7.8)

A missing integrity verification vulnerability in the Windows client software for ClearPass Policy Manager could allow malicious users on a local instance to elevate their user privileges. A successful exploit could allow these users to execute at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79805
(9.8 CRITICAL)

EPSS: 0.43%

updated 2026-10-07T21:33:24

1 posts

An authenticated path traversal vulnerability exists in ClearPass Policy Manager. Successful exploitation could allow an attacker to read and modify certain files on the underlying operating system.

thehackerwire@mastodon.social at 2026-10-06T20:30:48.000Z ##

🔴 CVE-2026-79805 - Critical (9.8)

An authenticated path traversal vulnerability exists in ClearPass Policy Manager. Successful exploitation could allow an attacker to read and modify certain files on the underlying operating system.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76744
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-10-07T21:33:23

1 posts

Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code.

CVE-2026-76750
(9.8 CRITICAL)

EPSS: 0.54%

updated 2026-10-07T21:33:23

1 posts

Deserialization of untrusted data vulnerabilities exist in the web interface of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code on the affected system.

CVE-2026-105857
(10.0 CRITICAL)

EPSS: 0.43%

updated 2026-10-07T20:28:48

1 posts

## Impact A vulnerability in `@payloadcms/plugin-form-builder` in versions < 3.90.0 allow submissions which could be crafted to execute remote code on the server. **You are affected if:** - You are using `@payloadcms/plugin-form-builder` ## Patches Users should upgrade Payload packages to `>= 3.90.0` or `>= 4.0.0-canary.34`.

thehackerwire@mastodon.social at 2026-10-06T17:30:51.000Z ##

🔴 CVE-2026-105857 - Critical (10)

Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can craft a form submission that executes code remotely on the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-106115
(7.5 HIGH)

EPSS: 0.35%

updated 2026-10-07T20:24:49

1 posts

### Summary The TIFF CCITT Group 4 (T6) encoder writes beyond its logical compressed-data buffer when encoding a 1-bit image. A valid 1×1 Group 4 TIFF decoded and re-encoded with the default `TiffEncoder` terminates the process with an unhandled exception. ### Affected package and versions - Package: `SixLabors.ImageSharp` (NuGet) - Affected range: `>= 2.1.0, <= 4.1.1` - Commit `0815358f9202a78

thehackerwire@mastodon.social at 2026-10-06T18:30:22.000Z ##

🟠 CVE-2026-106115 - High (7.5)

ImageSharp is a 2D graphics library. From 2.1.0 until 4.1.2, the TIFF CCITT Group 4 encoder allocates Width times rowsPerStrip bytes even though T6BitCompressor.CompressStrip can emit encoded row data and two 12-bit end-of-facsimile-block codes be...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-106112
(7.5 HIGH)

EPSS: 0.35%

updated 2026-10-07T20:24:38

1 posts

### Summary When ICC conversion is enabled, a malformed embedded ICC LUT16 profile with more than four output channels can corrupt memory during ImageSharp color conversion. The ICC parser accepts up to 15 CLUT output channels, while the conversion implementation stores intermediate values in `Vector4`. ### Affected package and versions - Package: `SixLabors.ImageSharp` (NuGet) - Affected publi

thehackerwire@mastodon.social at 2026-10-06T18:32:41.000Z ##

🟠 CVE-2026-106112 - High (7.5)

ImageSharp is a 2D graphics library. From 4.0.0 until 4.1.2, ICC LUT16 conversion accepts more than four output channels even though ClutCalculator.Calculate and LutEntryCalculator.CalculateLut store intermediate and output values in Vector4. When...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-106113
(7.5 HIGH)

EPSS: 0.35%

updated 2026-10-07T20:24:24

1 posts

### Summary `SixLabors.ImageSharp` can terminate a process when an application decodes an attacker-supplied 32-bit floating-point TIFF as `Image<HalfVector4>` and applies `HistogramEqualization()`. An IEEE positive-infinity TIFF sample reaches a non-finite or otherwise out-of-range `HalfVector4` component, depending on the release. The histogram equalization path derives a luminance-based histogr

thehackerwire@mastodon.social at 2026-10-06T18:32:50.000Z ##

🟠 CVE-2026-106113 - High (7.5)

ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit floating-point TIFF as Image and applying HistogramEqualization can produce a non-finite or out-of-range luminance in ColorNumerics.GetBT709Luminance...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107217
(7.5 HIGH)

EPSS: 0.34%

updated 2026-10-07T20:23:32

1 posts

### Summary `ColumnNameToNumber` (lib.go:220-237) accumulates the bijective base-26 value of a column name in an int64 with only an upper-bound check (`col > MaxColumns`) applied after the loop and no overflow detection. A 14-letter column name whose true value is 3·2⁶⁴ — e.g. **`VGWQHXLSDVIKWV`** — wraps to `col = 0` and passes the guard, so `CellNameToCoordinates("VGWQHXLSDVIKWV1")` returns `(c

thehackerwire@mastodon.social at 2026-10-07T19:45:50.000Z ##

🟠 CVE-2026-107217 - High (7.5)

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.0.0 to 2.11.0 in github.com/xuri/excelize/v2 and from 1.1.0 to 1.4.1 in github.com/xuri/excelize, ColumnNameToNumber accumulates a bijective base-26 val...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20362
(7.2 HIGH)

EPSS: 0.47%

updated 2026-10-07T20:17:12.390000

2 posts

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successfu

DailyCyberSecurity@infosec.exchange at 2026-10-08T02:26:40.000Z ##

A Cisco Finesse vulnerability, SSRF flaw CVE-2026-20362, has been publicly disclosed. Fixes arrive in early 2027, with no workarounds.

#Cisco #CiscoFinesse #ContactCenter #CVE202620362 #SSRF #Horizon3 #UnifiedCCX #Vulnerability

securityonline.info/cisco-fine

##

ssvc@infosec.exchange at 2026-10-07T16:17:37.000Z ##

There are 14 Cisco security advisories that came out today. sec.cloudapps.cisco.com/securi

A lot of 9.8 and even 10.0 across multiple products. While there's no mention of exploitation, there's zero-day disclosure pre-patch for Cisco Finesse Server-Side Request Forgery Vulnerability CVE-2026-20362 (7.2)

The Cisco PSIRT is aware that a public announcement is available for the vulnerability that is described in this advisory.

sec.cloudapps.cisco.com/securi

#cisco #CVE

##

CVE-2026-107219
(7.5 HIGH)

EPSS: 0.34%

updated 2026-10-07T20:17:11.450000

1 posts

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, agile decryption accepts an attacker-controlled spinCount and performs that many password-key derivation iterations before verifier validation. OpenFile reaches agileDecrypt, which passes the unbounded spinCount to convertPasswdToKey before password verification. When a crafted OLE encrypt

thehackerwire@mastodon.social at 2026-10-07T19:45:41.000Z ##

🟠 CVE-2026-107219 - High (7.5)

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, agile decryption accepts an attacker-controlled spinCount and performs that many password-key derivation iterations before verifier valid...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107214
(7.5 HIGH)

EPSS: 0.27%

updated 2026-10-07T20:17:11.320000

1 posts

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, the decryption dispatch performs insufficient structural and parameter validation before standard and agile decryptors slice, index, allocate, and divide using attacker-controlled values. Decrypt passes attacker-controlled EncryptionInfo and EncryptedPackage data into standardDecrypt or ag

thehackerwire@mastodon.social at 2026-10-07T18:30:53.000Z ##

🟠 CVE-2026-107214 - High (7.5)

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, the decryption dispatch performs insufficient structural and parameter validation before standard and agile decryptors slice, index, allo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107161
(7.5 HIGH)

EPSS: 0.24%

updated 2026-10-07T20:17:10.977000

1 posts

A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-

thehackerwire@mastodon.social at 2026-10-07T20:45:34.000Z ##

🟠 CVE-2026-107161 - High (7.5)

A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76498
(9.8 CRITICAL)

EPSS: 0.30%

updated 2026-10-07T19:17:41.153000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76498 are related to imprope

thehackerwire@mastodon.social at 2026-10-07T17:31:00.000Z ##

🔴 CVE-2026-76498 - Critical (9.8)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in softwar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76470
(8.8 HIGH)

EPSS: 0.18%

updated 2026-10-07T19:17:40.830000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76470 are related to incorrect calculation issues that are grouped

thehackerwire@mastodon.social at 2026-10-07T18:15:52.000Z ##

🟠 CVE-2026-76470 - High (8.8)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses mult...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76456
(8.6 HIGH)

EPSS: 0.28%

updated 2026-10-07T19:17:40.127000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76456 are related to improper input validation of special elements used

thehackerwire@mastodon.social at 2026-10-07T20:45:56.000Z ##

🟠 CVE-2026-76456 - High (8.6)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14911
(0 None)

EPSS: 0.32%

updated 2026-10-07T19:17:35.867000

2 posts

Improper Neutralization of Input During Web Page Generation (“Cross-site Scripting”) in ASUS router modules allows a remote attacker to read DOM information, modify router settings, and cause a denial-of-service condition when an authenticated user visits a crafted URL.Refer to the ' Security Update for ASUS Router Firmware  ' section on the ASUS Security Advisory for more information.

offseq@infosec.exchange at 2026-10-07T06:00:24.000Z ##

ASUS Router XSS (CVE-2026-14911, CRITICAL, CVSS 9.3): Remote attackers can exploit improper input neutralization to execute scripts, alter settings, or cause DoS if visited by authenticated users. No patch yet. Details: radar.offseq.com/threat/cve-20 #OffSeq #XSS #Cybersecurity

##

DailyCyberSecurity@infosec.exchange at 2026-10-07T03:06:10.000Z ##

Four ASUS router vulnerabilities are fixed, including critical XSS flaw CVE-2026-14911 and code execution bug CVE-2026-19386. Update firmware now.

#ASUS #ASUSRouter #RouterSecurity #CVE202614911 #CVE202619386 #XSS #FirmwareUpdate #Vulnerability

securityonline.info/asus-route

##

CVE-2026-107104
(0 None)

EPSS: 0.42%

updated 2026-10-07T19:17:33.483000

1 posts

This vulnerability exists in the ERP system due to unsafe deserialization of user controlled data in the affected functionality. An unauthenticated remote attacker could exploit this vulnerability by supplying specially crafted data to the vulnerable functionality of the targeted system. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code, manipulate

offseq@infosec.exchange at 2026-10-07T09:00:24.000Z ##

Manacle Technologies Multi-tenant ERP System hit by CVE-2026-107104 (CRITICAL, CVSS 9.3): Unsafe deserialization lets unauthenticated attackers execute code remotely. No fix yet — restrict access & monitor systems. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026107104 #ERP #infosec

##

CVE-2026-102255
(10.0 CRITICAL)

EPSS: 0.48%

updated 2026-10-07T18:33:12

5 posts

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.

beyondmachines1@infosec.exchange at 2026-10-08T14:01:49.000Z ##

SonicWall Patches Critical Pre-Auth SSRF in SMA 1000 Series Appliances

SonicWall patched four vulnerabilities in its SMA 1000 series appliances, including a critical pre-authentication SSRF (CVE-2026-102255) with a CVSS score of 10.0. The flaws allow unauthenticated attackers to access internal services and authenticated users to execute arbitrary code.

**If you use SonicWall SMA 1000 series appliances (SMA 6210, SMA 7210 or SMA 8200v), update them ASAP to firmware 12.4.3-03670 or 12.5.0-03082 or newer. Make sure the management console is reachable only from trusted internal networks, and check the appliance logs for unusual activity, since these gateways are a favorite entry point for ransomware groups.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

censys@infosec.exchange at 2026-10-07T21:02:33.000Z ##

🚨 Rapid Response: SonicWall has patched a critical CVSS 10.0 pre-authentication SSRF in SMA1000 appliances (CVE-2026-102255).

Censys detects 5,966 Internet-exposed hosts and 39,310 web properties running SMA1000/Secure Mobile Access after excluding honeypot-labeled systems. This indicates product presence, not confirmed-vulnerable systems.

Full Censys ARC advisory: censys.com/advisory/cve-2026-1

#CensysARC #SonicWall #Vulnerability #CyberSecurity

##

ifin@infosec.exchange at 2026-10-07T18:39:28.000Z ##

Chat, is it bad if your zero-trust VPN device forwards network requests without auth? Asking for thousands of friends.

SonicWall SMA1000 devices have a SSRF vulnerability that needs patching.

ifin.network/t/cve-2026-102255

#IFIN #ThreatIntel #ThreatIntelligence

##

jbhall56@infosec.exchange at 2026-10-07T12:56:31.000Z ##

Tracked as CVE-2026-102255, the vulnerability was found in the Appliance WorkPlace interface of SMA1000 6210, 7210, and 8200v models, but it does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls. bleepingcomputer.com/news/secu

##

ssvc@infosec.exchange at 2026-10-06T19:40:03.000Z ##

new SonicWall SMA1000 advisory. Check out CVE-2026-102255 (10.0 critical) Pre-authentication SSRF via unintended forward-proxy. No mention of exploitation, but it's not a good look that your Secure Mobile Access is not secure (including four known exploited vulnerabilities in the past 90 days)

psirt.global.sonicwall.com/vul

#sonicwall #sma1000 #cve

##

CVE-2026-95606
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-10-07T18:32:21

2 posts

Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Events Calendar allows Object Injection. This issue affects The Events Calendar: from n/a through 6.17.4.

offseq@infosec.exchange at 2026-10-08T00:00:35.000Z ##

CVE-2026-95606: CRITICAL deserialization of untrusted data in The Events Calendar (<=6.17.4) enables remote object injection & code execution. No patch confirmed — review vendor advisory. radar.offseq.com/threat/deseri #OffSeq #WordPress #Vulnerability #CVE202695606

##

thehackerwire@mastodon.social at 2026-10-07T17:20:46.000Z ##

🔴 CVE-2026-95606 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Events Calendar allows Object Injection.

This issue affects The Events Calendar: from n/a through 6.17.4.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76453
(8.8 HIGH)

EPSS: 0.34%

updated 2026-10-07T18:32:21

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76453 are related to improper neutralization issues that are grouped unde

thehackerwire@mastodon.social at 2026-10-07T20:15:40.000Z ##

🟠 CVE-2026-76453 - High (8.8)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76457
(8.6 HIGH)

EPSS: 0.28%

updated 2026-10-07T18:32:21

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76457 are related to out-of-bounds read issues that are grouped under the

thehackerwire@mastodon.social at 2026-10-07T19:16:13.000Z ##

🟠 CVE-2026-76457 - High (8.6)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76483
(9.1 CRITICAL)

EPSS: 0.22%

updated 2026-10-07T18:32:21

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. &nbsp; The vulnerabilities tracked by CV

thehackerwire@mastodon.social at 2026-10-07T19:01:36.000Z ##

🔴 CVE-2026-76483 - Critical (9.1)

As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-96335
(7.5 HIGH)

EPSS: 0.20%

updated 2026-10-07T18:32:21

1 posts

Missing Authorization vulnerability in WPMU DEV Forminator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Forminator: from n/a through 1.57.2.

thehackerwire@mastodon.social at 2026-10-07T18:30:42.000Z ##

🟠 CVE-2026-96335 - High (7.5)

Missing Authorization vulnerability in WPMU DEV Forminator allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects Forminator: from n/a through 1.57.2.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76499
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-10-07T18:32:21

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76499 are related to improper

thehackerwire@mastodon.social at 2026-10-07T17:31:09.000Z ##

🔴 CVE-2026-76499 - Critical (9.8)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in softwar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76486
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-10-07T18:32:21

1 posts

A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a Denial-of-Service (DoS) on an affected device. This vulnerability is due to improper input validation of IP traffic when the NGOAM feature is enabled. An attacker cou

thehackerwire@mastodon.social at 2026-10-07T17:30:50.000Z ##

🔴 CVE-2026-76486 - Critical (9.8)

A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a Denial-of-Serv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76484
(8.8 HIGH)

EPSS: 0.28%

updated 2026-10-07T18:32:21

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-

thehackerwire@mastodon.social at 2026-10-07T17:22:11.000Z ##

🟠 CVE-2026-76484 - High (8.8)

As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-95605
(9.3 CRITICAL)

EPSS: 0.25%

updated 2026-10-07T18:32:21

1 posts

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Passionate Programmer Peter WP Data Access allows Blind SQL Injection. This issue affects WP Data Access: from n/a through 5.5.82.

thehackerwire@mastodon.social at 2026-10-07T17:20:37.000Z ##

🔴 CVE-2026-95605 - Critical (9.3)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Passionate Programmer Peter WP Data Access allows Blind SQL Injection.

This issue affects WP Data Access: from n/a through 5.5.82.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76464
(9.6 CRITICAL)

EPSS: 0.19%

updated 2026-10-07T18:32:20

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by this CVE-2026-76464 are related to buffer management issues that are grouped

AAKL@infosec.exchange at 2026-10-08T15:52:31.000Z ##

Two more Cisco advisories today addressing critical vulnerabilities:

- CVE-2026-76471: Cisco NX-OS Software NX-API Remote Code Execution Vulnerability sec.cloudapps.cisco.com/securi

- CVE-2026-76463, CVE-2026-76464, and CVE-2026-76467: Cisco Meraki Security Hardening Release: October 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #Cisco #vulnerability

##

thehackerwire@mastodon.social at 2026-10-07T19:01:48.000Z ##

🔴 CVE-2026-76464 - Critical (9.6)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses mult...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76467
(7.5 HIGH)

EPSS: 0.25%

updated 2026-10-07T18:32:20

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76467 are related to issues concerning improper control of a resourc

AAKL@infosec.exchange at 2026-10-08T15:52:31.000Z ##

Two more Cisco advisories today addressing critical vulnerabilities:

- CVE-2026-76471: Cisco NX-OS Software NX-API Remote Code Execution Vulnerability sec.cloudapps.cisco.com/securi

- CVE-2026-76463, CVE-2026-76464, and CVE-2026-76467: Cisco Meraki Security Hardening Release: October 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #Cisco #vulnerability

##

thehackerwire@mastodon.social at 2026-10-07T19:15:55.000Z ##

🟠 CVE-2026-76467 - High (7.5)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses mult...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76463
(8.8 HIGH)

EPSS: 0.14%

updated 2026-10-07T18:32:20

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76463 are related to improper access control issues that are grouped

AAKL@infosec.exchange at 2026-10-08T15:52:31.000Z ##

Two more Cisco advisories today addressing critical vulnerabilities:

- CVE-2026-76471: Cisco NX-OS Software NX-API Remote Code Execution Vulnerability sec.cloudapps.cisco.com/securi

- CVE-2026-76463, CVE-2026-76464, and CVE-2026-76467: Cisco Meraki Security Hardening Release: October 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #Cisco #vulnerability

##

thehackerwire@mastodon.social at 2026-10-07T19:46:43.000Z ##

🟠 CVE-2026-76463 - High (8.8)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses mult...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76455
(9.8 CRITICAL)

EPSS: 0.28%

updated 2026-10-07T18:32:20

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76455 are related to improper access control issues that are grouped unde

thehackerwire@mastodon.social at 2026-10-07T20:16:00.000Z ##

🔴 CVE-2026-76455 - Critical (9.8)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-10-07T17:26:58.000Z ##

Cisco NX-OS vulnerabilities fixed, including critical NX-API RCE flaw CVE-2026-76471 and CVE-2026-76455, across Nexus, MDS and UCS gear. Patch now.

#Cisco #NXOS #Nexus #CVE202676471 #CVE202676455 #RCE #NetworkSecurity #Vulnerability

securityonline.info/cisco-nx-o

##

CVE-2026-76459
(8.8 HIGH)

EPSS: 0.28%

updated 2026-10-07T18:32:20

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76459 are related to out-of-bounds write issues that are grouped under th

thehackerwire@mastodon.social at 2026-10-07T19:46:33.000Z ##

🟠 CVE-2026-76459 - High (8.8)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76482
(10.0 CRITICAL)

EPSS: 0.20%

updated 2026-10-07T18:32:20

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-

thehackerwire@mastodon.social at 2026-10-07T18:17:30.000Z ##

🔴 CVE-2026-76482 - Critical (10)

As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-10-07T17:36:18.000Z ##

Cisco License On-Prem vulnerabilities include CVSS 10 flaw CVE-2026-76482 and password reset bug CVE-2026-20328. APIC and Meraki also patched.

#Cisco #SmartLicensing #APIC #Meraki #CVE202676482 #CVE202620328 #PatchNow #Vulnerability

securityonline.info/cisco-lice

##

CVE-2026-20328
(9.1 CRITICAL)

EPSS: 0.52%

updated 2026-10-07T18:32:14

2 posts

A vulnerability in the web-based management interface of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to gain unauthorized access to an affected application. This vulnerability is due to improper checks during the password reset process. An attacker could exploit this vulnerability by sending a malicious reques

thehackerwire@mastodon.social at 2026-10-07T21:16:31.000Z ##

🔴 CVE-2026-20328 - Critical (9.1)

A vulnerability in the web-based management interface of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to gain unauthorized access to an affected application.

...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-10-07T17:36:18.000Z ##

Cisco License On-Prem vulnerabilities include CVSS 10 flaw CVE-2026-76482 and password reset bug CVE-2026-20328. APIC and Meraki also patched.

#Cisco #SmartLicensing #APIC #Meraki #CVE202676482 #CVE202620328 #PatchNow #Vulnerability

securityonline.info/cisco-lice

##

CVE-2026-76500
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-10-07T18:32:14

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. &nbsp; The vulnerabilities tracked by CVE-2026-76500 are related to is

thehackerwire@mastodon.social at 2026-10-07T18:15:43.000Z ##

🔴 CVE-2026-76500 - Critical (9.8)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in softwar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76501
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-10-07T18:32:14

1 posts

A vulnerability in the Segment Routing over IPv6 (SRv6) Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) on an affected device. This vulnerability is due to improper input validation of IP traffic when the NGOAM and SRv6

thehackerwire@mastodon.social at 2026-10-07T17:22:00.000Z ##

🔴 CVE-2026-76501 - Critical (9.8)

A vulnerability in the Segment Routing over IPv6 (SRv6) Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privilege...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107206
(9.4 CRITICAL)

EPSS: 0.58%

updated 2026-10-07T18:32:14

1 posts

LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess mode HTTP server that allows remote unauthenticated attackers to access management endpoints listening on all interfaces by default. Attackers can read environment credentials via GET /env and configuration via GET /config, clear caches, delete cache objects, and modify tenant quotas to evict other tenants' c

thehackerwire@mastodon.social at 2026-10-07T16:49:47.000Z ##

🔴 CVE-2026-107206 - Critical (9.4)

LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess mode HTTP server that allows remote unauthenticated attackers to access management endpoints listening on all interfaces by default. Attackers can read envir...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107205
(8.6 HIGH)

EPSS: 0.39%

updated 2026-10-07T18:32:14

1 posts

LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess coordinator that allows remote unauthenticated attackers to access its HTTP fleet control API listening on all interfaces by default. Attackers can register or deregister instances via /instances, overwrite quotas via /quota endpoints, inject events via /events, and enumerate /directory/keys to disrupt cachin

thehackerwire@mastodon.social at 2026-10-07T16:49:38.000Z ##

🟠 CVE-2026-107205 - High (8.6)

LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess coordinator that allows remote unauthenticated attackers to access its HTTP fleet control API listening on all interfaces by default. Attackers can register ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92414(CVSS UNKNOWN)

EPSS: 0.62%

updated 2026-10-07T18:32:14

1 posts

: Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit. Jackrabbit WebDAV server attaches a cached authenticated session on any Lock-Token/TransactionId/SubscriptionId/If-header field token match with no credential check. This issue affects Apache Jackrabbit: from 2.23.0 through 2.23.5, from 2.22.0 through 2.22.4, from 2.20.0 through 2.20.17. Users ar

CVE-2026-96408
(9.4 CRITICAL)

EPSS: 0.64%

updated 2026-10-07T18:17:32.210000

1 posts

A code injection vulnerability exists in the upgrade script of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary Perl script or an SQL query on the affected product.

offseq@infosec.exchange at 2026-10-07T13:30:27.000Z ##

CVE-2026-96408 (CRITICAL): Movable Type Cloud Edition (v2.0 – 9.2.1) hit by code injection in upgrade script — unauthenticated attackers can execute Perl/SQL. No patch yet; restrict script access. radar.offseq.com/threat/cve-20 #OffSeq #CVE202696408 #infosec #vuln

##

CVE-2026-107212
(7.5 HIGH)

EPSS: 0.34%

updated 2026-10-07T18:17:18.670000

1 posts

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, Rows.Columns accepts a look-ahead row number above TotalRows without applying the limit enforced by Rows.Next. File.GetRows relies on Rows.Next and Rows.Columns, but Rows.Columns consumes the row r attribute without the limit check in Rows.Next. When a crafted worksheet places an oversized

thehackerwire@mastodon.social at 2026-10-07T19:00:55.000Z ##

🟠 CVE-2026-107212 - High (7.5)

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, Rows.Columns accepts a look-ahead row number above TotalRows without applying the limit enforced by Rows.Next. File.GetRows relies on Row...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105192
(9.8 CRITICAL)

EPSS: 0.48%

updated 2026-10-07T18:17:15.427000

3 posts

LMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and share KV cache blocks. Messages on that socket are msgpack. Extension code 1 is passed to DeviceIPCWrapper.Deserialize, which calls pickle.loads, while the server is still decoding request arguments and before the handler runs. A single unauthenticated ZMQ DEALER mes

1 repos

https://github.com/rxsklife/CVE-2026-105192

beyondmachines1@infosec.exchange at 2026-10-08T09:01:49.000Z ##

Unpatched Critical RCE Vulnerability in LMCache Exposes LLM Infrastructure to Remote Takeover

LMCache suffers from a critical unpatched vulnerability (CVE-2026-105192) that allows unauthenticated attackers to execute arbitrary code with root privileges via malicious ZeroMQ messages. The flaw stems from the unsafe use of Python's pickle library for data deserialization in the platform's multiprocess mode.

**If you run LMCache in multiprocess mode (versions 0.3.9 through 0.5.5), be aware that your system is critically vulnerable and there is no fix yet. Make sure its port is reachable only from localhost or a trusted internal network. Also update vLLM to version 0.30.0 or later, so a single bad request can't crash your AI service for everyone.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

cyberworldops@infosec.exchange at 2026-10-07T20:40:08.000Z ##

LMCache multiprocess mode is affected by CVE-2026-105192, an unauthenticated RCE via pickle deserialization over ZeroMQ, rated CVSS 9.8. Localhost binding by default limits exposure, but any reachable instance allows full process compromise. Prioritize network restriction and patching. #LmCache #RemoteCodeExecution #PickleDeserialization

cyberworldops.eu/en/lmcache-di

##

cR0w@infosec.exchange at 2026-10-07T12:50:02.000Z ##

what. the. fuck.

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.8 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

LMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and share KV cache blocks. Messages on that socket are msgpack. Extension code 1 is passed to DeviceIPCWrapper.Deserialize, which calls pickle.loads, while the server is still decoding request arguments and before the handler runs. A single unauthenticated ZMQ DEALER message to the transport port (default 5555) therefore executes code as the user the LMCache process runs as. Official container images run that process as root. The transport binds to localhost unless the operator sets a routable address with --host, which is how multi-node deployments let peers connect.

##

CVE-2026-104286
(9.8 CRITICAL)

EPSS: 2.20%

updated 2026-10-07T18:17:15.240000

1 posts

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

2 repos

https://github.com/ShadowForge-Cyber/CVE-2026-104286-POC

https://github.com/techupdate24/fortimail-zero-day-cve-2026-104286

youranonnewsirc@nerdculture.de at 2026-10-06T22:26:24.000Z ##

Recent news highlights critical cybersecurity threats as Citrix NetScaler (CVE-2026-88772) and FortiMail (CVE-2026-104286) zero-days are under active exploitation, targeting critical infrastructure and government entities. Apple also patched an exploited CoreGraphics flaw. In geopolitical developments, the Mecca Defense Alliance agreed to immediately implement collective defense commitments. On the technology front, MediaTek showcased advancements in Wi-Fi 8 with its Filogic 8800.

#Cybersecurity #AnonNews_irc #News

##

CVE-2026-106441
(7.8 HIGH)

EPSS: 0.17%

updated 2026-10-07T18:03:56

1 posts

## Summary Hydra passed its Python logging configuration to `logging.config.dictConfig()`. Python's logging configurator can resolve and invoke importable classes and factories named by configuration, including handler `class` values and formatter, filter, handler, queue, and listener `()` factories. This logging path was not mediated by Hydra's target policy. In versions that already protected

thehackerwire@mastodon.social at 2026-10-06T19:31:44.000Z ##

🟠 CVE-2026-106441 - High (7.8)

Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.6 and 1.4.0.dev9, Hydra passes Python logging configuration to logging.config.dictConfig() without applying Hydra's target policy to handler class values or formatte...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-106510
(7.7 HIGH)

EPSS: 0.44%

updated 2026-10-07T18:03:25

1 posts

### Impact An authenticated user who can register catalog entities can provide a crafted `mkdocs.yml` causing arbitrary OS command execution on the TechDocs build host when the docs are built. ### Patches Patched in `@backstage/plugin-techdocs-node`, version `1.15.4`. ### Workarounds If you cannot upgrade immediately: - Switch to `techdocs.builder: external` to isolate TechDocs builds in a c

thehackerwire@mastodon.social at 2026-10-07T17:05:36.000Z ##

🟠 CVE-2026-106510 - High (7.7)

Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by remote code execution via crafted markdown_extensions in techdocs mkdocs.yml. An authenticated user who can ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-102489
(9.8 CRITICAL)

EPSS: 1.26%

updated 2026-10-07T18:03:07.387000

1 posts

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The bug is also present in version 7.0.0 to version 7.1.2, but not exploitable due to changes in the underlying framework.

2 repos

https://github.com/horizon3ai/CVE-2026-102489

https://github.com/Hunt-Benito/the-cookie-in-the-error-message-cve-2026-102489-zammad-session-hijack-to-rce

CVE-2026-76468
(8.2 HIGH)

EPSS: 0.23%

updated 2026-10-07T17:16:59.680000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76468 are related to improper input validation that are grouped un

thehackerwire@mastodon.social at 2026-10-07T19:16:04.000Z ##

🟠 CVE-2026-76468 - High (8.2)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses mult...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76454
(9.1 CRITICAL)

EPSS: 0.58%

updated 2026-10-07T17:16:57.363000

1 posts

A vulnerability in the Cisco Smart Licensing Utility API of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to write arbitrary files to the system or cause a DoS condition on an affected application. This vulnerability is due to improper input validation and a lack of authentication in the management API. An att

thehackerwire@mastodon.social at 2026-10-07T20:15:50.000Z ##

🔴 CVE-2026-76454 - Critical (9.1)

A vulnerability in the Cisco Smart Licensing Utility API of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to write arbitrary files to the system or cause a DoS c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62253
(9.8 CRITICAL)

EPSS: 0.42%

updated 2026-10-07T17:16:56.627000

1 posts

Homer is open source telecom observability software. Prior to version 11.0.283, both JWT middleware functions (`JWTMiddleware` and `JWTMiddlewareV4`) immediately return `next(c)` when `jwtSecret == ""`. The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under `/api/v1`, `/api/v3`, and `/api/v4` are completely unauthenticated. Version 11.0.283 patches

thehackerwire@mastodon.social at 2026-10-07T21:16:22.000Z ##

🔴 CVE-2026-62253 - Critical (9.8)

Homer is open source telecom observability software. Prior to version 11.0.283, both JWT middleware functions (`JWTMiddleware` and `JWTMiddlewareV4`) immediately return `next(c)` when `jwtSecret == ""`. The JWT secret defaults to an empty string. ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62176
(9.1 CRITICAL)

EPSS: 0.46%

updated 2026-10-07T17:16:56.153000

1 posts

PraisonAI is a multi-agent teams system. Prior to version 4.6.78, the `deploy/api.py` module generates Python server code by directly interpolating the `agents_file` parameter into an f-string that is then written to a file and executed via `subprocess.Popen()`. An attacker who controls the `agents_file` value (via CLI argument, configuration, or upstream API) can inject arbitrary Python code. Ver

thehackerwire@mastodon.social at 2026-10-07T20:46:05.000Z ##

🔴 CVE-2026-62176 - Critical (9.1)

PraisonAI is a multi-agent teams system. Prior to version 4.6.78, the `deploy/api.py` module generates Python server code by directly interpolating the `agents_file` parameter into an f-string that is then written to a file and executed via `subpr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107204
(9.8 CRITICAL)

EPSS: 0.77%

updated 2026-10-07T17:16:53.657000

1 posts

LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run_script endpoint. Attackers can recover real builtins through the injected FastAPI app object, bypassing the guarded __import__, to import os and run operating system commands as the LMCache process.

thehackerwire@mastodon.social at 2026-10-07T16:49:30.000Z ##

🔴 CVE-2026-107204 - Critical (9.8)

LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run_script endpoint. Attackers can recover real builtins through the injected Fast...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-106501
(9.6 CRITICAL)

EPSS: 0.47%

updated 2026-10-07T17:16:49.597000

1 posts

Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensitive information exposure in scaffolder. An authenticated Backstage user who can read another user's Scaffolder task may receive internal execution data. In deployments where that data contains credentials for an external servic

offseq@infosec.exchange at 2026-10-08T04:30:25.000Z ##

CVE-2026-106501: @backstage/plugin-scaffolder-backend CRITICAL vuln (CVSS 9.6) allows authenticated users to access other users’ task data, incl. credentials. Patch to 4.1.0 now. Restrict task read perms as interim measure. radar.offseq.com/threat/plugin #OffSeq #Backstage #Vuln

##

CVE-2026-106118
(7.5 HIGH)

EPSS: 0.60%

updated 2026-10-07T16:18:57

1 posts

## Summary When decoding a tiled TIFF with fax compression (T4/T6/MH), `DecodeTilesChunky` allocates each tile buffer from **TileWidth** (`ceil(TileWidth*bpp/8)*TileLength` bytes) but constructs the fax decompressor with **frame.Width**: `TiffDecompressorsFactory` ignores the `isTiled/tileWidth/tileHeight` parameters entirely. The T4/T6/MH decompressors treat the full image width as the scanline

thehackerwire@mastodon.social at 2026-10-06T20:01:47.000Z ##

🟠 CVE-2026-106118 - High (7.5)

ImageSharp is a 2D graphics library. From 3.0.0 until 4.1.1, tiled TIFF decoding allocates a destination buffer using TileWidth but TiffDecompressorsFactory.Create constructs T4, T6, and Modified Huffman decompressors using the full frame width. T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-106117
(7.5 HIGH)

EPSS: 0.43%

updated 2026-10-07T16:18:52

1 posts

## Summary When decoding a fax-compressed strip TIFF (Compression=3 / Group 3 1D, or Compression=2 / Modified Huffman), the CCITT decompressors write decoded runs through `BitWriterUtils.WriteBits/WriteBit/WriteZeroBit`, which advance and write bits via `Unsafe.Add` with read-modify-write semantics — **without ever comparing the write position against the target buffer length**. The strip buffer

thehackerwire@mastodon.social at 2026-10-06T18:30:32.000Z ##

🟠 CVE-2026-106117 - High (7.5)

ImageSharp is a 2D graphics library. From 3.0.0 until 4.1.1, decoding a strip TIFF using CCITT Group 3 or Modified Huffman compression can pass attacker-expanded runs to BitWriterUtils.WriteBits without first checking the current row width. T4Tiff...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101027
(7.7 HIGH)

EPSS: 0.17%

updated 2026-10-07T16:17:31.953000

1 posts

When `[migrations] ALLOWED_DOMAINS` was configured, a hostname matching the allow list was accepted without checking its resolved address against the local-network restrictions. A user who can start repository migrations and control the DNS of an allowed hostname could make it resolve to loopback or private addresses and bypass `ALLOW_LOCALNETWORKS = false`, reaching internal services from the Git

CVE-2026-62251
(8.1 HIGH)

EPSS: 0.34%

updated 2026-10-07T16:13:09

1 posts

### Summary The `V4StatisticsQuery` handler passes the user-supplied `rawquery` field directly to DuckDB without calling the `sqlvalidator.ValidateRawSQL` function used throughout the rest of the codebase. Any authenticated user can execute arbitrary SQL statements against all data accessible through the FlightSQL service. ### Details **`coordinator/handlers/statistics_v4.go` lines 74-107** — `V4

thehackerwire@mastodon.social at 2026-10-07T20:46:14.000Z ##

🟠 CVE-2026-62251 - High (8.1)

Homer is open source telecom observability software. Prior to version 11.0.283, the `V4StatisticsQuery` handler passes the user-supplied `rawquery` field directly to DuckDB without calling the `sqlvalidator.ValidateRawSQL` function used throughout...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62252
(9.8 CRITICAL)

EPSS: 0.65%

updated 2026-10-07T16:12:03

1 posts

### Summary On every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an `admin` account with the password `sipcapture` (stored as a legacy SHA-256 hex hash). There is no first-login forced-change mechanism. Any attacker who reaches the login endpoint immediately gains full administrative access. ### Details **`config/config.go` lines 858-861:** ``

thehackerwire@mastodon.social at 2026-10-07T21:16:12.000Z ##

🔴 CVE-2026-62252 - Critical (9.8)

Homer is open source telecom observability software. Prior to version 11.0.283, on every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an `admin` account with the password `sipcapture` (stored as...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16516
(0 None)

EPSS: 0.15%

updated 2026-10-07T16:02:27.613000

2 posts

wolfSSH does not validate that the ECDSA curve identifier in a KEXDH_REPLY host key blob matches the algorithm negotiated during key exchange. In ParseECCPubKey() (src/internal.c), the blob's algorithm string is used to derive the curve via NameToId/wcPrimeForId without checking against the negotiated ssh->handshake->pubKeyId, and the RFC 5656 curve identifier string is discarded via GetSkip() rat

DailyCyberSecurity@infosec.exchange at 2026-10-08T03:54:29.000Z ##

wolfSSH 1.6.0 fixes five wolfSSH vulnerabilities, including critical host key flaw CVE-2026-16516 and Windows login bug CVE-2026-83540.

#wolfSSH #wolfSSL #SSH #CVE202616516 #CVE202683540 #EmbeddedSecurity #MitM #Vulnerability

securityonline.info/wolfssh-vu

##

offseq@infosec.exchange at 2026-10-07T03:00:26.000Z ##

wolfSSH <1.6.0 hit by CRITICAL vuln (CVE-2026-16516): ECDSA curve ID not verified in KEXDH_REPLY, allowing MitM signature bypass with weak key checks. Patch or harden key validation. radar.offseq.com/threat/cve-20 #OffSeq #wolfSSH #infosec #CVE202616516

##

CVE-2026-77214
(8.2 HIGH)

EPSS: 0.55%

updated 2026-10-07T15:57:20.793000

1 posts

libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching t

thehackerwire@mastodon.social at 2026-10-07T17:05:14.000Z ##

🟠 CVE-2026-77214 - High (8.2)

libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated b...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-106558
(8.8 HIGH)

EPSS: 0.47%

updated 2026-10-07T15:52:18.453000

1 posts

Backstage is an open framework for building developer portals. Prior to 1.14.8, 1.15.6, and 2.0.1, the @backstage/plugin-techdocs-node package improperly validated mapping-style markdown_extensions configuration. An authenticated attacker who can register or influence an SCM-backed documentation source may bypass TechDocs sanitization and cause Python objects to be imported and instantiated in the

thehackerwire@mastodon.social at 2026-10-07T17:05:26.000Z ##

🟠 CVE-2026-106558 - High (8.8)

Backstage is an open framework for building developer portals. Prior to 1.14.8, 1.15.6, and 2.0.1, the @backstage/plugin-techdocs-node package improperly validated mapping-style markdown_extensions configuration. An authenticated attacker who can ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-21589(CVSS UNKNOWN)

EPSS: 1.77%

updated 2026-10-07T15:31:33

20 posts

h3. Summary This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires p

Nuclei template

10 repos

https://github.com/rxsklife/CVE-2026-21589

https://github.com/tc4dy/CVE-2026-21589-PoC-Exploit

https://github.com/0xBlackash/CVE-2026-21589

https://github.com/BimBoxH4/CVE-2026-21589

https://github.com/murrez/CVE-2026-21589

https://github.com/renzi25031469/CVE-2026-21589

https://github.com/aduli198/CVE-2026-21589

https://github.com/MarcusProgram/CVE-2026-21589

https://github.com/ynsmroztas/AtlasSniper

https://github.com/watchtowrlabs/watchTowr-vs-Atlassian-CVE-2026-21589

jschauma@mstdn.social at 2026-10-08T16:58:05.000Z ##

Oh, Atlassian, never change! 😭

"CVE-2026-21589 - Arbitrary File Access Vulnerability impacts Multiple Products"

CVSS Score 9.3, so, you know, you better "Test that your rule blocks .. immediately adjacent to /".

APT /../../../../../../etc/passwd strikes again.

confluence.atlassian.com/secur

##

linuxmint_hun@mastodon.social at 2026-10-08T17:13:07.000Z ##

CVE-2026-21589 kritikus arbitrary file access hiba érinti több Atlassian Data Center terméket (Jira, Confluence, Bitbucket) és bejelentkezés nélkül hozzáférhetők lehetnek fájlok. Van internetre kitett példányod, ami veszélyben lehet, aggódsz? A végleges megoldás a frissítés; ideiglenes WAF/Tomcat RewriteValve mitigációk lehetségesek.

linuxmint.hu/hir/2026/10/kriti

#Atlassian #CVE202621589 #Jira #Confluence #Bitbucket #DataCenter #WAF #Tomcat #kiberbiztonság #infosec

##

jschauma@mstdn.social at 2026-10-08T16:58:05.000Z ##

Oh, Atlassian, never change! 😭

"CVE-2026-21589 - Arbitrary File Access Vulnerability impacts Multiple Products"

CVSS Score 9.3, so, you know, you better "Test that your rule blocks .. immediately adjacent to /".

APT /../../../../../../etc/passwd strikes again.

confluence.atlassian.com/secur

##

beyondmachines1@infosec.exchange at 2026-10-08T12:01:49.000Z ##

Atlassian Patches Critical File Access Flaw Exploited in the Wild

Atlassian released emergency patches for a critical arbitrary file access vulnerability (CVE-2026-21589) affecting eight Data Center products, which attackers are actively exploiting to gain administrator privileges.

**If you run self-hosted Atlassian Data Center or Server products (Jira, Confluence, Bitbucket, Bamboo, Crowd, Crucible/Fisheye), apply Atlassian's security update immediately, because this flaw is being actively exploited to steal passwords and take over admin accounts. If you can't patch, remove the instance from the public internet now, then check your logs for access attempts to WEB-INF or crowd.properties. Change any Crowd credentials that may have been exposed.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

benzogaga33@mamot.fr at 2026-10-08T09:40:04.000Z ##

Atlassian : une faille critique permet de lire des fichiers sur Jira, Confluence et Bitbucket it-connect.fr/atlassian-cve-20 #ActuCybersécurité #Cybersécurité #Vulnérabilité

##

threatnoir@infosec.exchange at 2026-10-08T08:07:02.000Z ##

⚠️ CRITICAL: Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details

A critical arbitrary file access vulnerability (CVE-2026-21589) in Atlassian Data Center products is under active exploitation as of public disclosure. Threat actors attempted exploitation within two hours of details going public, with potential access to credentials and sensitive files. All Atlass…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

censys@infosec.exchange at 2026-10-07T20:15:13.000Z ##

🚨 Rapid Response: CVE-2026-21589 (CVSS 9.3) is a critical arbitrary file access vulnerability affecting eight Atlassian Data Center products, including Confluence, Jira, Bitbucket, and Bamboo.

Censys currently detects 95,366 Internet-facing hosts and 431,502 web properties running affected products after excluding assets labeled as honeypots. This is product exposure, not a confirmed-vulnerable count.
Atlassian has released fixes for all eight products.

Full Censys ARC advisory: censys.com/advisory/cve-2026-2

#CensysARC #Atlassian #Cybersecurity #Vulnerability

##

threatcodex@infosec.exchange at 2026-10-07T16:50:50.000Z ##

Scans for Atlassian vulnerablity (CVE-2026-21589)
#CVE_2026_21589
isc.sans.edu/diary/rss/33406

##

youranonnewsirc@nerdculture.de at 2026-10-07T16:26:28.000Z ##

Recent developments include the US evacuating B-1 bombers from the UK due to an Iranian threat, while Hamas is reportedly plotting attacks in Gaza for October 7th. In cybersecurity, ASOS experienced a cloud breach via its Snowflake platform, and active exploitation of a critical Atlassian flaw (CVE-2026-21589) has begun. An FBI breach was also linked to a contractor error. Microsoft is hosting an AI-focused Surface event today.

#Cybersecurity #Geopolitics #TechNews

##

cyberworldops@infosec.exchange at 2026-10-07T15:45:24.000Z ##

Unauthenticated arbitrary file access in eight self-hosted Atlassian families (CVE-2026-21589) is seeing active probing after public PoC release. Exploitation requires exact file path and is limited to web root, without directory listing. Data Center operators should patch and reduce exposure promptly. #Atlassian #DataCenter #ThreatIntel

cyberworldops.eu/en/public-exp

##

sans_isc@infosec.exchange at 2026-10-07T15:01:52.000Z ##

Scans for Atlassian vulnerablity (CVE-2026-21589) isc.sans.edu/diary/33406

##

oversecurity@mastodon.social at 2026-10-07T14:50:53.000Z ##

Atlassian Warns of Critical Flaw Affecting Eight Self-Managed Products

Atlassian's CVE-2026-21589 lets unauthenticated attackers read files in Confluence and seven other Data Center products.

🔗️ [Thecyberexpress] link.is.it/gJ99W6

##

oversecurity@mastodon.social at 2026-10-07T13:51:15.000Z ##

Hackers exploit critical Atlassian flaw after public PoC release

A critical vulnerability (CVE-2026-21589) affecting multiple Atlassian product families, including Jira, Confluence, and Bitbucket, is being...

🔗️ [Bleepingcomputer] link.is.it/J8wKmL

##

jbhall56@infosec.exchange at 2026-10-07T13:39:07.000Z ##

An unauthenticated attacker can exploit CVE-2026-21589 to access specific files in the application's web root directory if they know the file's exact name and path. bleepingcomputer.com/news/secu

##

threatcodex@infosec.exchange at 2026-10-07T13:15:33.000Z ##

You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589)
#CVE_2026_21589 #Bitbucket #Confluence #Jira #AtlassianBamboo #AtlassianCrowd
labs.watchtowr.com/you-wont-he

##

DailyCyberSecurity@infosec.exchange at 2026-10-07T07:35:26.000Z ##

CVE-2026-21589 exploitation is underway against Atlassian servers after researchers published arbitrary file read PoC and technical details.

#Atlassian #Jira #Confluence #Bitbucket #CVE202621589 #PathTraversal #ExploitedInTheWild #Vulnerability

securityonline.info/cve-2026-2

##

christopherkunz@chaos.social at 2026-10-07T06:28:40.000Z ##

OK, this is an innovative directory traversal vuln:
GET /download/resources/jira.webresources:color-picker-popup/images/..::..::..::..::..::WEB-INF::web.xml HTTP/1.1

This is from CVE-2026-21589, labs.watchtowr.com/you-wont-he

The "::" gets replaced with "/" by some weird sanitation method, read more about it in the writeup.

Tagging @nynbinary for humorous memeing.

##

ssvc@infosec.exchange at 2026-10-06T19:58:17.000Z ##

@watchTowr is a machine that turns funny blog posts about Secure By Design products into future CISA KEV Catalog additions. This time it's Atlassian pre-auth arbitrary file read CVE-2026-21589 (9.3 critical). Given that there's a similar "Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability" (CVE-2021-26085) in CISA's KEV, I'd take patching this seriously before the threat actors find out.

labs.watchtowr.com/you-wont-he

#atlassian #confluence #CVE #jira #bamboo

##

oversecurity@mastodon.social at 2026-10-06T18:40:06.000Z ##

Atlassian warns of critical file-access flaw in Jira, Confluence

Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple...

🔗️ [Bleepingcomputer] link.is.it/yyKkUz

##

_r_netsec@infosec.exchange at 2026-10-06T17:33:21.000Z ##

You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589) - watchTowr Labs labs.watchtowr.com/you-wont-he

##

CVE-2026-106442
(7.8 HIGH)

EPSS: 0.16%

updated 2026-10-07T15:17:11.900000

1 posts

Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.6 and 1.4.0.dev9, the instantiate() target blacklist introduced for CVE-2026-68508 incompletely checks the effective callable selected by the target field. Execution wrappers such as timeit.timeit, executable deserialization through pickle.loads, aliases, callable-returning helpers, generic dispatch, and defe

thehackerwire@mastodon.social at 2026-10-06T19:31:53.000Z ##

🟠 CVE-2026-106442 - High (7.8)

Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.6 and 1.4.0.dev9, the instantiate() target blacklist introduced for CVE-2026-68508 incompletely checks the effective callable selected by the target field. E...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103059
(9.1 CRITICAL)

EPSS: 0.28%

updated 2026-10-07T15:16:56.737000

1 posts

When Gitea's built-in SSH server is enabled (`START_SSH_SERVER = true`), the presented public key was looked up with an SQL `LIKE` comparison of its encoded content, which is case-insensitive on some databases, including the default SQLite. An attacker who can construct a case variant of another user's registered RSA public key for which they can derive the private key could have that key matched

CVE-2026-106445
(0 None)

EPSS: 0.41%

updated 2026-10-07T13:58:29.527000

1 posts

Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars lookupProperty returns Function.prototype.constructor before applying the prototype-access deny list because constructor is an own property of Function.prototype. When an attacker can render a controlled template with allowProtoMethodsByDefault enabled and an accessible function in th

CVE-2026-102159
(9.8 CRITICAL)

EPSS: 0.36%

updated 2026-10-07T13:38:48.657000

1 posts

An access-control flaw in the CV-CUE backend may allow an unauthenticated network attacker to access functionality intended only for internal services. Successful exploitation may expose sensitive location information or disrupt affected services.

CVE-2025-64393(CVSS UNKNOWN)

EPSS: 0.36%

updated 2026-10-07T09:32:29

2 posts

This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execute arbitrary code as SYSTEM on the backup server.

ssvc@infosec.exchange at 2026-10-07T16:43:15.000Z ##

Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2 P4 from 10/6

CVE-2025-64393 (9.4 critical) low-privileged RCE

veeam.com/kb4934

#veeam #cve

##

DailyCyberSecurity@infosec.exchange at 2026-10-06T17:54:59.000Z ##

Critical Veeam Backup vulnerability CVE-2025-64393 (CVSS 9.4) enables RCE by low-privileged users. Update to 12.3.2 P4 now.

#Veeam #VeeamBackup #CVE202564393 #RCE #Deserialization #Ransomware #BackupSecurity #Vulnerability

securityonline.info/veeam-back

##

CVE-2026-59346
(9.3 CRITICAL)

EPSS: 0.26%

updated 2026-10-07T06:33:08

3 posts

VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Affected versions: - VMware Workstation: 25H2, 26H1 (fixed in 26H1u1) - VMware Fusion: 25H2, 26H1 (fixed in 26H1u1)

1 repos

https://github.com/0xCyberstan/CVE-2026-59346-POC

guru@thecybersecguru.com at 2026-10-08T18:05:42.000Z ##

PoC Released for Critical VMware VMXNET3 Integer Overflow Flaw Enabling Guest-to-Host Code Execution (CVE-2026-59346)

CVE-2026-59346 affects VMware VMXNET3 and enables guest-to-host memory corruption. A public PoC crashes vmware-vmx. Patch Workstation and Fusion now

thecybersecguru.com/exploits/c

##

guru@thecybersecguru.com at 2026-10-08T18:05:42.000Z ##

PoC Released for Critical VMware VMXNET3 Integer Overflow Flaw Enabling Guest-to-Host Code Execution (CVE-2026-59346)

CVE-2026-59346 affects VMware VMXNET3 and enables guest-to-host memory corruption. A public PoC crashes vmware-vmx. Patch Workstation and Fusion now

thecybersecguru.com/exploits/c

##

DailyCyberSecurity@infosec.exchange at 2026-10-08T02:17:27.000Z ##

A VMware VMXNET3 vulnerability, CVE-2026-59346 (CVSS 9.3), allows VM escape. Full details and PoC exploit code are now public. Patch to 26H1u1.

#VMware #VMXNET3 #CVE202659346 #VMEscape #Virtualization #Broadcom #PoC #Vulnerability

securityonline.info/vmware-vmx

##

CVE-2026-19572(CVSS UNKNOWN)

EPSS: 0.37%

updated 2026-10-07T06:33:01

1 posts

A security vulnerability has been identified in FlexNet Publisher lmadmin. The vulnerability exists in a SOAP handler, where a hardcoded authentication bypass could allow an unauthenticated user to obtain a privileged administrator session without providing valid credentials.

offseq@infosec.exchange at 2026-10-07T04:30:25.000Z ##

Flexera FlexNet Publisher (≤11.19.11) suffers a CRITICAL auth bypass (CVE-2026-19572, CVSS 9.3). SOAP handler flaw allows unauthenticated admin access. Patch not yet available — monitor systems closely. radar.offseq.com/threat/cve-20 #OffSeq #CVE202619572 #infosec #vuln

##

CVE-2026-91140
(9.6 CRITICAL)

EPSS: 1.92%

updated 2026-10-07T04:18:10.610000

1 posts

An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user invokes the generator.

beyondmachines1@infosec.exchange at 2026-10-08T10:01:49.000Z ##

Progress Software Fixes Critical Command Injection Flaw in DataDirect ARC GenAI Agents

Progress Software patched a critical command injection vulnerability (CVE-2026-91140) in its DataDirect ARC GenAI Agents that allowed attackers to execute code via malicious OpenAPI filenames.

**If you use Progress DataDirect ARC GenAI agents (the ARCGenAI-Generator or ARCGenAI-EntityGen files), update ASAP by pulling the latest version 2.1 files from GitHub. If you've recently fed it any OpenAPI or Swagger files from outside sources, check your developer machines and CI/CD pipelines for unexpected files or changes. From now on treat every external spec file as untrusted.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-101207
(8.8 HIGH)

EPSS: 1.66%

updated 2026-10-07T04:17:38.120000

1 posts

Dell OpenManage Integration with Microsoft Windows Admin Center, versions prior to 3.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

thehackerwire@mastodon.social at 2026-10-06T18:32:59.000Z ##

🟠 CVE-2026-101207 - High (8.8)

Dell OpenManage Integration with Microsoft Windows Admin Center, versions prior to 3.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-83540(CVSS UNKNOWN)

EPSS: 0.34%

updated 2026-10-07T03:30:31

1 posts

When password or public key authentication is used with the Windows port of wolfSSHd, the Windows logon token acquired for one authenticated connection is not released before a token is acquired for a subsequent connection, resulting in user login poisoning between connections. A less privileged user with a valid account on the server can exploit this to force a login as a more privileged user. Th

CVE-2026-105324(CVSS UNKNOWN)

EPSS: 0.65%

updated 2026-10-07T03:30:23

1 posts

An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files on the host system. By sending a crafted HTTP request with injected headers via the state parameter, the attacker can leverage the underlying web server's X-Sendfile mechanism to retrieve sensitive files without authentication. Affected products and versions incl

CVE-2026-86361
(8.2 HIGH)

EPSS: 0.14%

updated 2026-10-06T21:31:59

1 posts

Dell System Update, versions prior to 2.3.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

thehackerwire@mastodon.social at 2026-10-06T19:30:36.000Z ##

🟠 CVE-2026-86361 - High (8.2)

Dell System Update, versions prior to 2.3.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103007
(7.2 HIGH)

EPSS: 0.34%

updated 2026-10-06T21:31:57

1 posts

Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a delegated administrative privilege whose scope is not fully enforced during authorization checks. Elasticsearch contains an incorrect authorization weakness in a configurable, non-default privilege that lets an administrator delegate limited role-management capability to another user, scoped to specific indic

CVE-2026-102406
(8.8 HIGH)

EPSS: 0.35%

updated 2026-10-06T21:31:55

1 posts

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana could lead to cross-tenant data interception. In this context, "tenant" refers to a user or team sharing the same Kibana deployment, not a separate Elastic Cloud organization or customer. Kibana's Fleet package installation process allowed a user holding delegated Fleet package-management privileges, without direct Elasticsearch

CVE-2026-86362
(8.2 HIGH)

EPSS: 0.13%

updated 2026-10-06T21:31:53

1 posts

Dell System Update, versions prior to 2.3.0.0, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

thehackerwire@mastodon.social at 2026-10-06T19:30:46.000Z ##

🟠 CVE-2026-86362 - High (8.2)

Dell System Update, versions prior to 2.3.0.0, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-106382
(9.6 CRITICAL)

EPSS: 0.40%

updated 2026-10-06T21:31:51

2 posts

Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

offseq@infosec.exchange at 2026-10-07T12:00:27.000Z ##

Chrome 155 patches 247 vulnerabilities, including 4 CRITICAL use-after-free bugs (CVE-2026-106382, - 106197, - 106358, - 106347) across Chromecast, Browser, Navigation & Track. Update on Windows, macOS & Linux. No active exploits. radar.offseq.com/threat/chrome #OffSeq #Chrome #Security

##

DailyCyberSecurity@infosec.exchange at 2026-10-07T01:54:26.000Z ##

The Chrome 155 security update fixes 247 flaws, including critical use after free bugs CVE-2026-106382 and CVE-2026-106197. Update now.

#Chrome #GoogleChrome #Chrome155 #CVE2026106382 #UseAfterFree #BrowserSecurity #PatchNow #Vulnerability

securityonline.info/chrome-155

##

CVE-2026-104073
(7.6 HIGH)

EPSS: 0.28%

updated 2026-10-06T21:31:41

1 posts

NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vulnerability that allows a low-privileged user with the "Can add custom links" permission to steal session cookies and API tokens of other users by exposing the raw Django HttpRequest object to the Jinja2 template context. Attackers can craft a custom link template embedding request.COOKIES['sessionid'] or a user's API to

thehackerwire@mastodon.social at 2026-10-06T20:01:58.000Z ##

🟠 CVE-2026-104073 - High (7.6)

NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vulnerability that allows a low-privileged user with the "Can add custom links" permission to steal session cookies and API tokens of other users by exposing the raw Djang...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86360
(9.6 CRITICAL)

EPSS: 0.63%

updated 2026-10-06T20:17:34.090000

1 posts

Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute

thehackerwire@mastodon.social at 2026-10-06T19:30:27.000Z ##

🔴 CVE-2026-86360 - Critical (9.6)

Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, l...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-106443
(8.8 HIGH)

EPSS: 0.69%

updated 2026-10-06T20:17:26.023000

1 posts

WeasyPrint helps web developers to create PDF documents. Prior to 70.0, the image-loading path in weasyprint/images.py passes fetched image bytes from HTML img URLs, CSS image values, SVG image references, and data URIs to Pillow's generic image dispatcher without excluding EPS or PostScript formats. On hosts with Ghostscript installed, Pillow EpsImagePlugin invokes the interpreter for attacker-co

thehackerwire@mastodon.social at 2026-10-06T19:45:28.000Z ##

🟠 CVE-2026-106443 - High (8.8)

WeasyPrint helps web developers to create PDF documents. Prior to 70.0, the image-loading path in weasyprint/images.py passes fetched image bytes from HTML img URLs, CSS image values, SVG image references, and data URIs to Pillow's generic image d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-106440
(7.8 HIGH)

EPSS: 0.27%

updated 2026-10-06T20:03:40.690000

1 posts

Hydra is a framework for elegantly configuring complex applications. From 1.2.0 until 1.3.0 and 1.4.0.dev10, the hydra-optuna-sweeper package accepts a configuration-controlled dotted path in hydra.sweeper.custom_search_space, resolves it with hydra.utils.get_method(), and later invokes the returned callable in the Hydra controller process. Because get_method() is a trusted-input lookup helper and

thehackerwire@mastodon.social at 2026-10-06T20:01:36.000Z ##

🟠 CVE-2026-106440 - High (7.8)

Hydra is a framework for elegantly configuring complex applications. From 1.2.0 until 1.3.0 and 1.4.0.dev10, the hydra-optuna-sweeper package accepts a configuration-controlled dotted path in hydra.sweeper.custom_search_space, resolves it with hyd...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-106110
(7.5 HIGH)

EPSS: 0.35%

updated 2026-10-06T20:03:40.690000

1 posts

ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocates an undersized compressed-data buffer for narrow 1-bit images. TiffCcittCompressor.Initialize does not reserve enough space for the row data and T4 end-of-line codes, and T4BitCompressor.CompressStrip reaches unchecked writes when TiffCompression.CcittGroup3Fax is selected directly or inherited fro

thehackerwire@mastodon.social at 2026-10-06T18:30:42.000Z ##

🟠 CVE-2026-106110 - High (7.5)

ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocates an undersized compressed-data buffer for narrow 1-bit images. TiffCcittCompressor.Initialize does not reserve enough space for the row data and T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105859
(9.8 CRITICAL)

EPSS: 0.35%

updated 2026-10-06T20:03:40.690000

1 posts

Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can submit a request to a specific update endpoint that modifies collection documents without enforcing collection or field-level access control when orderable is enabled on a collection or join field. This issue is fixed in versions 3.90.0 and 4.0

thehackerwire@mastodon.social at 2026-10-06T18:16:55.000Z ##

🔴 CVE-2026-105859 - Critical (9.8)

Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can submit a request to a specific update endpoint that modifies collection documents without e...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105858
(8.1 HIGH)

EPSS: 0.48%

updated 2026-10-06T20:03:40.690000

1 posts

Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a crafted request to the public first-register operation can execute code remotely when local authentication is enabled and no initial user has been created. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.

thehackerwire@mastodon.social at 2026-10-06T17:31:01.000Z ##

🟠 CVE-2026-105858 - High (8.1)

Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a crafted request to the public first-register operation can execute code remotely when local authenticatio...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63697
(7.6 HIGH)

EPSS: 0.29%

updated 2026-10-06T19:58:37.060000

1 posts

Dell System Update, versions prior to 2.3.0.0, contains an Improper Certificate Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

thehackerwire@mastodon.social at 2026-10-06T19:31:35.000Z ##

🟠 CVE-2026-63697 - High (7.6)

Dell System Update, versions prior to 2.3.0.0, contains an Improper Certificate Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104070
(9.8 CRITICAL)

EPSS: 0.57%

updated 2026-10-06T18:31:38

2 posts

The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php, causing the authorization dispatcher to resolve an unconditionally-true handler instead of the proper modification check. Attackers can chain this flaw to write a m

cR0w@infosec.exchange at 2026-10-06T19:37:45.000Z ##

Someone needs to check on the USMC.

nvd.nist.gov/vuln/detail/cve-2

The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php, causing the authorization dispatcher to resolve an unconditionally-true handler instead of the proper modification check. Attackers can chain this flaw to write a malicious .html skeleton file, disclose sensitive configuration files containing the site secret, and forge a signed ajax context to execute the uploaded skeleton, achieving arbitrary PHP code execution as the web-server user.

##

thehackerwire@mastodon.social at 2026-10-06T18:46:54.000Z ##

🔴 CVE-2026-104070 - Critical (9.8)

The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php, causing the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105796
(8.8 HIGH)

EPSS: 0.90%

updated 2026-10-06T16:00:36.547000

1 posts

Kiota is an OpenAPI based HTTP Client code generator. From 0.5.0 until 1.35.0, Kiota's Java and PHP documentation-comment sanitizers delete block-comment terminators rather than neutralizing them, allowing overlapping characters to reform a terminator and place attacker-controlled OpenAPI text outside a generated documentation comment. The Java sanitizer also removes non-ASCII characters after del

thehackerwire@mastodon.social at 2026-10-06T20:16:03.000Z ##

🟠 CVE-2026-105796 - High (8.8)

Kiota is an OpenAPI based HTTP Client code generator. From 0.5.0 until 1.35.0, Kiota's Java and PHP documentation-comment sanitizers delete block-comment terminators rather than neutralizing them, allowing overlapping characters to reform a termin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104850
(7.5 HIGH)

EPSS: 0.18%

updated 2026-10-06T15:35:44

1 posts

### Summary In affected versions, the SDK's OAuth client let the MCP server decide which authorization server received the client's OAuth credentials. Credentials were not tied to the authorization server they belong to. A malicious or compromised MCP server could name its own authorization server. With no user interaction, the client would send it: - the `refresh_token` and `client_secret` stor

thehackerwire@mastodon.social at 2026-10-06T18:46:45.000Z ##

🟠 CVE-2026-104850 - High (7.5)

MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Starting in version 1.12.0 and prior to versions 1.31.0 and 2.2.0, the SDK's OAuth client support let the MCP server a client connected to decide whi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63688
(10.0 CRITICAL)

EPSS: 0.79%

updated 2026-10-06T15:32:11

1 posts

Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-storage gRPC server. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to storage backend administrator credentials for all registered storage arrays.

thehackerwire@mastodon.social at 2026-10-06T18:47:02.000Z ##

🔴 CVE-2026-63688 - Critical (10)

Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-storage gRPC server. An unauthenticated remote attacker could potentially exploit this ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63277
(0 None)

EPSS: 0.14%

updated 2026-10-06T15:03:59.427000

1 posts

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location. In fixed versions an entry in a Java class path has to be a file URL.

1 repos

https://github.com/HORKimhab/CVE-2026-63277

beyondmachines1@infosec.exchange at 2026-10-07T10:01:49.000Z ##

LibreOffice and OpenOffice Patch Critical Remote Code Execution Vulnerabilities

LibreOffice and Apache OpenOffice patched several critical vulnerabilities, including a remote code execution flaw (CVE-2026-63277) that allows attackers to run malicious Java code via manipulated spreadsheet documents.

**If you use LibreOffice, update it to version 26.2.5 or 26.8.0 ASAP, and until you do, don't open documents from unknown senders or unexpected sources. If you use Apache OpenOffice, there's no fix yet, so turn off Java in the program's options now and install version 4.1.17 as soon as it's released. Or better yet, switch to the patched LibreOffice.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-88779
(7.5 HIGH)

EPSS: 0.59%

updated 2026-10-05T15:33:23

2 posts

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.

2 repos

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

https://github.com/orjanj/netscaler_threat_hunt_helper

DailyCyberSecurity@infosec.exchange at 2026-10-07T07:44:20.000Z ##

Citrix reveals CVE-2026-88779, a critical memory overflow flaw in NetScaler SAML configurations leading to DoS, following recent RCE zero-day attacks.

#CitrixNetScaler #Cybersecurity #CVE202688779 #SAML #ZeroDay

meterpreter.org/citrix-netscal

##

otcyber@infosec.exchange at 2026-10-07T05:30:00.000Z ##

Vorfall-Lagebild: Citrix NetScaler: Zero-Day CVE-2026-88779 wird aktiv

Nach 24 Stunden: was bekannt ist, was offen ist und was wahrscheinlich passiert ist – Citrix NetScaler: Zero-Day CVE-2026-88779 wird aktiv ausgenutzt – SAML-G

#OTSecurity #ICS #KRITIS #NIS2 #Cybersicherheit
ot-cyber.de/blog/vorfall-lageb

##

CVE-2026-50572
(5.9 MEDIUM)

EPSS: 0.68%

updated 2026-10-05T14:12:02.027000

1 posts

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HTTP external-authorization client can retain a stale request callback after a request is rejected. When RawHttpClientImpl::onSuccess later processes the authorization response, it can invoke callbacks_ after the callback owner has been destroyed, causing a u

hugovalters@mastodon.social at 2026-10-08T16:40:23.000Z ##

CVE-2026-50572 Envoy use-after-free in HTTP ext-auth client crashes process under load. CVSS 5.9. Unpatched, so update to 1.36.10, 1.37.6, 1.38.4 or 1.39.1 now. valtersit.com/cve/CVE-2026-505 #CVE #infosec #Envoy

##

CVE-2026-48521
(5.9 MEDIUM)

EPSS: 0.74%

updated 2026-10-05T14:09:45.933000

1 posts

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ProdClusterManagerFactory::allocateConnPool dereferences transport_socket_options while selecting an HTTP/3 connection pool without first checking whether the pointer is null. LoadBalancerContext implementations used by synthetic, mirror, health-check, and as

hugovalters@mastodon.social at 2026-10-08T18:10:04.000Z ##

CVE-2026-48521 Envoy null pointer deref in HTTP/3 conn pool selection, CVSS 5.9, DoS risk in cloud-native proxies. Patch under review, versions before 1.36.10/1.37.6/1.38.4/1.39.1 affected. Update now. valtersit.com/cve/CVE-2026-485 #CVE #infosec

##

CVE-2026-53359
(8.8 HIGH)

EPSS: 0.98%

updated 2026-10-03T12:32:07

1 posts

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due to unexpected GFN") fixed a shadow paging mismatch between stored and computed GFNs; the bug could be triggered by changing a PDE mapping from outside the guest, and then deleting a memslot. Th

7 repos

https://github.com/chuzhongyun/CVE-2026-53359-Kernel-Fix

https://github.com/xj2268-TA/KVM-Januscape

https://github.com/ndouglas-cloudsmith/CVE-2026-53359

https://github.com/suominen/januscape

https://github.com/HORKimhab/CVE-2026-53359

https://github.com/Aoripus-LTD/Januscape-Hotfix

https://github.com/0xBlackash/CVE-2026-53359

CVE-2026-96940
(8.8 HIGH)

EPSS: 0.50%

updated 2026-10-02T21:32:13

1 posts

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

1 repos

https://github.com/HORKimhab/CVE-2026-96940

benzogaga33@mamot.fr at 2026-10-07T09:40:03.000Z ##

Microsoft Exchange : la faille CVE-2026-96940 permet de lire les boîtes aux lettres des autres utilisateurs it-connect.fr/exchange-server- #ActuCybersécurité #Cybersécurité #Vulnérabilité #Microsoft

##

CVE-2026-90970
(9.9 CRITICAL)

EPSS: 0.94%

updated 2026-10-02T18:44:11.270000

1 posts

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command

1 repos

https://github.com/techupdate24/gitlab-ai-gateway-cve-2026-90970

hackmag@infosec.exchange at 2026-10-06T21:03:18.000Z ##

⚪️ Critical 9.9-Point Vulnerability Fixed in GitLab AI Gateway

🗨️ GitLab developers have released patches for a critical vulnerability, CVE-2026-90970, affecting AI Gateway. The flaw received a CVSS score of 9.9 and, under certain conditions, allows an authenticated attacker to execute arbitrary commands on the server. The issue affects only…

🔗 hackmag.com/news/ai-gateway-pa

#news

##

CVE-2026-88772
(8.1 HIGH)

EPSS: 1.30%

updated 2026-09-28T12:32:09

1 posts

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

8 repos

https://github.com/FollowerSeize/CVE-2026-88772-POC

https://github.com/securekomodo/citrixInspector

https://github.com/technion/netscaler_scanner

https://github.com/emilstahl/pitscaler

https://github.com/murrez/CVE-2026-88772

https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

https://github.com/orjanj/netscaler_threat_hunt_helper

youranonnewsirc@nerdculture.de at 2026-10-06T22:26:24.000Z ##

Recent news highlights critical cybersecurity threats as Citrix NetScaler (CVE-2026-88772) and FortiMail (CVE-2026-104286) zero-days are under active exploitation, targeting critical infrastructure and government entities. Apple also patched an exploited CoreGraphics flaw. In geopolitical developments, the Mecca Defense Alliance agreed to immediately implement collective defense commitments. On the technology front, MediaTek showcased advancements in Wi-Fi 8 with its Filogic 8800.

#Cybersecurity #AnonNews_irc #News

##

GossiTheDog@cyberplace.social at 2026-10-08T16:55:50.000Z ##

Watchtowr have a good look at pray and spray #PitScaler exploitation. This isn’t the initial exploitation - their timeline should expand back to September 4th for that.

Also they make a good point re the latest SAML bug - by using it to DoS, it causes attacker commands in the logs to process immediately post reboot with PitScaler vuln. Not covered in blog: Attackers are actually doing this, they’re preloading the logs using the username field for failed logins.

watchtowr.com/intelligence/pos

##

GossiTheDog@cyberplace.social at 2026-10-08T16:55:50.000Z ##

Watchtowr have a good look at pray and spray #PitScaler exploitation. This isn’t the initial exploitation - their timeline should expand back to September 4th for that.

Also they make a good point re the latest SAML bug - by using it to DoS, it causes attacker commands in the logs to process immediately post reboot with PitScaler vuln. Not covered in blog: Attackers are actually doing this, they’re preloading the logs using the username field for failed logins.

watchtowr.com/intelligence/pos

##

DailyCyberSecurity@infosec.exchange at 2026-10-07T13:04:10.000Z ##

eSentire tracks four clusters behind CVE-2026-88771 exploitation, planting NetScaler web shells and backdoor accounts. Learn how to detect them.

#CVE202688771 #CitrixNetScaler #WebShell #ZeroDay #Platypus #eSentire #EdgeSecurity #CyberSecurity

securityonline.info/cve-2026-8

##

CVE-2026-91166
(5.7 MEDIUM)

EPSS: 0.22%

updated 2026-09-24T23:19:21.613000

1 posts

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.25.0 until 0.27.6, the browser SSH path in warpgate-web-ssh/src/manager.rs handles RCEvent::HostKeyUnknown without the presenting hop identity and instead passes ssh_options.host and ssh_options.port for the final target to KnownHosts::trust. In Prompt and AutoAccept modes, a jump host key can therefore be stored for th

hugovalters@mastodon.social at 2026-10-08T19:50:09.000Z ##

CVE-2026-91166 Warpgate SSH bastion host key confusion, CVSS 5.7. A jump host key can be trusted for the target address, risking MITM. Patch under review, so track it and update as soon as it lands. valtersit.com/cve/CVE-2026-911 #CVE #infosec #Warpgate

##

CVE-2026-93836
(7.2 HIGH)

EPSS: 0.24%

updated 2026-09-22T09:31:18

1 posts

The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qty' parameter in all versions up to, and including, 8.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The float c

CVE-2026-94504
(7.2 HIGH)

EPSS: 0.41%

updated 2026-09-22T09:31:17

1 posts

Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct submission URL, the script runs in the WordPress admin origin.

CVE-2026-94572(CVSS UNKNOWN)

EPSS: 0.53%

updated 2026-09-21T21:32:02

1 posts

In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The value is written verbatim into the HAProxy configuration generated on the amphora, and thus an authenticated project member who owns a TLS-enabled load balancer can embed a newline and inject arbitrary HAProxy configuration directives. Only deployment

hugovalters@mastodon.social at 2026-10-08T03:30:20.000Z ##

CVE-2026-94572: OpenStack Octavia Amphora driver config injection, CVSS 8.5. Authenticated project members can inject HAProxy directives via tls_ciphers. Patch is under review, hold off yet. Details: valtersit.com/cve/CVE-2026-945 #CVE #OpenStack #infosec

##

CVE-2026-87491
(8.8 HIGH)

EPSS: 3.14%

updated 2026-09-09T21:31:35

1 posts

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

2 repos

https://github.com/SneakyNachos/CVE-2026-87491-and-CVE-2026-85046-the-bagel-fell-off-the-counter

https://github.com/SneakyNachos/CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass.

CVE-2026-68508
(7.8 HIGH)

EPSS: 0.46%

updated 2026-08-21T20:57:32

1 posts

## Summary `hydra.utils.instantiate()` resolves and calls Python objects from config. If an application passes untrusted config to `instantiate()`, an attacker who controls `_target_` and its arguments can cause arbitrary code execution in the consuming process. Hydra is not a network service. Exploitation requires a consuming application, library, or user workflow to load attacker-controlled co

thehackerwire@mastodon.social at 2026-10-06T19:31:53.000Z ##

🟠 CVE-2026-106442 - High (7.8)

Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.6 and 1.4.0.dev9, the instantiate() target blacklist introduced for CVE-2026-68508 incompletely checks the effective callable selected by the target field. E...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47483
(8.2 HIGH)

EPSS: 0.55%

updated 2026-07-28T18:33:11

1 posts

NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption by submitting concurrent unauthenticated profiling requests. A successful exploit of this vulnerability might lead to denial of service and information disclosure.

Analyst207@mastodon.social at 2026-10-08T18:32:46.000Z ##

Nvidia Bug Exposes Thousands of GPU Servers to Potential Disruption

A newly discovered vulnerability in Nvidia's DCGM Exporter, tracked as CVE-2026-47483, has left around 2,100 GPU servers exposed to potential disruption, with a staggering 12,000 GPU UUIDs and $100M in hardware at risk. Researchers warn that unauthenticated actors could exploit this flaw to crash the GPU monitoring service,…

osintsights.com/nvidia-bug-exp

#GpuServerVulnerability #Nvidia #Cve202647483 #DcgmExporter #EmergingThreats

##

CVE-2025-54769
(8.8 HIGH)

EPSS: 3.33%

updated 2026-06-17T09:40:40.793000

1 posts

An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This can be used to overwrite existing PERL modules within the application to achieve remote code execution (RCE) by an attacker.

2 repos

https://github.com/byteReaper77/CVE-2025-54769

https://github.com/tunahantekeoglu/CVE-2025-54769

DarkWebInformer@infosec.exchange at 2026-10-06T17:47:04.000Z ##

🚨 PoC released for an authenticated LPAR2RRD remote code execution vulnerability; CVE-2025-54769

PoC: github.com/tunahantekeoglu/CVE

The flaw allows an authenticated read-only user to abuse the LPAR2RRD upgrade functionality to upload a crafted file and achieve remote code execution through directory traversal.

CVSS: 8.8
Affected: LPAR2RRD ≤ 8.04
Fixed: LPAR2RRD ≥ 8.05

The PoC builds and uploads a minimal upgrade archive, then verifies successful code execution by retrieving the output of whoami.

##

CVE-2025-41739
(5.9 MEDIUM)

EPSS: 0.35%

updated 2026-06-17T09:23:04.017000

1 posts

An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the CODESYS Control runtime system on Linux and QNX to trigger an out-of-bounds read via crafted socket communication, potentially causing a denial of service.

certvde@infosec.exchange at 2026-10-08T06:42:39.000Z ##

🔒 New CSAF advisory published

VDE-2026-105
KEB Automation: Multiple Vulnerabilities in COMBIVIS Control Runtime
CVE-2025-41659, CVE-2025-41691, CVE-2025-41739, CVE-2025-41738

The Docker-based COMBIVIS Control Runtime service is affected by several vulnerabilities in CODESYS Runtime Toolkit 3.5.21.10. These vulnerabilities are…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: keb-automation.csaf-tp.certvde

#OT #Advisory

##

CVE-2025-41738
(7.5 HIGH)

EPSS: 0.39%

updated 2026-06-17T09:23:03.883000

1 posts

An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.

certvde@infosec.exchange at 2026-10-08T06:42:39.000Z ##

🔒 New CSAF advisory published

VDE-2026-105
KEB Automation: Multiple Vulnerabilities in COMBIVIS Control Runtime
CVE-2025-41659, CVE-2025-41691, CVE-2025-41739, CVE-2025-41738

The Docker-based COMBIVIS Control Runtime service is affected by several vulnerabilities in CODESYS Runtime Toolkit 3.5.21.10. These vulnerabilities are…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: keb-automation.csaf-tp.certvde

#OT #Advisory

##

CVE-2025-41659
(8.3 HIGH)

EPSS: 0.22%

updated 2026-06-17T09:22:54.780000

1 posts

A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys. This allows sensitive data to be extracted or to accept certificates as trusted. Although all services remain available, only unencrypted communication is possible if the certificates are deleted.

certvde@infosec.exchange at 2026-10-08T06:42:39.000Z ##

🔒 New CSAF advisory published

VDE-2026-105
KEB Automation: Multiple Vulnerabilities in COMBIVIS Control Runtime
CVE-2025-41659, CVE-2025-41691, CVE-2025-41739, CVE-2025-41738

The Docker-based COMBIVIS Control Runtime service is affected by several vulnerabilities in CODESYS Runtime Toolkit 3.5.21.10. These vulnerabilities are…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: keb-automation.csaf-tp.certvde

#OT #Advisory

##

security_crawler_carl@infosec.exchange at 2026-10-07T20:29:36.000Z ##

Patch Ivanti Sentry against CVE-2026-10520 and scan your environment for PoeLLM infections before the next stanza drops.

Reward: You've received a Tattered Broadside of Suspicious Verse. We recommend not parsing it.

theregister.com/security/2026/

#Malware #CyberSecurity #Ivanti #ZeroDay #APT #PatchedOrPerish (3/3)

##

security_crawler_carl@infosec.exchange at 2026-10-07T20:29:36.000Z ##

It locates its command-and-control server not through conventional means, but by parsing poetry — extracting keywords, converting them to numbers via a hard-coded dictionary, and silently pivoting to wherever the operator rewrites the verse. Keats never had this kind of reach.

The compromised host, much like the lesser-spotted migratory waterfowl before a storm, immediately began scanning for further vulnerable devices. CVE-2026-10520 is the wound; the poem is the leash. (2/3)

##

CVE-2024-50623
(8.8 HIGH)

EPSS: 98.61%

updated 2025-10-22T00:34:15

2 posts

In Cleo Harmony before 5.8.0.20, VLTrader before 5.8.0.20, and LexiCom before 5.8.0.20, there is a JavaScript Injection vulnerability.

Nuclei template

4 repos

https://github.com/iSee857/Cleo-CVE-2024-50623-PoC

https://github.com/verylazytech/CVE-2024-50623

https://github.com/watchtowrlabs/CVE-2024-50623

https://github.com/congdong007/CVE-2024-50623-poc

security_crawler_carl@infosec.exchange at 2026-10-08T11:29:04.000Z ##

The verdict on whether Aon was actually breached, encrypted, or exfiltrated remains, as of October 7, 2026, unconfirmed. The court is unimpressed by this lack of closure.

Sentencing is pending, but the docket is clear: patch your Cleo managed file-transfer software against CVE-2024-50623 immediately or await your own summons.

Reward: You've received a Subpoena of Moderate Urgency. It is not transferable.

shattered.io/aon-ransomware-cv

#Ransomware #Cleo (2/2)

##

security_crawler_carl@infosec.exchange at 2026-10-08T11:29:04.000Z ##

🏆 New Achievement! Exhibit A: Two-Year-Old Bug, Still Loaded!

The court finds as follows. Aon, insurance and risk-advisory colossus, stands named in connection with the Termite ransomware group's exploitation of CVE-2024-50623, a vulnerability in Cleo's managed file-transfer software that has been kicking around since 2024. Rescana and BleepingComputer raised the charges. (1/2)

##

CVE-2021-26085
(5.3 MEDIUM)

EPSS: 99.94%

updated 2025-10-22T00:33:23

1 posts

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.

Nuclei template

2 repos

https://github.com/ColdFusionX/CVE-2021-26085

https://github.com/zeroc00I/CVE-2021-26085

ssvc@infosec.exchange at 2026-10-06T19:58:17.000Z ##

@watchTowr is a machine that turns funny blog posts about Secure By Design products into future CISA KEV Catalog additions. This time it's Atlassian pre-auth arbitrary file read CVE-2026-21589 (9.3 critical). Given that there's a similar "Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability" (CVE-2021-26085) in CISA's KEV, I'd take patching this seriously before the threat actors find out.

labs.watchtowr.com/you-wont-he

#atlassian #confluence #CVE #jira #bamboo

##

CVE-2025-41691
(7.5 HIGH)

EPSS: 0.55%

updated 2025-08-04T09:30:34

1 posts

An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime systems by sending specially crafted communication requests, potentially leading to a denial-of-service (DoS) condition.

certvde@infosec.exchange at 2026-10-08T06:42:39.000Z ##

🔒 New CSAF advisory published

VDE-2026-105
KEB Automation: Multiple Vulnerabilities in COMBIVIS Control Runtime
CVE-2025-41659, CVE-2025-41691, CVE-2025-41739, CVE-2025-41738

The Docker-based COMBIVIS Control Runtime service is affected by several vulnerabilities in CODESYS Runtime Toolkit 3.5.21.10. These vulnerabilities are…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: keb-automation.csaf-tp.certvde

#OT #Advisory

##

CVE-2023-22894
(7.5 HIGH)

EPSS: 1.66%

updated 2023-11-07T05:05:45

4 posts

### Summary Strapi through 4.7.1 allows unauthenticated attackers to discover sensitive user details for Strapi administrators and API users. ### Details Strapi through 4.7.1 allows unauthenticated attackers to discover sensitive user details for Strapi administrators and API users. The unauthenticated attacker can filter users by columns that contain sensitive information and infer the values

2 repos

https://github.com/Saboor-Hakimi/CVE-2023-22894

https://github.com/maxntv/CVE-2023-22894-PoC

secdb at 2026-10-08T19:00:11.504Z ##

🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3306 (secdb.nttzen.cloud/cve/detail/)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: proftpd.org/ ; lists.debian.org/debian-securi ; lists.opensuse.org/archives/li ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5477 (secdb.nttzen.cloud/cve/detail/)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: web.archive.org/web/2015072901 ; access.redhat.com/errata/RHSA-; supportportal.juniper.net/s/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2016-3081 (secdb.nttzen.cloud/cve/detail/)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: cwiki.apache.org/confluence/di ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-3199 (secdb.nttzen.cloud/cve/detail/)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; github.com/ONLYOFFICE/Document ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2023-22894 (secdb.nttzen.cloud/cve/detail/)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: strapi.io/blog/security-disclo ; github.com/strapi/strapi/relea ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-10-08T18:01:28.000Z ##

CVE ID: CVE-2023-22894
Vendor: Strapi
Product: Strapi
Date Added: 2026-10-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-10-08T19:00:11.000Z ##

🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3306 (secdb.nttzen.cloud/cve/detail/)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: proftpd.org/ ; lists.debian.org/debian-securi ; lists.opensuse.org/archives/li ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5477 (secdb.nttzen.cloud/cve/detail/)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: web.archive.org/web/2015072901 ; access.redhat.com/errata/RHSA-; supportportal.juniper.net/s/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2016-3081 (secdb.nttzen.cloud/cve/detail/)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: cwiki.apache.org/confluence/di ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-3199 (secdb.nttzen.cloud/cve/detail/)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; github.com/ONLYOFFICE/Document ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2023-22894 (secdb.nttzen.cloud/cve/detail/)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: strapi.io/blog/security-disclo ; github.com/strapi/strapi/relea ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261008 #cisa20261008 #cve_2015_3306 #cve_2015_5477 #cve_2016_3081 #cve_2021_3199 #cve_2023_22894 #cve20153306 #cve20155477 #cve20163081 #cve20213199 #cve202322894

##

cisakevtracker@mastodon.social at 2026-10-08T18:01:28.000Z ##

CVE ID: CVE-2023-22894
Vendor: Strapi
Product: Strapi
Date Added: 2026-10-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2016-3081
(8.1 HIGH)

EPSS: 93.35%

updated 2023-11-01T19:47:30

5 posts

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.

Nuclei template

ninjaintelgroup@mastodon.social at 2026-10-08T19:15:39.000Z ##

🚨 NEW on CISA KEV — exploited in the wild

🛡 Apache Struts
Apache Struts Command Injection Vulnerability
CVE: CVE-2016-3081 · patch by 2026-10-11

Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.

🔗 ninjasignal.ninja/intel/cve/CV
#cybersecurity #KEV #CVE #infosec

##

secdb at 2026-10-08T19:00:11.504Z ##

🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3306 (secdb.nttzen.cloud/cve/detail/)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: proftpd.org/ ; lists.debian.org/debian-securi ; lists.opensuse.org/archives/li ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5477 (secdb.nttzen.cloud/cve/detail/)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: web.archive.org/web/2015072901 ; access.redhat.com/errata/RHSA-; supportportal.juniper.net/s/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2016-3081 (secdb.nttzen.cloud/cve/detail/)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: cwiki.apache.org/confluence/di ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-3199 (secdb.nttzen.cloud/cve/detail/)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; github.com/ONLYOFFICE/Document ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2023-22894 (secdb.nttzen.cloud/cve/detail/)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: strapi.io/blog/security-disclo ; github.com/strapi/strapi/relea ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-10-08T18:01:13.000Z ##

CVE ID: CVE-2016-3081
Vendor: Apache
Product: Struts
Date Added: 2026-10-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-10-08T19:00:11.000Z ##

🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3306 (secdb.nttzen.cloud/cve/detail/)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: proftpd.org/ ; lists.debian.org/debian-securi ; lists.opensuse.org/archives/li ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5477 (secdb.nttzen.cloud/cve/detail/)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: web.archive.org/web/2015072901 ; access.redhat.com/errata/RHSA-; supportportal.juniper.net/s/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2016-3081 (secdb.nttzen.cloud/cve/detail/)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: cwiki.apache.org/confluence/di ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-3199 (secdb.nttzen.cloud/cve/detail/)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; github.com/ONLYOFFICE/Document ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2023-22894 (secdb.nttzen.cloud/cve/detail/)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: strapi.io/blog/security-disclo ; github.com/strapi/strapi/relea ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261008 #cisa20261008 #cve_2015_3306 #cve_2015_5477 #cve_2016_3081 #cve_2021_3199 #cve_2023_22894 #cve20153306 #cve20155477 #cve20163081 #cve20213199 #cve202322894

##

cisakevtracker@mastodon.social at 2026-10-08T18:01:13.000Z ##

CVE ID: CVE-2016-3081
Vendor: Apache
Product: Struts
Date Added: 2026-10-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-84276
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-10-08T19:30:41.000Z ##

🟠 CVE-2026-84276 - High (7.5)

IBM Guardium Data Protection 12.2.2 is affected by a denial-of-service vulnerability in the edge-controller. An unauthenticated remote attacker with network access to the edge-controller gRPC service can provide malformed task data that triggers a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-08T19:30:41.000Z ##

🟠 CVE-2026-84276 - High (7.5)

IBM Guardium Data Protection 12.2.2 is affected by a denial-of-service vulnerability in the edge-controller. An unauthenticated remote attacker with network access to the edge-controller gRPC service can provide malformed task data that triggers a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107332
(0 None)

EPSS: 0.00%

2 posts

N/A

awssecurityfeed at 2026-10-08T17:45:00.853Z ##

CVE-2026-107332 - Insecure default file permissions on cached credentials in AWS Toolkit for Visual Studio Code

Bulletin ID: 2026-129-AWS

Scope: AWS

Content Type: Important (requires attention)

Publication Date: 10/08/2026 10:30 PM PDT
Description:
AWS Toolkit for Visual Studio Code is an open source extension that lets developers ...

aws.amazon.com/security/securi

##

awssecurityfeed@infosec.exchange at 2026-10-08T17:45:00.000Z ##

CVE-2026-107332 - Insecure default file permissions on cached credentials in AWS Toolkit for Visual Studio Code

Bulletin ID: 2026-129-AWS

Scope: AWS

Content Type: Important (requires attention)

Publication Date: 10/08/2026 10:30 PM PDT
Description:
AWS Toolkit for Visual Studio Code is an open source extension that lets developers ...

aws.amazon.com/security/securi

#aws #security

##

japancyberwatch@infosec.exchange at 2026-10-08T11:28:03.000Z ##

JPCERT/CC has issued a warning on the wave of data breaches at Japanese organizations since around September.

Not one shared flaw. Three patterns:
- Scanning each target for known vulns and exposed config/backup files
- Internal API abuse, with endpoints and keys pulled from public smartphone apps
- Metabase SQLi (CVE-2026-72898)

Attacker IPs published. Macnica counts 119 similar breaches in Japan this year, 81 since July.

japancyberwatch.com/articles/j

#cybersecurity #APIsecurity #Japan #infosec

##

CVE-2026-77459
(0 None)

EPSS: 0.00%

1 posts

N/A

CVE-2026-103416
(0 None)

EPSS: 0.21%

1 posts

N/A

offseq@infosec.exchange at 2026-10-07T10:30:28.000Z ##

CVE-2026-103416: CRITICAL out-of-bounds write in Eclipse ThreadX NetX Duo (≤6.5.1.202602). Exploitable pre-cert auth; risk of code execution or DoS. Patch not released — check vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026103416 #infosec #vuln

##

CVE-2026-105797
(0 None)

EPSS: 0.56%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-06T20:16:13.000Z ##

🟠 CVE-2026-105797 - High (8.8)

SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. In versions 0.261.003 and 0.261.027, an authorization ordering flaw in POST /api/user/plugins allows an authenticated low-pri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105793
(0 None)

EPSS: 0.86%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-06T20:15:55.000Z ##

🔴 CVE-2026-105793 - Critical (9.1)

Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the press_key tool in ufo/client/mcp/http_servers/mobile_mcp_server.py accepts a free-form key_code parameter and passes it to `adb ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61744
(0 None)

EPSS: 0.51%

1 posts

N/A

hugovalters@mastodon.social at 2026-10-06T19:10:03.000Z ##

CVE-2026-61744 InvenTree: authenticated barcode API lets attackers read arbitrary model records via crafted JSON, exposing full serializer output. CVSS 6.5. Patch still under review, so restrict API access now. valtersit.com/cve/CVE-2026-617 #CVE #infosec #InvenTree

##

Visit counter For Websites